Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://github.com/Matty77o/malware-samples-m-h/raw/refs/heads/main/TheTrueFriend.exe

Overview

General Information

Sample URL:https://github.com/Matty77o/malware-samples-m-h/raw/refs/heads/main/TheTrueFriend.exe
Analysis ID:1540362
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found pyInstaller with non standard icon
Modifies existing user documents (likely ransomware behavior)
Creates a process in suspended mode (likely to inject code)
Drops PE files
Found dropped PE file which has not been started or loaded
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious desktop.ini Action
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6964 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6232 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=1888,i,6360710991559555093,7547686259353660829,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3924 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4900 --field-trial-handle=1888,i,6360710991559555093,7547686259353660829,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • TheTrueFriend.exe (PID: 2528 cmdline: "C:\Users\user\Downloads\TheTrueFriend.exe" MD5: 2345503234E8E31D072AB294FBD4DA67)
      • TheTrueFriend.exe (PID: 3540 cmdline: "C:\Users\user\Downloads\TheTrueFriend.exe" MD5: 2345503234E8E31D072AB294FBD4DA67)
  • chrome.exe (PID: 3600 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://github.com/Matty77o/malware-samples-m-h/raw/refs/heads/main/TheTrueFriend.exe" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • notepad.exe (PID: 4080 cmdline: "C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\encryption_notification.txt MD5: 27F71B12CB585541885A31BE22F61C83)
  • rundll32.exe (PID: 5144 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • cleanup
No yara matches
Source: File createdAuthor: Maxime Thiebaut (@0xThiebaut), Tim Shelton (HAWK.IO): Data: EventID: 11, Image: C:\Users\user\Downloads\TheTrueFriend.exe, ProcessId: 3540, TargetFilename: C:\Users\user\Downloads\desktop.ini
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI25282\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\Local\Temp\
Source: chrome.exeMemory has grown: Private usage: 25MB later: 39MB
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: github.com
Source: global trafficDNS traffic detected: DNS query: raw.githubusercontent.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: discord.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49714 version: TLS 1.2

Spam, unwanted Advertisements and Ransom Demands

barindex
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile deleted: C:\Users\user\Desktop\EOWRVPQCCS\GIGIYTFFYT.png
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile deleted: C:\Users\user\Desktop\EOWRVPQCCS.docx
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile deleted: C:\Users\user\Desktop\ZGGKNSUKOP\ZGGKNSUKOP.docx
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile deleted: C:\Users\user\Desktop\EIVQSAOTAQ\KLIZUSIQEN.xlsx
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile deleted: C:\Users\user\Desktop\EIVQSAOTAQ\UNKRLCVOHV.png
Source: classification engineClassification label: mal48.rans.win@27/960@9/87
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282
Source: C:\Users\user\Downloads\TheTrueFriend.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=1888,i,6360710991559555093,7547686259353660829,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://github.com/Matty77o/malware-samples-m-h/raw/refs/heads/main/TheTrueFriend.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4900 --field-trial-handle=1888,i,6360710991559555093,7547686259353660829,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=1888,i,6360710991559555093,7547686259353660829,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4900 --field-trial-handle=1888,i,6360710991559555093,7547686259353660829,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Users\user\Downloads\TheTrueFriend.exe "C:\Users\user\Downloads\TheTrueFriend.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Users\user\Downloads\TheTrueFriend.exe "C:\Users\user\Downloads\TheTrueFriend.exe"
Source: C:\Users\user\Downloads\TheTrueFriend.exeProcess created: C:\Users\user\Downloads\TheTrueFriend.exe "C:\Users\user\Downloads\TheTrueFriend.exe"
Source: C:\Users\user\Downloads\TheTrueFriend.exeProcess created: C:\Users\user\Downloads\TheTrueFriend.exe "C:\Users\user\Downloads\TheTrueFriend.exe"
Source: unknownProcess created: C:\Windows\System32\notepad.exe "C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\encryption_notification.txt
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: version.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: vcruntime140.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: libcrypto-3.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: libssl-3.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: mswsock.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: tcl86t.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: tk86t.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: netapi32.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: userenv.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: zlib1.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: logoncli.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: netutils.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: samcli.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: wintypes.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: wintypes.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: wintypes.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Downloads\TheTrueFriend.exeSection loaded: textshaping.dll
Source: C:\Windows\System32\notepad.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\notepad.exeSection loaded: uxtheme.dll
Source: C:\Windows\System32\notepad.exeSection loaded: mrmcorer.dll
Source: C:\Windows\System32\notepad.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\notepad.exeSection loaded: wldp.dll
Source: C:\Windows\System32\notepad.exeSection loaded: textshaping.dll
Source: C:\Windows\System32\notepad.exeSection loaded: efswrt.dll
Source: C:\Windows\System32\notepad.exeSection loaded: mpr.dll
Source: C:\Windows\System32\notepad.exeSection loaded: wintypes.dll
Source: C:\Windows\System32\notepad.exeSection loaded: twinapi.appcore.dll
Source: C:\Windows\System32\notepad.exeSection loaded: oleacc.dll
Source: C:\Windows\System32\notepad.exeSection loaded: textinputframework.dll
Source: C:\Windows\System32\notepad.exeSection loaded: coreuicomponents.dll
Source: C:\Windows\System32\notepad.exeSection loaded: coremessaging.dll
Source: C:\Windows\System32\notepad.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\notepad.exeSection loaded: urlmon.dll
Source: C:\Windows\System32\notepad.exeSection loaded: iertutil.dll
Source: C:\Windows\System32\notepad.exeSection loaded: srvcli.dll
Source: C:\Windows\System32\notepad.exeSection loaded: netutils.dll
Source: C:\Windows\System32\notepad.exeSection loaded: propsys.dll
Source: C:\Windows\System32\notepad.exeSection loaded: policymanager.dll
Source: C:\Windows\System32\notepad.exeSection loaded: msvcp110_win.dll
Source: C:\Windows\System32\notepad.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11659a23-5884-4d1b-9cf6-67d6f4f90b36}\InProcServer32
Source: Window RecorderWindow detected: More than 3 window changes detected

Persistence and Installation Behavior

barindex
Source: C:\Users\user\Downloads\TheTrueFriend.exeProcess created: "C:\Users\user\Downloads\TheTrueFriend.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\Unconfirmed 841325.crdownloadJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\python312.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_decimal.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\tcl86t.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_socket.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\libssl-3.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_tkinter.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_bz2.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\python3.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_cffi_backend.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\cryptography\hazmat\bindings\_rust.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_ssl.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\tk86t.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_queue.pydJump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\e9b904d1-fa9d-4614-9bf7-5fb88df07782.tmpJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\VCRUNTIME140.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_hashlib.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\charset_normalizer\md__mypyc.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\select.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\unicodedata.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\_lzma.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\zlib1.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI25282\libcrypto-3.dllJump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\python312.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_decimal.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_queue.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\VCRUNTIME140.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_socket.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_hashlib.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_tkinter.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_bz2.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\python3.dllJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_cffi_backend.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\cryptography\hazmat\bindings\_rust.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\charset_normalizer\md__mypyc.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\select.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\unicodedata.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_lzma.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI25282\_ssl.pydJump to dropped file
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI25282\
Source: C:\Users\user\Downloads\TheTrueFriend.exeFile opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Users\user\Downloads\TheTrueFriend.exeProcess created: C:\Users\user\Downloads\TheTrueFriend.exe "C:\Users\user\Downloads\TheTrueFriend.exe"
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\encoding VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\http1.0 VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\msgs VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\opt0.4 VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\Africa VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Argentina VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Argentina VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Argentina VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Argentina VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Argentina VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Argentina VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Argentina VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Argentina VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Indiana VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America\Kentucky VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data\tzdata\America VolumeInformation
Source: C:\Users\user\Downloads\TheTrueFriend.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI25282\_tcl_data VolumeInformation
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
11
Process Injection
1
Masquerading
OS Credential Dumping1
File and Directory Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network Medium1
Data Encrypted for Impact
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
1
Rundll32
LSASS Memory11
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Registry Run Keys / Startup Folder
11
Process Injection
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Extra Window Memory Injection
1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Extra Window Memory Injection
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\_MEI25282\VCRUNTIME140.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_bz2.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_cffi_backend.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_decimal.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_hashlib.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_lzma.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_queue.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_socket.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_ssl.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\_tkinter.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\charset_normalizer\md.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\charset_normalizer\md__mypyc.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\cryptography\hazmat\bindings\_rust.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\libcrypto-3.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\libssl-3.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\python3.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\python312.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\select.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\tcl86t.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\tk86t.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\unicodedata.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI25282\zlib1.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
discord.com
162.159.135.232
truefalse
    unknown
    github.com
    140.82.121.4
    truefalse
      unknown
      raw.githubusercontent.com
      185.199.108.133
      truefalse
        unknown
        www.google.com
        142.250.185.132
        truefalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.251.168.84
          unknownUnited States
          15169GOOGLEUSfalse
          1.1.1.1
          unknownAustralia
          13335CLOUDFLARENETUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.185.131
          unknownUnited States
          15169GOOGLEUSfalse
          185.199.108.133
          raw.githubusercontent.comNetherlands
          54113FASTLYUSfalse
          142.250.186.131
          unknownUnited States
          15169GOOGLEUSfalse
          142.250.186.110
          unknownUnited States
          15169GOOGLEUSfalse
          142.250.185.132
          www.google.comUnited States
          15169GOOGLEUSfalse
          140.82.121.4
          github.comUnited States
          36459GITHUBUSfalse
          142.250.184.206
          unknownUnited States
          15169GOOGLEUSfalse
          162.159.135.232
          discord.comUnited States
          13335CLOUDFLARENETUSfalse
          IP
          192.168.2.16
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1540362
          Start date and time:2024-10-23 17:35:16 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:defaultwindowsinteractivecookbook.jbs
          Sample URL:https://github.com/Matty77o/malware-samples-m-h/raw/refs/heads/main/TheTrueFriend.exe
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:20
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          Analysis Mode:stream
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal48.rans.win@27/960@9/87
          • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 199.232.210.172, 142.250.186.131, 142.250.186.110, 142.251.168.84, 34.104.35.123
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtCreateFile calls found.
          • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
          • VT rate limit hit for: https://github.com/Matty77o/malware-samples-m-h/raw/refs/heads/main/TheTrueFriend.exe
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
          Category:dropped
          Size (bytes):119192
          Entropy (8bit):6.6016214745004635
          Encrypted:false
          SSDEEP:
          MD5:BE8DBE2DC77EBE7F88F910C61AEC691A
          SHA1:A19F08BB2B1C1DE5BB61DAF9F2304531321E0E40
          SHA-256:4D292623516F65C80482081E62D5DADB759DC16E851DE5DB24C3CBB57B87DB83
          SHA-512:0DA644472B374F1DA449A06623983D0477405B5229E386ACCADB154B43B8B083EE89F07C3F04D2C0C7501EAD99AD95AECAA5873FF34C5EEB833285B598D5A655
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N.../c../c../c._]b./c..W.../c../b./c../c../c...`./c...g./c...f./c...c./c....../c...a./c.Rich./c.........................PE..d.....cW.........." ...&. ...d......................................................-.....`A.........................................e..4...4m...........................O...........N..p............................L..@............0...............................text...&........................... ..`fothk........ ...................... ..`.rdata..\C...0...D...$..............@..@.data...p............h..............@....pdata...............l..............@..@_RDATA...............x..............@..@.rsrc................z..............@..@.reloc...............~..............@..B................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):85272
          Entropy (8bit):6.581027304618609
          Encrypted:false
          SSDEEP:
          MD5:223FD6748CAE86E8C2D5618085C768AC
          SHA1:DCB589F2265728FE97156814CBE6FF3303CD05D3
          SHA-256:F81DC49EAC5ECC528E628175ADD2FF6BDA695A93EA76671D7187155AA6326ABB
          SHA-512:9C22C178417B82E68F71E5B7FE7C0C0A77184EE12BD0DC049373EACE7FA66C89458164D124A9167AE760FF9D384B78CA91001E5C151A51AD80C824066B8ECCE6
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......o~..+...+...+..."g..!...-...)...-.i.(...-...&...-...#...-.../...D...(...`g..)...+...t...D...#...D...*...D.k.*...D...*...Rich+...........................PE..d....K.f.........." ...&.....^...............................................`.......b....`.............................................H............@.......0..8......../...P..........T...........................p...@............................................text............................... ..`.rdata...>.......@..................@..@.data........ ......................@....pdata..8....0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B........................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):182784
          Entropy (8bit):6.193615170968096
          Encrypted:false
          SSDEEP:
          MD5:0572B13646141D0B1A5718E35549577C
          SHA1:EEB40363C1F456C1C612D3C7E4923210EAE4CDF7
          SHA-256:D8A76D1E31BBD62A482DEA9115FC1A109CB39AF4CF6D1323409175F3C93113A7
          SHA-512:67C28432CA8B389ACC26E47EB8C4977FDDD4AF9214819F89DF07FECBC8ED750D5F35807A1B195508DD1D77E2A7A9D7265049DCFBFE7665A7FD1BA45DA1E4E842
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........(...I.C.I.C.I.C.1MC.I.C.<.B.I.C.&#C.I.C.<.B.I.C.<.B.I.C.<.B.I.C.1.B.I.C.4.B.I.C.I.C I.C.<.B.I.C.1KC.I.C.<.B.I.C.<!C.I.C.<.B.I.CRich.I.C................PE..d...g..e.........." .........@......`........................................@............`..........................................w..l....w....... ..........l............0.......]...............................]..8............................................text............................... ..`.rdata..............................@..@.data...h].......0...|..............@....pdata..l...........................@..@.rsrc........ ......................@..@.reloc.......0......................@..B........................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):251672
          Entropy (8bit):6.565757128183933
          Encrypted:false
          SSDEEP:
          MD5:3055EDF761508190B576E9BF904003AA
          SHA1:F0DC8D882B5CD7955CC6DFC8F9834F70A83C7890
          SHA-256:E4104E47399D3F635A14D649F61250E9FD37F7E65C81FFE11F099923F8532577
          SHA-512:87538FE20BD2C1150A8FEFD0478FFD32E2A9C59D22290464BF5DFB917F6AC7EC874F8B1C70D643A4DC3DD32CBE17E7EA40C0BE3EA9DD07039D94AB316F752248
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........hW.....................f.......f.......f.......f.......f......................f.......f.......f.......f.......f......Rich............PE..d...yK.f.........." ...&.p...<......................................................i ....`..........................................D..P....E..................`'......./......T.......T...........................@...@............................................text...9o.......p.................. ..`.rdata..H............t..............@..@.data...X*...`...$...L..............@....pdata..`'.......(...p..............@..@.rsrc...............................@..@.reloc..T...........................@..B........................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):65816
          Entropy (8bit):6.241463396742061
          Encrypted:false
          SSDEEP:
          MD5:EEDB6D834D96A3DFFFFB1F65B5F7E5BE
          SHA1:ED6735CFDD0D1EC21C7568A9923EB377E54B308D
          SHA-256:79C4CDE23397B9A35B54A3C2298B3C7A844454F4387CB0693F15E4FACD227DD2
          SHA-512:527BD7BB2F4031416762595F4CE24CBC6254A50EAF2CC160B930950C4F2B3F5E245A486972148C535F8CD80C78EC6FA8C9A062085D60DB8F23D4B21E8AE4C0AD
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~z.A:...:...:...3ca.>...<...8...<...6...<...2...<...9...U...8...qc..8.......9...:.......U...;...U...;...U...;...U...;...Rich:...........................PE..d....K.f.........." ...&.T..........L@..............................................lg....`.............................................P.............................../......X...@}..T............................|..@............p..(............................text...wS.......T.................. ..`.rdata..&O...p...P...X..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..X...........................@..B........................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):160024
          Entropy (8bit):6.841300813767097
          Encrypted:false
          SSDEEP:
          MD5:05E8B2C429AFF98B3AE6ADC842FB56A3
          SHA1:834DDBCED68DB4FE17C283AB63B2FAA2E4163824
          SHA-256:A6E2A5BB7A33AD9054F178786A031A46EA560FAEEF1FB96259331500AAE9154C
          SHA-512:BADEB99795B89BC7C1F0C36BECC7A0B2CE99ECFD6F6BB493BDA24B8E57E6712E23F4C509C96A28BC05200910BEDDC9F1536416BBC922331CAE698E813CBB50B3
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........3..MRu.MRu.MRu.D*..IRu.K.t.ORu.K.p.ARu.K.q.ERu.K.v.NRu.".t.NRu..*t.ORu.MRt.(Ru.".x.wRu.".u.LRu."..LRu.".w.LRu.RichMRu.........................PE..d....K.f.........." ...&.f...........8..............................................`3....`......................................... %..L...l%..x....p.......P.......B.../......4.......T...............................@............................................text....d.......f.................. ..`.rdata..............j..............@..@.data...h....@......................@....pdata.......P......."..............@..@.rsrc........p.......6..............@..@.reloc..4............@..............@..B................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):32536
          Entropy (8bit):6.462349221807228
          Encrypted:false
          SSDEEP:
          MD5:6E0CB85DC94E351474D7625F63E49B22
          SHA1:66737402F76862EB2278E822B94E0D12DCB063C5
          SHA-256:3F57F29ABD86D4DC8F4CA6C3F190EBB57D429143D98F0636FF5117E08ED81F9B
          SHA-512:1984B2FC7F9BBDF5BA66716FC60DCFD237F38E2680F2FC61F141FF7E865C0DBDD7CDC47B3BC490B426C6CFE9F3F9E340963ABF428EA79EB794B0BE7D13001F6A
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........\.~...~...~.......~.......~.......~.......~.......~.......~.......~...~...~.......~.......~....}..~.......~..Rich.~..................PE..d....K.f.........." ...&.....8......................................................\]....`..........................................C..L....C..d....p.......`.......P.../..........p4..T...........................03..@............0..8............................text............................... ..`.rdata.......0......................@..@.data........P.......<..............@....pdata.......`.......@..............@..@.rsrc........p.......D..............@..@.reloc...............N..............@..B........................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):83224
          Entropy (8bit):6.336512797446254
          Encrypted:false
          SSDEEP:
          MD5:DC06F8D5508BE059EAE9E29D5BA7E9EC
          SHA1:D666C88979075D3B0C6FD3BE7C595E83E0CB4E82
          SHA-256:7DAFF6AA3851A913ED97995702A5DFB8A27CB7CF00FB496597BE777228D7564A
          SHA-512:57EB36BC1E9BE20C85C34B0A535B2349CB13405D60E752016E23603C4648939F1150E4DBEBC01EC7B43EB1A6947C182CCB8A806E7E72167AD2E9D98D1FD94AB3
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......D.i....}...}...}..}...}.0.|...}.0.|...}.0.|...}.0.|...}o0.|...}...}...}K..|...}o0.|...}o0.|...}o0.}...}o0.|...}Rich...}........PE..d....K.f.........." ...&.v...........-.......................................`............`.............................................P............@.......0.........../...P..........T...............................@............................................text....u.......v.................. ..`.rdata...x.......z...z..............@..@.data...............................@....pdata.......0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):178456
          Entropy (8bit):5.9718801387586655
          Encrypted:false
          SSDEEP:
          MD5:5B9B3F978D07E5A9D701F832463FC29D
          SHA1:0FCD7342772AD0797C9CB891BF17E6A10C2B155B
          SHA-256:D568B3C99BF0FC35A1F3C5F66B4A9D3B67E23A1D3CF0A4D30499D924D805F5AA
          SHA-512:E4DB56C8E0E9BA0DB7004463BF30364A4E4AB0B545FB09F40D2DBA67B79B6B1C1DB07DF1F017501E074ABD454D1E37A4167F29E7BBB0D4F8958FA0A2E9F4E405
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&h^.G...G...G...?...G.......G.......G.......G.......G.......G.......G...G..eF...?...G.......G.......G.......G.......G..Rich.G..................PE..d....K.f.........." ...&............X,..............................................c:....`.............................................d...D...................P......../......x.......T...........................@...@............................................text...$........................... ..`.rdata...#.......$..................@..@.data...h...........................@....pdata..P............b..............@..@.rsrc................n..............@..@.reloc..x............x..............@..B................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):21523
          Entropy (8bit):4.827830596623684
          Encrypted:false
          SSDEEP:
          MD5:08EDF746B4A088CB4185C165177BD604
          SHA1:395CDA114F23E513EEF4618DA39BB86D034124BF
          SHA-256:517204EE436D08EFC287ABC97433C3BFFCAF42EC6592A3009B9FD3B985AD772C
          SHA-512:C1727E265A6B0B54773C886A1BCE73512E799BA81A4FCEEEB84CDC33F5505A5E0984E96326A78C46BF142BC4652A80E213886F60EB54ADF92E4DFFE953C87F6B
          Malicious:false
          Reputation:unknown
          Preview:# auto.tcl --..#..# utility procs formerly in init.tcl dealing with auto execution of commands..# and can be auto loaded themselves...#..# Copyright (c) 1991-1993 The Regents of the University of userfornia...# Copyright (c) 1994-1998 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# auto_reset --..#..# Destroy all cached information for auto-loading and auto-execution, so that..# the information gets recomputed the next time it's needed. Also delete any..# commands that are listed in the auto-load index...#..# Arguments:..# None.....proc auto_reset {} {.. global auto_execs auto_index auto_path.. if {[array exists auto_index]} {...foreach cmdName [array names auto_index] {... set fqcn [namespace which $cmdName]... if {$fqcn eq ""} {....continue... }... rename $fqcn {}...}.. }.. unset -nocomplain auto_execs auto_index ::tcl::auto_oldpath.. if {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):133439
          Entropy (8bit):5.044814789288095
          Encrypted:false
          SSDEEP:
          MD5:88BB44A1364147FDD80F9FD78FBCEF61
          SHA1:2C3454D2669F0CA83FECF17976D599C85B86E615
          SHA-256:1947F8B188AB4AB6AA72EA68A58D2D9ADD0894FDF320F6B074EAE0F198368FB7
          SHA-512:010B13E8A2D50521B5D7ADCC5F32F7CDE3F12E1053961C575D967DC6CFD368640BF45D23832E5E9C3868CDCA9FE0505698F949C5557D4169353634C94AA196B5
          Malicious:false
          Reputation:unknown
          Preview:#----------------------------------------------------------------------..#..# clock.tcl --..#..#.This file implements the portions of the [clock] ensemble that are..#.coded in Tcl. Refer to the users' manual to see the description of..#.the [clock] command and its subcommands...#..#..#----------------------------------------------------------------------..#..# Copyright (c) 2004-2007 Kevin B. Kenny..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#..#----------------------------------------------------------------------....# We must have message catalogs that support the root locale, and we need..# access to the Registry on Windows systems.....uplevel \#0 {.. package require msgcat 1.6.. if { $::tcl_platform(platform) eq {windows} } {...if { [catch { package require registry 1.1 }] } {... namespace eval ::tcl::clock [list variable NoRegistry {}]...}.. }..}....# Put the library directory in
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):2.1033474959326957
          Encrypted:false
          SSDEEP:
          MD5:9E3A454FA480E9A99D2D5ACDAA775233
          SHA1:493637BB570A5C96BB62F998BD0391FB59AFC5F0
          SHA-256:FB87BF197F4F485B08EA81F7534BC07D9C3A538D022424BE11011A1FE3C413FD
          SHA-512:EDFCB2BB6AB052D28D5CEBD08AD57F36D3A4CB83D557B1359B0ADE1266E24D8F3CE87B8240881396A5BA4FB45F8B74014784E8885CDB86680D98977CC0D130F0
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: ascii, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E0000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):94389
          Entropy (8bit):3.3217406555698195
          Encrypted:false
          SSDEEP:
          MD5:41A874778111CC218BD421CF9C795EC2
          SHA1:80857D106F71199CE187833D38DB091A819A520C
          SHA-256:AD1ED201B69855BFD353BF969DFC55576DA35A963ABF1BF7FC6D8B5142A61A61
          SHA-512:4244624124F86A3EFAB4C70B115A46C8ADF02D708860FA5F327CDBFA24BC3F9EFAD0C6EE58DE96B0B6BBC4CF6D99B322BB8657129007C86D6482F41C1503AAD4
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: big5, multi-byte..M..003F 0 89..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):98634
          Entropy (8bit):2.438904802083714
          Encrypted:false
          SSDEEP:
          MD5:B6A7C59E6A48D91CC2DBCB2BBA7E4510
          SHA1:16A9338F18202B26981F2028BEA412DD03BB0FF2
          SHA-256:8924545CC92584169138AADB64683C07BBF846A57014C2E668D23B63F43F3610
          SHA-512:3D644CF394A528A8699BE3679F787A4E1DAD657C04B810580A4C520F2C043471640FBE080AC46DFD3924C47A73BEE12A6AC69D291D09EB791AD0D64A73750B43
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cns11643, double-byte..D..2134 0 93..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00004E284E364E3F4E854E054E04518251965338536953B64E2A4E874E4951E2..4E464E8F4EBC4EBE516651E35204529C53B95902590A5B805DDB5E7A5E7F5EF4..5F505F515F61961D4E3C4E634E624EA351854EC54ECF4ECE4ECC518451865722..572351E45205529E529D52FD5300533A5C735346535D538653B7620953CC6C15..53CE57216C3F5E005F0C623762386534653565E04F0E738D4E974EE04F144EF1..4EE74EF74EE64F1D4F024F054F2256D8518B518C519951E55213520B52A60000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.3578844928761034
          Encrypted:false
          SSDEEP:
          MD5:9568EDE60D3F917F1671F5A625A801C4
          SHA1:4F5B3308FE7F6845B46779DECF9B395E47AC7396
          SHA-256:E2991A6F7A7A4D8D3C4C97947298FD5BACB3EAA2F898CEE17F5E21A9861B9626
          SHA-512:9C32BE3E25FC2211CE91F7B9AE1F9EBA20071272BE2BBBA63A8B6E3CD6543C4C32CD62C4C4D153C94F5BE212E974A61EEFD70DDC005F1688D09D9D56E8E298A8
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1250, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0083201E2026202020210088203001602039015A0164017D0179..009020182019201C201D202220132014009821220161203A015B0165017E017A..00A002C702D8014100A4010400A600A700A800A9015E00AB00AC00AD00AE017B..00B000B102DB014200B400B500B600B700B80105015F00BB013D02DD013E017C..015400C100C2010200C40139010600C7010C00C9011800CB011A00CD00CE010E..01100143014700D300D4015000D600D70158016E00DA017000DC00DD016200DF..015500E100E2010300E40
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.358948900439905
          Encrypted:false
          SSDEEP:
          MD5:83DAF47FD1F87B7B1E9E086F14C39E5B
          SHA1:77AE330512EBFEF430A02213644BD1CFCE174298
          SHA-256:0AA66DFF8A7AE570FEE83A803F8F5391D9F0C9BD6311796592D9B6E8E36BE6FC
          SHA-512:D7CE2F44EDFE1DA6D3E07E9A41BB08AD42430BAAFADD09FD217F4B524323A01A1F4913B640C552D38AAEBFF75B0D50ED7A813A2A57C4019311158890C0162DF9
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1251, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..04020403201A0453201E20262020202120AC203004092039040A040C040B040F..045220182019201C201D202220132014009821220459203A045A045C045B045F..00A0040E045E040800A4049000A600A7040100A9040400AB00AC00AD00AE0407..00B000B104060456049100B500B600B704512116045400BB0458040504550457..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..043004310432043304340
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.292994562910468
          Encrypted:false
          SSDEEP:
          MD5:E9117326C06FEE02C478027CB625C7D8
          SHA1:2ED4092D573289925A5B71625CF43CC82B901DAF
          SHA-256:741859CF238C3A63BBB20EC6ED51E46451372BB221CFFF438297D261D0561C2E
          SHA-512:D0A39BC41ADC32F2F20B1A0EBAD33BF48DFA6ED5CC1D8F92700CDD431DB6C794C09D9F08BB5709B394ACF54116C3A1E060E2ABCC6B503E1501F8364D3EEBCD52
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1252, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202102C62030016020390152008D017D008F..009020182019201C201D20222013201402DC21220161203A0153009D017E0178..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..00D000D100D200D300D400D500D600D700D800D900DA00DB00DC00DD00DE00DF..00E000E100E200E300E40
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.422723556981327
          Encrypted:false
          SSDEEP:
          MD5:441B86A0DE77F25C91DF1CD4685F651D
          SHA1:D1E429916BC9423F55EEC8F17941521E9FE9D32B
          SHA-256:5B8D47451F847C1BDE12CACA3739CA29860553C0B6399EE990D51B26F9A69722
          SHA-512:35DF342DDA4E8790C6D53762465DF8B93B49B7B7E211D7A5753078EF559C9C9383EFF7285A90FF5C0020FBB16AF380EE3C8643F4CEB1E41917E72021079D722F
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1253, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202100882030008A2039008C008D008E008F..009020182019201C201D20222013201400982122009A203A009C009D009E009F..00A00385038600A300A400A500A600A700A800A9000000AB00AC00AD00AE2015..00B000B100B200B3038400B500B600B703880389038A00BB038C00BD038E038F..0390039103920393039403950396039703980399039A039B039C039D039E039F..03A003A1000003A303A403A503A603A703A803A903AA03AB03AC03AD03AE03AF..03B003B103B203B303B40
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.307590929679485
          Encrypted:false
          SSDEEP:
          MD5:5FA9162BEC5A4DEA97B5EA2840CFB065
          SHA1:F26858E3D2FB928F39CA87CBB8446AF099570CAD
          SHA-256:31639CA96A4D3602D59BD012540FE179917E0561CB11A0D0B61F1B950EB76911
          SHA-512:3CE7BEABBE1A0CB946149D263D3317A8B791F6D72C49DEC4621E27F50CC359D8FA3EE97C03FF05D44E47DAA59DB87F219386467614B8B3FF8CC21AB3E3BED5E6
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1254, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202102C62030016020390152008D008E008F..009020182019201C201D20222013201402DC21220161203A0153009D009E0178..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..011E00D100D200D300D400D500D600D700D800D900DA00DB00DC0130015E00DF..00E000E100E200E300E40
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.3385880810272774
          Encrypted:false
          SSDEEP:
          MD5:6DEA4179969D6C81C66C3B0F91B39769
          SHA1:7E2722576BFFABC3258C5EDB2D99FA2468D6A4B0
          SHA-256:47576CAE321C80E69C7F35205639680BF28010111E86E228ED191B084FAC6B91
          SHA-512:91CC626B6454517F06FB3616E9ED623D1A2A4BFE74AFA9885F00F6AEC835D8825A5587091B9D9AB0E5ABDA291FA3FE7CE87E2618E21EB2974D9118AE27B8A2FF
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1255, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202102C62030008A2039008C008D008E008F..009020182019201C201D20222013201402DC2122009A203A009C009D009E009F..00A000A100A200A320AA00A500A600A700A800A900D700AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900F700BB00BC00BD00BE00BF..05B005B105B205B305B405B505B605B705B805B9000005BB05BC05BD05BE05BF..05C005C105C205C305F005F105F205F305F40000000000000000000000000000..05D005D105D205D305D40
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.4033510023542655
          Encrypted:false
          SSDEEP:
          MD5:D50DFAFEE5C605C5C00A25A9EEE4D4CF
          SHA1:7D51BC17931D3D809716C06E7F07C6011286A144
          SHA-256:29340EA8E5AD3532BF67FA77CC852F055081B1238925CB109908AA72804CCC04
          SHA-512:D0A9B422A1061D6239E442767069B987E33239FCBA9BACE677923888F5F8BD1DCAABC71B83A985A0A86A15DCC44316781665BBFBF24558FCB94FDA6783285BCB
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1256, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC067E201A0192201E20262020202102C62030067920390152068606980688..06AF20182019201C201D20222013201406A921220691203A0153200C200D06BA..00A0060C00A200A300A400A500A600A700A800A906BE00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B9061B00BB00BC00BD00BE061F..06C1062106220623062406250626062706280629062A062B062C062D062E062F..063006310632063306340635063600D7063706380639063A0640064106420643..00E0064400E2064506460
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.344584404753015
          Encrypted:false
          SSDEEP:
          MD5:CC3D24543FDD4644BBBD4AAB30CA71BC
          SHA1:8E2658E7F782F005411BCB8423BDFC3C68BDED14
          SHA-256:C15AB85438728BF2C60D72B1A66AF80E8B1CE3CF5EB08BA6421FF1B2F73ACDF4
          SHA-512:5ECABF820098F7D24AB806ADD9CA3E1087C29914FB2DE6BA3DC656234202DE3FDF80A7E9ED433CCB2149FF07184F74884CEB37A1B689E9E0C1402916F3E13AFE
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1257, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0083201E20262020202100882030008A2039008C00A802C700B8..009020182019201C201D20222013201400982122009A203A009C00AF02DB009F..00A0000000A200A300A4000000A600A700D800A9015600AB00AC00AD00AE00C6..00B000B100B200B300B400B500B600B700F800B9015700BB00BC00BD00BE00E6..0104012E0100010600C400C501180112010C00C90179011601220136012A013B..01600143014500D3014C00D500D600D701720141015A016A00DC017B017D00DF..0105012F0101010700E40
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.2984943182702593
          Encrypted:false
          SSDEEP:
          MD5:12BCEAE6B6A5FAE5AE9C42F5998BA485
          SHA1:C9620DA0C763D2C3770386E69EE7E421BD1BA965
          SHA-256:29D93DEE7C01B2264778BC6B75F6EF76EA6AC53E9F4A334D83707229E7F482D2
          SHA-512:714BAF58462FB0E84A32D82C8FC2D63EDF78DF8CCE578391E2521737F94F860B5CCFE41B481E1D09879A6811FCFD8B98A2724DB1D15749BD5293A9B33BCAD071
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp1258, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202102C62030008A20390152008D008E008F..009020182019201C201D20222013201402DC2122009A203A0153009D009E0178..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C2010200C400C500C600C700C800C900CA00CB030000CD00CE00CF..011000D1030900D300D401A000D600D700D800D900DA00DB00DC01AF030300DF..00E000E100E2010300E40
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.515546664597914
          Encrypted:false
          SSDEEP:
          MD5:CE6D8A6542DC12D1783084FA4B2B63EA
          SHA1:5039A350C8E3E2C6F353B438B41BD0B6A7AB8069
          SHA-256:E5613C04D3D2EE44CCAD85AE53A37C257674491C540836E5D942BBCC4E4A8DB4
          SHA-512:E8C5CFB747486BBE0E567B6E87B59D5246D749A80C8F64F6669227C7FD849886F98A1F94451922AC099409AC14890F1A8B1E5F25EA584FDB1522ACE3AD0BE6A6
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp437, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE00EC00C400C5..00C900E600C600F400F600F200FB00F900FF00D600DC00A200A300A520A70192..00E100ED00F300FA00F100D100AA00BA00BF231000AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.6177058818384693
          Encrypted:false
          SSDEEP:
          MD5:8EF3CBCA101F5777846D12D3C96A0A7D
          SHA1:5EC5418B861894E0F18EA15AA4414019815E2EA2
          SHA-256:A0415F14F5D72AD24E9C3A5C91517A0E3D22E1ADBC3505C0C6E918B961F7A07D
          SHA-512:FB14C88E61E5459B4A8706751D88D0A261AC6B4171F72912D87CE78A2BC97A821CCF5B53676FB229C08F9E557BE624F4DC649B722A906B9B7944ED2D5E7F9065
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp737, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..039103920393039403950396039703980399039A039B039C039D039E039F03A0..03A103A303A403A503A603A703A803A903B103B203B303B403B503B603B703B8..03B903BA03BB03BC03BD03BE03BF03C003C103C303C203C403C503C603C703C8..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03C903AC03AD03AE03CA03
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.451057608106102
          Encrypted:false
          SSDEEP:
          MD5:9656761FA02EA24773EAD3E5C4BDB975
          SHA1:366228F25392708FA799E9CC0830CE9917EF6CA7
          SHA-256:C3C6542E902DEC2C44DDCFD8B5CB7ABF309B0413A7CED1614DC0B20CF7C5E35F
          SHA-512:A6A44B9A2193D75764DC284BE53264E57BFEB2A221FD54B4577DD90752F69A45E6B9D293108A7AB895F347A24FD10AAE84954A043AB1F466F485D707D7412380
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp775, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..010600FC00E9010100E4012300E501070142011301560157012B017900C400C5..00C900E600C6014D00F6012200A2015A015B00D600DC00F800A300D800D700A4..0100012A00F3017B017C017A201D00A600A900AE00AC00BD00BC014100AB00BB..259125922593250225240104010C01180116256325512557255D012E01602510..25142534252C251C2500253C0172016A255A25542569256625602550256C017D..0105010D01190117012F01610173016B017E2518250C25882584258C25902580..00D300DF014C014300F500
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.3718781469586827
          Encrypted:false
          SSDEEP:
          MD5:2169EE726DCC011E6C3505D586C88FC3
          SHA1:094252AD0634787E2D7F0D28A448437054D359C7
          SHA-256:13DF611F429A9B331DA1B34F3C718CCCAF0BD4AB44F71A9C632197987B4D643B
          SHA-512:BC5831EF1C131095A22C76FFCB5C4217081AF796B60455BE2DE2E2689CFE1033F07E8B45449F77E7804A7D52CBCFB916B0B4639828E65B14475BB3367F47C8EE
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp850, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE00EC00C400C5..00C900E600C600F400F600F200FB00F900FF00D600DC00F800A300D800D70192..00E100ED00F300FA00F100D100AA00BA00BF00AE00AC00BD00BC00A100AB00BB..2591259225932502252400C100C200C000A9256325512557255D00A200A52510..25142534252C251C2500253C00E300C3255A25542569256625602550256C00A4..00F000D000CA00CB00C8013100CD00CE00CF2518250C2588258400A600CC2580..00D300DF00D400D200F500
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.4509005787389877
          Encrypted:false
          SSDEEP:
          MD5:48402B424B5101BDEEB0192BBA96DB7D
          SHA1:C9EB93A37AF70F4134AA9CF05D914A30FB3201DD
          SHA-256:F3A18A8C7934F6586F023477E08D3F9D5EAD9A45E9E58A3F8D018AF9BB13F868
          SHA-512:4EE615605BFF3D94A7FC4FE23D8288F0F20F6792C8C69ECACABAE82F1A334D8417C5DFFC0DA3702E2DB09B7BE1E5FF19C6A0F460C9A5EC84D1856BB9C8061CA5
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp852, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E4016F010700E7014200EB0150015100EE017900C40106..00C90139013A00F400F6013D013E015A015B00D600DC01640165014100D7010D..00E100ED00F300FA01040105017D017E0118011900AC017A010C015F00AB00BB..2591259225932502252400C100C2011A015E256325512557255D017B017C2510..25142534252C251C2500253C01020103255A25542569256625602550256C00A4..01110110010E00CB010F014700CD00CE011B2518250C258825840162016E2580..00D300DF00D40143014401
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.4277025591531864
          Encrypted:false
          SSDEEP:
          MD5:8B8AA56F83BA750EB73FAE542E76FF1A
          SHA1:2F3C3BA4B854A7D6B0A3D27BC519EE66A042E05A
          SHA-256:E64FD2E639DA6F654D9BFBB2266F9432259A6A55941622F5CDDC3797E382EB0A
          SHA-512:8B4061176663F7AC01B3969D25F680B5870A8EAD864CFAD897F18E75409CE721E6CC367A88EBABAF72E77D4542EE1894F2A6EE47A43FB3D4C650CFA18DFD3D71
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp855, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0452040204530403045104010454040404550405045604060457040704580408..04590409045A040A045B040B045C040C045E040E045F040F044E042E044A042A..0430041004310411044604260434041404350415044404240433041300AB00BB..259125922593250225240445042504380418256325512557255D043904192510..25142534252C251C2500253C043A041A255A25542569256625602550256C00A4..043B041B043C041C043D041D043E041E043F2518250C25882584041F044F2580..042F044004200441042104
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.364496856690505
          Encrypted:false
          SSDEEP:
          MD5:BA52A031DE1B1A6ED1C41BED8946750C
          SHA1:BD54C0E2F62FD36675892A61FD8B340A56845D20
          SHA-256:B6CD5C6F2B54D89142679D599ED0A5DEE6955A3B3F6B6673E46AFE7A5A303CDC
          SHA-512:5F915AABE39F31CE9337B4B9B0239DF8ADA898D2D9F111DD09D97689DB89CF45B093AC187FC28484CFB213D14B0D8F58C5668D0A59726282D6F52D5D24697816
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp857, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE013100C400C5..00C900E600C600F400F600F200FB00F9013000D600DC00F800A300D8015E015F..00E100ED00F300FA00F100D1011E011F00BF00AE00AC00BD00BC00A100AB00BB..2591259225932502252400C100C200C000A9256325512557255D00A200A52510..25142534252C251C2500253C00E300C3255A25542569256625602550256C00A4..00BA00AA00CA00CB00C8000000CD00CE00CF2518250C2588258400A600CC2580..00D300DF00D400D200F500
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.506813480871637
          Encrypted:false
          SSDEEP:
          MD5:C416471B57FB894DC45D30C31B4BD2E2
          SHA1:BA378F8122280992AE51245A06814D8155564220
          SHA-256:804EFA345C5BBBAD2449C318A7A3F5B31F4234712AAD23DC49B3FB5AA33B7A57
          SHA-512:E7CDE706CFE573525C2DE319AD5783AE9D97C4F6D28B14A77A729F281540B0DAFAD4C14879EF76473BFDEBC38499C65CA228470983F2D1BC31938A91A2486522
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp860, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E300E000C100E700EA00CA00E800CD00D400EC00C300C2..00C900C000C800F400F500F200DA00F900CC00D500DC00A200A300D920A700D3..00E100ED00F300FA00F100D100AA00BA00BF00D200AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.5174672833207183
          Encrypted:false
          SSDEEP:
          MD5:4997979FD1692063E2B9AA9870E0BE4C
          SHA1:919012354B99BBEF4C85517E89A2C9CD340FCE49
          SHA-256:4B7E76AEB75289FACA76434EA6E9874E9504AD2BC3D8D47550EADBCC8294857E
          SHA-512:C122A1AE2DE79CB97E5989535B7478A76D905CDE60B01F80F5B84EDB9DF08BE6829E1811AF19608971DA048B8DA24F40DE0217A8054AC612EC2D8B3560500FBE
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp861, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800D000F000DE00C400C5..00C900E600C600F400F600FE00FB00DD00FD00D600DC00F800A300D820A70192..00E100ED00F300FA00C100CD00D300DA00BF231000AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.5573268031592717
          Encrypted:false
          SSDEEP:
          MD5:9B4D1B95B20BD67555517DCC3007B22A
          SHA1:2C0D6121DB49CDAB6FBAA81398BE2E44BE4E1110
          SHA-256:6C15CB256B1C22170292589C6F589E64E164EB36EC7E84F0BD48149BABB7C5FC
          SHA-512:34C3E401364D579E8AC7A4E1F1F7A29A84C62E1D5146D7664832639EA3997227DC4BAF1B64DC605E6574D680E61B55D0C69C329E35B1BEC41501FC68C5B634B7
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp862, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..05D005D105D205D305D405D505D605D705D805D905DA05DB05DC05DD05DE05DF..05E005E105E205E305E405E505E605E705E805E905EA00A200A300A520A70192..00E100ED00F300FA00F100D100AA00BA00BF231000AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.518080906819747
          Encrypted:false
          SSDEEP:
          MD5:C93CCDF65F7F349F22855745660F02AE
          SHA1:604888B1FB3C57DF47277CDD1153597BA89E8C36
          SHA-256:232D6FE34D7151920232EAAE9C515F36400AB64136DCC5B802D6245AC6F5D56B
          SHA-512:D5B65AE7353F694A37AF29177BF1A95477918FC5A002C2FE199624BD5B391698807BAECF54225BC40F62B3CA7912C7066A4AAF01B9E3E399133831CAA342BF4F
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp863, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200C200E000B600E700EA00EB00E800EF00EE201700C000A7..00C900C800CA00F400CB00CF00FB00F900A400D400DC00A200A300D900DB0192..00A600B400F300FA00A800B800B300AF00CE231000AC00BD00BC00BE00AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.72017408907567
          Encrypted:false
          SSDEEP:
          MD5:146E0D1779D50E070E0EF875E8374DF8
          SHA1:B51E5598712598BC387DD79AE80BD879F139140D
          SHA-256:81BEBFD9A61E9F17495763B68D57742FAB2A1A43871015699A2C8E5FDED4EC19
          SHA-512:1F0DAD8E77712C5A018894332BE72FF5C546C92F481421CCB8553AD6F1E9A18617765C8CEE4187265CCCB1AB073E221289D34C9AB1F0501231D52C81FC1C932B
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp864, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..00200021002200230024066A0026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00B000B72219221A259225002502253C2524252C251C25342510250C25142518..03B2221E03C600B100BD00BC224800AB00BBFEF7FEF8009B009CFEFBFEFC009F..00A000ADFE8200A300A4FE8400000000FE8EFE8FFE95FE99060CFE9DFEA1FEA5..0660066106620663066406650666066706680669FED1061BFEB1FEB5FEB9061F..00A2FE80FE81FE83FE85FECAFE8BFE8DFE91FE93FE97FE9BFE9FFEA3FEA7FEA9..FEABFEADFEAFFEB3FEB7FEBBFEBFFEC1FEC5FECBFECF00A600AC00F700D7FEC9..0640FED3FED7FEDBFEDFFE
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.5193842128126676
          Encrypted:false
          SSDEEP:
          MD5:150B2E00B3F84F8075F3653ED7A4C8E0
          SHA1:7131DC656EFE1F2277B19DA72F0EEB46B4EC54A0
          SHA-256:ADA1A52064EE93EBE6F8A5D101D01F8776038E12F21A5CA1C006EE833577C705
          SHA-512:AC56EEB0220826BF8FF6CA52768DB63961AAC46095A2F3EEBA11B5973CC92AF52DFBBE9E85A0DD04CAB8998212FA2599EDD83BAAA7FB2D394E330FF2F7C015DB
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp865, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE00EC00C400C5..00C900E600C600F400F600F200FB00F900FF00D600DC00F800A300D820A70192..00E100ED00F300FA00F100D100AA00BA00BF231000AC00BD00BC00A100AB00A4..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.5038992968715266
          Encrypted:false
          SSDEEP:
          MD5:FC33B5F773E87696A69E8798446E9772
          SHA1:4FC5589C1DD88BB8171758BC173A63B3A5687AE5
          SHA-256:32A45DEBA933C7ED99141535087A4C99BA79802175E3F762ACA6EB941157F85A
          SHA-512:332D2FEC532192F58F792441E61D675A8692C36BECF768D07F64B8C31561CC1A2DF402625A4719E758A9B59DE4228FFE9F94F067E7DC0D82F9DA2D6500E50304
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp866, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..0430043104320433043404350436043704380439043A043B043C043D043E043F..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..0440044104420443044404
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.5261138894265507
          Encrypted:false
          SSDEEP:
          MD5:4A2C66AA630D4AE2BF1E7546DCE2DAE5
          SHA1:FABB672957D21CA2B4E0EACA5FCE6093BAACF77A
          SHA-256:AFE6ED6EB5D07C45B6B928A48BC5EF57EFCF61602D36FF9FBDE4A8EA3FA6DF75
          SHA-512:A548002EB7AF8735DBBBCC9883B44B326F261C02A3C7CE65C373755DD92212A66740112EAE0FC556CAD5B86911709C6DF12167DC5B6AD1E01C6F1EB5AB16DB37
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp869, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850386008700B700AC00A620182019038820150389..038A03AA038C00930094038E03AB00A9038F00B200B303AC00A303AD03AE03AF..03CA039003CC03CD039103920393039403950396039700BD0398039900AB00BB..25912592259325022524039A039B039C039D256325512557255D039E039F2510..25142534252C251C2500253C03A003A1255A25542569256625602550256C03A3..03A403A503A603A703A803A903B103B203B32518250C2588258403B403B52580..03B603B703B803B903BA03
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1110
          Entropy (8bit):3.33737382140564
          Encrypted:false
          SSDEEP:
          MD5:FC8C876B4738236FC71A1AF96E4566D0
          SHA1:DDFDC3F62D99A6BD705CF0719B50F66449C8808A
          SHA-256:4F05F31CA026BBFEEEE49ED86504CB060784137A9CFAE0E5954D276E837AB5DE
          SHA-512:5BF58A810E029840825FFF3318E90415E6F2B7E46032FD428B4971923D41A64C127A6F438E4894E80EC9604CD34F1D47B4F9A02ABAB3E7D6351611811DC1F2B9
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp874, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC008100820083008420260086008700880089008A008B008C008D008E008F..009020182019201C201D20222013201400980099009A009B009C009D009E009F..00A00E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F..0E400E410E420E430E440E
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):49008
          Entropy (8bit):3.5144574650895364
          Encrypted:false
          SSDEEP:
          MD5:EF4508C84A025095B183E6BAD67B1ECD
          SHA1:D12D5381D50D578AA8687671DC542C462A7F490D
          SHA-256:6D1B512110BEAF2CD1296AC878F51D567848AB4A1CED4F18C72806BB136B3D23
          SHA-512:E695E7E6F4A11D5E8D62982E26B69B87DB2F1F3D6B6DCCD5F1DF51879F5C4533265CBD7B785E1F2652D8CA3FC913D4F862E7575F67C636314A6E6956FD96E023
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp932, multi-byte..M..003F 0 46..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000850086000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..0000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):134671
          Entropy (8bit):3.5217328918779645
          Encrypted:false
          SSDEEP:
          MD5:CF9CFD6329A4FB6C402052B9417DAC3A
          SHA1:75CE13FE1E5898D47B67F951C0C228851F1CC04D
          SHA-256:B6EC2BE0504CA62B9D1B6857F6BAA13FFAC5A567D4432F4EAB98ADC830F5D9C3
          SHA-512:7E19607EEA5342ECFE92D56DAAE82827DE147AE5AFDA8E9D67FD0970F528902CDE20A8A07CF2F341B926E59BB4FF792872976F1C7C5CD351959A71A8B6A1924A
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp936, multi-byte..M..003F 0 127..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):132551
          Entropy (8bit):3.100976362851161
          Encrypted:false
          SSDEEP:
          MD5:03E19A4DE3490A7DC50D04EC1F558835
          SHA1:9DFECAE08C98109EAA358F5920AED647888F722B
          SHA-256:477F8B79B67F4A22C963EE65B9B387DBD8E4B8F62D800B0A51D2276580C6ADBB
          SHA-512:7D6AD30AF75A3AA6332A860C6ABF87BF725EB6B4AF3B37699043A10EF3235471C63D0ECB4D437D5AD9438DF5DA646EB55117A9BB8B55EF6868F71E49035C18B7
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp949, multi-byte..M..003F 0 125..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):93330
          Entropy (8bit):3.319807723045599
          Encrypted:false
          SSDEEP:
          MD5:1D84B025DAB127F2073947D764D307B6
          SHA1:4E3D3CBD96D084836F1FE6F2AA497E3FAA463B9B
          SHA-256:F80E05533D1A1494C32F9412E9AD2D9C11FAF9AE0668A6F9D1FA5CEEDC6870E2
          SHA-512:188D649F9717F20524AFF47F85C3B23AEC3E7825BF54975285D06C17587D581DC24A3F6A7CAB1703DE7AD5521FE2FE2572DE627A81E6A48049A47BB219ED4AF8
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: cp950, multi-byte..M..003F 0 88..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1113
          Entropy (8bit):3.7780987266961663
          Encrypted:false
          SSDEEP:
          MD5:90FE0C57BBC6C2D8A3324DEB7FD45F3D
          SHA1:06B95BE43E4C859A0F1B01384EDD26500C6C1F9E
          SHA-256:EB9B262E4D179268E6F017C0D4EF0E7034E31A5B4893595D150640CA1F6A1C45
          SHA-512:6A5E67D9F3EC6046C42793E1437B8A6E50EBD72D8EC67FEFEB6DAD6FAB6A5B5C74F939363587D5A6529E217AF54FB8A9CF0F768E114DD931C57887451CACE56E
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: dingbats, single-byte..S..003F 1 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..00202701270227032704260E2706270727082709261B261E270C270D270E270F..2710271127122713271427152716271727182719271A271B271C271D271E271F..2720272127222723272427252726272726052729272A272B272C272D272E272F..2730273127322733273427352736273727382739273A273B273C273D273E273F..2740274127422743274427452746274727482749274A274B25CF274D25A0274F..27502751275225B225BC25C6275625D727582759275A275B275C275D275E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000276127622763276427652766276726632666266526602460246124622463..2464246524662467246824692776277727782779277A277B277C277D277E277F..2780278127822783278427852786278727882789278A278B278C278D278E278F..2790279127922793279421922194219527982799279A279B279C279D279E279F..27A027A127A227A327A
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1073
          Entropy (8bit):3.0039861897954805
          Encrypted:false
          SSDEEP:
          MD5:F7B3771D43BDE6AFF897683BED2FE6AD
          SHA1:E70C2C0902413536CB6163752D70F3AE4AF6A967
          SHA-256:165BE658AB7D61FFC3DF1E2F1438C2F9FCEE6808A756316302157F44E6D3ACD7
          SHA-512:F87DC718EB2DD95237B144FDA090BB636121B9479E492AC94E4F7EBDD88171F070B9E9F6165BDA7B7E2BA2A3E6188B1108D8F91AA5F142CCCFDAD317628DD941
          Malicious:false
          Reputation:unknown
          Preview:S..006F 0 1..00..0000000100020003008500090086007F0087008D008E000B000C000D000E000F..0010001100120013008F000A0008009700180019009C009D001C001D001E001F..0080008100820083008400920017001B00880089008A008B008C000500060007..0090009100160093009400950096000400980099009A009B00140015009E001A..002000A000E200E400E000E100E300E500E700F10060002E003C0028002B007C..002600E900EA00EB00E800ED00EE00EF00EC00DF00210024002A0029003B009F..002D002F00C200C400C000C100C300C500C700D1005E002C0025005F003E003F..00F800C900CA00CB00C800CD00CE00CF00CC00A8003A002300400027003D0022..00D800610062006300640065006600670068006900AB00BB00F000FD00FE00B1..00B0006A006B006C006D006E006F00700071007200AA00BA00E600B800C600A4..00B500AF0073007400750076007700780079007A00A100BF00D000DD00DE00AE..00A200A300A500B700A900A700B600BC00BD00BE00AC005B005C005D00B400D7..00F900410042004300440045004600470048004900AD00F400F600F200F300F5..00A6004A004B004C004D004E004F00500051005200B900FB00FC00DB00FA00FF..00D900F70053005400550056005700580059005A00B200D400D600D200D
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):83890
          Entropy (8bit):2.350315390677456
          Encrypted:false
          SSDEEP:
          MD5:F2DE0AE66A4E5DD51CC64B08D3709AAB
          SHA1:97558A51A6DD6C56FC7A42A4204141A5639021FD
          SHA-256:A3C916BA16BCAC9FAA5A1CCC62ACA61452D581CD8BA3EE07EC39122C697274C9
          SHA-512:0EAA90100527FF150D2653D7BB57647D69E592BE53B714DDD867114CFCC71E3A76882772F4FAECE040DF09FA8971D1C22DECC497E589B4CA827A6890497A48D9
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: euc-jp, multi-byte..M..003F 0 79..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D0000008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):95451
          Entropy (8bit):2.4080588863614136
          Encrypted:false
          SSDEEP:
          MD5:103843B3A57168BD574F6CACC550D439
          SHA1:982652EA2B0DCFBB55970E019A4EDFBFCFAF9C24
          SHA-256:5448643398685456A11CBB93AF2321F70B8659E2FFF3CCC534B4D53BD2F38C89
          SHA-512:27A8DE6F97DB4A96E5D0132692A32A99DAB8A6C98973A0C4E50A219F2D2F364E63D657E5E8478B2706CA33C45C376F55B5BFCC9459E06AEA88BFCD4F0E32525C
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: euc-kr, multi-byte..M..003F 0 90..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):88033
          Entropy (8bit):2.3790651802316996
          Encrypted:false
          SSDEEP:
          MD5:1A8E55DEA98B6D5EAC731ED233D3AD7C
          SHA1:1335FC0FC2AAE7E7F5EC42AC17A4168368B4A64D
          SHA-256:B4894AEDD2D5B5AE54B6D2840F7C89A88E9308EFD288F179E65936E172EF4B0D
          SHA-512:9DDCE366BA1196EB9FB913ACFDE8516BC9BB8D51894866D2E7E8CB313DC4D6C6D33C5A9E78142E83594DC423D10DA6F8DE211E69844B939198BC7DB9AED808F0
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: gb12345, double-byte..D..233F 0 83..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000030003001300230FB02C902C700A8300330052015FF5E2225202620182019..201C201D3014301530083009300A300B300C300D300E300F3016301730103011..00B100D700F72236222722282211220F222A222922082237221A22A522252220..23122299222B222E2261224C2248223D221D2260226E226F22642265221E2235..22342642264000B0203220332103FF0400A4FFE0FFE1203000A7211626062605..25CB25CF25CE25C725C625A125A025B325B2203B219221902191219330130000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.270324851474969
          Encrypted:false
          SSDEEP:
          MD5:D06664ACAA478BDEB42B63941109A4E3
          SHA1:4A6196FCC1BDE988C1A23EAA69745A9979F1AEFF
          SHA-256:ACD50951F81566C8D823670F9957B2479102EB5AE4CF558453E1D8436A9E31FF
          SHA-512:CB51A36B851FFDB5C6F9B9D0333EEA6A14CEF3796E0A60530198C16999D64E638047E873333630360299C9126F79CEDDA2D9F169028CED1FC04B1D3C55FFFC5B
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: gb1988, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..002000210022002300A500250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D203E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):85912
          Entropy (8bit):2.3945751552930936
          Encrypted:false
          SSDEEP:
          MD5:9357E05C74D6A124825F46A42B280C14
          SHA1:E5106ABE12D991AFE514F41E3B9E239202A4ADFE
          SHA-256:C445E4C9F676AE997D2DDA2BBC107B746F3547D85F39479951C56F46275EE355
          SHA-512:B2187D70A92FB38572BA46F3C3443233BEED1A4ABBFBA1B860F4BBAE6B3D8C16B8C9F52A20DAA12B2B8B40972E52F816860427B743530177E4CF0D8BA34EF381
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: gb2312, double-byte..D..233F 0 81..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000030003001300230FB02C902C700A8300330052015FF5E2225202620182019..201C201D3014301530083009300A300B300C300D300E300F3016301730103011..00B100D700F72236222722282211220F222A222922082237221A22A522252220..23122299222B222E2261224C2248223D221D2260226E226F22642265221E2235..22342642264000B0203220332103FF0400A4FFE0FFE1203000A7211626062605..25CB25CF25CE25C725C625A125A025B325B2203B219221902191219330130000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):86971
          Entropy (8bit):2.3925661740847697
          Encrypted:false
          SSDEEP:
          MD5:C5AA0D11439E0F7682DAE39445F5DAB4
          SHA1:73A6D55B894E89A7D4CB1CD3CCFF82665C303D5C
          SHA-256:1700AF47DC012A48CEC89CF1DFAE6D1D0D2F40ED731EFF6CA55296A055A11C00
          SHA-512:EEE6058BD214C59BCC11E6DE7265DA2721C119CC9261CFD755A98E270FF74D2D73E3E711AA01A0E3414C46D82E291EF0DF2AD6C65CA477C888426D5A1D2A3BC5
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: euc-cn, multi-byte..M..003F 0 82..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):204
          Entropy (8bit):4.949409835601965
          Encrypted:false
          SSDEEP:
          MD5:D3AC33390D31705FA4486D0B455247DF
          SHA1:2EE8613DC04A6FA84AB38FD5F3A2AA3FE330625B
          SHA-256:98074C85650A420A095ADA9138DA3A8A0AA4027BE47EA1E97A596F319EB084E9
          SHA-512:CB265B753C84968E2D1D6E706906DA9A7BB796D08F626290BCCA8F089771AFD176A9DC912773E8BA390D2AEC08592AD535C7D254E1DF92CF04848601481D4EFE
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso2022-jp, escape-driven..E..name..iso2022-jp..init..{}..final..{}..ascii..\x1b(B..jis0201..\x1b(J..jis0208..\x1b$B..jis0208..\x1b$@..jis0212..\x1b$(D..gb2312..\x1b$A..ksc5601..\x1b$(C..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):122
          Entropy (8bit):4.978693690727393
          Encrypted:false
          SSDEEP:
          MD5:057CB0AA9872AC3910184F67AC6621BC
          SHA1:BBA47F9D76B6690C282724C3423BD94E2C320A04
          SHA-256:234811FC8B0F8FF2B847D9CC3982F1699DF1D21A43C74DCE45BA855D22520007
          SHA-512:019F187D2D16FB51BF627ACB7E67778857E56D4C160E0E5ACA6ABC05EC5FDB624CE2715CB9E0DAD73BFF9D697982BE0D539BC55BCCD368FC7C8EE0FFC04E9F61
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso2022-kr, escape-driven..E..name..iso2022-kr..init..\x1b$)C..final..{}..iso8859-1.\x0f..ksc5601..\x0e..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):240
          Entropy (8bit):4.95909788984399
          Encrypted:false
          SSDEEP:
          MD5:BB186D4BE3FA67DD3E2DEE82DD8BD628
          SHA1:93CE8627038780CFFF8C06E746DD5FB2B041115C
          SHA-256:741B4C842557EED2952936204D0AE9C35FA3A0F02F826D94C50C46976291797C
          SHA-512:4921E7AA3DB8E33609603FE129B97275DFF80CFB06648D2068FA7950246C67B9B530B74827638F69F4DFB8F55CDD4AA952EA72EAEB6ABB527D52F20C6B46FB51
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso2022, escape-driven..E..name..iso2022..init..{}..final..{}..iso8859-1.\x1b(B..jis0201..\x1b(J..gb1988..\x1b(T..jis0208..\x1b$B..jis0208..\x1b$@..jis0212..\x1b$(D..gb2312..\x1b$A..ksc5601..\x1b$(C..jis0208..\x1b&@\x1b$B..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):3.236046263464657
          Encrypted:false
          SSDEEP:
          MD5:3538A970CD098BF5CE59005FE87B6626
          SHA1:285A96CC40D7CCE104FB4B407C7F0C400AA8F9CB
          SHA-256:A9CB4F4CA111608F882729BC5EB1C2F15530C515EF02DD2CA62F2D8DC5A210CF
          SHA-512:A6A6F2D8B5C22E240D195D168A604887062508FF3340D24E13BFCBD6C2E687347F2CFE724FA2ED12F36915B55EE2CFD901EC3F08E2B0A2FFD3BC2A98BBD12A50
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-1, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..00D000D100D200D300D400D500D600D700D800D900DA00DB00DC00DD00DE00DF..00E000E100E200E300
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.319750415373386
          Encrypted:false
          SSDEEP:
          MD5:CBDE40170FECD2496A9DA3CF770FAB7B
          SHA1:3E1D74DF6AFEB6CDE8ECBDAC8F81F2F9C64150DE
          SHA-256:48F4A239C25354F0E9F83A39F15D4632BB18A9C33E60C671C67307159917ECED
          SHA-512:A26B56A4CFE29E5A0A0B3A55283A7767397693388E2DEEC342C69B6F718FAE2407EB8D5ADE538FAE6947CBB8B052943C3A52F2D046ABAC7A3DAA86D730DC293F
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-10, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0010401120122012A0128013600A7013B011001600166017D00AD016A014A..00B0010501130123012B0129013700B7013C011101610167017E2015016B014B..010000C100C200C300C400C500C6012E010C00C9011800CB011600CD00CE00CF..00D00145014C00D300D400D500D6016800D8017200DA00DB00DC00DD00DE00DF..010100E100E200E30
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.3206399689840476
          Encrypted:false
          SSDEEP:
          MD5:E2A0BCB83BFC3F435CDCFC20D5CF2E0C
          SHA1:CFD18B5B5DB4EE46E63D912B8FD66D513C4C8D39
          SHA-256:21E769C5A66E4D12D6E7DB24022E92AF1EC0D0331FE3C8C605654F239C0F3640
          SHA-512:C86F9180F2F4A177F1EA10E26B0903ABEAFDDE0317C332A48F8D1BB586DAC91C68800E2E4FA2CD739C435419B106CBA4BEFC049F2BCD720E9FC2C0AE8436CFAC
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-11, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A00E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F..0E400E410E420E430
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.338879965076632
          Encrypted:false
          SSDEEP:
          MD5:21CEBB723D47B1450A7FB21A82470B97
          SHA1:A40FD3AFE1ECE89E3F682D527D281BC563DB3892
          SHA-256:3271D39D7B4DCD841E8E5D5153D1B8837718B88FEFEC73DC37D314816EEFE5E5
          SHA-512:3A0E033A4D93C679215F672C6C4FE425D63E1DE157AA671E7400639165EC3EB498E4EEB030D6FB8FF8BE2FD8C986D341036A8CED9FA094D092CF2822D5DC065B
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-13, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0201D00A200A300A4201E00A600A700D800A9015600AB00AC00AD00AE00C6..00B000B100B200B3201C00B500B600B700F800B9015700BB00BC00BD00BE00E6..0104012E0100010600C400C501180112010C00C90179011601220136012A013B..01600143014500D3014C00D500D600D701720141015A016A00DC017B017D00DF..0105012F010101070
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.3670559016263915
          Encrypted:false
          SSDEEP:
          MD5:FDAA88946DE4EB4E6D37F2B6AFCF6CAF
          SHA1:56FC4773941E7457EA04EDA92C883642DE45D100
          SHA-256:F0A5675027FB1CA34B4E4128D24C2968CD275890569A32A86AFA4994CE4983E0
          SHA-512:92658A6FEB42A41B3CFFC377C4A9A3F6780A79FC596D3FEDBA6D3B3D75A9F40E859A2CE8DC579A278BAEEDEEFA2408E2B7853D99D5C2D14AACF63C521FE2BB86
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-14, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A01E021E0300A3010A010B1E0A00A71E8000A91E821E0B1EF200AD00AE0178..1E1E1E1F012001211E401E4100B61E561E811E571E831E601EF31E841E851E61..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..017400D100D200D300D400D500D61E6A00D800D900DA00DB00DC00DD017600DF..00E000E100E200E30
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.260398494526282
          Encrypted:false
          SSDEEP:
          MD5:D779D5E2A0083C616A226B2D82ABF0EB
          SHA1:D1657DB5E2989EBA80BAB98A1E1217CFFFBB19DB
          SHA-256:C74E8E23A0FF0D5DEA7C318CA20DC817DA4E57B0DD61B3361FC0D5098A9316FE
          SHA-512:26E62BE8AE793ED3B725BF0D1BABF4D6ED63A6F3772ABD48955FC4394BDE5A47614D1FF89A21A828676BF1302F3C9361B557B0FBF0DF8561FB7E66542FE94CDC
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-15, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A000A100A200A320AC00A5016000A7016100A900AA00AB00AC00AD00AE00AF..00B000B100B200B3017D00B500B600B7017E00B900BA00BB01520153017800BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..00D000D100D200D300D400D500D600D700D800D900DA00DB00DC00DD00DE00DF..00E000E100E200E30
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.3065938185320918
          Encrypted:false
          SSDEEP:
          MD5:74FDEDDAF670023DA7751FB321E345A0
          SHA1:0677FED67C1333A9A74D50642E5214701A57E2AF
          SHA-256:640D977EC1D22B555C5075798DA009E3523E8F55F29BE22A3050CD1B4EF7B80E
          SHA-512:AC02FD95159A856A9DDEF4E6A8216B958DC07311B553FF39403DC5B77E1AFF2A2C4C03F5F26A2BB7AD5DB6800BEE03E895554556DBBFBE89426286796ADE55AC
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-16, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A001040105014120AC201E016000A7016100A9021800AB017900AD017A017B..00B000B1010C0142017D201D00B600B7017E010D021900BB015201530178017C..00C000C100C2010200C4010600C600C700C800C900CA00CB00CC00CD00CE00CF..0110014300D200D300D4015000D6015A017000D900DA00DB00DC0118021A00DF..00E000E100E201030
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):3.340505173539446
          Encrypted:false
          SSDEEP:
          MD5:9B87850646FFE79F3C8001CBCB5BB3A1
          SHA1:8F97576F3FB3B5DBEF71DC2C9314AB5E530974D6
          SHA-256:76949B03F57041B07F41902BD7505AB3594D79AA8F7BDEED5F0481004B10CBC3
          SHA-512:101A28AF0799E7E0A5723E5DD76D5EF0FEEF584AC479A88F499CB3B7D2AA93767D72F8E51C76F7547F08FF8DD3CBBA7FF444BD07F99A92755526E75C596109EF
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-2, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0010402D8014100A4013D015A00A700A80160015E0164017900AD017D017B..00B0010502DB014200B4013E015B02C700B80161015F0165017A02DD017E017C..015400C100C2010200C40139010600C7010C00C9011800CB011A00CD00CE010E..01100143014700D300D4015000D600D70158016E00DA017000DC00DD016200DF..015500E100E2010300
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):3.2507537230559977
          Encrypted:false
          SSDEEP:
          MD5:CBD0B9CDCD9BC3D5F2429A760CF98D2F
          SHA1:6DEF0343E0357E0671002A5D2F0BFC2E00C8BCF9
          SHA-256:1F51E7BDA64D466C16FEE9A120BBE3353A10CEB9DAB119FFA326779BA78D8C5D
          SHA-512:88DB6D23B53F4A78133C794ED42FA3F29A4ABAD35DE4B022040FA187AA59B00664CC13F47AFF4507D72F4CB2166F026144213EE760AB0FD67CDD2FA5906F434A
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-3, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0012602D800A300A40000012400A700A80130015E011E013400AD0000017B..00B0012700B200B300B400B5012500B700B80131015F011F013500BD0000017C..00C000C100C2000000C4010A010800C700C800C900CA00CB00CC00CD00CE00CF..000000D100D200D300D4012000D600D7011C00D900DA00DB00DC016C015C00DF..00E000E100E2000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):3.3413832766873073
          Encrypted:false
          SSDEEP:
          MD5:8B620EDECAC2DF15A024C2CE15FB64A5
          SHA1:65C5EE5D08964E37393E6A78ABA0DB16D51240E2
          SHA-256:66B3CF994F0B5E0103D13E812958320AFB555C91E3F81B579D4CBF231E6A0805
          SHA-512:93391325405D3AEA0A913F5EA8EA0391920D10F234C26AB1DA70992702889A3AF7B85E11A1FCA554690942B238CE313DD460798E59C5B1F4069036E7B0F24F44
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-4, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A001040138015600A40128013B00A700A8016001120122016600AD017D00AF..00B0010502DB015700B40129013C02C700B80161011301230167014A017E014B..010000C100C200C300C400C500C6012E010C00C9011800CB011600CD00CE012A..01100145014C013600D400D500D600D700D8017200DA00DB00DC0168016A00DF..010100E100E200E300
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):3.342721205983665
          Encrypted:false
          SSDEEP:
          MD5:6FBEFDC3DEC612B7B2CC903D8C53F45B
          SHA1:14EC3C166DC411149C32C262DBE8E327F6186669
          SHA-256:3130BF26DA0C840C1E02203A90C3B1C38966FB203130E2FBB3DD7CB3865A3539
          SHA-512:F3F15AD8B6C9D9B4C9C994FE3235B4463E59BE7DCE79CF3F7AA77905D6F4DC2C4AABB79B440767DB13D357B13F09EA34983FCA7BC92D0AFA15FB6CBEDDD04E38
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-5, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0040104020403040404050406040704080409040A040B040C00AD040E040F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..0430043104320433043404350436043704380439043A043B043C043D043E043F..044004410442044304
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):2.992219341429816
          Encrypted:false
          SSDEEP:
          MD5:52F025D943A45EE840D9C3DFD06E4D79
          SHA1:571EA14B49FA6150BFD2ABA79E52799955D9FA10
          SHA-256:CB71909BF01A3A7A4C7396359DA06D206B58A42AD68192CE37169D6640D46E13
          SHA-512:77FF9DC785A63CA59A7D58BB25C7D2C16F364E525F9B939177385EF80F7DE37734C8774F1BC829CF0270FD66257A4D31689654C8037DB0A86A0291FFDE637B90
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-6, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A000000000000000A40000000000000000000000000000060C00AD00000000..00000000000000000000000000000000000000000000061B000000000000061F..0000062106220623062406250626062706280629062A062B062C062D062E062F..0630063106320633063406350636063706380639063A00000000000000000000..064006410642064306
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):3.393893260854861
          Encrypted:false
          SSDEEP:
          MD5:4BFB0A35D971A9D4C5EA8D8099E93C37
          SHA1:8FED2CBB1343E5B4442748242B5F89A76110592D
          SHA-256:76F6BC85FC9CB89BC3F94D36275AB23C740BA17FD36EC8907479DA3A885415EA
          SHA-512:C9CE1E9EA57A1DEF62BBC60A115C06325C6EE8F92021695459E1ADAF1193A559BC5F0229191BFC2E344296DC137583ED4A9A61A65890F99F4CF97B3864C7AF0F
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-7, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A02018201900A320AC20AF00A600A700A800A9037A00AB00AC00AD00002015..00B000B100B200B303840385038600B703880389038A00BB038C00BD038E038F..0390039103920393039403950396039703980399039A039B039C039D039E039F..03A003A1000003A303A403A503A603A703A803A903AA03AB03AC03AD03AE03AF..03B003B103B203B303
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):3.0494739426493567
          Encrypted:false
          SSDEEP:
          MD5:5F69EAF54E7A1E8AC81C9E734DBE90D8
          SHA1:BA509C88A4FC03922EF5CDC887FAA7B594A9BC5A
          SHA-256:865E3665743B5FABA3E1AD6AA55515A666BD05DA6266879D9B66C98905DAFF3C
          SHA-512:D9924FBE59CB571AF721CA602DBE58CAD0D9310610EDF544F8FC0FBF3D1CE4E99597D0198E4E7C802107012786346FE4C1B9C6C3A76D5F60B9A83981B0EDA24D
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-8, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0000000A200A300A400A500A600A700A800A900D700AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900F700BB00BC00BD00BE0000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000002017..05D005D105D205D305
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1114
          Entropy (8bit):3.2591070910715714
          Encrypted:false
          SSDEEP:
          MD5:0B99E605E73B7D8DEFD8D643F5729748
          SHA1:F30E7CCBCD9C539126E8D6CA0886E4B2BD54E05D
          SHA-256:CF51E867DDE2F19553D98FEEC45A075C4B4F480FB1EDADB3D8DAD1EBEA9299F3
          SHA-512:DA0487CD7F2143195E80697C17FFDB61AFD464C888DDF84813B2B5D1BAB24D96466DA7A7F77C8E4A9D0D53F34D72928923380AFC1B92A96C0A3BFF46006A4E19
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: iso8859-9, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..011E00D100D200D300D400D500D600D700D800D900DA00DB00DC0130015E00DF..00E000E100E200E300
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1112
          Entropy (8bit):3.2708615484795676
          Encrypted:false
          SSDEEP:
          MD5:4E21F24F8D9CC5DF16B29CACD997AC69
          SHA1:064E723EFB82EF1C303E5267496304288821E404
          SHA-256:61B14A7C312366F79BB45F02C6B7EE362E6F51CBAD5E479E563C7F7E785DB654
          SHA-512:AF8FAEB47EFB51F2537139F7C4254ABED119E477FD2B5E83B90B7A903B43C4E02DDF43A7DDB044A0A9601E9F9ADE91B02EE7C0EC87FF5DDCF9951B9601A90435
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: jis0201, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D203E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..00000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):81772
          Entropy (8bit):2.3571626869060776
          Encrypted:false
          SSDEEP:
          MD5:F0661E22C7455994AA1F6EC1EDA401B4
          SHA1:928B2AC46A9FDE61A81F56BE225E6138B40C22E5
          SHA-256:F6B1C6AC5F5FC4E990A7A1AAC16A406012040936431BEFE7D2B6CD1DA9E422C4
          SHA-512:917CC58678A9E9F5CBE860D30828846ABA4EA8CDFAB7DD1AE6A66C47ECBB85CF67DD97BC3E6F95341DD30F4E757B2CEA571708D5B4CED18A29F19904C3138AE0
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: jis0208, double-byte..D..2129 0 77..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000300030013002FF0CFF0E30FBFF1AFF1BFF1FFF01309B309C00B4FF4000A8..FF3EFFE3FF3F30FD30FE309D309E30034EDD30053006300730FC20152010FF0F..FF3C301C2016FF5C2026202520182019201C201DFF08FF0930143015FF3BFF3D..FF5BFF5D30083009300A300B300C300D300E300F30103011FF0B221200B100D7..00F7FF1D2260FF1CFF1E22662267221E22342642264000B0203220332103FFE5..FF0400A200A3FF05FF03FF06FF0AFF2000A72606260525CB25CF25CE25C70000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):72133
          Entropy (8bit):2.3455261548208055
          Encrypted:false
          SSDEEP:
          MD5:07CE2C135BE17DBAFA558AA5949A53DB
          SHA1:5D9DBEFCCB44E76C1A4E61360C6FCED8DCC8EF4D
          SHA-256:785CFC5F5D9CB06DB8061730AB0016A0F70D0B59F6787D2A3CBB8D5779C99706
          SHA-512:E954D7198D58ACEDEB4C8E5F466107767C3DA43763A5F6CDDFCF567226F9B22B4C2DE27564F28CD125D7F1BA7CB9C6DE6DEC4065EC2676572C793BE458FDDD9D
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: jis0212, double-byte..D..2244 0 68..22..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000000000000000000000000000000000000000000000000000000000002D8..02C700B802D902DD00AF02DB02DA007E03840385000000000000000000000000..0000000000A100A600BF00000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000BA00AA00A900AE2122..00A4211600000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.531149521168141
          Encrypted:false
          SSDEEP:
          MD5:96F54CC639ACA8E466FB8058144C9350
          SHA1:0B9530D6080F2BAACABD5AA0D48BFF316FCCEF64
          SHA-256:0E43244BFC4F33FACB844B9E00270A1A4C24DC59B8A9B95104E2D788BB2F59FD
          SHA-512:5B7859325E5E34C9D4558B1198795BB9C6A8EF783EB97193EA80BA76C38AFE9BDD1B526B77401DF5456B7A0E85E942191FFD4B4F2B9F0C8168A7093EE452802E
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: koi8-r, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..25002502250C251025142518251C2524252C2534253C258025842588258C2590..259125922593232025A02219221A22482264226500A0232100B000B200B700F7..25502551255204512553255425552556255725582559255A255B255C255D255E..255F25602561040125622563256425652566256725682569256A256B256C00A9..044E0430043104460434043504440433044504380439043A043B043C043D043E..043F044F044004410442044304360432044C044B04370448044D04490447044A..042E04100411042604140
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.5076564572101714
          Encrypted:false
          SSDEEP:
          MD5:4B755EF2288DFC4009759F8935479D68
          SHA1:C3BDF0D9DF316DE8919DAA4329275C5AA81D61B4
          SHA-256:ED04D5B977B8C8944D8760B713FF061292DA5634BCBB67CDFB1C3A6FF5378C81
          SHA-512:3F1E1CC47327054FB9C54157ED10514230F10BFCD4BD9FDAFA02D7B238137DC7442CA2661B0739D8EEA3181E187D3B639A2C8118A0DE272C96000908121B6CFB
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: koi8-u, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..25002502250C251025142518251C2524252C2534253C258025842588258C2590..259125922593232025A02219221A22482264226500A0232100B000B200B700F7..25502551255204510454255404560457255725582559255A255B0491255D255E..255F25602561040104032563040604072566256725682569256A0490256C00A9..044E0430043104460434043504440433044504380439043A043B043C043D043E..043F044F044004410442044304360432044C044B04370448044D04490447044A..042E04100411042604140
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):94393
          Entropy (8bit):2.4104200953565513
          Encrypted:false
          SSDEEP:
          MD5:366C09E4A4CC10006E593F5B3F3461D7
          SHA1:A0DABFBEEB66E26FB342844EA41772D7A1D19C24
          SHA-256:9B27FE7E7054F36E279993F19E52E18AC03360D117AE80C42B4E984A97C590AA
          SHA-512:670F32D698C7992038E736D3AD40098D8589C0C5A1379E32A0F02A02FAF251B1312CAD131DDADC3F80B23A3821A91689F2E310309028BDDDF227D532EB505A20
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: ksc5601, double-byte..D..233F 0 89..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000030003001300200B72025202600A8300300AD20152225FF3C223C20182019..201C201D3014301530083009300A300B300C300D300E300F3010301100B100D7..00F7226022642265221E223400B0203220332103212BFFE0FFE1FFE526422640..222022A52312220222072261225200A7203B2606260525CB25CF25CE25C725C6..25A125A025B325B225BD25BC219221902191219321943013226A226B221A223D..221D2235222B222C2208220B2286228722822283222A222922272228FFE20000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1116
          Entropy (8bit):3.4295694929963667
          Encrypted:false
          SSDEEP:
          MD5:10850BCFB943318284D6191494EBD7D5
          SHA1:237D5DDF7969A422991F17021244D13A2BB0DE92
          SHA-256:81ECA6840B87F2DEF9FCDD171A55C2D71A49386D88401CE927AE57D7DDD7AAAA
          SHA-512:D797781C228B70D2D83DB8ABA08F840CE49846C9473CC89A2E316900D9E08A63142E68AD9ABBB2EF67BF9F1D392772FAB36CCC09632022A1437AE27C11F2284F
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macCentEuro, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C40100010100C9010400D600DC00E10105010C00E4010D0106010700E90179..017A010E00ED010F01120113011600F3011700F400F600F500FA011A011B00FC..202000B0011800A300A7202200B600DF00AE00A92122011900A822600123012E..012F012A22642265012B0136220222110142013B013C013D013E0139013A0145..0146014300AC221A01440147220600AB00BB202600A00148015000D50151014C..20132014201C201D2018201900F725CA014D0154015501582039203A01590156..01570160201A201E
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1116
          Entropy (8bit):3.3992482002374516
          Encrypted:false
          SSDEEP:
          MD5:A60FBDE33D13C732095713D1AB6713AB
          SHA1:4B0EB443F2D0E4B8DB7D0435F9311E5F9A625123
          SHA-256:BBE6F5EBB5EAB08C91DF7D524FAF39B03AA8B9F84C67ABA0553A84EC56668CB9
          SHA-512:3EEBA6BA3FCD875AFBD5DF41EDC21E872416A48D03343232904CC99CAF913045DAF7B1A1ACD0949EF794AD7B6C9AE8F93808423FFC4B67718E732B2FF5D9B6D7
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macCroatian, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..202000B000A200A300A7202200B600DF00AE0160212200B400A82260017D00D8..221E00B122642265220600B522022211220F0161222B00AA00BA03A9017E00F8..00BF00A100AC221A01922248010600AB010C202600A000C000C300D501520153..01102014201C201D2018201900F725CAF8FF00A9204420AC2039203A00C600BB..201300B7201A201E
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1116
          Entropy (8bit):3.4178221849964903
          Encrypted:false
          SSDEEP:
          MD5:C390D66441AC61CCF0A685CA5EE0BC1C
          SHA1:FCAE825B54400B9D736EF22A613E359E3F0FA6C2
          SHA-256:76EFE571ADDA7AED467F146CB0BD3A2351F2A720508EA0642C419F5347789CAA
          SHA-512:C891DB15E0F600965885DE6745EDD2A4E3A6A20CA30A9AAE89CBD8C429F8455C4AF7F2FC053FB3D730D8544AB6A6E78E769DB93DAD7B29868B746FA10373F021
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macCyrillic, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..202000B0049000A300A7202200B6040600AE00A9212204020452226004030453..221E00B122642265045600B504910408040404540407045704090459040A045A..0458040500AC221A01922248220600AB00BB202600A0040B045B040C045C0455..20132014201C201D2018201900F7201E040E045E040F045F211604010451044F..0430043104320433
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1116
          Entropy (8bit):3.870022681111701
          Encrypted:false
          SSDEEP:
          MD5:DCE78527E3A7B7CB1DE9EE5FAF12AFC6
          SHA1:20F4A3F4DB6B3422C04EBB6B21A568E4C173F9C1
          SHA-256:062E31D48DC33160999074E49205E08C3655DFF91C2C87F254522E6EBCE2DD96
          SHA-512:627F5FD2F12B341F2D7EE9032946FE057C4AC74D99687178CEA98B3E150307BB6AA2495B0FA46400760D467E2BF589BE31E998E25CE1D1E8465DA61F22047345
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macDingbats, single-byte..S..003F 1 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..00202701270227032704260E2706270727082709261B261E270C270D270E270F..2710271127122713271427152716271727182719271A271B271C271D271E271F..2720272127222723272427252726272726052729272A272B272C272D272E272F..2730273127322733273427352736273727382739273A273B273C273D273E273F..2740274127422743274427452746274727482749274A274B25CF274D25A0274F..27502751275225B225BC25C6275625D727582759275A275B275C275D275E007F..F8D7F8D8F8D9F8DAF8DBF8DCF8DDF8DEF8DFF8E0F8E1F8E2F8E3F8E4008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000276127622763276427652766276726632666266526602460246124622463..2464246524662467246824692776277727782779277A277B277C277D277E277F..2780278127822783278427852786278727882789278A278B278C278D278E278F..2790279127922793279421922194219527982799279A279B279C279D279E279F..27A027A127A227A3
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1113
          Entropy (8bit):3.4954458011071323
          Encrypted:false
          SSDEEP:
          MD5:0CC92F685A4132BE4B030006670D81CE
          SHA1:13B1074A90055E9EA061A6206A9C004DA29967A9
          SHA-256:1AABE561B5C944ABD11C293D4ACAC0F3A4A5A9E84A0342D066F4E3E992348895
          SHA-512:E1AF3D47D681CD68B6063DEC1241631CABE86FE835232FA73D855AC74D0175540D46511282BE7198A67A37970A5D05CDECF55C10424ED9C1413C108F116094D9
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macGreek, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400B900B200C900B300D600DC038500E000E200E4038400A800E700E900E8..00EA00EB00A3212200EE00EF202200BD203000F400F600A600AD00F900FB00FC..2020039303940398039B039E03A000DF00AE00A903A303AA00A7226000B000B7..039100B12264226500A503920395039603970399039A039C03A603AB03A803A9..03AC039D00AC039F03A1224803A400AB00BB202600A003A503A7038603880153..20132015201C201D2018201900F70389038A038C038E03AD03AE03AF03CC038F..03CD03B103B203C803B
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.3991839018654573
          Encrypted:false
          SSDEEP:
          MD5:747ADBE54D6992467415E322326FA1B9
          SHA1:5E3967B5DDF3A6DBF07E90ED6B9B9C2F3F3F35FE
          SHA-256:6FD08CE6FBA521D51E8058DE5C2DBD6583B80306A8BE7D015361F76314E70A35
          SHA-512:A04B946993985BF1F8FBA3A7A9AD3838F43F8F27F69B1FB1015D9DC8612AAFCE24E30CBC1FCABBDFB359FD487D51F70F18DA0CDA4A87749A2C82309CEB054849
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macIceland, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..00DD00B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8..221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8..00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153..20132014201C201D2018201900F725CA00FF0178204420AC00D000F000DE00FE..00FD00B7201A201E2
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):48813
          Entropy (8bit):3.3767502114972077
          Encrypted:false
          SSDEEP:
          MD5:3DCD22325E0194AAD4959C939B1DE24D
          SHA1:ABEF1372FBDA83714CE29E015D9A198D4B37B21C
          SHA-256:47007D9EBF4D34C6CE3599E50AFC7C1CF8129B88994DE2C2A857C09003F9CD2B
          SHA-512:B8ADFD2315EA38E5F7D4DED219759380069AAB539F1B5AAA5626CE32428CBBEB5E8215AD8351E023BCF72FA4DC30AB40CF59D6D45E33B6D1A6B41BEBFD4BD4C2
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macJapan, multi-byte..M..003F 0 46..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00A0FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..0000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1113
          Entropy (8bit):3.4060725247347516
          Encrypted:false
          SSDEEP:
          MD5:34691FADC788B85D98F63159640C7DD0
          SHA1:C8B3D084D3E831EFF6ECEF71B2029545F214C3D4
          SHA-256:C83D971D6BC0284EF323C197896E38C57A5FF44784E451EC2997EDA70C0DD85C
          SHA-512:77D5676F9B7AF7FD1D612A1C426889D8F2C0191887E180B78C4AA42202928A1B3078B76BD3C5F5ABB2A5CE1AE913E3CA6EFDE0483D2A2B0EFC173EF25EAE1D67
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macRoman, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..202000B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8..221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8..00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153..20132014201C201D2018201900F725CA00FF0178204420AC2039203AFB01FB02..202100B7201A201E203
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.412326247178521
          Encrypted:false
          SSDEEP:
          MD5:04E25073BFB0019D8381B72F7B433F00
          SHA1:B63B0AD9F10A44B0DDD12A3BDBCDEB2992D6D385
          SHA-256:0B805DAF21D37D702617A8C72C7345F857695108D905FF378791F291CEA150F0
          SHA-512:0514EC054676C15C65B01B02747CDBAD79BC89FD1A24A17797A8729752FB748FEDBE920E7BBFF41A6DA4BA99002E3B8DB674D53E30485DC36F6BF737EAF11702
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macRomania, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..202000B000A200A300A7202200B600DF00AE00A9212200B400A822600102015E..221E00B12264226500A500B522022211220F03C0222B00AA00BA21260103015F..00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153..20132014201C201D2018201900F725CA00FF0178204400A42039203A01620163..202100B7201A201E2
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1112
          Entropy (8bit):3.6062142626989004
          Encrypted:false
          SSDEEP:
          MD5:06DC6BA6E4A75CD7FF2D7A4248912C61
          SHA1:23FB16763A8F11EF48E805E4F453C2F812D48FC4
          SHA-256:A1802A2FEB01B255EC7C17425EEE4525372DF8CE226F4047D149172EB438F913
          SHA-512:41A487EC5C36C17B2746C5DC770882A836E6E75CF6A14C31595EB211022F0476BD3B953497C447F21554769F127C3A56E5B6EF8FB3C20A8AFF8C67E0CC94359D
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macThai, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00AB00BB2026F88CF88FF892F895F898F88BF88EF891F894F897201C201DF899..FFFD2022F884F889F885F886F887F888F88AF88DF890F893F89620182019FFFD..00A00E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3AFEFF200B201320140E3F..0E400E410E420E430E44
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.422718883614008
          Encrypted:false
          SSDEEP:
          MD5:4EA94A0DB35BED2081A2CC9D627A8180
          SHA1:AB2AC3ADA19F3F656780FF876D5B536A8DCE92C6
          SHA-256:AFB66138EBE9B87D8B070FE3B6E7D1A05ED508571E9E5B166C3314069D59B4E4
          SHA-512:7888F560D3728732BE1B7DCE49ECB61F3399CEF11191F4116C891E1D147B2A90ED8FB4A5E7B51904A001C47750BD9EB1B15EA5BA5B4EC5D69CDE7704B69529AD
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macTurkish, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..202000B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8..221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8..00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153..20132014201C201D2018201900F725CA00FF0178011E011F01300131015E015F..202100B7201A201E2
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1115
          Entropy (8bit):3.4157626428238723
          Encrypted:false
          SSDEEP:
          MD5:A5B48D6F2678579CBE6EA094A4655071
          SHA1:A13A41D530B21CE8443AFD7E811286537C5BA9C7
          SHA-256:F7E11736C9FF30102B31EC72272754110193B347433F4B364921E8F131C92BF0
          SHA-512:612F9D528CE940B5CA9E67CB127013A104655207511F4CF39C8696A127E6A8F4867F5603DCFB78C25A55668C6EE70F2997A8D1626F6F1DD44B19260967F17097
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: macUkraine, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..202000B0049000A300A7202200B6040600AE00A9212204020452226004030453..221E00B122642265045600B504910408040404540407045704090459040A045A..0458040500AC221A01922248220600AB00BB202600A0040B045B040C045C0455..20132014201C201D2018201900F7201E040E045E040F045F211604010451044F..04300431043204330
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):42552
          Entropy (8bit):3.5565924983274857
          Encrypted:false
          SSDEEP:
          MD5:EEB45AF9D7104872FE290D1EC18AB169
          SHA1:A80CF4EA46301F0B8B4F0BC306270D7103753871
          SHA-256:4A15ED210126BCDAE32543F60EB1A0677F985F32D49FCE923B9FAE8C5BCF3DA4
          SHA-512:C359042B04441AA50E536B23EEA0C6C7B2C1893DFB9CDB5459D3B46945D3BB50FD7A32A4F4E26A83622E76D3D2BB0DBBC3D1F3FB87AAF40520A243165B82AB34
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: shiftjis, multi-byte..M..003F 0 40..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000850086008700000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..0000000000000000000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):3.73983895892791
          Encrypted:false
          SSDEEP:
          MD5:D59E748D863A5FAEF0CEEC2564E041A3
          SHA1:4FFF3BE37F50C090FFC581F1C7769E20281E90C3
          SHA-256:9660537A7B62996478555C6F57C1962C78FB3972F19370B2E395C44842818A1F
          SHA-512:BF8FD0CF1CC55564C46976F53F441B26819ADBA7AB7BB04FF3FF5A313366FC3049DF29A839CCCB05EDEF4A7ECBB49FFCA62518EDA90AF2D7781874A8435073AE
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: symbol, single-byte..S..003F 1 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002122000023220300250026220D002800292217002B002C2212002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..22450391039203A70394039503A603930397039903D1039A039B039C039D039F..03A0039803A103A303A403A503C203A9039E03A80396005B2234005D22A5005F..F8E503B103B203C703B403B503C603B303B703B903D503BA03BB03BC03BD03BF..03C003B803C103C303C403C503D603C903BE03C803B6007B007C007D223C007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..000003D2203222642044221E0192266326662665266021942190219121922193..00B000B12033226500D7221D2202202200F72260226122482026F8E6F8E721B5..21352111211C21182297229522052229222A2283228722842282228622082209..2220220700AE00A92122220F221A22C500AC2227222821D421D021D121D221D3..22C42329F8E8F8E9F8EA2
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1112
          Entropy (8bit):3.0553142874336943
          Encrypted:false
          SSDEEP:
          MD5:467A67DE6809B796B914F5BFF98EF46D
          SHA1:C62418071A6C9CB0DCE3F67E130BFD2FB7AB0B58
          SHA-256:50B62381D6EDD4219F4292BFDC365954491B23360DE7C08033E7218A3D29C970
          SHA-512:BF98305AA7D759A087B9EABDC404714D8DC6B4F1BEED4ED0E1FFE646641E1AECA307673D64CF95FD09546D977B3409D6C04F56DCCA1D6332B0D9B6DD460B77A9
          Malicious:false
          Reputation:unknown
          Preview:# Encoding file: tis-620, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E0000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F..0E400E410E420E430E44
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8235
          Entropy (8bit):4.855903177272536
          Encrypted:false
          SSDEEP:
          MD5:8609B624CD3EC63DD02DBF89455C3A9B
          SHA1:B3E1843E34C38AA668FFDDF435A1A65D55449CA0
          SHA-256:5123DB837EADF45712EA7D449BC40BFD3E8E16D3D71E7D0CE9A32F164973D767
          SHA-512:B20B75473F34209888F38EE570B8A96061760E88466DFC2EC55C814968DC7F67D92D255E8635188B60455B88F2D1D517747613AD0F366D60412D2D6ECE231B0E
          Malicious:false
          Reputation:unknown
          Preview:# history.tcl --..#..# Implementation of the history command...#..# Copyright (c) 1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#.....# The tcl::history array holds the history list and some additional..# bookkeeping variables...#..# nextid.the index used for the next history list item...# keep..the max size of the history list..# oldest.the index of the oldest item in the history.....namespace eval ::tcl {.. variable history.. if {![info exists history]} {...array set history {... nextid.0... keep.20... oldest.-20...}.. }.... namespace ensemble create -command ::tcl::history -map {...add.::tcl::HistAdd...change.::tcl::HistChange...clear.::tcl::HistClear...event.::tcl::HistEvent...info.::tcl::HistInfo...keep.::tcl::HistKeep...nextid.::tcl::HistNextID...redo.::tcl::HistRedo.. }..}.....# history --..#..#.This is the main history command. See the
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):10066
          Entropy (8bit):4.806771544139381
          Encrypted:false
          SSDEEP:
          MD5:C2092F8CA2D761DFA8C461076D956374
          SHA1:90B4648B3BC81C30465B0BE83A5DB4127A1392FB
          SHA-256:8C474095A3ABA7DF5B488F3D35240D6DE729E57153980C2A898728B8C407A727
          SHA-512:09CE408886E2CEADDF70786A15D63AF9A930E70CAC4286AC9DDD2094C8EDCF97A2ADC2D3D2659B123F88719340D3B00D9F96E9BC7C8B55192735C290E7D24683
          Malicious:false
          Reputation:unknown
          Preview:# http.tcl..# Client-side HTTP for GET, POST, and HEAD commands...# These routines can be used in untrusted code that uses the Safesock..# security policy...# These procedures use a callback interface to avoid using vwait,..# which is not defined in the safe base...#..# See the http.n man page for documentation....package provide http 1.0....array set http {.. -accept */*.. -proxyhost {}.. -proxyport {}.. -useragent {Tcl http client package 1.0}.. -proxyfilter httpProxyRequired..}..proc http_config {args} {.. global http.. set options [lsort [array names http -*]].. set usage [join $options ", "].. if {[llength $args] == 0} {...set result {}...foreach name $options {... lappend result $name $http($name)...}...return $result.. }.. regsub -all -- - $options {} options.. set pat ^-([join $options |])$.. if {[llength $args] == 1} {...set flag [lindex $args 0]...if {[regexp -- $pat $flag]} {... return $http($flag)...} else {... return -code er
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):746
          Entropy (8bit):4.711041943572035
          Encrypted:false
          SSDEEP:
          MD5:A387908E2FE9D84704C2E47A7F6E9BC5
          SHA1:F3C08B3540033A54A59CB3B207E351303C9E29C6
          SHA-256:77265723959C092897C2449C5B7768CA72D0EFCD8C505BDDBB7A84F6AA401339
          SHA-512:7AC804D23E72E40E7B5532332B4A8D8446C6447BB79B4FE32402B13836079D348998EA0659802AB0065896D4F3C06F5866C6B0D90BF448F53E803D8C243BBC63
          Malicious:false
          Reputation:unknown
          Preview:# Tcl package index file, version 1.0..# This file is generated by the "pkg_mkIndex" command..# and sourced either when an application starts up or..# by a "package unknown" script. It invokes the..# "package ifneeded" command to set up package-related..# information so that packages will be loaded automatically..# in response to "package require" commands. When this..# script is sourced, the variable $dir must contain the..# full path name of this file's directory.....package ifneeded http 1.0 [list tclPkgSetup $dir http 1.0 {{http.tcl source {httpCopyDone httpCopyStart httpEof httpEvent httpFinish httpMapReply httpProxyRequired http_code http_config http_data http_formatQuery http_get http_reset http_size http_status http_wait}}}]..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):25633
          Entropy (8bit):4.885492991636381
          Encrypted:false
          SSDEEP:
          MD5:FE92C81BB4ACDDA00761C695344D5F1E
          SHA1:A87E1516FBD1F9751EC590273925CBC5284B16BD
          SHA-256:7A103A85413988456C2AD615C879BBCB4D91435BCFBBE23393E0EB52B56AF6E2
          SHA-512:C983076E420614D12AB2A7342F6F74DD5DCDAD21C7C547F660E73B74B3BE487A560ABD73213DF3F58BE3D9DBD061A12D2956CA85A58D7B9D9E40D9FA6E6C25EB
          Malicious:false
          Reputation:unknown
          Preview:# init.tcl --..#..# Default system startup file for Tcl-based applications. Defines..# "unknown" procedure and auto-load facilities...#..# Copyright (c) 1991-1993 The Regents of the University of userfornia...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 1998-1999 Scriptics Corporation...# Copyright (c) 2004 Kevin B. Kenny. All rights reserved...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# This test intentionally written in pre-7.5 Tcl..if {[info commands package] == ""} {.. error "version mismatch: library\nscripts expect Tcl version 7.5b1 or later but the loaded version is\nonly [info patchlevel]"..}..package require -exact Tcl 8.6.13....# Compute the auto path to use in this interpreter...# The values on the path come from several locations:..#..# The environment variable TCLLIBPATH..#..# tcl_library, which is the directory containing this init.tcl script...# [t
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1038
          Entropy (8bit):4.10054496357204
          Encrypted:false
          SSDEEP:
          MD5:DA8BA1C3041998F5644382A329C3C867
          SHA1:CA0BD787A51AD9EDC02EDD679EEEEB3A2932E189
          SHA-256:A1EACA556BC0CFBD219376287C72D9DBBFAB76ECF9BF204FD02D40D341BAF7DA
          SHA-512:4F086396405FDFE7FBDA7614D143DE9DB41F75BDBD3DB18B1EE9517C3DCCED238DD240B4B64829FD04E50F602DBF371D42A321D04C4C48E4B8B2A067CA1BAF2E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset af DAYS_OF_WEEK_ABBREV [list \.. "So"\.. "Ma"\.. "Di"\.. "Wo"\.. "Do"\.. "Vr"\.. "Sa"].. ::msgcat::mcset af DAYS_OF_WEEK_FULL [list \.. "Sondag"\.. "Maandag"\.. "Dinsdag"\.. "Woensdag"\.. "Donderdag"\.. "Vrydag"\.. "Saterdag"].. ::msgcat::mcset af MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Des"\.. ""].. ::msgcat::mcset af MONTHS_FULL [list \.. "Januarie"\.. "Februarie"\.. "Maart"\.. "April"\.. "Mei"\.. "Junie"\.. "Julie"\.. "Augustus"\.. "September"\.. "Oktober"\.. "November"\.. "Desember"\.. ""].. ::msgcat::mcset af AM "VM
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.925537696653838
          Encrypted:false
          SSDEEP:
          MD5:1B9DCD1C6FCDDC95AE820EA8DA5E15B8
          SHA1:E8160353FD415BAB9FD5ACCA14E087C5E6AE836E
          SHA-256:1548988458BBF0DFCCC23B7487CEC0E9C64E4CC8E045723E50BEC37C454A8C81
          SHA-512:532AF060B95AED5E381B161BE56BC88D91A8F3DF2ACFD835491991F99FE752ADB4A3F93AB6D4E68F7042C28A3C1DD87A6312DFD9FFFAFD6ECE3F1B76837C5B7F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset af_ZA DATE_FORMAT "%d %B %Y".. ::msgcat::mcset af_ZA TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset af_ZA DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2018
          Entropy (8bit):4.477377447232708
          Encrypted:false
          SSDEEP:
          MD5:D264D01B46D96455715114CAEDF9F05E
          SHA1:A3F68A4C6E69433BD53E52B73041575F3B3AC3F2
          SHA-256:B69D0061A728D59F89FF8621312789CD9F540BF2E2ED297804D22F6278561D85
          SHA-512:A4163DAA6821B293EADD5D499E0641A8B7C93180C710D6B364AE8681A8FF6F35EC948C8DDBE960A8466AF1ACABC15B0D465A08B084617E8005D708459F7E74D3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar DAYS_OF_WEEK_ABBREV [list \.. "\u062d"\.. "\u0646"\.. "\u062b"\.. "\u0631"\.. "\u062e"\.. "\u062c"\.. "\u0633"].. ::msgcat::mcset ar DAYS_OF_WEEK_FULL [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar MONTHS_ABBREV [list \.. "\u064a\u0646\u0627"\.. "\u0641\u0628\u0631"\.. "\u0645\u0627\u0631"\.. "\u0623\u0628\u0631"\.. "\u0645\u0627\u064a"\.. "\u064a\u0648\u0646"\.. "\u064a\u0648\u0644"\.. "\u0623\u063a\u0633"\.. "\u0633\u0628\u062a"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):265
          Entropy (8bit):4.872222510420193
          Encrypted:false
          SSDEEP:
          MD5:430498B4AB1E77C86BC1311A49747581
          SHA1:684EAD965D9010C2A6E73DCACB2224FDE585F9FF
          SHA-256:2E04B96DA002519D28125918A22FF2BB9659A668A7BCAD34D85DDDECEC8DC0B4
          SHA-512:9F85A88A383DCFC54DAA6253D94C307A14B1CC91D5C97AF817B8122AF98025AB2430D0B2D656EBED09E78FB854D1F9CF99F3B791A6ECB7834112012739140126
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_IN DATE_FORMAT "%A %d %B %Y".. ::msgcat::mcset ar_IN TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset ar_IN DATE_TIME_FORMAT "%A %d %B %Y %I:%M:%S %z %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1851
          Entropy (8bit):4.08645484776227
          Encrypted:false
          SSDEEP:
          MD5:5C62D606F4F14BC8994B28F9622D70DD
          SHA1:E99F8CC5D330085545B05B69213E9D011D436990
          SHA-256:5ADBB3D37C3369E5FC80D6A462C82598D5A22FAEF0E8DF6B3148231D2C6A7F73
          SHA-512:81AC9200459B0896E27A028BD089A174F7F921B0367BC8FF1AB33D3E561417B6F8EC23DAB750ECB408AC8A11CDFDBFA4F890F9E723BB8607B017C9FEE00928A0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_JO DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_JO MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1851
          Entropy (8bit):4.083347689510237
          Encrypted:false
          SSDEEP:
          MD5:6FC1CC738207E2F8E0871103841BC0D4
          SHA1:D2C62C7F6DA1EF399FCBE2BA91C9562C87E6152F
          SHA-256:1FC13070CF661488E90FECE84274C46B1F4CC7E1565EAB8F829CCAA65108DFCA
          SHA-512:E547D5CBB746654051AFDA21942075BC2224C2FF75D440C6C34C642AD24CF622E520FF919B8BD4AFC0116D9CE69B3ABA4E81EE247C1388F3C5741150201F5C60
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_LB DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_LB MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1851
          Entropy (8bit):4.084701680556524
          Encrypted:false
          SSDEEP:
          MD5:8188C37CA44FEFFF8D895AAD503AD4F6
          SHA1:C48F2E3B9FC055704D2DAFDC67E9D08EE6897D45
          SHA-256:294F3E46C55453EDAD44567E1330F9B43E69A07FA0655B24DD2780A4490C1194
          SHA-512:F86FCFC7C460473D46C472041AB2E1F9388CF34BCA9050295D1DAE454E35A2A0320D0C61D5E8CBB832AF74FFDD1A7511AF32EA2A53B481F39A1CBCF5F086D514
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_SY DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_SY MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2157
          Entropy (8bit):4.27810535662921
          Encrypted:false
          SSDEEP:
          MD5:6334BDDFC1E0EAE4DBB2C90F85818FD8
          SHA1:085EDC3D027D6B5A6A6A2561717EA89C8F8B8B39
          SHA-256:A636A82C7D00CCDC0AF2496043FFA320F17B0D48A1232708810D3BB1453E881E
          SHA-512:18ADB77314FCFD534E55B234B3A53A0BC572AB60B80D099D2F3B20E0C5FE66179FDC076AA43200DB3CA123BC6216989EC41448FA624D3BA9633413AD8AD6034C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset be DAYS_OF_WEEK_ABBREV [list \.. "\u043d\u0434"\.. "\u043f\u043d"\.. "\u0430\u0442"\.. "\u0441\u0440"\.. "\u0447\u0446"\.. "\u043f\u0442"\.. "\u0441\u0431"].. ::msgcat::mcset be DAYS_OF_WEEK_FULL [list \.. "\u043d\u044f\u0434\u0437\u0435\u043b\u044f"\.. "\u043f\u0430\u043d\u044f\u0434\u0437\u0435\u043b\u0430\u043a"\.. "\u0430\u045e\u0442\u043e\u0440\u0430\u043a"\.. "\u0441\u0435\u0440\u0430\u0434\u0430"\.. "\u0447\u0430\u0446\u0432\u0435\u0440"\.. "\u043f\u044f\u0442\u043d\u0456\u0446\u0430"\.. "\u0441\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset be MONTHS_ABBREV [list \.. "\u0441\u0442\u0434"\.. "\u043b\u044e\u0442"\.. "\u0441\u043a\u0432"\.. "\u043a\u0440\u0441"\.. "\u043c\u0430\u0439"\.. "\u0447\u0440\u0432"\.. "\u043b\u043f\u043d"
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1871
          Entropy (8bit):4.4251657008559935
          Encrypted:false
          SSDEEP:
          MD5:E5225D6478C60E2502D18698BB917677
          SHA1:52D611CB5351FB873D2535246B3A3C1A37094023
          SHA-256:CFE4E44A3A751F113847667EC9EA741E762BBDE0D4284822CB337DF0F92C1ACA
          SHA-512:59AB167177101088057BF4EE0F70262987A2177ECB72C613CCAAE2F3E8D8B77F07D15DA5BE3B8728E23C31A1C9736030AA4036A8CD00A24791751A298B3A88B3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bg DAYS_OF_WEEK_ABBREV [list \.. "\u041d\u0434"\.. "\u041f\u043d"\.. "\u0412\u0442"\.. "\u0421\u0440"\.. "\u0427\u0442"\.. "\u041f\u0442"\.. "\u0421\u0431"].. ::msgcat::mcset bg DAYS_OF_WEEK_FULL [list \.. "\u041d\u0435\u0434\u0435\u043b\u044f"\.. "\u041f\u043e\u043d\u0435\u0434\u0435\u043b\u043d\u0438\u043a"\.. "\u0412\u0442\u043e\u0440\u043d\u0438\u043a"\.. "\u0421\u0440\u044f\u0434\u0430"\.. "\u0427\u0435\u0442\u0432\u044a\u0440\u0442\u044a\u043a"\.. "\u041f\u0435\u0442\u044a\u043a"\.. "\u0421\u044a\u0431\u043e\u0442\u0430"].. ::msgcat::mcset bg MONTHS_ABBREV [list \.. "I"\.. "II"\.. "III"\.. "IV"\.. "V"\.. "VI"\.. "VII"\.. "VIII"\.. "IX"\.. "X"\.. "XI"\.. "XII"\.. ""].. ::msgcat::mcset bg MO
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2335
          Entropy (8bit):4.107102006297273
          Encrypted:false
          SSDEEP:
          MD5:5D25E7FC65824AC987535FEA14A4045C
          SHA1:85C10F05823CD3263FC7B3EC38796BEC261B3716
          SHA-256:890EA6521DEB1B3C3913CCD92562F6360E064DAEE2E2B0356A6DD97A46264A1F
          SHA-512:5D8A88ACAEBBF3CD721F288FA0F1FEE517EE568CA5482E30CFA1E36CD37DF011C449090E2D9041F1D046A191F13D4C5C4B6F9E2F16FD259E63CE46ECC4E4F81F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bn DAYS_OF_WEEK_ABBREV [list \.. "\u09b0\u09ac\u09bf"\.. "\u09b8\u09cb\u09ae"\.. "\u09ae\u0999\u0997\u09b2"\.. "\u09ac\u09c1\u09a7"\.. "\u09ac\u09c3\u09b9\u09b8\u09cd\u09aa\u09a4\u09bf"\.. "\u09b6\u09c1\u0995\u09cd\u09b0"\.. "\u09b6\u09a8\u09bf"].. ::msgcat::mcset bn DAYS_OF_WEEK_FULL [list \.. "\u09b0\u09ac\u09bf\u09ac\u09be\u09b0"\.. "\u09b8\u09cb\u09ae\u09ac\u09be\u09b0"\.. "\u09ae\u0999\u0997\u09b2\u09ac\u09be\u09b0"\.. "\u09ac\u09c1\u09a7\u09ac\u09be\u09b0"\.. "\u09ac\u09c3\u09b9\u09b8\u09cd\u09aa\u09a4\u09bf\u09ac\u09be\u09b0"\.. "\u09b6\u09c1\u0995\u09cd\u09b0\u09ac\u09be\u09b0"\.. "\u09b6\u09a8\u09bf\u09ac\u09be\u09b0"].. ::msgcat::mcset bn MONTHS_ABBREV [list \.. "\u099c\u09be\u09a8\u09c1\u09df\u09be\u09b0\u09c0"\.. "\u09ab\u09c7\u09ac\u09cd\u09b0\u09c1\u09df\u09be
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):265
          Entropy (8bit):4.868201122972066
          Encrypted:false
          SSDEEP:
          MD5:B91BB2ABC23B90962D2070B9588F2AB5
          SHA1:CBB4E9CD600773792C6E9F3E6B27E99C1846B44F
          SHA-256:B3D8A4632290B0F3DA690E47C1FDF06A8B9E171A96E938AFDB0DD52CF806CE54
          SHA-512:932FC4B8C3CA72731187D56012AD7DD7777C4D447F16EEB17B9D68235C9590DF99992FD22B8D7C85A843A610F93CD36FAFA993C34C441255A1C0A93C73BC5FE4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bn_IN DATE_FORMAT "%A %d %b %Y".. ::msgcat::mcset bn_IN TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset bn_IN DATE_TIME_FORMAT "%A %d %b %Y %I:%M:%S %z %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1152
          Entropy (8bit):4.2880653012847985
          Encrypted:false
          SSDEEP:
          MD5:72DDD60C907DD235BCE4AB0A5AEE902C
          SHA1:06150F793251687E6FBC3FDA3BC81BCBFC7DE763
          SHA-256:3BE295DCC8FCDC767FED0C68E3867359C18E7E57D7DB6C07236B5BC572AD328E
          SHA-512:3B0A85003692F1E46185D5CC09236D2DA5E6D29166C9812D07A7D6BF6AC6C3B0708F91C6899768D4DBA3528081B8B43E09F49622B70F1CF991AFAC5352B6BA37
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ca DAYS_OF_WEEK_ABBREV [list \.. "dg."\.. "dl."\.. "dt."\.. "dc."\.. "dj."\.. "dv."\.. "ds."].. ::msgcat::mcset ca DAYS_OF_WEEK_FULL [list \.. "diumenge"\.. "dilluns"\.. "dimarts"\.. "dimecres"\.. "dijous"\.. "divendres"\.. "dissabte"].. ::msgcat::mcset ca MONTHS_ABBREV [list \.. "gen."\.. "feb."\.. "mar\u00e7"\.. "abr."\.. "maig"\.. "juny"\.. "jul."\.. "ag."\.. "set."\.. "oct."\.. "nov."\.. "des."\.. ""].. ::msgcat::mcset ca MONTHS_FULL [list \.. "gener"\.. "febrer"\.. "mar\u00e7"\.. "abril"\.. "maig"\.. "juny"\.. "juliol"\.. "agost"\.. "setembre"\.. "octubre"\.. "novembre"\.. "desembre"\.. ""].. ::msg
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1354
          Entropy (8bit):4.466447248030554
          Encrypted:false
          SSDEEP:
          MD5:F32EAD82CC26754C5A8E092873A28DB3
          SHA1:325124660F62242B24623B4B737CB4616F86CFF3
          SHA-256:AFEA12A16A6FA750EA610245133B90F178BA714848F89AEC37429A3E7B06BE1A
          SHA-512:04E335AAFBF4D169983635FC87BCFFE86FBA570A3E1820D20240EF7B47E7A3CD94AE3598543DCE92A1F82B5146CAAD982EFE9490EFD9E581D58515CFC3930581
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset cs DAYS_OF_WEEK_ABBREV [list \.. "Ne"\.. "Po"\.. "\u00dat"\.. "St"\.. "\u010ct"\.. "P\u00e1"\.. "So"].. ::msgcat::mcset cs DAYS_OF_WEEK_FULL [list \.. "Ned\u011ble"\.. "Pond\u011bl\u00ed"\.. "\u00dater\u00fd"\.. "St\u0159eda"\.. "\u010ctvrtek"\.. "P\u00e1tek"\.. "Sobota"].. ::msgcat::mcset cs MONTHS_ABBREV [list \.. "I"\.. "II"\.. "III"\.. "IV"\.. "V"\.. "VI"\.. "VII"\.. "VIII"\.. "IX"\.. "X"\.. "XI"\.. "XII"\.. ""].. ::msgcat::mcset cs MONTHS_FULL [list \.. "leden"\.. "\u00fanor"\.. "b\u0159ezen"\.. "duben"\.. "kv\u011bten"\.. "\u010derven"\.. "\u010dervenec"\.. "srpen"\.. "z\u00e1\u0159\u00ed"\.. "\u0159\u00edjen"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1208
          Entropy (8bit):4.315504392809956
          Encrypted:false
          SSDEEP:
          MD5:27A6A8BE8903AEF9D0BE956906A89583
          SHA1:EE29FDF67CB3AE150DF6BBBE603C1C3F5DA28641
          SHA-256:0D422A991BCA13FE9033118691CFEDAB0F372222EBB0BC92BAF8E914EE816B84
          SHA-512:0E702A679AD94BF479226B7DE32077562F3F95210F6453AE564138386DBB179941BA5359AEE9AC532F4A6E5BE745D6962D6B638A21DD48B865716F2FD2A0CB01
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset da DAYS_OF_WEEK_ABBREV [list \.. "s\u00f8"\.. "ma"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f8"].. ::msgcat::mcset da DAYS_OF_WEEK_FULL [list \.. "s\u00f8ndag"\.. "mandag"\.. "tirsdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f8rdag"].. ::msgcat::mcset da MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset da MONTHS_FULL [list \.. "januar"\.. "februar"\.. "marts"\.. "april"\.. "maj"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset da B
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1276
          Entropy (8bit):4.349293509679722
          Encrypted:false
          SSDEEP:
          MD5:EE3963A5F7E29C05C9617BE3FD897114
          SHA1:0F978CA174DF596817F872B5EF1B447B9DFE651C
          SHA-256:4C27733502066E8391654D1D372F92BF0484C5A3821E121AE8AA5B99378C99AE
          SHA-512:EA933709C68F8199858A1CC1FFDA67EE7458CC57A163E672535EB0B4C37BFDC200604C7506748DAC3158B6CA63C2F076A2C6252B2A596E59F83D3B1D4BC9C901
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de DAYS_OF_WEEK_ABBREV [list \.. "So"\.. "Mo"\.. "Di"\.. "Mi"\.. "Do"\.. "Fr"\.. "Sa"].. ::msgcat::mcset de DAYS_OF_WEEK_FULL [list \.. "Sonntag"\.. "Montag"\.. "Dienstag"\.. "Mittwoch"\.. "Donnerstag"\.. "Freitag"\.. "Samstag"].. ::msgcat::mcset de MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mrz"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::msgcat::mcset de BCE "v.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):847
          Entropy (8bit):4.412930056658995
          Encrypted:false
          SSDEEP:
          MD5:A6227CD4F7434952D093F1F3C64B4378
          SHA1:0DDB9A49CB83DDF2396B2ECA85093260710496C2
          SHA-256:1C02D14140196623297F858E2EEF00B4159E1C6FAFE044EC65A48C9C24D46540
          SHA-512:D63F34024356F5CE0335D14EA557F4BBF238CCA8265DD27C039C70F7F28FE737F368B030DEE10B2C536512D2815E1F5B19838D08745C6A76A39050D573597EB3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de_AT MONTHS_ABBREV [list \.. "J\u00e4n"\.. "Feb"\.. "M\u00e4r"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de_AT MONTHS_FULL [list \.. "J\u00e4nner"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::msgcat::mcset de_AT DATE_FORMAT "%Y-%m-%d".. ::msgcat::mcset de_AT TIME_FORMAT "%T".. ::msgcat::mcset de_AT TIME_FORMAT_12 "%T".. ::msgcat::mcset de_AT DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1276
          Entropy (8bit):4.389082225723362
          Encrypted:false
          SSDEEP:
          MD5:C351057D8E5328C0790901D1F4DBEC9F
          SHA1:F73DE8AEF7F8083B0726760AA003E81067A68588
          SHA-256:532845CD15EC821C1939D000C648694A64E8CA8F0C14BAD5D79682CF991481CE
          SHA-512:8152AD082D0A6A4EBE7E1CCA9D4A5F2E48ABE3F09F4385A517C523A67CA3B08E0F20C193D0F6850F37E55ED0CD6FBD201FE22CC824AF170976D04DB061212F2D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de_BE DAYS_OF_WEEK_ABBREV [list \.. "Son"\.. "Mon"\.. "Die"\.. "Mit"\.. "Don"\.. "Fre"\.. "Sam"].. ::msgcat::mcset de_BE DAYS_OF_WEEK_FULL [list \.. "Sonntag"\.. "Montag"\.. "Dienstag"\.. "Mittwoch"\.. "Donnerstag"\.. "Freitag"\.. "Samstag"].. ::msgcat::mcset de_BE MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "M\u00e4r"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de_BE MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::m
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2304
          Entropy (8bit):4.371322909589862
          Encrypted:false
          SSDEEP:
          MD5:7DD14B1F4FF532DCAF6D4C6F0DF82E9A
          SHA1:707875FEF4207EBB71D066FDC54C7F68560C6DAD
          SHA-256:8B23E0E2F0F319BB9A2DFDCCDC565FF79A62FA85094811189B6BC41594232B6B
          SHA-512:5ECA072DE5DD7890270AE268C7C8D40EE2DB6966643604D16E54194DB0AD74FDA8D04848331E61B387E8B494AF18252E38671D939069EC4C90C672A629563B88
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset el DAYS_OF_WEEK_ABBREV [list \.. "\u039a\u03c5\u03c1"\.. "\u0394\u03b5\u03c5"\.. "\u03a4\u03c1\u03b9"\.. "\u03a4\u03b5\u03c4"\.. "\u03a0\u03b5\u03bc"\.. "\u03a0\u03b1\u03c1"\.. "\u03a3\u03b1\u03b2"].. ::msgcat::mcset el DAYS_OF_WEEK_FULL [list \.. "\u039a\u03c5\u03c1\u03b9\u03b1\u03ba\u03ae"\.. "\u0394\u03b5\u03c5\u03c4\u03ad\u03c1\u03b1"\.. "\u03a4\u03c1\u03af\u03c4\u03b7"\.. "\u03a4\u03b5\u03c4\u03ac\u03c1\u03c4\u03b7"\.. "\u03a0\u03ad\u03bc\u03c0\u03c4\u03b7"\.. "\u03a0\u03b1\u03c1\u03b1\u03c3\u03ba\u03b5\u03c5\u03ae"\.. "\u03a3\u03ac\u03b2\u03b2\u03b1\u03c4\u03bf"].. ::msgcat::mcset el MONTHS_ABBREV [list \.. "\u0399\u03b1\u03bd"\.. "\u03a6\u03b5\u03b2"\.. "\u039c\u03b1\u03c1"\.. "\u0391\u03c0\u03c1"\.. "\u039c\u03b1\u03ca"\.. "\u0399\u03bf\u
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):307
          Entropy (8bit):4.896073290907262
          Encrypted:false
          SSDEEP:
          MD5:5B31AD8AC0000B01C4BD04BF6FC4784C
          SHA1:F55145B473DDCAE38A0F7297D58B80B12B2A5271
          SHA-256:705C66C14B6DE682EC7408EABDBA0800C626629E64458971BC8A4CBD3D5DB111
          SHA-512:1CCE6BCAE5D1F7D80E10687F0BCA2AE1B2DD53F04A0F443DC9B552804D60E708E64326B62BA4E3787325D89837B4AC8CCCA9AF6F39CBD654BCC8A9C27EA63BB8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_AU DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset en_AU TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_AU TIME_FORMAT_12 "%I:%M:%S %P %z".. ::msgcat::mcset en_AU DATE_TIME_FORMAT "%e/%m/%Y %H:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):312
          Entropy (8bit):4.870560620756039
          Encrypted:false
