Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
OZ1ORrbotn.exe

Overview

General Information

Sample name:OZ1ORrbotn.exe
renamed because original name is a hash value
Original sample name:768d390a232501b58b9626b4764d10f7a41732dbd5a8f559664d2f1d9f7d1cd0.exe
Analysis ID:1547550
MD5:ccaa87a7a44fa59ae536138e2313bc3e
SHA1:01cb1af569bf29abb61f7d38623dd82c86c82617
SHA256:768d390a232501b58b9626b4764d10f7a41732dbd5a8f559664d2f1d9f7d1cd0
Tags:exeMammonuser-JAMESWT_MHT
Infos:

Detection

Mammon, TrojanRansom, Xmrig
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mammon Ransomware
Yara detected TrojanRansom
Yara detected Xmrig cryptocurrency miner
AI detected suspicious sample
Creates files in the recycle bin to hide itself
Infects executable files (exe, dll, sys, html)
Writes many files with high entropy
AV process strings found (often used to terminate AV products)
Abnormal high CPU Usage
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Startup Folder File Write
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • OZ1ORrbotn.exe (PID: 7704 cmdline: "C:\Users\user\Desktop\OZ1ORrbotn.exe" MD5: CCAA87A7A44FA59AE536138E2313BC3E)
    • conhost.exe (PID: 7712 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 7366FBEFE66BA0F1F5304F7D6FEF09FE)
  • OpenWith.exe (PID: 7528 cmdline: C:\Windows\system32\OpenWith.exe -Embedding MD5: E4A834784FA08C17D47A1E72429C5109)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
xmrigAccording to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling".In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.xmrig
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.binJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
    C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.binMacOS_Trojan_Metasploit_27d409f1Byte sequence based on Metasploit x64 shell_bind_tcp.rbunknown
    • 0x153ecdf:$a1: B8 61 00 00 02 6A 02 5F 6A 01 5E 48 31 D2
    SourceRuleDescriptionAuthorStrings
    Process Memory Space: OZ1ORrbotn.exe PID: 7704JoeSecurity_MammonYara detected Mammon RansomwareJoe Security
      Process Memory Space: OZ1ORrbotn.exe PID: 7704JoeSecurity_TrojanRansomYara detected TrojanRansomJoe Security

        System Summary

        barindex
        Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Users\user\Desktop\OZ1ORrbotn.exe, ProcessId: 7704, TargetFilename: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2024-11-02T17:15:23.671404+010020229301A Network Trojan was detected4.245.163.56443192.168.2.349788TCP
        2024-11-02T17:16:02.154705+010020229301A Network Trojan was detected4.175.87.197443192.168.2.349975TCP

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: OZ1ORrbotn.exeAvira: detected
        Source: OZ1ORrbotn.exeReversingLabs: Detection: 63%
        Source: Submited SampleIntegrated Neural Analysis Model: Matched 98.1% probability

        Bitcoin Miner

        barindex
        Source: Yara matchFile source: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.bin, type: DROPPED
        Source: OZ1ORrbotn.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: OZ1ORrbotn.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb& source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000854000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnL source: OZ1ORrbotn.exe, 00000000.00000003.2097427737.0000000000837000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\\ source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\LocalState\DiagOutputDir\LogFile_October_3_2023__13_9_20.txt.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C3335 source: OZ1ORrbotn.exe
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162eateL source: OZ1ORrbotn.exe, 00000000.00000003.1583557558.000000000086F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1583507198.0000000000866000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ~@2}Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.1972947945.0000000000889000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1973099889.0000000000889000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1973957352.0000000000885000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1974215590.000000000088A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\VirtualStore\.krnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.8\. source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnn source: OZ1ORrbotn.exe, 00000000.00000003.2083854165.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079686306.0000000000834000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080622552.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080130130.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081160302.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081189821.0000000000840000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*n source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbrch_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{bbb86b2c-c249-461d-ba34-fc7fe96992d0}\ source: OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000086C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: on Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD96 source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb*\*! source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Comms\Unistore\data\.Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162wy source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: od.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb source: OZ1ORrbotn.exe
        Source: Binary string: ettings\Temp\Symbols\ntkrnlmp.pdb\79BE8C368B source: OZ1ORrbotn.exe, 00000000.00000003.2044579034.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2007062074.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2002269430.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2017005513.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2052889663.0000000000824000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1993360166.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2030664722.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2017150890.0000000000825000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2007718531.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2034092489.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2018714581.0000000000825000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*t\DC source: OZ1ORrbotn.exe, 00000000.00000003.2074646045.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: INETCA~1.LOCntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbF4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnio source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\HQ source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdbewy\S-1-5-21-2246122658-3693405117-2476756634-1003.pckgdep:\\DocuL source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*Local Sd%q source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Temp\Symbols\winload_prod.pdb\C153C68A0C3335 source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*oc` source: OZ1ORrbotn.exe, 00000000.00000003.1704907286.0000000000886000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\. source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnmmnrel.v source: OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnnnn source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2090241017.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: .pdbLOG2\Application Data\Application Data source: OZ1ORrbotn.exe, 00000000.00000003.2060850420.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088988659.0000000000825000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2044579034.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081220028.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2068582856.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2007062074.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2090571269.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093715535.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2063612335.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2002269430.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2017005513.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2052889663.0000000000824000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1993360166.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2095001110.0000000000825000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2078808573.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2030664722.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2017150890.0000000000825000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2007718531.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2066340333.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2034092489.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2058839457.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2018714581.0000000000825000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdbl.e source: OZ1ORrbotn.exe, 00000000.00000003.2074646045.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.MAMwinload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnegtrans-Settingsx source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\B25B2951-6905-4482-AB91-A47DD720CC72\en-us.16\.l\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbndex\Settings_{03d2a361-c3db-4d42-9 source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000835000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704440447.000000000083A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2097427737.0000000000837000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnnnV source: OZ1ORrbotn.exe, 00000000.00000003.2083854165.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079686306.0000000000834000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080622552.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080130130.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081160302.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081189821.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2090241017.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\blob_storage\fc4f53ac-5f0b-4413-aa04-7f64527fa6c3\..ad_prod.pdbSettings\user\Local Settings\Application Data\Application Data\Ap source: OZ1ORrbotn.exe, 00000000.00000003.1951587983.000000000082E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1953691339.000000000082E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1952794203.000000000082E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1952193339.000000000082E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: NTKRNL~1.MAMntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn88000161Settings source: OZ1ORrbotn.exe, 00000000.00000003.2097427737.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbuEjectDialog_cw5n1h2txyewy2txyewyOriginTrials++ source: OZ1ORrbotn.exe, 00000000.00000003.1583601429.0000000000854000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1583690334.0000000000863000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbn Data\P source: OZ1ORrbotn.exe, 00000000.00000003.1993961449.0000000000836000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1994470497.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: NTKRNL~1.MAMntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.DBciconcachSettingsx source: OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammntaj source: OZ1ORrbotn.exe, 00000000.00000003.2033042610.0000000000800000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb3Hg source: OZ1ORrbotn.exe, 00000000.00000003.1994569774.0000000000829000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162 source: OZ1ORrbotn.exe, 00000000.00000003.1583557558.000000000086F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1583507198.0000000000866000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\icati source: OZ1ORrbotn.exe, 00000000.00000003.1978117344.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1978283801.00000000007FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841. source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdbtemAppData\.kck source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\*] source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162*ation@ source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb.. source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: UNISTO~1OA~1UnistoreDBd_prod.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1981401303.0000000000850000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.MAMwinload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn31009300Settings source: OZ1ORrbotn.exe, 00000000.00000003.2079898663.000000000084F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079686306.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb{ source: OZ1ORrbotn.exe, 00000000.00000003.1929227030.0000000000865000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\Legion\source\repos\Mammon\Release\Mammon.pdb source: OZ1ORrbotn.exe, 00000000.00000000.1336557047.0000000000A1F000.00000002.00000001.01000000.00000003.sdmp
        Source: Binary string: prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error_sbx\Adobe source: OZ1ORrbotn.exe, 00000000.00000003.1929227030.0000000000885000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1930910202.0000000000885000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\ source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\61\:P source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\FontCache\4\PreviewFont\*.pdb&m source: OZ1ORrbotn.exe, 00000000.00000003.1623589757.000000000082F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1622740547.000000000082F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\b\*D source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\jones\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rulesata\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfakData\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\wy.Apprep.ChxApp_cw5n1h2txyewy\AC\..* source: OZ1ORrbotn.exe, 00000000.00000003.2083178642.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079898663.000000000084F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080955368.000000000084D000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080622552.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079686306.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162ication Data\Application Data\Application Data\Application Data\Packages\ source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\***. source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841che\*a\* source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdbl.eu source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0che.pdb\*ml\P source: OZ1ORrbotn.exe, 00000000.00000003.1929227030.0000000000885000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ocu source: OZ1ORrbotn.exe, 00000000.00000003.1966701387.00000000007FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1994239568.0000000000863000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pplication Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355r source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162ore\* source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\ source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pplication Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb% source: OZ1ORrbotn.exe, 00000000.00000003.1902330338.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: on Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.8\. source: OZ1ORrbotn.exe, 00000000.00000003.1981401303.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162eeData\Application Data\Application Data\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\.silPr source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\VirtualStore\..rnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\.S source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.plica source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Media Player\Sync Playlistsockymbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2082721326.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\DLPCache\a\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.1905084073.0000000000854000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1905472454.0000000000855000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1903779977.0000000000850000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1907899808.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.pu7jrfDN96gg source: OZ1ORrbotn.exe, 00000000.00000003.1994569774.0000000000829000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \Symbols\winload_prod.pdb\C153C68A0C33354B45 source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ata\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B4 source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdbcgb77SIOCfnAbpfB4.br[1].jssschunk.v7[1].js source: OZ1ORrbotn.exe, 00000000.00000003.1632670065.000000000082A000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1632877389.0000000000834000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*e source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Shoppingter.locklockymbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2081021110.000000000088D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.et Explorer source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\* source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\TrustTokenKeyCommitmentsonModels0C33354B45AF72681ED993162\winload_prod.pdbkbeader_Upsell_CardsetCachetings\Microsoft\Windows\INetCookies\* source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temporary Internet Files\Low\.K3KK3A0C33354B45AF72681ED993162\winload_prod.pdbt9 source: OZ1ORrbotn.exe, 00000000.00000003.1975812958.000000000088E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1975985768.000000000088E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbcation Data\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\* source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\X source: OZ1ORrbotn.exe, 00000000.00000003.2060818248.0000000000863000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2060542912.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2060616599.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\..Apo- source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbEW source: OZ1ORrbotn.exe, 00000000.00000003.1993360166.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdboQ source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error\P source: OZ1ORrbotn.exe, 00000000.00000003.1994569774.0000000000829000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdble@zohomail.eu]ID-[7H4S3UQ1F4].mammngdep source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\* source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*ta*- source: OZ1ORrbotn.exe, 00000000.00000003.1993243536.0000000000836000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\..t.WindowsAlarmss.lnklnk0D9}.1.ver0x0000000000000004.db source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\.8d379.826.98.0_neutral_split.scale-200_8wekyb: source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9el source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000835000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704440447.000000000083A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\.. source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\Site Characteristics Database\.ation Data\Temp\Symbols\ntkrnlmp.pdb\*? source: OZ1ORrbotn.exe, 00000000.00000003.2018590414.000000000083D000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2018967453.000000000083F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2019406413.0000000000849000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2018676442.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: al Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.1902330338.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.PDBwinload_prod.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1993961449.0000000000836000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074810952.0000000000842000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1994470497.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841ation source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: tion Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\at source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\*.opleExperienceHost_cw5n1h2txyewy source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: 681ED993162\winload_prod.pdb.Mail-[help.filec source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbardz\Local Settings\Application Data\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\AC\plication Data\Microsoft\Windows\Burn\Burn\..` source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1981401303.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ion Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\* source: OZ1ORrbotn.exe, 00000000.00000003.1902330338.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbx\Settings_{69b21fa5-2b75-40c0-88e3-556556bc757a}e\* source: OZ1ORrbotn.exe, 00000000.00000003.1983788653.0000000000836000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*pdb& source: OZ1ORrbotn.exe, 00000000.00000003.1940277474.0000000000873000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162e source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0p.pdb source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\* source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ocu source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Safe Browsing.pdb\.- source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Subresource Filter.locklockymbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2080164020.000000000088C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\*3d8bbweo source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\..teockorer source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{29c400f0-1870-4d48-88d2-134a87e32571} source: OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000086C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbn source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000835000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704440447.000000000083A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\Windows. source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000854000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.. source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: NTKRNL~1.MAMntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnSync Data source: OZ1ORrbotn.exe, 00000000.00000003.2074810952.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\.d.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnm source: OZ1ORrbotn.exe, 00000000.00000003.2079686306.0000000000834000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080622552.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080130130.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081160302.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081189821.0000000000840000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbr4 source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000835000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1881469478.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1726874759.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704440447.000000000083A000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1865180584.000000000083D000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1727028469.000000000083C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\..\* source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Ma9 source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbF source: OZ1ORrbotn.exe, 00000000.00000003.1940277474.0000000000873000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: AF72681ED993162\winload_prod.pdb.Mail-[help.' source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.e source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: emp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2078342793.0000000000896000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: d Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\e\ source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\.\*%\sys source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: tings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE784 source: OZ1ORrbotn.exe, 00000000.00000003.1881469478.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1726874759.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1865180584.000000000083D000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1727028469.000000000083C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdbechToTextOverlay_8wekyb3d8bbwewef" source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb473\. source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE784155f2d8d379em source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000854000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162 source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn}n.mam source: OZ1ORrbotn.exe, 00000000.00000003.2079686306.0000000000834000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080130130.0000000000840000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: OA~1.MAMwinlSMLK4QDN.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn $ source: OZ1ORrbotn.exe, 00000000.00000003.2097427737.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\SystemAppDatalockymbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2078615098.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\a\A source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: p\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162pplicat source: OZ1ORrbotn.exe, 00000000.00000003.2048812071.000000000082C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: a\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.2063059831.0000000000868000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb*a\Default\tion Data\Application Data\Application Data\Applicat source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temporary Internet Files\IE\MHXXL5K6A0C33354B45AF72681ED993162\winload_prod.pdbdbMi source: OZ1ORrbotn.exe, 00000000.00000003.1975812958.000000000088E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1975985768.000000000088E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.MAMwinload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn_{bbb86bSettings4x,jAS source: OZ1ORrbotn.exe, 00000000.00000003.2074810952.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrometa\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.2063059831.0000000000872000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841a4a2c4er0x0000000000000011.dbication Data\Application Data\Application Data\Application Dalf source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: mp.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\w source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbr66.0_0\_locales\id\-7de1-4405-809c-51b7a8879b4c\*depll Users\Applica4 source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ta\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.. source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb7%@ source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbrp source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\All Users\Microsoft\Windows Defender\Definition Updates\{811A7D6A-257A-471C-BB51-AEE6C08504F5}\mpasbase.vdm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnta\Application Data\Temp\Symbols\winload_prod.pdb\.\*%\sys source: OZ1ORrbotn.exe, 00000000.00000003.1966701387.00000000007FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.MAMwinload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn88000161Settingsx| source: OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\**\*g source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temporary Internet Files\VirtualizedC68A0C33354B45AF72681ED993162\winload_prod.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1975812958.000000000088E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1975985768.000000000088E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnfile@ source: OZ1ORrbotn.exe, 00000000.00000003.2052923474.00000000007E4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.\* source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Comms\Unistore\data\tempbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\*yewy source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.2063470462.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2065584988.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2066291117.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1993961449.0000000000836000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1994470497.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.5 source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2090241017.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\d source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb* source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162 source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: XY~mp.pdbn source: OZ1ORrbotn.exe, 00000000.00000003.1726874759.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1727028469.000000000083C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\wdH source: OZ1ORrbotn.exe, 00000000.00000003.2117997003.0000000000838000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2116419439.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\L source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1966766492.00000000007F0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnn Data\ source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnmmnV source: OZ1ORrbotn.exe, 00000000.00000003.2074810952.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\:\\ source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Dataes00002.jrs.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841ata\Packages\NcsiUwpApp_8wekyb3d8bbwe\TempStateemAppData <H source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnon Data\A- source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb8E-4E1DDDE828FE_cw5n1h2txyewyi4-T source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\.A,) source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\.i source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1993360166.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ta\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162p source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: 81ED993162\winload_prod.pdb.Mail-[help.file@_ source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000854000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Defaultge\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\DawnCacheod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdbkckults\Provider Types\Type 001 source: OZ1ORrbotn.exe, 00000000.00000003.2017005513.00000000007E6000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\. source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\cu source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841 source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdb571} source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdbog_cw5n1h2txyewy5n1h2txyewybwexyewyail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*iu source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnRW source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\ source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\jones\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AccountsControl_cw5n1h2txyewysoft\Windows\Burn\.1.15.0.1\*a\**ore Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb* source: OZ1ORrbotn.exe, 00000000.00000003.2063470462.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2068582856.000000000082C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2065584988.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2060542912.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2068841238.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2066291117.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2060616599.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\1-Y source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD967 source: OZ1ORrbotn.exe
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnows.SecureAssessmentBrowser_cw5n1h2txyewy:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\WinX\Group2\.\* source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Symbols\winload_prod.pdb\C153C68A0C33354B45AS source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Xy~XY~mp.pdbn source: OZ1ORrbotn.exe, 00000000.00000003.1881469478.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1865180584.000000000083D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbrolpan source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\download.errorApps_{5fc69a56-0c9d-48e9-8c45-7102a9e2439b}\..js\ source: OZ1ORrbotn.exe, 00000000.00000003.1983788653.0000000000836000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp

        Spreading

        barindex
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpClient.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpRtp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableEngineEtwLocation\mpengine_etw.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpSvc.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAzSubmit.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAzSubmit.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\endpointdlp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\endpointdlp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpClient.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpSvc.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exeJump to behavior
        Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 4.245.163.56:443 -> 192.168.2.3:49788
        Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 4.175.87.197:443 -> 192.168.2.3:49975
        Source: OZ1ORrbotn.exe, 00000000.00000003.1901973402.00000000007FE000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1899106504.0000000000800000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1898435731.00000000007FF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://..twitte
        Source: OZ1ORrbotn.exe, 00000000.00000003.1903178045.00000000007FE000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1903050309.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1901973402.00000000007FE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://..wikipe
        Source: OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2271899915.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
        Source: OZ1ORrbotn.exe, 00000000.00000003.2279043085.00000000007F1000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2271899915.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
        Source: OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2271899915.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
        Source: OZ1ORrbotn.exe, 00000000.00000003.2279043085.00000000007F1000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2271899915.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
        Source: OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://evcs-aia.ws.symantec.com/evcs.cer0
        Source: OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://evcs-crl.ws.symantec.com/evcs.crl0
        Source: OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://evcs-ocsp.ws.symantec.com04
        Source: OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digic
        Source: OZ1ORrbotn.exe, 00000000.00000003.2279043085.00000000007F1000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2271899915.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0A
        Source: OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2271899915.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0C
        Source: OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.symauth.com/cps0(
        Source: OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.symauth.com/cps09
        Source: OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.symauth.com/rpa04
        Source: OZ1ORrbotn.exe, 00000000.00000003.1899106504.0000000000800000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1898435731.00000000007FF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.wikipedia.com/
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://adobesearch-sec-uss-stage.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://adobesearch-sec-uss.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://adobesearch-stage.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://adobesearch.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dc-api-stage.adobe.io/discovery
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dc-api.adobe.io/discovery
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://notify-stage.adobe.io/ans/v1/sms
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://notify.adobe.io/ans/v1/sms
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://p13n-stage.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://p13n.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pgc-stage.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pgc.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reviews-stage.adobe.io
        Source: OZ1ORrbotn.exe, 00000000.00000003.2294656121.0000000000805000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2294386911.00000000007FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reviews.adobe.io

        Spam, unwanted Advertisements and Ransom Demands

        barindex
        Source: Yara matchFile source: Process Memory Space: OZ1ORrbotn.exe PID: 7704, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: OZ1ORrbotn.exe PID: 7704, type: MEMORYSTR
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{811A7D6A-257A-471C-BB51-AEE6C08504F5}\mpavbase.vdm entropy: 7.99758495849Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{811A7D6A-257A-471C-BB51-AEE6C08504F5}\mpasdlta.vdm entropy: 7.99921676177Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\cookies.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99816123244Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\cookies.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99438812818Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\content-prefs.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99939051792Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\cert9.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99911359066Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\protections.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99697990684Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\places.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99398434599Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\permissions.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99785959414Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\key4.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99939817678Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\favicons.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.9954827267Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\extensions.json.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.9950773377Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\webappsstore.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99810445586Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\webappsstore.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99560867668Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\saved-telemetry-pings\633ed4f5-2d3f-4b02-b066-694e4cf70107.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99775753124Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\saved-telemetry-pings\400ba023-0dc1-4707-9559-f338ae70207e.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99507447934Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\ls-archive.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99852435235Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99569257499Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.995410953Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\saved-telemetry-pings\86377b8e-4b59-4e87-895a-85535c6fe18c.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99764862448Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99684550987Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99471852863Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99652446969Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99415372162Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99663892301Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99446939249Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99695270754Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99471286817Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99964352955Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\xte0v1np.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99422964982Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lst.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99905642347Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99916250571Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99716215941Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99467128255Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99385872418Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99409301619Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000010.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99551070215Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000011.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99510103739Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99821122489Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99674457435Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Safety\shell\remote\script_96032244749497702726114603847611723578.rel.v2.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99355878934Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000010.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99617314512Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000011.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99557478786Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.bin entropy: 7.9989014206Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.9985086013Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99701232259Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Safety\shell\remote\script_96032244749497702726114603847611723578.rel.v2.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.9935089214Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99195283016Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{811A7D6A-257A-471C-BB51-AEE6C08504F5}\mpasbase.vdm entropy: 7.99758834775Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles\CachedImage_1280_1024_POS4.jpg.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99711335547Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99842683951Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99456205899Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99524469726Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db-shm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99453157291Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99683995489Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\NotificationsDB\notificationsDB.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99183118982Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasbase.lkg entropy: 7.99737624483Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasbase.vdm entropy: 7.99758929668Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000e.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99935316718Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99972916448Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.lkg entropy: 7.9994600457Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.vdm entropy: 7.99872568825Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavbase.lkg entropy: 7.99765583387Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000000e.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99939099159Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavbase.vdm entropy: 7.99758495422Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99969500023Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\Default\NTUSER.DAT.LOG1.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99759168366Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\Default\NTUSER.DAT.LOG2.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99310005168Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg entropy: 7.99590282119Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\Default\NTUSER.DAT.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99932965386Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\Default\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TM.blf.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99717860862Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\Default\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000001.regtrans-ms.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99963074115Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Users\Default\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000002.regtrans-ms.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn entropy: 7.99958972457Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpasbase.lkg.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99737624483Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpasbase.vdm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99758929668Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.lkg.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.9994600457Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.vdm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99872568825Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpavbase.lkg.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99765583387Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpavbase.vdm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99758495422Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99590282119Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.bin.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.9989014206Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\{811A7D6A-257A-471C-BB51-AEE6C08504F5}\mpasbase.vdm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99758834775Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\{811A7D6A-257A-471C-BB51-AEE6C08504F5}\mpasdlta.vdm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99921676177Jump to dropped file
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\{811A7D6A-257A-471C-BB51-AEE6C08504F5}\mpavbase.vdm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn (copy) entropy: 7.99758495849Jump to dropped file

        System Summary

        barindex
        Source: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.bin, type: DROPPEDMatched rule: Byte sequence based on Metasploit x64 shell_bind_tcp.rb Author: unknown
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeProcess Stats: CPU usage > 49%
        Source: OZ1ORrbotn.exe, 00000000.00000003.2286548729.0000000000805000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMCIMPP.mppD vs OZ1ORrbotn.exe
        Source: OZ1ORrbotn.exe, 00000000.00000003.2286548729.0000000000805000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameFlash.mppD vs OZ1ORrbotn.exe
        Source: OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamecryptocmeL vs OZ1ORrbotn.exe
        Source: OZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameccme_eccL vs OZ1ORrbotn.exe
        Source: OZ1ORrbotn.exe, 00000000.00000003.2285581055.0000000000805000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqrcodepmp.dll< vs OZ1ORrbotn.exe
        Source: OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamecryptocmeL vs OZ1ORrbotn.exe
        Source: OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameccme_eccL vs OZ1ORrbotn.exe
        Source: OZ1ORrbotn.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.bin, type: DROPPEDMatched rule: MacOS_Trojan_Metasploit_27d409f1 os = macos, severity = x86, description = Byte sequence based on Metasploit x64 shell_bind_tcp.rb, creation_date = 2021-09-30, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/master/modules/payloads/singles/osx/x64/shell_bind_tcp.rb, license = Elastic License v2, threat_name = MacOS.Trojan.Metasploit, fingerprint = 43be41784449fc414c3e3bc7f4ca5827190fa10ac4cdd8500517e2aa6cce2a56, id = 27d409f1-80fd-4d07-815a-4741c48e0bf6, last_modified = 2021-10-25
        Source: classification engineClassification label: mal100.rans.spre.evad.mine.winEXE@3/1076@0/0
        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7712:120:WilError_03
        Source: C:\Windows\System32\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7528:120:WilError_03
        Source: OZ1ORrbotn.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile read: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.iniJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: OZ1ORrbotn.exeReversingLabs: Detection: 63%
        Source: unknownProcess created: C:\Users\user\Desktop\OZ1ORrbotn.exe "C:\Users\user\Desktop\OZ1ORrbotn.exe"
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Source: unknownProcess created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: twinui.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: powrprof.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: dwmapi.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: pdh.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: umpdc.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: onecorecommonproxystub.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: actxprxy.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepositoryps.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.appdefaults.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.immersive.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: ntmarta.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: uiautomationcore.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: dui70.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: duser.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: dwrite.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47mrm.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: uianimation.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d11.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: dxgi.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: resourcepolicyclient.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: dxcore.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: dcomp.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: oleacc.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: edputil.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windowmanagementapi.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: textinputframework.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: inputhost.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: coreuicomponents.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: coreuicomponents.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windowscodecs.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: thumbcache.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: policymanager.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: msvcp110_win.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: appresolver.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47langs.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: slc.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: sppc.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: tiledatarepository.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: staterepository.core.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepository.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: wtsapi32.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepositorycore.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: mrmcorer.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: appxdeploymentclient.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: appxdeploymentclient.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: sxs.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: directmanipulation.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: textshaping.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeSection loaded: photometadatahandler.dllJump to behavior
        Source: C:\Windows\System32\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
        Source: OZ1ORrbotn.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
        Source: OZ1ORrbotn.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
        Source: OZ1ORrbotn.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
        Source: OZ1ORrbotn.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: OZ1ORrbotn.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
        Source: OZ1ORrbotn.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
        Source: OZ1ORrbotn.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
        Source: OZ1ORrbotn.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb& source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000854000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnL source: OZ1ORrbotn.exe, 00000000.00000003.2097427737.0000000000837000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\\ source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\LocalState\DiagOutputDir\LogFile_October_3_2023__13_9_20.txt.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C3335 source: OZ1ORrbotn.exe
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162eateL source: OZ1ORrbotn.exe, 00000000.00000003.1583557558.000000000086F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1583507198.0000000000866000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ~@2}Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.1972947945.0000000000889000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1973099889.0000000000889000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1973957352.0000000000885000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1974215590.000000000088A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\VirtualStore\.krnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.8\. source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnn source: OZ1ORrbotn.exe, 00000000.00000003.2083854165.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079686306.0000000000834000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080622552.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080130130.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081160302.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081189821.0000000000840000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*n source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbrch_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{bbb86b2c-c249-461d-ba34-fc7fe96992d0}\ source: OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000086C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: on Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD96 source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb*\*! source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Comms\Unistore\data\.Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162wy source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: od.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb source: OZ1ORrbotn.exe
        Source: Binary string: ettings\Temp\Symbols\ntkrnlmp.pdb\79BE8C368B source: OZ1ORrbotn.exe, 00000000.00000003.2044579034.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2007062074.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2002269430.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2017005513.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2052889663.0000000000824000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1993360166.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2030664722.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2017150890.0000000000825000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2007718531.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2034092489.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2018714581.0000000000825000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*t\DC source: OZ1ORrbotn.exe, 00000000.00000003.2074646045.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: INETCA~1.LOCntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbF4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnio source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\HQ source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdbewy\S-1-5-21-2246122658-3693405117-2476756634-1003.pckgdep:\\DocuL source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*Local Sd%q source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Temp\Symbols\winload_prod.pdb\C153C68A0C3335 source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*oc` source: OZ1ORrbotn.exe, 00000000.00000003.1704907286.0000000000886000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\. source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnmmnrel.v source: OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnnnn source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2090241017.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: .pdbLOG2\Application Data\Application Data source: OZ1ORrbotn.exe, 00000000.00000003.2060850420.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088988659.0000000000825000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2044579034.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081220028.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2068582856.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2007062074.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2090571269.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093715535.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2063612335.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2002269430.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2017005513.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2052889663.0000000000824000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1993360166.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2095001110.0000000000825000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2078808573.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2030664722.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2017150890.0000000000825000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2007718531.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2066340333.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2034092489.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2058839457.0000000000823000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2018714581.0000000000825000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdbl.e source: OZ1ORrbotn.exe, 00000000.00000003.2074646045.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.MAMwinload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnegtrans-Settingsx source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\B25B2951-6905-4482-AB91-A47DD720CC72\en-us.16\.l\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbndex\Settings_{03d2a361-c3db-4d42-9 source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000835000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704440447.000000000083A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2097427737.0000000000837000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnnnV source: OZ1ORrbotn.exe, 00000000.00000003.2083854165.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079686306.0000000000834000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080622552.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080130130.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081160302.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081189821.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2090241017.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\blob_storage\fc4f53ac-5f0b-4413-aa04-7f64527fa6c3\..ad_prod.pdbSettings\user\Local Settings\Application Data\Application Data\Ap source: OZ1ORrbotn.exe, 00000000.00000003.1951587983.000000000082E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1953691339.000000000082E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1952794203.000000000082E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1952193339.000000000082E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: NTKRNL~1.MAMntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn88000161Settings source: OZ1ORrbotn.exe, 00000000.00000003.2097427737.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbuEjectDialog_cw5n1h2txyewy2txyewyOriginTrials++ source: OZ1ORrbotn.exe, 00000000.00000003.1583601429.0000000000854000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1583690334.0000000000863000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbn Data\P source: OZ1ORrbotn.exe, 00000000.00000003.1993961449.0000000000836000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1994470497.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: NTKRNL~1.MAMntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.DBciconcachSettingsx source: OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammntaj source: OZ1ORrbotn.exe, 00000000.00000003.2033042610.0000000000800000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb3Hg source: OZ1ORrbotn.exe, 00000000.00000003.1994569774.0000000000829000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162 source: OZ1ORrbotn.exe, 00000000.00000003.1583557558.000000000086F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1583507198.0000000000866000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\icati source: OZ1ORrbotn.exe, 00000000.00000003.1978117344.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1978283801.00000000007FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841. source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdbtemAppData\.kck source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\*] source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162*ation@ source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb.. source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: UNISTO~1OA~1UnistoreDBd_prod.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1981401303.0000000000850000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.MAMwinload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn31009300Settings source: OZ1ORrbotn.exe, 00000000.00000003.2079898663.000000000084F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079686306.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb{ source: OZ1ORrbotn.exe, 00000000.00000003.1929227030.0000000000865000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\Legion\source\repos\Mammon\Release\Mammon.pdb source: OZ1ORrbotn.exe, 00000000.00000000.1336557047.0000000000A1F000.00000002.00000001.01000000.00000003.sdmp
        Source: Binary string: prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error_sbx\Adobe source: OZ1ORrbotn.exe, 00000000.00000003.1929227030.0000000000885000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1930910202.0000000000885000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\ source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\61\:P source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\FontCache\4\PreviewFont\*.pdb&m source: OZ1ORrbotn.exe, 00000000.00000003.1623589757.000000000082F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1622740547.000000000082F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\b\*D source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\jones\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rulesata\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfakData\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\wy.Apprep.ChxApp_cw5n1h2txyewy\AC\..* source: OZ1ORrbotn.exe, 00000000.00000003.2083178642.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079898663.000000000084F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080955368.000000000084D000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080622552.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2079686306.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162ication Data\Application Data\Application Data\Application Data\Packages\ source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\***. source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841che\*a\* source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdbl.eu source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0che.pdb\*ml\P source: OZ1ORrbotn.exe, 00000000.00000003.1929227030.0000000000885000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ocu source: OZ1ORrbotn.exe, 00000000.00000003.1966701387.00000000007FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1994239568.0000000000863000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pplication Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355r source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162ore\* source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\ source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pplication Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb% source: OZ1ORrbotn.exe, 00000000.00000003.1902330338.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: on Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.8\. source: OZ1ORrbotn.exe, 00000000.00000003.1981401303.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162eeData\Application Data\Application Data\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\.silPr source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\VirtualStore\..rnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\.S source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.plica source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Media Player\Sync Playlistsockymbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2082721326.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\DLPCache\a\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.1905084073.0000000000854000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1905472454.0000000000855000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1903779977.0000000000850000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1907899808.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.pu7jrfDN96gg source: OZ1ORrbotn.exe, 00000000.00000003.1994569774.0000000000829000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \Symbols\winload_prod.pdb\C153C68A0C33354B45 source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ata\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B4 source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdbcgb77SIOCfnAbpfB4.br[1].jssschunk.v7[1].js source: OZ1ORrbotn.exe, 00000000.00000003.1632670065.000000000082A000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1632877389.0000000000834000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*e source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Shoppingter.locklockymbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2081021110.000000000088D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.et Explorer source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\* source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\TrustTokenKeyCommitmentsonModels0C33354B45AF72681ED993162\winload_prod.pdbkbeader_Upsell_CardsetCachetings\Microsoft\Windows\INetCookies\* source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temporary Internet Files\Low\.K3KK3A0C33354B45AF72681ED993162\winload_prod.pdbt9 source: OZ1ORrbotn.exe, 00000000.00000003.1975812958.000000000088E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1975985768.000000000088E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbcation Data\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\* source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\X source: OZ1ORrbotn.exe, 00000000.00000003.2060818248.0000000000863000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2060542912.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2060616599.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\..Apo- source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbEW source: OZ1ORrbotn.exe, 00000000.00000003.1993360166.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdboQ source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error\P source: OZ1ORrbotn.exe, 00000000.00000003.1994569774.0000000000829000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdble@zohomail.eu]ID-[7H4S3UQ1F4].mammngdep source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\* source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*ta*- source: OZ1ORrbotn.exe, 00000000.00000003.1993243536.0000000000836000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\..t.WindowsAlarmss.lnklnk0D9}.1.ver0x0000000000000004.db source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\.8d379.826.98.0_neutral_split.scale-200_8wekyb: source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9el source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000835000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704440447.000000000083A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\.. source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\Site Characteristics Database\.ation Data\Temp\Symbols\ntkrnlmp.pdb\*? source: OZ1ORrbotn.exe, 00000000.00000003.2018590414.000000000083D000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2018967453.000000000083F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2019406413.0000000000849000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2018676442.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: al Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.1902330338.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.PDBwinload_prod.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1993961449.0000000000836000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074810952.0000000000842000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1994470497.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841ation source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: tion Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\at source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\*.opleExperienceHost_cw5n1h2txyewy source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: 681ED993162\winload_prod.pdb.Mail-[help.filec source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbardz\Local Settings\Application Data\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\AC\plication Data\Microsoft\Windows\Burn\Burn\..` source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1981401303.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ion Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\* source: OZ1ORrbotn.exe, 00000000.00000003.1902330338.0000000000850000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbx\Settings_{69b21fa5-2b75-40c0-88e3-556556bc757a}e\* source: OZ1ORrbotn.exe, 00000000.00000003.1983788653.0000000000836000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*pdb& source: OZ1ORrbotn.exe, 00000000.00000003.1940277474.0000000000873000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162e source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0p.pdb source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\* source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ocu source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Safe Browsing.pdb\.- source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Subresource Filter.locklockymbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2080164020.000000000088C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\*3d8bbweo source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\..teockorer source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{29c400f0-1870-4d48-88d2-134a87e32571} source: OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000086C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbn source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000835000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704440447.000000000083A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.1975344754.000000000084C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\Windows. source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000854000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.. source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: NTKRNL~1.MAMntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnSync Data source: OZ1ORrbotn.exe, 00000000.00000003.2074810952.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\.d.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnm source: OZ1ORrbotn.exe, 00000000.00000003.2079686306.0000000000834000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080622552.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080130130.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081160302.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2081189821.0000000000840000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbr4 source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000835000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1881469478.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1726874759.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704440447.000000000083A000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1865180584.000000000083D000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1727028469.000000000083C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\..\* source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Ma9 source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbF source: OZ1ORrbotn.exe, 00000000.00000003.1940277474.0000000000873000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: AF72681ED993162\winload_prod.pdb.Mail-[help.' source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.e source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: emp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2078342793.0000000000896000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: d Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\e\ source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\.\*%\sys source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1959176109.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: tings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE784 source: OZ1ORrbotn.exe, 00000000.00000003.1881469478.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1726874759.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1865180584.000000000083D000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1727028469.000000000083C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdbechToTextOverlay_8wekyb3d8bbwewef" source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb473\. source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE784155f2d8d379em source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000854000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162 source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn}n.mam source: OZ1ORrbotn.exe, 00000000.00000003.2079686306.0000000000834000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2080130130.0000000000840000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: OA~1.MAMwinlSMLK4QDN.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn $ source: OZ1ORrbotn.exe, 00000000.00000003.2097427737.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\SystemAppDatalockymbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\*4ults\Provider Types\Type 001\ source: OZ1ORrbotn.exe, 00000000.00000003.2078615098.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\a\A source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: p\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162pplicat source: OZ1ORrbotn.exe, 00000000.00000003.2048812071.000000000082C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: a\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.2063059831.0000000000868000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb*a\Default\tion Data\Application Data\Application Data\Applicat source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temporary Internet Files\IE\MHXXL5K6A0C33354B45AF72681ED993162\winload_prod.pdbdbMi source: OZ1ORrbotn.exe, 00000000.00000003.1975812958.000000000088E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1975985768.000000000088E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.MAMwinload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn_{bbb86bSettings4x,jAS source: OZ1ORrbotn.exe, 00000000.00000003.2074810952.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrometa\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.2063059831.0000000000872000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841a4a2c4er0x0000000000000011.dbication Data\Application Data\Application Data\Application Dalf source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: mp.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\w source: OZ1ORrbotn.exe, 00000000.00000003.1980597339.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbr66.0_0\_locales\id\-7de1-4405-809c-51b7a8879b4c\*depll Users\Applica4 source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ta\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\.. source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb7%@ source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdbrp source: OZ1ORrbotn.exe, 00000000.00000003.1959176109.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\All Users\Microsoft\Windows Defender\Definition Updates\{811A7D6A-257A-471C-BB51-AEE6C08504F5}\mpasbase.vdm.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnta\Application Data\Temp\Symbols\winload_prod.pdb\.\*%\sys source: OZ1ORrbotn.exe, 00000000.00000003.1966701387.00000000007FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.MAMwinload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn88000161Settingsx| source: OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\**\*g source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temporary Internet Files\VirtualizedC68A0C33354B45AF72681ED993162\winload_prod.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1975812958.000000000088E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1975985768.000000000088E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnfile@ source: OZ1ORrbotn.exe, 00000000.00000003.2052923474.00000000007E4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\.\* source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Comms\Unistore\data\tempbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\*yewy source: OZ1ORrbotn.exe, 00000000.00000003.1965034801.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ source: OZ1ORrbotn.exe, 00000000.00000003.2063470462.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2065584988.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2066291117.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1993961449.0000000000836000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1994470497.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.5 source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2090241017.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\d source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb* source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162 source: OZ1ORrbotn.exe, 00000000.00000003.1633075823.00000000007E3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: XY~mp.pdbn source: OZ1ORrbotn.exe, 00000000.00000003.1726874759.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1727028469.000000000083C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\wdH source: OZ1ORrbotn.exe, 00000000.00000003.2117997003.0000000000838000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2116419439.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\L source: OZ1ORrbotn.exe, 00000000.00000003.1959106496.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1966766492.00000000007F0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnn Data\ source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ntkrnlmp.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnmmnV source: OZ1ORrbotn.exe, 00000000.00000003.2074810952.0000000000842000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\:\\ source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Dataes00002.jrs.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.2026474952.000000000084B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2026343030.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841ata\Packages\NcsiUwpApp_8wekyb3d8bbwe\TempStateemAppData <H source: OZ1ORrbotn.exe, 00000000.00000003.2074913007.000000000088C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2074455934.000000000088B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnon Data\A- source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb8E-4E1DDDE828FE_cw5n1h2txyewyi4-T source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\.A,) source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\.i source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Documents and Settings\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1993360166.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ta\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162p source: OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: 81ED993162\winload_prod.pdb.Mail-[help.file@_ source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb source: OZ1ORrbotn.exe, 00000000.00000003.1704287980.0000000000854000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Defaultge\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\DawnCacheod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdbkckults\Provider Types\Type 001 source: OZ1ORrbotn.exe, 00000000.00000003.2017005513.00000000007E6000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\. source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\cu source: OZ1ORrbotn.exe, 00000000.00000003.2089097541.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2088673617.0000000000841000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841 source: OZ1ORrbotn.exe, 00000000.00000003.1976186984.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: winload_prod.pdb571} source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdbog_cw5n1h2txyewy5n1h2txyewybwexyewyail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help source: OZ1ORrbotn.exe, 00000000.00000003.1583401821.0000000000838000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*iu source: OZ1ORrbotn.exe, 00000000.00000003.1994641501.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\winload_prod.pdb.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnRW source: OZ1ORrbotn.exe, 00000000.00000003.2048894263.0000000000824000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\ source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\jones\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AccountsControl_cw5n1h2txyewysoft\Windows\Burn\.1.15.0.1\*a\**ore Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb* source: OZ1ORrbotn.exe, 00000000.00000003.2063470462.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2068582856.000000000082C000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2065584988.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2060542912.0000000000833000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2068841238.0000000000860000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2066291117.000000000083E000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2060616599.000000000083E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\AppData\Local\Temp\Symbols\winload_prod.pdb\C153C68A0C33354B45AF72681ED993162\1-Y source: OZ1ORrbotn.exe, 00000000.00000003.1704703997.000000000081B000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1704851969.000000000081B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD967 source: OZ1ORrbotn.exe
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\download.error.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnows.SecureAssessmentBrowser_cw5n1h2txyewy:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\WinX\Group2\.\* source: OZ1ORrbotn.exe, 00000000.00000003.2093715535.00000000007F4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Symbols\winload_prod.pdb\C153C68A0C33354B45AS source: OZ1ORrbotn.exe, 00000000.00000003.2137967041.00000000007E5000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2118533106.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2124002162.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172506755.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2121714148.00000000007E3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2165436839.00000000007F3000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2172767146.00000000007F3000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Xy~XY~mp.pdbn source: OZ1ORrbotn.exe, 00000000.00000003.1881469478.0000000000840000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1865180584.000000000083D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdbrolpan source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\download.errorApps_{5fc69a56-0c9d-48e9-8c45-7102a9e2439b}\..js\ source: OZ1ORrbotn.exe, 00000000.00000003.1983788653.0000000000836000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\\Documents and Settings\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: OZ1ORrbotn.exe, 00000000.00000003.2093596549.0000000000868000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2093465396.000000000084F000.00000004.00000020.00020000.00000000.sdmp
        Source: OZ1ORrbotn.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
        Source: OZ1ORrbotn.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
        Source: OZ1ORrbotn.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
        Source: OZ1ORrbotn.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
        Source: OZ1ORrbotn.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD643 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeCode function: 0_3_007DD5E6 push FFFFFFA1h; ret 0_3_007DD642