          SSDEEP:
          MD5:DDA87ACED97F9F7771788A1A0A1E4433
          SHA1:E221653CD659C095098180344654770FF059331B
          SHA-256:BC87754A253C1036E423FA553DA182DBC56F62A13EDA811D8CD9E8AFA40404A6
          SHA-512:BB95D9241B05686CA15C413746DD06071635CB070F38847BE9702397A86C01A3D54DEBE1ACAA51834AB74DB8D0F75E353995183864E382721425756EE46B0B1E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_BE DATE_FORMAT "%d %b %Y".. ::msgcat::mcset en_BE TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset en_BE TIME_FORMAT_12 "%k h %M min %S s %z".. ::msgcat::mcset en_BE DATE_TIME_FORMAT "%d %b %Y %k:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.915769170926952
          Encrypted:false
          SSDEEP:
          MD5:4CBF90CE15ECCB6B695AA78D7D659454
          SHA1:30C26ADB03978C5E7288B964A14B692813D6E0B8
          SHA-256:EC48F18995D46F82B1CC71EA285174505A50E3BA2017BCCE2D807149B7543FD0
          SHA-512:CC809EBD1B2B5D9E918C2E2CE4E7075DFB0744C583F17C1C234D8437EF0C34654D2F09FF77544AD3430CEC78ABC70AA5F85F71AD1489A687B8087FCDFE07B088
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_BW DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_BW TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_BW DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):295
          Entropy (8bit):4.87629705076992
          Encrypted:false
          SSDEEP:
          MD5:BFC4A48F5B10D137A4D32B440C47D3C6
          SHA1:C90EF2A8291DE589BC12D0A5B8AF2F0B00FEB7CD
          SHA-256:3CF2D0937FD95264549CF5C768B898F01D4875A3EB4A85D457D758BC11DFEC6E
          SHA-512:A91B81A956A438CA7274491CA107A2647CBDFB8AEB5FD7A58238F315590C74F83F2EBA4AA5C4E9A4A54F1FC1636318E94E5E4BBEA467326E0EACED079741E640
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_CA DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_CA TIME_FORMAT "%r".. ::msgcat::mcset en_CA TIME_FORMAT_12 "%I:%M:%S %p".. ::msgcat::mcset en_CA DATE_TIME_FORMAT "%a %d %b %Y %r %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.892405843607203
          Encrypted:false
          SSDEEP:
          MD5:52E55DE8C489265064A01CEEC823DCDD
          SHA1:16F314A56AE0EAC9DAD58ADDEA6B25813A5BAA05
          SHA-256:C2CE5B74F9E9C190B21C5DF4106303B7B794481228FB9A57065B9C822A1059C3
          SHA-512:6010F29BF75D0CB4EE4F10781423A8CC68D5018DE8C633CD1217A7FE1299A0532E8C0E5D120188B748171EB255C587BB0B64B7384A58F725F3B6A4B9EA04393E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_GB DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_GB TIME_FORMAT "%T".. ::msgcat::mcset en_GB TIME_FORMAT_12 "%T".. ::msgcat::mcset en_GB DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):329
          Entropy (8bit):4.851471679101967
          Encrypted:false
          SSDEEP:
          MD5:DE2A484508615D7C1377522AFF03E16C
          SHA1:C27C0D10E7667AD95FFF731B4E45B2C6E665CC36
          SHA-256:563450A38DB6C6A1911BC04F4F55B816910B3E768B1465A69F9B3BD27292DBEE
          SHA-512:A360B0FD7E36BCC0FB4603D622C36199E5D4C705396C6701F29730EB5CB33D81B208541CADFAED5303FC329C7C6A465D23CA9584F0DEC2DE128E258478DD6661
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_HK AM "AM".. ::msgcat::mcset en_HK PM "PM".. ::msgcat::mcset en_HK DATE_FORMAT "%B %e, %Y".. ::msgcat::mcset en_HK TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_HK DATE_TIME_FORMAT "%B %e, %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.833246107458447
          Encrypted:false
          SSDEEP:
          MD5:57F0BBE1316D14BC41D0858902A7980A
          SHA1:B68BF99A021B9F01FE69341DF06F5D1453156A97
          SHA-256:9E0DCEE86A03B7BDD831E0008868A9B874C506315BF01DF3982AD3813FD3BA8E
          SHA-512:864F32254AAD39859AFC47D0C90DC5F38CA86EF0BBC7DE61BE253756C22B7806E616B59802C4F4D7B2F5543BF7C070FFF6FAF253E0A337EC443337E63A2E5A57
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_IE DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_IE TIME_FORMAT "%T".. ::msgcat::mcset en_IE TIME_FORMAT_12 "%T".. ::msgcat::mcset en_IE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):318
          Entropy (8bit):4.80637980762728
          Encrypted:false
          SSDEEP:
          MD5:1A54E506E70B2125C6016B373D3DD074
          SHA1:15289902BAA93208D8FB224E119166D0E044E34E
          SHA-256:ADEA3A1AB8AA84237DDB2F276ABDB96DCB4C51932E920D1A5E336904E1138664
          SHA-512:0D663233E6C96515713B3B829B605E72D8CE581AEF1C02FF6CA96598C040DCA42A3AC765EE9B5002E8969A331EB19A9AF0F8215F7113D0AD2F2EB2C560239D53
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_IN AM "AM".. ::msgcat::mcset en_IN PM "PM".. ::msgcat::mcset en_IN DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_IN TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_IN DATE_TIME_FORMAT "%d %B %Y %H:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):307
          Entropy (8bit):4.939458132662909
          Encrypted:false
          SSDEEP:
          MD5:7E81708F107658FFD31C3BFBF704A488
          SHA1:7941ED040707591B68581337F8D90FA03C5E1406
          SHA-256:EC305B7CB393421E6826D8F4FEA749D3902EBA53BFA488F2B463412F4070B9ED
          SHA-512:8F038FF960F81D96FF9E3454D8ABDA7FFDA5B99DA304ACECC42E74DDBED839388246F66B58928DA902D3B475FBA46602B34F6829A87ECB1124FFC47C036B4DBE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_NZ DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset en_NZ TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_NZ TIME_FORMAT_12 "%I:%M:%S %P %z".. ::msgcat::mcset en_NZ DATE_TIME_FORMAT "%e/%m/%Y %H:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):329
          Entropy (8bit):4.824360175945298
          Encrypted:false
          SSDEEP:
          MD5:E2E3BD806C20D7FB88109B7F3B84C072
          SHA1:2D7AD6BECA9C4D611BAE9747AD55A3E9385C2B42
          SHA-256:3A9C22B07906544C04F7A29B800FCE87C09D7FDF5C251236925115CF251A3890
          SHA-512:B14756B59BCABF8B29B41AC688E4F3A011735AF190B88F88B7B5FDDD3DA77F63FFC0F7875B3B453729CD3BC65E79F75F6E632CA68952EF473F78337D89E80BF2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_PH AM "AM".. ::msgcat::mcset en_PH PM "PM".. ::msgcat::mcset en_PH DATE_FORMAT "%B %e, %Y".. ::msgcat::mcset en_PH TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_PH DATE_TIME_FORMAT "%B %e, %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.911413468674953
          Encrypted:false
          SSDEEP:
          MD5:F70245D73BE985091459ADF74B089EBC
          SHA1:21D52C336C08526D9DCF1AEC1F0701CB8B073D7A
          SHA-256:D565679AE9AACBFE3B5273FE29BD46F46FFBB63C837D7925C11356D267F5FF82
          SHA-512:171C70EB10D5E6421A55CE9B1AE99763E23FB6A6F563F69FE099D07C07FCA0CF8D3F6F00C5BB38BFF59A5F4C311506C4A9593F86C12B3B9E1861E72656B3800B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_SG DATE_FORMAT "%d %b %Y".. ::msgcat::mcset en_SG TIME_FORMAT_12 "%P %I:%M:%S".. ::msgcat::mcset en_SG DATE_TIME_FORMAT "%d %b %Y %P %I:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):251
          Entropy (8bit):4.937431055623088
          Encrypted:false
          SSDEEP:
          MD5:FCA7B13CA6C9527D396A95BEA94CC92D
          SHA1:E6F338A08F72DA11B97F70518D1565E6EF9AD798
          SHA-256:67C253E2A187AA814809418E5B7A21F3A1F9FB5073458A59D80290F58C6C1EB4
          SHA-512:37B8B4EA24B1C77AF0252A17660650CB2D4F8BB55C75817D6A94E1B81A3DDEF9913D12D3BF80C7BFE524CD0AD84E353E73238056759E6545BFE69EF5F806B8B7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_ZA DATE_FORMAT "%Y/%m/%d".. ::msgcat::mcset en_ZA TIME_FORMAT_12 "%I:%M:%S".. ::msgcat::mcset en_ZA DATE_TIME_FORMAT "%Y/%m/%d %I:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.934659260313229
          Encrypted:false
          SSDEEP:
          MD5:A302091F490344B7A79C9463480AD7CF
          SHA1:E3992D665077177BAD5A4771F1BAF52C2AD1829C
          SHA-256:6F4754CE29DFA4F0E7957923249151CE8277395D1AF9F102D61B185F85899E4E
          SHA-512:FEBDB0BD6D0FD4C592DB781836F93F0C579399D324112F8829B769303CC6EEA487AAB14EBD60ED1B4F3B3DABF501601C9F65656327FF54853BF2CD9EC6A2F00F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_ZW DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_ZW TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_ZW DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1285
          Entropy (8bit):4.3537859241297845
          Encrypted:false
          SSDEEP:
          MD5:D87605E6282713EED41D56D53B7A04FD
          SHA1:41AAD4BD3B72CCBB6A762FEED3C24931642DD867
          SHA-256:98D52CAB5CA65789D1DC37949B65BAF0272AB87BCCBB4D4982C3AF380D5406AB
          SHA-512:4A4F51B2FD0248B52530B5D9FE6BFCFE455147CBE2C1F073804A53666945405F89CBBAD219FFF6904C1F92885F7C53B9D9A969732D662CEA8EC1717B3303B294
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eo DAYS_OF_WEEK_ABBREV [list \.. "di"\.. "lu"\.. "ma"\.. "me"\.. "\u0135a"\.. "ve"\.. "sa"].. ::msgcat::mcset eo DAYS_OF_WEEK_FULL [list \.. "diman\u0109o"\.. "lundo"\.. "mardo"\.. "merkredo"\.. "\u0135a\u016ddo"\.. "vendredo"\.. "sabato"].. ::msgcat::mcset eo MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "a\u016dg"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset eo MONTHS_FULL [list \.. "januaro"\.. "februaro"\.. "marto"\.. "aprilo"\.. "majo"\.. "junio"\.. "julio"\.. "a\u016dgusto"\.. "septembro"\.. "oktobro"\.. "novembro"\.. "decembro"\.. ""].. ::m
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1232
          Entropy (8bit):4.2910064237800025
          Encrypted:false
          SSDEEP:
          MD5:91DE6EE8E1A251EF73CC74BFB0216CAC
          SHA1:1FB01E3CF2CAFA95CC451BC34AB89DC542BBD7DD
          SHA-256:E9A6FE8CCE7C808487DA505176984D02F7D644425934CEDB10B521FE1E796202
          SHA-512:46CFD80E68461F165EE6A93AB6B433E4D4DA6A9A76CB7F3EF5766AC67567A7AFFB7B4E950A5AFA7C69C91F72AC82D2A448D32E39BBFC0BF26D2257460471EEC1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es DAYS_OF_WEEK_ABBREV [list \.. "dom"\.. "lun"\.. "mar"\.. "mi\u00e9"\.. "jue"\.. "vie"\.. "s\u00e1b"].. ::msgcat::mcset es DAYS_OF_WEEK_FULL [list \.. "domingo"\.. "lunes"\.. "martes"\.. "mi\u00e9rcoles"\.. "jueves"\.. "viernes"\.. "s\u00e1bado"].. ::msgcat::mcset es MONTHS_ABBREV [list \.. "ene"\.. "feb"\.. "mar"\.. "abr"\.. "may"\.. "jun"\.. "jul"\.. "ago"\.. "sep"\.. "oct"\.. "nov"\.. "dic"\.. ""].. ::msgcat::mcset es MONTHS_FULL [list \.. "enero"\.. "febrero"\.. "marzo"\.. "abril"\.. "mayo"\.. "junio"\.. "julio"\.. "agosto"\.. "septiembre"\.. "octubre"\.. "noviembre"\.. "diciembre"\.. ""].. ::msgc
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):248
          Entropy (8bit):4.878377455979812
          Encrypted:false
          SSDEEP:
          MD5:313966A7E4F50BB77996FDE45E342CA9
          SHA1:021DF7211DAE9A635D52F7005672C157DBBAE182
          SHA-256:B97DCEA4FEC3E14632B1511D8C4F9E5A157D97B4EBBC7C6EE100C3558CB2947F
          SHA-512:79DCC76263310523BAF1100C70918FCE6BECB47BE360E4A26F11C61F27E14FC28B588A9253AA0C1F08F45AE8A03312A30FBDCF4FDFFDC5BF9D086C4B539DE022
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_AR DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_AR TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset es_AR DATE_TIME_FORMAT "%d/%m/%Y %H:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.924579610789789
          Encrypted:false
          SSDEEP:
          MD5:EF58B1097A3C6F2133BD7AA8CCC1AD1B
          SHA1:BD479E4635F3CD70A6A90E07B7E92757BC9E2687
          SHA-256:B47F55539DB6F64304DEA080D6F9A39165F1B9D4704DCBA4C182DBD3AA31A11B
          SHA-512:F9EB1489E5002200D255A45DC57132DEFD2A2C6DE5BC049D0D9720575E4FDD1B6A212D9E15974C6A2E0D0886069EA0DD967AD7C20845EC38EB74CBED0C3E5BE1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_BO DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset es_BO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_BO DATE_TIME_FORMAT "%d-%m-%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.9352990174129925
          Encrypted:false
          SSDEEP:
          MD5:42BCE0EE3A3F9E9782E5DE72C989903A
          SHA1:0960646417A61E8C31D408AE00B36A1284D0300E
          SHA-256:9D1A2A6EBA673C6F6D964DBCDDF228CB64978F282E70E494B60D74E16A1DB9CB
          SHA-512:C53DDCC17F261CFFAA2205879A131CFD23A7BCF4D3787090A0EA8D18530C4805903ED6CF31B53A34C70510A314EBBB68676E9F128289B42C5EFBC701405D5645
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CL DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset es_CL TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CL DATE_TIME_FORMAT "%d-%m-%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.908553844782894
          Encrypted:false
          SSDEEP:
          MD5:6A8F31AE734DCEE4845454408CDB3BC5
          SHA1:A3B9A0124D3CFA9E0E5957612897B23193AD5D59
          SHA-256:5FAC53ACFB305C055AFD0BA824742A78CB506046B26DAC21C73F0BB60C2B889A
          SHA-512:188A65CFE2FBD04D83F363AEA166F224137C8A7009A9EBEB24B2A9AC89D9484D3A7109A4CE08F5C0A28911D81571230CC37554F4F19956AE163F9304911EE53C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CO DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_CO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CO DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.919346233482604
          Encrypted:false
          SSDEEP:
          MD5:2EDDA3F61BA4D049E6C871D88322CF72
          SHA1:40AFB64AF810596FCBDBD742ACAFE25CE56F3949
          SHA-256:A33DC22330D087B8567670B4915C334FF1741EE03F05D616CC801ECFDA1D9E64
          SHA-512:B6A6059B44F064C5CB59A3DAFAA7BE9064EE3E38F5FA6391017D931EF3A2B471DC4D556B7BEC6852FD1F6260EF17F476754D6BEA89E035748E9304977513CFB5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CR DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_CR TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CR DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.913083040975068
          Encrypted:false
          SSDEEP:
          MD5:76CFD4F568EA799F9A4082865633FF97
          SHA1:B09846BBF7A78243A5075F2DC9241791DCBA434B
          SHA-256:8DC2F857E91912ED46A94EB6B37DD6170EA7BCDDCD41CB85C0926A74EE12FCC1
          SHA-512:58B20A8A5D1F8C19AC36E61965106266B7E6F7E95DDD6AD9C4BB9FD7FFC561CB0E2103639D901A6A78CE2DD154CBF7F3AE0F71B4DC1CCB11DC6BB40D9C6E2157
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_DO DATE_FORMAT "%m/%d/%Y".. ::msgcat::mcset es_DO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_DO DATE_TIME_FORMAT "%m/%d/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.915857529388286
          Encrypted:false
          SSDEEP:
          MD5:94B713B1560FE7711EA746F1CEBD37CD
          SHA1:E7047E8F04D731D38FA328FBC0E1856C4A8BB23D
          SHA-256:52AB5A6C9DD4F130A75C049B3AF8F54B84071FC190374BCCF5FA0E1F3B91EB21
          SHA-512:EE807D4D74A609F642CC3C6FC3D736708F67A6931DEB95288AB5822DA256BE4C908A346036195CF4266408458906D28BB5C715EEAFCACFC4FE45D4E6D8E435FE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_EC DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_EC TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_EC DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.9102355704853435
          Encrypted:false
          SSDEEP:
          MD5:761D0A468DF2EE75BC2CAB09D5FF38CD
          SHA1:D627BE45FE71CCB3CA53153393C075FF5136C2F3
          SHA-256:19B4D3025156C060A16328370A3FDB9F141298DECFC8F97BE606F6438FECE2EE
          SHA-512:6CF7C9004A8A3B70495862B7D21921B1A6263C2153FEBC5C4997366498ABBFE70263B436C2B4998550780A4C3A58DCF0AAE7420FF9D414323D731FA44BD83104
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_GT DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_GT TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_GT DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.947925914291734
          Encrypted:false
          SSDEEP:
          MD5:33CEE7F947A484B076F5FA7871A30FEB
          SHA1:F77F8D1F42008770A6FF1F5097C863ECF482BEBE
          SHA-256:07873D4D59BB41000706A844859C73D26B1FF794058AA83CFFCA804981A24038
          SHA-512:EBF6873F9CB554489EFCD352943100C00171E49D27153769D1C4DB25E2D1F44F2D34869B596C267C9BB59ED0444468D9982137CFB1C6035FB15A855BB867133B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_HN DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_HN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_HN DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.9102355704853435
          Encrypted:false
          SSDEEP:
          MD5:678D7A6DC32355246BF3AC485A24AF4D
          SHA1:B6C273D3BE5FB9F5A221B0333870CCE41CEDFDE4
          SHA-256:A0F57137D2C0ABDC933E03CFB188F5632176C195CEADB9DC80D469C8DC6CEDC6
          SHA-512:571404CCB0591C681C975E3F7A6C6972FAF2362F1D48BFC95E69A9EAE2DB3F40BF4B666C41950C4924E3FD820C61ED91204F92283B8554F1BD35B64D53BD4125
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_MX DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_MX TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_MX DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.918215906418583
          Encrypted:false
          SSDEEP:
          MD5:471C41907CE5DB1F30C647A789870F78
          SHA1:C575A639609620AF7C56430991D0E4C2B50BDEC5
          SHA-256:6250663DA1378E54BEDCEF206583D212BC0D61D04D070495238D33715BB20CAE
          SHA-512:CAE32DF8F583542CAFE3292501725D85B697A5C1F9A0A7993490E8A69B6CE5CE3DE3AA2733B14D989A8D13B5E31B437DB42E9AB9D1851FE72313592C752B5061
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_NI DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_NI TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_NI DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.906719336603863
          Encrypted:false
          SSDEEP:
          MD5:571F6716293442672521F70854A5AD05
          SHA1:525EBDEA6F85FC769B6C0C0B179BD98381647123
          SHA-256:EBB661C1C09E7D4F6FBCC4B2DAD0F41442B1FFDD27F003ABDC0375DD316E57D7
          SHA-512:C6176EE48515BDFC09B8347DAC5FD2C0165AA765916457DC7B057E526785AC912481CB72F118D2943372213B23CE3C39739263C2B3DA4DBFEB24C522ACC0439D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PA DATE_FORMAT "%m/%d/%Y".. ::msgcat::mcset es_PA TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PA DATE_TIME_FORMAT "%m/%d/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.90959433688075
          Encrypted:false
          SSDEEP:
          MD5:5A5997D834DDD3E2E8FF8C6956AD54AC
          SHA1:AB4110E37B3665D738A8F2B3E64CBA9E99127301
          SHA-256:90C130B66958CF63CB3DDD2C633E58444357DBAB44C56831DD794CBD2EB1AED0
          SHA-512:1FEB8E77EA7B886E4A06279AC8A4B6200DBB86DCD28989651B92A0C9147A7BCFBB871DF8F904A1CF8F869BFFBD21325505AC44A4DBEBE1EFC87D43174597F1F3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PE DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_PE TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PE DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.905689521403511
          Encrypted:false
          SSDEEP:
          MD5:CE811BB8D12C7E6D53338759CCFB0A22
          SHA1:0AED290AA479DE6887CCB58D3F0A0F379EF8D558
          SHA-256:F790E8E48DC079DCD7DEB58170561006A31294F7E4ACBF9CF2ABFA3DB9E3FA9E
          SHA-512:0C73654CC3D33F76D9BF545BD6C5E42CBDD10B6D9750BFD6536806010F3B6A3C3647FB9D5E7E75A39823FDB857E13D07B7F987809C94B9F980E6D3A6D3108E85
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PR DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_PR TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PR DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.917539255090736
          Encrypted:false
          SSDEEP:
          MD5:9CD6FAC4121E3D287C87157142E32845
          SHA1:3081FE2197017EC8E052756A407880C1C4ED026A
          SHA-256:70263F7EB22822DFEE8849B7AC4418ED9331275A71E77236B59226396505CDFF
          SHA-512:25DC054085C4078734988EEDD87E31ABE93DA8B43512E924DE4BCDE9F8EC670436B72FAD1855484F9AC71DD0BEDD9ED30304D02219C4FFC4B0516D8889BDF9F9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PY DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_PY TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PY DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.929035824905457
          Encrypted:false
          SSDEEP:
          MD5:AF300EA6E733DC6820768EA16194B472
          SHA1:7766A6EB3D07BCC759CF6718EF3D6EC3FCE13565
          SHA-256:26A38B3745C95673D21BABB987F1D41EE08DDA945C670F5432BA0CE6F893C0E9
          SHA-512:C38D67C912584BE539D71881C6517AC186CBB336A160602DA716CE2708B2D38CE8FA7DD23EDB98890ABB7119B924B6C7816C18EC18F20C49D6284DF2386E32EE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_SV DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_SV TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_SV DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.923802447598272
          Encrypted:false
          SSDEEP:
          MD5:2DC550FEC3F477B1159B824479BCE707
          SHA1:4D0B20CF3E50B64D74655A405A7750E0B0BB4375
          SHA-256:1291B58810739EA0651493DD7887F5EE3E14BDB806E06DD4BB8AE2520C742EDA
          SHA-512:B12B927ACA6274904928A6A6CAEC8339A794C74A1F1804FF93AABC132AF9AD8AC5117F20067A60EFEBC9887150D7ACA5BE9643FF61509666011FD203211C25B9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_UY DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_UY TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_UY DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.928484426267027
          Encrypted:false
          SSDEEP:
          MD5:184D6C4B9F0AA874DEB959F63F7CC01B
          SHA1:5FB370B498289590C977F6B489FF646F0FB27425
          SHA-256:91191517403C712299919F9C797F952502E33CB6961D1DBEE3A7C9E8D2B170B9
          SHA-512:881CCAB0950AE993744ECCA141120C005F53D684167A3E5CBDDF950D110D630FB2B4F6AE6E3D0E06D5110AE25EA00A4F4DAFB03AD3B227DC8C63464D434431DA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_VE DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_VE TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_VE DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1258
          Entropy (8bit):4.391217201307309
          Encrypted:false
          SSDEEP:
          MD5:C8C5EF2FA6DD8DBD5BBD2699BE1A0BF6
          SHA1:F5E26B40786B8987C98F9CBDEF5522043574A9ED
          SHA-256:4BEE224C21B0483CFF39BE145C671AA20CB7872C8727FD918C0E8ECA2BBEB172
          SHA-512:757FA85C137A11C1A3F4A8392C7A4E4030A67D0E593FA25A98BEC07DB295399AB2C0D9EBE61E07420B14387A29C060DC3AF812A1E7B85110DBB13C3C3DCB3600
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset et DAYS_OF_WEEK_ABBREV [list \.. "P"\.. "E"\.. "T"\.. "K"\.. "N"\.. "R"\.. "L"].. ::msgcat::mcset et DAYS_OF_WEEK_FULL [list \.. "p\u00fchap\u00e4ev"\.. "esmasp\u00e4ev"\.. "teisip\u00e4ev"\.. "kolmap\u00e4ev"\.. "neljap\u00e4ev"\.. "reede"\.. "laup\u00e4ev"].. ::msgcat::mcset et MONTHS_ABBREV [list \.. "Jaan"\.. "Veebr"\.. "M\u00e4rts"\.. "Apr"\.. "Mai"\.. "Juuni"\.. "Juuli"\.. "Aug"\.. "Sept"\.. "Okt"\.. "Nov"\.. "Dets"\.. ""].. ::msgcat::mcset et MONTHS_FULL [list \.. "Jaanuar"\.. "Veebruar"\.. "M\u00e4rts"\.. "Aprill"\.. "Mai"\.. "Juuni"\.. "Juuli"\.. "August"\.. "September"\.. "Oktoober"\.. "November"\.. "De
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1032
          Entropy (8bit):4.002617252503668
          Encrypted:false
          SSDEEP:
          MD5:ED9805AF5BFB54EB28C6CB3975F86F5B
          SHA1:2BD91BD850028712F35A2DDB2555036FBF6E8114
          SHA-256:6889B57D29B670C6CFB7B5A3F2F1749D12C802E8E9629014D06CE23C034C7EF1
          SHA-512:16F31DE5D2B0D3ED2D975C7891C73C48F073CDAC28F17572FC9424C2D384DDFE9E5E235F17C788F42840CB2D819D2D9499B909AB80FEF1B09F2AE1627CF1DADC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eu DAYS_OF_WEEK_ABBREV [list \.. "igandea"\.. "astelehena"\.. "asteartea"\.. "asteazkena"\.. "osteguna"\.. "ostirala"\.. "larunbata"].. ::msgcat::mcset eu DAYS_OF_WEEK_FULL [list \.. "igandea"\.. "astelehena"\.. "asteartea"\.. "asteazkena"\.. "osteguna"\.. "ostirala"\.. "larunbata"].. ::msgcat::mcset eu MONTHS_ABBREV [list \.. "urt"\.. "ots"\.. "mar"\.. "api"\.. "mai"\.. "eka"\.. "uzt"\.. "abu"\.. "ira"\.. "urr"\.. "aza"\.. "abe"\.. ""].. ::msgcat::mcset eu MONTHS_FULL [list \.. "urtarrila"\.. "otsaila"\.. "martxoa"\.. "apirila"\.. "maiatza"\.. "ekaina"\.. "uztaila"\.. "abuztua"\.. "iraila"\.. "urria"\.. "azaroa"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):294
          Entropy (8bit):4.915392589807169
          Encrypted:false
          SSDEEP:
          MD5:4C91AA000D4316585893025CBB96E910
          SHA1:3D4E73839A1A8CB9DEC1E59D9D2813257D9480F0
          SHA-256:D45CC432E5743E6CEC34E9A1E0F91A9D5C315CDA409E0826B51AD9D908479EB6
          SHA-512:0731F2EEB22ADC7EF8AF215B9EB4C5A66B33BC90E4F80CF7AA482AD002CB30543547230124A0507EC79EDDD6903A042EDA5D7C8AFD77F7FC994EFC6853FABB05
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eu_ES DATE_FORMAT "%a, %Yeko %bren %da".. ::msgcat::mcset eu_ES TIME_FORMAT "%T".. ::msgcat::mcset eu_ES TIME_FORMAT_12 "%T".. ::msgcat::mcset eu_ES DATE_TIME_FORMAT "%y-%m-%d %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1711
          Entropy (8bit):4.21837106187395
          Encrypted:false
          SSDEEP:
          MD5:7AB25F4E7E457469DC61A33176B3AA72
          SHA1:EEA98283D250A99E33DD4D5D9B1B76A029716CE6
          SHA-256:86898728B275288693B200568DC927C3FF5B9050690876C4441A8339DAE06386
          SHA-512:7524437F91E91751BEB7A378D7674C49E5D84B716FE962F4C23580C46A671F3F33638FCD37A8F90C86E24DA8F54448E06AC9C3AEFFB5613E94A04E512C1AD68D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa DAYS_OF_WEEK_ABBREV [list \.. "\u06cc\u2214"\.. "\u062f\u2214"\.. "\u0633\u2214"\.. "\u0686\u2214"\.. "\u067e\u2214"\.. "\u062c\u2214"\.. "\u0634\u2214"].. ::msgcat::mcset fa DAYS_OF_WEEK_FULL [list \.. "\u06cc\u06cc\u200c\u0634\u0646\u0628\u0647"\.. "\u062f\u0648\u0634\u0646\u0628\u0647"\.. "\u0633\u0647\u200c\u0634\u0646\u0628\u0647"\.. "\u0686\u0647\u0627\u0631\u0634\u0646\u0628\u0647"\.. "\u067e\u0646\u062c\u200c\u0634\u0646\u0628\u0647"\.. "\u062c\u0645\u0639\u0647"\.. "\u0634\u0646\u0628\u0647"].. ::msgcat::mcset fa MONTHS_ABBREV [list \.. "\u0698\u0627\u0646"\.. "\u0641\u0648\u0631"\.. "\u0645\u0627\u0631"\.. "\u0622\u0648\u0631"\.. "\u0645\u0640\u0647"\.. "\u0698\u0648\u0646"\.. "\u0698\u0648\u06cc"\.. "\u0627\u0648\u062a
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2009
          Entropy (8bit):4.491667766230948
          Encrypted:false
          SSDEEP:
          MD5:C59EE7CA80AD9F612A21C8B6674A820E
          SHA1:AEFD631EFC1892063244FA622DE1A091C461E370
          SHA-256:6B56545C1AE1DE53BC2389BB7AE59F115BADE24F907E384E079491DC77D6541D
          SHA-512:42F52091480599D317FB80DF8E52A6C6F88614C6172BF4033974DD136FB30E6F47D38982C8A7BC14CF3165C3EBAE3680F94DF3A0ED079AB68165286251CD0BD7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa_IN DAYS_OF_WEEK_ABBREV [list \.. "\u06cc\u2214"\.. "\u062f\u2214"\.. "\u0633\u2214"\.. "\u0686\u2214"\.. "\u067e\u2214"\.. "\u062c\u2214"\.. "\u0634\u2214"].. ::msgcat::mcset fa_IN DAYS_OF_WEEK_FULL [list \.. "\u06cc\u06cc\u200c\u0634\u0646\u0628\u0647"\.. "\u062f\u0648\u0634\u0646\u0628\u0647"\.. "\u0633\u0647\u200c\u0634\u0646\u0628\u0647"\.. "\u0686\u0647\u0627\u0631\u0634\u0646\u0628\u0647"\.. "\u067e\u0646\u062c\u200c\u0634\u0646\u0628\u0647"\.. "\u062c\u0645\u0639\u0647"\.. "\u0634\u0646\u0628\u0647"].. ::msgcat::mcset fa_IN MONTHS_ABBREV [list \.. "\u0698\u0627\u0646"\.. "\u0641\u0648\u0631"\.. "\u0645\u0627\u0631"\.. "\u0622\u0648\u0631"\.. "\u0645\u0640\u0647"\.. "\u0698\u0648\u0646"\.. "\u0698\u0648\u06cc"\.. "\u0627\u0
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):426
          Entropy (8bit):5.12739029869254
          Encrypted:false
          SSDEEP:
          MD5:9778A7C3ABD37ECBEC0BB9715E52FAF8
          SHA1:D8063CA7779674EB1D9FE3E4B4774DB20B93038B
          SHA-256:3D9779C27E8960143D00961F6E82124120FD47B7F3CB82DB3DF21CDD9090C707
          SHA-512:B90B4A96CE5E8B9BF512B98C406603C60EA00F6740D04CD1FC30810C7155A37851AE5E28716F959137806F1A9E3152D2A0D79B8EA7E681A0737A28593657DE66
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa_IR AM "\u0635\u0628\u062d".. ::msgcat::mcset fa_IR PM "\u0639\u0635\u0631".. ::msgcat::mcset fa_IR DATE_FORMAT "%d\u2044%m\u2044%Y".. ::msgcat::mcset fa_IR TIME_FORMAT "%S:%M:%H".. ::msgcat::mcset fa_IR TIME_FORMAT_12 "%S:%M:%l %P".. ::msgcat::mcset fa_IR DATE_TIME_FORMAT "%d\u2044%m\u2044%Y %S:%M:%H %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1195
          Entropy (8bit):4.32217771842326
          Encrypted:false
          SSDEEP:
          MD5:CC06F0ABD8F985654DAD8256598EBCB7
          SHA1:71C880F9F395ACD32AF7F538033211F392F83645
          SHA-256:9929A6B7139BD7E0F29487F7888A83E4C4F5E9CE0352738CFCA94EE2DDF3BD6B
          SHA-512:E1292665270B6FBF7738CC3864B55194E7B827C6AD9492FB2E54DC1B626159B243052CE502335B9D92E2B8F58A4DD1FA0E628CB6A9D1D3A652FE2B93A3FB711A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fi DAYS_OF_WEEK_ABBREV [list \.. "su"\.. "ma"\.. "ti"\.. "ke"\.. "to"\.. "pe"\.. "la"].. ::msgcat::mcset fi DAYS_OF_WEEK_FULL [list \.. "sunnuntai"\.. "maanantai"\.. "tiistai"\.. "keskiviikko"\.. "torstai"\.. "perjantai"\.. "lauantai"].. ::msgcat::mcset fi MONTHS_ABBREV [list \.. "tammi"\.. "helmi"\.. "maalis"\.. "huhti"\.. "touko"\.. "kes\u00e4"\.. "hein\u00e4"\.. "elo"\.. "syys"\.. "loka"\.. "marras"\.. "joulu"\.. ""].. ::msgcat::mcset fi MONTHS_FULL [list \.. "tammikuu"\.. "helmikuu"\.. "maaliskuu"\.. "huhtikuu"\.. "toukokuu"\.. "kes\u00e4kuu"\.. "hein\u00e4kuu"\.. "elokuu"\.. "syyskuu"\.. "lokakuu"\.. "marraskuu"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1033
          Entropy (8bit):4.15884265510429
          Encrypted:false
          SSDEEP:
          MD5:5D224E66FD9521CA4327D4F164CD6585
          SHA1:FC8F4C1D9A69931679028DE02155D96A18F6542E
          SHA-256:2EC9B03469FA38B260915C93318F446EA5E12B9090BD441936B57552EBA1E3C9
          SHA-512:0E0F97D99F0274A8A92AA7DC992B252A0BB696D69A8835602D8F4C03A6A15780F45971F00863436949CD81AD7DF6EE6BC463CE5B9FECF5E39508BA4D4E83C693
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fo DAYS_OF_WEEK_ABBREV [list \.. "sun"\.. "m\u00e1n"\.. "t\u00fds"\.. "mik"\.. "h\u00f3s"\.. "fr\u00ed"\.. "ley"].. ::msgcat::mcset fo DAYS_OF_WEEK_FULL [list \.. "sunnudagur"\.. "m\u00e1nadagur"\.. "t\u00fdsdagur"\.. "mikudagur"\.. "h\u00f3sdagur"\.. "fr\u00edggjadagur"\.. "leygardagur"].. ::msgcat::mcset fo MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset fo MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "apr\u00edl"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.864028070948858
          Encrypted:false
          SSDEEP:
          MD5:92E2B6483B2374817548F4EAA1731820
          SHA1:071E1E9368CCB4EC864E78622B2113F460920203
          SHA-256:C3DCCF5E5904C24D4AD9AAA36160A78F5397A7452510C0C0E61DE4DE863305CB
          SHA-512:E79D4D38A22298252FA46D15C383CFB2A1E49E8196C265A58F9BA4982DFD9CE29E87C0B85BE3F39617359451831B792FCD3092A52EDF8FFD999AFE5CFE1D170D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fo_FO DATE_FORMAT "%d/%m-%Y".. ::msgcat::mcset fo_FO TIME_FORMAT "%T".. ::msgcat::mcset fo_FO TIME_FORMAT_12 "%T".. ::msgcat::mcset fo_FO DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1257
          Entropy (8bit):4.383721663740675
          Encrypted:false
          SSDEEP:
          MD5:4D63B4A7CF13A28A6F6784B5597EEF43
          SHA1:FE1B35A93CB72666D7D6BC37D9BE081B05A00CD9
          SHA-256:96B1E1E12CD13A56722EBF27D362C70B467342FA1282A40B89FB16B5105A0480
          SHA-512:5647CAE859B62C7CE1CEE6426A076361D2A29EFE6B6F311DDC0E7D006194BA68D575852FEC5FDE2AB43DF8AE440C57013D32A3951095CB856327070FD9BD1C76
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr DAYS_OF_WEEK_ABBREV [list \.. "dim."\.. "lun."\.. "mar."\.. "mer."\.. "jeu."\.. "ven."\.. "sam."].. ::msgcat::mcset fr DAYS_OF_WEEK_FULL [list \.. "dimanche"\.. "lundi"\.. "mardi"\.. "mercredi"\.. "jeudi"\.. "vendredi"\.. "samedi"].. ::msgcat::mcset fr MONTHS_ABBREV [list \.. "janv."\.. "f\u00e9vr."\.. "mars"\.. "avr."\.. "mai"\.. "juin"\.. "juil."\.. "ao\u00fbt"\.. "sept."\.. "oct."\.. "nov."\.. "d\u00e9c."\.. ""].. ::msgcat::mcset fr MONTHS_FULL [list \.. "janvier"\.. "f\u00e9vrier"\.. "mars"\.. "avril"\.. "mai"\.. "juin"\.. "juillet"\.. "ao\u00fbt"\.. "septembre"\.. "octobre"\.. "novembre"\.. "d\u00e9cembre
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.910112619660625
          Encrypted:false
          SSDEEP:
          MD5:07EEADB8C2F2425FF9A27E46A81827A2
          SHA1:AA18A651C64098C7885F1F869B9F221453F42987
          SHA-256:AAD828BCBB512FBD9902DCDD3812247A74913CC574DEB07DA95A7BBE74B1FE48
          SHA-512:1FA60B1A69B2F5FD2C009EC18695A937C4484D7C418F7E8398D95723B857698143E0584A546F9032B75894730CBBEF78453061AC13D90199FF702E148D983C28
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_BE DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset fr_BE TIME_FORMAT "%T".. ::msgcat::mcset fr_BE TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_BE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.890376345610709
          Encrypted:false
          SSDEEP:
          MD5:2F70BDDE7685E2892C5F79C632FC2F0F
          SHA1:FD1A6F6042E59D1563ABB5858C348C1D785C435E
          SHA-256:0624DF9A56723DDB89E59736C20A5837DEA2206A789EBE7EEF19AD287590CA45
          SHA-512:50FC0C91AB2C75FFC4F100C0D42DFC4B2101DB9713FD77E6FF5BF3F25A0AF4A535A4709CF4586809CEEE76C25B66ABC0DD4FD61524510C57AA0E63EA8F46E8D5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_CA DATE_FORMAT "%Y-%m-%d".. ::msgcat::mcset fr_CA TIME_FORMAT "%T".. ::msgcat::mcset fr_CA TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_CA DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):288
          Entropy (8bit):4.913241133684606
          Encrypted:false
          SSDEEP:
          MD5:83FC7EBA68C3727F7C13C8EEAF79823F
          SHA1:81C27F9B97F5F5190F7189230535EC09CD228158
          SHA-256:290CA6EB74BAEAC4E2420D0755D148849F89EE87E37860F25CBB7B8AFA3EDCBC
          SHA-512:35DA46558A246D7B3FAB02208001CE986E2E6DD88D6318AF743F4E81CA6920471D1425BB009A7476A79E7F61E1353C027B765331CD8EFA07A9E884DCB73F2195
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_CH DATE_FORMAT "%d. %m. %y".. ::msgcat::mcset fr_CH TIME_FORMAT "%T".. ::msgcat::mcset fr_CH TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_CH DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1188
          Entropy (8bit):4.314271783103334
          Encrypted:false
          SSDEEP:
          MD5:67D137E5D853DB61A4B4264871E793F7
          SHA1:4280E7F662DE792175AF8B4C93874F035F716F0F
          SHA-256:880806867ACABD9B39E3029A5ADD26B690CC5709082D43B0959EBA725EA07AB5
          SHA-512:C27B745143539D3E6D94BB754DCA35065CDE9B1AA6EE038D47F658175CFACC20236124D38BE5BBB03CAF8F613BD748C43CB8DFCC9234E915D18B5A477BAEF94E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ga DAYS_OF_WEEK_ABBREV [list \.. "Domh"\.. "Luan"\.. "M\u00e1irt"\.. "C\u00e9ad"\.. "D\u00e9ar"\.. "Aoine"\.. "Sath"].. ::msgcat::mcset ga DAYS_OF_WEEK_FULL [list \.. "D\u00e9 Domhnaigh"\.. "D\u00e9 Luain"\.. "D\u00e9 M\u00e1irt"\.. "D\u00e9 C\u00e9adaoin"\.. "D\u00e9ardaoin"\.. "D\u00e9 hAoine"\.. "D\u00e9 Sathairn"].. ::msgcat::mcset ga MONTHS_ABBREV [list \.. "Ean"\.. "Feabh"\.. "M\u00e1rta"\.. "Aib"\.. "Beal"\.. "Meith"\.. "I\u00fail"\.. "L\u00fan"\.. "MF\u00f3mh"\.. "DF\u00f3mh"\.. "Samh"\.. "Noll"\.. ""].. ::msgcat::mcset ga MONTHS_FULL [list \.. "Ean\u00e1ir"\.. "Feabhra"\.. "M\u00e1rta"\.. "Aibre\u00e1n"\.. "M\u00ed na Bealtaine"\.. "Meith"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.824539027053997
          Encrypted:false
          SSDEEP:
          MD5:C27BD7F317AAADB380F4C38AE0D2FDA6
          SHA1:79870A0E68AA0A9B301414EDC21889F83BB81E40
          SHA-256:3F9615C617D3CDBC1E127B3EFEE785B0CB5E92E17B7DABAC80DA2BEAF076362C
          SHA-512:3605B9A914284CF1D3CC90DF2F21A86C0472AEE59800942DC93D842C7AE164E1DA72813787F163DC80B72269D2C391953ABAD6A8B72CCF069BEE96D418A173E9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ga_IE DATE_FORMAT "%d.%m.%y".. ::msgcat::mcset ga_IE TIME_FORMAT "%T".. ::msgcat::mcset ga_IE TIME_FORMAT_12 "%T".. ::msgcat::mcset ga_IE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):997
          Entropy (8bit):4.120890519790248
          Encrypted:false
          SSDEEP:
          MD5:A3D098C1A47E380F7C25233A52FBDE38
          SHA1:C97E4EAA9E7A7F99950F422B93C57134B532C639
          SHA-256:34D61B49DBF9584893051FFB458D6DE9E7E2E7774AC0011F70C4DD4184EBA81C
          SHA-512:4687AB3D2FAA65FED90678EBC08C074959E93A9FEFAF3D61EEE39DB08FD200CB57C0DDB4DDBF6451FE1EF5E07EA976EDEF830769FF403CE51734129CEF24DA9F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset gl DAYS_OF_WEEK_ABBREV [list \.. "Dom"\.. "Lun"\.. "Mar"\.. "M\u00e9r"\.. "Xov"\.. "Ven"\.. "S\u00e1b"].. ::msgcat::mcset gl DAYS_OF_WEEK_FULL [list \.. "Domingo"\.. "Luns"\.. "Martes"\.. "M\u00e9rcores"\.. "Xoves"\.. "Venres"\.. "S\u00e1bado"].. ::msgcat::mcset gl MONTHS_ABBREV [list \.. "Xan"\.. "Feb"\.. "Mar"\.. "Abr"\.. "Mai"\.. "Xu\u00f1"\.. "Xul"\.. "Ago"\.. "Set"\.. "Out"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset gl MONTHS_FULL [list \.. "Xaneiro"\.. "Febreiro"\.. "Marzo"\.. "Abril"\.. "Maio"\.. "Xu\u00f1o"\.. "Xullo"\.. "Agosto"\.. "Setembro"\.. "Outubro"\.. "Novembro"\.. "Decembro"\.. ""]..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.886176304042503
          Encrypted:false
          SSDEEP:
          MD5:78B9163C5E8E5E7049CBF91D1A5889A4
          SHA1:F2F07AF3D79D61C8E0C73B13E2CA8266E10E396B
          SHA-256:B5688CA07D713227B713655877710258CD503617E8DF79293A971649E3134F05
          SHA-512:E86074B687670542CFA097C94D150292E1A73C9F231E92CD84386580A446569CC6F8F5817F46ED64A1D00F95D59F6F1F5D4B961DF3C8335938D83F3517794353
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset gl_ES DATE_FORMAT "%d %B %Y".. ::msgcat::mcset gl_ES TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset gl_ES DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1084
          Entropy (8bit):4.213672208102291
          Encrypted:false
          SSDEEP:
          MD5:518FC3964D50854081FB79189A42D3E7
          SHA1:59392F16CD56E3E6A685F78974D539FB3A972B98
          SHA-256:404795F2C88D0038F9ED0B5120A251D26EDF8B236E1B1698BC71ACD4DC75AC45
          SHA-512:E5C88CAB8741D631938CEC2E0959C0FE26685C395F5F9F4F1B5C9E146E84D23D897CD7A823AB46D4B62C590AE15EC76B87EB59308ACFB1BB6F61398890B43622
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset gv DAYS_OF_WEEK_ABBREV [list \.. "Jed"\.. "Jel"\.. "Jem"\.. "Jerc"\.. "Jerd"\.. "Jeh"\.. "Jes"].. ::msgcat::mcset gv DAYS_OF_WEEK_FULL [list \.. "Jedoonee"\.. "Jelhein"\.. "Jemayrt"\.. "Jercean"\.. "Jerdein"\.. "Jeheiney"\.. "Jesarn"].. ::msgcat::mcset gv MONTHS_ABBREV [list \.. "J-guer"\.. "T-arree"\.. "Mayrnt"\.. "Avrril"\.. "Boaldyn"\.. "M-souree"\.. "J-souree"\.. "Luanistyn"\.. "M-fouyir"\.. "J-fouyir"\.. "M.Houney"\.. "M.Nollick"\.. ""].. ::msgcat::mcset gv MONTHS_FULL [list \.. "Jerrey-geuree"\.. "Toshiaght-arree"\.. "Mayrnt"\.. "Averil"\.. "Boaldyn"\.. "Mean-souree"\.. "Jerrey-souree"\.. "Luanistyn"\.. "Mean-fouyir"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.936566750568767
          Encrypted:false
          SSDEEP:
          MD5:0B6BE614EF5F5F25A30D2D33701A9F94
          SHA1:65800FBD73D9DAE550E04E1D818A6B9D1AEF86FE
          SHA-256:86CABF3B9360C0E686CC4CBEB843E971C28BC6D35210ED378B54EB58CC41F3D5
          SHA-512:376D21B38DA49A8F7C2983F2B808FD55AC9F6383BC66DF28DB99DBF61FDC9FFF8CD20F077EC3ED873EF47F0F613BDD9AD02DFFB1CB51F9A36715C7FC798C3B70
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset gv_GB DATE_FORMAT "%d %B %Y".. ::msgcat::mcset gv_GB TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset gv_GB DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1990
          Entropy (8bit):4.298934047406144
          Encrypted:false
          SSDEEP:
          MD5:A0E60036EB17208A449AAFC3AAAE622C
          SHA1:9D7479BA85FBB00A2DF2B61F4ED2CBEA8F1EC8C3
          SHA-256:787DA79AF58872BF45AB09E3B6A920A4496B5BD8A4F3C7F010CF013EC2E8EFE0
          SHA-512:46D12C14B5736E5EA97EB728BF58999E9D7C2CF910D8F5AFA3F5D3A86329ABF41A3E2BEBD81EE4EF64BEA0DC173B77A9FE12471C1BD9D768ED552A55B3B80213
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset he DAYS_OF_WEEK_ABBREV [list \.. "\u05d0"\.. "\u05d1"\.. "\u05d2"\.. "\u05d3"\.. "\u05d4"\.. "\u05d5"\.. "\u05e9"].. ::msgcat::mcset he DAYS_OF_WEEK_FULL [list \.. "\u05d9\u05d5\u05dd \u05e8\u05d0\u05e9\u05d5\u05df"\.. "\u05d9\u05d5\u05dd \u05e9\u05e0\u05d9"\.. "\u05d9\u05d5\u05dd \u05e9\u05dc\u05d9\u05e9\u05d9"\.. "\u05d9\u05d5\u05dd \u05e8\u05d1\u05d9\u05e2\u05d9"\.. "\u05d9\u05d5\u05dd \u05d7\u05de\u05d9\u05e9\u05d9"\.. "\u05d9\u05d5\u05dd \u05e9\u05d9\u05e9\u05d9"\.. "\u05e9\u05d1\u05ea"].. ::msgcat::mcset he MONTHS_ABBREV [list \.. "\u05d9\u05e0\u05d5"\.. "\u05e4\u05d1\u05e8"\.. "\u05de\u05e8\u05e5"\.. "\u05d0\u05e4\u05e8"\.. "\u05de\u05d0\u05d9"\.. "\u05d9\u05d5\u05e0"\.. "\u05d9\u05d5\u05dc"\.. "\u05d0\u05d5\u05d2"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1777
          Entropy (8bit):4.2117128941697715
          Encrypted:false
          SSDEEP:
          MD5:4219A929E27308ADC04A9F368F063F38
          SHA1:FA728EEBA8751F4CE032ED32AECFDE124D1B68E2
          SHA-256:192F4A8E77E1627712F85533C9896EF6A040157C7BD56DF3A4A7FA56AD6746C2
          SHA-512:223B137AC1FC15908F5541067736EF3A29493549B963393EB78660036A82982E57CFC4AD09CBD33D32A5187FF9F4ACFB5F83A0C974702434B7FAD1B2539B7F76
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset hi DAYS_OF_WEEK_FULL [list \.. "\u0930\u0935\u093f\u0935\u093e\u0930"\.. "\u0938\u094b\u092e\u0935\u093e\u0930"\.. "\u092e\u0902\u0917\u0932\u0935\u093e\u0930"\.. "\u092c\u0941\u0927\u0935\u093e\u0930"\.. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\.. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\.. "\u0936\u0928\u093f\u0935\u093e\u0930"].. ::msgcat::mcset hi MONTHS_ABBREV [list \.. "\u091c\u0928\u0935\u0930\u0940"\.. "\u092b\u093c\u0930\u0935\u0930\u0940"\.. "\u092e\u093e\u0930\u094d\u091a"\.. "\u0905\u092a\u094d\u0930\u0947\u0932"\.. "\u092e\u0908"\.. "\u091c\u0942\u0928"\.. "\u091c\u0941\u0932\u093e\u0908"\.. "\u0905\u0917\u0938\u094d\u0924"\.. "\u0938\u093f\u0924\u092e\u094d\u092c\u0930"\.. "\u0905\u0915\u094d\u091f\u0942\u092c\u0930"\.. "\u0928\u0935\u
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.9286948144352865
          Encrypted:false
          SSDEEP:
          MD5:1C1E1484EA0286175FADCB90937C9F34
          SHA1:5CA1BF19021D529CB3B3A308EFFFCA7E4D073640
          SHA-256:5A3BF0DD61BFB5A2BF75E96B11E0E3528FFAB720A0BF1923853606F8CAF0E76D
          SHA-512:F9A43E1E18ADB6DC6B18BEDC3303A99F514DF6CA54F12100989F734233012D7D60216116915351CCACC12F6942795BF8F3BBD26B15A86E88101067D64BEE54F5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset hi_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset hi_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset hi_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1171
          Entropy (8bit):4.36311224714184
          Encrypted:false
          SSDEEP:
          MD5:906963A3AD09EAC781B35C190B77484E
          SHA1:E5AA49DA9C4987EAFA839115F84612426EB8615E
          SHA-256:105A9180BC5D23738183374FA0EA8DD80484BF3947E1432E515BDC2913C017D9
          SHA-512:557BD1C8306750D09215D9774069A52C7D60E03DE2DF39FF909A8F658AB0565739D127E24ACDC96F736C69A71BEFA30B8A30BB489C7B7FDEA85386C802166349
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset hr DAYS_OF_WEEK_ABBREV [list \.. "ned"\.. "pon"\.. "uto"\.. "sri"\.. "\u010det"\.. "pet"\.. "sub"].. ::msgcat::mcset hr DAYS_OF_WEEK_FULL [list \.. "nedjelja"\.. "ponedjeljak"\.. "utorak"\.. "srijeda"\.. "\u010detvrtak"\.. "petak"\.. "subota"].. ::msgcat::mcset hr MONTHS_ABBREV [list \.. "sij"\.. "vel"\.. "o\u017eu"\.. "tra"\.. "svi"\.. "lip"\.. "srp"\.. "kol"\.. "ruj"\.. "lis"\.. "stu"\.. "pro"\.. ""].. ::msgcat::mcset hr MONTHS_FULL [list \.. "sije\u010danj"\.. "velja\u010da"\.. "o\u017eujak"\.. "travanj"\.. "svibanj"\.. "lipanj"\.. "srpanj"\.. "kolovoz"\.. "rujan"\.. "listopad"\.. "studeni"\.. "prosinac"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1381
          Entropy (8bit):4.511450677731002
          Encrypted:false
          SSDEEP:
          MD5:E398158EE1CD49CB5286D9642D4A61DD
          SHA1:A93A588B0ADD198C067C4BB070DC1E5170E6E208
          SHA-256:993475532F89E1EA7214ADB265294040862305612D680CFF01DD20615B731CCC
          SHA-512:9E5791FB97110FE5F7A1F49FF2ED8801A05E49D5B9AF579474C0081073D2B40ECFFE6E4EB5B61F12B1995FDCC0A557CB572E5E116F951FD286A6254253DAEC01
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset hu DAYS_OF_WEEK_ABBREV [list \.. "V"\.. "H"\.. "K"\.. "Sze"\.. "Cs"\.. "P"\.. "Szo"].. ::msgcat::mcset hu DAYS_OF_WEEK_FULL [list \.. "vas\u00e1rnap"\.. "h\u00e9tf\u0151"\.. "kedd"\.. "szerda"\.. "cs\u00fct\u00f6rt\u00f6k"\.. "p\u00e9ntek"\.. "szombat"].. ::msgcat::mcset hu MONTHS_ABBREV [list \.. "jan."\.. "febr."\.. "m\u00e1rc."\.. "\u00e1pr."\.. "m\u00e1j."\.. "j\u00fan."\.. "j\u00fal."\.. "aug."\.. "szept."\.. "okt."\.. "nov."\.. "dec."\.. ""].. ::msgcat::mcset hu MONTHS_FULL [list \.. "janu\u00e1r"\.. "febru\u00e1r"\.. "m\u00e1rcius"\.. "\u00e1prilis"\.. "m\u00e1jus"\.. "j\u00fanius"\.. "j\u00falius"\.. "augusztus"\.. "szeptembe
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):961
          Entropy (8bit):4.02166638427728
          Encrypted:false
          SSDEEP:
          MD5:191ACF2E8A8F10A1360B283D42886382
          SHA1:EE2C00D021381EA638B6CE3F395DEA5F8491ED9B
          SHA-256:41C0C3D3B4491E9B36E719466503EFCD325175CB7824C4A5055CB113D347BE0F
          SHA-512:29BC4F7D3FAE7DE392B175FEA76138FA823B7D9D0B051A19A73F7D36D51DE34E0D0C7C129867307ABF51FC92E70853C15BD96B8484AD21EAB0A8EB83B0411E03
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset id DAYS_OF_WEEK_ABBREV [list \.. "Min"\.. "Sen"\.. "Sel"\.. "Rab"\.. "Kam"\.. "Jum"\.. "Sab"].. ::msgcat::mcset id DAYS_OF_WEEK_FULL [list \.. "Minggu"\.. "Senin"\.. "Selasa"\.. "Rabu"\.. "Kamis"\.. "Jumat"\.. "Sabtu"].. ::msgcat::mcset id MONTHS_ABBREV [list \.. "Jan"\.. "Peb"\.. "Mar"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Agu"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Des"\.. ""].. ::msgcat::mcset id MONTHS_FULL [list \.. "Januari"\.. "Pebruari"\.. "Maret"\.. "April"\.. "Mei"\.. "Juni"\.. "Juli"\.. "Agustus"\.. "September"\.. "Oktober"\.. "November"\.. "Desember"\.. ""]..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.904408530699153
          Encrypted:false
          SSDEEP:
          MD5:FEB4D50576BF3E11A0A40FD29ABE35A7
          SHA1:8CEAA187C8AA5EC101743060A877D039850964CA
          SHA-256:BA7FC0C0452D3E482DB6E19BDF512CACED639BA72B92ED8F66D80B52FEA11AC0
          SHA-512:8B5D18E3D6628F369FB387C8EF08CC80000E0CBE500972958F4AD75F1C2F0DD6058F9777BD7DD0D7C26E7ECAA65E5071E2BF51B560973E88637942116C7576FB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset id_ID DATE_FORMAT "%d %B %Y".. ::msgcat::mcset id_ID TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset id_ID DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1305
          Entropy (8bit):4.457417703528286
          Encrypted:false
          SSDEEP:
          MD5:ACF0452D5BB6D36A40061D2B0AF4D7A6
          SHA1:9DF4D88F1962A672EFBDDE524550F7A5D02D446D
          SHA-256:778BE3D6BFE2DFFB64FF1AFB9EC8351A3343B314CF93A68E8F7FD1073EE122BB
          SHA-512:34CC02D7D28B5E161ED10250C214375561FD3D00979BFB8BCF3DB72A81BD9B7C225301528B400F7C54D8B6379F772EB6477D5D03F2CF7DC4DD19D22AEEC151B5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset is DAYS_OF_WEEK_ABBREV [list \.. "sun."\.. "m\u00e1n."\.. "\u00feri."\.. "mi\u00f0."\.. "fim."\.. "f\u00f6s."\.. "lau."].. ::msgcat::mcset is DAYS_OF_WEEK_FULL [list \.. "sunnudagur"\.. "m\u00e1nudagur"\.. "\u00feri\u00f0judagur"\.. "mi\u00f0vikudagur"\.. "fimmtudagur"\.. "f\u00f6studagur"\.. "laugardagur"].. ::msgcat::mcset is MONTHS_ABBREV [list \.. "jan."\.. "feb."\.. "mar."\.. "apr."\.. "ma\u00ed"\.. "j\u00fan."\.. "j\u00fal."\.. "\u00e1g\u00fa."\.. "sep."\.. "okt."\.. "n\u00f3v."\.. "des."\.. ""].. ::msgcat::mcset is MONTHS_FULL [list \.. "jan\u00faar"\.. "febr\u00faar"\.. "mars"\.. "apr\u00edl"\.. "ma\u00ed"\.. "j\u00fan\u00ed"\.. "j\u00fal\
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1294
          Entropy (8bit):4.282101355195382
          Encrypted:false
          SSDEEP:
          MD5:3354A6FC06C298E33AA14163929E56EB
          SHA1:C3005370DAE8A266AE21F7E2B871AEA5A656A155
          SHA-256:1D72170B9F9028A237364F7CD7EA8B48BD4770E61922205CE862300103B13DE5
          SHA-512:58B64D4F5827CA2A1BF2DDFD1F7EFDDBBD46709A6A9B7277E8EB386D80043A87ADDE2B3D5A49A934E8EB8F797BD735FADA1D22AD3DD856FFE9507F71B9E45CBA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset it DAYS_OF_WEEK_ABBREV [list \.. "dom"\.. "lun"\.. "mar"\.. "mer"\.. "gio"\.. "ven"\.. "sab"].. ::msgcat::mcset it DAYS_OF_WEEK_FULL [list \.. "domenica"\.. "luned\u00ec"\.. "marted\u00ec"\.. "mercoled\u00ec"\.. "gioved\u00ec"\.. "venerd\u00ec"\.. "sabato"].. ::msgcat::mcset it MONTHS_ABBREV [list \.. "gen"\.. "feb"\.. "mar"\.. "apr"\.. "mag"\.. "giu"\.. "lug"\.. "ago"\.. "set"\.. "ott"\.. "nov"\.. "dic"\.. ""].. ::msgcat::mcset it MONTHS_FULL [list \.. "gennaio"\.. "febbraio"\.. "marzo"\.. "aprile"\.. "maggio"\.. "giugno"\.. "luglio"\.. "agosto"\.. "settembre"\.. "ottobre"\.. "novembre"\.. "dicembre"\.. "
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):250
          Entropy (8bit):4.8982877714191035
          Encrypted:false
          SSDEEP:
          MD5:E4400C16406A46C2880250522BED2EDE
          SHA1:787A04037A355FF845025B8865335EB938280BFB
          SHA-256:24B5F303F5C7AF6F63FDC23ADB4D713087AE74B6D18C117D787AF03374C5F57E
          SHA-512:3551DEEF0EAAC66042143F77F2F4DD9154764F35BD624DAB3C9F0F59F3489CA39CE34BC2A69BC5BFBB1926C6F5C39D74A806ECB1A47F6B374101071957FD417B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset it_CH DATE_FORMAT "%e. %B %Y".. ::msgcat::mcset it_CH TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset it_CH DATE_TIME_FORMAT "%e. %B %Y %H:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1689
          Entropy (8bit):4.951012555106795
          Encrypted:false
          SSDEEP:
          MD5:11FBE427747012444AEEAFD6134034A4
          SHA1:58C72C432053264EAE6335D6CC93C5FFA33C42B8
          SHA-256:2B6D15A191437F1B84FA7023E34153B61E6BF1DE1452EA921E9CCBBE5D4BEB1C
          SHA-512:4F993BDF5D50D6D9F7410C83D226FEF30BA8C989F9977A7025C36BE22CEECCD6C68CDD6AFC5C9CE3D700559C4EDC619042E14DD88EE7583B9D5AA66F0268FD23
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ja DAYS_OF_WEEK_ABBREV [list \.. "\u65e5"\.. "\u6708"\.. "\u706b"\.. "\u6c34"\.. "\u6728"\.. "\u91d1"\.. "\u571f"].. ::msgcat::mcset ja DAYS_OF_WEEK_FULL [list \.. "\u65e5\u66dc\u65e5"\.. "\u6708\u66dc\u65e5"\.. "\u706b\u66dc\u65e5"\.. "\u6c34\u66dc\u65e5"\.. "\u6728\u66dc\u65e5"\.. "\u91d1\u66dc\u65e5"\.. "\u571f\u66dc\u65e5"].. ::msgcat::mcset ja MONTHS_FULL [list \.. "1\u6708"\.. "2\u6708"\.. "3\u6708"\.. "4\u6708"\.. "5\u6708"\.. "6\u6708"\.. "7\u6708"\.. "8\u6708"\.. "9\u6708"\.. "10\u6708"\.. "11\u6708"\.. "12\u6708"].. ::msgcat::mcset ja BCE "\u7d00\u5143\u524d".. ::msgcat::mcset ja CE "\u897f\u66a6".. ::msgcat::mcset ja AM "\u5348\u524d".. ::msgcat::mcset ja PM "\u5348\u5f8c".. ::ms
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1025
          Entropy (8bit):4.097746630492712
          Encrypted:false
          SSDEEP:
          MD5:2F79804667D6F8C77BB188D59EF5F3DF
          SHA1:10950ECA798F24A7C405B3E18B559CCC0C056EC1
          SHA-256:96FF17F1CFF976E4E204D3616D1EFCED4D0F907C5E6A0F04B4536CB4AD1190C9
          SHA-512:1B8ADC3B7FF920F8F53A17BFCC7EA24A0F8E276A42E5C63F9880DAE9B74E12716DD12DB647A80A9D99294449146C643EC58A33B03681AA4FA26A5FBC508C248C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kl DAYS_OF_WEEK_ABBREV [list \.. "sab"\.. "ata"\.. "mar"\.. "pin"\.. "sis"\.. "tal"\.. "arf"].. ::msgcat::mcset kl DAYS_OF_WEEK_FULL [list \.. "sabaat"\.. "ataasinngorneq"\.. "marlunngorneq"\.. "pingasunngorneq"\.. "sisamanngorneq"\.. "tallimanngorneq"\.. "arfininngorneq"].. ::msgcat::mcset kl MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset kl MONTHS_FULL [list \.. "januari"\.. "februari"\.. "martsi"\.. "aprili"\.. "maji"\.. "juni"\.. "juli"\.. "augustusi"\.. "septemberi"\.. "oktoberi"\.. "novemberi"\.. "dece
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.882476709336307
          Encrypted:false
          SSDEEP:
          MD5:255830678C8724E65C05A7E020E68B5B
          SHA1:0AEA48AB0439C04F92B5CA9A3B5182718B7F116B
          SHA-256:3027CFE9EBD2172CEFC15C025786CAD47A6E2894BF0474AFC1B0C341E70202AA
          SHA-512:99039FFA7269DD136D1693121E261DB5586E86EC401D2B1EB8FB1D13A9A7F1E514D9FC941B838286B986C02ED281828ED67E59002D837E350A64F4832340516A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kl_GL DATE_FORMAT "%d %b %Y".. ::msgcat::mcset kl_GL TIME_FORMAT "%T".. ::msgcat::mcset kl_GL TIME_FORMAT_12 "%T".. ::msgcat::mcset kl_GL DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1621
          Entropy (8bit):4.612163420716489
          Encrypted:false
          SSDEEP:
          MD5:CCB2C2254D3FA3025183DB7E010CAD66
          SHA1:510BBB6A9162F2EF908E6561CC714848C2EA74CA
          SHA-256:EF6FB319C398EEA79B3A951319F831F3B186D556565D17D738E5F9B4B77570F2
          SHA-512:A0264565899BD1B0783ADC0388F893CCE713ADB23BDD63907CF092A74ACB4F7D3BE09DA29801E9C11A7B08CB1706E3771C598ACED351A0FCCBF4EBBD7871148D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ko DAYS_OF_WEEK_ABBREV [list \.. "\uc77c"\.. "\uc6d4"\.. "\ud654"\.. "\uc218"\.. "\ubaa9"\.. "\uae08"\.. "\ud1a0"].. ::msgcat::mcset ko DAYS_OF_WEEK_FULL [list \.. "\uc77c\uc694\uc77c"\.. "\uc6d4\uc694\uc77c"\.. "\ud654\uc694\uc77c"\.. "\uc218\uc694\uc77c"\.. "\ubaa9\uc694\uc77c"\.. "\uae08\uc694\uc77c"\.. "\ud1a0\uc694\uc77c"].. ::msgcat::mcset ko MONTHS_ABBREV [list \.. "1\uc6d4"\.. "2\uc6d4"\.. "3\uc6d4"\.. "4\uc6d4"\.. "5\uc6d4"\.. "6\uc6d4"\.. "7\uc6d4"\.. "8\uc6d4"\.. "9\uc6d4"\.. "10\uc6d4"\.. "11\uc6d4"\.. "12\uc6d4"\.. ""].. ::msgcat::mcset ko MONTHS_FULL [list \.. "1\uc6d4"\.. "2\uc6d4"\.. "3\uc6d4"\.. "4\uc6d4"\.. "5\uc6d4"\.. "6\uc6d4"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):354
          Entropy (8bit):5.058233326545794
          Encrypted:false
          SSDEEP:
          MD5:58CA45CE26AF8ECA729BA72898BB633D
          SHA1:CBBEDB7370890A1DB65080A359A9A5C164B525D5
          SHA-256:4CAC8FB43D290A63A4D3215F22228B358AB4FA174F08712DD6C5B64C5E485071
          SHA-512:48CCBD3F7B96D0998B6D1A1F8D7FE2B4B070BB5B8809FABE0A38209AEAF2E95E098292A5B9B5F0954E7729708A2173D32AAD70B6C0F336DB1E9BFA2968E6A56B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ko_KR BCE "\uae30\uc6d0\uc804".. ::msgcat::mcset ko_KR CE "\uc11c\uae30".. ::msgcat::mcset ko_KR DATE_FORMAT "%Y.%m.%d".. ::msgcat::mcset ko_KR TIME_FORMAT_12 "%P %l:%M:%S".. ::msgcat::mcset ko_KR DATE_TIME_FORMAT "%Y.%m.%d %P %l:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1997
          Entropy (8bit):4.202940482570495
          Encrypted:false
          SSDEEP:
          MD5:67FA08F588A3B44D67E42EC1025013BC
          SHA1:6895FEF0476DE0349895DB052B335AC46636B23A
          SHA-256:9D215E31A39FED45B3657144E5F73C942E59E500036CE16B1FFF201FD6358595
          SHA-512:4C2708BD9DD98320D3133EEFFD19A8018F49A36AB8348DB7C0B0287ADB4C052D3EFAD3686C8E46E0520F3CE27F361978272BA8752EB04E5A7BC07780398480DB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kok DAYS_OF_WEEK_FULL [list \.. "\u0906\u0926\u093f\u0924\u094d\u092f\u0935\u093e\u0930"\.. "\u0938\u094b\u092e\u0935\u093e\u0930"\.. "\u092e\u0902\u0917\u0933\u093e\u0930"\.. "\u092c\u0941\u0927\u0935\u093e\u0930"\.. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\.. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\.. "\u0936\u0928\u093f\u0935\u093e\u0930"].. ::msgcat::mcset kok MONTHS_ABBREV [list \.. "\u091c\u093e\u0928\u0947\u0935\u093e\u0930\u0940"\.. "\u092b\u0947\u092c\u0943\u0935\u093e\u0930\u0940"\.. "\u092e\u093e\u0930\u094d\u091a"\.. "\u090f\u092a\u094d\u0930\u093f\u0932"\.. "\u092e\u0947"\.. "\u091c\u0942\u0928"\.. "\u091c\u0941\u0932\u0948"\.. "\u0913\u0917\u0938\u094d\u091f"\.. "\u0938\u0947\u092a\u094d\u091f\u0947\u0902\u092c\u0930"\.. "\u0913\u0915\u094d\
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):260
          Entropy (8bit):4.904340548436718
          Encrypted:false
          SSDEEP:
          MD5:0AA20289A63BA3A14DCFED75EED980DE
          SHA1:2B76013593D886B0724D82849FD1840B20922902
          SHA-256:644F2B6D4BA27AF14891B781DEF60F708A9F18FC2F73566649B631A6DEA3EF09
          SHA-512:6E13E0DC8BFD2ABE0D04B0BC098C40972F088F8D3D6ACA00338B17473ABC6F69840A88EC0C965C493B4270DEC777A0EA2D762BC33044EFE7030E437604EE201B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kok_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset kok_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset kok_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1013
          Entropy (8bit):4.060027087416375
          Encrypted:false
          SSDEEP:
          MD5:CCEC7B77DCA1F6A406311FC43EE57030
          SHA1:4ED329BB09A8F7C67F8984CD790E9B6819DE6F00
          SHA-256:EAB468AC5BF1833D4F8CD658789413D4A46CAD16B63FB9B906CFF6DC9EA26251
          SHA-512:4EFF6E49CC479A1BF0CEEAE256A1FAE7D4AE7D0ACE23CD87851471EC96BB5AF580C58A142E1B6CE72BC8B6BFF946A38801E681443B7DD9527A1DEB6E7EDD7D22
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kw DAYS_OF_WEEK_ABBREV [list \.. "Sul"\.. "Lun"\.. "Mth"\.. "Mhr"\.. "Yow"\.. "Gwe"\.. "Sad"].. ::msgcat::mcset kw DAYS_OF_WEEK_FULL [list \.. "De Sul"\.. "De Lun"\.. "De Merth"\.. "De Merher"\.. "De Yow"\.. "De Gwener"\.. "De Sadorn"].. ::msgcat::mcset kw MONTHS_ABBREV [list \.. "Gen"\.. "Whe"\.. "Mer"\.. "Ebr"\.. "Me"\.. "Evn"\.. "Gor"\.. "Est"\.. "Gwn"\.. "Hed"\.. "Du"\.. "Kev"\.. ""].. ::msgcat::mcset kw MONTHS_FULL [list \.. "Mys Genver"\.. "Mys Whevrel"\.. "Mys Merth"\.. "Mys Ebrel"\.. "Mys Me"\.. "Mys Evan"\.. "Mys Gortheren"\.. "Mye Est"\.. "Mys Gwyngala"\.. "Mys Hedra"\.. "Mys Du"\.. "Mys Kevardhu"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.959913054070712
          Encrypted:false
          SSDEEP:
          MD5:18E8576F63B978F1AFEF15AC57B44FBF
          SHA1:D50EB90944FF81E3CBFF942B16C1874EB7EA2562
          SHA-256:EDAC14D929D1C6559EC46E9B460F8F44A189B78FB915F2D641104549CBD94188
          SHA-512:F3DE5EE77BB889DA1353F9C9A1811083AB28BBEE4B7D6C8782F38B1AE44CF77565371A0E18F7E2BACD7EF590BC1215CA3E41AF929A15F60B3E85F6099A4CF378
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kw_GB DATE_FORMAT "%d %B %Y".. ::msgcat::mcset kw_GB TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset kw_GB DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1307
          Entropy (8bit):4.506235846178408
          Encrypted:false
          SSDEEP:
          MD5:D4EC2E96995E0EB263F338DD16CC4F8D
          SHA1:7ED86175489B1AE3CA5C0E8D42969F951C895D6B
          SHA-256:855B652FCC8066BA45C7DC8DBFD3807D1B4759EA8D71C523567F47BF445D1DE6
          SHA-512:A55E0D759A22360FF6668CEFAFFB812BABB316C447ADDB1FD5CDBC06AE1DA2E891E09952D073164C013AD9BF4184614102E7ADA553EEEFB2BBA26208B79B277F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset lt DAYS_OF_WEEK_ABBREV [list \.. "Sk"\.. "Pr"\.. "An"\.. "Tr"\.. "Kt"\.. "Pn"\.. "\u0160t"].. ::msgcat::mcset lt DAYS_OF_WEEK_FULL [list \.. "Sekmadienis"\.. "Pirmadienis"\.. "Antradienis"\.. "Tre\u010diadienis"\.. "Ketvirtadienis"\.. "Penktadienis"\.. "\u0160e\u0161tadienis"].. ::msgcat::mcset lt MONTHS_ABBREV [list \.. "Sau"\.. "Vas"\.. "Kov"\.. "Bal"\.. "Geg"\.. "Bir"\.. "Lie"\.. "Rgp"\.. "Rgs"\.. "Spa"\.. "Lap"\.. "Grd"\.. ""].. ::msgcat::mcset lt MONTHS_FULL [list \.. "Sausio"\.. "Vasario"\.. "Kovo"\.. "Baland\u017eio"\.. "Gegu\u017e\u0117s"\.. "Bir\u017eelio"\.. "Liepos"\.. "Rugpj\u016b\u010dio"\.. "Rugs\u0117jo"\.. "Spa
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1271
          Entropy (8bit):4.460631492946299
          Encrypted:false
          SSDEEP:
          MD5:554ED2CAFD25F5F82DA54AE057F4BA98
          SHA1:E25CDF0F9C4B523B5B05408E7820F7B4F627D19E
          SHA-256:7E90D2008B220DB19C796C7107AD69D263B8AC8C7BDDFB879230699D978E9A0A
          SHA-512:612201CCD64A51EC943921196D8C74D8BCA3AB3E35B0C9E91AE7F3A6B36F4F255AA9ADB3A254EC03629B01BD221B0B3F8CC4DFBFAC1F1718775E81CAD188AA86
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset lv DAYS_OF_WEEK_ABBREV [list \.. "Sv"\.. "P"\.. "O"\.. "T"\.. "C"\.. "Pk"\.. "S"].. ::msgcat::mcset lv DAYS_OF_WEEK_FULL [list \.. "sv\u0113tdiena"\.. "pirmdiena"\.. "otrdiena"\.. "tre\u0161diena"\.. "ceturdien"\.. "piektdiena"\.. "sestdiena"].. ::msgcat::mcset lv MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Maijs"\.. "J\u016bn"\.. "J\u016bl"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset lv MONTHS_FULL [list \.. "janv\u0101ris"\.. "febru\u0101ris"\.. "marts"\.. "apr\u012blis"\.. "maijs"\.. "j\u016bnijs"\.. "j\u016blijs"\.. "augusts"\.. "septembris"\.. "oktobris"\.. "novembris"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2157
          Entropy (8bit):4.299300188052441
          Encrypted:false
          SSDEEP:
          MD5:888014F13A82511ABEF99497A753BFC3
          SHA1:7F4231BEDE191370B37E8B917B6AD8829D15CA7D
          SHA-256:4C0EB07F0FCB36DD12A3F7EDD6531616611ABF62BF7705B5A37CC59098221D5D
          SHA-512:D748127CC615584901D35B6492EC566448B6C4DA6363858B5145921E9CD09490355CF4315F0F7A8542AA12790CD3432011A643A3A8F74B0119DB0DCE19FD68A4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mk DAYS_OF_WEEK_ABBREV [list \.. "\u043d\u0435\u0434."\.. "\u043f\u043e\u043d."\.. "\u0432\u0442."\.. "\u0441\u0440\u0435."\.. "\u0447\u0435\u0442."\.. "\u043f\u0435\u0442."\.. "\u0441\u0430\u0431."].. ::msgcat::mcset mk DAYS_OF_WEEK_FULL [list \.. "\u043d\u0435\u0434\u0435\u043b\u0430"\.. "\u043f\u043e\u043d\u0435\u0434\u0435\u043b\u043d\u0438\u043a"\.. "\u0432\u0442\u043e\u0440\u043d\u0438\u043a"\.. "\u0441\u0440\u0435\u0434\u0430"\.. "\u0447\u0435\u0442\u0432\u0440\u0442\u043e\u043a"\.. "\u043f\u0435\u0442\u043e\u043a"\.. "\u0441\u0430\u0431\u043e\u0442\u0430"].. ::msgcat::mcset mk MONTHS_ABBREV [list \.. "\u0458\u0430\u043d."\.. "\u0444\u0435\u0432."\.. "\u043c\u0430\u0440."\.. "\u0430\u043f\u0440."\.. "\u043c\u0430\u0458."\.. "\u0458\u0443\u
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1846
          Entropy (8bit):4.220147808639664
          Encrypted:false
          SSDEEP:
          MD5:07F99E0A05083B10F80A4D6867163B23
          SHA1:B6036C7DA8043E3401583D03831E7A4BF755D93D
          SHA-256:AE873BF5484EACBBE179913D43451BE53378FA701B5D81594D052266B8A09AF0
          SHA-512:3A032C81B8FBFEE6EB66C1538CBD16329A1B393E4684B4E9B3FBCDD6344CE8AD34FA699F76EF953B3EB597D8E253345F54C2E92E7A43611C721038BCC2471EA2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mr DAYS_OF_WEEK_FULL [list \.. "\u0930\u0935\u093f\u0935\u093e\u0930"\.. "\u0938\u094b\u092e\u0935\u093e\u0930"\.. "\u092e\u0902\u0917\u0933\u0935\u093e\u0930"\.. "\u092e\u0902\u0917\u0933\u0935\u093e\u0930"\.. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\.. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\.. "\u0936\u0928\u093f\u0935\u093e\u0930"].. ::msgcat::mcset mr MONTHS_ABBREV [list \.. "\u091c\u093e\u0928\u0947\u0935\u093e\u0930\u0940"\.. "\u092b\u0947\u092c\u0943\u0935\u093e\u0930\u0940"\.. "\u092e\u093e\u0930\u094d\u091a"\.. "\u090f\u092a\u094d\u0930\u093f\u0932"\.. "\u092e\u0947"\.. "\u091c\u0942\u0928"\.. "\u091c\u0941\u0932\u0948"\.. "\u0913\u0917\u0938\u094d\u091f"\.. "\u0938\u0947\u092a\u094d\u091f\u0947\u0902\u092c\u0930"\.. "\u0913\u0915\u094d\u091f\u0
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.89440333975705
          Encrypted:false
          SSDEEP:
          MD5:67368E8A5715860BABD44E54A168192F
          SHA1:7790D4B4B28FE5E38AB11CD037FFB826A8EB77FD
          SHA-256:B7B1D379355A1D278E13EF557A887A662E84FB6A9B62B8E19A27927926270EF9
          SHA-512:E95C90CFFA7CC4E61026FC328A4AA0BEE6A54A0061BA0B9459F9F0F4B008DD36F81BC9B8D8B964FA051FCEAB7FECE6D107CD456B3FD01A83B4900ECC3A0BCFA4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mr_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset mr_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset mr_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):957
          Entropy (8bit):4.018924167342869
          Encrypted:false
          SSDEEP:
          MD5:7E6A943B7D82404F61BDBD95682073CD
          SHA1:B96DBB1738F293D2842FDCEDF2DEF13004F77A8D
          SHA-256:970B2F3ECC04980FCC2F9531CA6CE2BF36BC12942CB614BF70313B4CB0508985
          SHA-512:12F5A5F7A170EE79D1F4398E96FF2DE84472027C5B5003DE7E86F46713E3F0997439E2EBA03FFB7DB611F0CE0E06EB149F5BD08ED2AA0409DB8348867487FFFD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ms DAYS_OF_WEEK_ABBREV [list \.. "Aha"\.. "Isn"\.. "Sei"\.. "Rab"\.. "Kha"\.. "Jum"\.. "Sab"].. ::msgcat::mcset ms DAYS_OF_WEEK_FULL [list \.. "Ahad"\.. "Isnin"\.. "Selasa"\.. "Rahu"\.. "Khamis"\.. "Jumaat"\.. "Sabtu"].. ::msgcat::mcset ms MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mac"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Ogos"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dis"\.. ""].. ::msgcat::mcset ms MONTHS_FULL [list \.. "Januari"\.. "Februari"\.. "Mac"\.. "April"\.. "Mei"\.. "Jun"\.. "Julai"\.. "Ogos"\.. "September"\.. "Oktober"\.. "November"\.. "Disember"\.. ""]..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):265
          Entropy (8bit):4.818053174805798
          Encrypted:false
          SSDEEP:
          MD5:A02F11BE0DF920E63E7A3ACCE746E32D
          SHA1:4A8B1EF1A6F8A5FD022042D6E009A01E4B0FEBD3
          SHA-256:F5B859D8DD2A2B5F756E39B0DFEB26B95878D2F54BA3CE46C56F0F26CF2B554B
          SHA-512:5F9AF8C89F491CB4C158ED73EA4CF32E6A83CF44A94DA6FE1A962C58199BF2348530F3DEFA0C6F433BA3ADEF81AE9B3884F30CD7A841B159D52F9F21008B4F92
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ms_MY DATE_FORMAT "%A %d %b %Y".. ::msgcat::mcset ms_MY TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset ms_MY DATE_TIME_FORMAT "%A %d %b %Y %I:%M:%S %z %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):717
          Entropy (8bit):4.55153350337982
          Encrypted:false
          SSDEEP:
          MD5:D8BBEC2F8935054E6081BB5E4AE8F7E3
          SHA1:33FE6D51A284B8760BC6F442329B10374F506BDA
          SHA-256:7DBC4E82D82FDE8CDF522FA10E082289D46B0C1A4A7D7A5FA83FF116677F052B
          SHA-512:BF39C75DD6B3625897D7D44AC253AF5656CA21D0B394F78611584E2606CBC419C4A02353542D23393BEBCCF0CB4D861CDECD61AD89339F78C0260E966B495777
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mt DAYS_OF_WEEK_ABBREV [list \.. "\u0126ad"\.. "Tne"\.. "Tli"\.. "Erb"\.. "\u0126am"\.. "\u0120im"].. ::msgcat::mcset mt MONTHS_ABBREV [list \.. "Jan"\.. "Fra"\.. "Mar"\.. "Apr"\.. "Mej"\.. "\u0120un"\.. "Lul"\.. "Awi"\.. "Set"\.. "Ott"\.. "Nov"].. ::msgcat::mcset mt BCE "QK".. ::msgcat::mcset mt CE "".. ::msgcat::mcset mt DATE_FORMAT "%A, %e ta %B, %Y".. ::msgcat::mcset mt TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset mt DATE_TIME_FORMAT "%A, %e ta %B, %Y %l:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1209
          Entropy (8bit):4.313626715960843
          Encrypted:false
          SSDEEP:
          MD5:42D02C3CAF28BE4994F27CEF5A183AB7
          SHA1:DC411E8AC12C3D588AB2F3A3C95A75D8689AD402
          SHA-256:534C5DACEF12F818FAF4ED806997A559F95D591F1B6236B0C30B07A107DD13F3
          SHA-512:0BE27572106324FE2B6CDFF4513500DE7582AD1ABEF451FFC62B2050D3875A149DDDB66451E1B3F5BA9216268E9998D2A1C1E8343BBB9EF97947DA054B82818E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nb DAYS_OF_WEEK_ABBREV [list \.. "s\u00f8"\.. "ma"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f8"].. ::msgcat::mcset nb DAYS_OF_WEEK_FULL [list \.. "s\u00f8ndag"\.. "mandag"\.. "tirsdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f8rdag"].. ::msgcat::mcset nb MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset nb MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "april"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "desember"\.. ""].. ::msgcat::mcset nb BC
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1129
          Entropy (8bit):4.235969198645435
          Encrypted:false
          SSDEEP:
          MD5:B9B949794203D204628D4DBEA29587AE
          SHA1:1642D8040144469B5C359E80693E68036F87B849
          SHA-256:9E2FE3851CF13EC79A9B10A09B01CEB0A26044AE0DC90A4E00BE57745E854C79
          SHA-512:0CCCCF6D61423CEE0389C3BA1A8E94F2B092C53465D1937F5595AF91E46DD38B318D6C7EE3D88B89F32BFB952C0D55E0E67B46D7DF306ECA6690E283ADEB2CB9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nl DAYS_OF_WEEK_ABBREV [list \.. "zo"\.. "ma"\.. "di"\.. "wo"\.. "do"\.. "vr"\.. "za"].. ::msgcat::mcset nl DAYS_OF_WEEK_FULL [list \.. "zondag"\.. "maandag"\.. "dinsdag"\.. "woensdag"\.. "donderdag"\.. "vrijdag"\.. "zaterdag"].. ::msgcat::mcset nl MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mrt"\.. "apr"\.. "mei"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset nl MONTHS_FULL [list \.. "januari"\.. "februari"\.. "maart"\.. "april"\.. "mei"\.. "juni"\.. "juli"\.. "augustus"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset nl DATE_FORM
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.865165930946383
          Encrypted:false
          SSDEEP:
          MD5:3261F397ED0291368FF1881E7BA08ECE
          SHA1:7147ABB62034EB152B1FED9246A533535F07372C
          SHA-256:77A69DD60D171B321512B14794E75A66FF753410C007997B310790D86E09B057
          SHA-512:C1526F454FA594DAD056B056F76F01D8B2AB713D04EB2A3643416B8E741B248CC94E000BAEE5B0F60436B88B1216FB1DE7F7C3FA456D4A4FBDE24F97C3B739B8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nl_BE DATE_FORMAT "%d-%m-%y".. ::msgcat::mcset nl_BE TIME_FORMAT "%T".. ::msgcat::mcset nl_BE TIME_FORMAT_12 "%T".. ::msgcat::mcset nl_BE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1200
          Entropy (8bit):4.282788574144479
          Encrypted:false
          SSDEEP:
          MD5:985E97517C2BF37719A618F575DF392C
          SHA1:65BC07FC3A955300ED09B7485F90AEC18CBAD43F
          SHA-256:06FA2D6D8C59D0B8EAC2EDE5AB0DDB8B6E095D1A023B1966FCE3B65916FA14FB
          SHA-512:75BC14DBAD147A98D32D2AF0BE0BE50F115BB9C3BBE283B53977B9F264A055734B30F6B1C4EEE9686F1874D178C535111731C92D495B7D370FB17213B65C9A40
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nn DAYS_OF_WEEK_ABBREV [list \.. "su"\.. "m\u00e5"\.. "ty"\.. "on"\.. "to"\.. "fr"\.. "lau"].. ::msgcat::mcset nn DAYS_OF_WEEK_FULL [list \.. "sundag"\.. "m\u00e5ndag"\.. "tysdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "laurdag"].. ::msgcat::mcset nn MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset nn MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "april"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "desember"\.. ""].. ::msgcat::mcset nn BCE "f.Kr."
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1263
          Entropy (8bit):4.459506202908786
          Encrypted:false
          SSDEEP:
          MD5:79AB7C13AA3833A1DAEADDB1144CCE55
          SHA1:C01ABC2F16549CAEC6B081448B2CBA88A680E250
          SHA-256:61462C325DB0065352D8155307F949869862A86CAC67AD7BB6703F57A7FA2FF3
          SHA-512:79EB696164FDDD9B121558C2780E54E295FF2DC4D8E87A0DE507B4F2925612721A98FF5010199CB68CF894ACA7A07884E9E02F3DC1E078D241431E3DC884C0A1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pl DAYS_OF_WEEK_ABBREV [list \.. "N"\.. "Pn"\.. "Wt"\.. "\u015ar"\.. "Cz"\.. "Pt"\.. "So"].. ::msgcat::mcset pl DAYS_OF_WEEK_FULL [list \.. "niedziela"\.. "poniedzia\u0142ek"\.. "wtorek"\.. "\u015broda"\.. "czwartek"\.. "pi\u0105tek"\.. "sobota"].. ::msgcat::mcset pl MONTHS_ABBREV [list \.. "sty"\.. "lut"\.. "mar"\.. "kwi"\.. "maj"\.. "cze"\.. "lip"\.. "sie"\.. "wrz"\.. "pa\u017a"\.. "lis"\.. "gru"\.. ""].. ::msgcat::mcset pl MONTHS_FULL [list \.. "stycze\u0144"\.. "luty"\.. "marzec"\.. "kwiecie\u0144"\.. "maj"\.. "czerwiec"\.. "lipiec"\.. "sierpie\u0144"\.. "wrzesie\u0144"\.. "pa\u017adziernik"\.. "listopad"\..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1177
          Entropy (8bit):4.394980756969744
          Encrypted:false
          SSDEEP:
          MD5:8F53B3571DD29E12BD33349CFA32F28F
          SHA1:C125E059B8BFE5FECD482D1A1DA50B8678872BF6
          SHA-256:6F6EEEDDCF232BDCB952592A144810CED44A1CBB4BCC2C062D5F98D441505380
          SHA-512:5CD7E7097B720E5399795126A71348816CBA697FD8F14160779E982ADAB00D5994978E2F9445785B0DE62F6F14232278AD1A65BC53730CA58D676B057F0BC406
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pt DAYS_OF_WEEK_ABBREV [list \.. "Dom"\.. "Seg"\.. "Ter"\.. "Qua"\.. "Qui"\.. "Sex"\.. "S\u00e1b"].. ::msgcat::mcset pt DAYS_OF_WEEK_FULL [list \.. "Domingo"\.. "Segunda-feira"\.. "Ter\u00e7a-feira"\.. "Quarta-feira"\.. "Quinta-feira"\.. "Sexta-feira"\.. "S\u00e1bado"].. ::msgcat::mcset pt MONTHS_ABBREV [list \.. "Jan"\.. "Fev"\.. "Mar"\.. "Abr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Ago"\.. "Set"\.. "Out"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset pt MONTHS_FULL [list \.. "Janeiro"\.. "Fevereiro"\.. "Mar\u00e7o"\.. "Abril"\.. "Maio"\.. "Junho"\.. "Julho"\.. "Agosto"\.. "Setembro"\.. "Outubro"\.. "Novembro"\.. "Dezembro"
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):286
          Entropy (8bit):4.8608779725401785
          Encrypted:false
          SSDEEP:
          MD5:A2626EA95C2480FEA68906AE6A1F6993
          SHA1:A0592902337C00FC2E70B1DFB3A42453A86535BB
          SHA-256:320BE7D5B730091E6FA35F196314737261C8E154577DCF6AC8C2057D44394AD7
          SHA-512:9801A87D024565676D4F3EAF0702C213E59FC2B6719D8BE95C19C9ED53FC43487F65F5408378B401A2B4C2BD4E2E391C2D848CA87739A6082AB7766EC6B9EFE1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pt_BR DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset pt_BR TIME_FORMAT "%T".. ::msgcat::mcset pt_BR TIME_FORMAT_12 "%T".. ::msgcat::mcset pt_BR DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1224
          Entropy (8bit):4.350784108088039
          Encrypted:false
          SSDEEP:
          MD5:F6575EC17966320106FF7ABDFB3186E2
          SHA1:68C6B72D664FDA27450FCE8B5734AB627CE825D7
          SHA-256:25ED6AC7A353E23B954B98611AE3B7E56BDCF2B0CB0DB358253CFB8BEBBB831C
          SHA-512:E564543231922A17C898419545BFA65E5E31FE9F005FDD201B735CFDE08E96FB3B98349C2A7959E29CA8F7E6934B0C4C6DE6B5E67209D0DD9A7746DFEBF037B3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ro DAYS_OF_WEEK_ABBREV [list \.. "D"\.. "L"\.. "Ma"\.. "Mi"\.. "J"\.. "V"\.. "S"].. ::msgcat::mcset ro DAYS_OF_WEEK_FULL [list \.. "duminic\u0103"\.. "luni"\.. "mar\u0163i"\.. "miercuri"\.. "joi"\.. "vineri"\.. "s\u00eemb\u0103t\u0103"].. ::msgcat::mcset ro MONTHS_ABBREV [list \.. "Ian"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mai"\.. "Iun"\.. "Iul"\.. "Aug"\.. "Sep"\.. "Oct"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset ro MONTHS_FULL [list \.. "ianuarie"\.. "februarie"\.. "martie"\.. "aprilie"\.. "mai"\.. "iunie"\.. "iulie"\.. "august"\.. "septembrie"\.. "octombrie"\.. "noiembrie"\.. "decembrie"\.. ""].. ::msgcat:
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2091
          Entropy (8bit):4.2886524607041006
          Encrypted:false
          SSDEEP:
          MD5:9F1C8DD58550558977821FD500E7C0E0
          SHA1:EFDD809BC2872A5BE0E353D31BE6D7D72E4B829C
          SHA-256:BB35BB6F07BAEF72C329EC3E95D6527A2736070EE2FFE5DE227E1FF0332390F8
          SHA-512:AA3C5C40AE9D342F8287958355C3321CF60566AD3E84E3D18D782FC022A998DA275506A61010A65D2E7D7578F2919C47C63AB0BA63A38800AA48D4B88ACE54D3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ru DAYS_OF_WEEK_ABBREV [list \.. "\u0412\u0441"\.. "\u041f\u043d"\.. "\u0412\u0442"\.. "\u0421\u0440"\.. "\u0427\u0442"\.. "\u041f\u0442"\.. "\u0421\u0431"].. ::msgcat::mcset ru DAYS_OF_WEEK_FULL [list \.. "\u0432\u043e\u0441\u043a\u0440\u0435\u0441\u0435\u043d\u044c\u0435"\.. "\u043f\u043e\u043d\u0435\u0434\u0435\u043b\u044c\u043d\u0438\u043a"\.. "\u0432\u0442\u043e\u0440\u043d\u0438\u043a"\.. "\u0441\u0440\u0435\u0434\u0430"\.. "\u0447\u0435\u0442\u0432\u0435\u0440\u0433"\.. "\u043f\u044f\u0442\u043d\u0438\u0446\u0430"\.. "\u0441\u0443\u0431\u0431\u043e\u0442\u0430"].. ::msgcat::mcset ru MONTHS_ABBREV [list \.. "\u044f\u043d\u0432"\.. "\u0444\u0435\u0432"\.. "\u043c\u0430\u0440"\.. "\u0430\u043f\u0440"\.. "\u043c\u0430\u0439"\.. "\u0438\u044e\u
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):248
          Entropy (8bit):4.9420431225061
          Encrypted:false
          SSDEEP:
          MD5:DC98D88964650E302BE97FDB3B33326E
          SHA1:1DDDCC4265D7B980B867FEE674BEF2FD87D823F7
          SHA-256:13E4E79A0ED82034BADE0CFF8DEF5DE1222F6968108AD710662BDB7DAF36D7E1
          SHA-512:F3B9D528C529DD520FEDA3C20ED354E521C5B3C29F3317E15B7939CE06A3D67554D34DD6E54FE038585E46C560C604A1FD7E7F84914086B5994D52CE2C9E99CE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ru_UA DATE_FORMAT "%d.%m.%Y".. ::msgcat::mcset ru_UA TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset ru_UA DATE_TIME_FORMAT "%d.%m.%Y %k:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1212
          Entropy (8bit):4.359036493565628
          Encrypted:false
          SSDEEP:
          MD5:E297221FA73BD78577B398BC7D061D21
          SHA1:F2A6B456272F913A9E97C495CEE73AC774C90FA1
          SHA-256:E65D6E5E837DF0A2DF0DB77BCE45334BBC27EFFF9023C37119E75D49932D9D6C
          SHA-512:AB9DDAE7CB21193C7753041F0B88CF2D40987E7E604B47816219458D217F084AA4EBF36719E22AAB3FD71A271D9F956ADC353182991903D7ADE8C8F00F6B2F9B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sh DAYS_OF_WEEK_ABBREV [list \.. "Ned"\.. "Pon"\.. "Uto"\.. "Sre"\.. "\u010cet"\.. "Pet"\.. "Sub"].. ::msgcat::mcset sh DAYS_OF_WEEK_FULL [list \.. "Nedelja"\.. "Ponedeljak"\.. "Utorak"\.. "Sreda"\.. "\u010cetvrtak"\.. "Petak"\.. "Subota"].. ::msgcat::mcset sh MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Maj"\.. "Jun"\.. "Jul"\.. "Avg"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset sh MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "Mart"\.. "April"\.. "Maj"\.. "Juni"\.. "Juli"\.. "Avgust"\.. "Septembar"\.. "Oktobar"\.. "Novembar"\.. "Decembar"\.. ""].. ::msgcat::mcset sh BC
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1255
          Entropy (8bit):4.4043119723436135
          Encrypted:false
          SSDEEP:
          MD5:24DA40901D907D35195CC1B3A675EBC7
          SHA1:8AF31248F06FADA5CFB0D83A940CFF5CE70E2577
          SHA-256:976813F6C53C9BEBBF976B0F560FD7FC5E4EC4C574D7E1CD31F9A4056765CB7A
          SHA-512:A9BC6AAFE9AEEDFD1E483E54A2D27871A09ADD6807D8F90410CD2BB82A91BA9DF435652EC9A7C3AD0A080D7F153CA848BB47DAD3936BA30E4AEFF3C474C433CC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sk DAYS_OF_WEEK_ABBREV [list \.. "Ne"\.. "Po"\.. "Ut"\.. "St"\.. "\u0160t"\.. "Pa"\.. "So"].. ::msgcat::mcset sk DAYS_OF_WEEK_FULL [list \.. "Nede\u013ee"\.. "Pondelok"\.. "Utorok"\.. "Streda"\.. "\u0160tvrtok"\.. "Piatok"\.. "Sobota"].. ::msgcat::mcset sk MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "m\u00e1j"\.. "j\u00fan"\.. "j\u00fal"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sk MONTHS_FULL [list \.. "janu\u00e1r"\.. "febru\u00e1r"\.. "marec"\.. "apr\u00edl"\.. "m\u00e1j"\.. "j\u00fan"\.. "j\u00fal"\.. "august"\.. "september"\.. "okt\u00f3ber"\.. "november"\.. "decem
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1216
          Entropy (8bit):4.333705818952628
          Encrypted:false
          SSDEEP:
          MD5:CB76F54CBE0D1AAE8BA956B4C51CBD2A
          SHA1:C1F78375EDB0BD2504553E33B2024C0C63FDB1B2
          SHA-256:11A6264676DBED87E4F718075127E32E107854F35F141642454F484984084486
          SHA-512:69964348FF08DE6EEB5E3DD61057FF0DF5441105EB7BEE7FB7E9AC5E26DCC164E3C7C011CA5CD7BC5B97A7872532331C97CCBC80563F6C5A3548014BFA8BEF16
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sl DAYS_OF_WEEK_ABBREV [list \.. "Ned"\.. "Pon"\.. "Tor"\.. "Sre"\.. "\u010cet"\.. "Pet"\.. "Sob"].. ::msgcat::mcset sl DAYS_OF_WEEK_FULL [list \.. "Nedelja"\.. "Ponedeljek"\.. "Torek"\.. "Sreda"\.. "\u010cetrtek"\.. "Petek"\.. "Sobota"].. ::msgcat::mcset sl MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "avg"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sl MONTHS_FULL [list \.. "januar"\.. "februar"\.. "marec"\.. "april"\.. "maj"\.. "junij"\.. "julij"\.. "avgust"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset sl B
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1321
          Entropy (8bit):4.408176575111904
          Encrypted:false
          SSDEEP:
          MD5:E606F620F03EC0FBDBE6551601299C5F
          SHA1:0B50AB679E8D90D8E7319BCADAC426E004594D3B
          SHA-256:1F4EFD78F6B45B65F73F09B2F52FC13C2A7C4138DCB7664804878D197B6EBDF9
          SHA-512:08AF2B51EB7111E334ADDA3A03F9A8816C104E9742B523EC363FB5131A3DF73D298A8DDCD573D23C23C65CCFD2B8898DF75AE3D4F04BF80744044FB6BAB5EC0A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sq DAYS_OF_WEEK_ABBREV [list \.. "Die"\.. "H\u00ebn"\.. "Mar"\.. "M\u00ebr"\.. "Enj"\.. "Pre"\.. "Sht"].. ::msgcat::mcset sq DAYS_OF_WEEK_FULL [list \.. "e diel"\.. "e h\u00ebn\u00eb"\.. "e mart\u00eb"\.. "e m\u00ebrkur\u00eb"\.. "e enjte"\.. "e premte"\.. "e shtun\u00eb"].. ::msgcat::mcset sq MONTHS_ABBREV [list \.. "Jan"\.. "Shk"\.. "Mar"\.. "Pri"\.. "Maj"\.. "Qer"\.. "Kor"\.. "Gsh"\.. "Sht"\.. "Tet"\.. "N\u00ebn"\.. "Dhj"\.. ""].. ::msgcat::mcset sq MONTHS_FULL [list \.. "janar"\.. "shkurt"\.. "mars"\.. "prill"\.. "maj"\.. "qershor"\.. "korrik"\.. "gusht"\.. "shtator"\.. "tetor"\.. "n\u00ebntor"\.. "dhjetor"\.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2087
          Entropy (8bit):4.307749748884122
          Encrypted:false
          SSDEEP:
          MD5:BF363AB60B57F6D8FDCDBFD230A28DDF
          SHA1:6375CBA0A2197DA7E65BEE45C42F02C4F0B9142D
          SHA-256:FA00A7B22C9941F6C2B893F22B703DCB159CA2F2E4005FD6A74A632AEB786BFA
          SHA-512:91AD8085EF321A5A0E4D2ED204940CB66E8E230BBEDE59A8A07D1CEED9155FCC6B075A1FCC44AE834C1FEEEB3A59256C4310684C5AC453D4C50DFABD88469814
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sr DAYS_OF_WEEK_ABBREV [list \.. "\u041d\u0435\u0434"\.. "\u041f\u043e\u043d"\.. "\u0423\u0442\u043e"\.. "\u0421\u0440\u0435"\.. "\u0427\u0435\u0442"\.. "\u041f\u0435\u0442"\.. "\u0421\u0443\u0431"].. ::msgcat::mcset sr DAYS_OF_WEEK_FULL [list \.. "\u041d\u0435\u0434\u0435\u0459\u0430"\.. "\u041f\u043e\u043d\u0435\u0434\u0435\u0459\u0430\u043a"\.. "\u0423\u0442\u043e\u0440\u0430\u043a"\.. "\u0421\u0440\u0435\u0434\u0430"\.. "\u0427\u0435\u0442\u0432\u0440\u0442\u0430\u043a"\.. "\u041f\u0435\u0442\u0430\u043a"\.. "\u0421\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset sr MONTHS_ABBREV [list \.. "\u0408\u0430\u043d"\.. "\u0424\u0435\u0431"\.. "\u041c\u0430\u0440"\.. "\u0410\u043f\u0440"\.. "\u041c\u0430\u0458"\.. "\u0408\u0443\u043d"\.. "\
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1219
          Entropy (8bit):4.3542418837714285
          Encrypted:false
          SSDEEP:
          MD5:3B5C3FFA0829768470BDA1B46D882060
          SHA1:C96799036EC5CCDE799A6B50CD7748908935A2F3
          SHA-256:483916B51BD7E071E88F9EC36AAF3E08FEA823991532F832DE491C6C40B55A9F
          SHA-512:684FA249123878AA7F856DF0FD3B0D9F041113CFEA8EEFA47D0E1948DA23694330BF0D62BA896A3891CD559C16CAE9330BF31508F530AC003D2929D5FD9246D8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sv DAYS_OF_WEEK_ABBREV [list \.. "s\u00f6"\.. "m\u00e5"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f6"].. ::msgcat::mcset sv DAYS_OF_WEEK_FULL [list \.. "s\u00f6ndag"\.. "m\u00e5ndag"\.. "tisdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f6rdag"].. ::msgcat::mcset sv MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sv MONTHS_FULL [list \.. "januari"\.. "februari"\.. "mars"\.. "april"\.. "maj"\.. "juni"\.. "juli"\.. "augusti"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat:
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1040
          Entropy (8bit):4.108744949579904
          Encrypted:false
          SSDEEP:
          MD5:5774860C8AEECBD48F1502E616158CAB
          SHA1:DE7059713EA7913A0C79F5386833CE2BCAD2CFD7
          SHA-256:1DA068C9AA02EF14A2440758C6040D632D96044A20EC501DBB9E40D8592E0E7F
          SHA-512:91E69222DDF55E9E0E389DB77D7A0F2E082351DC3FB34A1A2C1E350E4187E8BB940F6C2EDE1B8651159C2787AA0BE4D7268F33F7A82CAED03514FCE462530408
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sw DAYS_OF_WEEK_ABBREV [list \.. "Jpi"\.. "Jtt"\.. "Jnn"\.. "Jtn"\.. "Alh"\.. "Iju"\.. "Jmo"].. ::msgcat::mcset sw DAYS_OF_WEEK_FULL [list \.. "Jumapili"\.. "Jumatatu"\.. "Jumanne"\.. "Jumatano"\.. "Alhamisi"\.. "Ijumaa"\.. "Jumamosi"].. ::msgcat::mcset sw MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Ago"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Des"\.. ""].. ::msgcat::mcset sw MONTHS_FULL [list \.. "Januari"\.. "Februari"\.. "Machi"\.. "Aprili"\.. "Mei"\.. "Juni"\.. "Julai"\.. "Agosti"\.. "Septemba"\.. "Oktoba"\.. "Novemba"\.. "Desemba"\.. ""].. ::msgcat::mcset sw BCE "
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1874
          Entropy (8bit):4.080580566597515
          Encrypted:false
          SSDEEP:
          MD5:85288236C3997302EA26D7403BBA2C15
          SHA1:05AB389CC4DCF17B37BFF6ED1ECD58D6E9850A01
          SHA-256:AEFDC4255890D5B3FFE5CEE1B457B7D711283C2287ABA644155C10956012F6C1
          SHA-512:8E389D46606176EE14B8356153095B49C9426B80139B672A620F488891F091D1A272D4FB116775900E4AB4EC84DDDEBD8D6AF81AC672F14F148F2BFC638D2B10
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ta DAYS_OF_WEEK_FULL [list \.. "\u0b9e\u0bbe\u0baf\u0bbf\u0bb1\u0bc1"\.. "\u0ba4\u0bbf\u0b99\u0bcd\u0b95\u0bb3\u0bcd"\.. "\u0b9a\u0bc6\u0bb5\u0bcd\u0bb5\u0bbe\u0baf\u0bcd"\.. "\u0baa\u0bc1\u0ba4\u0ba9\u0bcd"\.. "\u0bb5\u0bbf\u0baf\u0bbe\u0bb4\u0ba9\u0bcd"\.. "\u0bb5\u0bc6\u0bb3\u0bcd\u0bb3\u0bbf"\.. "\u0b9a\u0ba9\u0bbf"].. ::msgcat::mcset ta MONTHS_ABBREV [list \.. "\u0b9c\u0ba9\u0bb5\u0bb0\u0bbf"\.. "\u0baa\u0bc6\u0baa\u0bcd\u0bb0\u0bb5\u0bb0\u0bbf"\.. "\u0bae\u0bbe\u0bb0\u0bcd\u0b9a\u0bcd"\.. "\u0b8f\u0baa\u0bcd\u0bb0\u0bb2\u0bcd"\.. "\u0bae\u0bc7"\.. "\u0b9c\u0bc2\u0ba9\u0bcd"\.. "\u0b9c\u0bc2\u0bb2\u0bc8"\.. "\u0b86\u0b95\u0bb8\u0bcd\u0b9f\u0bcd"\.. "\u0b9a\u0bc6\u0baa\u0bcd\u0b9f\u0bae\u0bcd\u0baa\u0bb0\u0bcd"\.. "\u0b85\u0b95\u0bcd\u0b9f\u0bcb\u0baa\u0bb0\u0bcd"\.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):257
          Entropy (8bit):4.863003494480733
          Encrypted:false
          SSDEEP:
          MD5:CF078352DA0507C767F04E31D6C14296
          SHA1:0A9B1255BD85B60D3620AE61370F54748AB7A182
          SHA-256:4978A193076DE56944236F7F1DCECACFF739536DFB3DBEFC1F7FE2B97A8AEAF4
          SHA-512:6FFC85B2A8DECB373EC76B1CD1A9459A30E443319F2C8DB9BBE6E115F5EFEEBAC314D4E8BE996EA55EE46466C6F6057A73078F5FDCF1C4CBAF1A270E45BC10C0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ta_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset ta_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset ta_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2149
          Entropy (8bit):4.097884113767283
          Encrypted:false
          SSDEEP:
          MD5:61E4CB2AAD66285E9113071057F39C35
          SHA1:A2BD21090859669C4B6A875E077825381B7E2702
          SHA-256:9E96C7123100234A7018533764502985A208F2EB3314F5B6332D46016725A63F
          SHA-512:589A2D65508B07B5FDEDA883F71A4B496B25458CA1ECE7C4D4F5DAE82EB683DA82C8E21E57D63A235AB600174C9D362A746B2E27BAA6E3ADE1B7BD9D6000BE27
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset te DAYS_OF_WEEK_ABBREV [list \.. "\u0c06\u0c26\u0c3f"\.. "\u0c38\u0c4b\u0c2e"\.. "\u0c2e\u0c02\u0c17\u0c33"\.. "\u0c2c\u0c41\u0c27"\.. "\u0c17\u0c41\u0c30\u0c41"\.. "\u0c36\u0c41\u0c15\u0c4d\u0c30"\.. "\u0c36\u0c28\u0c3f"].. ::msgcat::mcset te DAYS_OF_WEEK_FULL [list \.. "\u0c06\u0c26\u0c3f\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c38\u0c4b\u0c2e\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c2e\u0c02\u0c17\u0c33\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c2c\u0c41\u0c27\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c17\u0c41\u0c30\u0c41\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c36\u0c41\u0c15\u0c4d\u0c30\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c36\u0c28\u0c3f\u0c35\u0c3e\u0c30\u0c02"].. ::msgcat::mcset te MONTHS_ABBREV [list \.. "\u0c1c\u0c28\u0c35\u0c30\u0c3f"\.. "\u0c2b\u0c3f\u0c2c\u0c4d\u0c30\u0c35\u0c30\u0c3f"\.. "\u0c2e\u0c3
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):419
          Entropy (8bit):5.058324650031252
          Encrypted:false
          SSDEEP:
          MD5:BCA040A356E7E8CC597EFB9B9065F8E1
          SHA1:ADAF7EC8C2035BC06E168D3F1BD7F39277E9273F
          SHA-256:B110FEEDDA21ECCEFA624BEF8E1476E9F221FB253880AC370967AE4D0237CA7A
          SHA-512:D408ECE8CF89FB23B45420D3CBA7655EEE713498210889A84EE25D3417360705546D97028EAAAA47764B6E9B0A3699669B98C0A53861A38E0DFCB9F3B8A47BEC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset te_IN AM "\u0c2a\u0c42\u0c30\u0c4d\u0c35\u0c3e\u0c39\u0c4d\u0c28".. ::msgcat::mcset te_IN PM "\u0c05\u0c2a\u0c30\u0c3e\u0c39\u0c4d\u0c28".. ::msgcat::mcset te_IN DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset te_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset te_IN DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2359
          Entropy (8bit):4.382796122808316
          Encrypted:false
          SSDEEP:
          MD5:7F61E1EA256D78948189EF07119663CD
          SHA1:6867E9780049FACE9984B7788B6F362B8D1AD718
          SHA-256:48BEAF693BF5B6EED15234DB0D375B97E6D576A749E9048420C153E6CAFC0259
          SHA-512:F3E24E0B41A7D722AC2FA0E429A2DCB1CCB5BAECC9912ADF6AF79C51366EA1AC9F931F0F44F068F3CEE6873516E6223CC5E7616CF523B1DFB9E528DE4D58454A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset th DAYS_OF_WEEK_ABBREV [list \.. "\u0e2d\u0e32."\.. "\u0e08."\.. "\u0e2d."\.. "\u0e1e."\.. "\u0e1e\u0e24."\.. "\u0e28."\.. "\u0e2a."].. ::msgcat::mcset th DAYS_OF_WEEK_FULL [list \.. "\u0e27\u0e31\u0e19\u0e2d\u0e32\u0e17\u0e34\u0e15\u0e22\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e08\u0e31\u0e19\u0e17\u0e23\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e2d\u0e31\u0e07\u0e04\u0e32\u0e23"\.. "\u0e27\u0e31\u0e19\u0e1e\u0e38\u0e18"\.. "\u0e27\u0e31\u0e19\u0e1e\u0e24\u0e2b\u0e31\u0e2a\u0e1a\u0e14\u0e35"\.. "\u0e27\u0e31\u0e19\u0e28\u0e38\u0e01\u0e23\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e40\u0e2a\u0e32\u0e23\u0e4c"].. ::msgcat::mcset th MONTHS_ABBREV [list \.. "\u0e21.\u0e04."\.. "\u0e01.\u0e1e."\.. "\u0e21\u0e35.\u0e04."\.. "\u0e40\u0e21.\u0e22."\.. "\u0e1e.\u0e04."\.. "\u0e21\u0
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1183
          Entropy (8bit):4.390397293529625
          Encrypted:false
          SSDEEP:
          MD5:017F0F989BD5DBBF25E7C797CE09C45C
          SHA1:162922DBD55A31A74410375A36EE7BC50E092BDD
          SHA-256:4B85B345D6C43F7257C6849A60A492397FD5FD9D82DF3A2252189D7A1ECCBB64
          SHA-512:73B6CF395753D863330687404E8A584CB08B81A8CC456DCE7BB49C4EA15EA19E45E3CC1E1367E10915DE14AC6258383289BCFEF55AD2768A50889DF390D37EF9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset tr DAYS_OF_WEEK_ABBREV [list \.. "Paz"\.. "Pzt"\.. "Sal"\.. "\u00c7ar"\.. "Per"\.. "Cum"\.. "Cmt"].. ::msgcat::mcset tr DAYS_OF_WEEK_FULL [list \.. "Pazar"\.. "Pazartesi"\.. "Sal\u0131"\.. "\u00c7ar\u015famba"\.. "Per\u015fembe"\.. "Cuma"\.. "Cumartesi"].. ::msgcat::mcset tr MONTHS_ABBREV [list \.. "Oca"\.. "\u015eub"\.. "Mar"\.. "Nis"\.. "May"\.. "Haz"\.. "Tem"\.. "A\u011fu"\.. "Eyl"\.. "Eki"\.. "Kas"\.. "Ara"\.. ""].. ::msgcat::mcset tr MONTHS_FULL [list \.. "Ocak"\.. "\u015eubat"\.. "Mart"\.. "Nisan"\.. "May\u0131s"\.. "Haziran"\.. "Temmuz"\.. "A\u011fustos"\.. "Eyl\u00fcl"\.. "Ekim"\.. "Kas\u0131m"\.. "Aral\u
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2165
          Entropy (8bit):4.289021158621493
          Encrypted:false
          SSDEEP:
          MD5:323BD95809A44B0BADC71AD36E5F095B
          SHA1:44F6016873CA955D27545C56CCD24BDB06A83C43
          SHA-256:7093DA7E39CEB6D3F51EB6CF1CCA2D7F3680ED7B8FE4A5F0CECEEF6BEB21AC77
          SHA-512:DB16E0E2D17CE47673DE781A7171944C14CC550FB8EB0920C05B979E4D067E36DF0B59B8BFA81F82D8FCE1FFDDAAD2755E68BFE5BC0DBB11E8716A4D18BA5F7E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset uk DAYS_OF_WEEK_ABBREV [list \.. "\u043d\u0434"\.. "\u043f\u043d"\.. "\u0432\u0442"\.. "\u0441\u0440"\.. "\u0447\u0442"\.. "\u043f\u0442"\.. "\u0441\u0431"].. ::msgcat::mcset uk DAYS_OF_WEEK_FULL [list \.. "\u043d\u0435\u0434\u0456\u043b\u044f"\.. "\u043f\u043e\u043d\u0435\u0434\u0456\u043b\u043e\u043a"\.. "\u0432\u0456\u0432\u0442\u043e\u0440\u043e\u043a"\.. "\u0441\u0435\u0440\u0435\u0434\u0430"\.. "\u0447\u0435\u0442\u0432\u0435\u0440"\.. "\u043f'\u044f\u0442\u043d\u0438\u0446\u044f"\.. "\u0441\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset uk MONTHS_ABBREV [list \.. "\u0441\u0456\u0447"\.. "\u043b\u044e\u0442"\.. "\u0431\u0435\u0440"\.. "\u043a\u0432\u0456\u0442"\.. "\u0442\u0440\u0430\u0432"\.. "\u0447\u0435\u0440\u0432"\.. "\u043b
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1471
          Entropy (8bit):4.44729506678271
          Encrypted:false
          SSDEEP:
          MD5:C127F54C462917D3B3EEF5F29F612138
          SHA1:B1D9A67F856D93F98524C6372B352EA0DE1B9CD3
          SHA-256:E9B7AECD456F1D2288604C982B5DED0DCF71DCA968C0B0EAFF4CA16CC3B73EC2
          SHA-512:0B0F132F10580751258D37E070338C3B39DF57FDECDB9D0AFA67E90D6766DDCB4D711876E551ED759D177F1B8F4E9E1DD8F7899F7CB57F8039F55EC4C2984E87
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset vi DAYS_OF_WEEK_ABBREV [list \.. "Th 2"\.. "Th 3"\.. "Th 4"\.. "Th 5"\.. "Th 6"\.. "Th 7"\.. "CN"].. ::msgcat::mcset vi DAYS_OF_WEEK_FULL [list \.. "Th\u01b0\u0301 hai"\.. "Th\u01b0\u0301 ba"\.. "Th\u01b0\u0301 t\u01b0"\.. "Th\u01b0\u0301 n\u0103m"\.. "Th\u01b0\u0301 s\u00e1u"\.. "Th\u01b0\u0301 ba\u0309y"\.. "Chu\u0309 nh\u00e2\u0323t"].. ::msgcat::mcset vi MONTHS_ABBREV [list \.. "Thg 1"\.. "Thg 2"\.. "Thg 3"\.. "Thg 4"\.. "Thg 5"\.. "Thg 6"\.. "Thg 7"\.. "Thg 8"\.. "Thg 9"\.. "Thg 10"\.. "Thg 11"\.. "Thg 12"\.. ""].. ::msgcat::mcset vi MONTHS_FULL [list \.. "Th\u00e1ng m\u00f4\u0323t"\.. "Th\u00e1ng hai"\.. "Th\u00e1ng ba"\.. "Th\u00e1ng t\u01b0"\.. "Th\u00e
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with very long lines (1598), with CRLF line terminators
          Category:dropped
          Size (bytes):3385
          Entropy (8bit):4.5164095151631125
          Encrypted:false
          SSDEEP:
          MD5:2F356DE14D48B1091DEAA32D20C38D96
          SHA1:4AB78D47A73290000955A7C1DFDF7106093F69FD
          SHA-256:EB247F5184A59414D3DF7E3ECA51F5998C248CFB27D2C02E62A7A30AB35197A7
          SHA-512:602410830018B455C68AE2EBDD83BA561CF59DA5898E00C80CE7EF619912E591EB38B4C8FE8D9B1F024E7105B0C4D2D326FC855F31E79C1B954429B947DFFBB1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh DAYS_OF_WEEK_ABBREV [list \.. "\u661f\u671f\u65e5"\.. "\u661f\u671f\u4e00"\.. "\u661f\u671f\u4e8c"\.. "\u661f\u671f\u4e09"\.. "\u661f\u671f\u56db"\.. "\u661f\u671f\u4e94"\.. "\u661f\u671f\u516d"].. ::msgcat::mcset zh DAYS_OF_WEEK_FULL [list \.. "\u661f\u671f\u65e5"\.. "\u661f\u671f\u4e00"\.. "\u661f\u671f\u4e8c"\.. "\u661f\u671f\u4e09"\.. "\u661f\u671f\u56db"\.. "\u661f\u671f\u4e94"\.. "\u661f\u671f\u516d"].. ::msgcat::mcset zh MONTHS_ABBREV [list \.. "\u4e00\u6708"\.. "\u4e8c\u6708"\.. "\u4e09\u6708"\.. "\u56db\u6708"\.. "\u4e94\u6708"\.. "\u516d\u6708"\.. "\u4e03\u6708"\.. "\u516b\u6708"\.. "\u4e5d\u6708"\.. "\u5341\u6708"\.. "\u5341\u4e00\u6708"\.. "\u5341\u4e8c\u6708"\.. ""].. ::msgcat::m
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):319
          Entropy (8bit):5.167825099880243
          Encrypted:false
          SSDEEP:
          MD5:9FCDC2E80E13984D434E3CC91E1ED14C
          SHA1:710D9EE2A71021F4AB609886138EED43C1380ACD
          SHA-256:4C8A855700FEFE8EE21B08030FF4159D8011AE50353F063229C42DE6292475CF
          SHA-512:D899A1F58DF1051BB2C2C4AC859C52A2D19B1593C37022A29439B37A8057ADC3941F3564E2E1D9CEB72AE123A4E12E24C3736343AA3A5EC8749AB5AEBBF65085
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_CN DATE_FORMAT "%Y-%m-%e".. ::msgcat::mcset zh_CN TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset zh_CN TIME_FORMAT_12 "%P%I\u65f6%M\u5206%S\u79d2".. ::msgcat::mcset zh_CN DATE_TIME_FORMAT "%Y-%m-%e %k:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):780
          Entropy (8bit):4.716025632367214
          Encrypted:false
          SSDEEP:
          MD5:CFDA7B6463305FA15DBBA72D725A1876
          SHA1:2BF885073FBAF4A38B7AFDA76CA391F195A5A362
          SHA-256:7E1C5BD9EC1A17BB851B0DCABD0DFA9FF9D64B89603D9D3FBEAAC609172346AE
          SHA-512:55F974C706933ECE0575A33C381D9B370B8A408C5C5514C805EC04C8B0CA5BAFAA47267DA98E1805B478A9589FFB7549D79002B2A7AF387049011D78DD7605B6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_HK DAYS_OF_WEEK_ABBREV [list \.. "\u65e5"\.. "\u4e00"\.. "\u4e8c"\.. "\u4e09"\.. "\u56db"\.. "\u4e94"\.. "\u516d"].. ::msgcat::mcset zh_HK MONTHS_ABBREV [list \.. "1\u6708"\.. "2\u6708"\.. "3\u6708"\.. "4\u6708"\.. "5\u6708"\.. "6\u6708"\.. "7\u6708"\.. "8\u6708"\.. "9\u6708"\.. "10\u6708"\.. "11\u6708"\.. "12\u6708"\.. ""].. ::msgcat::mcset zh_HK DATE_FORMAT "%Y\u5e74%m\u6708%e\u65e5".. ::msgcat::mcset zh_HK TIME_FORMAT_12 "%P%I:%M:%S".. ::msgcat::mcset zh_HK DATE_TIME_FORMAT "%Y\u5e74%m\u6708%e\u65e5 %P%I:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):347
          Entropy (8bit):5.062880051437783
          Encrypted:false
          SSDEEP:
          MD5:3218F8E6BEDD534277DE0849C423158E
          SHA1:10C006446A10406A5644C4033665E877EBF72AF7
          SHA-256:500546B3211D454659D845B4AB9AEF226125100DF40407C49530DE17CDD4363F
          SHA-512:3142893DA85BA8F83A5B6851B313B5F5FF80D2B989C1AE015665EE70373249B44EFB4FF7C621F1D8F37AC6019EF5E8D6D21C76C48998C3D9072F9C5060AA8813
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_SG AM "\u4e0a\u5348".. ::msgcat::mcset zh_SG PM "\u4e2d\u5348".. ::msgcat::mcset zh_SG DATE_FORMAT "%d %B %Y".. ::msgcat::mcset zh_SG TIME_FORMAT_12 "%P %I:%M:%S".. ::msgcat::mcset zh_SG DATE_TIME_FORMAT "%d %B %Y %P %I:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):354
          Entropy (8bit):5.124064818715749
          Encrypted:false
          SSDEEP:
          MD5:9010E34791B5DDB7F1E0AD4DA6BD4623
          SHA1:418F7374BABEF27FEC8E00D3A32F535084593AB9
          SHA-256:DBA0584B8E1925B439F06E0BF0965E97AFB7EB39E70E0E4C9B70769EBC5F996C
          SHA-512:D3AB698B725E84DAB06E472C41FF2EB55D63885D22B4598C596800BAC83A02A44CB524524F267D090952AF7E0031F47720786ACF9E354EF672CF9EEFB7DB3BD4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_TW BCE "\u6c11\u570b\u524d".. ::msgcat::mcset zh_TW CE "\u6c11\u570b".. ::msgcat::mcset zh_TW DATE_FORMAT "%Y/%m/%e".. ::msgcat::mcset zh_TW TIME_FORMAT_12 "%P %I:%M:%S".. ::msgcat::mcset zh_TW DATE_TIME_FORMAT "%Y/%m/%e %P %I:%M:%S %z"..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):33777
          Entropy (8bit):4.60013086740989
          Encrypted:false
          SSDEEP:
          MD5:4ECD97188BFED58A15FE22EC566FA6A3
          SHA1:6E4E91096298F1A0AE6CD4241F167C8B4F661EE5
          SHA-256:67A157F1873D606B53DC4D894BD8E71F6B1A0DD66177B9513BD039B348B40349
          SHA-512:1D5067BBB13DAB001168EEB41EBFA2D13BACB0F43A8067CC93923E8F4D062AA387DA23D7D98D6A2AE77D7C849A6026F2343102CBE03690C2CEA0890222339475
          Malicious:false
          Reputation:unknown
          Preview:# optparse.tcl --..#..# (private) Option parsing package..# Primarily used internally by the safe:: code...#..#.WARNING: This code will go away in a future release..#.of Tcl. It is NOT supported and you should not rely..#.on it. If your code does rely on this package you..#.may directly incorporate this code into your application.....package require Tcl 8.5-..# When this version number changes, update the pkgIndex.tcl file..# and the install directory in the Makefiles...package provide opt 0.4.8....namespace eval ::tcl {.... # Exported APIs.. namespace export OptKeyRegister OptKeyDelete OptKeyError OptKeyParse \.. OptProc OptProcArgGiven OptParse \... Lempty Lget \.. Lassign Lvarpop Lvarpop1 Lvarset Lvarincr \.. SetMax SetMin......################# Example of use / 'user documentation' ###################.... proc OptCreateTestProc {} {.....# Defines ::tcl::OptParseTest as a test proc with parsed arguments...# (can't be d
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):620
          Entropy (8bit):4.702477618616754
          Encrypted:false
          SSDEEP:
          MD5:07532085501876DCC6882567E014944C
          SHA1:6BC7A122429373EB8F039B413AD81C408A96CB80
          SHA-256:6A4ABD2C519A745325C26FB23BE7BBF95252D653A24806EB37FD4AA6A6479AFE
          SHA-512:0D604E862F3A1A19833EAD99AAF15A9F142178029AB64C71D193CEE4901A0196C1EEDDC2BCE715B7FA958AC45C194E63C77A71E4BE4F9AEDFD5B44CF2A726E76
          Malicious:false
          Reputation:unknown
          Preview:# Tcl package index file, version 1.1..# This file is generated by the "pkg_mkIndex -direct" command..# and sourced either when an application starts up or..# by a "package unknown" script. It invokes the..# "package ifneeded" command to set up package-related..# information so that packages will be loaded automatically..# in response to "package require" commands. When this..# script is sourced, the variable $dir must contain the..# full path name of this file's directory.....if {![package vsatisfies [package provide Tcl] 8.5-]} {return}..package ifneeded opt 0.4.8 [list source [file join $dir optparse.tcl]]..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):23995
          Entropy (8bit):4.884828325514459
          Encrypted:false
          SSDEEP:
          MD5:DDB0AB9842B64114138A8C83C4322027
          SHA1:ECCACDC2CCD86A452B21F3CF0933FD41125DE790
          SHA-256:F46AB61CDEBE3AA45FA7E61A48930D64A0D0E7E94D04D6BF244F48C36CAFE948
          SHA-512:C0CF718258B4D59675C088551060B34CE2BC8638958722583AC2313DC354223BFEF793B02F1316E522A14C7BA9BED219531D505DE94DC3C417FC99D216A01463
          Malicious:false
          Reputation:unknown
          Preview:# package.tcl --..#..# utility procs formerly in init.tcl which can be loaded on demand..# for package management...#..# Copyright (c) 1991-1993 The Regents of the University of userfornia...# Copyright (c) 1994-1998 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....namespace eval tcl::Pkg {}....# ::tcl::Pkg::CompareExtension --..#..# Used internally by pkg_mkIndex to compare the extension of a file to a given..# extension. On Windows, it uses a case-insensitive comparison because the..# file system can be file insensitive...#..# Arguments:..# fileName.name of a file whose extension is compared..# ext..(optional) The extension to compare against; you must..#..provide the starting dot...#..Defaults to [info sharedlibextension]..#..# Results:..# Returns 1 if the extension matches, 0 otherwise....proc tcl::Pkg::CompareExtension {fileName {ext {}}} {.. global tcl_platfor
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):844
          Entropy (8bit):4.883013702569192
          Encrypted:false
          SSDEEP:
          MD5:577787C2F4F5956BA70F83012B980AE5
          SHA1:040B2469F796F3FDFCD1E1DD2EB1C5B799EDEF62
          SHA-256:E269029C8263E3CBC1920C3604ECDCF15EDCCB208A0D68F9EB42B73954D620C0
          SHA-512:C2940F6F3D77412EFC537B8AB67352F519DFFA95739FCC17BF1817335AFD9E5BFE91ABE98CBA99E278CB4923D4E6D431ED9D72282745203C0F7D73193F550238
          Malicious:false
          Reputation:unknown
          Preview:# parray:..# Print the contents of a global array on stdout...#..# Copyright (c) 1991-1993 The Regents of the University of userfornia...# Copyright (c) 1994 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....proc parray {a {pattern *}} {.. upvar 1 $a array.. if {![array exists array]} {...return -code error "\"$a\" isn't an array".. }.. set maxl 0.. set names [lsort [array names array $pattern]].. foreach name $names {...if {[string length $name] > $maxl} {... set maxl [string length $name]...}.. }.. set maxl [expr {$maxl + [string length $a] + 2}].. foreach name $names {...set nameString [format %s(%s) $a $name]...puts stdout [format "%-*s = %s" $maxl $nameString $array($name)].. }..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):42223
          Entropy (8bit):4.822635446297551
          Encrypted:false
          SSDEEP:
          MD5:B8C1561D471CFBF4111C706411D59883
          SHA1:71483EAEEF377EE9AF90BEC44F70C7B12C5BC720
          SHA-256:C21DCE3AB31893118BBED01E559070F1D3541877FEE331BD45F5BF4300ED9654
          SHA-512:465065A938C71AF4588B3331B51A62DD57F57492EB1CB6C0F52B9FD0A2FE7A54B1E995AA56E4A41D7A99EAFF665C1E23E3B240FB3F9840AB242C21B1DBFFFF45
          Malicious:false
          Reputation:unknown
          Preview:# safe.tcl --..#..# This file provide a safe loading/sourcing mechanism for safe interpreters...# It implements a virtual path mechanism to hide the real pathnames from the..# child. It runs in a parent interpreter and sets up data structure and..# aliases that will be invoked when used from a child interpreter...#..# See the safe.n man page for details...#..# Copyright (c) 1996-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES.....#..# The implementation is based on namespaces. These naming conventions are..# followed:..# Private procs starts with uppercase...# Public procs are exported and starts with lowercase..#....# Needed utilities package..package require opt 0.4.8....# Create the safe namespace..namespace eval ::safe {.. # Exported API:.. namespace export interpCreate interpInit interpConfigure interpDelete \...interpAddToAccessPath interpFindInAccessPath setL
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5617
          Entropy (8bit):4.747404679682368
          Encrypted:false
          SSDEEP:
          MD5:C62FB22F4C9A3EFF286C18421397AAF4
          SHA1:4A49B8768CFF68F2EFFAF21264343B7C632A51B2
          SHA-256:DDF7E42DEF37888AD0A564AA4F8CA95F4EEC942CEBEBFCA851D35515104D5C89
          SHA-512:558D401CB6AF8CE3641AF55CAEBC9C5005AB843EE84F60C6D55AFBBC7F7129DA9C58C2F55C887C3159107546FA6BC13FFC4CCA63EA8841D7160B8AA99161A185
          Malicious:false
          Reputation:unknown
          Preview:# Tcl autoload index file, version 2.0..# -*- tcl -*-..# This file is generated by the "auto_mkindex" command..# and sourced to set up indexing information for one or..# more commands. Typically each line is a command that..# sets an element in the auto_index array, where the..# element name is the name of a command and the value is..# a script that loads the command.....set auto_index(auto_reset) [list source [file join $dir auto.tcl]]..set auto_index(tcl_findLibrary) [list source [file join $dir auto.tcl]]..set auto_index(auto_mkindex) [list source [file join $dir auto.tcl]]..set auto_index(auto_mkindex_old) [list source [file join $dir auto.tcl]]..set auto_index(::auto_mkindex_parser::init) [list source [file join $dir auto.tcl]]..set auto_index(::auto_mkindex_parser::cleanup) [list source [file join $dir auto.tcl]]..set auto_index(::auto_mkindex_parser::mkindex) [list source [file join $dir auto.tcl]]..set auto_index(::auto_mkindex_parser::hook) [list source [file join $dir auto.t
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):12204
          Entropy (8bit):4.763796758810551
          Encrypted:false
          SSDEEP:
          MD5:215262A286E7F0A14F22DB1AA7875F05
          SHA1:66B942BA6D3120EF8D5840FCDEB06242A47491FF
          SHA-256:4B7ED9FD2363D6876092DB3F720CBDDF97E72B86B519403539BA96E1C815ED8F
          SHA-512:6ECD745D7DA9D826240C0AB59023C703C94B158AE48C1410FAA961A8EDB512976A4F15AE8DEF099B58719ADF0D2A9C37E6F29F54D39C1AB7EE81FA333A60F39B
          Malicious:false
          Reputation:unknown
          Preview:# -*- tcl -*-..#..# Searching for Tcl Modules. Defines a procedure, declares it as the primary..# command for finding packages, however also uses the former 'package unknown'..# command as a fallback...#..# Locates all possible packages in a directory via a less restricted glob. The..# targeted directory is derived from the name of the requested package, i.e...# the TM scan will look only at directories which can contain the requested..# package. It will register all packages it found in the directory so that..# future requests have a higher chance of being fulfilled by the ifneeded..# database without having to come to us again...#..# We do not remember where we have been and simply rescan targeted directories..# when invoked again. The reasoning is this:..#..# - The only way we get back to the same directory is if someone is trying to..# [package require] something that wasn't there on the first scan...#..# Either..# 1) It is there now: If we rescan, you get it; if not you don
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):147
          Entropy (8bit):4.995501022397479
          Encrypted:false
          SSDEEP:
          MD5:FF8B5540631A6EE93507338C4E7AA49D
          SHA1:817B261A1B6B92AA498EC286349964EA10FB5A84
          SHA-256:7213997BB9CF9D384A7002B8C8EFEF25C01ABA6083D9835A16D583D5DCEE40A0
          SHA-512:8D78AC4868ED0013EDA536C0E82E0E91398772AA18C637AEFE22F24B142FCDA55A4CB853B2282951E907C9E2F62BD3F831A5CF995F52898F5225D16889943A9C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Abidjan) {.. {-9223372036854775808 -968 0 LMT}.. {-1830383032 0 0 GMT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.832432925672155
          Encrypted:false
          SSDEEP:
          MD5:52FDFD3DB98475FBBB620D0D5565C5CC
          SHA1:C7750452859663605272553DBEE0B6C134E1517C
          SHA-256:6040827AFED8CEF45F252FBD7E3E862C0B5E9D06C1C98C58BAD61DFE67BD57CC
          SHA-512:2FF9D96D81279148A86BE208FEEACCBCB8B4224D093D6C092ECD1C4EA2186589CCF947027D3A726600C703611B4CFEE029AA14ED3E8593C477B427C4F342CF27
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Accra) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.817170256300069
          Encrypted:false
          SSDEEP:
          MD5:30CDD4D37E9DD60FBF6D754C9343F364
          SHA1:56F896C21068764B7B8F884F374B18913CA3D9CA
          SHA-256:E11FD8AD8572B684333810CFDC23B92E1ACF619875866985E288D92F8277D07F
          SHA-512:78FC8043CCE25713404E70996229E5EA8238BF5C0F59029064EDA5494E2D4F54398931F3D855E30C82B2C53B789C40EE4CBF09D0F98C2BA6734595D4AA75017A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Addis_Ababa) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1080
          Entropy (8bit):4.187497782275587
          Encrypted:false
          SSDEEP:
          MD5:E8D3DF11CE0E7575485573FA07D955D5
          SHA1:3B2C00C85B6C0BFAA1C676C970D6DF1B4BDC3D4A
          SHA-256:E6874647561CE1C5FD1F650C9B167F77AC5B24FD2026046399A9043CF998E5C4
          SHA-512:E2968BE847622CF243C0E498436FD21BDC2E1DF0FD8D694F2C70569D17CE896CDE4968BB8ABDEF9F687439E4EA2D955AE87D6C15E81F881EE1413416A90765D4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Algiers) {.. {-9223372036854775808 732 0 LMT}.. {-2486592732 561 0 PMT}.. {-1855958961 0 0 WET}.. {-1689814800 3600 1 WEST}.. {-1680397200 0 0 WET}.. {-1665363600 3600 1 WEST}.. {-1648342800 0 0 WET}.. {-1635123600 3600 1 WEST}.. {-1616893200 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585443600 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1531443600 0 0 WET}.. {-956365200 3600 1 WEST}.. {-950486400 0 0 WET}.. {-942012000 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796262400 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766630800 3600 0 CET}.. {-733280400 0 0 WET}.. {-439430400 3600 0 CET}.. {-212029200 0 0 WET}.. {41468400 3600 1 WEST}.. {54774000 0 0 WET}.. {231724800 3600 1 WEST}.. {246240000 3600 0 CET}.. {259545600 7200 1 CEST}.. {275274000 3600 0 CET}.. {309740400 0 0 WET}.. {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.801054282631739
          Encrypted:false
          SSDEEP:
          MD5:A543BDEB3771017421FB75231F0004F2
          SHA1:D682C58C27562FF3ABAB8EDE8EB6EA754DA7C02E
          SHA-256:064EB7F9A1FA05A317C6BDCA6B102BC1560D980758F9E4DDB010C9E7DC068ECB
          SHA-512:44848D60EDC79AF784A819714C0D9F62DCCB6329B47F25D74AB8C174BF9EC3F783C66FEB27F588A93FABA9BECAF076F453D6D797CE4F28461F7AE69440EA54C7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Asmara) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.806258322241929
          Encrypted:false
          SSDEEP:
          MD5:1B5E386E7A2F10D9385DE4C5683EBB85
          SHA1:FECBA599C37493D2E0AEE8E21BAB40BF8E8DC82A
          SHA-256:76939852A98EA7BF156D0AC18B434CC610DAF5232322C0FBB066CD52C5B72AF7
          SHA-512:B36FABFCDB2187A3A4A211C8E033D96C91E3C4D47907D284E10786555562C82231566033EAB4753EF1E48DF1233CFC8C6C0FB3CA50748BE0B2554A972A88FBA0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Asmera) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.883634030944169
          Encrypted:false
          SSDEEP:
          MD5:6B9BB5B37C41AA727E31BF03483DC1CA
          SHA1:CB3BBA37B063EA4A54CD15C6E30C14D8CA30D3C0
          SHA-256:F6D1BA22115A6565B6D6ABEB578F001DDB41E673C422C8EA70D0DF77B24115F6
          SHA-512:23DB3E298FDEB165FD85D99E03C00835B584984B814AF7F54A9CDD4A9F93E16B0C58342D319129F46CF8EC36F93DE5EA51B492CA4CABDAB75D84709BC6C26119
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Bamako) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.882974805254803
          Encrypted:false
          SSDEEP:
          MD5:92FF9E5835C0C80F358BFE69120660A0
          SHA1:724758B43BD79DD8A29B02BE6910D492924F8280
          SHA-256:5047A507D22B68C9349EB6A48C41C80DB4C69F98F99C6574059DEA87178E36C0
          SHA-512:6FCB709DB4AC19191FECE1E8BAC55E77F265B5AF89F7A3565F06BFAF0BEE12E3EAF2F52CA09C68D75C358C25A31867505CE8AD75D7386DCD15F4BE1CE61272CD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Bangui) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.888193386512119
          Encrypted:false
          SSDEEP:
          MD5:46E5703CF284E44E15E5872DF075FCBC
          SHA1:EA4BFA6D568DFA877F72302ADA21ECC2840D9FD5
          SHA-256:77E610A02CCECE3045B09D07A9BE6100F5AA9C3C2AEB543535C9AE941194F4E4
          SHA-512:1454467FE63E97DFA4DE66E359F68B2D80C92CDE59FC15A4BE513629FFD154D2281EADF3FC78F7AFDDF5A5896195F3A69E66697A659BBB1A0EAFD3E1DA6565EC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Banjul) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):176
          Entropy (8bit):4.847843768169462
          Encrypted:false
          SSDEEP:
          MD5:7E710C939B9CC0C1AC1ECF4239B543C5
          SHA1:429CC87086FB22727815ED05AC6472333FF06013
          SHA-256:2A870E534DE67713C27F2F3B9BF26FA7498C240CF633988CE76DBDAC5B69214D
          SHA-512:70D9365C31C43A95211FC20E9290B24D356FFEFA935B8829CE32831026A196DECDD12226097F6DA3B4B919E137AA0181714680CDBB72B00C130A87E3A4735004
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Bissau) {.. {-9223372036854775808 -3740 0 LMT}.. {-1830380400 -3600 0 -01}.. {157770000 0 0 GMT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.904342145830274
          Encrypted:false
          SSDEEP:
          MD5:7AD3749D7047855CB9B9EC9696015402
          SHA1:F792359AD9EEC2ABD98DAFA6661C1E57BAB89EBE
          SHA-256:8F700409B8EEE33ACE5F050414971FFEE0270949842E58E9299BB5CD6CCF34DE
          SHA-512:681C1B318746C587DEBA6E109D1D5A99D1F3E28FE46C24F36B69D533D884FDDC6EA35BB31A475575D683B73BF129FED761523EC9285F2FF1E4CACA2C54C046C5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Blantyre) $TZData(:Africa/Maputo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.901235831565769
          Encrypted:false
          SSDEEP:
          MD5:7028268EE88250AC40547A3FDBBFC67C
          SHA1:5006D499CD1D1CB93EB3DA0EC279F76B7123DAA6
          SHA-256:596DB2D64CDD6250642CB65514D5BCB52F3E3EA83F50D8915D9D4FDEA008F440
          SHA-512:D623C69FE8A6050E77FB819C2F5FAEE35D5034182B1D30A409C17208155501656133E774E402875537335F8201E4734A0B5D327712CBF623AC330F1014D9025B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Brazzaville) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.947752840781864
          Encrypted:false
          SSDEEP:
          MD5:0EBC2D8F0BD1A32C21070F9397EAC9E2
          SHA1:95AAA97427265635784E8AC624CA863DB9F1475D
          SHA-256:9A15867255B43A954CA60DA11660F157553AAB6A15C50ACD49D182276E0CF4CC
          SHA-512:4CD2E14F84C58E955742637A51D99DB9493972671A2B5D801EBD9D901D4903654E374C59BF010C70071D33FA17788358F78004201A787CCA2AD714D670393488
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Bujumbura) $TZData(:Africa/Maputo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3852
          Entropy (8bit):3.7766651198444507
          Encrypted:false
          SSDEEP:
          MD5:9DCDB3DD41DA13D81EB8E1CAF56964DA
          SHA1:F95EE7B1EF464F2640EC4AE29F3C18B5BF2B2905
          SHA-256:8698B0A53D858AEA7C495EDF759EF0E6C63F7E07A256599393DEC7B7A7413734
          SHA-512:BA5898ABEE541BC72C9DEDD77BABB18024C7AEA0274FA3F809748FCBFF770BFAD902BF70680DDE989F7D3592E5398C100D0E0EA388D4200911ED7DE089535D6D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Cairo) {.. {-9223372036854775808 7509 0 LMT}.. {-2185409109 7200 0 EET}.. {-929844000 10800 1 EEST}.. {-923108400 7200 0 EET}.. {-906170400 10800 1 EEST}.. {-892868400 7200 0 EET}.. {-875844000 10800 1 EEST}.. {-857790000 7200 0 EET}.. {-844308000 10800 1 EEST}.. {-825822000 7200 0 EET}.. {-812685600 10800 1 EEST}.. {-794199600 7200 0 EET}.. {-779853600 10800 1 EEST}.. {-762663600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-165801600 7200 0 EET}.. {-147402000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5532
          Entropy (8bit):3.535398586134154
          Encrypted:false
          SSDEEP:
          MD5:18183122D242E0B69A80BC02BC0328DF
          SHA1:C9976ABC0663EB29A2FEAAFDF6746C05A264B67C
          SHA-256:8776EEDFDFEE09C4C833593127CEFAC9C33E2487AB9BF4BF8C73E5E11B4E5613
          SHA-512:9611A6EF9C5B55FAB752C1EC7E464B8AF60AE32383CE9BA72F35168ABB68A45DB0654A9099CBDC123F5F6E2B6DB7C8FBF56A8DDB813824187AD1090971F12219
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Casablanca) {.. {-9223372036854775808 -1820 0 LMT}.. {-1773012580 0 0 +00}.. {-956361600 3600 1 +00}.. {-950490000 0 0 +00}.. {-942019200 3600 1 +00}.. {-761187600 0 0 +00}.. {-617241600 3600 1 +00}.. {-605149200 0 0 +00}.. {-81432000 3600 1 +00}.. {-71110800 0 0 +00}.. {141264000 3600 1 +00}.. {147222000 0 0 +00}.. {199756800 3600 1 +00}.. {207702000 0 0 +00}.. {231292800 3600 1 +00}.. {244249200 0 0 +00}.. {265507200 3600 1 +00}.. {271033200 0 0 +00}.. {448243200 3600 0 +01}.. {504918000 0 0 +00}.. {1212278400 3600 1 +00}.. {1220223600 0 0 +00}.. {1243814400 3600 1 +00}.. {1250809200 0 0 +00}.. {1272758400 3600 1 +00}.. {1281222000 0 0 +00}.. {1301788800 3600 1 +00}.. {1312066800 0 0 +00}.. {1335664800 3600 1 +00}.. {1342749600 0 0 +00}.. {1345428000 3600 1 +00}.. {1348970400 0 0 +00}.. {1367114400 3600 1 +00}.. {13731
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7536
          Entropy (8bit):3.8315604186920704
          Encrypted:false
          SSDEEP:
          MD5:30155093248C4F7E45EF7C0132D2B2AB
          SHA1:FAD100CC49F0CB0910BDE39B43295A47512E1BE6
          SHA-256:8827F7311EDE69A9679BDF2B7418DBF350A2FC8F973E8B1E1E4390D4D5C6D2E8
          SHA-512:469A24AF0C2A4A40CB2488C3E21BB9BBDE057F876EACA08A31FC6F22845063D917A0A4AE96680401E45792DE534EE3A305F137A93C4DF879B4602510D881270E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Ceuta) {.. {-9223372036854775808 -1276 0 LMT}.. {-2177452800 0 0 WET}.. {-1630112400 3600 1 WEST}.. {-1616810400 0 0 WET}.. {-1451692800 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1427673600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364774400 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333324800 0 0 WET}.. {-1316390400 3600 1 WEST}.. {-1301270400 0 0 WET}.. {-1293840000 0 0 WET}.. {-94694400 0 0 WET}.. {-81432000 3600 1 WEST}.. {-71110800 0 0 WET}.. {141264000 3600 1 WEST}.. {147222000 0 0 WET}.. {199756800 3600 1 WEST}.. {207702000 0 0 WET}.. {231292800 3600 1 WEST}.. {244249200 0 0 WET}.. {265507200 3600 1 WEST}.. {271033200 0 0 WET}.. {448243200 3600 0 CET}.. {504918000 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.88110192592456
          Encrypted:false
          SSDEEP:
          MD5:8CDD2EEB7E0EC816F3EC051350FEBF13
          SHA1:37F3A149B4A01DFA2EAB42A28C810BE66AAB7C52
          SHA-256:3176C99FC45337CBCE0CD516DE4B02B8BAA47D00E84F698122A2ADD57797984E
          SHA-512:5A90B6DB45EDAD7734D596FB81FD1959A433F57E71D2212E1DCBD6A12F3FD1FE747FA363C4C787A4D3023F542553C1E2C9CF4F61E28F1BB13042E4AFE3D0FF31
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Conakry) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.856992353568779
          Encrypted:false
          SSDEEP:
          MD5:946D3B52F915445DBB8EE8BF67F4EFAB
          SHA1:18345968B95E886CA72634D49F2B38F9B29BA629
          SHA-256:D50F9732757B284BAC75526F2CFA585DF7F6974160827AFB0FF66124C7CFD361
          SHA-512:00B531D1352CF35045EE25C777C7FEA17294E9861E68CE2DE0D9884C05EBDEA84D5F4F0E8B5605721295E25C259979446B7DB76525A633C7D2FA35B38962CF43
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Dakar) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):191
          Entropy (8bit):4.8447607449193075
          Encrypted:false
          SSDEEP:
          MD5:7A819572758BC60F4085DF28F1DD1C01
          SHA1:0A5BA34EBFBA5A8E8B896713BA527781FC90FF01
          SHA-256:AB69948637416219A3D458777990FA4568BEBC89388884BBF129C0E1370A560B
          SHA-512:C03E785D1E85292056BB0BDD8DF8326C5DFEB6070AB1C071E1032D14EA69C9DEBC57B2CC7852E35D31652187126CCF0009A6A5C32F9DBB75D56C705535DF05CC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Dar_es_Salaam) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.829357904445218
          Encrypted:false
          SSDEEP:
          MD5:7981499F9430DC1636C9F834273E0B91
          SHA1:1D63F8578420D56E4A5D9D0881FBEC015421E416
          SHA-256:E7F7560CCD65D53C446ADAE7128A74D37E17DD0B907A2F2FD85322FB8707B497
          SHA-512:3C3F7D78E9A0DE6E2950E1C305EA2DBC986754AE9FB10AC410685F30C39EC235F6F221393099C012E62EE5A7B4F1BED67C96B7B81E90BBA064BA9FE685FE4050
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Djibouti) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.850101792457859
          Encrypted:false
          SSDEEP:
          MD5:44881E75AC32FA95FF6143066EF01B90
          SHA1:A221619B4CDE8BE6A181E1F3869EAB665F2E98B8
          SHA-256:FCF2DAD148F4D2951320EA99730C56D5EB43D505F37416BE4BAD265CE2902706
          SHA-512:4FA67A5F84758366189F0FC4A7FA6C820BA083E1C56EA95D25D21A367F25F76261B7EB5631DFFEB20E095CFD64E770338773F76BD50D4CF6AE29AD3EDFCEC408
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Douala) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5235
          Entropy (8bit):3.541189246992611
          Encrypted:false
          SSDEEP:
          MD5:956F5B51FA8BA2E954A0E59AAC8F3276
          SHA1:AE35A8502E57EA6EE173E3B42509E4CAC73DA091
          SHA-256:5FB102A95B3C004AAB8371840B1A04AC352F48FF9E9EAFDEAAF21960B0F3CAA6
          SHA-512:19E7F2574E2B62DF68CC24737F6B94864B3D64B2472BC7D78E6AB5142A1DC1AB3B3700AB802129CB16AED4A4FED29E2B8A5593EE327ADF496255FE2FEF6A7023
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/El_Aaiun) {.. {-9223372036854775808 -3168 0 LMT}.. {-1136070432 -3600 0 -01}.. {198291600 0 0 +00}.. {199756800 3600 1 +00}.. {207702000 0 0 +00}.. {231292800 3600 1 +00}.. {244249200 0 0 +00}.. {265507200 3600 1 +00}.. {271033200 0 0 +00}.. {1212278400 3600 1 +00}.. {1220223600 0 0 +00}.. {1243814400 3600 1 +00}.. {1250809200 0 0 +00}.. {1272758400 3600 1 +00}.. {1281222000 0 0 +00}.. {1301788800 3600 1 +00}.. {1312066800 0 0 +00}.. {1335664800 3600 1 +00}.. {1342749600 0 0 +00}.. {1345428000 3600 1 +00}.. {1348970400 0 0 +00}.. {1367114400 3600 1 +00}.. {1373162400 0 0 +00}.. {1376100000 3600 1 +00}.. {1382839200 0 0 +00}.. {1396144800 3600 1 +00}.. {1403920800 0 0 +00}.. {1406944800 3600 1 +00}.. {1414288800 0 0 +00}.. {1427594400 3600 1 +00}.. {1434247200 0 0 +00}.. {1437271200 3600 1 +00}.. {1445738400 0 0 +00}.. {1
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.866631090752554
          Encrypted:false
          SSDEEP:
          MD5:6C115220CF951FC2EE3C299F86935B6D
          SHA1:A1CAB8C710BF20553AF45343118C1726CFE922B7
          SHA-256:BC53A4D489F48F14C594C4B0E52079B34E043A5751BBC7DF254A560352243575
          SHA-512:E87A4FD145B645DF034182CAD7F9D2BE5B2D9F3A17B6A9B6C84A0B3E846D92EC4C69DF2E85129B7A1AFBC0CCAAC8E3B1D47EB09F0900A82B908E9F6BF63B9736
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Freetown) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.899477454245453
          Encrypted:false
          SSDEEP:
          MD5:07222D8ED83CDC456B4D5D84C4BDE320
          SHA1:2C657F461FA3F48D56C791AFE4AB7D2EAF45AF60
          SHA-256:653AF88955C4418D973E2F8681A99552EB7BE95BCA64C736072F488462F7B373
          SHA-512:3016D0636F401BD88BCD460F6A61782E7E8A2C32CE4ECB904C711DF414038A5818F0CA3D7FC671C5ABCE70647FC674A2EF9081C5289EBFD184B44885902E007A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Gaborone) $TZData(:Africa/Maputo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):181
          Entropy (8bit):4.884642061266759
          Encrypted:false
          SSDEEP:
          MD5:8666DABE8D196ACD94A9691C592FAF4E
          SHA1:9F7EE009DCEAACA79C6EAA6FC73015D595467919
          SHA-256:06B82C524585192E0E8FC69DCC1CF86183A8C5EF404645DC413FCF3F8C16B0AB
          SHA-512:AAA32FD1B01BFECDD0D1C9C1DF1163374DAFE094C75720EA4095C34F7EAE7DCB594D1A7F6A2A90FB43FF01020F7AEB48E92496E0EE2D039AF23076CD369DD2A7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Harare) $TZData(:Africa/Maputo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):309
          Entropy (8bit):4.695542624694403
          Encrypted:false
          SSDEEP:
          MD5:F0E153FC9B978E30742ABC025CA45E02
          SHA1:73D96F3188190DAC2453E6F18A1C683CECB9CDE3
          SHA-256:5EEF6475E1312051037FCAE3354E32DC0910BE7A5116B71F8CCBE1CCA08D3F1C
          SHA-512:E66F4B5FF18BAAD53AFB1ED36A0827115C793075A61F794F26F32BC9F6799DF816A1F817BEB0C0BC938F89E6F5BFBE1AB4F504F1AF518764103FB287746552C7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Johannesburg) {.. {-9223372036854775808 6720 0 LMT}.. {-2458173120 5400 0 SAST}.. {-2109288600 7200 0 SAST}.. {-860976000 10800 1 SAST}.. {-845254800 7200 0 SAST}.. {-829526400 10800 1 SAST}.. {-813805200 7200 0 SAST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1127
          Entropy (8bit):4.027824722230131
          Encrypted:false
          SSDEEP:
          MD5:32EC0589260D9D4BCC85FE91E6F04D00
          SHA1:BAA269852C4AC6B89EA7941E7A75A007E0CF9EDF
          SHA-256:F2646E15488ABF2E960759CEFE5705416E71DA71BB8407B26196244FD1A3394F
          SHA-512:4F485453BE1D186ADBE0908852475C63C57BA498091C222EFFB9A5FEA2DB7F55E1BB2DBDBF6AC0F24CC67D47549FA3F5257655B5449B1BCF1FB5CDB27B03D501
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Juba) {.. {-9223372036854775808 7588 0 LMT}.. {-1230775588 7200 0 CAT}.. {10360800 10800 1 CAST}.. {24786000 7200 0 CAT}.. {41810400 10800 1 CAST}.. {56322000 7200 0 CAT}.. {73432800 10800 1 CAST}.. {87944400 7200 0 CAT}.. {104882400 10800 1 CAST}.. {119480400 7200 0 CAT}.. {136332000 10800 1 CAST}.. {151016400 7200 0 CAT}.. {167781600 10800 1 CAST}.. {182552400 7200 0 CAT}.. {199231200 10800 1 CAST}.. {214174800 7200 0 CAT}.. {230680800 10800 1 CAST}.. {245710800 7200 0 CAT}.. {262735200 10800 1 CAST}.. {277246800 7200 0 CAT}.. {294184800 10800 1 CAST}.. {308782800 7200 0 CAT}.. {325634400 10800 1 CAST}.. {340405200 7200 0 CAT}.. {357084000 10800 1 CAST}.. {371941200 7200 0 CAT}.. {388533600 10800 1 CAST}.. {403477200 7200 0 CAT}.. {419983200 10800 1 CAST}.. {435013200 7200 0 CAT}.. {452037600 10800 1 CAST}.. {466635600 7200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.837466713772859
          Encrypted:false
          SSDEEP:
          MD5:E929ED1BC316C71AABE7E625BD562FB1
          SHA1:C20C172518C02D93327F4BBBC5D410BFFEF5039D
          SHA-256:8EA3028CE2B025F0C457DC8F7601279CA5AF565A88B9FE80208F9F1030F2B0D0
          SHA-512:B2FBCF06EACCF18DE97AF1D6BC57D9638E0A36DBF17044FF97F6B9E5089CF9E13E1304F304495324C0ACC1128A7D2D494E7C1FDB95DB0855FCE54F7028096C50
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Kampala) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1131
          Entropy (8bit):4.0421745451318385
          Encrypted:false
          SSDEEP:
          MD5:2BD3850DDBE2F05BF6F24F3AEFF7516C
          SHA1:22B0DBB54E071F30D51A8654CF103F99537F74CD
          SHA-256:F475DB8A857A46B310B12C21D6A9BC6CA9FF2960DA429A9D57FA375F9439E13B
          SHA-512:1CF82FC07348C697F26625673DA7E3D734358B3FBE69D8E2132CAC0D9F00C7E8CDC353676CD9BAC4CBB9E26CF6638CEAE41DF559E7445D9C453409D7115FFC6C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Khartoum) {.. {-9223372036854775808 7808 0 LMT}.. {-1230775808 7200 0 CAT}.. {10360800 10800 1 CAST}.. {24786000 7200 0 CAT}.. {41810400 10800 1 CAST}.. {56322000 7200 0 CAT}.. {73432800 10800 1 CAST}.. {87944400 7200 0 CAT}.. {104882400 10800 1 CAST}.. {119480400 7200 0 CAT}.. {136332000 10800 1 CAST}.. {151016400 7200 0 CAT}.. {167781600 10800 1 CAST}.. {182552400 7200 0 CAT}.. {199231200 10800 1 CAST}.. {214174800 7200 0 CAT}.. {230680800 10800 1 CAST}.. {245710800 7200 0 CAT}.. {262735200 10800 1 CAST}.. {277246800 7200 0 CAT}.. {294184800 10800 1 CAST}.. {308782800 7200 0 CAT}.. {325634400 10800 1 CAST}.. {340405200 7200 0 CAT}.. {357084000 10800 1 CAST}.. {371941200 7200 0 CAT}.. {388533600 10800 1 CAST}.. {403477200 7200 0 CAT}.. {419983200 10800 1 CAST}.. {435013200 7200 0 CAT}.. {452037600 10800 1 CAST}.. {466635600 7
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):181
          Entropy (8bit):4.910322325134086
          Encrypted:false
          SSDEEP:
          MD5:3017253E1C6ACCA8D470A014E4BB321D
          SHA1:671B7AC04580B56E2C34F88D123E8296947DDD7E
          SHA-256:73FEB807006897B4B485CB82394867444E890265EFE960EC66D6C0E325DA9372
          SHA-512:2498C380D761A16C183D78BC1BB18B1D2A1BFCB9C703D86A3FC04CCCE43D88C8D4BC3C47CC31639B78A5FE9C8A7445E9DBB52062E2F3B737DA1E7D0FF70F140A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Kigali) $TZData(:Africa/Maputo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.866127364448228
          Encrypted:false
          SSDEEP:
          MD5:41209A335A99803239A854575190C5ED
          SHA1:E6EA627C25513B9DDE053F9A24D509AA317C30A1
          SHA-256:611375C4901AD6C4844C2BB7D02FB17F34996F49E642546A6784D6F0B28530CC
          SHA-512:DF2C0B131F35F54DF5EBF7F8459F98DBABEB6F081247BA95B5D7B41146E2A2EF9BC6B1D909DE57A1223D9C258AB197D9668ED2E111A365C86BABDAA7DF551FB6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Kinshasa) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):235
          Entropy (8bit):4.7936510664790815
          Encrypted:false
          SSDEEP:
          MD5:EC08046589E85D999A597252FF5368B7
          SHA1:126E3DE158E1E7AF4737D0AB5B51C0F92F416DC7
          SHA-256:DCC9F52F539A67DFD7ABAFDE072ACDAE2B67754C559C8A5FE61979F5A286A066
          SHA-512:84B9AB18BC343C8B8934F5FDD2E2EB413925B04D6F5394AA8337B7B55E6487FB071A83A69BD4D0FA40F7F31EBC57B9908729674542CEA3083D700FCD02D77633
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Lagos) {.. {-9223372036854775808 815 0 LMT}.. {-2035584815 0 0 GMT}.. {-1940889600 815 0 LMT}.. {-1767226415 1800 0 +0030}.. {-1588465800 3600 0 WAT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.865878143076229
          Encrypted:false
          SSDEEP:
          MD5:35D8A58EE21E603C6FC4FB896AE6B3D0
          SHA1:F1D0A939D761F3F0954F045814CF5339A5597036
          SHA-256:AB3E797548C7663CF9ABA7FE163635FF7CAB9E6CB61FA1644C0F7B4B5CCE8B99
          SHA-512:97717961987F6B6832C24A7833150CDFE7E82BBEB32DFDB84D2500442AAD9263F8BD4E879591E913D56E9A1991C389EF730211853647A889F358AE3FA37C0185
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Libreville) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.862780607964543
          Encrypted:false
          SSDEEP:
          MD5:EA21ABBF8B11953916A1C509B8A1B427
          SHA1:35ADC230C57B001BE8A99A3D2E34B609A60A1162
          SHA-256:EACA9124F17E5B11F27D11FA6141D19EB3AC23E155E155B73467BDAA3BC99AA7
          SHA-512:A7972D4F1C5FB988CA04B39E2CDD580F51383BA9D7A66C478275C11A07B8D7A6EFF53A3E1929B0D89F10BCC39D22F285DB2601ED60DB4647C65465643F70C137
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Lome) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.856982839546061
          Encrypted:false
          SSDEEP:
          MD5:40CD47F6DCF51EBEFEF42489F1716257
          SHA1:DF245192A1899A72DE01A57F6969AC060E841734
          SHA-256:4C2FD1E44DFAAF0C0DD2EB56B84B538F1E2D84B301AB2CFB8EE7759783501444
          SHA-512:D39BEB0EEF344B1A44F7D6A806A1D5B956D7D402648EE0C67C4BA46493236840AF975D89A91B2D33B8AA7D6DC9A051E66718DCDBC1C83B0E964215C2E32ED923
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Luanda) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.940313336280723
          Encrypted:false
          SSDEEP:
          MD5:71A5DE1276902DB1542840318F9B1AF3
          SHA1:AC3825BF343482E0E4D9D6FAA6FCA4D1A125433B
          SHA-256:24384EEC359FD24D181AAEF3C017E3C345490A8D352B29D19B1B143A29A811C2
          SHA-512:2984EB42A79B8B32BB93DFE71F1C4C0CABFDC9B0A199971347BB3473463FA07FDB5D20227D288BF8653B1BDE347E1297459BBB4C3C34AF7A5434FBF945683577
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Lubumbashi) $TZData(:Africa/Maputo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):181
          Entropy (8bit):4.905174746463853
          Encrypted:false
          SSDEEP:
          MD5:1D7FDB388535CC59742CA0F1AEE27FBD
          SHA1:A99FF2CAC47FD333429C22B271E190D979EEC024
          SHA-256:B00801A7279741434D9C2D7EC7322DD93B85EA4F5C9976AB3A43F0AB142E1553
          SHA-512:0174D3C6F9116C36C62AD1EB58203EE7DFE8C37F618B8449D5E45AD6290CF8334F28798877D7A563A12EE533026244D6A49BCCF29B5D7FCB5BCC91481D0DDDE2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Lusaka) $TZData(:Africa/Maputo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.857096806490649
          Encrypted:false
          SSDEEP:
          MD5:1CA9B3E7BCD5BC1CC881453D16B09389
          SHA1:1B1964B314E72847D71A42C147CF2BF331B44461
          SHA-256:35D56EFFE9E7E60F17B32BD30486E566B635F0AE7A8948D77395B8E6332E26F1
          SHA-512:9E08D57B7824F5B076D159D9A5106E51450DF24729C36F485B9B68E8F47E8DFC50F9BEC3F11E0AE6579A8E372A5C0F0DA18A2E797CF2115519D1B4E5B64413DD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Malabo) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):149
          Entropy (8bit):4.952872531197478
          Encrypted:false
          SSDEEP:
          MD5:CD429B6891CBF603A93F9A9733E2391B
          SHA1:C6833B83B6D1694AC632018A27915E6F97F708AE
          SHA-256:FE6B6A4BE1B61F7F909A3F6137530DFE6D1754499A4D9B0D1CE4952FFF0AE62D
          SHA-512:6E57B70B71515998AD617954F9DDAE19968B20946542201153DAB47FBE63790D42F41AE29148ECBCE6D12812879BCF0A4EC881507B62CDB2675AB20267220BF9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Maputo) {.. {-9223372036854775808 7820 0 LMT}.. {-2109291020 7200 0 CAT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):199
          Entropy (8bit):4.964472328419063
          Encrypted:false
          SSDEEP:
          MD5:88C8FF2B480648EDADBD0FB93F754275
          SHA1:BED7A784C378909914CEB0D303DFE6D05FD576B7
          SHA-256:1D80FD86CB733D57D88ECD404E702F750B233ED0CCBFBFFFEED1AAD3B7F1CB04
          SHA-512:CB7F831CF099E85B948AE57FCE9D91C7EAAD39753AF82C56EC15B65830EB4115A71BBC83A71A2AC947CAB24DEDDB557E02FAA5A3264546AE6E60607DF6BD2FA3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Johannesburg)]} {.. LoadTimeZoneFile Africa/Johannesburg..}..set TZData(:Africa/Maseru) $TZData(:Africa/Johannesburg)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):200
          Entropy (8bit):4.957246428185456
          Encrypted:false
          SSDEEP:
          MD5:CA7255B86425BA706D214924856B6818
          SHA1:E9BE6CF871BB1786E842953D41392299952EC9AC
          SHA-256:547197C09C1987350AE5720A4EEC7E8D8F4B9F4A0559726E225E13C707F7C564
          SHA-512:23F9AD0F926A0945A17BBC3DCFF9A3D7EE68EC9423EA78985F5FFC60CC61641B57871F9AA703B5FB9BE842DCD4693D0641F9EDED702240873F58D24CD4D60C32
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Johannesburg)]} {.. LoadTimeZoneFile Africa/Johannesburg..}..set TZData(:Africa/Mbabane) $TZData(:Africa/Johannesburg)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):187
          Entropy (8bit):4.877126792757121
          Encrypted:false
          SSDEEP:
          MD5:5C2E2B5189E0E816D5BD7AFC8B49A35E
          SHA1:4E43A1ED51399528636D6442B1DDFFD820911407
          SHA-256:25E221BE49DEC5547A74AEB91B0041859C59BC866987272A447AB2343D1CC30C
          SHA-512:B74735CFAB692756BAADFB1A51A8CC0C986F981D8E7E7A8182370A9017E67439875F0115820A349AFB3BE2FA581A721440968EF817471DD2C5E1286E53B2FE99
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Mogadishu) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):208
          Entropy (8bit):4.8660011420394955
          Encrypted:false
          SSDEEP:
          MD5:1B3C94B5098E454981C73C1F2AF80164
          SHA1:1EBA9E2DBEA70BB1AE5EB13739518AB5A62D2130
          SHA-256:2BF0D90610211651127402680519B29AB50B15D344263D0C1A22EDEBE5E01E27
          SHA-512:DA4A0BCE7C6750BD7D3BA76B6301B9390723BE0C001C39BE453D80BD87020C2253A75629F68F83C19410D2A75FAF5223A435299CD4AA53DE545EC7C5B5AA54B7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Monrovia) {.. {-9223372036854775808 -2588 0 LMT}.. {-2776979812 -2588 0 MMT}.. {-1604359012 -2670 0 MMT}.. {63593070 0 0 GMT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):277
          Entropy (8bit):4.655052651600954
          Encrypted:false
          SSDEEP:
          MD5:B640661FB37BB74FAB172DBDF1B433E1
          SHA1:0236A5B53443A4A18B8B9D6AA7732620BE9A6553
          SHA-256:BD8E9765174431C0D403249D3E881C949C83966E9F8162552DA88AE53132467B
          SHA-512:53DCC6DF7C3E0B00A6D98A8DCC4988C8CFD6B53CC89E6F8D32DA41CB532A62D9C6A823675C5039F5639CE0D423F6D571F46F5B93FFC7EFFB4EDFFBF89D46AA12
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Nairobi) {.. {-9223372036854775808 8836 0 LMT}.. {-1946168836 9000 0 +0230}.. {-1309746600 10800 0 EAT}.. {-1261969200 9000 0 +0230}.. {-1041388200 9900 0 +0245}.. {-865305900 10800 0 EAT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):208
          Entropy (8bit):4.856754881865487
          Encrypted:false
          SSDEEP:
          MD5:EDB548348E590C8CFE04ED172D96B86C
          SHA1:AD3B631FB03819772164402E202AFA781687F597
          SHA-256:9ADA5F5AFB25E823E1F0E8AD2489AAA1C09F01356634A9403670D7AB21CA2E2C
          SHA-512:17E396A9BE497077B774AD1108CC8760ED35FC92F65FFF070F9ACD3C4FB67A335C1C57DF1CCB1570DE14B708EFCA0063990A969E30759C9A47731DA45ED25EFE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Ndjamena) {.. {-9223372036854775808 3612 0 LMT}.. {-1830387612 3600 0 WAT}.. {308703600 7200 1 WAST}.. {321314400 3600 0 WAT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.871519187180041
          Encrypted:false
          SSDEEP:
          MD5:0134039CD1666E983A9B6E43ABD6AF59
          SHA1:A2A99345390F4D17C892CEADE58C604257686764
          SHA-256:B517120AD8DB3F21EAB4E44A78001EE856EB4EA35852C54CCA96D38887DEBCFA
          SHA-512:E5911ADD3D776D87ACFC986C4D2564E3ED9AB12C67F23391ED35FF2A31AD8314B873E31DB8DA4D5E0DAEA12BE34110A8F0C27C9C6126977BAD51C6AD5CDFA39B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Niamey) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.909962899502589
          Encrypted:false
          SSDEEP:
          MD5:550E482599C2F4280F2C258019BB2547
          SHA1:A39045BEF313094CEDC100A7D695AE51BC9E498D
          SHA-256:64CAF2BF9D45095DF97F419714D5617CF6300ACDB544B621DCE1D594AA9B910C
          SHA-512:4FD29C5B4C0D2BDE69C437E9BF4F08A11E1DAAA689B69F28F3551F550BDCCDD055E4C1A241EDB2FA48B18825AFF792F4860F55983E106EA8224F1D87ED4F7546
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Nouakchott) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.920023025906233
          Encrypted:false
          SSDEEP:
          MD5:6CFC4E938E50C9B591F8CC42A14FA82A
          SHA1:FCE14A5CA62C9005C76D27B849A238E76C834F8A
          SHA-256:03B9C1FE350B5E9F6F333F9519FA394DCC562308D9388A903AF3D3FECEBDC762
          SHA-512:98F22F1D23A9930276A2D306A1473E64DC43547A16CFD01226E4F030A26A3CC4FDED77F790583CC5C078FC6DFCCE81C16A50879AE46A0D3A6F1FA98373F413C7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Ouagadougou) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.893842293207225
          Encrypted:false
          SSDEEP:
          MD5:6D979FCD225D5431C7391AE568C6409F
          SHA1:6C9DCD222061CC00FD386773C6BB2861F3429A60
          SHA-256:8FB8692DB9281AE2B087D704168BFD47D3D0901781FEF65BFD62FCB213BA6B50
          SHA-512:32AFA6AF6BFC3D42CA636DD2B96906048EF1ADFBB135BB7E7B77C444FED99FDABB84FBBADF56EC63828FFA7B3371191FF1311822B1C75241EBD9CF602467088E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Porto-Novo) $TZData(:Africa/Lagos)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):234
          Entropy (8bit):4.818597723513168
          Encrypted:false
          SSDEEP:
          MD5:28A5967C797F4B38FB63F823D6F07168
          SHA1:17872E91683B884191D2E4C777FB79DCE6D73EE7
          SHA-256:BA1D60DF2B41320F92A123A714E17E576C89383526B96E0541A464C3FBA415B7
          SHA-512:B335E3D3268631F3A71F4BAD59740F3A5222344E8223C201B8FE885BAA7F1A550FA7778E498D6DC2111F41053856F50B21413AECCE84B80833EC8176F2A1009C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Sao_Tome) {.. {-9223372036854775808 1616 0 LMT}.. {-2713912016 -2205 0 LMT}.. {-1830384000 0 0 GMT}.. {1514768400 3600 0 WAT}.. {1546304400 0 0 GMT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.905303708777235
          Encrypted:false
          SSDEEP:
          MD5:F2D7F7BC4EA3629EC7F0E45300A0CFD2
          SHA1:E7594D378C5DCFEB1E87E13AC79A026260D2E630
          SHA-256:9D8009ACAB019B32B1E87AB10E0AC3765ABCABE8066318DA8CA4905D41562F72
          SHA-512:795E58172907020C85CF0B10BBA35842D5F92872CCB3382DFDC787BAA504C79927FA23BC3104AD63541A95C44CA80977E8247846DE918A0B00963B970F4823D2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Timbuktu) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):954
          Entropy (8bit):4.151253074491018
          Encrypted:false
          SSDEEP:
          MD5:2DF9B050D82B06EB89DA908C31C1F1C9
          SHA1:CB294E12560A98D5CEA3BA7004B5519B6C22BAAC
          SHA-256:B447B6B1C351E77F22A2D77C0437F2BBB7D8BDFDFDC3D6285E0D260519CC7110
          SHA-512:BBE281D551E9F8DA7B6BB08D809177615410A11E4B1184ABD220EA8B1F355B2BBC090C6BAAF7E07FD61286891388ECD4026D4433C4E4B6A8D201F8D95E174532
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Tripoli) {.. {-9223372036854775808 3164 0 LMT}.. {-1577926364 3600 0 CET}.. {-574902000 7200 1 CEST}.. {-512175600 7200 1 CEST}.. {-449888400 7200 1 CEST}.. {-347158800 7200 0 EET}.. {378684000 3600 0 CET}.. {386463600 7200 1 CEST}.. {402271200 3600 0 CET}.. {417999600 7200 1 CEST}.. {433807200 3600 0 CET}.. {449622000 7200 1 CEST}.. {465429600 3600 0 CET}.. {481590000 7200 1 CEST}.. {496965600 3600 0 CET}.. {512953200 7200 1 CEST}.. {528674400 3600 0 CET}.. {544230000 7200 1 CEST}.. {560037600 3600 0 CET}.. {575852400 7200 1 CEST}.. {591660000 3600 0 CET}.. {607388400 7200 1 CEST}.. {623196000 3600 0 CET}.. {641775600 7200 0 EET}.. {844034400 3600 0 CET}.. {860108400 7200 1 CEST}.. {875919600 7200 0 EET}.. {1352505600 3600 0 CET}.. {1364515200 7200 1 CEST}.. {1382662800 7200 0 EET}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1111
          Entropy (8bit):4.150944563639585
          Encrypted:false
          SSDEEP:
          MD5:0C99335A41D33AA8BC1EDA0CB4CDCBF5
          SHA1:5CABC28D318FA5B8307429EA571FFF91EB8E1252
          SHA-256:0760D1028E733888E43E7F1E057217DC2B52786029FCEC67B27EB69CC6A54938
          SHA-512:C8FE685ACA46FD4836F3AABC15833F294E5EBED123A487D04E74A8C5668BDFAFB96D2326760452A6E5A1B9CC25AC6C3918D8C10A7F8EF737456640E3000BBA2F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Tunis) {.. {-9223372036854775808 2444 0 LMT}.. {-2797202444 561 0 PMT}.. {-1855958961 3600 0 CET}.. {-969242400 7200 1 CEST}.. {-950493600 3600 0 CET}.. {-941940000 7200 1 CEST}.. {-891136800 3600 0 CET}.. {-877827600 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-842918400 3600 0 CET}.. {-842223600 7200 1 CEST}.. {-828230400 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796269600 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766634400 3600 0 CET}.. {231202800 7200 1 CEST}.. {243903600 3600 0 CET}.. {262825200 7200 1 CEST}.. {276044400 3600 0 CET}.. {581122800 7200 1 CEST}.. {591145200 3600 0 CET}.. {606870000 7200 1 CEST}.. {622594800 3600 0 CET}.. {641516400 7200 1 CEST}.. {654649200 3600 0 CET}.. {1114902000 7200 1 CEST}.. {1128038400 3600 0 CET}.. {1143334800 7200 1 CEST}.. {1162083600 3600 0 CET}.. {11747
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1649
          Entropy (8bit):3.9974091170263066
          Encrypted:false
          SSDEEP:
          MD5:4846FB13467BA93EB134D88228D7F534
          SHA1:477FC6144B7DF365606A2E44EF1430F8DF6FB841
          SHA-256:DFC3D1FC182B315B31D999BC103C264BD205EB16F971C8636003A71170D7BD7C
          SHA-512:A719F5083F66CE44FE047880A10B2ED04B66E01C7F0F7DADAE2FFB95172308F091D669BCFED5A236D2A0F80A4A1D78DA7A778DDE3FAECB40170ECDA705573769
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Windhoek) {.. {-9223372036854775808 4104 0 LMT}.. {-2458170504 5400 0 +0130}.. {-2109288600 7200 0 SAST}.. {-860976000 10800 1 SAST}.. {-845254800 7200 0 SAST}.. {637970400 7200 0 CAT}.. {764200800 3600 1 WAT}.. {778640400 7200 0 CAT}.. {796780800 3600 1 WAT}.. {810090000 7200 0 CAT}.. {828835200 3600 1 WAT}.. {841539600 7200 0 CAT}.. {860284800 3600 1 WAT}.. {873594000 7200 0 CAT}.. {891734400 3600 1 WAT}.. {905043600 7200 0 CAT}.. {923184000 3600 1 WAT}.. {936493200 7200 0 CAT}.. {954633600 3600 1 WAT}.. {967942800 7200 0 CAT}.. {986083200 3600 1 WAT}.. {999392400 7200 0 CAT}.. {1018137600 3600 1 WAT}.. {1030842000 7200 0 CAT}.. {1049587200 3600 1 WAT}.. {1062896400 7200 0 CAT}.. {1081036800 3600 1 WAT}.. {1094346000 7200 0 CAT}.. {1112486400 3600 1 WAT}.. {1125795600 7200 0 CAT}.. {1143936000 3600 1 WAT}.. {1157245200 7200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8447
          Entropy (8bit):3.867931581740766
          Encrypted:false
          SSDEEP:
          MD5:DF52E726B33FA47EB115C1233614E101
          SHA1:26B0E49022FCB929F0160617F9C9D2DBEDC63610
          SHA-256:77231D179260C08690A70AEE6C2517E4B621ED4794D9AEEA7040539F4FF05111
          SHA-512:48AAF25419E07B06E076B0E19F9A0C27EB257556E62FD8F7B2AA963A817823DD89D33AB6AFEAAC2EF2230361D76776355E19CC2BBBB4D19536F823A347AC8AA4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Adak) {.. {-9223372036854775808 44002 0 LMT}.. {-3225223727 -42398 0 LMT}.. {-2188944802 -39600 0 NST}.. {-883573200 -39600 0 NST}.. {-880196400 -36000 1 NWT}.. {-769395600 -36000 1 NPT}.. {-765374400 -39600 0 NST}.. {-757342800 -39600 0 NST}.. {-86878800 -39600 0 BST}.. {-31496400 -39600 0 BST}.. {-21466800 -36000 1 BDT}.. {-5745600 -39600 0 BST}.. {9982800 -36000 1 BDT}.. {25704000 -39600 0 BST}.. {41432400 -36000 1 BDT}.. {57758400 -39600 0 BST}.. {73486800 -36000 1 BDT}.. {89208000 -39600 0 BST}.. {104936400 -36000 1 BDT}.. {120657600 -39600 0 BST}.. {126709200 -36000 1 BDT}.. {152107200 -39600 0 BST}.. {162392400 -36000 1 BDT}.. {183556800 -39600 0 BST}.. {199285200 -36000 1 BDT}.. {215611200 -39600 0 BST}.. {230734800 -36000 1 BDT}.. {247060800 -39600 0 BST}.. {262789200 -36000 1 BDT}.. {278510400 -39600 0 BST}.. {29423880
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8685
          Entropy (8bit):3.9620252256806845
          Encrypted:false
          SSDEEP:
          MD5:BFEACEA04AAA8A69A9AC71CF86BCC15C
          SHA1:1693971B8AAA35021BA34799FB1B9FADC3DA0294
          SHA-256:DE7FBE2B3ED780C6B82099E1E249DD41F4452A3ADB9DD807B1D0EC06049C2302
          SHA-512:E94112A2A5F268C03C58CE3BB4C243B2B9B0FC17CB27FDD58BCD2CCC8D377B805C87A552AE7DE1C5698C5F2C4B0FCAB00A3420B1DAD944C1A2F7A47CE7118F78
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Anchorage) {.. {-9223372036854775808 50424 0 LMT}.. {-3225223727 -35976 0 LMT}.. {-2188951224 -36000 0 AST}.. {-883576800 -36000 0 AST}.. {-880200000 -32400 1 AWT}.. {-769395600 -32400 1 APT}.. {-765378000 -36000 0 AST}.. {-86882400 -36000 0 AHST}.. {-31500000 -36000 0 AHST}.. {-21470400 -32400 1 AHDT}.. {-5749200 -36000 0 AHST}.. {9979200 -32400 1 AHDT}.. {25700400 -36000 0 AHST}.. {41428800 -32400 1 AHDT}.. {57754800 -36000 0 AHST}.. {73483200 -32400 1 AHDT}.. {89204400 -36000 0 AHST}.. {104932800 -32400 1 AHDT}.. {120654000 -36000 0 AHST}.. {126705600 -32400 1 AHDT}.. {152103600 -36000 0 AHST}.. {162388800 -32400 1 AHDT}.. {183553200 -36000 0 AHST}.. {199281600 -32400 1 AHDT}.. {215607600 -36000 0 AHST}.. {230731200 -32400 1 AHDT}.. {247057200 -36000 0 AHST}.. {262785600 -32400 1 AHDT}.. {278506800 -36000 0 AHST}.. {294235200 -3
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):202
          Entropy (8bit):4.908728298285591
          Encrypted:false
          SSDEEP:
          MD5:1C3CE9F156ABECEAA794E8F1F3A7ADDB
          SHA1:6F84D0A424FD2DE85E3420EA320A186B277B0295
          SHA-256:F38610019C0A2C18AC71F5AA108B9647D9B5C01DCB55211AFB8312308C41FE70
          SHA-512:CA2DA6F9551E4DBF775D7D059F6F3399E0C4F2A428699726CD2A1B0BB17CCF5CDEEF645EE1759A2A349F3F29E0343600B89CE1F4659CF5D2B58280A381C018AD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Anguilla) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):201
          Entropy (8bit):4.898881450964165
          Encrypted:false
          SSDEEP:
          MD5:DB16FFE76D625DEC731AB6320F5EF9BF
          SHA1:D286994E03E4F82C08DE094B436FA098648AFADE
          SHA-256:561E58E11DC5A86CAE04B5CB40F43EFCFF9ABC0C841FAC094619E9C5E0B403F8
          SHA-512:8842B616205378AF78B0B2FC3F6517385845DE30FFD477A21ACFA0060D161FB6462A3C266DCFD54F101729446B8E1B2ECF463C9CF2E6CE227B2628A19AF365F9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Antigua) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1782
          Entropy (8bit):3.733307964154526
          Encrypted:false
          SSDEEP:
          MD5:9B01680A362EA7B462DC236F6A35E14C
          SHA1:456A5E771F6B749BFDB2BFD59836A6A930499881
          SHA-256:B1327CBEC20A21E3FF873E28A2EDFA271EE3A5C01933779300EABD6B185DA010
          SHA-512:E6C2F5C489BEA31B0AAC3CB1DB750AC2B665DAC0AC82C1CE6756E768305300297BA5E3B32EDEB9E1715452F02223E47674C4F2B1844920F664623C9F34309240
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Araguaina) {.. {-9223372036854775808 -11568 0 LMT}.. {-1767214032 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2048
          Entropy (8bit):3.7664759014118188
          Encrypted:false
          SSDEEP:
          MD5:2B9A1EDE5110B46E24F4726664EA1E3F
          SHA1:939D1A7A50544F34B318ACDB52BC6930FE453F6D
          SHA-256:BC86AC89121EC4AA302F6259CCC97EFFD7022DC6CEE3B291C57DA72B6EA0C558
          SHA-512:C204740DACBCECF2CC5CF4FEB687E86B9150512623203C999D6F4EB5FB246D07681A35C28D8445F6A50F49940C321E0AA5E51FE5A73B8ED076F29CEB5B4D4CA2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Buenos_Aires) {.. {-9223372036854775808 -14028 0 LMT}.. {-2372097972 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2077
          Entropy (8bit):3.742645155048276
          Encrypted:false
          SSDEEP:
          MD5:3D2AF5714DFC392ED4BC976784D5A58A
          SHA1:9252DE40B6EF872E1D2F7CDD53DDD21145E93C5C
          SHA-256:A516BB0937977EF949D47B3C8675E30F1CA6C34F8BD298DCF6EBB943580D5317
          SHA-512:8D5FFDB5B578B8EA0291D3A21BDDE25F8301CB16B11AE794FFBA8DCFFE46F6AC5EC03D93E511061B132D84E69E5FAF1BB212837EB8A5A4B4BE517F783837E615
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Catamarca) {.. {-9223372036854775808 -15788 0 LMT}.. {-2372096212 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522740
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):242
          Entropy (8bit):4.72138001874583
          Encrypted:false
          SSDEEP:
          MD5:8A609667DE461CEDC1127BE38B161459
          SHA1:557D2D55DEA38D1CD1103E183F89C65F4016662B
          SHA-256:8CCD6FC77D55582938F1912B1BA66035882D1BFC18A797C631E5E89ABFBF570B
          SHA-512:DBAFDA069DB5FDBCBA11050AC91A733C1712BD6395939CFFFC5EAA78BD0B70B4AF2D9FB8954C6841CCF3AC5F8EDCF08E604D3F2CF67F1CBEA5EB6D3C4DC7F2FA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Catamarca)]} {.. LoadTimeZoneFile America/Argentina/Catamarca..}..set TZData(:America/Argentina/ComodRivadavia) $TZData(:America/Argentina/Catamarca)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2043
          Entropy (8bit):3.7481312409221594
          Encrypted:false
          SSDEEP:
          MD5:8C1D665A25E61CE462C2AC57687763BF
          SHA1:B5BBC26CF6A24BD5BEA42AC485D62C789B80905F
          SHA-256:FA75E274240A341C6BFE3539CFDC114D125AEAEA3161D3C2409347CF8046042A
          SHA-512:A89A7A92C025B87DA4CDFE99BF70CD0E64690D7BFE827DCBFBF0E91B188003FA26487E72B6B950D3BFC9C854B890E5936F414BBEAAD5F3F0673AC5EFE273CDF4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Cordoba) {.. {-9223372036854775808 -15408 0 LMT}.. {-2372096592 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2041
          Entropy (8bit):3.7481290145270245
          Encrypted:false
          SSDEEP:
          MD5:995EDE9E1E86DB500C7437A196325E21
          SHA1:4A8FB1511AA124CA2D299EC8DE155EE9D0479180
          SHA-256:43EB79ABC03CBAC661C563DE1BC09D9DD855CBC72DD2B6467EA98F0F90421BA9
          SHA-512:B58B35EA1B2F0388B8108DCF254F3BD1B21894F00A9F313ABC093BC52C36FCDD94B7486DBA38161C9EFCDB12BC3CD81E7E02395B0CA480A7F01148C43CD3054F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Jujuy) {.. {-9223372036854775808 -15672 0 LMT}.. {-2372096328 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000 -
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2106
          Entropy (8bit):3.744252944523733
          Encrypted:false
          SSDEEP:
          MD5:4A45A063D45EB94214005EF3CA5BCD6D
          SHA1:2420E8591DC53A39EE1A58B2E45DCFAF9503685F
          SHA-256:2B018B791E48269FA9EDA12662FFEC3E2DC33603A918E8B735B8D7D6BEB3B3AA
          SHA-512:0B2824FA3D40B2EDBE8488D50C30368F4CF6E45A39FF6DEBC5BB4FD86F85AD52F5331AD1EB50E5166FA2E735B7E8AA9D94A5FED9421334DB0499524DBE08F737
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/La_Rioja) {.. {-9223372036854775808 -16044 0 LMT}.. {-2372095956 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2077
          Entropy (8bit):3.738002814507529
          Encrypted:false
          SSDEEP:
          MD5:F6CB24E8567B2443224E9E17EE438BFE
          SHA1:8029426C30C4C645EA77C6240391CDB1C3107568
          SHA-256:DC39400BBFD5BDDDC174FE099194806FBFD3FC3AA20E670D67BE0AC35FE97AD4
          SHA-512:6869CFC24C21FBB2DFCCAA9AE7E21A0B24DC002EE792FB28A8F2F05C75C20E93C95A39BD8653AA272AF10FE95922B99EECC1208AACE814817D9441F84360E867
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Mendoza) {.. {-9223372036854775808 -16516 0 LMT}.. {-2372095484 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2080
          Entropy (8bit):3.7580685839169545
          Encrypted:false
          SSDEEP:
          MD5:212D13CE27AF114A8EC2E04023D218C4
          SHA1:C4C5F86BC6EC0D5EA4C9CF199309D085767B97E8
          SHA-256:A05B6708DEFF0607396BFC6661C2287341C3432841AE353D94A67AC742B5FAFA
          SHA-512:CE7201EEA6A86FB49641410D2EEE4030EDB1B96F3218D764762F5AE23883C796F5742ED69CEC985A9D3582D6C72ED74114DE81508F6DEB4B54865B6974ADC965
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Rio_Gallegos) {.. {-9223372036854775808 -16612 0 LMT}.. {-2372095388 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2011
          Entropy (8bit):3.7415813345133975
          Encrypted:false
          SSDEEP:
          MD5:A06C33CDFD7E7B630CB1DF34E72E61E5
          SHA1:694826B9B910DA0BD70A9CB547C26E6838B08111
          SHA-256:CAEFC60F2F36EF9FFE0C5921C3C392DE1E95755683A96C1C4EC0BA2C242A4D84
          SHA-512:D6696A6C14EECF2B77EC586F40137BDD95E5CE5C5193570C809FAB9E5FCA4B8744283CEB6818E525C73F6EFF657274410B2622902EE8C15912C8D5F5FA5C805E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Salta) {.. {-9223372036854775808 -15700 0 LMT}.. {-2372096300 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000 -
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2106
          Entropy (8bit):3.747934819596411
          Encrypted:false
          SSDEEP:
          MD5:32A50D0ABF408D9E59C0580D5B8CC472
          SHA1:EA5BB8860982F8BAFEAEFDE1D6ACD440DA132DFE
          SHA-256:41B2C25E42146A76934B866061BB3245B8ADA0FF4E1BFBA6F8842A30BDD5C132
          SHA-512:E5D2521A4EF53AAD3E74506708EC2768C4D2EE8D6D014DCCF4A6DC290B713B4D46021B66527548C35004E10D753E1B685EEFD55BBE7BF01EC6104D7D8AAC4403
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/San_Juan) {.. {-9223372036854775808 -16444 0 LMT}.. {-2372095556 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2081
          Entropy (8bit):3.7399269084699975
          Encrypted:false
          SSDEEP:
          MD5:FB06B66F5D41709C7E85C8B1E9BFCFA0
          SHA1:D5C0C4B12C6190856C300321B1C106C7474BA54B
          SHA-256:A43B35F25E54EF359D046E33281C0A978F0EE8811C93A6809F1F65750878BBB6
          SHA-512:D445F46D6A17A075AD995885E45234A711F53BF3FE2DFC6DFBB611E8AC154B10C91E137927DD66D6A7C596A93BAE5DE283796F341B5095FA0DD05595E1C3A077
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/San_Luis) {.. {-9223372036854775808 -15924 0 LMT}.. {-2372096076 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2105
          Entropy (8bit):3.741704529449777
          Encrypted:false
          SSDEEP:
          MD5:D9497141EC0DC172E5FF5304FED0BE6B
          SHA1:CD20A4F0C127A84791093010D59DF119DD32340A
          SHA-256:0F7DB23E1280FC19A1FB716E09A9699ADA2AAE24084CAD472B4C325CC9783CCF
          SHA-512:0B71952055013CD6045ED209FD98168083550655FAB91B7870C92098E40C4FE6827EAAF922D34ECE28298CBB14327A76AD6780D480E552F52F865AA11A4AA083
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Tucuman) {.. {-9223372036854775808 -15652 0 LMT}.. {-2372096348 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2075
          Entropy (8bit):3.7445758155279836
          Encrypted:false
          SSDEEP:
          MD5:16A89FD2CDEE50E534301A9797311A9D
          SHA1:4A4EBA1798214C7CF5ACDC0B2EC8B4716CD968CB
          SHA-256:10B6FF51314D8EE1D010187D8805C4E3D71B778BC6DECB26E66193A5BB3E9EA2
          SHA-512:DBB0BA3F8AA2B54C86EA8B6530C16DF95AF1331FC5F843B113A204DA20B8EF011FE93C27EB917D01B9040D4914057687B4AACCD292A847559AF69150D1BDC4B5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Ushuaia) {.. {-9223372036854775808 -16392 0 LMT}.. {-2372095608 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):199
          Entropy (8bit):4.893042770292303
          Encrypted:false
          SSDEEP:
          MD5:CC015E3E5D3293CAA1348B4E0EE5795C
          SHA1:75E7EFD905C9001CE9CA5872DA3915A19BCB00E0
          SHA-256:7490CD66408B8A14C549278FE67DC3338FE9E458F423F01CCBEA00B5E6F6CEF6
          SHA-512:66523F050E4A42A1C9FC8C02B822CD3864A6E35F6364FB6A675F2A503BD8030FE6E380B252068668A79A6593B5042520EE40700DA033517742B3F0ED33D79DAF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Aruba) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7944
          Entropy (8bit):3.5156463862656775
          Encrypted:false
          SSDEEP:
          MD5:181203CAD98E94355B9914A205514904
          SHA1:D361CB53955437270905A9432DE9E7F6C1AE7189
          SHA-256:EAEFE21276EE60C7F876C1D65039999AC069339DCDB82A23FC9206C274510575
          SHA-512:AE9262DFC35579AEB610DF8BB5F7FBB49232195F55F78402405017681F72C0D2A09FA9EB605B406065A1F44FE6785AC0163870C921DAFFC4746DA6EDA3081521
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Asuncion) {.. {-9223372036854775808 -13840 0 LMT}.. {-2524507760 -13840 0 AMT}.. {-1206389360 -14400 0 -04}.. {86760000 -10800 0 -03}.. {134017200 -14400 0 -04}.. {162878400 -14400 0 -04}.. {181368000 -10800 1 -04}.. {194497200 -14400 0 -04}.. {212990400 -10800 1 -04}.. {226033200 -14400 0 -04}.. {244526400 -10800 1 -04}.. {257569200 -14400 0 -04}.. {276062400 -10800 1 -04}.. {291783600 -14400 0 -04}.. {307598400 -10800 1 -04}.. {323406000 -14400 0 -04}.. {339220800 -10800 1 -04}.. {354942000 -14400 0 -04}.. {370756800 -10800 1 -04}.. {386478000 -14400 0 -04}.. {402292800 -10800 1 -04}.. {418014000 -14400 0 -04}.. {433828800 -10800 1 -04}.. {449636400 -14400 0 -04}.. {465451200 -10800 1 -04}.. {481172400 -14400 0 -04}.. {496987200 -10800 1 -04}.. {512708400 -14400 0 -04}.. {528523200 -10800 1 -04}.. {544244400 -14400 0 -04}.. {5
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):187
          Entropy (8bit):4.791603790249234
          Encrypted:false
          SSDEEP:
          MD5:5A45B70C79F533548B3DD332F988E15B
          SHA1:C7485828619A1D4F5CA59D80ABD197100AC58F64
          SHA-256:518BEB6E54AE811F8C725EA8CC42787D48FC605A3476D6E7A00A1B5733CBD6AC
          SHA-512:A81C2EBE282E019ED011EADDB8F74C3E6FBE88D87E8D8706B3022CDCC48EF92AD90F9BCF9F25031664BB6EFE069EAFDD23D9B55BF672FC7528A2DD8CB6B986B4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Atikokan) $TZData(:America/Panama)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):177
          Entropy (8bit):4.812527147763069
          Encrypted:false
          SSDEEP:
          MD5:13479F64BFBDC7583C637E1562C454B4
          SHA1:2F59484C779B0D6033FC14E205DA9BCAB7A5FCB1
          SHA-256:1D6FEE336E71FFFB64874A830C976867C071EBF6B133C296B32F87E3E7D814C9
          SHA-512:D2C5D35BBBDAB8D58BF6185328124796C06B67ADFB4C1828BA5A9CCA500A01BB8BE69635AE7EEA7FA837A27B20D488A08A29B121DD1617BC373390AD95D67E39
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Adak)]} {.. LoadTimeZoneFile America/Adak..}..set TZData(:America/Atka) $TZData(:America/Adak)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2012
          Entropy (8bit):3.703391569010329
          Encrypted:false
          SSDEEP:
          MD5:69DCC2477D8D81E2F49D295DB6907190
          SHA1:3C6ED0CEF15D3265C962873480EE1809A4DCACA2
          SHA-256:64F1EC14F6B43FF10B564F839152E88DF9262F0947D1DB347557FA902F6FD48C
          SHA-512:71DEA6D47F267AA7326A011872FA74762FA4F8CD57EB149E3B56B3DE9097B0B9258BC4F6C29188B49FC60C1942869B92D9E59FEE6980A5DA5D0029C383D99F39
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bahia) {.. {-9223372036854775808 -9244 0 LMT}.. {-1767216356 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2073
          Entropy (8bit):4.021485901155292
          Encrypted:false
          SSDEEP:
          MD5:4655AE5AB9C39CA05C1FF36FC366679F
          SHA1:F3F1D08EC35907A8F45AA2CFD097F6DCCA75C9B8
          SHA-256:A6233E5BB0D3B30D0E3B94CD797718041AC3C2E75B387D6646A5C0376C5591CD
          SHA-512:3915B845A312147C5B047096033B3D153E4E83AF4C8E4AAA73C8D12E2A8386CFE8EC4568730F9F28863017A60622DD9CC7D97991C966779B4068BC29F6C6B2B3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bahia_Banderas) {.. {-9223372036854775808 -25260 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-873828000 -25200 0 MST}.. {-661539600 -28800 0 PST}.. {28800 -25200 0 MST}.. {828867600 -21600 1 MDT}.. {846403200 -25200 0 MST}.. {860317200 -21600 1 MDT}.. {877852800 -25200 0 MST}.. {891766800 -21600 1 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):648
          Entropy (8bit):4.251560000277241
          Encrypted:false
          SSDEEP:
          MD5:DC4FA44B2174A4E6F0644FA8EA2E83F9
          SHA1:C12DF8C862A05D569EAF189272F8BF44303595A1
          SHA-256:FD5E04136506C6543A9ACDC890A30BCF0D561148E1063EC857E3913DE1EBA404
          SHA-512:5AC307CD48132B57215CCBAF0BB63F7FA9C5B28DC9F6217C905885D75B0DF131238D4DB2AE707C3DDEE2EDE6C0914644B435FB1CDD9913600D8B69AE95578B0F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Barbados) {.. {-9223372036854775808 -14309 0 LMT}.. {-1841256091 -14400 0 AST}.. {-874263600 -10800 1 ADT}.. {-862682400 -14400 0 AST}.. {-841604400 -10800 1 ADT}.. {-830714400 -14400 0 AST}.. {-820526400 -14400 0 -0330}.. {-811882800 -12600 1 AST}.. {-798660000 -14400 0 -0330}.. {-788904000 -14400 0 AST}.. {234943200 -10800 1 ADT}.. {244616400 -14400 0 AST}.. {261554400 -10800 1 ADT}.. {276066000 -14400 0 AST}.. {293004000 -10800 1 ADT}.. {307515600 -14400 0 AST}.. {325058400 -10800 1 ADT}.. {338706000 -14400 0 AST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1031
          Entropy (8bit):3.8842563546204225
          Encrypted:false
          SSDEEP:
          MD5:DFA5E50F6AEF1311A4CF74970477E390
          SHA1:5B63676EB8039B2BE767BAA44820F2DAE5B62876
          SHA-256:549625CCB30BD0E025BAC47668BA3AA0CDD8569E5887E483C8D62B5B7302FA50
          SHA-512:4BBB43694E3B54339C549AC3A5488B77366DB1189D8D1834DCF618D9448084A950B575E207064521B1CDFD2E41F7D1D8C5CD9CEB4668D4459585649556136EB0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Belem) {.. {-9223372036854775808 -11636 0 LMT}.. {-1767213964 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3284
          Entropy (8bit):3.8546064195941097
          Encrypted:false
          SSDEEP:
          MD5:4DA622B685B3B075CC94FC4E23322547
          SHA1:DEB23F0A434549DAE1BE60ACF757BB212C907B92
          SHA-256:E07F45264E28FD5AA54BD48CB701658509829CF989EC9BD79498D070A1BA270F
          SHA-512:9B00BF8870BC4AAEF7F06FCDFEEEF54686A2CC890103696631EB4DEF5AEEAD051EC9069D70A2B22397F18C0067E03A54E75DA18474D6B1BD3BDA2D5313E0AD16
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Belize) {.. {-9223372036854775808 -21168 0 LMT}.. {-1822500432 -21600 0 CST}.. {-1616954400 -19800 1 -0530}.. {-1606069800 -21600 0 CST}.. {-1585504800 -19800 1 -0530}.. {-1574015400 -21600 0 CST}.. {-1554055200 -19800 1 -0530}.. {-1542565800 -21600 0 CST}.. {-1522605600 -19800 1 -0530}.. {-1511116200 -21600 0 CST}.. {-1490551200 -19800 1 -0530}.. {-1479666600 -21600 0 CST}.. {-1459101600 -19800 1 -0530}.. {-1448217000 -21600 0 CST}.. {-1427652000 -19800 1 -0530}.. {-1416162600 -21600 0 CST}.. {-1396202400 -19800 1 -0530}.. {-1384713000 -21600 0 CST}.. {-1364752800 -19800 1 -0530}.. {-1353263400 -21600 0 CST}.. {-1333303200 -19800 1 -0530}.. {-1321813800 -21600 0 CST}.. {-1301248800 -19800 1 -0530}.. {-1290364200 -21600 0 CST}.. {-1269799200 -19800 1 -0530}.. {-1258914600 -21600 0 CST}.. {-1238349600 -19800 1 -0530}.. {-1226860200 -21600
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):206
          Entropy (8bit):4.938043196147077
          Encrypted:false
          SSDEEP:
          MD5:09FD8280CC890F238126F9641DB7C90E
          SHA1:98AB4E0DE8173C2BB2532B07FAE2E71F588AB26F
          SHA-256:FACD0A835D1F425CD323EE453ADE231810B2D1CF6EBA227BA1B50522AE3879F7
          SHA-512:117C24389B7BFB079F4409B1FA6AA547654D7C69A6CBB19218BF2B96F6CFE3CBAAD400D4C2EFE8A9BFE25F44402057427FC8A62DC20A98018D23A7CF9B87401F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Blanc-Sablon) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1199
          Entropy (8bit):3.7988385604912893
          Encrypted:false
          SSDEEP:
          MD5:9529221F9B4E104CC598491703B10E6C
          SHA1:5ACD61B525A18DE1919A7484C92EC5D787DF2F25
          SHA-256:10592EA1CB0D02C06A61059EC601F70A706A5053AC923B9EED29388D5E71EF3A
          SHA-512:66BEDB631469651A5E426155428764E3C1C14483E6FEE1505812E8676EB6E82CF0A88F6CC697F03FDA0AF906D91C7DE6E940DF3D33DD247BEF51DBD9A13DEE16
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Boa_Vista) {.. {-9223372036854775808 -14560 0 LMT}.. {-1767211040 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):246
          Entropy (8bit):4.705337479465446
          Encrypted:false
          SSDEEP:
          MD5:DB019451A7D678C3E7AEE706283861F6
          SHA1:57E63C5372F50CBD1A7FA32688C1B77ADDCC06EB
          SHA-256:B6ADC16815DC95E537548CA3572D7F93626A6D1DC390DD4CBABAB5AB855BBA30
          SHA-512:6C94B2D7EFA856E6BD41FC45B0E8D16A40E61D8B895397CD71230047FAD4793DDB9ABAAC57D2841549F161C9389D7E61D54D38F1BAC6F13ED3DD4C68CDD3272C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bogota) {.. {-9223372036854775808 -17776 0 LMT}.. {-2707671824 -17776 0 BMT}.. {-1739041424 -18000 0 -05}.. {704869200 -14400 1 -05}.. {733896000 -18000 0 -05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8605
          Entropy (8bit):3.8563913604109064
          Encrypted:false
          SSDEEP:
          MD5:005D0BF1320030A7E9CDC97D0C8BB44B
          SHA1:CB236DA840A49B4BCD261114DCA38DADA567B091
          SHA-256:93AF910CB2AD2203B71C1AD49D56DF4A4A14D07F885AFD4E755271F1372A517C
          SHA-512:16A5483392741673BEC020EF6EBE963AB0FB12629D662C586C27A1E9A1BE3FEA8DC3D05A0E84917B8166E48CADA45C74DFABFDC897A6BC94D3C5058D31AD5126
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Boise) {.. {-9223372036854775808 -27889 0 LMT}.. {-2717640000 -28800 0 PST}.. {-1633269600 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-1601820000 -25200 1 PDT}.. {-1583679600 -28800 0 PST}.. {-1471788000 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126255600 -25200 0 MST}.. {129114000 -21600 0 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):239
          Entropy (8bit):4.821972751564724
          Encrypted:false
          SSDEEP:
          MD5:6700956D5FE96CEC8D34EB49FF805374
          SHA1:69B9973EF31AE204EFED7485E59CEA99E00815C8
          SHA-256:DEFC5C9DA2D4D4146145A50D692A6BFF698C3B0A1F19EFD82AD0EE7678F39FCF
          SHA-512:A80C03A519F00A4270248E885463090A34B3992B3DEBA94DD6AEBCC50736541655461E4AA10856125B8EF9B92CEB697429EE7088DBC6AB4FAE383FDF11521B7A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Buenos_Aires)]} {.. LoadTimeZoneFile America/Argentina/Buenos_Aires..}..set TZData(:America/Buenos_Aires) $TZData(:America/Argentina/Buenos_Aires)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7739
          Entropy (8bit):3.8713679494465016
          Encrypted:false
          SSDEEP:
          MD5:E6AE12CDB55FED492C253E46E2690FE0
          SHA1:CD3699E50BC1694827E51E4101C713E52FA646C8
          SHA-256:3E0506A54B562DBC3AA6889DDD39B327FE0B85C63B00F0B39D606921A0936A59
          SHA-512:BA3D5D5420210E74E74A581C9678224948266828A8FACE06383E41E13475C682F82D288426FB915D618FFE7ED95BD8F1C7E9D59D31CE5B464D5EC1363AB5E340
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cambridge_Bay) {.. {-9223372036854775808 0 0 -00}.. {-1577923200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-147891600 -18000 1 MDDT}.. {-131562000 -25200 0 MST}.. {325674000 -21600 1 MDT}.. {341395200 -25200 0 MST}.. {357123600 -21600 1 MDT}.. {372844800 -25200 0 MST}.. {388573200 -21600 1 MDT}.. {404899200 -25200 0 MST}.. {420022800 -21600 1 MDT}.. {436348800 -25200 0 MST}.. {452077200 -21600 1 MDT}.. {467798400 -25200 0 MST}.. {483526800 -21600 1 MDT}.. {499248000 -25200 0 MST}.. {514976400 -21600 1 MDT}.. {530697600 -25200 0 MST}.. {544611600 -21600 1 MDT}.. {562147200 -25200 0 MST}.. {576061200 -21600 1 MDT}.. {594201600 -25200 0 MST}.. {607510800 -21600 1 MDT}.. {625651200 -25200 0 MST}.. {638960400 -21600 1 MDT}.. {657100800 -25200 0 MST}.. {671014800 -21600 1 MDT}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2918
          Entropy (8bit):3.6039149423727013
          Encrypted:false
          SSDEEP:
          MD5:230A9F7A87BA56C30ACB3B1732F823F3
          SHA1:8263EA723F2AEA7740C7EC54BE0000A06982D765
          SHA-256:6D5BD1355016B03EDEA58DF98BEC26281CD372725B2DCB60B4D748D2FB4346C8
          SHA-512:C357AA33833DBBDC6BC7DD3F23469EADDF08564AF17D7EE935C8AEA5F35B6E3BBDE1E181BC0DBF264051C4BE139261055633D191413DD610B0150AB3CDE161AF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Campo_Grande) {.. {-9223372036854775808 -13108 0 LMT}.. {-1767212492 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1412
          Entropy (8bit):4.034087321254386
          Encrypted:false
          SSDEEP:
          MD5:7FBCA91F4B7100C4667F24A9AB263109
          SHA1:163A77FF9EAC49B00B5F838DF4D47F079ECF6A83
          SHA-256:FD6C370F82E5CFE374637E0E222E72570857AC3F85143BEEEF9C3D0E7A6C0D04
          SHA-512:124A5D7F58B38F15A90BA48E63D1D38335371D98A2503E691EC6426EB51E87FD61CA05FCA83573DD1DC06DB9E599302C64D226D5DF13B8A62E0A6943318431BE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cancun) {.. {-9223372036854775808 -20824 0 LMT}.. {-1514743200 -21600 0 CST}.. {377935200 -18000 0 EST}.. {828860400 -14400 1 EDT}.. {846396000 -18000 0 EST}.. {860310000 -14400 1 EDT}.. {877845600 -18000 0 EST}.. {891759600 -14400 1 EDT}.. {902041200 -18000 0 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0 CST}.. {1207468800 -18000 1 CDT}.. {1225004400 -21600 0
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):284
          Entropy (8bit):4.588048586971241
          Encrypted:false
          SSDEEP:
          MD5:5DDB49759D58931A06740A14F76B431C
          SHA1:E9AC99265D42D140E12BB4DAAA24FABAC65E79FA
          SHA-256:D558C25F165E956E980AA8F554AB3BF24E91B51EADBD2B1065EF6DFDA0E2F984
          SHA-512:318804ED41F36A3A8746C8CD286116787A768B06CAD6057559D1C7105170DE6EAB807EFA52AA8A0E353491B6F8C47D623D4473C1AEAD20B5C00747E07BB282B2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Caracas) {.. {-9223372036854775808 -16064 0 LMT}.. {-2524505536 -16060 0 CMT}.. {-1826739140 -16200 0 -0430}.. {-157750200 -14400 0 -04}.. {1197183600 -16200 0 -0430}.. {1462086000 -14400 0 -04}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):227
          Entropy (8bit):4.666638841481612
          Encrypted:false
          SSDEEP:
          MD5:EEB851BE330BCC44A4831763534058B9
          SHA1:A5FC3E69DDBD3C40D9EB4317BBD5BB6C78751B36
          SHA-256:37CD6BDAA6C6EEDFAC3288CA1C11F5CBBE8A17E5F2E790E7635A64B867AFBD87
          SHA-512:7CD0BC822550325EB3198B4AD6CCD38938FA654A03A09C53117560D1FE3FDCD9C892D105F0D7AF44ED52DD7E0475721240D74A10C98619BE9EC4F5410B8FD87D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Catamarca)]} {.. LoadTimeZoneFile America/Argentina/Catamarca..}..set TZData(:America/Catamarca) $TZData(:America/Argentina/Catamarca)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.832612867310476
          Encrypted:false
          SSDEEP:
          MD5:6052E52C8E5A5F43102C47D895797A1F
          SHA1:23DBD40AE96C84E44ADCD1AC33E7871D217C17BC
          SHA-256:873285F3E13CB68DD28EB109ECAD8D260E11A9FF6DF6A4E8E0D4C00B0182695B
          SHA-512:DDE89C70B6F24AD4F585DC5424A6D029E5C898254C9085C588AE699CED4C8316840FF7C87685D7CFAA2E689F01687985454A0C9E3886342E936C56AB688DF732
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cayenne) {.. {-9223372036854775808 -12560 0 LMT}.. {-1846269040 -14400 0 -04}.. {-71092800 -10800 0 -03}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.774923706273939
          Encrypted:false
          SSDEEP:
          MD5:AD6E086BEDF05A0BEB66990BD9518BEE
          SHA1:FA0B7E8D6931E79092A90F7EECBA2293AE886AE3
          SHA-256:C38C49AE1C3E67BD2118002DCFCC3C0EFB6892FB9B0106908A9282C414D0BF2E
          SHA-512:A1E40422D15DBCB24A6FE353639A1541FAD7F394D20F8AEB32D4E39667BA264C3E815BAA703B88B90D381540168016A0641CA220BACAF05E80EAA698642B6FFA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Cayman) $TZData(:America/Panama)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):11372
          Entropy (8bit):3.814348526052702
          Encrypted:false
          SSDEEP:
          MD5:763E23AA7FB20F8D7CB2F0E87FAFD153
          SHA1:B131A10C1C208BB5E5E178ACD21A679FD0537AC5
          SHA-256:C7707AF88D650F90839E7258356E39D85228B33B6DBCC5C065C3D8733AE28CEE
          SHA-512:FE9C5D2EA253338DDFD79CC8ED2F94D6817BD770C0895752EFB1917E2313735C18475D67191C29BCCD53DEFFF35C1BF0CA5D98C92091DDCD1E97CD6302DC73A4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Chicago) {.. {-9223372036854775808 -21036 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-1577901600 -21600 0 CST}.. {-1563724800 -18000 1 CDT}.. {-1551632400 -21600 0 CST}.. {-1538928000 -18000 1 CDT}.. {-1520182800 -21600 0 CST}.. {-1504454400 -18000 1 CDT}.. {-1491757200 -21600 0 CST}.. {-1473004800 -18000 1 CDT}.. {-1459702800 -21600 0 CST}.. {-1441555200 -18000 1 CDT}.. {-1428253200 -21600 0 CST}.. {-1410105600 -18000 1 CDT}.. {-1396803600 -21600 0 CST}.. {-1378656000 -18000 1 CDT}.. {-1365354000 -21600 0 CST}.. {-1347206400 -18000 1 CDT}.. {-1333904400 -21600 0 CST}.. {-1315152000 -18000 1 CDT}.. {-1301850000 -21600 0 CST}.. {-1283702400 -18000 1 CDT}.. {-1270400400 -21600 0 CST}.. {-1252252800 -18000 1 CDT}.. {-1238950800
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2040
          Entropy (8bit):4.006586050664275
          Encrypted:false
          SSDEEP:
          MD5:67738E07092EDB5A9F484ED5CA217EFB
          SHA1:9E428C67AE4BDACA48D189DF60374F3B6523E120
          SHA-256:93438D65EA8F95691748FF749219FAFA1940469BC61CED0B7CBF995B417F20B4
          SHA-512:57C9FE7EAE37504465F33B2AB079ED91700528E330D227E94AE8A06C58DEFA65F1EA1CDF89F835910D92D037DADB45E684A2EA96512B08F83650DD33CCEB8EB6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Chihuahua) {.. {-9223372036854775808 -25460 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {820476000 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {883634400 -21600 0 CST}.. {891766800 -21600 0 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200 -25200 0 MST}.. {1143968400 -
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):192
          Entropy (8bit):4.844590153688034
          Encrypted:false
          SSDEEP:
          MD5:A0BF04CD77026DC1D2749848AB0EE45E
          SHA1:EA0F1BC11379DF2E421675BC5DE4805CE94B96D6
          SHA-256:C8CBF5A29CC1D0827390CA6E98B2EFCF90743C6DD0ECA143B300050DD4164041
          SHA-512:61968B4E42ECC60C801F959D18D13187AD39D9B81FA1A947F6B6862F99D73E3A30849AC4233DB5705D46F5373C42D8748B15BE9B82822971B4F47E601E5766D8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Coral_Harbour) $TZData(:America/Panama)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):219
          Entropy (8bit):4.78887878252354
          Encrypted:false
          SSDEEP:
          MD5:C7CCF5CEC7AA60D6063D1C30F4263ADC
          SHA1:FD8E9AEEEE50656FD3C694CA051895DDC8E5590B
          SHA-256:28B84710EADEF7AD5E7FA63EF519A9D93996D3BB91DD9018333DE3AC4D8FB8DD
          SHA-512:6974F8B238977EE5222368C4B79327BB240580819FCA082261D6994781144D81E2E8843B4F1C9D07EFBEE27311C8930BDAC9C0D6D6718F6FB1600D0000576CDE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Cordoba)]} {.. LoadTimeZoneFile America/Argentina/Cordoba..}..set TZData(:America/Cordoba) $TZData(:America/Argentina/Cordoba)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):431
          Entropy (8bit):4.506976345480408
          Encrypted:false
          SSDEEP:
          MD5:0446EF1A6985A62EDFFB9FFAC7F1DE0E
          SHA1:A43468E120E585E2DCC20205BA1D1E2CCB6C0BC2
          SHA-256:E3061DC6FA9F869F013351A9FDF420448592D7F959C2B4404093432508146F7E
          SHA-512:86D41B0C49489572C3EAEDD5466AA92319C721CCEC9437EBB0F2AAD772FB5ED91A2F2061E00448FB48096B0BAAE9A4E1E644F8AF595B76BE05DBC0C801E6D6ED
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Costa_Rica) {.. {-9223372036854775808 -20173 0 LMT}.. {-2524501427 -20173 0 SJMT}.. {-1545071027 -21600 0 CST}.. {288770400 -18000 1 CDT}.. {297234000 -21600 0 CST}.. {320220000 -18000 1 CDT}.. {328683600 -21600 0 CST}.. {664264800 -18000 1 CDT}.. {678344400 -21600 0 CST}.. {695714400 -18000 1 CDT}.. {700635600 -21600 0 CST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.8664633847782905
          Encrypted:false
          SSDEEP:
          MD5:0757DD22C0E297CCE8E6678ECA4B39C7
          SHA1:81B31299F9A35C8BA2EC1F59EC21129FFCDCD52F
          SHA-256:A01DDB460420C8765CE8EF7A7D031ABD7BDB17CFA548E7C3B8574C388AA21E17
          SHA-512:F1AFC0F6371A10E4CB74FB2C8985610AEE6C3511861BC09384EDC99D250E9099A1F4430BFC3B0B396C2702BF9991A5A4ECFD53A82C92883460715FA2C1E04579
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:America/Creston) $TZData(:America/Phoenix)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2912
          Entropy (8bit):3.588248620238414
          Encrypted:false
          SSDEEP:
          MD5:264E0CEA9491B404993594E64F13479F
          SHA1:6D4D277FA470A2C7AD0A59B5DA3CC15BEEB74E78
          SHA-256:2D8281CF3FD9E859C5206F781E264854FA876CB36562A08C6C01343C65F8A508
          SHA-512:759C19B4DD0E1F7F1176872806BFB1F17ADF9C992E41B96FEA67D77DD67E9DD3C1683E3B6D27FB092C731F534C6A7441BACFFF0301907217A064523B86992E23
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cuiaba) {.. {-9223372036854775808 -13460 0 LMT}.. {-1767212140 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200 -1
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):201
          Entropy (8bit):4.876961543280111
          Encrypted:false
          SSDEEP:
          MD5:9459043060E33E8EDC74E78332E96EDF
          SHA1:27963FE063965584D0F226BAE9A08EB2954398F0
          SHA-256:ACCF08CF53C9431E226714DF8BEDE3C91BAF62D5BD7B98CA8B50D7258124D129
          SHA-512:215D9AFAA7227F4447177CE2ABA5A6F7F2F46A9D787845DD32F10D5C22BF9CBE4047AF5E0E66FA7A4F70EEE064A7EC7B67949E565C3C5C60C31F3C19D6915D76
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Curacao) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1128
          Entropy (8bit):3.8794180227436557
          Encrypted:false
          SSDEEP:
          MD5:6E37A78AC686A6B48A78541E1900E33C
          SHA1:D41F39FDB6D45921B57341E95A006251B4875961
          SHA-256:968C56F1D0106E1D92C7B094EEF528B6EE1FFA3D7A18BE2F2BA59178C2C0F1E0
          SHA-512:397623149D95FF9A094750EE697F62DF90124BBBE407FB49FBAE335A61629449F2A61EF4471DBD57745B323DFCF3628611CAE9295F2EF7E4A7412A697651FF68
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Danmarkshavn) {.. {-9223372036854775808 -4480 0 LMT}.. {-1686091520 -10800 0 -03}.. {323845200 -7200 0 -02}.. {338950800 -10800 0 -03}.. {354675600 -7200 1 -02}.. {370400400 -10800 0 -03}.. {386125200 -7200 1 -02}.. {401850000 -10800 0 -03}.. {417574800 -7200 1 -02}.. {433299600 -10800 0 -03}.. {449024400 -7200 1 -02}.. {465354000 -10800 0 -03}.. {481078800 -7200 1 -02}.. {496803600 -10800 0 -03}.. {512528400 -7200 1 -02}.. {528253200 -10800 0 -03}.. {543978000 -7200 1 -02}.. {559702800 -10800 0 -03}.. {575427600 -7200 1 -02}.. {591152400 -10800 0 -03}.. {606877200 -7200 1 -02}.. {622602000 -10800 0 -03}.. {638326800 -7200 1 -02}.. {654656400 -10800 0 -03}.. {670381200 -7200 1 -02}.. {686106000 -10800 0 -03}.. {701830800 -7200 1 -02}.. {717555600 -10800 0 -03}.. {733280400 -7200 1 -02}.. {749005200 -10800 0 -03}.. {764730000 -72
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2967
          Entropy (8bit):3.9564096415565855
          Encrypted:false
          SSDEEP:
          MD5:F494405F3B250668BE00DC3864B9A2DC
          SHA1:20843AD6D95DD5D5950E2946BCAE4ECE2B676F70
          SHA-256:30E875343C81C8DE473E6313A27C55315F38E7CCDBD2CEE5783EC54D269D5807
          SHA-512:9102BD114436D5FE5A1942E31AE692ECE41F910AC1B6E52C02283801D5AA00CFF22D980C61E69928267D3DD34331E301C7324CA631B71AC2FBBDE06D7914F849
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Dawson) {.. {-9223372036854775808 -33460 0 LMT}.. {-2188996940 -32400 0 YST}.. {-1632056400 -28800 1 YDT}.. {-1615125600 -32400 0 YST}.. {-1596978000 -28800 1 YDT}.. {-1583164800 -32400 0 YST}.. {-880203600 -28800 1 YWT}.. {-769395600 -28800 1 YPT}.. {-765381600 -32400 0 YST}.. {-147884400 -25200 1 YDDT}.. {-131554800 -32400 0 YST}.. {315561600 -28800 0 PST}.. {325677600 -25200 1 PDT}.. {341398800 -28800 0 PST}.. {357127200 -25200 1 PDT}.. {372848400 -28800 0 PST}.. {388576800 -25200 1 PDT}.. {404902800 -28800 0 PST}.. {420026400 -25200 1 PDT}.. {436352400 -28800 0 PST}.. {452080800 -25200 1 PDT}.. {467802000 -28800 0 PST}.. {483530400 -25200 1 PDT}.. {499251600 -28800 0 PST}.. {514980000 -25200 1 PDT}.. {530701200 -28800 0 PST}.. {544615200 -25200 1 PDT}.. {562150800 -28800 0 PST}.. {576064800 -25200 1 PDT}.. {594205200 -28800 0 P
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1940
          Entropy (8bit):4.024810417421672
          Encrypted:false
          SSDEEP:
          MD5:7868720D39782147B2BD6B039A5BF7E0
          SHA1:6F66404E5CCFF7F020269A316D792D5E7AD4C280
          SHA-256:540804BECDEAB92340EF02D32A62BFD550B71A3DB8D829BE426EE4D210004643
          SHA-512:9CCD124FF954CA2988F07286FFE9ED740E0CEF5F4D76BF090367B74A577E91BF5590EDFE12AFC83ACF5CBFC88C5A68867C58082A2777D08C326A7B18889B08E2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Dawson_Creek) {.. {-9223372036854775808 -28856 0 LMT}.. {-2713881544 -28800 0 PST}.. {-1632060000 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-725817600 -28800 0 PST}.. {-715788000 -25200 1 PDT}.. {-702486000 -28800 0 PST}.. {-684338400 -25200 1 PDT}.. {-671036400 -28800 0 PST}.. {-652888800 -25200 1 PDT}.. {-639586800 -28800 0 PST}.. {-620834400 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589384800 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557935200 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526485600 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495036000 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463586400 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431532000 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-400082400 -25200 1 PDT}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8920
          Entropy (8bit):3.8540632258197514
          Encrypted:false
          SSDEEP:
          MD5:0D649599A899ECB3FCF2783DCEE3E37B
          SHA1:ACC796BE75F41A12FB1F8CCBD2B2839AF9876FFE
          SHA-256:3FE2EE8C05C5D6F268B58BD9FC3E3A845DEA257473B29F7B3FB403E917448F3C
          SHA-512:C10D41AB95439B8E978F12F9F58D1ACC9AD15404123FA5FBA0D1CC716E5CF5DA6BD2252450055AC3998DBCB8DD49F7A82ACD53413E3EE78CDA2C42F603DE2C56
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Denver) {.. {-9223372036854775808 -25196 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-1577898000 -25200 0 MST}.. {-1570374000 -21600 1 MDT}.. {-1551628800 -25200 0 MST}.. {-1538924400 -21600 1 MDT}.. {-1534089600 -25200 0 MST}.. {-883587600 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-757357200 -25200 0 MST}.. {-147884400 -21600 1 MDT}.. {-131558400 -25200 0 MST}.. {-116434800 -21600 1 MDT}.. {-100108800 -25200 0 MST}.. {-94669200 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -2
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8430
          Entropy (8bit):3.826664943157435
          Encrypted:false
          SSDEEP:
          MD5:2BBA922E9377D257CBDF6E1367BBB1A2
          SHA1:6F33A44834E8041E78660A326A5DDAF3D7F9DC2A
          SHA-256:84F6897B87D3978D30D35097B78C55434CE55EB65D6E488A391DFC3B3BB5A8FE
          SHA-512:D225824945C08A3521A8288B92B26DFFA712ED3505E72DEDE4A7D1777E58DEA79ADF3F042D22624E4142DD4203BAA4DFF8EB08B7033FDF00059F6C39954EA1A1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Detroit) {.. {-9223372036854775808 -19931 0 LMT}.. {-2051202469 -21600 0 CST}.. {-1724083200 -18000 0 EST}.. {-883594800 -18000 0 EST}.. {-880218000 -14400 1 EWT}.. {-769395600 -14400 1 EPT}.. {-765396000 -18000 0 EST}.. {-757364400 -18000 0 EST}.. {-684349200 -14400 1 EDT}.. {-671047200 -18000 0 EST}.. {-80506740 -14400 0 EDT}.. {-68666400 -18000 0 EST}.. {-52938000 -14400 1 EDT}.. {-37216800 -18000 0 EST}.. {-31518000 -18000 0 EST}.. {94712400 -18000 0 EST}.. {104914800 -14400 1 EDT}.. {120636000 -18000 0 EST}.. {126687600 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {157784400 -18000 0 EST}.. {167814000 -14400 0 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600 -14400 1 EDT}.. {278488800 -18000 0 EST}.. {294217200 -14400 1 EDT}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):202
          Entropy (8bit):4.86856578093135
          Encrypted:false
          SSDEEP:
          MD5:398D8DBB24CEA2D174EF05F63869C94A
          SHA1:6D0E04165952E873E6ECA33A0E54761B747F0A98
          SHA-256:3DA98AA7D3085845779BE8ED6C93CCBDA92191F17CA67BBF779803E21DA2ABF3
          SHA-512:2652AFD1A3F8A4B84078A964005FE10C64491EC2D47CDE57D5066D07D1D837308FD696F53B9E7B6B0E72F86F9A85128B8CBF5F302F91EADE6D840DF946DE85CD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Dominica) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8600
          Entropy (8bit):3.8579895970456137
          Encrypted:false
          SSDEEP:
          MD5:EBD169ECA4D45EED28BF7B27809361BC
          SHA1:E89C8484A29D792FB6349CFDFDD30C2FA6B78B6B
          SHA-256:026D51D73D30A3710288F440E0C337E44E3A14D0AA2D7B6C6E53AF43FC72A90C
          SHA-512:45C936ED7D4AF95261180547013454AAEC9FA7672B52AC6077DD99D9FEB6DDD57652FE4EC67BF81F1588384F3027A1872E0C72D9CAEB980B66D2CB6EE9B8ABB0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Edmonton) {.. {-9223372036854775808 -27232 0 LMT}.. {-1998663968 -25200 0 MST}.. {-1632063600 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1600614000 -21600 1 MDT}.. {-1596816000 -25200 0 MST}.. {-1567954800 -21600 1 MDT}.. {-1551628800 -25200 0 MST}.. {-1536505200 -21600 1 MDT}.. {-1523203200 -25200 0 MST}.. {-1504450800 -21600 1 MDT}.. {-1491753600 -25200 0 MST}.. {-1473001200 -21600 1 MDT}.. {-1459699200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-715791600 -21600 1 MDT}.. {-702489600 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {136371600 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {167821200 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {23072
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1230
          Entropy (8bit):3.7989525000422963
          Encrypted:false
          SSDEEP:
          MD5:6766E75702D8C2D1C986DFCEFCE554F9
          SHA1:39553F80D82BC0134FAF70C9830B96BDCBCEFF1C
          SHA-256:48FC987E5999EA79F24797E0450FE4DAB7CF320DFAD7A47A8A1E037077EC42C9
          SHA-512:A812D0D4254BB0B7DB7AE116652D2A8F97D22C59F2709A17D1CE435FCFB38B807A4E0ED6EA114A66897E29D85226875FA84D28B254A5D17BD1CBA95FAD8349B7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Eirunepe) {.. {-9223372036854775808 -16768 0 LMT}.. {-1767208832 -18000 0 -05}.. {-1206950400 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1175367600 -14400 1 -05}.. {-1159819200 -18000 0 -05}.. {-633812400 -14400 1 -05}.. {-622062000 -18000 0 -05}.. {-602276400 -14400 1 -05}.. {-591825600 -18000 0 -05}.. {-570740400 -14400 1 -05}.. {-560203200 -18000 0 -05}.. {-539118000 -14400 1 -05}.. {-531345600 -18000 0 -05}.. {-191358000 -14400 1 -05}.. {-184190400 -18000 0 -05}.. {-155156400 -14400 1 -05}.. {-150062400 -18000 0 -05}.. {-128890800 -14400 1 -05}.. {-121118400 -18000 0 -05}.. {-99946800 -14400 1 -05}.. {-89582400 -18000 0 -05}.. {-68410800 -14400 1 -05}.. {-57960000 -18000 0 -05}.. {499755600 -14400 1 -05}.. {511243200 -18000 0 -05}.. {530600400 -14400 1 -05}.. {540273600 -18000 0 -05}.. {562136400 -14400 1 -05}.. {571204800
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):279
          Entropy (8bit):4.760311149376001
          Encrypted:false
          SSDEEP:
          MD5:CEF7277443EB6990E72C7EA7F79A122C
          SHA1:1D3FEA364B3DC129DE3998A1455D5588EBAA6FF8
          SHA-256:C02C6E79398553BD07BEA0BE4B7F0EBDD8BC821595909CFFB49DE4290A0D1D0F
          SHA-512:E6FC530B2CCF010B8D38BC3F49A6859B5C68F4AB604E6305CE75FBE4FC9FF3FCD0187DEBEF6DAE652EEF9695568DBDE31F426E404CC3CC206D78183E0D919234
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/El_Salvador) {.. {-9223372036854775808 -21408 0 LMT}.. {-1546279392 -21600 0 CST}.. {547020000 -18000 1 CDT}.. {559717200 -21600 0 CST}.. {578469600 -18000 1 CDT}.. {591166800 -21600 0 CST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.836337676384058
          Encrypted:false
          SSDEEP:
          MD5:005D9C0E50291616A727CFB74A9FD37E
          SHA1:846AE6720382B4F67B37B4256E45246C81DAF899
          SHA-256:3E363BF82545F24CCE8CFA6EEC97BA6E1C2A7730B2A9CE6C48F784821D308A5D
          SHA-512:452326D11D01825764BC40A77D17444D822F3AA202582233DD8B122798478FA83E3A27A02508EAC4CF0C7922AC2563742D773AA870562AE496B34FBB41FBAD63
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Tijuana)]} {.. LoadTimeZoneFile America/Tijuana..}..set TZData(:America/Ensenada) $TZData(:America/Tijuana)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4578
          Entropy (8bit):3.8944281193962818
          Encrypted:false
          SSDEEP:
          MD5:4A4E023F635C4202018EA9E8F85B5047
          SHA1:38E121FE2D419413E9E791B6C22BFC8D9F7554BC
          SHA-256:AB15023807E7C7D1026C9970D190F1B405D48952464025242C2BB6C6BBB8391A
          SHA-512:F10D21A2C841224879D1C817FC7F477DF582E1BC3603666B55199C098D51D1D5429F8C088C1083C07FC7588AE5C42A1DFBCC6B7C636AD1BE84ED657807A229E5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Fort_Nelson) {.. {-9223372036854775808 -29447 0 LMT}.. {-2713880953 -28800 0 PST}.. {-1632060000 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-725817600 -28800 0 PST}.. {-715788000 -25200 1 PDT}.. {-702486000 -28800 0 PST}.. {-684338400 -25200 1 PDT}.. {-671036400 -28800 0 PST}.. {-652888800 -25200 1 PDT}.. {-639586800 -28800 0 PST}.. {-620834400 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589384800 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557935200 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526485600 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495036000 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463586400 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431532000 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):231
          Entropy (8bit):4.778858143786314
          Encrypted:false
          SSDEEP:
          MD5:24C369A3091452DCA7AAEBF4F48F5289
          SHA1:2C2174CB16F490689E6FAC17B6D18F4A0DBD2DC9
          SHA-256:C8948616262CF6990739343ABBBD237E572DB49310099E21DD8F9E317F7D11B3
          SHA-512:80F579572754579706B4EEA49BF30456F3231A308E0616DC430E2428A04992412773421542E4F7FE4E4C7491BA88942FA44B49E87E95A2183211AC2AB523B231
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Indianapolis)]} {.. LoadTimeZoneFile America/Indiana/Indianapolis..}..set TZData(:America/Fort_Wayne) $TZData(:America/Indiana/Indianapolis)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1423
          Entropy (8bit):3.784027854102512
          Encrypted:false
          SSDEEP:
          MD5:E7939C9A3F83D73B82A6DE359365EFD4
          SHA1:06D6E257DA7C317CAFAF6C0B04567A2453CC1660
          SHA-256:C0A836BDAF07F0376B7B0833A0AB3D52BA6E3E1D6F95E247E1AD351CD1096066
          SHA-512:E2BEA04084489B26ADD9A768D2580C1FF7EBAC8A3EA36818F49E85FB14E01500D59D53904F5A17F4DABEF27B4CC2FC3F977EE4C125E5CE739BBE90C130ED3B07
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Fortaleza) {.. {-9223372036854775808 -9240 0 LMT}.. {-1767216360 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8372
          Entropy (8bit):3.8225708746657316
          Encrypted:false
          SSDEEP:
          MD5:1C8B0B85BB5578E84A4867546111F946
          SHA1:E08A96F5B369FA53BC1F3F839EC14FF9D334F727
          SHA-256:58C207CBD9DE7A7BB15E48A62CEA9F15DA184B945133DEE88EFF29FD8B66B29E
          SHA-512:54CFBF208AB3E58AFB6BEC40265A452A3C4C684D7F278F51D6495FCA544652A1A5E05BC45F600911191B33C936E5D7D43A28FD2B0884AAB9F63B7AD5EFD574A1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Glace_Bay) {.. {-9223372036854775808 -14388 0 LMT}.. {-2131646412 -14400 0 AST}.. {-1632074400 -10800 1 ADT}.. {-1615143600 -14400 0 AST}.. {-880221600 -10800 1 AWT}.. {-769395600 -10800 1 APT}.. {-765399600 -14400 0 AST}.. {-536443200 -14400 0 AST}.. {-526500000 -10800 1 ADT}.. {-513198000 -14400 0 AST}.. {-504907200 -14400 0 AST}.. {63086400 -14400 0 AST}.. {73461600 -10800 1 ADT}.. {89182800 -14400 0 AST}.. {104911200 -10800 1 ADT}.. {120632400 -14400 0 AST}.. {126244800 -14400 0 AST}.. {136360800 -10800 1 ADT}.. {152082000 -14400 0 AST}.. {167810400 -10800 1 ADT}.. {183531600 -14400 0 AST}.. {199260000 -10800 1 ADT}.. {215586000 -14400 0 AST}.. {230709600 -10800 1 ADT}.. {247035600 -14400 0 AST}.. {262764000 -10800 1 ADT}.. {278485200 -14400 0 AST}.. {294213600 -10800 1 ADT}.. {309934800 -14400 0 AST}.. {325663200 -10800 1 ADT}
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.973070790103308
          Encrypted:false
          SSDEEP:
          MD5:8263D2B39C2EC3B38A179F8BAD5972DD
          SHA1:18D3462F6846768E16036E860DE90FB345C93047
          SHA-256:5FB2CFBA25CE2F49D4C3911AFF8E7E1FF84EFC2D01F5783772E88246BFBC56AC
          SHA-512:C175CAF972459759553001D48921268E9C6268CED56021BA6339F8CE3DD032DA6180E2B82974D3DCD0DC5F21566DFDBFBE1B6CF24E5E893F2335A449452DB27F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Nuuk)]} {.. LoadTimeZoneFile America/Nuuk..}..set TZData(:America/Godthab) $TZData(:America/Nuuk)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):10353
          Entropy (8bit):3.864463676759425
          Encrypted:false
          SSDEEP:
          MD5:0D646C67105FD0525E7CCC79585CE9DF
          SHA1:06D91FDD8FEEDC299E40079569372F97A9AC6F04
          SHA-256:52D2478289682BF95BFB93D64D679E888C9D23C0F68DFFF7E6E34BFC44B3D892
          SHA-512:FD672613C2B65E12425415630A2F489917EB80DDED41338C9AA7D5D3C6B54E52C516A32493593F518DACF22A91D7A9D2C96DB9C5F1BE2C3BB9842D274BDC04FF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Goose_Bay) {.. {-9223372036854775808 -14500 0 LMT}.. {-2713895900 -12652 0 NST}.. {-1640982548 -12652 0 NST}.. {-1632076148 -9052 1 NDT}.. {-1615145348 -12652 0 NST}.. {-1609446548 -12652 0 NST}.. {-1096921748 -12600 0 NST}.. {-1072989000 -12600 0 NST}.. {-1061670600 -9000 1 NDT}.. {-1048973400 -12600 0 NST}.. {-1030221000 -9000 1 NDT}.. {-1017523800 -12600 0 NST}.. {-998771400 -9000 1 NDT}.. {-986074200 -12600 0 NST}.. {-966717000 -9000 1 NDT}.. {-954624600 -12600 0 NST}.. {-935267400 -9000 1 NDT}.. {-922570200 -12600 0 NST}.. {-903817800 -9000 1 NDT}.. {-891120600 -12600 0 NST}.. {-872368200 -9000 0 NWT}.. {-769395600 -9000 1 NPT}.. {-765401400 -12600 0 NST}.. {-757369800 -12600 0 NST}.. {-746044200 -9000 1 NDT}.. {-733347000 -12600 0 NST}.. {-714594600 -9000 1 NDT}.. {-701897400 -12600 0 NST}.. {-683145000 -9000 1 NDT}.. {-67044
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7522
          Entropy (8bit):3.84007813579738
          Encrypted:false
          SSDEEP:
          MD5:A17723CE27EC99D1506C45AB1531085B
          SHA1:A83ED7BD09514A829CC8F2EA47BA113F5DCA1090
          SHA-256:560B39485CED4C2A0E85A66EB875331E5879104187D92CB7F05C2F635E34AC99
          SHA-512:110D1253D6915DB046247E4FD3BA9B881146BC3896DE779215E0CC6D1DCC59958C355441955509F5D38E3A3BA166DFD0F2F277000E9E89D6551FBEA0C16974B9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Grand_Turk) {.. {-9223372036854775808 -17072 0 LMT}.. {-2524504528 -18430 0 KMT}.. {-1827687170 -18000 0 EST}.. {284014800 -18000 0 EST}.. {294217200 -14400 1 EDT}.. {309938400 -18000 0 EST}.. {325666800 -14400 1 EDT}.. {341388000 -18000 0 EST}.. {357116400 -14400 1 EDT}.. {372837600 -18000 0 EST}.. {388566000 -14400 1 EDT}.. {404892000 -18000 0 EST}.. {420015600 -14400 1 EDT}.. {436341600 -18000 0 EST}.. {452070000 -14400 1 EDT}.. {467791200 -18000 0 EST}.. {483519600 -14400 1 EDT}.. {499240800 -18000 0 EST}.. {514969200 -14400 1 EDT}.. {530690400 -18000 0 EST}.. {544604400 -14400 1 EDT}.. {562140000 -18000 0 EST}.. {576054000 -14400 1 EDT}.. {594194400 -18000 0 EST}.. {607503600 -14400 1 EDT}.. {625644000 -18000 0 EST}.. {638953200 -14400 1 EDT}.. {657093600 -18000 0 EST}.. {671007600 -14400 1 EDT}.. {688543200 -18000 0 EST}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):201
          Entropy (8bit):4.892013473075135
          Encrypted:false
          SSDEEP:
          MD5:4B9ABEA103F55509550F8B42D88E84B7
          SHA1:E3AA1BCE5E260264E74F77E59C4071B7E496AB41
          SHA-256:EBED070E8E67C5F12FF6E03FE508BE90789F17C793DFE61237B4045B8222580F
          SHA-512:568E375464FF264C5048CB35995945BDE1D5BCC3A108B2A4D0F8389EBF18B4C58EBB1C2122F10BA777D512504A59C7EFDF6069EABD2A5DEA3189204B7F7A6EB4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Grenada) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):204
          Entropy (8bit):4.9138787435596765
          Encrypted:false
          SSDEEP:
          MD5:92B091A06198E233B73DF12DFCD818D5
          SHA1:C529488D09F86755E4F22CB4F0E3013C3A1B978D
          SHA-256:6CB1930532831D12057FCB484C60DB64A60A4F6D8195DAFD464826923116A294
          SHA-512:55EAE03CDECAC43BEDD3AA1A32C632A46808F29FF4D97A330F818544E4D10B9E9BA909D6627C38065EB7AC8E2C395FA37797F532CCFC8AB89D4698CCDE17F985
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Guadeloupe) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):399
          Entropy (8bit):4.513185345162455
          Encrypted:false
          SSDEEP:
          MD5:569CDE7CE1AB84C0F16A25E85A418334
          SHA1:EADE79AB6EDD98C7FE8B10B480C5C530CA014F5C
          SHA-256:14F6A98D602F3648C816B110F3A0BA375E1FFE8FA06BEEAB419DC1ABFA6EDCAF
          SHA-512:AE2ACBF09EED857906811BE2984D6BF92BF2955A9FE2F9F3FFEBB6790902F5C2C870F8561CA13AD9CB7826EECA434BED7CFE7D0D2739996BACEE506D0EB730DC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guatemala) {.. {-9223372036854775808 -21724 0 LMT}.. {-1617040676 -21600 0 CST}.. {123055200 -18000 1 CDT}.. {130914000 -21600 0 CST}.. {422344800 -18000 1 CDT}.. {433054800 -21600 0 CST}.. {669708000 -18000 1 CDT}.. {684219600 -21600 0 CST}.. {1146376800 -18000 1 CDT}.. {1159678800 -21600 0 CST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):249
          Entropy (8bit):4.745656594295655
          Encrypted:false
          SSDEEP:
          MD5:DF661E312C6CE279CD6829120BE33CF2
          SHA1:4ACDB31E27EF9175C5452BF95F94F9BC280A237F
          SHA-256:6806AA5814BDC679C6EF653C518D2699114BE71D973F49C0864F622038DC2048
          SHA-512:04E7FD01F4DAD981EE8A02487F4A889015C41D07D6DCF420183D387E2188FF3239E345B5D65FB195CA485F5C7B4AD8CFEF51FFFC11EE0C91F0C88FF7B7EF17C1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guayaquil) {.. {-9223372036854775808 -19160 0 LMT}.. {-2524502440 -18840 0 QMT}.. {-1230749160 -18000 0 -05}.. {722926800 -14400 1 -05}.. {728884800 -18000 0 -05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):248
          Entropy (8bit):4.673559445766137
          Encrypted:false
          SSDEEP:
          MD5:F06C226D8D53EF8859AD91D7EBA5959C
          SHA1:E0B4E6F4ADCB10F1D79FFD928E8684FFE0C0DC5F
          SHA-256:4078D2E361D04A66F22F652E3810CDF7F630CF89399B47E4EC7B1D32B400FD85
          SHA-512:B4385650A0C69B7BD66415CC4BB9FCA854DBB1427E9F2D6C1D8CDB8CCEF9ECBD699C66A83A9AC289DABC5CDBB0A2B044E4097E9A2977AE1802B3BF6E2BB518CF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guyana) {.. {-9223372036854775808 -13959 0 LMT}.. {-1843589241 -14400 0 -04}.. {-1730577600 -13500 0 -0345}.. {176096700 -10800 0 -03}.. {701841600 -14400 0 -04}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):11124
          Entropy (8bit):3.8106487461849885
          Encrypted:false
          SSDEEP:
          MD5:6FB9E47841FF397CE36A36C8280E2089
          SHA1:DA210300DC3D94FC3D8BA0A4531341BCA5C5936C
          SHA-256:01E11C7B07925D05E9E1876C310A2B87E0E80EF115D062225212E472B7A964F1
          SHA-512:F61B5A8A7532BBD54A4976DF17A1C6CF51BCC6DC396482FBE169C3081AF27B6CA863F0CDE3E483C59F5A5BD3365592F6984A97173C736B41D3CEEDAD4263A4E5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Halifax) {.. {-9223372036854775808 -15264 0 LMT}.. {-2131645536 -14400 0 AST}.. {-1696276800 -10800 1 ADT}.. {-1680469200 -14400 0 AST}.. {-1640980800 -14400 0 AST}.. {-1632074400 -10800 1 ADT}.. {-1615143600 -14400 0 AST}.. {-1609444800 -14400 0 AST}.. {-1566763200 -10800 1 ADT}.. {-1557090000 -14400 0 AST}.. {-1535486400 -10800 1 ADT}.. {-1524949200 -14400 0 AST}.. {-1504468800 -10800 1 ADT}.. {-1493413200 -14400 0 AST}.. {-1472414400 -10800 1 ADT}.. {-1461963600 -14400 0 AST}.. {-1440964800 -10800 1 ADT}.. {-1429390800 -14400 0 AST}.. {-1409515200 -10800 1 ADT}.. {-1396731600 -14400 0 AST}.. {-1376856000 -10800 1 ADT}.. {-1366491600 -14400 0 AST}.. {-1346616000 -10800 1 ADT}.. {-1333832400 -14400 0 AST}.. {-1313956800 -10800 1 ADT}.. {-1303678800 -14400 0 AST}.. {-1282507200 -10800 1 ADT}.. {-1272661200 -14400 0 AST}.. {-1251057600
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8729
          Entropy (8bit):3.8227313494100867
          Encrypted:false
          SSDEEP:
          MD5:564980AECB32F5778422EA15E8956879
          SHA1:545209C95043721C1839CCE5FEFD1A6F2DE3FE5F
          SHA-256:96B62BFBF0C05CF970245597C691F89EBF631175796459642A85287F131D0215
          SHA-512:25FE5DAA55E3466EAE1CDC73918F189403C3360D4E82D72D745FA04A374DE04F479AA9811D6154FC70CC8EA620F18035EA6A3074116806D4405936FA017CE8E6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Havana) {.. {-9223372036854775808 -19768 0 LMT}.. {-2524501832 -19776 0 HMT}.. {-1402813824 -18000 0 CST}.. {-1311534000 -14400 1 CDT}.. {-1300996800 -18000 0 CST}.. {-933534000 -14400 1 CDT}.. {-925675200 -18000 0 CST}.. {-902084400 -14400 1 CDT}.. {-893620800 -18000 0 CST}.. {-870030000 -14400 1 CDT}.. {-862171200 -18000 0 CST}.. {-775681200 -14400 1 CDT}.. {-767822400 -18000 0 CST}.. {-744231600 -14400 1 CDT}.. {-736372800 -18000 0 CST}.. {-144702000 -14400 1 CDT}.. {-134251200 -18000 0 CST}.. {-113425200 -14400 1 CDT}.. {-102542400 -18000 0 CST}.. {-86295600 -14400 1 CDT}.. {-72907200 -18000 0 CST}.. {-54154800 -14400 1 CDT}.. {-41457600 -18000 0 CST}.. {-21495600 -14400 1 CDT}.. {-5774400 -18000 0 CST}.. {9954000 -14400 1 CDT}.. {25675200 -18000 0 CST}.. {41403600 -14400 1 CDT}.. {57729600 -18000 0 CST}.. {73458000 -14400 1 CD
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):616
          Entropy (8bit):4.351214377567366
          Encrypted:false
          SSDEEP:
          MD5:E35A6C6E9DCF0CA34BFA2993CE445D6C
          SHA1:4FF9C7EDBC73B1AE0815661571B7199379AF479C
          SHA-256:C0A87DC3A474D25083F0CEA0C323D8E780D937453CAD23C98AF367D81AC2CA2D
          SHA-512:56A728ABCD3EA91D2492E1331B3F76F31EF5675BCD95A692F9D94F91518B72569FD8DF1BB0515668E8A9BE0347018B391C65761D316903CA27C59883BBE0DE80
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Hermosillo) {.. {-9223372036854775808 -26632 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-873828000 -25200 0 MST}.. {-661539600 -28800 0 PST}.. {28800 -25200 0 MST}.. {828867600 -21600 1 MDT}.. {846403200 -25200 0 MST}.. {860317200 -21600 1 MDT}.. {877852800 -25200 0 MST}.. {891766800 -21600 1 MDT}.. {909302400 -25200 0 MST}.. {915174000 -25200 0 MST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7230
          Entropy (8bit):3.882344472808608
          Encrypted:false
          SSDEEP:
          MD5:7824B3F2D20F16A9DCC8E0F7DC45C1B8
          SHA1:77014A0502DA1342EFA41B64C5613839B627354B
          SHA-256:4B114545167326F066AB3A798180896B43AC6FDC3B80D32BCC917B5A4A2359EB
          SHA-512:03F6A18C03E79E9177D16CD7AB75AC117197638370FA675BC2854A5A563021F865F3F0672B237B83098787AB9D419AC33D67F28324B1E25AD8560B5838F70807
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Indianapolis) {.. {-9223372036854775808 -20678 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-1577901600 -21600 0 CST}.. {-900259200 -18000 1 CDT}.. {-891795600 -21600 0 CST}.. {-883591200 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8755
          Entropy (8bit):3.8394539560522585
          Encrypted:false
          SSDEEP:
          MD5:8AF080A022DA0737E94742C50EAAC62E
          SHA1:704F0565B53AA8A20F70B79A7958D4D07085E07A
          SHA-256:F1253F5F3F5AACD1A5E1F4636DD4E083F4B2A8BD995CF3E684CDD384641849F1
          SHA-512:26AAF6D24B2E2B60451E19A514533DFAEC74F01F9B1AEB9F86690669C14130D77AE1CBFB9FC9091E1CD1FC1CBC2799BB05026DB68768C3CCB960355C18D111ED
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Knox) {.. {-9223372036854775808 -20790 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-725824800 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000 1 CDT}.. {-447267600 -21600 0 CST}.. {-431539200 -18000 1 CDT}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7273
          Entropy (8bit):3.8700915866109535
          Encrypted:false
          SSDEEP:
          MD5:C1A10440E6CCE4C5052E2510182D9AA7
          SHA1:56D4F3CCA1245D626BADA74CF3F6BAE8034BF58D
          SHA-256:675162381639598E7100E90663D42780F8EE1CB62BD6DA5B948B494F98C02FE3
          SHA-512:96B71472AD38ECFC589F935D9F5F1C8D42C8E942D8772FB6A77F9B9C0E2BD7A07FA61729E57EC02356121518E33797A784679F8DED2FCA3FC79F5C114783DD57
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Marengo) {.. {-9223372036854775808 -20723 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-599594400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 0 EST}.. {-31518000 -18000 0 EST}.. {-21488400 -14400 1 EDT}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7611
          Entropy (8bit):3.87971256165061
          Encrypted:false
          SSDEEP:
          MD5:A86042668CD478AFFC05D3383EDEE8FF
          SHA1:6476526F94A247C0ECF3B2813F2C5A4FB93E457E
          SHA-256:23B8FA75CE0A9555DFD84549723A12679FF7FC5FAA58E4B745BA3C547071FF53
          SHA-512:07A5487A087108E6D6E88580865885CA6243EF04BE8263FC913F38CADB8EA016386E8BBAD39F65FD081F1A2F14316FEAF008855E9CF2019B169D9511916AFF67
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Petersburg) {.. {-9223372036854775808 -20947 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-473364000 -21600 0 CST}.. {-462996000 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 1 CDT}.. {-257965200 -21600 0 CST}.. {-242236800 -18000 1 CDT}.. {-226515600 -21600 0 CST}.. {-210787200 -18000 1 CDT}.. {-195066000 -21600 0 CST}.. {-179337600 -18000 1 CD
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7100
          Entropy (8bit):3.8613085681914607
          Encrypted:false
          SSDEEP:
          MD5:E7FE9B7CFBC6505C446056967DEBC87B
          SHA1:81ADAD89F040F62E87D2F26D1D98B3E52710F695
          SHA-256:D368123DB703B55244700876906775837D408C274C5A5801D80B77EADB6D5853
          SHA-512:9C0746DE18C80B548AA443D59BB9971BDC304975717C5FCDEBDE72828ACF408FA1D687F87C42E7B8D6D0284C9F792EA236BF79C815947BE773D07364B630AC99
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Tell_City) {.. {-9223372036854775808 -20823 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-462996000 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 1 CDT}.. {-257965200 -21600 0 CST}.. {-242236800 -18000 1 CDT}.. {-226515600 -21600 0 CST}.. {-210787200 -18000 1 CDT}.. {-195066000 -21600 0 CST}.. {-179337600 -18000 0 EST
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.7511104559982
          Encrypted:false
          SSDEEP:
          MD5:7A2AD9BD8F8DEE5C600CABF2D5E9D07B
          SHA1:CF5D230A29946B7FA3ECD8EB99F1EF1BF0FA5B50
          SHA-256:ACA533B8BC82296373EDEC82F6E0AA45A34D817C7C18FF5E8E94B81C0BD30259
          SHA-512:95F8FA68735E88AB15C403191928FA4AA5D1628453BE64B87EE7E8DF9F35FB5DA74A3CED5F5289A13D84A8A12BBB86734E578059CA8B6405399CFF5E33C9384C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Mawson) {.. {-9223372036854775808 0 0 -00}.. {-501206400 21600 0 +06}.. {1255809600 18000 0 +05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):195
          Entropy (8bit):4.880387042335617
          Encrypted:false
          SSDEEP:
          MD5:88EE32AE5C538AEBFDE2D1D944ED5B2B
          SHA1:55E7234E6FFF298182A6C8889A9F506CDCE7C959
          SHA-256:E9D99293C5B275D8E0D7B066084177EDF670D5B52B81E87608BAB02025F33155
          SHA-512:45A3EA146CA719BA6F22E99EAA57AC1DED1C762E19BDFBA176E5FEAC36EC58586F771572DD16ACE09E660F97DEB91A701BA1B1F1AEF3BD8688F3451C0772420A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:Antarctica/McMurdo) $TZData(:Pacific/Auckland)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2613
          Entropy (8bit):3.6082359166067905
          Encrypted:false
          SSDEEP:
          MD5:BDFA5908E735F866FEC16F6B481AD385
          SHA1:524AEE21BB97D923A8812A5722AF2FEA43B4D971
          SHA-256:1637381A20E9D5C6A530F110BDB08D9515E675C9206F000407D8511074948E61
          SHA-512:3D65C7941BA15A698264848F9B6F43ED5B63D4CF86D495334E8E1DC381D63435E9424BBBC389229693D20044FDB8425A7CC805AB5EA055F59D3E0DD4C7AC2A28
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Palmer) {.. {-9223372036854775808 0 0 -00}.. {-157766400 -14400 0 -04}.. {-152654400 -14400 0 -04}.. {-132955200 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-101419200 -10800 1 -04}.. {-86821200 -14400 0 -04}.. {-71092800 -10800 1 -04}.. {-54766800 -14400 0 -04}.. {-39038400 -10800 1 -04}.. {-23317200 -14400 0 -04}.. {-7588800 -10800 0 -03}.. {128142000 -7200 1 -03}.. {136605600 -10800 0 -03}.. {389070000 -14400 0 -04}.. {403070400 -10800 1 -04}.. {416372400 -14400 0 -04}.. {434520000 -10800 1 -04}.. {447822000 -14400 0 -04}.. {466574400 -10800 1 -04}.. {479271600 -14400 0 -04}.. {498024000 -10800 1 -04}.. {510721200 -14400 0 -04}.. {529473600 -10800 1 -04}.. {545194800 -14400 0 -04}.. {560923200 -10800 1 -04}.. {574225200 -14400 0 -04}.. {592372800 -10800 1 -04}.. {605674800 -14400 0 -04}.. {624427200 -10800 1 -04}.. {63712
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):151
          Entropy (8bit):4.829975802206526
          Encrypted:false
          SSDEEP:
          MD5:C330982049AA053DA62B926627D2F2FA
          SHA1:050CE68265F1A183F0173C825AC59EAE8B6AB9EB
          SHA-256:943F10D8E836773F0B7ACD13ED8422C0B27813C7BBE0B09B57697D1D70D21ECE
          SHA-512:DE9953D0E505D6B110C0CC4E756B5B0311646C9CA4703A33B92147D36CFB4C288D73851E6766CE1432F41AB51B5D0A1D58680BDB4E28F067E1D36F670B4A192E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Rothera) {.. {-9223372036854775808 0 0 -00}.. {218246400 -10800 0 -03}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):198
          Entropy (8bit):4.906125935761354
          Encrypted:false
          SSDEEP:
          MD5:8095A3749DBDE05377836D74A4EEFE33
          SHA1:6987CA972B63AE26A65654961588D51D3EF2166C
          SHA-256:88057832175BB642B23FC99F788A2F78A24005CF1F84A7B1B5E8C84FB8F4D4C1
          SHA-512:9066104C9C16D2AB88523D651C74CE268468E093A497D128D0D12A986BD62DBC1388A56ED1737C2AFACF04185CF06FD0EE66797A3390B2F0E1EB08A4D92AAFAD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:Antarctica/South_Pole) $TZData(:Pacific/Auckland)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.871844665431957
          Encrypted:false
          SSDEEP:
          MD5:CA52057130DCF506D11A7CC069F4FBA3
          SHA1:2C38B7E7872BB41C3569DFCB539C3EC3AAE24FDD
          SHA-256:2488805DE4FEA42305689F679F1AE2D80B1E934E657FEA329AD39A82DAC63022
          SHA-512:B19D409870939C8F0834C6C028239E010EE5128DFA6E97D4903BECA229B04FE530EA376B936767D9BFE21709720C1791289D8E3622B17C18F2680B0670794A02
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Antarctica/Syowa) $TZData(:Asia/Riyadh)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5370
          Entropy (8bit):3.5134546899897146
          Encrypted:false
          SSDEEP:
          MD5:442F495C36B31CA5D7A9BEFF12105AEF
          SHA1:B3F6CA5B4A5756F9B2C09A27198F7A651CC6032D
          SHA-256:6FD5AB8B7B308CDCEA4B747A81D8675988AE218813C91714FC4CA97919CEBEA5
          SHA-512:C6EAECC26D67D218615EBB5602639DAB62A2578BD9683553D765DC1AC5580627D29B6F911388F5F1BFC284278EA4EBECE94630D3C6B95FF9EF93D3D61A3C2028
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Troll) {.. {-9223372036854775808 0 0 -00}.. {1108166400 0 0 +00}.. {1111885200 7200 1 +02}.. {1130634000 0 0 +00}.. {1143334800 7200 1 +02}.. {1162083600 0 0 +00}.. {1174784400 7200 1 +02}.. {1193533200 0 0 +00}.. {1206838800 7200 1 +02}.. {1224982800 0 0 +00}.. {1238288400 7200 1 +02}.. {1256432400 0 0 +00}.. {1269738000 7200 1 +02}.. {1288486800 0 0 +00}.. {1301187600 7200 1 +02}.. {1319936400 0 0 +00}.. {1332637200 7200 1 +02}.. {1351386000 0 0 +00}.. {1364691600 7200 1 +02}.. {1382835600 0 0 +00}.. {1396141200 7200 1 +02}.. {1414285200 0 0 +00}.. {1427590800 7200 1 +02}.. {1445734800 0 0 +00}.. {1459040400 7200 1 +02}.. {1477789200 0 0 +00}.. {1490490000 7200 1 +02}.. {1509238800 0 0 +00}.. {1521939600 7200 1 +02}.. {1540688400 0 0 +00}.. {1553994000 7200 1 +02}.. {1572138000 0 0 +00}.. {1585443600 7200 1 +02}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.940298769001579
          Encrypted:false
          SSDEEP:
          MD5:F61B4D02530B54A8EB1CA7B34BF6D553
          SHA1:EB85E044EF9F7D11310C5EBB8D1D0C49A1E3067F
          SHA-256:1892E98C13AC141C8C92EAB942B073A464BA5E2C000C250F97F860BE6B108127
          SHA-512:E725E909A4056B7E4FADBE66B69E6C4752595F3357E670A7D740A2DA957F2C9502ECA57B9BA874045ED032B8F65A10D11AFAF69EA9673187FD4AE08793492470
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Urumqi)]} {.. LoadTimeZoneFile Asia/Urumqi..}..set TZData(:Antarctica/Vostok) $TZData(:Asia/Urumqi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):187
          Entropy (8bit):4.947168975083595
          Encrypted:false
          SSDEEP:
          MD5:A4F076D7D716467B78EA382FA222CB38
          SHA1:21D7FBA308ADC652F541A0336929B862F7B1BD0B
          SHA-256:25462B656D240DA6B01C1A630FAC04B25DD65C799B659BE1C8BD3AB62610966F
          SHA-512:1B6BD455E533D5BDC7F3506561A9CA804B1F9CA5CC0665AAB0FC083106AB32FF149DD5FFF62EF7BABAD87E3274F264446D492FB8BE160C9C7F281C7060BF1F61
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Arctic/Longyearbyen) $TZData(:Europe/Berlin)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):171
          Entropy (8bit):4.829666491766117
          Encrypted:false
          SSDEEP:
          MD5:60D7F3194F19179E0CF0F561F9C40EE6
          SHA1:B079EC49485CFBFFB7A5BE6149319B75684258E9
          SHA-256:8FCDDB246932BAED880B70C0CA867057E7989AEA55EDDC174430E1055CD1058D
          SHA-512:0BDC86B1D473D4875C6F7C092F955D0999E6C1F2EF83CFC7726A3C5BFEB0F5CB8E00B1F0CBC1F91F806EC635C472927504DF681A32DAC55EF372DA16FEA9EF40
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Asia/Aden) $TZData(:Asia/Riyadh)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1637
          Entropy (8bit):3.732051305399264
          Encrypted:false
          SSDEEP:
          MD5:D6BCB21F65642F36A159AFD72EC93953
          SHA1:D3E670E579924E6E4F04AB574D48334FF521D8B2
          SHA-256:06DC608C0B8CDD69CCE66A6BF86F141C46DF39CB45312E684E46F19ED8CAFF15
          SHA-512:9A633B629873E5EE5AF923A94865EBE5FD9ECA181B2C47B7368A0828468715E07AD3FD825D5E2312D2D0BA1FA5490E3817C36B6339824C8012A0B75538C4A0DC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Almaty) {.. {-9223372036854775808 18468 0 LMT}.. {-1441170468 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {695768400 21600 0 +06}.. {701812800 25200 1 +06}.. {717537600 21600 0 +06}.. {733262400 25200 1 +06}.. {748987200 21600 0 +06}.. {764712
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2682
          Entropy (8bit):3.7873260611521915
          Encrypted:false
          SSDEEP:
          MD5:7E70BD44FBF5BF70E3C5246D3A83A49B
          SHA1:10A28B0A3189DF347CF9853C024E9467CAC56DBA
          SHA-256:B70AABECACD3F62AF506DF395AB44F47F2CA091522B04EC87AC1407172DD1BFA
          SHA-512:766565F837EB777749B2C8AAE6C73A2274A772CEF12E7C2E30A89809FEF1E9ED6B067DF044A4676AA4BE76A64A904692C3887336BF01BA4D5D9A5020FB792938
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Amman) {.. {-9223372036854775808 8624 0 LMT}.. {-1230776624 7200 0 EET}.. {108165600 10800 1 EEST}.. {118270800 7200 0 EET}.. {136591200 10800 1 EEST}.. {149806800 7200 0 EET}.. {168127200 10800 1 EEST}.. {181342800 7200 0 EET}.. {199749600 10800 1 EEST}.. {215643600 7200 0 EET}.. {231285600 10800 1 EEST}.. {244501200 7200 0 EET}.. {262735200 10800 1 EEST}.. {275950800 7200 0 EET}.. {481154400 10800 1 EEST}.. {496962000 7200 0 EET}.. {512949600 10800 1 EEST}.. {528670800 7200 0 EET}.. {544399200 10800 1 EEST}.. {560120400 7200 0 EET}.. {575848800 10800 1 EEST}.. {592174800 7200 0 EET}.. {610581600 10800 1 EEST}.. {623624400 7200 0 EET}.. {641167200 10800 1 EEST}.. {655074000 7200 0 EET}.. {671839200 10800 1 EEST}.. {685918800 7200 0 EET}.. {702856800 10800 1 EEST}.. {717973200 7200 0 EET}.. {733701600 10800 1 EEST}.. {749422800
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2086
          Entropy (8bit):3.7698340044911616
          Encrypted:false
          SSDEEP:
          MD5:6EFC35043BDCA4AB61D72E931DB954E6
          SHA1:F0B4E76C154DC773073E41AA8E94030E972A986A
          SHA-256:D9DF64FDA4638F7604624B0F68A885D5ABADB1DE12AF1AF5581C2AF7DD971562
          SHA-512:16AE582B113D6960C73B64620A8AF20F9D436AA4B3EC8E881617AED3389EB4357931882103F162F19EE8202953A7E6FB4FDD6D7760FB7621F4DB9D229AD13F17
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Anadyr) {.. {-9223372036854775808 42596 0 LMT}.. {-1441194596 43200 0 +12}.. {-1247572800 46800 0 +14}.. {354884400 50400 1 +14}.. {370692000 46800 0 +13}.. {386420400 43200 0 +13}.. {386424000 46800 1 +13}.. {402231600 43200 0 +12}.. {417960000 46800 1 +13}.. {433767600 43200 0 +12}.. {449582400 46800 1 +13}.. {465314400 43200 0 +12}.. {481039200 46800 1 +13}.. {496764000 43200 0 +12}.. {512488800 46800 1 +13}.. {528213600 43200 0 +12}.. {543938400 46800 1 +13}.. {559663200 43200 0 +12}.. {575388000 46800 1 +13}.. {591112800 43200 0 +12}.. {606837600 46800 1 +13}.. {622562400 43200 0 +12}.. {638287200 46800 1 +13}.. {654616800 43200 0 +12}.. {670341600 39600 0 +12}.. {670345200 43200 1 +12}.. {686070000 39600 0 +11}.. {695746800 43200 0 +13}.. {701791200 46800 1 +13}.. {717516000 43200 0 +12}.. {733240800 46800 1 +13}.. {748965
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1665
          Entropy (8bit):3.7149890651919644
          Encrypted:false
          SSDEEP:
          MD5:A72FB1FE01C93BD7E0A8136635C72639
          SHA1:2383CF839F50784D4BF8B7EDDB324C80E2DDD0DC
          SHA-256:96B510AF9B8C6BC1DFA84E9ED5E072F3FD484EEB66BBEBC7B6826ED859ED9027
          SHA-512:061FECE3C750C0229638DD8AF38FB3E8E48E59E0DE1B13BCFE46483A7A170B71B9BCB0D6F110B6B2EF68510FA940F9066F14CBD59829E222D6644D3657CE1893
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Aqtau) {.. {-9223372036854775808 12064 0 LMT}.. {-1441164064 14400 0 +04}.. {-1247544000 18000 0 +05}.. {370724400 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {7647156
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1666
          Entropy (8bit):3.721746335201775
          Encrypted:false
          SSDEEP:
          MD5:E278B985BD2515DBCAED8CB741BE9208
          SHA1:BC9F5E72C430661D7ED1AF04571CE5D0F73DD18D
          SHA-256:991638FA2AB2A2F7A091A23D78D99306EE73A740F1A03FBAC448EDCAB55A0E38
          SHA-512:9951DB729B837647CC4B3D2E605525DCCBAFFD39D76460331BF62235DCAE5E4470CDA578F940B1739AABFEC55D293FF60D79AE0EFDFE1EB64E84571881FDEA6A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Aqtobe) {.. {-9223372036854775808 13720 0 LMT}.. {-1441165720 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):878
          Entropy (8bit):3.937249024843323
          Encrypted:false
          SSDEEP:
          MD5:259179C7A1CA04F9F3A373B6C8FCB8C5
          SHA1:D042DF8EFD8EC1473B45B1131BD5EB714F1B2C17
          SHA-256:13745BFA25E6E2D8D0FABAE42CB7C37CF9F974CFB343D4FE84E4E2D64A25926B
          SHA-512:703BEAD5A1E5B3816D98057A08A87C2139F418787F38561FE35175B84E2005365727F85D1B949CC5DF464B207A7D01BB65FB1A632E73DDA523E843B82D76FBBD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ashgabat) {.. {-9223372036854775808 14012 0 LMT}.. {-1441166012 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +05}.. {370720800 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.801820439218014
          Encrypted:false
          SSDEEP:
          MD5:5193EF7ADB646798801245BC50C8DDA6
          SHA1:83ED851CBC60EFB330A8FC119E1BED5B4C0BA630
          SHA-256:2C752F641B98E3C05B14AE31330D1F198DAA4A7E354BA9670C7754926BFB891A
          SHA-512:E940E1BE67A9AC895F3D060B1CB34797A429147A9DC2AC0F1162D37D86661EF217EDABA720F0AE3796186FE801229210AC785BB4511CBBE5A41791D236101D8C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ashgabat)]} {.. LoadTimeZoneFile Asia/Ashgabat..}..set TZData(:Asia/Ashkhabad) $TZData(:Asia/Ashgabat)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1666
          Entropy (8bit):3.7265766742957402
          Encrypted:false
          SSDEEP:
          MD5:0236793F90ABC6F68718DDBB44AF5E2F
          SHA1:A5EFAEEF9B9159E748A3FED231F8A978E400482E
          SHA-256:4B7B118E6AE72D41740CF0CB2BD8E970700758DCBC0DD6F298199D841DF8408E
          SHA-512:851C7A9C110790454312BB9C5B5D3C426365EEF4673191B9ABB2E4A32301894C5FB1ADCBE2A4C67BEE416AD63FB8BED85F94EF9BF42473DA4BFFA7824935A1D5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Atyrau) {.. {-9223372036854775808 12464 0 LMT}.. {-1441164464 10800 0 +03}.. {-1247540400 18000 0 +05}.. {370724400 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {764715
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1702
          Entropy (8bit):3.7261419515679393
          Encrypted:false
          SSDEEP:
          MD5:690013310A46BD1AE250A5E019353809
          SHA1:0DF434C7EEB707DC071007FAB112F4DEB37E936F
          SHA-256:D20B75D2604C3B742C1629C5EE02CFF6783E472249982B272B68F2A6DE9BDC38
          SHA-512:FF8C33E55E4F006C38D3FD37A1AD3E1200718CA374ECBEAE8255C7635912F0BB23A59A600BF7130D5660A24C515F726E8440D0D908E560CB59F74059638E6AA2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Baghdad) {.. {-9223372036854775808 10660 0 LMT}.. {-2524532260 10656 0 BMT}.. {-1641005856 10800 0 +03}.. {389048400 14400 0 +03}.. {402264000 10800 0 +03}.. {417906000 14400 1 +03}.. {433800000 10800 0 +03}.. {449614800 14400 1 +03}.. {465422400 10800 0 +03}.. {481150800 14400 1 +03}.. {496792800 10800 0 +03}.. {512517600 14400 1 +03}.. {528242400 10800 0 +03}.. {543967200 14400 1 +03}.. {559692000 10800 0 +03}.. {575416800 14400 1 +03}.. {591141600 10800 0 +03}.. {606866400 14400 1 +03}.. {622591200 10800 0 +03}.. {638316000 14400 1 +03}.. {654645600 10800 0 +03}.. {670464000 14400 1 +03}.. {686275200 10800 0 +03}.. {702086400 14400 1 +03}.. {717897600 10800 0 +03}.. {733622400 14400 1 +03}.. {749433600 10800 0 +03}.. {765158400 14400 1 +03}.. {780969600 10800 0 +03}.. {796694400 14400 1 +03}.. {812505600 10800 0 +03}.. {82831
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):171
          Entropy (8bit):4.784355129067593
          Encrypted:false
          SSDEEP:
          MD5:1B5E0D449DAEF469D586A853CB3073AD
          SHA1:FD735B0472B31644E787767B82B737CC39EC4175
          SHA-256:3D437037FBF2BBDF969C8E71967080947F24860D431B39F5D8F23151316ABCD5
          SHA-512:2A2DC33D4258A5E1AE59172883F3B11723798ED35CF5AF1B8BA81A8807DC6F8222C8044D82B152EF6AF43E7350FEB2625D4406C6C7DD309CE65810EA3D3286B6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Qatar)]} {.. LoadTimeZoneFile Asia/Qatar..}..set TZData(:Asia/Bahrain) $TZData(:Asia/Qatar)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2149
          Entropy (8bit):3.6155622322573713
          Encrypted:false
          SSDEEP:
          MD5:294DFC98F67AC00A188EC3D3B87C501C
          SHA1:93C434CD9AA170E35AD676C88EE09986A94EC02A
          SHA-256:873E8F08B87610D0DAFE239D32345248A4595C6B13D1DA83EC214D78E88FA12C
          SHA-512:5346082CCA733724C0D2C36B768467E59BA9ED6452B6CF1BA923AF4F0D2BC05C67DB49E804CA81DAD449D30D0835026D708D9AB632D02FDA1EA1A0BF717111DE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Baku) {.. {-9223372036854775808 11964 0 LMT}.. {-1441163964 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {701823600 14400 1 +03}.. {717548400 14400 0 +04}.. {820440000 14400 0 +04}.. {828234000 18000 1 +05}.. {846378000 14400 0 +04}.. {852062400
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):181
          Entropy (8bit):4.911309754748998
          Encrypted:false
          SSDEEP:
          MD5:9AC4947AC29C797055B7EBFA4F6AC710
          SHA1:E7758A9A8BFA255F6B2D27F5366D9FE2A26DDF6C
          SHA-256:6E72BA908F250FD45D554A12E3E7B3BD2F1C02A6C2431F806FD2A054F843AA90
          SHA-512:F9D0F0CB7D3726C2AB3B5049429172D9DD4BA21353F6F98570CBA4EE969F7D97BD973CB165AECFF930AFFA8633E8052624D44EE7FB91763681ED3F78A61F4F98
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Bangkok) {.. {-9223372036854775808 24124 0 LMT}.. {-2840164924 24124 0 BMT}.. {-1570084924 25200 0 +07}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2117
          Entropy (8bit):3.7025684250364725
          Encrypted:false
          SSDEEP:
          MD5:6CC13B6910412A3A3D16CA36ADF00352
          SHA1:061CF4A8FEA8C139F50F96E6B6506B50ED3DD792
          SHA-256:992F93A7975F8CD4E94D96B3BA1ECFB3585E52A53F4442A15993402D3F955F66
          SHA-512:4E9750B1C3C0BA4F7922BCBC76276A3E74031D78A98E21DC59F66D6EA8E1B70865BBEB50A6B77EB0423421A18428B97B47412053CE15213128CEED669F4DD6E8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Barnaul) {.. {-9223372036854775808 20100 0 LMT}.. {-1579844100 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {76470
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8024
          Entropy (8bit):3.7230911686481774
          Encrypted:false
          SSDEEP:
          MD5:1D99E2BBB01B1669403CFBAF7E03F733
          SHA1:DBDD58C7FD195FC602C4541D6F416CC96094C121
          SHA-256:17AF14646D562AFE17DCCFD1D2FBA95C122F3E0263906A36EB48BFF04ACF233E
          SHA-512:98524E8DCD17C090058F17BDA1200D9801EB1B14EB5CEB8C31149A4A402A53BA4923A2AFF457E0A72DAA601D88095247806F945F704000F874FCBF73631DD135
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Beirut) {.. {-9223372036854775808 8520 0 LMT}.. {-2840149320 7200 0 EET}.. {-1570413600 10800 1 EEST}.. {-1552186800 7200 0 EET}.. {-1538359200 10800 1 EEST}.. {-1522551600 7200 0 EET}.. {-1507514400 10800 1 EEST}.. {-1490583600 7200 0 EET}.. {-1473645600 10800 1 EEST}.. {-1460948400 7200 0 EET}.. {-399866400 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336794400 10800 1 EEST}.. {-323578800 7200 0 EET}.. {-305172000 10800 1 EEST}.. {-291956400 7200 0 EET}.. {-273636000 10800 1 EEST}.. {-260420400 7200 0 EET}.. {78012000 10800 1 EEST}.. {86734800 7200 0 EET}.. {105055200 10800 1 EEST}.. {118270800 7200 0 EET}.. {136591200 10800 1 EEST}.. {149806800 7200 0 EET}.. {168127200 10800 1 EEST}.. {181342800 7200 0 EET}.. {199749600 10800 1 EEST}.. {212965200 7200 0 EET}.. {231285600 10800
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1669
          Entropy (8bit):3.7443715330695735
          Encrypted:false
          SSDEEP:
          MD5:1EE8FF3DF0D931A140ADBB021EB3BFEB
          SHA1:F1F15EF70C4E9F456849AF89CAC97AD747D9E192
          SHA-256:1D5E9A8F6A04273AF741F648EF10718B004A60D7884FE432DDF85A8F558BEA98
          SHA-512:155539A5CF21A34FBFACBF1652D934BF32255F4E505E60B3B4D8B5F2F7FAE552E6CB4824D8608A9C56370F58E48702335995BBD16B7A296A86A72A615FBC8ABC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Bishkek) {.. {-9223372036854775808 17904 0 LMT}.. {-1441169904 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {683586000 18000 0 +05}.. {703018800 21600 1 +05}.. {717530400 18000 0 +05}.. {734468400 21600 1 +05}.. {748980000 18000 0 +05}.. {765918000 21600 1 +05}.. {78042
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):176
          Entropy (8bit):4.949517569857329
          Encrypted:false
          SSDEEP:
          MD5:716D842F23974137C5E07A1A65CEFC5D
          SHA1:C7248C9DBD6AE5AF33BD4B3602D17737EBE023A0
          SHA-256:F3110E9DD514E3654A9DE777E22B2D2391692927954B4B7E42ED54AB665C3CF5
          SHA-512:4EC012EAABE60728D9447EEDF4BA7B16CA82786AA39EE79B2F9B32F227F9816FCE42F173153261F9AF88A12209752E84EBD7170C54D126C2DBB1ED3A8D069668
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kuching)]} {.. LoadTimeZoneFile Asia/Kuching..}..set TZData(:Asia/Brunei) $TZData(:Asia/Kuching)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.774027471796823
          Encrypted:false
          SSDEEP:
          MD5:8BB098AB77CB0469B1FA0E0B64C4A9E7
          SHA1:88C73626985071DD0923E1CAB343ACCD854A7297
          SHA-256:1BAEF7850111D2C33B2A766A8AE804534ABA1711BF80A4087A89656DDD8469D5
          SHA-512:82216A7F787AF20A4C97C7AA754CD6BE979FEF24137CF9A8B18EECA5E8FBCF12834DD8A6FC9CD2357D807F1629806745B46B11DC0472E0284E18DCCC983897DE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kolkata)]} {.. LoadTimeZoneFile Asia/Kolkata..}..set TZData(:Asia/Calcutta) $TZData(:Asia/Kolkata)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2086
          Entropy (8bit):3.6981807774781017
          Encrypted:false
          SSDEEP:
          MD5:69E03A5CEB689E19B60168C0F7EBAE8E
          SHA1:95C6396EB753753B4FE4AE1B98D76332523E72A4
          SHA-256:10B6F435B05D887176A4D90CA5AC957F327F62F36F15D6F6E4F81844662429B9
          SHA-512:DFA72EDC54A11F0840ADBEE7F5AD8EA472AA52A1F196292F1341CD92A68FB2EC0A5BC7DE6C8E83C975420DB4B76CECD4393370FDB2C09F86EC11A50E540F6F02
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Chita) {.. {-9223372036854775808 27232 0 LMT}.. {-1579419232 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {7647012
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1619
          Entropy (8bit):3.775783980828041
          Encrypted:false
          SSDEEP:
          MD5:540A7304A62ABB8D7F84454ABD6E2556
          SHA1:52C37529929218A668D7A4AD6FD1B5FE0A727E16
          SHA-256:94B2C14EF45C695EF6B19D94722E1BCBB629A595F2866DBA80F00A66721040B5
          SHA-512:3B535D109DB369E301D6B412F21EC990976B997826F22B2E16ECEEEB048D60F064C7CA1A616393DC2F1B491BAC0548DC0965B9EA149A95280FFDBCAD6726EF0F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Choibalsan) {.. {-9223372036854775808 27480 0 LMT}.. {-2032933080 25200 0 +07}.. {252435600 28800 0 +08}.. {417974400 36000 0 +09}.. {433778400 32400 0 +09}.. {449593200 36000 1 +09}.. {465314400 32400 0 +09}.. {481042800 36000 1 +09}.. {496764000 32400 0 +09}.. {512492400 36000 1 +09}.. {528213600 32400 0 +09}.. {543942000 36000 1 +09}.. {559663200 32400 0 +09}.. {575391600 36000 1 +09}.. {591112800 32400 0 +09}.. {606841200 36000 1 +09}.. {622562400 32400 0 +09}.. {638290800 36000 1 +09}.. {654616800 32400 0 +09}.. {670345200 36000 1 +09}.. {686066400 32400 0 +09}.. {701794800 36000 1 +09}.. {717516000 32400 0 +09}.. {733244400 36000 1 +09}.. {748965600 32400 0 +09}.. {764694000 36000 1 +09}.. {780415200 32400 0 +09}.. {796143600 36000 1 +09}.. {811864800 32400 0 +09}.. {828198000 36000 1 +09}.. {843919200 32400 0 +09}.. {8596
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.865222436335267
          Encrypted:false
          SSDEEP:
          MD5:C5DC40C6325391F7247251ADB2C07F78
          SHA1:3DDB1BF94532FB1F1271095B9C8CAA779BC545EF
          SHA-256:A87382DC5F3C3141547A65E3746AF1DAF94B51468B96DA6CEF30E95754C97D37
          SHA-512:062FF8D5E5392E5372B0405EDF3C7CF997AC33F95EBFFAA9CC9AB82BBE27B60C80255FCCEE9E6F5E02CBFCB163F99984BB2103217FFD1F80BDEC5C684BF2F61A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Chongqing) $TZData(:Asia/Shanghai)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.889115378893491
          Encrypted:false
          SSDEEP:
          MD5:C3676771EB813B346F58A7B574D0D7B5
          SHA1:A473EF621309E019F29F3DEF95C38593775B8404
          SHA-256:D6D2B4A761C547F1F853AE901AC71AB49FBE825037079C4E0C89DC940AE4A822
          SHA-512:21C3A5D499E6E0427FBF585CA8CC5D99D193C586483AB107C4D8E9F9DC8412021E8E019A314757DAFE1225D2635F6D48E9C54A511709863F22A02449FA201E02
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Chungking) $TZData(:Asia/Shanghai)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):369
          Entropy (8bit):4.465596050904646
          Encrypted:false
          SSDEEP:
          MD5:9541BB43E79AB0C6E8163945B5BFB1BF
          SHA1:C4994420DB8313DECDE19B4B9F6C5DB0126A95A7
          SHA-256:E5B5E6D607A15DA65CB00C92C35A63EAF25F547E64CB34BB419CB8CFC2714B1B
          SHA-512:46F623B3F7CF8A50F97DD812521398EB9100C9CDFB967C18EF1BD112306AAEB3C9CB224424E48611CB8CC21D1DC3D820DD83032D12BC9DF19301CF07786FA664
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Colombo) {.. {-9223372036854775808 19164 0 LMT}.. {-2840159964 19172 0 MMT}.. {-2019705572 19800 0 +0530}.. {-883287000 21600 1 +06}.. {-862639200 23400 1 +0630}.. {-764051400 19800 0 +0530}.. {832962600 23400 0 +0630}.. {846266400 21600 0 +06}.. {1145039400 19800 0 +0530}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):169
          Entropy (8bit):4.786111096226559
          Encrypted:false
          SSDEEP:
          MD5:BA575D37459540907A644438071277F8
          SHA1:14CF10D6AABBAF7BAE42B3B9641D8469C206567F
          SHA-256:B3AD560F66EA330E54A147017E6E6AB64452A5255D097B962D540836D7B19EE7
          SHA-512:9CA386EF4D812B00C2E63558B81B273F92BBCA98AF304C9FD6FC166210FC4E2F92B769E1D6FB96B670650DC76EFFAD2FC6E39AE12C24B47EAED4E50A2AFAC2D7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dhaka)]} {.. LoadTimeZoneFile Asia/Dhaka..}..set TZData(:Asia/Dacca) $TZData(:Asia/Dhaka)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3692
          Entropy (8bit):3.7832279883701254
          Encrypted:false
          SSDEEP:
          MD5:1D6B2CC38669C0F7378D9A576F10C477
          SHA1:09A31E6295D9FC39219DFA4FC598B46F55C41180
          SHA-256:7E577F0F9DA459BA1A325BE95C1FA0DB2C6ECFC1D64CDB73F3ADB09588293BA7
          SHA-512:A0BBD5CE7883C275BF9752C75BA0C9AF0181046D94D27EFC96EC8823C374BADCB69B2B11D2C4497295E5BC25D5790634C69C6E7185F406F2107A8E16044E670F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Damascus) {.. {-9223372036854775808 8712 0 LMT}.. {-1577931912 7200 0 EET}.. {-1568592000 10800 1 EEST}.. {-1554080400 7200 0 EET}.. {-1537142400 10800 1 EEST}.. {-1522630800 7200 0 EET}.. {-1505692800 10800 1 EEST}.. {-1491181200 7200 0 EET}.. {-1474243200 10800 1 EEST}.. {-1459126800 7200 0 EET}.. {-242265600 10800 1 EEST}.. {-228877200 7200 0 EET}.. {-210556800 10800 1 EEST}.. {-197427600 7200 0 EET}.. {-178934400 10800 1 EEST}.. {-165718800 7200 0 EET}.. {-147398400 10800 1 EEST}.. {-134269200 7200 0 EET}.. {-116467200 10800 1 EEST}.. {-102646800 7200 0 EET}.. {-84326400 10800 1 EEST}.. {-71110800 7200 0 EET}.. {-52704000 10800 1 EEST}.. {-39488400 7200 0 EET}.. {-21168000 10800 1 EEST}.. {-7952400 7200 0 EET}.. {10368000 10800 1 EEST}.. {23583600 7200 0 EET}.. {41904000 10800 1 EEST}.. {55119600 7200 0 EET}.. {73526400 10800 1
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):364
          Entropy (8bit):4.412125512631861
          Encrypted:false
          SSDEEP:
          MD5:B5496A038AC230B9D75AA22BB2BE6BDD
          SHA1:ACFD9C78F803F344272E8E188C41ED969EBADA16
          SHA-256:BFC4562055CC4355E79F9EFAA580A4C6A658285916159A5D390A0CDA96A97E98
          SHA-512:AB05D0176DADC1ED03CC526C372B9827A5FA03459E4F4B4365C6CE4B6FBDA043514A9D3FE2DA747159C5A1BC0E07727E6578A101E42B4DB120AF9624368C5FEA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dhaka) {.. {-9223372036854775808 21700 0 LMT}.. {-2524543300 21200 0 HMT}.. {-891582800 23400 0 +0630}.. {-872058600 19800 0 +0530}.. {-862637400 23400 0 +0630}.. {-576138600 21600 0 +06}.. {1230746400 21600 0 +06}.. {1245430800 25200 1 +06}.. {1262278800 21600 0 +06}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):235
          Entropy (8bit):4.597480383845617
          Encrypted:false
          SSDEEP:
          MD5:316DDF860FA234621698EB473E558DB7
          SHA1:35BF955F764555945CF8B314B8E881DAD6CF557B
          SHA-256:8BC2E0D77AC35B6D63E11B820AC45EC23A4195ED773680C600C772FDF4B953F8
          SHA-512:D1A8D5F1DAAB7827BDCBC14506AF8681FD1ED94C6101CC4A3C8CC2A76EA7D3649038069158C539A2007A1B0734FBD87DE120415E07A3F08F44417100C95459F5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dili) {.. {-9223372036854775808 30140 0 LMT}.. {-1830414140 28800 0 +08}.. {-879152400 32400 0 +09}.. {199897200 28800 0 +08}.. {969120000 32400 0 +09}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):148
          Entropy (8bit):4.97292023820863
          Encrypted:false
          SSDEEP:
          MD5:861BA4A0A71E6C3F71B90074275FD57C
          SHA1:BC6FC5233340BB19AE4BD0BA563875479AC0A2B9
          SHA-256:3DB174F1568BC23BF467A3DC7BAF8A2A2952B70653D4DE54F4DB391EC50B6925
          SHA-512:B187735E0783F299253D9F93E002AEFF131FCCA50FB3E04CF0545B334B051D5ED978108A47C6957B608F5F93ED4CC3D69751FE0F40413719EE1C0440CD49AC76
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dubai) {.. {-9223372036854775808 13272 0 LMT}.. {-1577936472 14400 0 +04}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):820
          Entropy (8bit):3.969189280047274
          Encrypted:false
          SSDEEP:
          MD5:9ABD0ECB5F3E738F49CDD1F81C9FF1A4
          SHA1:46B68C7BBD1BE9791B00128A5129AA3668435C93
          SHA-256:550DB44595F59D0F151BE4AF70D6FECE20580AB687EF45DE2A0A75FB2515AC80
          SHA-512:67E2B0EF216D509C4B6DD367519E0A733E54A7CA767D5F7960715E8056E61B7B633C7516D568544F55C9277E90412C1443B822C6EED3341C01F1BD9AA9476FA1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dushanbe) {.. {-9223372036854775808 16512 0 LMT}.. {-1441168512 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 21600 1 +06}.. {684363600 18000 0 +05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7597