        Persistence and Installation Behavior

        barindex
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpClient.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpRtp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableEngineEtwLocation\mpengine_etw.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpSvc.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAzSubmit.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAzSubmit.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\endpointdlp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\endpointdlp.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpClient.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpSvc.dllJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeSystem file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exeJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Application Data\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\Accessibility\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\Accessibility\Magnify.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\Accessibility\Narrator.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\Accessories\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\Maintenance\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\System Tools\Administrative Tools.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\System Tools\Command Prompt.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\System Tools\computer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\System Tools\Control Panel.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\System Tools\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\System Tools\File Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\System Tools\Run.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\Default\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Administrative Tools.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Application Data\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Accessibility\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Accessibility\Magnify.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Accessibility\Narrator.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Accessories\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Accessories\Internet Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Administrative Tools\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Maintenance\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Startup\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\System Tools\Administrative Tools.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\System Tools\Command Prompt.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\System Tools\computer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\System Tools\Control Panel.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\System Tools\Desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\System Tools\File Explorer.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\System Tools\Run.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\Documents and Settings\user\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammnJump to behavior
        Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_neutral_split.scale-100_8wekyb3d8bbwe\Assets\AppTiles\StoreAppList.scale-100.png VolumeInformationJump to behavior
        Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
        Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
        Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
        Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\OZ1ORrbotn.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
        Source: OZ1ORrbotn.exe, 00000000.00000003.1374460191.00000000007E8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: MsMpEng.exe
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
        DLL Side-Loading
        1
        Process Injection
        1
        Process Injection
        OS Credential Dumping1
        Security Software Discovery
        1
        Taint Shared Content
        Data from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/Job1
        Registry Run Keys / Startup Folder
        1
        DLL Side-Loading
        1
        Hidden Files and Directories
        LSASS Memory1
        File and Directory Discovery
        Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
        Registry Run Keys / Startup Folder
        1
        DLL Side-Loading
        Security Account Manager13
        System Information Discovery
        SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
        Obfuscated Files or Information
        NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        OZ1ORrbotn.exe63%ReversingLabsWin32.Ransomware.MammonRansom
        OZ1ORrbotn.exe100%AviraTR/AD.Nekark.wdqnz
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://www.symauth.com/cps0(0%URL Reputationsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        s-part-0036.t-0009.t-msedge.net
        13.107.246.64
        truefalse
          unknown
          s-part-0017.t-0009.t-msedge.net
          13.107.246.45
          truefalse
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            http://..wikipeOZ1ORrbotn.exe, 00000000.00000003.1903178045.00000000007FE000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1903050309.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1901973402.00000000007FE000.00000004.00000020.00020000.00000000.sdmpfalse
              unknown
              http://www.wikipedia.com/OZ1ORrbotn.exe, 00000000.00000003.1899106504.0000000000800000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1898435731.00000000007FF000.00000004.00000020.00020000.00000000.sdmpfalse
                unknown
                http://www.symauth.com/rpa04OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpfalse
                  unknown
                  http://www.symauth.com/cps09OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpfalse
                    unknown
                    http://www.symauth.com/cps0(OZ1ORrbotn.exe, 00000000.00000003.2318034416.0000000000805000.00000004.00000020.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://..twitteOZ1ORrbotn.exe, 00000000.00000003.1901973402.00000000007FE000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1899106504.0000000000800000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.1898435731.00000000007FF000.00000004.00000020.00020000.00000000.sdmpfalse
                      unknown
                      http://ocsp.digicOZ1ORrbotn.exe, 00000000.00000003.2269728469.00000000007F0000.00000004.00000020.00020000.00000000.sdmp, OZ1ORrbotn.exe, 00000000.00000003.2270186025.00000000007FC000.00000004.00000020.00020000.00000000.sdmpfalse
                        unknown
                        No contacted IP infos
                        Joe Sandbox version:41.0.0 Charoite
                        Analysis ID:1547550
                        Start date and time:2024-11-02 17:14:10 +01:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 12m 12s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:default.jbs
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:18
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Sample name:OZ1ORrbotn.exe
                        renamed because original name is a hash value
                        Original Sample Name:768d390a232501b58b9626b4764d10f7a41732dbd5a8f559664d2f1d9f7d1cd0.exe
                        Detection:MAL
                        Classification:mal100.rans.spre.evad.mine.winEXE@3/1076@0/0
                        EGA Information:Failed
                        HCA Information:Failed
                        Cookbook Comments:
                        • Found application associated with file extension: .exe
                        • Override analysis time to 240s for sample files taking high CPU consumption
                        • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
                        • Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                        • Excluded IPs from analysis (whitelisted): 184.28.89.167, 20.190.159.23, 20.190.159.0, 40.126.31.69, 40.126.31.71, 20.190.159.64, 40.126.31.73, 40.126.31.67, 20.190.159.4
                        • Excluded domains from analysis (whitelisted): www.bing.com, prdv4a.aadg.msidentity.com, fs.microsoft.com, slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, www.tm.v4.a.prd.aadg.akadns.net, clientconfigcdnmsftuswe2.azureedge.net, clientconfigcdnmsftuswe2.afd.azureedge.net, clientconfigcdn.msauth.net, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, e11290.dspg.akamaiedge.net, clientconfig.msa.msidentity.com, go.microsoft.com, login.live.com, go.microsoft.com.edgekey.net, clientconfig.passport.net, azureedge-t-prod.trafficmanager.net, www.tm.clientconfig.prod.aadmsa.trafficmanager.net, www.tm.lg.prod.aadmsa.trafficmanager.net
                        • Execution Graph export aborted for target OZ1ORrbotn.exe, PID 7704 because there are no executed function
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                        • Report size getting too big, too many NtCreateFile calls found.
                        • Report size getting too big, too many NtOpenFile calls found.
                        • Report size getting too big, too many NtOpenKeyEx calls found.
                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                        • Report size getting too big, too many NtQueryValueKey calls found.
                        • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                        • Report size getting too big, too many NtReadFile calls found.
                        • Report size getting too big, too many NtSetInformationFile calls found.
                        • Report size getting too big, too many NtWriteFile calls found.
                        • VT rate limit hit for: OZ1ORrbotn.exe
                        TimeTypeDescription
                        12:16:25API Interceptor1x Sleep call for process: OpenWith.exe modified
                        17:15:50AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn
                        17:16:03AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn
                        17:16:16AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn.Mail-[help.file@zohomail.eu]ID-[7H4S3UQ1F4].mammn
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        s-part-0036.t-0009.t-msedge.nethttps://api.inspectrealestate.com.au/email/track?eta=1&t=B32-5UARLGTXC6GHXC7PJPHCGUP7HMF6FJEQ76L6MOL7WYB6P6EYQNBONANBBGKOXFRO3HPDET5TXGOZXG5FJNMJJC437YUYUWDF5VEVIWPK6LECEZJV3OMRCXF6VI76ZOGYOFIOERVACTHYB4KHK22IKKEWLYPTUBLONXLA7QVY2SW2TZMW4ULVG2UAKDR3DM3RL4TTJAF3F3ROXQ3ZLRVYS7Z2T4TIQETEEUV73V42AQLF65YKSUX6JMYEW3ZHXPREAMXXBOQV32GKOYOISFZKX4GPTPR2IMSMCULLR2V4QUSMU3MWF7NQ%3D%3D%3D%3DGet hashmaliciousUnknownBrowse
                        • 13.107.246.64
                        (No subject) (98).emlGet hashmaliciousHTMLPhisherBrowse
                        • 13.107.246.64
                        https://mail.kb4.io/XV2pCbFUvdkZ0U1V3cHZQWXpqL3hjTU9wcmY4ZmEyNXZRWTRiU1VvMTVwRnRrYWdnVjdlM0lLQ3VmVXlCSlpGdkkvQUNJWjZLaHpVWnRmYjY0VktjbmJLUFlpV0xzWTVEdkJsa1hrWXY0dGZHMUNoclZ3aDRORWlpQlNhTlpLSy9pdXMwQXozSHVrYSthQnJrS2J6T0EvSVBMYUFYRG1EZ254WlBRUGdyZU55TkdBZjB0aWhCMFdIN081T2RsdFFIMVpIdFAvU2Q2NXlLKzNJY1JZQ1JNMTBwaDlZPS0tNE01L0hRZXp6Tm50TW1MTS0tSlkrYWNuVllJcXZpelZWZ2ppaVRSdz09?cid=2260646675Get hashmaliciousUnknownBrowse
                        • 13.107.246.64
                        https://1drv.ms/o/s!BOd5RNxFaxkGg1r5bc30bgQWmkNc?e=J67qxK-KfEurqpMk0dasTw&at=9Get hashmaliciousUnknownBrowse
                        • 13.107.246.64
                        Secured_Voice_Transcription_Arnoldclark_847.shtmlGet hashmaliciousHTMLPhisherBrowse
                        • 13.107.246.64
                        file.exeGet hashmaliciousLummaCBrowse
                        • 13.107.246.64
                        2QPrBtk3J8.exeGet hashmaliciousClipboard HijackerBrowse
                        • 13.107.246.64
                        Fax_Message_04 September, 202411_21_58 AM_564308269612697.htmGet hashmaliciousHTMLPhisherBrowse
                        • 13.107.246.64
                        https://cswlawgroup.artoffice.cloud/Get hashmaliciousUnknownBrowse
                        • 13.107.246.64
                        https://t.co/yXelyYqHRkGet hashmaliciousUnknownBrowse
                        • 13.107.246.64
                        s-part-0017.t-0009.t-msedge.netSecuriteInfo.com.Win64.MalwareX-gen.31330.3086.exeGet hashmaliciousUnknownBrowse
                        • 13.107.246.45
                        SecuriteInfo.com.Win64.MalwareX-gen.2477.17602.exeGet hashmaliciousUnknownBrowse
                        • 13.107.246.45
                        SecuriteInfo.com.Win64.MalwareX-gen.31330.3086.exeGet hashmaliciousUnknownBrowse
                        • 13.107.246.45
                        SecuriteInfo.com.FileRepMalware.9433.30814.exeGet hashmaliciousUnknownBrowse
                        • 13.107.246.45
                        https://parrots-run-fjh.craft.me/kKsdDph47M82kHGet hashmaliciousUnknownBrowse
                        • 13.107.246.45
                        uqBq7FwS83.exeGet hashmaliciousAsyncRATBrowse
                        • 13.107.246.45
                        https://all-filehub.oss-ap-southeast-1.aliyuncs.com/2nd.zipGet hashmaliciousLummaCBrowse
                        • 13.107.246.45
                        American.ps1Get hashmaliciousAsyncRATBrowse
                        • 13.107.246.45
                        Reservation Detail Booking.com ID.batGet hashmaliciousAsyncRATBrowse
                        • 13.107.246.45
                        ap4pkLeaVp.exeGet hashmaliciousUnknownBrowse
                        • 13.107.246.45
                        No context
                        No context
                        No context
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):659
                        Entropy (8bit):7.672365055861335
                        Encrypted:false
                        SSDEEP:12:kjsHoi3zlZLzRXm5BarCO3jTJKSXniM0aS2/Ojz/2YKaD9Ehirih/:kQHoiDlZLFeBarCujTES3iM0z2GjzBET
                        MD5:749C1A4C71C8A0BBF075D68849811127
                        SHA1:0C7CEDE447FCEEEA764C04E259AFB52756BBAD12
                        SHA-256:209C9601B57648F575C868007AF31B09AA34F7395C43B1F5DF6BBE028B22C702
                        SHA-512:0FDC89B9DBE91E612AC359FCF1BB50DD9D4814D1AFC4411C609C2F6C841C4B3367BB773A77CE68E598944D7DD20A1B9656ABA7D99F825B3A1FB6DD10E12FF5DB
                        Malicious:true
                        Reputation:low
                        Preview:u..V.@m3....G.........,.!.....=.....*....S...p+...TK..l.k..!."O.....*..Qpj..e{....A.U..gK.....t.6....{2G..r1d...kx<.. .6.-.B.A`g.....a"K:R%X...l........k.x..*V/.....;+.U..\.`.O...w#7.w.k.7...Y.A...^..S.a.....:.+!.|..qYD......I..( ..|..]...z+y...u...I..1p..|w.".b..@.*p_.P..%.,.{.J..2kE...Sw..4.D.qD.N..,Y.Y.E.}.0..(.u".a1.b|,5>o.....WU../.:.r.m.. |.cK6....E.|...|.t<.oi.@.)....G..m..XH.zL_....p..'(.B.X|.uawI..q...9.......@...z#.1.....U.V....9.&.).b.L..........D_.!$.R...:!/&J.f#$.H.t..= ...m>fJ-.....].&N.._:...K...*..Qu../..m.%.B.0...@3..w..a......w.W........V+.IX......$..1.,.H._h]..J...o.9....S/A..tSr...c...Q'B....P..D...L.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):659
                        Entropy (8bit):7.693735520620102
                        Encrypted:false
                        SSDEEP:12:7pMB2SHYT8HeKg2x0MNKWRLP1yahjN/S0PEIc1/E0ET3K8xF2BsiDBLz+q0QsHF:WgVT8KeNv9dyejNqFf1/ElxxFObD9z+D
                        MD5:C6527D8DFA840F6A0759BEAB40D251B8
                        SHA1:3B149D260D55DF75F1D4CE0395460BD2877C768B
                        SHA-256:2CED5DF763098F79B276A4784691D2BB7EDD1AD8787AC4819E376634C45016D9
                        SHA-512:05DAD4DF02B364630064D2472AEAA05B19858DE68C6D0DAFBD777689839A2E4AF8AE696B2FB0CAE7DE718B623D09ADED14DED819C173B29C97DCFA32554FA91C
                        Malicious:false
                        Reputation:low
                        Preview:.|l..P.^...>....FN..3kY.v{j...48@'.MXJ..t%.%.U.;.y.6...)=...B).<a.*.>...iA.~..O.f..^`.!..H'.qPF..m.!!.'.P.Z...@.O.?*3../H..........f$...HZK:.vp.{.zF.....K.DD.`....a....?.6*[.^H(.%.../..y...yEZ...y....(..B......%=s.......Wx.h.F.2r_.T$.c..x.9........A.E.....G...p..Tk....z2........Iab.A...%h..;GM../Z.5-4ER]..u[i.=Z..H.A.?.V..).}r..*..G,c.|!.u..8....;UJ.."...{x..2..;..>......S....x.[4N?...!..>..+>...^.........NVWZ.........j..W.\..iL`].....V..%s..+.&b...wA1..2.S.N<.2.< 8s....../I.bf.....p.+.T..m5.02.T...`....`..h.:H..e7..u[.Z..2.......S.G..d."P.Z..."....F......R?....`X.@..Wq....\...#.......F.`?l.l..._.......v..b..e...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):659
                        Entropy (8bit):7.682159303584529
                        Encrypted:false
                        SSDEEP:12:2C0ZGJ0fGQa6syq2Ik1KfQUIf3MTmBHTCgMUtOJLYROZhnGCvFWJAuuUO1Xn73:2uGf9q2QfQNfqIH2geUYGGFkAumL3
                        MD5:82454F86B020C5BCA35EEB44AE728C09
                        SHA1:18DB70C08BFFDEA3B33E703D716F0BD1E788F9DB
                        SHA-256:C525940E6937F1881BBBBD55D67FA17E76ED7D843691F08C90CC6600C965B367
                        SHA-512:309E8DD879687522A4FD2A73111195F7C18C70A81437C159231D6D3082ACC2415DCB6F77A57BFC154D5438F9C1C5BB53F85D67D94AD408DE8E2709F9571DE348
                        Malicious:false
                        Reputation:low
                        Preview:./.g........i....Q.iw.{!IV.....}.cYd|..3.....D..0*..ja....X..hk.....uc/...6.g...'.1jT}..\?...3.~.!...\...$.oF...jK....0.....m.-...AO.....K:].-.....^..D..7{'..V.....n..ZAa.R....f..K.u.c..b`3....U:D=8.(....V.........k..Y....vr...E.<c........".Z}.Y}.%.$enSPD&...hb........xg.,.....p._.G...S8N$...D...]...Ob}..S..4....a...<.M..6."(.,.._..3...(.mlN..n..W...^...t........rF.Xy...q./..kB.'b.....R....n="\.h.SKW..|wm$...(8I4\..'.E@$I.......x<.n...M...g.vB..5...U.EM.)....V.... .s....l.C............e.P..Q_"......g[eu..x..%%.Ak...P....^..Z...r.?..tP]..{h...x..O......d%d XhwW.6.d..q~..+Y.......|...p..I)'`A...............Y.@..[..Tm....Y...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):659
                        Entropy (8bit):7.692819702693999
                        Encrypted:false
                        SSDEEP:12:fGVsccDsRkSXS8ilm7pKjS6cTHfORDHeYiwsRxuLF0BDgP+zJH+hVmRPNWJ7U6oE:fesccDDp8ilmNKjg7fOiw6uh0VgmR4Jx
                        MD5:1ADCE5EB05BE3EAABE4B13DD6D4C6D99
                        SHA1:FBB1A7744BD1104B9C93505AADBCFB7E1057A144
                        SHA-256:AF6191EDBA3E7369EE0BA8DC490E879D76109653793BC0F3D6B50D5967B455F2
                        SHA-512:8EA0A61B1090E8B1A0970DCA8164B244BE5F20E485B49B8A61DE87DF796AED4FA7D993FD7402D9B443C3DED189EF02BA8805DB24D4333990C32B51C1F5C880EF
                        Malicious:false
                        Reputation:low
                        Preview:....._.RS...bH.)....\....).%..1............}..v...9=.nK.d.%...~G.W...W.-..8..6!...s.5.pp.<c.].6"..s..H|...q*.].1...Q.....>...=..$+.b.....G.K:.....G.]..[K#~,....q..[....[.=..I\p..H.:,.....!X...U..yd.J.g.'........Wp.C. ..+d.A..]...Dm......b...f.....P..9..lT..u.Re./L...4...V..|a.E....|i...............pV.4..{.3BO...7..tB.;.......(].PK.H.$....qBcCL.....|..~..$...-.75,.6...VS.[/.."..$.L.7h~k...$...QO[.f.......R...].V6O.!+......7 &V0.a.D.pQ.[....K.$..+.J....y..;2...G.a).>..T...i\N.Nb..i{Tf.. V..fD[...z@.(..]S\.2....[.....{7.-......X..v.R!..z4y|9(Y...'.I'`&.e..%.BO..z.n...a.5.c.q.fHyEG..?......-.... .1.s!..b..LG...5h.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.16540649208618013
                        Encrypted:false
                        SSDEEP:768:FJLuLR1dDEBmHl4iDopGwsCuXH8a+ciyJP5P:FJLoR1dDEBmHlbDul7u38a+ciy
                        MD5:8F48253B7FA7631E21DD86879805E645
                        SHA1:3896F2018579A8089D54B5E8C47F1CAC5311C252
                        SHA-256:D1531C1E6DE8E75C919D0CD3C0B9BA15754F093A55B97F8364DCC41FD8BD7A70
                        SHA-512:2850689D1A5896BA817BB881720517BD3E3E1CE00F9504A950AA4BECB0299CEAE9942CD4A8CA3135038909D023AB334BD6608C1A22E8DAC5074CC1A41398F192
                        Malicious:false
                        Reputation:low
                        Preview:.I..........@..@.....|..................<............|..................C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@..........................................#.................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:Extensible storage engine DataBase, version 0x620, checksum 0x1035ec82, page size 16384, DirtyShutdown, Windows version 10.0
                        Category:dropped
                        Size (bytes):786432
                        Entropy (8bit):0.14017016676795194
                        Encrypted:false
                        SSDEEP:192:CC6nC62XWppQ0Tt2pRZyThY5/4MSP8+AWppQ0Tt2pRZyThY5/4m5f:CCSCXW0StseCJ4MRW0StseCJ4If
                        MD5:D2D97DDD644CDDA3FE7AA7B15A63EA90
                        SHA1:C35EE28432DACCF607134D6CF9502E4E8A3919BE
                        SHA-256:E5544377F69D6C700A33454FA9A4A9777D750FB0E0A185AA8EBC93315916C597
                        SHA-512:EFBCDC792E3958BFD8DFD60EA9604C3D0E19F83FAE4C68322439F26F58D11A963DE5113203F8912891823041716D9CBB2FCF9A88635426989F37106467FE068B
                        Malicious:false
                        Reputation:low
                        Preview:.5.... .......-................|...........................................|!.h....................................|..........................................................................................................eJ......n....@...................................................................................................... ............|...................................................................................................................................................................................................|...................................[.l.....|-..................{w0.....|a..........................#......h.......................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1939974
                        Entropy (8bit):5.643159328614193
                        Encrypted:false
                        SSDEEP:12288:MlgEXtpGO83Lql0kZOvbHARtJG7cyQqyOsy0xlgty:JEXzr8o0kwWFey0y
                        MD5:60547E66C22EF250BF3284A4478E7143
                        SHA1:8ACC3DC02D5ED27BBCF608ACBB6898A98E8EFB9F
                        SHA-256:FA6927DCE47C3947C4BC43926ED26A02D7FB4D731DE2D39C9447F984A3EC693E
                        SHA-512:69740B0C6137F8E38384EF0E8C8F1FB5362BD278A7D43AC21B4E82B7EC87223D097442D8F5070CCBC3B67B5C100D5617B5EE50A834CC5E94FCA8A23D419BA9FF
                        Malicious:false
                        Reputation:low
                        Preview:.....|Q...(..U...".dU.g9.:......n.uVF....yt~.....=....n:h.|.N.I>..]5..5_...........H.]..E.0S.F....VX9.=.1*r..[W...G...NPJ.R..-4.&vx.#..M.P..uS.x..tMB...[.......JA7..L...44.CU.MP.y.....$%6.4......k....3.)..cN.j............b$...ci...:V...Q.e..h..a....<9..L....&..)..Y....qe.`..xM+.6.......x.>..G....8.Ev.E.@.U.D.D.......^...6._..@...z.......A..."<..iR.Y.'....N.....f.6.?-{~D.k.....T......7..2.t..e{..{A..-.F........5...^..1M.4..w3...P.....b..]..4..^..(..B..B...^..YU......s..~j.c....ChZ...U.!..>s...... .....M9..V......b?..a,..~...>%..>....a.}.l.0....`......AZ./.l"......4...t.vd6[e./.6...?j..H.....U.k)...g..8......!<.!.........jl....R..k....z. .~P..,...,..0.'.G..jhR..9H..A...2.O..z.4pg-.nw.j....H/._y"...~./7........&.<...jQ`..m1.....HH...u.2..<.`.)^.S...9..r...N$....X..n..3...b.......*...gs.#.D.a|.U....|...\....)w.......*...I.P.).....PR%.xf.Vg.....Od>..T...f.O!..l...wl.?........OE..7.*d.....1* O....O.X.&kM".V6Za].".......[N.......f.y...Q$.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):2.8567097867775586
                        Encrypted:false
                        SSDEEP:6144:myKt2roQ2b7lfkzRxBr0OA1ehcB7VoBgYEL0InCK:pu8/2Vk3BrtvhcNVo
                        MD5:895DBBA1D9DDB01477AC19B1F80E25C6
                        SHA1:4DDAFD03C957D08719DB79092002F38FA954354F
                        SHA-256:E3D0F4AD7D134AA3FF64E15CB578E17D57A5918472ABCC09F97D6520F7BBD0AF
                        SHA-512:48DF758667E7541E127B5DCF6A8645AAAE40E83C63D9A8EECFBF075ECD2E7CA214D0969F787B3C74EF4B82C6FEA9757862D64C206E6ADA705556292B5D77DCE6
                        Malicious:false
                        Reputation:low
                        Preview:;..?v3k.Azl.3lP).......c..P.W"...`%.|~..le...6..W"w._..S.....X.o.....|.NwJ.!..}qf.I."..m.l...W.....].....4r8....[b.t........A..~9....y7..#;......!.M>.T........3..f36*O..aZR-..C..X.2.5.O..?h............# ...T.. ..E.].R./.s..P.Q.K,.<m.F.C.W.;........8k..p=../.}...@~k..v...,...d...lokE...muV...5."..d9Y.W..|.:..>,o}.3..P%.O2i........>.*Nt..z ...`$r......\.O..!.7.\/...80cx._.N.p..........F....3]......._....{.,p.V.;...gL6....x.b..y.]..p@gN.x......`.....E..y\..4......6.s..{`.+0.!....C..U]..O.A....8:.E.....;3..%.s ..2.~....).%.x.k.?.?.A}..VA'....wn..cB.K.{SO..$b;.L...\........g1$s[@.0...4...$..J.....O..<.C.j-... .&t*,N...i..C!. .C....X.jx!....}4....T.(\....(.u.......=.#.D;...2.F.%yLX.;.....|.`..;y.$&_...q..&a.....M.?....GP.C4JTJFx6O........C..>/q.A.$*..%..0.^..,...o..Ic...S=-.."9.#9..b.....*..0...a...a..Z.R7...[_i.B.W4...[.b. .%..S.......J'y..'.5e.zN....s....u.`}=..4.~;P.i..z.33;..8S...N1...8.b}6"rt6....L.~..tE.5O.O...@..T..5.....|Z..i.Afd....~f.E'..nQ..)Zw
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:1045BFD216AE1AE480DD0EF626F5FF39
                        SHA1:377E869BC123602E9B568816B76BE600ED03DBD0
                        SHA-256:439292E489A0A35E4A3A0FE304EA1A680337243FA53B135AA9310881E1D7E078
                        SHA-512:F9F8FCC23FC084AF69D7C9ABB0EF72C4684AC8DDF7FA6B2028E2F19FD67435F28534C0CF5B17453DFE352437C777D6F71CFE1D6AD3542AD9D636263400908FD2
                        Malicious:false
                        Reputation:moderate, very likely benign file
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:1045BFD216AE1AE480DD0EF626F5FF39
                        SHA1:377E869BC123602E9B568816B76BE600ED03DBD0
                        SHA-256:439292E489A0A35E4A3A0FE304EA1A680337243FA53B135AA9310881E1D7E078
                        SHA-512:F9F8FCC23FC084AF69D7C9ABB0EF72C4684AC8DDF7FA6B2028E2F19FD67435F28534C0CF5B17453DFE352437C777D6F71CFE1D6AD3542AD9D636263400908FD2
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:1045BFD216AE1AE480DD0EF626F5FF39
                        SHA1:377E869BC123602E9B568816B76BE600ED03DBD0
                        SHA-256:439292E489A0A35E4A3A0FE304EA1A680337243FA53B135AA9310881E1D7E078
                        SHA-512:F9F8FCC23FC084AF69D7C9ABB0EF72C4684AC8DDF7FA6B2028E2F19FD67435F28534C0CF5B17453DFE352437C777D6F71CFE1D6AD3542AD9D636263400908FD2
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):2148944
                        Entropy (8bit):5.517502618397121
                        Encrypted:false
                        SSDEEP:12288:aQs1bGIiB3dLiyrris2UZh+RPbVB5nHxna:ap1zW3dOyHZZ4/B5nRa
                        MD5:69420026FF1010CC4A74422C7EC0B367
                        SHA1:0E1982B91EE5446410538590E5B6DA0062FC39BC
                        SHA-256:3E0C15C740A2FC325BAD3195F272C9B5CA86389D6E23B25B966830DA0544A1D5
                        SHA-512:234DD846CFF9B2F915109D9A3F53234008F5E8080BE4E85748975B8DE656D78346E4BD74C857B705E2F3B94159B21FAFDA890D1F30465258A8B75D31B8FB60E5
                        Malicious:false
                        Preview:.B.y.i.....0.Uf...G.....F....(.o.gH... ..j58"e#..X.Y+.......s,lL....K.^q..>.zR.^...[0....?...s!D.l..w...(..5".P...6.........*."...o%.K.e.F.8._(.....Q......z.9......B....W..6R.'....wV.b..F...........I.3o4.....Y..ia.s.m.....b..#G.:V.WR..^.....e.do.].w2"@Q5.o.}.Y.....3......."l....k.rx....r.........#..x.....e.}W6..6|(....j.N.*E&h..+.....LF!0.r..f?...E..x.dK.....T...kx.=*.I..P.H.R..R.s..G...B5.yI...m.j..9w.._>...R..E..T)..7..."(}q..:..m..a.M.Eo...%.QW. ...b.bzQ;....@iM.W..<.A..O&..J..%L(...i...?..!M..e...)..`..n48e..6..L.l[%.1[`.9.9(....r/.?.b...*.cE.k......j...t..D...HD..t(RfaYEU...R...={y.k.@G}......W..F?"I..-..P&........P.)...4.$2/,.C....!.4...b.c.1.u.......r.T&..:0&.#.4l^...t..i.h.a.;t..w...4....x.......l.9..XjQm)V.`.[I.S...67..8.......u.p.N%...V.{.....:M...?..|..6....Y.#..Yp.".....\0.-%&........U.........K]....[...VV...H...r.k...7.....4.g../...l....>fu.^`....A.W{h..j.x..".\.Xie...1r+.y4...?.nG8....`K.K.>.b..0.yA.:29S.j...8].D<9!..i`.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16777216
                        Entropy (8bit):1.9996377881997445
                        Encrypted:false
                        SSDEEP:98304:fHc2SHsR8kfWX6/EEJrcf8oZBzYS4lH6:l7fWX6/EEJrcf8oZSS4Q
                        MD5:344890440C3039BD7857486C1D195BB7
                        SHA1:ECF10B5FC4D423B5376A97A6B811BFF39CD7A087
                        SHA-256:C121AA1BC51911CF98B9280A0A7DD7B63D341CEB7473783115E2229865833DCE
                        SHA-512:55587F20F021CAAF8426740A7A687C53E077A3F5FF3107DD346CE6657EF0B4BB8D0BDC07D7EF2FF4495A43BF849AACADB0A9AB058A61C41731B0970F141D60F3
                        Malicious:false
                        Preview:.....S..+..+-\~.p.F..M.m'{....^.c<..A._.2..;..5...*. >.>Y....}._.....6"C.3.--.F...r...^J(...,cgq.c..K.......N........./.....iI..X..a.!.^E..........3...I...$..`!....D.\x.?.nl.E.hm........#g.7..s...CF..5Wp...[.......w..r.s!.0..I/z....{...30..C.........6.w%.......|............$.UF rw.]..R..>R.H...JX........L...IQ\.p..}...Z.......D.../...q4..y.....S.7......?.....n|.&.......M.Cg.k..6_&.H..%%.b...Gz...x4.....,-...q:...3HC6S...}..:L!....x...C;...D.?..]....^</'.G..=:........8SM.l...Hx.....DR.....<G.W...5i..Z#bBh'.T!.....fm......T../._...qf..(...x.b..S..O.....o_..R.....7.%.{.-,....k@.T..S.D-.wp..q...|.K.fT..E.}.#f]D..E..&..J;....)....xS..x...T.h.-..<.....r...:...,....X@..{..H.Dsk.i...j`.2.......f,..~..O.`.. #v.....J.f..-.+h..(.)U..Q.c<..M4..S..!.....>.c.+;4@..QmE$.E....1.3.....E..s...j...h/.s...X_...U..G..co.d....$.LHx..U......KEP.%.|..y.3J.......'o.....a...>..gUG...K.1.....L.<O?.]h.....CB.n.....9....I.#..UH...^.B..X.{........ .CG%...)..).7.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):84068344
                        Entropy (8bit):7.99737624482664
                        Encrypted:true
                        SSDEEP:1572864:WgxWQPdrI301Ahdr95wKilp3zqoAmxThz0BYQrQ747IAL3Bmp:WuWQFrY06z9PUpjqb2OYE+4fmp
                        MD5:32108383766B562B5A278861B9733D44
                        SHA1:04C3FB4FDB565035B3A430F865FEF01C066B1867
                        SHA-256:EC9B64DD2EC7BFCC052DD4004B9818484DCC4FAA5AF1DE473E0400AF1CAFD777
                        SHA-512:9C27F16D06E2F19190D2883D161C34497532DE8DDE64DF9DCC0E4C414D10AFE879F8AFC79C03083B8A199937A43EEACECA00F69FC1E1CEB51E75296B4537FA24
                        Malicious:true
                        Preview:...:..^...m|........W..}.F.+.0...(..iQ...k...P2C+2Q..Q".0....e.}x...C.c.~......f6..A<.O...p.Y..o.nv.|....Nm....7^.`......B...B.g^)...)D}|..<..6w...At..|..2n.&$.qH#.+H.........|s........H=.....e.I.....v......b.Q .aEr..}..M.....`*...0.ez>O)......ES..c..M....V..~.Yw$SlTX...gj.|a.M...@..@.L...}.=........3e.z,....!0r4:}..$...3...t...6.d.Pz..(.....i..1.b..?.r.~...y.......q..l...x.).sL......l9..]....$. .....3..u.A........R.;S....EK \..J...Ii;9(...sE.T.M./+.~...q.e_.G~M...]U....Er.....v......'S~Fho.@.......Y.B......r.L..H..(e1.iG&....!.c."..`..*.cf]b....v".:...D.P......4}+..`..R..j.Xf{......E.q,.W.bS..."..?\.....h.r.......\....r..t<L....VM.*.?B......zo&9....PO...h.h].j....;n."b.ugtB4~....V9..."....<.......w.u.A.O.,8t.D.x..'7.UZ^d~.O)....l./_.%..k....\..{=..I5..qK3.g....{..d..-g9.../.B.V3...-E.i|[.!%E..B.r..m....`.Q.1....cZ...ZEuu...C...R.P....,W.[R..3.D....N..%.....<.M1h.]..'....f...7#...*FG.......B...^;.`jC".nA`....L..ds......O$.br.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):68955736
                        Entropy (8bit):7.99758929668477
                        Encrypted:true
                        SSDEEP:1572864:LFXdwLL8wkPi0N1AvxHwaAzCYORK6FDksTdNrX6k4CGf:FdwUfq0N1ApyCHptksdNrX6k43f
                        MD5:278B2FBB0AAFA379C3CB89DB89196655
                        SHA1:5441D42295FF491CF9BA4035193735EBA01E90E5
                        SHA-256:82758E1A69526CF1AAABC00B486E1EBE3CA3CCE8EBA1C6C5F91D1B2FB27973B8
                        SHA-512:25FF5A27C6397DBFF3483B94210AAD957EF3D8506EF016512880532E16FB6C841F51120CF159F13DD4B22CD7CDCEDE85255BED742870DE88CDD5BDA0A66B5BD0
                        Malicious:true
                        Preview:.........?!n..gI.;..G.a....2L5D...N....:....g.G.32......e..`...x......P.......N.Q.X......B8..1.......P./qx.6s..;.......|."t.....;. ...v%..OX..H.D..)I."..L9.......ik...}..]...p+.......BUP....9nr..FX.._.....@..^........mO.(.0.e~.f\...HW.....x.x..k...u.Z.Z...wl_ .b..nQ..........aN..k'..s....N.-..Y\.|c6....FXwj{.&.YJ.=..l]I;...[.M.\........:R...l...pHD.....T.al..^`..3.G..c....H.%......p.zRf.M...........O..........*.o.....7...h......1...*^}m+W.[....S;.m.0.oh9.MnS..3..........*.aW..9.W..0Z)..u.*...D.Z.M.e.j..r&..V.~jE.ql.....<...<.....V$..3..H} !Wv.N.r......c.|DIq...h..0.*.U....)..L..,].2G..-*...z....!U).D...J...%....TC|.&...{h..SIwC.@.Q.2.8..&;.9..."Xi..z.....C...#]...Q....J.."d..<9dv*!..K..&5._f.'........L.l'.;uZ...|K...#."@z.j...w...S@. > ..e.....r%G...,.1{...6.(...Y....[....{..72...Q......:o...d).:p5.pl'.t-.^,....i.A..o..?.....+.../p}V...MJ!A..9X.. ...._......i.|..........M.(h...a...l......<}-..c..#k..M.H.F;l.......u..h......|.qS5.%.m...w