          Entropy (8bit):3.7170041442081203
          Encrypted:false
          SSDEEP:
          MD5:F8E4BA3E260452AE13CF234E60149A62
          SHA1:8DDB08E2FDEEF6539EE0C0038B166908BFED16CD
          SHA-256:8CFE85C48FC22033411432F8B75EE4C097A5D84897698CB1AFD5AB51C47FF5A3
          SHA-512:487177411FB7E9F83AB9AAD84B685322B13A85784D4F90BB9C30F57BFAA6A9298E5C4F36C97444DE1117E51F85A62DC639D08B405460D071C2B29C898553E9A3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Famagusta) {.. {-9223372036854775808 8148 0 LMT}.. {-1518920148 7200 0 EET}.. {166572000 10800 1 EEST}.. {182293200 7200 0 EET}.. {200959200 10800 1 EEST}.. {213829200 7200 0 EET}.. {228866400 10800 1 EEST}.. {243982800 7200 0 EET}.. {260316000 10800 1 EEST}.. {276123600 7200 0 EET}.. {291765600 10800 1 EEST}.. {307486800 7200 0 EET}.. {323820000 10800 1 EEST}.. {338936400 7200 0 EET}.. {354664800 10800 1 EEST}.. {370386000 7200 0 EET}.. {386114400 10800 1 EEST}.. {401835600 7200 0 EET}.. {417564000 10800 1 EEST}.. {433285200 7200 0 EET}.. {449013600 10800 1 EEST}.. {465339600 7200 0 EET}.. {481068000 10800 1 EEST}.. {496789200 7200 0 EET}.. {512517600 10800 1 EEST}.. {528238800 7200 0 EET}.. {543967200 10800 1 EEST}.. {559688400 7200 0 EET}.. {575416800 10800 1 EEST}.. {591138000 7200 0 EET}.. {606866400 10800 1 EEST}.. {622587
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8427
          Entropy (8bit):3.7494839792487094
          Encrypted:false
          SSDEEP:
          MD5:DEB2D261D6885CD83054391D010DE6AD
          SHA1:5779B343F4EB2BC75613C593E2FA3A026857F940
          SHA-256:A1823EDA63434ACF1A37B3A781A783CFEB6BB4CC53ED0469BB685834837F2289
          SHA-512:D024B2D324D981A6792127551B0D466EAFFC5294C84CB5752A71E5267FB2E9162E7EFAED5A5CA3B06BBAD285F62BF955B0EF86DD39307EE5F935FC601F4EEEFA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Gaza) {.. {-9223372036854775808 8272 0 LMT}.. {-2185409872 7200 0 EEST}.. {-933638400 10800 1 EEST}.. {-923097600 7200 0 EEST}.. {-919036800 10800 1 EEST}.. {-857347200 7200 0 EEST}.. {-844300800 10800 1 EEST}.. {-825811200 7200 0 EEST}.. {-812678400 10800 1 EEST}.. {-794188800 7200 0 EEST}.. {-779846400 10800 1 EEST}.. {-762652800 7200 0 EEST}.. {-748310400 10800 1 EEST}.. {-731116800 7200 0 EEST}.. {-682653600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-16580
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.86422571961583
          Encrypted:false
          SSDEEP:
          MD5:1BCCB3578FADE993EE8B2C11EAC06CD8
          SHA1:CAEAB714E014CD5040C44E4603708B97BC0B03D4
          SHA-256:12811A7944B892E3D1C0B4B09057CC1899F28081B3CD47FFD248BA49BA308AF0
          SHA-512:1D791DC0E8F45359366DF33C2C337688D2E0E972A90F038733B840D28585505AEF542DDBAD014C9EA8C252048A588CD017DD67A84545A81EDB7C17E3B2E65092
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Harbin) $TZData(:Asia/Shanghai)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8402
          Entropy (8bit):3.7520828858184325
          Encrypted:false
          SSDEEP:
          MD5:6F176787C7FC5764A63719F0041690BA
          SHA1:C292A8CEA597D7FD9E2D071AB7AE93E7ABCA21A5
          SHA-256:732CAA355542C8781C61FC8F5265EBFC59C8CC24E78D01011E1E3256E6B34DC7
          SHA-512:EE8F39A3D65D75E14B59B4D9CCB27894210CA269E82A7AC7F98BE67764688A8895EBB9C1ACEAB4C1B368B4F1BC5AFCB34E8866CEDFD91232926DF47517096513
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hebron) {.. {-9223372036854775808 8423 0 LMT}.. {-2185410023 7200 0 EEST}.. {-933638400 10800 1 EEST}.. {-923097600 7200 0 EEST}.. {-919036800 10800 1 EEST}.. {-857347200 7200 0 EEST}.. {-844300800 10800 1 EEST}.. {-825811200 7200 0 EEST}.. {-812678400 10800 1 EEST}.. {-794188800 7200 0 EEST}.. {-779846400 10800 1 EEST}.. {-762652800 7200 0 EEST}.. {-748310400 10800 1 EEST}.. {-731116800 7200 0 EEST}.. {-682653600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-165
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):395
          Entropy (8bit):4.431055857167822
          Encrypted:false
          SSDEEP:
          MD5:A49A3D55C1E10A37125C51F9C6363868
          SHA1:7C1B5D44643ADC3F02681F6379E82C3F4512F0C1
          SHA-256:D8A19C70BE5A9AE1E6091DC8FD03D7719110D1F3D78786C91D5BD0949FB5A428
          SHA-512:804C44E51BB9E93B156B0CB4CB125651003B3C42D65334A052BE149734221315CC75D4FBDE34F62DFC102F1A9C968D1C9B573839C7ECBF7397B61BD90E530B20
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ho_Chi_Minh) {.. {-9223372036854775808 25590 0 LMT}.. {-2004073590 25590 0 PLMT}.. {-1851577590 25200 0 +07}.. {-852105600 28800 0 +08}.. {-782643600 32400 0 +09}.. {-767869200 25200 0 +07}.. {-718095600 28800 0 +08}.. {-457776000 25200 0 +07}.. {-315648000 28800 0 +08}.. {171820800 25200 0 +07}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2226
          Entropy (8bit):4.0055033036300145
          Encrypted:false
          SSDEEP:
          MD5:26BCBBA28AE34FE3CF7D17EF4C6B69C8
          SHA1:5324DEA8E7965C66650E7B4769EFA1297B508486
          SHA-256:EE9A6997BC1AAD4A8FA95DB312774C3F37FBB895549230C30FC66C02CC170EB6
          SHA-512:54594CD18838B4A8947EBB5BDE2415727CC127CF79AEC98FC0F5D5A32F68EEAF4E079853239DE9F753CE90F18EFD55AE51FC43D64E313666CEA0EF8AC93BF065
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hong_Kong) {.. {-9223372036854775808 27402 0 LMT}.. {-2056690800 28800 0 HKT}.. {-900910800 32400 1 HKST}.. {-891579600 30600 1 HKWT}.. {-884248200 32400 0 JST}.. {-761209200 28800 0 HKT}.. {-747907200 32400 1 HKST}.. {-728541000 28800 0 HKT}.. {-717049800 32400 1 HKST}.. {-697091400 28800 0 HKT}.. {-683785800 32400 1 HKST}.. {-668061000 28800 0 HKT}.. {-654755400 32400 1 HKST}.. {-636611400 28800 0 HKT}.. {-623305800 32400 1 HKST}.. {-605161800 28800 0 HKT}.. {-591856200 32400 1 HKST}.. {-573712200 28800 0 HKT}.. {-559801800 32400 1 HKST}.. {-541657800 28800 0 HKT}.. {-528352200 32400 1 HKST}.. {-510211800 28800 0 HKT}.. {-498112200 32400 1 HKST}.. {-478762200 28800 0 HKT}.. {-466662600 32400 1 HKST}.. {-446707800 28800 0 HKT}.. {-435213000 32400 1 HKST}.. {-415258200 28800 0 HKT}.. {-403158600 32400 1 HKST}.. {-383808600 28800 0 HKT
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1583
          Entropy (8bit):3.7521760184466206
          Encrypted:false
          SSDEEP:
          MD5:A77140A0D8C2D3E2993E4BA7CADFB4C6
          SHA1:AE3586264A86D42F578D4B0F7A30C9BE6047EAB1
          SHA-256:CA88A45E954A9854C680B399E69E4858BF5E861FABFADC19D62D97B734B25415
          SHA-512:05EA9D903EEC755F799B7C2399ED933245A5AE3A594648FE37AF1CE7699AE499B4ED159F428D91259D80BC9AF5117F2DA055A506AED94E5281C38B7AFF69C6FE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hovd) {.. {-9223372036854775808 21996 0 LMT}.. {-2032927596 21600 0 +06}.. {252439200 25200 0 +07}.. {417978000 28800 1 +07}.. {433785600 25200 0 +07}.. {449600400 28800 1 +07}.. {465321600 25200 0 +07}.. {481050000 28800 1 +07}.. {496771200 25200 0 +07}.. {512499600 28800 1 +07}.. {528220800 25200 0 +07}.. {543949200 28800 1 +07}.. {559670400 25200 0 +07}.. {575398800 28800 1 +07}.. {591120000 25200 0 +07}.. {606848400 28800 1 +07}.. {622569600 25200 0 +07}.. {638298000 28800 1 +07}.. {654624000 25200 0 +07}.. {670352400 28800 1 +07}.. {686073600 25200 0 +07}.. {701802000 28800 1 +07}.. {717523200 25200 0 +07}.. {733251600 28800 1 +07}.. {748972800 25200 0 +07}.. {764701200 28800 1 +07}.. {780422400 25200 0 +07}.. {796150800 28800 1 +07}.. {811872000 25200 0 +07}.. {828205200 28800 1 +07}.. {843926400 25200 0 +07}.. {859654800
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2089
          Entropy (8bit):3.7296034934492694
          Encrypted:false
          SSDEEP:
          MD5:C9F7AC464970567E5C38CB01ED2297AE
          SHA1:453718BACCAE3FACD761AF22CA5875185478ADDD
          SHA-256:61BAAAD6315FFBDAED6F266880165B06ECCAF72F660B7FB01C8B654F3952D68E
          SHA-512:72044EFAE262CC12974F2DE2AAF06AC4C31BE73071ACD53DDC6B8D8BFC6FBDF937EC03DC881901F730659BDE662FBCFC76C57B2C086DAA97F160530464FBA7C6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Irkutsk) {.. {-9223372036854775808 25025 0 LMT}.. {-2840165825 25025 0 IMT}.. {-1575874625 25200 0 +07}.. {-1247554800 28800 0 +09}.. {354902400 32400 1 +09}.. {370710000 28800 0 +08}.. {386438400 32400 1 +09}.. {402246000 28800 0 +08}.. {417974400 32400 1 +09}.. {433782000 28800 0 +08}.. {449596800 32400 1 +09}.. {465328800 28800 0 +08}.. {481053600 32400 1 +09}.. {496778400 28800 0 +08}.. {512503200 32400 1 +09}.. {528228000 28800 0 +08}.. {543952800 32400 1 +09}.. {559677600 28800 0 +08}.. {575402400 32400 1 +09}.. {591127200 28800 0 +08}.. {606852000 32400 1 +09}.. {622576800 28800 0 +08}.. {638301600 32400 1 +09}.. {654631200 28800 0 +08}.. {670356000 25200 0 +08}.. {670359600 28800 1 +08}.. {686084400 25200 0 +07}.. {695761200 28800 0 +09}.. {701805600 32400 1 +09}.. {717530400 28800 0 +08}.. {733255200 32400 1 +09}.. {748
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):187
          Entropy (8bit):4.9013773460609
          Encrypted:false
          SSDEEP:
          MD5:8A92C690BE27A69D122BFF51479B7B56
          SHA1:52DB64587A347F34153A51788BDE8C349D966575
          SHA-256:1F77C4BD27574E1D2066885DEF01806A02D3E444424A219A8EC5C114F89665E5
          SHA-512:FEDF57C4862B6792A789F339EB1027EC8A8472B01B7D1D0814C419850B9AC03A7B454FDB04D8BECE166E9A8BCAA58B0B461007A6C824B30B1080991A1DB49CCA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Istanbul)]} {.. LoadTimeZoneFile Europe/Istanbul..}..set TZData(:Asia/Istanbul) $TZData(:Europe/Istanbul)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):370
          Entropy (8bit):4.4733192761103515
          Encrypted:false
          SSDEEP:
          MD5:C689A1AA9FFE535AEB3AD3D7EDE55172
          SHA1:0520FC9A4619FB555A79C5DF2AE82422BF2C5EDA
          SHA-256:2F39D9F93761B85C254F458317A7DE2B4184BE9459F2193A85C08662E801269A
          SHA-512:C1034FB2FCFEF201C5362AF21B048B6637A824C5C93D75854CF3807892C772CD4376533E58BFF8D8726F531F43CB231365B8012EBD3C1BECED865D3CD2D6673D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jakarta) {.. {-9223372036854775808 25632 0 LMT}.. {-3231299232 25632 0 BMT}.. {-1451719200 26400 0 +0720}.. {-1172906400 27000 0 +0730}.. {-876641400 32400 0 +09}.. {-766054800 27000 0 +0730}.. {-683883000 28800 0 +08}.. {-620812800 27000 0 +0730}.. {-189415800 25200 0 WIB}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):213
          Entropy (8bit):4.834345288972067
          Encrypted:false
          SSDEEP:
          MD5:2CB3A13FCC48F8C4457E001FC309918B
          SHA1:83174176815CB93D216B5BC532C120EC8AC433CF
          SHA-256:761C1E80FEBF46D6D6215CEBF211F121974156D9BCE2FB4258C1074C6ED2CE22
          SHA-512:65009020AB9FEC2F8158A4851A78B71127F9B262DDD1472583942E19B7C086304F54BC8DAE5A40BD1448BCAEDA0FDBACCD19400E10FFA0357E324535F9036EF0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jayapura) {.. {-9223372036854775808 33768 0 LMT}.. {-1172913768 32400 0 +09}.. {-799491600 34200 0 +0930}.. {-189423000 32400 0 WIT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8135
          Entropy (8bit):3.770028446231146
          Encrypted:false
          SSDEEP:
          MD5:884227D48C92BA6C519BFE571D4F1037
          SHA1:21F8977816C2B439686A50D353B836A6D132A946
          SHA-256:0BDC2C693134199C2ECD374CC01468813DB29DF47422C706A3EA2BE5ECCA177A
          SHA-512:8A09F1FE11DAD203501A16FE6A2CAEC969FE3553B456B8BD1997E55B3EE430B2BB4B54F7D87C5E99931FD96E7C769CAA618C777EBD23FBD1E1A0F57409422914
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jerusalem) {.. {-9223372036854775808 8454 0 LMT}.. {-2840149254 8440 0 JMT}.. {-1641003640 7200 0 IST}.. {-933638400 10800 1 IDT}.. {-923097600 7200 0 IST}.. {-919036800 10800 1 IDT}.. {-857347200 7200 0 IST}.. {-844300800 10800 1 IDT}.. {-825811200 7200 0 IST}.. {-812678400 10800 1 IDT}.. {-794188800 7200 0 IST}.. {-779846400 10800 1 IDT}.. {-762652800 7200 0 IST}.. {-748310400 10800 1 IDT}.. {-731116800 7200 0 IST}.. {-681955200 14400 1 IDDT}.. {-673228800 10800 1 IDT}.. {-667958400 7200 0 IST}.. {-652320000 10800 1 IDT}.. {-636422400 7200 0 IST}.. {-622080000 10800 1 IDT}.. {-608947200 7200 0 IST}.. {-591840000 10800 1 IDT}.. {-572486400 7200 0 IST}.. {-558576000 10800 1 IDT}.. {-542851200 7200 0 IST}.. {-527731200 10800 1 IDT}.. {-514425600 7200 0 IST}.. {-490838400 10800 1 IDT}.. {-482976000 7200 0 IST}.. {-459388800 10800 1 I
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.8546989169864085
          Encrypted:false
          SSDEEP:
          MD5:9BD9B21661C235C0794078EC98978D3B
          SHA1:3D854780F49D0E5F5A190DC9367C7406127C5E4D
          SHA-256:A59C95C038F2E945D685D96FA9B859CE82A643A1B7F56EB36B2C809DE91CD4BA
          SHA-512:A76E99CF03DA8897F0A210A98DB79E4CD60070F2BE363D0D0960D9882919F9B49978FA55BB2500F1648ADD4080730CAD85BAFF61D885A9EAD394AC04C850F6BA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kabul) {.. {-9223372036854775808 16608 0 LMT}.. {-2524538208 14400 0 +04}.. {-788932800 16200 0 +0430}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2060
          Entropy (8bit):3.788131608921229
          Encrypted:false
          SSDEEP:
          MD5:390F39934F095F89358B73D056D90264
          SHA1:6B57CE5346B50ED88BFBB6BC57F834FB3F564905
          SHA-256:6E0278E389072437BC07A5032CD58E9E5B1B2BDB20918632C422EFA97BC43ABF
          SHA-512:6C54D94E95D73030F2FFCF8D130494CBD79FB1CEB9B59ADE0743C10F02557C3DD59CC6274B262A7E29C2D4C35DDA4B6A9A0398C661F5BD40F3B92181192B9577
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kamchatka) {.. {-9223372036854775808 38076 0 LMT}.. {-1487759676 39600 0 +11}.. {-1247569200 43200 0 +13}.. {354888000 46800 1 +13}.. {370695600 43200 0 +12}.. {386424000 46800 1 +13}.. {402231600 43200 0 +12}.. {417960000 46800 1 +13}.. {433767600 43200 0 +12}.. {449582400 46800 1 +13}.. {465314400 43200 0 +12}.. {481039200 46800 1 +13}.. {496764000 43200 0 +12}.. {512488800 46800 1 +13}.. {528213600 43200 0 +12}.. {543938400 46800 1 +13}.. {559663200 43200 0 +12}.. {575388000 46800 1 +13}.. {591112800 43200 0 +12}.. {606837600 46800 1 +13}.. {622562400 43200 0 +12}.. {638287200 46800 1 +13}.. {654616800 43200 0 +12}.. {670341600 39600 0 +12}.. {670345200 43200 1 +12}.. {686070000 39600 0 +11}.. {695746800 43200 0 +13}.. {701791200 46800 1 +13}.. {717516000 43200 0 +12}.. {733240800 46800 1 +13}.. {748965600 43200 0 +12}.. {764
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):457
          Entropy (8bit):4.396286144160272
          Encrypted:false
          SSDEEP:
          MD5:DF604BCD42A3C1E6BABD0E4FF5764CA3
          SHA1:984111F3A75EE7D8760AA2B839010545AF8EE359
          SHA-256:4E7F7ACAE8B4018A835328744F680C8054771805BB0BB07678A09737963C090D
          SHA-512:690AC3FC7CA3C66AA70F17E38C6B43FFACAB3F86040C3BA94FBFF80AC8C1AECF8192E503282109DABF3228F8DC73C732F1041C80455B8B26BDB25C4C32FA286A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Karachi) {.. {-9223372036854775808 16092 0 LMT}.. {-1988166492 19800 0 +0530}.. {-862637400 23400 1 +0630}.. {-764145000 19800 0 +0530}.. {-576135000 18000 0 +05}.. {38775600 18000 0 PKT}.. {1018119600 21600 1 PKST}.. {1033840800 18000 0 PKT}.. {1212260400 21600 1 PKST}.. {1225476000 18000 0 PKT}.. {1239735600 21600 1 PKST}.. {1257012000 18000 0 PKT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):174
          Entropy (8bit):4.967143524972358
          Encrypted:false
          SSDEEP:
          MD5:259662F35AA09A891C2DDF8FCFECD6F0
          SHA1:DBB3A363A34C33F0B6B0D677E43C2985E2BAF976
          SHA-256:7B2251F0A41CBADF45D69F24604834167B14D8D33B510E635719AB404CABBCE2
          SHA-512:CD7E514555D58985C774535556B66542EFC5FB7CD5891F42FE21B591612CB7EBD4B41E96593E26E9283BA1B01EF3BE0FDFAE871F5EF6ADF2286AF1E479DCB44B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Urumqi)]} {.. LoadTimeZoneFile Asia/Urumqi..}..set TZData(:Asia/Kashgar) $TZData(:Asia/Urumqi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.896398105471451
          Encrypted:false
          SSDEEP:
          MD5:7AC6429D2A08372C71C61B4521246FEC
          SHA1:6E50F5AD1018398491453D751F8B717B618EF46E
          SHA-256:F0A0816E62036637F75081CBF17A1E6B8FBC2D86AEC3CD2E234BBBDD6EC9F109
          SHA-512:A5389A318896ABCAFE419262F6B8CA86C917788F1E2AFBC8CB1C074A52870E7A92C9F6F7D79DDE4AB0D267D870D3CCD69B3FC5FD57520352EFE36C583B493FB9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kathmandu) {.. {-9223372036854775808 20476 0 LMT}.. {-1577943676 19800 0 +0530}.. {504901800 20700 0 +0545}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.8363583658476745
          Encrypted:false
          SSDEEP:
          MD5:4CCC96293A33113D9ADC4130DCD19CBA
          SHA1:7BAB4B8DD6BB415A2FC86D9AB36BE2A893C03153
          SHA-256:9ACC9586B6F8B53BFE8B242283A434A9A9633D60559EBFDEE263B4C8915D50CA
          SHA-512:644E1777E01C15A728E30526F131462FCE50476A8FEDA9B99F41D95013BB8833A79437E75AA2025E2FD2E253B9AD40709DEF77E1F0C73DAAE7A9CF886A175A03
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kathmandu)]} {.. LoadTimeZoneFile Asia/Kathmandu..}..set TZData(:Asia/Katmandu) $TZData(:Asia/Kathmandu)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2119
          Entropy (8bit):3.707911838150672
          Encrypted:false
          SSDEEP:
          MD5:D7B394A9662D60D01781005FE73CC9E8
          SHA1:50B5EBD02596DC45D1F69358C5B69DD3058905FC
          SHA-256:33203D7FB7F3D1F848640ECE0642A2305E1863B4D47413075E2E7E40BD7418E7
          SHA-512:055EBA420F2F6049E803796ACCA263264B9E585E5312A86B8DF7B409C5F1CB1810F3AEDACD66CCF4605E55198947D263C240486C2A4D453D23C89802F0C66BBA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Khandyga) {.. {-9223372036854775808 32533 0 LMT}.. {-1579424533 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {7647
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):336
          Entropy (8bit):4.614218930153471
          Encrypted:false
          SSDEEP:
          MD5:248F1B5A26455000C936CE8BC02C1A0B
          SHA1:0C3F8CD4E038B113E5238AC52652809B6CA27999
          SHA-256:6D464564ED2EFC9DADA1586D4FC99FE333726D2BE15A00E30C2391F588896463
          SHA-512:AF36B0B3D410305ED504726C87265ACCAF5577A9B5DD7E7DAF135420E356C651287873197431B65B5317B4BA2009274288E4F101AC1274045A8D99E2414AB132
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kolkata) {.. {-9223372036854775808 21208 0 LMT}.. {-3645237208 21200 0 HMT}.. {-3155694800 19270 0 MMT}.. {-2019705670 19800 0 IST}.. {-891581400 23400 1 +0630}.. {-872058600 19800 0 IST}.. {-862637400 23400 1 +0630}.. {-764145000 19800 0 IST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2062
          Entropy (8bit):3.7086418466382605
          Encrypted:false
          SSDEEP:
          MD5:A59F7FFD0C3EBAD47EC5F2B89EBBD9FA
          SHA1:ACB94E28E0CF7C6606086267CEA1F63A3E755F56
          SHA-256:53B8D5E7FB1BD67FECE66A933D9BDBB773F14A8C04D316A2A1B00EC6DBC151DD
          SHA-512:7B3886B9D0A793CCEEDB2B190523922CFEBE5C82A5201C9EFA30CA4C7F63FB75C998CC7E1BD48D5D489F16E36FC0C22BD954CB7D321B3C09B36B60629C4C9F7E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Krasnoyarsk) {.. {-9223372036854775808 22286 0 LMT}.. {-1577513486 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {7
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.956557779400841
          Encrypted:false
          SSDEEP:
          MD5:E70767DA85A7E1FA9395FF0B16CFE5CE
          SHA1:3F78034F166CFC80B54E56AF289C7700A7E4AA5C
          SHA-256:056D352DDCFEC155375430FFF3C8743ED5C9B51B866A099E97E12CC381071F50
          SHA-512:FEDC854FB043AA79F132827F98F8983E480727FAA039CF2FB5B82611E724312A4F3F006EE58707F12B0AA90F5872E17F76E2A040CFB3A90D017C5CF92E52DA0A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Singapore)]} {.. LoadTimeZoneFile Asia/Singapore..}..set TZData(:Asia/Kuala_Lumpur) $TZData(:Asia/Singapore)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):669
          Entropy (8bit):4.074079100812583
          Encrypted:false
          SSDEEP:
          MD5:489E706324960E86B6E174D913C72E02
          SHA1:C7D77482C0D41F3426FC269B3B6C0575EF0E8C7E
          SHA-256:6E35E560675B0B5322474900D4EC8326C504788C1F82E533B09785DEEFF092DF
          SHA-512:5CEFD44656C041E59A16481E042EA914E7C003BDE6ADF5F49B57052E91F4F732A91A244BD8BC09EF5DC2640D3210DEE53882717C5C4CBD85CCE44A93B028E9C3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kuching) {.. {-9223372036854775808 26480 0 LMT}.. {-1383463280 27000 0 +0730}.. {-1167636600 28800 0 +08}.. {-1082448000 30000 1 +08}.. {-1074586800 28800 0 +08}.. {-1050825600 30000 1 +08}.. {-1042964400 28800 0 +08}.. {-1019289600 30000 1 +08}.. {-1011428400 28800 0 +08}.. {-987753600 30000 1 +08}.. {-979892400 28800 0 +08}.. {-956217600 30000 1 +08}.. {-948356400 28800 0 +08}.. {-924595200 30000 1 +08}.. {-916734000 28800 0 +08}.. {-893059200 30000 1 +08}.. {-885198000 28800 0 +08}.. {-879667200 32400 0 +09}.. {-767005200 28800 0 +08}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):173
          Entropy (8bit):4.877362838821003
          Encrypted:false
          SSDEEP:
          MD5:EA1DB4B80CC74CBA024B9BF3734B31F2
          SHA1:D8131C093BCA3B378BEC606CFEB56A40CB4E246F
          SHA-256:8E0C60A9AA64FB8602EDC35311F7436B04853970A21C1F6C871494A09AAD5787
          SHA-512:3B57C9CCC16AA4FE71D275D5EC6A7BC1838841023EE4408158362A7E13E7F1B345F7D95006BC8D2FC270158864E286A1A9364C792F679D5803BD82148399C199
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Asia/Kuwait) $TZData(:Asia/Riyadh)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):169
          Entropy (8bit):4.781739054385376
          Encrypted:false
          SSDEEP:
          MD5:55DAE27AEAA74FE822338C20B6CDFF68
          SHA1:F00EB827DC29EB2063B3A0EDBC39856637C55F33
          SHA-256:4308D741C83B263C7C9FB8EC692A7B7B502135E407B265B12EA7EF92523455C0
          SHA-512:398EE6015C58BDBBEAB49B74833B938FD84DE1AC6D3B8D095CE772ECA980D9E93F4EBFFFFCEAE7F91E287C8CE4F94B1A078D8E1460C352B7C2018F99915838FF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Macau)]} {.. LoadTimeZoneFile Asia/Macau..}..set TZData(:Asia/Macao) $TZData(:Asia/Macau)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2217
          Entropy (8bit):3.9638741177777868
          Encrypted:false
          SSDEEP:
          MD5:B184E7403CB7168607D2C9E158F86A3B
          SHA1:48B003B8F822BE979FBCB08CBDBFFC617BCF99DB
          SHA-256:FBCB92CECB1CB0BC284ADC30D70C5F57B3AFC992136A0D898ABC64490BB700FB
          SHA-512:D8C5C67CAEB7C670B7BD1DACC1203C4DEE4DDB16A780F502C4440997CFCFF869E86842EF87C2CD0E0B942941C02A6BC3BDAB7CEAD78B026B68F4A031173400C8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Macau) {.. {-9223372036854775808 27250 0 LMT}.. {-2056692850 28800 0 CST}.. {-884509200 32400 0 +09}.. {-873280800 36000 1 +09}.. {-855918000 32400 0 +09}.. {-841744800 36000 1 +09}.. {-828529200 32400 0 +10}.. {-765363600 28800 0 CT}.. {-747046800 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716461200 32400 1 CDT}.. {-697021200 28800 0 CST}.. {-683715600 32400 1 CDT}.. {-667990800 28800 0 CST}.. {-654771600 32400 1 CDT}.. {-636627600 28800 0 CST}.. {-623322000 32400 1 CDT}.. {-605178000 28800 0 CST}.. {-591872400 32400 1 CDT}.. {-573642000 28800 0 CST}.. {-559818000 32400 1 CDT}.. {-541674000 28800 0 CST}.. {-528368400 32400 1 CDT}.. {-510224400 28800 0 CST}.. {-498128400 32400 1 CDT}.. {-478774800 28800 0 CST}.. {-466678800 32400 1 CDT}.. {-446720400 28800 0 CST}.. {-435229200 32400 1 CDT}.. {-415258200 28800 0 CST}.. {-403158600
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2088
          Entropy (8bit):3.7643610103361134
          Encrypted:false
          SSDEEP:
          MD5:F62A89F441C9C17EB99F64223C815651
          SHA1:408C38A79E056FF9B03D0DA85114DC015CB66938
          SHA-256:0C6EEEB7975A95C2B0678D137E6A735238D244A37FA11078050051511DE499FE
          SHA-512:55DC72546BDC26450D5318E9D2819E32A91C27D06A7AF5432BD50F8722C69984BBAA8599055A824D2935D919F0C0AA357687DD9B47F49F213EEE21AF7458FE17
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Magadan) {.. {-9223372036854775808 36192 0 LMT}.. {-1441188192 36000 0 +10}.. {-1247565600 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {76469
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):243
          Entropy (8bit):4.737440985553183
          Encrypted:false
          SSDEEP:
          MD5:9116C0B70AB33EC49F933EAE0238FD4B
          SHA1:BA390E8FBEAF5EA6E861AFC5A51CD4DF0B422461
          SHA-256:30D8AB00E32ECE51442C0310E650D89D6989E0809600EE334CB10C506D84BF9D
          SHA-512:499E60E8CBDA72226BCB4E241020E62B6F88E7D3E4329D260A6536EF87C02D7D61FD1BECC47D4FF308B4EB5D3E7FFBE2EC1C96FE2DEDC09DD1D973421C5FFE1E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Makassar) {.. {-9223372036854775808 28656 0 LMT}.. {-1577951856 28656 0 MMT}.. {-1172908656 28800 0 +08}.. {-880272000 32400 0 +09}.. {-766054800 28800 0 WITA}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):421
          Entropy (8bit):4.48495488773916
          Encrypted:false
          SSDEEP:
          MD5:0FBF0ED252638DF31826C33EB3FFBFE2
          SHA1:3496E4A5251A9BDF3AA4368297140780B6DBF66D
          SHA-256:070D61A0E39643A700ABA89A8A4BE5733BA456958966098405E11ECDFA854D76
          SHA-512:2A40E14964B357809E596DF88D8C4141ED78664BACA0A7724A7CA837EF427DC2B07C48D9DBE5787FAB0015673F5BDE002223D489334C5B91B74EEC5507A14B78
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Manila) {.. {-9223372036854775808 -57360 0 LMT}.. {-3944621040 29040 0 LMT}.. {-2229321840 28800 0 PST}.. {-1046678400 32400 1 PDT}.. {-1038733200 28800 0 PST}.. {-873273600 32400 0 JST}.. {-794221200 28800 0 PST}.. {-496224000 32400 1 PDT}.. {-489315600 28800 0 PST}.. {259344000 32400 1 PDT}.. {275151600 28800 0 PST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):170
          Entropy (8bit):4.805992552335358
          Encrypted:false
          SSDEEP:
          MD5:8AEB5C3E81069F884A370714E8013F1F
          SHA1:4E3DD4A84627E75E84726C0CBA72CA6801280C2B
          SHA-256:011B7DE1C9F7EC241B224BC864D8AE66ACB433FBC8AD939E4DBEB12BE6390243
          SHA-512:50B1DE2615AE9B4781505DC709F9D07F6221D4E6D7B61D7BDA682377EAD9807F47FF0E933B79823D0DFD9F3647A82CFC28FB41FBB2226ED1D08B76F86FEB45DC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Asia/Muscat) $TZData(:Asia/Dubai)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7625
          Entropy (8bit):3.7113086720696398
          Encrypted:false
          SSDEEP:
          MD5:2ADD0DFC1F133E4D044727234251A3DC
          SHA1:0D1502986258349E384017BA6CB8FA0AC424638C
          SHA-256:3C3E4844C70D361893EF022D6C3C8E38B243E91D40C5A726C924355476816F25
          SHA-512:70CDD53E7E44EDABF653A4F92EECBF5BB20A31DA95D65209D1CADE7DD9FC68946B8EC8829C28AE00BE5F42AAB545B9282CBBCFC5834437D6A94A179BF4FE0141
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Nicosia) {.. {-9223372036854775808 8008 0 LMT}.. {-1518920008 7200 0 EET}.. {166572000 10800 1 EEST}.. {182293200 7200 0 EET}.. {200959200 10800 1 EEST}.. {213829200 7200 0 EET}.. {228866400 10800 1 EEST}.. {243982800 7200 0 EET}.. {260316000 10800 1 EEST}.. {276123600 7200 0 EET}.. {291765600 10800 1 EEST}.. {307486800 7200 0 EET}.. {323820000 10800 1 EEST}.. {338936400 7200 0 EET}.. {354664800 10800 1 EEST}.. {370386000 7200 0 EET}.. {386114400 10800 1 EEST}.. {401835600 7200 0 EET}.. {417564000 10800 1 EEST}.. {433285200 7200 0 EET}.. {449013600 10800 1 EEST}.. {465339600 7200 0 EET}.. {481068000 10800 1 EEST}.. {496789200 7200 0 EET}.. {512517600 10800 1 EEST}.. {528238800 7200 0 EET}.. {543967200 10800 1 EEST}.. {559688400 7200 0 EET}.. {575416800 10800 1 EEST}.. {591138000 7200 0 EET}.. {606866400 10800 1 EEST}.. {62258760
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2063
          Entropy (8bit):3.718004112421892
          Encrypted:false
          SSDEEP:
          MD5:513B6A2AF76DAED9002C037BEC99862F
          SHA1:82D1C47BDF46B8B901C35BACACE8595C093BF5F2
          SHA-256:96A445D47D834C28480D1E2036ECA4962B35AFA494C219065D4879F71C1830DB
          SHA-512:2FE5AF4FA9D6AAB4FBD8E354789B82D39FA1B52394D3A0ABFBC6A30A531E0B7429A3D9AC7835A2843A6E9859E0255565F151FDFC87004ACB4EBD1AAD40BDA8A4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Novokuznetsk) {.. {-9223372036854775808 20928 0 LMT}.. {-1441259328 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2121
          Entropy (8bit):3.714792994893581
          Encrypted:false
          SSDEEP:
          MD5:AC8C8D768503C8334A9FBAEF4C3A9CAB
          SHA1:CA10BB99E2D7AB329229759BD4801068A3AEB6D5
          SHA-256:EF799077291F6B3B19E0AEC88F224BB592FAAD09D30740F2376D3D20F2169639
          SHA-512:34049B1AC4254F999C3E5AD8CB31ABF88AC2D972E20E19927F33CC59935354F92125A0342A413E64227E8AE29DDFC2FFE5F67AE538C89D8EBAD7FCA889321DFA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Novosibirsk) {.. {-9223372036854775808 19900 0 LMT}.. {-1579476700 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {738090000 25200 0 +07}.. {7
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2055
          Entropy (8bit):3.6912374223526396
          Encrypted:false
          SSDEEP:
          MD5:3E06B20B0B62AA09FA03082FAEE4FD62
          SHA1:8886EC80528ECA13D3364138BFFE92F881768169
          SHA-256:2605CD1E26E4AB48BCB4399BB5B17BAD115A47F87BA3DD54B55BB50C3FE82606
          SHA-512:04C1B6A898D12C8EA1B0B2F6665C870434061C63CC8F7A067BFC708E9828BA2E60104B82E2025E42D51DA2F485890C4D34EC0341EF466A7942649BE64F5EEE17
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Omsk) {.. {-9223372036854775808 17610 0 LMT}.. {-1582088010 18000 0 +05}.. {-1247547600 21600 0 +07}.. {354909600 25200 1 +07}.. {370717200 21600 0 +06}.. {386445600 25200 1 +07}.. {402253200 21600 0 +06}.. {417981600 25200 1 +07}.. {433789200 21600 0 +06}.. {449604000 25200 1 +07}.. {465336000 21600 0 +06}.. {481060800 25200 1 +07}.. {496785600 21600 0 +06}.. {512510400 25200 1 +07}.. {528235200 21600 0 +06}.. {543960000 25200 1 +07}.. {559684800 21600 0 +06}.. {575409600 25200 1 +07}.. {591134400 21600 0 +06}.. {606859200 25200 1 +07}.. {622584000 21600 0 +06}.. {638308800 25200 1 +07}.. {654638400 21600 0 +06}.. {670363200 18000 0 +06}.. {670366800 21600 1 +06}.. {686091600 18000 0 +05}.. {695768400 21600 0 +07}.. {701812800 25200 1 +07}.. {717537600 21600 0 +06}.. {733262400 25200 1 +07}.. {748987200 21600 0 +06}.. {76471200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1664
          Entropy (8bit):3.708603813141953
          Encrypted:false
          SSDEEP:
          MD5:A3BD0C15642AE4F001F98F8E060E8374
          SHA1:366F3C7FD4000AC23B79AB0FF4429371ED323B81
          SHA-256:933BBCD7AE0BF59A5B4A6E0EF74C237FEEDC42E6A3AEB2158131AA70FBA6FE47
          SHA-512:16D8692D3EA96D3594E6220A6989BBFBB926A66EEBEB240C4DC68BE75C69C5206659D9D341D92AE6128928FD38A5F45B445621CBBBA4E4BA8C34C3AC52BF3C08
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Oral) {.. {-9223372036854775808 12324 0 LMT}.. {-1441164324 10800 0 +03}.. {-1247540400 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {701816400 14400 0 +04}.. {701820000 18000 1 +04}.. {717544800 14400 0 +04}.. {733269600 18000 1 +04}.. {74899440
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.958543249401788
          Encrypted:false
          SSDEEP:
          MD5:EBF01E229CC41EB8B27650A3D668EDC1
          SHA1:33E1B252C1B45EAE326FCF8CC7C80C78A46F7E8D
          SHA-256:DCEE88876D00396918F43DECA421B6C9B02F84B5866A2CE16E641B814B390A9F
          SHA-512:80840600F37A256B8FD9933760FBAE7C13DE1E24EFD970E47BE8DEC731DFABF6D6FB76999BEEC775FF8C8B8719E94788ED7EEB04376A34C827ACB443F720F7E3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Asia/Phnom_Penh) $TZData(:Asia/Bangkok)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):369
          Entropy (8bit):4.492596995768464
          Encrypted:false
          SSDEEP:
          MD5:9ADB1A9E41A143A06116E24EA0A53D90
          SHA1:6E50B549E1A705C0090BD5EDE26F7DED78CDF71A
          SHA-256:AC8370AEDF5FE3FE1E80710CE117DEE23815BE377D418E4B4F3259A1930E8DBF
          SHA-512:92790B20B960AC518AB2E18F902C6E0BA887F268909F5571CAC1068F5E719CCF6943AE6902DA1B683E170658B5E7BE06C6A187C1C0A652DD052D5BD0B2A7B84D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Pontianak) {.. {-9223372036854775808 26240 0 LMT}.. {-1946186240 26240 0 PMT}.. {-1172906240 27000 0 +0730}.. {-881220600 32400 0 +09}.. {-766054800 27000 0 +0730}.. {-683883000 28800 0 +08}.. {-620812800 27000 0 +0730}.. {-189415800 28800 0 WITA}.. {567964800 25200 0 WIB}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):273
          Entropy (8bit):4.709411633376997
          Encrypted:false
          SSDEEP:
          MD5:727BBC1A1662B500F616F544A484F213
          SHA1:93C1D902D9D4AA4197C7D16C61FB784AC01D0DE5
          SHA-256:29BA17F756F5C0BBA30FEBF44E620504D04921C832BD1CB56E1B60EF288B57DF
          SHA-512:C3C91E2F180109FF33E6491722F679A1B8DCE8CD31DE006D7FF2CBE270C008E927507C953641D28EE77D139BBEA54DEA1B7DBD6C30B208DDAB1B58756C32AC02
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Pyongyang) {.. {-9223372036854775808 30180 0 LMT}.. {-1948782180 30600 0 KST}.. {-1830414600 32400 0 JST}.. {-768646800 32400 0 KST}.. {1439564400 30600 0 KST}.. {1525446000 32400 0 KST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):176
          Entropy (8bit):4.851251407399968
          Encrypted:false
          SSDEEP:
          MD5:CBA9635133F88AD3B27E23B95430C27C
          SHA1:5E41232EC03BBC71B522F58CB2D05E6BFFFF1A75
          SHA-256:18CCA69F933795CE3F7DB31506EFC063E6CE1DFDCAB32AA387C398456D7F7E1F
          SHA-512:D7C43F1F9ADA54C914ADB3CB2C9063EB7044089CFC7755ACFD08828CDEBA3C116AE2BE916ABE5D561E63699B921BC52636DD0BBC2C4304F813616D320D7DDAAF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qatar) {.. {-9223372036854775808 12368 0 LMT}.. {-1577935568 14400 0 +04}.. {76190400 10800 0 +03}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1668
          Entropy (8bit):3.7299735983334195
          Encrypted:false
          SSDEEP:
          MD5:F5DBE4E72FA5AB0019CC98C8E21EC86E
          SHA1:27ECB901AA07C18EA7F38235E8EFE0B1635FEFBC
          SHA-256:4191629B874C988291E8FD13E675A3ED685D677F6541313975FC4610E47F1DCD
          SHA-512:D5EFD4EFFFFE2E41909AEB7B67BD1FA6FAF4B8E9AC645518D5B33BD1B3C5084F59D47D4ED052E0D4B9F9989BDDBA3AECB3D1E67F5237914D24C01F9C95242396
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qostanay) {.. {-9223372036854775808 15268 0 LMT}.. {-1441167268 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {7489
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1670
          Entropy (8bit):3.734572151642808
          Encrypted:false
          SSDEEP:
          MD5:026EC6E479EC006C4398288362254680
          SHA1:24AD03DD21DA394B3423D27211955BFD694F8E73
          SHA-256:CD6B067AA3EF6935B4E89CA36E6A03FCB97F1E0EE61A7B5D46C06BF4DE140774
          SHA-512:023AC55E118F13A31CE996C7BA155C90D47DEB6C223EEB3C0EE7B702871FF0CCA13CDF61D65FDDABE41B888CD7A74274AA5730059CC5688F8ED4DDBF8FE4ECA4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qyzylorda) {.. {-9223372036854775808 15712 0 LMT}.. {-1441167712 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {701812800 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {764
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):174
          Entropy (8bit):4.812955128020714
          Encrypted:false
          SSDEEP:
          MD5:BD3F294F1EDDD21467E980C9F5A0E7DE
          SHA1:11A3FC3E4489C18BDF9BFFB4C44615559D9DD99D
          SHA-256:E4D2C38D8E7377A528291A88129CDAC40CA4D40A5F1CD8ADB98228527556906E
          SHA-512:FA5FD600627793EABB83C1066BE246A47BCCE1FC57830596B9C0CDE8901B949AF178ABDE876C3B73CC3751312E8A4C03C390888B0B5A9669F511344143F83073
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Yangon)]} {.. LoadTimeZoneFile Asia/Yangon..}..set TZData(:Asia/Rangoon) $TZData(:Asia/Yangon)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):148
          Entropy (8bit):4.973311159904374
          Encrypted:false
          SSDEEP:
          MD5:AD3236CFF141732831732357AB181EE3
          SHA1:EAF51A63898A2048EA5FBE9BA4C001EEE37FFDB2
          SHA-256:411E31D09FFA48E44169C42661AE2F7FC142460BCAA216837D8C4740983CA7BD
          SHA-512:6CA2D89C02568580786BE98A863453ADCF4D21CAC52E5B44C4F7A05E76D29AEB3E28E353D6FB758BB553DBC8F35389462B388F61E94C68F5DB50A3E8C429336D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Riyadh) {.. {-9223372036854775808 11212 0 LMT}.. {-719636812 10800 0 +03}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.946090704619887
          Encrypted:false
          SSDEEP:
          MD5:0766480A295525EE5D65F1ED32094858
          SHA1:7A2D68E1009DDD809A4A700931456C617DCD343A
          SHA-256:C695981A0DF691C3F4509999FBC52858ADC75024CCCBDEFBE1094FED17E809E4
          SHA-512:A21536FB61A64E953E8D6414FF0AEF1BC7E68A33C5DCF7090517A91FC449B96A93A4FBDF2C00682540D1193FDB29603349F5BDB455FD90045FDBCA61247A9860
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ho_Chi_Minh)]} {.. LoadTimeZoneFile Asia/Ho_Chi_Minh..}..set TZData(:Asia/Saigon) $TZData(:Asia/Ho_Chi_Minh)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2117
          Entropy (8bit):3.7276904131666577
          Encrypted:false
          SSDEEP:
          MD5:295D51B8FBBE890C97637687B8F32322
          SHA1:7BB72B0EC783898DDF625D275E3BBB964D1693FB
          SHA-256:D7D0EA5CEF908442AB0D777A4B097BED18540CD5280FF63F33DD989E27E72908
          SHA-512:9B3E3BA01EAE38A00B0EE8A8FB17191CB4ED2EE9E46AE06403BA8C1193804764C86599840DC03E0C6A631456E1BE2BC560BDF6CF0450068EF78A6E494041326C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Sakhalin) {.. {-9223372036854775808 34248 0 LMT}.. {-2031039048 32400 0 +09}.. {-768560400 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {76469
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):879
          Entropy (8bit):3.9460497720710506
          Encrypted:false
          SSDEEP:
          MD5:10A758996B0DF756E520541BEA9B7D75
          SHA1:137E5FD4E00CFA4B3939EF11868862B7F93D87CD
          SHA-256:35E4B905723891281D9A6A0A1FD3760A3A48136E1419C686BE31ACE83BF7AA9D
          SHA-512:7E32661731EAB2ED8C387533ACCB4853F5B6225BAC11E93247E7B06D7AA856E6A665F63718BFE395CFD00F80A4C16789D7097FFA8DAD88B1D707BF9C155C1D4C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Samarkand) {.. {-9223372036854775808 16073 0 LMT}.. {-1441168073 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {694206000 18000 0 +05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):985
          Entropy (8bit):4.121802167517286
          Encrypted:false
          SSDEEP:
          MD5:A1DE6975DEA70D7241B5B3C43E1EA3AA
          SHA1:35EE563A2BCA77C761F7E878997763EA8D258040
          SHA-256:C4F82C94650572FE4D03BC1FE54CED8F4BF55DFBEE855D52DE3EA6378240AF93
          SHA-512:1639B0609115DBEA6A381986A732A5CA1523952AEF84843B4D714D5B2FF40B16C4166D8D60D31D4FC2C2BA34DED1F6DB39474336195603562265BDBF71687696
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Seoul) {.. {-9223372036854775808 30472 0 LMT}.. {-1948782472 30600 0 KST}.. {-1830414600 32400 0 JST}.. {-767350800 32400 0 KST}.. {-681210000 36000 1 KDT}.. {-672228000 32400 0 KST}.. {-654771600 36000 1 KDT}.. {-640864800 32400 0 KST}.. {-623408400 36000 1 KDT}.. {-609415200 32400 0 KST}.. {-588848400 36000 1 KDT}.. {-577965600 32400 0 KST}.. {-498128400 30600 0 KST}.. {-462702600 34200 1 KDT}.. {-451733400 30600 0 KST}.. {-429784200 34200 1 KDT}.. {-418296600 30600 0 KST}.. {-399544200 34200 1 KDT}.. {-387451800 30600 0 KST}.. {-368094600 34200 1 KDT}.. {-356002200 30600 0 KST}.. {-336645000 34200 1 KDT}.. {-324552600 30600 0 KST}.. {-305195400 34200 1 KDT}.. {-293103000 30600 0 KST}.. {-264933000 32400 0 KST}.. {547578000 36000 1 KDT}.. {560883600 32400 0 KST}.. {579027600 36000 1 KDT}.. {592333200 32400 0 KST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):981
          Entropy (8bit):4.16042656890735
          Encrypted:false
          SSDEEP:
          MD5:A266AA43A84FD5E4890BC77AA4E240D0
          SHA1:CD88C5D451CD7D3F50C9B36FDD47C84D20377441
          SHA-256:3AABB42D9EFE95D906B7F34640E7815919A1A20979EBB6EC1527FCAA3B09B22A
          SHA-512:13AE48F58C9AF24002F0FE4F28BF96B10EE0ED293E0DE9D29BCEBAAE102B2EA818F42CA4069544A254C95444A48604EC57E6AB2BEBDA4B5E72C82B49E61AD0A0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Shanghai) {.. {-9223372036854775808 29143 0 LMT}.. {-2177481943 28800 0 CST}.. {-1600675200 32400 1 CDT}.. {-1585904400 28800 0 CST}.. {-933667200 32400 1 CDT}.. {-922093200 28800 0 CST}.. {-908870400 32400 1 CDT}.. {-888829200 28800 0 CST}.. {-881049600 32400 1 CDT}.. {-767869200 28800 0 CST}.. {-745833600 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716889600 32400 1 CDT}.. {-699613200 28800 0 CST}.. {-683884800 32400 1 CDT}.. {-670669200 28800 0 CST}.. {-652348800 32400 1 CDT}.. {-650016000 28800 0 CST}.. {515527200 32400 1 CDT}.. {527014800 28800 0 CST}.. {545162400 32400 1 CDT}.. {558464400 28800 0 CST}.. {577216800 32400 1 CDT}.. {589914000 28800 0 CST}.. {608666400 32400 1 CDT}.. {621968400 28800 0 CST}.. {640116000 32400 1 CDT}.. {653418000 28800 0 CST}.. {671565600 32400 1 CDT}.. {684867600 28800 0 CST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):372
          Entropy (8bit):4.436676898144829
          Encrypted:false
          SSDEEP:
          MD5:C3D13D921E4C6E475910E5080B761C32
          SHA1:8C5AE73C4098D03908E5D567FD7C4D827601D718
          SHA-256:05C76B58A4E356FD358E24FBC71FAE98DCB18C441C8D8CBB13A18D4F6E406062
          SHA-512:3A620597469D31577ECAAA098C95C244F0C288ABACE9E8964D8641154C1893967EFBD7211A41751D0D4CC1B0B9A2286F11738EFB7D01F110A4826BBE1844A2EA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Singapore) {.. {-9223372036854775808 24925 0 LMT}.. {-2177477725 24925 0 SMT}.. {-2038200925 25200 0 +07}.. {-1167634800 26400 1 +0720}.. {-1073028000 26400 0 +0720}.. {-894180000 27000 0 +0730}.. {-879665400 32400 0 +09}.. {-767005200 27000 0 +0730}.. {378664200 28800 0 +08}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2064
          Entropy (8bit):3.7913177223006698
          Encrypted:false
          SSDEEP:
          MD5:B4FA38E884A85F6BD47C8BB02BB0500C
          SHA1:1DD135B79CC0D81C048D7B2C6BE0CF71171DD19E
          SHA-256:705D6D8360C2DCD51E909E39E1910FE876145220D151031612DA36B247207395
          SHA-512:2D32AAAF1BCC865B5F2810BFE0FB82BE98140BB5F2ECA1DA7FD148A3074DA127B81242F17B8BA9C9E259B61CBB123FD1513CCE6A85C8D7679ADFC0D689B552BB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Srednekolymsk) {.. {-9223372036854775808 36892 0 LMT}.. {-1441188892 36000 0 +10}.. {-1247565600 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1344
          Entropy (8bit):4.062084847879695
          Encrypted:false
          SSDEEP:
          MD5:AECA800C8F2A679D0B19E5BB90AFD858
          SHA1:2C7DCEB709F9A4312C511971FE1E6A9DC1FBD0E8
          SHA-256:389C9D3EE2970665D0D8C5CB61B8B790C5FBDDC0DF0BF2B9753046F5953A477F
          SHA-512:C2D6BB4FEB5848D0704647D26F94C0BD8CD7E834AA2187EC9C877E80157E9CC225BBA3BECEE0148894C8639105D292AB50EE95830992BF357C632ACF001E020F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Taipei) {.. {-9223372036854775808 29160 0 LMT}.. {-2335248360 28800 0 CST}.. {-1017820800 32400 0 JST}.. {-766224000 28800 0 CST}.. {-745833600 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716889600 32400 1 CDT}.. {-699613200 28800 0 CST}.. {-683884800 32400 1 CDT}.. {-670669200 28800 0 CST}.. {-652348800 32400 1 CDT}.. {-639133200 28800 0 CST}.. {-620812800 32400 1 CDT}.. {-607597200 28800 0 CST}.. {-589276800 32400 1 CDT}.. {-576061200 28800 0 CST}.. {-562924800 32400 1 CDT}.. {-541760400 28800 0 CST}.. {-528710400 32400 1 CDT}.. {-510224400 28800 0 CST}.. {-497174400 32400 1 CDT}.. {-478688400 28800 0 CST}.. {-465638400 32400 1 CDT}.. {-449830800 28800 0 CST}.. {-434016000 32400 1 CDT}.. {-418208400 28800 0 CST}.. {-402480000 32400 1 CDT}.. {-386672400 28800 0 CST}.. {-370944000 32400 1 CDT}.. {-355136400 28800 0 CST}.. {-3394080
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):878
          Entropy (8bit):3.9280321712564845
          Encrypted:false
          SSDEEP:
          MD5:DB59DB8E401E12917B7367D5604D3DE6
          SHA1:7CC7C5C1DB551BD381B833C81746201D36BC59A9
          SHA-256:4445F3F892C7267A6867009CC1A3F0B0548D0240408375A9D15360B28993C2A9
          SHA-512:2C7AE63C408A9F06F973AAC16845E1DBE92D15A421BBBE420914F21155AD5E57CD058D7E4427E43185E023D2FF475EBF9D74003ECEF004FF4E5F9D5681ADFB80
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tashkent) {.. {-9223372036854775808 16631 0 LMT}.. {-1441168631 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {694206000 18000 0 +05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1729
          Entropy (8bit):3.6815162494646034
          Encrypted:false
          SSDEEP:
          MD5:C376C9ED66F6CC011E063D3E8E0DCED1
          SHA1:13C6345F8CB0EC79FE7C78B156C5737BCB66E49E
          SHA-256:B637BB0E49144C717E99E93540CB2C4D3695D63B91FE42547F2F0AA006498693
          SHA-512:FD60192CBEDC91C5D6B3B5E6F19DEDCAE14DCF48DCAE6D4865A8F0BBDC01CBF8DAAE92C4C46C353AF5B3EEE36CCC87B23F193DDF221132F5404C42507B708364
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tbilisi) {.. {-9223372036854775808 10751 0 LMT}.. {-2840151551 10751 0 TBMT}.. {-1441162751 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {694213200 10800 0 +03}.. {701816400 14400 1 +03}.. {717537600 10800 0 +03}.. {733266000 14400 1 +03}.. {748
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2354
          Entropy (8bit):3.666553647637418
          Encrypted:false
          SSDEEP:
          MD5:A7A174A14E51E0ACD7092D2A5AA50F99
          SHA1:69ADDDDB68084B90819AD49A5230D5B0E1A9CD85
          SHA-256:25870503A8A679DA13B98117BD473EAA0C79B094B85D3AD50629FF0946D5EACE
          SHA-512:1ECFB558B13C94BDC848E7BBBB0CA1BB854BB12E112EBF306045EC14F00CE3E3C2DA51EBA8AF2D63C95D71B945647C3D9E9881158FE128DEBE940A742C4BFEB1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tehran) {.. {-9223372036854775808 12344 0 LMT}.. {-1704165944 12344 0 TMT}.. {-1090466744 12600 0 +0330}.. {227820600 16200 1 +0330}.. {246227400 14400 0 +04}.. {259617600 18000 1 +04}.. {271108800 14400 0 +04}.. {283982400 12600 0 +0330}.. {296598600 16200 1 +0330}.. {306531000 12600 0 +0330}.. {322432200 16200 1 +0330}.. {338499000 12600 0 +0330}.. {673216200 16200 1 +0330}.. {685481400 12600 0 +0330}.. {701209800 16200 1 +0330}.. {717103800 12600 0 +0330}.. {732745800 16200 1 +0330}.. {748639800 12600 0 +0330}.. {764281800 16200 1 +0330}.. {780175800 12600 0 +0330}.. {795817800 16200 1 +0330}.. {811711800 12600 0 +0330}.. {827353800 16200 1 +0330}.. {843247800 12600 0 +0330}.. {858976200 16200 1 +0330}.. {874870200 12600 0 +0330}.. {890512200 16200 1 +0330}.. {906406200 12600 0 +0330}.. {922048200 16200 1 +0330}.. {937942200 12600
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.876713308636272
          Encrypted:false
          SSDEEP:
          MD5:40B15013485EE2138A3DCB915F9121E7
          SHA1:3ADBE38686C7CA1FDE3DDD12BE908F39BFD1E228
          SHA-256:07537A30E6236D9E334DAFD5C4D352D25FDEF95D6DC7496F5D93EFAB74D9EBB1
          SHA-512:DA3B7B44B3BEF07CA8AA5253BF684A838181D8A15D7CCF0447A6B5F5BAE28D155CF65BCFB6286EB36C0B9F4FDD1FE862A3297ADB6FC33532B9F766334283D725
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Jerusalem)]} {.. LoadTimeZoneFile Asia/Jerusalem..}..set TZData(:Asia/Tel_Aviv) $TZData(:Asia/Jerusalem)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):176
          Entropy (8bit):4.906503135441824
          Encrypted:false
          SSDEEP:
          MD5:081862B6FB33389BEC9B0E6B500AA342
          SHA1:AF9467BB87C4C28921DF62A87B81223052F9FF4A
          SHA-256:37459C17B59639DF62B3F3943751902CE6AAF1F11B7630069DB45052EBEFB5B9
          SHA-512:CAF6F1C928528C4471229A2EF2944623545626532986628E6CE38884535286A0B38BA88C1A295E8B11322475D6BFAC61BF89786A76330C1A0C729339A3532BAF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Thimphu)]} {.. LoadTimeZoneFile Asia/Thimphu..}..set TZData(:Asia/Thimbu) $TZData(:Asia/Thimphu)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.887493603495978
          Encrypted:false
          SSDEEP:
          MD5:F239452984CCA9F23E97A880652C39E6
          SHA1:52D25282D03B79960F152D21E7492EE26DAEBBAA
          SHA-256:B797C74E3840298C3CD8149FC8AA4BCE839EFE79E7C3310986FF23C965607929
          SHA-512:1044BEDAE04FCA7BD62937AFCE70F6C447583A90DD1596C3029A64A8251E3F73C106F4D940548DD38E895D67FEFDCD196B257E11437DEB399085EE80C345AA50
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Thimphu) {.. {-9223372036854775808 21516 0 LMT}.. {-706341516 19800 0 +0530}.. {560025000 21600 0 +06}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):388
          Entropy (8bit):4.470556147950505
          Encrypted:false
          SSDEEP:
          MD5:3CCC15B63A882DB1B7459A51CD1C8165
          SHA1:77A3EFE6E4EE524B9EC6F51593DD7521FD7B8DAD
          SHA-256:3DA522FA88541A375D53F30A0B62DC4A305FA0315FEE534B7998C9E0A239450A
          SHA-512:15238E96DABAB5D2B9FFD25B3F50417ED32205FA69239D6F6B28DA97A378D669FD409164964D0DD2A5B1D795C8F60E8D4EB15924046348C3D6010646A536E07C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tokyo) {.. {-9223372036854775808 33539 0 LMT}.. {-2587712400 32400 0 JST}.. {-683802000 36000 1 JDT}.. {-672310800 32400 0 JST}.. {-654771600 36000 1 JDT}.. {-640861200 32400 0 JST}.. {-620298000 36000 1 JDT}.. {-609411600 32400 0 JST}.. {-588848400 36000 1 JDT}.. {-577962000 32400 0 JST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2116
          Entropy (8bit):3.695316005718174
          Encrypted:false
          SSDEEP:
          MD5:E95DE93CBCE72C5E02D7ECFE94C96308
          SHA1:59A49EBFE544D97545BADFEFE716BB5659C64C20
          SHA-256:6B64A01D0F0B5EC7A1410C3BD6883BA7CC133E9F073D40E8BFECE037E3A3FA24
          SHA-512:9E33DC9C1C6D60F3226263C484AF46A14AAB31F838516A0D69BA08F8F416EF10D09697E8D7ABAC1CE1F5BCE8AB0C2635D99FBE70C89ECC268DED0DCE89E67466
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tomsk) {.. {-9223372036854775808 20391 0 LMT}.. {-1578807591 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {7647084
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.897140749162557
          Encrypted:false
          SSDEEP:
          MD5:F6AE33D706C36FDD8A21F44AD59F5607
          SHA1:94D6EC7A437249AEBE2FA4AF8AFB029A620368C0
          SHA-256:732751845ACEDBFFD3C6170F4B94CB20B25BFDCFCC5EEA19F4BE439F5C5B573A
          SHA-512:2314AB2B154887842211C9A570BC1323D9B4375FF60C96296835DB001E8A277CA62D40B8562BC34EDDF281D96D5325640B79F7907558C6E0319C7D2A76BE239C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Makassar)]} {.. LoadTimeZoneFile Asia/Makassar..}..set TZData(:Asia/Ujung_Pandang) $TZData(:Asia/Makassar)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1590
          Entropy (8bit):3.7728141273024374
          Encrypted:false
          SSDEEP:
          MD5:A4647294401D2B54ABAA8E509BF05A6F
          SHA1:BF804CC38996D7715E3BA9BAD715D7ADBED781B9
          SHA-256:A56A26981163A717CF388A423CFE7A2BAD1BE8652BE2E338670CBC0C0A70E5E9
          SHA-512:B43157FABDE016FA6636CAB7B06CC1DEA53526B42FB46BB41DC4B7E48188D191C325BEF0D170B125E885F321C4316746A8D478D798828E2DC4A51C71DA4A610C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ulaanbaatar) {.. {-9223372036854775808 25652 0 LMT}.. {-2032931252 25200 0 +07}.. {252435600 28800 0 +08}.. {417974400 32400 1 +08}.. {433782000 28800 0 +08}.. {449596800 32400 1 +08}.. {465318000 28800 0 +08}.. {481046400 32400 1 +08}.. {496767600 28800 0 +08}.. {512496000 32400 1 +08}.. {528217200 28800 0 +08}.. {543945600 32400 1 +08}.. {559666800 28800 0 +08}.. {575395200 32400 1 +08}.. {591116400 28800 0 +08}.. {606844800 32400 1 +08}.. {622566000 28800 0 +08}.. {638294400 32400 1 +08}.. {654620400 28800 0 +08}.. {670348800 32400 1 +08}.. {686070000 28800 0 +08}.. {701798400 32400 1 +08}.. {717519600 28800 0 +08}.. {733248000 32400 1 +08}.. {748969200 28800 0 +08}.. {764697600 32400 1 +08}.. {780418800 28800 0 +08}.. {796147200 32400 1 +08}.. {811868400 28800 0 +08}.. {828201600 32400 1 +08}.. {843922800 28800 0 +08}.. {859
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):192
          Entropy (8bit):4.728285544456033
          Encrypted:false
          SSDEEP:
          MD5:D2EAEA6182FB332CAA707B523F6C8A9D
          SHA1:3BFC654E2B3BCF902AF41AEEC46772C84FFF3890
          SHA-256:D17FDAF17B3DAC3A1310E2332F61585598185E64CED799ABD68249EB5B698591
          SHA-512:E16BEE28BFE3AFFFE6F0025C09D0D65001F38D5045AAB1B554E4D3A66A88273F985B7BAA11F8D26E76E5ABC9F559E3E4B794CC939AAD5FF012A5A47924D08CB3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ulaanbaatar)]} {.. LoadTimeZoneFile Asia/Ulaanbaatar..}..set TZData(:Asia/Ulan_Bator) $TZData(:Asia/Ulaanbaatar)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):149
          Entropy (8bit):5.006390440264841
          Encrypted:false
          SSDEEP:
          MD5:D6245CAAEC9BA2579F4CEFFF196A9369
          SHA1:4D182953F2CEEFF3583265F977B14F40C1A2FB43
          SHA-256:C445B8030DEDDDED0AFF5CC692CC323B63BE8C14BBD42DC3FDE90AD4F9D14785
          SHA-512:A32C477B6FAA79247907D1C4E2DF400B05AF4B529277C4CE12B33097872311E3F579115DC8CBA93DAC936928FD574414F3473A9CB7C8E85AB57CCA57489B60F8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Urumqi) {.. {-9223372036854775808 21020 0 LMT}.. {-1325483420 21600 0 +06}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2058
          Entropy (8bit):3.773734429231407
          Encrypted:false
          SSDEEP:
          MD5:5ADD78E4AFCBA913D078A8790861A2DE
          SHA1:BB63A762D5D76C0FD3CB9AB2BCDE95718E1C99EB
          SHA-256:9D639C0FC69B3BEEBC96969092F9590EB48E7946E901B225BF245E165973B9A8
          SHA-512:7C2418FD1F96F101B83E2ABDF2551405C6E429DBBF30A2FA7CD2477E2CE1CEEBB790C51B28AEFF043BA7A7A914CEF3C812668058D69225B9FE9475C56508453D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ust-Nera) {.. {-9223372036854775808 34374 0 LMT}.. {-1579426374 28800 0 +08}.. {354898800 43200 0 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {764694000 43200 1 +12}.. {780418
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.858039387006872
          Encrypted:false
          SSDEEP:
          MD5:D23A09C84A5368FBB47174BC0A460D14
          SHA1:045A72FEA79C75E5F0029BD110E33A022C57DFAB
          SHA-256:18F5E4FE8247F676278AC5F1912AC401DC48DF5B756D22E76FF1CFA702F88DA7
          SHA-512:404EABC2FC162E18C678CED063249C7FF4C28653880EA1903CE846FD191CD1C5B61E0610736F250B79BBAC768B1AFD6B9A8824D56D74591A95D7301B47D48387
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Asia/Vientiane) $TZData(:Asia/Bangkok)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2062
          Entropy (8bit):3.7094518963173035
          Encrypted:false
          SSDEEP:
          MD5:5C0C094B088D0212182E7B944197D4FE
          SHA1:CF43A511FE9CD295207DF350704462E09D4D5278
          SHA-256:2558C96E25359C72F168DAC6FB3C16C54F8FD7D0724EEB1671156D4A1F42AC6C
          SHA-512:5D659EBDC8C2B06C964B083ECC78B4370A4658590D83F020CD23910C44E2D8DAFE69F61E8EB569E1905E89F38CD03ABE6B92F6CE36CF0B1EE0732A7645AFA65D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Vladivostok) {.. {-9223372036854775808 31651 0 LMT}.. {-1487321251 32400 0 +09}.. {-1247562000 36000 0 +11}.. {354895200 39600 1 +11}.. {370702800 36000 0 +10}.. {386431200 39600 1 +11}.. {402238800 36000 0 +10}.. {417967200 39600 1 +11}.. {433774800 36000 0 +10}.. {449589600 39600 1 +11}.. {465321600 36000 0 +10}.. {481046400 39600 1 +11}.. {496771200 36000 0 +10}.. {512496000 39600 1 +11}.. {528220800 36000 0 +10}.. {543945600 39600 1 +11}.. {559670400 36000 0 +10}.. {575395200 39600 1 +11}.. {591120000 36000 0 +10}.. {606844800 39600 1 +11}.. {622569600 36000 0 +10}.. {638294400 39600 1 +11}.. {654624000 36000 0 +10}.. {670348800 32400 0 +10}.. {670352400 36000 1 +10}.. {686077200 32400 0 +09}.. {695754000 36000 0 +11}.. {701798400 39600 1 +11}.. {717523200 36000 0 +10}.. {733248000 39600 1 +11}.. {748972800 36000 0 +10}.. {7
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2058
          Entropy (8bit):3.7081033128260934
          Encrypted:false
          SSDEEP:
          MD5:E43E5F0EA7C4575525BAB130984DCDCC
          SHA1:2D715749469FEA51A8E25D1F4F8DC4FF9178817D
          SHA-256:3BEF13638C46F16435D326C675907E61BB68C8173153CED3359E983BE0E413E5
          SHA-512:27954FEC865031BC363CFDE94E97B3B19836A6F777646EA4AAB12ECCAEE6D60A0C690711EA192B917AC717F94A01D1EF64BAE97DF968069CC12415971B070498
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yakutsk) {.. {-9223372036854775808 31138 0 LMT}.. {-1579423138 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {76470
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):244
          Entropy (8bit):4.692243303623333
          Encrypted:false
          SSDEEP:
          MD5:D45766D30074719C9A88ACE8BB53204B
          SHA1:69B333DFCCCCEB66DD0F7DC28B272BB10769B6B0
          SHA-256:2526557810747E78E713AE09BC305621A80FAEECF8D441632E7825738D4C79CB
          SHA-512:5255DEED72D7D13862A4D6BED7E0458C099D2EF5A1B41536CAA7C0E65A61DE8B8D1AD62AD44559F970B6613ADFB3862778D1CC99B9A05CB5BBCA7F0202B5A5B2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yangon) {.. {-9223372036854775808 23087 0 LMT}.. {-2840163887 23087 0 RMT}.. {-1577946287 23400 0 +0630}.. {-873268200 32400 0 +09}.. {-778410000 23400 0 +0630}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2095
          Entropy (8bit):3.704641905144701
          Encrypted:false
          SSDEEP:
          MD5:D4DABA407BB8A10E4961D1DE5D9781D1
          SHA1:6933DE65336331BD90E2BEC6AEA0609B16DAEDC9
          SHA-256:2C78699EFC60758B8F8D0D1DEEDFDED5E65C65EBF3082B23E60BDEA8BF8FBCFE
          SHA-512:459E2187FAA66414F5CE934C335F563DFD2FA5316B86A54D1A29123A0460AFD65B7CE46629BD6A070A14CB6873A28A2F2803DE5FF4F29EA610712EB07FAD303F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yekaterinburg) {.. {-9223372036854775808 14553 0 LMT}.. {-1688270553 13505 0 PMT}.. {-1592610305 14400 0 +04}.. {-1247544000 18000 0 +06}.. {354913200 21600 1 +06}.. {370720800 18000 0 +05}.. {386449200 21600 1 +06}.. {402256800 18000 0 +05}.. {417985200 21600 1 +06}.. {433792800 18000 0 +05}.. {449607600 21600 1 +06}.. {465339600 18000 0 +05}.. {481064400 21600 1 +06}.. {496789200 18000 0 +05}.. {512514000 21600 1 +06}.. {528238800 18000 0 +05}.. {543963600 21600 1 +06}.. {559688400 18000 0 +05}.. {575413200 21600 1 +06}.. {591138000 18000 0 +05}.. {606862800 21600 1 +06}.. {622587600 18000 0 +05}.. {638312400 21600 1 +06}.. {654642000 18000 0 +05}.. {670366800 14400 0 +05}.. {670370400 18000 1 +05}.. {686095200 14400 0 +04}.. {695772000 18000 0 +06}.. {701816400 21600 1 +06}.. {717541200 18000 0 +05}.. {733266000 21600 1 +06}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2029
          Entropy (8bit):3.6487650030366106
          Encrypted:false
          SSDEEP:
          MD5:2CFA7C55D0731D24679CA5D5DC716381
          SHA1:2BB66783D75C71E76409365757980FBC15F53231
          SHA-256:20871FA6AA959DDFB73D846271B4A568627B564CFC08A11BDD84B98C2F2019A3
          SHA-512:CAB10A48859B2C0B2CC7C56E0AA530AE7E506A4986BADC5ED974D124BD46DB328B50C423F83FCFD52D31962A249EEFC10351798B86D51EDA500F412C8D42E6BC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yerevan) {.. {-9223372036854775808 10680 0 LMT}.. {-1441162680 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {701823600 14400 1 +03}.. {717548400 10800 0 +03}.. {733273200 14400 1 +03}.. {748998000 10800 0 +03}.. {764722800 14400 1 +03}.. {780447
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9879
          Entropy (8bit):3.557602151081988
          Encrypted:false
          SSDEEP:
          MD5:E7F2A3EE0362E9ED3ECBAD24168AD098
          SHA1:98832274F6D9B641B809123D1272A1C04EEAA177
          SHA-256:6B3609BE4E93D21A2AB492594EDD387931E2C787E8471C9F2D3A677F34002D8F
          SHA-512:C48A76F8251AE455C759CB98802E40B3BEF716FD8E7441B6DE0242942C913367E3572B7C871082E97CA9BE67EC7DC37F8D01C438965217AC0EC36AD508DCE0D4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Azores) {.. {-9223372036854775808 -6160 0 LMT}.. {-2713904240 -6872 0 HMT}.. {-1830376800 -7200 0 -02}.. {-1689548400 -3600 1 -01}.. {-1677794400 -7200 0 -02}.. {-1667430000 -3600 1 -01}.. {-1647730800 -7200 0 -02}.. {-1635807600 -3600 1 -01}.. {-1616194800 -7200 0 -02}.. {-1604358000 -3600 1 -01}.. {-1584658800 -7200 0 -02}.. {-1572735600 -3600 1 -01}.. {-1553036400 -7200 0 -02}.. {-1541199600 -3600 1 -01}.. {-1521500400 -7200 0 -02}.. {-1442444400 -3600 1 -01}.. {-1426806000 -7200 0 -02}.. {-1379286000 -3600 1 -01}.. {-1364770800 -7200 0 -02}.. {-1348441200 -3600 1 -01}.. {-1333321200 -7200 0 -02}.. {-1316386800 -3600 1 -01}.. {-1301266800 -7200 0 -02}.. {-1284332400 -3600 1 -01}.. {-1269817200 -7200 0 -02}.. {-1221433200 -3600 1 -01}.. {-1206918000 -7200 0 -02}.. {-1191193200 -3600 1 -01}.. {-1175468400 -7200 0 -02}.. {-1127689
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8784
          Entropy (8bit):3.833553120942514
          Encrypted:false
          SSDEEP:
          MD5:B04E22B9B42722013941169B5D04DEA2
          SHA1:32B96A7D9504D5022A6C4E2D310E95B5F062947F
          SHA-256:099C3BEFBA3B4C00AE19BC53D475A52B32FAC9B36EC823C8EAEFC7D00F78F388
          SHA-512:8B93BCA1E923B7A43F2EB0889216E8FF991D13CB8D25BD300310ED7CD8537DBD858E8F422C9B52AE2F52F7C1CB450EF0B7C5C1B3AE547C9C1E18E2A851569DD5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Bermuda) {.. {-9223372036854775808 -15558 0 LMT}.. {-2524506042 -15558 0 BMT}.. {-1664307642 -11958 1 BMT}.. {-1648932042 -15558 0 BMT}.. {-1632080442 -11958 1 BMT}.. {-1618692042 -15558 0 BST}.. {-1262281242 -14400 0 AT}.. {-882727200 -10800 1 ADT}.. {-858538800 -14400 0 AST}.. {-845229600 -10800 1 ADT}.. {-825879600 -14400 0 AST}.. {-814384800 -10800 1 ADT}.. {-793825200 -14400 0 AST}.. {-782935200 -10800 1 ADT}.. {-762375600 -14400 0 AST}.. {-713988000 -10800 1 ADT}.. {-703710000 -14400 0 AST}.. {-681933600 -10800 1 ADT}.. {-672865200 -14400 0 AST}.. {-650484000 -10800 1 ADT}.. {-641415600 -14400 0 AST}.. {-618429600 -10800 1 ADT}.. {-609966000 -14400 0 AST}.. {-586980000 -10800 1 ADT}.. {-578516400 -14400 0 AST}.. {-555530400 -10800 1 ADT}.. {-546462000 -14400 0 AST}.. {-429127200 -10800 1 ADT}.. {-415825200 -14400 0 AST}.. {1
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):6856
          Entropy (8bit):3.8064107143060752
          Encrypted:false
          SSDEEP:
          MD5:8ABD279386C50705C074EEE18BF5AE59
          SHA1:C392231DBE744F5942DA4BFAC8AD0ABEBAEA0BF3
          SHA-256:2026944DCDEBC52F64405E35119F4CF97EA9AA1E769498730880B03F29A2B885
          SHA-512:3095759D01AC7EEA25E427CA38E8A0395BEFA7250E7A0C1327BF9D61F07F4570CDF7313FBE6695973EB0DD66D201C6C63591CC0DA8A1E0029926DC7056F4C95B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Canary) {.. {-9223372036854775808 -3696 0 LMT}.. {-1509663504 -3600 0 -01}.. {-733874400 0 0 WET}.. {323827200 3600 1 WEST}.. {338950800 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}.. {749005200 0 0 WET}.. {764730000 3600 1 WEST}.. {780454800 0 0 WET}.. {796179600
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):246
          Entropy (8bit):4.637993677747699
          Encrypted:false
          SSDEEP:
          MD5:1581C6470850E0C9DB204975488B1AF8
          SHA1:6933ED13F18AD785CEDF0837F86EFAC671297A85
          SHA-256:2EA59ACDB5BBDD3C6ABCEEA456838A5CA57371A3D2BB93604B37F998ED8B9D4D
          SHA-512:9FFFA013D82CEFF6F447521C19270ECDD71152F23670164423E6013FEC46253C62D2CB79B42630BD786BD113F27369E746CA981DD17E789F7571F473B47247C1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Cape_Verde) {.. {-9223372036854775808 -5644 0 LMT}.. {-1830376800 -7200 0 -02}.. {-862610400 -3600 1 -01}.. {-764118000 -7200 0 -02}.. {186120000 -3600 0 -01}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.709193799640151
          Encrypted:false
          SSDEEP:
          MD5:601EB889A87F9CAD6F1DF4D1AB009FAE
          SHA1:EB43C253A48755442A67A2408D7E3295549F831C
          SHA-256:64FB8CAD17CD36666C7027AAD01344FEF659B13699EEF1942365842F8ED2170E
          SHA-512:9CFC4A446ED6A3BEF6C26AE57324F10A970EE2ADD6933130447FAD6A3DB538841F2490DD461AF5776FACD9BD2CDC4A83247DFA6B34802AE844DDC6D4C37B28EA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Atlantic/Faroe)]} {.. LoadTimeZoneFile Atlantic/Faroe..}..set TZData(:Atlantic/Faeroe) $TZData(:Atlantic/Faroe)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):6796
          Entropy (8bit):3.804838552487436
          Encrypted:false
          SSDEEP:
          MD5:F97CC7EB9C52D00177BFF4715832FCD5
          SHA1:CD9DCBB5E6ADD6EA91C8F142957EC229FC7F6DA3
          SHA-256:795F438E7F01342D5F25ECCDD09FCE65C03C5D2D561B9B5191301D57EC16B850
          SHA-512:9586289FEB6C597160011A47432F0AC40000483FA2E579BD89046EFD33E98DDAD652B792FD80CEDEB4CD87B6439A7B473F25F1B7375BC75353CBAF9F77E1084E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Faroe) {.. {-9223372036854775808 -1624 0 LMT}.. {-1955748776 0 0 WET}.. {347155200 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}.. {749005200 0 0 WET}.. {764730000 3600 1 WEST}.. {780454800 0 0 WET}.. {796179600 3600 1 WEST}.. {811904400 0 0 WET}.. {828234000 3600
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.957633978425468
          Encrypted:false
          SSDEEP:
          MD5:95C2D55CCE5809089CDB041EA3D464F8
          SHA1:B395F5F26CE979BDF2B9E2CB51C06929AED11A6C
          SHA-256:11BF0746F95BA01807D3B34C8FAE3FF4AE9DB5E4E6BC0CB8B36906CC3F44EDE5
          SHA-512:AB2BE22E95A7C36E18EBA1BB63B3930A523ED793E43A3F597A8F63AE2F0E44436C39144BC136E7E5716D7FCBFAE7F1FAF36BCFFCF9C8D51151FF25BB14D6F8B5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Atlantic/Jan_Mayen) $TZData(:Europe/Berlin)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9709
          Entropy (8bit):3.80455694200614
          Encrypted:false
          SSDEEP:
          MD5:AC6647F9B53B5958214EC3F3B78A4D85
          SHA1:7355622AF99296F069F73899D5C70941C207F676
          SHA-256:B2A0D0DDC26806A05B2BE806CA3F938DB12A3FA40110B8B21FD3F04EFED3A531
          SHA-512:07569CA4D5DC6D57D91D6FDC370671A7546B73BA653D094E1B501D33570F7700727AD7FF2A083BC79E9EDE807C47E7A5604BEF5803F290B2F277C51DEF10FA6B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Madeira) {.. {-9223372036854775808 -4056 0 LMT}.. {-2713906344 -4056 0 FMT}.. {-1830380400 -3600 0 -01}.. {-1689552000 0 1 +00}.. {-1677798000 -3600 0 -01}.. {-1667433600 0 1 +00}.. {-1647734400 -3600 0 -01}.. {-1635811200 0 1 +00}.. {-1616198400 -3600 0 -01}.. {-1604361600 0 1 +00}.. {-1584662400 -3600 0 -01}.. {-1572739200 0 1 +00}.. {-1553040000 -3600 0 -01}.. {-1541203200 0 1 +00}.. {-1521504000 -3600 0 -01}.. {-1442448000 0 1 +00}.. {-1426809600 -3600 0 -01}.. {-1379289600 0 1 +00}.. {-1364774400 -3600 0 -01}.. {-1348444800 0 1 +00}.. {-1333324800 -3600 0 -01}.. {-1316390400 0 1 +00}.. {-1301270400 -3600 0 -01}.. {-1284336000 0 1 +00}.. {-1269820800 -3600 0 -01}.. {-1221436800 0 1 +00}.. {-1206921600 -3600 0 -01}.. {-1191196800 0 1 +00}.. {-1175472000 -3600 0 -01}.. {-1127692800 0 1 +00}.. {-1111968000 -3600 0 -01}.. {-
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.910514445868106
          Encrypted:false
          SSDEEP:
          MD5:ECB480DA99D29C0ACE67426D45534754
          SHA1:784CF126B030C3D883EE541877E6181F795C9697
          SHA-256:BDA015714260001BAE2848991DD21E802580BE2915797E5DABC376135D1C5246
          SHA-512:54C1B20E45C7C73354DCD4E0F4444720771820ED10B282F745DC391BEADEAEDC629BEF97B1908FB62CDAEC915D32AF1F54FC6AA9DC83E317E7CE19FC2586EF28
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Atlantic/Reykjavik) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):160
          Entropy (8bit):5.011466665416709
          Encrypted:false
          SSDEEP:
          MD5:3B310BB8C90CA716DC1AC5A697ACA9CD
          SHA1:CD583F49478DCDAD91EF78539502C6FC62945C1E
          SHA-256:51BFABCB3388107753A3C1A8CF31118E6627132BAA09B9878D9E7CEDBEBB4886
          SHA-512:F593B7A1FAF0EA6B42D5EE86C20C9A8F5CD7ACD9B30EF7755E45ECAFEA8752C32E4CF4BEDF531F494E59D9F0C49CCC6FCA077292E20794AA265DFC0A56DFE579
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/South_Georgia) {.. {-9223372036854775808 -8768 0 LMT}.. {-2524512832 -7200 0 -02}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.880390141563645
          Encrypted:false
          SSDEEP:
          MD5:2C73A963F515376A46762CE153AAF5C5
          SHA1:996C3C93DFAD89EA80AC5DFA1DFBD7CECD9ED28D
          SHA-256:1C9CA8966FC8BD0BE70F4A187E17E56FB99139BC88C392E82BA2E23E23111C54
          SHA-512:35A9ADC047DB058D71C21FC4ECB57CD14B0D9BA4416506763D1800D72CE6C9E81636F332AAD3533616F05C86F90A60416BD4065C5F832A51AA3DC186218BDCAE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Atlantic/St_Helena) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2256
          Entropy (8bit):3.662522763865322
          Encrypted:false
          SSDEEP:
          MD5:77C7ECE4FCBE150069B611C75E8DAA0E
          SHA1:22F4E5F15BCA92D8456B70BB36230F2605CA5E1C
          SHA-256:F0E99EF01F140CD5AAFE16803A657922207E6F7F6AF10B0AE795790916C302C4
          SHA-512:6FB57E8499A587292AFAFA9BD003721572393D5268CAF956230DA76983A112B27D6731BE561A22CCEF84935F43AC988B667C2DC404C157EA8D0E7830FC1A2AB8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Stanley) {.. {-9223372036854775808 -13884 0 LMT}.. {-2524507716 -13884 0 SMT}.. {-1824235716 -14400 0 -04}.. {-1018209600 -10800 1 -04}.. {-1003093200 -14400 0 -04}.. {-986760000 -10800 1 -04}.. {-971643600 -14400 0 -04}.. {-954705600 -10800 1 -04}.. {-939589200 -14400 0 -04}.. {-923256000 -10800 1 -04}.. {-908139600 -14400 0 -04}.. {-891806400 -10800 1 -04}.. {-876690000 -14400 0 -04}.. {-860356800 -10800 1 -04}.. {420606000 -7200 0 -03}.. {433303200 -7200 1 -03}.. {452052000 -10800 0 -03}.. {464151600 -7200 1 -03}.. {483501600 -10800 0 -03}.. {495597600 -14400 0 -04}.. {495604800 -10800 1 -04}.. {514350000 -14400 0 -04}.. {527054400 -10800 1 -04}.. {545799600 -14400 0 -04}.. {558504000 -10800 1 -04}.. {577249200 -14400 0 -04}.. {589953600 -10800 1 -04}.. {608698800 -14400 0 -04}.. {621403200 -10800 1 -04}.. {640753200 -14400 0 -
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.862270414049974
          Encrypted:false
          SSDEEP:
          MD5:2EF41863430897F45E0CBB51E6A44069
          SHA1:8E9561060E9509FAF235E5E033FC9C2918E438DB
          SHA-256:DF7CBDDCBB2F5926A07D19A35739E5B8DCD9733C037F7D1FF95753C28D574674
          SHA-512:9D3A37D64DCCCA28093C30FAB595690D021FACEC15F351A77CA33A779D645D305A2FA031869F0DE3B0404C498C2C321D3D02E4DC592D3C632F6700F5DCB54900
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/ACT) $TZData(:Australia/Sydney)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8372
          Entropy (8bit):3.894755849491153
          Encrypted:false
          SSDEEP:
          MD5:94E1A0C4326D09AF103107E64625CC6C
          SHA1:C026565F020EB158309549D98313632BAA79205F
          SHA-256:5C43D3152982BCFD5B9F51D0E909CF3A558BED1C270FEFFE030531D38D6F91B7
          SHA-512:CA08A8BC0EB740D59650FE0A9E56D9E169348AD0994F2BFFD6CCFBF9CC42E82F892FB719E80C4E2084B5702E9725C651359EE3066BD71BB19397EA83B6A68430
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Adelaide) {.. {-9223372036854775808 33260 0 LMT}.. {-2364110060 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}.. {31501800 34200 0 ACST}.. {57688200 37800 1 ACDT}.. {67969800 34200 0 ACST}.. {89137800 37800 1 ACDT}.. {100024200 34200 0 ACST}.. {120587400 37800 1 ACDT}.. {131473800 34200 0 ACST}.. {152037000 37800 1 ACDT}.. {162923400 34200 0 ACST}.. {183486600 37800 1 ACDT}.. {194977800 34200 0 ACST}.. {215541000 37800 1 ACDT}.. {226427400 34200 0 ACST}.. {246990600 37800 1 ACDT}.. {257877000 34200 0 ACST}.. {278440200 37800 1 ACDT}.. {289326600 34200 0 ACST}.. {309889800 37800 1 ACDT}.. {320776200 34200 0 ACST}
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):674
          Entropy (8bit):4.32071371733564
          Encrypted:false
          SSDEEP:
          MD5:900B39F1D4AB93A445F37B6C0A8DE3D9
          SHA1:DE82800779DCB8094C395B5024BD01FFA3C3BB8C
          SHA-256:0D3C39EDAB34A8DB31A658A1549772F7D69EB57565E40AA87B707953A2D854A4
          SHA-512:8D115D1D14FE6FF21A4AE77E3AAC075E6A877214E568956B9A4FD2E75A46E458CAA5AE26B483F128B4C62960D73BD7543BC32F22B760059423B3D9ABCBA24B6A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Brisbane) {.. {-9223372036854775808 36728 0 LMT}.. {-2366791928 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {625593600 39600 1 AEDT}.. {636480000 36000 0 AEST}.. {657043200 39600 1 AEDT}.. {667929600 36000 0 AEST}.. {688492800 39600 1 AEDT}.. {699379200 36000 0 AEST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8437
          Entropy (8bit):3.902306256303896
          Encrypted:false
          SSDEEP:
          MD5:1553DAAB804A6C9BB15D711554980D3B
          SHA1:5E3161B1FBB4C246DCB5E11ABD94095121CE38ED
          SHA-256:734F295BD0B558BDF6178DE62151B8913699D08AB2B1D101C55B8DEBC410074C
          SHA-512:06B21886070E39E390ECBD18841B7FDBFCA2C7C8573495D2BAA2B92EB113CD1C73C18D73C49DE3C49572CBCBCBED2FAD3248BC651BEB825A1E089B1DEDEFCBFA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Broken_Hill) {.. {-9223372036854775808 33948 0 LMT}.. {-2364110748 36000 0 AEST}.. {-2314951200 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}.. {31501800 34200 0 ACST}.. {57688200 37800 1 ACDT}.. {67969800 34200 0 ACST}.. {89137800 37800 1 ACDT}.. {100024200 34200 0 ACST}.. {120587400 37800 1 ACDT}.. {131473800 34200 0 ACST}.. {152037000 37800 1 ACDT}.. {162923400 34200 0 ACST}.. {183486600 37800 1 ACDT}.. {194977800 34200 0 ACST}.. {215541000 37800 1 ACDT}.. {226427400 34200 0 ACST}.. {246990600 37800 1 ACDT}.. {257877000 34200 0 ACST}.. {278440200 37800 1 ACDT}.. {289326600 34200 0 ACST}.. {309889800 37800 1
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):195
          Entropy (8bit):4.851279484907769
          Encrypted:false
          SSDEEP:
          MD5:8944D3DF8FBECC03A8FB18C3B2DA3B53
          SHA1:6B17B38D6560592CA49840C47DB9BDA7E79F9F76
          SHA-256:5FE3CED97293FE0573D5ECE0CEF59CE5DDB4C57BC568AE7199E77B01D3ADE17C
          SHA-512:907D8BB7EA840E0B3AC683884F2F709A2C06D67CE9258BE46400A0DA63581A9B1403A44FA43E1059BE8F5C7E06F9FA05C176309AD6295317BF14F0E9FA5741E4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/Canberra) $TZData(:Australia/Sydney)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):193
          Entropy (8bit):4.79231670095588
          Encrypted:false
          SSDEEP:
          MD5:0C1DFC0877CE8EB08007B7C2B7AF2D87
          SHA1:02F835BE2DA4FCA79DC2A6959BB4EB6ACC8DF708
          SHA-256:1DD4EC4ED4F854E2EF6162B2F28C89208710F8EC5AABB95FFA9425D3FBBCAB13
          SHA-512:358347045915B7D10940DB15E49528D0C636BEC1BE70129847D0B9D034F9E96E847394D88358E87D98A9E581605A3C2AB917B85FDE1296F290B4194BB7E3FA46
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Hobart)]} {.. LoadTimeZoneFile Australia/Hobart..}..set TZData(:Australia/Currie) $TZData(:Australia/Hobart)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):437
          Entropy (8bit):4.508468081487136
          Encrypted:false
          SSDEEP:
          MD5:A81864B2C0BD7BF81F4FA21F17800059
          SHA1:518AC9E040A17083ED3962F4FBB47D1D83764FF7
          SHA-256:AC004FD4B3C536406991EC13EBB3E64E0EC0C7B264BC18C0700C8FA545868155
          SHA-512:3C24F4C2CC3072B3E820FCC1C68A747DCCBB9481FE743C1555783CC932DCBA44FE4851A732D24EABF62E845474D4E1278F120A04DB7549A18C7C49C31FB8D425
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Darwin) {.. {-9223372036854775808 31400 0 LMT}.. {-2364108200 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):759
          Entropy (8bit):4.110997549215461
          Encrypted:false
          SSDEEP:
          MD5:1BC8DBD2E24606EFA49F933034FC0EEF
          SHA1:A511695A1B87A689C6BFF65257C11D3962FDDA3D
          SHA-256:79D0C770A304360DB33F3D1EF7B3935F1E4E8125893E0DCE683AC35A51302CFB
          SHA-512:A839D390D70F22FC833322029B732F3AE68FF48793B07005041BD12322DD6E5D5E5FF31787AA004A507A57F8FC245133891F266C4EF19D49F085E6B412E5B04C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Eucla) {.. {-9223372036854775808 30928 0 LMT}.. {-2337928528 31500 0 +0945}.. {-1672555500 35100 1 +0945}.. {-1665384300 31500 0 +0945}.. {-883637100 35100 1 +0945}.. {-876120300 31500 0 +0945}.. {-860395500 35100 1 +0945}.. {-844670700 31500 0 +0945}.. {-836473500 35100 0 +0945}.. {152039700 35100 1 +0945}.. {162926100 31500 0 +0945}.. {436295700 35100 1 +0945}.. {447182100 31500 0 +0945}.. {690311700 35100 1 +0945}.. {699383700 31500 0 +0945}.. {1165079700 35100 1 +0945}.. {1174756500 31500 0 +0945}.. {1193505300 35100 1 +0945}.. {1206810900 31500 0 +0945}.. {1224954900 35100 1 +0945}.. {1238260500 31500 0 +0945}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8734
          Entropy (8bit):3.8515786470328823
          Encrypted:false
          SSDEEP:
          MD5:5E04BF8E1DEBFCC4130FDD1BBD67B2DF
          SHA1:796AADCE7BB2FAF5E6FC916C941A4E3DCAFACC9E
          SHA-256:D813F6A97BEFC22CA4F24C59EB755D269B9C68A449CC7CF0D2C61F911860EBE7
          SHA-512:3A69CF1D1F57D6BD39E5F4DAF76BBB06A749D42BEB29452A0A5BDAA68F5DACC0DF176EDDA7A083F5B5B84FC651926C09D46CAAD2F6C4F1595AB9CCA1A958D653
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Hobart) {.. {-9223372036854775808 35356 0 LMT}.. {-2345795356 36000 0 AEST}.. {-1680508800 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-1646640000 39600 1 AEDT}.. {-1635753600 36000 0 AEST}.. {-1615190400 39600 1 AEDT}.. {-1604304000 36000 0 AEST}.. {-1583920800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {-94730400 36000 0 AEST}.. {-71136000 39600 1 AEDT}.. {-55411200 36000 0 AEST}.. {-37267200 39600 1 AEDT}.. {-25776000 36000 0 AEST}.. {-5817600 39600 1 AEDT}.. {5673600 36000 0 AEST}.. {25632000 39600 1 AEDT}.. {37728000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AES
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):199
          Entropy (8bit):4.912882643701746
          Encrypted:false
          SSDEEP:
          MD5:425DC7B1E31F4AA41DAD74E3C9AE3562
          SHA1:D92A3269F7BF5EC00F082C64CEF6E20C43017180
          SHA-256:4D84E4040FBC529C9E0366BB74D0CFADEEEEDA0DFCC6C2C9204DED6C6455CAC3
          SHA-512:F3031F16C0D00D9F8A38CD378F599EB3E63F4FF85F120DB38E3013E93F08E6F512D969F164BBC88CD625910FB3E086F3352E5B8FFC1373C3CC98F363FB3FD3F7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Lord_Howe)]} {.. LoadTimeZoneFile Australia/Lord_Howe..}..set TZData(:Australia/LHI) $TZData(:Australia/Lord_Howe)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):824
          Entropy (8bit):4.249672335529665
          Encrypted:false
          SSDEEP:
          MD5:504A422280E0459A2126E7CB02F527E6
          SHA1:EF61B98EFB1E44EE59020E99A69EA67D6B8ACFC2
          SHA-256:01B278309353849CC2FDF62A30E2FF483833D5713CF5E329252738BE6F2C0A84
          SHA-512:BFDAAD56D817CD3AAB17DFD0A33EFDD422645BC542ABE269C0F8520E33796DF4F19EAB2E40BFC6C4AF93EF654239B8F2E285639B4662040D865B9C340A23CFAD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Lindeman) {.. {-9223372036854775808 35756 0 LMT}.. {-2366790956 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {625593600 39600 1 AEDT}.. {636480000 36000 0 AEST}.. {657043200 39600 1 AEDT}.. {667929600 36000 0 AEST}.. {688492800 39600 1 AEDT}.. {699379200 36000 0 AEST}.. {709912800 36000 0 AEST}.. {719942400 39600 1 AEDT}.. {731433600 36000 0 AEST}.. {751996800 39600 1 AEDT}.. {762883200 36000 0 AEST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7764
          Entropy (8bit):3.5615258807990537
          Encrypted:false
          SSDEEP:
          MD5:10F983F4683CDE13A1228AC0B04D8513
          SHA1:45378BA5949BE53D698108F50FECFF50C9E3D296
          SHA-256:76D1F1ED67B8F8D6903789C2FDDF79590A83677972D416F5F3C9687614EC6238
          SHA-512:D60D802EF215A33750E4F859657BA12A67084B1E9FCF1B4A7CEEE7B9D816BC2C6670775D93C88EC8380CDD7790AD574133D6F90F0828F848313C26583B2F196A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Lord_Howe) {.. {-9223372036854775808 38180 0 LMT}.. {-2364114980 36000 0 AEST}.. {352216800 37800 0 +1030}.. {372785400 41400 1 +1030}.. {384273000 37800 0 +1030}.. {404839800 41400 1 +1030}.. {415722600 37800 0 +1030}.. {436289400 41400 1 +1030}.. {447172200 37800 0 +1030}.. {467739000 41400 1 +1030}.. {478621800 37800 0 +1030}.. {488984400 37800 0 +1030}.. {499188600 39600 1 +1030}.. {511282800 37800 0 +1030}.. {530033400 39600 1 +1030}.. {542732400 37800 0 +1030}.. {562087800 39600 1 +1030}.. {574786800 37800 0 +1030}.. {594142200 39600 1 +1030}.. {606236400 37800 0 +1030}.. {625591800 39600 1 +1030}.. {636476400 37800 0 +1030}.. {657041400 39600 1 +1030}.. {667926000 37800 0 +1030}.. {688491000 39600 1 +1030}.. {699375600 37800 0 +1030}.. {719940600 39600 1 +1030}.. {731430000 37800 0 +1030}.. {751995000 39600 1 +1030}.. {762
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8341
          Entropy (8bit):3.8532171550973526
          Encrypted:false
          SSDEEP:
          MD5:40D06B80A4A0DB415270EFD9698B97BF
          SHA1:1999F0E8C7EBAA11BD21D64D9E07FA911F13C64C
          SHA-256:F21B9EA51C0D41BAD0420FE0601E5A4B491FB895856F4BDDF6541D704469D92F
          SHA-512:E47D597CC85D177CF2804C44C216EB4C5B74472457F15F697704311A847BF8A051DCAFD26FA61DD689555F35640151E26F25D5DC5319EFEFEA62AD86657A4A95
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Melbourne) {.. {-9223372036854775808 34792 0 LMT}.. {-2364111592 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AEST}.. {152035200 39600 1 AEDT}.. {162921600 36000 0 AEST}.. {183484800 39600 1 AEDT}.. {194976000 36000 0 AEST}.. {215539200 39600 1 AEDT}.. {226425600 36000 0 AEST}.. {246988800 39600 1 AEDT}.. {257875200 36000 0 AEST}.. {278438400 39600 1 AEDT}.. {289324800 36000 0 AEST}.. {309888000 39600 1 AEDT}.. {320774400 36000 0 AEST}.. {341337600 39600 1 AEDT}.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.893713405897538
          Encrypted:false
          SSDEEP:
          MD5:80B7CDD1EA5A5308CE84C038180005F2
          SHA1:B7CA15B58ADA8CA3EB74B7971073022D57D8EE70
          SHA-256:73D7C9E207E61ACF8DF7242BDCD84488189033E22A84873A953B65DE02FA1B0B
          SHA-512:F627F5FF335600AC9158D6A0D3694AB7E70180177449C17B5605BBF7B1B7F8FB447A9C207F4E1BCB627074DB47B8A66F5D78E03C6DB8FA17F8BDD6AABB331665
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/NSW) $TZData(:Australia/Sydney)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):192
          Entropy (8bit):4.830368875485429
          Encrypted:false
          SSDEEP:
          MD5:14CB7EA1C028F457345EBEB8ADDC9237
          SHA1:208BF676F56533BA271D1B98363A766DF17CF6F2
          SHA-256:A983C9CAD7E542CAED43B083E68CD2B782959A4B54015F374C29250D3ACF9B8D
          SHA-512:099F65E5FA705FD7257CF7B8E103905EE313C6D082844F69CCD3F318E3E7F4098B29F952FA0AA28655E1FE290A0FB2E809911088315889DE7CAAF0E04698C2FC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Darwin)]} {.. LoadTimeZoneFile Australia/Darwin..}..set TZData(:Australia/North) $TZData(:Australia/Darwin)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):739
          Entropy (8bit):4.31793586514766
          Encrypted:false
          SSDEEP:
          MD5:01B1A88867472AD60B8F5C0E1648E3ED
          SHA1:9975EA750458E8061DD8A83585675CB7E4910CA6
          SHA-256:FC1B54CA261074E47A8A486FEAC12DD04D46166D1D2B44163BD8791BEC32D275
          SHA-512:20BDFBCD1A5038C81552EBD955F3921DE3447A1F30E64935937768B2B98735AE53049601DCDD2D519646C78E6D03289EB465CFF4F2DADEA7D89A329504C6C475
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Perth) {.. {-9223372036854775808 27804 0 LMT}.. {-2337925404 28800 0 AWST}.. {-1672552800 32400 1 AWDT}.. {-1665381600 28800 0 AWST}.. {-883634400 32400 1 AWDT}.. {-876117600 28800 0 AWST}.. {-860392800 32400 1 AWDT}.. {-844668000 28800 0 AWST}.. {-836470800 32400 0 AWST}.. {152042400 32400 1 AWDT}.. {162928800 28800 0 AWST}.. {436298400 32400 1 AWDT}.. {447184800 28800 0 AWST}.. {690314400 32400 1 AWDT}.. {699386400 28800 0 AWST}.. {1165082400 32400 1 AWDT}.. {1174759200 28800 0 AWST}.. {1193508000 32400 1 AWDT}.. {1206813600 28800 0 AWST}.. {1224957600 32400 1 AWDT}.. {1238263200 28800 0 AWST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):203
          Entropy (8bit):4.803539644461131
          Encrypted:false
          SSDEEP:
          MD5:401B6B2E30EF17BE20212645287EB94B
          SHA1:67D15A45C61122CE680B829FE0FA3A1C501A8C8F
          SHA-256:DDA669B9BFB3E08FC23CE67030148B9E4740824ADD8DE02580D6AFD31CE05BAB
          SHA-512:F4348F8F4FF261C47854725AEE4E14E7E334B3C31496E5C46B0E0041551CB6861380E684E8888AFE9DA7E8E97236AC322B9CE2738EF245E9D46C9681665F83A1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Brisbane)]} {.. LoadTimeZoneFile Australia/Brisbane..}..set TZData(:Australia/Queensland) $TZData(:Australia/Brisbane)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):198
          Entropy (8bit):4.752918480727309
          Encrypted:false
          SSDEEP:
          MD5:D226A0718185854DFE549E00856AA8D5
          SHA1:94EE96FAE259D90C2FDF169DD95BD82B3171FFAE
          SHA-256:D9DCFDC377901EC0C0FEB9CEA743C2C1425273F69A1BAA7BF3B74FEC5885B267
          SHA-512:7EE29A7235CAAEF4889246B7A2241CA9A0D5D2B2E1D56B20141247C93B8736F17280F0D46004AC4588E137D1E76F661C779C906BBFC2B5F8FA73C19F7657F952
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Adelaide)]} {.. LoadTimeZoneFile Australia/Adelaide..}..set TZData(:Australia/South) $TZData(:Australia/Adelaide)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8338
          Entropy (8bit):3.847525715050911
          Encrypted:false
          SSDEEP:
          MD5:C0F1776E011C4C86B7709A592E7CA1EB
          SHA1:1CA528D529BF4995E145D6E0D87A8752A3577E7F
          SHA-256:FC453486325ADE1D31F14087B76D4936F3A6D551ABD1DB6FCAC129BDB043951C
          SHA-512:F872182962C2615A35F012ECAB30C88F07C6BEF0261207AD52706DB22D8CDD0DA65723CD801FDA7C548C5EB0ECFC39DD66CC17503BAA3BBB77BFA35D20650E4F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Sydney) {.. {-9223372036854775808 36292 0 LMT}.. {-2364113092 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AEST}.. {152035200 39600 1 AEDT}.. {162921600 36000 0 AEST}.. {183484800 39600 1 AEDT}.. {194976000 36000 0 AEST}.. {215539200 39600 1 AEDT}.. {226425600 36000 0 AEST}.. {246988800 39600 1 AEDT}.. {257875200 36000 0 AEST}.. {278438400 39600 1 AEDT}.. {289324800 36000 0 AEST}.. {309888000 39600 1 AEDT}.. {320774400 36000 0 AEST}.. {341337600 39600 1 AEDT}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):195
          Entropy (8bit):4.777331394201868
          Encrypted:false
          SSDEEP:
          MD5:9C58D9EFBB03472BBDA76CE2FFAD4BB4
          SHA1:30959E3681B64AE26F7FA3957887896C26AF7F19
          SHA-256:C94FA7A7640CD00963EE8FF1A3D9DCDA2075408739D998EDBF7CFC998DB764FD
          SHA-512:2D6B778217726691F2CB4A4995A8B1AB08DDB7FE4570A3FD04EF54F718F455EF3CBD4EEF1A1BCC99A2088C82A6E89DB455BAF1327CECD6BF608837E50F14A6C1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Hobart)]} {.. LoadTimeZoneFile Australia/Hobart..}..set TZData(:Australia/Tasmania) $TZData(:Australia/Hobart)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):204
          Entropy (8bit):4.818875198673406
          Encrypted:false
          SSDEEP:
          MD5:0B144A2E47C81354BC510BC741DE5150
          SHA1:A7396F1741F02C6C208FD1286362E4E0720198B8
          SHA-256:DBEF9C5BDD290FEC5FA740D697143332D3CA1FC373CF1DF736F1883AC9BA3298
          SHA-512:562B029591F9ADB8C324BA56E849B2B524E91B26D3DB441510194882A8E1E63E6948D041874A00A0A76F29925A1CEAC53DD2AE5D7F23123B6FE919346CBFD8CC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Melbourne)]} {.. LoadTimeZoneFile Australia/Melbourne..}..set TZData(:Australia/Victoria) $TZData(:Australia/Melbourne)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.831654343064909
          Encrypted:false
          SSDEEP:
          MD5:5F5916CB038876BE27AA5E2AD74EE085
          SHA1:18AC21B638188B542455BA3DA91F958DF1724E68
          SHA-256:75ABB7F20C4A0B618138AA190AF33CEAF2A6D2C707DA6C1314E4BFF2F9904F58
          SHA-512:ADFD83E292AC1BB5E19255A9B2DA0E3BB9323A5F9B92D458DE34C291D7F9B6CFBBF62AA3351FB320E54F34305DD485ADC72134D21AFA6A27B2B8B7D93DCA2113
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Perth)]} {.. LoadTimeZoneFile Australia/Perth..}..set TZData(:Australia/West) $TZData(:Australia/Perth)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):212
          Entropy (8bit):4.918079927018121
          Encrypted:false
          SSDEEP:
          MD5:BEDEA56FCE4B2F0A3F3E9319856A5560
          SHA1:9FD0FE998A003C6B4CCCD00A977153347DE07F55
          SHA-256:55A9264D0414644A1BE342106AE86086A6659596DC9322A74FC4D1DDB41F7C60
          SHA-512:7C438B72262B99EDEEB31AC95E0135BB722A3B0B049278B6DE67DB5FB501837FB9C03785233B538E83F4B56104F6EA3B3DA0F7C2275E0F78F232161840AA4C63
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Broken_Hill)]} {.. LoadTimeZoneFile Australia/Broken_Hill..}..set TZData(:Australia/Yancowinna) $TZData(:Australia/Broken_Hill)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):194
          Entropy (8bit):4.888429541699473
          Encrypted:false
          SSDEEP:
          MD5:A8A7A10DA4321819ED71F891480770F8
          SHA1:930674EF7711542D7F471A59C1870D4576E027FD
          SHA-256:2F594239A434052D36053A2B3EAB134EADBAD06EB6737E67CF72166DAB157537
          SHA-512:C6AD1869A713DDE0E4DE53F7894E5CE0B7AEFDDD7C5C3D83BB5B92FB7D8E20B373A6694045053E1AE8EA98A7B7D0C052EF2C21310E47DC650A7A399A5F73D586
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Rio_Branco)]} {.. LoadTimeZoneFile America/Rio_Branco..}..set TZData(:Brazil/Acre) $TZData(:America/Rio_Branco)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.875339623736144
          Encrypted:false
          SSDEEP:
          MD5:E0D0EFBEC37E27532B49FF6DD9893DA0
          SHA1:9C00993A885AF448E48201A46E17629A7A602FC6
          SHA-256:A676562A90FF8587A775F6F0E3BE05D870456A56D25B5330816BF9043C8D475B
          SHA-512:AB0E6907F9C0002CA5C050A0069AF013B14BADA08CA4553C96B302C078DF7629D5D7EDE4A19A53DEC6E7B9E6D9857F14EC7A1DB9BC11F2EEC9FFBAC70E129EEE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Noronha)]} {.. LoadTimeZoneFile America/Noronha..}..set TZData(:Brazil/DeNoronha) $TZData(:America/Noronha)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):191
          Entropy (8bit):4.948480276987682
          Encrypted:false
          SSDEEP:
          MD5:FCCB5F44903E1B988A058E5BBF5E163B
          SHA1:E1CC03DD4A804C7305D8B0C12D8451D08AE262EA
          SHA-256:961FB3AB99A63B1E9704B737EAB2D588B5A39D253A213E175CC678BEDFFD498D
          SHA-512:F31C80E4AD6EBE6CB8A3382E0052DC47601D073E8F81375D50241105675AA3AB45433FFD0534524D9992ABE1086C6671D85FF7C72B0D6766EB9984426F608B77
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Sao_Paulo)]} {.. LoadTimeZoneFile America/Sao_Paulo..}..set TZData(:Brazil/East) $TZData(:America/Sao_Paulo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.902113962502196
          Encrypted:false
          SSDEEP:
          MD5:9F4B43F4F27D0B7EAC0C5401A1A794B4
          SHA1:2A8543B994E93E54BD50EAA78463905E6A8EBE74
          SHA-256:0500C9A248C8CE9030EA30D0AF9DD95DC465480BAF60646C0B7C511FA23C6D1F
          SHA-512:0ADAF708ACFBD80F4704951EEBC24AD144FD5856997A429279E804F3A7F7F9A8FED41DCEE85BFB1ECDBF1E05137E87E7430186474BCF5DE42067FFC74746F048
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Manaus)]} {.. LoadTimeZoneFile America/Manaus..}..set TZData(:Brazil/West) $TZData(:America/Manaus)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7736
          Entropy (8bit):3.7984816540097843
          Encrypted:false
          SSDEEP:
          MD5:6DB983AD72FB2A88FC557BE5E873336F
          SHA1:C64E988010087ED559A990B3D95078949C9B4D72
          SHA-256:E2AEA7CFD428A43D9DB938BCC476623ADC1250BD8057013A7FFF5F89D7FF8EFC
          SHA-512:C0A646F80FB2FD42D9146A4FD36CF5A7F62016684F8D5AF80453EC190F4AEA65EDADC5BCF071AE746ABFB43B29C27B2743F2152B6986D41BFDE1617CA774A7C5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:CET) {.. {-9223372036854775808 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766623600 3600 0 CET}.. {228877200 7200 1 CEST}.. {243997200 3600 0 CET}.. {260326800 7200 1 CEST}.. {276051600 3600 0 CET}.. {291776400 7200 1 CEST}.. {307501200 3600 0 CET}.. {323830800 7200 1 CEST}.. {338950800 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CET}.. {386125200 7200 1 CEST}.. {401850000 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8505
          Entropy (8bit):3.8095769056779916
          Encrypted:false
          SSDEEP:
          MD5:A6F88C55E8613A27DE3E6C25B0672910
          SHA1:3B593CC17BF153A6209FC5AACE7B88DA9603BD44
          SHA-256:73A9841F233AA657AFB6CED8A86A37D55FE5582DD996B9B28975D218BCCC078F
          SHA-512:526A922B1594A2800B03F363F7BFEC29203D4A4F2B49C5F2618469F59176CE4F8AFBA0616B226AC39D308DB05DE7147714D9B6CDBB2EA7373A041A4D47F50E2E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:CST6CDT) {.. {-9223372036854775808 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-84384000 -18000 1 CDT}.. {-68662800 -21600 0 CST}.. {-52934400 -18000 1 CDT}.. {-37213200 -21600 0 CST}.. {-21484800 -18000 1 CDT}.. {-5763600 -21600 0 CST}.. {9964800 -18000 1 CDT}.. {25686000 -21600 0 CST}.. {41414400 -18000 1 CDT}.. {57740400 -21600 0 CST}.. {73468800 -18000 1 CDT}.. {89190000 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {126691200 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {162374400 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000 1 CDT}.. {247042800 -21600 0 CST}.. {262771200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.804821796604604
          Encrypted:false
          SSDEEP:
          MD5:33A04963E70EBF29339204348E0DF874
          SHA1:456C0DB88ECE4D180EEE5AE5AEF5FBEB6E977D00
          SHA-256:6DC6354D761CBE7820C9186568CAB87AD48CA925507F6A740357195B60E16D87
          SHA-512:DF8F46827760BD7EC922C6837E0B6649B4FBD220B79E6F1B67FE3DD8CB3D2D035ECDAF4CF6CE5BDE6DC79C6F7B6EE2B9787AF08A97845CD0D647720A2E78D7EF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Halifax)]} {.. LoadTimeZoneFile America/Halifax..}..set TZData(:Canada/Atlantic) $TZData(:America/Halifax)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):191
          Entropy (8bit):4.863241040396457
          Encrypted:false
          SSDEEP:
          MD5:97E50CE9FBA3F1A6DFCF333F9E6D592C
          SHA1:EE472C411079E788DBF32FAC9C5B7EE121960DC2
          SHA-256:DB32E83949D62478D229E9FB57BB1624D21B3A9CCEE4CD55335F8262C01D820A
          SHA-512:D547E3DC03848A677BE67F7CF4124E067F76EE09BB724A5B10F028BEA72C1526B17678A035B2C53F69498E9ECAACD3C5445D42B7FE58DF706DD2C5F2ADA05A73
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Winnipeg)]} {.. LoadTimeZoneFile America/Winnipeg..}..set TZData(:Canada/Central) $TZData(:America/Winnipeg)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.758562813220951
          Encrypted:false
          SSDEEP:
          MD5:4365BEFA3D50EEE20843EF97A095E512
          SHA1:7756049B4CD6459742686925E9516E64A9727306
          SHA-256:22844994AE893F3236A091B050E932E84A5218EC0D01F72595E17CCC471FA564
          SHA-512:CB265E79DF926026BEBF7158590369ABE5353C759540F509ABBA2A7ADBE59A705BC2AB936F400614BE610EDB761DE9A2B1E179A0A8B0A87E595392362C2516AA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:Canada/Eastern) $TZData(:America/Toronto)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):192
          Entropy (8bit):4.8181126338833655
          Encrypted:false
          SSDEEP:
          MD5:FA0D0024AD72CCE4EC7229FA897FB1B7
          SHA1:4373A07F2674FE974189CC801987652AA97F0204
          SHA-256:D7A203E60FF19DCDEAAD14121720DE51DA73392D25B40FFA301C1935CDF89517
          SHA-512:82EF7F429604A69734B04D298B4C9C9AC3BE57B9DD8C4CECF59C7AB3470BDFBA0505886C4E6AA3864F5EC7FBB4C69C54CF153A6417376828234833013C29A0C1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Edmonton)]} {.. LoadTimeZoneFile America/Edmonton..}..set TZData(:Canada/Mountain) $TZData(:America/Edmonton)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):196
          Entropy (8bit):4.998628928230972
          Encrypted:false
          SSDEEP:
          MD5:A2DCCB8BFC65DD4E7C3BB7F10DCEFF11
          SHA1:6FD2F4FAE06C5D4D3F189A167A98AA76497569DD
          SHA-256:87F42F45FD7D059CA47650D445420DE8320F3A7C1CBC7671FBFA8A8881274433
          SHA-512:F42E32C5BD785BA914E5054784BF67DDF951460A708290D1899621CEEDC63475B584FC052A86A3B6D45BF3C651D42427FB6F9CE2A2A33764DFFF731053BECC16
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/St_Johns)]} {.. LoadTimeZoneFile America/St_Johns..}..set TZData(:Canada/Newfoundland) $TZData(:America/St_Johns)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):194
          Entropy (8bit):4.887587766811186
          Encrypted:false
          SSDEEP:
          MD5:68900CE38FE0E40578323BBD3D75184E
          SHA1:9D5EAB5CBCD495DD46974207FBE354A81DD2070F
          SHA-256:5C4FD46054B190A6D4B92585B4DAE4E3A8233EE2996D14472835DDD264911DC6
          SHA-512:3EF53F0FCD8D88A1B977886BDFAA03D7B84EF021AC6BEDF7C571BFBF2242BFC3F3EB6A6B6A9C2F6852AF412A96DFBC30F3BB25A6619CBCD8736F3DF5B64DE1BF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Vancouver)]} {.. LoadTimeZoneFile America/Vancouver..}..set TZData(:Canada/Pacific) $TZData(:America/Vancouver)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.887593462838566
          Encrypted:false
          SSDEEP:
          MD5:A4237BDCAF68B0EFECA97178F3DEE724
          SHA1:A9CBC02B5545A63A0C9B38C8FA7FA2DE6D483188
          SHA-256:46BA00AE3A07A4DC83D6CB517D87C9CBBA491B3421FE9AD6C74CAC5695EB73F7
          SHA-512:832BF256BE8CB2DD205DDE50017448D5830B46FF4DCA77BDB852067EE0C9DF9977014F2A3E3DD6944336158D8EA377CFBBE519EE5B56FB26EB64325B45476B9D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Regina)]} {.. LoadTimeZoneFile America/Regina..}..set TZData(:Canada/Saskatchewan) $TZData(:America/Regina)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):195
          Entropy (8bit):4.889486451014262
          Encrypted:false
          SSDEEP:
          MD5:490D99BD5465CBF5A8FE28F33180B8A6
          SHA1:4783295C31A804BE98145270ED28956A0783E655
          SHA-256:A1B1AF37DC89C6BA663E4E967A18409AE4E0FA9EF1B908D0461368DA31001C09
          SHA-512:9F6B4F204A21B69E1DFCB766C0671D3736414C73269DCEDCDB4FC3DBA869BBA1511DF6B5061F8964F0AF9C3816133D04E5DFB8A6AD07CA06E7712787A8FECC5A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Whitehorse)]} {.. LoadTimeZoneFile America/Whitehorse..}..set TZData(:Canada/Yukon) $TZData(:America/Whitehorse)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):194
          Entropy (8bit):4.812019117774239
          Encrypted:false
          SSDEEP:
          MD5:6EF54792279C249B16877100682F1806
          SHA1:A62629EA055207D917740E3AEF4F0B005EA49CC4
          SHA-256:5B40167DD0C0B5C293861070C4AC249F78DDF8BAD798DD0165E3AE894C9B9570
          SHA-512:3CF93003C3EA2B4386660F0C87074F9AE2BAC4EE72D88451DCB1EA8B79502D2187B1608B6D5CE8D7EDC00AED99CF9DB7B006EB6ED2A2B5009F2C0E757D282D74
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Santiago)]} {.. LoadTimeZoneFile America/Santiago..}..set TZData(:Chile/Continental) $TZData(:America/Santiago)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.808907056781067
          Encrypted:false
          SSDEEP:
          MD5:2EC4FDD1EFBAF1D9F9DBAC8B1B5EDD09
          SHA1:FECED8EBC7B666628B7B45C9694FCB3A0B20A42A
          SHA-256:1E2DA1862E0E0F131B7C6EB12FAC5F920852C61C162993A30BC843A464A5AAD4
          SHA-512:74D61141505BAF1ABAD61FB91941C63C169EFE3C85829FEBB4D29A72EA54D1A07EC84E2E9B48E963E65CBF7663245459FAD288D620B1BEFFE682A2D1C243794D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Easter)]} {.. LoadTimeZoneFile Pacific/Easter..}..set TZData(:Chile/EasterIsland) $TZData(:Pacific/Easter)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):175
          Entropy (8bit):4.857134440822812
          Encrypted:false
          SSDEEP:
          MD5:3FB16EA4A9B0529220133C4A7B05215B
          SHA1:BD56B6E76A92A5925140CB5CC3D940E1DE90993F
          SHA-256:6F4F2D7F5BCA4E5183460C0153D2B98F5239A99F149DE6638B311C73CEDB1329
          SHA-512:690EC1BCE7FA979BD55725B8ED6DF042BB331CAD332827B2C64B31F107539934AA5A30268B1F03D52697528E68A1BA72E4D56B5199A68B1ED897B75FAFB33A8A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Havana)]} {.. LoadTimeZoneFile America/Havana..}..set TZData(:Cuba) $TZData(:America/Havana)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7440
          Entropy (8bit):3.695300167191082
          Encrypted:false
          SSDEEP:
          MD5:34339D40AC889DCB5A09D10F123175AD
          SHA1:57E1F70FA8999106FA3874A9CE1E75A7ACBC81E9
          SHA-256:64E284F9F7A36CC0A352809141D76E73A99344A9F30CFFEA254CBB9D2C589ADA
          SHA-512:2DCF16D9D7593FC3E5844E18FD689AADA157866490CFD37A38A47F747DDA189822055F6DD470CA2D77040D2C5A2527512880C22ED8EC16D9424EDF3DC228AFED
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EET) {.. {-9223372036854775808 7200 0 EET}.. {228877200 10800 1 EEST}.. {243997200 7200 0 EET}.. {260326800 10800 1 EEST}.. {276051600 7200 0 EET}.. {291776400 10800 1 EEST}.. {307501200 7200 0 EET}.. {323830800 10800 1 EEST}.. {338950800 7200 0 EET}.. {354675600 10800 1 EEST}.. {370400400 7200 0 EET}.. {386125200 10800 1 EEST}.. {401850000 7200 0 EET}.. {417574800 10800 1 EEST}.. {433299600 7200 0 EET}.. {449024400 10800 1 EEST}.. {465354000 7200 0 EET}.. {481078800 10800 1 EEST}.. {496803600 7200 0 EET}.. {512528400 10800 1 EEST}.. {528253200 7200 0 EET}.. {543978000 10800 1 EEST}.. {559702800 7200 0 EET}.. {575427600 10800 1 EEST}.. {591152400 7200 0 EET}.. {606877200 10800 1 EEST}.. {622602000 7200 0 EET}.. {638326800 10800 1 EEST}.. {654656400 7200 0 EET}.. {670381200 10800 1 EEST}.. {686106000 7200 0 EET}.. {701830800 10800 1 E
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):111
          Entropy (8bit):4.924838898127838
          Encrypted:false
          SSDEEP:
          MD5:B221E7141FFC9DEA317F64F81C7BB4E0
          SHA1:B13BBDE790B169D8B9075275523F319D5173E2C7
          SHA-256:6344BE02529C1CC5F7B5FE14B7E9BBCED4DDE68A24B824601EEBCAE207ABFDF2
          SHA-512:FFFA733476D6C7DCF49C0B88C9F5E381DE2B69BAEDF6C7B1D91C6F45CE2D36E06D40F25B6BB65D4B5D650471BB52CD2EC3F68703DAB4BD5414F8D3F831D92BD2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EST) {.. {-9223372036854775808 -18000 0 EST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8505
          Entropy (8bit):3.8091719283634853
          Encrypted:false
          SSDEEP:
          MD5:4578FE48781599B55F4BCF5560019789
          SHA1:4EAA7134621DFDEBFD1405F5CC58227FA7E80C3A
          SHA-256:0BE6161403BC5A96BFAB174F2C3FCBA8A677D4349699B408E9872B9DD0FE15CE
          SHA-512:9ACC2EF396F635D22E3DF6B785831AD74B510049F1BE85F996467A5BBC0DF49A28B2FC3E4CA0CA9DC8FC2C29EA50D909F0B153265B107445D3052E81D9A4D50A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EST5EDT) {.. {-9223372036854775808 -18000 0 EST}.. {-1633280400 -14400 1 EDT}.. {-1615140000 -18000 0 EST}.. {-1601830800 -14400 1 EDT}.. {-1583690400 -18000 0 EST}.. {-880218000 -14400 1 EWT}.. {-769395600 -14400 1 EPT}.. {-765396000 -18000 0 EST}.. {-84387600 -14400 1 EDT}.. {-68666400 -18000 0 EST}.. {-52938000 -14400 1 EDT}.. {-37216800 -18000 0 EST}.. {-21488400 -14400 1 EDT}.. {-5767200 -18000 0 EST}.. {9961200 -14400 1 EDT}.. {25682400 -18000 0 EST}.. {41410800 -14400 1 EDT}.. {57736800 -18000 0 EST}.. {73465200 -14400 1 EDT}.. {89186400 -18000 0 EST}.. {104914800 -14400 1 EDT}.. {120636000 -18000 0 EST}.. {126687600 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {162370800 -14400 1 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):170
          Entropy (8bit):4.862365884559795
          Encrypted:false
          SSDEEP:
          MD5:ACD69F34396296BA553243267D06CEE0
          SHA1:9575FFE5E7833B9532F17AC5413EA9DB23F07ECA
          SHA-256:936B6484469351DEF8FAFE8EC180862729F5E43BDE4E53E2E9636E221B54C3C2
          SHA-512:149D23FF35747127E9A2F4056D09472E8E689970BC795D5411C5BF621D949ADDEBDA68674D375A248A63106ABDFF6C54A8AFE5385C45BE2916CAED0C30F7C4A1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Cairo)]} {.. LoadTimeZoneFile Africa/Cairo..}..set TZData(:Egypt) $TZData(:Africa/Cairo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):172
          Entropy (8bit):4.901791318009318
          Encrypted:false
          SSDEEP:
          MD5:E9C2C97EB65526F1D4BE1AD7385336FA
          SHA1:09E4000CE320F779E2DFCA2FFD6B9258FFBA6CE4
          SHA-256:B78A833337EFEC8B5F64622F1BFDA21FCB79CF290E9CF32A54B206EB20C6FDE9
          SHA-512:EAEC097B58BF466CC7D6C0C6297628AF910CC308AC822565FD6CDABF96CD4EC57D4CC724FE782B6C1B606DFF9424013F6A890A871339577F7CB68BBB3C425E65
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Dublin)]} {.. LoadTimeZoneFile Europe/Dublin..}..set TZData(:Eire) $TZData(:Europe/Dublin)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):110
          Entropy (8bit):4.928744204623185
          Encrypted:false
          SSDEEP:
          MD5:9C08898081382F52CE681B592B8E2C8D
          SHA1:165944424740B1FA9B4B3B8E622198ABD0BDA0F8
          SHA-256:66B0DF8888883BFF44B18728B48CDF24AAED0BB745D601F3422C4F2D4063E0AC
          SHA-512:86EA639F999169F2FBA2457BE5042463A1938031268CCA71FDD03CCBC6194932937BA58B49FBED461E055E9AA668FF6EBF391AA7EC603C0A425416DF2E6CC84D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT) {.. {-9223372036854775808 0 0 GMT}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):159
          Entropy (8bit):4.910789466104329
          Encrypted:false
          SSDEEP:
          MD5:333F2BFA92742A49BB88F11C7CD896A9
          SHA1:BB5BEC010C36427AEEBDDA2FB72083E22A3F5073
          SHA-256:64466EA3759301E88C29AD1A833CDCBBC495EB4A5A3AC45E7B2987FECD6702BD
          SHA-512:E2270F4B57C5F1C849726259B886E8644DCF497FA0D034AD48885146BEDC70DC8899900DA9AC01F2609A2DA881E10F9042CCBF75A3F5DA7344D7E92F1B070806
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT+0) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.980500771169276
          Encrypted:false
          SSDEEP:
          MD5:A7C3FD06D1E06F125813C9687C42067C
          SHA1:515622C0B63E977AFBFC78AD8466053C4A4A71A6
          SHA-256:3BE1EC71D2CC88FA9A3DB7DC0476475F33FE5BCBE6BC35C0F083859766466C32
          SHA-512:548DA608CFCA5B8539652F94CA2040D624602D2DF64B2C8CCDB8B219B9B384E01386CDF95F3BF77409DF0584FA12A3B73D56D13107D98BEB4C2555F458B3F374
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+1) {.. {-9223372036854775808 -3600 0 -01}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):118
          Entropy (8bit):4.965033464829338
          Encrypted:false
          SSDEEP:
          MD5:FF71149E56D4CB553D0ED949B5F4C122
          SHA1:3459B47E0EEC80D7A29512CA4F3F236C89E86573
          SHA-256:E61E826E6FBC2396EF152640698098F4477D4FFDFE5F791F62250C3EC5865304
          SHA-512:43B0CC8BD7F1EFC80C3F14F115D651EADD5743B17B854C2FB7AC25995138D3DF8792915C2952B80F35784A7115F8FB335ACE171479B24C668190AC175523DB21
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+10) {.. {-9223372036854775808 -36000 0 -10}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):118
          Entropy (8bit):5.002239901486653
          Encrypted:false
          SSDEEP:
          MD5:08AABA917A8D6B3BB3D0DD1637F5ABFC
          SHA1:D1D704F0250D4CBD450922A02D021E0000FBF5CF
          SHA-256:143528946275DDC8B894218D3F1BE56C950F740828CEC13166C3D7E8E1B6BB7E
          SHA-512:F37AE54864A613C830308CB94AB7CEA9534A86A53B52B4A2C28CEEFE6F5BC0518143AAFD77A6DA5EC55D392F5BD34FCD4B5BE51794B1A386ED783B9BA89C10C3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+11) {.. {-9223372036854775808 -39600 0 -11}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):118
          Entropy (8bit):4.97889339723103
          Encrypted:false
          SSDEEP:
          MD5:7374B66D6E883D7581E9561C3815EB92
          SHA1:235E96A7420DF6733F3CA368D4A2D57766656043
          SHA-256:A93EAFAC2C1089C608C8536127D0E8B53D8C7CFD13AE7DD69339E12A89F803C6
          SHA-512:9BA59B17F20D65DFF1A5A2D557B535F69B04C172AECB15F88CA3484D74CC7D53894985C08653CF13D868BCBD5E7E5041E0CB2F457B5B603F3851198E552E33A7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+12) {.. {-9223372036854775808 -43200 0 -12}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.922268982357521
          Encrypted:false
          SSDEEP:
          MD5:FDDC663E40F8FFFE27959E94625725DF
          SHA1:EE3FBC1F6C8BBCF1BDC9E5DB4D2EA1A57E2E9BB3
          SHA-256:AD5833153446960BDE0653A22AE2111BF80CFD61C3010993CE87B81D40C75C72
          SHA-512:A1B2A153834FEAD7DC27C0918E1B1CB905671F82850C1CAAEBD89F5535703FB259F02F699EA7F82F3044E37668EE93DFA4D4EB862CD437AFF0DABA84867B1963
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+2) {.. {-9223372036854775808 -7200 0 -02}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.949132511023475
          Encrypted:false
          SSDEEP:
          MD5:5C6F16F2CFD46030688066F9BFBE675D
          SHA1:1DB5F36584822EB92E75B9AC9F440FD671BD90AE
          SHA-256:C7BEE4C71905EDDB40BAF42C0CD0DC70BB9F298EAAB8B9367D484B8431DD084A
          SHA-512:FFB2C4CD8EA7DE165C3D989454898FF2023D1A1E3B2B34EC23B1B71EFA7BF2538488DA0069E59F1152B8933D2263B762D2D7C56ADBED826C33FC0BA6672E34DB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+3) {.. {-9223372036854775808 -10800 0 -03}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.971627677226461
          Encrypted:false
          SSDEEP:
          MD5:E35244C1A6084C7BC1D79E437677C55C
          SHA1:898619DA4B8B9AC72E69C7BD30DEA2ADEF9440FE
          SHA-256:26D1EF512CC5797FC63BA2B83C7D6271025F4D4F5C904D9FA8E97F053393D9A7
          SHA-512:0687758558C4C5FF7802F3A57212694A1515761A8337D4B75FFE81434D2AD8A221B005DEC36BF013F2FC3DE1E46DFBED36352811EB7C5A5AE3A167A2E314F57C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+4) {.. {-9223372036854775808 -14400 0 -04}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.956438091983076
          Encrypted:false
          SSDEEP:
          MD5:7C560A0F3C42E399AC1247CB6C516DC6
          SHA1:C314B09D4E369C69C23A8DC1FB066FD0CFDC7211
          SHA-256:054910BDDFC44D9B806BBD3008C30547FA57ECD3C043418C406A725158144688
          SHA-512:FCE8431B759BD5359847734FD98D9D91394916235B2AF587FC927D5F3196FB283E241A6A9200EA852F9265ECEF81402FF6ACD0FA3A4AAEF6DF9DB1B056B3A9EF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+5) {.. {-9223372036854775808 -18000 0 -05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.974743300958087
          Encrypted:false
          SSDEEP:
          MD5:EEB1A3E0FD3339E332587D19C116D4EF
          SHA1:5DBF046031CD354B1EF88E46D3FED74706D21AC6
          SHA-256:D53BB247E0E429A6243AB9A9BDCAE1EE1CF5F271D79748A843631906AB63A988
          SHA-512:07BDF9056DC335C773684E634B1D389FBD139464D4597DE862B7EAC096676A093934682BF911F4E68F299789931218C0E431F0CC6BEBD7275B5FC8015EDD0942
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+6) {.. {-9223372036854775808 -21600 0 -06}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.930134062078826
          Encrypted:false
          SSDEEP:
          MD5:F92B31548D6BF8CCFA326C0CA6E205A0
          SHA1:3FFC6C214EDBCBE9C2509306CE73B429113E1C8A
          SHA-256:6BA5779E35D581B409F53B14B6E28ECC16F536FFEDD45DDBC8DAE4B8C28F66E7
          SHA-512:317872E986099D02AF083397AE936854043D54CEBF45A70672F02DDC9E2F3B27BC3FA80902F9675131C51A09BBD3C2BD1CD437330935CEA113C643769E0DF20C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+7) {.. {-9223372036854775808 -25200 0 -07}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.915798027862021
          Encrypted:false
          SSDEEP:
          MD5:B31B15E6006F8DF0D7627D6C90FF39AF
          SHA1:7C4137BE11DA84771DF6DC5EBC32D5E5E87E060F
          SHA-256:CA87559B154B165E83482AEE3D753BA8E38ABCA347A005E8504C566433CF4CB3
          SHA-512:220F7E7379EABBC8ACD7ADBB7A4AC8E93E4B268F8F1C0965B7E6A09735EE86E293EF1C492990331EEB4176B8301A91EC20579756B962AE45C858A96C09349CCD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+8) {.. {-9223372036854775808 -28800 0 -08}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.95764928386407
          Encrypted:false
          SSDEEP:
          MD5:5B10173EB7119F1219250763504A3526
          SHA1:A845021437C4638079040EF27AEF163C865FF8F8
          SHA-256:A0987A1D078B0993FB3B07208E3F4538A2319DCDDDEB2FAEA32FC463DEAFB8DB
          SHA-512:D213285D0A723B7771263122AFA269C2ABD0325A97D32C3870341255C06597DD6851C22860CFF42BF54E3FF5A36FC88C306F3BF1C69E7BD7FD7F69FE7601ED1A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+9) {.. {-9223372036854775808 -32400 0 -09}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):159
          Entropy (8bit):4.898210849752128
          Encrypted:false
          SSDEEP:
          MD5:5AFB7F12BA056619252D48904523DFA9
          SHA1:CD6E6681C8302BF38095975DF556BD14959FDAC8
          SHA-256:EFF27B3DEE9306641FF344801E06BB33FF768CDCCFE2409FA8AF752FF6D39F66
          SHA-512:2869BB347F42667A3D174816466B15916FC61FCB5A6A1BE1DD750C5C1751602FEE0FE5A27651B7A19C9F6764872DD0F00D3D5AA16CA1A743DBA09646D25A4EB2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT-0) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):115
          Entropy (8bit):4.979902281541545
          Encrypted:false
          SSDEEP:
          MD5:4000096844091488200125FC8F50E2F5
          SHA1:9FFEAE66405CFB254180C7DBE185288791DFEE5F
          SHA-256:B4BF883FBE9246EF4079179A746B1F9E59F2C77D4F598794B60732D198DC6044
          SHA-512:25C69E04018C2978A2E5748F0D3C61157453D998C16FA4B3C257A6515B87F5FD2B754893B47604BBC60AB60B60BA162BF2D1463E616E72CB8713C736F1B4D428
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-1) {.. {-9223372036854775808 3600 0 +01}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.964101313797091
          Encrypted:false
          SSDEEP:
          MD5:AE6601FACF6BE1E68083F8D353901181
          SHA1:8B3BFA307D2A94BADD3A1A5E42545D6F7C620BCE
          SHA-256:EF3046D7789CAE069B5473D053F3EF0157248F8A359A1282EE02BA613A75FC94
          SHA-512:1859E6A2CB94EFEE7CD5C17803AA4F2DEEBE4DCF43D3B1EA737DF00BA86ECEC79D296D75E69D5829DECB48380B6B650724104FFA7959FD18FE032DF7D002A88B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-10) {.. {-9223372036854775808 36000 0 +10}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):5.00162575418652
          Encrypted:false
          SSDEEP:
          MD5:D864BA451C9E441BF47D233626C57B99
          SHA1:6C38E6F8BA292575C496124572D187F97C9F8E73
          SHA-256:CCDEADBD18BE81E59A669A460A14AFCBFF733C3A5D164FC2B6B93DEAF009B78A
          SHA-512:5C16BD1189F3FE6789CB3630C841FD168EC87D0498EE6FCC4C8D635F8CF4BCAF0558B44F859C37E418F6BC5A7F6693D6EF1DD218A1DB6DA2D54FF55916685119
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-11) {.. {-9223372036854775808 39600 0 +11}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.978079707159482
          Encrypted:false
          SSDEEP:
          MD5:C3E7748C7CB9D8A7F7FA5170D5098983
          SHA1:54F5374A32173BEC6EDA430745DCD18749ABC233
          SHA-256:23B61B18C653E25F7245B0BB6E04AD347E038585B145962FD1EEACE26F118D54
          SHA-512:4783A7CD4C94CCC67C1C71F9C5D9CD99A3918EA4792D8CE2443ACE8F034B9023EBC02405B5DEAB919AA35FD1FD29D8980774316AC96D32ECDEBEFA15BBE6878D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-12) {.. {-9223372036854775808 43200 0 +12}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.994320173226919
          Encrypted:false
          SSDEEP:
          MD5:224AAAA8A31C283F50149A090E3970D5
          SHA1:E7E4876EC2474FEFD82D4B174CA8E3A3427062F5
          SHA-256:A9F1AD5A7CB5ED43C5E6E8A7A9B887329890ABB75B9FC9483B8543A367457EBE
          SHA-512:6EE0C6F519AAB2DAA3F7D802F0F838BA9F6BF1D56530000D3C9EA4FDA81DCB9832A3285E36208F29EEB23C27EC5BFD3438DC272929A7531268B7C0626A65D6A5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-13) {.. {-9223372036854775808 46800 0 +13}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):117
          Entropy (8bit):4.9895752453470585
          Encrypted:false
          SSDEEP:
          MD5:8ADF71739DCADE63433B7BF8321EAC77
          SHA1:AA6BDE83FF0D8BCFDE0426160250F2D17D3AF81D
          SHA-256:A37A7160027BD38356764C4D1AA5B9B17F8D5DC3CFB81EF2ED399E44C41734CE
          SHA-512:AEE3929DE269ADB5265A54841F041E41595359C101539F6309A4E737E3F5DF0BC91560781C7118975398C29A084113682C78F66E07E2E4AC5EAC8DFC33C4F0ED
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-14) {.. {-9223372036854775808 50400 0 +14}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):115
          Entropy (8bit):4.921164129348819
          Encrypted:false
          SSDEEP:
          MD5:CABB864F4E76B90928F5C54CD9334DEB
          SHA1:4818D47F83F16B9F7612D1E979B2440C170ECDB9
          SHA-256:7211BF8329B2388563ED8FA8C5140099A171B8A303A9473E9A6F3AF0C5D239CB
          SHA-512:1FDCB05D675F1D28CB52B9F5EAC7EC52FDF2CE7E7411740A6F8FB5E9D443ED636CE268E3AF9E08605CC3E13A49B2D86FF4EA6A85F518D5C79E263BA94263361D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-2) {.. {-9223372036854775808 7200 0 +02}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.948161547682094
          Encrypted:false
          SSDEEP:
          MD5:4AE5F29A13A86E4A7064E9200668E43B
          SHA1:2460BD1BB0FF3A3C774A5C7CC3DA10235DA06B0D
          SHA-256:BFC86D65B0B94725DCE4C88EDC4300141ABBCA4B6CDECF037C437DF49F0C1D6A
          SHA-512:190DC38B4A20F964C967866507086317D85D979DFCFA415D1569C485C6476024922BC6E7103273C41889D9D7B22E97933F286FCF4D341248077C1BA777D0EE3B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-3) {.. {-9223372036854775808 10800 0 +03}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.970850637731657
          Encrypted:false
          SSDEEP:
          MD5:BBAF760E27C02D176A675AC3CF2D1E6D
          SHA1:E524FAA7D424A1C1545D1D8EC00169125A68E8E5
          SHA-256:02E2EEAF88EE179EF63DD29ACC7384A4B46DE1E3A151C1F3A5DD31BBB5A05AEE
          SHA-512:6AC7CC0E52E7793C7F2D3DDA9551709DEAE654C1182EAD7108D04F1BAAAB7E1C473B6E8A3A126B0E421D8A246294A03B2EE9E070330924502DF2869CC61C37F7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-4) {.. {-9223372036854775808 14400 0 +04}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.955530107787899
          Encrypted:false
          SSDEEP:
          MD5:17F64A5969D3755211E60C0A9F83974F
          SHA1:FEFA84725EFAE6405F43797296C342B974F2D272
          SHA-256:3A2C75DCA11D1167126F0D44A8682420FAF75B0B82B3DCFC35A9F028A9A759E8
          SHA-512:77DBCD8284A470E4869976E2E8A5EDE28104283F120C863785A6B2E64CF87E06243196817C0055A9B32D6FFFE94A25772F67D58BF8E885F7EC06C34FABE38766
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-5) {.. {-9223372036854775808 18000 0 +05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.973993120288556
          Encrypted:false
          SSDEEP:
          MD5:51CAF7956E133C8A9788AE0B8C6145AB
          SHA1:47F8B49DF9ED477BD95F908693A483AE4FDE881F
          SHA-256:D22C87321373EC0EFB0F312925476CD0747323EF303E17621A871BF814C8ABB1
          SHA-512:EC4B4BE74C1BA64DEC8EF11DAAA338C52BD67D55E8A2352FBC6C83FA142F8DBE424CC1110E9A9D9A891E1E858D1FFA6D1E3B997D41BBB374556FA1F9A708559E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-6) {.. {-9223372036854775808 21600 0 +06}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.928999319005163
          Encrypted:false
          SSDEEP:
          MD5:56D88B54CA33B43E2E7D3EA6AD3A4D6E
          SHA1:9351E0C001C5D83325281AF54363D76D65548B7D
          SHA-256:70CB3A766A2E84148B68613D68687D263D3592ED4B6E672797FB20801ECA8231
          SHA-512:32B58AD16F64590903C7AB49BA4890DAF6F1F3D33187A7654D3DA88A1C0047483EAA58B2498D824A30116E235FCC8F8FB3FADD57F86396240E5D92B2CA337027
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-7) {.. {-9223372036854775808 25200 0 +07}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.9145396982864895
          Encrypted:false
          SSDEEP:
          MD5:E462AD5E0C046EA6769EDB4B2C80F4D4
          SHA1:6DDB94485648622875E0927BA1E8CFE67CEC1382
          SHA-256:80C85D59416CEC91DB3DAC5FDD2FD7B91D6FC74A37BBBEF6FF58F6F6816E8FC9
          SHA-512:42734FD2DA8BD6E0BC271FF1375A31DEB72EED85AB5EA6E1E0F81EE4E3E7E74380FFC98FAC30409684F736DB580AAAF4F62DB4757AA35C10383584F6144EF363
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-8) {.. {-9223372036854775808 28800 0 +08}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):116
          Entropy (8bit):4.956751740978211
          Encrypted:false
          SSDEEP:
          MD5:98F70EC1B1AC7D38CB8D01705FB0CA56
          SHA1:EDAFA132E48935ACEB8E72D3FF463E4FC857C1A9
          SHA-256:57395BB968AFA5A041EADA4B684B82F0379A9333F9522D69F069A79FDEA2B8D7
          SHA-512:97B8D7603D6B54C075B005B905B2A7A28B8BEA67894F055663C44D2BF730BB937AC8EF5B2DF182BDD2D9EFFDBD135DF9467C813AEE39AA6B34256908A12DC011
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-9) {.. {-9223372036854775808 32400 0 +09}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):158
          Entropy (8bit):4.886484135647838
          Encrypted:false
          SSDEEP:
          MD5:F879FB24EA976394B8F4FAF1A9BF268C
          SHA1:903714237EBD395A27EAF00B3DAAA89131267EE5
          SHA-256:AB742F93BE44BD68AB8FE84505FA28120F1808765D9BAED32A3490AF7C83D35B
          SHA-512:F5EE4C331E37036516F2A1BF12F2E088B2E2C7F6475127BF4E7B4937F864550D64D570BC855B6058D4311755E8696EC42095A36AEF13BB29E62192EE0AFB6EAF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT0) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):163
          Entropy (8bit):4.911342539638601
          Encrypted:false
          SSDEEP:
          MD5:CDD2DE9CF0FECFEA0CDD32DAC32DCDE2
          SHA1:311CD4C6E819E18BAAACC382F81359BC208E2F73
          SHA-256:F89167B6117838D9679C0397496B6D96D3A7BEAEF0BD99406ABACDBDB658FBCC
          SHA-512:1AF061D07D2F579A089905B6B259AABD7C58F4FA0CD379EE54206164F0DCAEA5C720FB1F5E76F5782F8613E62D8F83BD55F1848D5D7A73D4A5C9F7BC6B9F5DB1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/Greenwich) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):157
          Entropy (8bit):4.838936002050477
          Encrypted:false
          SSDEEP:
          MD5:0587EB7D1B1C684A4A0F90D3CB0959C8
          SHA1:3F2840AE512774494D9A0B6357C52CCB7DBA5265
          SHA-256:0856D14DBBC53D46460BCD530BD070E9E8966D1C96BA01BA556E215A98C09CD4
          SHA-512:DE38EF28893853219AC24AE4A522307ADAA1502F6D0C129219FAD9D75CFCE03A505C3E0758CFF2D2D4F7101414A5F7E4FC1C1B119B667E6A9C89B60DDA641E86
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/UCT) $TZData(:Etc/UTC)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):110
          Entropy (8bit):4.903699772785336
          Encrypted:false
          SSDEEP:
          MD5:3D3F94B6AC5FA232E509356C703D9177
          SHA1:502B8EE9D4A1EA75A91272181AC87B9B6ECE1F84
          SHA-256:4D74D9EC2397B1708FEF47806294B0BCA26679F3A63149AE24E4E0C641976970
          SHA-512:205A761A01C577F602236CB5C9938C834B7F3F9F681B94036B0A86101119893EF87D206D0C3F7737075ED833D4E35E374ACAE6605163E9C37B705D99BEBC928C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/UTC) {.. {-9223372036854775808 0 0 UTC}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):163
          Entropy (8bit):4.874807282103623
          Encrypted:false
          SSDEEP:
          MD5:65E28EFF342B625E79175793FD38F9FD
          SHA1:08B11474822E670DEAB8F0EA168BAED7D5E3DBE1
          SHA-256:A2B62C5914DE169A68A018A5B47C1253DBCA10A251862D17B0781ECFD19B6192
          SHA-512:79641D0E05F81BFB80034937D34E74B7483A790F33C1F9A0FA92C6A7913AC8C03036CFDEFB43850B84EFB3DD3C4A39022DC8F22E5B5DE6353586A546E03A5789
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/Universal) $TZData(:Etc/UTC)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):158
          Entropy (8bit):4.874356623237119
          Encrypted:false
          SSDEEP:
          MD5:EDABCAC858EC9632D5D8DCCFB28F4D6E
          SHA1:E5BEF1367A97A1900749CE6B1E01CF32F582BDD9
          SHA-256:BBD6E93206FF3B7017AFBE63905B4C932C422B582F3CE2A79A7B885D390EE555
          SHA-512:3A22364D423F2F970123561408018A2B72F43C4978836D3B6DF7517217445605838DCB8DDBDA204FD01C49A4A7D5ADAD4CA8BDA7C3B412D54750BAEAA589B683
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/Zulu) $TZData(:Etc/UTC)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.892809684252761
          Encrypted:false
          SSDEEP:
          MD5:B0B409D665190569A56697799FBA5CD3
          SHA1:840AA7D61E64ACE61FDDAB96F716575A61CEDB52
          SHA-256:46141E7BC0F99D2117319C661569F8B38AF7D00108CED5784FA3A3B5090EF8E9
          SHA-512:D7C0588D98AC46B5191D7C7E8F5181E94306EFFCC9E3F2DBA9E0003BAE51D992334527ADDD6D0C9701CFD60169A74984B3401E7A6A1322A734BC3D90DCC933BC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Brussels)]} {.. LoadTimeZoneFile Europe/Brussels..}..set TZData(:Europe/Amsterdam) $TZData(:Europe/Brussels)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):6927
          Entropy (8bit):3.8182041031531897
          Encrypted:false
          SSDEEP:
          MD5:D897DCA686A03495EB2C3323FAB0BEAD
          SHA1:1433BC303DE92F7B36F881C8595A42B35E0814FC
          SHA-256:F0B48DA7CA3659450D87CC0DDFDDFD28B464543DF1EE40D935C44D5CD7C9B9B3
          SHA-512:A1C4AE1E0EC26B159B0F5D058A7A77B8774F611A4D3C6AECEDD7186957D6BD9F15CDFCBA248FCC8A4B4146BD72CD7D66B9F88A2BF7CDEF416F1831A2F335D48C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Andorra) {.. {-9223372036854775808 364 0 LMT}.. {-2177453164 0 0 WET}.. {-733881600 3600 0 CET}.. {481078800 7200 0 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 3600 0 CET}.. {733280400 7200 1 CEST}.. {749005200 3600 0 CET}.. {764730000 7200 1 CEST}.. {780454800 3600 0 CET}.. {796179600 7200 1 CEST}.. {811904400 3600 0 CET}.. {828234000 7200 1 CEST}.. {846378000 3600 0 CET}.. {859683600 7200 1 CEST}.. {877827600 3600 0 CET}.. {891133200 7200 1 CEST}.. {909277200 3600 0 CET}.. {922582800 7200 1 CEST}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2063
          Entropy (8bit):3.679377249443024
          Encrypted:false
          SSDEEP:
          MD5:CB860328FA96A14055BF51A3B2D35A08
          SHA1:CFA49DC861F4AC3D29A78D63D71C2D6D83D68F84
          SHA-256:4B5FB0AF225974D117374028285F20A02B833FF4136E6BFAE7B65E6D6D28829E
          SHA-512:960152826F4245012462E53F80B69B0C45C27D75D46C70D485674CA19071DF268671C7691B614BE53B9E7BD8CFEC5D24F3DCF933F2F14D827F2A32EB347D7540
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Astrakhan) {.. {-9223372036854775808 11532 0 LMT}.. {-1441249932 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {764722800 14400 1 +04}.. {7
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7954
          Entropy (8bit):3.7252594544513795
          Encrypted:false
          SSDEEP:
          MD5:8B2C99E1CD04D7559709FDF8D382343C
          SHA1:C595D5159C742B815AF89EC8604376E01291F9F1
          SHA-256:47353319419505AAB205C23F8C97EA0B12E5DED2113147794F77B67349AFF52F
          SHA-512:227CA21A3B6160357988582E261A62AE7B09D46D479EABFAC8039185D710EFA765CD1694F4388EBF8800978A1E1DB69F6AF9BB9BF82C0FCD66E883930E1F8249
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Athens) {.. {-9223372036854775808 5692 0 LMT}.. {-2344642492 5692 0 AMT}.. {-1686101632 7200 0 EET}.. {-1182996000 10800 1 EEST}.. {-1178161200 7200 0 EET}.. {-906861600 10800 1 EEST}.. {-904878000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844477200 7200 1 CEST}.. {-828237600 3600 0 CET}.. {-812422800 7200 0 EET}.. {-552362400 10800 1 EEST}.. {-541652400 7200 0 EET}.. {166485600 10800 1 EEST}.. {186184800 7200 0 EET}.. {198028800 10800 1 EEST}.. {213753600 7200 0 EET}.. {228873600 10800 1 EEST}.. {244080000 7200 0 EET}.. {260323200 10800 1 EEST}.. {275446800 7200 0 EET}.. {291798000 10800 1 EEST}.. {307407600 7200 0 EET}.. {323388000 10800 1 EEST}.. {338936400 7200 0 EET}.. {347148000 7200 0 EET}.. {354675600 10800 1 EEST}.. {370400400 7200 0 EET}.. {386125200 10800 1 EEST}.. {401850000 7200 0 EET}.. {417574800 10800 1 EEST}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.876296755647751
          Encrypted:false
          SSDEEP:
          MD5:7160C6EE32380846653F016AE8AFD52A
          SHA1:DE7805089639C54893F2107FA67342DA72A79BBC
          SHA-256:557023674F6E8376707517103EE69C1DEBBE53CDD4BCAB11E763CC53B9CB1908
          SHA-512:FDBDECBBDB0C419226E2604608FD2923CFB06E4B6948493208FD83FD796880E81F6147C0FAFEB572079C9C916831B7B055620EC939164CCA1DAF76897BE60F2C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Belfast) $TZData(:Europe/London)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7309
          Entropy (8bit):3.8204712502914653
          Encrypted:false
          SSDEEP:
          MD5:02A003411B61A311896A6407B622152A
          SHA1:3B8BC6D1AF698CE7BB14A08307F5A4295EB8ED03
          SHA-256:74B225511B518B0CED972CBB33D694697712CCB96A6D81E0F50ADA28CF6E2C92
          SHA-512:9E03B3EB1E528E5B1ADBA09F808E73BF9C4314EDCBF6F96E46844D51A5F425BED3EE8FD5BA8706C46A7FB9882485F119F81996F2EAB7E1E9B598978C402DDE0F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Belgrade) {.. {-9223372036854775808 4920 0 LMT}.. {-2713915320 3600 0 CET}.. {-905824800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-777942000 7200 1 CEST}.. {-766623600 3600 0 CET}.. {407199600 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 360
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8020
          Entropy (8bit):3.820756136386754
          Encrypted:false
          SSDEEP:
          MD5:84027C3C8315BD479B38DE11F38E873F
          SHA1:6E92A2A9734A9C6B02ECCD99F114D667C909C5BA
          SHA-256:7E7111F06288069B52A4E1CA0B016216DF9328FB3B1560A740146497CCDD4D24
          SHA-512:5FFDE523021FC0C490261F55999204C9CE6C8C274888525EA6EE7C01BC5CCABC7A3877FD454B4167D81F4B89BACB087E8BA6AB0BAC46C2874ED9257BE2092340
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Berlin) {.. {-9223372036854775808 3208 0 LMT}.. {-2422054408 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-776559600 10800 0 CEMT}.. {-765936000 7200 1 CEST}.. {-761180400 3600 0 CET}.. {-757386000 3600 0 CET}.. {-748479600 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-717631200 7200 1 CEST}.. {-714610800 10800 1 CEMT}.. {-710380800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {315529200 3600 0 CET}.. {323830800 7200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.943205109348136
          Encrypted:false
          SSDEEP:
          MD5:C69AB60BE74D4BB7E31BE4E5ECCD8FD2
          SHA1:9DD0BA6171080F074858EF88ADA2E91C1F465619
          SHA-256:1D7C539AAA1E3AD5EF3574A629523B5B781F1A91D352C9B39B8DE7316756026E
          SHA-512:C273B97CCFB5F328EB7A13CCA3126DE8D91B3876CBD248990C0BE063DDBE5B0F31EA138E31A1C5C43B1ABCF42EA511448E6DC589EB99E8172D7C2A68BA31A8E7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Prague)]} {.. LoadTimeZoneFile Europe/Prague..}..set TZData(:Europe/Bratislava) $TZData(:Europe/Prague)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9223
          Entropy (8bit):3.8450929464870804
          Encrypted:false
          SSDEEP:
          MD5:E6C1153C3F71C8C005D7A46DDF6461FB
          SHA1:CBDF7D5D36AF57D83859C910B493464617EC9571
          SHA-256:1402A2072ADC9EBB35F4C0368D2E9A7A11493626C667C022614FFB7CC05B6CB6
          SHA-512:8B1B47678F75DBE59DB08E034F0701BD11FF4FD3AD0304C8ABF45E848F717D2787B8E47558D3C334D369E0938C633DC217178D3EAE6486CEFBE25CF1668479F6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Brussels) {.. {-9223372036854775808 1050 0 LMT}.. {-2840141850 1050 0 BMT}.. {-2450995200 0 0 WET}.. {-1740355200 3600 0 CET}.. {-1693702800 7200 0 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1613826000 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585530000 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1520557200 0 0 WET}.. {-1507510800 3600 1 WEST}.. {-1490576400 0 0 WET}.. {-1473642000 3600 1 WEST}.. {-1459126800 0 0 WET}.. {-1444006800 3600 1 WEST}.. {-1427677200 0 0 WET}.. {-1411952400 3600 1 WEST}.. {-1396227600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301263200 0 0 WET}.. {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7974
          Entropy (8bit):3.7264631277913853
          Encrypted:false
          SSDEEP:
          MD5:88DB5686937D3499A8142413B2CF2EB5
          SHA1:E37BAD2127553600D0E38A43053D1B07B2498DA8
          SHA-256:C560D45104A8DD73FC7370B5AC1615E22043DBC93DFB46A9ECC6468C2D38B19A
          SHA-512:375B8A63CFF2E278CD8C78BF9DBC86288FFB1AD57DAED00CD2199F0B05F4FBFA7D17D93C6458B20B86F6D05F3E3A49D594E60AC97DDB47141E21D7CDE10F8456
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Bucharest) {.. {-9223372036854775808 6264 0 LMT}.. {-2469404664 6264 0 BMT}.. {-1213148664 7200 0 EET}.. {-1187056800 10800 1 EEST}.. {-1175479200 7200 0 EET}.. {-1159754400 10800 1 EEST}.. {-1144029600 7200 0 EET}.. {-1127700000 10800 1 EEST}.. {-1111975200 7200 0 EET}.. {-1096250400 10800 1 EEST}.. {-1080525600 7200 0 EET}.. {-1064800800 10800 1 EEST}.. {-1049076000 7200 0 EET}.. {-1033351200 10800 1 EEST}.. {-1017626400 7200 0 EET}.. {-1001901600 10800 1 EEST}.. {-986176800 7200 0 EET}.. {-970452000 10800 1 EEST}.. {-954727200 7200 0 EET}.. {296604000 10800 1 EEST}.. {307486800 7200 0 EET}.. {323816400 10800 1 EEST}.. {338940000 7200 0 EET}.. {354672000 10800 0 EEST}.. {370396800 7200 0 EET}.. {386121600 10800 1 EEST}.. {401846400 7200 0 EET}.. {417571200 10800 1 EEST}.. {433296000 7200 0 EET}.. {449020800 10800 1 EEST}.. {465
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8287
          Entropy (8bit):3.8244305880244567
          Encrypted:false
          SSDEEP:
          MD5:11468F958796F971ADD5FB1A0C426D78
          SHA1:3FA58BEF391BCF7BAC6A124D093B6505B4EAC452
          SHA-256:B58F3E9066B8B57EB037D509636AA67A06ACC8348BE6C48482D87CDC49844A4E
          SHA-512:0492EABD6EE16392C00A196AF38995E5F9E55E30A82A50EFFB381DC978E9E63E801555CDC219869E6251BD51115972F742D8A7D9524372B8B11702AE4B28BFB7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Budapest) {.. {-9223372036854775808 4580 0 LMT}.. {-2498260580 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1640998800 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1600470000 7200 1 CEST}.. {-1587250800 3600 0 CET}.. {-1569711600 7200 1 CEST}.. {-1555196400 3600 0 CET}.. {-906775200 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-778471200 7200 1 CEST}.. {-762656400 3600 0 CET}.. {-749689200 7200 1 CEST}.. {-733276800 3600 0 CET}.. {-717634800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-686185200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {-492656400 7
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.952483060656419
          Encrypted:false
          SSDEEP:
          MD5:CED145F8D9B231234E021D2214C1064B
          SHA1:7B111DC24CA01C78A382CECD3247CF495D71CD34
          SHA-256:F511A80AB70FF93A0EB9F29293F73DF952B773BB33EB85D581E4FB1FE06E4F05
          SHA-512:E2323C04BF99909ABA9A09A66F9B4696519B5F9FE3AF178FB04D5E0053F41CAA8B937DC4148954ED093D317F454E0547786BEC934F2ABF22A60AAA6A24E63BF9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Zurich)]} {.. LoadTimeZoneFile Europe/Zurich..}..set TZData(:Europe/Busingen) $TZData(:Europe/Zurich)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8096
          Entropy (8bit):3.7635458172251406
          Encrypted:false
          SSDEEP:
          MD5:E7F52393523729CA3916768B3F3B4E55
          SHA1:1524A3E610DCD33AC0006946BAB2929CA7F5A33F
          SHA-256:2BD1C0AB412A5E9C97F533C4D06B773D045215B92568A4E89ADC93C7462D62EC
          SHA-512:218674ECD9FD6C1A1C83EE69AFE6AA5AD0D5A8BB59FF497FDF2573B7CF52DAE98ECE0815CF99668CA4E172FF67D220B227369865076333B3EE802A8839C65279
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Chisinau) {.. {-9223372036854775808 6920 0 LMT}.. {-2840147720 6900 0 CMT}.. {-1637114100 6264 0 BMT}.. {-1213148664 7200 0 EET}.. {-1187056800 10800 1 EEST}.. {-1175479200 7200 0 EET}.. {-1159754400 10800 1 EEST}.. {-1144029600 7200 0 EET}.. {-1127700000 10800 1 EEST}.. {-1111975200 7200 0 EET}.. {-1096250400 10800 1 EEST}.. {-1080525600 7200 0 EET}.. {-1064800800 10800 1 EEST}.. {-1049076000 7200 0 EET}.. {-1033351200 10800 1 EEST}.. {-1017626400 7200 0 EET}.. {-1001901600 10800 1 EEST}.. {-986176800 7200 0 EET}.. {-970452000 10800 1 EEST}.. {-954727200 7200 0 EET}.. {-927165600 10800 1 EEST}.. {-898138800 7200 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-800154000 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.925156646979837
          Encrypted:false
          SSDEEP:
          MD5:3AEDE4B340D0250D496C49CADBA04E62
          SHA1:C466D8275C465752F5B024615268F6D1CBBA4B41
          SHA-256:2B9A0F1775355E311FB63903E3829F98B5F6C73C08F1BECE1A2D471ACC2673E3
          SHA-512:2B08B57D58699C65A9AAA43AC87F29DD1EDCBA9F91E79DF4B1E07832032F5B03A43847E20345484730E8D2323199E7439D8C1FC662E812E8BA6EE19C53C89681
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Copenhagen) $TZData(:Europe/Berlin)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9810
          Entropy (8bit):3.7678769652077873
          Encrypted:false
          SSDEEP:
          MD5:E1EB426EA3351AF0D7D563006F9146BC
          SHA1:1E94F3B38366FE43BB031A57D19894B569EBABED
          SHA-256:895957521D6CA4DE7E4089DC587A6C177B803D8ADF63303B1F85DEB279726324
          SHA-512:8F24E9519F5D42F34AEE5C52A94CAC7D035EAE7B31DC3E629C29CFE3BD85F1510188290D35CD327492A030168443FED8BD80EC57ED27811B786C4DC89B4B1181
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Dublin) {.. {-9223372036854775808 -1521 0 LMT}.. {-2821649679 -1521 0 DMT}.. {-1691962479 2079 1 IST}.. {-1680471279 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1517011200 0 0 IST}.. {-1507500000 3600 1 IST}.. {-1490565600 0 0 IST}.. {-1473631200 3600 1 IST}.. {-1460930400 0 0 IST}.. {-1442786400 3600 1 IST}.. {-1428876000 0 0 IST}.. {-1410732000 3600 1 IST}.. {-1396216800 0 0 IST}.. {-1379282400 3600 1 IST}.. {-1364767200 0 0 IST}.. {-1348437600 3600 1 IST}.. {-1333317600 0 0 IST}.. {-1315778400 3600 1 IST}.. {-1301263200 0 0 IST}.. {-1284328800 3600 1 IST}.. {-1269813600 0 0 IST}.. {-1253484000 3600 1 IST
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9509
          Entropy (8bit):3.8837074152297704
          Encrypted:false
          SSDEEP:
          MD5:D04F8EDDA1C3611692FB91E317CCADFE
          SHA1:1C483FC95459EC6F1D5FE4DD275879A9EBCA1718
          SHA-256:0524A31131405347C1D5D86C5EE38A2064AB055C030AB3B43F25DB3B28FFD8D2
          SHA-512:4E2E18EBDE2765F2251B1FE41EF8E6AC79875617348974A28619F5E59EC0467239C682CCE8DEBD7A698BE2F00252C77D1F7FA50B6CAFF920B3BE53A0B836F815
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Gibraltar) {.. {-9223372036854775808 -1284 0 LMT}.. {-2821649916 0 0 GMT}.. {-1691964000 3600 1 BST}.. {-1680472800 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1507500000 3600 1 BST}.. {-1490565600 0 0 GMT}.. {-1473631200 3600 1 BST}.. {-1460930400 0 0 GMT}.. {-1442786400 3600 1 BST}.. {-1428876000 0 0 GMT}.. {-1410732000 3600 1 BST}.. {-1396216800 0 0 GMT}.. {-1379282400 3600 1 BST}.. {-1364767200 0 0 GMT}.. {-1348437600 3600 1 BST}.. {-1333317600 0 0 GMT}.. {-1315778400 3600 1 BST}.. {-1301263200 0 0 GMT}.. {-1284328800 3600 1 BST}.. {-1269813600 0 0 GMT}.. {-1253484000 3600 1 BST}.. {-1238364000 0 0 GMT}
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.879252060643389
          Encrypted:false
          SSDEEP:
          MD5:07AF23DA01CB963EA9E57534E34E7704
          SHA1:1C4A214FF3B722E80C0ECACA0FFD5DFF302F6AE9
          SHA-256:F7046808A8E80B7AE449D1A49AE3E480096736B7D3F554A240C7DFB10F82076A
          SHA-512:713860D340C0EBA5EEF873ECB9B28CCDE9BFAD31B6A8626EF507E96585F5CC1091BF8D8A2DB7E5CB532E44F4561FBAE1797141724EF934755B69919FEA09A78A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Guernsey) $TZData(:Europe/London)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7368
          Entropy (8bit):3.7258352536809705
          Encrypted:false
          SSDEEP:
          MD5:7FF902B06FA79F14553670A70E77FF8C
          SHA1:0105051541F38956EA6192BD0C7ED4047668005E
          SHA-256:5B5C0A9261A414EA8DC34F594EE05BEE16F695488B230857D2B569A6B603BC39
          SHA-512:551940199783A0FF9D73695B77B10300644F50E91D6B02FE79BB0CD4B78C7BA88CCE56F4B9408EC146361BF408F52D01A1F435183360C801EA5E219FB718247F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Helsinki) {.. {-9223372036854775808 5989 0 LMT}.. {-2890258789 5989 0 HMT}.. {-1535938789 7200 0 EET}.. {-875671200 10800 1 EEST}.. {-859773600 7200 0 EET}.. {354672000 10800 1 EEST}.. {370396800 7200 0 EET}.. {386121600 10800 1 EEST}.. {401846400 7200 0 EET}.. {410220000 7200 0 EET}.. {417574800 10800 1 EEST}.. {433299600 7200 0 EET}.. {449024400 10800 1 EEST}.. {465354000 7200 0 EET}.. {481078800 10800 1 EEST}.. {496803600 7200 0 EET}.. {512528400 10800 1 EEST}.. {528253200 7200 0 EET}.. {543978000 10800 1 EEST}.. {559702800 7200 0 EET}.. {575427600 10800 1 EEST}.. {591152400 7200 0 EET}.. {606877200 10800 1 EEST}.. {622602000 7200 0 EET}.. {638326800 10800 1 EEST}.. {654656400 7200 0 EET}.. {670381200 10800 1 EEST}.. {686106000 7200 0 EET}.. {701830800 10800 1 EEST}.. {717555600 7200 0 EET}.. {733280400 10800 1 EEST}.. {749
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.914274131294981
          Encrypted:false
          SSDEEP:
          MD5:F9A0F19FAF3131D8A70C50FF21B365B7
          SHA1:7FC2B5302FAD06BC4C633CD22A80A7D40073FFF8
          SHA-256:2F1151B0528A5325443379D4E7CCE32C00213722AD9DF764E1DC90198084B076
          SHA-512:6D04DF4480FE132A6641C4BF7E01936E2E4A71A3A6C2AB9F7DA7A9D8A4B836BC66EE2BB597B8C318D07A06F72C05B07E6785B53308ED9BC1103AE6DBDD0FF24E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Isle_of_Man) $TZData(:Europe/London)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3683
          Entropy (8bit):3.814835316757376
          Encrypted:false
          SSDEEP:
          MD5:A8256656B971F58CB991BC270BF93B26
          SHA1:189796E1B8E29A7A7B8B0E143DD9B44BAF217AB2
          SHA-256:08061A80FC0F1EF375EEFE784EACDF0812E289FD67E8613BDEC36209985CA1D7
          SHA-512:1F11308B5BAC1F3DB75CAC7322BBEA6E51C6B4A2A3450F1DB84DE6AA127F0F1BAA7DAB409FAF1288C100BDA77DA6FA1C6E3C0BA962F9406D1445D7C9E2AA3A60
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Istanbul) {.. {-9223372036854775808 6952 0 LMT}.. {-2840147752 7016 0 IMT}.. {-1869875816 7200 0 EET}.. {-1693706400 10800 1 EEST}.. {-1680490800 7200 0 EET}.. {-1570413600 10800 1 EEST}.. {-1552186800 7200 0 EET}.. {-1538359200 10800 1 EEST}.. {-1522551600 7200 0 EET}.. {-1507514400 10800 1 EEST}.. {-1490583600 7200 0 EET}.. {-1440208800 10800 1 EEST}.. {-1428030000 7200 0 EET}.. {-1409709600 10800 1 EEST}.. {-1396494000 7200 0 EET}.. {-931053600 10800 1 EEST}.. {-922676400 7200 0 EET}.. {-917834400 10800 1 EEST}.. {-892436400 7200 0 EET}.. {-875844000 10800 1 EEST}.. {-764737200 7200 0 EET}.. {-744343200 10800 1 EEST}.. {-733806000 7200 0 EET}.. {-716436000 10800 1 EEST}.. {-701924400 7200 0 EET}.. {-684986400 10800 1 EEST}.. {-670474800 7200 0 EET}.. {-654141600 10800 1 EEST}.. {-639025200 7200 0 EET}.. {-622087200 10800 1 EEST}.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):181
          Entropy (8bit):4.8801202136140915
          Encrypted:false
          SSDEEP:
          MD5:FE10770868A75F4F8D76C5E23D99AA81
          SHA1:30AC768BA47AF7A53831F5142B58ECEC41933621
          SHA-256:97EB33915ED7C9C34144F8F42357FAB2262B3CD45287F3CFFD26C33D65F7651E
          SHA-512:1D82DF45AB0CCDFBFAD0431C668794996E01776800F34DD4131C5287D37291657A749D497AA5B0AB81CAFF3190896633FBFF456BFFEB7E93A3420AA841E54842
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Jersey) $TZData(:Europe/London)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2512
          Entropy (8bit):3.941165221943348
          Encrypted:false
          SSDEEP:
          MD5:104CCB93300F40BAF8F4D7CC882EFC05
          SHA1:EA83F3C3791BD6F083844939DC405B248E738FE3
          SHA-256:2387D26DF5429DF9867F42F7D4F872DC146643B4B3CC57DA7298C18561DE8BFE
          SHA-512:12724C5BBEE0835626A98B66BF55C3DF1311F07018C70D76FC5C50E7E7BA5C4A9F064D9EDC376CC3B06C4FFFECA3FAF5B66948615A03DFECA7C361E326D950EA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kaliningrad) {.. {-9223372036854775808 4920 0 LMT}.. {-2422056120 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-780368400 7200 0 EET}.. {-778730400 10800 1 EEST}.. {-762663600 7200 0 EET}.. {-749095200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):173
          Entropy (8bit):4.970386708540243
          Encrypted:false
          SSDEEP:
          MD5:74ACF46A3248341CFD84B1592F884A8F
          SHA1:888FBB54381A1B5BC19E65AF38A1913635A8E7E4
          SHA-256:05C55F87182F0D5D3E8E6C1F9164EDDBDB8035146A0955C04283BC1347D45B30
          SHA-512:21A752390E023CBD582BC43865D43458B44B036299A2373948269196071742ED7EB6067DD9A288F3A15E808B452FE4192750FAE813F70738FAB0C866219D57CB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Kiev) $TZData(:Europe/Kyiv)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2029
          Entropy (8bit):3.668326642402654
          Encrypted:false
          SSDEEP:
          MD5:57BB199152815B12FE4491C92FE25186
          SHA1:7BC5ECDE9EFADE812AF40CB92CCE5323FB57C78D
          SHA-256:60884D4B8B17A9AB8FB5697DA95F62E570755348109C661D783D56CD047BBE9E
          SHA-512:2043FDBA860E8F6578F7E26A80C7787B82C7D15188327923EC36D153FDF9BEEAE063012ACE4309B76DB9DBA2DFFB7404DE370BA85023CCE93159FCAD3B9B92B5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kirov) {.. {-9223372036854775808 11928 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {764722800 14400 1 +04}.. {78044
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7455
          Entropy (8bit):3.7624983280224953
          Encrypted:false
          SSDEEP:
          MD5:F37C7529B53C4C158341AF90F80C3A11
          SHA1:210650A882350D35C72A934749F276C58C572DFA
          SHA-256:591264F69DB19DDCDC90E704525E2D3D3984117B710F482F19DA8F88628EE6A7
          SHA-512:F23B0C5251EB7418A1C80344AB7623D2A0197E681E3B7D152E416187BF66DE09A7A60A65F8ED6A810272CF0C253D63684F08AF594A8C22ABEA89E3BBADC8F0A0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kyiv) {.. {-9223372036854775808 7324 0 LMT}.. {-2840148124 7324 0 KMT}.. {-1441159324 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-892522800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-825382800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {638319600 14400 1 MSD}.. {646786800 10800 1 EEST}.. {686102400 7200 0 EET}.. {701827200 10800 1 EEST}.. {7175
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9878
          Entropy (8bit):3.8275310275285723
          Encrypted:false
          SSDEEP:
          MD5:0DA331C2A815739E6758797BD24554EA
          SHA1:3829C441E908BEFDC4ED6AB65FD4ACD0C97D5E1B
          SHA-256:9FAC9812411F88014779D34722F3E0D2750E45BF21595DF1AE14CB9CCFD3F33F
          SHA-512:FEBBA05F64AC1F3066AF6351493DD89768154FD171D447503DAEDB90D16858BEDBCE4A74E24AC0C37B5FF191692AF44AADDE4A92E752F88C48DA646352AD9A0B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Lisbon) {.. {-9223372036854775808 -2205 0 LMT}.. {-2713908195 -2205 0 LMT}.. {-1830384000 0 0 WET}.. {-1689555600 3600 1 WEST}.. {-1677801600 0 0 WET}.. {-1667437200 3600 1 WEST}.. {-1647738000 0 0 WET}.. {-1635814800 3600 1 WEST}.. {-1616202000 0 0 WET}.. {-1604365200 3600 1 WEST}.. {-1584666000 0 0 WET}.. {-1572742800 3600 1 WEST}.. {-1553043600 0 0 WET}.. {-1541206800 3600 1 WEST}.. {-1521507600 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1426813200 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301274000 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269824400 0 0 WET}.. {-1221440400 3600 1 WEST}.. {-1206925200 0 0 WET}.. {-1191200400 3600 1 WEST}.. {-1175475600 0 0 WET}.. {-1127696400 3600 1 WEST}.. {-1111971600 0 0 WET}.. {-1096851
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.948438246006353
          Encrypted:false
          SSDEEP:
          MD5:56C6C95484FEAF9BAF755683E7417B58
          SHA1:A43176BEBC5B4D7144A7E1109E0AAEFD95C21EC6
          SHA-256:713A842197516D618F2D86977262542A1CA334D7DF6026539FA2F2980DBF4CD3
          SHA-512:566B6DF2D76A8A4D3405C4785C7A471A23D65CD8838831BD0DEDF5BF194E8A3B304CA9920CB4A8EC9D6CD60EAA9BE0335E38D9547A4D23C7E4E5E5A39A09DDAC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Ljubljana) $TZData(:Europe/Belgrade)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):10211
          Entropy (8bit):3.826887992237191
          Encrypted:false
          SSDEEP:
          MD5:0625C99E16D3C956DED1C0C0F867DEC3
          SHA1:6ACDF0DB619B63E21EC89046B9320A85FBD3397A
          SHA-256:D04C4E25DF4DE1C1CFE1EF84B3B6DD746CF08A271AB0958F22C7D580A3ED10E6
          SHA-512:07AC42F0635DF01CC0AFD13F9668B143D4943BA0E4C377D254B5AF034D9DDBAB77BA813187E9AB73D2EEAD86EBAA26DC15599FD74FC82EEF287F5A6AB9C01635
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/London) {.. {-9223372036854775808 -75 0 LMT}.. {-3852662325 0 0 GMT}.. {-1691964000 3600 1 BST}.. {-1680472800 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1507500000 3600 1 BST}.. {-1490565600 0 0 GMT}.. {-1473631200 3600 1 BST}.. {-1460930400 0 0 GMT}.. {-1442786400 3600 1 BST}.. {-1428876000 0 0 GMT}.. {-1410732000 3600 1 BST}.. {-1396216800 0 0 GMT}.. {-1379282400 3600 1 BST}.. {-1364767200 0 0 GMT}.. {-1348437600 3600 1 BST}.. {-1333317600 0 0 GMT}.. {-1315778400 3600 1 BST}.. {-1301263200 0 0 GMT}.. {-1284328800 3600 1 BST}.. {-1269813600 0 0 GMT}.. {-1253484000 3600 1 BST}.. {-1238364000 0 0 GMT}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):191
          Entropy (8bit):4.920751023999728
          Encrypted:false
          SSDEEP:
          MD5:E4A8C25756D6C5D2073A51D2B54E3A0C
          SHA1:4A24667ADC9BD31E8CB298BE3787C12301C3F1C8
          SHA-256:8C0486A5B235E8B01069420976E1B8D08D77A4BEF587203AF1B68D7B5333546E
          SHA-512:F3593C3B75C9DA931FB39BC2054EB9691C3A544A74F871425169C3244040D6D060510741FE1E352A1E59F53E5A585307D434A0D7C9D159D065717E78C807787C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Brussels)]} {.. LoadTimeZoneFile Europe/Brussels..}..set TZData(:Europe/Luxembourg) $TZData(:Europe/Brussels)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8517
          Entropy (8bit):3.8326167134909177
          Encrypted:false
          SSDEEP:
          MD5:63263380F57B756A1DFA3796E4188CD3
          SHA1:8EEE707AC4FEA1C098C81AC2D289A46239121A5E
          SHA-256:5337C9843C56DEEC6B91C4468C76EC1C896E80421B72B583B69DE5579063E09A
          SHA-512:ACA4830020715C471741E27EB2292ACF002D2CD7EDCD1061978B64967EB447F61AA095F960D8A75A01B9B87558D83FF409F30BDACA83E063024F1E2381FA64C4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Madrid) {.. {-9223372036854775808 -884 0 LMT}.. {-2177452800 0 0 WET}.. {-1631926800 3600 1 WEST}.. {-1616889600 0 0 WET}.. {-1601168400 3600 1 WEST}.. {-1585353600 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1427673600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364774400 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333324800 0 0 WET}.. {-1316390400 3600 1 WEST}.. {-1301270400 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269820800 0 0 WET}.. {-1026954000 3600 1 WEST}.. {-1017619200 0 0 WET}.. {-1001898000 3600 1 WEST}.. {-999482400 7200 1 WEMT}.. {-986090400 3600 1 WEST}.. {-954115200 0 0 WET}.. {-940208400 3600 0 CET}.. {-873079200 7200 1 CEST}.. {-862621200 3600 0 CET}.. {-842839200 7200 1 CEST}.. {-828320400 3600 0 CET}.. {-811389600 7200 1 CEST}.. {-796870800 3600 0 CET}.. {-779940000 7200 1 CEST}.. {-765421200 3600 0 CET}.. {-74849
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8724
          Entropy (8bit):3.816380386871747
          Encrypted:false
          SSDEEP:
          MD5:9B09D6EED8F23BAFFB62929C0115E852
          SHA1:4AEF15333C73C2836C09D818FD0E20440D7C4780
          SHA-256:C5C240BAAECE8235D1FBDD251C1A67CB2D2FC8195DD5BBE37FF9CFF0445FCDA2
          SHA-512:43AA3492BD335A290C6EFEE275B47EA18E544199E37A9BBAE2E350D42BDFF42F0E9ED461A4BB1824CA33F84A90D4060906844A3E22DA49C9821E4CB460832D6E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Malta) {.. {-9223372036854775808 3484 0 LMT}.. {-2403478684 3600 0 CET}.. {-1690765200 7200 1 CEST}.. {-1680487200 3600 0 CET}.. {-1664758800 7200 1 CEST}.. {-1648951200 3600 0 CET}.. {-1635123600 7200 1 CEST}.. {-1616896800 3600 0 CET}.. {-1604278800 7200 1 CEST}.. {-1585533600 3600 0 CET}.. {-1571014800 7200 1 CEST}.. {-1555293600 3600 0 CET}.. {-932432400 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812588400 7200 1 CEST}.. {-798073200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766717200 3600 0 CET}.. {-750898800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-719456400 7200 1 CEST}.. {-701917200 3600 0 CET}.. {-689209200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-114051600 7200 1 CEST}.. {-103168800 3600 0 CET}.. {-81997200 7200 1 CEST}.. {-71715600 3600 0 CET}.. {-50547600 7200 1
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.959733196757503
          Encrypted:false
          SSDEEP:
          MD5:C1844961691214F6E6DF6487788A7758
          SHA1:6D08E9FB7B8602A80622148BFACD9676F45F0E2B
          SHA-256:6136C3CFA4A767E7C9DDA23A283AD98B72E9868F192E6A8E3BFE6396F6989BD1
          SHA-512:B2D1EA51AC5B34792AC02820A9D60FD41F3B91AB6505896476FCB0DC339B8DC1DE9E2C89A7627F69E16247661AE8040D789FFD2F8F1CD59F243B57C4845B450F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Helsinki)]} {.. LoadTimeZoneFile Europe/Helsinki..}..set TZData(:Europe/Mariehamn) $TZData(:Europe/Helsinki)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2177
          Entropy (8bit):3.9354590900153172
          Encrypted:false
          SSDEEP:
          MD5:9C10EAE9FA0DE192C5FD4F76E12606F0
          SHA1:AFD5650410EC3E6ED564A8B2ABF91709D090B4AD
          SHA-256:8C95EA696EA578DEF726502AC181AF475A676030878F56B4E2D667757BBD1C49
          SHA-512:3B9ED6B68858485B9A46A0863B7D9D3C1E4C5BBA269457F24A9A12C274F0F9B35E63D8C25EB53E7200DB57DD35ACCB7FD7D8AB005FEE2C4D7FC6E72E8CF57194
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Minsk) {.. {-9223372036854775808 6616 0 LMT}.. {-2840147416 6600 0 MMT}.. {-1441158600 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-899780400 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-804646800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {631141200 10800 0 MSK}.. {670374000 7200 0 EEMMTT}.. {670377600 10800 1 EEST}.. {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.9089012087310095
          Encrypted:false
          SSDEEP:
          MD5:2015CF8BBEEE12AF0D9C82FD2E246C72
          SHA1:062BFFBB266C3EBB5776A509DDB7A6044C82B864
          SHA-256:9DF16BB1C26100635DC4CB1DF409B0FA7B139C22BF09574ED337EE244CA3C546
          SHA-512:FD3479588D4F3B84CF6C8B8A5DB1AB3BFA0A87CA2FFADB4FEBBBB25711C77963BE7CD0D1DA5ED985D729F39C5B44E8CBD429F1E2DA813DF26272D66CAE4F425A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Paris)]} {.. LoadTimeZoneFile Europe/Paris..}..set TZData(:Europe/Monaco) $TZData(:Europe/Paris)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2430
          Entropy (8bit):3.942836780611272
          Encrypted:false
          SSDEEP:
          MD5:4547D47E9364ACAFB2A4BEE52D04BFBB
          SHA1:1E7F964692F81D49AEAF581FE70AD22D4E36226B
          SHA-256:31F9C3C2F17B3EE4FA6D9EE6A86BF407AC0377DE4D666C65E86CE5AC591F829F
          SHA-512:7F1D7C80A1BF611D5440EEF9085DA6CDED86B5EF4C2737C105640030E5AA998A0951182E72DC224190A25DA8846CDE856A78EBAA8876AA0B18B1CBCADBB060FF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Moscow) {.. {-9223372036854775808 9017 0 LMT}.. {-2840149817 9017 0 MMT}.. {-1688265017 9079 0 MMT}.. {-1656819079 12679 1 MST}.. {-1641353479 9079 0 MMT}.. {-1627965079 16279 1 MDST}.. {-1618716679 12679 1 MST}.. {-1596429079 16279 1 MDST}.. {-1593820800 14400 0 MSD}.. {-1589860800 10800 0 MSK}.. {-1542427200 14400 1 MSD}.. {-1539493200 18000 1 +05}.. {-1525323600 14400 1 MSD}.. {-1491188400 7200 0 EET}.. {-1247536800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.7873368289068905
          Encrypted:false
          SSDEEP:
          MD5:BE82205480617CF07F76BA0DF06C95BC
          SHA1:46D2D8D9FE4FB570C2A09BC809B02C8960F9601F
          SHA-256:FC93B7516933EDFDC211AC0822EE88BF7ACAD1C58A0643B15294F82EB0F14414
          SHA-512:F490A70053A6011D80FB0A4E96D2871BFEEB168690E21C4EC31F2F5C0E24A67C706528C81322A1D48E71242F0FFA277550192925FDE5B1F34BFCB308290E11FC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Nicosia)]} {.. LoadTimeZoneFile Asia/Nicosia..}..set TZData(:Europe/Nicosia) $TZData(:Asia/Nicosia)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.910647918749938
          Encrypted:false
          SSDEEP:
          MD5:242748F361AD524CD8E288BEE8611E19
          SHA1:A636A544BB54851185E2BE83DAC69C813B824827
          SHA-256:C84E9C0D22059573079211CBF487072CAB95C14B5ECEFB596CF1F594ABD3458C
          SHA-512:404B272D0C6B70332052601EA65C0F7AE71C12F62D19FD3010BBA6FB25E4F2F95BB9E5F295D8494CBADB1AE9C7F833C42382AE7488317EA6F0C20E60B63BEFE8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Oslo) $TZData(:Europe/Berlin)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9152
          Entropy (8bit):3.8506895725632746
          Encrypted:false
          SSDEEP:
          MD5:9CAF8C5C5AF630E7F782C0480DD786E7
          SHA1:9FBEF9EEDD8BAFB48B17E3AC388CFEF8DCD10CB0
          SHA-256:AE61491C4A587F56426A9F2118E31060276F2B0231E750C461781577551CA196
          SHA-512:F809744BB597184A2815758A27B6A07C515C65DB96CFFB3625FD059DEBBF05EE903E999483B3459C7C8D3991824746F8530CD1378F8A63B1F54F60CFACE9F89B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Paris) {.. {-9223372036854775808 561 0 LMT}.. {-2486592561 561 0 PMT}.. {-1855958961 0 0 WET}.. {-1689814800 3600 1 WEST}.. {-1680397200 0 0 WET}.. {-1665363600 3600 1 WEST}.. {-1648342800 0 0 WET}.. {-1635123600 3600 1 WEST}.. {-1616893200 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585443600 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1520557200 0 0 WET}.. {-1507510800 3600 1 WEST}.. {-1490576400 0 0 WET}.. {-1470618000 3600 1 WEST}.. {-1459126800 0 0 WET}.. {-1444006800 3600 1 WEST}.. {-1427677200 0 0 WET}.. {-1411952400 3600 1 WEST}.. {-1396227600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301274000 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269824400 0 0 WET}.. {-1253494800 3
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.910162937111088
          Encrypted:false
          SSDEEP:
          MD5:52C36955D6BD1D9FE9CB64822D04B6DB
          SHA1:D5FF82EC486409E6FB314AD5ACE608577C9632CF
          SHA-256:B87630FF459DE07EB16CD0C2452660772E3FFC4EEB8419EA77A013B6F63A5900
          SHA-512:ABA49D3F05A41A4982600E4DA5C225D8994251F447401EE6FE8478E008BCD5D41C057034185B5CFF805634D571F3CC98EFE98093ABC8E6271351E11A4DA1E7AD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Podgorica) $TZData(:Europe/Belgrade)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8038
          Entropy (8bit):3.8240363895915914
          Encrypted:false
          SSDEEP:
          MD5:828134FA1263FEFA2B06A8B2F075F564
          SHA1:4B332DE6E0855F8B9517F7098A3FB439671FC349
          SHA-256:5D3AFED5C1B07C6C6635D6BDEB28A0FB4D11A61F25F26C91227B2254BE5F4AA0
          SHA-512:9AB1462CDBD7F13F0CECDCCC2D91A85D8C0576B71508F935D26638C25ED023CF8FF4BA4FFDA402B308E6142B135D1B9D88700A519DBE2381E8E945329A5354F7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Prague) {.. {-9223372036854775808 3464 0 LMT}.. {-3786829064 3464 0 PMT}.. {-2469401864 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-777862800 7200 0 CEST}.. {-765327600 3600 0 CET}.. {-746578800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-728517600 0 1 GMT}.. {-721260000 0 0 CET}.. {-716425200 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654217200 7200 1 CEST}.. {-639010800 3600 0 CET}.. {283993200 3600 0 CET}.. {291776400 7200 1 CEST}.. {307501200 3600 0 CET}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7658
          Entropy (8bit):3.7750218768791806
          Encrypted:false
          SSDEEP:
          MD5:0D3C919F60081388524BD5DB22E6904B
          SHA1:6691EAB901C8B57D2F2693120A45A67799D05FCB
          SHA-256:8B64A42BAFD90F9255CACFDBAC603D638DD7C18DC27249F9C9B515E1DA634424
          SHA-512:62A2820B8C1C5468AC1F1BB626F9AAAD0BA1DEC5B73740F00FE4DB8CFA3F2BCF9947968E693824FC8770BA20AB962F93F7E5E345AE8A85F99CDB18E2B510308E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Riga) {.. {-9223372036854775808 5794 0 LMT}.. {-2840146594 5794 0 RMT}.. {-1632008194 9394 1 LST}.. {-1618702594 5794 0 RMT}.. {-1601681794 9394 1 LST}.. {-1597275394 5794 0 RMT}.. {-1377308194 7200 0 EET}.. {-928029600 10800 0 MSK}.. {-899521200 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-795834000 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {6
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8813
          Entropy (8bit):3.8168470239811736
          Encrypted:false
          SSDEEP:
          MD5:C4F49446D3696301EDB339691DCB2FDB
          SHA1:537963A77B9BE9BE6B997A812A6E6DD120F6F247
          SHA-256:DCD2D9144507311E573568598E1FFD0E0574FB677AA0DAFC5641D80A19EB6E58
          SHA-512:1F0A9A549FA0995C51E90AC392671E3F09744B268F1EE6A27CA7E3C41C2B02A4BA0F98369BE40BA482FBA1FED8F1EE712F0B3217AD86164D1AD498E369C24D76
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Rome) {.. {-9223372036854775808 2996 0 LMT}.. {-3252098996 2996 0 RMT}.. {-2403565200 3600 0 CET}.. {-1690765200 7200 1 CEST}.. {-1680487200 3600 0 CET}.. {-1664758800 7200 1 CEST}.. {-1648951200 3600 0 CET}.. {-1635123600 7200 1 CEST}.. {-1616896800 3600 0 CET}.. {-1604278800 7200 1 CEST}.. {-1585533600 3600 0 CET}.. {-1571014800 7200 1 CEST}.. {-1555293600 3600 0 CET}.. {-932432400 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-830307600 7200 0 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-807152400 7200 0 CEST}.. {-798073200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766717200 3600 0 CET}.. {-750898800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-719456400 7200 1 CEST}.. {-701917200 3600 0 CET}.. {-689209200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-114051600 7200 1 CEST}.. {-103168800 36
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2118
          Entropy (8bit):3.664269700453612
          Encrypted:false
          SSDEEP:
          MD5:965D987F6576F66A08871697144D4CDB
          SHA1:AF7226DF81C2B3C3A5832F59FC708A6BCBF389CA
          SHA-256:8F395352AA05D35E7D13380E73659A0D5B56FFC17E3F4E40E4F678A902F0E49B
          SHA-512:B82E0CFA5EDA0FCDF03609AE439255F8937A7E9EFA0AFE15EA8877316782AFC74514BCD2B4F06F1B5F0F3C5A64A933D73CB50D5AED2BB1491BD6CACBB77B10E8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Samara) {.. {-9223372036854775808 12020 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +04}.. {-1102305600 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 7200 0 +03}.. {670377600 10800 1 +03}.. {686102400 10800 0 +03}.. {687916800 14400 0 +04}.. {701820000 18000 1 +05}.. {717544800 14400 0 +04}.. {733
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.955758257767983
          Encrypted:false
          SSDEEP:
          MD5:D253DA6880630A31D39DB0CFA4933ABD
          SHA1:E5798DAAE574729685FE489F296B964BC1CCF2E4
          SHA-256:B6856A0E38C2404F7D5FA1821559503F8AE70923A562F0D993124D131515F395
          SHA-512:CFB6005F3E8D1C585AF36EB7A8C9F49760EF6F446C97E7804EB61EFD0804424C4FB6AE81B71C5A867274EF89A17DAC0D2A0FF882A0F6AEA1D5FFD51593726C5F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Rome)]} {.. LoadTimeZoneFile Europe/Rome..}..set TZData(:Europe/San_Marino) $TZData(:Europe/Rome)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.937834327554967
          Encrypted:false
          SSDEEP:
          MD5:F7C7DAE9C5D371EF9EE1F490246ED3CC
          SHA1:40C388FE2A55078C8E0524A4385B3F8846960E24
          SHA-256:BC00D953C2F3E55E40EDA13838AB66B9E9D0BDAD620E4EB917637761ABB06FB1
          SHA-512:EB22C59F4D58D96797A718FC59B010795F587626E456D44A3E6398E0FBF4ECD97BCDC151BC1359151798B5AF2964FE5708233F8ECD0D344C3E27629F2645687F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Sarajevo) $TZData(:Europe/Belgrade)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2061
          Entropy (8bit):3.6638125261109824
          Encrypted:false
          SSDEEP:
          MD5:CC4D7C478790588D232568CAB12D8E67
          SHA1:07A7CFCFFFF91D124EDFC99F5053BAFC79FBB12B
          SHA-256:AB90363DEE5077C39EC55FE8E519593FF08223E5A8E593F6CCE01FB5B8B35BAE
          SHA-512:23944D20624C942CFDE58F1019160D64401BD0AFB8C3EC49F904038482FAA6741812548C860A2DAE050B8D17A7E08ED9C6EBE7FF19393CFA46D78B1D21B1CACA
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Saratov) {.. {-9223372036854775808 11058 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 10800 0 +04}.. {575420400 14400 1 +04}.. {591145200 10800 0 +03}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {764722800 14400 1 +04}.. {780
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2389
          Entropy (8bit):3.9491446081772748
          Encrypted:false
          SSDEEP:
          MD5:03E05E60E064198BF6562B2E6E8DA8D2
          SHA1:51461207B671536CD4A7587BA283DE2D0017AA4A
          SHA-256:D51CD3DE50C50BCA1624EFC952ADD15D418A09EC213760DF5BC3097E35C5A7A0
          SHA-512:73B7773DABE19F20DD211E178B822FD35620DC4AC8B9D20259971B1157ED7A60A5A41026258FAA8B15016268D241ED804AC1307CACDA00D6FE657407D254B02C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Simferopol) {.. {-9223372036854775808 8184 0 LMT}.. {-2840148984 8160 0 SMT}.. {-1441160160 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-888894000 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-811645200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {631141200 10800 0 MSK}.. {646786800 7200 0 EET}.. {701042400 7200 0 EET}.. {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):187
          Entropy (8bit):4.953089768975736
          Encrypted:false
          SSDEEP:
          MD5:0BF8ADBB63F5D6187C75FF1B0BAC761E
          SHA1:7DE15E767D34812F784CE6E85438A592E2CBA418
          SHA-256:52F20858433261B15797B64F0A09CEE95D552EF93B5DAA7C141BFAB6D718C345
          SHA-512:27D395635427C8FA1A4E0063A32F482701D2CC7C7724B4A06E661D4A419D23E219672888D37367FE5E70B6872914EB9EE034AE359DCB6A4C4CE05CA34C3589A9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Skopje) $TZData(:Europe/Belgrade)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7654
          Entropy (8bit):3.727428614069594
          Encrypted:false
          SSDEEP:
          MD5:91357DFC23ADB0CE80C463E4B6D896BE
          SHA1:273F51BE4C67A9AC1182F86AC060E963684151D5
          SHA-256:6415F279CB143EA598CF8272263AC5B502827B10CEEB242B39E6EFCC23A2EE12
          SHA-512:8EA7E2D4C2239879A4D6CCE302C38A6D2A9093A2CADEF4F4294E60D373AB9A2C468BA6E3D54DEC7F73D954CE5226EF2B022F8BDEF29B3B4AAB3838B05C72EA29
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Sofia) {.. {-9223372036854775808 5596 0 LMT}.. {-2840146396 7016 0 IMT}.. {-2369527016 7200 0 EET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-781048800 7200 0 EET}.. {291762000 10800 0 EEST}.. {307576800 7200 0 EET}.. {323816400 10800 1 EEST}.. {339026400 7200 0 EET}.. {355266000 10800 1 EEST}.. {370393200 7200 0 EET}.. {386715600 10800 1 EEST}.. {401846400 7200 0 EET}.. {417571200 10800 1 EEST}.. {433296000 7200 0 EET}.. {449020800 10800 1 EEST}.. {465350400 7200 0 EET}.. {481075200 10800 1 EEST}.. {496800000 7200 0 EET}.. {512524800 10800 1 EEST}.. {528249600 7200 0 EET}.. {543974400 10800 1 EEST}.. {559699200 7200 0 EET}.. {575424000 10800 1 EEST}.. {591148800 7200 0 EET}.. {606873600 10800 1 EEST}.. {62259
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.956798438511978
          Encrypted:false
          SSDEEP:
          MD5:ACFB8E2D1D4BA0D2D46410F2F2823B21
          SHA1:4AC3A19E94DE606DFF7D93BC6C7F113F3D2D083A
          SHA-256:64615AEA9EF14A2609D2C804901281C83FDDC0A8BCA9B377D6CAD62D81801C66
          SHA-512:2E23AC0DE7D3D0CF2BA4FE3EE31E15EB614A7442097578209D38CE2FF2E3DF006881463866FE67DD4DDEAB179E5CD2946E8A9E8F7401F1B953E9AB216EC753F0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Stockholm) $TZData(:Europe/Berlin)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7549
          Entropy (8bit):3.76585669030767
          Encrypted:false
          SSDEEP:
          MD5:54EF0224F5E28FA78F212EC97D4AE561
          SHA1:FA7C9A951ED943F1E1E609D2253582016BC26B57
          SHA-256:6F3594CCDA78B02B2EE14C8FAE29E668E47193AF2DFCF5AF1ECD210F13BCE9CE
          SHA-512:2D1CA2BB1945AE5E3F56AF8FA7F950CE7169F215C783E683634581C5EC01B54159E47A0E9551897077BBEAB06158906029A4E4B0051A263D9E5D903EA9DA1692
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Tallinn) {.. {-9223372036854775808 5940 0 LMT}.. {-2840146740 5940 0 TMT}.. {-1638322740 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1593824400 5940 0 TMT}.. {-1535938740 7200 0 EET}.. {-927943200 10800 0 MSK}.. {-892954800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-797648400 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 10800 1 EEST}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7675
          Entropy (8bit):3.809498345470167
          Encrypted:false
          SSDEEP:
          MD5:1983B88075A92942209BB2B80E565F4E
          SHA1:12A0401026C5C036144FD1D544173AAB39969F61
          SHA-256:C62686BF598138FEFB72E8CC6632BA75A5FE147F2A30124EE3583BE1F732E38D
          SHA-512:E95C38FA0A2B526C00B9DCF5CDF53059DECF64B085AA18BE000968DA626561944415D053CF7A5C32BC672085538920CFD67A3A3B627CFD5B1A4C9CEC49AA3F96
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Tirane) {.. {-9223372036854775808 4760 0 LMT}.. {-1767230360 3600 0 CET}.. {-932346000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-843519600 3600 0 CET}.. {136854000 7200 1 CEST}.. {149896800 3600 0 CET}.. {168130800 7200 1 CEST}.. {181432800 3600 0 CET}.. {199839600 7200 1 CEST}.. {213141600 3600 0 CET}.. {231894000 7200 1 CEST}.. {244591200 3600 0 CET}.. {263257200 7200 1 CEST}.. {276040800 3600 0 CET}.. {294706800 7200 1 CEST}.. {307490400 3600 0 CET}.. {326156400 7200 1 CEST}.. {339458400 3600 0 CET}.. {357087600 7200 1 CEST}.. {370389600 3600 0 CET}.. {389142000 7200 1 CEST}.. {402444000 3600 0 CET}.. {419468400 7200 1 CEST}.. {433807200 3600 0 CET}.. {449622000 7200 1 CEST}.. {457480800 7200 0 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 C
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.906212162381389
          Encrypted:false
          SSDEEP:
          MD5:E0C99DB7673EEE440BA1848046455BA1
          SHA1:1BCCC1BE46306DEF8A9CA249DE8FA11FC57CC04D
          SHA-256:FDD53FDB5F754BBBA8FF98F0B1555FE0BAEB7852843220A7CF93A190B641A9AD
          SHA-512:CD56B540AE9084DEAA9D0A1DBBAF89733C465424C22CE74696B9AE90FD4FEFAB265CF23C5B13A7F04597D75FD0147BD593E0552B56D87372170CB4CA1BFC8259
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Chisinau)]} {.. LoadTimeZoneFile Europe/Chisinau..}..set TZData(:Europe/Tiraspol) $TZData(:Europe/Chisinau)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2119
          Entropy (8bit):3.680951255407528
          Encrypted:false
          SSDEEP:
          MD5:83C86E437B5FBA1DC9CC5235396AC381
          SHA1:5493A59C3A5A1B55ACD493E67F9E29D2A415A8DB
          SHA-256:9FA9D09509B4F8F5A9C8E422DBA02605070C3EBDAEB7C1DF8527C8EEF5E3632D
          SHA-512:86222489C65C87646939DECF91C2EC336EB46F64B644526A3FA8A4854B9D11819F6FD253107AB8A3DE911E254C88092D25137442164A6E437CDAF258A7CBB66C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Ulyanovsk) {.. {-9223372036854775808 11616 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 7200 0 +03}.. {670377600 10800 1 +03}.. {686102400 7200 0 +02}.. {695779200 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):177
          Entropy (8bit):5.051734481833866
          Encrypted:false
          SSDEEP:
          MD5:17A0CC51331756920B13FFA3FF556751
          SHA1:C575FEF4F053393C57B34C7C7B0C1E9605413792
          SHA-256:F8CAF5DBE12F1647B28E7CCDDB2E09E36788A766690D12E770A8ABD82E708644
          SHA-512:E73F0FE5BE4DD91948A88DC895E148D81267576BA3BCFEA777E25C01EAE9C06845DBFFB651526045B70B7A3CCDB195DFFF60486C01E0A115DFB856873970008E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Uzhgorod) $TZData(:Europe/Kyiv)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.953146873643623
          Encrypted:false
          SSDEEP:
          MD5:A0BAEC8B6AF1589ECBE52667DDB2A153
          SHA1:37093F4F885CBFA90A1F136D082E8B7546244ACC
          SHA-256:06B235BF047FC2303102BC3DC609A5754A6103321D28440B74EEC1C9E3D24642
          SHA-512:DBEC235AFB413FA8D116FA1AFFE73706762E7458038B6D68E0BFD71C339510D766825BA97055A06DEE14D5880EAE6CD035BFE0C935C0DF44B0107A356D293A78
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Zurich)]} {.. LoadTimeZoneFile Europe/Zurich..}..set TZData(:Europe/Vaduz) $TZData(:Europe/Zurich)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):176
          Entropy (8bit):4.914414313741477
          Encrypted:false
          SSDEEP:
          MD5:2404265F8DE1F7D7745893DD4752BA1C
          SHA1:C07E7F72DBDC7F5F746385523EA733C2714F5DA2
          SHA-256:C203E94465BD1D91018FC7670437226EF9A4BB41D59DDE49095363865CA33D00
          SHA-512:5C20834542B74041AAB1DBE35686781B32EEB5814B1A35A942E87D1FC3B6D8F9264CB90433C44A480EA86DDEA65D8C152F41CE3E983C1DE5FA74D6FB5208F701
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Rome)]} {.. LoadTimeZoneFile Europe/Rome..}..set TZData(:Europe/Vatican) $TZData(:Europe/Rome)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7930
          Entropy (8bit):3.8193566380830273
          Encrypted:false
          SSDEEP:
          MD5:6A3A8055DD67174E853C7A208BABAC9B
          SHA1:64445543DE9D6C01FA858442976E249E37BE23EF
          SHA-256:A8165313C9B51DAEF130401439CBA60DAA9887FC5EAA61A5AFD4F7BAD1AD934F
          SHA-512:4407B9E8709A8DD05337A10030895AA9876EAF64EF5347952249EE2A541E304331B46D38532FD7CDFF9E633BF8C9884282F0A5ED259EBA1D99DC0914AF1A50C6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Vienna) {.. {-9223372036854775808 3921 0 LMT}.. {-2422055121 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1577926800 3600 0 CET}.. {-1569711600 7200 1 CEST}.. {-1555801200 3600 0 CET}.. {-938905200 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-780188400 3600 0 CET}.. {-757386000 3600 0 CET}.. {-748479600 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-717634800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {323823600 7200 1 CEST}.. {338940000 3600 0 CET}.. {347151600 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CE
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7485
          Entropy (8bit):3.7711709848169592
          Encrypted:false
          SSDEEP:
          MD5:1AB5FCEACC4E09074BA9F72F0B7747D5
          SHA1:E0134E61EC0ADC60BF6DB4544EA7B7FFA4EC7857
          SHA-256:B762DB4A068DC79FA57691E070D7026086E5A6D2FC273D5C1872E7C8E3711533
          SHA-512:07565071D05CF972DD64F6060599EB68A00BF264172873BA310168AD07CE0CFCF90D0019B775433EC910DA748B89F0C614E7FD4E821993DA53C7E33F194C6A97
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Vilnius) {.. {-9223372036854775808 6076 0 LMT}.. {-2840146876 5040 0 WMT}.. {-1672536240 5736 0 KMT}.. {-1585100136 3600 0 CET}.. {-1561251600 7200 0 EET}.. {-1553565600 3600 0 CET}.. {-928198800 10800 0 MSK}.. {-900126000 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-802141200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 7200 0 EEMMTT}.. {606873600 10800 1 EEST}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2123
          Entropy (8bit):3.667144931158014
          Encrypted:false
          SSDEEP:
          MD5:53E5BA5747B3255BB049F6FF651CEE25
          SHA1:A69E2BFDB89AC8756E1CD2EAA9109ACD924A0850
          SHA-256:22968D40DAC2B669E6D2BC43ED6B16C8A9CA3E1F9DACBF8B246299C3C24CC397
          SHA-512:3269D20DF9C9DDFF8252F33ED563B118771FC71049542DA7C6678E0B5B75FFEA00845FA6F3BC26EDABB4BB7CE449B0B7E00B72473D8D95F126AB3893A9A969B4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Volgograd) {.. {-9223372036854775808 10660 0 LMT}.. {-1577761060 10800 0 +03}.. {-1247540400 14400 0 +04}.. {-256881600 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 10800 0 +04}.. {575420400 14400 1 +04}.. {591145200 10800 0 +03}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8662
          Entropy (8bit):3.8187545871488995
          Encrypted:false
          SSDEEP:
          MD5:992C1D268E336AF1FB8200966C111644
          SHA1:C893B82224C8EF282DB2E16A5BBCC3A21C49B6FE
          SHA-256:F9DC10EC2AE2CC810A6C08837059B34BE651900BA4E1CEDB93C209972CCFB5A2
          SHA-512:EC4E0D8684D57FA66144F11D8E8C80E5272D4A7304300FEBE20E236476C1B8B33BBC5E479BF96D9ED12900FE6D41DD1DC0D11CBE02B89E0C4C7A153B4BFBCB1F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Warsaw) {.. {-9223372036854775808 5040 0 LMT}.. {-2840145840 5040 0 WMT}.. {-1717032240 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618696800 7200 0 EET}.. {-1600473600 10800 1 EEST}.. {-1587168000 7200 0 EET}.. {-931734000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796870800 7200 0 CEST}.. {-796608000 3600 0 CET}.. {-778726800 7200 1 CEST}.. {-762660000 3600 0 CET}.. {-748486800 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-715215600 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {-397094400 7200 1 CEST}.. {-386812800 3600 0 CET}.. {-371088000 72
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):187
          Entropy (8bit):4.899266605519742
          Encrypted:false
          SSDEEP:
          MD5:B07D9D3A5B0D11A578F77995A5FBE12B
          SHA1:1C4E186F2D53C0A1E6A82A6D33B172E403A41D6D
          SHA-256:A49B3894EB84F003EB357647D6A40CEAF6213523196CC1EC24EEFD7D9D6D3C3E
          SHA-512:43520AE325980B236C47C866620D1DA200AC0CD794E8EB642D2936D4B0ECEFE2DA0A93C9559D08581B3CCE2BC75251A4D5B967D376B16EB0C042B0ADCE1DCD01
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Zagreb) $TZData(:Europe/Belgrade)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.999265802825238
          Encrypted:false
          SSDEEP:
          MD5:5B150E25521FE5DD8B83DD9B1B8F3A7A
          SHA1:0BB6F73F2C4B2464F3B1E62138843389AF1A07BC
          SHA-256:EF928AC09B9A366FD015F488B6A19FEFD72DE1BAF34E5CADFB8334946BCF19FE
          SHA-512:4A85A4E929EC6FE66AE60899FA55A75156D075CB2FE41C19337A128F5FA7363B9208AC2DC1BF4E44B76D5F115143D73F6D923E255EA78538D1BE4E45DEBA2049
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Zaporozhye) $TZData(:Europe/Kyiv)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7305
          Entropy (8bit):3.8199799674700277
          Encrypted:false
          SSDEEP:
          MD5:EBD66FAEA63E1B90122CC1EB21634ECE
          SHA1:C6487BB8AB2A6A72B2170B220F383ADB6B9AC91C
          SHA-256:95AFA61E439CA38551306D8FDB11C2788D935C42768D0407C9E4337F105A3E93
          SHA-512:25A8D0ED9BBE6BF23A1A76CC6D5378CF4D50544AA22DA97DDCD0673D7A5CCFEFFD81B660A1AEFB254B8BBEA55F6EF734BBBD3F0CB903E0721BE107667CA1E328
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Zurich) {.. {-9223372036854775808 2048 0 LMT}.. {-3675198848 1786 0 BMT}.. {-2385246586 3600 0 CET}.. {-904435200 7200 1 CEST}.. {-891129600 3600 0 CET}.. {-872985600 7200 1 CEST}.. {-859680000 3600 0 CET}.. {347151600 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CET}.. {386125200 7200 1 CEST}.. {401850000 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 3600 0
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):170
          Entropy (8bit):4.8978035005721265
          Encrypted:false
          SSDEEP:
          MD5:68667037110E713DB3F51922DDE929FE
          SHA1:2EB02BE3FD35F105B59847892A78F1AA21754541
          SHA-256:E20D829C605A7C5B2A96B83C3480DF28C964A13381A8BD2C72C2A37295131FA7
          SHA-512:3A8CC2EC9E3053283F996CA2C4B422061D47F1D16CA07985CBA2C838DF322C23CC9DD28033646F22EAE0E401781480B9D3AF82A539444166A4DD9B7BCCAE45FE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:GB) $TZData(:Europe/London)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):175
          Entropy (8bit):4.90874180513438
          Encrypted:false
          SSDEEP:
          MD5:625520BAAB774520AC54BFB9EDCF9FCA
          SHA1:C72F0FD45F448901C6B2E24243175729591B9A54
          SHA-256:C9334480D0A970254B6BA6FF22E958DC8DD8BF06288229461A551C7C094C3F1D
          SHA-512:1B672218FF9C86168E065A98C3B5F67DAB710D1C2A319E9D6599B397C4B4C00D3721B76C735C8AB04BCB618C1832B07F6CCDAF4266CC0D12A461A3A862D1AEB2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:GB-Eire) $TZData(:Europe/London)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):153
          Entropy (8bit):4.867609984313873
          Encrypted:false
          SSDEEP:
          MD5:A01FE6FC260711F0E11C85DC3DE3550A
          SHA1:988311B71498591425C63669DC3F802F270B2C44
          SHA-256:747C15CDC239855D5380B7A7F47112F2A26C61B0BF300EEB9711E6521550D189
          SHA-512:BE4678DCBAE5DBC72865665413206C1909F28BA54F4943257870EFFBA6525457866DED7A985E89F2689C810B314DE4AA2FA3A0A1826A664727F5F7113AA56595
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):155
          Entropy (8bit):4.917182390229381
          Encrypted:false
          SSDEEP:
          MD5:3327B1BF3118AC6AFC02C31DF5B67CD9
          SHA1:3932577E66801AD31519B0BB56CCE7B9E36221A9
          SHA-256:BE48462CCFBB3AEE19597F082A17C2C5D2FD8BB1C9122245EFAB0A51F8F413B0
          SHA-512:53866FD513B039E8203E51FF3434D5736D3A4C4E0A46874D1C99A17115181AF749F0D079C2E14C5B0538D3DFA52B1645C977CD6599DA3EDA57CC7F84EEAB2D06
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT+0) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):155
          Entropy (8bit):4.904279164422928
          Encrypted:false
          SSDEEP:
          MD5:0CFFC5655F031D954BD623CC4C74DC9C
          SHA1:CE5E7AD67252F52D7E70719725FF5BE393DD6EF0
          SHA-256:944C86F516141DDC3AEC1AE4A963E9769879C48ED12DADDF4ED63A01313ACD00
          SHA-512:C7352D1394E8B8AC90CD19EE753D5277259BE5512ADDCAED2A2DEF144762CF20BE7A9FA09AAA1829EE401DD195C2AED8C967A7FF46739236E042AF4298EC84A2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT-0) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):154
          Entropy (8bit):4.892526720357546
          Encrypted:false
          SSDEEP:
          MD5:565B41A5DB28F9FE7D220E9BA39062A4
          SHA1:5183689210F07C8A71F880DCE8E5C2CB62CEB17D
          SHA-256:54850A5F488205DB01FBB46E2DA9FFF951C4571029EA64D35932DDEA5346DAAF
          SHA-512:BD6E5141F06B03D62DCF725E9E48D6AA8ECD6E8E47A4015B25DC3F672392065FFFD80D688C6695324DC105EA528025CF447FA77E6D17E15D438E61DC51879CB7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT0) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):159
          Entropy (8bit):4.917976058206477
          Encrypted:false
          SSDEEP:
          MD5:443FA76F107ED438F9571A044B848C6A
          SHA1:1CF508429DFC40643B1FAB336A249A3A287D8C7C
          SHA-256:9E7A8DAA26CE36E8F7D7F13460915C063EE98E2A4DB276AD9D15CA5C7C06815F
          SHA-512:6C0C5FF513A742FBDA349AC3A2581D456701B5348A54ECF38E496DAA1EFC74D937982B6F69F1761CC2FC4B88D9A971EFA2B16096E71EAF002EC5CE4130B533DE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Greenwich) $TZData(:Etc/GMT)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):111
          Entropy (8bit):4.90682088010982
          Encrypted:false
          SSDEEP:
          MD5:79C82A5F8B034E71D0582371E3218DBB
          SHA1:1476CE8EA223095094B6D25D171E6319C96669F4
          SHA-256:8D710699AF319E0DDB83E9F3A32D07AE8082EA2F7EABBD345EFFFFB0F563062E
          SHA-512:ADEE55581D1A158929F09A63B03883ABE9193337DDF225C61AFDBB8A2C7D0BD248ADC4714E0EEFD334826C54C1AFFC8B1E6C2B0D6EF830C3CCA50CC79834F473
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:HST) {.. {-9223372036854775808 -36000 0 HST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.913328649996328
          Encrypted:false
          SSDEEP:
          MD5:6A307B229C302B1BAE783C8143809269
          SHA1:EA169AF81AD12380A69FB6B7A12479BA8B82878B
          SHA-256:359C9C02A9FA3DE10BA48FA0AB47D8D7AFF3B47F950CFAF5EB68F842EA52AB21
          SHA-512:505445FD0B3E140384EDC27993923BBF9ACD23A244B0F14D58804BFAA946D0BC4C0D301FBCCB492BAFDA42C8A92F4163FB96F4D75DD7374858D1C66183BEC24B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Hong_Kong)]} {.. LoadTimeZoneFile Asia/Hong_Kong..}..set TZData(:Hongkong) $TZData(:Asia/Hong_Kong)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):178
          Entropy (8bit):4.853280551555672
          Encrypted:false
          SSDEEP:
          MD5:710D3A32EA8EAD11B45D4911DA8F2676
          SHA1:146D2A6D48940E58567EFA3BCA134D195E4649E6
          SHA-256:8A531293F672D8FE38996989FC4EEB22B5EFE6E046E2F58E94D01DA9CE56EF68
          SHA-512:70432973549C1A83036E0658AEE81C883F19D0D631E35F4C70F2EC69C9384E99340004618EF8B414D8EA9090C6C3120CF46A5D9ABDE4113917995B2844337988
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Iceland) $TZData(:Africa/Abidjan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.807410166086502
          Encrypted:false
          SSDEEP:
          MD5:0F20CBF1F7600D05F85D4D90FDAB2465
          SHA1:2F3C9479C4F4CD7999B19C07359B89A5FB1B9839
          SHA-256:1B1177CE4D59D7CBCAE9B0421EB00AD341ECB299BD15773D4ED077F0F2CE7B38
          SHA-512:657341FC2CCD6A4F7B405ABC8E24C651F6FFEFD68EBD6E2086ADF44834DCBF21D1B9D414436E42C8DCE46FFB88116B98C1D073782E214B3996D49EC00DFF4383
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Antananarivo) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.853088038233057
          Encrypted:false
          SSDEEP:
          MD5:06143C3DFD86B3FE4F2A3060C0E05BB6
          SHA1:88E0E30CEE4AB8117860A35AD03B16AF48988789
          SHA-256:11044AD7CB0848CC734D2A67128AA6AC07CB89268399AA0A71A99024DE4B8879
          SHA-512:79195D3D0D475BEA982F40683D4BA14AC33B3FA91311F513DCED955C9297C2B0F12D94CCA930FAE0FB7F95DB34CD4E74B5AF0233E792122646592B7EFF0F3163
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Chagos) {.. {-9223372036854775808 17380 0 LMT}.. {-1988167780 18000 0 +05}.. {820436400 21600 0 +06}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):181
          Entropy (8bit):4.910217468889087
          Encrypted:false
          SSDEEP:
          MD5:39CB9E58C0086B80FB12AC10A6D371E2
          SHA1:2A9A5CCA411779615A62D9E82023B6A066CB3CF3
          SHA-256:78A208B73426A1B6D7CF2FE89A0EF3F01721F877D569BC43F2E5B6625A947299
          SHA-512:BB6C8CF2B6AF9F93A7F7382A453261FA43E6E42E9ED1223F25A70DAD2ABBBF2F5777288553F4BC0155944754655D2C3F81BD81E5B1F611C4B2CCDB729B67AAC5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Indian/Christmas) $TZData(:Asia/Bangkok)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):174
          Entropy (8bit):4.818886812441817
          Encrypted:false
          SSDEEP:
          MD5:9462E9CFC88C3DA3CCCDA18C92E49A97
          SHA1:B50C82C6C7361BD6F028F82E2FEAF8486D798137
          SHA-256:EB301EE97A9FDE8ACE0243941C0FAC9ED0E3ACFD6497ABE408F08E95FAE3B732
          SHA-512:A48EBDA0A93C3505BC6149863F4A7B1043F856A8EB516CF42C050A95E81CD152BC1C0313B3DD115D53DABA95413AF34902D7D11C984DE5A03FC5FFADAF8EA89F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Yangon)]} {.. LoadTimeZoneFile Asia/Yangon..}..set TZData(:Indian/Cocos) $TZData(:Asia/Yangon)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.825881690094318
          Encrypted:false
          SSDEEP:
          MD5:7EBDFA311C7852AFADF880395071DE48
          SHA1:F6EC21FDFB75EC1BE45B1C4170147CBA3E870E7B
          SHA-256:53FA58E32DC2E4ABB574B2F78011815EEB7F89F453CC63C6B6C1460ABBB4CA5C
          SHA-512:DFBCD4EA4AFFA1D1CAE7308168874527FD36B5CAE76153AADA9C5E5F628258AB26654A16C8A5F8906FC5918398FD880B15B6DD4E3EF6AD3BE63D4A2455701FA8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Comoro) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.822075418239496
          Encrypted:false
          SSDEEP:
          MD5:9AB222C67E079B55DDF3ACAE67BD0261
          SHA1:F9E6C34A00F9F1B152CEA729F087BD24993CA2E8
          SHA-256:138C7FFBFC520372658CA0CD1B42C4E5A240E9D9B98A277B02481DE5701222FC
          SHA-512:5F3EFF78506056F981DB0446436B39953D90265227890176D8287E2149B176B9DCCA14E795083B1EBC202D02AA88D584A9BB49868F30895EF17E92AA98ACB7C7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Indian/Maldives)]} {.. LoadTimeZoneFile Indian/Maldives..}..set TZData(:Indian/Kerguelen) $TZData(:Indian/Maldives)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):170
          Entropy (8bit):4.84472938642971
          Encrypted:false
          SSDEEP:
          MD5:C866B2A879786B7D9341FA904FC7D01A
          SHA1:DAF7B405E6DAA0C88C6F3A26AAA172E38CE5CAF3
          SHA-256:613C5C05A8867E4B59A97A3D8C7235DDC0CA23239F2D57A5BFD42E4AB94FD510
          SHA-512:BB01A464366F1F93591F48C42F300421AF774E50E5B5232AB0C755482E3306EDDB54A9BCF6E9D325EAE63AAC6D3857F4D754FC28A34F90AC728B7158B61E2C57
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Indian/Mahe) $TZData(:Asia/Dubai)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.883092265054605
          Encrypted:false
          SSDEEP:
          MD5:4DF975C040D78FA8F9C92E5565D63A73
          SHA1:48488F076871530D32278084F1C9CB90CB1E6AB4
          SHA-256:9FAC69DC609CC6074ECD67E0BE8AE62E33D8D9C7F055A3E0DEE1430C7FFC54F6
          SHA-512:880B920FB51F48731BA8C741B9583038A3276221C55F1CE0B464D2797D71EF9D22B4E166841BAB0544B7091CE683697BFCA5A4235FF1E6264B0619DBDD4BB619
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Maldives) {.. {-9223372036854775808 17640 0 LMT}.. {-2840158440 17640 0 MMT}.. {-315636840 18000 0 +05}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):272
          Entropy (8bit):4.5144164346164715
          Encrypted:false
          SSDEEP:
          MD5:05362B6A17C5F4F4E8CBE5A676D5D0DE
          SHA1:84675D5E8D1425A5E9DB07D1BC1E6A5921B5AC91
          SHA-256:A2B1B93CBEECBD900ED71E61A4932509EB52688E97A6015DAD067066D0D42072
          SHA-512:351D2BC5F5888D8E842BF160D11D57E059811186D63B0413061768C7FE348CECB700748A0C0125F0ABCBB039FC74FF7BEEFDD42088BA1E28C785E545ED2CDF24
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Mauritius) {.. {-9223372036854775808 13800 0 LMT}.. {-1988164200 14400 0 +04}.. {403041600 18000 1 +04}.. {417034800 14400 0 +04}.. {1224972000 18000 1 +04}.. {1238274000 14400 0 +04}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.828945679595274
          Encrypted:false
          SSDEEP:
          MD5:8ABBEC0E138C1A68CB5D096E822DE75E
          SHA1:E9C5CE1A249F6DC0F6EDBB3F5B00F3106E3BD6CA
          SHA-256:845C45FD7B6F0604B03A3C72DB117878B568FB537BCA078304727964157B96AB
          SHA-512:15790CCA70140D3139F3E2A202DC8F12E68466A367C68458D6A78CDDC7822FB5EDB87D630926B51F3DE48D95DE7CA3FCB946CD7B762FE5B15866DAA9DBA40B46
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Mayotte) $TZData(:Africa/Nairobi)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):173
          Entropy (8bit):4.825214661273383
          Encrypted:false
          SSDEEP:
          MD5:7B22FE05231A5721C939B6018F8A2814
          SHA1:E272C25E79ABE705B2DB106D70DEAB3245EA9D35
          SHA-256:5560B0D4A2D8A13D9FE9787FFFE31200D405A8C875F046C8FDDF850AF98662B6
          SHA-512:26244855D029151B84A4D57E2FA69632B4F19F8C00B2E500A394D76A29857BE2A412344794BA0DFF50A2863FF17889210A151D0E231A67E55091F4909EC4AE79
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Indian/Reunion) $TZData(:Asia/Dubai)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):166
          Entropy (8bit):4.809541513808179
          Encrypted:false
          SSDEEP:
          MD5:A90C26358FEF60E49044E3BE02866FAC
          SHA1:137AC8CCA23F39E7A16C4050EA9A3A8731E9AAD7
          SHA-256:FE7F4453CB5F6B81B23C1C795356B91FE319F0762BE7868FAFE361DB1F9C2A2B
          SHA-512:D6C74CACF69D29E14CB46E5DD885234AC50EE2E258E0C5E3AC76465061622F064F974D33E91A6A020B9D618D90799DDA6EB1EA53022EDB6E26A9CB6ADFE0AA30
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Tehran)]} {.. LoadTimeZoneFile Asia/Tehran..}..set TZData(:Iran) $TZData(:Asia/Tehran)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):177
          Entropy (8bit):4.8290104377288925
          Encrypted:false
          SSDEEP:
          MD5:6BCC43951637D86ED54585BE0819E39C
          SHA1:6F04F306B3AB2A6419377294238B3164F86EF4A3
          SHA-256:805105F5F17B78929F8476BAE83ED972128633FF6F74B7748B063E3C810C27A6
          SHA-512:ABB9F4308BF4BD5C62C215A7ECD95042CBFB3005AF1E75F640962B022574C930DD5A12CD0CE0AF8A3D7E38B999E37C3A45A55091683F6A87E9D0CDA9EE417293
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Jerusalem)]} {.. LoadTimeZoneFile Asia/Jerusalem..}..set TZData(:Israel) $TZData(:Asia/Jerusalem)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):181
          Entropy (8bit):4.722012123002917
          Encrypted:false
          SSDEEP:
          MD5:1F020341AD51AA82794B8018F214DE0D
          SHA1:4414E56C1277B4D31FE557F8652D522C0594F4B2
          SHA-256:F01B00D52BD7B2694BF5CB55A17028C30A41BD22A774CA54740E8B1DDE4FCB2E
          SHA-512:CC41848A851D4992AE9F27C38669CB87CE2FD05A33AB6989EA21AFCB1A2707DE0CB4D62BCC45E536DD944859991D7564847205F47509A42D41932370496A77D7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Jamaica)]} {.. LoadTimeZoneFile America/Jamaica..}..set TZData(:Jamaica) $TZData(:America/Jamaica)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):164
          Entropy (8bit):4.8422204749795545
          Encrypted:false
          SSDEEP:
          MD5:9554A65BFFCFFCFB2C1588569BB4638E
          SHA1:B377ECB04586396D37093856AEF8BBDC93192F66
          SHA-256:98DBD07AE3B9251B9091F4D265336CE98BDFB492AF863C1F3FF25248A2CADF35
          SHA-512:E2E761B8B1995B68721BC714A546E0F45EEC025FAF81DE579FF0D73D37783D0E031B9E78BA2FAC6B097E3673C47AFB8761FBC58E42E33018FD44B77F2871E0C6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Tokyo)]} {.. LoadTimeZoneFile Asia/Tokyo..}..set TZData(:Japan) $TZData(:Asia/Tokyo)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.810216093939366
          Encrypted:false
          SSDEEP:
          MD5:05C0C40F2AA456F580EAAFC4F7E49B56
          SHA1:5796A9122693B2D6010BC5E617A6091F46330B0C
          SHA-256:85E95363ACF468043CD5146927A97B2D9E3B141EDA0A7993DADA9382D1D6DD54
          SHA-512:2155F8E3EB73312F0AFD5CDDF4B19EBB67A15658101870C2CEDF96955470DBC7B30F34E143D9C14CBFA7A138F63324009581BD0B807AE295C68588CA0470D7AD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Kwajalein)]} {.. LoadTimeZoneFile Pacific/Kwajalein..}..set TZData(:Kwajalein) $TZData(:Pacific/Kwajalein)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):176
          Entropy (8bit):4.829980800076139
          Encrypted:false
          SSDEEP:
          MD5:4D44D88336212E162CCEFADE6321EDBC
          SHA1:B9EE7AFE26DC61AA9EA37EB99A3C10DD176E8063
          SHA-256:F776839C1999056E6A0D2ECFDF9054FC309454AFDFF8E8BC803F33EC423B7361
          SHA-512:FDDCBD194DE07B51DEBBDEF4FD96762EE3507117443FB9F7975FB56E0AE97B0D1F8657FE26B092021FB12B5A5D3EFFAB9E0A54B1C2AFCEC1029855442A0A95AB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Tripoli)]} {.. LoadTimeZoneFile Africa/Tripoli..}..set TZData(:Libya) $TZData(:Africa/Tripoli)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7736
          Entropy (8bit):3.799706947156251
          Encrypted:false
          SSDEEP:
          MD5:02B993B4A6956014A2DB844E8A5498C0
          SHA1:378333547254AC43BEB4FA2CBC24B8DE241B3078
          SHA-256:DF45F5414F1636B1856C7534BB5F3D4387C32D56283A68BB47D8C48C1DDAD5BC
          SHA-512:CC3ABCC1FB5ABD10A685F140931DE38D6875142D3595F8D9A581F5B31A7F354FA4CCC9727B69F58E0D2F773EA0F76D9ACFDF7ACBAFC6BAA6E93A46EAE8F18672
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MET) {.. {-9223372036854775808 3600 0 MET}.. {-1693706400 7200 1 MEST}.. {-1680483600 3600 0 MET}.. {-1663455600 7200 1 MEST}.. {-1650150000 3600 0 MET}.. {-1632006000 7200 1 MEST}.. {-1618700400 3600 0 MET}.. {-938905200 7200 1 MEST}.. {-857257200 3600 0 MET}.. {-844556400 7200 1 MEST}.. {-828226800 3600 0 MET}.. {-812502000 7200 1 MEST}.. {-796777200 3600 0 MET}.. {-781052400 7200 1 MEST}.. {-766623600 3600 0 MET}.. {228877200 7200 1 MEST}.. {243997200 3600 0 MET}.. {260326800 7200 1 MEST}.. {276051600 3600 0 MET}.. {291776400 7200 1 MEST}.. {307501200 3600 0 MET}.. {323830800 7200 1 MEST}.. {338950800 3600 0 MET}.. {354675600 7200 1 MEST}.. {370400400 3600 0 MET}.. {386125200 7200 1 MEST}.. {401850000 3600 0 MET}.. {417574800 7200 1 MEST}.. {433299600 3600 0 MET}.. {449024400 7200 1 MEST}.. {465354000 3600 0 MET}.. {481078800 7200
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):111
          Entropy (8bit):4.902637155364683
          Encrypted:false
          SSDEEP:
          MD5:36119516E87814F3C219193069CD6A90
          SHA1:BDB25531B30E6FC454100F37177EC9D4A0FB4E39
          SHA-256:E57746D5DB479A8B30973F2BC16E2B8DFB6E2BFAECBFF0FB956F04526E4B935B
          SHA-512:2730C5DABA0B2CCFD32A799C48EE07351659F51B9C2B91DCD145675AF276F2D0B5AA51ACF7D283C0DC236D3AFA3A75E58EB9F970B1831A6E36F02139CAF6A655
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MST) {.. {-9223372036854775808 -25200 0 MST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8505
          Entropy (8bit):3.8405400251137207
          Encrypted:false
          SSDEEP:
          MD5:87B3BCD4A793BA383889ECFDB44C846E
          SHA1:3EA34B5E6E3078A9501653BA069D5E5E879D7FE4
          SHA-256:A5DEB89D59613D9A54C1E146056A805B3DE9F2A2593AEC2B8A25F863328699C0
          SHA-512:AA4DAC2614661EF18A2A60A5BD4D5BBBCCB5D721F90A25E9D11C5B6AF8C39FD475B3E23894719E2F8F74469F13D5492FF31DDD193D9E3172182FBCBCDD860A41
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MST7MDT) {.. {-9223372036854775808 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -21600 1 MDT}.. {247046400 -25200 0 MST}.. {262774800
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.884776849010803
          Encrypted:false
          SSDEEP:
          MD5:3050A0100A2313C1D3AB4278B464F17A
          SHA1:1A140447B3972900F13768659FD6979F68126E97
          SHA-256:F8CA38A845CD01BF785EE222277DAD9325AB6BD17E44A362C450855AEB522814
          SHA-512:C91C4BF2318C50D473E6051855C12F0E11CBAA8580B88115CDDE054D36476A1D8DDC5D17A7A123BD84148C20B96BD839511EAD573F5FD2C9A8556646B9CDE5E5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Tijuana)]} {.. LoadTimeZoneFile America/Tijuana..}..set TZData(:Mexico/BajaNorte) $TZData(:America/Tijuana)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):191
          Entropy (8bit):4.8897674180962145
          Encrypted:false
          SSDEEP:
          MD5:FAFD9727A0E153AFCB726690D215DA76
          SHA1:3CD3B2737FC781F38DE26E255968CBB88B773CBF
          SHA-256:2E6E32A40487F0146B59150B66FF74901CA853B12D47922819AF23EEA5B4149C
          SHA-512:76D110494D4EB76961C818B2A2CCB2303B31DA161664FA712C87B95B81DE7B8F3E50DC7B2836C6ECC6437AE9595668E62E4E706F1B343EFEA12C32210F113540
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Mazatlan)]} {.. LoadTimeZoneFile America/Mazatlan..}..set TZData(:Mexico/BajaSur) $TZData(:America/Mazatlan)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):200
          Entropy (8bit):4.877941255622543
          Encrypted:false
          SSDEEP:
          MD5:29ACBFCD0FD521EC0C9523906B9E2252
          SHA1:BBC1AD3F78CAA634A2F0BC38059975EF8E4A2CE9
          SHA-256:2DFF1B83FECFAD5C27EC47B206696C29B91398F8185B5D406A66FA9E0AECA93F
          SHA-512:802502010CFB6F1F4E60C22ECB0E6CA22750975E5838BE7E7DC9D12EA019CB6508F0F87465A113A98356CC9E145E32E6633AE2B45B93412A358C4AD13E923EFE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Mexico_City)]} {.. LoadTimeZoneFile America/Mexico_City..}..set TZData(:Mexico/General) $TZData(:America/Mexico_City)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.888611285267583
          Encrypted:false
          SSDEEP:
          MD5:92548E239012515D756E002768CA876A
          SHA1:6BDC73DBD7356C3F82C5C76E6E2D58656FA9E21D
          SHA-256:E22D629D53C54960AD156C377DE0AE461C27F554990A3D1305724CA8F869BCE4
          SHA-512:42AD074EE08E083EE91270F203707698A8B3308005C94514B8B2D950F4C6F0B37D7D32973EC9F6AB49A0875209076FB40341B31433A27E47B3CC0EA711ECE321
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:NZ) $TZData(:Pacific/Auckland)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):181
          Entropy (8bit):4.881663364410736
          Encrypted:false
          SSDEEP:
          MD5:3811C133C6311E33FDAF93660E1EAED5
          SHA1:64756FF877B2EB91BAED2889B3924DAB6784DF43
          SHA-256:83F4CA3522B64F9B151EDEFAE53E0F28C2E6C4CE16D0982186B3344F2A268724
          SHA-512:7724D6CD08E13E116CCDF073F86CE317C0D4A849C5FE81DF3127D435704507FBF554BFC6E7A50CCA3852F6001D8654B7FF90466878DB8C3298338BE16149FD32
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Chatham)]} {.. LoadTimeZoneFile Pacific/Chatham..}..set TZData(:NZ-CHAT) $TZData(:Pacific/Chatham)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):177
          Entropy (8bit):4.8545620422964015
          Encrypted:false
          SSDEEP:
          MD5:5E9F3294F68873BF503F3DDDDF6713B0
          SHA1:954CD6F123C043E64F5E49733327E2C78877BDFB
          SHA-256:2CC8CE235F2EE3160E6AFD04A4E28AA0312494EBB6FED08D8CC81D414EC540EE
          SHA-512:200FC489989CA57219D5B28FB135BE5BDAC67239F3D243C496545D86D68089E51856CEAC4D2E700C0E47BAE4D5FEAB18A367C554235615B2B860F4E5E1BB08C3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:Navajo) $TZData(:America/Denver)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):171
          Entropy (8bit):4.902914099699953
          Encrypted:false
          SSDEEP:
          MD5:87C439DC623BF5C7EB01ADA6E67FB63A
          SHA1:1CC357558E09CDEA49F821826D2AEA9A6EF2C824
          SHA-256:6A5BAA9CA54B2A2C6D21287443BE0B1064AA79B5C4C62939933F8A0AD842B73E
          SHA-512:E628B8F1C967AABAEFBB68A33416F6FE47422970BA18414BB3396AC063E65A4DC892595D4071395194AF320633EE915A494E1F8D4216EE8194A034739D275C49
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:PRC) $TZData(:Asia/Shanghai)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8505
          Entropy (8bit):3.836877329152454
          Encrypted:false
          SSDEEP:
          MD5:45E7E9E183A990F56E17C04FA48CE620
          SHA1:A1F39E0ECEA3C64E761A9A3159E331FA51B625F9
          SHA-256:D148708F1E70EEFA51E88E5823776CBE710535D4D6D6356E7753A44463A1C5AB
          SHA-512:1D1F4BA90D07D7EE12DFD0E37DBFD5410A4EAFFBA8960B816FDD5963CD6B20938080A4248E7B249AAE02F068E817AB9A85735D226F7DA8DD2C5462A70B18E8EF
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:PST8PDT) {.. {-9223372036854775808 -28800 0 PST}.. {-1633269600 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-1601820000 -25200 1 PDT}.. {-1583679600 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-84376800 -25200 1 PDT}.. {-68655600 -28800 0 PST}.. {-52927200 -25200 1 PDT}.. {-37206000 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):909
          Entropy (8bit):4.042826306713664
          Encrypted:false
          SSDEEP:
          MD5:E5B913965F72AB807BAE67BD20C0A699
          SHA1:2161B73EC868C8D18C09970766D19A8583FF7981
          SHA-256:983884249ACC11C3FE740D78E72B1A89BE9C8B077283549BF6BCD8C93FA71731
          SHA-512:F8807C52DB852C48C62F25569C990C31D977BC7D0DF502CF2B92F9ED6BCB89A6DD8A6758FBD1185E0B5C34DE5450D5C748B71760AC93E72DC3976B3B31D1A605
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Apia) {.. {-9223372036854775808 45184 0 LMT}.. {-2445424384 -41216 0 LMT}.. {-1861878784 -41400 0 -1130}.. {-631110600 -39600 0 -11}.. {1285498800 -36000 1 -11}.. {1301752800 -39600 0 -11}.. {1316872800 -36000 1 -11}.. {1325239200 50400 0 +13}.. {1333202400 46800 0 +13}.. {1348927200 50400 1 +13}.. {1365256800 46800 0 +13}.. {1380376800 50400 1 +13}.. {1396706400 46800 0 +13}.. {1411826400 50400 1 +13}.. {1428156000 46800 0 +13}.. {1443276000 50400 1 +13}.. {1459605600 46800 0 +13}.. {1474725600 50400 1 +13}.. {1491055200 46800 0 +13}.. {1506175200 50400 1 +13}.. {1522504800 46800 0 +13}.. {1538229600 50400 1 +13}.. {1554559200 46800 0 +13}.. {1569679200 50400 1 +13}.. {1586008800 46800 0 +13}.. {1601128800 50400 1 +13}.. {1617458400 46800 0 +13}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8772
          Entropy (8bit):3.900078030355782
          Encrypted:false
          SSDEEP:
          MD5:8174D7205622711F58E0B515246FE89D
          SHA1:9777B2633ACF5588268D5072F817E65C879358AC
          SHA-256:201CFADB00FBCD3283249DAD73872ED75C5BEC07F5A5B157726638C20728B833
          SHA-512:64121ED1EE70D5423710319E806B19261576AECC89A64CBEC44A29BF4AC9FEE21C6484CC3C4550CC92C315B3855BE265F696F8CD4D95027226D608B3ADD022F1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Auckland) {.. {-9223372036854775808 41944 0 LMT}.. {-3192435544 41400 0 NZMT}.. {-1330335000 45000 1 NZST}.. {-1320057000 41400 0 NZMT}.. {-1300699800 43200 1 NZST}.. {-1287396000 41400 0 NZMT}.. {-1269250200 43200 1 NZST}.. {-1255946400 41400 0 NZMT}.. {-1237800600 43200 1 NZST}.. {-1224496800 41400 0 NZMT}.. {-1206351000 43200 1 NZST}.. {-1192442400 41400 0 NZMT}.. {-1174901400 43200 1 NZST}.. {-1160992800 41400 0 NZMT}.. {-1143451800 43200 1 NZST}.. {-1125914400 41400 0 NZMT}.. {-1112607000 43200 1 NZST}.. {-1094464800 41400 0 NZMT}.. {-1081157400 43200 1 NZST}.. {-1063015200 41400 0 NZMT}.. {-1049707800 43200 1 NZST}.. {-1031565600 41400 0 NZMT}.. {-1018258200 43200 1 NZST}.. {-1000116000 41400 0 NZMT}.. {-986808600 43200 1 NZST}.. {-968061600 41400 0 NZMT}.. {-955359000 43200 1 NZST}.. {-936612000 41400 0 NZMT}.. {-923304600 4320
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):280
          Entropy (8bit):4.715653436088026
          Encrypted:false
          SSDEEP:
          MD5:4E858B3754BD8864719A61839ACA64E6
          SHA1:597025A8DAFD5AE75EBD162AC0E9DA71815816BA
          SHA-256:2D3BFDED297214BA25CFD8C6F508D0C8B1A1CD7D46701A78EC5E510076185EB6
          SHA-512:720F301B73C852EA8EEFA79DEF6B6762554E50222DE114FE87EB5178507F1895A9A39B3872A1A4B9DFF58D1CC6460BA4A82F2C165E3659E13036451F22E389C3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Bougainville) {.. {-9223372036854775808 37336 0 LMT}.. {-2840178136 35312 0 PMMT}.. {-2366790512 36000 0 +10}.. {-868010400 32400 0 +09}.. {-768906000 36000 0 +10}.. {1419696000 39600 0 +11}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8165
          Entropy (8bit):3.6566720439018874
          Encrypted:false
          SSDEEP:
          MD5:8105A806A1762932897AB59C47BBE89E
          SHA1:386E41A4A83FA84DBFCA994F679242D067CEED64
          SHA-256:CA0EEF84DBC5964EF2265E9252237BE58BB8D75C34817CC2305CCCFAEC7E690C
          SHA-512:8A609E7F4868BD455DA811E62142FECD792D0CA0DAAF7C10C4E4254C9EC44B8EB92D388D9224C8FD3CC3FB326A106D831B80F5E1264CCF3EABBCE177BB82E9D6
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Chatham) {.. {-9223372036854775808 44028 0 LMT}.. {-3192437628 44100 0 +1215}.. {-757426500 45900 0 +1245}.. {152632800 49500 1 +1245}.. {162309600 45900 0 +1245}.. {183477600 49500 1 +1245}.. {194968800 45900 0 +1245}.. {215532000 49500 1 +1245}.. {226418400 45900 0 +1245}.. {246981600 49500 1 +1245}.. {257868000 45900 0 +1245}.. {278431200 49500 1 +1245}.. {289317600 45900 0 +1245}.. {309880800 49500 1 +1245}.. {320767200 45900 0 +1245}.. {341330400 49500 1 +1245}.. {352216800 45900 0 +1245}.. {372780000 49500 1 +1245}.. {384271200 45900 0 +1245}.. {404834400 49500 1 +1245}.. {415720800 45900 0 +1245}.. {436284000 49500 1 +1245}.. {447170400 45900 0 +1245}.. {467733600 49500 1 +1245}.. {478620000 45900 0 +1245}.. {499183200 49500 1 +1245}.. {510069600 45900 0 +1245}.. {530632800 49500 1 +1245}.. {541519200 45900 0 +1245}.. {56208
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):202
          Entropy (8bit):4.943709180393636
          Encrypted:false
          SSDEEP:
          MD5:7D9980F68F044EB9B7FA7ED2883645F2
          SHA1:9444DA9D3139F51C6DFDA174C8C52A231215D71E
          SHA-256:F324CA637180F50DB79FFA25204D974C6A7A6FAEFDA69FD1A280B9F366349A09
          SHA-512:850577ABD3A3653076797D46AF481343CDF8103AC597EB68F575C5FF4931242C6ACEB054D14E0F6A9A90E5D22069F78027215A4E44FC900292445FDEAFB8F92D
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Chuuk) $TZData(:Pacific/Port_Moresby)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8203
          Entropy (8bit):3.5469404823178463
          Encrypted:false
          SSDEEP:
          MD5:002F3607DE2061A2E1A8EB8EBCB6E492
          SHA1:6521B47847CFA76FE45AE5CC649109E4AD6C5262
          SHA-256:D79A2A67606F25D6420F31129FAE966A54287DE96C661003CCE5F82B618014BC
          SHA-512:03F3F262538FAF5A1B38832EFA62E3CC41A70BF54E73DE59BC99DCCA035AB002142F42BEDA5BFC2102CD556601E0A278908FDCC838A2211AC63C49A8483CE72B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Easter) {.. {-9223372036854775808 -26248 0 LMT}.. {-2524495352 -26248 0 EMT}.. {-1178124152 -25200 0 -07}.. {-36619200 -21600 1 -07}.. {-23922000 -25200 0 -07}.. {-3355200 -21600 1 -07}.. {7527600 -25200 0 -07}.. {24465600 -21600 1 -07}.. {37767600 -25200 0 -07}.. {55915200 -21600 1 -07}.. {69217200 -25200 0 -07}.. {87969600 -21600 1 -07}.. {100666800 -25200 0 -07}.. {118209600 -21600 1 -07}.. {132116400 -25200 0 -07}.. {150868800 -21600 1 -07}.. {163566000 -25200 0 -07}.. {182318400 -21600 1 -07}.. {195620400 -25200 0 -07}.. {213768000 -21600 1 -07}.. {227070000 -25200 0 -07}.. {245217600 -21600 1 -07}.. {258519600 -25200 0 -07}.. {277272000 -21600 1 -07}.. {289969200 -25200 0 -07}.. {308721600 -21600 1 -07}.. {321418800 -25200 0 -07}.. {340171200 -21600 1 -07}.. {353473200 -25200 0 -07}.. {371620800 -21600 1 -07}.. {384922800
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):789
          Entropy (8bit):4.0457106900970325
          Encrypted:false
          SSDEEP:
          MD5:6841B8A2FB9BBF464AA00088CBDCEC80
          SHA1:26CC5CCE00A765F8B6493ED24F50957AA7F0089B
          SHA-256:332372E5EFB46123FBB66F9F32F91B59EBD88ADB956249DB3F14CAAB01CE2655
          SHA-512:A6C67A0F7361E599369597E9A8A52FC7D5C96DE6B5A7C1BE1D02F5DF11051F448289786C7F0E82E71CDEB825215E64E072CF034C45D6E2F822D7201AB8B41B57
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Efate) {.. {-9223372036854775808 40396 0 LMT}.. {-1829387596 39600 0 +11}.. {125409600 43200 1 +11}.. {133876800 39600 0 +11}.. {433256400 43200 1 +11}.. {448977600 39600 0 +11}.. {464706000 43200 1 +11}.. {480427200 39600 0 +11}.. {496760400 43200 1 +11}.. {511876800 39600 0 +11}.. {528210000 43200 1 +11}.. {543931200 39600 0 +11}.. {559659600 43200 1 +11}.. {575380800 39600 0 +11}.. {591109200 43200 1 +11}.. {606830400 39600 0 +11}.. {622558800 43200 1 +11}.. {638280000 39600 0 +11}.. {654008400 43200 1 +11}.. {669729600 39600 0 +11}.. {686062800 43200 1 +11}.. {696340800 39600 0 +11}.. {719931600 43200 1 +11}.. {727790400 39600 0 +11}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.82787610497142
          Encrypted:false
          SSDEEP:
          MD5:CD1AC50AADC3CF9C0E7A055D587E790D
          SHA1:BEE0E16D3954DF33C697DEA469A130BD9875AB8B
          SHA-256:790E6B48B261D6DEF7D183CC8F38FB8D8A6E3EFB8844281EFABB2DFD621E53B5
          SHA-512:B6A93DFB4CBE2F35268AACA88FDCC4D19949A2E8DC9464D8341C38065C6FF48A3C49FE756FFCE777C8F806DE309C8AFC4CE4BC4ABD183C28808F995A0F89B091
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Kanton)]} {.. LoadTimeZoneFile Pacific/Kanton..}..set TZData(:Pacific/Enderbury) $TZData(:Pacific/Kanton)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.913439535905759
          Encrypted:false
          SSDEEP:
          MD5:6250F332356787613A2D1853EF6D1AC3
          SHA1:0464B9EE8B691990022295D2DEFE1AAE4B247E63
          SHA-256:336058DCA4802C79ED43F6177ADB73085D4FA0754B94051CAE2A19346B0C4904
          SHA-512:B8FAB5E128D2EF3CB7050DA717D80247045BE09F7F6542AA154CB85F4A56884F195EE2776421890A3F86D133106DCA4672D7D9329E0DE6F4A7CF8F4030822988
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Fakaofo) {.. {-9223372036854775808 -41096 0 LMT}.. {-2177411704 -39600 0 -11}.. {1325242800 46800 0 +13}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):986
          Entropy (8bit):3.950865906618592
          Encrypted:false
          SSDEEP:
          MD5:E329ACBF859B35950B27F434D725B3F8
          SHA1:9B46C4318CA0F03E016F8FF68FEE50EA93B22360
          SHA-256:0FF7AF55C92806751473CBF7A55E860850719BA7255CD65FD630B99E05C7C177
          SHA-512:84A7491E2C8A6866B40A3673C084ABF3F1E344CB0290C607A0BB06FF19D43EF0B9648CDA6489D10C410D39C700D8C62A8BA11EEF07AD36F5A9AD85C596205939
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Fiji) {.. {-9223372036854775808 42944 0 LMT}.. {-1709985344 43200 0 +12}.. {909842400 46800 1 +12}.. {920124000 43200 0 +12}.. {941896800 46800 1 +12}.. {951573600 43200 0 +12}.. {1259416800 46800 1 +12}.. {1269698400 43200 0 +12}.. {1287842400 46800 1 +12}.. {1299333600 43200 0 +12}.. {1319292000 46800 1 +12}.. {1327154400 43200 0 +12}.. {1350741600 46800 1 +12}.. {1358604000 43200 0 +12}.. {1382796000 46800 1 +12}.. {1390050000 43200 0 +12}.. {1414850400 46800 1 +12}.. {1421503200 43200 0 +12}.. {1446300000 46800 1 +12}.. {1452952800 43200 0 +12}.. {1478354400 46800 1 +12}.. {1484402400 43200 0 +12}.. {1509804000 46800 1 +12}.. {1515852000 43200 0 +12}.. {1541253600 46800 1 +12}.. {1547301600 43200 0 +12}.. {1573308000 46800 1 +12}.. {1578751200 43200 0 +12}.. {1608386400 46800 1 +12}.. {1610805600 43200 0 +12}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):187
          Entropy (8bit):4.770127787944403
          Encrypted:false
          SSDEEP:
          MD5:BBB00369FA8DCC23A7824EDB964BF48D
          SHA1:A97E42B3CC45860CC0DFC62F468B24A628B43973
          SHA-256:AFFB0A5D9CBD5949F2FC5047820FA2A2798F7C303F7BC972EC49CCF27837B00E
          SHA-512:2D4C8616308522C987437C39C74E250973C2AC7AA1499C60321F42E84CE52C28D1F6AE81E6390B116C92C7B208EA0F211EB3C5A86E6E4CEE0620014DE5359F4F
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Funafuti) $TZData(:Pacific/Tarawa)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):247
          Entropy (8bit):4.687336389955113
          Encrypted:false
          SSDEEP:
          MD5:0557D164DCD8DF5D99F7AF5A2AB1AD4F
          SHA1:68AFD04303E5F541480425405D82E1827F78A8DF
          SHA-256:192545659F971084ADC8489A2B96A6439FF391599DC962AA13375ACCFB3C09D9
          SHA-512:1DA004E51F8E7A712EDE920CBB62E81F9F55450FB52B62F78F1CD4F8F4E342B4DAB2C28AA5161E8B24942A7A5BD55F978AFDA1C5E1949241E71D738079DEF9B8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Galapagos) {.. {-9223372036854775808 -21504 0 LMT}.. {-1230746496 -18000 0 -05}.. {504939600 -21600 0 -06}.. {722930400 -18000 1 -06}.. {728888400 -21600 0 -06}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):155
          Entropy (8bit):4.976931060677737
          Encrypted:false
          SSDEEP:
          MD5:45330CE0FA604304C6ACF8EF8CAF51EC
          SHA1:20EEF9646996C2EC9B2641EBCCBE4766BF38B17B
          SHA-256:190E02A0C00D165FA45C73AEF9C0D6C82B1720E7406E5610DD860AED10A021A5
          SHA-512:51C7931B503405DA0B4078F6BE411895DD00E86AC7C5BE475030664D5302AD614293541DEE7FFC3D86A9DDB1BDA32BCAA746CF1D207DB063FBA2F9E9BE12836C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Gambier) {.. {-9223372036854775808 -32388 0 LMT}.. {-1806678012 -32400 0 -09}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):157
          Entropy (8bit):4.9796189407775255
          Encrypted:false
          SSDEEP:
          MD5:DF09960360D8CEDCA2A4DC19A177C4A6
          SHA1:9F73F271B8C85B25FE6392B8BF7465C92EFFE621
          SHA-256:161762334DFF48B1D58824911E1FF4171386EA18234DD3DD5B0798515593086A
          SHA-512:1BE9E0F90DA529C99E317F399BFDB913A076651CF8801A1849247B26A350A76D8B5807AB139F3DBB97790DDFC332BDBEB57B364BF67FA2BB440AFEDC4130A648
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Guadalcanal) {.. {-9223372036854775808 38388 0 LMT}.. {-1806748788 39600 0 +11}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):733
          Entropy (8bit):4.244282318063802
          Encrypted:false
          SSDEEP:
          MD5:BA319E451BE323C852A8ABFC299DDA28
          SHA1:FC9314C162FF1FE1ED5E2C5DF962A55D4D6D8115
          SHA-256:42CB69ABC83415F63CA7D2A3E5314A41817AEE3206ECCC7172C50A74B1597DB0
          SHA-512:3BF733B9ED2A57B01BE173A8421B2D5A45888A230461EA0BD8C5B4AC7DC010BB527346731196141C70AFECDF88DD47AFE48636243DFC395D88E58231BEDF7D2A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Guam) {.. {-9223372036854775808 -51660 0 LMT}.. {-3944626740 34740 0 LMT}.. {-2177487540 36000 0 GST}.. {-885549600 32400 0 +09}.. {-802256400 36000 0 GST}.. {-331891200 39600 1 GDT}.. {-281610000 36000 0 GST}.. {-73728000 39600 1 GDT}.. {-29415540 36000 0 GST}.. {-16704000 39600 1 GDT}.. {-10659600 36000 0 GST}.. {9907200 39600 1 GDT}.. {21394800 36000 0 GST}.. {41356800 39600 1 GDT}.. {52844400 36000 0 GST}.. {124819200 39600 1 GDT}.. {130863600 36000 0 GST}.. {201888000 39600 1 GDT}.. {209487660 36000 0 GST}.. {230659200 39600 1 GDT}.. {241542000 36000 0 GST}.. {977493600 36000 0 ChST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):344
          Entropy (8bit):4.640604617840767
          Encrypted:false
          SSDEEP:
          MD5:F3F0E64655FAA79E40860765EEBB5B77
          SHA1:7F6C2FC100AEABC26B7205AB53C1E016B12E4D60
          SHA-256:69319015799D32D3CF7C0A3E9991B4B1F3E0C5D1B4FBF400517350CCA9D2C3B7
          SHA-512:7C9238BCCB13B90D4DC9B5E776C421A42C25D21B4E026406F57FA1E70983E8F6BF1CE927AB9D0D6261C5C1802A8B810399F506915262F82F487417CFD704B2F1
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Honolulu) {.. {-9223372036854775808 -37886 0 LMT}.. {-2334101314 -37800 0 HST}.. {-1157283000 -34200 1 HDT}.. {-1155436200 -34200 0 HST}.. {-880201800 -34200 1 HWT}.. {-769395600 -34200 1 HPT}.. {-765376200 -37800 0 HST}.. {-712150200 -36000 0 HST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):193
          Entropy (8bit):4.844454917943834
          Encrypted:false
          SSDEEP:
          MD5:4244078A03C2493009EF2F6BDA2F326F
          SHA1:AC2FF3E91A8831A479B33DF32A0118BC2EB255D0
          SHA-256:6E52B361AC8A6A578C709F6D58AA7535F06C0CB1707081C2D5A63FA8545D955C
          SHA-512:398B32E0FAF80E40DF3ACD203DF380D61DC39322F0BA0388A18281BC26973945F45683A104B9A785BB9DF5E514322F6994F934289E4B56B7982F94D4528D4272
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:Pacific/Johnston) $TZData(:Pacific/Honolulu)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):208
          Entropy (8bit):4.669308556946547
          Encrypted:false
          SSDEEP:
          MD5:544A0A83241333805192A6F03888E359
          SHA1:99D2BE79D57B44BD538386F9E7551C9E1874D7E3
          SHA-256:0B1345555EC2B4738CC4DEBFE496C287966F238386263032FF1E27912CCBFBA6
          SHA-512:61C91265632D01FBB7F4C739368756C428258FA6C141E49E88B6C78ABEA6150A74B8DFCF14C5AADDA03C1EA6F04D122734654495C26B8614561786B1C5C7EF10
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kanton) {.. {-9223372036854775808 0 0 -00}.. {-1020470400 -43200 0 -12}.. {307627200 -39600 0 -11}.. {788871600 46800 0 +13}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):219
          Entropy (8bit):4.739672105601744
          Encrypted:false
          SSDEEP:
          MD5:1B695BBB9C50F6AFC05F67DE30374160
          SHA1:08AD8BBB6C99EB36FC3E462DB41C6896F52F150C
          SHA-256:4F7235B956A5A01676BE05275E086D5157EBC24FD91022E87817020669F915F7
          SHA-512:DC35CB1C2E5E035A82F91D1B1F4B48D7B112D9B7A1A7DB9C4A4C42C4D58002E1ECD9D24B2EA5B624DBB526ADDF9A8AB37D4315843207C34C16B2EFE33A254752
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kiritimati) {.. {-9223372036854775808 -37760 0 LMT}.. {-2177415040 -38400 0 -1040}.. {307622400 -36000 0 -10}.. {788868000 50400 0 +14}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):394
          Entropy (8bit):4.441317927120857
          Encrypted:false
          SSDEEP:
          MD5:B489D7BDE8EB805B2A24726A6FB0C441
          SHA1:7997A33AA56857EC52B1198DBEF4CE1DB50D69FD
          SHA-256:B528E5E712E5F878603183E7CCFF55E5DB97CB47D7628BCB635342796317B899
          SHA-512:4898AC2747FB8620BE29933CC7AA344AF1A3B7777D1AFF08BB4C6CE6E7AF205581937CCB488F3CB39CC8CA7FB42EDC8E1CAD8BADC9FCA40E3CAD23271CD66FCB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kosrae) {.. {-9223372036854775808 -47284 0 LMT}.. {-3944631116 39116 0 LMT}.. {-2177491916 39600 0 +11}.. {-1743678000 32400 0 +09}.. {-1606813200 39600 0 +11}.. {-1041418800 36000 0 +10}.. {-907408800 32400 0 +09}.. {-770634000 39600 0 +11}.. {-7988400 43200 0 +12}.. {915105600 39600 0 +11}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):304
          Entropy (8bit):4.5947337310364835
          Encrypted:false
          SSDEEP:
          MD5:7D1FC9913941693ACBD6A3CCB2F34555
          SHA1:D07C8AAED1DF9614BCA6EEF0F72FB98BE46CF5EF
          SHA-256:38133BE70100D7DC244A680827879E6B240646C7C0B68F58652051E681A71985
          SHA-512:419F0A1D1D71C8F84765C7B54271D7EFD6A81F428751523A214ABB24A8770DD5A7666F634A20AF97D5AAB8F21C0DEF23DCDE068CF4C1CCC7639ABC43864A9DBC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kwajalein) {.. {-9223372036854775808 40160 0 LMT}.. {-2177492960 39600 0 +11}.. {-1041418800 36000 0 +10}.. {-907408800 32400 0 +09}.. {-817462800 39600 0 +11}.. {-7988400 -43200 0 -12}.. {745934400 43200 0 +12}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.7986219497241995
          Encrypted:false
          SSDEEP:
          MD5:EB409C340A475B60993965A0E2892B6E
          SHA1:819881A078F34EF8FC55D71D829B82C56E6723D7
          SHA-256:935BC00C13863715D09463E54DC2A6FF0F1A7EEA8D5895C87836AA59716CBD57
          SHA-512:A28AF85022F8B3C2EE5F93BF6FDC0C349B73F25D88BA151ACE424EED1A95FA29608A6B1AD3D5FD952B2FB7F48DF6FDF8E6504F2B53E6782E4FF73335AF9A15C0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Majuro) $TZData(:Pacific/Tarawa)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):159
          Entropy (8bit):4.976348164850869
          Encrypted:false
          SSDEEP:
          MD5:80CB45F42BAB1AA72CD7C7BC394DF3F8
          SHA1:8B5ED2BCCA1AEB41F22AFD14F46533959828B2BE
          SHA-256:AE0B5055C6E57516F23749B13681205EAD376E682959716A457B1377AF8160BA
          SHA-512:71562E340B7A96B91D04FCBCAF71B66EA725CA1BD1094343C4442F8F9A8C67A3BE378034849197407D21C3EE74E2C753B1FD3BAFF2378714B993AD9336236A0E
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Marquesas) {.. {-9223372036854775808 -33480 0 LMT}.. {-1806676920 -34200 0 -0930}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):194
          Entropy (8bit):4.81307101485774
          Encrypted:false
          SSDEEP:
          MD5:13CE48F8FF74BFCEFCB8D217D6357E38
          SHA1:296D31E3F868934C6EB34BF1BF4C23F3E1839294
          SHA-256:F62C6A2DEC1E9EC78115D5F14E5B9DB7C86F788662D2E68F7E6714F4A05DC974
          SHA-512:778813FC08EF803743F392000BECE73C1C079883DAFC26FAC0AF8FA3FA4AE1D94BA8F3CAA5E82DD4DB1A5F12AD49E123901908F5483E0E325952622AB4C4A26A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:Pacific/Midway) $TZData(:Pacific/Pago_Pago)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):244
          Entropy (8bit):4.702705620563736
          Encrypted:false
          SSDEEP:
          MD5:30A8285FCCE2E98889E53DF60B906C3D
          SHA1:C7789CB11A2C8FE3861FF3C0A7A41F6CAFD87631
          SHA-256:22C367F3219B5FC736260D9DBFEF5FCB767F1A6BDA991C9352F790A3D1FFE884
          SHA-512:02DA82680588839B06F820979AECC78B7FBEAB9D6D49176B513B80F1C8BA2D55FB3674B19EFDD574EE6FC01539EF7C3081A4B34D14A54DACF367D816B62E5843
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Nauru) {.. {-9223372036854775808 40060 0 LMT}.. {-1545131260 41400 0 +1130}.. {-862918200 32400 0 +09}.. {-767350800 41400 0 +1130}.. {287418600 43200 0 +12}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.846897598147338
          Encrypted:false
          SSDEEP:
          MD5:6E8EC957423917AE7A7EF503661C1A77
          SHA1:B4FA3C3E3F96C28B7DB87BFD441D2EE99CC81B6F
          SHA-256:869CCA656BE88E4E7481C75737C3656BAB6924AD1751505815AC719C59269842
          SHA-512:9047ABE673259699C7A548BC7B5636DD646DD382C751B796522F65404162AB1B0BB022FD274653921E5B23C847EE248AEF6749E15ED2CFC1DCE35BBA294D8251
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Niue) {.. {-9223372036854775808 -40780 0 LMT}.. {-543069620 -40800 0 -1120}.. {-173623200 -39600 0 -11}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5139
          Entropy (8bit):3.65794255179185
          Encrypted:false
          SSDEEP:
          MD5:E19700A894AA64715D14F501D8D2FA98
          SHA1:57CFC96E2EBB985720DB290F59181860AF2AC1AA
          SHA-256:5D16C3EF1DB996C1B8E33AD884C33946F77DA872F35F41EC3BD5B288F43CC9AF
          SHA-512:E11EAF2A7B217CDBEECB57635184F04171F0DB088FCC4702AA8D40A3A5453904592F5869849913E2EB02DC5941C84203A76D270E8930B0B691A3B9C39B78BF30
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Norfolk) {.. {-9223372036854775808 40312 0 LMT}.. {-2177493112 40320 0 +1112}.. {-599656320 41400 0 +1130}.. {152029800 45000 1 +1230}.. {162916200 41400 0 +1130}.. {1443882600 39600 0 +11}.. {1561899600 39600 0 +12}.. {1570287600 43200 1 +12}.. {1586012400 39600 0 +12}.. {1601737200 43200 1 +12}.. {1617462000 39600 0 +12}.. {1633186800 43200 1 +12}.. {1648911600 39600 0 +12}.. {1664636400 43200 1 +12}.. {1680361200 39600 0 +12}.. {1696086000 43200 1 +12}.. {1712415600 39600 0 +12}.. {1728140400 43200 1 +12}.. {1743865200 39600 0 +12}.. {1759590000 43200 1 +12}.. {1775314800 39600 0 +12}.. {1791039600 43200 1 +12}.. {1806764400 39600 0 +12}.. {1822489200 43200 1 +12}.. {1838214000 39600 0 +12}.. {1853938800 43200 1 +12}.. {1869663600 39600 0 +12}.. {1885993200 43200 1 +12}.. {1901718000 39600 0 +12}.. {1917442800 43200 1 +12}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):326
          Entropy (8bit):4.531117764974758
          Encrypted:false
          SSDEEP:
          MD5:2F1E92A11DF44C72DC305C13111DEA35
          SHA1:847F551C3D6C75CD2D0D6D87FCF3294CA8DD90B2
          SHA-256:238683C027D2319C33D975A837E9FC9D24DD53B1A67108EDBF7ABDF0DB050881
          SHA-512:E35D8C71AFDBB9A7507E873925001AEDE3734B1D235F509D19952E85279CBCC233A73412EA1F79CB534A45D36FEAA8AFDA98D9964DC93C7892B318F4AFC9A076
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Noumea) {.. {-9223372036854775808 39948 0 LMT}.. {-1829387148 39600 0 +11}.. {250002000 43200 1 +11}.. {257342400 39600 0 +11}.. {281451600 43200 1 +11}.. {288878400 39600 0 +11}.. {849366000 43200 1 +11}.. {857228400 39600 0 +11}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.985607855830399
          Encrypted:false
          SSDEEP:
          MD5:E86D90DAA694B0EAC42F8C01346BC95B
          SHA1:CD29DEFC291C939296E86DC7EF5D0654D85285E8
          SHA-256:CCA96640AB3BC707224FA86D9AF66F9D53A204A97B370B2785BA8208688BF8B6
          SHA-512:937BA420061E3781F831779B458E914A0FC465C4B41796F8B7CB1E548822F5777A6450FC6002AB13EBC5C9F54E374D3ED731D05B2B302B95359BE34094E5062B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Pago_Pago) {.. {-9223372036854775808 45432 0 LMT}.. {-2445424632 -40968 0 LMT}.. {-1861879032 -39600 0 SST}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.919381181565273
          Encrypted:false
          SSDEEP:
          MD5:2E6C7EC61C7E29A147475C223B163F6B
          SHA1:3A98D3441335224E7EBC0648990BCA1DE3BDF5C6
          SHA-256:97DE6C2C717BFEAD00F83B5D39D654C32CEE580226F5F084484EBAD57BBCE7FF
          SHA-512:5868C43966DDEBA8EC4BBBB29CDFDDFF0C7B01FD4D579FF655F3363029059F969B39C9221190672B6A2F7938583594AA0B103FC2A7ED573E2BC1C3A1623DE8DD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Palau) {.. {-9223372036854775808 -54124 0 LMT}.. {-3944624276 32276 0 LMT}.. {-2177485076 32400 0 +09}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.809907977056877
          Encrypted:false
          SSDEEP:
          MD5:3F4987676F9C461895EDF9985AD22E06
          SHA1:A96E470209010B837EF5BB3AC93BAE74BF2CCF64
          SHA-256:5D363729A986E24C79F4B817CC88D2B22ACCCE3ADD20138D51C4422C4297AD6F
          SHA-512:988FB98EFD3F57F5D66A932CC6B9D0387E9B0951FC590E08DAF19ACF5E4F39BC1B25265F16E14930BCF394902F5F0EF507E0E91C98902DFB10FA16D716091AB0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Pitcairn) {.. {-9223372036854775808 -31220 0 LMT}.. {-2177421580 -30600 0 -0830}.. {893665800 -28800 0 -08}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):201
          Entropy (8bit):4.7682565894416005
          Encrypted:false
          SSDEEP:
          MD5:1B418E3A4239AAFE1E15B57FFF913FA1
          SHA1:0E278FCC058DE1B3F4715771819F14568A6C10BB
          SHA-256:F744CD8337C5C72023D61F348DD03F48824F817D62F54ACC6A23DDD8B0F9EDC4
          SHA-512:8E3E10B41CF64A07411B272C0BCA6DC7AA9FFBF625B31075651603B7D0A52A719F7174A67593BFDE45725C243D347D01560B2BC7813C2ABD2F4BF4B1BAD57E56
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guadalcanal)]} {.. LoadTimeZoneFile Pacific/Guadalcanal..}..set TZData(:Pacific/Pohnpei) $TZData(:Pacific/Guadalcanal)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):200
          Entropy (8bit):4.742862539020017
          Encrypted:false
          SSDEEP:
          MD5:514C399D990C87271812440A4B19FB21
          SHA1:E1512482D10C8984DCD69C883F07C412E144081A
          SHA-256:5BB11553F711BD591617F657A9D1811CC3E3FB46374F6867316A7C8F6B3765D9
          SHA-512:DB227134822EA73407B6C0259FF7413D4961B558F3018BFF51E4E426DDB2DF581DCF7A6DE9E4890CE35F785BC3D07CC880DA883C93D73FFB249F403701BD8023
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guadalcanal)]} {.. LoadTimeZoneFile Pacific/Guadalcanal..}..set TZData(:Pacific/Ponape) $TZData(:Pacific/Guadalcanal)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):190
          Entropy (8bit):4.945354510868153
          Encrypted:false
          SSDEEP:
          MD5:2CFB7C2A3D26D7AF0F6AE32ADD81C364
          SHA1:80C96E50D23A9A9531E4EE33744CF445C054B901
          SHA-256:124C137B091D9D54D5E0579131485428FAAE040ACC978D20D6A8C8E4DE9889AA
          SHA-512:A215FF5A69BD3E786BD3F8C952C8593396402EFA85005F5342093028617A6862EAE8BFD7B6D5737F90D90897AB62CF785544A4157A222AE4D0F70797FFBEC2CB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Port_Moresby) {.. {-9223372036854775808 35320 0 LMT}.. {-2840176120 35312 0 PMMT}.. {-2366790512 36000 0 +10}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):969
          Entropy (8bit):3.943959457262612
          Encrypted:false
          SSDEEP:
          MD5:64AD3A103F4D145C48484BF8FACF41C2
          SHA1:40C00CFA56C87E506C254A93A164D7227DFF3BD5
          SHA-256:5AB006A686E564E30C94884FF8A9D728AEC74681DA8772E9722B6FE203630B5D
          SHA-512:D1088C3B673B5456A8706B69BE4D7AB18615EE53A82BF4ABE76E86700837E6BAD0BD79C13EDA9B04776B08A95B835BA755AA565F86E45BFE507E8783896C1EE2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Rarotonga) {.. {-9223372036854775808 48056 0 LMT}.. {-2209555256 -38344 0 LMT}.. {-543072056 -37800 0 -1030}.. {279714600 -34200 0 -10}.. {289387800 -36000 0 -10}.. {309952800 -34200 1 -10}.. {320837400 -36000 0 -10}.. {341402400 -34200 1 -10}.. {352287000 -36000 0 -10}.. {372852000 -34200 1 -10}.. {384341400 -36000 0 -10}.. {404906400 -34200 1 -10}.. {415791000 -36000 0 -10}.. {436356000 -34200 1 -10}.. {447240600 -36000 0 -10}.. {467805600 -34200 1 -10}.. {478690200 -36000 0 -10}.. {499255200 -34200 1 -10}.. {510139800 -36000 0 -10}.. {530704800 -34200 1 -10}.. {541589400 -36000 0 -10}.. {562154400 -34200 1 -10}.. {573643800 -36000 0 -10}.. {594208800 -34200 1 -10}.. {605093400 -36000 0 -10}.. {625658400 -34200 1 -10}.. {636543000 -36000 0 -10}.. {657108000 -34200 1 -10}.. {667992600 -36000 0 -10}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):179
          Entropy (8bit):4.854594370903023
          Encrypted:false
          SSDEEP:
          MD5:EFC985F07B24BEDA22993C9D0EA7E022
          SHA1:6D05D12925621F1D05999A5DCC81B8C6F4D18945
          SHA-256:4F6A1C20A11E186012466091CD4B3C09D89D35E7560F93874DEC2D7F99365589
          SHA-512:5FB4D8784D2EB8AEF660D6CBC7C403561EE5874BEC0439762F3688C64830B52B1F557B467CA65B64B1210E82F385E134BF676F3CA443FB480702A2C90B3C3757
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guam)]} {.. LoadTimeZoneFile Pacific/Guam..}..set TZData(:Pacific/Saipan) $TZData(:Pacific/Guam)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):193
          Entropy (8bit):4.78073436515702
          Encrypted:false
          SSDEEP:
          MD5:8E335F5D0A2082BB673E7FEB56167A89
          SHA1:EF37235922D4477AC9B3D9576888CDE41E700741
          SHA-256:98D06302EFC18FAD7751F7E5A059FE4ABAFBC361FDC365FE1EB576209D92C658
          SHA-512:2572D99EE8BAF264B8A2EF3D7647D33A387EE83E036F9E7BDB21F64C2FCB43317AF9C899C8CDD822A2A5A207EF17504E71B217370473ED95AE925BBA2CFA90F9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:Pacific/Samoa) $TZData(:Pacific/Pago_Pago)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):154
          Entropy (8bit):4.946903999617555
          Encrypted:false
          SSDEEP:
          MD5:341B0F535043051A91A21297BFA39DC0
          SHA1:6AD9177FC237503E6D36DE5408790A68D5D36E2C
          SHA-256:440A87DDB4F304DCBEAED1B0DE8F6058840E597918B688E0782F584DA03B1BBC
          SHA-512:D97D399A0F1B4347F8AE5F15E43A8787697339AB0EFB4E1106C790528FFC529ADC5B44B231D95449D39DB464D84A5DDF7B61E7D190E3E2B0091D1EC204B530A2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tahiti) {.. {-9223372036854775808 -35896 0 LMT}.. {-1806674504 -36000 0 -10}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):152
          Entropy (8bit):4.969953728206455
          Encrypted:false
          SSDEEP:
          MD5:AA67FBBB6A02F5B30486C54E3A5C11D7
          SHA1:C64FD3654A47A0ECDD681B8A4D9B621AC6D97DBE
          SHA-256:91AA5DA8D5D1E72B1F561D0AEAB4B07E02EDD4EB95AE8C9F1C503C820460599F
          SHA-512:FC170904098011C091622A263CA554CEE952D64888D3573EB324E0A262E1A0C0885C059429F0FFF9219FEB8F1B6B97EC34661DD8DD547124D0C6C0A1C8EE24B7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tarawa) {.. {-9223372036854775808 41524 0 LMT}.. {-2177494324 43200 0 +12}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):451
          Entropy (8bit):4.343299747430587
          Encrypted:false
          SSDEEP:
          MD5:87CFDA2399A8126117E5BFC018B06518
          SHA1:6291611BCFB34293F9C20BA77170A13C1502C2ED
          SHA-256:ECC9D2E7AD7B5E5D6599CF442941595C99C4D69E802A4DDB4DA321898CDDE91D
          SHA-512:846FE07FEB82EC5F87FAE137D23074934246DBB7C7EE30F44F6C5373183B5FD2211B58E5CF1AB9A47938D282CA322FBDE80B58054FE6517CDC549992439F19A8
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tongatapu) {.. {-9223372036854775808 44352 0 LMT}.. {-767189952 44400 0 +1220}.. {-284041200 46800 0 +13}.. {915102000 46800 0 +13}.. {939214800 50400 1 +13}.. {953384400 46800 0 +13}.. {973342800 50400 1 +13}.. {980596800 46800 0 +13}.. {1004792400 50400 1 +13}.. {1012046400 46800 0 +13}.. {1478350800 50400 1 +13}.. {1484398800 46800 0 +13}..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):201
          Entropy (8bit):4.903352083734246
          Encrypted:false
          SSDEEP:
          MD5:443F5FFA58C5DB1F02695C5B76DF4F5E
          SHA1:115AFE9C3EB36F836E2DF95AF42C43EA5C21C1E6
          SHA-256:323A858946A2E8EC67C28176977D646C0A0F6DC8B48F9C4A3F8E7112C9B1B71D
          SHA-512:33717F3423CE06D827445FEA85BE8A989712CF8C06C54A17B9610A4DAD50BF64CAE80DE15AB12AB0610CD6B5582A897DD9C543098108543FA3E6273AAD9467DE
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Truk) $TZData(:Pacific/Port_Moresby)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):183
          Entropy (8bit):4.771810884789573
          Encrypted:false
          SSDEEP:
          MD5:992D44D728747D79E1F7EF47E3CB2EF2
          SHA1:8F05E8DA2A2A45F04B9B89BB34F0B7833B56A261
          SHA-256:B6041BC18B595E38953632ACAD1D25F7394BF7C759A72FCCD81AF637F8016373
          SHA-512:C59D360941240C8B11D892A930B6CFE141B1A55007483683AF400B1A0C98EF0BBBE7EF595EF6BA73A6EECB8E3D0658A681CF3203E5E32DE80DD61EDB9C6CBDB0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Wake) $TZData(:Pacific/Tarawa)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.752883303864462
          Encrypted:false
          SSDEEP:
          MD5:862ADA129322E53235ED5099A72FE8EE
          SHA1:7DAB7BF451CF0FE483EA512C0C733B090FF22EFF
          SHA-256:9601B749413D591D820AFAD431B3C30E577ACAB000EA11EC03DEB36EF0738DC3
          SHA-512:D9C94BE2F08220E49A336A5760DBF43FCB889ADA95E29117AE5E237E33E9EE50BD32203D2743346A21354AF3F1ADDA43A2953FB55205B6FA998A6294CC57F063
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Wallis) $TZData(:Pacific/Tarawa)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):200
          Entropy (8bit):4.896778032757086
          Encrypted:false
          SSDEEP:
          MD5:343CCAC12AEB0DD78FC60405DF938729
          SHA1:B7B4DF0178DEEC2BA6F23AF5CD896CF16CEAF224
          SHA-256:16CF9FAB116E5E1732B4B601DA919798985A0C15803F0964844C7040894C5DBA
          SHA-512:041609C63E95322460A31AC83BCC4F8F90B8D44B2740A5CF7E37F66CCD9F928416D74D313370516D7B1780DF2C9C9A78B7069CE2DA6BFFE88C46FB47CE1A4CB2
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Yap) $TZData(:Pacific/Port_Moresby)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):174
          Entropy (8bit):4.940195299412468
          Encrypted:false
          SSDEEP:
          MD5:E6AA2F6A05B57AA9B4AEF8E98552EEB2
          SHA1:22470C204152702D8826CA52299E942F572C85ED
          SHA-256:C27E1179B55BF0C7DB6F1C334C0C20C4AFA4DBB84DB6F46244B118F7EAB9C76E
          SHA-512:B28A264907C32F848D356FB0F5776C2CE819DCB6BC08A5E2DCD4FA455EE1616966E816748079C7A55485BABFFB292D567E6F958168F945889E33A267B0E7EDA9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Warsaw)]} {.. LoadTimeZoneFile Europe/Warsaw..}..set TZData(:Poland) $TZData(:Europe/Warsaw)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):176
          Entropy (8bit):4.9353841548970205
          Encrypted:false
          SSDEEP:
          MD5:7D7BD6E40D3ADCA04754255D69B5CC9D
          SHA1:EE32167B450DE7B0F1A15199795AEF9524BE623B
          SHA-256:EFD666F3062D52C5D0B4F83B1A206E6840C1EAEC356CD77A0A71C7EDFA78C964
          SHA-512:6056AAF078316A89079D19555F0BAEFB4C1CDBAA5426A8BEE76E0BFA5C69A5DAAFD199DEF978ABD67287AE1B80F754B7845EAFD5CC0995FE10E44D1F34D5435C
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Lisbon)]} {.. LoadTimeZoneFile Europe/Lisbon..}..set TZData(:Portugal) $TZData(:Europe/Lisbon)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):165
          Entropy (8bit):4.795776391333205
          Encrypted:false
          SSDEEP:
          MD5:C5AE3A1DAD32C870651C74E367F604CF
          SHA1:9FF81383C43D98441841E182BC783381EF565204
          SHA-256:9AEC39777013B23D63D0509EBB2F01D57A2C1592264DBB19CE2C61C7D7DDD8DE
          SHA-512:3A7217ED885011972262B71DB7F5D7E4C9C6E82B4BEEF0718BCB9452E49FDBDD5ED78564156577AB09150140B862E1944B4B739BCE0C50E63667050C35329503
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Taipei)]} {.. LoadTimeZoneFile Asia/Taipei..}..set TZData(:ROC) $TZData(:Asia/Taipei)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):162
          Entropy (8bit):4.900717350092823
          Encrypted:false
          SSDEEP:
          MD5:59E4C80F97FAFC92987B08BFA03B5EE5
          SHA1:4F86FCE17A51C3789DEB887BE01A1A0E6EA3D2DE
          SHA-256:63153B40225270ADB7CD248788CA9F18C6DEBAF222B3165BBAB633337592DF44
          SHA-512:9FCC0F747096775D0FB8DD252A73E6F47C16BF2D7DB0C3FBDFD206EE57393276FB40F65C1441296AE2AC115CFEE11098474DF3FEF8EE1FABE139427A8991F052
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Seoul)]} {.. LoadTimeZoneFile Asia/Seoul..}..set TZData(:ROK) $TZData(:Asia/Seoul)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.85623787837429
          Encrypted:false
          SSDEEP:
          MD5:5EABBAAF3B29B5DFF9E54136F7ABC654
          SHA1:44615F03264012D97512F9AB386413DD72BE1090
          SHA-256:B9443FB17F0128DDB9F2DF657DC5D2DF176F64C61B0D02B272E5DFB108537678
          SHA-512:B930D637A1E69E0847ADDEAB013B2C25BC27EBB9CDF20B9CDDFDAC111E9F26BB5EBC83194E845ACC3E1B9A08C386C94FCC4FDE32292EB558E3F7463832BB38B9
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Singapore)]} {.. LoadTimeZoneFile Asia/Singapore..}..set TZData(:Singapore) $TZData(:Asia/Singapore)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):201
          Entropy (8bit):4.996391010176349
          Encrypted:false
          SSDEEP:
          MD5:1AC81E2C60D528A6C5BF2E6867146813
          SHA1:73D2D24FE6D56CA34ABF11B9A95DC22F809C5158
          SHA-256:978C4E5256057CE7374AD7929605090FC749B55558495BD0112FB0BB743FA9C2
          SHA-512:DB2673FB54C1308BBEB298A186F9130FB9090CE33B958C82D62B9BD88EE39BAB9A1BE40645547BA4167FD475892A323CF8EBA16C97F6FDF5693F1BF7A313FE9A