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6672464
                        Entropy (8bit):7.999460045702652
                        Encrypted:true
                        SSDEEP:98304:dcGogvgsBUTQmgQaHG4lIy/1ALL24ZBVJN1pzsiag095to7ZKqtucbo7Gfs1SJ/X:eGxg/32G4lQf2gVNHzb095yVTC1602
                        MD5:B0F8467522242FAB21BC46494EC59E12
                        SHA1:C8D1A045445E9D092851BC38EA8A8E3D1732C372
                        SHA-256:935C225CEF426BAA307BDBF196EE09C6AF0B63119C583AEB645EAFC075A4C426
                        SHA-512:046016665540EB158429365DD291FD344492C00C5789B78EB35BD24C1AEDC20A0A7D75E3280B4BA978938B5F715FB21CBE0D1AD434D42E6FD06B1CE6CB36961B
                        Malicious:true
                        Preview:..9.h._.u<.S5.".T..=.:h[.5.V...~p..*........Z......L....C.........g)X.g...y.K..#~.!..3..d...............+.....|uJ|...m. .C...[.........co......]k.p........&.)4{...DW.,kX>.d.H..S{.......226..>i..d.......yc."(E.g......,...L...c.;.Z...8..0*na.=.h........1..:r(.H.?N..ng...p$VS?.RF..4..5.......o..%0M..}.\......+~[h....Y..8v.2..F....6.2)..ug....g..8...+KWo....(mb..=h.........eD..#exFO<%.X.4.~X.ga"od.$.4. .....wt3~..]]UX.1..{lmz..C)..I..@wu..+.?.|.)#.(.........8.p.2.D..Bk'`.9v.I.....b......f9yn.Ig.1..*T.t'w,2e.....x.u.. ..[.;......:......&.p..e....V2!..[..F=|..B.f..p... g.a.[7...Dd.3f8.z.Go...n........-..;CP...l.h..N.7..H..c.g..Z....._.._..h.!*...w..=.?...4d<C..<*... .#..B/...4u4.M. \.......[...k..yq.."..@&40..7.Ap..D..E>/...eK....-.5&....j..6..V..H.4.'...D..\G..)@..-H...E.n|k..i.B8".....G....c.*..t...mQ.. ...5.E1..>.<..hC..fz...B......Bw$.$..#c..:...J.....A..Ex1y..gR....lZ...aH...r.nj.Lr....co..}..<...-.W.9.....RC$...C.....Q.qAFVz..n.n@..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1098232
                        Entropy (8bit):7.998725688245956
                        Encrypted:true
                        SSDEEP:24576:YZ42l6gOw/HoqM4POQ1q+cbor3EhoMHEg7CsxrEgA1dxsf0:Ymtg7H64GKibWEZHP7pyFdxK0
                        MD5:DD71FB8E4E7E9996BBAA8D44C0D4A302
                        SHA1:A70A2E56E418383EB80A32F781B0C72D7488BF86
                        SHA-256:0F9C48ABCC1471A8F3D424775B1DD77B5F9C3D00FF79B9B987F2CF2C046B7176
                        SHA-512:CAC61D576A93A6558C5708D4AAC842E1EBAAD83E1F72DB8A2163A8C97DDB402529FD0019C27E143C4EEF5492FF58D90103894F1B41A005595D5C50B13A6CBD8E
                        Malicious:true
                        Preview:...je...i..N.JG..m.....l..{..X.w*O.}.W....Z..H:.2......a@..I.I2(?M_.M....-?.-..2t....(I..=..&n..S.=.9..H.....j...6.b.....=.2.}...@.g.0c..O.r....p.,w1+....-@..4.a".G.M.+.!.D..uc.k.....'`.j{W.&..R....2..e..HJ.x.HPz#...JZ...V-....TX....B.....FMW...u...V>.,.R....q..E...k...C........*1QP....+..c....r.U.l....8D._Y.y ...v?...o.\D...Y..r....i...c...Z=...S..x....yg.T..6....b.n.....U.c....Y.n...=.\/?Xc.._..G.4.........&Hi.B.I.G../Pg.>}jC..{3....e.L....k.X..s....k7..._.....d.C(......uc.P0..4:80P..0....]..5.=O&..W ....3...._..v.t.W..Pr.+:.....0W...v.W.Z.3...^s.\....V..l...nBv.z...R...[.k....NY1.6.&.9..WR/~...B...%...\.......\...l....P..F|*p.....d.VZ.u..$.N..ZY..2n..-P.Z...b........""...+.0..a.....n,..w..y...3...^.EC.D...q..M..3.....8[...b..Sr...T}~V..I./4..]..Q..(...o..:...j................=.......p.Y.)..c...W... .qM.v..bN.)...7.}.g..........(.A..q........N....p..s...h...ry:.n........v~s#.k..iw.l..E..._..>......PG&.X.iP....O..eF.5..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):41554408
                        Entropy (8bit):7.997655833868397
                        Encrypted:true
                        SSDEEP:786432:dgEI2dkTY6SR1eKeMPHs7HOnX8AA1LoNtGoh7l76OVO7PRwlqM4zu6XuseXX8aS:dgEI2dCnMPHsTc8rGNtGot1/VuPRwMMk
                        MD5:AD5905DE2710955C5137606416F876FB
                        SHA1:8EF23B317C83A87D1E4997333EB6C46D46785CEA
                        SHA-256:39F919663789B99F02EF98CF12608BBE538B6F3A57B7A907D6A4EB919FD342B5
                        SHA-512:C84381E1588084FEE2BC2D1AE62CF225F776285B1B395DC1FBD8AB61EE6F8CE34C0C94C821DD227F5CE2B574A09C7D23C313A86ED3CD39885395DC48E29092FB
                        Malicious:true
                        Preview::...{........9...k.Y..&.X.b5&.....p..u/.3.Xb...B;.!u....>.....L......p..z1v.q...B.}X.z.P ....c..~e..\..^...%...D.m...g.dR!.` .@a...L.fyN{...nD&WB.."J..6;7.x.=.p.~...t.~.......!.._..!......0.......Tr.!.,..]#........NUv9f..3.m.3.,.kkfg_n.m....U.]x&|Y5.{...1.[.Qbd..BL.&.x(...yKSB....t......T`.y:.?.T'.o..q..mH#I..8FE.........h%......B.]...~7"...../.....=.......t.p..M%.0..+...tDx.D...x..:.G....r"A.@Q...Z....!..R4.CS...S.....(.A..u..S..........=Jn....=xR....m..Q!..%>.9k-.K...c.....*...|r....qb.d:.CA..$..>.i..c......`..o%\k.V....&n....t..aL!...*...Q...iKM....qk..2B..J......^.z.%7G.S.......}..}..>......T.j..~...6&n.,.3..f...:.+....a.JwI...|.m..~3.L'.6....W\3......i....2Qx0kH..K,.'nbrm..b..... ...:..hF_....5..l.e...~q..-}0h...+W4.....nR..d..Q..$...#........Pz".<.~T...lG#.k:..C........g..8P.v3.~.4I.o<SZ.a6.......}N..L....Ra.d.2...R......)...y<\.Z.wO....{5.3....~.+... ..A"../...i......~E..GQ....4%...b.D.t.:U...b...z.|.s....g.;.j(....yG?.....o..6
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):42694232
                        Entropy (8bit):7.997584954215088
                        Encrypted:true
                        SSDEEP:786432:rFSlJNYfD8X3/UQL/cQqvTZ7mfucYxPCGLof06m+afiGeyFkTby:rFSbNYs/Ttq7InGE1wfiJPTm
                        MD5:42862DBFB7A8219F6BC6CBE0FCBEB770
                        SHA1:B8870A37F743C75E24162A19F7254260F59B9464
                        SHA-256:FD6139A74A3A9B70735251EB47AC9ADC259CEFF937510E7F037223C94569B38F
                        SHA-512:BD1989B2F85846FC305548E7E1A9991158D2B8CC8A045FED38DEFCC16BC6EDFED3F1DC7EDFE1AEF7F29446462410DEA1DDF0DD4EEF0AEB388E3B847C914C7591
                        Malicious:true
                        Preview:.UF..._+...K..^x|.c...\.._.......m....B..5.K..m."....<..{..P.X7.7|k../..M..gPPP...!..U..G.^.).a..\yk.Mq...#B.a..2.|.[.;.....]Y'.k....Z.]..........t...}../...Z.sD4.......C......+:Oo..=:.c..#Ke..omN.\Go...(.}i.n..o.@18".....).V-.....r.t.q...L.4..T......~.$2.*..}^........;.I.ro....=ly..3.%.2..."Y4/....A.N..J....[7.V..#.m....J..w1..x......@Z..B;<<..\..>.O.#.(...w.'.....Ts...g...D.B.x...J........L.....>.?7*..Z.T....Nz..*..,.6J*a!#T.$Z.U....!.\.l...D..4.........Q....88.;p........6...gO=....S....".._lq"vR....a.}...Q.*wfq.....t.tpk.C.\Z..P...!2...n....+.70...afP.....?O P$.H....c.,(S.|..2Pt...(.f.....G..-.. .f..C..Q.......*.......s.M...[....>.+.vw...H..V.-D..[...^..E4....../<.sp..b.x...+.?.EP>..)..E..I.wWy...H...)B.v|JTc.j.U.Q.;...U.........B..P@.7]..^`SW*..1D.l...h@B.......R..h.D..uY..=..c.*E..d^......z...q.....T.....z.. z.;-.."../.q..35MQ............t..ti.KM.3...L..;+.w.I...>.....>kY...,2$8.-...#.!..D...Hi\.&.K^.|...:.1.....!.!.^...Vi".*!...F54.F.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2410600
                        Entropy (8bit):7.995902821192981
                        Encrypted:true
                        SSDEEP:49152:08MWT9MWEXPGG2ep4f0OHuM89gBRIdx+py4V:FR0fGdtHagn6YpyC
                        MD5:34B528E2F372B1910C43CF0A2B5ED029
                        SHA1:2A41ED0A0E42D53AD5486A193AA0AC720AB81E91
                        SHA-256:005D822CB63516AE726224C05ACF20D1B73C99CC1028271287B573DB528BFA28
                        SHA-512:F052FC548563C5DFFCBCAC41BD8461B0C02891690FDEB5221EC4AB24D6AEC3DAFE5B429281008BB1255960BCC4867253470B1CF349B9B7A3FB213C25ECA1BD48
                        Malicious:true
                        Preview:[.....Hw7B...cl.g...?..6...W..,..9...0E..eFuA..tT.u......n7...@7(...kt....* *........hU..Eh!..S.Q..p...\@......*..t.6..fG#..._V...].q....@.[1..."..Q.R.M.._u.rd:.b=.[.Z.^...yp.Nq'....8..}.%T.....G.&.1.=.Qoz.)...Z...L...FN..Iy.[`.s....".....I.)p.\,..g.R..psY.\K.N].f.4..7.............H...In.=O.....6,.hw4.....V...*..h.s.....k..Cd|.....c..^...0)..J.......YQf.qY.v.-....^....k..4S.T......U2......_.1r.(~O8...a.......;(....m...o..'W.......B.i...".j.}...u.Y...WI.B..9.......#.GZ5......UM.x..<p...v..*.]....:$QQS.jDbZD..sh.m..[...u$..Z..I.W.../Y.......c.3..J...J.y....G...Q31..Fj...8.7..im.{.d..z@.E..}Nu...%.UT..`.p....x....rv!S.. ..8)m^.._g.:....k...5.m..4o).(..VC..!.....*7.t....~.H.Ac4.+7O.?.i..o.....av.>...M...'..^.!.RE..5..;SI..,...........Z..Q.......s...3.& ;w.y~q._l.(q.....%..'...(.q&..H.{.8...*.vp|. ..xu.1cD.1+De....n..5...."*..\T@.'"......wG(x...<.LX|..&...cO..K.....1<Y1.....x.~.X.h.CT..?.<..8.T../.D.......Z>CMt..MbN.h.W..9....F..........o.r2=...*?.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18690416
                        Entropy (8bit):6.4344765683717196
                        Encrypted:false
                        SSDEEP:196608:LOUm0ImFIEjZLGhwP1B6GgImqWFiA26hF/dtPSoLBFYs03kGHpOwrZo4Bs:SvsTP1BksWwA2a3PhoXs
                        MD5:B3A8A69358D235C81D6F3D01F6DFA9F4
                        SHA1:E3A3546D0FFBB1C879C2969F158C772E1BF55C59
                        SHA-256:B9CADF81457F9D0A4E13432AB178CCF1EF854DF9D5D0173F7162BFBE7D5D5817
                        SHA-512:73468CF8A5BCBD7E3EA131876DF112EF5DF91419A7437F898019AD1FD9B3B9B0F6F42F2FE41C38F01C0A05A23E3EB84527F9C984F24BB7652FA358FE1412CD24
                        Malicious:false
                        Preview:...|..I.I|..d1...V..O....EN..M.UBHF..$q..A.I<"L...-\..p...Q%O..spw o...-<......q......XL....yM....Y.r{...qO^2..d.X.xV2........v.6k.2.q#J....Z.....%.ipm.0......J ...T.>..gi....dE..E.e......YY}.C..._.[-..$...B.#..G....gF.l...!Xq-V.{..^...............jo..'^....#...^JkZ...3.ZSA.S.0.?}.#...".X.n.....A&..M9%...t....o..V........tQ..3..ii...!F.lbB.Q......m.V9.T.q...._....Q......0K#..........B...*.bB.@.f.D..)..ba...9...[...#..`.V{`VA..j.c.7...o.0 ..N......Z ...O.<..B.}..v1ab./0....`G..'...p...,z..k|.y.....v/w..V&.q......i......+..g;..N.).......t.Zh|....r.Q..d=p@....u..Cn..Zt)....G......0..PO.t.U.`;..@.94s..v......C..S.....A{j........... .....0.x....".....-.....\(A.Lu<Nq.@.F..L.............`%.".]..o..qp@..Pw......}O..&.i...v.%.n.}Ym..(D"N%...'....0?......E=..W....ta...4.e.{..Cj.w,.=.......@q...Y.e..z.k.h....l8:U..j.....^....l.?.M...y ..PKK...8Y..c..O..y...v..f..1g...+....!.}.Y...c.....J..........Os...?O....o.)..C..G..DV.I.5-...v,.].1.vi..s.,...+
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1385856
                        Entropy (8bit):6.682804683304676
                        Encrypted:false
                        SSDEEP:12288:wC2BdNNcqD/kN/rRld7NE+JqPGhGbzlayZMX3IdP2LZP82qoY8i4mVSIpXc+lwox:N2FaNbdhIl8sP2LZP82qv8mSilHT
                        MD5:3BE76FE7646D5F158930F41F8430DEC5
                        SHA1:211D0054ED85E9D2BE688147F1647ED2734811B2
                        SHA-256:9037DE960AE4F6474ADB8EC88795273086F14556DA8693A0242CE26B77F0EE00
                        SHA-512:33FC7585D0868275682B86ED4CD1CEA65F515C508841CBD662BD1F6F60493B6BE898CCB20ED01CC4715A92591DDDCDF0681EA53B829B319D8C5D7123330FAD77
                        Malicious:false
                        Preview:.u}._.....2?..}.W...9F)..d?....]'#f`&.q|.k.N.D......X2..-mW.R..-G..z5..~..z.2.ku...q\...5...f.xw8..?.......Q.. ....q......X9c..;..o..\..X5E.t>..N.._...3....z.@l..D.x.8;.?.{.a...A..EY...|.........y.@.7d.f....@..^.ZlO.~G...$$>.NEsd3..PQO.....a.d.XB...G...9(.J-...6./<. \.a.J..<I")F..D.|UH.k.2....E.8i50*.(..U.....'..`.^!.*.[}..9.:.k.].p...@.:So.f.j.....dX...`....n.+...w.X..7......{!}....B".......1.!P0>......%...MF..ur.[.#.#.!..L.U..3..S._.-..d.......h2~Y!...W.|W.?...^t,v/.......cdX.PX.@....U...Yi.x.8I.K..l.`.6...#..7...Kfi...a.B.a...x^....e~& ,|.O..0......_]..xg/.....%.).Go...l.n....D..A.T..ZI..Q...l_...kP.=0~...P....t8....{7....j1sBb..(q.3..C.+.........|..e.Z.......3C..(.h/.G..&......d.=....B...SBJ....,'. :..#...K....{s.8S....qm.4..=....c{.....*...B..A}....h&.?.(.<.~E...JU&......e........'.N.^_\/.,.+:.Y....&..$.T..C..d...P..t...M..=..P...r..{.*..".b.....x!2......,.....J.......z..m.H.....;j.q.2....X`k....'.7...9.......b..S..t.,.b..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1234320
                        Entropy (8bit):6.61673684382516
                        Encrypted:false
                        SSDEEP:24576:zY0wnkTOMqCoWYELeoWdS6x7S7cB+8umBceQGrbpC:zhSEOZCnYELeoaSABVceQGA
                        MD5:E05F56D92511DDCC7511725DDA66A25B
                        SHA1:3F7D9D7623E62917501EB6082560AF6C21D5673C
                        SHA-256:E54E8911A73AA6F8CA75F868D0B6FAF44A5B3379F91A9C259E5B058860150C49
                        SHA-512:73DBA13FACAC976A48933CEA463AF82FEC526E7545793DACCE04B8BD79B8C94614BB8F9253F56841CFB27B92C21AE1B7BC314D568A2FCD15EFFABF16BF97FBEF
                        Malicious:false
                        Preview:..%.....x.....tU..%X.p.F_&.m.Z*..k\f.@.s.7.....Q#;#..+..b/p.B.?.5ob[>.o.^,..5.i....VL.(.....'........pd...0._\.8.`'HT....Z.4..s~L^........?.<7...@.....MB...)..4..}.oS...6t.h&U...xO..`..Q.-.B......G}...Q.,....46.{X.....YsO....">.....w.e.*.!u......-V.....J..g....p..Ijc..S..a....S..b............i;...o...u.y.U^wR.0_b.D9..tw.7=fd1._&_.,2...q#2.$....u.u.$P..{_YE...Uwq..s..YD..fL-.+.e.*$.[.@P.......?a..2...)&...1.8..S..nz..b%....^......c...e....b.1.....L..=RC......Ya(....gv....e%..G...T....)..Zr..C+.cK.a-b.Lf.D..f]."..X....#]..$..)z.K..zC.&3..CYK.......W..S....5...!.......K....]>!|)..cJ ..P.]..j.!i...0$.*.....V.L$W..*&C....b[....)...a3.<..,._{..O.3.~.6.kM...~q2..7.....2..WC....-.$..+.m.....z.....1....S*..6Z!&<.{....t..g.v.9.......X5.^.........v.?J.Hy..~d^..gA.)8M+j>.\h..="....).}.?.0....\.j./..5..i."..U..`.G7.7.&..EJN..._f.h....M?.`t...*.u.\..Kn....J..O..aZ.I...t2.Y....^..Sr...*..<...Z....#....+.3N.\....UE"f.>..}'f...rrfD$u........6&../....../
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1596304
                        Entropy (8bit):6.611041309006607
                        Encrypted:false
                        SSDEEP:24576:/DxKwKqzSmKsvwMZJ1XBsn/gu2bRC6dulyyn2WdXM6cWlA:/DxFTwMZJ1XBsn/UC6dugWq
                        MD5:75AC88B134838887598FF2AD47BBCD9E
                        SHA1:E38D400A798EEF649FD0CC3E3A629949CA332997
                        SHA-256:390E4A23F1477A26B03C4D3A02F3CCCDD5056927522023128807DF444B9C8DD1
                        SHA-512:98265FC2427F4876E471E4D2BCA3089E3C0F549CCBACB81AEA390451E8493253F15042ED54C0E54BE5CCFA15EFC481C868C46AC5E6CE38A5CF67FEE8698C56CC
                        Malicious:false
                        Preview:.*.NY.IJ.g1RD...N..qJ......Cm.....M.N....u..p.5...s._..)......Hh...=>FGz...}j-R......ZS..WZ.6...}.a...[1.6..O..K..*.........P.jP:.P.....qW..5..k.P.=%A.X..xA.q..jDH....?..LL........W..{....t.........u../..}.3']1D|....:.b~K+ny...7...>[...w..>.CZ.|.r...m{F<B..9Va..`...:.9.C...qF....Ot...]...^....]@H?S..^.bW.v'H......&D... .z]k......L......ya........v...i.......8M:..^.K...X.i..#...&?....B.E....<\,*j.f.eFx...7'7..l..^[..h.....Z4..S.|p+.#.p.<.5..+".8.S.a..unX..a...#...mrO.......z........^7V..y.L..Zn..Hn....\-Q3....j..a6.Jx.[.:....k.q..[e8....$..Z>..+..m....T..LI..m......-<.<./=.E.ve.P.."z..........v../.-).."......,....'.~NX.'..X.N..._..8.&.! C...b'..y.].b..J.{.....|H4.HV....%...8,t..I_#1B......mA......c....#......%.....3i..F...];.a....kTA7/.+7E9.8h......+.;...(%..#..lY..f...|.A9K<.Kw.f..]Q........7V.....z.7S...I......RR..6.7..ke@.%.@o09....7...G..c.....yF_/.....W..0%.t.q..7v..%....D[.....!T.Q%n....&.....@..Y'..%.y......+..|..h...E."..."x...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2536856
                        Entropy (8bit):6.602655335652069
                        Encrypted:false
                        SSDEEP:49152:Zyfde2gamG2nPY38hmI3f8Oyl4TwWrOcAkUCbBxYmKpLv33MaB/b1ie6:Z6de2g1hB5gcB5
                        MD5:BE0863A281B2DCF10A4582E95BB75539
                        SHA1:2B4613A07F92434A5928D818A3A7B005126D82B0
                        SHA-256:6EF2162D6C6CC91578CF6DF649CD22C99E936992AEC1A02BBEED0F4D8D7A1366
                        SHA-512:11EE3657D22CCC35F12C4C117F4F27A8B85FC1C19F4F3B81C6697F1E43BF7E2B880D0C24184FD589D74E453CA2675B5B2DC4C8FB834D3FD038E996A08A019089
                        Malicious:false
                        Preview:'. #..f..C1x.k:|M;G_]f.;......z..F.k...'...:.&G<@..../U....9.,Y....b.UG.fz;.....\.&m0..M..E..c%up...".v...KH......ZF....P.!.....a:.v..JH\....;.......p"..-.I.{.4...Hh=.... .X.Y...R5.tT...%..........}..l.%..(&%.ED.....C.F....IB2.Y..%c.Q.h.......OT..w.._.h.p.u.o.....H.:.4:<`x...=..0.~a|_....P.X.....,. `..g...I2..^.D$........ .=.....J..{.......Ivo{.-..iG.n.q"W\..1t..Ae...p..u...V.q.....A&...1v...!.g.G.......t.........q....p...w].!..._K.S....;...L..5$.vE....iM..a........w.,.!U&.3t...xC...E...w9.......7n...5:M...#......M.nA.G&..{sM..ihT.K.....b.`...}..Q...,..u.d...Rd.}........v.F.e..q1. )...z.GVRi.1s.9a. .._R..p.n.....$...S...,H...6../.{..=~.A,..t..=.`n..SH..m.L....3.q.++GU..M.9.h.H...h...!.1+....0..~D;.H4..G.I_ }1=~..&K...)d..[.M.WE.tO.<%'1V...b*u.z.$QH.k0#.M}..a.Rd._....%...6...(...w..g.b.`..n..6(F./...=eyT.l.fbw-......x<.....X.y..',...T...+.........C...U*.."..O.....k....e..im[C.|....&A..']Bv..".d-.`...G...qc.../..C._..!.;Z...pd..b..Xjw)QB....3
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4035968
                        Entropy (8bit):6.489446164671789
                        Encrypted:false
                        SSDEEP:49152:d2BLihGQki09C3hn/6u8XrnZeZeVCVBRwoOuU4gTQLswejDOHKCbBxhHMlku0RQm:giAQNqmziopHRqi4owi
                        MD5:12A336FFF480AE2082876B9C4BE14697
                        SHA1:25F8F00E7A67B259E0F8D83FBC8F1F99A6E6AED2
                        SHA-256:73F650BA55599B8B7D7C426F096FB8A99DA91B58841A8930EE8B1DED9AB61D2E
                        SHA-512:A7A8680075A5DA03D5373588F85E60696CD4C1DBAFDDE660BC29AFD36FECD5258E2BBFEED34D0F3BA867DF6178C8CF2CC7C5B520F229A7FD526EBE47AA2FFAB7
                        Malicious:false
                        Preview:.n..++..dcM..#.L.*.>d1.m|..OhP..mbd.<{|y..:I..c}[......9p.m@J....x.g.S..K$.Uq..I._{'p...A]..r.rFoPy|..%..M....Dg....W.....6o}l.}..h..k......Uw....;.K|....x5..T.....vj.7...!...EFk.|.o.j.4-.........,_.43=..]..#...'#ez../...-./$..!x`....t.>.R;.u..g.3W&M.;..P.'^H..w.DA.......?Mx......Q/V...>ET~.....nE....F.N..Z.3......+.):i......Q...V$tM.F7Q...<..............)8..y.)....1.PEV...'M..........[.(L..[.6...(......?1Ea.8.X.2.`yb.`.l.n...8%4h..s.).F..wg.b!..nn;.......Y.o...z.s......)>QZJ...voE._l..P....q7...(.....*..)H.,*.L..'.4.^.c.>N..o.m.29..S..L&.A..*..1E{O.HG.gn.._....*.r../....%...6q..5Wa....R+w.7.>.1W:q....D........0nd..l....Bt.........P|B..+=.F6...7p.x....i.i./.|.b.....F&G.....6h...*4..o......q..&@.O>..x....R.....%R..9}d..%.........p.:]..{M..[......q..YP.!.M...O.-..G{m.u...m....4..!.x.p5. .....J.n..^....Nt...Eg....Y{k.3..V.Y>...vv...J...Y6.r.P...t...=4..YJ..O@/.r..n.&...g..u.3.dt. ...z7.Z\F.\..C%...k.1b:.|.S.,.O.O.j..\....M:...Q;n8...-.X.N
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3121008
                        Entropy (8bit):6.639809606104245
                        Encrypted:false
                        SSDEEP:49152:f4eZcLW4jqFRZega3xejvY7GQOx4K1fm15FKqO7t78Ity6fod76lmlW8Z:wyXs3OBj4UmOq
                        MD5:D5025FE00E28C1A461AFED8C9336B8FF
                        SHA1:5CCC46146FF3F39995AC05C92E86E4F3FD4AEFEB
                        SHA-256:8CD4EDBE7AB61393034AB0FB939E805A860FDC9581287378FE327895B49FF624
                        SHA-512:F839206F3948A8B903496A23B96AC2643F935FF8F9D15E1CEA99DEB20DC898D1DE3358080A2E056B48709AF63E59394B65EB6A7B8F0FEF7DD9AA93AFD9B3628C
                        Malicious:false
                        Preview:..ff......um.F....`B....,B_....q......M.......:.....%)...~._.F.= ..ZLWl.I~..v.2..v......j."..}.....//k..C..8.......na......r.>...........Mv..(..g.8g...t...d&J.<.[:..\....7.........i...S..b..vU0..j..N.V/..[f"g.q.8..x..7....|...=.Py.#.0-..D.nF..H?..$.}...&..`'..G0...H\".....5..c.k.A..?..Jqd%2.CU..l..N.|*>...M.i4E..E........h.n?..3+.=K7m..^.O8..I.E~...b..............3f..RZ.j.j.K..h~.....b.X.u...F4.D.....67.7..h/c.q..>a6M...fO.w.Y...x.KF.X[x.b.F..)*......N..........^j..A.()57..Q(.......X.T...OBJ..+.......E|f.}..TyO].Z.m..%....Id]bfT.....U.H.\....K...).[M..@.......RA..N>.5....s0..\_.."...H...;..@.X0....q.:C.....x.4..b..|..;....V#u..Io....yI....D..?...f$a.-."OJ..".B.u.Y-x0.5.YY........ky.0.7=...p...xJ...?q....g.....x..u..G5.%s.Z.....x...fF.G...e.............@W3?..j...u...+.rfd&7....i!.V`.....=......K...l..v...G..*5*JOt......UL1e...e..._W...-..3...U.h......t%.zT3..>S...>...t...JN.n.n.*_..2....`N.....9..oM...*...c.O..^u@}.[.y..`Z.|...0..W9*y.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1267936
                        Entropy (8bit):7.0403616975617735
                        Encrypted:false
                        SSDEEP:24576:+UiQFBUpoOQO+sGOL9NLM3r4Viwj6KLqGua43loEeUFmwD:+UjZOQO4AA4eGua43lgUFrD
                        MD5:FEC6FAE5F5902D6EC7271FD9A0F3C9D9
                        SHA1:9283F78581B93A596D344996C5A8399A19E82586
                        SHA-256:79E5689DE7FB2644680B3C5361B76D595FB232072FB3BDAE8C26DEE02E654B1E
                        SHA-512:866143A9D118FB249425FF1D0E0C2069AD2ECDD71EC6273C513AD4417F6AA50EBEE22D6A6ACC93BBD64971BCE1DF0C405D1384D0FA096204C5275C91FA64EB4C
                        Malicious:false
                        Preview:....G..~%CB.....ki...6..o..f(...>.nSd:....Q..D...O.I.|....................7...$..l$.{.c...2....5L... .c.U....d.s.....^./"..S.Al.r@.......G._W@6..z....{......,^x..t.}.d...V$.K$..tEP^tq.m.L.5.HG..6.SY.....)..\...p..pp.7#.h.W.=..h@uk..}u......7.l.....>y........H.ypt].U.guO)...v......rg.."..j.'Y.|.#B....$(!.C..1....?..-.5...3...2.....H......3..!U-....h...)d....l..v......... )..."m)..j..T........y.C......i.1..(.S`.w.... .c.....0(X..7<d7)&.^.....>.9k...t?~....."b...g<..`......?I.O&B[jN...1......p....<..y...qA..)Dws..}r.>K>....xI...k:...{.....%..@q?+..M..w*.["....b1......@X.....A..:.nn.q..E.3l-dN.."....'u.?..$..E.V....D...V....f..`?MX..g..d@.#...JE.....a/>..._.T....N%.J..c.3.F$.O.C6.....[W$*.K..\eR-^...[k,.HE).*.<..m...%J.....x..`Q.|.z"H...C..H.<G'.U....Z..s%x1..m..!.....*..S.../F.z.N........?~...+Q?.I...xaJgiL.t..4...6..._f..%.b..D...../..k..]xUx..|.8.P.h....0.....e..D...........^..\.Cc..hJ*@.L~%.8.TP.@.....l..^..=.......:....c1n.../+l.V..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1131816
                        Entropy (8bit):6.721698222848399
                        Encrypted:false
                        SSDEEP:24576:2tojO2HPooM0sy2Mun2r7tbg6Cn1AQUz3JQy0:PjO2vooFsyGnuq7n1e32
                        MD5:02080469FAEF631B82033A50B990A01B
                        SHA1:AF9EBB8ACC83DEF6384722117030E8D60C7DDCFE
                        SHA-256:CCCB19FD05A50809DA7DD7EBF1535E1ECBCC69406775F081DC4755AF3ADCC7CE
                        SHA-512:81F9D217995F76401455BF6121AC52A24DFC34C77BF18549AB02935CB3E7E007D96D2ECC8B7E68A790C47A459B7198093EF963E2A96F24A6958F46057637042A
                        Malicious:false
                        Preview:.....7 ..K.y...j..o.ys.SAD.L....vT...p...T...V._}....9U..*r.e.o..j....Sa.\......z.S.+....e...l?{.J.e....E.1.{...8..QY....u.Y..b..v..X...E....x....uh.w...d:A.L@........#`S-.{h.5...#.7...c.}:..p...KBW..<{.T...P.z..]..9..C....n.@..........j..I..+.9.Zhd{.F..5.@CB..RN....?..'...L...& .vc.G^....h....[.RS^.S%....^Z9u(.....4..8(I.=.~.q.....&U.....I.......X..S/t.+...s..9<e[.39Tf...4).D...nw.....7.G..xWy.]Ty..C.W.Hz2.-I...X..,,..9.-..]..T..Y9R......2.$.m...}.....D5..b.D.7.fH...[.S|S.$33l.]..Z.....-.kq.hAl...};-w;..H1.1%.......3q.,.!..T.....a....."l..!T.....o.L..OY....0.84d.n.W#.$.F@.U...e9..e......M.&.........n....Z..O...e\@K..........?Z.]...8.7w...r.....3T]........P..V.06;i....~..N...U.T...T.n1&..q..#....[..&..c1m.q.. .(.]..$?.L..T./.VY.."......o...f>..@..9..e..~O.N..1.<.@5.Q.}~.Bu..2.'....<....9.(f_<...n.U.O..W[so.......n.....c.j.........._...B.:K...Z.EF...7......e..n1.p..BPJ..)...l..>Y..*...{....n-]>..d.-.q.....-.KB.......<..mI...I..4...m..n==.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1385768
                        Entropy (8bit):6.6831718708187
                        Encrypted:false
                        SSDEEP:12288:LDZUA+9RDV5nUTZJ6Yhgt0o0pNfP2LZP2Bo4YuwEbVCIpXc+tYotX:LeA+9RDVQHWd0HP2LZP2B/3BCitfX
                        MD5:9948AC4E9E99FF1D3AE26FF91ACCC1AF
                        SHA1:B7B61F0328F27FCBB001C658D03F84E5B8BAFA46
                        SHA-256:226D07CAB8DAB8281962D6A8A684D21ED6D563A9B15A73528FCC73125E89A317
                        SHA-512:001360849485D698D2DDE846EDACCDCB8528A447A25BD3E7B31EF8775A5D3687FF045F0AA319E01E79C6B5A7CD9CA498F3898B321859380413686D959ADFF319
                        Malicious:false
                        Preview:SVV.[6...L.!."3^........".]...R..........g...P... ..Os..0..uaO.....t9g.n.t.t.o.........e.r....*.=...BV.N..?..?..........Z>.fAR.............8..M..e..=.........h\1.p.....4.T.6....!...x....8....L=.H.^.Y.01....k..@.....:...n.....m...B.b....$.J.k..D.J.ZO ....U.z..?..7..k1%{...... k..s.......t.............,.......#7q...:..IW.g.,T]HLdo.K.....x..*0..*....s...}.S.......}.... ..Y..!..K...i..Xu.....2y..%.t2.b.....q.-...d...Pw?&.....k. ^....!.g#...e..g..B.rU.C..]..N.`..~L.H&....g....nCY:.Nv"dC...A_<..*.qY....n&....!.w....?.[...K.fOG..@...z!..:)..E..N..CG.a.u.z.{.]X]....5.8.......D.&...DX?....~4,m.T_...g.j..Z.I1..3..`U..,.X.W..../e.l.:...;.b..t..5M..Ia...0...oD..4....G.....3g?rS(..I.00.!5M..k8t.......H..9.....6....h.J....Kx.Q...F.M^/...k.)m.....>...GPZ:..4.7..Cet.Bh..s.....NU.T.P..w...|..Kc.s.Jz....e[Y.....j.....[.G.-o.I},.y.=.._....Jk.$.&.~....^...B.....~..]te...M.or'-...t......y>.Q..Y.jS{8.....L..-.....%...c.....M....z..$..pG..d.,..!...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1250600
                        Entropy (8bit):6.6118957944868475
                        Encrypted:false
                        SSDEEP:24576:x8NLMYeDNijQm/sWg+dwJP0+2vyVCQgQIbetoYd:x8NLMxDNijQm2+WPnytQIbeb
                        MD5:4BB55E12593B1A6041A36A6B02A14855
                        SHA1:133D465BA4D3CDFECFD1CCC31C49392B69EB658A
                        SHA-256:E7EE1FA2FFF69519B60833949E607AF22E19690EC2DD04BB6BD166227E05A604
                        SHA-512:D5ADB889D0FEB7DA71CBD6EAF341F66823B19D8885E265DAD46CD451C782918460FA304AE6F5F135B551F505A771E6262E355F89DD5515450477B91B9F62959A
                        Malicious:false
                        Preview:..0.......0o...}T.&gi..R.4}.....h..'.Kt.......HQ...t....a.|.v..O`.kR...6./.....6...e.O.`>.....v...x.B...:...Ss..7...^.......L\?.8.N.n.O..-...o.7..t...n."..............c...|..F.....M..!r...H*.L,.s..X..H.7.3.Cy.3W"..ptZ."...{.).W......%.W.|.}..=O.TNk.,X.k...D.|....6;...A.^1..[..NT..../>....i..>w'.A......._..H..PX.I..;.7dPsg.u.X....pz...$......5D...Rk...n..Qgf8..gS.......a.R.......E...#)>A.;...F`r..|.d.g.....<.+C.........!...H.}O....B....$....D... [H...fQ{...I..,@+*........f.A.h.....z.i.../../I+...E_.I9...F......DR.xm..*.IE....)..~..O.>s.O.....X.o....n{.....:.b.).{...E..|..S.)Kb..)Y8...Kuo.Nb....x..,D...<.T.8>.....z!.h.;-.$......V..P\.{.......R&<6I.=.......q.yf..B.x./.......b./.m..*1.=J....BeCu.Eg|-..@W.3.F..O.4.....c.....dG..}....Z.....[..O.F.........l...ebT7...7. .EYC.7D.5].....P...N..~.O..".....b.y.....VsR..O.G,w.....NJ.F...7..w .$".6.,.d|I.B...$.fm..`Hw2c*.{...S.jQ.'h.EJ..q...M.*o<.|.........AW:...bO...2F{.......".E.1.)..3.v..T..<..}l..q
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1596304
                        Entropy (8bit):6.610761756726846
                        Encrypted:false
                        SSDEEP:24576:H0Erlwun1UDCmasrf9Xr5wzW27+w3E4nZ1jDkCZTunfmrd/Mq8pqiV+yeci+i:HXr1UD3f9Xr5wzW2x3E4vDkCZTEJ+7
                        MD5:CE796AA75C3D823531B333AFF3BEE5F4
                        SHA1:24103D7168C3C8460D51D716AC5A6FC5298B7D59
                        SHA-256:D75775FED8E673F3A2777BC96C4EAA6D6C40BF0C05CE919A53079940D08AB286
                        SHA-512:2FB7E20E8AF7D6622A6B335EB503256850892D5C4E773A8F94470FDD409E18274910D49CF3A2957D1FEF5AE3D931A387F46F130821589CA802B0B6F43808BA04
                        Malicious:false
                        Preview:....OU..9Z.2...`G..1.B.....9:X&.....K...@=...........NK..z...uY......@v...|...xA.i..f.?...!..}....*WH....?.R.i...5.M.>B.....ks^b:3..uC....k!hjf.g....[Y.d..1...C..<..W72` N..e.D%.x..@..5.Kx..'...r...`/#:X...4....r..tp,...........C5.....|._.....`...)BA.........)..LO...khW......)..0..O....a0..,.......\.>i.....).....<;.q..=..om.qDw...e.F]:.n..{.:.9^t..R..._.Sm..+=HF....=..Y..u.....Nk...%Z...-\f9z..0A[b.....{.hJ#...1.....z.}....O.Q...O..L.R..mT....K..>.....+...m..nf...Xo.$...1...?..n.G.......>....BM.........rtxS..!.....b.#o.T.X...+f...........h....QJ..U.e...s...e..D.....xO.%T..}.`...Z8..c..V.....?%HL..eX"~.Rm...y..)..v.W.g.....Xg.W..(..4...rN...=.-..+&k(8...>w../.x-l..*...H..e...N<'.]...E.4.;..d.uM...^....x.L.u.<:.y......y.1!W..;....D.....Ph....G..8i[..h/....xE)...ezc....X..X..W.,..j!.W.c!....|..j..V.YR...'..w../.:..oh-J....=j#m4%...9."bh0F.%NuC.*..%-.3.....W2@@...gA.~~U...?.....+~.J\...%l.:...a.w....Am.(.K.j)6".d.e..A.r....b.....x.,.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1193240
                        Entropy (8bit):6.745643391113015
                        Encrypted:false
                        SSDEEP:24576:+W7cJt3cAXZv5Qi2c9e10HRC6VX0spKERCl+aB/belll:XKtMAXZv5Qe41mc6VXJKx+aB/befl
                        MD5:22E3F750EE0DFE10BDB306C7756784BE
                        SHA1:C83334AC092116F887BD216F3D2428BE13322AF5
                        SHA-256:7E5800668B4EED5B1121816E68B6A3259E8C6515FF88DCD57F22E4F2F98B463E
                        SHA-512:88F558AD8E88809459D35073E55E83FEED3400E3D2C356D09A6D5A4711DB5741D024FCD985B8C02E08A4EB2FB4FC8790DEC4B181D6C6243D072109FC92D878F0
                        Malicious:false
                        Preview:..q8....Dw......q ....m.x.s.]......Z.....Y.3...I...`4[.q.d}.6.../.DD.hG......K.x...6..Yx5....;......BK5j..K.$.U.....Ux.\`.r...;..=.....l....o......6na.|.Z.cN.20.(n.0...).I..v....Hp..<.j...f..S.=!.,S8...}{P.z.S.......Q...Hv.;Y^..#r.|..:~;..I...1j:.......%.eS.GN.q..A.L,A....z...6..qX.X..-0...3...E../d=&...3..Z.....\..n.$$<.-.EZ>'0Ed...%...w.J..m.......e...$\..-w4M46%...&.H..a....v.]..4;Q_t...0.*R^{s......v=.g....j`....-,.[.........0f.X.J.....c...."k...p.o.Nj]...6...6...-......6i$.R]......A..&.....+I.d.z.Q-.....Pu.C.3..s>.C..r.i...]..|.P.a.....6.+.kp...g{OW..+B....3.......5..|<....L..l..y.......{.,^..T>7hRxR..>.7..v....TS..`....3pz/J<.z..*...........i.r..l...6.9..;.......U..e._...u.k...3.G*..BS.K4.......3..E#Z.K....!.y.<.\~.h,....;8/.Jx..T.#.6.I....m...=.;+].J...G`.........PEdg^.f.iBn?1S...7.z...y.A..F..@E'...lxn`V.....x=....19b.pN...|I.'u[.?L.....{.d.A+..bM....,...>.sV.....52..7/%>..-.......M5.nZ.-......"..<d,.D...R..zR.nj>.T[RUK,'Ua....k.Vo...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1971480
                        Entropy (8bit):6.633518798272021
                        Encrypted:false
                        SSDEEP:49152:ZfooSiGO1jehvXtDZduKGsuOpeqVAjXr0M1i1:ZAA1jKdwW
                        MD5:EB0F59F04D8D454BF133432DA6596D60
                        SHA1:3A3757532E16161C5C8E1D2708E3EDA33765D983
                        SHA-256:7F8065F811038DFCD2951A39ECBD0A94B1373C71E9CEBBCF6E1117BF9AE3BCAF
                        SHA-512:EAD97B6B9FEC11833F1D7865CEC412E1BB48B8BD1FF278BB74A5961068C0354B6E34A6C7EA58CC9CF3778400AF26BE4412D14E7D251E077CBC67B9F51B8F489F
                        Malicious:false
                        Preview:........S/.?..3q....8D....l;.n.....nU.....rhc.X....Z.$W...[..N..O.j.$..5^.. ..f..~.=....p.gx9.v]...D....".;.......0.w...p..{J..D...H..R...`.b...j...t..@.E....U.,.1.....Q...'.......Y..7ZD 9jqG*..>.Azs...H...5.2.=....;.o.z..j..;.."..2C...T.6...|...!..{.T.e..|.D.%.d...4P..j...].....r...Bp...N....".*^lo6..GQ..~.....r.i.pS$..{'.?...j.~.c......?...s+)..xzta_.[y.@%#W&M.}=Ah.].K.S..VOT`.*._h.eR..f:<..+.8.{..........d.EQ.........."......4..o.*..Tt.J.%'.....J.P..MZs&...$M..<..T:y.2..u...cp...9A\J...S......|.......(^......i.>>....W.r..T,At.E.CU6F.....B....7H..m[....S.....P...h.T."B...\.$.........r......o..fg.Pc'...v.'T.|QU.s..ec.C"....JIvBg1/B.@...........4.t.....w2.u..K....ki.vz.-q^.9.J..5..n..1.fZ.......Y.*....*q.+...?m.2..p3(..9..... YGr..w.....iUgG6.O....@..>..B.W.y..\.:..Mz..... bE.1..-......'}.9.O...kX.F..X........Ee..C.?..L<..K....=....n2FL.A.[^.*)M.fUm.~... .m.v..!./.C~..]m.e.2-zl..R..O.L..)....7...q^...&...b...a...,....\.2.u.O.m%..!...Q.C.#..D.+.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3941672
                        Entropy (8bit):6.476149185430821
                        Encrypted:false
                        SSDEEP:49152:y+Sx761uRHb+7Lj7kFwn3j1m0M/t4yh9D14aZW3tW98ZfzT/Z2IZw4+mJcITLzEX:yp61uR7WpCl1lW3p2RH
                        MD5:AB9F39329C8B79B599EA2B32B74ACBA2
                        SHA1:7C8D6FEC052D37A4306482506FEBD1F9C9108BF9
                        SHA-256:37A67155666862FD1632E8B44A8B49F0F54865E493AA7408857AF5B16B082AAB
                        SHA-512:CDB76E492B38DABAD87C05CC214D8063EDD8FD950BB4CDCF6596A9B06FD7C9DC91773D565B0D497451DEF271AFA89AB07579FC2E7B3DA81049BE071BB9A9E498
                        Malicious:false