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:SystemV/AST4) $TZData(:America/Puerto_Rico)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):192
          Entropy (8bit):4.9470542553730255
          Encrypted:false
          SSDEEP:
          MD5:2AB4B896957F26B114A990F69989F3FB
          SHA1:8048C99F5EE02C021F311709B30EB28D650D884D
          SHA-256:0114C111F5BCD838A28F2E16E01ECB79D8AFC8CBF639A672889ED0D692FC6CDC
          SHA-512:353744359CD94B1E8184A8B83F762459C69D3AEEA43DA638C1F4CC34E01E9D86C2EBCF7F7BFD059CB23B64051510D1C4556A49D180F8A92DE8449139194DCDC9
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Halifax)]} {.. LoadTimeZoneFile America/Halifax..}..set TZData(:SystemV/AST4ADT) $TZData(:America/Halifax)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.957831162100758
          Encrypted:false
          SSDEEP:
          MD5:3EC0B09EAB848821D48849673B24401C
          SHA1:41599CBA78E124A7DA9744D2B4EA8CDC10008E0B
          SHA-256:30428B85B37898AD98B65BE5B6A8BD599331D9A1B49605FC6521464228E32F8F
          SHA-512:9A3303B3338C01B281A40BB48B93C446ADB92BBDC45371667F09EDA92F9EE2AEC60CE8E98CE15C0112B823799C76AEF14895B15DC997DA506494D75BBE58D662
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Regina)]} {.. LoadTimeZoneFile America/Regina..}..set TZData(:SystemV/CST6) $TZData(:America/Regina)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):192
          Entropy (8bit):4.975428048518589
          Encrypted:false
          SSDEEP:
          MD5:D85CCC5EFAA1ED549D02F09A38A53C68
          SHA1:642ED571E4C6F60A953D42DA4F756F2262E4E709
          SHA-256:44BEF7D4660A9A873EB762E3FDC651D31D97893545DE643FA1B2D05991C090A1
          SHA-512:3CC6A14A17EA4833958A7D444073D6C2709FD61BF54387E5C362151E9143F795B2432B621080DD53E0FC9BDD7C58F406E046E3D0A2BBA4132D99E7C705E6D645
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Chicago)]} {.. LoadTimeZoneFile America/Chicago..}..set TZData(:SystemV/CST6CDT) $TZData(:America/Chicago)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):204
          Entropy (8bit):4.928128138328689
          Encrypted:false
          SSDEEP:
          MD5:506D15E2F37F501F5A592154142A5296
          SHA1:5ACA12E0BA0FFF9734ED978A9C60AAA9D1E05A59
          SHA-256:798F92E5DDA65818C887750016D19E6EE9445ADFE0FCB7ACB11281293A09C2C7
          SHA-512:2EE08D39461CAD3492BE88B421BA463B4CEB8497F036518794BCF605F477057FEA218A9DFBB6335A28A5120750EA06AED9D2EA84CD0007D34CDE562DCD79CC0C
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indianapolis)]} {.. LoadTimeZoneFile America/Indianapolis..}..set TZData(:SystemV/EST5) $TZData(:America/Indianapolis)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):195
          Entropy (8bit):5.113680059406992
          Encrypted:false
          SSDEEP:
          MD5:AAD8EF3067E97785D4052B80F5C4ACE1
          SHA1:3EF0A06FCC41119F4A60A32CED0E5A1E0E8B4300
          SHA-256:D159140114A13C69F073CFE9AD0B67D713E8811CBFF773A3D1681FC38EA0E699
          SHA-512:A8774ADF6818D85476A6C147A45E55B338F413CD9B61BF9FDB0CB7A335C0CE8F8C6D1970783FEFECC2CE18388DF91304CB295BD4DFD29FB538D74F6A414A441D
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/New_York)]} {.. LoadTimeZoneFile America/New_York..}..set TZData(:SystemV/EST5EDT) $TZData(:America/New_York)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):193
          Entropy (8bit):4.9733028894475195
          Encrypted:false
          SSDEEP:
          MD5:458061B3F3C8F06C61B5726393A26BA2
          SHA1:E894F5615654D1110C9964B8F6A54C048442D8EB
          SHA-256:BF62C8650BBA258000F62F16B0C7CBB66F4FD63F8CFDAF54273BB88A02A6C8D6
          SHA-512:6A161A7AE44CBF8CE4C704C94456A5B714AAF2A3FAF30731254C9FE056F9DDF207119D516CC6A4C44AE76EC078F5C59F5EC6DD6701FAA3A36F061AF3953B7C7D
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:SystemV/HST10) $TZData(:Pacific/Honolulu)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.999038624718282
          Encrypted:false
          SSDEEP:
          MD5:B06AB4998A57446FC4D5A5B986BCA0A9
          SHA1:5E4A28466383CBAB2067B9B6D22882CF6D83C3FB
          SHA-256:FEBE49FAE260E5595B6F1B21A0A3458D8A50ACA72F4551BF10C1EDB2758E0304
          SHA-512:9E44174C4E348E1B768039585BA6393FD001B606E111092EEC57C75210A1E87BF3C72728321945D584CA60D4C848D88EB8B2F82CB88F38F90224A43FDCFEA9AA
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:SystemV/MST7) $TZData(:America/Phoenix)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.956231227702093
          Encrypted:false
          SSDEEP:
          MD5:5D3C1ADB8AC4EAC9E9A31734CD6884BD
          SHA1:535B024EA088B9B192BE4206CBDD56BC5B163762
          SHA-256:64556A7B20E425C79375C2A7CCF72B2B5223A7DE4FF4C99A5C039DB3456C63F6
          SHA-512:FB799A42880613752AD6010D7B4E97ACCF7F6AE281D9A37057F6423AEF2607B608DB2AC52176F1653D8B2D086223C9658B101E73125F0FF7D6D9E8CD876EEC53
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:SystemV/MST7MDT) $TZData(:America/Denver)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):192
          Entropy (8bit):4.831981174214766
          Encrypted:false
          SSDEEP:
          MD5:B568B46A0207800D9C022BAB1E48709B
          SHA1:71CE3F0E75E440D5BBA219BCBB92AF9C1F5A7466
          SHA-256:0B8227AFC94082C985E8E125DF83E5EFADE7CD9CA399800D7B8E8B2BEAE22C7D
          SHA-512:5067AAD0CD02EBDECA6980F9C7CCC80D076C34D6463C5B6B19B678D76B5E69C1C3639D046F56FE9D6255CBEA49189EDD735F66AD9EE2CB0389BE020E7ED3AD50
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pitcairn)]} {.. LoadTimeZoneFile Pacific/Pitcairn..}..set TZData(:SystemV/PST8) $TZData(:Pacific/Pitcairn)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):204
          Entropy (8bit):5.003766957083974
          Encrypted:false
          SSDEEP:
          MD5:7E587175CA0F938C47FA920D787C57BD
          SHA1:C3F7D8576C0AC74D6B70F4363EE2C174FADC70B0
          SHA-256:D51D9549835E9C058F836C8952932CB53C10F7F194CD87452E9B13494D1C54C9
          SHA-512:4460686AAA470F07A6DB1F8957FA4DB600E116273497F46E8A2D3FDECF622122DF753556B78C39FA2ADFDB2AF3C3ABB3C330ADA79B35C6A3CD8C498A0319CEE6
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Los_Angeles)]} {.. LoadTimeZoneFile America/Los_Angeles..}..set TZData(:SystemV/PST8PDT) $TZData(:America/Los_Angeles)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.9524733332469095
          Encrypted:false
          SSDEEP:
          MD5:5970A466367825D72D9672293FCD4656
          SHA1:1A736D61A6797295EEC8C094AED432171E98578E
          SHA-256:55710EFDED5B5830B2F3A2A072037C5251E1766F318707ED7CD5EB03037FED43
          SHA-512:1F2A1B2A7D0A3E410652546C174D9EC18C91C9327F11C384A0AA1EB12D7EFE85C4D53CA3C2A6C347C0068A4CE92A3138EB17232B0DEC88D52465C5DEDEEE6827
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Gambier)]} {.. LoadTimeZoneFile Pacific/Gambier..}..set TZData(:SystemV/YST9) $TZData(:Pacific/Gambier)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):198
          Entropy (8bit):4.994125896811442
          Encrypted:false
          SSDEEP:
          MD5:560B18DFB138DAF821CFDAE017B94473
          SHA1:0BB0312C742CC0097DF033656AE3D10723035C30
          SHA-256:DA20018DE301F879E4F026405C69FA0370EB10184FE1C84A4F1504079D5DAFA1
          SHA-512:B1D4EAD5F549E319DAD55EE67DAFD732E755164748C08633AA8F07C280B2CF617380D6F886304142D0E4D50026E63678DACFBE2DC809F780BA4CFF35A90DE906
          Malicious:false
          Reputation:unknown
          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Anchorage)]} {.. LoadTimeZoneFile America/Anchorage..}..set TZData(:SystemV/YST9YDT) $TZData(:America/Anchorage)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):180
          Entropy (8bit):4.9295990493611495
          Encrypted:false
          SSDEEP:
          MD5:1FABF2DFD4BFD0184AE22ED76F7569E5
          SHA1:5859266B26357B4FCADD7EC65847667631E303EB
          SHA-256:8471A5575B9D9E47412D851A18A26C4405480540AABC8DAED5F81BE0C714C07C
          SHA-512:1DCBECEF6D1F923E6C9CEA70CB10F1FF4E453265966AA88FBC8739E93EF40F8A16AAD85AF4ECC5CC1E52F22F49E5D3F4EE01A97DE2302FC4FBC063FE814F3851
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Istanbul)]} {.. LoadTimeZoneFile Europe/Istanbul..}..set TZData(:Turkey) $TZData(:Europe/Istanbul)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):153
          Entropy (8bit):4.844017562912325
          Encrypted:false
          SSDEEP:
          MD5:DA060D2F397C978E0842631B4EC73376
          SHA1:649BC85430B04662BE079C0AAD43DF5D5D499D28
          SHA-256:356A9BB6F831971C295CF4DCE0F0CDC9EDF94FD686CA3D3195E5F031A0B67CBA
          SHA-512:3359BFC6F0837D2DA9D72DA8053773CE0C1A1B1A47C33163BF38965E2104F57BC147F9EEC228A3591B75BF1BA93285AB83E8427E8E2E697AB18501DC017B6E6A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:UCT) $TZData(:Etc/UTC)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):189
          Entropy (8bit):4.911775112130145
          Encrypted:false
          SSDEEP:
          MD5:4379C0BF618649AA07CC4BDAC75F62EF
          SHA1:7813B54BF2BD0C40A39CA9A29CC50C6D034880A3
          SHA-256:CED56F09D68BE00555219594C7B2F3E7EFE8323201FB3E2AA0E1FA9A6467D5AF
          SHA-512:AC822061F5C9743120A66E11C02B199253A40460A87F78DC154B0BDD91E410EDDA581E889F5D2A74670939034F39A7F6C7E814E038A1371DAB71EF79A8911AE7
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Anchorage)]} {.. LoadTimeZoneFile America/Anchorage..}..set TZData(:US/Alaska) $TZData(:America/Anchorage)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):176
          Entropy (8bit):4.8886795125313585
          Encrypted:false
          SSDEEP:
          MD5:AB14CF1840CBDA2B326660DBD51273B4
          SHA1:78144B3A2C75568307E4E86AE3B01EA7F541B011
          SHA-256:A4F1398CF84D0AE09BF19288770756622D1710CCBFBFE79E0D3239497731287D
          SHA-512:557A3ED9D1401E76291DC41524A1FD04AFF0829CEF66E103CEF9D10CD751F04FDEB6B7C0490302C71297F53AA8DC42930649AD274215D5DF068BCDE837E73756
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Adak)]} {.. LoadTimeZoneFile America/Adak..}..set TZData(:US/Aleutian) $TZData(:America/Adak)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.9334626069754455
          Encrypted:false
          SSDEEP:
          MD5:30ED80335BE37C7CBA672C33FDE23490
          SHA1:B627E86F023FE02A5590FE8D55FF41946BE6D24B
          SHA-256:9503403F231BA33415A5F2F0FDD3771CE7FF78534CE83C16A8DB5BC333B4AD8A
          SHA-512:C1352612EC0B4FF2F6F279CDB6008D7E9DA7F94F0009EFD959AD3092393150ECA83A09E72C724E1A4BFC3A057B9218D54A87FFA1102E2D9BF058B78AC0A0B1AB
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:US/Arizona) $TZData(:America/Phoenix)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):184
          Entropy (8bit):4.90255068822036
          Encrypted:false
          SSDEEP:
          MD5:7770A6B85B2FE73BCCE9D803E0200F23
          SHA1:784AD1082FF1569961C2AC44F6D6F7605FBBE766
          SHA-256:B6AC9FAE0AB69D58ECFD6B9A84F3C6D3E1A594E40CEEC94E2A0A7855781E173A
          SHA-512:EEE79D37D77E6B80B91E8F30CE48B107371F6A58F0C91785E3C74EF210AE1011D0EB913113F1873BE6099B0BE1260410F0C74650446CB377F8FDB5505A44F266
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Chicago)]} {.. LoadTimeZoneFile America/Chicago..}..set TZData(:US/Central) $TZData(:America/Chicago)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):228
          Entropy (8bit):4.7645631776966715
          Encrypted:false
          SSDEEP:
          MD5:96828B6BA17CA96723794F4B3744B494
          SHA1:C3A824A925AEFE2A13A0E65548078D9842C2C7D7
          SHA-256:5D86F8D36598516FB2342A18A87DB2701BABD265B0671CC9321C48DB22C7ECA5
          SHA-512:2A27A455787DEAC3EC78A2784FB989DAB178E9D6DD7721CD3F5D3337231A3C651994B964D6CE040B7858E0127D7F70C0C48CB0D553D5B725B649C828288224B5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Indianapolis)]} {.. LoadTimeZoneFile America/Indiana/Indianapolis..}..set TZData(:US/East-Indiana) $TZData(:America/Indiana/Indianapolis)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):187
          Entropy (8bit):5.0345860115708785
          Encrypted:false
          SSDEEP:
          MD5:375DB249106C5D351CA0E84848835EDB
          SHA1:ECC5C0C9DA68773B94C9013F4F1A8800D511CC4C
          SHA-256:2FFCAD8CBEF5ECDC74DB3EE773E4B18ABC8EFA9C09C4EA8F3A45A08BADAF91A9
          SHA-512:21550743BF4E1A79754F76AB201F0EB6BA6B265F43855901640054316A4A32A5D01D266B2441E4A6415720715A2ABD367D82E3D40949A7A66BE9F8366E47A8DD
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/New_York)]} {.. LoadTimeZoneFile America/New_York..}..set TZData(:US/Eastern) $TZData(:America/New_York)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):186
          Entropy (8bit):4.88075715646936
          Encrypted:false
          SSDEEP:
          MD5:C0475756CFEC302F737967468804846E
          SHA1:85C13CA0A908C69B8BBB6040FC502AFF96B8F8C7
          SHA-256:529BB43EFDA6C1584FEAEA789B590CEF1397E33457AB3845F3101B1FC126E0FB
          SHA-512:D3FF374443344E8438D50803872E8A8EA077B2299B38C1BD155386B4D2C6008BBD0C0B0B26DE9680812D4AFC9A187B644BDCCB04C23880337228BCEC06D5D61B
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:US/Hawaii) $TZData(:Pacific/Honolulu)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):206
          Entropy (8bit):4.87340978435866
          Encrypted:false
          SSDEEP:
          MD5:00AAFD60A0B1146274981FAB6336AFD9
          SHA1:20AD47ED52874202585C90FE362663F060E064D3
          SHA-256:5827B6A6D50CF0FB75D6BA6E36282591AD25E1F0BE636DCFC5D09BDA29A107FD
          SHA-512:61113AB72B7D671D7B429106709E73DB57D5B8A382680BA37A54126C7F54BC2D6B47A2584177CE6B434793546DA7EB9B8B7DF9163816DBFC67C83D9930D6A158
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Knox)]} {.. LoadTimeZoneFile America/Indiana/Knox..}..set TZData(:US/Indiana-Starke) $TZData(:America/Indiana/Knox)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):185
          Entropy (8bit):4.83459089067994
          Encrypted:false
          SSDEEP:
          MD5:D955A5A943B203DC4B87A91ED196B82A
          SHA1:C7ACC48AB2033C372C60C741F68B12FFAEA147DE
          SHA-256:B4E4269C4FEBFEFF26750B297A590226C0A6872519A6BFDE36F6DC3F6F756349
          SHA-512:445DC9A50487A4BA0A7F79078441696DCAA31F9988E5B515B5A827AC9275776B22DE303040900C1726EB99CABA8AD09E57AA674F798EA3FDEBC580E4B87D9439
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Detroit)]} {.. LoadTimeZoneFile America/Detroit..}..set TZData(:US/Michigan) $TZData(:America/Detroit)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):182
          Entropy (8bit):4.892777905787396
          Encrypted:false
          SSDEEP:
          MD5:E53EDD55E6448C624DD03A8A100EF5AF
          SHA1:1D266553CAFA23A3375CFAF7AFE6636553CC7B70
          SHA-256:3763BF520D3C97148C34DCFBDF70DEC2636D4E38241555900C058EFEE3BD1256
          SHA-512:B7FCF01DBB4231F30FEFA77C339B2CD7D984D6E6182F3BD15D6B64AC9525994E7CBF90C3F1F520FD22B54E19831B3CBAE1C22F04F60244C0C60A1809942422A4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:US/Mountain) $TZData(:America/Denver)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):196
          Entropy (8bit):4.932311644026309
          Encrypted:false
          SSDEEP:
          MD5:37AF94FAB52D80AF32C766644892E36D
          SHA1:03CE96A3B3EBFC16C9ED192DD2127FB265A7ED49
          SHA-256:54E5F126D4E7CC13555841A61FF66C0350621C089F475638A393930B3FB4918C
          SHA-512:405A7F414FA0864111E5E9F06FCA675BF4EF11FE0F82F5438416273BEF820A030A50E4D43E4E522ED79C08C0C243E9DD3692971DC912C9ADFB1BEABEB935CDDC
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Los_Angeles)]} {.. LoadTimeZoneFile America/Los_Angeles..}..set TZData(:US/Pacific) $TZData(:America/Los_Angeles)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):188
          Entropy (8bit):4.838968615416201
          Encrypted:false
          SSDEEP:
          MD5:509CF35F5F7C9567FD19CC5C137DC070
          SHA1:AA5F27D36BC617A6A4107E3CA0CB0C10A71A1D9E
          SHA-256:E51FC51C65FFEAB514D7636271157EE8941BDACF602CBC380F5D60B5FA674E87
          SHA-512:E23633A16F11015F3FE2F4E675B5A60B4FDC61F8CF152FDB9BA7ED4C213B8897117721A78C5470296DAFB0FD4F0DDC019DD0DB8C28C1F1B2BE0D3A289F53D5B3
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:US/Samoa) $TZData(:Pacific/Pago_Pago)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):153
          Entropy (8bit):4.844017562912325
          Encrypted:false
          SSDEEP:
          MD5:3402C8784654C24F7E956731866B833F
          SHA1:C34F3CCA074A50E6564B8C78683C8763B37A3002
          SHA-256:DEE28FF84E3FC495ED3547D5E5E9FAFDACC36A67329E747D434248ED45BF1755
          SHA-512:FBA2840B0FA0F084EE9840BCF56E497F8A7ABF509FA10FA66FB26BA3D80079C4F9A363577A453CD68557080EAF9DD7F1F7B5AF957B64BDA2A897B1E08C85DD19
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:UTC) $TZData(:Etc/UTC)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):159
          Entropy (8bit):4.879221007428352
          Encrypted:false
          SSDEEP:
          MD5:5F24A249884C241D1E03D758C2641675
          SHA1:63AAC15A68659006F8A14FEC3F2A66B55A8AC398
          SHA-256:B7B0B82F471D64704E1D6F84646E6B7B2BD9CAB793FAD00F9C9B0595143C0AB7
          SHA-512:A7AB5E26A2C23BA296942D7C524C6EE6708A9A38CDD88022EA92E2180BC3CCFE930758FC20A24A0D271AD70733EB924B0E530FBF83CC0FC49EAD411B28503CC0
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Universal) $TZData(:Etc/UTC)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):172
          Entropy (8bit):4.999171213761279
          Encrypted:false
          SSDEEP:
          MD5:5444E85070CA2E7A52D38D6D53216B88
          SHA1:0F9A4FB1156312EBD0B9C81DA2164E89D21878E1
          SHA-256:F7DA75B585F45AB501B2889E272FF47B1C4A1D668E40AED7463EB0E8054028C2
          SHA-512:BBC94F98C84641392D3A4B67C152E92EDB3011DA329319ADB2485DBEAFD44DED328D80FBCA89E58687E1F0EB6BED8580BBB0075CA42284B6206A8641D76F2DE5
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Moscow)]} {.. LoadTimeZoneFile Europe/Moscow..}..set TZData(:W-SU) $TZData(:Europe/Moscow)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):6945
          Entropy (8bit):3.7806395604065135
          Encrypted:false
          SSDEEP:
          MD5:1EC38B05B53ECF2DD3A90164C4693934
          SHA1:00900F0ADDB7526C63C67CA1662C038E95A79245
          SHA-256:7E6E2369C19DD19A41BE27BB8AD8DF5BE8B0096ED045C8B2C2D2F0916D494079
          SHA-512:47A8DAAB1B891FF09A94AF01B6673213392F70C6C1EE53D95A59D6E238FD06B0E80FA21C7279A9ADA891F5CA5B86E4D6B696EE8CFE14BFEF0ACCC9759AF1419A
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:WET) {.. {-9223372036854775808 0 0 WET}.. {228877200 3600 1 WEST}.. {243997200 0 0 WET}.. {260326800 3600 1 WEST}.. {276051600 0 0 WET}.. {291776400 3600 1 WEST}.. {307501200 0 0 WET}.. {323830800 3600 1 WEST}.. {338950800 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):154
          Entropy (8bit):4.8800842076244715
          Encrypted:false
          SSDEEP:
          MD5:DDB6F69CA4F0EF6A708481F53F95EAB9
          SHA1:A63E900A9257E9D73B4BB4BACBA8133C3D1DC41B
          SHA-256:A06E8CCCF97CC8FB545DFDB4C89B5E5C8EDF0360547BDC1823B4AC47B1556C31
          SHA-512:C8EA1039BE001F5EF52662B28DBF46D02E4848F08F05923850DEA1994732037B4C8D6030B742D97FA4276AF5FEE3F17C47C7DDA4F44DD23244F9976A076D5CC4
          Malicious:false
          Reputation:unknown
          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Zulu) $TZData(:Etc/UTC)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5030
          Entropy (8bit):4.838527643033185
          Encrypted:false
          SSDEEP:
          MD5:70450A0CF04EF273EFF2B070053FCFA6
          SHA1:47974D6C0FC986EE1273C4E13DDB9E1288CEF0FF
          SHA-256:678F891615E2209A8ECBA17857922A9723E78709ADB983032E89CA706000C44D
          SHA-512:AFD3E47324D1497CC46AC6141191FCEB843977D0B0285C807FF8985DCC56FDE10977F57D503D986CD2C1EDC6C62F01E405A0EB483340B247B129FC8D6D9FE689
          Malicious:false
          Reputation:unknown
          Preview:# word.tcl --..#..# This file defines various procedures for computing word boundaries in..# strings. This file is primarily needed so Tk text and entry widgets behave..# properly for different platforms...#..# Copyright (c) 1996 Sun Microsystems, Inc...# Copyright (c) 1998 Scritpics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# The following variables are used to determine which characters are..# interpreted as white space.....if {$::tcl_platform(platform) eq "windows"} {.. # Windows style - any but a unicode space char.. if {![info exists ::tcl_wordchars]} {...set ::tcl_wordchars {\S}.. }.. if {![info exists ::tcl_nonwordchars]} {...set ::tcl_nonwordchars {\s}.. }..} else {.. # Motif style - any unicode word char (number, letter, or underscore).. if {![info exists ::tcl_wordchars]} {...set ::tcl_wordchars {\w}.. }.. if {![info exists ::tcl_nonwordchar
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8806
          Entropy (8bit):4.863085192885279
          Encrypted:false
          SSDEEP:
          MD5:C5E9A2E32AE83A79DF422D1145B692DF
          SHA1:08350F930FB97A95970122920C91FB9CED8329E9
          SHA-256:8822365EE279BEBF7A36CFDEDBA1114762F894781F4635170CC5D85FF5B17923
          SHA-512:71420E15A3D63329560074F6FFAD42CB464401284BC29D0DC8E34D83F8F77079F26BB4C5703E656A48E6931C3DBF6B873756FB212D0860483E0301B29EDE1212
          Malicious:false
          Reputation:unknown
          Preview:# bgerror.tcl --..#..#.Implementation of the bgerror procedure. It posts a dialog box with..#.the error message and gives the user a chance to see a more detailed..#.stack trace, and possible do something more interesting with that..#.trace (like save it to a log). This is adapted from work done by..#.Donal K. Fellows...#..# Copyright (c) 1998-2000 by Ajuba Solutions...# Copyright (c) 2007 by ActiveState Software Inc...# Copyright (c) 2007 Daniel A. Steffen <das@users.sourceforge.net>..# Copyright (c) 2009 Pat Thoyts <patthoyts@users.sourceforge.net>....namespace eval ::tk::dialog::error {.. namespace import -force ::tk::msgcat::*.. namespace export bgerror.. option add *ErrorDialog.function.text [mc "Save To Log"] \...widgetDefault.. option add *ErrorDialog.function.command [namespace code SaveToLog].. option add *ErrorDialog*Label.font TkCaptionFont widgetDefault.. if {[tk windowingsystem] eq "aqua"} {...option add *ErrorDialog*background systemAlertBackgroundActi
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):21612
          Entropy (8bit):4.947590677310969
          Encrypted:false
          SSDEEP:
          MD5:AEB53F7F1506CDFDFE557F54A76060CE
          SHA1:EBB3666EE444B91A0D335DA19C8333F73B71933B
          SHA-256:1F5DD8D81B26F16E772E92FD2A22ACCB785004D0ED3447E54F87005D9C6A07A5
          SHA-512:ACDAD4DF988DF6B2290FC9622E8EACCC31787FECDC98DCCA38519CB762339D4D3FB344AE504B8C7918D6F414F4AD05D15E828DF7F7F68F363BEC54B11C9B7C43
          Malicious:false
          Reputation:unknown
          Preview:# button.tcl --..#..# This file defines the default bindings for Tk label, button,..# checkbutton, and radiobutton widgets and provides procedures..# that help in implementing those bindings...#..# Copyright (c) 1992-1994 The Regents of the University of userfornia...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 2002 ActiveState Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for buttons...#-------------------------------------------------------------------------....if {[tk windowingsystem] eq "aqua"} {.... bind Radiobutton <Enter> {...tk::ButtonEnter %W.. }.. bind Radiobutton <1> {...tk::ButtonDown %W.. }.. bind Radiobutton <ButtonRelease-1> {...tk::ButtonUp %W.. }.. bind Checkbutton <Enter> {...tk::ButtonEnter %W
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Nim source code, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9960
          Entropy (8bit):4.802555950168837
          Encrypted:false
          SSDEEP:
          MD5:818E4F0112931F12B4FAC4CAD262814C
          SHA1:AC7060DF952F9DB52C3687B8F5E6AA4ADF06992E
          SHA-256:35B208E8570B0D1E0CA1C911D4FE02EE3B0CFE5667CF1BDEC006CF9D043122BA
          SHA-512:0C535B6621BC83412B7A64CB6AC2BA526B8E49BB5F6BC5EBEDA41D223D68DEB031DB9C8A31F8671BC5F327D720942E7FDAE3328334B0B550AC991191F96909D6
          Malicious:false
          Reputation:unknown
          Preview:# choosedir.tcl --..#..#.Choose directory dialog implementation for Unix/Mac...#..# Copyright (c) 1998-2000 by Scriptics Corporation...# All rights reserved.....# Make sure the tk::dialog namespace, in which all dialogs should live, exists..namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {}....# Make the chooseDir namespace inside the dialog namespace..namespace eval ::tk::dialog::file::chooseDir {.. namespace import -force ::tk::msgcat::*..}....# ::tk::dialog::file::chooseDir:: --..#..#.Implements the TK directory selection dialog...#..# Arguments:..#.args..Options parsed by the procedure...#..proc ::tk::dialog::file::chooseDir:: {args} {.. variable ::tk::Priv.. set dataName __tk_choosedir.. upvar ::tk::dialog::file::$dataName data.. Config $dataName $args.... if {$data(-parent) eq "."} {.. set w .$dataName.. } else {.. set w $data(-parent).$dataName.. }.... # (re)create the dialog box if necessary.. #.. if {![winfo exis
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):22103
          Entropy (8bit):5.03166227244502
          Encrypted:false
          SSDEEP:
          MD5:AD86E0265C307348A16E9E4B64D8F235
          SHA1:66EC6726DF997EE6096F642EBBBDB8C3201BA571
          SHA-256:D210DCFA9ADB4C23E44EBF744839158CAB4E21EACF9483C6BA91BA6EC4660EB8
          SHA-512:A0C9DF815FE54C26EED69C84B29FD829EB1B7E43D2787E98C71D091607226532F6F0E9213E83FF8263FCB6DA892178029D5EF475FD46D22F9BB8AB31B87BF438
          Malicious:false
          Reputation:unknown
          Preview:# clrpick.tcl --..#..#.Color selection dialog for platforms that do not support a..#.standard color selection dialog...#..# Copyright (c) 1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#..# ToDo:..#..#.(1): Find out how many free colors are left in the colormap and..#. don't allocate too many colors...#.(2): Implement HSV color selection...#....# Make sure namespaces exist..namespace eval ::tk {}..namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::color {.. namespace import ::tk::msgcat::*..}....# ::tk::dialog::color:: --..#..#.Create a color dialog and let the user choose a color. This function..#.should not be called directly. It is called by the tk_chooseColor..#.function when a native color selector widget does not exist..#..proc ::tk::dialog::color:: {args} {.. variable ::tk::Priv.. set dataName __tk__color.. upvar ::tk::dialog::color::$da
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8690
          Entropy (8bit):5.098389551322902
          Encrypted:false
          SSDEEP:
          MD5:ABF277E4F62423F4345B6AD65640B8C2
          SHA1:E66A4E37D51C7827C9ACA449A42E0966AACBC8C8
          SHA-256:C7DA292CCF5F413E599C3491C331FFD58CF273F8477FACB097E6F36CF1F32A08
          SHA-512:AA9F75D7C5C915B5FCD2F454856D080D186AB9BA149DC139FEAF7F4AC3DC51E6769E138E3B1BE45B3FEC3AE744189DE44DB2B748F0628FF13E4E733B9CD68BD5
          Malicious:false
          Reputation:unknown
          Preview:# comdlg.tcl --..#..#.Some functions needed for the common dialog boxes. Probably need to go..#.in a different file...#..# Copyright (c) 1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# tclParseConfigSpec --..#..#.Parses a list of "-option value" pairs. If all options and..#.values are legal, the values are stored in..#.$data($option). Otherwise an error message is returned. When..#.an error happens, the data() array may have been partially..#.modified, but all the modified members of the data(0 array are..#.guaranteed to have valid values. This is different than..#.Tk_ConfigureWidget() which does not modify the value of a..#.widget record if any error occurs...#..# Arguments:..#..# w = widget record to modify. Must be the pathname of a widget...#..# specs = {..# {-commandlineswitch resourceName ResourceClass defaultValue verifier}..# {....}..# }..#..# flags
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):33347
          Entropy (8bit):4.995865221021151
          Encrypted:false
          SSDEEP:
          MD5:4CA2E90A125FFD6191D0C5AC6818D18F
          SHA1:855F10234FA1D65521C2508206EA58DC565E452B
          SHA-256:A4B21DBF699C20EA5AC334EC109F731BE8EB2B8F9A34CCC2EBE538F4BF8A05F8
          SHA-512:ED5AE05A7F1D379F8343FF4AD7EF561C5C4D9B7E02399A7281DF8B8930B924B0482FDC5B4E3F90C2214ADA4F87D9A5E64DB2259194C58A2135D969C01BBE64F9
          Malicious:false
          Reputation:unknown
          Preview:# console.tcl --..#..# This code constructs the console window for an application. It..# can be used by non-unix systems that do not have built-in support..# for shells...#..# Copyright (c) 1995-1997 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Ajuba Solutions...# Copyright (c) 2007-2008 Daniel A. Steffen <das@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# TODO: history - remember partially written command....namespace eval ::tk::console {.. variable blinkTime 500 ; # msecs to blink braced range for.. variable blinkRange 1 ; # enable blinking of the entire braced range.. variable magicKeys 1 ; # enable brace matching and proc/var recognition.. variable maxLines 600 ; # maximum # of lines buffered in console.. variable showMatches 1 ; # show multiple expand matches.. variable useFontchooser [llength [info command ::tk::fontchooser]
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5988
          Entropy (8bit):4.829498876074983
          Encrypted:false
          SSDEEP:
          MD5:B2B3AA971D42FDBF92F13B45111EE1D3
          SHA1:A74F2C2707463D6E209D0E0C96D75083AC6920A5
          SHA-256:1C977052C1D8293CC5FE4198A538BECA9BC821AF85E76E4EEFBFB75B33CE8BED
          SHA-512:146F658DA3E6E9176FA51C9836D7C1DCFC14E148A26B224155F6493C195A7FB20C2DC4EE21994E5A193B8DA8561C75374E830304F94F0C844E52AD829F6810D5
          Malicious:false
          Reputation:unknown
          Preview:# dialog.tcl --..#..# This file defines the procedure tk_dialog, which creates a dialog..# box containing a bitmap, a message, and one or more buttons...#..# Copyright (c) 1992-1993 The Regents of the University of userfornia...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#..# ::tk_dialog:..#..# This procedure displays a dialog box, waits for a button in the dialog..# to be invoked, then returns the index of the selected button. If the..# dialog somehow gets destroyed, -1 is returned...#..# Arguments:..# w -..Window to use for dialog top-level...# title -.Title to display in dialog's decorative frame...# text -.Message to display in dialog...# bitmap -.Bitmap to display in dialog (empty string means none)...# default -.Index of button that is to display the default ring..#..(-1 means none)...# args -.One or more strings to display in buttons
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):18440
          Entropy (8bit):4.982597499983157
          Encrypted:false
          SSDEEP:
          MD5:007F42FBCDC57652AC8381F11AF7FB67
          SHA1:1BB1B0FCAD6F5633D1BEB8903112F180B1C4BA7F
          SHA-256:65BA33A1E0B21E8E074780A51189CEE6FD9926C85273E9E7633987FC212A17B2
          SHA-512:A27089719ADAFC48B5ABB905E40D0C6A0A2507526223D72C1CFF36AB7C15362C6F0B8EE5775181BA1730852802AFA64631EE3720E624B630E3274BFB32F6A59A
          Malicious:false
          Reputation:unknown
          Preview:# entry.tcl --..#..# This file defines the default bindings for Tk entry widgets and provides..# procedures that help in implementing those bindings...#..# Copyright (c) 1992-1994 The Regents of the University of userfornia...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button went down (so, for example,..#...start dragging out a selection)...# pressX -..X-coordinate at which the mouse button was pressed...# selectMode -..The style of selection currently underway:..#...char, word
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5035
          Entropy (8bit):4.819523401259934
          Encrypted:false
          SSDEEP:
          MD5:63B219BE9AFF1DE7DE2BAF0E941CAE38
          SHA1:A2FEBB31380E12FF01E6F641FE8B4F815941462F
          SHA-256:8872F236D7E824AEC0ACD4BACC00FDD7EC9BC5534814ECF2160610C10647B7C5
          SHA-512:057700F8FDE4B7C3D7AB7CEFD6C531060BF2B1B3B727CAD6A37ECD42EBC557765D94B83ADD438BD5AFA1F6F919D80AE755A8D98918981167B871F31AD42FDF5E
          Malicious:false
          Reputation:unknown
          Preview:# focus.tcl --..#..# This file defines several procedures for managing the input..# focus...#..# Copyright (c) 1994-1995 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_focusNext --..# This procedure returns the name of the next window after "w" in..# "focus order" (the window that should receive the focus next if..# Tab is typed in w). "Next" is defined by a pre-order search..# of a top-level and its non-top-level descendants, with the stacking..# order determining the order of siblings. The "-takefocus" options..# on windows determine whether or not they should be skipped...#..# Arguments:..# w -..Name of a window.....proc ::tk_focusNext w {.. set cur $w.. while {1} {.....# Descend to just before the first child of the current widget......set parent $cur...set children [winfo children $cur]...set i -1.....# Look for the next sibling that isn't a top-leve
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):18232
          Entropy (8bit):4.723225284452692
          Encrypted:false
          SSDEEP:
          MD5:CFA99C2D3F02AE6538809774699A9CE7
          SHA1:DADB7B3D1D9531710BA7D3025CE18F6F8149F280
          SHA-256:4EE521F4980A5056077005B748717D91CB6B17342CDD20135962AB92A665B580
          SHA-512:DCF54AAEA439C986AE28CEC0241F204BB5001DE4E98C2E7A9C282F9E47747AD62E9B2CF6FBBAC068BF1F1BB0AAC866F85476E9EE79935CE1E3656F122C2D002D
          Malicious:false
          Reputation:unknown
          Preview:# fontchooser.tcl -..#..#.A themeable Tk font selection dialog. See TIP #324...#..# Copyright (C) 2008 Keith Vetter..# Copyright (C) 2008 Pat Thoyts <patthoyts@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....namespace eval ::tk::fontchooser {.. variable S.... set S(W) .__tk__fontchooser.. set S(fonts) [lsort -dictionary -unique [font families]].. set S(styles) [list \.. [::msgcat::mc Regular] \.. [::msgcat::mc Italic] \.. [::msgcat::mc Bold] \.. [::msgcat::mc {Bold Italic}] \.. ].. set S(sizes) {8 9 10 11 12 14 16 18 20 22 24 26 28 36 48 72}.. set S(strike) 0.. set S(under) 0.. set S(first) 1.. set S(-parent) ... set S(-title) {}.. set S(-command) "".. set S(-font) TkDefaultFont.. set S(bad) [list ]..}....proc ::tk::fontchooser::Canonical {} {.. variable S.... foreach style $S(styles
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):17565
          Entropy (8bit):4.959816621842895
          Encrypted:false
          SSDEEP:
          MD5:FDB839B85C4CEB34DEC04E0EBD6A3C96
          SHA1:0FD8981093CC6ED9927D1DDE708FECE84B9C5E6F
          SHA-256:07812124D27E47621AF74FDB90C777D3219B02F657FC2F97F606C69EF9468A01
          SHA-512:E65616B3F6BDC3910FC90E9710426370AA4B0A0D9EB6289871B9C30A98A2F2B5CC1E471B63203210AAE89120F20F164A33E01DA45BCCCCCEC7BFC1CCFD70FAC7
          Malicious:false
          Reputation:unknown
          Preview:# iconlist.tcl..#..#.Implements the icon-list megawidget used in the "Tk" standard file..#.selection dialog boxes...#..# Copyright (c) 1994-1998 Sun Microsystems, Inc...# Copyright (c) 2009 Donal K. Fellows..#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#..# API Summary:..#.tk::IconList <path> ?<option> <value>? .....#.<path> add <imageName> <itemList>..#.<path> cget <option>..#.<path> configure ?<option>? ?<value>? .....#.<path> deleteall..#.<path> destroy..#.<path> get <itemIndex>..#.<path> index <index>..#.<path> invoke..#.<path> see <index>..#.<path> selection anchor ?<int>?..#.<path> selection clear <first> ?<last>?..#.<path> selection get..#.<path> selection includes <item>..#.<path> selection set <first> ?<last>?.....package require Tk....::tk::Megawidget create ::tk::IconList ::tk::FocusableWidget {.. variable w canvas sbar accel accelCB fill font index \...itemList itemsPerColumn list
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):11037
          Entropy (8bit):6.048349526382653
          Encrypted:false
          SSDEEP:
          MD5:995A0A8F7D0861C268AEAD5FC95A42EA
          SHA1:21E121CF85E1C4984454237A646E58EC3C725A72
          SHA-256:1264940E62B9A37967925418E9D0DC0BEFD369E8C181B9BAB3D1607E3CC14B85
          SHA-512:DB7F5E0BC7D5C5F750E396E645F50A3E0CDE61C9E687ADD0A40D0C1AA304DDFBCEEB9F33AD201560C6E2B051F2EDED07B41C43D00F14EE435CDEEE73B56B93C7
          Malicious:false
          Reputation:unknown
          Preview:# icons.tcl --..#..#.A set of stock icons for use in Tk dialogs. The icons used here..#.were provided by the Tango Desktop project which provides a..#.unified set of high quality icons licensed under the..#.Creative Commons Attribution Share-Alike license..#.(https://creativecommons.org/licenses/by-sa/3.0/)..#..#.See http://tango.freedesktop.org/Tango_Desktop_Project..#..# Copyright (c) 2009 Pat Thoyts <patthoyts@users.sourceforge.net>....namespace eval ::tk::icons {}....image create photo ::tk::icons::warning -data {.. iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAABHNCSVQICAgIfAhkiAAABSZJREFU.. WIXll1toVEcYgL+Zc87u2Yu7MYmrWRuTJuvdiMuqiJd4yYKXgMQKVkSjFR80kFIVJfWCWlvpg4h9.. 8sXGWGof8iKNICYSo6JgkCBEJRG8ImYThNrNxmaTeM7pQ5IlJkabi0/9YZhhZv7///4z/8zPgf+7.. KCNRLgdlJijXwRyuDTlcxV9hbzv8nQmxMjg+XDtiOEplkG9PSfkztGmTgmFQd+FCVzwa3fYN/PHZ.. AcpBaReicW5xcbb64IEQqko8Lc26d/58cxS+/BY6hmJvyEfQBoUpwWCmW1FErKaGWHU13uRk4QkE.. UtxQNFR7QwIoB4eiKD9PWbVKbb10CZmaCqmpxCormRYO26QQx85B0mcD+AeK0
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):329
          Entropy (8bit):4.3973643486226655
          Encrypted:false
          SSDEEP:
          MD5:921245A21F7E783997DC7B859AF1B65B
          SHA1:2EFE3C8F70CF18621006890BF21CC097770D140D
          SHA-256:C6DB098EBD8A622164D37D4AB0A8C205DB1A83AC3065D5CDE3CB5FB61925D283
          SHA-512:CAD823FF3D13A64C00825961E75B5133690556FB1F622834F8B1DF316A9E75BABB63B9F5148DAE7B1391123B4C8D55B4B8B2EB6F8E6E1DA9DE02A5BD7AC0FD6F
          Malicious:false
          Reputation:unknown
          Preview:README - images directory....This directory includes images for the Tcl Logo and the Tcl Powered..Logo. Please feel free to use the Tcl Powered Logo on any of your..products that employ the use of Tcl or Tk. The Tcl logo may also be..used to promote Tcl in your product documentation, web site or other..places you so desire...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PostScript document text conforming DSC level 3.0, type EPS
          Category:dropped
          Size (bytes):34991
          Entropy (8bit):5.248845410801251
          Encrypted:false
          SSDEEP:
          MD5:23C4EDED40DEC065F99E6653AEE1BB31
          SHA1:3175E261BE198731DEDB07264CCB84C8DEDF7967
          SHA-256:76207D8DFDE189A29DC0E76ADB7EAAA606B96BC6C1C831F34D1C85B1C5B51DD3
          SHA-512:BA139A64BE72BB681040924C4294E2726BA5AB243E805E60A854D2D23E154705E2431D1AB2DE732BFA393747FD30D8A5C913895CBE1463DBF50CC23CAE5B0454
          Malicious:false
          Reputation:unknown
          Preview:%!PS-Adobe-3.0 EPSF-3.0..%%Creator: Adobe Illustrator(TM) 5.5..%%For: (Bud Northern) (Mark Anderson Design)..%%Title: (TCL/TK LOGO.ILLUS)..%%CreationDate: (8/1/96) (4:58 PM)..%%BoundingBox: 251 331 371 512..%%HiResBoundingBox: 251.3386 331.5616 370.5213 511.775..%%DocumentProcessColors: Cyan Magenta Yellow..%%DocumentSuppliedResources: procset Adobe_level2_AI5 1.0 0..%%+ procset Adobe_IllustratorA_AI5 1.0 0..%AI5_FileFormat 1.2..%AI3_ColorUsage: Color..%%DocumentCustomColors: (TCL RED)..%%CMYKCustomColor: 0 0.45 1 0 (Orange)..%%+ 0 0.25 1 0 (Orange Yellow)..%%+ 0 0.79 0.91 0 (TCL RED)..%AI3_TemplateBox: 306 396 306 396..%AI3_TileBox: 12 12 600 780..%AI3_DocumentPreview: Macintosh_ColorPic..%AI5_ArtSize: 612 792..%AI5_RulerUnits: 0..%AI5_ArtFlags: 1 0 0 1 0 0 1 1 0..%AI5_TargetResolution: 800..%AI5_NumLayers: 1..%AI5_OpenToView: 90 576 2 938 673 18 1 1 2 40..%AI5_OpenViewLayers: 7..%%EndComments..%%BeginProlog..%%BeginResource: procset Adobe_level2_AI5 1.0 0..%%Title: (Adobe Illustrator
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 68 x 100
          Category:dropped
          Size (bytes):2341
          Entropy (8bit):6.9734417899888665
          Encrypted:false
          SSDEEP:
          MD5:FF04B357B7AB0A8B573C10C6DA945D6A
          SHA1:BCB73D8AF2628463A1B955581999C77F09F805B8
          SHA-256:72F6B34D3C8F424FF0A290A793FCFBF34FD5630A916CD02E0A5DDA0144B5957F
          SHA-512:10DFE631C5FC24CF239D817EEFA14329946E26ED6BCFC1B517E2F9AF81807977428BA2539AAA653A89A372257D494E8136FD6ABBC4F727E6B199400DE05ACCD5
          Malicious:false
          Reputation:unknown
          Preview:GIF89aD.d...............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....D.d........H......*\...z..Ht@Q...92.p...z.$.@@.E..u.Y.2..0c..q.cB.,[..... ..1..qbM.2~*].....s...S.@.L.j..#..\......h..........].D(..m......@.Z....oO...3=.c...G".(..pL...q]..%....[...#...+...X.h....^.....
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 43 x 64
          Category:dropped
          Size (bytes):1670
          Entropy (8bit):6.326462043862671
          Encrypted:false
          SSDEEP:
          MD5:B226CC3DA70AAB2EBB8DFFD0C953933D
          SHA1:EA52219A37A140FD98AEA66EA54685DD8158D9B1
          SHA-256:138C240382304F350383B02ED56C69103A9431C0544EB1EC5DCD7DEC7A555DD9
          SHA-512:3D043F41B887D54CCADBF9E40E48D7FFF99B02B6FAF6B1DD0C6C6FEF0F8A17630252D371DE3C60D3EFBA80A974A0670AF3747E634C59BDFBC78544D878D498D4
          Malicious:false
          Reputation:unknown
          Preview:GIF89a+.@...............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....+.@........H. .z..(tp......@...92....#. A.......C.\.%...)Z..1a.8s..W/..@....3..C...y$.GW.....5.FU..j..;.F(Pc+W.-..X.D-[.*g....F..`.:mkT...Lw...A/.....u.7p..a..9P.....q2..Xg..G....3}AKv.\.d..yL.>..1.#
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 354 x 520
          Category:dropped
          Size (bytes):11000
          Entropy (8bit):7.88559092427108
          Encrypted:false
          SSDEEP:
          MD5:45D9B00C4CF82CC53723B00D876B5E7E
          SHA1:DDD10E798AF209EFCE022E97448E5EE11CEB5621
          SHA-256:0F404764D07A6AE2EF9E1E0E8EAAC278B7D488D61CF1C084146F2F33B485F2ED
          SHA-512:6E89DACF2077E1307DA05C16EF8FDE26E92566086346085BE10A7FD88658B9CDC87A3EC4D17504AF57D5967861B1652FA476B2DDD4D9C6BCFED9C60BB2B03B6F
          Malicious:false
          Reputation:unknown
          Preview:GIF89ab.................f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....b..........H......*\....#J.H....3j.... '.;p....(.8X..^.0c.I...z8O.\.....:....$..Fu<8`...P.>%I.gO.C.h-..+.`....@..h....dJ.?...K...H.,U.._.#...g..[.*^.x.....J.L.!.'........=+eZ..i..ynF.8...].y|..m.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 87a, 120 x 181
          Category:dropped
          Size (bytes):3889
          Entropy (8bit):7.425138719078912
          Encrypted:false
          SSDEEP:
          MD5:BD12B645A9B0036A9C24298CD7A81E5A
          SHA1:13488E4F28676F1E0CE383F80D13510F07198B99
          SHA-256:4D0BD3228AB4CC3E5159F4337BE969EC7B7334E265C99B7633E3DAF3C3FCFB62
          SHA-512:F62C996857CA6AD28C9C938E0F12106E0DF5A20D1B4B0B0D17F6294A112359BA82268961F2A054BD040B5FE4057F712206D02F2E668675BBCF6DA59A4DA0A1BB
          Malicious:false
          Reputation:unknown
          Preview:GIF87ax............................................................................z.....{..o.....m..b...`{.X....vy...hk.Um.N...I`.D..Z^.LP.?R.;!....?C.5C.3#.l..,6.*&.15...`..#(.If.y.....l...._..#/...Hm.>_.y..4R.k..#6..._......w..*K.^.."<.....G{.w..3_."C.Q..F....v..!K...v.2m.)_.[..!R.u.1t.g..)f. X.O..E..1z.g. _.Z..D..:..0..Z.. f.D..0..'z..m.N..C../.z.svC.q/.m.ze7.\..P..I..1%.,...............................................................................................................................................................................................................................................................................................................................................................................................,....x..........H.......D..!...7.PAQ...._l8.... C.<.a...*.x....0q.. ..M.%.<.HBe.@.....Q..7..XC..P..<z3..X...P.jA.%'@.J.lV.......R.,..+....t....7h.....(..a...+^.'..7..L.....V...s..$....a.....8`.9..}K......
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PostScript document text conforming DSC level 3.0, type EPS
          Category:dropped
          Size (bytes):29706
          Entropy (8bit):5.33387357427899
          Encrypted:false
          SSDEEP:
          MD5:4AE11820D4D592D02CDE458E6F8CE518
          SHA1:A2E8D3D6191B336D43E48A65C3AE6485B07D93C6
          SHA-256:87FD9E46DBB5F2BF1529AFB411182C9FB9C58E23D830C66A233AF0C256BB8EFF
          SHA-512:E0AD4ED570D414BF00931B0F5BBB61FEF981ABDB22ECC42F8E9841905D38874CDFE38F22EDB17ACD0F7539B2932F9C4A865FA73A49BB1458CE05EE10A78BE357
          Malicious:false
          Reputation:unknown
          Preview:%!PS-Adobe-3.0 EPSF-3.0..%%Creator: Adobe Illustrator(TM) 5.5..%%For: (Bud Northern) (Mark Anderson Design)..%%Title: (TCL PWRD LOGO.ILLUS)..%%CreationDate: (8/1/96) (4:59 PM)..%%BoundingBox: 242 302 377 513..%%HiResBoundingBox: 242.0523 302.5199 376.3322 512.5323..%%DocumentProcessColors: Cyan Magenta Yellow..%%DocumentSuppliedResources: procset Adobe_level2_AI5 1.0 0..%%+ procset Adobe_IllustratorA_AI5 1.0 0..%AI5_FileFormat 1.2..%AI3_ColorUsage: Color..%%CMYKCustomColor: 0 0.45 1 0 (Orange)..%%+ 0 0.25 1 0 (Orange Yellow)..%%+ 0 0.79 0.91 0 (PANTONE Warm Red CV)..%%+ 0 0.79 0.91 0 (TCL RED)..%AI3_TemplateBox: 306 396 306 396..%AI3_TileBox: 12 12 600 780..%AI3_DocumentPreview: Macintosh_ColorPic..%AI5_ArtSize: 612 792..%AI5_RulerUnits: 0..%AI5_ArtFlags: 1 0 0 1 0 0 1 1 0..%AI5_TargetResolution: 800..%AI5_NumLayers: 1..%AI5_OpenToView: 102 564 2 938 673 18 1 1 2 40..%AI5_OpenViewLayers: 7..%%EndComments..%%BeginProlog..%%BeginResource: procset Adobe_level2_AI5 1.0 0..%%Title: (Adobe I
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 64 x 100
          Category:dropped
          Size (bytes):1615
          Entropy (8bit):7.461273815456419
          Encrypted:false
          SSDEEP:
          MD5:DBFAE61191B9FADD4041F4637963D84F
          SHA1:BD971E71AE805C2C2E51DD544D006E92363B6C0C
          SHA-256:BCC0E6458249433E8CBA6C58122B7C0EFA9557CBC8FB5F9392EED5D2579FC70B
          SHA-512:ACEAD81CC1102284ED7D9187398304F21B8287019EB98B0C4EC7398DD8B5BA8E7D19CAA891AA9E7C22017B73D734110096C8A7B41A070191223B5543C39E87AF
          Malicious:false
          Reputation:unknown
          Preview:GIF89a@.d.............................f.................f...ff.f3.f..33.3.........f..ff.f3.33.3.f..f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,....@.d....@.pH,..E.... ..(...H$..v..j....K....q..5L......^).3.Y7..r..u.v|g..om...\iHl..p...`G..\~....fn[q...P.g.Z.l....y...\.l......f.Z.g...%%....e...e...)....O.f..e. ....O..qf..%..(.H.u..]..&....#4.......@.).....u!.M..2. ..PJ..#..T..a.....P.Gi... <Hb....x..z.3.X.O..f.........].Bt..lB.Q.r...9pP....&...L. ..,`[.....E6.Q.....?.#L......|g........N....[.._........."4......b....G6.........m.zI].....I.@.......I.9...glew...2.B..c>./..2....x.....<...{...7;.....y.I.....4G.Qj0..7..%.W.V...?!..[...X..=..k.h..[Q<.....0.B....(P.x.,.......8O*Z.8P!.$....u.c..Ea!..eC....CB.. .H..E..#..C..E...z..&.Nu........c.0..#.T.M.U........l.p @..s.|..pf!..&.......8.#.8.....*..J>. .t..h6(........#..0.A...*!..)...x..u.Z....*%..H.....*.......`......|.....1.......&.....T*...f.l...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 97 x 150
          Category:dropped
          Size (bytes):2489
          Entropy (8bit):7.708754027741608
          Encrypted:false
          SSDEEP:
          MD5:711F4E22670FC5798E4F84250C0D0EAA
          SHA1:1A1582650E218B0BE6FFDEFFD64D27F4B9A9870F
          SHA-256:5FC25C30AEE76477F1C4E922931CC806823DF059525583FF5705705D9E913C1C
          SHA-512:220C36010208A87D0F674DA06D6F5B4D6101D196544ABCB4EE32378C46C781589DB1CE7C7DFE6471A8D8E388EE6A279DB237B18AF1EB9130FF9D0222578F1589
          Malicious:false
          Reputation:unknown
          Preview:GIF89aa...............................f.................f...ff.f3.f..33.3............f..ff.f3.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,....a......@.pH,...r.l:..TB.T..V..z..H.j..h...&.......t"....F...d..gN~Y...g....}..r....g.....o...g.......Y.w..W......N....Z....W....f...tL.~.f....New............W.M.r.........O.q........W-./i.*...`..z..F9.../9..-.......$6..G..S...........zB.,nw.64...e4.......HOt......f.....)..OX..C.eU.(.Qh.....T..<Q.Y.P.L.YxT....2........ji..3.^)zz..O.a..6 ...TZ........^...7.....>|P.....w$...k.ZF.\R.u....F.]Z.--(v+)[Y....=.!.W..+.]..]._.....&..../Ap...j...!..b.:...{.^.=.`...U.....@Hf..\?.(..Lq@.........0..L...a...&.!.....]#..]G \..q...A.H.X[...(.W......,...1a..B...W(.t.8.AdG.)..(P=...Uu.u..A.KM\...'r.R./.W..d2a.0..G...?...B......#H........1Q.0...R....%+...0.I..{.<......QV.tz'.yn.E.p..0i.I.g......L....%....K...A.l.ph.Q.1e...Z....g..2e...smU&d;.J..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 113 x 175
          Category:dropped
          Size (bytes):2981
          Entropy (8bit):7.758793907956808
          Encrypted:false
          SSDEEP:
          MD5:DA5FB10F4215E9A1F4B162257972F9F3
          SHA1:8DB7FB453B79B8F2B4E67AC30A4BA5B5BDDEBD3B
          SHA-256:62866E95501C436B329A15432355743C6EFD64A37CFB65BCECE465AB63ECF240
          SHA-512:990CF306F04A536E4F92257A07DA2D120877C00573BD0F7B17466D74E797D827F6C127E2BEAADB734A529254595918C3A5F54FDBD859BC325A162C8CD8F6F5BE
          Malicious:false
          Reputation:unknown
          Preview:GIF89aq...............................f.................f...ff.f3.f..33.3............f..ff.f3.3f.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3................................................................!.. -dl-.!.......,....q......@.pH,...r.l:....A}H...v..R......D.VF..,%M....^.....fyzU.P..f...i.....t..Uqe..N..Z..i......~....g......u.....g......\...h.....P...h.....Q..g....Z..h......]......\...M...[..s...c2.+R.$. ......#.....)v..4....MO.b.....9......[.M.........h'..<-..=.....HQD....D?.~......W7. ..V.W0..l....*0p}..KP?c.\@KW.S(..M..B.....-q...S2...*.,..P.{....F..._MAn ....i.Y3............zh.y.j@...a876...ui.i..;K.........p...`.,}w....tv.m...Y..........;.;.e).e&.......-.NC.*4..(........*..F........[,w....f......E....h..a3.T.^.........)...C.N8.h\T...+&.z....g]H..B..#.t6..Z.....j.-..N......TI....A........M?..Q&V'...Mb.f.x...h.$r.U .9..Ci. ].4.Zb..@...X....%..<..b)V!........Y)x......T.....h.p.d..h..(........]@.**J.M.U.Jf...Y.:....F..g:..d..6q.-..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 130 x 200
          Category:dropped
          Size (bytes):3491
          Entropy (8bit):7.790611381196208
          Encrypted:false
          SSDEEP:
          MD5:A5E4284D75C457F7A33587E7CE0D1D99
          SHA1:FA98A0FD8910DF2EFB14EDAEC038B4E391FEAB3C
          SHA-256:BAD9116386343F4A4C394BDB87146E49F674F687D52BB847BD9E8198FDA382CC
          SHA-512:4448664925D1C1D9269567905D044BBA48163745646344E08203FCEF5BA1524BA7E03A8903A53DAF7D73FE0D9D820CC9063D4DA2AA1E08EFBF58524B1D69D359
          Malicious:false
          Reputation:unknown
          Preview:GIF89a................................f.................f...ff.f3.f..33.3............f..ff.3f.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,...........@.pH,...r.l:..T..F$XIe..V$.x..V.Z.z..F.pxd~..........{....o....l..{.b...hi[}P.k...y.....y.f.._R.\...............m.....y.....x......^.Q...j.....\S.....^.......l......]...[.......).....{....7...`..<...`..">..i.?/..@............>..Z.z@....0B..r...j.V.I.@..;%R...*...J.p.A.t.*..$A*...>`.....@g5BP.A..p.x.............q..8...... ...(.Q..#..@...F..YSK..M..#o.....D.m..-.....k}...BT..V......'.....`.d..~;..9+..6...<b.eZ..y^0]0..I...=.6.....}.0<.Z...M...Y1*35.e.....b...U0F~.-.HT......l2.s.q`-....y...e....dPZ....~.zT.M.... "r.E/k. ...*..Lj@'........Pcd&.(..mxF_w.."K..x!..--Y`..A.....Be.jH.A..\..j.....du#.....]^...>......].i.FMO..].9n1",Y...F...EW.9.....0TY.T...Cv!i`%...Hz@.]..U.!Y...#Dv&pi.z(.mn.A....@Q.0.%...&.4.v.cw(.`cd'|..M9..."...,*.......
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 48 x 75
          Category:dropped
          Size (bytes):1171
          Entropy (8bit):7.289201491091023
          Encrypted:false
          SSDEEP:
          MD5:7013CFC23ED23BFF3BDA4952266FA7F4
          SHA1:E5B1DED49095332236439538ECD9DD0B1FD4934B
          SHA-256:462A8FF8FD051A8100E8C6C086F497E4056ACE5B20B44791F4AAB964B010A448
          SHA-512:A887A5EC33B82E4DE412564E86632D9A984E8498F02D8FE081CC4AC091A68DF6CC1A82F4BF99906CFB6EA9D0EF47ADAC2D1B0778DCB997FB24E62FC7A6D77D41
          Malicious:false
          Reputation:unknown
          Preview:GIF89a0.K.............................f.................f...ff.f3.f..33.3.........f..ff.f3.3f.33.3.f..ff.ff.f3ff333f.3f.33.33f.3......................................................................!.. -dl-.!.......,....0.K....@.pH,...GD.<:..%SR.Z......<.V.$l.....z......:.. .|v[D..f...z.W.G.Vr...NgsU.yl..qU..`.......`fe`.......Fg....(.&...g.Y.. .."..q.V.$.'.Ez.W....y...Y.U...(#Xrf.........Xux.U..........(U.4...X....G.B..t..1S...R..Y. ...l ..".>.h......,%K....A.....<s....#..8.iK.....a.y$h..DQh.PE)....6.....MyL.qzF..... ."..Y0..a......2..*t..Ma..b...M..R.....\..st..=....Q......,>s`....Qt.,..B.R.....!.$..%.....(...s...B.T...`,".h(. D....8..dC..\Q.p.......x.#A.....:..du..(D.XV......7....S.#n8a....2`...f.:G,...==(......`!..$...t....b..../N|...f..J.x... P&.|.d._!N...].1w.3D.0!....@o&H...N.B.J....pz8..w.i....=r.............@5.-!.......H."..[.j.AB<..p....h...V.D..6.h...ab1F.g...I !.V~.H..V.........:.G..|c...,.....TD5..c[.W.....LC.....FJ..71[..lH.M.....8.:$......
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:GIF image data, version 89a, 100 x 100
          Category:dropped
          Size (bytes):5473
          Entropy (8bit):7.754239979431754
          Encrypted:false
          SSDEEP:
          MD5:048AFE69735F6974D2CA7384B879820C
          SHA1:267A9520C4390221DCE50177E789A4EBD590F484
          SHA-256:E538F8F4934CA6E1CE29416D292171F28E67DA6C72ED9D236BA42F37445EA41E
          SHA-512:201DA67A52DADA3AE7C533DE49D3C08A9465F7AA12317A0AE90A8C9C04AA69A85EC00AF2D0069023CD255DDA8768977C03C73516E4848376250E8D0D53D232CB
          Malicious:false
          Reputation:unknown
          Preview:GIF89ad.d...................RJJ...B99.......RBB..B11ZBB!....R991!!...)....{{B!!R)).JJ.ss.ZZ.BB.kk.RR.JJ.BB9...JJR!!.ZZ.BB.11.99.{s.sk.kc.cZ.ZR.JB.ZR.JB.JB.RJ.B9.91.B9...{.JB.91.B9.B9.1){)!.)!.9)..ZR.JB{91.cR{1).ZJ.ZJ.RB.J9.B1.B1.9).1!....{B9.{k.scc1).kZZ)!c)!.9).B1.9).9).1!.1!.1!.B).9!.9!.1..).....{.sZ1)R)!.B1.B1.ZBR!..9).ZB.9).R9.R9.1!.J1.J1.B).B).9!.9!.1..1..).....sZ.J9.ZB.cJJ!.{1!.B).9!{)..9!.J).B!.B!.9..R1).kJ)!.B1{9).R9.cB.Z9.Z9.B).Z9.B).R1.9!.R1.J).J).B!.1..9....{.s.J9.{Z.ZB.sR.kJk1!.cB.cB.R1.R).1..B!.J!.B.....R91.J1).c.kJ.J).Z1.B!.B!..9!..{R.sJ.Z9.R1{9!..s.R9.Z...J91Z9){B)...............B91..1)!..............................RJR............B)1......R19........BJ.9B..{..s{......!.......,....d.d.@............0@PHa....*.p...7.8.y...C.s6Z.%Q.#s.`:B.N....4jd.K.0..|y....F@.......1~ ......'Y.B"C&R.V.R.4$k.3...D.......Ef*Y3..M........BDV._.....\..).]..>s..$H\%y0WL...d.......D..'..v..1Kz.Zp$;S
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2307
          Entropy (8bit):5.135743409565932
          Encrypted:false
          SSDEEP:
          MD5:F090D9B312C16489289FD39813412164
          SHA1:1BEC6668F6549771DADC67D153B89B8F77DCD4B9
          SHA-256:0D1E4405F6273F091732764ED89B57066BE63CE64869BE6C71EA337DC4F2F9B5
          SHA-512:57B323589C5A8D9CBB224416731D8CE65C4B94146DF15CE30885DF63B1D0B3F709093B65390A911F84F20B7C5DE3C0AF9B4D7D531742BE046EDA6E8C3432EF6E
          Malicious:false
          Reputation:unknown
          Preview:This software is copyrighted by the Regents of the University of..userfornia, Sun Microsystems, Inc., Scriptics Corporation, ActiveState..Corporation, Apple Inc. and other parties. The following terms apply to..all files associated with the software unless explicitly disclaimed in..individual files.....The authors hereby grant permission to use, copy, modify, distribute,..and license this software and its documentation for any purpose, provided..that existing copyright notices are retained in all copies and that this..notice is included verbatim in any distributions. No written agreement,..license, or royalty fee is required for any of the authorized uses...Modifications to this software may be copyrighted by their authors..and need not follow the licensing terms described here, provided that..the new terms are clearly indicated on the first page of each file where..they apply.....IN NO EVENT SHALL THE AUTHORS OR DISTRIBUTORS BE LIABLE TO ANY PARTY..FOR DIRECT, INDIRECT, SPECIAL, INCI
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):15255
          Entropy (8bit):4.9510475386072095
          Encrypted:false
          SSDEEP:
          MD5:804E6DCE549B2E541986C0CE9E75E2D1
          SHA1:C44EE09421F127CF7F4070A9508F22709D06D043
          SHA-256:47C75F9F8348BF8F2C086C57B97B73741218100CA38D10B8ABDF2051C95B9801
          SHA-512:029426C4F659848772E6BB1D8182EB03D2B43ADF68FCFCC1EA1C2CC7C883685DEDA3FFFDA7E071912B9BDA616AD7AF2E1CB48CE359700C1A22E1E53E81CAE34B
          Malicious:false
          Reputation:unknown
          Preview:# listbox.tcl --..#..# This file defines the default bindings for Tk listbox widgets..# and provides procedures that help in implementing those bindings...#..# Copyright (c) 1994 The Regents of the University of userfornia...# Copyright (c) 1994-1995 Sun Microsystems, Inc...# Copyright (c) 1998 by Scriptics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....#--------------------------------------------------------------------------..# tk::Priv elements used in this file:..#..# afterId -..Token returned by "after" for autoscanning...# listboxPrev -.The last element to be selected or deselected..#...during a selection operation...# listboxSelection -.All of the items that were selected before the..#...current selection operation (such as a mouse..#...drag) started; used to cancel an operation...#--------------------------------------------------------------------------....#--------------
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9862
          Entropy (8bit):4.786615174847384
          Encrypted:false
          SSDEEP:
          MD5:D83ED6AC2912900040530528A0237AB3
          SHA1:2D18E42A8B96C3D71C1C6701010FDF75C1E6D5D8
          SHA-256:848258B946C002E2696CA3815A1589C8120AF5CC41FBC11BBD9A3F5754CC21AF
          SHA-512:00B4CD0D58029FC37820C163A4AE1DEAD22FB5C767BDC118659EACE26D449C362189611DFB3FAB1AC129FABFEC2CE853EA2C10D418FAE5AEB91DDC9330FF782D
          Malicious:false
          Reputation:unknown
          Preview:# megawidget.tcl..#..#.Basic megawidget support classes. Experimental for any use other than..#.the ::tk::IconList megawdget, which is itself only designed for use in..#.the Unix file dialogs...#..# Copyright (c) 2009-2010 Donal K. Fellows..#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#....package require Tk.....::oo::class create ::tk::Megawidget {.. superclass ::oo::class.. method unknown {w args} {...if {[string match .* $w]} {... [self] create $w {*}$args... return $w...}...next $w {*}$args.. }.. unexport new unknown.. self method create {name superclasses body} {...next $name [list \....superclass ::tk::MegawidgetClass {*}$superclasses]\;$body.. }..}....::oo::class create ::tk::MegawidgetClass {.. variable w hull options IdleCallbacks.. constructor args {...# Extract the "widget name" from the object name...set w [namespace tail [self]].....# Configure things...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):39790
          Entropy (8bit):4.915612301723047
          Encrypted:false
          SSDEEP:
          MD5:B7DAA21C1C192B8CB5B86CBD7B2CE068
          SHA1:AE8ABF9017F37CCDF5D0D15DE66BB124A7482BA0
          SHA-256:312AF944A276CDBF1EE00757EF141595670984F7F13E19922C25643A040F5339
          SHA-512:B619E3B8BE5EC4545E97B7A7A7F7FECC2AAFA58438F9CA3819F644720CF5FF5C44DA12AC25988570E595D97CAD799F87D93C24D5E67A7A953B9F5312952FBEB6
          Malicious:false
          Reputation:unknown
          Preview:# menu.tcl --..#..# This file defines the default bindings for Tk menus and menubuttons...# It also implements keyboard traversal of menus and implements a few..# other utility procedures related to menus...#..# Copyright (c) 1992-1994 The Regents of the University of userfornia...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1998-1999 Scriptics Corporation...# Copyright (c) 2007 Daniel A. Steffen <das@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# cursor -..Saves the -cursor option for the posted menubutton...# focus -..Saves the focus during a menu selection operation...#...Focus gets restored here when the menu is unposted...# grabGlobal -..Used in conjunction with tk::Priv(oldGrab): if..#...tk::Priv(oldGrab) is non
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):30840
          Entropy (8bit):5.142909056222569
          Encrypted:false
          SSDEEP:
          MD5:983C7B78F1A0EBACAB8006D391A01FCD
          SHA1:7EA37474EA039ED7A37BFDD7D76EAE673E666283
          SHA-256:C5BDCA3ABA671F03DC4624AB5FD260490F5002491D6C619142CCF5A1A744528A
          SHA-512:A006EF9B7213E572F6FC540D1512A52C52FEC44E3A07846DE09662AE32B7191C5CF639798531847B39E4076BF9DD6314B6F5373065C04F4FEF221185B39C3117
          Malicious:false
          Reputation:unknown
          Preview:# mkpsenc.tcl --..#..# This file generates the postscript prolog used by Tk.....namespace eval ::tk {.. # Creates Postscript encoding vector for ISO-8859-1 (could theoretically.. # handle any 8-bit encoding, but Tk never generates characters outside.. # ASCII)... #.. proc CreatePostscriptEncoding {} {...variable psglyphs...# Now check for known. Even if it is known, it can be other than we...# need. GhostScript seems to be happy with such approach...set result "\[\n"...for {set i 0} {$i<256} {incr i 8} {... for {set j 0} {$j<8} {incr j} {....set enc [encoding convertfrom "iso8859-1" \.....[format %c [expr {$i+$j}]]]....catch {.... set hexcode {}.... set hexcode [format %04X [scan $enc %c]]....}....if {[info exists psglyphs($hexcode)]} {.... append result "/$psglyphs($hexcode)"....} else {.... append result "/space"....}... }... append result "\n"...}...append result "\]"...return $result.. }.... # List of adobe glyph names. Converted from glyph
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:xbm image (32x, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):16786
          Entropy (8bit):4.717927930017041
          Encrypted:false
          SSDEEP:
          MD5:217087AB6B2A8F9D7252E311D69C3769
          SHA1:09AEB2BC5B7C7F4AB3DE4211D786C519AE0970F6
          SHA-256:A07E3A3809CED3C6C9C1E171DCA5AD1F28357734CD41B2B9DD9F58085B3D2842
          SHA-512:6E57633C924BFC16D380C014C20DD24D5727E70D4843FCEC4D7995B4DB21941EA8F2A5FD6E5386DF3364B6905D4D66B2B9595DC8FC70CFF40A2D49A92A1B6FBA
          Malicious:false
          Reputation:unknown
          Preview:# msgbox.tcl --..#..#.Implements messageboxes for platforms that do not have native..#.messagebox support...#..# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# Ensure existence of ::tk::dialog namespace..#..namespace eval ::tk::dialog {}....image create bitmap ::tk::dialog::b1 -foreground black \..-data "#define b1_width 32\n#define b1_height 32..static unsigned char q1_bits[] = {.. 0x00, 0xf8, 0x1f, 0x00, 0x00, 0x07, 0xe0, 0x00, 0xc0, 0x00, 0x00, 0x03,.. 0x20, 0x00, 0x00, 0x04, 0x10, 0x00, 0x00, 0x08, 0x08, 0x00, 0x00, 0x10,.. 0x04, 0x00, 0x00, 0x20, 0x02, 0x00, 0x00, 0x40, 0x02, 0x00, 0x00, 0x40,.. 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80,.. 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80,.. 0x01, 0x00, 0x00, 0x80, 0x02, 0x00, 0x00, 0x40, 0x02, 0x00, 0x00, 0x40,.. 0x04, 0x00,
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4235
          Entropy (8bit):4.789130604359491
          Encrypted:false
          SSDEEP:
          MD5:5A8B46B85DCCBF74E2B5B820E1A7B9D1
          SHA1:980F4FC5BABA82BA0FE02F9BD03A23DF6D565BB1
          SHA-256:4DFFBEEDBF0D66D84B13088016D1A782CEAAD4DED27BE1E38842F8969C0E533F
          SHA-512:2D81FC06CF3C20E4F6314BD13AF81FDE38A9B06510584C84C6A0C8C36314F980F77D02BD8056E7EE5DE599A0620E0C0349124147334B9C141145270046B19D90
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset cs "&Abort" "&P\u0159eru\u0161it".. ::msgcat::mcset cs "&About..." "&O programu...".. ::msgcat::mcset cs "All Files" "V\u0161echny soubory".. ::msgcat::mcset cs "Application Error" "Chyba programu".. ::msgcat::mcset cs "Bold Italic".. ::msgcat::mcset cs "&Blue" "&Modr\341".. ::msgcat::mcset cs "Cancel" "Zru\u0161it".. ::msgcat::mcset cs "&Cancel" "&Zru\u0161it".. ::msgcat::mcset cs "Cannot change to the directory \"%1\$s\".\nPermission denied." "Nemohu zm\u011bnit atku\341ln\355 adres\341\u0159 na \"%1\$s\".\nP\u0159\355stup odm\355tnut.".. ::msgcat::mcset cs "Choose Directory" "V\375b\u011br adres\341\u0159e".. ::msgcat::mcset cs "Cl&ear" "Sma&zat".. ::msgcat::mcset cs "&Clear Console" "&Smazat konzolu".. ::msgcat::mcset cs "Color" "Barva".. ::msgcat::mcset cs "Console" "Konzole".. ::msgcat::mcset cs "&Copy" "&Kop\355rovat".. ::msgcat::mcset cs "Cu&t" "V&y\u0159\355znout".. ::msgcat::mcset cs "&
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3987
          Entropy (8bit):4.651948695787255
          Encrypted:false
          SSDEEP:
          MD5:227B0F255F854460E8E5146ED7A17B85
          SHA1:99A080CAD631F21963C51A5B254BDAD3724DC866
          SHA-256:FEEF8F8AD33BB3362C845A25D6ED273C398051047D899B31790474614C7AFD2D
          SHA-512:36A4B48831316CC29686CC76DA00110EB078EC56F55A960D11AE427AA3D913C340C1E3805BF2AD40C1A8A92FC6587DA5D2C245E7501289FC3E228BE14FE49598
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset da "&Abort" "&Afbryd".. ::msgcat::mcset da "&About..." "&Om...".. ::msgcat::mcset da "All Files" "Alle filer".. ::msgcat::mcset da "Application Error" "Programfejl".. ::msgcat::mcset da "&Blue" "&Bl\u00E5".. ::msgcat::mcset da "Cancel" "Annuller".. ::msgcat::mcset da "&Cancel" "&Annuller".. ::msgcat::mcset da "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan ikke skifte til katalog \"%1\$s\".\nIngen rettigheder.".. ::msgcat::mcset da "Choose Directory" "V\u00E6lg katalog".. ::msgcat::mcset da "Cl&ear" "&Ryd".. ::msgcat::mcset da "&Clear Console" "&Ryd konsolen".. ::msgcat::mcset da "Color" "Farve".. ::msgcat::mcset da "Console" "Konsol".. ::msgcat::mcset da "&Copy" "&Kopier".. ::msgcat::mcset da "Cu&t" "Kli&p".. ::msgcat::mcset da "&Delete" "&Slet".. ::msgcat::mcset da "Details >>" "Detailer".. ::msgcat::mcset da "Directory \"%1\$s\" does not exist." "Katalog \"%1\$s\" finde
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4914
          Entropy (8bit):4.6221938909259475
          Encrypted:false
          SSDEEP:
          MD5:2203F65BCDA61BC15AEAC4F868C6D94A
          SHA1:C4CC3975679D23892406E4E8971359A0775B1B86
          SHA-256:C0F574B14068A049E93421C73873D750C98DE28B7B77AA42FE72CBE0270A4186
          SHA-512:79F134FDAD3B12524D43BF9F59D3C04CAE30A95F591A51B82C8DF7CC8563BEA5D464AEECC457D9F60C04365E30459C447ED537AFC832BA25E1815DE06C2B81E5
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset de "&Abort" "&Abbruch".. ::msgcat::mcset de "&About..." "&\u00dcber...".. ::msgcat::mcset de "All Files" "Alle Dateien".. ::msgcat::mcset de "Application Error" "Applikationsfehler".. ::msgcat::mcset de "&Apply" "&Anwenden".. ::msgcat::mcset de "Bold" "Fett".. ::msgcat::mcset de "Bold Italic" "Fett kursiv".. ::msgcat::mcset de "&Blue" "&Blau".. ::msgcat::mcset de "Cancel" "Abbruch".. ::msgcat::mcset de "&Cancel" "&Abbruch".. ::msgcat::mcset de "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kann nicht in das Verzeichnis \"%1\$s\" wechseln.\nKeine Rechte vorhanden.".. ::msgcat::mcset de "Choose Directory" "W\u00e4hle Verzeichnis".. ::msgcat::mcset de "Cl&ear" "&R\u00fccksetzen".. ::msgcat::mcset de "&Clear Console" "&Konsole l\u00f6schen".. ::msgcat::mcset de "Color" "Farbe".. ::msgcat::mcset de "Console" "Konsole".. ::msgcat::mcset de "&Copy" "&Kopieren".. ::msgcat::mcset de "
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with very long lines (355), with CRLF line terminators
          Category:dropped
          Size (bytes):8784
          Entropy (8bit):4.334043617395095
          Encrypted:false
          SSDEEP:
          MD5:780F863903BBDAA6C371EC0D3C7E6D59
          SHA1:DF5D435E132BEE4C076A7FC577C8C275A8B68CD5
          SHA-256:3F6F155864FE59A341BFD869735E54DD21CEE21BBD038433D9B271AD77BA3F7E
          SHA-512:091965EE912513AE1943BE840A2E757188FBA6F760F7C47BE80D06313D59B051F183E3A29D4B1CEDE1F9E54CA3CA23D75FF2C3A3672A4E71FB56F0FA76F7FA0D
          Malicious:false
          Reputation:unknown
          Preview:## Messages for the Greek (Hellenic - "el") language...## Please report any changes/suggestions to:..## petasis@iit.demokritos.gr....namespace eval ::tk {.. ::msgcat::mcset el "&Abort" "\u03a4\u03b5\u03c1\u03bc\u03b1\u03c4\u03b9\u03c3\u03bc\u03cc\u03c2".. ::msgcat::mcset el "About..." "\u03a3\u03c7\u03b5\u03c4\u03b9\u03ba\u03ac...".. ::msgcat::mcset el "All Files" "\u038c\u03bb\u03b1 \u03c4\u03b1 \u0391\u03c1\u03c7\u03b5\u03af\u03b1".. ::msgcat::mcset el "Application Error" "\u039b\u03ac\u03b8\u03bf\u03c2 \u0395\u03c6\u03b1\u03c1\u03bc\u03bf\u03b3\u03ae\u03c2".. ::msgcat::mcset el "&Blue" "\u039c\u03c0\u03bb\u03b5".. ::msgcat::mcset el "&Cancel" "\u0391\u03ba\u03cd\u03c1\u03c9\u03c3\u03b7".. ::msgcat::mcset el \.."Cannot change to the directory \"%1\$s\".\nPermission denied." \.."\u0394\u03b5\u03bd \u03b5\u03af\u03bd\u03b1\u03b9 \u03b4\u03c5\u03bd\u03b1\u03c4\u03ae \u03b7 \u03b1\u03bb\u03bb\u03b1\u03b3\u
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3377
          Entropy (8bit):4.279601088621442
          Encrypted:false
          SSDEEP:
          MD5:D48CFC9EC779085E8F6AAA7B1C40C89A
          SHA1:0CF6253BFF39F40CA0991F9B06D3394BFEA21ED2
          SHA-256:4A33B44B2E220E28EAAE7FAC407CAFE43D97C270DA58FA5F3B699A1760BFB2A4
          SHA-512:C00EC0CFB48ABE621EF625C51952BCF177CE3BC7F0DEC5276EF84C9A97C7E014806B106EA8DEE202C43F8DD54ED7261A8D899E3EE12E3F37A90C387D864463AE
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset en "&Abort".. ::msgcat::mcset en "&About...".. ::msgcat::mcset en "All Files".. ::msgcat::mcset en "Application Error".. ::msgcat::mcset en "&Apply".. ::msgcat::mcset en "Bold".. ::msgcat::mcset en "Bold Italic".. ::msgcat::mcset en "&Blue".. ::msgcat::mcset en "Cancel".. ::msgcat::mcset en "&Cancel".. ::msgcat::mcset en "Cannot change to the directory \"%1\$s\".\nPermission denied.".. ::msgcat::mcset en "Choose Directory".. ::msgcat::mcset en "Cl&ear".. ::msgcat::mcset en "&Clear Console".. ::msgcat::mcset en "Color".. ::msgcat::mcset en "Console".. ::msgcat::mcset en "&Copy".. ::msgcat::mcset en "Cu&t".. ::msgcat::mcset en "&Delete".. ::msgcat::mcset en "Details >>".. ::msgcat::mcset en "Directory \"%1\$s\" does not exist.".. ::msgcat::mcset en "&Directory:".. ::msgcat::mcset en "&Edit".. ::msgcat::mcset en "Effects".. ::msgcat::mcset en "Error: %1\$s".. ::msgcat::mcs
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):66
          Entropy (8bit):4.262228832346611
          Encrypted:false
          SSDEEP:
          MD5:3D41FC47CD9936F817EF9645D73A77ED
          SHA1:E62BBE094B71CAF4A389DE3ECD84D2EEFBA33827
          SHA-256:01238293356E82F1D298896491F8B299BB7DC9C34F299C9E756254C736DA612B
          SHA-512:B92582C32C4D7CD9DE6571CBB6B93DD693A8B5A80645468E2D02B80C339BE2B95D5B4878A0DA9AFFE9E2F98A6C38AAE9CC1FF2440146D0ED128FE8C9A92EECDB
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset en_gb Color Colour..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4035
          Entropy (8bit):4.614759526381991
          Encrypted:false
          SSDEEP:
          MD5:3704A08985B0AA3C521FDF9C2DA59D97
          SHA1:3F1E42C5697504B4DEE1EE314CD361B4203BF686
          SHA-256:84B117857674A2426290946053A61316C5C8C6808F2C6EDF0ECC5C4A9C5C72AC
          SHA-512:99FE97B10B1CA59DDA0385161E7C05F7D22424B6B1FB844138921EF94B2E9809D73EBC0062897D0DDE040CF92C96A6E4916CC9F3F02442AE2C4162858434B6BA
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset eo "&Abort" "&\u0108esigu".. ::msgcat::mcset eo "&About..." "Pri...".. ::msgcat::mcset eo "All Files" "\u0108iuj dosieroj".. ::msgcat::mcset eo "Application Error" "Aplikoeraro".. ::msgcat::mcset eo "&Blue" "&Blua".. ::msgcat::mcset eo "Cancel" "Rezignu".. ::msgcat::mcset eo "&Cancel" "&Rezignu".. ::msgcat::mcset eo "Cannot change to the directory \"%1\$s\".\nPermission denied." "Neeble \u015dan\u011di al dosierujo \"%1\$s\".\nVi ne rajtas tion.".. ::msgcat::mcset eo "Choose Directory" "Elektu Dosierujon".. ::msgcat::mcset eo "Cl&ear" "&Vakigu".. ::msgcat::mcset eo "&Clear Console" "&Vakigu konzolon".. ::msgcat::mcset eo "Color" "Koloro".. ::msgcat::mcset eo "Console" "Konzolo".. ::msgcat::mcset eo "&Copy" "&Kopiu".. ::msgcat::mcset eo "Cu&t" "&Eltondu".. ::msgcat::mcset eo "&Delete" "&Forigu".. ::msgcat::mcset eo "Details >>" "Detaloj >>".. ::msgcat::mcset eo "Directory \"%1\$s\" does not exi
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4024
          Entropy (8bit):4.536517819515934
          Encrypted:false
          SSDEEP:
          MD5:4765F3C055742530E4644771EBC6C69F
          SHA1:8BEA722AC00522DEAA5B380AEEF4CA57D7A271BD
          SHA-256:D2842B80F1B521EFF2D2656A69274B5F2A8F4F5831AF2E8EE73E3C37389F981F
          SHA-512:9CA247F22797A1A1FCA42B5CDABF58262ED95EECDDD321CEB1440A60A4375923E0F511238F360D159EB5EED6F82CBBE0B8907A07CC77DB831BF97082932CD0FD
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset es "&Abort" "&Abortar".. ::msgcat::mcset es "&About..." "&Acerca de ...".. ::msgcat::mcset es "All Files" "Todos los archivos".. ::msgcat::mcset es "Application Error" "Error de la aplicaci\u00f3n".. ::msgcat::mcset es "&Blue" "&Azul".. ::msgcat::mcset es "Cancel" "Cancelar".. ::msgcat::mcset es "&Cancel" "&Cancelar".. ::msgcat::mcset es "Cannot change to the directory \"%1\$s\".\nPermission denied." "No es posible acceder al directorio \"%1\$s\".\nPermiso denegado.".. ::msgcat::mcset es "Choose Directory" "Elegir directorio".. ::msgcat::mcset es "Cl&ear" "&Borrar".. ::msgcat::mcset es "&Clear Console" "&Borrar consola".. ::msgcat::mcset es "Color".. ::msgcat::mcset es "Console" "Consola".. ::msgcat::mcset es "&Copy" "&Copiar".. ::msgcat::mcset es "Cu&t" "Cor&tar".. ::msgcat::mcset es "&Delete" "&Borrar".. ::msgcat::mcset es "Details >>" "Detalles >>".. ::msgcat::mcset es "Directory \"%1\$s\"
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4693
          Entropy (8bit):4.640083757706223
          Encrypted:false
          SSDEEP:
          MD5:BD795A1D95446BEE7AEB16FB6E346271
          SHA1:38469DBD386C35B90EBE0A0FE2CE9F1AB5A5444A
          SHA-256:893BEDCDAED4602898D988E6248B8BB0857DD66C06194B45F31340CA03D82369
          SHA-512:B9BDDECB1DE2025C6C4027BF6228A14D5F573F5859ED3444298809266F06E6203F72004D589314C6529A2E198039355B4FD6160F87DA8F97B55E9F841B6C3F5A
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset fi "&Abort" "&Keskeyt\u00e4".. ::msgcat::mcset fi "&About..." "&Tietoja...".. ::msgcat::mcset fi "All Files" "Kaikki tiedostot".. ::msgcat::mcset fi "Application Error" "Ohjelmavirhe".. ::msgcat::mcset fi "&Apply" "K\u00e4&yt\u00e4".. ::msgcat::mcset fi "Bold" "Lihavoitu".. ::msgcat::mcset fi "Bold Italic" "Lihavoitu, kursivoitu".. ::msgcat::mcset fi "&Blue" "&Sininen".. ::msgcat::mcset fi "Cancel" "Peruuta".. ::msgcat::mcset fi "&Cancel" "&Peruuta".. ::msgcat::mcset fi "Cannot change to the directory \"%1\$s\".\nPermission denied." "Ei voitu vaihtaa hakemistoon \"%1\$s\".\nLupa ev\u00e4tty.".. ::msgcat::mcset fi "Choose Directory" "Valitse hakemisto".. ::msgcat::mcset fi "Cl&ear" "&Tyhjenn\u00e4".. ::msgcat::mcset fi "&Clear Console" "&Tyhjenn\u00e4 konsoli".. ::msgcat::mcset fi "Color" "V\u00e4ri".. ::msgcat::mcset fi "Console" "Konsoli".. ::msgcat::mcset fi "&Copy" "K&opioi".. ::msgcat::mcs
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3877
          Entropy (8bit):4.630737553723335
          Encrypted:false
          SSDEEP:
          MD5:E279E5FFF03E1B8E9063ABC8A499A6BD
          SHA1:80910911F6B4830BA4DCBA9A9EAD12C9F802DDC9
          SHA-256:3F2CEB4A33695AB6B56E27F61A4C60C029935BB026497D99CB2C246BCB4A63C4
          SHA-512:8333388E421AC3F342317BEBE352809B0B190EF8B044A0BAE2FE4051974D86008BAFDCB7098E9DC39A8D9E1E08FB87F54B9D3388AF2D0185FF913DB6788C5AB5
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset fr "&Abort" "&Annuler".. ::msgcat::mcset fr "About..." "\u00c0 propos...".. ::msgcat::mcset fr "All Files" "Tous les fichiers".. ::msgcat::mcset fr "Application Error" "Erreur d'application".. ::msgcat::mcset fr "&Blue" "&Bleu".. ::msgcat::mcset fr "Cancel" "Annuler".. ::msgcat::mcset fr "&Cancel" "&Annuler".. ::msgcat::mcset fr "Cannot change to the directory \"%1\$s\".\nPermission denied." "Impossible d'acc\u00e9der au r\u00e9pertoire \"%1\$s\".\nPermission refus\u00e9e.".. ::msgcat::mcset fr "Choose Directory" "Choisir r\u00e9pertoire".. ::msgcat::mcset fr "Cl&ear" "Effacer".. ::msgcat::mcset fr "Color" "Couleur".. ::msgcat::mcset fr "Console".. ::msgcat::mcset fr "Copy" "Copier".. ::msgcat::mcset fr "Cu&t" "Couper".. ::msgcat::mcset fr "Delete" "Effacer".. ::msgcat::mcset fr "Details >>" "D\u00e9tails >>".. ::msgcat::mcset fr "Directory \"%1\$s\" does not exist." "Le r\u00e9pertoire \"%1\$s\"
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4678
          Entropy (8bit):4.7955991577265245
          Encrypted:false
          SSDEEP:
          MD5:4F1610E0C73DAE668E3F9D9235631152
          SHA1:63EE54A6C1A69B798C65C999D5F80A7AB252B6D8
          SHA-256:E063AD7CA93F37728A65E4CD7C0433950F22607D307949F6CB056446AFEAA4FE
          SHA-512:37F4B8A9CD020A77591C09AF40FBC2FA82107B2596D31B5F30CE6ECAA225417CF7A5C62FB7A93539B0D7E930D0A44F9BF2EE6BE113F831B0A72B229444672AFD
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset hu "&Abort" "&Megszak\u00edt\u00e1s".. ::msgcat::mcset hu "&About..." "N\u00e9vjegy...".. ::msgcat::mcset hu "All Files" "Minden f\u00e1jl".. ::msgcat::mcset hu "Application Error" "Alkalmaz\u00e1s hiba".. ::msgcat::mcset hu "&Blue" "&K\u00e9k".. ::msgcat::mcset hu "Cancel" "M\u00e9gsem".. ::msgcat::mcset hu "&Cancel" "M\u00e9g&sem".. ::msgcat::mcset hu "Cannot change to the directory \"%1\$s\".\nPermission denied." "A k\u00f6nyvt\u00e1rv\u00e1lt\u00e1s nem siker\u00fclt: \"%1\$s\".\nHozz\u00e1f\u00e9r\u00e9s megtagadva.".. ::msgcat::mcset hu "Choose Directory" "K\u00f6nyvt\u00e1r kiv\u00e1laszt\u00e1sa".. ::msgcat::mcset hu "Cl&ear" "T\u00f6rl\u00e9s".. ::msgcat::mcset hu "&Clear Console" "&T\u00f6rl\u00e9s Konzol".. ::msgcat::mcset hu "Color" "Sz\u00edn".. ::msgcat::mcset hu "Console" "Konzol".. ::msgcat::mcset hu "&Copy" "&M\u00e1sol\u00e1s".. ::msgcat::mcset hu "Cu&t" "&Kiv\u00e1g\u00e1s".. ::ms
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3765
          Entropy (8bit):4.49679862548805
          Encrypted:false
          SSDEEP:
          MD5:B74C54666A5A431A782DB691B4CA3315
          SHA1:2BC63982C14BBA8A4C451CE31540181F40CE2216
          SHA-256:806930F283FD097195C7850E3486B3815D1564529B4F8E5FA6D26F3175183BC1
          SHA-512:8120E2FFD14E0A992E254796ADDC0DC995C921BE31688C0995D7A36FE82609D78791FEF73EAF5B14E2F0D40AD256AB8DAAA07C18E6950362B28E40B71E47C0B6
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset it "&Abort" "&Interrompi".. ::msgcat::mcset it "&About..." "Informazioni...".. ::msgcat::mcset it "All Files" "Tutti i file".. ::msgcat::mcset it "Application Error" "Errore dell' applicazione".. ::msgcat::mcset it "&Blue" "&Blu".. ::msgcat::mcset it "Cancel" "Annulla".. ::msgcat::mcset it "&Cancel" "&Annulla".. ::msgcat::mcset it "Cannot change to the directory \"%1\$s\".\nPermission denied." "Impossibile accedere alla directory \"%1\$s\".\nPermesso negato.".. ::msgcat::mcset it "Choose Directory" "Scegli una directory".. ::msgcat::mcset it "Cl&ear" "Azzera".. ::msgcat::mcset it "&Clear Console" "Azzera Console".. ::msgcat::mcset it "Color" "Colore".. ::msgcat::mcset it "Console".. ::msgcat::mcset it "&Copy" "Copia".. ::msgcat::mcset it "Cu&t" "Taglia".. ::msgcat::mcset it "Delete" "Cancella".. ::msgcat::mcset it "Details >>" "Dettagli >>".. ::msgcat::mcset it "Directory \"%1\$s\" does not ex
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4557
          Entropy (8bit):4.524344068436489
          Encrypted:false
          SSDEEP:
          MD5:E56229BAC5A8ABB90C4DD8EE3F9FF9F8
          SHA1:7527D6C3C6C84BFF0E683FFA86A21C58458EB55D
          SHA-256:0914FBA42361227D14FA281E8A9CBF57C16200B4DA1E61CC3402EF0113A512C7
          SHA-512:13649DDB06DB4BA9E39BEAF828211086A519444DA9AB5CBDD1B88B29208388189A5141F75AD94B56A348EDDE534FFADE8B19B557CB988EA4ECC9A84B135D36C1
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset nl "&Abort" "&Afbreken".. ::msgcat::mcset nl "&About..." "Over...".. ::msgcat::mcset nl "All Files" "Alle Bestanden".. ::msgcat::mcset nl "Application Error" "Toepassingsfout".. ::msgcat::mcset nl "&Apply" "Toepassen".. ::msgcat::mcset nl "Bold" "Vet".. ::msgcat::mcset nl "Bold Italic" "Vet Cursief".. ::msgcat::mcset nl "&Blue" "&Blauw".. ::msgcat::mcset nl "Cancel" "Annuleren".. ::msgcat::mcset nl "&Cancel" "&Annuleren".. ::msgcat::mcset nl "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan niet naar map \"%1\$s\" gaan.\nU heeft hiervoor geen toestemming.".. ::msgcat::mcset nl "Choose Directory" "Kies map".. ::msgcat::mcset nl "Cl&ear" "Wissen".. ::msgcat::mcset nl "&Clear Console" "&Wis Console".. ::msgcat::mcset nl "Color" "Kleur".. ::msgcat::mcset nl "Console".. ::msgcat::mcset nl "&Copy" "Kopi\u00ebren".. ::msgcat::mcset nl "Cu&t" "Knippen".. ::msgcat::mcset nl "&Dele
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4932
          Entropy (8bit):4.799369674927008
          Encrypted:false
          SSDEEP:
          MD5:8CFA2E38822303FDCB55AE3277F0B81B
          SHA1:447F28A5064FCEA019C60B3F9B6D50CD43C2D0E3
          SHA-256:EACEB1F08DE0863CCF726881E07FE5B135EA09646C5253E0CBF7DDB987EB0D92
          SHA-512:E38BA9059AFF55C2B22A4AE24D6A76149C76DBA8BF8646AE81D6E07D7ED490D0605034B29D9AC848E6685C8EC26A3DBE5B2EAF462B14D96376E80076FBE7082A
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset pl "&Abort" "&Przerwij".. ::msgcat::mcset pl "&About..." "O programie...".. ::msgcat::mcset pl "All Files" "Wszystkie pliki".. ::msgcat::mcset pl "Application Error" "B\u0142\u0105d w programie".. ::msgcat::mcset pl "&Apply" "Zastosuj".. ::msgcat::mcset pl "Bold" "Pogrubienie".. ::msgcat::mcset pl "Bold Italic" "Pogrubiona kursywa".. ::msgcat::mcset pl "&Blue" "&Niebieski".. ::msgcat::mcset pl "Cancel" "Anuluj".. ::msgcat::mcset pl "&Cancel" "&Anuluj".. ::msgcat::mcset pl "Cannot change to the directory \"%1\$s\".\nPermission denied." "Nie mo\u017cna otworzy\u0107 katalogu \"%1\$s\".\nOdmowa dost\u0119pu.".. ::msgcat::mcset pl "Choose Directory" "Wybierz katalog".. ::msgcat::mcset pl "Cl&ear" "&Wyczy\u015b\u0107".. ::msgcat::mcset pl "&Clear Console" "&Wyczy\u015b\u0107 konsol\u0119".. ::msgcat::mcset pl "Color" "Kolor".. ::msgcat::mcset pl "Console" "Konsola".. ::msgcat::mcset pl "&Copy" "&Kopiu
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3987
          Entropy (8bit):4.63232183429232
          Encrypted:false
          SSDEEP:
          MD5:4018686F2A8E299D86BDB1478BC97896
          SHA1:0EECE3D57F2EA5EECE8157B06F3AFB97E1F2551A
          SHA-256:D687F71F0432BB0D02EFDF576E526D2C19D4136F76C41A3224A2F034168F3F34
          SHA-512:4D730068B2A21E1D6004205B10A9D0D5EE9683FEB03B6FB673E8B9B94ED6BE468086A52DFE97C4DBF35A07CBB2C5E276DF0952A06C78E029D53D796CB6FCC8DF
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset pt "&Abort" "&Abortar".. ::msgcat::mcset pt "About..." "Sobre ...".. ::msgcat::mcset pt "All Files" "Todos os arquivos".. ::msgcat::mcset pt "Application Error" "Erro de aplica\u00e7\u00e3o".. ::msgcat::mcset pt "&Blue" "&Azul".. ::msgcat::mcset pt "Cancel" "Cancelar".. ::msgcat::mcset pt "&Cancel" "&Cancelar".. ::msgcat::mcset pt "Cannot change to the directory \"%1\$s\".\nPermission denied." "N\u00e3o foi poss\u00edvel mudar para o diret\u00f3rio \"%1\$s\".\nPermiss\u00e3o negada.".. ::msgcat::mcset pt "Choose Directory" "Escolha um diret\u00f3rio".. ::msgcat::mcset pt "Cl&ear" "Apagar".. ::msgcat::mcset pt "&Clear Console" "Apagar Console".. ::msgcat::mcset pt "Color" "Cor".. ::msgcat::mcset pt "Console".. ::msgcat::mcset pt "&Copy" "Copiar".. ::msgcat::mcset pt "Cu&t" "Recortar".. ::msgcat::mcset pt "&Delete" "Excluir".. ::msgcat::mcset pt "Details >>" "Detalhes >>".. ::msgcat::mcset pt "D
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8620
          Entropy (8bit):4.477728981060218
          Encrypted:false
          SSDEEP:
          MD5:C69A904A57FDC95520086E9DDFED362C
          SHA1:F0220602ABE91FE563E5AA6A4EA4AB43818C0CFC
          SHA-256:F0D310A2EE9C0AF928D822CBB39BCBE54FB2C1C95EE8167DFFD55EDC1B2FE040
          SHA-512:808B82F29B7BA06AF5AE44C6C23EC8DD743E93B391F060C7586D6D3FF26C97294BD11AD215848EBA422491BD50C4509330DD24C83134C7A384E81304133CAADB
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset ru "&Abort" "&\u041e\u0442\u043c\u0435\u043d\u0438\u0442\u044c".. ::msgcat::mcset ru "&About..." "\u041f\u0440\u043e...".. ::msgcat::mcset ru "All Files" "\u0412\u0441\u0435 \u0444\u0430\u0439\u043b\u044b".. ::msgcat::mcset ru "Application Error" "\u041e\u0448\u0438\u0431\u043a\u0430 \u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435".. ::msgcat::mcset ru "&Apply" "&\u041f\u0440\u0438\u043c\u0435\u043d\u0438\u0442\u044c".. ::msgcat::mcset ru "Bold" "Bold".. ::msgcat::mcset ru "Bold Italic" "Bold Italic".. ::msgcat::mcset ru "&Blue" " &\u0413\u043e\u043b\u0443\u0431\u043e\u0439".. ::msgcat::mcset ru "Cancel" "\u041e\u0442\u043c\u0435\u043d\u0430".. ::msgcat::mcset ru "&Cancel" "\u041e\u0442&\u043c\u0435\u043d\u0430".. ::msgcat::mcset ru "Cannot change to the directory \"%1\$s\".\nPermission denied." \....."\u041d\u0435 \u043c\u043e\u0433\u0443 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0432 \u043a\u043
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3908
          Entropy (8bit):4.658068191079967
          Encrypted:false
          SSDEEP:
          MD5:1D085A672A6FCDECEF5D7D876E4C74A3
          SHA1:1A40C03F15A6926359CA3E5C0A809485CAD28AEE
          SHA-256:A6821A13D34FB31F1827294B82C4BF9586BB255CA14F78C3ACE11181F42EF211
          SHA-512:981EDEEF5E4C915BB8F10044096B412D1855CAD08F98A448C6C0A49A54222945EBD102DDCB9525535E0FB19313C319155FA59384605B2C36CC8B4A58693D57E7
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset sv "&Abort" "&Avsluta".. ::msgcat::mcset sv "&About..." "&Om...".. ::msgcat::mcset sv "All Files" "Samtliga filer".. ::msgcat::mcset sv "Application Error" "Programfel".. ::msgcat::mcset sv "&Blue" "&Bl\u00e5".. ::msgcat::mcset sv "Cancel" "Avbryt".. ::msgcat::mcset sv "&Cancel" "&Avbryt".. ::msgcat::mcset sv "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan ej n\u00e5 mappen \"%1\$s\".\nSaknar r\u00e4ttigheter.".. ::msgcat::mcset sv "Choose Directory" "V\u00e4lj mapp".. ::msgcat::mcset sv "Cl&ear" "&Radera".. ::msgcat::mcset sv "&Clear Console" "&Radera konsollen".. ::msgcat::mcset sv "Color" "F\u00e4rg".. ::msgcat::mcset sv "Console" "Konsoll".. ::msgcat::mcset sv "&Copy" "&Kopiera".. ::msgcat::mcset sv "Cu&t" "Klipp u&t".. ::msgcat::mcset sv "&Delete" "&Radera".. ::msgcat::mcset sv "Details >>" "Detaljer >>".. ::msgcat::mcset sv "Directory \"%1\$s\" does not exist." "Mapp
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Unicode text, UTF-8 text, with CRLF line terminators
          Category:dropped
          Size (bytes):4951
          Entropy (8bit):5.319678095131993
          Encrypted:false
          SSDEEP:
          MD5:1435107EB17A09E4AD7277FFA1C76913
          SHA1:9990C26829275F16C6FC494D32C4298EC541E7D3
          SHA-256:B6802B7B080A2D8BC3D81614EC55A609CB5EF673C7A81E93E07925D6710F90DD
          SHA-512:4B2CAE4FA135411761D5B7CBFFABCE87D745A9B6496C7FD7C4AF10E76EE36E51CA62A1417CF6C27070EFF9539A305BE45C010AE4F8532C8C2D915FA101F5157E
          Malicious:false
          Reputation:unknown
          Preview:namespace eval ::tk {.. ::msgcat::mcset zh_cn "&Abort" "&..".. ::msgcat::mcset zh_cn "&About..." "&....".. ::msgcat::mcset zh_cn "All Files" "....".. ::msgcat::mcset zh_cn "Application Error" "......".. ::msgcat::mcset zh_cn "&Apply" "&..".. ::msgcat::mcset zh_cn "Bold" "..".. ::msgcat::mcset zh_cn "Bold Italic" "....".. ::msgcat::mcset zh_cn "&Blue" "&..".. ::msgcat::mcset zh_cn "Cancel" "..".. ::msgcat::mcset zh_cn "&Cancel" "&..".. ::msgcat::mcset zh_cn "Cannot change to the directory \"%1\$s\".\nPermission denied." "...... \"%1\$s\".\n......".. ::msgcat::mcset zh_cn "Choose Directory" ".....".. ::msgcat::mcset zh_cn "Cl&ear" ".&.".. ::msgcat::mcset zh_cn "&Clear Console" "&....".. ::msgcat::mcset zh_cn "Color" "..".. ::msgcat::mcset zh_cn "Console" "..".. ::msgcat::mcset zh_cn "&Copy" "&..".. ::msgcat::mcset zh
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5772
          Entropy (8bit):5.038729016734604
          Encrypted:false
          SSDEEP:
          MD5:FC9E03823BEB08DAF7681C09D106DF7D
          SHA1:7D06FC8F98140E0FFAA2571BD522FC772E58DE54
          SHA-256:540EEECBA17207A56290BAFFDAE882BBD4F88364791204AD5D14C7BEDD022CCC
          SHA-512:2B5BAD311A703A0FE2ED67ACE311BAD4C767BCD23DFC3D9ABDF5C3604146A6A15D6BD13A14BDEFCDB2B602C708AACFAB404E96FCBA7C546AD0DAECD4BE2EB34A
          Malicious:false
          Reputation:unknown
          Preview:# obsolete.tcl --..#..# This file contains obsolete procedures that people really shouldn't..# be using anymore, but which are kept around for backward compatibility...#..# Copyright (c) 1994 The Regents of the University of userfornia...# Copyright (c) 1994 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# The procedures below are here strictly for backward compatibility with..# Tk version 3.6 and earlier. The procedures are no longer needed, so..# they are no-ops. You should not use these procedures anymore, since..# they may be removed in some future release.....proc tk_menuBar args {}..proc tk_bindForTraversal args {}....# ::tk::classic::restore --..#..# Restore the pre-8.5 (Tk classic) look as the widget defaults for classic..# Tk widgets...#..# The value following an 'option add' call is the new 8.5 value...#..namespace eval ::tk::classic {.. # This may need t
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1629
          Entropy (8bit):4.784780799273752
          Encrypted:false
          SSDEEP:
          MD5:9B7A8FD2C6B538FF31BDC380452C6DE3
          SHA1:3F915BFE85CED9F6C7E9A352718770E9F14F098E
          SHA-256:40CA505C9784B0767D4854485C5C311829594A4FCBDFD7251E60E6BB7EA74FD1
          SHA-512:43937152B844BE1E597E99DA1270E54AB1D572AE89CB759E6D41C18C9C8044CCC15A6925F9C5AF617AE9EC1404E78C2733231F4D5C6CFE4D23C546387B1FC328
          Malicious:false
          Reputation:unknown
          Preview:# optMenu.tcl --..#..# This file defines the procedure tk_optionMenu, which creates..# an option button and its associated menu...#..# Copyright (c) 1994 The Regents of the University of userfornia...# Copyright (c) 1994 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_optionMenu --..# This procedure creates an option button named $w and an associated..# menu. Together they provide the functionality of Motif option menus:..# they can be used to select one of many values, and the current value..# appears in the global variable varName, as well as in the text of..# the option menubutton. The name of the menu is returned as the..# procedure's result, so that the caller can use it to change configuration..# options on the menu or otherwise manipulate it...#..# Arguments:..# w -...The name to use for the menubutton...# varName -..Global variable to hold the currently
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8418
          Entropy (8bit):4.964814946573677
          Encrypted:false
          SSDEEP:
          MD5:4CE08A10CD9AE941654B8C679DF669F3
          SHA1:F1288BABCA698FD18C3BD221E6AE6C02F2975AAE
          SHA-256:849B4C57E4644E51BEAEAEB3AE59B7FF067E582ECD10F1B2CAF6B6E72F11F506
          SHA-512:0F37539DA3540E9B1DA7B0377E3BBB359B71DB4271D63BC9501E95931B4E609E8CB91DC2F7B08A6452598D4A0D58C6A2034049A215000EEF0F93A9963D003632
          Malicious:false
          Reputation:unknown
          Preview:# palette.tcl --..#..# This file contains procedures that change the color palette used..# by Tk...#..# Copyright (c) 1995-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_setPalette --..# Changes the default color scheme for a Tk application by setting..# default colors in the option database and by modifying all of the..# color options for existing widgets that have the default value...#..# Arguments:..# The arguments consist of either a single color name, which..# will be used as the new background color (all other colors will..# be computed from this) or an even number of values consisting of..# option names and values. The name for an option is the one used..# for the option database, such as activeForeground, not -activeforeground.....proc ::tk_setPalette {args} {.. if {[winfo depth .] == 1} {...# Just return on monochrome displays, otherwise errors
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5370
          Entropy (8bit):4.979530133775421
          Encrypted:false
          SSDEEP:
          MD5:286C01A1B12261BC47F5659FD1627ABD
          SHA1:4CA36795CAB6DFE0BBBA30BB88A2AB71A0896642
          SHA-256:AA4F87E41AC8297F51150F2A9F787607690D01793456B93F0939C54D394731F9
          SHA-512:D54D5A89B7408A9724A1CA1387F6473BDAD33885194B2EC5A524C7853A297FD65CE2A57F571C51DB718F6A00DCE845DE8CF5F51698F926E54ED72CDC81BCFE54
          Malicious:false
          Reputation:unknown
          Preview:# panedwindow.tcl --..#..# This file defines the default bindings for Tk panedwindow widgets and..# provides procedures that help in implementing those bindings.....bind Panedwindow <Button-1> { ::tk::panedwindow::MarkSash %W %x %y 1 }..bind Panedwindow <Button-2> { ::tk::panedwindow::MarkSash %W %x %y 0 }....bind Panedwindow <B1-Motion> { ::tk::panedwindow::DragSash %W %x %y 1 }..bind Panedwindow <B2-Motion> { ::tk::panedwindow::DragSash %W %x %y 0 }....bind Panedwindow <ButtonRelease-1> {::tk::panedwindow::ReleaseSash %W 1}..bind Panedwindow <ButtonRelease-2> {::tk::panedwindow::ReleaseSash %W 0}....bind Panedwindow <Motion> { ::tk::panedwindow::Motion %W %x %y }....bind Panedwindow <Leave> { ::tk::panedwindow::Leave %W }....# Initialize namespace..namespace eval ::tk::panedwindow {}....# ::tk::panedwindow::MarkSash --..#..# Handle marking the correct sash for possible dragging..#..# Arguments:..# w..the widget..# x..widget local x coord..# y..widget local y coord..# proxy.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):376
          Entropy (8bit):5.040809246948068
          Encrypted:false
          SSDEEP:
          MD5:8A0517A7A4C70111080ED934329E2BC5
          SHA1:5B465E0D3500A8F04EE1C705662032F44E2ED0D2
          SHA-256:A5D208887A94832328C3A33928A80F3B46AA205C20DB4F050A47D940E94071B4
          SHA-512:D9F502A006A5E0514FD61426818AD1F4168E449588F9D383D6B0BF87A18BE82C420863A9A28E1BEB441284A0B1BC2A0B3D3276A0FE3196341AEC15A27920DE5D
          Malicious:false
          Reputation:unknown
          Preview:if {![package vsatisfies [package provide Tcl] 8.6.0]} return..if {($::tcl_platform(platform) eq "unix") && ([info exists ::env(DISPLAY)]...|| ([info exists ::argv] && ("-display" in $::argv)))} {.. package ifneeded Tk 8.6.13 [list load [file join $dir .. .. bin libtk8.6.dll]]..} else {.. package ifneeded Tk 8.6.13 [list load [file join $dir .. .. bin tk86t.dll]]..}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):7632
          Entropy (8bit):4.891666209090638
          Encrypted:false
          SSDEEP:
          MD5:21A3AC11146EC26784C0E729D8D644D0
          SHA1:C7E0918E8692C42C1D1DD1BBCBFFF22A85979B69
          SHA-256:579701605669AADFFBCDB7E3545C68442495428EE6E93C2D3A3133583BCD3D33
          SHA-512:724ED83B989AD9033BEC4211EE50E4C9E85B51054C518CDF7E02D0ED0416F636B9F38C0B0D29F8F4F7F465B77C7D2E01D0918D2C2C3FEC4C7739EA982302FA2E
          Malicious:false
          Reputation:unknown
          Preview:# safetk.tcl --..#..# Support procs to use Tk in safe interpreters...#..# Copyright (c) 1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# see safetk.n for documentation....#..#..# Note: It is now ok to let untrusted code being executed..# between the creation of the interp and the actual loading..# of Tk in that interp because the C side Tk_Init will..# now look up the parent interp and ask its safe::TkInit..# for the actual parameters to use for it's initialization (if allowed),..# not relying on the child state...#....# We use opt (optional arguments parsing)..package require opt 0.4.1;....namespace eval ::safe {.... # counter for safe toplevels.. variable tkSafeId 0..}....#..# tkInterpInit : prepare the child interpreter for tk loading..# most of the real job is done by loadTk..# returns the child name (tkInterpInit
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8693
          Entropy (8bit):4.968450834020619
          Encrypted:false
          SSDEEP:
          MD5:D45202D3D2D052D4C6BFE8D1322AAB39
          SHA1:8CDF184AC2E9299B2B2A107A64E9D1803AA298DE
          SHA-256:0747A387FDD1B2C7135ECEAE7B392ED52E1D1EBF3FFA90FEBE886DBC0981EB74
          SHA-512:27B005F955BAE00D15C4492E7BD3EBDC5EE3BF9C164C418198B4BD185709C8810AA6CF76CBCC07EEB4C1D20F8C76EF8DF8B219563C18B88C94954C910BFF575D
          Malicious:false
          Reputation:unknown
          Preview:# scale.tcl --..#..# This file defines the default bindings for Tk scale widgets and provides..# procedures that help in implementing the bindings...#..# Copyright (c) 1994 The Regents of the University of userfornia...# Copyright (c) 1994-1995 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for entries...#-------------------------------------------------------------------------....# Standard Motif bindings:....bind Scale <Enter> {.. if {$tk_strictMotif} {...set tk::Priv(activeBg) [%W cget -activebackground]...%W configure -activebackground [%W cget -background].. }.. tk::ScaleActivate %W %x %y..}..bind Scale <Motion> {.. tk::ScaleActivate %W %x %y..}..bind Scale <Leave> {.. if {$tk_strictMotif} {...%W configure -activebackground
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):13188
          Entropy (8bit):5.063842571848725
          Encrypted:false
          SSDEEP:
          MD5:5249CD1E97E48E3D6DEC15E70B9D7792
          SHA1:612E021BA25B5E512A0DFD48B6E77FC72894A6B9
          SHA-256:EEC90404F702D3CFBFAEC0F13BF5ED1EBEB736BEE12D7E69770181A25401C61F
          SHA-512:E4E0AB15EB9B3118C30CD2FF8E5AF87C549EAA9B640FFD809A928D96B4ADDEFB9D25EFDD1090FBD0019129CDF355BB2F277BC7194001BA1D2ED4A581110CEAFC
          Malicious:false
          Reputation:unknown
          Preview:# scrlbar.tcl --..#..# This file defines the default bindings for Tk scrollbar widgets...# It also provides procedures that help in implementing the bindings...#..# Copyright (c) 1994 The Regents of the University of userfornia...# Copyright (c) 1994-1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for scrollbars...#-------------------------------------------------------------------------....# Standard Motif bindings:..if {[tk windowingsystem] eq "x11" || [tk windowingsystem] eq "aqua"} {....bind Scrollbar <Enter> {.. if {$tk_strictMotif} {...set tk::Priv(activeBg) [%W cget -activebackground]...%W configure -activebackground [%W cget -background].. }.. %W activate [%W identify %x %y]..}..bind Scrollbar <Motion> {.. %W activate [%
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):16543
          Entropy (8bit):5.034958189335699
          Encrypted:false
          SSDEEP:
          MD5:EAA36F0AA69AE19DDBDD0448FBAD9D4D
          SHA1:EB0ADB4F4D937BAC2F17480ADAF6F948262E754D
          SHA-256:747889C3086C917A34554A9DC495BC0C08A03FD3A5828353ED2A64B97F376835
          SHA-512:C8368F19EC6842ED67073B9FC9C9274107E643324CB23B28C54DF63FB720F63B043281B30DBEA053D08481B0442A87465F715A8AA0711B01CE83FF7B9F8A4F4C
          Malicious:false
          Reputation:unknown
          Preview:# spinbox.tcl --..#..# This file defines the default bindings for Tk spinbox widgets and provides..# procedures that help in implementing those bindings. The spinbox builds..# off the entry widget, so it can reuse Entry bindings and procedures...#..# Copyright (c) 1992-1994 The Regents of the University of userfornia...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1999-2000 Jeffrey Hobbs..# Copyright (c) 2000 Ajuba Solutions..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button went down (so, for example,..#.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):20523
          Entropy (8bit):4.786929402401609
          Encrypted:false
          SSDEEP:
          MD5:9378397DD3DCA9DFB181F6F512B15631
          SHA1:4F95DD6B658B6A912725DC7D6226F8414020D6C7
          SHA-256:B04B1A675572E6FCD12C5FE82C4FD0930395548436FF93D848BF340AE202E7E3
          SHA-512:D28CC3C8F3D0B1B2371CBD9EE29AC6881BABD8A07C762FF8F3284449998EE44FA44752CC8AB0DE47A3492776CE1D13BC8EA18CFDBDF710639D2D62D02CB917A9
          Malicious:false
          Reputation:unknown
          Preview:# Tcl autoload index file, version 2.0..# This file is generated by the "auto_mkindex" command..# and sourced to set up indexing information for one or..# more commands. Typically each line is a command that..# sets an element in the auto_index array, where the..# element name is the name of a command and the value is..# a script that loads the command.....set auto_index(::tk::dialog::error::Return) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::Details) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::SaveToLog) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::Destroy) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::bgerror) [list source [file join $dir bgerror.tcl]]..set auto_index(bgerror) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::ButtonInvoke) [list source [file join $dir button.tcl]]..set auto_index(::tk::ButtonAutoInvoke) [list sou
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5309
          Entropy (8bit):4.74935501162253
          Encrypted:false
          SSDEEP:
          MD5:5F042DE8AD8941C7B9EF6D7BE06C86E4
          SHA1:A4DFCEA2ACCAC2E85EAAA186DC765086D1E3AA3C
          SHA-256:A4A8568633F827B54326640E6D1C3FDE4978EDC9E9FA1FB1D7B58F189DF1B1DC
          SHA-512:E92A00028696A1557666CAB1C25AE6B63F25D75A9811BFAC56DFC069ECC769CC751B71CC81FA85C9CDE8F7FB6D7121EB64B58548CEE8AFE3F6C4A5C243507216
          Malicious:false
          Reputation:unknown
          Preview:# tearoff.tcl --..#..# This file contains procedures that implement tear-off menus...#..# Copyright (c) 1994 The Regents of the University of userfornia...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk::TearoffMenu --..# Given the name of a menu, this procedure creates a torn-off menu..# that is identical to the given menu (including nested submenus)...# The new torn-off menu exists as a toplevel window managed by the..# window manager. The return value is the name of the new menu...# The window is created at the point specified by x and y..#..# Arguments:..# w -...The menu to be torn-off (duplicated)...# x -...x coordinate where window is created..# y -...y coordinate where window is created....proc ::tk::TearOffMenu {w {x 0} {y 0}} {.. # Find a unique name to use for the torn-off menu. Find the first.. # ancestor of w that is a
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):34969
          Entropy (8bit):4.95825801435303
          Encrypted:false
          SSDEEP:
          MD5:9CA5094ED6FE46620ABF090BF8E2AE63
          SHA1:60DC3C2E3F69CE5B6DB4F2B3A1F3C109D766BC63
          SHA-256:AB88556E349F03BACA2D8DC2121071A4F299DB86F484CAB2D9249FF4C7007564
          SHA-512:0B0C20A754BE744A7FA214BA06AB0744A9BC466D51F96310D97EA1E61119A8ACFEF24E6DC5C4EBDD2C126BF84ACE74FFE622E9641C87E5A240DD13D1F7B5E6AF
          Malicious:false
          Reputation:unknown
          Preview:# text.tcl --..#..# This file defines the default bindings for Tk text widgets and provides..# procedures that help in implementing the bindings...#..# Copyright (c) 1992-1994 The Regents of the University of userfornia...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1998 by Scriptics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of ::tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# char -..Character position on the line; kept in order..#...to allow moving up or down past short lines while..#...still remembering the desired position...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button we
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):24102
          Entropy (8bit):5.137459715823081
          Encrypted:false
          SSDEEP:
          MD5:184D05201893B2042D3FA6140FCF277C
          SHA1:AAD67797864456749ADF0C4A1C0BE52F563C8FB8
          SHA-256:1D5E7518AFC1382E36BF13FC5196C8A7CD93A4E9D24ACF445522564245A489B0
          SHA-512:291BDF793CABC5EC27E8265A8A313FE0F4ACAB4DB6CE507A46488A83EEF72CD43CF5815762B22D1C8D64A9EEDEA927E109F937E6573058E5493B1354DD449CB3
          Malicious:false
          Reputation:unknown
          Preview:# tk.tcl --..#..# Initialization script normally executed in the interpreter for each Tk-based..# application. Arranges class bindings for widgets...#..# Copyright (c) 1992-1994 The Regents of the University of userfornia...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Ajuba Solutions...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES.....# Verify that we have Tk binary and script components from the same release..package require -exact Tk 8.6.13.....# Create a ::tk namespace..namespace eval ::tk {.. # Set up the msgcat commands.. namespace eval msgcat {...namespace export mc mcmax.. if {[interp issafe] || [catch {package require msgcat}]} {.. # The msgcat package is not available. Supply our own.. # minimal replacement... proc mc {src args} {.. return [format $src {*}$args].. }.. proc mc
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):39557
          Entropy (8bit):5.186073482848965
          Encrypted:false
          SSDEEP:
          MD5:670837EBC804E7B6E2F65F840BC508D6
          SHA1:2DD316487F87DDE5D05F65F564CAE4E1306CE662
          SHA-256:3AAA66AE8E74B94481C3F6642634E78BB5D7892771E7C27B54DFA56DED0B2F3C
          SHA-512:BB8350ADDF1A25C037DFD60A4AFCBF401CACAD2A370B60BD0BA0981D938C46394BD8D40D1E9A66F4E3C46FCC2A41CF688E78C4F1FE918B45E70D3E92D8B3D116
          Malicious:false
          Reputation:unknown
          Preview:# tkfbox.tcl --..#..#.Implements the "TK" standard file selection dialog box. This dialog..#.box is used on the Unix platforms whenever the tk_strictMotif flag is..#.not set...#..#.The "TK" standard file selection dialog box is similar to the file..#.selection dialog box on Win95(TM). The user can navigate the..#.directories by clicking on the folder icons or by selecting the..#."Directory" option menu. The user can select files by clicking on the..#.file icons or by entering a filename in the "Filename:" entry...#..# Copyright (c) 1994-1998 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {.. namespace import -force ::tk::msgcat::*.. variable showHiddenBtn 0.. variable showHiddenVar 1.... # Create the images if they did not already exist... if {![info exists ::tk::Priv(updirImage)]} {...s
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3713
          Entropy (8bit):4.915055696129498
          Encrypted:false
          SSDEEP:
          MD5:01F28512E10ACBDDF93AE2BB29E343BC
          SHA1:C9CF23D6315218B464061F011E4A9DC8516C8F1F
          SHA-256:AE0437FB4E0EBD31322E4EACA626C12ABDE602DA483BB39D0C5EE1BC00AB0AF4
          SHA-512:FE3BAE36DDB67F6D7A90B7A91B6EC1A009CF26C0167C46635E5A9CEAEC9083E59DDF74447BF6F60399657EE9604A2314B170F78A921CF948B2985DDF02A89DA6
          Malicious:false
          Reputation:unknown
          Preview:#..# Ttk widget set: Alternate theme..#....namespace eval ttk::theme::alt {.... variable colors.. array set colors {...-frame .."#d9d9d9"...-window.."#ffffff"...-darker ."#c3c3c3"...-border.."#414141"...-activebg ."#ececec"...-disabledfg."#a3a3a3"...-selectbg."#4a6984"...-selectfg."#ffffff"...-altindicator."#aaaaaa".. }.... ttk::style theme settings alt {.....ttk::style configure "." \... -background .$colors(-frame) \... -foreground .black \... -troughcolor.$colors(-darker) \... -bordercolor.$colors(-border) \... -selectbackground .$colors(-selectbg) \... -selectforeground .$colors(-selectfg) \... -font ..TkDefaultFont \... ;.....ttk::style map "." -background \... [list disabled $colors(-frame) active $colors(-activebg)] ;...ttk::style map "." -foreground [list disabled $colors(-disabledfg)] ;.. ttk::style map "." -embossed [list disabled 1] ;.....ttk::style configure TButton \... -anchor center -width -11 -padding "1 1" \... -reli
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3838
          Entropy (8bit):4.940737732832436
          Encrypted:false
          SSDEEP:
          MD5:F07A3A86362E9E253BE91F59714FE134
          SHA1:84DE1AB2EAE62E4B114F0E613BD94955AFA9E6C7
          SHA-256:E199CC9C429B35A09721D0A22543C3729E2B8462E68DFA158C0CEC9C70A0D79D
          SHA-512:324EAF9F857076CA4FECB26D8DF76F8BB1D3F15EAE55D6B6C9689BF1682B306AC7A3592B6A518D23F9FE4DC21EFB6ACF1ECA948F889FA1ADFFA0E12C0BEAB57F
          Malicious:false
          Reputation:unknown
          Preview:#..# Aqua theme (OSX native look and feel)..#....namespace eval ttk::theme::aqua {.. ttk::style theme settings aqua {.....ttk::style configure . \... -font TkDefaultFont \... -background systemWindowBackgroundColor \... -foreground systemLabelColor \... -selectbackground systemSelectedTextBackgroundColor \... -selectforeground systemSelectedTextColor \... -selectborderwidth 0 \... -insertwidth 1.....ttk::style map . \... -foreground {....disabled systemDisabledControlTextColor....background systemLabelColor} \... -selectbackground {....background systemSelectedTextBackgroundColor....!focus systemSelectedTextBackgroundColor} \... -selectforeground {....background systemSelectedTextColor....!focus systemSelectedTextColor}.....# Button...ttk::style configure TButton -anchor center -width -6 \... -foreground systemControlTextColor...ttk::style map TButton \... -foreground {....pressed white... {alternate !pressed !background} white}...ttk::styl
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3014
          Entropy (8bit):4.917794267131833
          Encrypted:false
          SSDEEP:
          MD5:D4BF1AF5DCDD85E3BD11DBF52EB2C146
          SHA1:B1691578041319E671D31473A1DD404855D2038B
          SHA-256:E38A9D1F437981AA6BF0BDD074D57B769A4140C0F7D9AFF51743FE4ECC6DFDDF
          SHA-512:25834B4B231F4FF1A88EEF67E1A102D1D0546EC3B0D46856258A6BE6BBC4B381389C28E2EB60A01FF895DF24D6450CD16CA449C71F82BA53BA438A4867A47DCD
          Malicious:false
          Reputation:unknown
          Preview:#..# Bindings for Buttons, Checkbuttons, and Radiobuttons...#..# Notes: <Button1-Leave>, <Button1-Enter> only control the "pressed"..# state; widgets remain "active" if the pointer is dragged out...# This doesn't seem to be conventional, but it's a nice way..# to provide extra feedback while the grab is active...# (If the button is released off the widget, the grab deactivates and..# we get a <Leave> event then, which turns off the "active" state)..#..# Normally, <ButtonRelease> and <ButtonN-Enter/Leave> events are..# delivered to the widget which received the initial <Button>..# event. However, Tk [grab]s (#1223103) and menu interactions..# (#1222605) can interfere with this. To guard against spurious..# <Button1-Enter> events, the <Button1-Enter> binding only sets..# the pressed state if the button is currently active...#....namespace eval ttk::button {}....bind TButton <Enter> ..{ %W instate !disabled {%W state active} }..bind TButton <Leave>..{ %W state !active }..bind TButton <s
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4809
          Entropy (8bit):4.905115353394083
          Encrypted:false
          SSDEEP:
          MD5:2B20E7B2E6BDDBEB14F5F63BF38DBF24
          SHA1:43DB48094C4BD7DE3B76AFBC051D887FEFE9887E
          SHA-256:CFFC59931FDD1683AD23895E92522CF49B099128753FCDFF34374024E42CF995
          SHA-512:1EB5EA78D26D18EAD6563AFBF1798F71723001DCC945E7DB3E4368564D0563029BE3565876AD8CB97331CFE34B2A0A313FA1BF252B87049160FE5DCD65434775
          Malicious:false
          Reputation:unknown
          Preview:#..# "Clam" theme...#..# Inspired by the XFCE family of Gnome themes...#....namespace eval ttk::theme::clam {.. variable colors.. array set colors {...-disabledfg.."#999999"...-frame .."#dcdad5"...-window .."#ffffff"...-dark..."#cfcdc8"...-darker .."#bab5ab"...-darkest.."#9e9a91"...-lighter.."#eeebe7"...-lightest .."#ffffff"...-selectbg.."#4a6984"...-selectfg.."#ffffff"...-altindicator.."#5895bc"...-disabledaltindicator."#a0a0a0".. }.... ttk::style theme settings clam {.....ttk::style configure "." \... -background $colors(-frame) \... -foreground black \... -bordercolor $colors(-darkest) \... -darkcolor $colors(-dark) \... -lightcolor $colors(-lighter) \... -troughcolor $colors(-darker) \... -selectbackground $colors(-selectbg) \... -selectforeground $colors(-selectfg) \... -selectborderwidth 0 \... -font TkDefaultFont \... ;.....ttk::style map "." \... -background [list disabled $colors(-frame) \..... active $colors(-lighter)] \..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3864
          Entropy (8bit):4.935603001745302
          Encrypted:false
          SSDEEP:
          MD5:0205663142775F4EF2EB104661D30979
          SHA1:452A0D613288A1CC8A1181C3CC1167E02AA69A73
          SHA-256:424BBA4FB6836FEEBE34F6C176ED666DCE51D2FBA9A8D7AA756ABCBBAD3FC1E3
          SHA-512:FB4D212A73A6F5A8D2774F43D310328B029B52B35BEE133584D8326363B385AB7AA4AE25E98126324CC716962888321E0006E5F6EF8563919A1D719019B2D117
          Malicious:false
          Reputation:unknown
          Preview:#..# "classic" Tk theme...#..# Implements Tk's traditional Motif-like look and feel...#....namespace eval ttk::theme::classic {.... variable colors; array set colors {...-frame.."#d9d9d9"...-window.."#ffffff"...-activebg."#ececec"...-troughbg."#c3c3c3"...-selectbg."#c3c3c3"...-selectfg."#000000"...-disabledfg."#a3a3a3"...-indicator."#b03060"...-altindicator."#b05e5e".. }.... ttk::style theme settings classic {...ttk::style configure "." \... -font..TkDefaultFont \... -background..$colors(-frame) \... -foreground..black \... -selectbackground.$colors(-selectbg) \... -selectforeground.$colors(-selectfg) \... -troughcolor.$colors(-troughbg) \... -indicatorcolor.$colors(-frame) \... -highlightcolor.$colors(-frame) \... -highlightthickness.1 \... -selectborderwidth.1 \... -insertwidth.2 \... ;.....# To match pre-Xft X11 appearance, use:...#.ttk::style configure . -font {Helvetica 12 bold}.....ttk::style map "." -background \... [list disabled
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):12718
          Entropy (8bit):5.063548300335668
          Encrypted:false
          SSDEEP:
          MD5:F7065D345A4BFB3127C3689BF1947C30
          SHA1:9631C05365B0F5A36E4CA5CBA83628CCD7FCBDE1
          SHA-256:68EED4AF6D2EC5B3EA24B1122A704B040366CBE2F458103137479352FFA1475A
          SHA-512:74B99B9E326680150DD5EC7263192691BCD8A71B2A4EE7F3177DEDDD43E924A7925085C6D372731A70570F96B3924450255B2F54CA3B9C44D1160CA37E715B00
          Malicious:false
          Reputation:unknown
          Preview:#..# Combobox bindings...#..# <<NOTE-WM-TRANSIENT>>:..#..#.Need to set [wm transient] just before mapping the popdown..#.instead of when it's created, in case a containing frame..#.has been reparented [#1818441]...#..#.On Windows: setting [wm transient] prevents the parent..#.toplevel from becoming inactive when the popdown is posted..#.(Tk 8.4.8+)..#..#.On X11: WM_TRANSIENT_FOR on override-redirect windows..#.may be used by compositing managers and by EWMH-aware..#.window managers (even though the older ICCCM spec says..#.it's meaningless)...#..#.On OSX: [wm transient] does utterly the wrong thing...#.Instead, we use [MacWindowStyle "help" "noActivates hideOnSuspend"]...#.The "noActivates" attribute prevents the parent toplevel..#.from deactivating when the popdown is posted, and is also..#.necessary for "help" windows to receive mouse events...#."hideOnSuspend" makes the popdown disappear (resp. reappear)..#.when the parent toplevel is deactivated (resp. reactivated)...#.(see [#18147
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4674
          Entropy (8bit):4.836935825704301
          Encrypted:false
          SSDEEP:
          MD5:1A799FE3754307A5AADE98C367E2F5D7
          SHA1:C64BE4B77F0D298610F4EE20FCEBBAEE3C8B5F22
          SHA-256:5B33F32B0139663347D6CF70A5A838F8E4554E0E881E97C8478B77733162EA73
          SHA-512:89F367F9A59730BCDFC5ABDE0E35A10B72A1F19C68A768BA4524C938EF5C5CAF094C1BFA8FC74173F65201F6617544223C2143252A9F691EE9AAA7543315179F
          Malicious:false
          Reputation:unknown
          Preview:#..# Map symbolic cursor names to platform-appropriate cursors...#..# The following cursors are defined:..#..#.standard.-- default cursor for most controls..#.""..-- inherit cursor from parent window..#.none..-- no cursor..#..#.text..-- editable widgets (entry, text)..#.link..-- hyperlinks within text..#.crosshair.-- graphic selection, fine control..#.busy..-- operation in progress..#.forbidden.-- action not allowed..#..#.hresize..-- horizontal resizing..#.vresize..-- vertical resizing..#..# Also resize cursors for each of the compass points,..# {nw,n,ne,w,e,sw,s,se}resize...#..# Platform notes:..#..# Windows doesn't distinguish resizing at the 8 compass points,..# only horizontal, vertical, and the two diagonals...#..# OSX doesn't have resize cursors for nw, ne, sw, or se corners...# We use the Tk-defined X11 fallbacks for these...#..# X11 doesn't have a "forbidden" cursor (usually a slashed circle);..# "pirate" seems to be the conventional cursor for this purpose...#..# Windows has a
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4553
          Entropy (8bit):4.933885986949396
          Encrypted:false
          SSDEEP:
          MD5:FC79F42761D63172163C08F0F5C94436
          SHA1:AABAB4061597D0D6DC371F46D14AAA1A859096DF
          SHA-256:49AE8FAF169165BDDAF01D50B52943EBAB3656E9468292B7890BE143D0FCBC91
          SHA-512:F619834A95C9DEB93F8184BCC437D701A961C77E24A831ADBD5C145556D26986BFDA2A6ACB9E8784F8B2380E122D12AC893EB1B6ACF03098922889497E1FF9EA
          Malicious:false
          Reputation:unknown
          Preview:#..# Settings for default theme...#....namespace eval ttk::theme::default {.. variable colors.. array set colors {...-frame..."#d9d9d9"...-foreground.."#000000"...-window..."#ffffff"...-text .."#000000"...-activebg.."#ececec"...-selectbg.."#4a6984"...-selectfg.."#ffffff"...-darker .."#c3c3c3"...-disabledfg.."#a3a3a3"...-indicator.."#4a6984"...-disabledindicator."#a3a3a3"...-altindicator.."#9fbdd8"...-disabledaltindicator."#c0c0c0".. }.... ttk::style theme settings default {.....ttk::style configure "." \... -borderwidth .1 \... -background .$colors(-frame) \... -foreground .$colors(-foreground) \... -troughcolor .$colors(-darker) \... -font ..TkDefaultFont \... -selectborderwidth.1 \... -selectbackground.$colors(-selectbg) \... -selectforeground.$colors(-selectfg) \... -insertwidth .1 \... -indicatordiameter.10 \... ;.....ttk::style map "." -background \... [list disabled $colors(-frame) active $colors(-activebg)]...ttk::style map "."
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):17658
          Entropy (8bit):5.026830367336785
          Encrypted:false
          SSDEEP:
          MD5:7FFD7A32C7F8E234763E99E3357DB624
          SHA1:67C67557F3A6DC8B240E85D46F6B733FEE45A013
          SHA-256:266553EB9EED333DD836BA96204AE008F10686F4F12C404187F1E01CAB65D246
          SHA-512:D18B73E44F37ED92B9FD7C1F6510285D1280EB5BC665B46996E538924E9D1CAD63337279BF92587132C3AEA497325A17CCE671EA59537B350F6D921C25346F39
          Malicious:false
          Reputation:unknown
          Preview:#..# DERIVED FROM: tk/library/entry.tcl r1.22..#..# Copyright (c) 1992-1994 The Regents of the University of userfornia...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 2004, Joe English..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....namespace eval ttk {.. namespace eval entry {...variable State.....set State(x) 0...set State(selectMode) none...set State(anchor) 0...set State(scanX) 0...set State(scanIndex) 0...set State(scanMoved) 0.....# Button-2 scan speed is (scanNum/scanDen) characters...# per pixel of mouse movement....# The standard Tk entry widget uses the equivalent of...# scanNum = 10, scanDen = average character width....# I don't know why that was chosen....#...set State(scanNum) 1...set State(scanDen) 1...set State(deadband) 3.;# #pixels for mouse-moved deadband... }..}....### Option database settings...#..option add *TEntry.cursor [ttk::cursor text] widg
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5732
          Entropy (8bit):5.001928619185109
          Encrypted:false
          SSDEEP:
          MD5:80331FCBE4C049FF1A0D0B879CB208DE
          SHA1:4EB3EFDFE3731BD1AE9FD52CE32B1359241F13CF
          SHA-256:B94C319E5A557A5665B1676D602B6495C0887C5BACF7FA5B776200112978BB7B
          SHA-512:A4BD2D91801C121A880225F1F3D0C4E30BF127190CF375F6F7A49EB4239A35C49C44F453D6D3610DF0D6A7B3CB15F4E79BD9C129025CC496CEB856FCC4B6DE87
          Malicious:false
          Reputation:unknown
          Preview:#..# Font specifications...#..# This file, [source]d at initialization time, sets up the following..# symbolic fonts based on the current platform:..#..# TkDefaultFont.-- default for GUI items not otherwise specified..# TkTextFont.-- font for user text (entry, listbox, others)..# TkFixedFont.-- standard fixed width font..# TkHeadingFont.-- headings (column headings, etc)..# TkCaptionFont -- dialog captions (primary text in alert dialogs, etc.)..# TkTooltipFont.-- font to use for tooltip windows..# TkIconFont.-- font to use for icon captions..# TkMenuFont.-- used to use for menu items..#..# In Tk 8.5, some of these fonts may be provided by the TIP#145 implementation..# (On Windows and Mac OS X as of Oct 2007)...#..# +++ Platform notes:..#..# Windows:..#.The default system font changed from "MS Sans Serif" to "Tahoma"..# .in Windows XP/Windows 2000...#..#.MS documentation says to use "Tahoma 8" in Windows 2000/XP,..#.although many MS programs still use "MS Sans Serif 8"..#..#.Should use
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):6443
          Entropy (8bit):4.9213750923402735
          Encrypted:false
          SSDEEP:
          MD5:F11A76FBABF35E446A1200A5A7A6730A
          SHA1:4CBAB3507C1EF275691C98620D2B5CEEB9043B3E
          SHA-256:54663FBF524CAD9D74AB1EC44B7FDDE0B87F06E5347191962C97F51F714E29BB
          SHA-512:95471D1519AE663EC7EB4639D847019E0C9F70DEA2B0680D81FB8BBE7CD1FF643A3DF5E06CA2CC54385BE094BDCC64AB0F1AA1652F91D16C4EF7B68CB670371E
          Malicious:false
          Reputation:unknown
          Preview:#..# Bindings for Menubuttons...#..# Menubuttons have three interaction modes:..#..# Pulldown: Press menubutton, drag over menu, release to activate menu entry..# Popdown: Click menubutton to post menu..# Keyboard: <space> or accelerator key to post menu..#..# (In addition, when menu system is active, "dropdown" -- menu posts..# on mouse-over. Ttk menubuttons don't implement this)...#..# For keyboard and popdown mode, we hand off to tk_popup and let..# the built-in Tk bindings handle the rest of the interaction...#..# ON X11:..#..# Standard Tk menubuttons use a global grab on the menubutton...# This won't work for Ttk menubuttons in pulldown mode,..# since we need to process the final <ButtonRelease> event,..# and this might be delivered to the menu. So instead we..# rely on the passive grab that occurs on <Button> events,..# and transition to popdown mode when the mouse is released..# or dragged outside the menubutton...#..# ON WINDOWS:..#..# I'm not sure what the hell is going on h
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5825
          Entropy (8bit):4.96378772387536
          Encrypted:false
          SSDEEP:
          MD5:F811F3E46A4EFA73292F40D1CDDD265D
          SHA1:7FC70A1984555672653A0840499954B854F27920
          SHA-256:22264D8D138E2C0E9A950305B4F08557C5A73F054F8215C0D8CE03854042BE76
          SHA-512:4424B7C687EB9B1804ED3B1C685F19D4D349753B374D9046240F937785C9713E8A760ADA46CB628C15F9C7983CE4A7987691C968330478C9C1A9B74E953E40AC
          Malicious:false
          Reputation:unknown
          Preview:#..# Bindings for TNotebook widget..#....namespace eval ttk::notebook {.. variable TLNotebooks ;# See enableTraversal..}....bind TNotebook <Button-1>..{ ttk::notebook::Press %W %x %y }..bind TNotebook <Right>...{ ttk::notebook::CycleTab %W 1; break }..bind TNotebook <Left>...{ ttk::notebook::CycleTab %W -1; break }..bind TNotebook <Control-Tab>..{ ttk::notebook::CycleTab %W 1; break }..bind TNotebook <Control-Shift-Tab>.{ ttk::notebook::CycleTab %W -1; break }..catch {..bind TNotebook <Control-ISO_Left_Tab>.{ ttk::notebook::CycleTab %W -1; break }..}..bind TNotebook <Destroy>..{ ttk::notebook::Cleanup %W }....# ActivateTab $nb $tab --..#.Select the specified tab and set focus...#..# Desired behavior:..#.+ take focus when reselecting the currently-selected tab;..#.+ keep focus if the notebook already has it;..#.+ otherwise set focus to the first traversable widget..#. in the newly-selected tab;..#.+ do not leave the focus in a deselected tab...#..proc ttk::notebook::ActivateTab {
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2274
          Entropy (8bit):4.951790637542993
          Encrypted:false
          SSDEEP:
          MD5:848A62BCF6ED3C16A8CFD26C43E1BC4E
          SHA1:6F5E3EDF62716B511CF575BE2C6C997AFA2FA1E7
          SHA-256:20EE6AD9D701709724292A926AF93C93784B254B48A656ECC140EF3A0FE10A11
          SHA-512:AE78028EAF96E5B77DEFF0CD655360DB3A8058AC98B6753D9B77D629EDFFC582999A22A7075B9F5BA83EE65DA093E2CCB0EEAA4049898910D7AF517FDE60B28E
          Malicious:false
          Reputation:unknown
          Preview:#..# Bindings for ttk::panedwindow widget...#....namespace eval ttk::panedwindow {.. variable State.. array set State {...pressed 0.. .pressX.-...pressY.-...sash .-...sashPos -.. }..}....## Bindings:..#..bind TPanedwindow <Button-1> ..{ ttk::panedwindow::Press %W %x %y }..bind TPanedwindow <B1-Motion>..{ ttk::panedwindow::Drag %W %x %y }..bind TPanedwindow <ButtonRelease-1> .{ ttk::panedwindow::Release %W %x %y }....bind TPanedwindow <Motion> ..{ ttk::panedwindow::SetCursor %W %x %y }..bind TPanedwindow <Enter> ..{ ttk::panedwindow::SetCursor %W %x %y }..bind TPanedwindow <Leave> ..{ ttk::panedwindow::ResetCursor %W }..# See <<NOTE-PW-LEAVE-NOTIFYINFERIOR>>..bind TPanedwindow <<EnteredChild>>.{ ttk::panedwindow::ResetCursor %W }....## Sash movement:..#..proc ttk::panedwindow::Press {w x y} {.. variable State.... set sash [$w identify $x $y].. if {$sash eq ""} {.. .set State(pressed) 0...return.. }.. set State(pressed) .1.. set State(pressX) .$x.. set
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1138
          Entropy (8bit):4.763501917862434
          Encrypted:false
          SSDEEP:
          MD5:DBF3BF0E8F04E9435E9561F740DFC700
          SHA1:C7619A05A834EFB901C57DCFEC2C9E625F42428F
          SHA-256:697CC0A75AE31FE9C2D85FB25DCA0AFA5D0DF9C523A2DFAD2E4A36893BE75FBA
          SHA-512:D3B323DFB3EAC4A78DA2381405925C131A99C6806AF6FD8041102162A44E48BF166982A4AE4AA142A14601736716F1A628D9587E292FA8E4842BE984374CC192
          Malicious:false
          Reputation:unknown
          Preview:#..# Ttk widget set: progress bar utilities...#....namespace eval ttk::progressbar {.. variable Timers.;# Map: widget name -> after ID..}....# Autoincrement --..#.Periodic callback procedure for autoincrement mode..#..proc ttk::progressbar::Autoincrement {pb steptime stepsize} {.. variable Timers.... if {![winfo exists $pb]} {.. .# widget has been destroyed -- cancel timer...unset -nocomplain Timers($pb)...return.. }.... set Timers($pb) [after $steptime \.. .[list ttk::progressbar::Autoincrement $pb $steptime $stepsize] ].... $pb step $stepsize..}....# ttk::progressbar::start --..#.Start autoincrement mode. Invoked by [$pb start] widget code...#..proc ttk::progressbar::start {pb {steptime 50} {stepsize 1}} {.. variable Timers.. if {![info exists Timers($pb)]} {...Autoincrement $pb $steptime $stepsize.. }..}....# ttk::progressbar::stop --..#.Cancel autoincrement mode. Invoked by [$pb stop] widget code...#..proc ttk::progressbar::stop {pb} {.. variabl
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2787
          Entropy (8bit):4.795451191784129
          Encrypted:false
          SSDEEP:
          MD5:F1C33CC2D47115BBECD2E7C2FCB631A7
          SHA1:0123A961242ED8049B37C77C726DB8DBD94C1023
          SHA-256:B909ADD0B87FA8EE08FD731041907212A8A0939D37D2FF9B2F600CD67DABD4BB
          SHA-512:96587A8C3555DA1D810010C10C516CE5CCAB071557A3C8D9BD65C647C7D4AD0E35CBED0788F1D72BAFAC8C84C7E2703FC747F70D9C95F720745A1FC4A701C544
          Malicious:false
          Reputation:unknown
          Preview:# scale.tcl - Copyright (C) 2004 Pat Thoyts <patthoyts@users.sourceforge.net>..#..# Bindings for the TScale widget....namespace eval ttk::scale {.. variable State.. array set State {...dragging 0.. }..}....bind TScale <Button-1> { ttk::scale::Press %W %x %y }..bind TScale <B1-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-1> { ttk::scale::Release %W %x %y }....bind TScale <Button-2> { ttk::scale::Jump %W %x %y }..bind TScale <B2-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-2> { ttk::scale::Release %W %x %y }....bind TScale <Button-3> { ttk::scale::Jump %W %x %y }..bind TScale <B3-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-3> { ttk::scale::Release %W %x %y }....## Keyboard navigation bindings:..#..bind TScale <<LineStart>> { %W set [%W cget -from] }..bind TScale <<LineEnd>> { %W set [%W cget -to] }....bind TScale <<PrevChar>> { ttk::scale::Increment %W -1 }..bin
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):3285
          Entropy (8bit):4.979174619784594
          Encrypted:false
          SSDEEP:
          MD5:3FB31A225CEC64B720B8E579582F2749
          SHA1:9C0151D9E2543C217CF8699FF5D4299A72E8F13C
          SHA-256:6EAA336B13815A7FC18BCD6B9ADF722E794DA2888D053C229044784C8C8E9DE8
          SHA-512:E6865655585E3D2D6839B56811F3FD86B454E8CD44E258BB1AC576AD245FF8A4D49FBB7F43458BA8A6C9DAAC8DFA923A176F0DD8A9976A11BEA09E6E2D17BF45
          Malicious:false
          Reputation:unknown
          Preview:#..# Bindings for TScrollbar widget..#....namespace eval ttk::scrollbar {.. variable State.. # State(xPress).--.. # State(yPress).-- initial position of mouse at start of drag... # State(first).-- value of -first at start of drag...}....bind TScrollbar <Button-1> ..{ ttk::scrollbar::Press %W %x %y }..bind TScrollbar <B1-Motion>..{ ttk::scrollbar::Drag %W %x %y }..bind TScrollbar <ButtonRelease-1>.{ ttk::scrollbar::Release %W %x %y }....bind TScrollbar <Button-2> ..{ ttk::scrollbar::Jump %W %x %y }..bind TScrollbar <B2-Motion>..{ ttk::scrollbar::Drag %W %x %y }..bind TScrollbar <ButtonRelease-2>.{ ttk::scrollbar::Release %W %x %y }....# Redirect scrollwheel bindings to the scrollbar widget..#..# The shift-bindings scroll left/right (not up/down)..# if a widget has both possibilities..set eventList [list <MouseWheel> <Shift-MouseWheel>]..switch [tk windowingsystem] {.. aqua {.. lappend eventList <Option-MouseWheel> <Shift-Option-MouseWheel>.. }.. x11 {..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2503
          Entropy (8bit):4.830288003879418
          Encrypted:false
          SSDEEP:
          MD5:DD6A1737B14D3F7B2A0B4F8BE99C30AF
          SHA1:E6B06895317E73CD3DC78234DD74C74F3DB8C105
          SHA-256:E92D77B5CDCA2206376DB2129E87E3D744B3D5E31FDE6C0BBD44A494A6845CE1
          SHA-512:B74AE92EDD53652F8A3DB0D84C18F9CE9069805BCAB0D3C2DBB537D7C241AA2681DA69B699D88A10029798D7B5BC015682F64699BA475AE6A379EEF23B48DAAF
          Malicious:false
          Reputation:unknown
          Preview:#..# Sizegrip widget bindings...#..# Dragging a sizegrip widget resizes the containing toplevel...#..# NOTE: the sizegrip widget must be in the lower right hand corner...#....switch -- [tk windowingsystem] {.. x11 -.. win32 {...option add *TSizegrip.cursor [ttk::cursor seresize] widgetDefault.. }.. aqua {.. .# Aqua sizegrips use default Arrow cursor... }..}....namespace eval ttk::sizegrip {.. variable State.. array set State {...pressed .0...pressX ..0...pressY ..0...width ..0...height ..0...widthInc.1...heightInc.1.. resizeX 1.. resizeY 1...toplevel .{}.. }..}....bind TSizegrip <Button-1> ..{ ttk::sizegrip::Press.%W %X %Y }..bind TSizegrip <B1-Motion> ..{ ttk::sizegrip::Drag .%W %X %Y }..bind TSizegrip <ButtonRelease-1> .{ ttk::sizegrip::Release %W %X %Y }....proc ttk::sizegrip::Press {W X Y} {.. variable State.... if {[$W instate disabled]} { return }.... set top [winfo toplevel $W].... # If the toplevel is not resi
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):5003
          Entropy (8bit):5.055050310142795
          Encrypted:false
          SSDEEP:
          MD5:9C2833FAA9248F09BC2E6AB1BA326D59
          SHA1:F13CF048FD706BBB1581DC80E33D1AAD910D93E8
          SHA-256:DF286BB59F471AA1E19DF39AF0EF7AA84DF9F04DC4A439A747DD8BA43C300150
          SHA-512:5FF3BE1E3D651C145950C3FC5B8C2E842211C937D1042173964383D4D59ECF5DD0EC39FF7771D029716F2D895F0B1A72591EF3BF7947FE64D4D6DB5F0B8ABFFB
          Malicious:false
          Reputation:unknown
          Preview:#..# ttk::spinbox bindings..#....namespace eval ttk::spinbox { }....### Spinbox bindings...#..# Duplicate the Entry bindings, override if needed:..#....ttk::copyBindings TEntry TSpinbox....bind TSpinbox <Motion>...{ ttk::spinbox::Motion %W %x %y }..bind TSpinbox <Button-1> ..{ ttk::spinbox::Press %W %x %y }..bind TSpinbox <ButtonRelease-1> .{ ttk::spinbox::Release %W }..bind TSpinbox <Double-Button-1> .{ ttk::spinbox::DoubleClick %W %x %y }..bind TSpinbox <Triple-Button-1> .{} ;# disable TEntry triple-click....bind TSpinbox <Up>...{ event generate %W <<Increment>> }..bind TSpinbox <Down> ...{ event generate %W <<Decrement>> }....bind TSpinbox <<Increment>>..{ ttk::spinbox::Spin %W +1 }..bind TSpinbox <<Decrement>> ..{ ttk::spinbox::Spin %W -1 }....ttk::bindMouseWheel TSpinbox ..[list ttk::spinbox::MouseWheel %W]....## Motion --..#.Sets cursor...#..proc ttk::spinbox::Motion {w x y} {.. variable State.. ttk::saveCursor $w State(userConfCursor) [ttk::cursor text].. if { [$w ide
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):10180
          Entropy (8bit):4.886259798213254
          Encrypted:false
          SSDEEP:
          MD5:F705B3A292D02061DA0ABB4A8DD24077
          SHA1:FD75C2250F6F66435444F7DEEF383C6397ED2368
          SHA-256:C88B60FFB0F72E095F6FC9786930ADD7F9ED049EABC713F889F9A7DA516E188C
          SHA-512:09817638DD3D3D5C57FA630C7EDF2F19C3956C9BD264DBF07627FA14A03AECD22D5A5319806E49EF1030204FADEF17C57CE8EAE4378A319AD2093321D9151C8F
          Malicious:false
          Reputation:unknown
          Preview:#..# ttk::treeview widget bindings and utilities...#....namespace eval ttk::treeview {.. variable State.... # Enter/Leave/Motion.. #.. set State(activeWidget) .{}.. set State(activeHeading) .{}.... # Press/drag/release:.. #.. set State(pressMode) .none.. set State(pressX)..0.... # For pressMode == "resize".. set State(resizeColumn).#0.... # For pressmode == "heading".. set State(heading) .{}..}....### Widget bindings...#....bind Treeview.<Motion> ..{ ttk::treeview::Motion %W %x %y }..bind Treeview.<B1-Leave>..{ #nothing }..bind Treeview.<Leave>...{ ttk::treeview::ActivateHeading {} {}}..bind Treeview.<Button-1> ..{ ttk::treeview::Press %W %x %y }..bind Treeview.<Double-Button-1> .{ ttk::treeview::DoubleClick %W %x %y }..bind Treeview.<ButtonRelease-1> .{ ttk::treeview::Release %W %x %y }..bind Treeview.<B1-Motion> ..{ ttk::treeview::Drag %W %x %y }..bind Treeview .<Up> ..{ ttk::treeview::Keynav %W up }..bind Treeview .<Down> ..{ ttk::treeview
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):4993
          Entropy (8bit):4.954034141173847
          Encrypted:false
          SSDEEP:
          MD5:AF45B2C8B43596D1BDECA5233126BD14
          SHA1:A99E75D299C4579E10FCDD59389B98C662281A26
          SHA-256:2C48343B1A47F472D1A6B9EE8D670CE7FB428DB0DB7244DC323FF4C7A8B4F64B
          SHA-512:C8A8D01C61774321778AB149F6CA8DDA68DB69133CB5BA7C91938E4FD564160ECDCEC473222AFFB241304A9ACC73A36B134B3A602FD3587C711F2ADBB64AFA80
          Malicious:false
          Reputation:unknown
          Preview:#..# Ttk widget set initialization script...#....### Source library scripts...#....namespace eval ::ttk {.. variable library.. if {![info exists library]} {...set library [file dirname [info script]].. }..}....source -encoding utf-8 [file join $::ttk::library fonts.tcl]..source -encoding utf-8 [file join $::ttk::library cursors.tcl]..source -encoding utf-8 [file join $::ttk::library utils.tcl]....## ttk::deprecated $old $new --..#.Define $old command as a deprecated alias for $new command..#.$old and $new must be fully namespace-qualified...#..proc ttk::deprecated {old new} {.. interp alias {} $old {} ttk::do'deprecate $old $new..}..## do'deprecate --..#.Implementation procedure for deprecated commands --..#.issue a warning (once), then re-alias old to new...#..proc ttk::do'deprecate {old new args} {.. deprecated'warning $old $new.. interp alias {} $old {} $new.. uplevel 1 [linsert $args 0 $new]..}....## deprecated'warning --..#.Gripe about use of deprecated comman
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):8624
          Entropy (8bit):5.001791071900077
          Encrypted:false
          SSDEEP:
          MD5:51086BC3315A4AE4A8591A654CFC3CEA
          SHA1:2AC08309C63575B7A01FA62D3C262643CD8C823A
          SHA-256:4AA041C050758B3331DC395381F7FBCE81E387908FC7A3C6107C4E7140F56F2E
          SHA-512:6D69F7EAC9D5AF3B3EA85AE3E74BDFA6278789502D5E35EFE94349BFC543503BE7540D783D2632E349DD53F21074C702AC1FC487EE70C74234A08397F7238723
          Malicious:false
          Reputation:unknown
          Preview:#..# Utilities for widget implementations...#....### Focus management...#..# See also: #1516479..#....## ttk::takefocus --..#.This is the default value of the "-takefocus" option..#.for ttk::* widgets that participate in keyboard navigation...#..# NOTES:..#.tk::FocusOK (called by tk_focusNext) tests [winfo viewable]..#.if -takefocus is 1, empty, or missing; but not if it's a..#.script prefix, so we have to check that here as well...#..#..proc ttk::takefocus {w} {.. expr {[$w instate !disabled] && [winfo viewable $w]}..}....## ttk::GuessTakeFocus --..#.This routine is called as a fallback for widgets..#.with a missing or empty -takefocus option...#..#.It implements the same heuristics as tk::FocusOK...#..proc ttk::GuessTakeFocus {w} {.. # Don't traverse to widgets with '-state disabled':.. #.. if {![catch {$w cget -state} state] && $state eq "disabled"} {...return 0.. }.... # Allow traversal to widgets with explicit key or focus bindings:.. #.. if {[regexp {Key|F
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):9710
          Entropy (8bit):4.6639701588183895
          Encrypted:false
          SSDEEP:
          MD5:0AA7F8B43C3E07F3A4DA07FC6DF9A1B0
          SHA1:153AFB735B10BBA16CFBE161777232F983845D90
          SHA-256:EC5F203C69DF390E9B99944CF3526D6E77DC6F68E9B1A029F326A41AFED1EF81
          SHA-512:5406553211CD6714C98EF7765ABD46424CCB013343EFF693FDD3AE6E0AAE9B5983446E0E1CC706D6B2C285084BF83D397306D3D52028CBBCFB8F369857C5B69C
          Malicious:false
          Reputation:unknown
          Preview:#..# Settings for Microsoft Windows Vista and Server 2008..#....# The Vista theme can only be defined on Windows Vista and above. The theme..# is created in C due to the need to assign a theme-enabled function for..# detecting when themeing is disabled. On systems that cannot support the..# Vista theme, there will be no such theme created and we must not..# evaluate this script.....if {"vista" ni [ttk::style theme names]} {.. return..}....namespace eval ttk::theme::vista {.... ttk::style theme settings vista {.... .ttk::style configure . \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -insertcolor SystemWindowText \... -font TkDefaultFont \... ;.....ttk::style map "." \... -foreground [list disabled SystemGrayText] \... ;.....ttk::style configure TButton -anchor center -padding {1 1} -width -11...ttk::style configure TRadiobutton -padding 2...ttk::
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2865
          Entropy (8bit):4.917847108902527
          Encrypted:false
          SSDEEP:
          MD5:769C0719A4044F91E7D132A25291E473
          SHA1:6FB07B0C887D443A43FB15D5728920B578171219
          SHA-256:AE82BCCCE708FF9C303CBCB3D4CC3FF5577A60D5B23822EA79E3E07CCE3CBBD1
          SHA-512:47FED061DDC6B4EB63EF77901D0094FF2EBB1BAFACB3F44FBF13FB59DEA1EC83985B2862086ECF1A7957819A88A0FAA144B35F16BEA9356BBD9775070D42E636
          Malicious:false
          Reputation:unknown
          Preview:#..# Settings for 'winnative' theme...#....namespace eval ttk::theme::winnative {.. ttk::style theme settings winnative {.....ttk::style configure "." \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -fieldbackground SystemWindow \... -insertcolor SystemWindowText \... -troughcolor SystemScrollbar \... -font TkDefaultFont \... ;.....ttk::style map "." -foreground [list disabled SystemGrayText] ;.. ttk::style map "." -embossed [list disabled 1] ;.....ttk::style configure TButton \... -anchor center -width -11 -relief raised -shiftrelief 1...ttk::style configure TCheckbutton -padding "2 4"...ttk::style configure TRadiobutton -padding "2 4"...ttk::style configure TMenubutton \... -padding "8 4" -arrowsize 3 -relief raised.....ttk::style map TButton -relief {{!disabled pressed} sunken}.....ttk::style configure TEntry \... -padding 2 -select
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):2103
          Entropy (8bit):4.9805308941424355
          Encrypted:false
          SSDEEP:
          MD5:162F30D2716438C75EA16B57E6F63088
          SHA1:3F626FF0496BB16B27106BED7E38D1C72D1E3E27
          SHA-256:AEDB21C6B2909A4BB4686837D2126E521A8CC2B38414A4540387B801EBD75466
          SHA-512:6EBF9648F1381D04F351BB469B6E3A38F3D002189C92EAF80A18D65632037FF37D34EC8814BBF7FAE34553645BFC13985212F24684EE8C4E205729B975C88C97
          Malicious:false
          Reputation:unknown
          Preview:#..# Settings for 'xpnative' theme..#....namespace eval ttk::theme::xpnative {.... ttk::style theme settings xpnative {.....ttk::style configure . \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -insertcolor SystemWindowText \... -font TkDefaultFont \... ;.....ttk::style map "." \... -foreground [list disabled SystemGrayText] \... ;.....ttk::style configure TButton -anchor center -padding {1 1} -width -11...ttk::style configure TRadiobutton -padding 2...ttk::style configure TCheckbutton -padding 2...ttk::style configure TMenubutton -padding {8 4}.....ttk::style configure TNotebook -tabmargins {2 2 2 0}...ttk::style map TNotebook.Tab \... -expand [list selected {2 2 2 2}].....ttk::style configure TLabelframe.Label -foreground "#0046d5".....# OR: -padding {3 3 3 6}, which some apps seem to use....ttk::style configure TEntry -padding {2 2 2 4}...ttk::
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):10521
          Entropy (8bit):5.0647027375963996
          Encrypted:false
          SSDEEP:
          MD5:508F7E258C04970FAE526990168CB773
          SHA1:33785204B18C0E0F5CDCB5B49399B5907351FDB8
          SHA-256:B463B366F139DDF7FED31F34C6D2341F9F27845A1A358011DFC801E1333B1828
          SHA-512:A12985B58DD1D46297119CED47B7F44EF4139CED6C36FD028E66DD657E5ED0663B744C679A5BF7A39B39D17A32E1280D2945F6B9AD59AEF20436F68040F6070C
          Malicious:false
          Reputation:unknown
          Preview:# unsupported.tcl --..#..# Commands provided by Tk without official support. Use them at your..# own risk. They may change or go away without notice...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# ----------------------------------------------------------------------..# Unsupported compatibility interface for folks accessing Tk's private..# commands and variable against recommended usage...# ----------------------------------------------------------------------....namespace eval ::tk::unsupported {.... # Map from the old global names of Tk private commands to their.. # new namespace-encapsulated names..... variable PrivateCommands.. array set PrivateCommands {...tkButtonAutoInvoke..::tk::ButtonAutoInvoke...tkButtonDown...::tk::ButtonDown...tkButtonEnter...::tk::ButtonEnter...tkButtonInvoke...::tk::ButtonInvoke...tkButtonLeave...::tk::ButtonLeave...tkButtonUp...::tk::ButtonUp...tk
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):26991
          Entropy (8bit):4.974180990171971
          Encrypted:false
          SSDEEP:
          MD5:FA99EF44FAA88A6BA1967A1257DEB97B
          SHA1:CC99DBF678F4169A90ACC5A89C6F8DAB48052EC6
          SHA-256:C4722EADEDE763FA52E7937D40067B0F8EB86B7A4B707F90212ED3E5289690D0
          SHA-512:3AF16095784908A444CD61EEF178A30B9FED9C20AA91D94044A3AECB6047267FB80BCE790FC1F28FB19AEF664A6618FD832612F541FDADCC34B6C01E92E5EA40
          Malicious:false
          Reputation:unknown
          Preview:# xmfbox.tcl --..#..#.Implements the "Motif" style file selection dialog for the..#.Unix platform. This implementation is used only if the..#."::tk_strictMotif" flag is set...#..# Copyright (c) 1996 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Scriptics Corporation..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {}......# ::tk::MotifFDialog --..#..#.Implements a file dialog similar to the standard Motif file..#.selection box...#..# Arguments:..#.type.."open" or "save"..#.args..Options parsed by the procedure...#..# Results:..#.When -multiple is set to 0, this returns the absolute pathname..#.of the selected file. (NOTE: This is not the same as a single..#.element list.)..#..#.When -multiple is set to > 0, this returns a Tcl list of absolute..# pathnames. The argument for -multiple is ignored, but for consistency..#
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):64280
          Entropy (8bit):6.281608660509971
          Encrypted:false
          SSDEEP:
          MD5:1DF0201667B4718637318DBCDC74A574
          SHA1:FD44A9B3C525BEFFBCA62C6ABE4BA581B9233DB2
          SHA-256:70439EE9A05583D1C4575DCE3343B2A1884700D9E0264C3ADA9701829483A076
          SHA-512:530431E880F2BC193FAE53B6C051BC5F62BE08D8CA9294F47F18BB3390DCC0914E8E53D953EEE2FCF8E1EFBE17D98EB60B3583BCCC7E3DA5E21CA4DC45ADFAF4
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............og..og..og......og...f..og...b..og...c..og...d..og...f..og...f..og.G.f..og..of..og...j..og...g..og....og...e..og.Rich.og.................PE..d....K.f.........." ...&.h...f......................................................<_....`.............................................P................................/......$.......T...............................@...............p............................text....f.......h.................. ..`.rdata...@.......B...l..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..$...........................@..B................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Zip archive data, at least v2.0 to extract, compression method=store
          Category:dropped
          Size (bytes):1333651
          Entropy (8bit):5.5868779115750264
          Encrypted:false
          SSDEEP:
          MD5:8DAD91ADD129DCA41DD17A332A64D593
          SHA1:70A4EC5A17ED63CAF2407BD76DC116ACA7765C0D
          SHA-256:8DE4F013BFECB9431AABAA97BB084FB7DE127B365B9478D6F7610959BF0D2783
          SHA-512:2163414BC01FC30D47D1DE763A8332AFE96EA7B296665B1A0840D5197B7E56F4963938E69DE35CD2BF89158E5E2240A1650D00D86634AC2A5E2AD825455A2D50
          Malicious:false
          Reputation:unknown
          Preview:PK..........!.x[_C............_collections_abc.pyc......................................Z.....d.Z.d.d.l.m.Z.m.Z...d.d.l.Z...e.e.e.............Z...e.d.........Z.d...Z...e.e.........Z.[.g.d...Z.d.Z...e...e.d.................Z...e...e...e.........................Z...e...e.i.j%..........................................Z...e...e.i.j)..........................................Z...e...e.i.j-..........................................Z...e...e.g.................Z...e...e...e.g.........................Z...e...e...e.d.........................Z...e...e...e.d.d.z...........................Z...e...e...e.........................Z...e...e.d.................Z ..e...e.d.................Z!..e...e...e"........................Z#..e.i.j%..................................Z$..e.i.j)..................................Z%..e.i.j-..................................Z&..e.e.jN..........................Z(..e...d...................Z)d...Z*..e*........Z*..e.e*........Z+e*jY............................[*d...Z-..e-........
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text
          Category:dropped
          Size (bytes):292541
          Entropy (8bit):6.048162209044241
          Encrypted:false
          SSDEEP:
          MD5:D3E74C9D33719C8AB162BAA4AE743B27
          SHA1:EE32F2CCD4BC56CA68441A02BF33E32DC6205C2B
          SHA-256:7A347CA8FEF6E29F82B6E4785355A6635C17FA755E0940F65F15AA8FC7BD7F92
          SHA-512:E0FB35D6901A6DEBBF48A0655E2AA1040700EB5166E732AE2617E89EF5E6869E8DDD5C7875FA83F31D447D4ABC3DB14BFFD29600C9AF725D9B03F03363469B4C
          Malicious:false
          Reputation:unknown
          Preview:.# Issuer: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Subject: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Label: "GlobalSign Root CA".# Serial: 4835703278459707669005204.# MD5 Fingerprint: 3e:45:52:15:09:51:92:e1:b7:5d:37:9f:b1:87:29:8a.# SHA1 Fingerprint: b1:bc:96:8b:d4:f4:9d:62:2a:a8:9a:81:f2:15:01:52:a4:1d:82:9c.# SHA256 Fingerprint: eb:d4:10:40:e4:bb:3e:c7:42:c9:e3:81:d3:1e:f2:a4:1a:48:b6:68:5c:96:e7:ce:f3:c1:df:6c:d4:33:1c:99.-----BEGIN CERTIFICATE-----.MIIDdTCCAl2gAwIBAgILBAAAAAABFUtaw5QwDQYJKoZIhvcNAQEFBQAwVzELMAkG.A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv.b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw05ODA5MDExMjAw.MDBaFw0yODAxMjgxMjAwMDBaMFcxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i.YWxTaWduIG52LXNhMRAwDgYDVQQLEwdSb290IENBMRswGQYDVQQDExJHbG9iYWxT.aWduIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDaDuaZ.jc6j40+Kfvvxi4Mla+pIH/EqsLmVEQS98GPR4mdmzxzdzxtIK+6NiY6arymAZavp.xy0Sy6scTHAHoT0KMM0VjU/43dSMUBUc71DuxC73/OlS8pF94G3VNTCOXkNz
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):10752
          Entropy (8bit):4.674392865869017
          Encrypted:false
          SSDEEP:
          MD5:D9E0217A89D9B9D1D778F7E197E0C191
          SHA1:EC692661FCC0B89E0C3BDE1773A6168D285B4F0D
          SHA-256:ECF12E2C0A00C0ED4E2343EA956D78EED55E5A36BA49773633B2DFE7B04335C0
          SHA-512:3B788AC88C1F2D682C1721C61D223A529697C7E43280686B914467B3B39E7D6DEBAFF4C0E2F42E9DDDB28B522F37CB5A3011E91C66D911609C63509F9228133D
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......B..............................M....................................... ...?.......?.......?.a.....?.......Rich............................PE..d....jAe.........." ...%.....................................................p............`..........................................'..p...`(..d....P.......@...............`..,...`#.............................. "..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):122880
          Entropy (8bit):5.917175475547778
          Encrypted:false
          SSDEEP:
          MD5:BF9A9DA1CF3C98346002648C3EAE6DCF
          SHA1:DB16C09FDC1722631A7A9C465BFE173D94EB5D8B
          SHA-256:4107B1D6F11D842074A9F21323290BBE97E8EED4AA778FBC348EE09CC4FA4637
          SHA-512:7371407D12E632FC8FB031393838D36E6A1FE1E978CED36FF750D84E183CDE6DD20F75074F4597742C9F8D6F87AF12794C589D596A81B920C6C62EE2BA2E5654
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........C..r...r...r......r...s...r...s...r...w...r...v..r...q...r.#.s...r...s...r..8z...r..8r...r..8....r..8p...r.Rich..r.........................PE..d....jAe.........." ...%.:...........<.......................................0............`.........................................@...d.......................(............ ......P...................................@............P...............................text....8.......:.................. ..`.rdata...W...P...X...>..............@..@.data...8=.......0..................@....pdata..(...........................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text
          Category:dropped
          Size (bytes):4
          Entropy (8bit):1.5
          Encrypted:false
          SSDEEP:
          MD5:365C9BFEB7D89244F2CE01C1DE44CB85
          SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
          SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
          SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
          Malicious:false
          Reputation:unknown
          Preview:pip.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text
          Category:dropped
          Size (bytes):5440
          Entropy (8bit):5.074342830021076
          Encrypted:false
          SSDEEP:
          MD5:554DC6138FDBF98B7F1EDFE207AF3D67
          SHA1:B6C806E2AFF9A0F560916A90F793348DBF0514BA
          SHA-256:0064A9B5FD2AC18605E512EF7127318AD9CF259E9445488C169F237A590602E1
          SHA-512:3A71B533874F4D0F94F15192791D2FA4DF9E8EBF184C711F1D4FA97230C04764C1C9A93258355B08107E5B72053C6901E883E3DB577E8A204D5B9EB3F8BC7BFC
          Malicious:false
          Reputation:unknown
          Preview:Metadata-Version: 2.3.Name: cryptography.Version: 43.0.1.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: Apache Software License.Classifier: License :: OSI Approved :: BSD License.Classifier: Natural Language :: English.Classifier: Operating System :: MacOS :: MacOS X.Classifier: Operating System :: POSIX.Classifier: Operating System :: POSIX :: BSD.Classifier: Operating System :: POSIX :: Linux.Classifier: Operating System :: Microsoft :: Windows.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.7.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Classif
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:CSV text
          Category:dropped
          Size (bytes):15579
          Entropy (8bit):5.567434003079107
          Encrypted:false
          SSDEEP:
          MD5:E8478B758300439BF58613F2A3A2676C
          SHA1:39ED064E67212A54E4B8D1C909E6AD2ACF48025D
          SHA-256:5ADEAA62D3045659DDF79324823AA3BCB1CA78F264442D6F6F6B9C8A8470A634
          SHA-512:D7029823DC5585FBE885DDB52EED2D02D1584EB945EF23916391201FCBD17DF0B14F338BDFC6E81318297F831CA99796423206F781373857317E068F0C0B321C
          Malicious:false
          Reputation:unknown
          Preview:cryptography-43.0.1.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..cryptography-43.0.1.dist-info/METADATA,sha256=AGSptf0qwYYF5RLvcScxitnPJZ6URUiMFp8jelkGAuE,5440..cryptography-43.0.1.dist-info/RECORD,,..cryptography-43.0.1.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..cryptography-43.0.1.dist-info/WHEEL,sha256=8_4EnrLvbhzH224YH8WypoB7HFn-vpbwr_zHlr3XUBI,94..cryptography-43.0.1.dist-info/license_files/LICENSE,sha256=Pgx8CRqUi4JTO6mP18u0BDLW8amsv4X1ki0vmak65rs,197..cryptography-43.0.1.dist-info/license_files/LICENSE.APACHE,sha256=qsc7MUj20dcRHbyjIJn2jSbGRMaBOuHk8F9leaomY_4,11360..cryptography-43.0.1.dist-info/license_files/LICENSE.BSD,sha256=YCxMdILeZHndLpeTzaJ15eY9dz2s0eymiSMqtwCPtPs,1532..cryptography/__about__.py,sha256=pY_pmYXjJTK-LjfCu7ot0NMj0QC2dkD1dCPyV8QjISM,445..cryptography/__init__.py,sha256=mthuUrTd4FROCpUYrTIqhjz6s6T9djAZrV7nZ1oMm2o,364..cryptography/__pycache__/__about__.cpython-312.pyc,,..cryptography/__pycache__/__ini
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text
          Category:dropped
          Size (bytes):94
          Entropy (8bit):5.016084900984752
          Encrypted:false
          SSDEEP:
          MD5:C869D30012A100ADEB75860F3810C8C9
          SHA1:42FD5CFA75566E8A9525E087A2018E8666ED22CB
          SHA-256:F3FE049EB2EF6E1CC7DB6E181FC5B2A6807B1C59FEBE96F0AFFCC796BDD75012
          SHA-512:B29FEAF6587601BBE0EDAD3DF9A87BFC82BB2C13E91103699BABD7E039F05558C0AC1EF7D904BCFAF85D791B96BC26FA9E39988DD83A1CE8ECCA85029C5109F0
          Malicious:false
          Reputation:unknown
          Preview:Wheel-Version: 1.0.Generator: maturin (1.7.0).Root-Is-Purelib: false.Tag: cp39-abi3-win_amd64.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text
          Category:dropped
          Size (bytes):197
          Entropy (8bit):4.61968998873571
          Encrypted:false
          SSDEEP:
          MD5:8C3617DB4FB6FAE01F1D253AB91511E4
          SHA1:E442040C26CD76D1B946822CAF29011A51F75D6D
          SHA-256:3E0C7C091A948B82533BA98FD7CBB40432D6F1A9ACBF85F5922D2F99A93AE6BB
          SHA-512:77A1919E380730BCCE5B55D76FBFFBA2F95874254FAD955BD2FE1DE7FC0E4E25B5FDAAB0FEFFD6F230FA5DC895F593CF8BFEDF8FDC113EFBD8E22FADAB0B8998
          Malicious:false
          Reputation:unknown
          Preview:This software is made available under the terms of *either* of the licenses.found in LICENSE.APACHE or LICENSE.BSD. Contributions to cryptography are made.under the terms of *both* these licenses..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text
          Category:dropped
          Size (bytes):11360
          Entropy (8bit):4.426756947907149
          Encrypted:false
          SSDEEP:
          MD5:4E168CCE331E5C827D4C2B68A6200E1B
          SHA1:DE33EAD2BEE64352544CE0AA9E410C0C44FDF7D9
          SHA-256:AAC73B3148F6D1D7111DBCA32099F68D26C644C6813AE1E4F05F6579AA2663FE
          SHA-512:F451048E81A49FBFA11B49DE16FF46C52A8E3042D1BCC3A50AAF7712B097BED9AE9AED9149C21476C2A1E12F1583D4810A6D36569E993FE1AD3879942E5B0D52
          Malicious:false
          Reputation:unknown
          Preview:. Apache License. Version 2.0, January 2004. https://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial ow
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text
          Category:dropped
          Size (bytes):1532
          Entropy (8bit):5.058591167088024
          Encrypted:false
          SSDEEP:
          MD5:5AE30BA4123BC4F2FA49AA0B0DCE887B
          SHA1:EA5B412C09F3B29BA1D81A61B878C5C16FFE69D8
          SHA-256:602C4C7482DE6479DD2E9793CDA275E5E63D773DACD1ECA689232AB7008FB4FB
          SHA-512:DDBB20C80ADBC8F4118C10D3E116A5CD6536F72077C5916D87258E155BE561B89EB45C6341A1E856EC308B49A4CB4DBA1408EABD6A781FBE18D6C71C32B72C41
          Malicious:false
          Reputation:unknown
          Preview:Copyright (c) Individual contributors..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are met:.. 1. Redistributions of source code must retain the above copyright notice,. this list of conditions and the following disclaimer... 2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... 3. Neither the name of PyCA Cryptography nor the names of its contributors. may be used to endorse or promote products derived from this software. without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOS
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):7900672
          Entropy (8bit):6.519460416205842
          Encrypted:false
          SSDEEP:
          MD5:81AD4F91BB10900E3E2E8EAF917F42C9
          SHA1:840F7AEF02CDA6672F0E3FC7A8D57F213DDD1DC6
          SHA-256:5F20D6CEC04685075781996A9F54A78DC44AB8E39EB5A2BCF3234E36BEF4B190
          SHA-512:11CD299D6812CDF6F0A74BA86EB44E9904CE4106167EBD6E0B81F60A5FCD04236CEF5CFF81E51ED391F5156430663056393DC07353C4A70A88024194768FFE9D
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......l..(...(...(...!...:...8...*...8...,...8... ...8...9...c..&...G...*...(...+...`...V...(.....`...)...`...)...Rich(...........................PE..d....j.f.........." ...).`Z..V........X.......................................x...........`.........................................p.r.......r...............t...............x......Cj.T....................Cj.(....Aj.@............pZ..............................text...._Z......`Z................. ..`.rdata..ZR...pZ..T...dZ.............@..@.data....+....r.......r.............@....pdata........t.......s.............@..@.reloc........x.......w.............@..B........................................................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):5191960
          Entropy (8bit):5.962142634441191
          Encrypted:false
          SSDEEP:
          MD5:E547CF6D296A88F5B1C352C116DF7C0C
          SHA1:CAFA14E0367F7C13AD140FD556F10F320A039783
          SHA-256:05FE080EAB7FC535C51E10C1BD76A2F3E6217F9C91A25034774588881C3F99DE
          SHA-512:9F42EDF04C7AF350A00FA4FDF92B8E2E6F47AB9D2D41491985B20CD0ADDE4F694253399F6A88F4BDD765C4F49792F25FB01E84EC03FD5D0BE8BB61773D77D74D
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............l..l..l......l...m..l...i..l...h..l...o..l..m.y.l...m...l...o..l...h.l...l..l......l...n..l.Rich.l.........PE..d......e.........." ...%..7..4......v.........................................O.......P...`.........................................P.H.0....kN.@.....N.|.....K.d.....O../....N....P.C.8.............................C.@............`N..............................text.....7.......7................. ..`.rdata....... 7.......7.............@..@.data....n....K..<....J.............@....pdata..0.....K......4K.............@..@.idata...%...`N..&....N.............@..@.00cfg..u.....N.......N.............@..@.rsrc...|.....N......0N.............@..@.reloc........N......8N.............@..B................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):787224
          Entropy (8bit):5.609561366841894
          Encrypted:false
          SSDEEP:
          MD5:19A2ABA25456181D5FB572D88AC0E73E
          SHA1:656CA8CDFC9C3A6379536E2027E93408851483DB
          SHA-256:2E9FBCD8F7FDC13A5179533239811456554F2B3AA2FB10E1B17BE0DF81C79006
          SHA-512:DF17DC8A882363A6C5A1B78BA3CF448437D1118CCC4A6275CC7681551B13C1A4E0F94E30FFB94C3530B688B62BFF1C03E57C2C185A7DF2BF3E5737A06E114337
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........>:V.PiV.PiV.Pi_..iX.PiC.QhT.Pi..QhT.PiC.UhZ.PiC.Th^.PiC.ShR.PillQhU.PiV.QiH.PillThf.PillPhW.Pill.iW.PillRhW.PiRichV.Pi................PE..d......e.........." ...%.*..........K........................................ ............`..........................................g...Q..............s.......@M......./......`.......8...........................`...@............p...............................text...D).......*.................. ..`.rdata..Hy...@...z..................@..@.data....N.......H..................@....pdata...V.......X..................@..@.idata...c...p...d...H..............@..@.00cfg..u...........................@..@.rsrc...s...........................@..@.reloc..4...........................@..B........................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):68376
          Entropy (8bit):6.149155712539885
          Encrypted:false
          SSDEEP:
          MD5:79B02450D6CA4852165036C8D4EAED1F
          SHA1:CE9FF1B302426D4C94A2D3EA81531D3CB9E583E4
          SHA-256:D2E348E615A5D3B08B0BAC29B91F79B32F0C1D0BE48976450042462466B51123
          SHA-512:47044D18DB3A4DD58A93B43034F4FAFA66821D157DCFEFB85FCA2122795F4591DC69A82EB2E0EBD9183075184368850E4CAF9C9FEA0CFE6F766C73A60FFDF416
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........^..?e..?e..?e...m..?e...e..?e......?e...g..?e.Rich.?e.........................PE..d...fK.f.........." ...&.............................................................t....`.........................................`...H................................/..............T............................................................................rdata..............................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):6928664
          Entropy (8bit):5.765764546579782
          Encrypted:false
          SSDEEP:
          MD5:3C388CE47C0D9117D2A50B3FA5AC981D
          SHA1:038484FF7460D03D1D36C23F0DE4874CBAEA2C48
          SHA-256:C98BA3354A7D1F69BDCA42560FEEC933CCBA93AFCC707391049A065E1079CDDB
          SHA-512:E529C5C1C028BE01E44A156CD0E7CAD0A24B5F91E5D34697FAFC395B63E37780DC0FAC8F4C5D075AD8FE4BD15D62A250B818FF3D4EAD1E281530A4C7E3CE6D35
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ ._.A...A...A.......A.......A.......A.......A.......A...9e..A...9...A...A...@......cA.......A.......A.......A..Rich.A..........PE..d...cK.f.........." ...&..(..*B.....8.........................................j.....$cj...`.........................................0nN.d....;O...... i......._.TI....i../...0i..Z....2.T.....................H.(...`.2.@............0(..............................text...r.(.......(................. ..`.rdata...0'..0(..2'...(.............@..@.data....D...pO......PO.............@....pdata..TI...._..J....^.............@..@PyRuntim......b......"a.............@....rsrc........ i......$h.............@..@.reloc...Z...0i..\....h.............@..B........................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):30488
          Entropy (8bit):6.576230704358061
          Encrypted:false
          SSDEEP:
          MD5:92B440CA45447EC33E884752E4C65B07
          SHA1:5477E21BB511CC33C988140521A4F8C11A427BCC
          SHA-256:680DF34FB908C49410AC5F68A8C05D92858ACD111E62D1194D15BDCE520BD6C3
          SHA-512:40E60E1D1445592C5E8EB352A4052DB28B1739A29E16B884B0BA15917B058E66196988214CE473BA158704837B101A13195D5E48CB1DC2F07262DFECFE8D8191
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&.tb..'b..'b..'k.V'`..'d(.&`..'d(.&n..'d(.&j..'d(.&f..'.(.&`..'b..' ..')..&g..'.(.&c..'.(.&c..'.(:'c..'.(.&c..'Richb..'........PE..d....K.f.........." ...&.....2............................................................`..........................................@..L...,A..x....p.......`.......H.../......L....3..T............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data...X....P.......6..............@....pdata.......`.......8..............@..@.rsrc........p.......<..............@..@.reloc..L............F..............@..B................................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):1816344
          Entropy (8bit):6.495083998132025
          Encrypted:false
          SSDEEP:
          MD5:21DC82DD9CC445F92E0172D961162222
          SHA1:73BC20B509E1545B16324480D9620AE25364EBF1
          SHA-256:C2966941F116FAB99F48AB9617196B43A5EE2FD94A8C70761BDA56CB334DAA03
          SHA-512:3051A9D723FB7FC11F228E9F27BD2644AC5A0A95E7992D60C757240577B92FC31FA373987B338E6BC5707317D20089DF4B48D1B188225FF370AD2A68D5FF7BA6
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......1.y+u..xu..xu..x...yw..x...xv..x...yx..x...y}..x...yq..x..yw..x|..xg..x...yt..x...yx..xu..x]..x...y...x...yt..x...xt..x...yt..xRichu..x........................PE..d...1,.c.........." ...!..................................................................`..............................................`.. _..h.......8................/..........................................`...@............0...............................text............................... ..`.rdata..|L...0...N..................@..@.data...."...........f..............@....pdata...............n..............@..@.rsrc...8............f..............@..@.reloc...............j..............@..B................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):11707
          Entropy (8bit):5.03328629946697
          Encrypted:false
          SSDEEP:
          MD5:A0B269D76DB613C2D927EFA84FEE88E2
          SHA1:F9C7AD375F4D4223F0668FA1E2C4E5A83CAC2D03
          SHA-256:32348D51F3637F375B056FE99E9B4D89D85D45DB907847DC370BD72812A2E2FE
          SHA-512:5427762147825DC2ED3FEEE4011BBF2100932A4D93F3242CCAD15499C9DC39F42A82AEB42ED5DB5839560CD7AAE5D30621AC3694552FFC650A1F572CEE32FA54
          Malicious:false
          Reputation:unknown
          Preview:# -*- tcl -*-..# ### ### ### ######### ######### #########..## Overview....# Heuristics to assemble a platform identifier from publicly available..# information. The identifier describes the platform of the currently..# running tcl shell. This is a mixture of the runtime environment and..# of build-time properties of the executable itself...#..# Examples:..# <1> A tcl shell executing on a x86_64 processor, but having a..# wordsize of 4 was compiled for the x86 environment, i.e. 32..# bit, and loaded packages have to match that, and not the..# actual cpu...#..# <2> The hp/solaris 32/64 bit builds of the core cannot be..# distinguished by looking at tcl_platform. As packages have to..# match the 32/64 information we have to look in more places. In..# this case we inspect the executable itself (magic numbers,..# i.e. fileutil::magic::filetype)...#..# The basic information used comes out of the 'os' and 'machine'..# entries of the 'tcl_platform' array. A number of general and
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):6218
          Entropy (8bit):4.843141834641668
          Encrypted:false
          SSDEEP:
          MD5:8ABC3029963E433D1D9865AAA7E1057B
          SHA1:A88091DC98B2FD0AE3A258B59F8BE43F41F04323
          SHA-256:0A6B4B109CFDFC4B40FBDEFDB2282F9B1AF3CC2F9624DD39958EEBD78781AFB2
          SHA-512:D5068375615A2200DDC13EEB852B2E21B7E4AA416FB7A0E97C98B8B106D7701792C523739E8BF266D2ABE411D4298A0B5B3884CFB9DF820FD4A2B61B22F9DECF
          Malicious:false
          Reputation:unknown
          Preview:..# -*- tcl -*-..# ### ### ### ######### ######### #########..## Overview....# Higher-level commands which invoke the functionality of this package..# for an arbitrary tcl shell (tclsh, wish, ...). This is required by a..# repository as while the tcl shell executing packages uses the same..# platform in general as a repository application there can be..# differences in detail (i.e. 32/64 bit builds).....# ### ### ### ######### ######### #########..## Requirements....package require platform..namespace eval ::platform::shell {}....# ### ### ### ######### ######### #########..## Implementation....# -- platform::shell::generic....proc ::platform::shell::generic {shell} {.. # Argument is the path to a tcl shell..... CHECK $shell.. LOCATE base out.... set code {}.. # Forget any pre-existing platform package, it might be in.. # conflict with this one... lappend code {package forget platform}.. # Inject our platform package.. lappend code [list source $base]..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):35136
          Entropy (8bit):4.945501767273492
          Encrypted:false
          SSDEEP:
          MD5:BD4FF2A1F742D9E6E699EEEE5E678AD1
          SHA1:811AD83AFF80131BA73ABC546C6BD78453BF3EB9
          SHA-256:6774519F179872EC5292523F2788B77B2B839E15665037E097A0D4EDDDD1C6FB
          SHA-512:B77E4A68017BA57C06876B21B8110C636F9BA1DD0BA9D7A0C50096F3F6391508CF3562DD94ACEAF673113DBD336109DA958044AEFAC0AFB0F833A652E4438F43
          Malicious:false
          Reputation:unknown
          Preview:# msgcat.tcl --..#..#.This file defines various procedures which implement a..#.message catalog facility for Tcl programs. It should be..#.loaded with the command "package require msgcat"...#..# Copyright (c) 2010-2015 Harald Oehlmann...# Copyright (c) 1998-2000 Ajuba Solutions...# Copyright (c) 1998 Mark Harrison...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....package require Tcl 8.5-..# When the version number changes, be sure to update the pkgIndex.tcl file,..# and the installation directory in the Makefiles...package provide msgcat 1.6.1....namespace eval msgcat {.. namespace export mc mcexists mcload mclocale mcmax mcmset mcpreferences mcset\.. mcunknown mcflset mcflmset mcloadedlocales mcforgetpackage\... mcpackageconfig mcpackagelocale.... # Records the list of locales to search.. variable Loclist {}.... # List of currently loaded locales.. variable LoadedLoc
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, Unicode text, UTF-8 text, with CRLF line terminators
          Category:dropped
          Size (bytes):107674
          Entropy (8bit):4.841458743618635
          Encrypted:false
          SSDEEP:
          MD5:655EC828777244F9F048E0D08203482F
          SHA1:790446D04FE7BE12FD5DCF6E6FBD4C5A08C45C98
          SHA-256:35A88F56DF57E6AC6F2CCC4D193210FBB9BD224AC99670603E077DDF8C5610BC
          SHA-512:C249CAA5DA76A0B0876DD1BD201FF2D249D4FCD8467992C9DE51BA5A1C5471F98C10D69C46DF5B25DBA7941F4301B446D90CBF17BCCFB8B0ED27B22BF4DA20F3
          Malicious:false
          Reputation:unknown
          Preview:# tcltest.tcl --..#..#.This file contains support code for the Tcl test suite. It..# defines the tcltest namespace and finds and defines the output..# directory, constraints available, output and error channels,..#.etc. used by Tcl tests. See the tcltest man page for more..#.details...#..# This design was based on the Tcl testing approach designed and..# initially implemented by Mary Ann May-Pumphrey of Sun..#.Microsystems...#..# Copyright . 1994-1997 Sun Microsystems, Inc...# Copyright . 1998-1999 Scriptics Corporation...# Copyright . 2000 Ajuba Solutions..# Contributions from Don Porter, NIST, 2002. (not subject to US copyright)..# All rights reserved.....package require Tcl 8.5-..;# -verbose line uses [info frame]..namespace eval tcltest {.... # When the version number changes, be sure to update the pkgIndex.tcl file,.. # and the install directory in the Makefiles. When the minor version.. # changes (new feature) be sure to update the man page
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:Tcl script, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):118419
          Entropy (8bit):4.888789841897662
          Encrypted:false
          SSDEEP:
          MD5:ACB85FEB97B27F1362E1D76B686D498F
          SHA1:92C370F838BD67C72E153FBF7AD05E26FF40A393
          SHA-256:7A30E7A49C1F6939537EB7A80CF2F5BC7A4969F2B2AD99BA4E26DB85BBC2FCC7
          SHA-512:EA504863386817E1B21549376148FD05C7EAF74F91A3A8DA97EFCF3784530ED3CF1910DF9B2431EC47D1175759CDEB1A0E9E9E02BBA94EC2123EAFB7CBD2B90A
          Malicious:false
          Reputation:unknown
          Preview:# http.tcl --..#..#.Client-side HTTP for GET, POST, and HEAD commands. These routines can..#.be used in untrusted code that uses the Safesock security policy...#.These procedures use a callback interface to avoid using vwait, which..#.is not defined in the safe base...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES.....package require Tcl 8.6-..# Keep this in sync with pkgIndex.tcl and with the install directories in..# Makefiles..package provide http 2.9.8....namespace eval http {.. # Allow resourcing to not clobber existing data.... variable http.. if {![info exists http]} {...array set http {... -accept */*... -pipeline 1... -postfresh 0... -proxyhost {}... -proxyport {}... -proxyfilter http::ProxyRequired... -repost 0... -urlencoding utf-8... -zip 1...}...# We need a useragent string of this style or various servers will...# refuse to send us compressed content
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):1555736
          Entropy (8bit):6.182100088642903
          Encrypted:false
          SSDEEP:
          MD5:9FB68A0252E2B6CD99FD0CB6708C1606
          SHA1:60AB372E8473FAD0F03801B6719BF5CCCFC2592E
          SHA-256:C6FFE2238134478D8CB1C695D57E794516F3790E211FF519F551E335230DE7DE
          SHA-512:F5DE1B1A9DC2D71AE27DFAA7B01E079E4970319B6424B44C47F86360FAF0B976ED49DAB6EE9F811E766A2684B647711E567CBAA6660F53BA82D724441C4DDD06
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......y.P.=n>.=n>.=n>...?.?n>...;.1n>...:.5n>...=.9n>...:.>n>...:.<n>.4...-n>...?.(n>.=n?.wo>...6..n>...>.<n>.....<n>...<.<n>.Rich=n>.................PE..d...],.c.........." ...!............|.....................................................`..........................................?..L@..,...|........{...P..D......../.......E...T...............................S..@...............@............................text...h........................... ..`.rdata..0...........................@..@.data...............................@....pdata..D....P......................@..@.rsrc....{.......|..................@..@.reloc...E.......F...H..............@..B................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):1137944
          Entropy (8bit):5.462087550450309
          Encrypted:false
          SSDEEP:
          MD5:16BE9A6F941F1A2CB6B5FCA766309B2C
          SHA1:17B23AE0E6A11D5B8159C748073E36A936F3316A
          SHA-256:10FFD5207EEFF5A836B330B237D766365D746C30E01ABF0FD01F78548D1F1B04
          SHA-512:64B7ECC58AE7CF128F03A0D5D5428AAA0D4AD4AE7E7D19BE0EA819BBBF99503836BFE4946DF8EE3AB8A92331FDD002AB9A9DE5146AF3E86FEF789CE46810796B
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........aM...#...#...#..x....#.."...#..&...#..'...#.. ...#..."...#..x"...#..."...#.......#...#...#......#...!...#.Rich..#.................PE..d....K.f.........." ...&.>..........\*.......................................p.......Q....`.........................................p...X............P.......@.........../...`......P^..T............................]..@............P..p............................text....=.......>.................. ..`.rdata..\....P.......B..............@..@.data........ ......................@....pdata.......@......................@..@.rsrc........P......."..............@..@.reloc.......`.......,..............@..B........................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
          Category:dropped
          Size (bytes):146712
          Entropy (8bit):6.609130019215802
          Encrypted:false
          SSDEEP:
          MD5:297E845DD893E549146AE6826101E64F
          SHA1:6C52876EA6EFB2BC8D630761752DF8C0A79542F1
          SHA-256:837EFB838CB91428C8C0DFB65D5AF1E69823FF1594780EB8C8E9D78F7C4B2FC1
          SHA-512:F6EFEF5E34BA13F1DFDDACFEA15F385DE91D310D73A6894CABB79C2186ACCC186C80CEF7405658D91517C3C10C66E1ACB93E8AD2450D4346F1AA85661B6074C3
          Malicious:false
          Antivirus:
          • Antivirus: ReversingLabs, Detection: 0%
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...x.Oc..........."...'............P..........A....................................@.....`... ......................................@.......P..8......................../......................................(....................Q..p............................text...............................`..`.data...............................@....rdata...W.......X..................@..@.pdata..............................@..@.xdata....... ......................@..@.bss.........0...........................edata.......@......................@..@.idata..8....P......................@....CRT....X....`......................@....tls.........p......................@....rsrc...............................@....reloc..............................@..B................................................................................................................................
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:35:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2673
          Entropy (8bit):3.9837636175737847
          Encrypted:false
          SSDEEP:
          MD5:C2A9DA2CB225F7AD5CC785FADCE77EBA
          SHA1:C175CAD89D9D7CDF11F2BBEF3BC7A6650A7634C1
          SHA-256:9C5F22F3B5BDCDAC10108E878EB80416439D7751CA506C70B17F7F052B973C16
          SHA-512:E82A5068C6B8911F03CFFF37477E39BABB51E3E669CDB80CFA6FEB7E180F0591068C34495D1C705361866DA53E14FEA1CE5BBEE1A998EC2671A7DF8B41FB0AC1
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,....^..:a%..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IWYn|....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VWYv|....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VWYv|....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VWYv|..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VWYx|...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........P........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:35:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2675
          Entropy (8bit):3.9994705394362184
          Encrypted:false
          SSDEEP:
          MD5:C29CAA38F3F9DEC8D00FA87CD304AD02
          SHA1:EF5A4AEEC5CF00B78D1F8DCEAF030559EE010FEB
          SHA-256:33DC1C8CD9B236B7D8F6C2744339053A935C1DB3BBF33040FE26C2EDF66CFFC1
          SHA-512:5E2BCD15BA3C943489C1A6776EB3A36CEB44C0E1932BBB0A9613314C2B596190E25966F395D3337899C19AF510E3729D6960A66BA316C116D5913E509B977493
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,......:a%..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IWYn|....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VWYv|....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VWYv|....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VWYv|..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VWYx|...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........P........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2689
          Entropy (8bit):4.008002530841249
          Encrypted:false
          SSDEEP:
          MD5:4DF1B9EE4A64806B573C2DDF7231B453
          SHA1:C8085B6EF59F660AE99E00FFB0E547AA63C5C739
          SHA-256:90FE2916763C5A40391200EC5769E34FB14FFF911CDC68BEC9F3B700B22DB93C
          SHA-512:99FFC37E16227B8A381646C794E71F4C4915323E81733DBF6FD1D4484C73E2BB6257C700EA63A9CC953E4F41AC4052D59007FC82647CD0C1AD8656E88A13EC94
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IWYn|....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VWYv|....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VWYv|....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VWYv|..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........P........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:35:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.994896371350938
          Encrypted:false
          SSDEEP:
          MD5:4E8B78748E1417233AA7EE4601E486BE
          SHA1:E8E4FC3BB88274591CC085E6715B1A07BD10EBBD
          SHA-256:1F63A0E53DBB435021735DAC3C96DDCBFDB09D5DB5F8DCE49CED19B7A67021CC
          SHA-512:7C7084021BAFF9D772E793882A9EA24CF8C8C0C209B5C2CA4C6ADE73901692F18D684688B7DA654773BE13571EB1AD8DC94E0F02AD73FD39F5480E026E652291
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,....Gs.:a%..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IWYn|....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VWYv|....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VWYv|....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VWYv|..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VWYx|...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........P........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:35:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.9835597348709326
          Encrypted:false
          SSDEEP:
          MD5:9134D5F025D35A13DD177526851E9909
          SHA1:E85A259DA227FE1D2226BAADF24F857D9805E657
          SHA-256:77C4C3E216CB8C47A842EEBC9CC7F2319CFBFE4A9838F5066A7B926E7FC004B1
          SHA-512:BF70844641D8CFB5424261BD70894BA902871A5CB8D34927C5816690DF4E39D04D7F8BD0FA0DB867F2AED0CA167B445976712648F5CCC49FF223B835BE79A550
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,....C@.:a%..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IWYn|....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VWYv|....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VWYv|....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VWYv|..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VWYx|...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........P........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:35:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2679
          Entropy (8bit):3.996012891731987
          Encrypted:false
          SSDEEP:
          MD5:335CFD19D4E494589770ADBF4AE2FA6B
          SHA1:1281CB418C9A9E6815486142ECA60B3533D53A4A
          SHA-256:338B98C03616E9FE5E8C8D3F5EC923D89A2018BD3CA26F489D3DC744D772DAA2
          SHA-512:61A2806D185B8F1B8F1824EA18D8E73A47D1FF7F6011DADFB7FBE73D13E1E5E69294E7F75713C54BADA091CB7F3AAB43F8AE57D2F8F5D0305479220C06E8BC32
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,.....z.:a%..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IWYn|....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VWYv|....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VWYv|....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VWYv|..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VWYx|...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........P........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.499789933654265
          Encrypted:false
          SSDEEP:
          MD5:CC1684A057C1475F241B8EA562FE8ED9
          SHA1:30CFB2BA8B720424B3B958B68513AF18E0A1ED25
          SHA-256:BE2B549EFEDF5FF6F3B304F4363083FD12559AE1822B55DA7BA62F266EF855FB
          SHA-512:BCCA3F46C73CE98FF5C39FBFA30D5070D8D402C37E1C58433F95341338C0729C3515B69BEF213D74FFE4435042DAC91D3709B5C28601758D1DCBEAE22BE30CE9
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................u]...@...a...{....R.....kO^DT.~...on.RhAAW...!ekW......3F".:..I...........F..b.#]ir..).d&.?..&......,Z.<..(A....X.8,.p.q..Z...3...D+..2...\.."..q..c....V...v6<....D..C....>.@.g..m.......t...........i..@b..]..`G.{.F.AU..E6nx.L.]=....Wj.z.N...)..Q.._..R8gmS...p.j...g...&...X...;kP..i}.%Z..7..%.o.J.)....PV.&..W,>..[.,.W6Z^..>..p.B.....;.7.9.w5#V...H.:..6...y....+...*..j..=R.m..J_6....?=...Le..q.n.?S...f.p.g.(.2.5...p....j..(>..n."...Bg.=...t..e....} ..eX...4$........q.g.@..aj..7...#...T.U......V.|.5.{.!.7.....e.=li....7...O..n8....x..o?\.3U........y".*I.M...p.x.N.?../.Jn.S.....0.5W.....T..;....6ft..I.~.H.E..~NG.....E... ]....85..\..ZAa_O..=sP.C...w..'.z.......H...|.....^To...&.\la."e.?.F".4..M..zM....mKK...n."...;.........Q.'.7.O>n5...*j'..&."A.....c....DaN..A..?...,..'....M.*..W)B..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.483240023826998
          Encrypted:false
          SSDEEP:
          MD5:1ECD00FA86DBDABD8D7C04BD8DD8EFD8
          SHA1:3673E27E79693944C7BCE584F797AA099654200E
          SHA-256:13B4781678FA161AE1867749591F648E179B375ADA47013520981005048023E3
          SHA-512:4127B7895BCDDC42467DF2D7DC0B3FAF04850CA97322372FCE6D8CE6AB0CB7C4E66AF189C7397B32C2FE12C9900E2F1081B45D999F92E0D65DEC4ABBF1E65F43
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1........................................................................................................................................n.gc..1...?.H.]z..(<..2..r.R......}H..wmS.;.2.$G..d.Kj....F=*.g.9C.i..]...m_..xd...r...C..........V...N..........3Cq...d.....s80....{0..........F.qM....+pm...U...p...N4.h...T..avW.{...}AS...1.9...m5.gN......>E[.5.\.[`Mp..Rm...I..@Xt(..N3.@6(.P..1a.."+... >...O:....9...}.L....+.V...3...k...).^.3}..;o..A7L.....b.7.*A';!F.*~(`.v...._.......d..Q.'...H....m.H]#...*..t(...-.8.LK..]^y.....5?n...+R...5.4F..Z..B.Gv._i.@E..v"k .e.M....t..j8M...&....E..s...q.y.U..b`.p....NG...^..?..C...\3.y.V......%M.bC..f+..".k......XV......\.=.Ru.W .....@./7.%..`.Q....].0.....E...;.6..\.1.,..N......o.=.`..I.@..$.3.OF..(....g.E..e.uP.)......O...]..:...w.....s......,r=.....M.s.i..B8..F...d.......?.....t.........._....|.LR..fU.LX...1..Y...g.2`RN.HY.....#.9q@A.^...0.b.......v..b...C..%....y......`L
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.484062657186237
          Encrypted:false
          SSDEEP:
          MD5:F5AD80EF114FC61F4DD7C2045DC022A3
          SHA1:822C062BF42207EC8FD756BED167620AE7D77C24
          SHA-256:69750A05A9AD2C7DB73EDC83BEDA4AD9621AB6F194FF0A6B108024573D162A98
          SHA-512:91B457D8D7F02D980D1BD8249538F04E48F0E2DA3D8CCBFF9A457ECCCE9BA5188E65B225DB9C3149DE5C1DAA291341ABBB8AB8AA7EDE1DD47BD4FDCA265E6E55
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................E^.J.Y.~...kWs.).[.>r.._c.......T..c.2b.2....>...*....|p.n..m.``......7... ...o......=*w}......r+<PxD.n._.qm.3#.].=.l.+5 ...t.>@.i.p3..$.>.Z....N...}X...;..H..<..Ki..|E...X......b#..&B.Ft...T...S>..Ps+7.g...L....[Wee%q......g^.=...........G...%;,.j.Gm.2..;..-..0..'f.e.S....E......[0.HbCs.,st.....!.K.;.r.`E...Y...4F..X....W.x..........s.U'K+pfL.0.M..$.&.j..5....gRP.-.].0......,8.Yt..R$.E.>L..<..o.....YX.g..3...A..k..L.?...d.T.\?..........D....=#.......r,..ev;m..D.t....._......m..9"..%1Q.^.m.6Q..Th.H.!..LOm...D..........E...4.8.....%F.=.)%...c.."..k..!.=P.Z....K[\v\.u..z.\.s2.z...W....Z.F..v/^...%M..h.Rt..6V&Q....E....Ie+I."..qf=W...<..>..5.o.Z1.<.:.........t....PB.Oi...A.......!.g.t^T|k.....e..6.....A6....w^F ....%.Z.V@.v.'...x9.....-.{.:....I4.A.>....J&...F..l....'..>..^..~|vFt......J._.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.5028776895047296
          Encrypted:false
          SSDEEP:
          MD5:80B0ECDF8901A2BC4FBD6E0A5D402772
          SHA1:82364C81143DD956F012842C4FE446179178D3B6
          SHA-256:1F27768B7A10C799ACD6555D3375FB0C92268A6FCBB4612D936B756C2813106A
          SHA-512:C58E04A0525FB40B7A01F78414F95D260225DFFE8AC8B7D0E2E330847D4139EE40C9899BDE487727DB62F86BC724DA3381AED0D0EF61707ADABC1717CF0AF76E
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................f..S\P.QgLc|I.O.{.7 L.......O}Q.....H.HX.....vq.3$....(>.. ...Q..9Y.....|...".jE*..a.|3w-c/...........>!RT2J-.......S..N..."..?.....h....hC...YSp....b..I:.n...~.?....(+yq........).QK..x.U..*>.d....9j./.....w...[a....g.....Q/,-2.;....S.....+..:r......LN.9.......c..P..<.j...BGD...'TW........~......h..~....pw.e...{.._Go5.\S.....,.....Z.:.E.}._i$.U.ODOK..-....RBi....X:G...i`....#."....:.......=6La#.u... R.....[>...$....."J.....F....O...xU*.E...Lo...F&..)...e...t...d........kt....Y.^........Z..:.(quI..1o...1.J..../....T(....[d.66..j.[......C...m.....F..^^yXv..-.! l../..........W.....8?p/M..f.-+.q.........f...w!...AV...|K..L....R...T{V..d]..G.\c./.j.\.fxfz2..m.. .2....P....c2...s .w...J..p.....8o.i.....R...,.. .a.9E.Mo"....e....@]...../....FsE.uD..%..].cT..b...K..-p.....j.R.......h[.......l..^
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.498566974201875
          Encrypted:false
          SSDEEP:
          MD5:AF7F5E68F33DF4990AA8B8EA83759EDB
          SHA1:AA34961DAEF4FA86766C8DEE149AB73E12700F93
          SHA-256:2E3DDD61060C1042AE31A7521BB3643E5016E93D2C393E470615980C65618913
          SHA-512:CD26BC0E0BB1B7EE841F5B78A4C32F7296A86B0B2CCA4608D07248578BA8B803910555CE23C7E097974FEE8396F851A0A78B44D03EA4A94199896457E8630918
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1........................................................................................................................................W.d...f..i..1....th.(.3...Fe#.k..]....vig.G>....7S.4..qfP.3zb..C.|...a,..>.Taf.3../@........c.;u.he .G...'.@..3.f.R.8.o.d>B9.A.Hf.VU]F..N.....Uj.yrc.m.c.../.....i\f..r...,t."...{..n.X....P....t$.[.m.t)6u..'.........X....6x.........4._e..B......d\.)ow.......F..;.].e.y....+..Wo..ygZ..+.C_....l...E#`...<..j.4\.xD..h...$...BR.d....!H..%Z0Y .8V.g{...t.....!....#...'8k.RZ)..H..rNX..S..........l......+.&...u&.s;.)2..k...co0........1...DQ....lc'...@..C...8..!...-?../...?....6.K+..."hdi.{#?..S...z....:.."@OR..f.....i....E...P.nP.w.'..DL.9O...,.......`....)...........y.JS..........."...:.....s.I.Y..q.v.E.a...9..;8.qn.~.i">.l...`..Q{......a.R...f.$..:..UuM(.o`.."..M.].{}...o.4.i.M4U.6.|.L.".<...V2..S..?&.S?j.~.B!o.3..B8..m.oN..i.S..Ll*..n..gW...OX7.FT...,.6.^.h.n...kKg.e.a..G....T....v......Ta.._.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.509825432205081
          Encrypted:false
          SSDEEP:
          MD5:84E95E27082E64F24C69C2DA242E741A
          SHA1:3764FF6CDD4404C53F03FFA3C5ABC498D9B3A306
          SHA-256:BB2140BBCD992BB1F9E0244E445FA49AB4DD88103F53DC4203AED05132919A13
          SHA-512:0FF596AB35BF4B6B12FFA2CF2A2671504386BE246FE034AC6A961519489DB5F4C69064D34301F04E4A9CAAC9AB1D0EDDFE909FE933BB022295FF53B228ECF00C
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................La.>-S.~m&.`+K.N.....;*...W>O.I...F..j.m"H...y;.[.......e.t..g..W}as.}..;K. z.`....g...%4..j.1..PFv(i\.!....}KZ..B&...Ea.(./.....ZZ...G- ....v...E..cl.l.s....t.JG........0-...9..._.`.....v....l...g..xF1.M9oF!.........#...I.@K_......a.......X.p .:..n. ..[!.....{w,.)K|.[..S.1lI..&...^...mE.i..s*}U._.........mG..A.q{^.......W...Pt.]O......-<..0.z.:3W.U...........I....)p.*.|.G.../.eK..5e..i...h....~..q.l.]..../IN..t.C..q.$..W...H....)d.B...R.JE........0...r.....M`?....gY..;$.(.q.........5....e".>...F.`.j..B...1.].'...AB0@..Y ...:.<V..J.........5C...h...}..O.......G.G.,......6...s....p1..v9w...tp+c..D.e.=......"..J.+.f0.).6.....G.....&. ...Z^..)..i.?2........Hm..|~...j.q.*....b.....~....w.r.y.g.:/......>.%@kn_.^~....M.....J.L.;.....G....h.QH.1W?...+h......ok.1..~>.K.V.*E.......
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.479812693460543
          Encrypted:false
          SSDEEP:
          MD5:500210610C50A67BC96B0BA3F65DA97C
          SHA1:7C8A6D3FDE82C8D5784C121BE4967A3C1E48641C
          SHA-256:F3F339965E23F8227E867C20CA05FE4D710EF9625E85113BB50A4547DA35DFE7
          SHA-512:C5CD7A382EAEE06D0903F77F261EFE6E9F0EEE70E2A2A9FC8BDA98378B27009D410646EBE13B760C0720E62C2C34EF17485F8931D9D7AC22375569D2CC8CE088
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................9.wg....g..X}...i.=9.zM.X.;...#+o.d...YuV}..P.5[......rFm.$.l..h7HoA..`...>..wI.9.<bo.?.iNsr'\.HJ.C..p.....P...j.Ol5...SRp._..y...c.D|.L.+....G....(..........J...4e..=.<S3.8..k..>R....Is.a....QF.=.&9@..?..}.*e.....O.#CN...KE.L.#^..N..7...].9LC...N..v#_&.m.I..{..y.5L.7../.gA..rdk.7RT.2.$..q4....cP.!.!Xa..i....=...6...p...e..V..}..Y.?O.C`s..u..#.|.V.sM..{...}<...n+,..jbBx9..E.....AK4.........i.X.3V...e.i..b...m.b.&....p".^.xD&...<2|h..p...._8}...;.o.....f..@....#..Y.z...%.v.......mg..NZ.....G.,4............;z.w.N.......y........p.q.j.5 8..)'..u...../.X!>.r.....O.DX.u.WQ..r..E/!.g.G.O.a.}.V..b.<h..0I;.....fBo,%.....1...!.SB0.....XG.1H...g../......Ffc.u.0,..%..x#....J&...?.....6.0.=.j7..7.3Y.aS{/..b..Y.O...f)......p.!..;e.[....t.9Vcp.G..a....\N.T. N.2.C....&%.M.....#...j.....l. .7.2.&b.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.5066806716216465
          Encrypted:false
          SSDEEP:
          MD5:A1CEB38A87DD09F598AEBCBE45193324
          SHA1:6CA5E734EB0D66D418C03108F325122128F31C79
          SHA-256:B379E4F5B8BDDF2216C27DD21388876430E03087C4BE184EFBC6DD18F2106DCA
          SHA-512:063700D6F72BF45C1FF3B236386D1F6C6545D03A8D1D60A5C7DFCE12659F66319637A1E82C1C2C4910E104C8432D4DFEBC82E69BAC5BCCD8EBD6E8287FB56921
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................j(..I.o..3...q.. .;.."..X.%l.R.y.Q.,...j.v.../..6.A.'d...W.n.k$.".X..i..D.....(.7...;....j.....b.%4mN....Z.<...Y..wr'.y. g..G...T.v..Vu.j.*a2..L .h..'...r ....r.!.........i*d..k#...yi..*Z.".rfX+w...E..a*..(..(1..^..=...%..-...P.....Z..uL.)...4e*...^..I....=..mQ:j.q.;......ymwyxS.r1.....;.w..w...Q..$...f.!.x{.m..E.B2..3......".s.9 &E.`w....f.....h.<zY..(F..ZP...M..B/......2X..B...A..I\d..Yw.N..j..-..=kft......E%4..9.....P.p....:J......k.d."..%..,.<i#....z.]1....0G....^i$`...k+B..~0M.S..>...*.....H...O..=..1B"!K..k.J{...'^.........Rh.r..a.l.J.S.#r...=bv:..e..^...`S.....69.(..|.U4.\.#,..j..e...N.?....6,...S...?...##..T._..G.o.........f....v....7->L#......I.}5.._..mn..5....o>!1..............O...q.).W....$s?.....K.,r.M...G.NJ..v..!f....t.. )al...8.j.RE.W(,.+m&}.D2G...7.b)..H..<.>
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.4886591248778895
          Encrypted:false
          SSDEEP:
          MD5:8C90085C07FB71BA03E9E7A8486C6AC6
          SHA1:84320A8C7953BCC60C296067B233E52B3EF3DF11
          SHA-256:2BAC5225F3AE71FB7BBE1A11A4D51902EDE666E0500013CC5338F4510E8826DA
          SHA-512:178E4A2DF66B43472D1B3153FC1A9583AEE3643D5601C9A383642C75921E0F05D5A167558BC3C8187B5201B38A2B30314F248764428160D6CF15F799981673BE
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................=.....tQH....8.~B...-7>R~..K....v.a. e..&.. ..1y..r.........Wj.x$..s...j.:...ZO..\...%M...........S...\b6...Z....$P5u...&......[....D.>..Qy..2..o.."q./p....'<K...A...L.qYK.;.;%.1:c..m-....QM.8..=...r.n..T.W|a..9.K?!......z......?...,.....Xe....Tu..LM........#.......V.!5L....?&tKWIg.....$.F.b..?e...#./..J}...e.D.*.o.-$n.C.D.l;.........I.hm.RC..SZ[T.A.J.!....2.....V.+..~..vY.J..\....=gg,weQ6.Rr.9.d|.$.E?.F-..Q.....N.V.P....gO.E0.2...>R..t7Q....'O....<.r..^l[..../T...>....>.8...qW....hc~Lc.~i.../}.>....M).M,o.J.=.mC.v.u.4C"...C .v..r:(I.^$..r.#..T...a.\~kl.-...Ql....K....N.|.]mIp.+9.._..O...s.lRx.r.~[..)C..=......~......f..I..a$.......1!@......=..A<..........j.?E...#..]...+Pp.my............Fu.Y....f.\).0.....s...Y\.==1..6G.A..,...\..[Pl.S.}j~%.#............LB:..*z.Cg..N(...e
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.513742970086653
          Encrypted:false
          SSDEEP:
          MD5:6F385C31808CBFDF65BE588795E9D86C
          SHA1:C44D13D77B27624394440E83C026C49944819F0C
          SHA-256:6D9562DB4FBFC5805F72618F039429B68326499D94432A00838B5B3D7EF1EF1F
          SHA-512:562DC95501BDF2D93A4709444889180938008780C3C1E182E12D0B02658609774DF89A1DD6B8CDFD859ACA52BAFCF825D462A624571375F3B6FE5A4EB658375A
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................h{<~...x.......]\;\...,7.!...p.....n.n.}..1...}..X....C....7.>_....\.Q."....U.4.mo...1..Wk..6..(>..B{...#..Q.R.f.^K..[B.=...d...w.v..D...X....cN.;...3..bLM.Eu.=4......0..%.......>1.1..(.n:..U>........{.1_.T...4.....1.#8.....<b....*E...T*.E...# .K7..=..0.....`8.<.@.~.!=..;..1.!.SV..}...gT.$;ttd}...n..+......zO.2........b......A.*k..3.:.53>n.aH.a.dFQ..;B.j...R...&A,m......JE..............3p.t.H@..A...h....$......}N.....Z..y..c.7...%.F1\.;....k...&.:....]..>9*.aG.0o7...R..Y.>...x.S.b..W.......Az...;...N...*/i....h......w..=..'.D..7&...:?....U>.l..$.l..Zv.J.~.vU..rJL.y.L\.-...g?...t?E.W.........6j.-...e..G'.T0....H....3.4.o....:..."#.. ....o+J..P......p;.....B#.>r.H.+.K0.Rq..w?.).<...zj$]..S.]..3..w.J.kR.....4.*..qi=)..E\...........H3...SkF.2.w..(..u.....|o....7.?....@.\=Z..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.5103295802659
          Encrypted:false
          SSDEEP:
          MD5:91993739C96A2281E32BF412513675E9
          SHA1:58FEF9520898882C5B854F2A13EA0B0EAC310356
          SHA-256:0A6C9B5BC4AD19EF7DB980D0F1142AB72C005A73391BCE07575D7ED3C01F3E1A
          SHA-512:E91752FFD1458556F7FB11E4E56B2991A740EAE8011F39321B4888A1CF301D8ACB4A23DA5CD389CC640980C3CAEA9C0A5B30CDB3EB1DE2A7F64790EFAC83392A
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................J...../0i.&z.Z.y.F."...ghY..#p........cG.S... ...kVL.11.J*.Zel...|...0.4...o.H..3.{...tj?O..P"@eC..F?=r{.!.Z..A......K.=.].qd&..M.r..@%;.Wp4?).*..s.1.....1....5..>...)U.rG.4...'&...:_.Nk~..[.U...n.$..S.T_4L....:.7_.9.9O..N%..w.b..l.Y....B.e.q..l.^`2.e..P......H.-..F.2...j.H.U&..n.!.>..1.....q.SD.K-.}....'.....0x.....7..8FW.]...v2r%...Z..[:...}..*.<.)......}un.?.l^.....?2V$....+2..(2...n..E.ec..L.._R.LQs...3..b.a..i:..rM6~/.&..h)...2\E%...'.......o.........|"..in@.....<......kvT...{.).[.Y.z....2.A....>.....R.3.p.A].tOu....SvFS@:.,XiN.DSTE{.m.y...`..i..2.%c..O.J.q'0..)C.....R..J..l..}..&..X18.Z0....*X...l.......Ww..cy(............v.vI=..[..O7W...p.b.N.^.....-...b....Ik..J..\.h..{..<u1..|..._.4..4&.[...1..+..>.K.k...p...\5l.2{V".A...g.......Z.n..&.>>,..K...<..u..hd.x......
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.517498650867365
          Encrypted:false
          SSDEEP:
          MD5:2B44485F446427993DC41F05ADCE9A12
          SHA1:C89BD97DB72914899C8990D2F5255CC198EF682F
          SHA-256:9F196A1BF285EF0DBCA9389AE730BCEB18E95FDF4D150DB4FEF22E030C34A0F3
          SHA-512:0660A7C13701ED4B58B3ABDBD44B7068C3843639AD08EDC45B781802B0013BA0D20D73EC560AFAAE5168F904CF5B4F433739FD1DD8D071DA0E3663669F072DBD
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................$...u.g`.V.7f........h..Y.JI..3.?d< ?./.+2I.....X.....`.'.I=jW....lgL................9r!%|......i.......^,)..l.H9..G..(...LKt.WBn*...F..D"w........1M3...>.5..+.'].V@y..X%W#.6'...L..M.Y.......f...X....j.....fi...EJ;.ly)..{l+.....=..k..=S.)QM.n.......#@C. ..:;y...6.y....kxL.m.~K..#.P.6.-B.[...A...[.m.dk...4~.......a..v.^.`2.w..Z..\p..,...D.*...+.cc..0.?.YL~.....d...p.7.....AV xP.p.d.N...Y7.Q.........#..E.c..0....p...=.Z.r.f.....2..0..9...'.H.....kS...^+|..M.x..#..........$D'i*.O.[g......LZ.......H.x.5..".F.c.N....pI..._.....gNW6w^.NZL..?.>..UU.......sp.Fe..,.P.W ~..0;CA.?*I..`.0.e...].S...b.{.........80..U^..$_.b$..8)(.0.`..?..b..[.vY.?. bn....kf.bs...c..Y.Pc.[...P.m.e...).[D..7.k".......$.o....i...x...riW.Q.U8..z_..n.l.5T...8>....sZU.Gy.....T..'...4.N.5..UZ."R.....p...9.=.Zz...?.0}..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.495644783981797
          Encrypted:false
          SSDEEP:
          MD5:0A1C3315223801F5626D0D872F9EA8E8
          SHA1:950D05201CA10279949DE03110372291CC0C4977
          SHA-256:9D36743F968E82D0CA744626485847B15B385C5BB55F98D7430613D151B919A6
          SHA-512:273621AE45C2E60DE975D85AB2638A524FD8208FDF0F37E5070F3F44E60909F050E8DCFD50BDD736B4A22C9F626AD4CE72BFCDD8FAF23692FC87F97D3A44520E
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................S...m*....S9.).....X.e.{..........STm.1.:....e..d...&..N.)....R.F^..........W}&i..r}%....T..N...@.F.......N.n.....4,7.....7B1U....|B..)...5LFb..Zx..^~G..k..5j.d..d...I.-...|.%Z..=.2.y.....T.H.........|3.G^.g..g....&n/zW-.P..5.V...X8;w?..!.U'...Z(N..C...?F...a..e. ..D..TJ0.,=.z]^...s....(..S..pG54....Lk...N...m.]k..kXu<...b#nB..x........'Y.....c.fs.g.iW..p....-..%..[9..=.@.H...Y.+....^......aEh.....A.O.b.+...@.HQ+.*dh......D.,.@.i.@P..(..\.f.....-..R..%..z.L`.........(....n.Z~...I.3...}p...<..G.[&t...f.Br.-Q...`... ...w.u#.....;Z..'...9......\E./.z.y..c.........w.\c.IG.g.w.a..?..t.2...<........N..R>.K.W........t....Z...D.)W...._..%...IA.&.C.A..j..#.5....g...H..R..k,.._i......$1.(.<$,G....b..........u,O..8BI.-.y.....|)Lx..Vg...8.7 ...6r.<.;.....BDjE..0.v..k...V.kY-..e..^.......9.t
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.514538620829061
          Encrypted:false
          SSDEEP:
          MD5:3BC9ADFCF9513F4D788F391FD593C15B
          SHA1:8A3B66C45AC95FACDBF4A58A6F07F6B771BDE5A3
          SHA-256:B5FAD03414642482EDE6220053246EE2A6B1CAF8A4E24CDD238D0B0128204585
          SHA-512:D9C503B36F592AB0D3E7A3F571F52F4EDAB84CB92B513BD0686B04E66FE2439E13DB446789AA79325FC20829E6134251CE867C68EA9ED502E85602BE63A55083
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................'.u..O..|....Z@:"p&.l.1.m.......Di....z.F.p6..;_P...87.R....../|]...$k...Q..[..'Pq^.<.j..Paj(.8....Q;B.R.@.......#(....._;.....p0.W....l}l....a\....T[+.k_.YQ...o...Do.dW7...r.r...~:<.S;).h....Q...~.X.BY.FH...... ..u...z..-I|...~...w{Za...#.)N...2.c'#.J....A8$S%LdX.^(.......C..HP....+.."...c.,..Rv.6...-.<C.....k.$l9...,IT.S.8NA....~..X_...3.'.../..dKf.(..&S.B.Q..5;...v.2....r.Z..1.._.Q.S.....mkH....H..t./.U..'....H^.v..7.7.*VL..2j.)....b(..........D....oT..Z......<..V.[R.h..D...c.O....4x8... ...y.zUywo...6]='..?).o.x(e.j.........W.."W..'d..n..l.}On......3.$.l.Sa5..}M..H.-ll!..X...,........&(.{....6^.....lm...;.3a.$k6....C....n......`..@...Ss&....F5.j.{.,..c..Y.OS...v.O).....!.)X...../..)</.........X...w.....F.B.V,....\...".s.U.m..?....A.3......u<Xe.M.R......u.J....]@}..4.yw.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.488628251782603
          Encrypted:false
          SSDEEP:
          MD5:FB8C2FA385CAFB8ADA25D0CA6B6D914C
          SHA1:37F3A52727EDC336074376E5D43E1B4057F8A9F9
          SHA-256:20BF7975F6BB887BDC78579860992B5B4F37DD1A445D78F996E64A85E7D2DCE2
          SHA-512:DCCBDF67AE97C49E9D30A40F73ABF2BDBFC13BD8FD79EF8797C5AE0F5B38ADF6A47D11A122485D713B1DFDE0738E378C39072033AA10130946DCAA9A02F202DC
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.......................................................................................................................................eMf....$3Dl9..[..N9.]rD_.,,?.w.w...*.X/W..+/.(.I..:"..U)T.{q........$t....v..z...k...........X....x_imHS...,.u..m...O......8Z.`x.Z....Y.m+).Qy.....'...j4....At2.B..@....nK 2.R.>i..Vy.k...8Y.].K.....(.zXQ........_...>....g.Q.!...A.Q....{Y.....b/./$p..H_.1zo.Y|kr3'#.u....o..(...`...'.)..w...2....{A.......,WgJY^..a..5vJc+r8 ...;.v........):[..q]..,.]......>;h....u...DQVW..Yl.c.....Q)....Ii.........D..qk...e~...=..V.v.*.^'z..7.W..O`...JG,P.]?Gn...W..}.......z......@\j..%....L..!.....zY^....o.HD...'B.@W?.l}`......y..EB..C.ZV.b..$.13o~.".L.......Q..-..w.._...H...%...q.Z..2.ko........*........B3..7.@H.r}.P.......l."..!...h,2.............UY....o.......eiv".p...3Q...X.@..`Pp^7G.R.L..z*.Y3..7.[.A<]H.i.b......l....k/..P.>..}.....We...M).......<OlH...^g=..../`q;L...tu...9.....jh.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.508608428193514
          Encrypted:false
          SSDEEP:
          MD5:A0BB245AC4C24DCF8E320249FB913897
          SHA1:B6AD6FA7926863F0BE04B4F22F29E8E421D9DEB4
          SHA-256:6F5774CDD41D0AD31E114F6DA38B4279E45DC5E2761E3EE2A7526929644CDBC3
          SHA-512:D4524F28F0D019B2BBF77A61AF74EB67BEC74031C4CD2B47F3E3C186D5A0D75A87910C9437696F9105DF59F092C8DC97A9C87725D6AE2AC135C1F7D6E8E06748
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................%....O7..7..L...)V9aU{t.E.nW.P..m]..IK......G..IPOik.@..#^......+.s..!...k.5>...m{KQzj...l.a.m.K>~...|..#0............4....h7=..2z...Xyh.... .e.G.....(.h......}.u.|5..3...."...Z...!..1?...V.N..'^e8...........TSL...0..........Xn.;Qc.H{.............;............(.....k+..E...V....:.>y.....2.R[=.E.."...~Q=D_Z..X.C.E.4..."..?.....f8]....S?'(G........1.....^l.(..~.F8..=....n...}.................. ..+..Jo...[..4.....F....]...W.Ve....W...J......&.>.....vW.E@.[biTg.C.wb7..5..,.s~-T.....F.x..u...D..&.7_..J.....,.d...OK.u..Dp..nj...Q.X..n.._...[.......|.\.U*>..+.Q..E.o6.}L....m.a...j.......`^SQ....\...Y....g.ByMY..f.mR].=r.Q.T..^OZ..I]L-.2|..%....:.....\..v......._K.:......%d..........H:../..m]../;...j..5..]..n...o@f..?.%....0..V.w._..do..Sh..%.K..x...&..F....n.|..T....y?.;...x
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.507749660287802
          Encrypted:false
          SSDEEP:
          MD5:EB28DE14AE02E22652E96FD243B7A8E8
          SHA1:B8E0BCB5F17E3AFAA4DE8FABAF96FA98A650DF93
          SHA-256:2E5E4E05FFC7E6E8A5606CBD56BA76BF2D9DE5639BD02E8307BA0CDF89124C69
          SHA-512:752D24EC4FD8908C94B969FF1F3B72F923A5C7E97EB5D1CB21CB4D06DC14F98C90C6DE1F0447FD2FCEB23DBCBABFA790CAA040D35137E053C475B2301D462812
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................t......k..k*..R"$H.`........?.[8.....aS.N...f....gx.>).:..p._..]e...c.......'=&O."..#......l..&..rS.v...f8......._U..OX..i....~G...Q.L.Lcs.I......F.'..@.U..R.p.....8N...o...t.`r@.*..../..j.4cH...~..|df;.#..<gu..X..EKAc...?3......gv.(J..X....6....yAOFS[...."L...N..v9.......I4....@....(Q.V...jF#....+2K..).4p.D.6./.&..:.A}.W.....v...S ..H.&.7..G.<.f.4.{.x.X.n#......?%..Y..D..}gp..3..N...qQGt.h.....&..a..v.v....D:.a.....?..".Z...,..n..$..4N.D...N1.|..Rez;..$..P%.+...z....6..7.B7L(2f..DFb.;.7rfdsuT.."...N.%...<.^o.CNC.w.".....[.*/...U2M.a.}.w.y.Vt.........C..I.Q?.H..g..".n+...PO1.zi....l...Vi1.o#.w~.. ZIp.Pm.V|./4..?=."Eb.tov?.do$...m.e..mB..f..m....7....f9B\.....<-...x....A,.x..5.{...8RQ......6....yg..v.....>..$....;.R~..p.g1\....uJ..]ih.el..B..P.v.(..`..........r[....@$....),...7x]bw
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):2759
          Entropy (8bit):7.807294668026275
          Encrypted:false
          SSDEEP:
          MD5:BF9C567EA0D74E685D05E3720C79FF08
          SHA1:FDF28CA59DE35CFB5DECE39E54C74AD86882D294
          SHA-256:CCFB738F3FFBDDB35F2636980C4390D37EC33943701BE64EC53E98D40DC569AD
          SHA-512:2D7797E88B7EA100EF2C22C43E94B13A741533AB426EE9F96315962C25C9262773DB2CC1886B69F77619E22BB6E20569A6693A3EF33F636E7E962A96A3B014B7
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................p.G..(w._$..6....)...;&=;K.T.{~.3..d.u....x.N.{=o.m0/G!......^N.O.Vj.sN..$7..`.@w.*...y.D7...H0...m..Tr.V.0..j..y...|l. ..Y.^\r6.n....K.Btd>.k>.....U#.N....+..$.....>.@M...H........rv.z......3..@vF...S...w..i/...^OF..]Z|...C.S.Q.{.....#......e.Y.......5".=Q.j...Y......t.7!Q..o..]...i.-$>{....d....%._.M..p..Y... .c8:..;.@..u.U..9wj...y..t4.7Y.\........Tb.....>..m.>..54...5*w.....Q.5..."..[i..!i......].6..2g.....%xJ....>.39.c....:../...8...b...S.4..]..La.\.....B.....v....Q.v,..&.H..G....hj..y.....PN...... 7W.4.NF.......U.....r.%uj.d..U....!wdC..s....Q.@..F.....2q.ae.....~...]._......q,.xI. @#.~.....t.....y.M..`...T!Y.._2X.J.Gg.W.t.y.-..I.&b.[...Z.^.xV.V.`O.W:.%.Z..Zs...!L........*.8h.14.E.h6.z..h.....V..9..1~j....Nc.M..}.5.].8ua.].@...[...F.yL..N..|.).u.(P........+.`.=m.Z.[../..f...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.488359539923026
          Encrypted:false
          SSDEEP:
          MD5:6B463C00374D77566FB53E1348770CB7
          SHA1:86BB61F53F3811E2C7437A6701F6D21451D6EA32
          SHA-256:11050DE925CF85A9418D8469981B086A779C8195FC91532E5FBE90FBFF0C889C
          SHA-512:F5C581FA1C8C93C3281407BFA0694E3632378482EB8701A7B80B48C21A73ED121C845F4A1B0968B69DF42714C0D053A7755DE0DD6280CA506777E853F16C7759
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................B....@W...2.B#..Z.7........l.hX...F@=..|.3...............'...F.c^...q...Q.{k...e..@.]i.Z.M4......g....d.I..c........ct....zV..Vj.:}..EW....... ..S..&AN}..X.Yn./.S.j..m.x..mC.f..o.....Kn...[.......T..-.-..j....I.........C3^...u.....!......../.V.%.RR...`\.B..;c..Z]?}}F.(.X...UU..|+...bG.........m...d...!..4.....F."..j....*C..V.....e...f.."V.....%-.S.fw|.q.A....b......x..L. M-.....s..*.i..../~.....U..uZ............'_.......K...q....zJd.N...G.&...KL.oo...g..q.)....N.&.N.]..JT....V).....b........v.....Np.i.mGo_<oi..`\:.x....%|.K...~..#...s...y..Tdop..q....I....?O..5.:(7.|..f..@h.da{.f&.>A8jh...v...<G....l...%.&Y...*............9tf2(...j.:....m.F..m.........k.S....OF...L......r...?...A .g...R..S..7..f.,.@.s.....P...Z... :..[N.........<..Gtj...$...>z..j.a.*....l.@|..h.....zzj(....cioi.@})..u...v.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.51775535365516
          Encrypted:false
          SSDEEP:
          MD5:31EF98300F6157478B2FF58BA2474CED
          SHA1:E04BDE82EBB7EACF40863C89DF280685C617E5B1
          SHA-256:071DBEE88E47A333DB0AE7B6E64579348A78C852651D01F396196A7E5D19C26D
          SHA-512:B5D75972438017F3212F4F7A74FD37853E06D314205B1E9B9603CE6B21D2675435F76AC7A691BF148326965A2868ECD07AF8F64ED0931E0DC9086131B8E94336
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1...........................................................................................................................................qb..hzG.dU.fp...5......r.&.e.+K.?.NX.C.]..:P./I(..z....\:..}p.i.*..?p.......G=..r.....j...Q......$.....Y....C.Y.v.xlJ.zGe..*Q.......}M.....1...>...u....%...r6o.N....)...I..i.....1...l..!.;....&.}{jrwh..}Uj.2.D...,w{9E_@....zd{.T. D......=/w..D;~[Fi5.d.Z.m/.-e|,.DN.`H^.V.{..'dp.e.....D..-...[......sX.a..>:.c7....X.H..dYhXRo......PBm,/7.j..*Q...}.l~.....k.t..L._.....k0.e..ZY...'L.Z......+...Q1S...\T.hX0.9&K.F.I..".g.`.t.%i.1BR........u...^C...?>....\)W..S.re...X..,...O...[..D6L.....?......?X..u.+c.D...Pb.@.ir.+....k..t.C...L..~........n.A..mT.2......Wl..z5.0....SV..u...... ..F0..d.t........F.>......?.<.-....l...0...r.f'_`........7.B2.v.b!...A3.t..|.?.6...pa....D..(@.0B...~..J...}..<...C.)..*.&.(\.R......#..^q...6.)F.=.h...P.K./.s..r..1+.-.M...&}!.XI....t.....(.....t.Mee.h.[..8
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.474121594267723
          Encrypted:false
          SSDEEP:
          MD5:B5C0B43922137ECF661B08E15B779BE8
          SHA1:CB6903FBD2EB37238E3D21A3663383979B500245
          SHA-256:7E20FCA768FBEDE7CC0384C8E621AFF97191EC4456FBDA0389CD1B28561B1B45
          SHA-512:C022986030CE36E154D8AC61AF101AF58465ABFA4002E86BBFCB6D714E41CDBFB73218849591E28E34B93C809A1AC36BEB00581946290C9615D67694C3F58CC7
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................v.?jy..'..yU'}-....b[...o;......I..N. .i...t...;.4z.y.f.b...j...G.?....C.e.)..1.f(r...o".c....]..8..~.e..K(...Y|.{~.I.....E<iy..[B.....~......|..k5.Zh7.[.D..5...@n"J.-..D)(11w...^...+.4..y...Y".d.........f2...D(#....-.>&.)H.6.(h.#0.i.Z.yV..`O.@......p...4B~..l)...b6/...w.._.....|...hE..#Jh4...>.....o;&..\.....L.....S..c.;o....N'/.6}..E.....+LO..U|z...k..:XG........1r...........B@..!..hB.}....+./7L........../f.6{.......O.?..#.q..`7<k....Kwp......iG..k.G.4ur'..6....c....O.....3...u.P.2...z".h"G..Z..$.&{...*.%).t....3M_.2.+.K.x..2(.@./...|=-I..........7/+E....MK..{3...8W...#v[..WD>....2)........yp+58..#.R.e..o...U.....nU...Ef.'5u.3.zSH....H.`>t.s.i.....x.[......}... ......K....A,!.e[.3.....O....#}.Eo.Z.u...(..Sb.K...O|a.Us.#{EN;./..o..c..cl.}.>....>Q....%'.-...k.|....,$..kHA......".