                        Preview:....`Y.... ....%...s;...l.?.IJ...?...%..S\...]&o..#.}..VO....:'vK0\.yw...".C.x.z........h.F.,.....i....t.v..^b&.*N..9.b?.P......l..cM..........5.0U..{)..v6....`X....X`{.-a...W@.w.g..2G..7S...-2.K.T.V...U}?..E.bI.A#...Y~V(......>.a.Y.;.:a6..L..A.Z...Co.L..P...D..b.<...CC.p.1..(....Su..i=.?q6.3....nR.rU..&.......4<Rz..%..Xe.:..-Y.S.:....v..L...f..Z..xb..._.n..F.$T...2Q}.I.C..7.yQ...0..m.p.n.2.a./%B....`B@}.>....@...u.......X.o..R.Q%....`...E.Bc.B.8M8]!...}......9. .+pc.iLY>XE"...A."........K........-.MN.......iaz^F.... r;..a..Y.j/g..$..5.9..|.z.K.\...P...Gh.-...x...$...?.?VD...;.M...h.....<..?.....z{<-...=.....$ozb....;2T..$f..>....}..~...s...`trt./`...?.h|...z......l.W6....R.....Z{.].G..O ...3.A...,.....9...&-eN...k.K.'...1.=..e!.G"..%._5! (..L._.=.B..J.f..(U..Z..X.....=L7IKX..[..W+.....E.Pk'.(G.%.s..Ld..UZ..9..i...L...N]....#......;$.G.'.j..|...dY.......=A~.+*..<bL.o.Y.$...*TK.A.h....w...f.I.nS.q.}@[VT.E..........D..$.D.K..........[[
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3116904
                        Entropy (8bit):6.634504886871152
                        Encrypted:false
                        SSDEEP:49152:LW1wJNnw/bT9uzlAndnpufoDbRwU/xv3lNOsWReEQZeEO1QOiPQOo4r+:LW1l/VmUAYr
                        MD5:342365B1A1E3C844F28FC765857870B4
                        SHA1:D906CD009BD59758BEB9B04971DDE99CC8112821
                        SHA-256:5740E73974432C3693F36004C56FEC5933288250987196E14CF6B50F888F0BA0
                        SHA-512:D301B0A4B25AB2702BE3B138BFE958A9A8A080186C0D64F09EA82E9B895B1DFA22178CA1F021897F532B575362C35814605F91A613E1574EB87BAB5CEE773389
                        Malicious:false
                        Preview:.<..a}.,ez.=z.y.u]....N..u.........G.....j"....h....j.2.:.2.Ux.......fV.-.3.....j...f...?........!....<...%.svH:..$.....`...;....]..<'X..d..Jm..n@.mfiD?3.78..%.UmX..{5.....Su%p..>..........;.l..B.....R.*.da...k.a.U..yE.....DZ4\.E...]..?T6...w7L...;Z.........y....2..k.E...T.yX..$..@..IkJ0<T..Y.W`!(a...ke...%..rw.H...hf..#ENfT...C..S.=....DN..S7.=.....+f.........6!.DR\...S.`.>R.........#.&.m.A.cq...>.....D.....Y.SU....Z+\.J..w.U....?.r......7.T..EM.%".....K=.?G....m.eZ,pK.unm.z8.....~..5..o.Z......X....{.....IO.NE..-c.BN..:.7..|.5.M<.('.Z.aw....D&.!...J#.....d.H...:....X..0X.%.`O.....R.&p...%(Ck..3..D....L-.R../.<5a._#..qE...;...F..*nW..!,.'V.x.kWh...C.C.....9.Y.....m..t.3...C.0....h%..u..p...6''.z...t..^p.....2.M+....!1......A0(.....Eu..u..I.h..'.@.#........F..{.w`..kY.B.{...8.^.ibk...... .$4q.......E.E^l>...L..nb......T.N$.M...Z.Bo.If.).|{.....)n1D .......=.....a...&... .....,.U.&w.+T&2S.$..I...u...j_A;...}.."...*<XM`'){A.P..s........*
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):1268064
                        Entropy (8bit):7.040963845894607
                        Encrypted:false
                        SSDEEP:24576:sLayYsvbIUnHtg+i54V0tqDNbu5kDIPQy+NTD4XnFzX:i7zXzdMkDIPQy+Nv4VX
                        MD5:D23A8373B561FA631B6F5E6C120BC84F
                        SHA1:B50676539305CAE79655C45BDD71C38238B95D2F
                        SHA-256:AA09BBE3D6356615E6BE3DDACE94AEC8F520D3AA7E54843B2B708F85231F6D87
                        SHA-512:3E18063A7C5FAF5124C2EF6C3D90278C0F6986FAA280C8E487858BEDAB699EAA326426A9F9C54AF5A214BD48965A709A5BFC3F38FBD0A0227932F1E27369066F
                        Malicious:false
                        Preview:..*..5......?.J}.....%p..j../......C9..?V......W.........Ioh..,9Bi.{l8.V..0..q/.<.. .Hd.m.(.K.Y].M.U..<.^..8~u.5..s.l5...R.....>.Hw.g../.PLc^.-.Q..h.V..f..@.(NRk..)..p.../.9.f.).7.......h.Ws......f."D..> ..[.......K.....z..,.C.:.....JO`..=...C.S..G.......P.v_.n...:.4...P.3.o.....o.......Q..TY...}7I...u......z.......%xo...@YB}J4.y..[I..O..|(..l.......:f?....(.<....H1..Z.........M...3,~C. l.].{.....4-...\o...g...C<.*...[sJ.....a.B/R..<.f.1,.u.....E.o.s...@ ........e...,....F"....ea0.y/..I$._...........s..uU"s........Q........./.}i....4..(.=...@.i.n...r...sI......].u......'..3..N*G......._."..iH_.....n.......`'...}.|b.cR..y_.Z..O.8x..9f..R.....E..+..u..|.&.......iO...m..t.....EP..M..p.x(..j.H...T...>.a..e...}.$......;^I....6....;...w9f..K....V...%W..Ho.o0z`..GI*.1.@..Z..]...........|w......3z.E_D0....W....u..23.T.Ju.....;_..t...|.e[?>..&H$.8<eA\..?92..{..4...aee...}.X...$ ...@6+.>...@......w.MB..U.......m..Dg.s...v...s...m.w+P.fNH...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1148200
                        Entropy (8bit):6.722846225069604
                        Encrypted:false
                        SSDEEP:12288:OcpY2iCB27hkRnH1qdv/2XxFG6N5nI6kPBpS78mSGR3u0cdZlb3iO/JwtfoJcAnX:qutVqdviFG6Xny7SAGSlbiO/Jwtfshbb
                        MD5:77EF1E1984E4E47FB6C1301D6DA9B5DB
                        SHA1:605F53F9785D6BB9A73AF4CF9F7FCEC420520658
                        SHA-256:6E876221BE93EABE18C07DA9729227B7B80E0F767EF3D6A5B410C62FB2DD22B7
                        SHA-512:89CEF0285B1525153445B4DDA1A8DC64ED8F3608A13D19EEA8EEB85A8A3E362B32609D87737B0139D54E959BF114F572152CAE2F75F206DBDC7231E7F5547AA4
                        Malicious:false
                        Preview:4?{.0`....'#..4U..X..)....eBx....O<...3..I.....'/..-t.....@..1.`.=VR;..s=..K{......K@...h_"...1...i.W"..4=..c......5...`.r5].6...>.......|.q..ka.fV<.x.].3.E.......s}.mTw.L.........A-l..Be.).0..n..{...3#..;.}3...">ZZ.I')...k.K.....,3..G....t.....y2.r.'...7]........p;.[o&..#....aR;...........I....W..8......+.;..G.....j.o.....nJ...5......nG. .(.>q.....w.!.<.4...CA...x.....t(.(..:";.o...f2.49..Om1.....B.9......b..1..|d.u3.F@..L..lGV.*...lV..Y.,........}...#...yyY........m..G]..a.......a3Tu.w..2....7....P.O 7D(..R....R...M...~.I..C...RH.....-..-..;...=.8.....-?Lt.C;u...2.....3..[..-...,g...r..O(i......R../...C.%..Xq.b..z..HT.4.B..c.....DBS..vl.f.xp$?.%..oS..Q:~.@.^DR}...t.e....S...sp.o.O&4w....v.8...'..`..N'..N....y'.,.L. ..7]5/i..S'JOg1.QN.u^..i..H....4M.@NX......4>...g.-.V..>..J.u.P..QD.....<v...LX.rl...[u...Px.e..?).B.s....2Y.L....6^.>f#@+.c.*&~..kI.)?.b........?-.SF....FL..V......D**..=h....1......?.$.C...%2..hq...8..~.`......BE..........j
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1903668
                        Entropy (8bit):4.562140217529925
                        Encrypted:false
                        SSDEEP:6144:O0sHUvmNEk+7UVG/v1wXRKJaDUuTe59GF6iPGnDD4owAvtOBTa60wuZ:O0spNEkRaGXAt66iC
                        MD5:482D3FA0B4983C98F1B834BA1EF32A6C
                        SHA1:A60F8A4B1A17A9816F3A9AC25E6B5F7A620BC396
                        SHA-256:2EF954118B1100D4E3D1861EACA9474B05A21C137F414304E80A7E9BC0899665
                        SHA-512:DE239DC3B098BE858144F300BAD918791266CAEC18C309172A55C7554E458B22CF38E0E10754D833BA18ED6A70D2448D51CFA4F8951FD310F7348DD1D9A8D202
                        Malicious:false
                        Preview:.`..Z.I..a.P...,.Nrv.,..&..8K..S.....\..1....A7.8./.H.3L..r...]Hew...h ..A..p5......$.........&Pz.s0*.a|...Q.B.:l|.2y.@.sv.:Q.a$..6-O.['K..nr..$.cX;.d......-.&.....I.9}..:.)..6e(Js.n...$J..~H.@......w.Y.:..xN....>.P..Dc..,r.G.....y..O..I...4..U....=.Q.].........z...M.]<FI..\y.._.ba...[...5..L~..0.M1..weW|...].........9..,.,.......7Xs&.@.0x..J.U^V.:.+....}75|.....`.o...N?.....[.....Y..........:./..mGD~..tF..b-.......E.X.$n.G..L.,.}...nY...g....h...:.....j...wUe3...r.{X....l.^.?L,...c.hM.d)%...v../..~.&Ms...LY.7...T.-..A.h..v...y.i@...mt..n"..%..B...\..i.'m..m..........!:<.z..l...r;....~.q.99f.s..........tV.I...?.......v e>...Q.j+...:2f...kX=.?....jP.~_.R.Mx..[...4...}.:...|...^`....x..XhRf....x...t.u.c....&@."...x..^.C.......?.RY.y.?.(...[A.M.C..T,.g2GF'.~"...U<.1.....T9...k..R..e`q.... Z...........$.6d.y2...3?.q..G%..V.f~...qK.6..4..=!...$U..H.Znb].E.........6.'.&.?..a...f-6..>..j.:E#......;.......x. E.@%..K!x.0.2L1...@..'..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):11251712
                        Entropy (8bit):6.880600840374145
                        Encrypted:false
                        SSDEEP:98304:9ZB1ztj1P5KtHzdTLI7XEwbidVnOoMmSz2r:JezVy0wbGVnObmSKr
                        MD5:9801C7235290784B5BD32E2205762CB0
                        SHA1:8D1A8DBE63346A75434DE4C65F028709C82EED91
                        SHA-256:5CAC36867B41736140B859C11EBAF937BB4534E82217E3DD33D0B84EA6F43DBE
                        SHA-512:B6D400482D42D5FB0330B3E2B33401D8CB8B4DA9616EBFF5BA37D16B3B8AA888CBB848D075BF6A8DE398E5DE7FE23718CDA452D576FE3F27441B19736C020E16
                        Malicious:false
                        Preview:..%..7.d9..:.!.6..)...}..:;.......w.....!g...m.R..L.P...X.#b...:.1.......F.p..v.....7.\..w..Q..e.\.bQu?%@.H...-d.^...(.W..pb.Z....U2..i..}"....J..X3...rr.S. .....!2.b..C...7|.m4.da.....=..\..._w.<.%.e.L..m..C..G.N@.........%ex6..t.A%U..SPg?L. BG..h..+C.@~.v/s.H.\xr.D.g..N...}K.....f.w3...j.2B...$9.)...s..R.%.[..B.3....#..h.5..=.|.0.?.!....g{8....A.?...;.#...... Q..fm..xH.5.....1.%.n...<.... *....+{8..~..2..IH....Ys.oH.G.....4..!.>.....D........ze.D....e.].]$.T...8....Gy.$.i.sq.S..........:3."..Jaic:Z.}T..\.I...i..B...K!.1]\.F..U.H.p.;,08..e{...`.QF.S.).?.X...c..9.?...X./.....".....7.y./.!Z*.Fu....3..'.Qn....(.M....y.....P.,.GY...*....U.)....k|2Vl....~..&...Nu~.l...2.\,.I.....e@....:..q23..._.K..-...7...,+....+6.q...fv..T,...y#p0......Y/G..:^..vlD.ly.*.x..<..b...l.,.q.U...*.[......}.2?R1.4C0.b}|..Y...R..H`...A;i..'..e...o7YgKB..JK..f....Z2......d...qKH,.M.....a}.P...y... .>.DS`......8....!T{......W...$.k.i'.!#.m_.fd.8.Z..m..Y....7?
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4432104
                        Entropy (8bit):6.668233897307436
                        Encrypted:false
                        SSDEEP:98304:RS1kkCqyDEY7+o3OBvfGVY+40yajyS+9s/pLU:RIkkCqaE68eV+0y8E6LU
                        MD5:847002F1C75D338718A9B2E860844418
                        SHA1:0EEB47627F409978683CEE1FAEBD23F7EFEEEF3D
                        SHA-256:A1A985CA07037B0CF9D93B4984748F96EB3AABC5C10AA0EF20409371E1232F9F
                        SHA-512:1CCC46CA193DD81CA08AB94F5CE3D0791CB613D4A5B8CCA7FA589FC6172B5DD6683C47B42B4E6BB75D05CA0B916112DC3E834E06B741432D1C69C7AE92B26021
                        Malicious:false
                        Preview:C.J...@....Lk.../...4.1..7..l..i"........GE.....^....Y.8.....^.......6<I_../.....8..S....... z.."..$.....6.. ...1.......a....(.........8...v..9.mq^..{;.a...9!"-.(...IW.mE....s.dq..q.8~...V...1..+-..</1...$ ....b._#.z...4.................)....C..%..EO.....{.$....c;.s[0q^Hi.D....T..l..;>...I. .3...S.V......;..%z8.y..p+.t...@.......R....r..}...6J....F.P.........CN,Nj.E.D...[j60V+.z....;r....1.C...6_.d.... ;......:....cE8V.....U...@.C+..!.S..j..I^j.V<a.t...rmF #<w.. ....S....?..N.......a+..j.'..O....."b.Y=...#...'.c 52.w7u.....@[].W.L....-x.1$j.F..j..7.F.8.....V5..@......g..H......I.V*Cv..-.NQt...:I.9s.r....E.......Kw..v8.d.B..M..G.l.%....N.*.X.BU.] >m*.....)r..2.^2.......k....{Le....`a)..Y...@..t.......0wBs..o...).k.87.g.g..hPS+V...z'...R...^..![..4.i.....9.E...9.v.Q...1]4.(G.1..k.d.....Y.......c...;...G.j4Q9~....2.n.N..8\...q.4#.....k..?.HA.t.t@..,?..x....t......<.[..u.....u?T,q......Aj.u).z...e.....!.W......[A.h.....Ol!...._....W
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1132290
                        Entropy (8bit):6.213552495604628
                        Encrypted:false
                        SSDEEP:6144:CczCWQqKR/fsevPhh/y98SgRSqVqKQuMTzTqxbvqk2CH1g5wdGWODSwaD23TNNXl:CylKR3BLHlPTVt78S6
                        MD5:EA8E689DD9FF08FCD65CDAA76AB6646D
                        SHA1:F2388807BCD01E3BD01F8CBC53C370531DF7E16D
                        SHA-256:89F397826D029C93C901A9E073B524CEBDF0B62133E6ECBF7AD3B73C84E32064
                        SHA-512:F3087CDF82E8CF44C744344D1382D71EAC6BF6EB8274B4ACA7BDFBED673AE0766EFD4F81D999717AF2CC8175D3747673D27FA4B949057E4822F928AA3B4A716A
                        Malicious:false
                        Preview:VC.....!.Hj.g@RD..N=....M..?.r...p...S,h...z.]_..9|.,.5.._V.m...d....^'.[^.........@.......kL9\.(....l.e..\.....L..S[L.{..4\.&{m*.3...]yE..._..}..(.g{.g....bC." ..^C..(..;i...y....:..;h.......].....To_...H4....>...=....y...`.....,5mC.1.1~..^gW#...D@1.N.j.Jw..0p7@..\.)....2...........PL!'T.....v:..n..#H.P.@)o..a.7=.H.....sD.s..~.^v.n....sH........3...t........5..KBk....:..c.<..{..Z..X...H..C..........UV...c1L.1..C. O{.W..lP.8.qm.R.....:D'..o.^.w?..BSv./.....?..8....#..s..A..?..z.......Z.5o3.5.qP..9.......k..2*....C2.h....MD:.....=..........s;7'q.F.[/..\F...'8...{...d.3.T......m.V_-+Q.Z..v^.........a..."...7.w0.O.dB..K....X.........@.~.H......O.[P.c._.F9...$...*......kd.Y...LA.b.C.M*E.w.^`a>.... -k...'.....J.#.h.B..e..g..'Ug.8J.n.B.....T^.SyGx0R.M.....Ak.6..[o.`T..bc. .I.I$.K.=.. S...)c..Y.l.p;xV.C...9.A.6..(.TL...<......#.c..o.&nk8......gS..^.....`..3..\.*...rf,..K..dDh.....w../..Y.p1.y.EJ...WM.g.>O.;.1.n...U~.u......../a..`.B....@..H..{..q.h.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18690416
                        Entropy (8bit):6.434479067503647
                        Encrypted:false
                        SSDEEP:196608:Vm0ImFIEjZLGhwP1B6GgImqWFiA26hF/dtPSoLBFYs03kGHpOwrZo4Bs:0sTP1BksWwA2a3PhoXs
                        MD5:8FB71711E924ED77179BD19B86AF00CC
                        SHA1:EEB2D46896804384F1C422E067BC024664AF4F6E
                        SHA-256:0BDE5C69AEAB0ABF5BFB92A43E045461E237A7432A14F182E859274B413D0A2D
                        SHA-512:E75DDE1BFC38775ADB3CBAA2FA2D58907780A984FEBDF31912DDF563170B2E8148E902E21518DB55C42C8D8BE2EEC0312CF8D329FA058EB0425BF457C6B048BB
                        Malicious:false
                        Preview:.u#.g.[.....GQ?|....|A.D..8.d.v.`..e...D.....CQ.9.;j./..|K.>....#.A....=v.{.e....%.A.{....;....@?..L.... .6R.p..V7.j.~......Z.....a..cz...,.fP..%(.ml...Ma....g........\.+...}.yt;..#.......f.n.l......WP,.~....Co...r._...{?..w.W....G.V.3.....P....:...T..."'ZX^*%0.... .A...Q,.....=z4)..Z..x..a...x..Y..IC..my`....Tu..\..B......t..E......)...u............v...{........P..f4<...8...lBJ...<.....e..K.<@.......w..^%3.@xj....^l.RY?e[..VCZ.]c.Oct...i.n\B.....<..v.Os.o6^....i.....p...k2..{0F..l.A..(.9.v.....v..B.....I...=.x\+.\.#....H..S|..[....B.F..C/.....J.d.PxgB..k..+i..:(...(.....EClx.F.J.d..&q..%Q......$....J.&C.X...K?.+....$J..35...Mu.I..{..Q.k.....n..........6Sh7..C.....fy..*B,y.O.*.x..".........~X...f..|....L4T.2.....x.+.5.Q.z.vd...9.P.......O....f!....d#i.v.T..q.0$-.w.#....h....0...:!7.P..3...|..+..F5#p...G...o.....K..V..J..+..R.|/FU..H.m...k5..B.!G.os.........n......U..8.d..SE..&....SE.4...2.c...\=mV.{9....._c# ..........?.O.\p..g.....@...Q
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1881416
                        Entropy (8bit):6.801360237534382
                        Encrypted:false
                        SSDEEP:49152:VaWT9wxBjJMXDUlxqK/PDLWf+kfilcOk+4AgAQm:VaW5ADam
                        MD5:E06E225CE09F3029C17E0573392046BA
                        SHA1:FB642484641404DF9D572139FE2C6DEEFCE99933
                        SHA-256:F11198596ACD1A85DC550F5AC65518257033BE4A28595A5C39049E08E3F8611C
                        SHA-512:25A66FCC8061AB67A4DD8DA38947721B5FF541509B76B3C9134727AF47671D99E5573713ED4C8FE4F456BC66A774F56F7FD3D5F3A660A897DF6D7C8A11AF774C
                        Malicious:false
                        Preview:..0...4cJ<.G.....n..K....x...*T...]@.G....H_0.}|.._x.M..#...W0..)/(...iS.'.C..F....@T*.Z.).Wo=v....-.)O..9-_f......af.<k,.. f~6.9.c=8.}.*P.g.....5....%X..5rn....05....}.T..Y...%J...s5j.mb..g..|.........Ju`-...eAI..*.O..}.."....".<...$dZ.8..$..n.qaj~.s ...cP....[.3/.^!.c..._........&{.4..ET.. .U.Y..?.^Ao....b.O.(..]E+.\..6v..d.h....F...o.zhO...Q|.l."..$../..DB...v.Ne.~.i....C;.!.r.b.6.(.A_..@.vw.....}......$.v...~.DJ.....6......+.....T.3.3.Q....g.'../..<%x..yC..1.."...y.B#....I.H..|j......m.N_?.xhMd_.vA./.1......d...|.q...4".;Gb...".......0...........!....s.../..v.G...Cc.}.~.....kT<..&..uS.y..Xp..}.J..|V.......C.p.....Z.Y...M........;9....Pls~._.....!.E[!.EK.h1#..Z....q..*.8.B....O.Q....;.....ZOQ.....+..o.s*....?..y.....6,.....\=].T.......S.....T..X..TZ6...Ewq.FM.........|....l..$c..L...;..RY.F?...=1%.}4.(..8].?.o{..5.z^.....&x.b..M3>....L.V5.o.U..4O/..X..J...6.k.J...T..X.x.D..'.]~..k(..r.....P7\...D.m...icB.[K.S.s0.f..o.f.CU._.....dReJ....&.dSy..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):27667253
                        Entropy (8bit):7.998901420599089
                        Encrypted:true
                        SSDEEP:393216:aVdX5eFSW+/DuXC1+vqFY/OL6Dhtn9ixz+H4OIMDoX63g3q+ncR5e7wolRNmLSN:qdQFxuS4+qFY/R1nqGoEqt3HcR5oX0Ly
                        MD5:F6DEB78B6B0E4E4BA55F583347EDE8A4
                        SHA1:1B58B0E792739BDED3971A52F541739F3E88FD0A
                        SHA-256:E6A85444F1DF333F74488333EAFBCFC61AC913B6F8F0FEE611ADF48765C4057C
                        SHA-512:60F454AAFBDFDB2AE94E24CF3E39AAC8FE623B3F6700E54AAB4723352AD51CA9D0EA65953BF95F1CCE0774BC44B18454716DED3E317430D64B9936EC450C72DB
                        Malicious:true
                        Preview:.[.....T..X.i.....G..G.W...e;....E.89.....t"...j.JjD!. ...:u...p4E.9C|R<.:.P..\D..S..S....G..E(I.'.%.Y>;.;..z1....'..o....... .+..p.K~..:.N..#p.l....v.....:..)(.W.....gX.M.u.tr..'.....f.]T..e......2..&\.,Px,.;.v$..>.Y..ck.S....#M......24..R.G.R...mt..L...]....B.z[.....@.[.j...gw.A.b..P v.?..^.y\w.^..Z3..2.'.H.pC....a"...&3`...&..!...JP..8..[g........_b.a..N......>~...6...Z..l...4T..^..f....y.v/..X..2.M.t0u+...x%.....z(.W}.b...:>7$.7a.b....l...x........~Fc.9W.{..ORh...n.}.x..@=....S&N...W.!...@......`"w....H.='.GiV..|..h.Z.^...f#...{..E....}%...Ea..Dl.b.u.P.l....#l... .'...T....4x.r).)f..X....U.g..K.v...E......MrE..5..PA._.@...%P5H.n.)..C...X.,...<.v@$Ya.=...A.M.u.@0....{o.NE..;K.1,...w...+..\Hk..... .._...%....A...R..*..U.4;4_..u....wa.0Mx.pd4.cq~.$.....h.P.z9........n>.......XH.J....c..l0..Odq.,...l.O\..7b..,..0.@ mQ..I+@..."o....HC.b.V[.....[;q<....A...V.....,.UtC*._.@..j)I......T....{..........z.z..pm...~..?.Am.U...'.bP..ST.h.n&B|..K....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1253376
                        Entropy (8bit):6.241339401076667
                        Encrypted:false
                        SSDEEP:6144:h/b1sSXtI8KImSZEJnP4eIDdoBmLndA2pZLg8cmxqN6ndVS9v:h/b1sSX28KI2AeMaBmLnBZhcLN6nvSV
                        MD5:36F3782F04B64CFF57C0A5D71F0D850B
                        SHA1:347D55509A0A3A3E9800EC1ADE25D5346FBE89B3
                        SHA-256:155C9650D4453EC5684673268D8359F99B3F7655B7D69FF4E9C1B848733E28F1
                        SHA-512:016B83230D72E85CC45546847513A3062B504A3FC44ADEE9C635433D5DF9FB92F506C31392F74BC018A228015FFD22ABE9FB2D1C816074639D5FA2C41BE69D34
                        Malicious:false
                        Preview:V....nvn\.^.<.......b.SZJ,..-h.`.........(.,. ...k.I*.M.!7.w]h.N.d..~...9%vV5=..SG3.."'.T......X...2..i......K......'...E..RVs...+..rc...HEU...k...........O...)....nR..x[ri.F{.=....k+.(.!Xj...e.p.C$/.Z.K.....Uk....zs. mU..>-?.. .....1..^:<..?P......0....u....F..6U...e..:.....G.^y7....9}...+.n8.$t.D.A..Y&..*.'.&...D.h...|.....5.I<.U.....1...m...!....r@.%y..1.8...@,|-m.`%..\.k.BLdS#...10...u...9...o?.UsBb...V.j.L..6Trl..!.....7..RC.A.}0:....`.RY.PZ..(n*.AX.s.B.b....H......).Z.`."#...0.h..XS....v.+...r...Ax"..b.ue*.qI.#w_C#.v..Y.S..Ft...o..[..;..q....z.o.0.X.2:Ye.Z.V..w...(..z`..."..\(...j.n.....r.$...........}.E+4.......?x'.g...\.Z4.`}.........\.v3G......xO........'-H.X^o....s.Y].........L.hz.2...mn=sL..C......R.......Eg.*B...K|;I....M..'.I....\.....A.....yNVe.m.U....]..t..t.....{..P....DV..V{.}:.-M.G...6hY......]'dr4.g[..Q..0..2.b....&N.%....j........u.........".:....^.M..B}<...7N.R.I'5.%.2=.. .at......T.J!.t2.......l....gO.n......$.....4
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7761920
                        Entropy (8bit):4.600458280488324
                        Encrypted:false
                        SSDEEP:24576:aWOkm09iHTH0AA3GxtLyqdHbY1bsbgfqANeGgQgnuGL+vnaUdZ3v8ZP:aWOkm0zALD7Y1bsecXnuOOZf8R
                        MD5:991986F10F6971DC165BA71047AD6CF2
                        SHA1:12CBAEC09410DFCA7D534EA1AEB8CE32FC4A143C
                        SHA-256:2720CF3793E549C2F990EF3E5E644E6F06989E87E06D966CEC503E8D8A077CA6
                        SHA-512:0262646D0635E6F4CF7D109D23C0627C381878B2293FEF98127140A52A53B745BB1F14F1E3AB03D100926D9203A0E781E9811380DC1C65E597CA9A2D9C812350
                        Malicious:false
                        Preview:#T..eqC;9......a>.c<.."..._...A.j.Dw...7....`.Q..T....O&. .n8......PU.....7.Z,..7'....GY.0|...q.....]...b..|.}.J. .rR......_.a...............j.;./...+.)t@.a#.C..,.."..*.Z..4r.."..1,....K$D....'/5g.O...AO.k..J<>H...V...J....8.m......W:i...5`k..o....WY(q~.[......V......!..I....*....8....^Mq...P^?.:...p1.$QDB..''...H...<..T".Y.......j....Sp^...8..x....N.....,..Q..=..L.\.'.S{<.Xj.snI.{._>2U0P.....Ej4-.}..$...`..]1]!"...h.3I{..6B|...I..Z..R..X.e..O..e".*......-.+....GD.V..=..#.....+4....R....;WG........A.d.%.0w.{g....-........;d.......N......S.....o(..).....Yd3.9..%...s..h....8..FC....k...M.|c.w.b......B.....h.sV+z..I. .....v.>.W.}5S..FK...ru.ij...UT|HK.a..`:-KV..p+....`..\4.f..."v.n.."..0.H.Qmi..5..H.M..k..."v.....1w.u...J.S..A..h.C..}...D>N.f..6u.pL...?)..O`tn.....D.E.\.0..5..N>7..%+....+.eV.....fl.X...Jx..|..y.P[(..<a.. ..z.Ve.+.....?...\6.R.[-...gE...i..Q.`p.q.E.y..t.......:..U.._ow..R...".YW&#..`.L..yr..9+5..C8....c..0g..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1940486
                        Entropy (8bit):5.644401518719204
                        Encrypted:false
                        SSDEEP:12288:MlgEXtpGO83Lql0kZOvbHARtJG7cyQqyOsy0xlgtI:JEXzr8o0kwWFey0I
                        MD5:B3AFEE7C60D219338F914B0A14BEFFB3
                        SHA1:9C4F70F2497548E2FF9DE5D638D1E5A69BF414BC
                        SHA-256:E3F852CB41B5FBA57B484929D22CD2C2F860A6830870C8A8525E9056632D289D
                        SHA-512:1DBC1BDF662C5DD0BC2C41E74FFBFE06E2A8A191F35561FB720BD7937454887F6EC2F6E0818BE97D94B809B058ADFA0A4F02F108479FA300FD107C99AE04C1AD
                        Malicious:false
                        Preview:.....|Q...(..U...".dU.g9.:......n.uVF....yt~.....=....n:h.|.N.I>..]5..5_...........H.]..E.0S.F....VX9.=.1*r..[W...G...NPJ.R..-4.&vx.#..M.P..uS.x..tMB...[.......JA7..L...44.CU.MP.y.....$%6.4......k....3.)..cN.j............b$...ci...:V...Q.e..h..a....<9..L....&..)..Y....qe.`..xM+.6.......x.>..G....8.Ev.E.@.U.D.D.......^...6._..@...z.......A..."<..iR.Y.'....N.....f.6.?-{~D.k.....T......7..2.t..e{..{A..-.F........5...^..1M.4..w3...P.....b..]..4..^..(..B..B...^..YU......s..~j.c....ChZ...U.!..>s...... .....M9..V......b?..a,..~...>%..>....a.}.l.0....`......AZ./.l"......4...t.vd6[e./.6...?j..H.....U.k)...g..8......!<.!.........jl....R..k....z. .~P..,...,..0.'.G..jhR..9H..A...2.O..z.4pg-.nw.j....H/._y"...~./7........&.<...jQ`..m1.....HH...u.2..<.`.)^.S...9..r...N$....X..n..3...b.......*...gs.#.D.a|.U....|...\....)w.......*...I.P.).....PR%.xf.Vg.....Od>..T...f.O!..l...wl.?........OE..7.*d.....1* O....O.X.&kM".V6Za].".......[N.......f.y...Q$.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311232
                        Entropy (8bit):2.8595194022158608
                        Encrypted:false
                        SSDEEP:6144:myKt2roQ2b7lfkzRxBr0OA1ehcB7VoBgYEL0InCK6:pu8/2Vk3BrtvhcNVoR
                        MD5:6EDAAFFD7798522BA518420C12106868
                        SHA1:EAAE5571455CED3CA175094B8F918887DB0073C5
                        SHA-256:6DE7E46F1653671C537911B64ECAA61A249EE57EF634C60C0A98A78BBACB9B1D
                        SHA-512:513A5BF2841D9420E7A957495C1CB4146D39555039EEDE652C9B5F2570D6A4C40AB05A1C91C66A4CE22875F1737868222B98FB52660DAE9C5F5A2E0EAA45F1C5
                        Malicious:false
                        Preview:;..?v3k.Azl.3lP).......c..P.W"...`%.|~..le...6..W"w._..S.....X.o.....|.NwJ.!..}qf.I."..m.l...W.....].....4r8....[b.t........A..~9....y7..#;......!.M>.T........3..f36*O..aZR-..C..X.2.5.O..?h............# ...T.. ..E.].R./.s..P.Q.K,.<m.F.C.W.;........8k..p=../.}...@~k..v...,...d...lokE...muV...5."..d9Y.W..|.:..>,o}.3..P%.O2i........>.*Nt..z ...`$r......\.O..!.7.\/...80cx._.N.p..........F....3]......._....{.,p.V.;...gL6....x.b..y.]..p@gN.x......`.....E..y\..4......6.s..{`.+0.!....C..U]..O.A....8:.E.....;3..%.s ..2.~....).%.x.k.?.?.A}..VA'....wn..cB.K.{SO..$b;.L...\........g1$s[@.0...4...$..J.....O..<.C.j-... .&t*,N...i..C!. .C....X.jx!....}4....T.(\....(.u.......=.#.D;...2.F.%yLX.;.....|.`..;y.$&_...q..&a.....M.?....GP.C4JTJFx6O........C..>/q.A.$*..%..0.^..,...o..Ic...S=-.."9.#9..b.....*..0...a...a..Z.R7...[_i.B.W4...[.b. .%..S.......J'y..'.5e.zN....s....u.`}=..4.~;P.i..z.33;..8S...N1...8.b}6"rt6....L.~..tE.5O.O...@..T..5.....|Z..i.Afd....~f.E'..nQ..)Zw
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311232
                        Entropy (8bit):1.8710104560845997
                        Encrypted:false
                        SSDEEP:6144:k57SxwxUA5+Erb//zOAH/OShBa+FeEML58i:k5Fxb+GacfeEMLJ
                        MD5:03990B85A7D00BA66118F273656E1188
                        SHA1:0927428BD9CBC740C1BC0BEBE68040725779D80F
                        SHA-256:D6383A374FC7158ED611CB1E21471FF2866F954EE88A4168CED88922348F2919
                        SHA-512:33A61A8D05F0BB11765B8D17B07DB6543BAE4DC33A6B2B55FEA87E3911373D6D674575BC47CB33DED8DBB49BB36859A57F67FBB6943CB2D90094426EA7888403
                        Malicious:false
                        Preview::.X...4..%u.H.>..~..y..,..~.XPm..0b.rV.v.fw..r.'.Y...]..D.0.Z..u.&........T..kE..v.A./D.W. X..._~.~..'....k.....J....u:n..].2N\.........WB...i.1....G.%..;E!..l.t..j../.5F../.D..z(T`.1N...7A..0./.../..j.m.O....c....<.IU.].y.9.....Q?K.n.j.@.m.ngq.0*A.C..DU."......a..a..E[...<...._....*+.20$..mJ....}."].S..Z=..'dF..I....rq.6...L"o..7..J.x....b.....EB.w.;.D..b.......Bj$qa.z..}..N......"...[AB7.....oy.....2I.b...A..M0..<s.|.......Z...6y.(.lV..^j.<l.4a.H....}.[X..J.B..{.p.Ir.oHq,.tT..H.....%.B4;....H..f..GQ.S..[I]..}.m_..?t......I....S[..K.....T.hU%Jg......*M.w`.eJ..Y....3....WE..(.Q...........}$.....}b{.U.}..f.4(.].....^6....%8'./...x.....Rh................-.........}@2....2....."K".c?O.........~.....0D_E...`......N....w......2.U.m..o.P...............K..,.9.@....)H+4.....D..|*....G..{.tc!.f..#.w...Y...y.O....$...............b..../;3T.a....Ir.I...]8...5q..o...)O..&..........\..Wu.qd....u...........@sL....W...).ZW..r.\{.\!.#..]
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311232
                        Entropy (8bit):1.8714133532582655
                        Encrypted:false
                        SSDEEP:3072:lA+/3TpiDFZtfUgwbMqOyEUfyl+sQR3qY9bCO5VXGTS6iaH06bvEZhZE8QCVdOk5:jPFiBrf6dOw6UJa0sIbmv892kgf+6toZ
                        MD5:A7C7E2D17D6DDFD3EA424D7A217147E7
                        SHA1:98F40A2DD3E6D7C94976085446F031148F20E25A
                        SHA-256:15974C56C08508F4CAE4E8B00B8BF8BF8F2E2AC41CEDEF0238FBABD79A73564A
                        SHA-512:11DBD2B24AA480A31BABDE05D63C59251EED2E44C88BE85F250F643A1EFAA9EC2EEABEE487B854E8A6F8A95F473803D24F22D93433E1125423311812248F7FE1
                        Malicious:false
                        Preview:..+..g.............g...^.R....I..#c....o.....E...@.......y..8V..8.zV*{....|j.g.cr#.......{....f........5^.!..)6..5N.N...m.,._d...Mb{........._{...To&.3_..o....<.$|..^"....T..N..et....,......k.......W6620;.2Y......<..?...1.ai.&l,..6..t.....$.......f...K..[(..<.f...3J....yHe#.^"..Y..v..1.=(..B..O.)U..M".R].....i....2.{..%j.J...w.O.....5.*....K..U-...!..7-./.WS.ko.N..].aC*..%{rj...K...\N.K...^5*,.......A8.oSW..*.(..uU....\...)F.H.t.E...i..P...Q.......N;P.3....5b.8p.,......9s...}....S.x)m.D..~.I.6 . ...O..,..%.....7r....@f.Tw...g.7...q...h.$.ph...&;..s...U.+.O..~.b.......`..->......!aS.5D.Q..".T....~T.&.,C.e..O. ./|8..f8Pq&..a.a..A.......}ra.........q$.".qu....l.....mx...5...0/......B8.Q.y...\..bO...z...Z......o.....@1..vsAjq.&.I.(&..<,{..N.O5..7........!.x.y.o. ".Y.z8.....X....\.5.Yg.0.U..h.....P..%.a.-S..;.....@.....c..j`...Xv..-|.Z..u...2..E.z.zH.N.tGD$Ly.D...P>s.U_.........pwF....... !......}->.:..J..<..QVl...~.`7....9...d.....{m.......tu..z7C`....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311232
                        Entropy (8bit):1.8712886684385146
                        Encrypted:false
                        SSDEEP:6144:TZPwg+mGyy1CwOEGZAXpOtoRve5a3qAqy208puqY0:T90xtuZGIoRv+7y5Vd0
                        MD5:DD8F3598E4FC307C4DE44911F4148AA0
                        SHA1:10FDA4CDE9AAD3016601BB76B4847955CB585D34
                        SHA-256:FAB7E8D77EBECA217328D857702175DDCC67C84998B7F2A8A480E386627B64B6
                        SHA-512:F06D858A03EAB16611B107306F025EAB81B5CCFDBDE6BF72E6CBF3E7EA5D0D45BF686A86936067CD6DDF3F5C5A1FE5D1E12F7C14C97BB80B9D3453BF141221E1
                        Malicious:false
                        Preview:.p....'.;.S.....3....v..z...;...|R..g..P.p].D7..h...~.S....^.t..LM.8#g..^.VR......*..D./L;Axm.!..s..P.^.7.......p].$.g....`.o...@T....._....w.....1.0!T../Z.Es.m~t.d+...XTnx... ...\..A.........+4/.tt.6N.3...>..T}:)..e.....Z/.....# ..d.F..{..O.......M..B.p3=.4.zm..'.be'B#/-.R+.m...:.K.\.....F....H;........wg.t.qd..RAn..d...~"}.8..x....}#...e.....t.B..5.h....A......5....Im...,@..D../...'..z..~.....I.Q.......J.r..Ol..Z.2.{.K.+.Ns....b..L.]...... ..GM...;F..u..S.Z.U.vL.%....<.1..wg{n.94..7RA}.-..o...........\2..:..f.w.Z.`....[. `.$Ct4..R.._s....K..g..6.o..$+, Jw...w...tx...;.......`qa.4.C55mW.....5n)(..P=...zT*.....:...I....E_F.7.'.'....%..e]....)gp9L?.?/......i%..4....eq......{....y.Y-....k.DR...X...$r..R.$.....@..a........G...=.....O..`..`J!...W......SD.q].o.Q(A<P.@;:<..,_).<9....@...8.u............FV....>.(V.......8... ...,+. .x.-.0.....i..Lc... ....(...!Aim$.}G. ]J...5&M:.a..*....a.9.O.B.....3.t..n.....,...6.H..&...<S.j..;!C.Y.B...f.#.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):68955736
                        Entropy (8bit):7.997588347754092
                        Encrypted:true
                        SSDEEP:1572864:PFXdwLL8wkPi0N1AvxHwaAzCYORK6FDksTdNrX6k4CGf:JdwUfq0N1ApyCHptksdNrX6k43f
                        MD5:2E192B9B247CC4574E4ACFEB4F305B2E
                        SHA1:6C30949C9C4EB8D0853FF97D637DB4AB296C2945
                        SHA-256:935B32484BBBD7E350E082E8936607FE19CEB87230173CA57EFD7B0DC9BF1B0F
                        SHA-512:23CB554C8C2DB990621A53B9D239152C97966C2D8CD8943A0629E9FCDA8F15B5BF86D8E5E781EBB568BD9CCB7D6CEC0E8A2E1BBD0FAA5FF07C94C35A34C7C9E1
                        Malicious:true
                        Preview:.....-...!#'...5.p.|..;N....).T.G.*...v.,.....T..Z.R.'d.t.M...4.X.I..h.).9.v..d...W0.....C....$.%.TS..I..x......!....} .....v.Z.A......~.|..(sq0.....[..n.v.....8s......;1VO*|....<'..0..G+$.f?.....0..'V..Q.RR^.....?........Li....%.V.lS..>..2.I6..Nb0Qn.Q+..0.~..X..c.."..k.....S....g...e.n..nB.oH.Ub2...2.C.ox.,$....j...".1K.k.I.}....&...>.o0.'...i..=3`#H..m.$....]IB..p...v~.V.x&.q...".??...Nw.. fp..?..4[.{....]..$....1....[......"..}g.F..=.z.3..`k..>.S:.Z.4=.n....i....<.'.;9.....FU4..j"..k.mY.b.&K.A(..W6.W...............y.c.$7.......Z...-k..S,XIQ.O{V"!.......&...7.a..2K..D.6..)..e.../.......Q..9#..6.{Z.6.S`u...........5...a....d..9K.Y.og.c|8>.C^..........j-R.R......6Phx..0...F.k...J.n..}7t..J.%)..R..U.i\..}....%.........L.H#...|..w .o....*....;...&._h...2.v?#y.H#.mx.i..f"P._nj...B.x|.;O..0T.[...M.$3...[..4.9|,#.....>Y..s..........L..k.rl...yd.b...~...D\.I.5.#...........S...,...n.....3..Z..x....).Vy.Ct.d*.%u.T...L...C5o...nI...#X
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1456728
                        Entropy (8bit):7.999216761769341
                        Encrypted:true
                        SSDEEP:24576:OMbfFbr2FAAjl3AOoXmQhWKCHGa64RQL+veBWFLXsqzp9XdWLl/wrRYCGM:NbRr2F1h3A2CWKS64CWeudUYruCGM
                        MD5:20B802A9EA6BE061CCF2DA0C43A42D10
                        SHA1:50E118052A3B284C51CFD912F3F740F8DF90425D
                        SHA-256:5CD069308E07427FDACE0D1C33268A90DFF81077A74DD3AEABBC91394CC5D49D
                        SHA-512:32CCFFFA4BFFB0922AC64C6C464A2FBB1801400360DFA1E285AC7E098C81DD96E2E5DBBD360B90646D82F682F0D0BCB9936157472FEB8F54E0A324018DDF5756
                        Malicious:true
                        Preview:....A.UM.....(...,..Qop.h..-."...M^.....?.J...$?...i1.W.7...R. ...@.vrL..)?.F..r..AN.\]ID..4l.}..O&..O...@.Ag....]H..2}6.W....0.7.Q.j.]....h/....x...........1."...dz=u.TQusF.}0.$`..sx0z{....0,..Z...JBLU.#.........nz._..,.....4.@1...l.5...3.Q.V..V.R;.tL..!......}..B....".....@..g..M........4s"|B...=.2..e..YII.:....V...}..J../..Rr../.q...'.P.8...........`*.J...d.H.WD.+!...^,.A.-..f|....*u.._,.xT.NG..kM...-......#..-.U..i.4.X...b........G4|:../.E~,D...L..!|._...v...b^*...T.y.;...*..6...\{....]].M.=q....<-&...wm!..T.+.....-_....t.$o.q..R.aGi...z..-v!...4.p..S..\5y.....8G...Pft.a....)..D....J...$....>.3...%.$=.9N.. ..q..*dh......q.;....{..*.R.....I...lB..........5Q...K.U.O.r.&..jq..bD;...AK.Zl...x..,.H.P.H.........n.gI.t.m9.....|...l.....iq(y....,..X..7.?.G.x6.[.F......8.}..k.....'...N..4....U.....o..v.v.`.o.....fgJ..I............N.\....1...G..H......!.Y..p.....I.a.W...0X...hIu&..c.....Q..X.m:.....e......'..7.........w.:9.......U.....4S{..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):42694232
                        Entropy (8bit):7.9975849584903544
                        Encrypted:true
                        SSDEEP:786432:hFSlJNYfD8X3/UQL/cQqvTZ7mfucYxPCGLof06m+afiGeyFkTby:hFSbNYs/Ttq7InGE1wfiJPTm
                        MD5:2EB9A0CD8A1FB63BAEEA290D62CDE508
                        SHA1:14AF0AF45A04ED63E025AC2711720234BE541667
                        SHA-256:834CACBBA3ADDD37DCF486353A7AEECDF0651972154BD758A5063810B2FDBC1F
                        SHA-512:29EF4A5B53DE07368CDCFFBEFFF939414EB4DC6E71EBB660EBD0BD0B21C70EE509D342CB2209E84534D1C70546A2E281D2E66FFB67FA4D2F040EB129F5BED808
                        Malicious:true
                        Preview:....x.Q...w.te.....l..'y.t..Tp3......#O...`.D....n1.H~..8}5T.^..3.[8...?T..?q.o..i~....,I.O...H<.~.M.X[.IB...X;.x......mX"p!.B<...._...)..E...8..q..#..q!) .Cb.W.........<m<Xy...B...dj'.r*.4..O.?,...n...Cp.NrSe.H..-.qO.k-g..`..c$...*..d1....O<.._...1.pKz.}d......o..*.K_.^.......|.....wM......`.....8.B......Q6t}.......uD.....^c'..0.M...r.2...o-.#....7.:.z..}...q......a....u..`z.y..K~A....*....8|.i#.<...B.Kg..3^<.....2RbJ..[1...H8R.c...e......a.....G...Fd]n....K0FTI. F........^..:.o1r.7.~;s.a..9.u..K.)R..3.}...@...v.....m.....9Ed.....b...<...6..............CQ.L..u.B..?........~..U..nO...qlJ/.....F..EV..?x*.........v..E.k#.)..U..W.$y.k.9tW.......x.\Y.+...=.8k...rI..^..2..Qod...X'.Y...Fv.R1.".....!?G.J..@q...[...2y.X..{.../........p.....M.l.K..+....a..6Y.[5]l>O...L....@.F...o.^..m.."b..."..O/...0..A..........K=(/....#.F..~.5.+..P......62..C....u..*.....RB4i..mi,......68..)..J....B....X.6E.,$...+.(.<{.....S... I....0..X..M..1. .0..L'...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3:V:V
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3:V:V
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3:V:V
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1598
                        Entropy (8bit):7.865705160368599
                        Encrypted:false
                        SSDEEP:48:7vxdudbqxIuFQsVttY96K4TJuIhQqZfW+Z:TuRqxBFQsNY9AzQqZfL
                        MD5:7865F6B69BB84EFC961727E33A8BF6FE
                        SHA1:0EA6C2A044AA57053BE6A5DAF4E89EF6136D86FE
                        SHA-256:16BAD27DF7B1FD2A2D33CE20E8C9539E11B73C62BB05DEB7F094BF7369D7B444
                        SHA-512:F97A8284724D0E3BB1E9A61802D6EFA56EAA916E4D1441B1CE86AD906E6C4F3BEF4E3A6D8498F1B1F66C34230D6A761171289F8FFE34F1469AA73AC05E71A172
                        Malicious:false
                        Preview:......U[p.}.`..8.W..................[.D.IQ..Y..4.....q..>...U).#....Dw=.M......Y2..{j>.BX.X.L...Tw.M.A!A }X..`.)N..j5..E....".=...8.....T..w.A.;wg'..~b....e.hA..*I....'.Q......"c.)...gHR...-...6\..9r...}.M0V...E.._.S.....f.#....?. .U..*%N.:.4.l...Wq?.'.J.\<r..u3.uT*.M.Y.c#.....Gl,...@j.G.\2.....?..L....CQgR..L...$g.G.s3...&bw,<...*....&l.!..Z...%.....YV..}..r"Y.>....{.......... ^WX.....}..(1......+G.Q..#.w..x.\<... .t./...........~....,O....F..T).......J....[.n{..........rTY...vG..Y..,+.E.u...........S..u........X.......L....<.5]"...jn*......L....}.b.......;..G&..!..B..../...Q`.<.M.....r,.K.-~...@?.i}....5..>. .zt+.D@f...E...K3.............I.bGhH.(S....*.....r..:..{<@..... g.A.ew.e....D6...=.........h......!!...eu.8YS..gj.[...^...*.'/...y.d..e.'.....r.%.....Sw.xe...9.)..x.....tn..E.;....A...qO.i6-.,.._.a..oSs+...?...b..0RP\O....}.).x.F...sfE..qJ.....i..}.o/...aq.t...B....Dw....2...A....C.vx...h...._.U......Z.;l.D......"'Ncy.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7761920
                        Entropy (8bit):4.600458280488324
                        Encrypted:false
                        SSDEEP:24576:aWOkm09iHTH0AA3GxtLyqdHbY1bsbgfqANeGgQgnuGL+vnaUdZ3v8ZP:aWOkm0zALD7Y1bsecXnuOOZf8R
                        MD5:991986F10F6971DC165BA71047AD6CF2
                        SHA1:12CBAEC09410DFCA7D534EA1AEB8CE32FC4A143C
                        SHA-256:2720CF3793E549C2F990EF3E5E644E6F06989E87E06D966CEC503E8D8A077CA6
                        SHA-512:0262646D0635E6F4CF7D109D23C0627C381878B2293FEF98127140A52A53B745BB1F14F1E3AB03D100926D9203A0E781E9811380DC1C65E597CA9A2D9C812350
                        Malicious:false
                        Preview:#T..eqC;9......a>.c<.."..._...A.j.Dw...7....`.Q..T....O&. .n8......PU.....7.Z,..7'....GY.0|...q.....]...b..|.}.J. .rR......_.a...............j.;./...+.)t@.a#.C..,.."..*.Z..4r.."..1,....K$D....'/5g.O...AO.k..J<>H...V...J....8.m......W:i...5`k..o....WY(q~.[......V......!..I....*....8....^Mq...P^?.:...p1.$QDB..''...H...<..T".Y.......j....Sp^...8..x....N.....,..Q..=..L.\.'.S{<.Xj.snI.{._>2U0P.....Ej4-.}..$...`..]1]!"...h.3I{..6B|...I..Z..R..X.e..O..e".*......-.+....GD.V..=..#.....+4....R....;WG........A.d.%.0w.{g....-........;d.......N......S.....o(..).....Yd3.9..%...s..h....8..FC....k...M.|c.w.b......B.....h.sV+z..I. .....v.>.W.}5S..FK...ru.ij...UT|HK.a..`:-KV..p+....`..\4.f..."v.n.."..0.H.Qmi..5..H.M..k..."v.....1w.u...J.S..A..h.C..}...D>N.f..6u.pL...?)..O`tn.....D.E.\.0..5..N>7..%+....+.eV.....fl.X...Jx..|..y.P[(..<a.. ..z.Ve.+.....?...\6.R.[-...gE...i..Q.`p.q.E.y..t.......:..U.._ow..R...".YW&#..`.L..yr..9+5..C8....c..0g..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):11251712
                        Entropy (8bit):6.880600840374145
                        Encrypted:false
                        SSDEEP:98304:9ZB1ztj1P5KtHzdTLI7XEwbidVnOoMmSz2r:JezVy0wbGVnObmSKr
                        MD5:9801C7235290784B5BD32E2205762CB0
                        SHA1:8D1A8DBE63346A75434DE4C65F028709C82EED91
                        SHA-256:5CAC36867B41736140B859C11EBAF937BB4534E82217E3DD33D0B84EA6F43DBE
                        SHA-512:B6D400482D42D5FB0330B3E2B33401D8CB8B4DA9616EBFF5BA37D16B3B8AA888CBB848D075BF6A8DE398E5DE7FE23718CDA452D576FE3F27441B19736C020E16
                        Malicious:false
                        Preview:..%..7.d9..:.!.6..)...}..:;.......w.....!g...m.R..L.P...X.#b...:.1.......F.p..v.....7.\..w..Q..e.\.bQu?%@.H...-d.^...(.W..pb.Z....U2..i..}"....J..X3...rr.S. .....!2.b..C...7|.m4.da.....=..\..._w.<.%.e.L..m..C..G.N@.........%ex6..t.A%U..SPg?L. BG..h..+C.@~.v/s.H.\xr.D.g..N...}K.....f.w3...j.2B...$9.)...s..R.%.[..B.3....#..h.5..=.|.0.?.!....g{8....A.?...;.#...... Q..fm..xH.5.....1.%.n...<.... *....+{8..~..2..IH....Ys.oH.G.....4..!.>.....D........ze.D....e.].]$.T...8....Gy.$.i.sq.S..........:3."..Jaic:Z.}T..\.I...i..B...K!.1]\.F..U.H.p.;,08..e{...`.QF.S.).?.X...c..9.?...X./.....".....7.y./.!Z*.Fu....3..'.Qn....(.M....y.....P.,.GY...*....U.)....k|2Vl....~..&...Nu~.l...2.\,.I.....e@....:..q23..._.K..-...7...,+....+6.q...fv..T,...y#p0......Y/G..:^..vlD.ly.*.x..<..b...l.,.q.U...*.[......}.2?R1.4C0.b}|..Y...R..H`...A;i..'..e...o7YgKB..JK..f....Z2......d...qKH,.M.....a}.P...y... .>.DS`......8....!T{......W...$.k.i'.!#.m_.fd.8.Z..m..Y....7?
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4432104
                        Entropy (8bit):6.668233897307436
                        Encrypted:false
                        SSDEEP:98304:RS1kkCqyDEY7+o3OBvfGVY+40yajyS+9s/pLU:RIkkCqaE68eV+0y8E6LU
                        MD5:847002F1C75D338718A9B2E860844418
                        SHA1:0EEB47627F409978683CEE1FAEBD23F7EFEEEF3D
                        SHA-256:A1A985CA07037B0CF9D93B4984748F96EB3AABC5C10AA0EF20409371E1232F9F
                        SHA-512:1CCC46CA193DD81CA08AB94F5CE3D0791CB613D4A5B8CCA7FA589FC6172B5DD6683C47B42B4E6BB75D05CA0B916112DC3E834E06B741432D1C69C7AE92B26021
                        Malicious:true
                        Preview:C.J...@....Lk.../...4.1..7..l..i"........GE.....^....Y.8.....^.......6<I_../.....8..S....... z.."..$.....6.. ...1.......a....(.........8...v..9.mq^..{;.a...9!"-.(...IW.mE....s.dq..q.8~...V...1..+-..</1...$ ....b._#.z...4.................)....C..%..EO.....{.$....c;.s[0q^Hi.D....T..l..;>...I. .3...S.V......;..%z8.y..p+.t...@.......R....r..}...6J....F.P.........CN,Nj.E.D...[j60V+.z....;r....1.C...6_.d.... ;......:....cE8V.....U...@.C+..!.S..j..I^j.V<a.t...rmF #<w.. ....S....?..N.......a+..j.'..O....."b.Y=...#...'.c 52.w7u.....@[].W.L....-x.1$j.F..j..7.F.8.....V5..@......g..H......I.V*Cv..-.NQt...:I.9s.r....E.......Kw..v8.d.B..M..G.l.%....N.*.X.BU.] >m*.....)r..2.^2.......k....{Le....`a)..Y...@..t.......0wBs..o...).k.87.g.g..hPS+V...z'...R...^..![..4.i.....9.E...9.v.Q...1]4.(G.1..k.d.....Y.......c...;...G.j4Q9~....2.n.N..8\...q.4#.....k..?.HA.t.t@..,?..x....t......<.[..u.....u?T,q......Aj.u).z...e.....!.W......[A.h.....Ol!...._....W
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1132290
                        Entropy (8bit):6.213552495604628
                        Encrypted:false
                        SSDEEP:6144:CczCWQqKR/fsevPhh/y98SgRSqVqKQuMTzTqxbvqk2CH1g5wdGWODSwaD23TNNXl:CylKR3BLHlPTVt78S6
                        MD5:EA8E689DD9FF08FCD65CDAA76AB6646D
                        SHA1:F2388807BCD01E3BD01F8CBC53C370531DF7E16D
                        SHA-256:89F397826D029C93C901A9E073B524CEBDF0B62133E6ECBF7AD3B73C84E32064
                        SHA-512:F3087CDF82E8CF44C744344D1382D71EAC6BF6EB8274B4ACA7BDFBED673AE0766EFD4F81D999717AF2CC8175D3747673D27FA4B949057E4822F928AA3B4A716A
                        Malicious:false
                        Preview:VC.....!.Hj.g@RD..N=....M..?.r...p...S,h...z.]_..9|.,.5.._V.m...d....^'.[^.........@.......kL9\.(....l.e..\.....L..S[L.{..4\.&{m*.3...]yE..._..}..(.g{.g....bC." ..^C..(..;i...y....:..;h.......].....To_...H4....>...=....y...`.....,5mC.1.1~..^gW#...D@1.N.j.Jw..0p7@..\.)....2...........PL!'T.....v:..n..#H.P.@)o..a.7=.H.....sD.s..~.^v.n....sH........3...t........5..KBk....:..c.<..{..Z..X...H..C..........UV...c1L.1..C. O{.W..lP.8.qm.R.....:D'..o.^.w?..BSv./.....?..8....#..s..A..?..z.......Z.5o3.5.qP..9.......k..2*....C2.h....MD:.....=..........s;7'q.F.[/..\F...'8...{...d.3.T......m.V_-+Q.Z..v^.........a..."...7.w0.O.dB..K....X.........@.~.H......O.[P.c._.F9...$...*......kd.Y...LA.b.C.M*E.w.^`a>.... -k...'.....J.#.h.B..e..g..'Ug.8J.n.B.....T^.SyGx0R.M.....Ak.6..[o.`T..bc. .I.I$.K.=.. S...)c..Y.l.p;xV.C...9.A.6..(.TL...<......#.c..o.&nk8......gS..^.....`..3..\.*...rf,..K..dDh.....w../..Y.p1.y.EJ...WM.g.>O.;.1.n...U~.u......../a..`.B....@..H..{..q.h.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1939974
                        Entropy (8bit):5.643159328614193
                        Encrypted:false
                        SSDEEP:12288:MlgEXtpGO83Lql0kZOvbHARtJG7cyQqyOsy0xlgty:JEXzr8o0kwWFey0y
                        MD5:60547E66C22EF250BF3284A4478E7143
                        SHA1:8ACC3DC02D5ED27BBCF608ACBB6898A98E8EFB9F
                        SHA-256:FA6927DCE47C3947C4BC43926ED26A02D7FB4D731DE2D39C9447F984A3EC693E
                        SHA-512:69740B0C6137F8E38384EF0E8C8F1FB5362BD278A7D43AC21B4E82B7EC87223D097442D8F5070CCBC3B67B5C100D5617B5EE50A834CC5E94FCA8A23D419BA9FF
                        Malicious:false
                        Preview:.....|Q...(..U...".dU.g9.:......n.uVF....yt~.....=....n:h.|.N.I>..]5..5_...........H.]..E.0S.F....VX9.=.1*r..[W...G...NPJ.R..-4.&vx.#..M.P..uS.x..tMB...[.......JA7..L...44.CU.MP.y.....$%6.4......k....3.)..cN.j............b$...ci...:V...Q.e..h..a....<9..L....&..)..Y....qe.`..xM+.6.......x.>..G....8.Ev.E.@.U.D.D.......^...6._..@...z.......A..."<..iR.Y.'....N.....f.6.?-{~D.k.....T......7..2.t..e{..{A..-.F........5...^..1M.4..w3...P.....b..]..4..^..(..B..B...^..YU......s..~j.c....ChZ...U.!..>s...... .....M9..V......b?..a,..~...>%..>....a.}.l.0....`......AZ./.l"......4...t.vd6[e./.6...?j..H.....U.k)...g..8......!<.!.........jl....R..k....z. .~P..,...,..0.'.G..jhR..9H..A...2.O..z.4pg-.nw.j....H/._y"...~./7........&.<...jQ`..m1.....HH...u.2..<.`.)^.S...9..r...N$....X..n..3...b.......*...gs.#.D.a|.U....|...\....)w.......*...I.P.).....PR%.xf.Vg.....Od>..T...f.O!..l...wl.?........OE..7.*d.....1* O....O.X.&kM".V6Za].".......[N.......f.y...Q$.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1940486
                        Entropy (8bit):5.644401518719204
                        Encrypted:false
                        SSDEEP:12288:MlgEXtpGO83Lql0kZOvbHARtJG7cyQqyOsy0xlgtI:JEXzr8o0kwWFey0I
                        MD5:B3AFEE7C60D219338F914B0A14BEFFB3
                        SHA1:9C4F70F2497548E2FF9DE5D638D1E5A69BF414BC
                        SHA-256:E3F852CB41B5FBA57B484929D22CD2C2F860A6830870C8A8525E9056632D289D
                        SHA-512:1DBC1BDF662C5DD0BC2C41E74FFBFE06E2A8A191F35561FB720BD7937454887F6EC2F6E0818BE97D94B809B058ADFA0A4F02F108479FA300FD107C99AE04C1AD
                        Malicious:false
                        Preview:.....|Q...(..U...".dU.g9.:......n.uVF....yt~.....=....n:h.|.N.I>..]5..5_...........H.]..E.0S.F....VX9.=.1*r..[W...G...NPJ.R..-4.&vx.#..M.P..uS.x..tMB...[.......JA7..L...44.CU.MP.y.....$%6.4......k....3.)..cN.j............b$...ci...:V...Q.e..h..a....<9..L....&..)..Y....qe.`..xM+.6.......x.>..G....8.Ev.E.@.U.D.D.......^...6._..@...z.......A..."<..iR.Y.'....N.....f.6.?-{~D.k.....T......7..2.t..e{..{A..-.F........5...^..1M.4..w3...P.....b..]..4..^..(..B..B...^..YU......s..~j.c....ChZ...U.!..>s...... .....M9..V......b?..a,..~...>%..>....a.}.l.0....`......AZ./.l"......4...t.vd6[e./.6...?j..H.....U.k)...g..8......!<.!.........jl....R..k....z. .~P..,...,..0.'.G..jhR..9H..A...2.O..z.4pg-.nw.j....H/._y"...~./7........&.<...jQ`..m1.....HH...u.2..<.`.)^.S...9..r...N$....X..n..3...b.......*...gs.#.D.a|.U....|...\....)w.......*...I.P.).....PR%.xf.Vg.....Od>..T...f.O!..l...wl.?........OE..7.*d.....1* O....O.X.&kM".V6Za].".......[N.......f.y...Q$.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):2148944
                        Entropy (8bit):5.517502618397121
                        Encrypted:false
                        SSDEEP:12288:aQs1bGIiB3dLiyrris2UZh+RPbVB5nHxna:ap1zW3dOyHZZ4/B5nRa
                        MD5:69420026FF1010CC4A74422C7EC0B367
                        SHA1:0E1982B91EE5446410538590E5B6DA0062FC39BC
                        SHA-256:3E0C15C740A2FC325BAD3195F272C9B5CA86389D6E23B25B966830DA0544A1D5
                        SHA-512:234DD846CFF9B2F915109D9A3F53234008F5E8080BE4E85748975B8DE656D78346E4BD74C857B705E2F3B94159B21FAFDA890D1F30465258A8B75D31B8FB60E5
                        Malicious:false
                        Preview:.B.y.i.....0.Uf...G.....F....(.o.gH... ..j58"e#..X.Y+.......s,lL....K.^q..>.zR.^...[0....?...s!D.l..w...(..5".P...6.........*."...o%.K.e.F.8._(.....Q......z.9......B....W..6R.'....wV.b..F...........I.3o4.....Y..ia.s.m.....b..#G.:V.WR..^.....e.do.].w2"@Q5.o.}.Y.....3......."l....k.rx....r.........#..x.....e.}W6..6|(....j.N.*E&h..+.....LF!0.r..f?...E..x.dK.....T...kx.=*.I..P.H.R..R.s..G...B5.yI...m.j..9w.._>...R..E..T)..7..."(}q..:..m..a.M.Eo...%.QW. ...b.bzQ;....@iM.W..<.A..O&..J..%L(...i...?..!M..e...)..`..n48e..6..L.l[%.1[`.9.9(....r/.?.b...*.cE.k......j...t..D...HD..t(RfaYEU...R...={y.k.@G}......W..F?"I..-..P&........P.)...4.$2/,.C....!.4...b.c.1.u.......r.T&..:0&.#.4l^...t..i.h.a.;t..w...4....x.......l.9..XjQm)V.`.[I.S...67..8.......u.p.N%...V.{.....:M...?..|..6....Y.#..Yp.".....\0.-%&........U.........K]....[...VV...H...r.k...7.....4.g../...l....>fu.^`....A.W{h..j.x..".\.Xie...1r+.y4...?.nG8....`K.K.>.b..0.yA.:29S.j...8].D<9!..i`.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.16540649208618013
                        Encrypted:false
                        SSDEEP:768:FJLuLR1dDEBmHl4iDopGwsCuXH8a+ciyJP5P:FJLoR1dDEBmHlbDul7u38a+ciy
                        MD5:8F48253B7FA7631E21DD86879805E645
                        SHA1:3896F2018579A8089D54B5E8C47F1CAC5311C252
                        SHA-256:D1531C1E6DE8E75C919D0CD3C0B9BA15754F093A55B97F8364DCC41FD8BD7A70
                        SHA-512:2850689D1A5896BA817BB881720517BD3E3E1CE00F9504A950AA4BECB0299CEAE9942CD4A8CA3135038909D023AB334BD6608C1A22E8DAC5074CC1A41398F192
                        Malicious:false
                        Preview:.I..........@..@.....|..................<............|..................C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@..........................................#.................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):2.8567097867775586
                        Encrypted:false
                        SSDEEP:6144:myKt2roQ2b7lfkzRxBr0OA1ehcB7VoBgYEL0InCK:pu8/2Vk3BrtvhcNVo
                        MD5:895DBBA1D9DDB01477AC19B1F80E25C6
                        SHA1:4DDAFD03C957D08719DB79092002F38FA954354F
                        SHA-256:E3D0F4AD7D134AA3FF64E15CB578E17D57A5918472ABCC09F97D6520F7BBD0AF
                        SHA-512:48DF758667E7541E127B5DCF6A8645AAAE40E83C63D9A8EECFBF075ECD2E7CA214D0969F787B3C74EF4B82C6FEA9757862D64C206E6ADA705556292B5D77DCE6
                        Malicious:false
                        Preview:;..?v3k.Azl.3lP).......c..P.W"...`%.|~..le...6..W"w._..S.....X.o.....|.NwJ.!..}qf.I."..m.l...W.....].....4r8....[b.t........A..~9....y7..#;......!.M>.T........3..f36*O..aZR-..C..X.2.5.O..?h............# ...T.. ..E.].R./.s..P.Q.K,.<m.F.C.W.;........8k..p=../.}...@~k..v...,...d...lokE...muV...5."..d9Y.W..|.:..>,o}.3..P%.O2i........>.*Nt..z ...`$r......\.O..!.7.\/...80cx._.N.p..........F....3]......._....{.,p.V.;...gL6....x.b..y.]..p@gN.x......`.....E..y\..4......6.s..{`.+0.!....C..U]..O.A....8:.E.....;3..%.s ..2.~....).%.x.k.?.?.A}..VA'....wn..cB.K.{SO..$b;.L...\........g1$s[@.0...4...$..J.....O..<.C.j-... .&t*,N...i..C!. .C....X.jx!....}4....T.(\....(.u.......=.#.D;...2.F.%yLX.;.....|.`..;y.$&_...q..&a.....M.?....GP.C4JTJFx6O........C..>/q.A.$*..%..0.^..,...o..Ic...S=-.."9.#9..b.....*..0...a...a..Z.R7...[_i.B.W4...[.b. .%..S.......J'y..'.5e.zN....s....u.`}=..4.~;P.i..z.33;..8S...N1...8.b}6"rt6....L.~..tE.5O.O...@..T..5.....|Z..i.Afd....~f.E'..nQ..)Zw
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311232
                        Entropy (8bit):2.8595194022158608
                        Encrypted:false
                        SSDEEP:6144:myKt2roQ2b7lfkzRxBr0OA1ehcB7VoBgYEL0InCK6:pu8/2Vk3BrtvhcNVoR
                        MD5:6EDAAFFD7798522BA518420C12106868
                        SHA1:EAAE5571455CED3CA175094B8F918887DB0073C5
                        SHA-256:6DE7E46F1653671C537911B64ECAA61A249EE57EF634C60C0A98A78BBACB9B1D
                        SHA-512:513A5BF2841D9420E7A957495C1CB4146D39555039EEDE652C9B5F2570D6A4C40AB05A1C91C66A4CE22875F1737868222B98FB52660DAE9C5F5A2E0EAA45F1C5
                        Malicious:false
                        Preview:;..?v3k.Azl.3lP).......c..P.W"...`%.|~..le...6..W"w._..S.....X.o.....|.NwJ.!..}qf.I."..m.l...W.....].....4r8....[b.t........A..~9....y7..#;......!.M>.T........3..f36*O..aZR-..C..X.2.5.O..?h............# ...T.. ..E.].R./.s..P.Q.K,.<m.F.C.W.;........8k..p=../.}...@~k..v...,...d...lokE...muV...5."..d9Y.W..|.:..>,o}.3..P%.O2i........>.*Nt..z ...`$r......\.O..!.7.\/...80cx._.N.p..........F....3]......._....{.,p.V.;...gL6....x.b..y.]..p@gN.x......`.....E..y\..4......6.s..{`.+0.!....C..U]..O.A....8:.E.....;3..%.s ..2.~....).%.x.k.?.?.A}..VA'....wn..cB.K.{SO..$b;.L...\........g1$s[@.0...4...$..J.....O..<.C.j-... .&t*,N...i..C!. .C....X.jx!....}4....T.(\....(.u.......=.#.D;...2.F.%yLX.;.....|.`..;y.$&_...q..&a.....M.?....GP.C4JTJFx6O........C..>/q.A.$*..%..0.^..,...o..Ic...S=-.."9.#9..b.....*..0...a...a..Z.R7...[_i.B.W4...[.b. .%..S.......J'y..'.5e.zN....s....u.`}=..4.~;P.i..z.33;..8S...N1...8.b}6"rt6....L.~..tE.5O.O...@..T..5.....|Z..i.Afd....~f.E'..nQ..)Zw
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:1045BFD216AE1AE480DD0EF626F5FF39
                        SHA1:377E869BC123602E9B568816B76BE600ED03DBD0
                        SHA-256:439292E489A0A35E4A3A0FE304EA1A680337243FA53B135AA9310881E1D7E078
                        SHA-512:F9F8FCC23FC084AF69D7C9ABB0EF72C4684AC8DDF7FA6B2028E2F19FD67435F28534C0CF5B17453DFE352437C777D6F71CFE1D6AD3542AD9D636263400908FD2
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311232
                        Entropy (8bit):1.8710104560845997
                        Encrypted:false
                        SSDEEP:6144:k57SxwxUA5+Erb//zOAH/OShBa+FeEML58i:k5Fxb+GacfeEMLJ
                        MD5:03990B85A7D00BA66118F273656E1188
                        SHA1:0927428BD9CBC740C1BC0BEBE68040725779D80F
                        SHA-256:D6383A374FC7158ED611CB1E21471FF2866F954EE88A4168CED88922348F2919
                        SHA-512:33A61A8D05F0BB11765B8D17B07DB6543BAE4DC33A6B2B55FEA87E3911373D6D674575BC47CB33DED8DBB49BB36859A57F67FBB6943CB2D90094426EA7888403
                        Malicious:false
                        Preview::.X...4..%u.H.>..~..y..,..~.XPm..0b.rV.v.fw..r.'.Y...]..D.0.Z..u.&........T..kE..v.A./D.W. X..._~.~..'....k.....J....u:n..].2N\.........WB...i.1....G.%..;E!..l.t..j../.5F../.D..z(T`.1N...7A..0./.../..j.m.O....c....<.IU.].y.9.....Q?K.n.j.@.m.ngq.0*A.C..DU."......a..a..E[...<...._....*+.20$..mJ....}."].S..Z=..'dF..I....rq.6...L"o..7..J.x....b.....EB.w.;.D..b.......Bj$qa.z..}..N......"...[AB7.....oy.....2I.b...A..M0..<s.|.......Z...6y.(.lV..^j.<l.4a.H....}.[X..J.B..{.p.Ir.oHq,.tT..H.....%.B4;....H..f..GQ.S..[I]..}.m_..?t......I....S[..K.....T.hU%Jg......*M.w`.eJ..Y....3....WE..(.Q...........}$.....}b{.U.}..f.4(.].....^6....%8'./...x.....Rh................-.........}@2....2....."K".c?O.........~.....0D_E...`......N....w......2.U.m..o.P...............K..,.9.@....)H+4.....D..|*....G..{.tc!.f..#.w...Y...y.O....$...............b..../;3T.a....Ir.I...]8...5q..o...)O..&..........\..Wu.qd....u...........@sL....W...).ZW..r.\{.\!.#..]
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:1045BFD216AE1AE480DD0EF626F5FF39
                        SHA1:377E869BC123602E9B568816B76BE600ED03DBD0
                        SHA-256:439292E489A0A35E4A3A0FE304EA1A680337243FA53B135AA9310881E1D7E078
                        SHA-512:F9F8FCC23FC084AF69D7C9ABB0EF72C4684AC8DDF7FA6B2028E2F19FD67435F28534C0CF5B17453DFE352437C777D6F71CFE1D6AD3542AD9D636263400908FD2
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311232
                        Entropy (8bit):1.8714133532582655
                        Encrypted:false
                        SSDEEP:3072:lA+/3TpiDFZtfUgwbMqOyEUfyl+sQR3qY9bCO5VXGTS6iaH06bvEZhZE8QCVdOk5:jPFiBrf6dOw6UJa0sIbmv892kgf+6toZ
                        MD5:A7C7E2D17D6DDFD3EA424D7A217147E7
                        SHA1:98F40A2DD3E6D7C94976085446F031148F20E25A
                        SHA-256:15974C56C08508F4CAE4E8B00B8BF8BF8F2E2AC41CEDEF0238FBABD79A73564A
                        SHA-512:11DBD2B24AA480A31BABDE05D63C59251EED2E44C88BE85F250F643A1EFAA9EC2EEABEE487B854E8A6F8A95F473803D24F22D93433E1125423311812248F7FE1
                        Malicious:false
                        Preview:..+..g.............g...^.R....I..#c....o.....E...@.......y..8V..8.zV*{....|j.g.cr#.......{....f........5^.!..)6..5N.N...m.,._d...Mb{........._{...To&.3_..o....<.$|..^"....T..N..et....,......k.......W6620;.2Y......<..?...1.ai.&l,..6..t.....$.......f...K..[(..<.f...3J....yHe#.^"..Y..v..1.=(..B..O.)U..M".R].....i....2.{..%j.J...w.O.....5.*....K..U-...!..7-./.WS.ko.N..].aC*..%{rj...K...\N.K...^5*,.......A8.oSW..*.(..uU....\...)F.H.t.E...i..P...Q.......N;P.3....5b.8p.,......9s...}....S.x)m.D..~.I.6 . ...O..,..%.....7r....@f.Tw...g.7...q...h.$.ph...&;..s...U.+.O..~.b.......`..->......!aS.5D.Q..".T....~T.&.,C.e..O. ./|8..f8Pq&..a.a..A.......}ra.........q$.".qu....l.....mx...5...0/......B8.Q.y...\..bO...z...Z......o.....@1..vsAjq.&.I.(&..<,{..N.O5..7........!.x.y.o. ".Y.z8.....X....\.5.Yg.0.U..h.....P..%.a.-S..;.....@.....c..j`...Xv..-|.Z..u...2..E.z.zH.N.tGD$Ly.D...P>s.U_.........pwF....... !......}->.:..J..<..QVl...~.`7....9...d.....{m.......tu..z7C`....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1310720
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:1045BFD216AE1AE480DD0EF626F5FF39
                        SHA1:377E869BC123602E9B568816B76BE600ED03DBD0
                        SHA-256:439292E489A0A35E4A3A0FE304EA1A680337243FA53B135AA9310881E1D7E078
                        SHA-512:F9F8FCC23FC084AF69D7C9ABB0EF72C4684AC8DDF7FA6B2028E2F19FD67435F28534C0CF5B17453DFE352437C777D6F71CFE1D6AD3542AD9D636263400908FD2
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1311232
                        Entropy (8bit):1.8712886684385146
                        Encrypted:false
                        SSDEEP:6144:TZPwg+mGyy1CwOEGZAXpOtoRve5a3qAqy208puqY0:T90xtuZGIoRv+7y5Vd0
                        MD5:DD8F3598E4FC307C4DE44911F4148AA0
                        SHA1:10FDA4CDE9AAD3016601BB76B4847955CB585D34
                        SHA-256:FAB7E8D77EBECA217328D857702175DDCC67C84998B7F2A8A480E386627B64B6
                        SHA-512:F06D858A03EAB16611B107306F025EAB81B5CCFDBDE6BF72E6CBF3E7EA5D0D45BF686A86936067CD6DDF3F5C5A1FE5D1E12F7C14C97BB80B9D3453BF141221E1
                        Malicious:false
                        Preview:.p....'.;.S.....3....v..z...;...|R..g..P.p].D7..h...~.S....^.t..LM.8#g..^.VR......*..D./L;Axm.!..s..P.^.7.......p].$.g....`.o...@T....._....w.....1.0!T../Z.Es.m~t.d+...XTnx... ...\..A.........+4/.tt.6N.3...>..T}:)..e.....Z/.....# ..d.F..{..O.......M..B.p3=.4.zm..'.be'B#/-.R+.m...:.K.\.....F....H;........wg.t.qd..RAn..d...~"}.8..x....}#...e.....t.B..5.h....A......5....Im...,@..D../...'..z..~.....I.Q.......J.r..Ol..Z.2.{.K.+.Ns....b..L.]...... ..GM...;F..u..S.Z.U.vL.%....<.1..wg{n.94..7RA}.-..o...........\2..:..f.w.Z.`....[. `.$Ct4..R.._s....K..g..6.o..$+, Jw...w...tx...;.......`qa.4.C55mW.....5n)(..P=...zT*.....:...I....E_F.7.'.'....%..e]....)gp9L?.?/......i%..4....eq......{....y.Y-....k.DR...X...$r..R.$.....@..a........G...=.....O..`..`J!...W......SD.q].o.Q(A<P.@;:<..,_).<9....@...8.u............FV....>.(V.......8... ...,+. .x.-.0.....i..Lc... ....(...!Aim$.}G. ]J...5&M:.a..*....a.9.O.B.....3.t..n.....,...6.H..&...<S.j..;!C.Y.B...f.#.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:Extensible storage engine DataBase, version 0x620, checksum 0x1035ec82, page size 16384, DirtyShutdown, Windows version 10.0
                        Category:dropped
                        Size (bytes):786432
                        Entropy (8bit):0.14017016676795194
                        Encrypted:false
                        SSDEEP:192:CC6nC62XWppQ0Tt2pRZyThY5/4MSP8+AWppQ0Tt2pRZyThY5/4m5f:CCSCXW0StseCJ4MRW0StseCJ4If
                        MD5:D2D97DDD644CDDA3FE7AA7B15A63EA90
                        SHA1:C35EE28432DACCF607134D6CF9502E4E8A3919BE
                        SHA-256:E5544377F69D6C700A33454FA9A4A9777D750FB0E0A185AA8EBC93315916C597
                        SHA-512:EFBCDC792E3958BFD8DFD60EA9604C3D0E19F83FAE4C68322439F26F58D11A963DE5113203F8912891823041716D9CBB2FCF9A88635426989F37106467FE068B
                        Malicious:false
                        Preview:.5.... .......-................|...........................................|!.h....................................|..........................................................................................................eJ......n....@...................................................................................................... ............|...................................................................................................................................................................................................|...................................[.l.....|-..................{w0.....|a..........................#......h.......................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):16777216
                        Entropy (8bit):1.9996377881997445
                        Encrypted:false
                        SSDEEP:98304:fHc2SHsR8kfWX6/EEJrcf8oZBzYS4lH6:l7fWX6/EEJrcf8oZSS4Q
                        MD5:344890440C3039BD7857486C1D195BB7
                        SHA1:ECF10B5FC4D423B5376A97A6B811BFF39CD7A087
                        SHA-256:C121AA1BC51911CF98B9280A0A7DD7B63D341CEB7473783115E2229865833DCE
                        SHA-512:55587F20F021CAAF8426740A7A687C53E077A3F5FF3107DD346CE6657EF0B4BB8D0BDC07D7EF2FF4495A43BF849AACADB0A9AB058A61C41731B0970F141D60F3
                        Malicious:false
                        Preview:.....S..+..+-\~.p.F..M.m'{....^.c<..A._.2..;..5...*. >.>Y....}._.....6"C.3.--.F...r...^J(...,cgq.c..K.......N........./.....iI..X..a.!.^E..........3...I...$..`!....D.\x.?.nl.E.hm........#g.7..s...CF..5Wp...[.......w..r.s!.0..I/z....{...30..C.........6.w%.......|............$.UF rw.]..R..>R.H...JX........L...IQ\.p..}...Z.......D.../...q4..y.....S.7......?.....n|.&.......M.Cg.k..6_&.H..%%.b...Gz...x4.....,-...q:...3HC6S...}..:L!....x...C;...D.?..]....^</'.G..=:........8SM.l...Hx.....DR.....<G.W...5i..Z#bBh'.T!.....fm......T../._...qf..(...x.b..S..O.....o_..R.....7.%.{.-,....k@.T..S.D-.wp..q...|.K.fT..E.}.#f]D..E..&..J;....)....xS..x...T.h.-..<.....r...:...,....X@..{..H.Dsk.i...j`.2.......f,..~..O.`.. #v.....J.f..-.+h..(.)U..Q.c<..M4..S..!.....>.c.+;4@..QmE$.E....1.3.....E..s...j...h/.s...X_...U..G..co.d....$.LHx..U......KEP.%.|..y.3J.......'o.....a...>..gUG...K.1.....L.<O?.]h.....CB.n.....9....I.#..UH...^.B..X.{........ .CG%...)..).7.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):84068344
                        Entropy (8bit):7.99737624482664
                        Encrypted:true
                        SSDEEP:1572864:WgxWQPdrI301Ahdr95wKilp3zqoAmxThz0BYQrQ747IAL3Bmp:WuWQFrY06z9PUpjqb2OYE+4fmp
                        MD5:32108383766B562B5A278861B9733D44
                        SHA1:04C3FB4FDB565035B3A430F865FEF01C066B1867
                        SHA-256:EC9B64DD2EC7BFCC052DD4004B9818484DCC4FAA5AF1DE473E0400AF1CAFD777
                        SHA-512:9C27F16D06E2F19190D2883D161C34497532DE8DDE64DF9DCC0E4C414D10AFE879F8AFC79C03083B8A199937A43EEACECA00F69FC1E1CEB51E75296B4537FA24
                        Malicious:true
                        Preview:...:..^...m|........W..}.F.+.0...(..iQ...k...P2C+2Q..Q".0....e.}x...C.c.~......f6..A<.O...p.Y..o.nv.|....Nm....7^.`......B...B.g^)...)D}|..<..6w...At..|..2n.&$.qH#.+H.........|s........H=.....e.I.....v......b.Q .aEr..}..M.....`*...0.ez>O)......ES..c..M....V..~.Yw$SlTX...gj.|a.M...@..@.L...}.=........3e.z,....!0r4:}..$...3...t...6.d.Pz..(.....i..1.b..?.r.~...y.......q..l...x.).sL......l9..]....$. .....3..u.A........R.;S....EK \..J...Ii;9(...sE.T.M./+.~...q.e_.G~M...]U....Er.....v......'S~Fho.@.......Y.B......r.L..H..(e1.iG&....!.c."..`..*.cf]b....v".:...D.P......4}+..`..R..j.Xf{......E.q,.W.bS..."..?\.....h.r.......\....r..t<L....VM.*.?B......zo&9....PO...h.h].j....;n."b.ugtB4~....V9..."....<.......w.u.A.O.,8t.D.x..'7.UZ^d~.O)....l./_.%..k....\..{=..I5..qK3.g....{..d..-g9.../.B.V3...-E.i|[.!%E..B.r..m....`.Q.1....cZ...ZEuu...C...R.P....,W.[R..3.D....N..%.....<.M1h.]..'....f...7#...*FG.......B...^;.`jC".nA`....L..ds......O$.br.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):68955736
                        Entropy (8bit):7.99758929668477
                        Encrypted:true
                        SSDEEP:1572864:LFXdwLL8wkPi0N1AvxHwaAzCYORK6FDksTdNrX6k4CGf:FdwUfq0N1ApyCHptksdNrX6k43f
                        MD5:278B2FBB0AAFA379C3CB89DB89196655
                        SHA1:5441D42295FF491CF9BA4035193735EBA01E90E5
                        SHA-256:82758E1A69526CF1AAABC00B486E1EBE3CA3CCE8EBA1C6C5F91D1B2FB27973B8
                        SHA-512:25FF5A27C6397DBFF3483B94210AAD957EF3D8506EF016512880532E16FB6C841F51120CF159F13DD4B22CD7CDCEDE85255BED742870DE88CDD5BDA0A66B5BD0
                        Malicious:true
                        Preview:.........?!n..gI.;..G.a....2L5D...N....:....g.G.32......e..`...x......P.......N.Q.X......B8..1.......P./qx.6s..;.......|."t.....;. ...v%..OX..H.D..)I."..L9.......ik...}..]...p+.......BUP....9nr..FX.._.....@..^........mO.(.0.e~.f\...HW.....x.x..k...u.Z.Z...wl_ .b..nQ..........aN..k'..s....N.-..Y\.|c6....FXwj{.&.YJ.=..l]I;...[.M.\........:R...l...pHD.....T.al..^`..3.G..c....H.%......p.zRf.M...........O..........*.o.....7...h......1...*^}m+W.[....S;.m.0.oh9.MnS..3..........*.aW..9.W..0Z)..u.*...D.Z.M.e.j..r&..V.~jE.ql.....<...<.....V$..3..H} !Wv.N.r......c.|DIq...h..0.*.U....)..L..,].2G..-*...z....!U).D...J...%....TC|.&...{h..SIwC.@.Q.2.8..&;.9..."Xi..z.....C...#]...Q....J.."d..<9dv*!..K..&5._f.'........L.l'.;uZ...|K...#."@z.j...w...S@. > ..e.....r%G...,.1{...6.(...Y....[....{..72...Q......:o...d).:p5.pl'.t-.^,....i.A..o..?.....+.../p}V...MJ!A..9X.. ...._......i.|..........M.(h...a...l......<}-..c..#k..M.H.F;l.......u..h......|.qS5.%.m...w
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6672464
                        Entropy (8bit):7.999460045702652
                        Encrypted:true
                        SSDEEP:98304:dcGogvgsBUTQmgQaHG4lIy/1ALL24ZBVJN1pzsiag095to7ZKqtucbo7Gfs1SJ/X:eGxg/32G4lQf2gVNHzb095yVTC1602
                        MD5:B0F8467522242FAB21BC46494EC59E12
                        SHA1:C8D1A045445E9D092851BC38EA8A8E3D1732C372
                        SHA-256:935C225CEF426BAA307BDBF196EE09C6AF0B63119C583AEB645EAFC075A4C426
                        SHA-512:046016665540EB158429365DD291FD344492C00C5789B78EB35BD24C1AEDC20A0A7D75E3280B4BA978938B5F715FB21CBE0D1AD434D42E6FD06B1CE6CB36961B
                        Malicious:true
                        Preview:..9.h._.u<.S5.".T..=.:h[.5.V...~p..*........Z......L....C.........g)X.g...y.K..#~.!..3..d...............+.....|uJ|...m. .C...[.........co......]k.p........&.)4{...DW.,kX>.d.H..S{.......226..>i..d.......yc."(E.g......,...L...c.;.Z...8..0*na.=.h........1..:r(.H.?N..ng...p$VS?.RF..4..5.......o..%0M..}.\......+~[h....Y..8v.2..F....6.2)..ug....g..8...+KWo....(mb..=h.........eD..#exFO<%.X.4.~X.ga"od.$.4. .....wt3~..]]UX.1..{lmz..C)..I..@wu..+.?.|.)#.(.........8.p.2.D..Bk'`.9v.I.....b......f9yn.Ig.1..*T.t'w,2e.....x.u.. ..[.;......:......&.p..e....V2!..[..F=|..B.f..p... g.a.[7...Dd.3f8.z.Go...n........-..;CP...l.h..N.7..H..c.g..Z....._.._..h.!*...w..=.?...4d<C..<*... .#..B/...4u4.M. \.......[...k..yq.."..@&40..7.Ap..D..E>/...eK....-.5&....j..6..V..H.4.'...D..\G..)@..-H...E.n|k..i.B8".....G....c.*..t...mQ.. ...5.E1..>.<..hC..fz...B......Bw$.$..#c..:...J.....A..Ex1y..gR....lZ...aH...r.nj.Lr....co..}..<...-.W.9.....RC$...C.....Q.qAFVz..n.n@..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1098232