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.490986123035512
          Encrypted:false
          SSDEEP:
          MD5:BB601229F15FD38058A531F5C62090B5
          SHA1:0E62CBA24E491A88F9FC957F847216FB44CDDB32
          SHA-256:31FEBEC1B5CB0BFE876893A781CBA0539B845C942F9A964A84359C47E5E15F9F
          SHA-512:0389E99B30FE55712443EE9746F01DFED9EBB8D9D394FDD49ADB74F01B0A70FC00F46F2DBCAE81A5A9BDDFB57DBDF3FCFE88B58EA6109A5274C5E88F82B72B85
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................J...h-*..i...Y&qJ.*\...f.~M../........z;.%e.,.....j....=.p.5.Dmm.N.6...-/u..... 7..d. .@.g...F....(..-.R.7-P~..f../..h]..h.s.M. .pH...GC.....5..c..-%..v.[...q..J..G..D*.u....3E.2pQN.....D...7.&..vY...d.p...W..p..J..o......._.....OWw....gJ.....R..F.......f... .....J1.G..e\w7..>R.wML..os......S.....|.H.. ........k.*...t*.Z..S.).!....z&...@T..H..8br...RyBR..<7./..=.....S7...\`.C.BA..Z.{.....zc...?.27.p.2.C...x....B..$.f^..D...k..GPB.:x..{Z=..2.1.?-.^..3...En..1g....x....*.!y.1)....7..L....mY.....n...>YU..c..y..|u..fS.......q..{.aK.....\..)..........E..L...a....#.X.....;+.k..J&.>..*dL[..{.....J....*P....y.^O!N5.._..{<&..J.+:..J.wN.^.G.3...S........y....O..!.....*4I...j..d..."..MS;..t...".....d........v.j`....(...A....{.=.&.]S........*.m.f.`.<..F.7.q.T.....J.'...x....u!..`Q{DW.._.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.492295807293615
          Encrypted:false
          SSDEEP:
          MD5:BC86C4679979CCC7DE4681C7DD788363
          SHA1:56101B9C08D6B060E789F1CF076A97F424CD3302
          SHA-256:3FC699FC67E350927B6B2BD90A255345427A979C7DAC0F052776C4CAA55CE051
          SHA-512:681E6AD5B0FD199A8B224ABF35C3C94D11E42ADF75133408A523600A4ADAB29BA69DF0B9763F3DF9CBF7AF3D542C565D0B4F10CD90DD256F5CD5C45853F7CFB6
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................g;l.&t.._...w.6......n.H.t.-Fk[.........../.o.}}...L.;.$SV...\.S..s.r....%....3[..G&.POB.../DVui<..5Q..f~|..:..J.7..@9...Z,......B...5...!5.k...E3\...^.....`.k............."..\O._>.hY..u.?.~69.j6.6|e.....#>gX1.{.`...!..=._L...Z..|.....Mr....b...\...x0.....k.......W...`.....g.R..g.N.n.SU...;.....#'C.r1.H<.4.F.z..mvz..tS...........?"..*<-mmt.......h...#1...Cy(k......6...A...^...1.uD...9.....O.Oa.F"..5.D.V.[...>2TJF./c2..."H...P......fd.A-..^.......JO..<6\...bxKV.i...I...=K...^..cG%.Jo"2..o.....pu?..K.!..6........".k..I> ..<..|..U~..O...].c...R...:..nn....<m0`N&.........o%.AnLzE.J.}>.k.L..14(#..u27.{...&[..3R.6.%,.....p...#...UV.oo=.|.....1s.R.E.l.W.6;...p19.*.d:._...SqM.y...3._.:T.!G..i../.B..b t..$.l.....G.....*.i..}.s.y.s.'.\U...z ...k...0..<....w.H...:r.k.F*K.i1C.*.G)sTZ0p.2.z..T
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.5018418238412785
          Encrypted:false
          SSDEEP:
          MD5:138ACFB7A8880B0D21229D9C11A84C45
          SHA1:733705F5BBC5A79B4D1A05914B81D85CAE702AC4
          SHA-256:635D1B4EC1E7CF998704C8CC32A4266A0720FB0120C1A3F95F0E6EA953B6CC49
          SHA-512:1C22FEBED982B4C531E5F17FB9DB594280EF8CB834021EDD6E12B6076E360756AB7AD9CA967D9822D7B69129BC388ECA5FE3E1E1035B4EB267BB783B25DA2DF5
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................o....... (B.vd"N.^.g.s.....)...9A...."....<.D.m..|X.6M......Q.z.i......i.w.-0.EE/x....xA..:..6.#h1.uB..)..tv..c~-.<.Y....3.s......NH...v..Z.c...\....!.G>.>z....xG..+Z.....o.q.|kj.T....2.....[.{.i`[R..f1.&^Z$M.#.`.#u^.........x..}.6.....Z?.....).S.T...i.J..&...Z.=.?...[^E........A."B....C-.*T...1.A.87..u....8.\..p..j.u..zb.uid...).?.......H.K~a...g.9.B.*.9.b.mj......../.gh....Hp...|.+....2.7..#.%4sb....V......p..g;...4...a..H..G..%"\...-...c.'.!..kXX.9../..J.J......r..%4._.3..@{.......;.T....>..nBY.1.....O?f.t...e.F....s...d\,.Dd....X.....}......K...&M.L.q..|I.d6...|.u...#R2..n.........)..(...K.2....(.M.*jE...#)P2q@1.....d?..9....6.`....o..Q.E...ns..l.t.......E........f.v..J.I....3.:..U.c... =...^.kp.._..].a..+r...SP*.%d.-X&D.D..Z...V...h]h..<....y.....g...x3$.)[..2.wIG.-..N@....A.IB
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.498801099226739
          Encrypted:false
          SSDEEP:
          MD5:55C06BC078FF8CC9CFE3E371710F71E2
          SHA1:B0D52A37F98B989F8F0462C86C22B052EEA83377
          SHA-256:171DE32479F95A5131E6A225E0F244D34759EAFB39625F63F28292508A79A79D
          SHA-512:A1F5D397C6E8591673E32B1893AB1280ECDB9E268697D09C54181E69F2D4E54C25F6AE20E8E54A55E2555855549CA95FF1D549475D9232C4FC166B31E72E216D
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................d.:...[......eC.3OUW#..."...$.....2.2../..Z.?...^...D..W.aT.....#H..ZNJs..q6.Dv.....I)]....].....m'?.X.!.5.lV.t..o....Q.z.P0..F..qG@.M+...Bak.Um....@..d...P.......k.*..N.YUV.5..;...\.9.....Em.............9j.....+.........}.H.C..Z......X(...q....L(*.t.Yhi......-.?..?..Q..|._H...r..O.X...p...s.C...n...I..n.'H..1.C%..Z..O....2t[..+.S-.@......O*'^J\.^..\..y.......qa..(&.$..,....@.....q.w.....D.z/..*-g/cR...'Id...y.Yz[..Dd9.f.guv...C....6x....8....x|X.."..ng.6...........".q.....@`..|(3.....v.e.zj.0...W..^.....#l..K(..4yn.....K......{.R..s.w.=1....9~.!.......(..lp;.|b.......S..r..k89.{.........X$.8x.HG...c=...$.....`.V>S..&..\..U...0..HiJ..Y../\.e=^..".o9...r.w.^.Z.N*..=....%B..XP...#H...J...hu.l..w.....~...g..N......b...y.8.............=eB.....;..j.....\.].0.8s...:...x.rkf;m.o.~.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.506492518319511
          Encrypted:false
          SSDEEP:
          MD5:43E31C586085DAAFEFB3F03FAFD25BB2
          SHA1:66D059B5FEFE4A63BB028BF8F440518B4F2EC504
          SHA-256:3B9073EAF06D8CD1451FA781B6D5EE6C9F9AA82869C2430DE7238AF88531BE32
          SHA-512:099B407002044339C8360E1C6CBA2FCDC13A5C6A114D0ED51D84B4325F94F265AADC4F91CD06714AD232018AAED7E0F4B195B8F7FA068D1B0611E0639326CF35
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................h...P.W.$.'. .s1*.3..M.9?.....#@!....q..L..c{.+.(.....E.y.K....*.t}....0..7.|@."0c../A.@=..3.YW-1..Ap..l..PW^.1Z....]..%0.|.LH.4......`/Og...z......d..}.....^r.J]Vng....f}..aa..z.........5<~?..4[...oF.R.....hj.]6....S.,j.7.......:...e>(.}.B.a.d.y...A.....$..~W ...Km.m.KI..Tyb0..bU.S...`).jv.O...'6...XNQ....~.u..Y..,cZG......O....i..Q.vdWp..T.7.t#..?...l.<..(.......x..[/.y...Z......l......T..T~a.B....R.......;.pT.......v..c.....I.w..Q..9X.Q...{k......8..E..C.'...(.kJ.e.......mw..2.T.k.s!..~0l%{.V..z.Q.A0.~...!..&.....y...-P.=...@l.9.w5Z./..;)........}..9[R....2'uB...~..|.?..2.#5.....L..*p..j..*.....*..Ns~..Ddo-q0.p....Y..j.ka@.".}..W!D.b...........o.x.,.`.....~.M.)C...p...C...`)...T...f....J...r-.r....?..R<G.0...zN.$}.*.T.W<..?........5R.k$o.9.u.wG......v.=.q....!..Yj.dd..+.v./.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.496141358645843
          Encrypted:false
          SSDEEP:
          MD5:4D36415EF7BD6BE4F11A90CE48E07164
          SHA1:CDBFEAF6BAAA2CC9D116A3902410D6F40B430E63
          SHA-256:F16A01C6B6156E6BB038CB4A0D260056826DA193AFC74254EA8D81633C3C8704
          SHA-512:08D0C66CF7B6A887829F81B4E6ADCA966901BA57C3EB4D8FC2ADF3BC2CA477CB35F6AE2B31C55983874FEDE02D1B835DCEE5C2EC04B88C01898E68793908629B
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................j.9r....-v..$.8%T#6...=.5D.I.......7@........q5_...:.'..4.6...s..D.t8...\..k...y.^.8s..Y...\&.[rX...Tp.M.i."@.Y....^.x...."......5........KZ.3......~...@.S#..)5...Z.....i..x.Hv^!.*..KW.Z...(Ls.,}...c.'..h.V.$.. ....G......#T...F..4Lc...m.po...2-...........+...~!..E}.......A`5Q..R.p..S..M.D...pOw..+..M...IZ75.`..m.Q...........3.........20...`..@.R.}!...&c.....F;...<.... .QG..j.........#%5_K\...3.../..>..O.R.w...06@b.1......F(..Y*..*.<@.c..0..P.....'.....5.....,.'........?r#...z/..2.J.....,........Z.....UI(..NV.....t..U(...=.oiE..?...l5..(.....w....4D..Q.$..So.J,...N...G...XW`3.Rj..c#\c....r.H..`...q.kw..T*..|.c.K.l.Vf.x1.*.Kz.....9.gK8.....tA.C..G2.DjJ.7....!...D1u._[.i.........sK....heb.'.5 .>...A).@.{..0.z.R.7z.t.....3.....x...4..?....l=...C......s.,...1z.....X1...)q..rVp[
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.4930612297711825
          Encrypted:false
          SSDEEP:
          MD5:15BAE65756986C3CC5F7C78C1EFC796B
          SHA1:BA956D6D19399B904AD70FAE2AF2C4A94F979FF0
          SHA-256:32081633644F56B05DBE1DB6F60708886923E38E6001BAF3A4CFA3A7A2302444
          SHA-512:3DAD52D4723361935BEA1A524B1A9A26B975B6449CA1DD49FEA8F16B0538860BC3225F1334EFE424B3E06BB07EB8ED2DFB9F5B709DD016E7DA06DC9203F05096
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................7.;.O.)[x..3>..-|i....`.f..L..w.T..s..x..n..k.......%..mo.R.,....g\.3>[....qEiL..o..t.$..E..65$q`.u.R.-.Y.L.R....6...e.j..".E....<W.(.6.+.]eO!..h..f.f...*..F.. CA.._..nFn,...._...PK.u..6.X.q-M.J.&...o-^...J.W.44...T.2..mf./..]E.Z.[8.^...X..W.&.......Q.o]~/...3B.l.2.'G....N!..?...!..U...j.$....JH..-z..O6f\.h.......g..E..].pI...2....xwY3c...A.x-.......>.mr.8......:.....v?...d.i.....Z.....{i..J..28W...G.=Z..5y..!:...\..H.?`{.:g...<....>....i3.G.zG.../..'..G..........a...T.C.#).l.4.|(..:08........(."..._.ba..w.ao..~0"..$......@.Z.K...h..hDR7..y..C.?.e...C...~k...l.og..2.......w..u....H......J.<.......l}.1&1.-..'..t.Jp].U.....^.7..K.3.:.\..<..8E.9..*....\@..d...f....|UOxN..a..&...Pi....n............$...c.%v..0b....v....e...2@.I.u;..g2...0rm....jh..).]...*..gTe\....u..N...w.w..r.?..y.6.kB8..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.505010738657248
          Encrypted:false
          SSDEEP:
          MD5:5C6E4E1AAA9BF5E0D5375B6E16F14B67
          SHA1:B46529516C635936D68E05108E1334F56D573058
          SHA-256:E219F956374140B0543545EDADEF6547B1698EF568D039092362C89A457E6A7E
          SHA-512:92B426FBE682057329BDC86FA0B6C7E5FD89A37F5A6F5740F9D21A105D21E3F76A7340F02222BB2394906A27420E33BFC49ECBE8A95BF47CB9163896894EF104
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................#...s<Bv;...I.......6.XQ...9O....n..-9.R..,<.`:T.a..~..SG!.....p...S.v...vLu.Y/...?S....%..{y..D.E.4.:SY.^.,.......*.._%..n..t.?..=..U.MQ..0. ..m.....]s.{N..........2....1..X..c...S4.....a.z...R(.....L.].O.o....-+...n......S...8E;....J....B.U.K...5Wc...h'...c..l..L.K)V......a;.,O{u.f.R.7NC..].b.H....J.._V....(..r_[/A.-.D.h.id.......p.<....f..I..T/.q>..?...Z..!.:x.....F...jU./$0w...j....iR$......^..'...1g.....m..2.P......G.]O..TY....eT..6.*&.=...[I>...A&Tgo.......q.!.lzY@..C.....$.....z......2.c.....5.C.\..\~..=p..f;>....:#.S>.......Idu..AKrg.S...E_.....Wv5.^. ...F.%..._.i..T.N|..U...9H........z?%.B.X.7..E.z.Y.[u....9.......%a.A0..w.NZ..vtl....Pz8O...EoGg.^..gI.<.D.K.|.O.Y.R..../......QfF....j^.?.T|R>...=0W`\u..S..mqK%U`F.....8j).. ....8t&.y.<B..&#..e.......R..DU.._:*..(.r...].#.K8.....
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.504872928039021
          Encrypted:false
          SSDEEP:
          MD5:3D6D6CDC71E8D25527126A55917E1E86
          SHA1:BAEA7EA161CB31B0A58CADD453387E02C1CA8100
          SHA-256:716BB98EA8577A0ECD4DCD6F65AEC9278A6BDDFCEA0BE4EDAC7581B6498EDB5B
          SHA-512:ACC49DDE35AE8D1400A1953B449AF9785BED33B94EDCD5E2187264930E87FB15E5427DCDC67EF5336B254FF4428D9BBC6FBEDC3F99DF4AA91F149CAC4E4225B2
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................;K...Vd5...EfeI2W.;c3..h.'...)..g.a...-....B....{.O..>.qk...^.i.K....a..3-..|.....!q..g.G.....1.'..........H.B....^@E-..;bJq...>.....D..x....|7.A...h.T.f.....).....<.T3 ..L..]/j......N. .^.......Y\..84..c....M1..i.-...DR..3...s?^2....m..D..z=.s..w..R.A&..b.I\....&......G.&..o....F-..U.r..kA.a.....&..f........b.I.N.T....<.<N..Q...gw.M._.pX0...g.s[3.l.@k.....K`..<...s...!...i....>.s.Q.>F.2l.2.y..?.Vi...(\._.b.Ta...........C..9%$U....O.k...sQX.8......0.!....`n...9.A..E..........\-t...}_<.....&].)d.....)..*...r#WF]..6d...K@6.....Ng.....~.".1.KIe.......Y.;c...i.9..R.+:)>....$.R%.e.}.2*.+?.Gj....5^....!.0..N(...C....<..,..1a.j.`.)l../#p.%..2.]..x.*okY..r......{.)J.U.P..M..0.....n.*.......z.......3u.........d.>.>k./..]..l.W..U.....o.L....k[M....6.....`.R.C....s.n0...2ie+..:.oM..c.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.484419225769953
          Encrypted:false
          SSDEEP:
          MD5:04FBB658D1E737707E3F422FB9139A38
          SHA1:8B70299CB126A9DEED188031021616310A2A5984
          SHA-256:5C813B92A588A75752ABD4344D37A5D5A335C4730F2298917710A44A0B0CC309
          SHA-512:746DCA079455F961FD930BB5DC20603976D2F176C264804132B8DD03B71EB9E272D645F6E5C73A376325D90A89903FD63E54F4919C8588AA9274479BA8A2119B
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................h....W....%.S.He..i`..7W.]...6..#....p..E...,I..l..'h..?.+.?. (...X.l.....;..8}|..5..2.&.K..m......t...r&....P+.2A/...5....X7.q._F..c.*..v.........ox....)Q.3r..X..4p$..jK.v..s..TK...../_..*.@.......0....`...X...~9W.QX..!T....S..3...c...*.H.........._.p....7..P/.0.$..D.=.n..7.U....#....).S.......a....&m.R..t.......v&..S.J......_6.2.z'......v.r....}z.n+>.j,../..p.{...'......Yd..m..].6$X....SK...r...C."..N.}...[.....`.2l05..o..2:.._...b..,..pi...(G.o..yL.......T.!..\......o.Z.....8??.....[`..&G5...Q.s..!...^UA. ....D(.#...ei.P.i".p.~.S.1)..x.t.~.!7...a:W!.[..q..i...6...`.c.....~.x....ny.]y.{X....A.%.jK......(........miv.....xXaJ......A....7.y..p..~.~...%G.....7|Q..N......h.~......t\.......LWD._..c...MIg6.t.r.|tK.....C..|2.H...mFY.q.y.....sf..jjKi.f...QE.......>..F... .g....c.....l
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.508973646595516
          Encrypted:false
          SSDEEP:
          MD5:35C2940929C8F93BD5968C7119870AF6
          SHA1:6449AFAB43AA6F9AF3EDB7C6D567C7AAC1F2CF80
          SHA-256:C3ED1C3EC13E2DF06BAC68A6D548A9D393AC0BA6D5D8A961A56ECDD02142DDC5
          SHA-512:544F723DD852B2F9BF9DEFE68956B01C0B62F49708D20FA47322E978166CF74D2B187D980BF0D771F2E52EA502D0B4AE982334586E569564F2871DFED518A3BD
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.......................................................................................................................................2.8.....*.-.R.Ql3b.4....e.x..F65..L....-.;=..o.k.../..t.$. K.E..5.#..R.....Fb..>.q.M.......8....Q..(_%...E./...].....d0c..+.KN7d.@*.E.w.W.......`>..7.J....u..;.y=.-...Z....B.;..../.&.?Sc..:..8...M.e...@Dt;..N......$.e.K:."..PI.Xg....Jw...83..XA.Y`p ...._P....u.^.[_=E~.Nx..k..;....<.Q..AM.D.A.fO.[d5.../P)k...y....z.w........#..U*).#.'.LH...};3.W]b.A..}..u.C...z.&...nW;....'.....(..5|.+^.`RI...z;D.h..*U.`?.@M..U"".s.Z-K.<........Ow....U.8d...;..D...N5.t..M.tT.......Kq.p..).R.... ..WG:.....gQ.Vl4%.8..O...Q!.t....F..nl.....O....$..\.9.]..j?/......O............x....dO........?.\0....=...]kO......y...`\.v..`y.yLa.d..r^;=.3Mp&..>........z...K.r.....~@.m..A.......(...I.9.iA;..scS.....Q..C.3.W.%....q.g.H2.ij.^9.s...b..M..n.Q...@.|..... ..}......Ou...?.K....J..................n..i..Q.Wn...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.5240402545991
          Encrypted:false
          SSDEEP:
          MD5:74FF5E578AA2B48F8A04D4B8757C5071
          SHA1:14529058BB032951A6F2D3F2D8E8C2C4D9A2A335
          SHA-256:87DB63E33849E669A3B24BDF14AD070280FE2C18CE03E7E79564F7FDDDF664DD
          SHA-512:9C21F716D5C92CA90F99096928DF8A9917335DA15758CF234B2378BC9FF5559A507FBD8C2B65499D8EE8DB3510F655FD7871A2FDEE7AF1A416FBF566001772E2
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................a`........5h7..L..s....W.zD...~...5.......S.+.V...q.....`..~......FT.....x.DR*..fY...~...b.E8t..1E.FU....J&=/.....T.r.a.}.....yu......C....[...4....I..../HM...$.@.T..h..g..<..3E.....t>..;!aKBJ..l.gO ...n..n.....O..'..;..<.5......:H.i%.....R.8:`gs...e ...4....u.f.;.......?re.....f....Z.....A[.(....y!..j.*......x.y.....^>.D..Q.8F.f.5.=....&...?ZK._Y.Jq{....0.....gI.q.....a.....+&...(N.+.........20.>,..G.`....=)..8..$...OB..!.q.`...g.5...XC...q1...v..]...n..........\Z^.9kr.'.L..&.t.u.~......1h....Lx.O...a.u...=.-8....q.....3...m.h}...M(....N.INm>.T...B=/}....)...X.......!k..,:4..G.d...x;k.R.b....eFc..l6ss...2...3..@.....>%....=Gd.v]S.4..,Xy..l.L.:...M...d..SVG....KW.P@....U_1a.S..%BH...FL.^G......V#W....E?.A...?|....;.coW.a.$..X.._.7......m..2.-Bc........&..I.\.^...A.`x../....
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.478123335102845
          Encrypted:false
          SSDEEP:
          MD5:80139961E309C676422CDC4DD475A581
          SHA1:E80B78C294A33203D3F54CFA1B769E4E706497D0
          SHA-256:A5CCD95887BB327B863460A22F6FF72DEA34D54720DF4F557DE27253F7B9FCA4
          SHA-512:0FD1662E5DA1B593B3D2DC437289DD2C4641A02543AAA0D9F771B09814E14FAA43AA63293E011BAC220A3BE6CE5BA30E63D1E45BCC9F0A1260ED5C123F118BC4
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................@.;.....X..&IP.=.P`........E...A._......v.N..!y..r......\..\..9O.n.kX...\.t..4A...np?0..b}?}...c..?.(]......K......@...\W.(.-."....!..[.&@N.hj..gNJk.N.B{....Ug.ey.y....y.Q.A......L.'..Tf..G....3C.*...,1......+d.(.e.)...m.......%l...L..Lh..'j...{...M#...^..v.Q.t.;.e(...(...}........x..S.*......=h.....L..0..@pJT`.A....e.....V....p..o."._P&....K..yL?1i...+. !o...CR./W..M..Tg...../..*..j.lx%A[\.YV...q...wz9.............a.j..p...B./Y#.2.'..m4^..VH2."..n..&N.,R.t..W.&..`m.1.`...T.x.8yN..o...:...S.JeIJ.y.C...8`.B...G.....koxs.,=....Zv.;X.IH..~.?.b.o...c..L.3....]..#..f.c..C.+.....)7...[T.y(..o...Hlg.1|..,.B.~!.o.l!.....%......%.Hx..<.S....'.rE`.5.~+.-.-..H."q.c0.5/..n9X.n..2.......J9.S.At...p.V......b......XKZ.f.!/...s.P..L.G..Oae..XN....w..?E..t......lx.[!.mZ&/....$<..t...)}.i?.P
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.499059871315594
          Encrypted:false
          SSDEEP:
          MD5:87EC14071B58FADE5FEF4C909320CF8A
          SHA1:68E0B5F8D0D7040F349C9322229711C8C47764E3
          SHA-256:48B3ECC79FF59CEC54E082109309DD8D87872BF34EC40E358F74254D7C23027F
          SHA-512:08F44FC5B4C08397AF89BD3B1BD91ABCBA6456EECFE92ABAD9E8443F98DC8BA817FA2CCA79AB94FF94D128952A7844EB204E56DE55EF2AEFB71547DFA3E2EDC8
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................y;.=.(......`..&......~.t...C..%|&..@.._IC..a-4...P.>.rx~...c.E...6E.....!..nx.M..C.......H.......D...&&q...q........}..2.k.V..$....S...g.c.a5u.....^..2....i....u..H.......b9.X.....JZ-8b@,....F}....kFxl..1......Z......4L.4.........w..(.%hr.H..i.;...a =J9..O.th.Iz....~j.....:S.C.....!!!8#`.....~.=;V7..l....O.?...:Du.M..M.@..<....E.ay.....E.....-.]C7J@..'....`..Z.....~.}.....s.D..e,.#.h....N.bw.#..4.$is.. ..BCt..n.....W.&.Q$XE.H+..^.x...h.X~a5...Z....{.y...#.jwHJF..9..P:?..'.D..(.h#lL..Z.".~.....K. Y.h........<... .'q..M.N.}j?......\....S.J.:...=.ae.........M..!.SD.7.`.]m.|#.h........v..y.9'......B...8hc3.U..G..&h...P<....Z3"....<s\.b.....2...gy......L...G..9E...k...C.[.......Y..J.r(.1.f.#7.....w.B{`....$S.......3`}......SKi..6B...N........_<...G..u..D..&..?{_...s...F..HM+#...Xn..m...T
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.476667000193106
          Encrypted:false
          SSDEEP:
          MD5:1097B7BE46496DB1CF05A09B521F0B6D
          SHA1:CEF53DF58A41FAC54E8774A1AF9B35892FD1B235
          SHA-256:1104CC70020E4AFB242DA22328029F184EEF98143455DC5D616DC04C3A5FC0BE
          SHA-512:EDF3107FFB8CDC3EACCE8EDE2A5F73E963B37581D821F384F017B5715897A111AD51F924468A722145249397F601CE55B4AEC6EDAC092D241F6D30BF076E8A8E
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1..............................................................................................................................................q$..DLB..D..:.Hq`...-.VF.f...?..3...W.$sb.f..\.......|!.MW...c...E4......AT#q.0.j...<Er.........%.Y........q.%............).Ud9.g.[.$.T....zi.....I=.-2..@.[TP..DO=..0..%.....o/t....H^...T..g...;........Z1K.p...%...b..6);Z...[.a.D..}....R.bJ....-..$..2=t0...[.=..P,(s.e.8+....q..&..a=.<. "....%..;.w(.q..9.K.:U..d.&..F.52.@....Yb..:....7v....R.S^.;xk..PB..z..`1).G.y*...}..i..zH5."....o.`....t...JKE_.^.#6h.%b..9=Zv.....".j...c'...z.......a...B..5...[[.t...<A.*.S..mbbZ.3.EN5g...'...NR....."j...O..N..ur.2.c........#..ht^..bB..$`...n.B.e..w.AF...AO..^zh.]e../.).4...'...X!q...u..X4.d.fX....|..lR....S.#.....h4..N..>..|..I8...<......bw1.i.....vU..1X....W.+.e..".1.....Hj.s.d...m..l.;...h.%... ...(..N|@..U...7....5K.2.29%..._...+L....%.x!....3.%.?!.^.......S...kl...c.C.-L.)...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.526594601746644
          Encrypted:false
          SSDEEP:
          MD5:137DBAB7AC7DB273EC0FB73132F1FEC0
          SHA1:C5E009E48CBC2529E28164201C6B9C7ACC375A94
          SHA-256:ABD00BDC8CAA6FD33D1685CAE2F403416AA2AD741962ECE8E9BB10E92A03107C
          SHA-512:A0965812CEC569896DBAD728F8AC63CBF6883353EEC33B414F4C6D1B7D81C62D32895C272ACF3257E0917CE1A204C66C0B2200D850B38C141B1D696466122CAA
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................tY.1..b.a...2p./...5.....q).^J6{.'..8...dDK)v?BB..F.#"..k..........X#.a.sP.....4...}.{..w.._.W.v.F...8.vj.U|.?#...j..hVGH..J...r7..~........T....K..FT.......x..._..@W...6..cw......9..*..D..M.}.3..VvJ..L.;..F../Z.0..b....\.F.....M......i.b...y.\....+.~ga.&...<ac...:9S.f.....w...).M...k{7("+.cMi...p...%.....e.)....d..0....-.......x."h?..m..s|.k.aq.{(.M}.h...Wbm......#n..H%..A.?...k..;.W..K.q`b`..H.q.../2........d..T.....h..c..........>N.y.....=.vD..e..3...>+@.T.......z.B..L...w.$.?y...\ ...5#..a.._...J......."..3R..G6ua..o.....S..:Dl.^.'-.T...&#&.)Y.{..y...]EG.B=.W^.....r.B...AQ.Dc.z.X'XS...!d...o..]...6.Or.+...9.N74:!v.8.9.|.u.&...z.[......8.,pV."..c..O, ....r.x.........3?KN...5..q.s,......a.e[.; ^....ZgHZ.P..6.%..<.......q..........C..|..jADO.R...-.[yzm......O.u.m...?1.7Q
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):583
          Entropy (8bit):6.524373607825347
          Encrypted:false
          SSDEEP:
          MD5:133166D626BC8E4681C3CA0240331726
          SHA1:98B2C1A8F4AE0F66B30260E95BC4BC9E48883FE2
          SHA-256:20533D3C6AC73BDC895379B290C7CCD57D0F81C56771F44ADEC6CD5E3F35B002
          SHA-512:FC9F5A9323852E14F4A4ABE3EF8C0F4AE744D2BE17DF242DF20E0A2070977B23A76227016829FCF32112865A0AC8676C023900E92DEF4419F2610038E1DD43BC
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................N...g(.!.0!..P3E.....r.3..^...h....\....K....$-..'.[3...+.^...N......[..pS&.bvw.....B{zHy.|Q6.1....,(..o.6..~.x.T..3A........ ...H.L.j.....*..n.N...5.`W......`...,..c{.i=...E.&...U!qR....k...S..e.xl...zI..Yc.B.!..[".A....<.Z...H.......)...K..jD.(...yI.....>.|....2l...s,....q...7.bq...a4..0.2.A.....N?A.v...L.............. ..$q.!.....53..K..F...kL........%J.?.[r.`Z6A..k..&...N.&e.kl.u...3L.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:ASCII text, with CRLF line terminators
          Category:modified
          Size (bytes):353
          Entropy (8bit):4.355956030814421
          Encrypted:false
          SSDEEP:
          MD5:6A919C737A4838CA7352831ECE9E75CA
          SHA1:5B4641FD551BBA7B8D2BC4E3D628FB34241565BC
          SHA-256:622B36B80993E6ECC9603F8A165A48AF8B487210FC4516EA4B34A58946814042
          SHA-512:E2461039428517BAAB39B384E2F5892D1BFC46104D5DCACEEF27151ACDD8CFBEB95DA81130974A1F9A86EAFA3612B3C6B030AFB783B9C1A89C6F3F45AB45C533
          Malicious:false
          Reputation:unknown
          Preview:Hello mattiscool,..All your files have been encrypted and your login details have been sent to me...If you want all your files back and your login details back, message meerkatworlds on Discord with your username...If you fail to do this after 10 minutes, all your files will be deleted...If you enter the password wrong, all your files will be deleted.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.511055348334633
          Encrypted:false
          SSDEEP:
          MD5:DB930AEFEAAD67441BE3F2FB00BAE644
          SHA1:C8D2A43F0AB60CC859DD05CBF6E85BE9678D43B4
          SHA-256:46F58F02EC2C728847770C59C68B31AFFE0AAE251280675EB58AC3FE66F369CC
          SHA-512:4E01B4687D31F47EE87DD6629E1C5C0AC01A3AB2ECACFC59E9189D12532CEEC4A7EF4D0A8795102EDA3EE4A647AFB58DE0F6EB3ADBE7C76A5C1613EA1C200845
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................4..B?H.`-H3.L.$kT....)..l.Qm:......_.R<......f..N.. a}....2.....Z.4w.j...0...2-V].. ../...F..BY..\5....:$s." .<g'.}..lV...nm9.m.P..t.g...P.51z.gP..c..3..s.<....z..hG....0oc.`..o.Q..2.j.......+gi.}amoJ..-..l.k.U.D..J..f.C..i9>Y.q4...p...T....r...Og.r-BR.......&...o....b.....YK...$&.v..5........G.u.@\q.O...m...O..-F\O./...4..@....N|.J%..[.6.s5.z......6w..S...d....S]>TC.IK.!...... .b..w#.t.....wF..'..ge.\.=O..KI-.....4.u.....-...z..-...s...f.......;q....R+C.-.....UT.....>I....&...Ng.2N}.R.|.,...d..'..Z.p...._.Gu...sc`..7...=..Dh...u. .cn..)...E:.x.]I...fR......i.....P..*./Zkf..EPq....C..F~0D).]..-l...";)......8..`.....}....n.E...,Z......<I....u..qv...t....N.w.Q........@...P;.c....6.,'[D[.|.lAb...<1..M.B.n)..I..beF.......e.w.({a..Z...%s.f,..|E!. ....z=X....>..`.&...i.......
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.498805609216399
          Encrypted:false
          SSDEEP:
          MD5:E9DF88AA8F6116DB76FFB001FEA60861
          SHA1:A2D4B2D56A6C477F5A9B9AC001189E24F0FD6C6A
          SHA-256:2D75E0FC24BAFDD0389E518D275B594CF64D54E797565089787AD13C00047B1B
          SHA-512:0061C244F8B6BE7A3ED2CDE4C29C27B8D28649E609B76099ECE2192C36427F8AF31BAB1D8F82FE732A0B9096290F07572C75D09E3C5683F7C64A7BF868FDE0AB
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................e_..7D.k..t....,.J.F._...K.e=0^..^.@.....F.N......`...^..v....w......\...@G...6....O....).t....Rv4b....5.....C..@....)...3.....E_..4].:W..C.....R{.6;.....3.x....n.xv..1*h[.....Xx.B-.r=.l84..P..M.`1...V..........H...m....n.U....*6..Z^4rq..Hpr9.N..2..Z.A.............0~H|......nf...'...h"p(.... .R......B'..j.Juq>..H..p...T...>...F<.R.;...X..%P...qj..V..!..r'.@h>iN.{.n..X@..9mP...z.....A;.rf.".+.4.{.u....o....q..".]....U..a.....?-... \..`.4.........|.6Q..>5.w.....TX..U..G...".#T.>...N}[..O........]Wh.2v|.z./.)hJ.c...T.!...<.,>.).Wh*>.*..)|.z..=..K.bY.....0..0>...Je!.52Z.:>.).gLs^..,.l...E7...2*.....R.^O.U.j.w.yc...-....I....~._...O0.k/....?...2..2.C*`..c...Ig.b.u.M..&......5...['|.5Dwa.[ww.S...D...g...\F2.70.{.y......0..g.C7..h.....<.{$*..u....O'......y...^.[.b.G+.S..@..[.@{?
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.505662449794098
          Encrypted:false
          SSDEEP:
          MD5:D7953E15E6F79FC5F3E106A283A01374
          SHA1:A35E023152F9243070FF45A93D6D87039C0E0299
          SHA-256:580BA71AC2FBA7CE391BA3D92465C0F26E3F75D6017260F5EAAE09B91C1B5583
          SHA-512:0AC5ADEA9F2F0BD0B1B0F83D987E54862B9D5ED08C1BC1B487AB0CA8280C73A3F9691C33597B1C5344A435C5F70A4EA6CD1FA36BBCC238B10A6F7B03C67DBD34
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................I@.q.........5.....OL.e]uy.}....K.yHx..s3....m...3.t03.p...A.+k).j|.m.a.....|.....3..>.&^H.w.3.5.u.s....H.b..6...B9!..s....oJ..6....3?.-..S..bH....).F....'......*.nP."..Q.o..^I,...o..xr......Y-..j.C.....e"h.6z:....[...;.X=.v=gj.D_......}.d...g......./..x......n. .....!...;..IY..L...s.Y..s.....q....l#.........}..N.W...........B.c>.tp.xM.<I.+...*.XT.z......v...".S...Md....\.....l....A...R.v...<.2-..jt..dM.w"..o....m.D....C..8....m....2...vE....Y....Nt.i.X..0KY...Ln..Yy.g....h.$..l...'J.H.`.A..e.P.u..F........N..w.@..0c..[..~.Jn.F.o..#G...4..}g.........J+jiqgz......{...q&.c..E...O.. .,E............Aw.|.RU.:..g.B.....j..O..J......8.*..(.........o..\Yf..[...Q;t......._.1....c[u 0.............rU..]....I..~X..x{*.z.oTt.-~.6.g.-.%E|qgA$V.p.Q'....>...$N.3.Y@.]........)....^...2.Zp7.7.T..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.509683262872797
          Encrypted:false
          SSDEEP:
          MD5:6E32DECACC96D7E70C39AEA129CC737A
          SHA1:FC7D80A8A134DD6577F53CE5FC91E8C5C0FD6B99
          SHA-256:D066C8A21A2EDB36820C96C7AACBEA23394FB444795D16AB9B22BD6C554616E0
          SHA-512:28BF45D8652479E59FE7FB29FCAD9AEA82F1C6B0D95F7B18C1D3878FE16FAC9F5253E056E61CF317ED9C6D060815838B9A0025CD31A6831A8D7147A1609418CA
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................X..<..K.#u.E/2.....H......_.X.f.....i.,.B5k...4.&z...J.o.}.....S.+...y....j.94..K.).&.p...[.i.....*o..V@...;.....:........r].2Eko......=.).. ..L.[.2E....P.T...(k......"rmtJ..@.Q...I..^=..L..*...W..W.~#.z.(.KZ..M&.hvK.,.....U}.d..5..t.7.......}5.>n!.../..K..b....P..l.w.......!....!B.H...O.1K..7.>M..1k...Wy.5....S.+L...s.[l}./.6..D<.. ......+._..DQ...!@y..q..r.dH..Uaq....K4.....<+NboB|!....L........h....T1.X.R...o>...?,QC..u.p{..X.+..`...K.6.T...l.wW..^.......S.l.,....`0..).'5..-Z:.1~W.._...^....a.i|s.h.M.i...4......|vP...5..,.$.UvZ).lel..`PQ.......#...k...6.4j....A.0.t..Pg..%().iF..w...7.|$...M..>.G.".2...D.5.BW.{.M.....[k..o.mB.`.k#..~m...C.>T/u.?.V...N...{....s...rW.........l. .Fy.=.l..H$.'......~.-....J...<......^...#>...|.\..(..d...D...8G[.V..P)....L.|......(.5@..>f^.]4=.q..`...I
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.51465463957274
          Encrypted:false
          SSDEEP:
          MD5:CBF1F92C8F240965E85557D8A8078986
          SHA1:E4F1DA87054E24AA6BD60C86A5F6775A19631A98
          SHA-256:79B5A2752CD6E9BBF30A1E3BED339458E41129729BE1248DB60D119934793DCF
          SHA-512:1B153A3C13D38FC0A345ABB258B45213E2066DA66B2EFE62A58FD5506F5526DA721540228C699D326B8CD5E3FDB3B14AED828955914065CD7B7BFC73084D4683
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................._....J{mm.i3`.U.......P_v........5.....3...PM_|.(7.w.>...2.[;.<.E.....|...fX.6Q..y:!...J.5Rf@...@...8Fa]{`.]..o."6..`O`...E=.g..P...R...g,C....-.>>..7..q.J.+..T.G..V....V.]N..&.u.....l e...N...|..G.<.....@...W9....*:..rsD."R...K.m4.%.x.,.O...]...+..$....l.......q..@...'SV.......A~..0.d.y.f.G...x.(8.I.&./...:....X....o2...:.7NG......2.i..5..M..2.Wc...Oh..........7S....x.w...@."......~U.....1...'..u.$..^..k...h^...(u..N....+... ....a.....p8....0.S.#+|.O...3=.|.....d.gR.l.3G9..0%........^..tE..i.<,U=.;L.U......*... ...w:...".P..A....H/1..s{...9s."6z.L....8...@!.$...iR....!I...B..O..@..l..K....!...~T.3{.?f[.?...p..2G.8C.h.j.....d%....X...'.....&.....o8Ph.....k.&I.... b#u._..~.....U......AF~...=..o.....Z;...E...zMkUV-.8.e.=.p.1.".UVH.r).cm0.h.j..d.Iq}..:e.X.^....z...0.9....G#c...Y..9.Y.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.498957263053934
          Encrypted:false
          SSDEEP:
          MD5:4DA5E3FB3A40FEF2C3BEE122F4219A3B
          SHA1:E887B417524EF235F535615175EB175C51BC129D
          SHA-256:5F6C3BEE7F690B2BA7151C36167E280778882B1B81DA68B63D7B31F0644414D1
          SHA-512:BB064B38E71753E41A9D4F834E77AE15E0CD681B0E954555E50C359EF90C9850CDF5C25910680AD01B2DAEA8861A7C317D518A5C0FC04F573368335174B92A4D
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................p.Ol.....B..`-.M..>..j+..t.|......f...n/._.*.<,@.P5BG....J..##.\..D.W...l..eL...i+M..?a.R.{..3u.....6..U027...AT.:..1}...u@...Y7...|WgQ_...Jh.n..I~.....6..-R...tk..6..|...OC.T%..%t..F......i....b.&..O.IJ...}j.......a.5.....,.X..qC.j..(.s9.[..h.....b..tSo.e_|.|,..x......<.g.5......>.B.zs.....G. ..B..:....d..%}..#)..6-.7....<Gs_...e...g.....`@...A.%.\....Ha<.G....be.`...]..r........)..}AX.=B)}..W....X:.JM.jx...3Q$.)ZU....d7.....e.9...F...C.....]q J....N.q}m.c]...g\h...P..$p.D.c...^. CA.......c9..4...b...C/...r.\.ED._.u..[..../\ R..7.%...F.T...f....}]D.1..I+..6.sg..D.$..g.U..>#.@.U,..bN.#;Y.lT.v...."-&.......$8a...O.$ChPR... .5L...+...|.....h=>.K.....C.5^.kXI...`wD.8M..P.==n...^.....j.]uG..|..2..A.!".4`.....k.M,....]0..(U...U.?.2.......D.`=T(...U..Ps.....vq.........o'./.!..(+
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.51632889671299
          Encrypted:false
          SSDEEP:
          MD5:96ECA0A65E1151A3D02529792D4788B4
          SHA1:42A2DE2E744FAB77B79DCC93217721BA349DCCA1
          SHA-256:3BD8F402FF9315B69C942EC41AF4F1E31E5BC41D292B93EC99138ADCCE9124DB
          SHA-512:6B430061D2F8132FAAAC531B315CB42425B66F209EE29838CDEA9F5C9ABE747AD562047ADB6D7730D3FFB8E315512EFBB9F8BF552E1BC48E6D78C5CB9B4A0C02
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................M.s.)6..........F._.4...0.`...&..9..y.......P.V..Y.........j......K.vT.~.R.....2.../..,e......._..N.<.|...YO..E>.e?.....)........|O.......?.#..v....TQ.2....Hu..N.,..a~.b1.w.y....?T{...v.P.6..r3...W#...&W...L..W...)...VaR......_...F.#e..b=.R..+O?/.x....S..A....u.....}c.#....rD4....ff....k*.ebRU3....5.h.J$N.r`R...cCg:V..X..D..:M.&>.t.V!\.D...@...*..c.bC....H...j7.z.....G..k...|I......).6.]V=.]..'...HE"2...Av.E.>n.zcDa..sS.br.y?....0.Y2..A..:X.{.l].>...A..U...w...DX........+./.R...w.x...v......8.m.I.9...08..l..33..y.c.....M..%$...>W..Gl...p.Ww...oto7.7$.;n..p.y......z.,s......i....B...n...u.......H.Cu.......!p.G....R..t..>rwa.>.U&.t.)..b>.7...m.'.U...w..U.$...3....ZG....[.bR.._..w#nb.8....p...kg.......JRP.t.h.yv.....Z....v....h...W......:...WN.p...D..W(.h....F..6W..!U.a....oN9...m.b..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.518685031233535
          Encrypted:false
          SSDEEP:
          MD5:6954E8E64DB02D62C4C127B8AEDB4557
          SHA1:88C46F9D7960EDA7EE771FF1230B6E0FF7B49416
          SHA-256:1AE5E2552FDE241FC1E736AD8F88E24490F5D534A358EC7007A83FD30361C7FB
          SHA-512:E5F9725C61D0E52D5352D66E26C94A53971B21BF205E7CE845D8369156BE5D390AF3B2B2EDE20C849860E4842C1DD061516334C871534E3CCF17F58021088296
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................0R...hy.pk......%.g#8..%.?...L..^d..............e;E*9..%....Xt..)...t...AP..q.v<w.'....(+....q*...vX.LZ.*.9..@]..P..Y.E..Yf`ypN.......a.:.p1._.&/..k.........>.Y.V.1~d..w.#.n..6.ct|I..l ..P.6/.....Jd.....l....m...}...c...h......rs0..".!.]j...v{./4..r..~.T.H4.7U$S....m,^....X..T.."..T&...E{.%..[Q..<..._... .....d.j#......[.(..R.H..<?Ak...GQ.......n..V.zV...U....$.}.V.+.m.....u&'.*.5..0....T....=....f.+..i...5~BWx.c....A.p.._N......._..r.DE.......N._...B.......P../.....q.eM8g...={R..D.e..........a.....O.....8..nC.=?8Z.f."......~.*.......c.2S/.(O..q..l]........U.H..u...,.4F.........4.i_..2... S...2z..).k(s.X.MP..d#.(.Ws...A.....s.cRr.@..{..e_#W.}.5,....c.....=..f..CN.N......J.~L.t.W<..f.1.!.(.vy.h..F......G. .A.$....5.ES...dn..'..G.*E..:|..UP=g.........Q..[WPu.......... .7...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.48550714602489
          Encrypted:false
          SSDEEP:
          MD5:D7A4E04442E5859FBCAC03A2E4E5B91B
          SHA1:D9028353D1730C4A0DE01280ECBC8B11840A31A3
          SHA-256:A51086C9C3F7DAFDE77CD8C1E8B5B72F72D687BBBD7B3AD79B42291E4ACC44B4
          SHA-512:21861E4E0E290036C51E43E9820FE108C52A7F99236F98DB5009318D465102DA759384EEE14654D6897940AF32A3DA9DC1FA32DBAF4CA9DA9826D1642259507E
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.......................................................................................................................................A.Y^...[.......].D\~dQY..\....P..X....%.M..Jz.....?..!. H1...j.6.w...J.dd.@...rWh.............z...4`.......h.`Ku._.....d3.._H.ab5..~.sz..m..Fu....y..w...\m.m.0j;>....Ms.....H...~.\.......@.).......AK..<..0..Zs.#.q.!..Wq.,..>-vjZ.P.gH..Q.M.u..(.X{...*i...ZW.......`........!Q.1J...<`.#......d..h$.c...I..U..!...ZQ.L>.U...i..M..X6..5.1....g.~..!. .....Gp.`..'.b..N^.S@.Tz..(...F..n.F.vT..J..e.........|.m..u.t.\z...P.@........{.....>.uXg..G..2.....H.:.[..j....h^.....4,&lS.:..O]..A...a.w]|^l.C`...m.b.D.}.h5....q.A..r.....WX.[..9_s.H2.y..I....F....... ...H..t..C.'....q.A...5.\Q..}}J..`s.|0v..&t.( cu{.?...'P5K$...B.N!.F.......... %...c7.z.>.u.wdS.y.\...x.H.....P....u.f..C...0..k..3...q....c.;.....z(.J".s.la.(.Xf.d......h(R.QF..F.WFS.....c.k..l..si$o..h0[..>.KK{"6..~Q...(.j.........W8|)..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.482887307392273
          Encrypted:false
          SSDEEP:
          MD5:48DE0CC19E8302FE49A959E9EB6B00FE
          SHA1:308AEA0958069C6AF367F57EBFF0941DD730FCF7
          SHA-256:65BFA689C8FAFD0A04E5236E6984C38685939DC60FF280D4451955E5BA47191F
          SHA-512:385102DF1F3FC5DC45F218F69C2D6D9473BB3925C734DB65DB495809B819D535E8887471E6B41D6B239CA487631E04E4838DD8E6D5B13E113E05AFC6FF76E085
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................l5l..$../....:+.c..h...P..{...*s.....W...|...F..j..qV~D..S..qoF.`..N..5.~d4.a0.V.Q.........9"_..Gi...;./i..Wq.\.m..mm..]...}?.......z.CP....YD...PA..#...dN.TG9R.._....`...p...).kf.......\3D..wRB..NQ.....R.^M.......[1..r5....}.......P...s;..3s...\.R.J.BE..#Sl...;....C.<.k.r...:...k.b].<{...tj...i.A^h../gcz....^..=J.U.R.6un....J..d.Dw.i..e.i..Z.[.._.s.Z...._e&..Ze.....^,{.P.v}B(........<'..h..Q;V..of..BD.D.A.{q..d.]j.4!.j..E..V...(../.0..d.\/.l...{...R.(..].......#.vTg...4O+.}..G..1.Y.......&>.C.5..8h.2>u.....(....L...$.8.z.WQ..-w4..\4..,".&>H.Z..!K..s..]..U3:5[!I.I.......N...tv&....[..7....-.GC.B.;..\ ........R........}.".:D|..=.{497.q...V_....2...MZ_. ...m......2i...F.L..U..Y......M....G,..;...|..0..5.@8.8{.8...Z.....,Tw.v..).....&....9e..g.Cy....'....sI.....v..Z..8....j.q.U.:9./...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.500926585701408
          Encrypted:false
          SSDEEP:
          MD5:986034AEF45CC9C6D3F1A56BDED20CAF
          SHA1:BDF38C32CB44F6E9CC508E297A6E043A91559121
          SHA-256:5887B0EE4BB0C6540F6B42998471C89E5D9589BDC2AD9E5139EAC4F3CACAB233
          SHA-512:2C861A183186AA6FA370F94733A0CD3E778ED668010D64FECDAB438EBCCC8ECEBBF0BC5A50BB3CF86D5C8EE789EEF03D8FCF386542B4B06B35DF7DF21DDB1B8E
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................5.JN.3..a...s..13c.J[..S[..4....7...^.....}.._@'......=.W....Td.CwT..~C.....CZ..u.-../.Y..E4..n..W5nb....Q.u2._.%.!h1{..(.k&h*nR....$..^a.0.'.0&[~.....KHE.H.:._....S%.|.K.;...T.. .ATZ.a..b.2E.......jPT|".$.SP...S...P...}eg..k%..'..c......EY.q.].bb.....G....yl...~;~cP.......8<...5......s..}x..u..h..........n.8...|..^A.I.x.u`.....}.G..JMO.?.B.%N...G.b..L[2...M..W9....<....@3..ko.U.o>..dMlJ.#ms.........Y.ze>..[..Y<.fbU...F.V.kT.c.T..X.M.H ?.<.@...!.G...o.N_...EN..[...a@.<.......|b.....a:.C..?5k.~.....'JH./........-.]..H9.....zz....P..Ob.....{.I+.!A.h.....V0eD......H...Y.S.."jD./.]f.g...1....m.^....m...>... ...}.....#E.`7j.R*f.S.'.2....XPD..j~...m\o...-`.n...%....z..^..e..+aH..}.v..>..".q.lf.".}Bv,..._.f.).i)Bca,.>..T..;......S.<..6B..q....g.T..K.A...y.H}.F..u...x.}K(.e..e...2]p.q;..\..4J9o.$<
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.494465561441051
          Encrypted:false
          SSDEEP:
          MD5:6FC6290C8E9CF5EB7716DC478E43A0D1
          SHA1:B40550568B67F11EEF40C95EDFC9C2181516CCF4
          SHA-256:906C8F85AB97436F0AA660E0E3D2B1C41B56785998E3D1258A56229F73338B6B
          SHA-512:785BED7EA67E4311230975C5B8ACEDA9E3BF148109FD040AEC44F7823C49360DB3481A172FC461B855DF6393DAEE02F98F1898F0C20EA713FDD08CE1063CB441
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................y..2.I...g../...K.....|.......r........6..f$.c2\.8..Ls....]...Qp.\..Xj(6.=..+a....95_....d..gM..!.7...Kl....)...-.......G.q.._E ! .$.).6F..Z.6m..].#...6E$....<.............N...}u.k.@.W.t.l ..W.g....#.....n...!.I|.p.J..*.Qw.......[Ke..t.?.g...{\2.wE.P.\....f.!..!y......T...!.....:q.......7.f..~..h..:e..1....B6.+....R.=$...z<......7(...Q..].l.'MC<..9....X.4...6U.....U....._W....B.Z..........>.TV..i=.....\. .]........4......].D...X4N..o.8.....|.:T+..h.v......"rP....[z.5$..Z"/...h[cT|@tzu.~..-..m.....0....u..c. I........p.+!......(.&LI...._.H.&.}.@MN.(.v.....\K."....?.}.}$.hd...gi.OCT.....fJ1"..j.J.f.O...\F..ch .3....q..qZ...C....<!..>..z.q..z........~%.?....-.U..y......P...e......A@@...+.6...............3U.?H>.....).Y.....o..l.3...{.l4A.>.;.._.t?K..ob....>.......J@.....'.zg..._....
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.468345052336045
          Encrypted:false
          SSDEEP:
          MD5:7F466052423BC18884BE375D58DF333D
          SHA1:08EBC6356B88C5FE7D773E4AA249857C5FB9DD19
          SHA-256:8571D604ACB95EB5EF8A459895F5D0E732E6292F45599FA729E5091292E617BF
          SHA-512:C41C9B06044317F13A773A54FD5873CC55ACBD2F45A03B930F1079837880DE08DCA8B9CA5F9E2D6DCFC5174B498F063F19DCB09A310A8937B40E42F5CCBF4A45
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................[W...'S0.d....W..iq...{..J.d...l~..z3..`..^e@*."..#..H.M~.76.s.#.....r&....d........k.{.m.$.=..}B.X...l.8.....W......;p\:.W4..r...`...l.....l..E.f.~.3I... .>.[:.=....z...n$@:.w...Gc.Z....R.!0d3l.{.GxB."<..._.b.a:...=......e....R.=op(Q.N.o..AD...X.V..,..4..bN)..R..z.9........>b..{|.$....Y...|..?.._.u.. T.....e....]..>w.).,...X...G.l.M.-...b..#S7az@,...iMk...A.....>...m..s.lj.|.......0.......t..W..S,/G.C)^.&v....Z.]%..?.e...G..G-....#N,y..wl._g..wG.u....y..@.D.Kk...j..../[.R1]......l.q.Sw...?..\..(.w..C.d...r./{-...A.....s...^..#.0......O..=.uj.g............wE..B>N....&..#J5AQ...Ae.....W..'XB.9.....9p....;b......%._O...w.F.^..D...n.....U..RG......]6...Q...b..XU..O9[..:g9.....A...W.......".].4....M..$....".0.Z.#...3...}h....t.F...s....+.....S.O..j...O.Q7.zM<j0..:.#.e].h.=S..c..%S1......*..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.491592020663243
          Encrypted:false
          SSDEEP:
          MD5:D4F45FC3749703F4FF5FEB401CA70B17
          SHA1:6608673C6B4A57809217A668495D882627D199B6
          SHA-256:1BDF5D5986F8D23AA657897368A7C184315EEDA50258C0FDD6C4FE17F7711CFD
          SHA-512:94B6256ED3761E6B4C4DC08949423C093359731A58AEF6CCE6F930FAB3B86811233F5005CEDE60D371F181E731FDA57F11D2821CBFC2FD2B29648E4A0779AB5D
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................O..WJ^...Z..$...........[.[...........[...f%...r..].~.o[....gM:)B...l...,......e....B_<?..#$..I..y.`...U.he..`.v.A....h....tUv:.r.8.g.....E.....v....4...`.3-.u.>W6 .....">.....Qg..u...)..._.9..b%].|.!.A.k0..jTP...Fh$pXxZI....H'..p..^^.......RGhZ>..}...O^.........wsR.....X....h..0X]7i.zZ.4.d.....y...+@..tr.}]...,.....B....Qm..f..AWs.epE....v.U.TtJ.i.....E}.1....W....i....aT.wc.....\.........Z\......5.!.k./Z...E!k...l.e^....C..A-...Hc....m..g.dy.{....g...\...m....i..m.....U.y-....#/....[9.5.a...y.g.jO..0..|(;[....[...J....#....6PI.=.'.-.c.a.rbH...3\O.V1..<..0......%......'.....].......R..s ...'i....H.{..\N#.C..Cf..P..~.N^.."K3 ...g.o.:....YA.EV.)Y.sB..CA.Y}0.%.z....k..8.......;..(.$....L..}.......J...C..S5........"..Q....|....O..Jv.F.....@.w..VA...o...(...k|.b..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.485367530607175
          Encrypted:false
          SSDEEP:
          MD5:0B094667D4784FEE53BD72F4864ADE5D
          SHA1:57EF4C1424EC67C2D72E49F0D54157826A7CA9D6
          SHA-256:2B3E00E98F84D3BE2DE72CED6FA9BEEDC4A240DD2B6C5F7652327DDFC8B43684
          SHA-512:A68E13038702C4417870D57EDFF377B32D23DE95A288AA8C2E7FB31C3F70C976C53FF7152C71F1E1E86EADAF700742FDAA483759DED5E54A6B34FFF59B5A87BE
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................x.C.D.mZ..2.-.D....y.....%..J..r......;.~\.u...s....U..C.>..t.....(i].....bR....DP.5-.B....&.Y........t..&.../.O...9.Nw....9.....77....H....6...*.{.......&.%..e.'.".I....VU..........d1.......,.7.B...F......Vy.7..i....]"...T.>..;.{X.f..........s..u..wH..5d.<...l....e...\....Bd..c..[J.*>.:.|.]....%.k..%..T......=..........1..1...e.v.rv...(3....zp..Q..#.../.....Y-O.`..d.....B'......\..DU0b>.r)...7../.n.q.A. y...u.....^..##h.*...?$.gbh..(j0U..a..W....mK....V........%..B#'.Ds.u........q.9.".'.....`)B~..5...hI.6*..A...8.)%H.....GW.0..^...K..F.[.t5.i..<...CH.......}.....w.F)...e.T...l.......Mv#5..VG..<Y.P..Y.G..Nj......{F....{.Y..........O.;-............A.8.m........CC.......w3V.e.-..a...C....*b..`/wQ.2|.Tc./..g....Bz...=O..}.4vF...W.?.F$E[....h7....3W}.....T.9|z....x8.vb.{&.'.]V..,.jM.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.5097560992192145
          Encrypted:false
          SSDEEP:
          MD5:BAD4A4BF8D90167EFEAED46B053E105C
          SHA1:E47FFD9FBF58D4CE12B4FB9B4DDFB296481D396D
          SHA-256:D8E6F56CF5319B6BFF235ECB35E9D560B21DC8253189CF0C0A5FCF420F5BEEC5
          SHA-512:37D7C4F980F3CB6C1121F57358D229B93A424ADE365153CAE4FFE70A3B84CCC4A43DFEC9FFAA0389F8BB57DDF9BA49CF34B69C8F105836B3B7E2DC336457FDFE
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................5p...-....f.|....d.v.C...8....o.[..G..-..{ ..L|..."o.].{0..]k....:...~..@....t.'X..*E{...=.pY.k....8.P.9m..........%....!T8A.q.3v.9"r}.......(..Yj(XI^hC51.F.o..b.{...$.d;d.<....:..4.V..-..R.6.u....C.mB....J.......<....lU.K..{....CwrH.......*...........Z...Z..}..d.+.l..].r..z[..d0.z)..V.Q..7..Ity..D.C.}+...;..L.........wX...c....D .W..+.b.......5......8....b..&O..bCX.....S....]N.=+?3..rp..mL.(..`...l..TL.`:......U.+s&.+J.......`>.y.d.2/....8.z..J.3..@r5.........T.t,..z.E..<.*...S.~r.....P..7.}EyL...;"..|..........+.n(...9P.)....!....j..E.=..i....lF.....A.Rf.....u.l.}5p..x..c...6.Fdko..W..-..r.N..)...[..S"<.P/TH.;..:`...H..$......P..;.Q.w.............T.$.(...?.b9!".o||...*.7'..........N&. .c.N..[7....d.....x..6.2.......`.X...L......Z.X .../.u3.\%....D6...|P.<..7-......./.Q.&...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.51909506665082
          Encrypted:false
          SSDEEP:
          MD5:A6EECA5B480E0CA9FFA47986A6493EFF
          SHA1:35E596DE7ACBB65E1A91DAD85A3B399A3ECF6F9B
          SHA-256:99B1DC5926B53BAF8679B9A8F1E0A718581FE9159039B3AC632277E04EE802F8
          SHA-512:9CB1BDB9591C42F266864C2329ED002433CCDDCD2C825FF53CA69F52E68F50DC21F291A8E36E7094D7B71FAF0499A231A31F417E81E188FC4216B72471556F3B
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................!0.!.cUc|.|..]...L.'..1.s..,.Rg.............;&.r.P:3.cL..{...D..V..p..R..n...'+..9Q/]..;1.|@......Dh.m.n:...;rXh.i...J.q......w)..g.P./d&...u..d.S2~SLr.?..hrJ.YHi.2.......7O.N....3A..[@.ox2L...R......9%.x....<o^4I.....h.rk...,.#...\h.....6.../.3\.Ji}D(....UY[....)Cv.r.H'.=.6.=..:....%...sYL...P.O..\c...|g.j...._+3}E?O.>...f..;..+...~L....IT....}...]S7.z.n.d.....R;0$e/.!*...X..O(D...v..........E...p...B.?.N.N..|.J.a...6.yI)...*a.N".+.../....O....m.X.`|.x..h. (w.k../\5...X):.......$....K..Y.Dw.F..[..a$...2!.L......#................j.]4.....R...g.2....cq.VuL.P4E!.&...p.s.#..."...,..'..-.=..Q.[:h:..o..6.....j.....~.+|8..'.X..qUn6.........k..+......Y...l.w`........=?.2....(a.X......g..v%.Q7iz"...]*.P...,,..b...vV......C.U.......!.V..g.O.......Qz.$..iWo.WY.l....J:....2..A.5.........
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.49183582613793
          Encrypted:false
          SSDEEP:
          MD5:F453DF31F3A9A78C6FB92A4FEFD8EBCB
          SHA1:B8E3F587D0B3EACABA4CC56E5940EFC69DDBA3F8
          SHA-256:AFE2DD42D47D1AB087A6339D20A7E992B5E2A0E1DEE761AE29F3903A54B50BF0
          SHA-512:27A90231175938C795C9EBFBDFB089F98EBEF56708B46D16095970466F6C90F4DA178C7D166E4D8E975A2A0527735BF558B99AADD62F1B6F372F75BD048ED4AC
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1........................................................................................................................................w..{ =4...6..c..M....H.BXO..q.)w?}.....6'...f.K`.....W}..{..3.N...(...Jj:..Q_k..RZ.g...l....;.u.u..w.N...)....nr...(...0w.$.....'.n..'.Rw.<..Q.m.)f...\..%...yv.Z.(..R:.......x.w..b........../..p.r...._v....4m.{.5...<.|.G..E,) ..4.vV....2sg..w1..a..........=...I h<.wnC.'..Wt....^.M'..........u........\...>5D..'Q..Xl....p.4".@[.p.V|TI....e...%..T.S...i...6..sn.O......h.).->.q`..t#....q'q....c...]$...b8Y.F..f=.o.a.H.D.T,.Qj.F...T.*J...........H4.F...\G5..PB..\j..'......B.......X.7.....3...[...Ee.*.W/qC,.*.t..X,.>...`....'I8G3I.1...<..F.T]..>N....(6K..V..N..<.5...s]In....F:.....'.v...(3...y..... .lM..(......R<.....X\.WL.q....o.}...? I.y.y.........K.r.V......jO-..*4..e..f......KA.o.........,c.4..vP#=......Q.5...5..^.2.z.N....W..>.,I.....%vH.E.Mp......5u.....4.V.|.)...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.516303937210643
          Encrypted:false
          SSDEEP:
          MD5:148C2D4E336B42DCFAC0DB65BAB04FBF
          SHA1:459317D8B019603D3BC3FDC80DB942B9645390C8
          SHA-256:A2B1ED59D7FF94B3094EEE588D6222AE4E3D2B02B1A2DF191E1C69775BCD4FD1
          SHA-512:71F160DAAFA9A086C70174B5ED70C27CC70D0FF1D1F81252FB14798541E5EDDD9A1343AE560D1846A7C30E0E93402AEB89429B0485389A70D8F57754B5E3F787
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................$.....+.zQ........I>...i..U.xV0.\`...fn..F..5.m...a..~H...z...7.;HH%a.....Z_.)..m.{u..@.%.AS.>.T.Xr.m.......n...^F;.NS..!.8....(.g..m.w..e.....F..5...,..N/.......AD.....s..f........^2.'...-n.&.v....f....#.U...K.^..(.JW/.8T....y....oN.o3..L....h.7l.go.......C.........?\.}...:-/2. I......~.$..^=..O}Q.H.:v.Ak...kd.,.O.yR.6}..<c..z..r.:^.I-._...W...0..$.Kq......-....Y+.t..c,....G_.)L.u.q....r?.M..z....G.`r......^Yh.5".h...q+.n...SFUI.....L.Yj..:+..3.Y.v-M."...........7....B.....R...Z..027........{.P~O].u.[..Mx...:....d.$=.f.G.u....+.]=M.rc.SJ....A.?6...._......1..@........Ls...^.|.b.?..)ZPiW......5..fB.....i..|..(...[FT...1..O.V.[......./.Q......On.../...G.B.......i..&.D.~<N/......F@C.....2t.!n.s.h..J("..P....`.C7..M.hM.Y....W..y..y.........w.2y....(.Iw(...O.....>.4['.Bd...OA.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):271655
          Entropy (8bit):7.999352433663239
          Encrypted:true
          SSDEEP:
          MD5:D6256AF97469F3A4C81F566CC001E891
          SHA1:1A97B3D7AE721DE2C79AA38EC024A1F4AC38F9C3
          SHA-256:33A5E5F762CD606D98D6BCECA0D177901550AC8ABF6203084D62CBBCBB91EB1B
          SHA-512:1506F74F1527F8874B024D2D288130A31FE1C051F38E7C9DDB638F2306C7B92B7A1B7B843F4ED63594A2C6B32C1495025CACC090F718210B2DB4023202D29765
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................'.Z9...z...z.]..t)`..S7..gk..GV...(..XY.. .Ek.'..6......WkM....Lk,..V..b.V.`...`{.L..4...b.!. -r.:u..0..1h....D...Vcc&..62.~..&m./.T.6+[-..y.c9.R.w.6..dB..o..<.(..^.....G..`...,.....).)mR..]...\...F.+..`.QO.>.F..k. .3....q.c.....82.2Y.R.M[........]....x.....u..b..]K...`..z.C....\W$=...<.H......M....a.k....wW...>..=.......~x...Y.#x..z0'.&....,.p=Ry2..BXS=..!....i6.e.Q.p%].....aT.nv..0.S....u|.xL..[(..,....>.....(.e'.. ..b..u..S.'...X.....U]..K./..U.K.e..\mW...{..{.#`..fx.kT"....X..1b.p\.R....x.}1....A?...V.7....sH.4.$B..M.N..W$@|^..~#..8).^.v...`..q.-Z0FY|.. ...0.U..3..^llV.}M2.@]..I..{..1..F.....C.._.).....@....?....#...m.2?.X..Z..[..:.~....@...7N..!"..5Z.!.`1....0\:......&.1.L..'.K\...GB...ST.!5.^O../....XY......'...... g..]..-.=.H%..\h......F.~)1..R.By.$f.........r+Nd..c..w..d.~.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.493024521678624
          Encrypted:false
          SSDEEP:
          MD5:1A53884101D72B41BAD1E12A525CFC01
          SHA1:7A24315D6A667F7716A4B2E4241AF146C1D197BD
          SHA-256:CC482FA8726FD093F771A5EF86EF103EFEF224C068EE97AE39C9129C1B0EFF23
          SHA-512:821E1FA89BAF9BFD05BED9F2023F65094AF8BD7011987E917A8237D2D2DC664954E6D295E4258196A689C8FF28BD74529E929F28E73B0CCDA215788424C941C3
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................a.l/..Y...q....2L?U.]_t.A...FsY.O...Sn....yq.'.._..>Gl.v.KL.A.2$........ d..s.j.D..eG......NDk.C..=..e.5X)d.K.oV...W.g.3D(Z/;..........'...cW..v..c<3.0...[S[3%..]...!*.M...b.q9....J....v}.....5s.k.......-.vU.<.m7.R.Y<......_.h..b*...*....V.rM...K<Al.r...e_....d[J....#..t|02.9.}.K...YA..M.8...gu...N.R.oH...{..9../..<.=.^....u...P.1........#.rEo..~....0e.7s.VGh.*.....C9EW..UJV...8.'.r.B6`.E.3.+8{...!v..0...0J.......0.....B'.qC.S...dl.....n.T..y4x.8...(.....(1.7.q..E.5..s..:.x.U&...1. ...T./......nt....'...2m., vx.....Sf|..G..@=.@YNp.)........r=.r...a;....u".K.h&.R....f".Bs...9.={7k.4..9.+....5(.Oy.fxL..FT...6S.p.....{.<....(9.x\.q..4\.w.|>..0..b.(.}. ..}0.....1.P?h..P..+O........y..bK..B.a....f.....4N.z|.&..#....O..(.....s..(...m....1..:......QCQ...o`....r....X.........d.xK...v6..G,.....
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.493542620639597
          Encrypted:false
          SSDEEP:
          MD5:94C7E0AB5988A403D9643AD6FEE5762B
          SHA1:BC75CE2023AD7827A145133894D2B810B46EF568
          SHA-256:124C4576C97F4A8503CB39AD2170F72BBCDE72E64EA60E99F993BDB9138ED2D3
          SHA-512:84DD7D1366511ECA0CEA3812648DE3DA8E87B4CDD93BF1437C3994C9EFD7708B23300CB91E918500DE16CEF95F183CE5CD856D63A09928CE565735D17DCBAE62
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................../.....2.g..[...m.w.....C.h........?/Z.....]....?..................5A..-..!..y.1.<W.."..'4.+.-!.....W.....8.XX....@...p.H[b.h......^..i...[..r!.01.}..J....H..D..+....)..L&d.X......z8..E{....Q..n.N.....K......]&..]P/..^..\._K...A..al.v.............XGU..#....S&!..........n....Rz.)\...6P..X!oA..=.........F...I.I....W.K.s...z=..e..fz.....i:1..@Xk.J$...k..:.c._q..<.0`.T.p(rh6rf.a...mt......^..&..6!:..>.AXE.t..eNd.i.&..v.uqW..M.....T...0..Z.].W.....2$.2..I.6..g......L.....*H. ^,o.YU..L..t..5.......&8.....l..E.a.F\.5k..@8....K.m.......R...oQ.}..;#."l.s...239..x.L.Y..U.8.Ms.G*.W.+...T.A5._.`T.. ...qkQLl.....+.-.h;.......R...[C..m....+...h.."...x....e........Qs0...`.n.r....s.c../...,....F}..l.........\.cq..bO.i)...lBd.,....T.^...\..Z..{.0Uu'jeC...Jx.nQ..i.V...p....,.....i.d.....:.:G"....2.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.501960710384037
          Encrypted:false
          SSDEEP:
          MD5:FC37745D305C7CB9182538E519120967
          SHA1:3EF18047C9E31C755E5341300E6F7C11FC15B13F
          SHA-256:09A07D5F320BF356ED407A4F0D14D239BCE8CE1A50D748B806CA2A9971984A64
          SHA-512:66F1323BEC6FED7D2EE0FCBA0785DE4E2B8342100F43D4EE119906681729BFA9B4D2D4969C3CE35FE48FCBA4AB6D5DA3334B4DE8F56F6CE86009A84FE90740B1
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................e....d......)..vcg.r...c0.W.2(F[^w8N.........A..a...Z..E..~{.M.O|.....i.Y.V.X.rs.....+...."K.qO^.N..k....^......=..U...~......b.....w.'N...%2.Q.N..k..K..z|t._..k....vP|^..+;..$Voh...pCC......Pc*.R.*.....Q.......Uf...S...N3........A.<.....v...~.K......aC......s..M.d..I..n..A&..t.W.B..P.A.s...K.:.F.....G...X.H.=.... Z....K........^..3U...pi......n.Z...D.7Vt.zG.....b..u...R....f....d.."......%.Ql.y..%...*.|h8#g{)..q|....].b>...}gQ.M....k._.D.....0..-.S...Q.ia.G.-k....#..*....`..,.N....<Nq.....z...e..Q_n..^...\..N...Lr...$.....E....1Q.{....zdX ...2u.....u........f....7.bQ<.N...),..s.....pz1.....f.A..Q..J4.N.y.T..$.w......9.ag..T..a....}:.....E....y....e)p.m....c|;^..~D.;...j.(.mCJ4.t&.K..:.I.|...AL.bv.....w......5T.z...9*.R".E..CO.....v...[u....~....$G..h.....1...6n..8A.b.O..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.515039596599514
          Encrypted:false
          SSDEEP:
          MD5:71F1408167DCC7BF86073C415248E7A2
          SHA1:7678CD67B85339E129B0B5E0E39B640766CBBCCF
          SHA-256:0013321F9602514E80EAE789511EC4D8ED679B2E3EEA6E40459FAD4F420A4158
          SHA-512:BDDB52863C4F4BB10C647CA76CB373A43813752C390A9C1F481DCDA0F15A0A2DE2CEE51A9DCED4ECC334C54476D7F7AF6F8A1471C55B8EF031346DBD78619438
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................ha.B...6...G..5\g.{..A...7.H)..(...H.H.d...~..]H... ..*.O....gZFJ....'..:.iw...S7.yq...q]!1...^M..]d.....-..,.j. ..b.X.e.b.%!.{..#.w7<5..c}.e.....'0..)...j...o...#...^<...j..Q..u.q. CI..,..L...;.t)N:U..2{..GNsb`........u...e..>-...O...K.*. .A&gGo..`...w..s.wn|..._......k.;/W.7Jb.g.c....d.f*.."8OY..>l.&.....V....&.....@.J[...G.V.o.q9.A.y.F\..A.3...r...h..b..G!.6/..L.b...]..f.C...b....x.'.I.....7^_..T...u..(.[..L5v&i..........p..z.. E@T....9....8B......H........T...a...6.,..B.)..z5_.]7.K....[..KE.6.I...7.9H..j..{.k.|.5..e...!W....U...u...<.)&;.+\:.C...b.h.x.Ki.-....".,{z......h..W.E..&.;....@%.Kx.cZA..sl....B2..9x!.+....oW.W.?.p.^...M...0.b..K...V-F.W.#.P.....d..U...`......6\S.....hX.Y.:..O..A.s8C..-..Q.....3..#r=~. h1.._@9.G>....P.>..)...y;..N..'..{i..gXF..a^....-...Uw.0.]djr0.pM......
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.521433645620502
          Encrypted:false
          SSDEEP:
          MD5:D634F6C4F6FCB2168B18FF4157F82C26
          SHA1:753FFA9938FCEA19EF0F0B73264113CF72FFEADB
          SHA-256:4EEF09D5C460C85A8D9AEC860443277359865A9D66CACCBC0ED2090F50B9907D
          SHA-512:BE069BDA6E7F53E33D1D8F3205E6079037A7EA5DDB2596D00A5BF17C7EE4B1F96F765F07787BE77216B2A74B1933659772C9072D19C6DB931DB37643A0E0A7AF
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................w2..W..i6,.{).....E.....,...l.V..|(.W..8....Z1qG..hL.L..)vk.2.n<.ms..Z. ...G.':....>%.rq..d..Ag7|#.B..9....~.e....PL.V=.m$...s...+"......n.Lo..A.5.T..m.6.Y...H3..&MFy..O.4...'a.1N....b.=......J..h.j.,tp...f.....UK...L.15...W.t...4s.$..C.O90~S..Sz......4xj.>p.:{...LTIz'.!..|...)..t.....miA=..=..S......t..?t....w.Yd...q...Xuu..i..HXA..p..?.P..jX3....3..Ek".....%.a...r..Z........G)g.p.....6........k....>1..~|.p...I.Wo..u...z..C.R...F.....@./.O.......N...w.}N.F)4......f.4..~SDd...\..t..a....Lb..g...T..FU..].!W....n6P....7.6.....sA....'.&.&........._PMS...5Tj;..Lp..?..z-.?..V.=^....wF.)y..._..e*t..#RI....@. ..... .....1...j.k.....v..m.6......0}...4.X>..^H..8K.sn...D.....Pc.........6.6...I.7..J.......3.n.c.Bd.K....&.......h.F.......ugm.L7..c.~....X."-$.....f<..'x....1]..I..#..%.wr8.u
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.4898091961180935
          Encrypted:false
          SSDEEP:
          MD5:8F46A607A5D035713E4D9BA883C30AA8
          SHA1:32C49B7D3B1FB180EB2C2B61FDDD477E5BE59D6A
          SHA-256:2B0DCD737A6324BA18D804B11B33CF3CC49C554089F01696083423B4A0A4F41D
          SHA-512:20630C39499F1C65264ECCF819E4BC3F93D8483505DB7286869A0CEBC548A1ECA3B322E20B37A01ED8AAB916EC54FE618759B832ACBD325A3B3C3BD02B2EE130
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................7....Q..}.Tj....jUw.A#..$...1S...a...3..<s1:.......ro.[...1Iw]C..G..N...S....n.H].(.Q.K.".c._.s.........j.....s.3O...7.8..HnWm....YE..5...}h>.........r..x....../..>......}F#.%3.V......YN6&IP:P7..L..X.kE`..e..E`..h....%;.S6.Ho+..>.CG#.+cY.. }.......t.._X.X3...$.W.R...w..../...N.OrZ......@(.J.....^..K....h.H.}.....y..)y.!...j.(]..J.,..[.8.&...=x._..t..Ln....:....G.T.] ..Z..B....^z....H....b.OE/.n.7..X.YA@.].4b"..r......H.#.....-..|..j.N.S.;.{.....>..d.;>..x.C.....)hq../....~r.b...h).+....K..$......+5.~`h..m.B..ODo.!.@x....!`.../M;..)=L.E6..V..bT.>.nc....z.z.%P^..=b.%nq...y%.m..#.G...fI..2M^.{,..2.2........r..C..C:..}..=q..a..]ia,%.Ts~qE.Ccp-...U.IO]Sz..(.|.-PN.Q.(..^....3...i.;b.|-. .&2f.Ha...O..lY.u.$..)?.......`Y.8+....Gp..'G..Y..Y.ODz....M.9..1.P3.o..hM......s`j.An..u.V8.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.500328534091824
          Encrypted:false
          SSDEEP:
          MD5:32F0DAD8045821136CBA5141934DBDB1
          SHA1:89DD00507DD01607FD47CF2744BB602EF8534B63
          SHA-256:6C5E2B712B0282E4C4579F975AB5DD013C8C3C1AA281FCD0B6C95225B9E5BECF
          SHA-512:75D6F5DF1FF7DC9608C19F340C4D0C0BA2577D263729B005429DF3DBF407CAEF194CEDA1BE0CB4C98FE3C72D45E8F8FBF2F64306148107948EDB2F0A84EA39D3
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................".....AB..2..~....q.W*7..Z.......>e#.-T....y...=.<.6GX.#t\.)..Hv[.....+K...L.wq......%....6.b......*....+..a...KD.2..^..........Pgr...VK&/.h#.....`F...{....f..L..x...=.......?../.m..7....<k...T(y.k....K}..,......%A93.......T..\.-E]..3...,h.;.R.9U..&.r..o..T..}....o.9...S.[.....gO.za......A.).k..l^....G<....0...3..#..@.z...]+...>.n...FPs.>r.M......XnO.BI.a..6.q[..>.,.#SC........x..`.x_....p.=6......-.r...R?6.(...(.#..U........n.*..}!.W...E.o...p...<.C.M......u......t.l..........^.^.t..q#......|~.....O.,.*....|.8'..........v..._.\ G..k....g..{.... ..HD).d......X0...**..d....y..j...Y?.z.P..ss.o..hP.......B...i.]..|....P...)F.p.:Z...<i...3K4A.:Cr...DZ2!...c.s..Ue_.#..R.....^Pb(....3Ao.U..M.......'...=.....6e..fB.G....Q......O..RA_.1..].=._.'...l...x...H.Shr1.Qr.jI........
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.449320210080964
          Encrypted:false
          SSDEEP:
          MD5:7982CC5D5F4FCEB48E0DC8589A40BBC2
          SHA1:1876D6A3CA651B14BD6A396560E79E287C41B29A
          SHA-256:E4F863D9EAF5A83D5EE6976062B1D2453E119985A0AB75EA8A97376D9F24F21A
          SHA-512:0F0C15C1DF662D41C587FDA5A756ABD8F234FB3CC4688F356F4D273FE8E8062278EC9CB6F51DCB41E7876DAB0D93752D17D1F8365D0FCD04F87AD8BA37531471
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................B..qiz.8...N\n.D....%.p...dd......}Y.Ue...x7V.....1...}.x;..^.:...9....4.x..M......Y....B..7..0...}.'M..C.N.....$.(v(.v?g.V...J..s.pt....[.....d...{.sa.l."M..2...r.>......m.&...?)...+.I0.....Bo.!.@f....Y....or.D....b.m!KgT..."`?.#0....:z.<.....ksM.<.s..Q....d\9.....G.v..%? ...(.!f..,...Er...P...q.{..%v.SUY...2...b7".1...:.......P.L..h.'..l4...:VZ.&.{..............?....b^.~.x.giOYI...(%-...6.....~]N9......"~5.Iz{HW?.;..x04........1..'m.....2E.).. ...O.*&....j.."..}......c..c.%...r.....g..z.]......b..|.l..1....]=m.&I.."..[..l...r...$..x..J. `m.].....aC...lM.M.M.A...Kmj.VEl..{..!...bN..k..W/.O.c.......- y?.T..&...zR.U.*/)..b..":.....u....0.,k.Y..Yz.d.c8x ....q.J.I.(.XB3..*..L=Q.>.U......N?......__....3..\.Q...B.....F......T..b.-.-(.Qc.*........i*.....b.p..M.b..{G.+.....L.Yc.c.{^oU.....
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.505657848915707
          Encrypted:false
          SSDEEP:
          MD5:1D8424DBB8D85D8667BE27A7BC160281
          SHA1:D057E3C79FCFB4408E621CB95EB003DAC8C0D395
          SHA-256:2840DA7BE5BDEFCCD5A7BED0C14BB7E031377D4F238E6EB236A3EC1D9AAF85D5
          SHA-512:E58F7EBE058B3B6769EE5E97A5A9A3A7C1C175E7ED665E8B812F95F21EBBADD978F1194FB5316AE779D52A1008F2C6F68821025DB54533F74BD3C0404E3E6715
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................Q.,..r...D.:...d. ...0<......3jf..3.......S.....?../W:J.K.|$.n.w9.....F...t...p..(Q...a.....4u..m.'.v......h...@...d.]F.!...ViW.d?.2..>.1b_a...... ...(...:..s....].O...Q...-..B..]w.Ii......].lN.....x.....7.?.#..g....H..[|.......2Tg=.....D.r....j1#.......t..m...kz........i......g.X...6.?$9Gu~.>....Z.N......3N..f|.n......CME6.2YX..1. ......I..a.GD....,.DA.?.w.Dr.c..[.oE?.`..P."[G(it. ... mX.!..>C.Z.R7..gH,\....aR.$.w...}........Y+.....4."tA.'....8....5...<B.3PM...Y.x....>.z.....Ywa..L..v..K..DD.c.3....L.....5..tv;.rm..ad...S.?(DX:X.<....c..q. d.V,......S..5dm....R..+.(..X..I.G..S...f.......GY...% ...9...'EU.*.m......d(...g.{.!h5...'!.\.AJ).._^..5.k....SJ...o..!w....$.p.....,rd.7....Y......[)...^^.E.....P................R..>g..}~....Znc.........t6.....6.....y5..C=..J.=.:......
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.502856858108503
          Encrypted:false
          SSDEEP:
          MD5:BF19EACE0F799C70685497E40DCFECAE
          SHA1:30330E5C8A225B6DF2A7931AEF911FCC066A531B
          SHA-256:4845DFA2083B994B8C4B0A4828CA2E8C89CA0CF951978203412E0666C40D04FF
          SHA-512:03C35F2503DE23C7A70D18B6E68390ED3A3485A2E1B8A824C87D8F790B2890993308C63BC63A9AA80008A4C1980B03FB9990D0F6D25F1D06A2CD1CF90414834B
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.......................................................................................................................................y...kI.-..'alj.C.u......$....m..h..J.2.(.OWE.!Z$.....gFe...siif.oK.....N..0.....b...$.2.0./e...h..M..?N.:n..fl.Q,r..N.P{..R.4$.y.[Y...A}.....`..D.S.D..z,e.@..*.L...u..2.L....,N.....pkT...g.........A..>W..c.O..;..#......%q.cN.....a.....+..8.J.4..=...C..7.|.....kO~... a.......A....T6S.mT.<d.[u.m0....t....)../.!.....9....RD.H.*..V..9...d.....<)..e..I.X.lJ.O.mmU.\..].......T.J.1..Lg.&.l..,.I.{Y.>h.....]Xd.MA..(36...).."686<..`.u....{.J...G ...X_.L...bT".ES..~qf..;.1.r.....r.W..Y.w...5.}....7d@r..'..cx.vD.h6.:.Z..X...k..$.4.}.\....iS[!.....n..f..tY..gO;...J.6.o....n..Lv..l~..)`....w....dm.....8. .;..[W..}...m.@OTy.....P..p....T;.............s....,.........u'2.eh.$~.|a.]/J-}...."=..o..I.D.J....a...>....d.u....^8.[L:......UK..R....0.$......T.8/d.g.*...Z....8G..G......E/.Y.'g.:*.......4r.....?
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):711
          Entropy (8bit):6.851453141522426
          Encrypted:false
          SSDEEP:
          MD5:0ACD68EB569BB00893D429AC2BA3B52C
          SHA1:71996D6A04FE5EB1D2A59F34276114E55608EF8A
          SHA-256:A8B7552EFA514732CFDC72EFD839A54A3C154CCED4726F03C1EEA1276A6E9873
          SHA-512:01081928EC879ABEB14C6FE2DEF51E22A412B34DBC9E1067CA682447F73C42DDA19660AA2B47853DDD23F20C5031EE0AA71B7D4789AA4549CC580B35C012054D
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1........................................................................................................................................9...>......l$..%.R.d.>...z?.....V..Rs..z......q.6.@i.=...2......3s....^l.$..E.F..N.]w-...6.Q.,..96g...y\.!...`H...... ..8am..m...x;. .=.....a...,.d...'%<.y..4v.5....&l2.'.z..A1.<..>...d.YBP.h.u.Ju@......-.p.\.....f..TX.%.....6.I../....|...3..tL....T..A...\.(...........^w..|..h..[.U.......#.e..;..8....xL.....4...||=....N....T.p.IQ......[.C.RV..Zt7c..~...!......I......F..Vp.=....GeD.]..}#...Dr.x..?k.E.bU..N.c#.O..!L..|.xl...A[..6D1a..U.-P..p<);Vv....q$..Q6.-.........Fp...b........1...!1..@..81C...<M...|..k.Wb..?.T.Q.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.484757608986946
          Encrypted:false
          SSDEEP:
          MD5:319EF48F1FAC66274471167720F5BD4E
          SHA1:E441CE572E07F962C9C40FDC6A759E6153EED834
          SHA-256:B02EF0CC93EF8D4EA4044A2275237ADD1DAC26E8AEF384102949172251A52337
          SHA-512:143C34F263E734F20030D025E8536A9E17BFFE557703EB6D03DCA72C75568B2FDAC2629D1564C7625B585009B5EA40712A7C68A6F093DBF54CB49CD350BECB83
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................3p..U6.b..@..)i..\....I-.3.M8.*.(.]..#...u....3R:..L.U...M..!t.Ec1....M:.Uf.%+...lo.5,...)Y.<.o^..q#Bp...G.5.b. ~ g..?..h.WM..1....y~...YXCvy..P.~.....b.1.4.%...Z.#@....%...bJ..UtT3xO..s..a`..$.....R.l....vE.Q..W.......,.&.....p..9...Yji..,.Z.`....i...........T.&~dM.7..ug.[?y\Bv@&.......2u....+Ia.$.:7V..D.E...{.9..|G{k.../....C.t..x.....D..<g.W.vw....+Jjw|Z.b......8H....pOI...v........$.$._f.........K.E.VLTl..h......`...8.$.......$.J.t.&.A.k.Q.'.[. ..^.%O7..da*7O..m.@...O...~..H..t.5!.<.K.2.B.K$S].#..*........1..8-...z....k......M.....%...4..c.F.....1......g.w....@.I.G..Fpio."...<...}..O.....i..a......(...4..=.)R.U$[.{.61...B.t..&.|.k...R@.Xi.%c....^Z.y..9.........}.....j.$..q......3.?8..6v..M....iK....W..i0.41.mA....2... .v......._.."6f..,AM.Q.^k..h2.CH..K..A.f.c.....?.1...O].N..U.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.519573138212161
          Encrypted:false
          SSDEEP:
          MD5:B62155B2764B3710FC166AA283B24686
          SHA1:11CC7C37AF3FE59F6A2205AFED2A21D16F484D2D
          SHA-256:1C84FEAFF4F5932C23827AC45DC870FCF8B35E1C0B30CB889BA46770F00045CE
          SHA-512:064C887F8F2B1A327F68FBC01ADD8C9F9A5DFB1BD89871658BC47F2536BECC4A7AF16E5AC86DB80259F06948E89A548B9FA12CCB15BFB139210ECFF628FC1D37
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................-.P}7...h.QS....O......%....1@g-|.....&........a-..$/.*._..._.[.qR..u.>i)Q.ZC..{..u].#.zN/.....lo..y.v...-..t2:.i.../..6.Qj.+._xOg7J3..).F...@=./4.rb......u.KA.LR.~.!...Q.e....v....&V..mFn.......c....-....#<.......'.y..w?..E..o.I.Jm..a..D.\NE....N.a......(q.V.........3....Z....tG..Y..3..HAV........&4..G.A....x....)v.......<.'...5..M. ..j[-]T...E.........yNi..4..?.c...do.Q....+.?.*....9Y..g..X.W.<x3{`..z.....R....9...........l..2p..O.M.-.u.vP.T..\9%R:.h..Z.[...-Ds....Q.^....T.X.....Q...TL...C@;.3.(wS.r%.i.#.'....&uD{Y]|.b.p....]..h...o...$.+...\q/...._..y..Jv.C RVF.L.i.......[Lph.NFZ....J.t..+J..N.....v...A.a._....X.._...Z,E.+.4.<8..8hS..@....5<D.}..+........O..'....(l.*..%....B....+..?\.E.......=..d5...QK2.}..^.Z .M.@..:..?.,..U.).)0...P.4Q...AGu%.2:...t\.m.S..3...D_...........3.0=.$.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.500359760468648
          Encrypted:false
          SSDEEP:
          MD5:07D20754D052AF58BCDA5BAFBE28F2EA
          SHA1:B4B86F4D0B787B4188A939C68DA9673CE3E38C56
          SHA-256:BED4017C367B49A0D1A9E6553C6DC5C8386F9B457196B6A01350DD1D143DE7AD
          SHA-512:A239D8618EBA68B75AC16D806E41F6A46DCC20B794B8E27A137E1993B5F4BA71D4EE2591A171AE1B01FE297AFFADD95B876C4C765CF6EE5E1C60D4AF41A84D8C
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.......................................................................................................................................3[..&)..S.=....qH..".._....$.....1.-..i.]..... #..~Y.K.xf/....).u.*K..o@X@..R.,..@......].tt;...m).FiVfe|...@...S...Qb*...W....16#6....2..L+..= <.$.c......S`....../........T.I....9.8d....?...<.].i.C1.n3.N.....,....o..CP..w..8...8e...CH..o.8..x.p.-..O@P.]...T.(.V..z..9v...1...=:. ..H..S.y.........Xv..y........C4.\......O..[.l\..J.r.k.Ro7.N..~.a.x.D....6..#u...~.W@.....4=3l|..`.......;;XEIs.7T..Q}D..j&.....M...a.......;g.....>.......5... .q....."}....pk...O.`..7..u.E./t.F.hJ.<~j.%..i.b.l.....U. ]..y.~iX.V..=.\..R....R....A..Ka...X...vx....Y|UD+!D.../.=.?'z...;. ...1....r.......S/..z.L.^L......."`..D...t.N..?..}..G.".$..b.n..L...#.7.._...._~...7...).G..E....6.o.h....E8.Z.H..}.s/.LZ.....X.....0...e...V.o<(..as..&Z.P..xM~..N@zB/r..............p.e.<k(....DB}c..U..z.q.]..........8O.......{
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.51791661873067
          Encrypted:false
          SSDEEP:
          MD5:55D4542ECD60999B0B4340947AB06DC4
          SHA1:F1120612B25590D3B6890323A9D862D03CEFF713
          SHA-256:5D44DF18687163163C8D96F32B7FABA14F93D365E87D74DF40E2CF9292801541
          SHA-512:A5B7F26519A6AF8A6FA25F226139C26AC0DE0434AE88C4634AB7E734272AAAFF453B5E3DD96ED5ED1F6C530FA9550B544184EFBF326E2B4F3621A72FD7F433DB
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1........................................................................................................................................k.:.-.N....1..(....;.....t.....F.)...fh...~x....RD.UI....s.....k.{.I...g..E....#.......|}........pT..R..5n.>T.......9{.n2.Q.5.L*....eftl.:B;.ER....-n...|....*n.hW#...L.d.'./z.9./Lk.2..w....8...a.....&..utaG8..r.._W.. ...$R...:R..@....Pm..=_gb..U<a..,fT.y..I.y..|.z.]....~.~k..v.d3.,...._..6.nk..-%d..0.%...fdV.iA..9.l1..f.T....Bo>.CY>...b..d.I3.........-.u59)...8"..._`.OR|.a..P.,r.....Q........Yg.......r..$........f...aR..$Z.....8q.C.GU.+=...J+. <. !nf%....R..c-6.<..j\ .Piu..|;.......g....._..\.3..:.Y...%K...;.G..kD.K?.~:":...q$=..]s.}.V......tl.....M.._.S..8G..{....e.k..R.d...g"$sd..5.W.r..J.e..L+....?..EuS..l........Z....M.'J.:Z...;.;..?..C.;.v.O..D.naw"..yq.....A8..;MO.....eC...?.R#j....'.N.z.......I...=:+2}h.....,...Y.i.)..G.^Y.&.*o....:..tMDz..h.C............;l.%@...X5...au..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.516503100139648
          Encrypted:false
          SSDEEP:
          MD5:E521955AF629FBB42ADC40CDBAFC327F
          SHA1:38AE76E0083F9DD0A20D72F2ED2A8D243E4D14F0
          SHA-256:0FF25D437327F509093AC03DE5AAA439CAD093DA0E3EED481739054552E35EDB
          SHA-512:6E968F51ECB421EB086F6147881C4F496CA7B2D85807C69655DAD79F8FD3628DBC1FB2159CB1FCC713963A18B485B5780D25D873F28776B1595B56C59CCA53B0
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1...........................................................................................................................................|AF....A... ...~h."....(..h...I.<..N.{ .R6.2..E...dZ. ..1...o...... ..~.JL..%.......a5......$..0S.a......./.!...#\5s&.....F..Qd.......q(.......`3.:.\".....`[).t..@.......|.....!..........-&..Yk.&..~-..N&^...i~<.G)...L...x......X(.R..>.m.-.n%g..B,.5x#.6.......3>n.P.tE.4..t.&.0|s..-....8..ky...9....h@7......Q.S`.{...o...S...h.6;0|qV.._..j.J..f......!.y..<`"...D%.....Nz9.......KtP...JOE.....+s...k...)_.D.j.T.._..;e...|.n....o..2....d.}.....%H$p.A....F...R.?..mj...#....y..+ m..6R.../...=.LB......s..u..)...u>...y.>...W........z9..I..P#r...J.d.&.P.]W(..S.B..YZ}..Z..+...t.....hP.....N.=%.5..,..........#!...c...0 ..@....:7..M..In.k.Vp......D...RJ.:...w.W_.a..cW.^5...YS\._{.7.V......R..A~....S.x.).......G...|.B.[..{...........*.L....s.w.....CY(....H.K.?i.9.p...gd...%g".I{S.....[...J.8p..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.502303028590777
          Encrypted:false
          SSDEEP:
          MD5:31E2D4E95C523D863E99FEB807E76CE7
          SHA1:13E8455750A3FC9A7D6E13C5A5159371A6D5DEB8
          SHA-256:5345435D32D5D49F4E9A1CFA977A4772024D3A5041AFE3C9EE34506CAE468916
          SHA-512:84F0F127A655DA0E2C01D5941ABC223C0BD730CD6C472221E5E80E4036D872B46BE67EFD944BC4C6A75C5BC46B8B195F8D3DFE644B500101531D708618472DCF
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1........................................................................................................................................0.....0\.N.@yc....x.C...\.ak..bc...........9=|rqu.r......._..C..c....*.k..x.$%.Z...S1...D...,8........D.H..x..M\....[..mfK...^...I..)..QDY'..fS.@.o.P.dj.v.`,...t6?.&B..M.6P.....:]d...c..<c..E.....D.B...B..<..M.p^...T(,34.q....3..r<wM..Omt,...Ek^..$-.`h...B.z....B.Y....7a....&i.m.....]..z5.kt........!......GE7..vtu.z.E....Iy...v..D5 ..5..fPX.X..A5f\.[.R.N4.........%$..f(\..Z.:.u.Py.....YGQ...r...L..."R..w..|.....e.a.t|.%...lsZ.~.U......,..Pvv.."...o..d..5..U<6MB^@.!..P./.r..:.)..(..8............aM.!3Ean...I...>.5..=...\./..(.c..x.s..9...`0...........Q.F...d..~.h.B..`..Zu...K.\.7...s+....6bQ..k.....H...U..Ppp........6t.Q.#.....T..|..*....6..c...........q...%]Op./....j...F.S.oN......E../..i.L..I.|.U.m...."+.D..!.x,.*(......F...auhT#pB.........Z..e..t...{e.z.Q..x.....n.|...UTR4+U_.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.476646075738458
          Encrypted:false
          SSDEEP:
          MD5:88E12EBA7ABD1DDE62706F8A278EBAC2
          SHA1:295055B5D549ECDE5144AE42DD5186FED368657F
          SHA-256:DA2BDC118BB5045D19FB588102D040E3221F865F2B9AFC1E0983CC4D0B8FB54A
          SHA-512:66DF96BC694653C129CB9648AA0B9B6FC864DB27050A9CADFBDACBB648448CA342B1C96D619760E5B2CC529F392D90B1502FF3B6289EC48D5BC93DB42E7B55F7
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................to\..T.....<?.A../V.`u7...{.5....5.w#...U ...{....P....v.............p..|....e.........Y...........?......q....#.Pt..~k2.3;[..-..).k...'.'.\;C...t{..p......o.a...(.r}..z.d..Du.wj....Fd...^Kh.7.'2.Pyk.......g...3X,.%.|A.3.....rU......$....6..>.....zCYDLV.f.c...8./..W.....-H......l......"|..=K......<icp...fa..&.8.$O\.i........e.2.O|.q5"dP..e..#..P.u.=.6...W.*b.rn.....M.....I./.`>)...Mt>....i.|.<...(y.o.pcF...g5....2z.2y@.. .....f:..8Gc.........8[H>..fog..+:l.;.j..m.2......9...R..).....`.P.{B......<=....^*.._:M.`.........S.....-....`~;"...Jt....C|.W..9]Y..a.W....T........95.Y.|...0.5.y..E.].q....:..sc.|2=...'8u.[..Q....D..1...@.iZ.....<i.k..R.m.|.vBH;...*..,......U.t69........&9+@J.G....7....E..".A{.*.y.s.......z9.9!.a..<E.........A....O.q..W4-.......oj.k...N....W."b.[...ZrXJ.^7..Z&..2L-...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.492050980135084
          Encrypted:false
          SSDEEP:
          MD5:7C305A72C5E9981EE60EBD729E8D5278
          SHA1:B394A09C01C0693388D45E07F878823EB127F683
          SHA-256:5012AEF29DCD421652FAC02409DCB100504903B10D8B9F23C5B2FD6533054CDC
          SHA-512:76D8CC1A37491FF3206C395EB8F04709C36649C01908EE9C806B97AB69208AA980C0DD63511D08D1C255095EC657CA17E3AAE27EE798299FF229721D322D0829
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................a.e,t..ARDq...R......=..cN....Ap....%v5?.../w..2...9.M.p.......<..A.K'.......A..%.:..4.e.dU.u.8......)>.?.`..l..j.{.H;c.2..x.5.{.....:.....H.BE.U..ltuGwW.p$Z:......B.`."\..$/.....%.B.(.b.24.7.....s.0..c...qj..yzN.g......y.u`..#.<.;.....rh...j......<.......~mu..^J.E;'#..d.H[b<....)...~4.l.E.0m2c&.[kl...E..0.n.......H B..;.......Q}...}.......qp+...N7.*{4d...~.SX|..........Y......>.fM..j..5...u(.6.d......WL.5..V%.).../.`..1U-`K.LFu<.....R...1d2.a...."..........j..e...Y..;...k.......}.p+..\....S.=.6.......H*...=..m.|d....".".0.,X{}..X.......9[..+..L...J...&t.}..R..}..gIxT....mF....J\\&...z.j..k.".E.....}...l..Y..l.Q.3./..S....ho.....@_.4O.p...[hC...[....i...........F....$.1...c..*A.y..'..v.F.....s...z...w]..'....J+.t..{Q..M\.}{..wec0fQ.{.0.kc...S.kNi..+.Z+.....4B.AlR....t...y..3\....s@.....Y.'...}s
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.498876488274437
          Encrypted:false
          SSDEEP:
          MD5:83349DF86020A2AFCC7C8D50D4A694E6
          SHA1:01F1841F964F1FC354A6443AF59C13E3D0EF633C
          SHA-256:6488C924B23128986E698F0C2B85E97CBEC21F9D4DCE3DDDFE425D8999BBD8DF
          SHA-512:E9353DF05EDEFC8C77B2D2AFA8A6A7980000E603858A635EA930E87C9291331848FD14C454A60E22118C2C39168D24E1159EE04A45B5F6A5A5D5C659543F55E4
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................i.g.5jEa.,.....}B.....x..d.Yzu.:.\..h6.a......J...q..h<].H.(..d<w".V.$.......n..@...M.^g11Wep...h..o.....2...|0I^..5.S).KO.3...Y.]@r.=.2.|.%.[x.N..n..T63.J;.1$sI...;...z.0DD...i...b.iB....IN.X.@+..o.N....Q..w;].TZV...!5l..VwRP.T...........'f...@.|{..@...P.UW.....>.'..<....Y)AL.H.....P.*.K.......|....);.|8..s..Y.......n..K|zq...r..j5Lm....6ik.Y..T.eq.z/..............E.I.A......_.].......D..8y....+..9Z.y.D..Z.kF...........{..X...........:#....OKw..&bmo.....7.#f.,.E.e.4...Vl.r.....G0V2.;.M.h.ZRA.....y........~...1.........?C.....Mt.7..}......{.~...tjBa.@....p.sV...Z....!!w.h....=.._.!.O.....hv.r...H)........?..La..Qf...f.f.m.5u...`.P....{..)"...[.Wv.(.....}Ky..b...s.FNq..h..:....&;.w..<.Z..p{....-...............2.>[..<.m...:.Jp.....S..._..0R..1.&./..x...+.2T.....f.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.508682669021498
          Encrypted:false
          SSDEEP:
          MD5:37DA287814C0243E0D0FBCAEB82BBC33
          SHA1:5FFBD3066F0C978F767D14BC04D963E229980AF6
          SHA-256:41C6B646821BDED8363AA190CCA182DB35BC9335EB0CB2D6517422D737DCECD3
          SHA-512:41957A2DF3C2509638680BA4528FC382BF5B8C3BE863A427D31776FF437D410B24F989E7E36F6E86A8C366657D050DE0BEF34CC92C4FC064AE95FBCFD6CE4B37
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................s.M<.....tjX...dR.Y.;t..o......o!..C.?..9.D..S.8.A./.V........I.#d.R...=l4.!MVT.A,C....../'Q.....\".^]....x....OOf.xK*R.W...(....+. ..-..!;..\#...M;x......z.F.-$....T.IT8g..k.p..z.l.\...JRZjUU.s.!)[.L....a.]@...xg......Xvkz)......t..d..}.(.?..%mB..U..o.~j..NZ;....{....!.$.z.;W.M/:...;{5.6..qI."..]4foB\.{0.gz.D.0..)&..|..-x@'J..{....)}..U.:.T..-.e.X.I.F(Q..6*`|F..g....&...?i..]".z._c;..|a.''.].:..kj.xQ.dx...".....*p....k.Q..e.2.........#.H.b....U.N._.L.....0..A..9.kY(H...x..Q. .....-TQM^."wS_..{...eRs;....`....[....o.t....*..y.-.s.*.A..{..<r....Y...s.._7'...L@,..]...5N..}.!Md#....nd...v.l5.mQ.3._<\g...4<.<n.4....~.D..X/.+Ug(.2I*..u0x.a......a"=..1..I9...C....Q...d...?|`....hNG'..Mc..z..8...<..5...b...2M.]..K$avVip..4T.A....#.+.r>n.n.~r.=}'"9....E.k.3[.............+..{.$.R1G(.`AH.9..P{
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.496666643181701
          Encrypted:false
          SSDEEP:
          MD5:17067A23E6E2CC3965570C425A0A10AE
          SHA1:7F85F9C4025BEF742D44C9846DF5F9DCCA62BD82
          SHA-256:03DC77E0900E6E58CF7E51FE9A9F55D48A902F20EF42BF706EE7B380A718F100
          SHA-512:897E10D56ABFF3E098FB0315BE8B23C3FFB69C7DF91C7A7721D3C007FF1019058627348A5704F15CBF03422DDDF1752D1B68E703572F7B5E19145E5F926E339C
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................~+q.1...1l......<..[?....*QG[oX.....a..j.^.CO7...5....`/".1B.3d.}..._e!./.....6nK9.|u)D_..d4....4.b..P&.[.......D....^r.(J..udM!:..NAy..g....w..`.2....:Ng...\./.......rU.o..f......Lv1....J..o..8.$...>..w6...p....w*.+..`.6..*..yja.].G?.?....&.....?o.34;G.T;.\u....#...Py.R._~.....A......%..?....a...d!.>#;q].../tTB.u....m.....^.?.T.D4).cl6s&....rb;...Ll....;.@f.c...6....n.Y4......Gd.t/..<8.H..m.v....k-.Bb..j...tn.,+(....cp-*......OI_..6#*d..(.....q...G.}.76.....k..bt6%.l....]6q.V...*....).1BH3p...+.rmc.!..T.....Ea...N[....T.J..K..g......*.0v].'{.....G8Z...+.R....in..=b9.H...{.I.V..n......'.....mA....z..).y..AP...?W..2.h.m.....9.6.U.c..P~.`..[/.....w.x...9.......,....i..n`.e..#............. >hP..{..u..1Oh.~...W$u{..~,...b.Z.+...UQi..m.}..%.../......W.. \....BN.....Y...s}......]d...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.515950159811677
          Encrypted:false
          SSDEEP:
          MD5:578A381B1833C33D1C296D3D47DE2007
          SHA1:3BA8D0E8040BC6230954FB8B5E89BB3B62D50E8E
          SHA-256:6FC9556AA301282C470D49C11998EC0055EB6FBCCDBC56FEA39DC5C86AB9EFBC
          SHA-512:15A4C36C91EF81A22A51DF05EE3BAC62B06DE9B2BF47CFE45DF12600614EAA8DB46DBC578A9941EBE6D53849FE1321FEED0C2F7C5FCE96D481B6EE55E5BE4314
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.....................................................................................................................................T..^... ...[.u.T+M,.as..D..E..J.l...nnQ.....@].&......V.....LW....J7.6g........=.X..y....l.{.N[.....G..'.0..x.T1.7..-V0H..^..-.H~I...q....B..o%@=.3.Y....Y....&.0?Z.....iC.....d0I..4.>bFK.`..`._=...@..FUo;I....8:D...H....0.....ZreC6.{..>...!.xq]..8....O...j......:.....TbY........_.#aT.S........p..#E.uL.nF.#..#..k.&.?Q....i......M7.FD...~....X..~S.t.e.M.3...(.........po..A...z..f.9..<D^...$.D..uk..(_7y;.....RO.`..%[T..d......'5e.T.....".bg..:S..........#.&.....s....NJtg... ..X.....B..]..N.........^.N....&{..9v.bo.7.SK.y.K}.....yB..8..xs......O..|-.G.|..nsu..)I..5.}..1......P"...c|..._2...e..V...{.....^*..HUmdQp.Q4.n.u`........Z.b..w..+..F<./M..|.8..p.....=....K.......1...iR..aPG*w.{..6...B........a......H_.Sg..9..%.......%..o2.y.....$C[..k....R.)...x.z....)...ps..&
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.497146043051443
          Encrypted:false
          SSDEEP:
          MD5:7D7FF16559B9C4B28757847711DC96C4
          SHA1:0B1059F3003F0837932EE8C61F1DB9C52E54D806
          SHA-256:02FA838CB3D50360AE842A96BBF6FF4F0D5E2CC02B54C99FE430AA17BEBC3CF6
          SHA-512:A5616741DB64A71B422FFC1915F622BB2096D9C964BEBECDA3FF0212A34E3EE7DB1313E4DA8F25D4E4EF54C969E421A04E8C3FC0785E7284EA3891E8ACDDA07C
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................RQ.%.&.............AU...^.L7..m.r`..]7[...q]..^D..l............C...1..@A..1E...$.J?_.._...<T..Q..1....].KJ.....>...2zm...b.R....P...U.j..l.g..(GQ..........EI.......f.c.?.......?..J9<.X....n.}....wuM0.X......pM...nD.`_6.........A......_...d./=G.R.9...S.S.8%WC....7..+P..........G..8...........V.A.7.&.Yb.v...^..z.Gy.`./.Z.Fi.C(>3..@..dY.\.....).-L.....N...c.HF.+.(.Z;...UM..z`....ar56..7[...j..b.k!&.........6..2b6.F...x.T...W..+..i .E5......0I.p.5...4...+....jx..........0X..C...e...F0.....}...v..v..<C*B....aq..;.>.D`......*....6.u.....w%P..n@...>.h.cZ...X...+.....].U(.N.{gB........i%..Wl..x..;_.............o.ppB.*>.$..c.(..I;...R.pJ3. .=T.~..tp 9.....V..b{...'G.gm..O.#=..%.{G.G..3...Q=D.G...?%.`R5.X_.`....a.k..G=..';..(.$...}.......;.+W.$..6.W4.|......EG...A$/... ...CA...
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.487326064301366
          Encrypted:false
          SSDEEP:
          MD5:1CFE5EC494700F672FBC6F135300058E
          SHA1:B0E8B82342B3E7956DE9AAF430D616CF3B86F534
          SHA-256:EC78A1AE824FD2E08BE80EE23572837CA242F5AACA970F46719BC9E5723B5E1B
          SHA-512:034902CEA4C2D72B8B541CF839CC9C4DF0FDAF404CCD186B0B35DD59263496CFB1C3A39C973B11E7CA2EA93FA16BE5A8AC4006F74FAF3E62DAE90A212FC84133
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.......................................................................................................................................th..{.v..th..~.......Ni.....!6.K..Q(ob3...:..Id-...v8O...b.D8....M..*.w0H.x?=.r.ZdW...O...?..3R.g...(9.AI.c.I....SYk.......T....w[/..C.........-./.X..jpE.....^.2.......ZCz"...=.w.4<"........p...&9...O....2.b.+7^...h(l..+.[..b..s..v....C....rC..n..t.."}....(}...i3.6..|....G.es..v.ls.!....I].....Q..r.G.%..".qw+j?.e...G.!....}.t=.....4.......m.&..`..Hd...'...s..yp.....;...E...V..{4......3....%..&..&[./]]e....x..r.y...xNs..4.....F..V..ptN.j.u.|.1..Z........2.....ma.Ab..G...w..<.%7.S...\.J.AnZ..>...z.(..A.....oO.oD..r...dr..5...C,N..!..%........f...V....Q..DZ.AN....IsO"t....1.0M^..H....>..G.i[W...g....2].i...e.v.'..5D.xs..h....j(.....71......n-...A...xr[......X..q.#.;2NiyR..~..yf>1....>..I.7"s:-&..........P.YLo......Oo..):.!.|.z..y9._...v...X.ea^..0.p.....0.).]:.C.5.Q4.........'|M..
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.478653959246912
          Encrypted:false
          SSDEEP:
          MD5:07963BEDF45940D4DB867A013AC15F09
          SHA1:172E1AC67DDF71DC57B78126FDDD6F08A24CACAF
          SHA-256:34B8276065C6C58BC63B883ACF18B2B28A0EAE875CF1838344FEA489579439D9
          SHA-512:4CB3C7E3D2119DC301C05EB19BC05031882FADDBE731D188EAB8264C21C34BAB94B8D79CB2A49B24EDE0A2C377C3B05734FB529B9D1A9B2911BB04CAA7A06A57
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................9.t.K=.(.G;......./..'rh....i..Q....0.+V\_..."KQ.c..%.h...;..M...a....../.......#.m.!i........gX...8#..'n...be....hY..f.3.v..9..(...........v#x.q....@.U....(.RA..[..."..\..Og...2...iE26.,.........;..(......91...}{fb....haMR...2y.V|.~...9zK#_l.h.w/.....mH..?W1...1....9.m..#..N..bV.#f.Ln...f.G...n:.......q........q|.-I....K4..Qo..=l3...`....N;.+.I#r....c}.iZ+.v,zs4C..(.an...2..YDCQ3.(.}<.."t..^.3.}.d....^..gavc=/..lT..I.KP.xQGB.OjL..)A!..<.j....H.......V+b@.`&.VL....L?..3-.v.A......4}......I..^.].1...P.x.o.J..4-f..H....d._H...)...X....l ...dH..O...a...i.......5..##KE#VS=_.OL...\(...../iO.....(.9.h......@...Z...3r..e.A^.j[.2.OP..#...rx.?9"...^;~>}.L.....[..5q.C.D.....\.B.w.q......-.."..]p.I..V.GZ.....W+.*..;-..SY.../..,66..........0.}={!...L....w..G.....Zp._N*....gD.hWs.?.S9..&.x
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:PE32+ executable (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):0
          Entropy (8bit):0.0
          Encrypted:false
          SSDEEP:
          MD5:2345503234E8E31D072AB294FBD4DA67
          SHA1:4D42819FD890C55F9367B13FBF39A2696FE00180
          SHA-256:456143DE4D3ADD60A5082745921C839B06840544A508A4111CBD608E8479091C
          SHA-512:A8042F2F9F764046C1F46116D0AC88739D30549ABAE17340470556C5C3D104B766D060946087AC36315D5C52A3845CF383EE95509068593920EE4C03C10B16C2
          Malicious:true
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........Zpc.Zpc.Zpc...`.]pc...f..pc...g.Ppc....Ypc...`.Spc...g.Kpc...f.rpc...b.Qpc.Zpb..pc.O.g.Cpc.O.a.[pc.RichZpc.........PE..d....g.f.........."....(.......................@.............................0......Ey....`.................................................\...x....p......@..P"........... ..d...................................@...@............................................text............................... ..`.rdata..P*.......,..................@..@.data....S..........................@....pdata..P"...@...$..................@..@.rsrc.......p......................@..@.reloc..d.... ......................@..B........................................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.514832685538097
          Encrypted:false
          SSDEEP:
          MD5:58646634FDF7EA6C6571AE57129EEEAA
          SHA1:A7E002DC2C6E20F4AE27E64AA2F85095AE7A569B
          SHA-256:849DE216EBE02628AD5A4C971B6F0836B79BED4BE49F0094B8618778F9A4131E
          SHA-512:8F1B5E2F36359D2C36E4AFFEBA18E5C0D55D0A1EABF790EAFFE4EE95A7B1208142621AA7721080E0C0291332296433BE1B653E047491E43B0850BD876C30F828
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1...........................................................................................................................................E^.v..>7....Qc.{.H.i...PC.]...H..R....Y..m.I.............R.0;B.hhj.7......].p.v!...o%./N.....k.(t..D...NY..B[.R.8O..^ohh 7...Q.........{..D....,..+...R.g.K..%.E....jH...-F"w..8;......R....b..mV...j5..h`>i.{.z(ZX.c.x.".pLq..l.6.N..e.5...=...^..C......}..P:.........?....S.|..?j$....I..8...qK.5\.{..>.3Mz.#.~.....^..:.D..8.b..$..g..I5......E.;~....i..l.l.6.....3..r...k\'.O...6..\.....|B@.........4....d.."..r.D.o.l].._.ps...r.Kq{;...7...1q.}.XT......s.\....u....y...@.M.>n..ly...Z`...1...[. ........b!.........4..y...)...;....].._..|@.:.J<|1<:.D4.;#..q......,BWq.]...:.,..`a..+.@...w....T.....y.s..d.=e....ajr...&4...).....+.+Sa.......*2T....Ki...S..Vaq.>..P..Be..De..W~...OG.....BI.Z....s.a..J.....9n...S...+.\k..j........?.3....M.I...7;.%.`..2J......H....-.>U....;._..#8B...HF.'..2....
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:PE32+ executable (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):14820824
          Entropy (8bit):7.986367713017296
          Encrypted:false
          SSDEEP:
          MD5:2345503234E8E31D072AB294FBD4DA67
          SHA1:4D42819FD890C55F9367B13FBF39A2696FE00180
          SHA-256:456143DE4D3ADD60A5082745921C839B06840544A508A4111CBD608E8479091C
          SHA-512:A8042F2F9F764046C1F46116D0AC88739D30549ABAE17340470556C5C3D104B766D060946087AC36315D5C52A3845CF383EE95509068593920EE4C03C10B16C2
          Malicious:false
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........Zpc.Zpc.Zpc...`.]pc...f..pc...g.Ppc....Ypc...`.Spc...g.Kpc...f.rpc...b.Qpc.Zpb..pc.O.g.Cpc.O.a.[pc.RichZpc.........PE..d....g.f.........."....(.......................@.............................0......Ey....`.................................................\...x....p......@..P"........... ..d...................................@...@............................................text............................... ..`.rdata..P*.......,..................@..@.data....S..........................@....pdata..P"...@...$..................@..@.rsrc.......p......................@..@.reloc..d.... ......................@..B........................................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.489748805658294
          Encrypted:false
          SSDEEP:
          MD5:7E6E01BFB892E27EF75109C7253F88D7
          SHA1:C302B7E26C0C7B157156A97D8A82F376C2379FDA
          SHA-256:F2349028D5D904F5C2FCA1BC5FCFB366D44C2A8750F618E1C695E2ED95A99264
          SHA-512:D73E79C71530BE152BEEBC74C1B840486B0E0DCEBBA0F0AC5F3A421F736C147088B227F340AAF34F996A5F440BDC872F9B9DC0EBE1AEEDF7603E41711D80DF2D
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................}:.h.K.w.).h...0u;...^..8..y....q...w..UW.{.0..2......{...a~u.`D....).....P/<S-.Xp4.v..|o..ct$....jVy....,......~K.".X..=.b$f:_.$...}l....5.B..a..].l...Z.y.-.#H...$$;...MO..\........a......I../..2wuy.E<?..g....Sl...L.{..\...`........bZ.&u(M>.TDY ..1P..#m.?.a....e,.E2.->xZ.Mp...R..,C>.My.s.f.xWm.r..E.q.M.A.9x.........n.....#...cu.9..c.IpHp.0.AF...O...z.O^Q.q.|Q.Y..KQ/..`QGbE..zI..q..1d'.:.K.:.\........O.V....v.T.;].*."...s.?........=..sQ..g...o....Ch....^G.O1......l.r..w.q....~...b...f..h.0eMb...$.@d.m.-.2...?u.....q[.h...<8...r.h....O...,b...Q..p.....HNhF.../_..#..4.!d..%.ef{;J...jF...C9]'5...Zd.F....!@!.kO.^......~Y.jyl..|..2......\|[...l.....D.*DQ...s6.........m."S^.Cka..F0sn[..I.......\1.hE......V.z5..]..mh...._i....i.Z.*>6!.../p...4..).o.|^..j..x.jg..f.W.lG..7Q?z....`Y$.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):1335
          Entropy (8bit):7.502103336474072
          Encrypted:false
          SSDEEP:
          MD5:D86F9FA2EB02BBD9AC83BC491C64A0D7
          SHA1:5C085E07BA30E333D0431E12BC9C4BC1929F6B1B
          SHA-256:05C1F1CD5D299E039E43CE62B6CC876B83B83263850BE089434A77EB54428BFF
          SHA-512:6DDE3B5D72B48A8F575A1C6FCE18FA16BFDAC7EB9C6F6349EC8BAB7B3A916587FC73871A1878AC497BA9FC10E422EC97AB9EA6AA451121247D6A9589B05AA1B1
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................K...+ug_F.#).-...d.....O8..'.\.G......=.u.]ow.>...5.i"F..rx..2RL.v.]].Hq..8..|.o.ZZ..Ad97ooVm`2.+l.S.s%1:_........].S..|.SG.@E.V1....s.kt......F.#..2\@..t.|...|=.v.C....].................S.@.}"...)P.SK...E+.....p..\..w...hB..b..,...kIj.>....[7.;Y....I...... .....6..x..f6s&..SZz..F...y....M<9..;p|....%............m.WH..=... \Dl"....Q?...R3..4i..#`..L.....e..z.n.......J..4.'P.T.."jd@..gG..A..5.....RQ&y;..3..^.'Ln..U..n...Q..73]e|...{GD.....ah.y.......j:v.r.o....^..s.=.&...z.a_....L...Y... }d.l.....|.B.LB........0.....y.R/.P.|qe...).....K..X..g(.k.....w. ...ob..DRz...f.EO.*.....G.7.0#_..%.m....^....).`.W.~v.^..v..=.u1..:^..b.........T..^[..K...t...S....kK..w.......;$Yw..w..t.,t .*A|...!.........+L..(..z..(.R6\QBC..`r...%..u..M.w....x!t7`../P'..u:..........XPFQ.....c......8..*.H.Q
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):583
          Entropy (8bit):6.5408519894922
          Encrypted:false
          SSDEEP:
          MD5:DA797846725634DC4C80FD63F2131C58
          SHA1:72E9D43C28C88AFEFD0D9F0A27327F1C83AA4F38
          SHA-256:779CB8847F86EE38A162E73D2D746749A09AD9B63A0D2EDD71534527FA3C2AD7
          SHA-512:66BD4E058ACB986011CFD33AFCFA31D3A45F86FE969F1FBA27D70CB2910E367542AA6512D650960389070694BA395491D58A26D252AA408E32C6D5D55BB7E4B1
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1..........................................................................................................................................0`..31..gv*..$.._y...Bkg.{(..)a-..g..... F.9.V.~..L.K....F.,.Om..\..8.:w.]..`.S..4...9.O..-c..A..U5.q\A.(...eT..4.p.g4...um::.U..lN..C.iP?.!...wwY.5...,....f...........}U<.Co..=....Niaew;|...N!..Z.A{ ..?^X.b.S%..>.LsG...%/"T5..h.1...C....A..*....=.A..D.ou.....R.../1.r`.T.cI...........No......i..I].c.\....!;..VG.O...G.. I.......NNsM.B.he..&.&.u.\.........gN..t..g.K.inl...!....;..y0...$...
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:PE32+ executable (GUI) x86-64, for MS Windows
          Category:dropped
          Size (bytes):11024
          Entropy (8bit):5.981297001510571
          Encrypted:false
          SSDEEP:
          MD5:5D9EBFFA7643CC1CE6A6901A9488FA55
          SHA1:A801F0493A437069D42829D29BE298A3884CEFDE
          SHA-256:7DEE53EAB5962033F9A950B8111815FFB38520206239DCA9483221D93A3F4BE8
          SHA-512:9D7CF8068CAD8205BC6B97474B54280179C0C57FE83728DCE89050DBAD327B3B6867B6A4B54EDDB7FBC6CEE61C5C377275813F77359ED24CBEB2D12BC8798D9A
          Malicious:false
          Reputation:unknown
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........Zpc.Zpc.Zpc...`.]pc...f..pc...g.Ppc....Ypc...`.Spc...g.Kpc...f.rpc...b.Qpc.Zpb..pc.O.g.Cpc.O.a.[pc.RichZpc.........PE..d....g.f.........."....(.......................@.............................0......Ey....`.................................................\...x....p......@..P"........... ..d...................................@...@............................................text............................... ..`.rdata..P*.......,..................@..@.data....S..........................@....pdata..P"...@...$..................@..@.rsrc.......p......................@..@.reloc..d.... ......................@..B........................................................................................................................................................................................................................................................
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):487
          Entropy (8bit):6.172541266943811
          Encrypted:false
          SSDEEP:
          MD5:AA7C2C5C1C50D4B7E2A92AF9FD412636
          SHA1:054D94CEEF1ED230D386D26B9DD7D56330675150
          SHA-256:22E11B0502A6AC70BDF7DA9F6BB9D9DF2FE92144B247223782C2DBD490ED9F16
          SHA-512:1813BEF804C9624313C8F5B1490DA17B13FC359A4E0D74A3486BF429E48541FAA4470DF1C740D01282A4F36B7AC7F5445F3AC5145B5BF4BC92E53D74F71EDC77
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1......................................................................................................................................@(...V.+H.K...../4xA.I./......W.!..1.*..u.o.[.Y.vI...`.G...R...Q.x.)T..d.......^.U-3^M.Fm...R|~..k......~.C....Hb...c....`.l.^..CF.3..1Em..!.0.}....\....yc[.t.!.....x...Kv.......K...l....=.R.....dzn.d....).(........t...9...A....Xs..Q.?.-....!E......*._.....X...B..... .CA...............1.O..p..cO.`.t.3
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):487
          Entropy (8bit):6.15755279990561
          Encrypted:false
          SSDEEP:
          MD5:00E163BF0EA286DA17CC2358BCA5A8C7
          SHA1:22D4A002839092EA4B3FDB4045DFBE2A1A03FCF3
          SHA-256:D1C2FCB674E7C2D01BE154B858B5055F889A3034025ACA496522A46B1BE91033
          SHA-512:45711784FEB005A2D5AE1E60AC8D611B77B94E6AECDA3572BCA7084FFF231A6617BE59D68E3FB22A7629864639FDE7FF337464BC97C7D0A4F7599B2784278633
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1.........................................................................................................................................x.Y...S.....a.Jg.o^KI7!8....v..g...`..T.2...}].*C..w..SBT.HI.g8gE..F.`..G#.q(.g.B.....K.8....g.n1...........a)..3..*R........=..a.g..|...S.s..~..^...".%Rs.y.r.o.5.k.r.q6g.....g..b.K.|...1._.{....%.+......3.(s..../.......f9....[...W`.........D.MY.....4....>.\O....>....+...(0.^.2F...=.....7......V
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.035313719045336
          Encrypted:false
          SSDEEP:
          MD5:8B8121FA63BFE63A2AD80B941D37FF83
          SHA1:888743AECB6EA2D1057E46927A2BB9BBF3B12988
          SHA-256:C6926A1DEEDF5549375EF0FDCF52550D09E078A706636FC42E3F512E4E30D266
          SHA-512:9E8D5FF5E4AA0F47B4C7655F9687EF5681B1E62E44BE651A422978B039ED5CDA33D19D4689E7090397E45CFFE7DC914F01A5BCDB34E5DF0CD7D3F767B0F202BA
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................^.._..7h.t.D..!-U#^...!..'0M9.MI..*H!].8.^.6..Xhs..,9{.d~.u...{W..4b'~..!Dc`......`..7M........G..lS.M.@.L..cA.=..}.t.K..........+......,..X..~Um.?6...UMa.>..eG...@#&.80%..\.s...-.6..T.|.fK.....H..$....F!.cc#F.].;..4v........F...A......v...5.0....Iu.$.......;......).FJ..6..".....x.z.nB.+../.'`......E\..D0.%D...vi.[c...^O.'.....E.....Jr.7O......&..{..e.Na.....Pi..m..B.".y.y4....X2...b.x..*.o....c.q.<.j`..x?..do..h!)#...%.......).....nE.QLk..c.x..u.7.'...S.q..e...].`...R.4.Dx0....5......;...#7%kx.dy......u....9.......$..]p....`...fo..b....(.N....L.X9....%.Y.%.....Q@..&@?.J.....k.H....6..T....@.:`1u....MF!@+.
          Process:C:\Users\user\Downloads\TheTrueFriend.exe
          File Type:AES encrypted data, version 2, created by "pyAesCrypt 6.1.1"
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.057280546162961
          Encrypted:false
          SSDEEP:
          MD5:3B934E1F78DD4F30D73AAFF6FDE97A16
          SHA1:7617441F6FBBAF7F265226BAE7B4D85CBCB8BA0D
          SHA-256:46E548181A7C9AB2487D76CF5E9097E5B318B06D6126E4CD6983F87CB3B422E8
          SHA-512:133A016353AEDDF81E351A343BEF2649201AC738FDB0E430C06597A581F98A9204E21CCBD1D19731D5FEC725B8BE18DEEE3B56A721FB53DD0C48880EED78D3FF
          Malicious:false
          Reputation:unknown
          Preview:AES....CREATED_BY.pyAesCrypt 6.1.1....................................................................................................................................o".#.....@$........~&...{...9esr.B......Z... .%....H..`%..o8..."O..t..N......C...:-t......L..]..0.....gA@........#..k.aC]...b.0...Mt....e7....9.V/.HsW`......!.4.E:*,Y..I"b..i..8....o.a...$...0..3..^.Z...........pz...5-.Y....T..<gb..#..}.NVR..7..X{;{.>..5....?;.c.A....G.-t..X.+C .'.g"j4.VWG...W...o.....'u.cBD.....Z.8...k...T.+^..m!....h.}.+.t.a..NO7i....{.z....0..d..R..G..jy.\......UV:)s..YF.Kpz..s.h..U..M/. .ap1...r...5fqb....j.l...\...3.M.8.M.....Z....L...A....|..w...t._.}&[....Y...!....m..x-3+.#...E....t......{.-.U.*d...ZJ...h.J..|..it.6..\...&@.....3I.tP...c...D....k....C!.O..P...Wy.G...0A@...>..!....
          No static file info