                        Entropy (8bit):7.998725688245956
                        Encrypted:true
                        SSDEEP:24576:YZ42l6gOw/HoqM4POQ1q+cbor3EhoMHEg7CsxrEgA1dxsf0:Ymtg7H64GKibWEZHP7pyFdxK0
                        MD5:DD71FB8E4E7E9996BBAA8D44C0D4A302
                        SHA1:A70A2E56E418383EB80A32F781B0C72D7488BF86
                        SHA-256:0F9C48ABCC1471A8F3D424775B1DD77B5F9C3D00FF79B9B987F2CF2C046B7176
                        SHA-512:CAC61D576A93A6558C5708D4AAC842E1EBAAD83E1F72DB8A2163A8C97DDB402529FD0019C27E143C4EEF5492FF58D90103894F1B41A005595D5C50B13A6CBD8E
                        Malicious:true
                        Preview:...je...i..N.JG..m.....l..{..X.w*O.}.W....Z..H:.2......a@..I.I2(?M_.M....-?.-..2t....(I..=..&n..S.=.9..H.....j...6.b.....=.2.}...@.g.0c..O.r....p.,w1+....-@..4.a".G.M.+.!.D..uc.k.....'`.j{W.&..R....2..e..HJ.x.HPz#...JZ...V-....TX....B.....FMW...u...V>.,.R....q..E...k...C........*1QP....+..c....r.U.l....8D._Y.y ...v?...o.\D...Y..r....i...c...Z=...S..x....yg.T..6....b.n.....U.c....Y.n...=.\/?Xc.._..G.4.........&Hi.B.I.G../Pg.>}jC..{3....e.L....k.X..s....k7..._.....d.C(......uc.P0..4:80P..0....]..5.=O&..W ....3...._..v.t.W..Pr.+:.....0W...v.W.Z.3...^s.\....V..l...nBv.z...R...[.k....NY1.6.&.9..WR/~...B...%...\.......\...l....P..F|*p.....d.VZ.u..$.N..ZY..2n..-P.Z...b........""...+.0..a.....n,..w..y...3...^.EC.D...q..M..3.....8[...b..Sr...T}~V..I./4..]..Q..(...o..:...j................=.......p.Y.)..c...W... .qM.v..bN.)...7.}.g..........(.A..q........N....p..s...h...ry:.n........v~s#.k..iw.l..E..._..>......PG&.X.iP....O..eF.5..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):41554408
                        Entropy (8bit):7.997655833868397
                        Encrypted:true
                        SSDEEP:786432:dgEI2dkTY6SR1eKeMPHs7HOnX8AA1LoNtGoh7l76OVO7PRwlqM4zu6XuseXX8aS:dgEI2dCnMPHsTc8rGNtGot1/VuPRwMMk
                        MD5:AD5905DE2710955C5137606416F876FB
                        SHA1:8EF23B317C83A87D1E4997333EB6C46D46785CEA
                        SHA-256:39F919663789B99F02EF98CF12608BBE538B6F3A57B7A907D6A4EB919FD342B5
                        SHA-512:C84381E1588084FEE2BC2D1AE62CF225F776285B1B395DC1FBD8AB61EE6F8CE34C0C94C821DD227F5CE2B574A09C7D23C313A86ED3CD39885395DC48E29092FB
                        Malicious:true
                        Preview::...{........9...k.Y..&.X.b5&.....p..u/.3.Xb...B;.!u....>.....L......p..z1v.q...B.}X.z.P ....c..~e..\..^...%...D.m...g.dR!.` .@a...L.fyN{...nD&WB.."J..6;7.x.=.p.~...t.~.......!.._..!......0.......Tr.!.,..]#........NUv9f..3.m.3.,.kkfg_n.m....U.]x&|Y5.{...1.[.Qbd..BL.&.x(...yKSB....t......T`.y:.?.T'.o..q..mH#I..8FE.........h%......B.]...~7"...../.....=.......t.p..M%.0..+...tDx.D...x..:.G....r"A.@Q...Z....!..R4.CS...S.....(.A..u..S..........=Jn....=xR....m..Q!..%>.9k-.K...c.....*...|r....qb.d:.CA..$..>.i..c......`..o%\k.V....&n....t..aL!...*...Q...iKM....qk..2B..J......^.z.%7G.S.......}..}..>......T.j..~...6&n.,.3..f...:.+....a.JwI...|.m..~3.L'.6....W\3......i....2Qx0kH..K,.'nbrm..b..... ...:..hF_....5..l.e...~q..-}0h...+W4.....nR..d..Q..$...#........Pz".<.~T...lG#.k:..C........g..8P.v3.~.4I.o<SZ.a6.......}N..L....Ra.d.2...R......)...y<\.Z.wO....{5.3....~.+... ..A"../...i......~E..GQ....4%...b.D.t.:U...b...z.|.s....g.;.j(....yG?.....o..6
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):42694232
                        Entropy (8bit):7.997584954215088
                        Encrypted:true
                        SSDEEP:786432:rFSlJNYfD8X3/UQL/cQqvTZ7mfucYxPCGLof06m+afiGeyFkTby:rFSbNYs/Ttq7InGE1wfiJPTm
                        MD5:42862DBFB7A8219F6BC6CBE0FCBEB770
                        SHA1:B8870A37F743C75E24162A19F7254260F59B9464
                        SHA-256:FD6139A74A3A9B70735251EB47AC9ADC259CEFF937510E7F037223C94569B38F
                        SHA-512:BD1989B2F85846FC305548E7E1A9991158D2B8CC8A045FED38DEFCC16BC6EDFED3F1DC7EDFE1AEF7F29446462410DEA1DDF0DD4EEF0AEB388E3B847C914C7591
                        Malicious:true
                        Preview:.UF..._+...K..^x|.c...\.._.......m....B..5.K..m."....<..{..P.X7.7|k../..M..gPPP...!..U..G.^.).a..\yk.Mq...#B.a..2.|.[.;.....]Y'.k....Z.]..........t...}../...Z.sD4.......C......+:Oo..=:.c..#Ke..omN.\Go...(.}i.n..o.@18".....).V-.....r.t.q...L.4..T......~.$2.*..}^........;.I.ro....=ly..3.%.2..."Y4/....A.N..J....[7.V..#.m....J..w1..x......@Z..B;<<..\..>.O.#.(...w.'.....Ts...g...D.B.x...J........L.....>.?7*..Z.T....Nz..*..,.6J*a!#T.$Z.U....!.\.l...D..4.........Q....88.;p........6...gO=....S....".._lq"vR....a.}...Q.*wfq.....t.tpk.C.\Z..P...!2...n....+.70...afP.....?O P$.H....c.,(S.|..2Pt...(.f.....G..-.. .f..C..Q.......*.......s.M...[....>.+.vw...H..V.-D..[...^..E4....../<.sp..b.x...+.?.EP>..)..E..I.wWy...H...)B.v|JTc.j.U.Q.;...U.........B..P@.7]..^`SW*..1D.l...h@B.......R..h.D..uY..=..c.*E..d^......z...q.....T.....z.. z.;-.."../.q..35MQ............t..ti.KM.3...L..;+.w.I...>.....>kY...,2$8.-...#.!..D...Hi\.&.K^.|...:.1.....!.!.^...Vi".*!...F54.F.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2410600
                        Entropy (8bit):7.995902821192981
                        Encrypted:true
                        SSDEEP:49152:08MWT9MWEXPGG2ep4f0OHuM89gBRIdx+py4V:FR0fGdtHagn6YpyC
                        MD5:34B528E2F372B1910C43CF0A2B5ED029
                        SHA1:2A41ED0A0E42D53AD5486A193AA0AC720AB81E91
                        SHA-256:005D822CB63516AE726224C05ACF20D1B73C99CC1028271287B573DB528BFA28
                        SHA-512:F052FC548563C5DFFCBCAC41BD8461B0C02891690FDEB5221EC4AB24D6AEC3DAFE5B429281008BB1255960BCC4867253470B1CF349B9B7A3FB213C25ECA1BD48
                        Malicious:true
                        Preview:[.....Hw7B...cl.g...?..6...W..,..9...0E..eFuA..tT.u......n7...@7(...kt....* *........hU..Eh!..S.Q..p...\@......*..t.6..fG#..._V...].q....@.[1..."..Q.R.M.._u.rd:.b=.[.Z.^...yp.Nq'....8..}.%T.....G.&.1.=.Qoz.)...Z...L...FN..Iy.[`.s....".....I.)p.\,..g.R..psY.\K.N].f.4..7.............H...In.=O.....6,.hw4.....V...*..h.s.....k..Cd|.....c..^...0)..J.......YQf.qY.v.-....^....k..4S.T......U2......_.1r.(~O8...a.......;(....m...o..'W.......B.i...".j.}...u.Y...WI.B..9.......#.GZ5......UM.x..<p...v..*.]....:$QQS.jDbZD..sh.m..[...u$..Z..I.W.../Y.......c.3..J...J.y....G...Q31..Fj...8.7..im.{.d..z@.E..}Nu...%.UT..`.p....x....rv!S.. ..8)m^.._g.:....k...5.m..4o).(..VC..!.....*7.t....~.H.Ac4.+7O.?.i..o.....av.>...M...'..^.!.RE..5..;SI..,...........Z..Q.......s...3.& ;w.y~q._l.(q.....%..'...(.q&..H.{.8...*.vp|. ..xu.1cD.1+De....n..5...."*..\T@.'"......wG(x...<.LX|..&...cO..K.....1<Y1.....x.~.X.h.CT..?.<..8.T../.D.......Z>CMt..MbN.h.W..9....F..........o.r2=...*?.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18690416
                        Entropy (8bit):6.4344765683717196
                        Encrypted:false
                        SSDEEP:196608:LOUm0ImFIEjZLGhwP1B6GgImqWFiA26hF/dtPSoLBFYs03kGHpOwrZo4Bs:SvsTP1BksWwA2a3PhoXs
                        MD5:B3A8A69358D235C81D6F3D01F6DFA9F4
                        SHA1:E3A3546D0FFBB1C879C2969F158C772E1BF55C59
                        SHA-256:B9CADF81457F9D0A4E13432AB178CCF1EF854DF9D5D0173F7162BFBE7D5D5817
                        SHA-512:73468CF8A5BCBD7E3EA131876DF112EF5DF91419A7437F898019AD1FD9B3B9B0F6F42F2FE41C38F01C0A05A23E3EB84527F9C984F24BB7652FA358FE1412CD24
                        Malicious:true
                        Preview:...|..I.I|..d1...V..O....EN..M.UBHF..$q..A.I<"L...-\..p...Q%O..spw o...-<......q......XL....yM....Y.r{...qO^2..d.X.xV2........v.6k.2.q#J....Z.....%.ipm.0......J ...T.>..gi....dE..E.e......YY}.C..._.[-..$...B.#..G....gF.l...!Xq-V.{..^...............jo..'^....#...^JkZ...3.ZSA.S.0.?}.#...".X.n.....A&..M9%...t....o..V........tQ..3..ii...!F.lbB.Q......m.V9.T.q...._....Q......0K#..........B...*.bB.@.f.D..)..ba...9...[...#..`.V{`VA..j.c.7...o.0 ..N......Z ...O.<..B.}..v1ab./0....`G..'...p...,z..k|.y.....v/w..V&.q......i......+..g;..N.).......t.Zh|....r.Q..d=p@....u..Cn..Zt)....G......0..PO.t.U.`;..@.94s..v......C..S.....A{j........... .....0.x....".....-.....\(A.Lu<Nq.@.F..L.............`%.".]..o..qp@..Pw......}O..&.i...v.%.n.}Ym..(D"N%...'....0?......E=..W....ta...4.e.{..Cj.w,.=.......@q...Y.e..z.k.h....l8:U..j.....^....l.?.M...y ..PKK...8Y..c..O..y...v..f..1g...+....!.}.Y...c.....J..........Os...?O....o.)..C..G..DV.I.5-...v,.].1.vi..s.,...+
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18690416
                        Entropy (8bit):6.434479067503647
                        Encrypted:false
                        SSDEEP:196608:Vm0ImFIEjZLGhwP1B6GgImqWFiA26hF/dtPSoLBFYs03kGHpOwrZo4Bs:0sTP1BksWwA2a3PhoXs
                        MD5:8FB71711E924ED77179BD19B86AF00CC
                        SHA1:EEB2D46896804384F1C422E067BC024664AF4F6E
                        SHA-256:0BDE5C69AEAB0ABF5BFB92A43E045461E237A7432A14F182E859274B413D0A2D
                        SHA-512:E75DDE1BFC38775ADB3CBAA2FA2D58907780A984FEBDF31912DDF563170B2E8148E902E21518DB55C42C8D8BE2EEC0312CF8D329FA058EB0425BF457C6B048BB
                        Malicious:true
                        Preview:.u#.g.[.....GQ?|....|A.D..8.d.v.`..e...D.....CQ.9.;j./..|K.>....#.A....=v.{.e....%.A.{....;....@?..L.... .6R.p..V7.j.~......Z.....a..cz...,.fP..%(.ml...Ma....g........\.+...}.yt;..#.......f.n.l......WP,.~....Co...r._...{?..w.W....G.V.3.....P....:...T..."'ZX^*%0.... .A...Q,.....=z4)..Z..x..a...x..Y..IC..my`....Tu..\..B......t..E......)...u............v...{........P..f4<...8...lBJ...<.....e..K.<@.......w..^%3.@xj....^l.RY?e[..VCZ.]c.Oct...i.n\B.....<..v.Os.o6^....i.....p...k2..{0F..l.A..(.9.v.....v..B.....I...=.x\+.\.#....H..S|..[....B.F..C/.....J.d.PxgB..k..+i..:(...(.....EClx.F.J.d..&q..%Q......$....J.&C.X...K?.+....$J..35...Mu.I..{..Q.k.....n..........6Sh7..C.....fy..*B,y.O.*.x..".........~X...f..|....L4T.2.....x.+.5.Q.z.vd...9.P.......O....f!....d#i.v.T..q.0$-.w.#....h....0...:!7.P..3...|..+..F5#p...G...o.....K..V..J..+..R.|/FU..H.m...k5..B.!G.os.........n......U..8.d..SE..&....SE.4...2.c...\=mV.{9....._c# ..........?.O.\p..g.....@...Q
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):68955736
                        Entropy (8bit):7.997588347754092
                        Encrypted:true
                        SSDEEP:1572864:PFXdwLL8wkPi0N1AvxHwaAzCYORK6FDksTdNrX6k4CGf:JdwUfq0N1ApyCHptksdNrX6k43f
                        MD5:2E192B9B247CC4574E4ACFEB4F305B2E
                        SHA1:6C30949C9C4EB8D0853FF97D637DB4AB296C2945
                        SHA-256:935B32484BBBD7E350E082E8936607FE19CEB87230173CA57EFD7B0DC9BF1B0F
                        SHA-512:23CB554C8C2DB990621A53B9D239152C97966C2D8CD8943A0629E9FCDA8F15B5BF86D8E5E781EBB568BD9CCB7D6CEC0E8A2E1BBD0FAA5FF07C94C35A34C7C9E1
                        Malicious:true
                        Preview:.....-...!#'...5.p.|..;N....).T.G.*...v.,.....T..Z.R.'d.t.M...4.X.I..h.).9.v..d...W0.....C....$.%.TS..I..x......!....} .....v.Z.A......~.|..(sq0.....[..n.v.....8s......;1VO*|....<'..0..G+$.f?.....0..'V..Q.RR^.....?........Li....%.V.lS..>..2.I6..Nb0Qn.Q+..0.~..X..c.."..k.....S....g...e.n..nB.oH.Ub2...2.C.ox.,$....j...".1K.k.I.}....&...>.o0.'...i..=3`#H..m.$....]IB..p...v~.V.x&.q...".??...Nw.. fp..?..4[.{....]..$....1....[......"..}g.F..=.z.3..`k..>.S:.Z.4=.n....i....<.'.;9.....FU4..j"..k.mY.b.&K.A(..W6.W...............y.c.$7.......Z...-k..S,XIQ.O{V"!.......&...7.a..2K..D.6..)..e.../.......Q..9#..6.{Z.6.S`u...........5...a....d..9K.Y.og.c|8>.C^..........j-R.R......6Phx..0...F.k...J.n..}7t..J.%)..R..U.i\..}....%.........L.H#...|..w .o....*....;...&._h...2.v?#y.H#.mx.i..f"P._nj...B.x|.;O..0T.[...M.$3...[..4.9|,#.....>Y..s..........L..k.rl...yd.b...~...D\.I.5.#...........S...,...n.....3..Z..x....).Vy.Ct.d*.%u.T...L...C5o...nI...#X
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1456728
                        Entropy (8bit):7.999216761769341
                        Encrypted:true
                        SSDEEP:24576:OMbfFbr2FAAjl3AOoXmQhWKCHGa64RQL+veBWFLXsqzp9XdWLl/wrRYCGM:NbRr2F1h3A2CWKS64CWeudUYruCGM
                        MD5:20B802A9EA6BE061CCF2DA0C43A42D10
                        SHA1:50E118052A3B284C51CFD912F3F740F8DF90425D
                        SHA-256:5CD069308E07427FDACE0D1C33268A90DFF81077A74DD3AEABBC91394CC5D49D
                        SHA-512:32CCFFFA4BFFB0922AC64C6C464A2FBB1801400360DFA1E285AC7E098C81DD96E2E5DBBD360B90646D82F682F0D0BCB9936157472FEB8F54E0A324018DDF5756
                        Malicious:true
                        Preview:....A.UM.....(...,..Qop.h..-."...M^.....?.J...$?...i1.W.7...R. ...@.vrL..)?.F..r..AN.\]ID..4l.}..O&..O...@.Ag....]H..2}6.W....0.7.Q.j.]....h/....x...........1."...dz=u.TQusF.}0.$`..sx0z{....0,..Z...JBLU.#.........nz._..,.....4.@1...l.5...3.Q.V..V.R;.tL..!......}..B....".....@..g..M........4s"|B...=.2..e..YII.:....V...}..J../..Rr../.q...'.P.8...........`*.J...d.H.WD.+!...^,.A.-..f|....*u.._,.xT.NG..kM...-......#..-.U..i.4.X...b........G4|:../.E~,D...L..!|._...v...b^*...T.y.;...*..6...\{....]].M.=q....<-&...wm!..T.+.....-_....t.$o.q..R.aGi...z..-v!...4.p..S..\5y.....8G...Pft.a....)..D....J...$....>.3...%.$=.9N.. ..q..*dh......q.;....{..*.R.....I...lB..........5Q...K.U.O.r.&..jq..bD;...AK.Zl...x..,.H.P.H.........n.gI.t.m9.....|...l.....iq(y....,..X..7.?.G.x6.[.F......8.}..k.....'...N..4....U.....o..v.v.`.o.....fgJ..I............N.\....1...G..H......!.Y..p.....I.a.W...0X...hIu&..c.....Q..X.m:.....e......'..7.........w.:9.......U.....4S{..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):42694232
                        Entropy (8bit):7.9975849584903544
                        Encrypted:true
                        SSDEEP:786432:hFSlJNYfD8X3/UQL/cQqvTZ7mfucYxPCGLof06m+afiGeyFkTby:hFSbNYs/Ttq7InGE1wfiJPTm
                        MD5:2EB9A0CD8A1FB63BAEEA290D62CDE508
                        SHA1:14AF0AF45A04ED63E025AC2711720234BE541667
                        SHA-256:834CACBBA3ADDD37DCF486353A7AEECDF0651972154BD758A5063810B2FDBC1F
                        SHA-512:29EF4A5B53DE07368CDCFFBEFFF939414EB4DC6E71EBB660EBD0BD0B21C70EE509D342CB2209E84534D1C70546A2E281D2E66FFB67FA4D2F040EB129F5BED808
                        Malicious:true
                        Preview:....x.Q...w.te.....l..'y.t..Tp3......#O...`.D....n1.H~..8}5T.^..3.[8...?T..?q.o..i~....,I.O...H<.~.M.X[.IB...X;.x......mX"p!.B<...._...)..E...8..q..#..q!) .Cb.W.........<m<Xy...B...dj'.r*.4..O.?,...n...Cp.NrSe.H..-.qO.k-g..`..c$...*..d1....O<.._...1.pKz.}d......o..*.K_.^.......|.....wM......`.....8.B......Q6t}.......uD.....^c'..0.M...r.2...o-.#....7.:.z..}...q......a....u..`z.y..K~A....*....8|.i#.<...B.Kg..3^<.....2RbJ..[1...H8R.c...e......a.....G...Fd]n....K0FTI. F........^..:.o1r.7.~;s.a..9.u..K.)R..3.}...@...v.....m.....9Ed.....b...<...6..............CQ.L..u.B..?........~..U..nO...qlJ/.....F..EV..?x*.........v..E.k#.)..U..W.$y.k.9tW.......x.\Y.+...=.8k...rI..^..2..Qod...X'.Y...Fv.R1.".....!?G.J..@q...[...2y.X..{.../........p.....M.l.K..+....a..6Y.[5]l>O...L....@.F...o.^..m.."b..."..O/...0..A..........K=(/....#.F..~.5.+..P......62..C....u..*.....RB4i..mi,......68..)..J....B....X.6E.,$...+.(.<{.....S... I....0..X..M..1. .0..L'...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1385856
                        Entropy (8bit):6.682804683304676
                        Encrypted:false
                        SSDEEP:12288:wC2BdNNcqD/kN/rRld7NE+JqPGhGbzlayZMX3IdP2LZP82qoY8i4mVSIpXc+lwox:N2FaNbdhIl8sP2LZP82qv8mSilHT
                        MD5:3BE76FE7646D5F158930F41F8430DEC5
                        SHA1:211D0054ED85E9D2BE688147F1647ED2734811B2
                        SHA-256:9037DE960AE4F6474ADB8EC88795273086F14556DA8693A0242CE26B77F0EE00
                        SHA-512:33FC7585D0868275682B86ED4CD1CEA65F515C508841CBD662BD1F6F60493B6BE898CCB20ED01CC4715A92591DDDCDF0681EA53B829B319D8C5D7123330FAD77
                        Malicious:true
                        Preview:.u}._.....2?..}.W...9F)..d?....]'#f`&.q|.k.N.D......X2..-mW.R..-G..z5..~..z.2.ku...q\...5...f.xw8..?.......Q.. ....q......X9c..;..o..\..X5E.t>..N.._...3....z.@l..D.x.8;.?.{.a...A..EY...|.........y.@.7d.f....@..^.ZlO.~G...$$>.NEsd3..PQO.....a.d.XB...G...9(.J-...6./<. \.a.J..<I")F..D.|UH.k.2....E.8i50*.(..U.....'..`.^!.*.[}..9.:.k.].p...@.:So.f.j.....dX...`....n.+...w.X..7......{!}....B".......1.!P0>......%...MF..ur.[.#.#.!..L.U..3..S._.-..d.......h2~Y!...W.|W.?...^t,v/.......cdX.PX.@....U...Yi.x.8I.K..l.`.6...#..7...Kfi...a.B.a...x^....e~& ,|.O..0......_]..xg/.....%.).Go...l.n....D..A.T..ZI..Q...l_...kP.=0~...P....t8....{7....j1sBb..(q.3..C.+.........|..e.Z.......3C..(.h/.G..&......d.=....B...SBJ....,'. :..#...K....{s.8S....qm.4..=....c{.....*...B..A}....h&.?.(.<.~E...JU&......e........'.N.^_\/.,.+:.Y....&..$.T..C..d...P..t...M..=..P...r..{.*..".b.....x!2......,.....J.......z..m.H.....;j.q.2....X`k....'.7...9.......b..S..t.,.b..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1234320
                        Entropy (8bit):6.61673684382516
                        Encrypted:false
                        SSDEEP:24576:zY0wnkTOMqCoWYELeoWdS6x7S7cB+8umBceQGrbpC:zhSEOZCnYELeoaSABVceQGA
                        MD5:E05F56D92511DDCC7511725DDA66A25B
                        SHA1:3F7D9D7623E62917501EB6082560AF6C21D5673C
                        SHA-256:E54E8911A73AA6F8CA75F868D0B6FAF44A5B3379F91A9C259E5B058860150C49
                        SHA-512:73DBA13FACAC976A48933CEA463AF82FEC526E7545793DACCE04B8BD79B8C94614BB8F9253F56841CFB27B92C21AE1B7BC314D568A2FCD15EFFABF16BF97FBEF
                        Malicious:true
                        Preview:..%.....x.....tU..%X.p.F_&.m.Z*..k\f.@.s.7.....Q#;#..+..b/p.B.?.5ob[>.o.^,..5.i....VL.(.....'........pd...0._\.8.`'HT....Z.4..s~L^........?.<7...@.....MB...)..4..}.oS...6t.h&U...xO..`..Q.-.B......G}...Q.,....46.{X.....YsO....">.....w.e.*.!u......-V.....J..g....p..Ijc..S..a....S..b............i;...o...u.y.U^wR.0_b.D9..tw.7=fd1._&_.,2...q#2.$....u.u.$P..{_YE...Uwq..s..YD..fL-.+.e.*$.[.@P.......?a..2...)&...1.8..S..nz..b%....^......c...e....b.1.....L..=RC......Ya(....gv....e%..G...T....)..Zr..C+.cK.a-b.Lf.D..f]."..X....#]..$..)z.K..zC.&3..CYK.......W..S....5...!.......K....]>!|)..cJ ..P.]..j.!i...0$.*.....V.L$W..*&C....b[....)...a3.<..,._{..O.3.~.6.kM...~q2..7.....2..WC....-.$..+.m.....z.....1....S*..6Z!&<.{....t..g.v.9.......X5.^.........v.?J.Hy..~d^..gA.)8M+j>.\h..="....).}.?.0....\.j./..5..i."..U..`.G7.7.&..EJN..._f.h....M?.`t...*.u.\..Kn....J..O..aZ.I...t2.Y....^..Sr...*..<...Z....#....+.3N.\....UE"f.>..}'f...rrfD$u........6&../....../
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1596304
                        Entropy (8bit):6.611041309006607
                        Encrypted:false
                        SSDEEP:24576:/DxKwKqzSmKsvwMZJ1XBsn/gu2bRC6dulyyn2WdXM6cWlA:/DxFTwMZJ1XBsn/UC6dugWq
                        MD5:75AC88B134838887598FF2AD47BBCD9E
                        SHA1:E38D400A798EEF649FD0CC3E3A629949CA332997
                        SHA-256:390E4A23F1477A26B03C4D3A02F3CCCDD5056927522023128807DF444B9C8DD1
                        SHA-512:98265FC2427F4876E471E4D2BCA3089E3C0F549CCBACB81AEA390451E8493253F15042ED54C0E54BE5CCFA15EFC481C868C46AC5E6CE38A5CF67FEE8698C56CC
                        Malicious:true
                        Preview:.*.NY.IJ.g1RD...N..qJ......Cm.....M.N....u..p.5...s._..)......Hh...=>FGz...}j-R......ZS..WZ.6...}.a...[1.6..O..K..*.........P.jP:.P.....qW..5..k.P.=%A.X..xA.q..jDH....?..LL........W..{....t.........u../..}.3']1D|....:.b~K+ny...7...>[...w..>.CZ.|.r...m{F<B..9Va..`...:.9.C...qF....Ot...]...^....]@H?S..^.bW.v'H......&D... .z]k......L......ya........v...i.......8M:..^.K...X.i..#...&?....B.E....<\,*j.f.eFx...7'7..l..^[..h.....Z4..S.|p+.#.p.<.5..+".8.S.a..unX..a...#...mrO.......z........^7V..y.L..Zn..Hn....\-Q3....j..a6.Jx.[.:....k.q..[e8....$..Z>..+..m....T..LI..m......-<.<./=.E.ve.P.."z..........v../.-).."......,....'.~NX.'..X.N..._..8.&.! C...b'..y.].b..J.{.....|H4.HV....%...8,t..I_#1B......mA......c....#......%.....3i..F...];.a....kTA7/.+7E9.8h......+.;...(%..#..lY..f...|.A9K<.Kw.f..]Q........7V.....z.7S...I......RR..6.7..ke@.%.@o09....7...G..c.....yF_/.....W..0%.t.q..7v..%....D[.....!T.Q%n....&.....@..Y'..%.y......+..|..h...E."..."x...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2536856
                        Entropy (8bit):6.602655335652069
                        Encrypted:false
                        SSDEEP:49152:Zyfde2gamG2nPY38hmI3f8Oyl4TwWrOcAkUCbBxYmKpLv33MaB/b1ie6:Z6de2g1hB5gcB5
                        MD5:BE0863A281B2DCF10A4582E95BB75539
                        SHA1:2B4613A07F92434A5928D818A3A7B005126D82B0
                        SHA-256:6EF2162D6C6CC91578CF6DF649CD22C99E936992AEC1A02BBEED0F4D8D7A1366
                        SHA-512:11EE3657D22CCC35F12C4C117F4F27A8B85FC1C19F4F3B81C6697F1E43BF7E2B880D0C24184FD589D74E453CA2675B5B2DC4C8FB834D3FD038E996A08A019089
                        Malicious:true
                        Preview:'. #..f..C1x.k:|M;G_]f.;......z..F.k...'...:.&G<@..../U....9.,Y....b.UG.fz;.....\.&m0..M..E..c%up...".v...KH......ZF....P.!.....a:.v..JH\....;.......p"..-.I.{.4...Hh=.... .X.Y...R5.tT...%..........}..l.%..(&%.ED.....C.F....IB2.Y..%c.Q.h.......OT..w.._.h.p.u.o.....H.:.4:<`x...=..0.~a|_....P.X.....,. `..g...I2..^.D$........ .=.....J..{.......Ivo{.-..iG.n.q"W\..1t..Ae...p..u...V.q.....A&...1v...!.g.G.......t.........q....p...w].!..._K.S....;...L..5$.vE....iM..a........w.,.!U&.3t...xC...E...w9.......7n...5:M...#......M.nA.G&..{sM..ihT.K.....b.`...}..Q...,..u.d...Rd.}........v.F.e..q1. )...z.GVRi.1s.9a. .._R..p.n.....$...S...,H...6../.{..=~.A,..t..=.`n..SH..m.L....3.q.++GU..M.9.h.H...h...!.1+....0..~D;.H4..G.I_ }1=~..&K...)d..[.M.WE.tO.<%'1V...b*u.z.$QH.k0#.M}..a.Rd._....%...6...(...w..g.b.`..n..6(F./...=eyT.l.fbw-......x<.....X.y..',...T...+.........C...U*.."..O.....k....e..im[C.|....&A..']Bv..".d-.`...G...qc.../..C._..!.;Z...pd..b..Xjw)QB....3
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4035968
                        Entropy (8bit):6.489446164671789
                        Encrypted:false
                        SSDEEP:49152:d2BLihGQki09C3hn/6u8XrnZeZeVCVBRwoOuU4gTQLswejDOHKCbBxhHMlku0RQm:giAQNqmziopHRqi4owi
                        MD5:12A336FFF480AE2082876B9C4BE14697
                        SHA1:25F8F00E7A67B259E0F8D83FBC8F1F99A6E6AED2
                        SHA-256:73F650BA55599B8B7D7C426F096FB8A99DA91B58841A8930EE8B1DED9AB61D2E
                        SHA-512:A7A8680075A5DA03D5373588F85E60696CD4C1DBAFDDE660BC29AFD36FECD5258E2BBFEED34D0F3BA867DF6178C8CF2CC7C5B520F229A7FD526EBE47AA2FFAB7
                        Malicious:true
                        Preview:.n..++..dcM..#.L.*.>d1.m|..OhP..mbd.<{|y..:I..c}[......9p.m@J....x.g.S..K$.Uq..I._{'p...A]..r.rFoPy|..%..M....Dg....W.....6o}l.}..h..k......Uw....;.K|....x5..T.....vj.7...!...EFk.|.o.j.4-.........,_.43=..]..#...'#ez../...-./$..!x`....t.>.R;.u..g.3W&M.;..P.'^H..w.DA.......?Mx......Q/V...>ET~.....nE....F.N..Z.3......+.):i......Q...V$tM.F7Q...<..............)8..y.)....1.PEV...'M..........[.(L..[.6...(......?1Ea.8.X.2.`yb.`.l.n...8%4h..s.).F..wg.b!..nn;.......Y.o...z.s......)>QZJ...voE._l..P....q7...(.....*..)H.,*.L..'.4.^.c.>N..o.m.29..S..L&.A..*..1E{O.HG.gn.._....*.r../....%...6q..5Wa....R+w.7.>.1W:q....D........0nd..l....Bt.........P|B..+=.F6...7p.x....i.i./.|.b.....F&G.....6h...*4..o......q..&@.O>..x....R.....%R..9}d..%.........p.:]..{M..[......q..YP.!.M...O.-..G{m.u...m....4..!.x.p5. .....J.n..^....Nt...Eg....Y{k.3..V.Y>...vv...J...Y6.r.P...t...=4..YJ..O@/.r..n.&...g..u.3.dt. ...z7.Z\F.\..C%...k.1b:.|.S.,.O.O.j..\....M:...Q;n8...-.X.N
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3121008
                        Entropy (8bit):6.639809606104245
                        Encrypted:false
                        SSDEEP:49152:f4eZcLW4jqFRZega3xejvY7GQOx4K1fm15FKqO7t78Ity6fod76lmlW8Z:wyXs3OBj4UmOq
                        MD5:D5025FE00E28C1A461AFED8C9336B8FF
                        SHA1:5CCC46146FF3F39995AC05C92E86E4F3FD4AEFEB
                        SHA-256:8CD4EDBE7AB61393034AB0FB939E805A860FDC9581287378FE327895B49FF624
                        SHA-512:F839206F3948A8B903496A23B96AC2643F935FF8F9D15E1CEA99DEB20DC898D1DE3358080A2E056B48709AF63E59394B65EB6A7B8F0FEF7DD9AA93AFD9B3628C
                        Malicious:true
                        Preview:..ff......um.F....`B....,B_....q......M.......:.....%)...~._.F.= ..ZLWl.I~..v.2..v......j."..}.....//k..C..8.......na......r.>...........Mv..(..g.8g...t...d&J.<.[:..\....7.........i...S..b..vU0..j..N.V/..[f"g.q.8..x..7....|...=.Py.#.0-..D.nF..H?..$.}...&..`'..G0...H\".....5..c.k.A..?..Jqd%2.CU..l..N.|*>...M.i4E..E........h.n?..3+.=K7m..^.O8..I.E~...b..............3f..RZ.j.j.K..h~.....b.X.u...F4.D.....67.7..h/c.q..>a6M...fO.w.Y...x.KF.X[x.b.F..)*......N..........^j..A.()57..Q(.......X.T...OBJ..+.......E|f.}..TyO].Z.m..%....Id]bfT.....U.H.\....K...).[M..@.......RA..N>.5....s0..\_.."...H...;..@.X0....q.:C.....x.4..b..|..;....V#u..Io....yI....D..?...f$a.-."OJ..".B.u.Y-x0.5.YY........ky.0.7=...p...xJ...?q....g.....x..u..G5.%s.Z.....x...fF.G...e.............@W3?..j...u...+.rfd&7....i!.V`.....=......K...l..v...G..*5*JOt......UL1e...e..._W...-..3...U.h......t%.zT3..>S...>...t...JN.n.n.*_..2....`N.....9..oM...*...c.O..^u@}.[.y..`Z.|...0..W9*y.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1267936
                        Entropy (8bit):7.0403616975617735
                        Encrypted:false
                        SSDEEP:24576:+UiQFBUpoOQO+sGOL9NLM3r4Viwj6KLqGua43loEeUFmwD:+UjZOQO4AA4eGua43lgUFrD
                        MD5:FEC6FAE5F5902D6EC7271FD9A0F3C9D9
                        SHA1:9283F78581B93A596D344996C5A8399A19E82586
                        SHA-256:79E5689DE7FB2644680B3C5361B76D595FB232072FB3BDAE8C26DEE02E654B1E
                        SHA-512:866143A9D118FB249425FF1D0E0C2069AD2ECDD71EC6273C513AD4417F6AA50EBEE22D6A6ACC93BBD64971BCE1DF0C405D1384D0FA096204C5275C91FA64EB4C
                        Malicious:true
                        Preview:....G..~%CB.....ki...6..o..f(...>.nSd:....Q..D...O.I.|....................7...$..l$.{.c...2....5L... .c.U....d.s.....^./"..S.Al.r@.......G._W@6..z....{......,^x..t.}.d...V$.K$..tEP^tq.m.L.5.HG..6.SY.....)..\...p..pp.7#.h.W.=..h@uk..}u......7.l.....>y........H.ypt].U.guO)...v......rg.."..j.'Y.|.#B....$(!.C..1....?..-.5...3...2.....H......3..!U-....h...)d....l..v......... )..."m)..j..T........y.C......i.1..(.S`.w.... .c.....0(X..7<d7)&.^.....>.9k...t?~....."b...g<..`......?I.O&B[jN...1......p....<..y...qA..)Dws..}r.>K>....xI...k:...{.....%..@q?+..M..w*.["....b1......@X.....A..:.nn.q..E.3l-dN.."....'u.?..$..E.V....D...V....f..`?MX..g..d@.#...JE.....a/>..._.T....N%.J..c.3.F$.O.C6.....[W$*.K..\eR-^...[k,.HE).*.<..m...%J.....x..`Q.|.z"H...C..H.<G'.U....Z..s%x1..m..!.....*..S.../F.z.N........?~...+Q?.I...xaJgiL.t..4...6..._f..%.b..D...../..k..]xUx..|.8.P.h....0.....e..D...........^..\.Cc..hJ*@.L~%.8.TP.@.....l..^..=.......:....c1n.../+l.V..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1131816
                        Entropy (8bit):6.721698222848399
                        Encrypted:false
                        SSDEEP:24576:2tojO2HPooM0sy2Mun2r7tbg6Cn1AQUz3JQy0:PjO2vooFsyGnuq7n1e32
                        MD5:02080469FAEF631B82033A50B990A01B
                        SHA1:AF9EBB8ACC83DEF6384722117030E8D60C7DDCFE
                        SHA-256:CCCB19FD05A50809DA7DD7EBF1535E1ECBCC69406775F081DC4755AF3ADCC7CE
                        SHA-512:81F9D217995F76401455BF6121AC52A24DFC34C77BF18549AB02935CB3E7E007D96D2ECC8B7E68A790C47A459B7198093EF963E2A96F24A6958F46057637042A
                        Malicious:true
                        Preview:.....7 ..K.y...j..o.ys.SAD.L....vT...p...T...V._}....9U..*r.e.o..j....Sa.\......z.S.+....e...l?{.J.e....E.1.{...8..QY....u.Y..b..v..X...E....x....uh.w...d:A.L@........#`S-.{h.5...#.7...c.}:..p...KBW..<{.T...P.z..]..9..C....n.@..........j..I..+.9.Zhd{.F..5.@CB..RN....?..'...L...& .vc.G^....h....[.RS^.S%....^Z9u(.....4..8(I.=.~.q.....&U.....I.......X..S/t.+...s..9<e[.39Tf...4).D...nw.....7.G..xWy.]Ty..C.W.Hz2.-I...X..,,..9.-..]..T..Y9R......2.$.m...}.....D5..b.D.7.fH...[.S|S.$33l.]..Z.....-.kq.hAl...};-w;..H1.1%.......3q.,.!..T.....a....."l..!T.....o.L..OY....0.84d.n.W#.$.F@.U...e9..e......M.&.........n....Z..O...e\@K..........?Z.]...8.7w...r.....3T]........P..V.06;i....~..N...U.T...T.n1&..q..#....[..&..c1m.q.. .(.]..$?.L..T./.VY.."......o...f>..@..9..e..~O.N..1.<.@5.Q.}~.Bu..2.'....<....9.(f_<...n.U.O..W[so.......n.....c.j.........._...B.:K...Z.EF...7......e..n1.p..BPJ..)...l..>Y..*...{....n-]>..d.-.q.....-.KB.......<..mI...I..4...m..n==.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1385768
                        Entropy (8bit):6.6831718708187
                        Encrypted:false
                        SSDEEP:12288:LDZUA+9RDV5nUTZJ6Yhgt0o0pNfP2LZP2Bo4YuwEbVCIpXc+tYotX:LeA+9RDVQHWd0HP2LZP2B/3BCitfX
                        MD5:9948AC4E9E99FF1D3AE26FF91ACCC1AF
                        SHA1:B7B61F0328F27FCBB001C658D03F84E5B8BAFA46
                        SHA-256:226D07CAB8DAB8281962D6A8A684D21ED6D563A9B15A73528FCC73125E89A317
                        SHA-512:001360849485D698D2DDE846EDACCDCB8528A447A25BD3E7B31EF8775A5D3687FF045F0AA319E01E79C6B5A7CD9CA498F3898B321859380413686D959ADFF319
                        Malicious:true
                        Preview:SVV.[6...L.!."3^........".]...R..........g...P... ..Os..0..uaO.....t9g.n.t.t.o.........e.r....*.=...BV.N..?..?..........Z>.fAR.............8..M..e..=.........h\1.p.....4.T.6....!...x....8....L=.H.^.Y.01....k..@.....:...n.....m...B.b....$.J.k..D.J.ZO ....U.z..?..7..k1%{...... k..s.......t.............,.......#7q...:..IW.g.,T]HLdo.K.....x..*0..*....s...}.S.......}.... ..Y..!..K...i..Xu.....2y..%.t2.b.....q.-...d...Pw?&.....k. ^....!.g#...e..g..B.rU.C..]..N.`..~L.H&....g....nCY:.Nv"dC...A_<..*.qY....n&....!.w....?.[...K.fOG..@...z!..:)..E..N..CG.a.u.z.{.]X]....5.8.......D.&...DX?....~4,m.T_...g.j..Z.I1..3..`U..,.X.W..../e.l.:...;.b..t..5M..Ia...0...oD..4....G.....3g?rS(..I.00.!5M..k8t.......H..9.....6....h.J....Kx.Q...F.M^/...k.)m.....>...GPZ:..4.7..Cet.Bh..s.....NU.T.P..w...|..Kc.s.Jz....e[Y.....j.....[.G.-o.I},.y.=.._....Jk.$.&.~....^...B.....~..]te...M.or'-...t......y>.Q..Y.jS{8.....L..-.....%...c.....M....z..$..pG..d.,..!...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1250600
                        Entropy (8bit):6.6118957944868475
                        Encrypted:false
                        SSDEEP:24576:x8NLMYeDNijQm/sWg+dwJP0+2vyVCQgQIbetoYd:x8NLMxDNijQm2+WPnytQIbeb
                        MD5:4BB55E12593B1A6041A36A6B02A14855
                        SHA1:133D465BA4D3CDFECFD1CCC31C49392B69EB658A
                        SHA-256:E7EE1FA2FFF69519B60833949E607AF22E19690EC2DD04BB6BD166227E05A604
                        SHA-512:D5ADB889D0FEB7DA71CBD6EAF341F66823B19D8885E265DAD46CD451C782918460FA304AE6F5F135B551F505A771E6262E355F89DD5515450477B91B9F62959A
                        Malicious:true
                        Preview:..0.......0o...}T.&gi..R.4}.....h..'.Kt.......HQ...t....a.|.v..O`.kR...6./.....6...e.O.`>.....v...x.B...:...Ss..7...^.......L\?.8.N.n.O..-...o.7..t...n."..............c...|..F.....M..!r...H*.L,.s..X..H.7.3.Cy.3W"..ptZ."...{.).W......%.W.|.}..=O.TNk.,X.k...D.|....6;...A.^1..[..NT..../>....i..>w'.A......._..H..PX.I..;.7dPsg.u.X....pz...$......5D...Rk...n..Qgf8..gS.......a.R.......E...#)>A.;...F`r..|.d.g.....<.+C.........!...H.}O....B....$....D... [H...fQ{...I..,@+*........f.A.h.....z.i.../../I+...E_.I9...F......DR.xm..*.IE....)..~..O.>s.O.....X.o....n{.....:.b.).{...E..|..S.)Kb..)Y8...Kuo.Nb....x..,D...<.T.8>.....z!.h.;-.$......V..P\.{.......R&<6I.=.......q.yf..B.x./.......b./.m..*1.=J....BeCu.Eg|-..@W.3.F..O.4.....c.....dG..}....Z.....[..O.F.........l...ebT7...7. .EYC.7D.5].....P...N..~.O..".....b.y.....VsR..O.G,w.....NJ.F...7..w .$".6.,.d|I.B...$.fm..`Hw2c*.{...S.jQ.'h.EJ..q...M.*o<.|.........AW:...bO...2F{.......".E.1.)..3.v..T..<..}l..q
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1596304
                        Entropy (8bit):6.610761756726846
                        Encrypted:false
                        SSDEEP:24576:H0Erlwun1UDCmasrf9Xr5wzW27+w3E4nZ1jDkCZTunfmrd/Mq8pqiV+yeci+i:HXr1UD3f9Xr5wzW2x3E4vDkCZTEJ+7
                        MD5:CE796AA75C3D823531B333AFF3BEE5F4
                        SHA1:24103D7168C3C8460D51D716AC5A6FC5298B7D59
                        SHA-256:D75775FED8E673F3A2777BC96C4EAA6D6C40BF0C05CE919A53079940D08AB286
                        SHA-512:2FB7E20E8AF7D6622A6B335EB503256850892D5C4E773A8F94470FDD409E18274910D49CF3A2957D1FEF5AE3D931A387F46F130821589CA802B0B6F43808BA04
                        Malicious:true
                        Preview:....OU..9Z.2...`G..1.B.....9:X&.....K...@=...........NK..z...uY......@v...|...xA.i..f.?...!..}....*WH....?.R.i...5.M.>B.....ks^b:3..uC....k!hjf.g....[Y.d..1...C..<..W72` N..e.D%.x..@..5.Kx..'...r...`/#:X...4....r..tp,...........C5.....|._.....`...)BA.........)..LO...khW......)..0..O....a0..,.......\.>i.....).....<;.q..=..om.qDw...e.F]:.n..{.:.9^t..R..._.Sm..+=HF....=..Y..u.....Nk...%Z...-\f9z..0A[b.....{.hJ#...1.....z.}....O.Q...O..L.R..mT....K..>.....+...m..nf...Xo.$...1...?..n.G.......>....BM.........rtxS..!.....b.#o.T.X...+f...........h....QJ..U.e...s...e..D.....xO.%T..}.`...Z8..c..V.....?%HL..eX"~.Rm...y..)..v.W.g.....Xg.W..(..4...rN...=.-..+&k(8...>w../.x-l..*...H..e...N<'.]...E.4.;..d.uM...^....x.L.u.<:.y......y.1!W..;....D.....Ph....G..8i[..h/....xE)...ezc....X..X..W.,..j!.W.c!....|..j..V.YR...'..w../.:..oh-J....=j#m4%...9."bh0F.%NuC.*..%-.3.....W2@@...gA.~~U...?.....+~.J\...%l.:...a.w....Am.(.K.j)6".d.e..A.r....b.....x.,.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1881416
                        Entropy (8bit):6.801360237534382
                        Encrypted:false
                        SSDEEP:49152:VaWT9wxBjJMXDUlxqK/PDLWf+kfilcOk+4AgAQm:VaW5ADam
                        MD5:E06E225CE09F3029C17E0573392046BA
                        SHA1:FB642484641404DF9D572139FE2C6DEEFCE99933
                        SHA-256:F11198596ACD1A85DC550F5AC65518257033BE4A28595A5C39049E08E3F8611C
                        SHA-512:25A66FCC8061AB67A4DD8DA38947721B5FF541509B76B3C9134727AF47671D99E5573713ED4C8FE4F456BC66A774F56F7FD3D5F3A660A897DF6D7C8A11AF774C
                        Malicious:true
                        Preview:..0...4cJ<.G.....n..K....x...*T...]@.G....H_0.}|.._x.M..#...W0..)/(...iS.'.C..F....@T*.Z.).Wo=v....-.)O..9-_f......af.<k,.. f~6.9.c=8.}.*P.g.....5....%X..5rn....05....}.T..Y...%J...s5j.mb..g..|.........Ju`-...eAI..*.O..}.."....".<...$dZ.8..$..n.qaj~.s ...cP....[.3/.^!.c..._........&{.4..ET.. .U.Y..?.^Ao....b.O.(..]E+.\..6v..d.h....F...o.zhO...Q|.l."..$../..DB...v.Ne.~.i....C;.!.r.b.6.(.A_..@.vw.....}......$.v...~.DJ.....6......+.....T.3.3.Q....g.'../..<%x..yC..1.."...y.B#....I.H..|j......m.N_?.xhMd_.vA./.1......d...|.q...4".;Gb...".......0...........!....s.../..v.G...Cc.}.~.....kT<..&..uS.y..Xp..}.J..|V.......C.p.....Z.Y...M........;9....Pls~._.....!.E[!.EK.h1#..Z....q..*.8.B....O.Q....;.....ZOQ.....+..o.s*....?..y.....6,.....\=].T.......S.....T..X..TZ6...Ewq.FM.........|....l..$c..L...;..RY.F?...=1%.}4.(..8].?.o{..5.z^.....&x.b..M3>....L.V5.o.U..4O/..X..J...6.k.J...T..X.x.D..'.]~..k(..r.....P7\...D.m...icB.[K.S.s0.f..o.f.CU._.....dReJ....&.dSy..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1193240
                        Entropy (8bit):6.745643391113015
                        Encrypted:false
                        SSDEEP:24576:+W7cJt3cAXZv5Qi2c9e10HRC6VX0spKERCl+aB/belll:XKtMAXZv5Qe41mc6VXJKx+aB/befl
                        MD5:22E3F750EE0DFE10BDB306C7756784BE
                        SHA1:C83334AC092116F887BD216F3D2428BE13322AF5
                        SHA-256:7E5800668B4EED5B1121816E68B6A3259E8C6515FF88DCD57F22E4F2F98B463E
                        SHA-512:88F558AD8E88809459D35073E55E83FEED3400E3D2C356D09A6D5A4711DB5741D024FCD985B8C02E08A4EB2FB4FC8790DEC4B181D6C6243D072109FC92D878F0
                        Malicious:true
                        Preview:..q8....Dw......q ....m.x.s.]......Z.....Y.3...I...`4[.q.d}.6.../.DD.hG......K.x...6..Yx5....;......BK5j..K.$.U.....Ux.\`.r...;..=.....l....o......6na.|.Z.cN.20.(n.0...).I..v....Hp..<.j...f..S.=!.,S8...}{P.z.S.......Q...Hv.;Y^..#r.|..:~;..I...1j:.......%.eS.GN.q..A.L,A....z...6..qX.X..-0...3...E../d=&...3..Z.....\..n.$$<.-.EZ>'0Ed...%...w.J..m.......e...$\..-w4M46%...&.H..a....v.]..4;Q_t...0.*R^{s......v=.g....j`....-,.[.........0f.X.J.....c...."k...p.o.Nj]...6...6...-......6i$.R]......A..&.....+I.d.z.Q-.....Pu.C.3..s>.C..r.i...]..|.P.a.....6.+.kp...g{OW..+B....3.......5..|<....L..l..y.......{.,^..T>7hRxR..>.7..v....TS..`....3pz/J<.z..*...........i.r..l...6.9..;.......U..e._...u.k...3.G*..BS.K4.......3..E#Z.K....!.y.<.\~.h,....;8/.Jx..T.#.6.I....m...=.;+].J...G`.........PEdg^.f.iBn?1S...7.z...y.A..F..@E'...lxn`V.....x=....19b.pN...|I.'u[.?L.....{.d.A+..bM....,...>.sV.....52..7/%>..-.......M5.nZ.-......"..<d,.D...R..zR.nj>.T[RUK,'Ua....k.Vo...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1971480
                        Entropy (8bit):6.633518798272021
                        Encrypted:false
                        SSDEEP:49152:ZfooSiGO1jehvXtDZduKGsuOpeqVAjXr0M1i1:ZAA1jKdwW
                        MD5:EB0F59F04D8D454BF133432DA6596D60
                        SHA1:3A3757532E16161C5C8E1D2708E3EDA33765D983
                        SHA-256:7F8065F811038DFCD2951A39ECBD0A94B1373C71E9CEBBCF6E1117BF9AE3BCAF
                        SHA-512:EAD97B6B9FEC11833F1D7865CEC412E1BB48B8BD1FF278BB74A5961068C0354B6E34A6C7EA58CC9CF3778400AF26BE4412D14E7D251E077CBC67B9F51B8F489F
                        Malicious:true
                        Preview:........S/.?..3q....8D....l;.n.....nU.....rhc.X....Z.$W...[..N..O.j.$..5^.. ..f..~.=....p.gx9.v]...D....".;.......0.w...p..{J..D...H..R...`.b...j...t..@.E....U.,.1.....Q...'.......Y..7ZD 9jqG*..>.Azs...H...5.2.=....;.o.z..j..;.."..2C...T.6...|...!..{.T.e..|.D.%.d...4P..j...].....r...Bp...N....".*^lo6..GQ..~.....r.i.pS$..{'.?...j.~.c......?...s+)..xzta_.[y.@%#W&M.}=Ah.].K.S..VOT`.*._h.eR..f:<..+.8.{..........d.EQ.........."......4..o.*..Tt.J.%'.....J.P..MZs&...$M..<..T:y.2..u...cp...9A\J...S......|.......(^......i.>>....W.r..T,At.E.CU6F.....B....7H..m[....S.....P...h.T."B...\.$.........r......o..fg.Pc'...v.'T.|QU.s..ec.C"....JIvBg1/B.@...........4.t.....w2.u..K....ki.vz.-q^.9.J..5..n..1.fZ.......Y.*....*q.+...?m.2..p3(..9..... YGr..w.....iUgG6.O....@..>..B.W.y..\.:..Mz..... bE.1..-......'}.9.O...kX.F..X........Ee..C.?..L<..K....=....n2FL.A.[^.*)M.fUm.~... .m.v..!./.C~..]m.e.2-zl..R..O.L..)....7...q^...&...b...a...,....\.2.u.O.m%..!...Q.C.#..D.+.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3941672
                        Entropy (8bit):6.476149185430821
                        Encrypted:false
                        SSDEEP:49152:y+Sx761uRHb+7Lj7kFwn3j1m0M/t4yh9D14aZW3tW98ZfzT/Z2IZw4+mJcITLzEX:yp61uR7WpCl1lW3p2RH
                        MD5:AB9F39329C8B79B599EA2B32B74ACBA2
                        SHA1:7C8D6FEC052D37A4306482506FEBD1F9C9108BF9
                        SHA-256:37A67155666862FD1632E8B44A8B49F0F54865E493AA7408857AF5B16B082AAB
                        SHA-512:CDB76E492B38DABAD87C05CC214D8063EDD8FD950BB4CDCF6596A9B06FD7C9DC91773D565B0D497451DEF271AFA89AB07579FC2E7B3DA81049BE071BB9A9E498
                        Malicious:true
                        Preview:....`Y.... ....%...s;...l.?.IJ...?...%..S\...]&o..#.}..VO....:'vK0\.yw...".C.x.z........h.F.,.....i....t.v..^b&.*N..9.b?.P......l..cM..........5.0U..{)..v6....`X....X`{.-a...W@.w.g..2G..7S...-2.K.T.V...U}?..E.bI.A#...Y~V(......>.a.Y.;.:a6..L..A.Z...Co.L..P...D..b.<...CC.p.1..(....Su..i=.?q6.3....nR.rU..&.......4<Rz..%..Xe.:..-Y.S.:....v..L...f..Z..xb..._.n..F.$T...2Q}.I.C..7.yQ...0..m.p.n.2.a./%B....`B@}.>....@...u.......X.o..R.Q%....`...E.Bc.B.8M8]!...}......9. .+pc.iLY>XE"...A."........K........-.MN.......iaz^F.... r;..a..Y.j/g..$..5.9..|.z.K.\...P...Gh.-...x...$...?.?VD...;.M...h.....<..?.....z{<-...=.....$ozb....;2T..$f..>....}..~...s...`trt./`...?.h|...z......l.W6....R.....Z{.].G..O ...3.A...,.....9...&-eN...k.K.'...1.=..e!.G"..%._5! (..L._.=.B..J.f..(U..Z..X.....=L7IKX..[..W+.....E.Pk'.(G.%.s..Ld..UZ..9..i...L...N]....#......;$.G.'.j..|...dY.......=A~.+*..<bL.o.Y.$...*TK.A.h....w...f.I.nS.q.}@[VT.E..........D..$.D.K..........[[
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3116904
                        Entropy (8bit):6.634504886871152
                        Encrypted:false
                        SSDEEP:49152:LW1wJNnw/bT9uzlAndnpufoDbRwU/xv3lNOsWReEQZeEO1QOiPQOo4r+:LW1l/VmUAYr
                        MD5:342365B1A1E3C844F28FC765857870B4
                        SHA1:D906CD009BD59758BEB9B04971DDE99CC8112821
                        SHA-256:5740E73974432C3693F36004C56FEC5933288250987196E14CF6B50F888F0BA0
                        SHA-512:D301B0A4B25AB2702BE3B138BFE958A9A8A080186C0D64F09EA82E9B895B1DFA22178CA1F021897F532B575362C35814605F91A613E1574EB87BAB5CEE773389
                        Malicious:true
                        Preview:.<..a}.,ez.=z.y.u]....N..u.........G.....j"....h....j.2.:.2.Ux.......fV.-.3.....j...f...?........!....<...%.svH:..$.....`...;....]..<'X..d..Jm..n@.mfiD?3.78..%.UmX..{5.....Su%p..>..........;.l..B.....R.*.da...k.a.U..yE.....DZ4\.E...]..?T6...w7L...;Z.........y....2..k.E...T.yX..$..@..IkJ0<T..Y.W`!(a...ke...%..rw.H...hf..#ENfT...C..S.=....DN..S7.=.....+f.........6!.DR\...S.`.>R.........#.&.m.A.cq...>.....D.....Y.SU....Z+\.J..w.U....?.r......7.T..EM.%".....K=.?G....m.eZ,pK.unm.z8.....~..5..o.Z......X....{.....IO.NE..-c.BN..:.7..|.5.M<.('.Z.aw....D&.!...J#.....d.H...:....X..0X.%.`O.....R.&p...%(Ck..3..D....L-.R../.<5a._#..qE...;...F..*nW..!,.'V.x.kWh...C.C.....9.Y.....m..t.3...C.0....h%..u..p...6''.z...t..^p.....2.M+....!1......A0(.....Eu..u..I.h..'.@.#........F..{.w`..kY.B.{...8.^.ibk...... .$4q.......E.E^l>...L..nb......T.N$.M...Z.Bo.If.).|{.....)n1D .......=.....a...&... .....,.U.&w.+T&2S.$..I...u...j_A;...}.."...*<XM`'){A.P..s........*
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):1268064
                        Entropy (8bit):7.040963845894607
                        Encrypted:false
                        SSDEEP:24576:sLayYsvbIUnHtg+i54V0tqDNbu5kDIPQy+NTD4XnFzX:i7zXzdMkDIPQy+Nv4VX
                        MD5:D23A8373B561FA631B6F5E6C120BC84F
                        SHA1:B50676539305CAE79655C45BDD71C38238B95D2F
                        SHA-256:AA09BBE3D6356615E6BE3DDACE94AEC8F520D3AA7E54843B2B708F85231F6D87
                        SHA-512:3E18063A7C5FAF5124C2EF6C3D90278C0F6986FAA280C8E487858BEDAB699EAA326426A9F9C54AF5A214BD48965A709A5BFC3F38FBD0A0227932F1E27369066F
                        Malicious:true
                        Preview:..*..5......?.J}.....%p..j../......C9..?V......W.........Ioh..,9Bi.{l8.V..0..q/.<.. .Hd.m.(.K.Y].M.U..<.^..8~u.5..s.l5...R.....>.Hw.g../.PLc^.-.Q..h.V..f..@.(NRk..)..p.../.9.f.).7.......h.Ws......f."D..> ..[.......K.....z..,.C.:.....JO`..=...C.S..G.......P.v_.n...:.4...P.3.o.....o.......Q..TY...}7I...u......z.......%xo...@YB}J4.y..[I..O..|(..l.......:f?....(.<....H1..Z.........M...3,~C. l.].{.....4-...\o...g...C<.*...[sJ.....a.B/R..<.f.1,.u.....E.o.s...@ ........e...,....F"....ea0.y/..I$._...........s..uU"s........Q........./.}i....4..(.=...@.i.n...r...sI......].u......'..3..N*G......._."..iH_.....n.......`'...}.|b.cR..y_.Z..O.8x..9f..R.....E..+..u..|.&.......iO...m..t.....EP..M..p.x(..j.H...T...>.a..e...}.$......;^I....6....;...w9f..K....V...%W..Ho.o0z`..GI*.1.@..Z..]...........|w......3z.E_D0....W....u..23.T.Ju.....;_..t...|.e[?>..&H$.8<eA\..?92..{..4...aee...}.X...$ ...@6+.>...@......w.MB..U.......m..Dg.s...v...s...m.w+P.fNH...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1148200
                        Entropy (8bit):6.722846225069604
                        Encrypted:false
                        SSDEEP:12288:OcpY2iCB27hkRnH1qdv/2XxFG6N5nI6kPBpS78mSGR3u0cdZlb3iO/JwtfoJcAnX:qutVqdviFG6Xny7SAGSlbiO/Jwtfshbb
                        MD5:77EF1E1984E4E47FB6C1301D6DA9B5DB
                        SHA1:605F53F9785D6BB9A73AF4CF9F7FCEC420520658
                        SHA-256:6E876221BE93EABE18C07DA9729227B7B80E0F767EF3D6A5B410C62FB2DD22B7
                        SHA-512:89CEF0285B1525153445B4DDA1A8DC64ED8F3608A13D19EEA8EEB85A8A3E362B32609D87737B0139D54E959BF114F572152CAE2F75F206DBDC7231E7F5547AA4
                        Malicious:true
                        Preview:4?{.0`....'#..4U..X..)....eBx....O<...3..I.....'/..-t.....@..1.`.=VR;..s=..K{......K@...h_"...1...i.W"..4=..c......5...`.r5].6...>.......|.q..ka.fV<.x.].3.E.......s}.mTw.L.........A-l..Be.).0..n..{...3#..;.}3...">ZZ.I')...k.K.....,3..G....t.....y2.r.'...7]........p;.[o&..#....aR;...........I....W..8......+.;..G.....j.o.....nJ...5......nG. .(.>q.....w.!.<.4...CA...x.....t(.(..:";.o...f2.49..Om1.....B.9......b..1..|d.u3.F@..L..lGV.*...lV..Y.,........}...#...yyY........m..G]..a.......a3Tu.w..2....7....P.O 7D(..R....R...M...~.I..C...RH.....-..-..;...=.8.....-?Lt.C;u...2.....3..[..-...,g...r..O(i......R../...C.%..Xq.b..z..HT.4.B..c.....DBS..vl.f.xp$?.%..oS..Q:~.@.^DR}...t.e....S...sp.o.O&4w....v.8...'..`..N'..N....y'.,.L. ..7]5/i..S'JOg1.QN.u^..i..H....4M.@NX......4>...g.-.V..>..J.u.P..QD.....<v...LX.rl...[u...Px.e..?).B.s....2Y.L....6^.>f#@+.c.*&~..kI.)?.b........?-.SF....FL..V......D**..=h....1......?.$.C...%2..hq...8..~.`......BE..........j
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):27667253
                        Entropy (8bit):7.998901420599089
                        Encrypted:true
                        SSDEEP:393216:aVdX5eFSW+/DuXC1+vqFY/OL6Dhtn9ixz+H4OIMDoX63g3q+ncR5e7wolRNmLSN:qdQFxuS4+qFY/R1nqGoEqt3HcR5oX0Ly
                        MD5:F6DEB78B6B0E4E4BA55F583347EDE8A4
                        SHA1:1B58B0E792739BDED3971A52F541739F3E88FD0A
                        SHA-256:E6A85444F1DF333F74488333EAFBCFC61AC913B6F8F0FEE611ADF48765C4057C
                        SHA-512:60F454AAFBDFDB2AE94E24CF3E39AAC8FE623B3F6700E54AAB4723352AD51CA9D0EA65953BF95F1CCE0774BC44B18454716DED3E317430D64B9936EC450C72DB
                        Malicious:true
                        Yara Hits:
                        • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.bin, Author: Joe Security
                        • Rule: MacOS_Trojan_Metasploit_27d409f1, Description: Byte sequence based on Metasploit x64 shell_bind_tcp.rb, Source: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1061241D029D55D7F01F7D3B4CD7498A8D494AA.bin, Author: unknown
                        Preview:.[.....T..X.i.....G..G.W...e;....E.89.....t"...j.JjD!. ...:u...p4E.9C|R<.:.P..\D..S..S....G..E(I.'.%.Y>;.;..z1....'..o....... .+..p.K~..:.N..#p.l....v.....:..)(.W.....gX.M.u.tr..'.....f.]T..e......2..&\.,Px,.;.v$..>.Y..ck.S....#M......24..R.G.R...mt..L...]....B.z[.....@.[.j...gw.A.b..P v.?..^.y\w.^..Z3..2.'.H.pC....a"...&3`...&..!...JP..8..[g........_b.a..N......>~...6...Z..l...4T..^..f....y.v/..X..2.M.t0u+...x%.....z(.W}.b...:>7$.7a.b....l...x........~Fc.9W.{..ORh...n.}.x..@=....S&N...W.!...@......`"w....H.='.GiV..|..h.Z.^...f#...{..E....}%...Ea..Dl.b.u.P.l....#l... .'...T....4x.r).)f..X....U.g..K.v...E......MrE..5..PA._.@...%P5H.n.)..C...X.,...<.v@$Ya.=...A.M.u.@0....{o.NE..;K.1,...w...+..\Hk..... .._...%....A...R..*..U.4;4_..u....wa.0Mx.pd4.cq~.$.....h.P.z9........n>.......XH.J....c..l0..Odq.,...l.O\..7b..,..0.@ mQ..I+@..."o....HC.b.V[.....[;q<....A...V.....,.UtC*._.@..j)I......T....{..........z.z..pm...~..?.Am.U...'.bP..ST.h.n&B|..K....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1903668
                        Entropy (8bit):4.562140217529925
                        Encrypted:false
                        SSDEEP:
                        MD5:482D3FA0B4983C98F1B834BA1EF32A6C
                        SHA1:A60F8A4B1A17A9816F3A9AC25E6B5F7A620BC396
                        SHA-256:2EF954118B1100D4E3D1861EACA9474B05A21C137F414304E80A7E9BC0899665
                        SHA-512:DE239DC3B098BE858144F300BAD918791266CAEC18C309172A55C7554E458B22CF38E0E10754D833BA18ED6A70D2448D51CFA4F8951FD310F7348DD1D9A8D202
                        Malicious:false
                        Preview:.`..Z.I..a.P...,.Nrv.,..&..8K..S.....\..1....A7.8./.H.3L..r...]Hew...h ..A..p5......$.........&Pz.s0*.a|...Q.B.:l|.2y.@.sv.:Q.a$..6-O.['K..nr..$.cX;.d......-.&.....I.9}..:.)..6e(Js.n...$J..~H.@......w.Y.:..xN....>.P..Dc..,r.G.....y..O..I...4..U....=.Q.].........z...M.]<FI..\y.._.ba...[...5..L~..0.M1..weW|...].........9..,.,.......7Xs&.@.0x..J.U^V.:.+....}75|.....`.o...N?.....[.....Y..........:./..mGD~..tF..b-.......E.X.$n.G..L.,.}...nY...g....h...:.....j...wUe3...r.{X....l.^.?L,...c.hM.d)%...v../..~.&Ms...LY.7...T.-..A.h..v...y.i@...mt..n"..%..B...\..i.'m..m..........!:<.z..l...r;....~.q.99f.s..........tV.I...?.......v e>...Q.j+...:2f...kX=.?....jP.~_.R.Mx..[...4...}.:...|...^`....x..XhRf....x...t.u.c....&@."...x..^.C.......?.RY.y.?.(...[A.M.C..T,.g2GF'.~"...U<.1.....T9...k..R..e`q.... Z...........$.6d.y2...3?.q..G%..V.f~...qK.6..4..=!...$U..H.Znb].E.........6.'.&.?..a...f-6..>..j.:E#......;.......x. E.@%..K!x.0.2L1...@..'..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1253376
                        Entropy (8bit):6.241339401076667
                        Encrypted:false
                        SSDEEP:
                        MD5:36F3782F04B64CFF57C0A5D71F0D850B
                        SHA1:347D55509A0A3A3E9800EC1ADE25D5346FBE89B3
                        SHA-256:155C9650D4453EC5684673268D8359F99B3F7655B7D69FF4E9C1B848733E28F1
                        SHA-512:016B83230D72E85CC45546847513A3062B504A3FC44ADEE9C635433D5DF9FB92F506C31392F74BC018A228015FFD22ABE9FB2D1C816074639D5FA2C41BE69D34
                        Malicious:false
                        Preview:V....nvn\.^.<.......b.SZJ,..-h.`.........(.,. ...k.I*.M.!7.w]h.N.d..~...9%vV5=..SG3.."'.T......X...2..i......K......'...E..RVs...+..rc...HEU...k...........O...)....nR..x[ri.F{.=....k+.(.!Xj...e.p.C$/.Z.K.....Uk....zs. mU..>-?.. .....1..^:<..?P......0....u....F..6U...e..:.....G.^y7....9}...+.n8.$t.D.A..Y&..*.'.&...D.h...|.....5.I<.U.....1...m...!....r@.%y..1.8...@,|-m.`%..\.k.BLdS#...10...u...9...o?.UsBb...V.j.L..6Trl..!.....7..RC.A.}0:....`.RY.PZ..(n*.AX.s.B.b....H......).Z.`."#...0.h..XS....v.+...r...Ax"..b.ue*.qI.#w_C#.v..Y.S..Ft...o..[..;..q....z.o.0.X.2:Ye.Z.V..w...(..z`..."..\(...j.n.....r.$...........}.E+4.......?x'.g...\.Z4.`}.........\.v3G......xO........'-H.X^o....s.Y].........L.hz.2...mn=sL..C......R.......Eg.*B...K|;I....M..'.I....\.....A.....yNVe.m.U....]..t..t.....{..P....DV..V{.}:.-M.G...6hY......]'dr4.g[..Q..0..2.b....&N.%....j........u.........".:....^.M..B}<...7N.R.I'5.%.2=.. .at......T.J!.t2.......l....gO.n......$.....4
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):17444
                        Entropy (8bit):7.988980624337536
                        Encrypted:false
                        SSDEEP:
                        MD5:904CFFC0712A0473585E5AA918D72490
                        SHA1:A87C5E198DF518DC7F6E3B90879EF9DF6D17198A
                        SHA-256:356F7F2B9F4515ECF96E5BEDDCD06A69C6B365E1B425FD758E23C137010466E9
                        SHA-512:36296D0C65F7E3D10908CAE85104F6A080EC6460B66563F2A8D9868BE896C896CEC5DFF28B2F7D64831979708C3D7E73708AC4E0CF9F5400C17DDF8B06ABE197
                        Malicious:false
                        Preview:...=..JbUo.&6......[.<maS..G..FG.$.R......O..\'.t.H....li....\...q....&.....?...[....S.R..-6...a...s.c..z...0|s....A.....$.h.&.(.I.C>*...U)..@^.z..?..............n.i.5........(..Ym.)_....W#B.....UJ.[..V.CfW.l.`{h...qw"......+..`.{....h..Q.9......)...r.f.28..^r..a..<..?vg....8..f...\x..)....w..G...@.m.D.s%.#..!9A.el8..e.Eyv..........2...A...E...+..U.7..oHY.......<.P.....'...;..${.I.s.m1].....mZD.5.^C= .0..K=.7....A....C".....M^.....6.g6,......~...,..rn.c.}s#K0\.._Sw?d.bP=."...&.-!.D..!..4.....)OF..# ....v.g-.,...d..%..;...Hk......}w....C.n.>R..?u...5+..#E.j."...~.......:.u......dI5.....*..nM-..I.9...u..y............ya/.T.S...Ey..]..j..4.J..p8..h.o{../B..Gyg<.<y...W.>..B..$ab....72..2..K.DA1y.V..Uj~.r.W ...k\.F..:..C@K.............I.........49.o...F.?...}..-...iS..;...0...8..W..1~F.Se..a.yN&...).$.C..G.Fo\.$8..u..x..;9.)...kt..vD...7...IF.f...w..7p...O.."....Nv.I....<7-....W.UN.%*.........>DV.y..=Q........(..[.8.^.E+.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):17974
                        Entropy (8bit):7.988495180253089
                        Encrypted:false
                        SSDEEP:
                        MD5:905D57221D9332D565634E2BA66A09CB
                        SHA1:013422A5E481EA2373E5FC51FDD2526848F2A97F
                        SHA-256:18A3EB8C99395F37CAC49A640CBA1AB6845C52D384CCE8B8C405D0A6CFB56398
                        SHA-512:201C64C05F1B2920372E9A9817B7188EA819773111F44B328D28153575256ED32403A99F1ACE3E1DEA2550E9303E014AC77AFC1853C8E8C7A70170BAB75E4669
                        Malicious:false
                        Preview:.bb.K.........-.4..D.n.....\/?....#./..e.c..hB.......na.xr>.....2.C......g}...l.. lv.S..a....=...mFzyrib..i.)..).....!.\.z...e...6`H......7.....=..v5.....5.R.0.+.G....`Nw{-..3.,B/..R.Q.w..5_2....<M...P_2...c.C.\[.Z..p...~jV)......Z.0w.9R.).. ..........'....9e....Q.~..`nS.:...A.I..n|.....b7.u..*:2..f....v...CZ...r).....7*..^?.g....ae...n@...D.{.....!.xd.......J..........c..x6;;....n..........P...A.<.}@e......*..L.|r}b.Po...b...v.2..d..>.6.r..5.9n.~..MEzh..tUf.~....Z;9"l.n.+..q..uf.{....u.<I..=B..r...S.Nr...5.m.H......4T..4.....k .gic..m....D^.rYBW.qx80...w....mN..l.....m.Ecc..:~............w.1. -`.......0..8,-.p...Q;....||z....6..^$o.&M...V.%....W4......0..[...6.zU..Je..gW.L..QSP\..q.3K..........C..K..Stw*Y.`.[i......g__k...fE4/..\G....+.;#S..nO.bSF..+...;M....l..._.8=)L2.I.\Th.S\H|g7.`..(..z|..0m?.y.......c.V/U..><.'^M5s..W\/.....f....@Xy.f.........g|...4.yk.....q...U.....D....~...M9x...l...V........c..C............QJ..]...4...f..S.._cf@.#.<P...&..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1770
                        Entropy (8bit):7.886748810394863
                        Encrypted:false
                        SSDEEP:
                        MD5:73435C1A327AF82475A37269A448DED4
                        SHA1:BBDD81830A4DB662CCC5673109E4D190B7924C98
                        SHA-256:31459A5811DCA04D9048D7CA971E8D8D13644A61B62CFFF648641C37B611E8EA
                        SHA-512:762E44F476984F3450A2720EA44D5BB1CE7BF5D59DE29C10D06D37B164072C9608E602ACB5D9F27429C1608BC23E6D51467C88204075D385AEBC140A6D15E7F3
                        Malicious:false
                        Preview:7..3uVGK.2..AX..A.K.#...=....A.........`&..eo..#.t....Qd...Hh..M.gI......(o.L....M.O.j..gH.(>...).....Fe.<..W8..`K.V..*z..DAq{.)-....u....`0*S.Jg...1.. d,5...EP`.1.`..77. ..>...e..8.B...G.)$ko.R..x{|P*Y.-Y..#.{%.B.:...4..N[....!.1;k.,..'......rc.d.!.~.......Wn..#D.KdU.O....Lb...L'4.3.O..+I!6g...I.,...1.;i..G.....D.....k@Z.!..M...#.dT.-.l.n...I...0C2.e[.Q..N._...3..Rz....!..O..~...[.a.. V.F.....J...Z..;.....z........L,.u.:.s.......fj5..RM.WN.]2.....D.o.....Z.Y9.q...a..........L ...~..@."G.x.j>c..vF....q.]....-Cv'P...CN\<..6.M.,k.%.UR*..E.).../...z..,N.z...7..~.q..:.....xP.+......kB.p.$c.f...y.I.'......vD..l..k.3k.!....7&...rk..T..n.[>..i.l.._].5!.c.......t..Do..A........p.9Ap1..Bx.p...2wVr...{+9X..|.i...'D2....7x"...u..G.XMs.t...G.7{.......^>})j....0.@D7...w.u.............d/.(^..O..M.l..:..P...f+.....$X..|]...E....mr?:..81-o&.s.Z}.ZZ\y.B........7..8...+.+n...B.{p....sY.<...3...r..W...H<8.dKt......H...hec:p.J.b..Fn..0G.^.ek.......):u.H...G.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2300
                        Entropy (8bit):7.917204145996131
                        Encrypted:false
                        SSDEEP:
                        MD5:1AAF5307E15C06CEC255942C08C5B145
                        SHA1:0009ECD7AFDA6F5E4AF4D60763B0D11ABB50DBF8
                        SHA-256:1958ADFDE06778AB2153FB755C2CA01BA1C3878F129F1C9806F3C44247BDEFB5
                        SHA-512:4C20F81928ECD7FF0A85D24C98B1AF83CCE45999CC6768E656BA91A4FC6A86F1AFAEA6CC2655D4FD59355BA75F7BF8EAE7454F15F15324D3F8FF7CED38B332A4
                        Malicious:false
                        Preview:H.FD.S.0...S.P..l..e..$..#...LW.._....8.N.+&'2...NN...6\.q....U.N.."v......kz.FP...,.x)c.u%.R...+.i$..l.kY.ZR.1.]+..L.n.....-.pCY.b|c.Y.e..`..b....m.!D..w... SL...k..K..+.v]...!..R=X.p.......9.d.J.....r....Q....':..$...D...;Pu{8!p.....RA.P.}.w.P....B.@.e.m+g...*Xv.........0.....A.tN.ao.^..O.:../<. .$.b=..m.ZU..dv.]J..\j....%i.k.S42'..b...HNR.<6......OY=...<......[..)...c.Tv.~..r....8._Z.............e.......J2..I..w.<.5...........5...'..h..H.V....6J..9Z.N...nX,Wia.'"....hU...iQU.\..A.kr......Y2....Sn.n....$...KST.T#..B.n.>....s.[.Is&..<..&!D7..*._.....2R........!{D..G....._n.=.*x....a.[...]C....-....%..T.4.U5.2..v.Y0...%..P.>..H.u..+%Ly.4(...2../w.3to.K..HOh.....$.(p...R/...:j.l&6P....i....@q.!.6IS.IS....3...F..}.L.%:.J.:..f.z......G.. ...c.aD....(.A..1..@..T..D....O..........zry..c&..u).=#.C`.B..'`.1..U.pC.....Hvz.j..>.v....4......%m#....W..b.2O<7..3W...*\...I.:....Y.....uA..R.$..4r.@.UQR........UR,$...|..9.M..[..i...f.)..y!.I.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1594
                        Entropy (8bit):7.889828479550644
                        Encrypted:false
                        SSDEEP:
                        MD5:6E28240DBCB7A35231C54C81C927B6BD
                        SHA1:B28E5250421CE824B00A3866BB867EBF97B9D92B
                        SHA-256:0FBA06BDCB03A305974212B41FBC068BFAF39A0E1D0D7A0D399D2C66B2221861
                        SHA-512:5A9C4F76971EF2B8CB47423D5F69DF2E8408218DED81B9D0505514B1B75AE874B9BFF9C8AA43DCCD52884E085422EF83EAEF4D91F460EF621A1E03BDB6E08829
                        Malicious:false
                        Preview:..}<.U%(..,.F.8^......+.p.; ..._zY...:i ..h.`......N.Z.-R4..c<..S.......'.......$..Z3.....r..\U...<.I.(.....b...qfD..E..{T.0...QG...C.ExG.qPh#......jd...[...K!...SWq..l..a(...>k..Q@+<k.i.4?0..?...].*.......Q....K...M"J.D.....Og.BY1..B..po...1./....c3...._Y..'........X....'\9.^..M...E..$.. ...L.k-D.H!..g.x.4.$sn..y/.3.I..:..m.A.p...C....Z."..U,...aP7]....+#.,...r..t`4.bC...Q..:.":..rs+...'S2iO....u.97..e.....%-...;o....].46A...BY...}.....l.m..0...S..J.H.3*....Z.}...%{./f....Y.8*.D............9..g\..X..{X J2.....a....#..Md..6...dQ.x>.c..j.X...l0....!,..].:.y`..H.q...m..A..|...".....j.....<rj+..u-.DY.fe..{/.=..U\..^.....)..VG....9..:..x..YCY..$@ 3T..N.W...........%.cfH.i$...|".&.:.l.4...._a.d.@4%.'...g.N.%.....TsY=r#....?....:A...!...)`x..ee...XL..N.Hp...7.....g..9..${.c.(b.[ .@...+..;....f..aIH#s...d...GU.r...b.P...."o]..Z.H.h&..G-....W'...D....4..B..!..cAUg..(.^./|.O...#.PN.....oM*..Yi...b...L.d.......`..;..\........I..P..z.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2124
                        Entropy (8bit):7.91380183254627
                        Encrypted:false
                        SSDEEP:
                        MD5:0BECDD3694F29004F63B56B5216AEF30
                        SHA1:9CDB8F87C9509FDBF52AC2F5BD468F91D6DACD37
                        SHA-256:4FCFC5DA181BE22161567F8173E305400F2522858899CB5AD700FCABF2059F26
                        SHA-512:68B179926F399E1AB70F484AC56970AED1F0E5C39D385702DAF1049D22D2A167FD96EBB5CD20400850C5705222BF540C284500038ADB9007482FD3CEFF4CD65F
                        Malicious:false
                        Preview:pP..O...r?.....'.._?...>.....]..t`$....8.DW.ZZ^.0..".X}Y.A.>.~8.g....9...o...c...t.....gH...g...1..1...W..zs.\......f.:.@.}Uc..h..I.?p..ZY#.@..I=.v..v~a.........._.U`....|...\..A..hS.!6U6.....^...-..iq%:..[8.....XE.r...E:M.&-.0..............FB.i6....j..B.../..<.z$..3...C`T...Kk.....>..s@....^S....1gJq!2..>#.x..G<O|..s.3.r....n.%O..0TX...M.)..C.H.J..]..L..b.,G.d......).=........x."}a[.,.Ok..5..Y....y.H..?..d.jG.M.....5l|...c.h......t.....S..2..,w'7$X...UH`..?.b.........(c.T..f..,^..E../......S?..i...]I..n.H.>W.P...>wV."..[ ...}.Y...I...g7.[=a...~.".....=v4tN0.......{6.;.......h...&..:.x.[X}..w>6..b..VV.w...W..r...M....b....h,6hN.2.............lc*......2.$l..O.(^@...&".q\..(.. _..k.R....E....0.....v.p.<L...N3a../..dv....Y....f?:+2.\..'j(C.O.Y.IQ6..!Q....W.X.....+>..^.I....Q....b3n...va....Z....:O}......R..2X.o...d..{P....d...I...@..%#..$..P...x{=..w.uCp...t .k.c...{GSF.]..W....k...'(..^)......:..Qj.b../.^K.k..M~.....c
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):297386
                        Entropy (8bit):7.999353167175665
                        Encrypted:true
                        SSDEEP:
                        MD5:FD5B914CC4DB43C0B28181721014EB2E
                        SHA1:94A3B8B0241A7BA24CA786F339F38B75FE7F30FB
                        SHA-256:B6759EB16BBA0EC89758060B9C88B8FC700138D844771F39FB1FA9E92E7C0F76
                        SHA-512:75B11DE50B012021ECDB20820239281B6ABB847CCE775A55E900F41E1A58D0534B2EE85C01A4511122AD3A46E8E2AB202EEDEE91BA51CF8EAB54D852DCE44B5E
                        Malicious:true
                        Preview:;.F...Z.2.l[..'v......BJ...P. ..`..IH.U.V...>.b.1c1.a........BZ...n:..&U....i4...)....p%8.Q.........+..)..._W.].F..r..p...X..r..+..(..#4OB....7r8A..eI.t.2`q..K..e5b.....a...q..,...NT.v......o..x)<..dn..7.mV.6..[...9...,8..}Iy.....x..\tqq.......fy......*.e>+.o.c...)..-...m....m@.B.."..Q}.6.z-..^.(.W;..So92k.q...........t.M.mq...D....:;<.5.4]...sc.......J......q.... .8.E.h...n.....P..a....YD...6`.......2...Y6....h.......Z...j.$J-e.U...V#U......S#8sDS..c.%.X(.7.$.7O.3\F. ...J.)...ue..!h@..J@....dKI......Qcc.#U.vu.T....N......a.DgAUt..D......r.G..l[q.x.:.*K.'nH..rb.I..z_l1...~..,:.*.q.d.z..0`...0.....6a).-YQ...7...6.3[.4k...|....V...I.(..0.\.)a.a..M..u._.....F..&....)|...9LT. .B.5(.J.S. FY.P.v......q.@^A..!.....~^jO..eG.{....Ffci.^_..;j.&2.D^._...Y..x9Fy.....[)..+....w.&fxtq-...c../...........#..#....|OtB.E3M........r..w......c.X</.y....h.....D.H;+...N.....zZd^.._..G.y.,>.C. c..#.../t...f.:..d....9..{......#V.)..<..8.t..b%..?.A....m...Kh.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:DOS executable (COM)
                        Category:dropped
                        Size (bytes):297916
                        Entropy (8bit):7.999390991586468
                        Encrypted:true
                        SSDEEP:
                        MD5:674C310D1C0CC45C5CF7A5187D55E07D
                        SHA1:221E0CECCA0D447B41E811ED4A89406B8680F8AB
                        SHA-256:D8B6C332913CB862D55A3122DC57BF1BE5B977D929355EC629FCF49EE47643C4
                        SHA-512:43CBED0A9578B7FF5A96F5340ED224B2776ACDADE665F7FE89D7FD1BE81E197DBABCB86F7711058D28CCC014BFA88726073CF1D332501C8AA64B2B0853C15E00
                        Malicious:true
                        Preview:.m......lOY.#"`.w....<Ci.t.7m......Vmd...^..j...F..b8...c....S),W....H<..=...e.>...]#..}eS.Q....I-.n..].(..ot.d!.../.=..^-.MI...Q..4..._..[...9..dh./K.Q]..J.^.}Pu...V....L.6u"=*..(.w.........]..V".Y..\..8f.....X....bC@........7..>s.6...na.../$>..t..|..z(.B.#.6..3......SN..0.GuL6.&w...'.N....mKS.N....R6R...1...b..Xh:....ug....?...N$Hc../ND.H.......v \F1b2c.]!<=.......x..N.=...3x..\..6..5..;./&..8.x..3!.TcJ!*..>...V..v.o..`..qK..y7..#..6B...\K.W..@.h.Z{......;i}.........BW....3.:.;.Z.!.kb.....X>.qR.*.$}.&..e.._...tU .i6......L..d...h.z>L....D..,zoX. x...H+........j.....y.......'=.l......s.. !.g..jG.?...I..m.......(,./2..1..s... ..l..CJ4.Y..2..SQ.:...../V....~..`...:.:Fp......oc.9s..g..M,.....K........V{....s.u.[n.p.....c.H._.)..r...%u@$.P..6..A...#L.>.K.Wjd=O.A..59u.h...pXB..#).=.1.H.....V.lW.....R.........Y-.i....3...C........Fl..KrQB..,Qn./..8l...-..4.y...Rkf8"..K,.u\]....wU....*....g...].m<TH..b..Z.~.}...EQ}<...Z].....n.[..D....V,.....L.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1594
                        Entropy (8bit):7.866835176226305
                        Encrypted:false
                        SSDEEP:
                        MD5:FF12EC4BAF07FEC49E2FA9806304EDCA
                        SHA1:5F77AB7251DD49ADE44547AFA86E9BB618F67BA1
                        SHA-256:7745C8D87A8414D4E969F70399C3884B9BA5A0D25AF759D96AD91C70C6C42CF2
                        SHA-512:E9E0FE11A6E69866CA314A29B124D15C407295FEA1009C9EFAA30DD06FDEC89B6A909B417C190565D98460C65ABB8C6415D37F44D224A777F050393C33B758E7
                        Malicious:false
                        Preview:q.X'.X......a...(..}J...R.\........TYy.*|g(...]m...~.n.r..?.+..NO...cZn....N.AH.7..h.e..I.y.....q2)7....P.....@G..?..w.h...^x..O.e4.....0Mj.q..9.B.P...E.....j<U.. L.Hrj.q...K95=...OP......i.?R..'.p.T.".......D..v.q............HN...T..N1.p3X..;n...wX.{.U3......3..b.....D:5..~.c..................9..:.5..-a,.M.....fa.{2...H....a\r.G.*.=...k...s.7....b...x.I)M.....uTX....J...j.X..g....Y.^.....1qS.m".iY........o..f..9t.....c4_.....Or..<..d;..l.uV..R.....KN..M.. .+P-...6.u".......r0d9..A.1S..].g{..jpK6....u........9.>BJN...q.~...q..N..Q.....E.6..i.9}..=!z......J.[.s\Y,..A....s:.3.6.!..kpg..I.~j...Z.K+....P7.<.\N.|.... ..).......%...6iT}5.....\b..KG...-.........8.....!J....%PLX%.PB.\.E..b......e /U.^.U......2P.....O....[]%....St.U.$.+fx]..4...C.f.N.V]k...nN.f..F...bbO..S...........b.;....<PS.?e...}...5"Q..ii.[".c?.{.-+...Q..j..C..... .....4..t..9V.-,.........6..@..`...=......u..O;.......z.....5a..J......G.u<~.Z.... ..LM....yS...8....@=....G'Bj@
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:GRand Unified Bootloader stage2 version 11.193, installed partition 345944416, saved entry -152882288, identifier 0xdf, LBA flag 0x3, GRUB version =\333h\221\342'2r\354\261\026\302\017\200J\330\033\340\303&Q\021\266\257X\004}@\210\277\003\364\2135\006D\024^\345\027\225/z\356\255NK\255\3623BH\2008UM\321\224%r\262\255J^r\215\236\352$\220+\265\366\033\2709\305'\343\017KT6\3035\232`\022n\310\026:Z\214\016\252T'\350\271\177\212\212\202\025<\363\342\343\277^\026\311\206\372\336\375\017$, configuration file '2r\354\261\026\302\017\200J\330\033\340\303&Q\021\266\257X\004}@\210\277\003\364\2135\006D\024^\345\027\225/z\356\255NK\255\3623BH\2008UM\321\224%r\262\255J^r\215\236\352$\220+\265\366\033\2709\305'\343\017KT6\3035\232`\022n\310\026:Z\214\016\252T'\350\271\177\212\212\202\025<\363\342\343\277^\026\311\206\372\336\375\017$
                        Category:dropped
                        Size (bytes):2124
                        Entropy (8bit):7.911532097786921
                        Encrypted:false
                        SSDEEP:
                        MD5:E0584872D8ADA1FDF5A29F5E5FB7E992
                        SHA1:9684D12E819B92BBEA9D7820A6325AFBD5CC2671
                        SHA-256:9EA2E83465CD5954811366A13DCDE3E4756F9038874F15A1C2CE30DF960A0EC5
                        SHA-512:8F5B1D0F8260590F7967FEFA0365D377B90627F74974093FFFDCB1DD6A90FD7D6477FE4629997E00EF07FDBACE09208DEDBF4BEF800316881FE2F34E536324D0
                        Malicious:false
                        Preview:x`.L.......c.0.....C...NB.`..[.6..5b....".........y.QA].........f...N.y.X..JT{o....!....."..d~j^...2IO...I.....8.,.5nq.i..4....Hi.j.aK..p...n....BG....\@4`....$..G..M^.J..+Z...).H.............<Q..H]....f..^.^.w.,i9{W....&...O.,%..........a...b..0.....|...='.._dAi.&.+.[~.m.M.....^....:.>......T.....".i..x..}..A../.........>.z...I.j/.r.g.,.s....m..ic.....R.>S.5.....D..*.JC..&...L.P...F.s.o.;^.Q,.J..?;D.Mt...j...%..K.......[7p._e....+..kKw'..{@....:..@q.Q....n...*uxU.P....'.p'Yt...`....3....=.h..'2r.....J....&Q...X.}@....5.D.^.../z.NK..3BH.8UM.%r..J^r...$.+....9.'..KT6.5.`.n..:Z...T'......<...^......$.1@..=.`..vt8[?..`..UwL..(r].(.7.........IxL...2_..&.qsIbJO..)..?p#....-v..........N.&....I...{q..Y.`t.C.R^N.#.....|.;....^w.n...b....E..h..*.....v|..>K.=...q..F/1 ..q..1....L..Y...T.V%2..W..q.....h`..............9&9.6...,.:...v..\...e..R..../..j...I..0..E.....Q...S.Dr8-....k......N.U.f...D.._4.+.........n.4,W.q.@.~..s.......X
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1770
                        Entropy (8bit):7.8910191064936175
                        Encrypted:false
                        SSDEEP:
                        MD5:C40F66F041E25ABF014915B8A5672DA0
                        SHA1:7E397E4EF9AB7AEA3116F46B03809BB4BE04E60D
                        SHA-256:4747D0C22A86F63147D05F6A1A6024A1362E4F06F6614AEF2665BFC3B0631750
                        SHA-512:259A6489161B300642F97B2EA9BE2DEB871FDFF0113D96F84D7151FBDD45A1642A30DEF97EE17F206B505EB2DC2DEB1C1047D16785A144E6962CDACA67CD5451
                        Malicious:false
                        Preview:DW..hFry.d...k.tf..X._%%.....MQ.n..;.x!.l.5.+...n.L...R.[.{..(..-E........u.>..(e... .../..4..dYp..BDw...^!dAh...A$...Yn..[oWM..t.w...[hV.ib..M..........K...\}..:T.l.i....yhW.\...w^.O'P..@...S.........t&r..+...<n.3..S...e.=.........T`*.2Y3*p..XG8.=;P&/.f..A........%..\..s.a..95S...UK...>\"H.@N~.......t.Jy1...?..`._^..J.......d.....l.../qk.0t....}.*.}.?.!..2....J.,g>~\....R...z;.N.M~..C.(.b...H.p]a...2+..... B...+9%.s..!.6..H.]..#..TC...$FLX..:.".........=...7.Q.yu........HU0..W...C.....H..ft.=.i.N...,=...#.1....krA.....LB.X ...K.\....b..E(y....-...1..F.E..3.1.O}...]P...........E..2B#.......\.>..{`.=.T.}I............b..P.s<~.....P.. ..;...S.2....t...eCN._..|-.W`.!.rOB@./}...[2.$...N..X/..../.}....#.EWn..|..I......C.>..b.....y....4..$.0....eVh.O."...e...o.c.gkt.W./?5...b...{.5..x.~.=..<.p..:..d..9a..4...va...)....H.$.t..\\..>.......w.*..B....[...|NQ..'.j........T...8.....&...Q.m.A.........V..E.O......!..{.ET.......`...D.>..H....B.....K=
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:SysEx File - Synthaxe
                        Category:dropped
                        Size (bytes):2300
                        Entropy (8bit):7.928057079154724
                        Encrypted:false
                        SSDEEP:
                        MD5:BEE1DB6D97A62F0FA444CF3D4C9E7E55
                        SHA1:B87400D868B87ED8C57A2ACA0466C4DDF59FBA85
                        SHA-256:C086D21974AC54B41ACB57A06D3C25067077B358CA99F6FE0EFD7BC6C16E7F9F
                        SHA-512:A6A6F6A30F887A135FC566DD525DCDA0ED29E514904C6B29098C46F84EC4BF29EA8274D13F84B0669B5A720EFE28FA65B1F11D0AAD1E9E77673AF3B41A86CEEB
                        Malicious:false
                        Preview:."."(.`.L..?.P'F...HQ.oJ.j...1~.j$.sp7.R.h{.....t.....w{......So*.h=.1G-/..J.e.R.Q...u.GV_V./6q?v....}c......F`..n....,z..,...c..t).6.#....%.[....0..H7i.M.H9...8?*Gcn..|.=\o........2.Y.mhh',.|u...........R.m...\#....yB.e.....M.....z.7.\.o....6..^.e.g3.....2...=..s.+)(;.)...~....b.A....yu......N....m...Oi...+) j.).Ly..Mv.......}!(.^.6&Mj.a.."6Tq0...M..05........@].o..........9.@.....l.O.....r0o*P{..2....S;U!.G..'...$nGvz....k..(..Z.P....w.2K1nt.@......}.5.A(..a*......eSy.2(v..S.\..Q.O..A...&..`H..IHmf .p6.r`%)/tfB'.Z........y.9..[..Ch.d...AJf..@.$?%...N...J.TAn...?Q!.&.xk.^..,..6......}..B....\..I...F.....A...$.:..m..m...h....S8q+Z].~..D%..-....6..2.)......0...Bf.-...D..DeEp.....e...w..%sZ..b..:x.!..V..:..K..v"...'.D..B7..K.!`>.n.F.u.6.p.....+..{W.F.;.W....O...H.n.b..".......Y$......0.bH<.X..?.. ...q.9....r.N..a|v..?vc..q...~.QG.6...........C.}.M....i1W....;..7..T(..i.1..M`iN..L~,.........8...o.....q.........~...?....4..^.8.."u.Ut...o..{|.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):638386
                        Entropy (8bit):7.999729164475098
                        Encrypted:true
                        SSDEEP:
                        MD5:4BFEB6F04EED530BC8939F4E891E0360
                        SHA1:5AF771C0428470EEAF7E4A1B1E588C6BD447540C
                        SHA-256:D9353A25930ADEA9A0C518787ADBF9B2B08E27EE3DD51B73301AB7884849265F
                        SHA-512:B0E5D4A8369C6A5FBB6B961AECD76B9B3254C695A96905C06EB1115DA6CCFB0FB9FDA654F06BCB6AB53896F0EFA780459D7B139C7E71DF9E045C00753CC84FF9
                        Malicious:true
                        Preview:AUJ.........5..J..i.k...+......)../}G...si..h.S......W..v..'.)q <..q.P.m..>.<FN....r..v..>...=.3..A....T.....|..v;G`..#........Q|...B....=X.t...I.....q..9h..cA....f...\^..GLB..v"*........V..9.n....8Q.D..9...f.._..j..S...2...s.J......KSJ7.0z.._.....I..o:CX.u....)...{..E.S)..rFo3....6..B......0.>.m.Lg......L..I*.._..H...-.;.P...".y~...)to.y.D..{.D....vCd.g.%.T.-.8...[.b..W.XI.......w....8.\M...Z.E.=L4...V...`..'!i..Hdm..>..a...~..a...,.ge....W.q.....aj .k`J6...x.;.]C.....c...`$.[.^.l.-h.o6NM.6l}X&..y..P.....f......Y\...O...2.~%... ..X.T.....z..p.....X...F...8.....&......=.. ..j.nW..J_.. .......f./..:....O...O....y.z...U.[......Y.8kX!..^J.wo..@.F5.......X....*.0`......y..p.q..^.-.*..t....Q....sK..=...\....x...=}.Vp-.uH.....6@...5.r.:.]...8..zL...k"...u..x.n..y&..H.!$c.....L.*0~O.R1...2..Ot..i.]....6 ...`'..b.H8..khZ...0.........P%.g..O_.{~.....[.t........*.....K.+H..xA......HU3..a.....E.#.,,...p.c)../.@...,~N>:...T6x.2...].i...`.S.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):638916
                        Entropy (8bit):7.999695000232331
                        Encrypted:true
                        SSDEEP:
                        MD5:BDB2B7AFDF4EFC2FC3BE7759C8D0D261
                        SHA1:032584FF111DA3726C72DD5013298A6D7A13C82C
                        SHA-256:73A483604154224B275F35ABEA4379FDC884F3938C4C0A82D16C645C99658AA5
                        SHA-512:B0FB056E3916E9D54FCC4BD183DB71F1D3D5E6A4D9BBCAD3D4DB9657577DE6D8A0FC4B66EC98CA0E0009E4659B229E0E915458627B5468D96FD81CF34DC1F297
                        Malicious:true
                        Preview:..vJ.|+J..8...TH;.[cZ..]..zS..P..|w.G...U...k.$N..s.?i....(8.....C.a.1..6.).c.._MQ.u.B...t...n.a2W.oef...I'Y.Q..YJ.B.Q..S......B..u...CGD.Y"W.C'.....J...3....x......a..P]...,..G.(..l.."iEf....m...y.IZ.WBR...........8.<6.......F...~.....,......&'...=.9.z...p..uu.......Q.!..%.?...!.II..x#..Ju\.H...nUh...A.........zB..va.v.w........J.Z.....D...?.k..<b...G....7.g....).@..1..7S.r..pSe.N......D..J....k.X>..Of...q...=e...k.&u..sEE.!..;..m...A..JI(.`...hG"..PL.......!.............}O.3}$o..>......!...r[....5..Z..[m..R.L.*~6n...th.\.:#..a......b......92......r..Y_Y..].~..x.m..,.>.x..+...H.mY.V^..p...3UBj..|.`.{.I....m.4..._.$+w_j<9a.2...q.....x.x.{....X....7_G....B.b^...t}....s...r2V.TBf...*......l..f...c.).xx@.WU.._......o.D..MP...2...e.;9...0s|V`.v&.....;.............,.>.U...@..>|....?..DMA..x y.q...=.B..q.h.....A....[...D....<..s.../.(.m.$G)0.oh'...u....r..=. .Xt....Z[0..d......0.7.0&..u....<......%."....I....c..mrK...o..C...:.9.,.e..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1598
                        Entropy (8bit):7.897233677261131
                        Encrypted:false
                        SSDEEP:
                        MD5:48EE3FD55D6653EC6A7C2D3EB7E915FE
                        SHA1:BD7E867DD77883DBC4668CC27E85ECB4B3AB0E8E
                        SHA-256:DE509D402DF593BB0D6745A4D39FF9441557889179E913CE5B3DCE677F223548
                        SHA-512:98F4A2705ACD95A165C9E11D9D0B8FBDAF0129FCD3DF51C6FAC3FDEE0FE3658EDE7D0D4C801D19F8BB2D3CE73E3836D0507B2C7B35266BAD072662F3F4ED7A76
                        Malicious:false
                        Preview:.:b.S....>`.....w!..y.M..^.s.\NVT...A...7..!.UlC.../.k.@..Ah..q...o...(O...PU...]e.}.0.1..,L+........'.#.......%4....n..Z......".uv..L}...IHp.N_(.QG@~./.7:9...... ..4.z...#&.B*'..6O$*T.;h.B....^..mS{|..>MA!.:a....e"-..Z,-s..{..g....gwm...dnZ.@M.w..u.W....7.Q..}..e..7d...E..r.Q.3.4y....u..N...y..T..Zf.6+%^H..M......4.No..3..~;....I....-.|i.N_.v..`....<......_...b.y........E.{U..]T...+..b3.$_.5.J/.t.U.W.Y.bQ..K.\(-.yR.d/..W|...nh:c....H.T ...c..p...(x..p9.M....sU...s...+.IO.........f.aY.....\i......=W.i..=Om.4.IX.J..@.?0DO..Pm.n...S..[.7"..2 ".e.q....!ji..k>.&G...........l..t.z.....@&....&]--<.(..?mf....g.\.e..8....3d.....T.^.f.h..9f..#...C....Z...$@.S2......H.........q....e..C....fS.0c..#;....MH..O.kp..,.4...,....F7.O...Kc!.g....Vr.....P'x......l.T1.c.Ac.){C..gM.cV...=h..y..J2..}.......o~....ut...$e...f.3d&.QKBV..G...b'9s.P....r.o...\..#E.v.m4.{..p-..."..8..|g.C.%w@...^.sZB={....:NE.0.....;k..L.s.G....J.....<..8.'.Z.79..CB...8.z........
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:ASCII text, with no line terminators
                        Category:dropped
                        Size (bytes):10
                        Entropy (8bit):3.121928094887362
                        Encrypted:false
                        SSDEEP:
                        MD5:A6E6674E7A97F6982338E0AAB69D3350
                        SHA1:CD78DF730D5484961E439935A4F4E5B2857D0E8E
                        SHA-256:32A199D2D45C9F262AE8D62DDA6153225F27F4060433154C32BBD0088D80D3EF
                        SHA-512:E5075CBF2129F7806AB61C078C818897B7D2DFCEE98F0CBC8331ECC52D32941606E23BA522712BEE028A245765F735B0E76C11F729A2BAFF3C40EA963B0DE722
                        Malicious:false
                        Preview:7H4S3UQ1F4
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3866
                        Entropy (8bit):7.952576805936191
                        Encrypted:false
                        SSDEEP:
                        MD5:FD7343A262B1AC607276282048D63744
                        SHA1:1CED3E068A25105733F9128A79FFE042E548C550
                        SHA-256:7B6BAE12019D7A7349B20FB08FDE62B9804D86044413A5CB0375705DF5F6A320
                        SHA-512:8292F55F17272D8A5DB170F2B29784514335441A9FB8F61A3D00725A69E71BCCD3B7D285BEBFC7AFC9844F4AAF8307C01A566421024F13C1F4A34D489F8B7538
                        Malicious:false
                        Preview:..TO......n.\P...>.x...:D!D....>..ypd.nn.9r.D.b....\...g..bh..........H2.0..?d.x1.%4.<.>...%.q.G..r.Rb.s.,VO.r.*D........R@....q.z,.....`)..=|]T.a.....k....z.....o..w.j/XU>...+o!.x..Ci8...H....x.~.....Zu..5...">.L ...l..'.W...LBD. ,.h...7...!.`....g>6_J..~.J...f..M*:.R...T@^.2.*.vK.M4=..N..2g.5.R0..o..a.....%.C.7~Z..!.....f.];(.. ..]...2..?^<t....^.#..L.%.)W.p...9Zj9<.G...u.a..@R.....%.@...}....Sa.\...xd.(.&.I.o...,y.......^...D].....L>~...925......A.~...".l)!..)..~.jW-%...R.r61.......0!y.......S3c....c...$$]@.c..I..y.3@R.....J.h.+..h.(.([#}Z.,....u?.?vw..w....$T2.jJH....H.lttc...N.6......g../;n...-.P.....D...g._...h......q.G.*^....W.'@.y.K......6..S.i.......*Y.....ry.....{X.@Mw..'.]d.aU.....M.Z3/.nJ......6[pL...j..su...,. Pc.5Z...+. .U.K}i+x.j......zJ.D...._..... ..XPC...c:...a.^.Pm.4/.*P./K7VU.. Eo3cG.X...Y.'<7......pXto'..*.*.h..}.^....V.yn..hSB....8...#@.,...L.@tGQ...d.X.3f.I+.]2.GD..w..D..P..f0!6.D....nw13.diV+.p.ZO..`..K
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):754
                        Entropy (8bit):5.998186698544737
                        Encrypted:false
                        SSDEEP:
                        MD5:6CEFA56E6216B93780A9D0BC0242F76D
                        SHA1:791C32D56A8FFA1F3A61DA4C2E216C885D22FA2C
                        SHA-256:51ED708186F48A4AAEDE5BAA4B1CBA0E4EF3591C5F769D43A1F1C45F77ADC12C
                        SHA-512:DEF6EDF1DF6F6E963D9C48B16550A9D7E9D93691625DA31524CBB6B94FE66B1821392A0A4F5CCDE6926DE95F8EA412D85173D6EEB5A63D11710BF2A8B15EEC34
                        Malicious:false
                        Preview:MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAshrJlqUsdrkESXUyIdxJiEFOuidk..UWzEg/7QnPpkaUfeoAKyOJyZimP1hZ/JrG5O9BW2s7v+5aQVY46JNpPWSa4dmy8MWM/dhJCW..CpSpev6cE2pM+7x3FttUvYEkHKi281qpv8F3RqPrLSQXLkWJmSaFu4qDTUc4bpLZuPIsiD75..UxjzonFRw7c/6/PyjAXzB4u7/gVSi3GwzUT+QU7oVX84BjDWIHl9UkKtbZ/xgchpiQXksmzb..rRArVdXyRnSBezDqoOUEW3OpPy90QAuE6eVRdrF6zMN8FFeqdxjgCBaq6FGNzrRmac/Sg2EG..r+7WPVLDyBsR0yMP5NM+zU730XD1ZCxPKuPaFI2mNPAbMG4Uz+jGIfoOtFe5bIaoBKZ+pWRJ..ByC2GnX+7Xpyfk3Dl3M2qVhDqPwae2TW/LLZJgRFHJsnv7QyV9hrLQJAZbBOpu7jrfDN96gg..fH2YOK88d381XQ0SB7cQfRDQT1/PhSV0KHwRQepmgAce5Xwfzf0JMAg2tLDjaQZ0AFt4xZx4..KNy8bniJmh2tAXKi9crBri7qL8hZlwEncTsgVjXhi+SZubtsiswUDLr/lN/UvvlNicZvpSlL..d6a0WvsRrP8OGud40fEY4YVb3MxmvQsKM2yRybVqeOODAzi1EK4BC9r+h6MlIFof4NB4WbCm..2Zk8KkcCARE=..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1412
                        Entropy (8bit):7.896050437449815
                        Encrypted:false
                        SSDEEP:
                        MD5:2BA71FC66A8D3EEB07C8EDA90EAFBD2D
                        SHA1:5F0AD54F7898C90DD6157EF016B65FCE0248EE24
                        SHA-256:C0F42F0AAD2ED08B80FDCFB5FB9FBC87FEFAA41A5E27B6EC15D1C455C634CD14
                        SHA-512:7FB59FFE8EE1DD0D6FEE0AA13E18D068A1FC6EB8DCA0A85BB56F12B958E77C814D09D203BA791E7926CE3B7D983CA08FF73BAED10794051B1B7E8CE0E7053A2D
                        Malicious:false
                        Preview:...'."Co.i...|..h.x:.#...v.h..oR....5`......j............%.....Ha'W@..3$.d..;.1Of..Lkg..O.....NG..fs`._S.]..$.}.h[.d.(.U....P.|.k^......vyj.s.#ZJ.......3O.0..zB.'...."...P....r.'.z .....V.jK"=8......L.R[.$1..I/2...<.Gq..x..I......0......\..........2......E...:.K...P..|..w...E..d...A...s3e3..._Rz....x...H>....6#.N.<b.F....%.......K.10.OA.?.rfc...3...~..;....4o....D......3.R.t.#9....^j..Q.#..B..g..<y....|J..Q$x.Hr..0.Cc..u.....,.P..By.|..S$...k..G...~P....@n`b...y.[....b..]'...l...7F.=UQ)W.9.....K.a.co%.. P.^.~.V..J.(.?..(.....QKA.[.$,~.u.Fy.k......9.1....By...**........^.]..,;f....6%....*J#.C....Y?....p......aEI..C.p.M....@.2.._...p-.....J0...)....O..rxc[.....5.)t.|.2...... ...pv...-...j.....3.+.tEC...2..w...Ev.V..0b.6U]."...........vr>.gG...tt.^4~.|_#..%..XS-i'p?..xj...V.K.x9N. ..$.]}.{...4...*5.d..6$...b8A....N....e.X.....2N..._5x........J....XC...K:I..............]....9.1..$.Q.!.F...8%Q....gL.b.........|.[...3.....`.....?.8U..0Mn&..hm...ED...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1394
                        Entropy (8bit):7.867011063153508
                        Encrypted:false
                        SSDEEP:
                        MD5:00F3E65FA533E65B90E137D5C119FF07
                        SHA1:8E6AE868475F854D11383A5CB8EFF740B35D5575
                        SHA-256:577E31B047586A4D99BAC07A6674C2F2AA18D63CD5B54B9CE7EF77DE424075FE
                        SHA-512:ED0A85C4F430053450F872C4B0981344D5CF792A7E7B594177A52AF3AC85BAE7754CE1A60F9AB8FD6EA880CAC028F0349BE3DFBB609881FE2C8759130374043A
                        Malicious:false
                        Preview:w.#a...:l..c8.K.\4~|z...(.V.. Zy|N.. ..6..l.T.q..M.....r.....]W......-S.:..80.....I...e..^('...A.tvXP...Y.'..C.n1.L\{k.H.yW.!(..8.....3.B.....[6.`......x...+.%.......t95.%.!.!.%...Q.}H.a..k.P3X.^....3Q..t...Z.."S1dI....a\B.r..M.Z0....l'.....]z..s.......6#.X....?......%o81..G.-2F..n...,......m.{.K...N.N.......?.......v@,....~.=..CZ..2,..~j\i...h.6{.:.6.Kr..7i.tR...cT.....s.......`"...#G.j..."..('.D.._...........NH.........:K....7e..^..d6n...#.F..=9.L.q.....5.V..=.K......,..f...9....s..N.R:...O..$3....6v.-...V].?.9q...6........R1...3....U~.O.1..$...0.......i...W.x.*........a$....q?..O........y.)...Z4.P..B..^.x+#F.n.jYW.......[.......1.Z.5..z........C/..wcl.Q.......|.'s..<.b...C.....i.^.%...E.l#....N.c.)f..hP.f@o.....:..L...._.n.t\..$.b....b8#.E.t.....|..\.N...d.M...G.........u?.I'.....6g....F......$oP.pA...B....|9.M......x..K:..........O...21...J7..]<..Rr1....jh?r..Ps...Y..6?|...i/..S([.h...G...z.`.nE.lO.+...{..#.nh.....V..D]t...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1738
                        Entropy (8bit):7.891768814837751
                        Encrypted:false
                        SSDEEP:
                        MD5:3C8A3BF1BFD67456449CE0DDD02243FF
                        SHA1:F9C0D6646A727D8D885600666ACC30FE6FE7B12C
                        SHA-256:0F85E1200BE73CFA6260D3F1111975881C0340A400DA8883A20EE834879DDBE7
                        SHA-512:9D5E846EDE7ABB4B2D807F45E2E63453EA38018B5F073376FB6B53DAA9DE369ED277A828F548DFA0FD01A43544340C5E0CC3C47B8B71F1AFC759E3E39F5863A8
                        Malicious:false
                        Preview:..b....f...n1x..g.....sj..\..:..A.).ut....V.../N/r._.|...0.*G3.pEP..G...V...U.O.....@.c...(,S.......ppjR_.\?gJ.....0.Y...c.A.A+.jT..:m...$.....*uhc.h9..r.d6xdK*~`...J..J.#...>:>.....a.......bM5....s..v....v.h..@..]M...an..>Ena..q.s.....{.9.S..M.c!...J...#.r.r....d..e..1.L. .@.......!9R.L........Y...Pe8..s...&.....U8.Y....8.........e......6SV..n.efh.tr.h=..g....r..\.....o..(.......u.`.. S.:.oW..b.[..G0..[.2...e..5........)..S........T........3..A...*v.[...7.........P..b..<..h).t..Q^....6.e.....f\O...i}.f..._.u.x.1..PC.......L..#..........;..Il..g.:......o..l.3..{O.>..b.?A.q.L..~..o.r].Lr1.p-.jh...D..m..le.....O..WT.f...Tt.0.......KF.E..31D..z.4...6.....B..G\.8....VlV.a.p.t.v.."....+..>..D+..Z8tHS....;.......E...m] ...k}yrQH.x..\.....;R9..._V?....j...C...7;Q_...x..p.F>...x[74...yAW....Q3.O.|..jA....d..mW...'o..*..1.......!..I.zQ..j.....L..s....^<.bw....Wy..J........q..t..X.r5=8..6.t.C^.N .....1Ah...*..M\...7.J1.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1593
                        Entropy (8bit):7.874213028836778
                        Encrypted:false
                        SSDEEP:
                        MD5:9D1583290A55619FC4A2812788ABE977
                        SHA1:55E3C096918238BC63F76EFF362EE11C72889BD0
                        SHA-256:B6B20C53A4DFC7A4B195588B682BBF8453AB4C181A51CF09982B558620B95CDC
                        SHA-512:0AF99033886FF3CC993DDD3A76D6E54AFED2CA40F7038A478D06C710E4B57EB19DC515A3487D00C72615C8D900DAF1E202DA149B4548EC64E242973F8AADA34D
                        Malicious:false
                        Preview:.....T^.KyF5..g..CB;....@.e...r..%.L.P....o..S/3_..|.b..G73..(W.w..%....Ow..x.{7f....j...T.>..n...R.ba..[..c..^..xsPT.......&.m.\.A...>......[..6W0...$...q.{.9...i.=.^?...z.l..o..h.ep..a..R.v.%.. .S...o........F;QyBFH....-m|2.8..{.s..n..:H.i..mx.......6.....qjj._.>........J....s.s^1..O..9......,.k............O....\.bu.;|...s.$.hx..^.c...C2.'....T..*}v.y...y^..%.!E.Q...>...!..Q|....ip.jNg.._J.X2[.V.<L[;\.bf.n-....h.E.Qn.......\s.PGV..j.8't......`...........}Ht..gWd..iF.Uxj..V`...^$a..V.2.d..\W...6..5 ..3.../Q.Z...sy+..../Q[S...G...J6..{.).=.$.|.....;........H...U..GlE....9..&........?...!3.7?5...N..ae......t.#..i.W..t......y.b..}l...j([....4X.m...,E."B..jv...|r...(Z4.VP...Q.2..4,.n...0?8..Q......g...a..)6........%..[.E%..(.?V.0S2.(.Lh......M1..eD.1b'.d..0.Ue9..8.m......s;oT...}..W.Q.jf3..Nn.T.4%.(2k."L.L.d.,.....$........x.......j......:L.9.]....M... ..... {...#6[.......UH.4..M.d$.....s[o.....9.../..G;(F...r.`.. .38.AXs...5.....j..l....;
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1597
                        Entropy (8bit):7.87001798189352
                        Encrypted:false
                        SSDEEP:
                        MD5:DFFBD5B29D3B86B5D470EA5CA5B7AAB9
                        SHA1:FD9F99621EC6F4F85857F1FDE6ECAC7451A304ED
                        SHA-256:4DABCFEC80E8A417C465FF8459504D439D153BE4310BFC21ED2F4749A96D0457
                        SHA-512:AAFBE09D493919F16686D49C288CAD85A645F1C0C7B1B336619C5E9739BAD7EE041D416DA79AAB51C242CB90DF8226C3C57CD728D46767EB5B3CEF72393E4820
                        Malicious:false
                        Preview:..W&2..U^=.z..y7.h.ic.4/.nf.J.B..........#Os..`NZ.....gf~u.Z.C....5...0...p9..].u......BWOv..w...x.,W..v.H.......;h.HO..\.(7z=6IS...H..... :o:N^..#...a.....+.......F..rZ.....e..aT.`T..o....<.[3.*.........4.t.h..$%..........b_._4.S..L..]L.fZ..7l..I.a)t....Zj...%+1)...W...a..6...&(/._.n..D..gD....!.p......?..%z(/$.M.L..Z.......XA!&.RX.*.EO....}.s.*.p...1,....D.....cO.....i.tp..s.......;.L...UH... .r..NE31@.......z..NuL......l..?5..o...G.c...z.....j5#k.4\..l}....;.....~.{!...f..,...1pr..l2%.=S..Q......z{...&e.j.R.{A1D,.~r..}.G..l......2oDm.......L._|..l......G.=@....G....h..O...@+{;..-.....%.$.-^..[%....4 .0../....\[.~.^...+.Oia..D........h.q|.-.210..N.!z$[.uR....w-.....%.s.L.3...m._nU...j.:(.......?...U.q....v5F...]@.W...X..?R..o!.......=.z..03.....$.X. ..|...x...ek7.-b......D..F.4va..yzy..*...R..Q..'..Y..I.>F.d"..\..Q.@......j~.il...1..S.@T.8.* .,......!......G...[..(.{....GJ....].?.H..M...h`{.>..|....6G.E/...9....n.../.r.......
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2702
                        Entropy (8bit):7.91938689947353
                        Encrypted:false
                        SSDEEP:
                        MD5:EDD9D0ECA1D48895B4234B2061708A0B
                        SHA1:1609945F8856BC40118AAA9F652899AFFCC843A4
                        SHA-256:4C4B7725D1FC72C421151B1D3FDB7B7E658E4A20CC907AAA7E5C1A799D88B0F4
                        SHA-512:FF5520DF6093D301B61AA1CE3DFF935B6A421A458C81684AE13F0F5579BAF0DB9AB6E1E9E8ADF16F2632AB7F707C3FFB344BC234A3CECF9562D8B38667D2B1FC
                        Malicious:false
                        Preview:z....: '.....P %.....&5....6/.rf.x.|...+.$....%J.yr....._/r..].MZ.......xt..5....1...U.o.,C..<).LD......d.SDx...$r..........o......f.J,.....*!......p.v[./..e.,.Y...f..6.ff5.N.Sng.,.*v..1./.8Q..>.M<.H.?.Qt.\....o..]ne.Z..y8ro.#%..y...ZG.~1.x...i|/%..J]......bWfw:.eCb...m.h.......Ve....R.3._...`..{.J......lWW..+.a.L....BX.Lpa?....;d.?$......1m..|...V~..g&.KH..e../.P....Y..@;.....<.h.._.#..1......d...6.5....6tH]u.........'7....~Q.4..c.;Cv...., .....igC..,7.=x..?.......=o..Q..$1.`..}...s.;.vp.}ZTh.ky.....pJn......#!3;.+s.<+..=,.Q.....v......=.|};...... /!.l#e.....!^.N~.x.z7.,o...~).#A....@N...........f?.q....^...B..7-.U6.m...QY.n....0G.0...v..........kaW...s...5...zy~Y.D^.z.,`4J..r...`....C5g.........B{$9K.IYLv\]...@Gj..._.|..r..Wf.....,q.>qE...q....K.k....K.SW...u@B...`n..M..._6...:..p...W@2u.jF..n...N...B../.....`.q.&.y..M"..f.T.........79H]....Hf~..^..g]...&,H......6...&..nu..F.$..^......_.msZ9.......d7..$...S.n.'w<....M..9XU..V...N......
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1594
                        Entropy (8bit):7.8793796176965385
                        Encrypted:false
                        SSDEEP:
                        MD5:219E1D00D8C47A3E51BCE27559AA42E3
                        SHA1:EF10A88B8A126999F42883CC3307BB2D7F1E126E
                        SHA-256:870C68C3BE367B663FB60BE85B8E37738BC84E65014AA259A1487E4B0EA8C218
                        SHA-512:DF7EA145B2B53B0536A8BE5BF607F16198D98F8D7C1A36C2FB2A97B11FF3206FFACC647B20F52BFCBD85932C5864BB1DC775916318F1CADD770BE3EBB78EA1F7
                        Malicious:false
                        Preview:..&;..I#/...M...\h.3?8...w{.....bO#.91..e@Gckl......i.(.DW............aY.._..?&."...._...%..Dl.j..?.,8..Y)..:.T.-o.k.Q.G...t.C.....p4.....{._......3s.~p..K._.|W{T...b..W..ZY.~....%. .3..).7..s.[.....g....Ls....O...."..B..".} s.P.`..80.JP.(.V....m..........z`1...Y@.4..?.fw.2}...6IV.O.v}E.X......6....".nYt`..Z.tgiy.9.cw..enS.#(\.....]...;......gcn}.|...1c1'i.G...gpy.I..WV...4M..&;9. 6..9.i..._.!.(..Y0Tp.>M...Z.}D1.,...t...x.9.'..@.......Za.!3z.........D.FQ..~..+.iH.......f.D..[.%6lv..[..y..I..X.=...qL....y....K<K.&.O.S.Tw.+.'...f~..,5.M36i..c.3........Q..}.....[.&.`u(.F..%..B..dG....H,L....q.1.PQ....H.!.........=..m..YX....-5..g.6.^.C.)....9.....h....P.*..Qqf...[a\.Y=.....o.6.@.y.E...@............=.........5Ei.....3Z`...Mm...m&..7..*..+dy.#lw1....D].p[......o4..........R.~....kIj1Q..Bs.T%....)2..D%..N.'l.v.T....J.=.P0.X..q.6...'..O.UO....}....9..=.}T.|...B..8)..@....Q.......K..UR.t.v....A..........K...Q.{g..6.8|A...L.....L...I..,.V
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2148
                        Entropy (8bit):7.908211368881754
                        Encrypted:false
                        SSDEEP:
                        MD5:A534E02D8AD9BB4FABAD31483DA66C49
                        SHA1:DF12CFE658A1A597456EB9282EED7616A404105A
                        SHA-256:5124D63E24698093F95A02D7F84F85ADDCD27CB9A239DA0A930FDA111C5FD9A0
                        SHA-512:DB6212970642D72B900F3EEED4F2AD0A1298BBC625BEB1B69696DB1E53284A02597AEB95145573578CE38D29A8F4390F03A26AE5314536C27D0EEACA268015E1
                        Malicious:false
                        Preview:.:]y..G*pn..5Q}(...w.<T..t..lg.....)..I. U.Y.0.(..rz............9{K5$.3.e.dHNM.+M..&.Bd).RU%9.N..DCS.....'.....#A\.o^..y.&..^.oD..zN..8.T.q....~<.B.....N....._../.^....ue..ZZ.\.uy..b.t .3...S.4.$N...L.......z...Y.d..I'0.}......NV.}..K..B......".K..........x..q.Qva.!,X.v'..n.].L....P"Sk.T.Qn..X....I..4..%.......^......V.{.&.))...Q...U..........6.E>..s*...L.W.a.(.X...7...m)....h{....C......{Oup...d..~J...........4..7...d#.EB.~..f<.*._.d.H.M7.$....}....>...p1.|...m.p..~.......4.;.%..........;[....K4.B......F........$..T....FY.|bJ%.i:P.. ..1..S....A..S....Y=1Wx....(../.norIH.7.v...~...oe....Y.8..d...^.P._....k.*XiX.#;...JU....ww.\.;....$....tk[..`.~3./.V..5e..8h..D...N.'.z....F .!.....S......F....(..cX.b.....Z.o.S..K..)kf.!T..Z..o..x.....Kx.zI:x.!....`....XT.6....X..j<..I....T*... .I)...$@\B....Z...t9. .=...E........\7.>...R.~>..~DU.fy.V....oV..W....rN..`.:n......h..[b.2....5c.d-:..&...'I.LAz.MI.H....;...t..V.@#......,.H.~... 8O.0.bG\..?...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2696
                        Entropy (8bit):7.928491483695972
                        Encrypted:false
                        SSDEEP:
                        MD5:E3DA4373C59CF4D5367936CE3C77FEEC
                        SHA1:957F9BB836EA021A75E8ED0221298E93B94C3367
                        SHA-256:BF24AC34618624E2DC1E34BC1BB97263303D700C07696D931680F408916514C3
                        SHA-512:F81BB250D82D50F8D4F4B11500FF33F7BFE583EEF9106A084C27ED462339ADEED32B52E5ED3F6D811795A3150F26E4D5B5CA48563FD1BE4437F69ED93C418F07
                        Malicious:false
                        Preview:..S.A.O:.......\..R.-.U....).._.......y.l..3H...."n..S.Hl.>......v..].....|s..V....f.c....^..7..#:/?...v...zp..q....Y.......X\.T.%s.9.d.{..m>rqK.......s.H...iM{.^.."d.WA.{.eW.<H....-/. ..p..y.j0..."...W........K....5.7..C.o..$.e{..)F.....l......Kv"..Ea........G.u..6...k.~...&......B..o;P#..].co;..HA...us.....t.aq..S.c....&i[.'...N}...[.C....O...6z^..A....q3..h:.........2J...P0X#..1........ w....Z].'.5....r...&+n...%F.+D.I'..=....u.D.....|......\...H../..M.h..@.F..h%5.1B.|..s/.v.8..#....LO/.x..1u......\9....*.....u..V.@tPM.},.[...^....TE......uvB2......e.}&Kh{._M.k7....$.....j......v.....L...Z...\.j.....m.K..#....N..1]. P#...9D..b....4...f/.%..*..P..w..@r.f.k..6n;...-.;7.~.DV.n...bm~..}......K.b...(.O..|y...k.,`.&.....v;.\.V..b.A,E0(.*?.5UIcRO.....Moo...pO.._.....-..@.Hg.X....?.t..U.Zs../.r....!.W...h..6.zN..h.nBi}6k.....B..}..7;...*..'*1....vY]......u...kK%z.8...^1.=..-.7.....3.?..b[..<.........h..i.....q..N.....^...."...z..h.. .Cf@S..^.;
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2698
                        Entropy (8bit):7.942623603981066
                        Encrypted:false
                        SSDEEP:
                        MD5:13BA2BA1ACF13CE3FE4F11B24651F430
                        SHA1:8DF04CC7544ED166814ED256ACE8B08460506B7D
                        SHA-256:D009E717BBC7CF3F7617269DB635C40E6471B6FEE5F7394A7B3F6F284E7CDC55
                        SHA-512:BEBD1004BFD013196886965C07ACB1BCCF5C472517C6B90F4741897C7882ECFE94E4BEF7947930269D012FA1986934E4AF73FC13DBF657F730BC8438CE2C0C4E
                        Malicious:false
                        Preview:~..[...%Q?.V......2...;2...Jy..8..PD...*.L...i.s..O..e.......h.2...._..t.. ...m.r.....]i.........B..P?.........4..=S........'.3..<,..n>...........81..W....y...I~6.LW..v..N...o.J..{.t1,t.8.Sv.<.....mI.;.#..fy...P...8.$:2z.Q......J.n.L....9m.m.!..t...P..V5~.K3..../H;...xi...T..}......34...;...m..4.#...c[.....R.N..).@..al..Ef.o....i>..[*=.P!bp-.. m=,.,...0.Z@..(.\.I.c..h..J...P..#an.L.;.Ju.a.:.H......Q.....~..P./p...qB.E3F..(.....G....BM+.!.F........3...#A.g..!...X..lT.M........(....D&..V.._....CN.....3..Z.;.....||...|...`U......H.,*..77p..D.7.w=....?J.x..,..\....J.../.............bv...Q...`I.v.Y...C^.^.....;..];./..%..aI...L$........P....A....T.T..?.<.t.1].i...M.b*.?@ :.v4.....[.K.I...z..h..fW...j.3.m.?F..miSw..3.+...*.|.}`.!9.....O.i.V.....hh..zF..........um>.....R.3o\.L......5.....x..%m.........v.G$......*.$.O>.*.6V..d...e.. \2..Dnn..G...(au.U[.[v.....ZQ.)D3...aEN...B.y.XP`...]M..X...;J'. .....QDfG....g.Kd.G>..64A.k.._..$....#.......6...o.c
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2696
                        Entropy (8bit):7.91975132851868
                        Encrypted:false
                        SSDEEP:
                        MD5:AB188D045B7D323EECFD7A7A288A6789
                        SHA1:25DFD97B0CF6D58B2255BE7AAE706B29354D7C20
                        SHA-256:0F152A4F852E487551092D0563642840EADCFBAC02C9FF33E875C863B2C5BC5E
                        SHA-512:3FBE4E10A7A8764FE35938CE5D034D1F6743B85434D4D5631F93E925352DE737B868320FCBB483062CFC3AD26685782F92FF2787858712568102F9482BAA6460
                        Malicious:false
                        Preview:.S....?CQ...#.5.B..6LZ...'..lC...T.o7.p].`...%X.7...0.G. ..wu...A./.B-....R........'.Xc...7kp8...i...']...;.=b...*S..H0..jr2.*e..1B(M{..E.........~.....8.8.[3...`qe.s..!.....`.X..p.............M....=.].w]x...x.."......1[.T..'...[.8vP...{.VzD..#.v..c....h..h..<2s.....h...>.ffK....y......$ *.L...q.:.....@m..\.`.t.Y2;..n1.L.N .G....@..(.p=...X.WE..}-..Y.?|i.G.i.G......y........Q..:..`.....J.{i"......u.. (.....w..Z4.P...'..H^.|......*;.G.......[...w..u.....v...+.I.9*....../..).`.E..~..........&|.3.Gy&R.@d...w..>.(...U.$.T.s#,.-.....KG*..-IK...\1D.+0K)...R..O........Z.m....}...N........._.....D.rv.....M.g..K].+.h&........L#6.j...gf..}......\.....x.....jL.L....'.)b.ZM.3.@$.x{n...g.8h.....N;a5..>....dZ.....g.N..........G...f4.`...x.F.....Y+...v~.,.2...M..b...Nh.....w.a.1....y.g..z#..&\.Kp.b4.O\..5..&.1.F&..eTg.0|.R.u...4..P.....J...)..W.;0.l.0.v.Us,.'..vg........Ex(3...S.^.:~..Bq"Z._.B.)S..f....y..'iP..Q2.#"..-.j.<..=7...CZm'H.Z.z.v?!.v.(
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2158
                        Entropy (8bit):7.9281462149828235
                        Encrypted:false
                        SSDEEP:
                        MD5:BCDB8E7D875B9AF0C965A50ED2B1C795
                        SHA1:AE2B69F0FF892B8E6ECAB09158A90C7BE4C01360
                        SHA-256:056BE2413F344449CF175AFEDD9CA2D5E57F97310376A0291861E1EB569B60D9
                        SHA-512:2E49BC326DA80EB31EBD452F4F2B0B3CFC73E217CC71F93B20464B6B2BF6AA0B158A3E1FF6710A64EE1B9129D7DD97A90CC1CDD91FCD72589852A1DD4AB8CD02
                        Malicious:false
                        Preview:....&...u......\...d..W.S..%..*MO.[...L..%pb...j.uK..s..ah.t<M...O...g..1.e.0RR(...S.......f.P.\...M..J.7.3;.?V.L..].%..S.X4.......w.B\..k...F2)......>.0g...Tzqa+.-....[.8.R.{..............Z=..YZ]....H2.z...> m!.B..x<.ar..E&..A2.2.M..qb`9b...G-..'.5.Z{.C.Cl}...S<U.D.{.p.`]....#!d1.v.|..l$..P....!.G.Q.7.AM.E...!".Xc...D*...8......6.h......i#..z...{.XS&..6....".}h....<.........40$./. .@.D..W-6Cm)..n.=..&.....n..h.c<.. .......0..........t.A~(>Gd..v.-..%.~...1..;G.+.w..o5.._...C.bX.....Q../:%..-.b E..Im..!..:..QU.v.Z4N..{...T.z.8.K|oH.p..'...D.|.5E..j...p.w..,.......K....n.h...I.#~}.:...+.....X..8.#.C.O...l..A3.&.2...HB:o.5*.d.......>p.....f-..&..*.28...'..Q#....9.\.....+.........e....... ..*...:...9....+........d....:...e/.f.....*....`/.R...e..{...M...V.Ip=..%.;).m...r..kVON..G`....U...X.Q.S.[<].....>..f...).k.[.Ewk....KC.z.t...I...=.........A=...<j.n.......x8.%./+...q..}l.*..yTzz.7./.sj1xN.....$.k.L.....N(.k.!.p..............h.e.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1808
                        Entropy (8bit):7.913665653036657
                        Encrypted:false
                        SSDEEP:
                        MD5:37538EFB6524758F6E4F824E14F521E5
                        SHA1:5DF368E136564CE588132329544E8B42F228B931
                        SHA-256:CCD61E5CC6A9AA338A69EA786B69EA9BB46E15F90FDA3838579471632070F3C4
                        SHA-512:125530908C88FAB28FDC300B949EEF77C0DCE142F903AAB1AF545BBE6726C460A25828F3460DC115ADE76FF4BB814AAB8922E4D25600EB0F3E1E9BA0D6F7E5A3
                        Malicious:false
                        Preview:.v..Hi...H....G9..&.,.:..2.[...DT.....}...^v.&..8.......T.._..{..B..$9..c..l....n....:........."..U.`Y|........U.....7........VC..-.O.,*xo8..8.Y._.lI..$e}..\.p:.....}......56..N.....-.q.....}}.q6H......S.'.....T.w....5..P9 .C%......:sX.x7ZS.<.R-..........4.t.Nt..S.RF.|J..m'..G'...jQ....O..t......'t..92.w..k&..l..PeB.%~$_y.O.}.n..........[9.b.$.Tu*......).&......1..X..G....&..7...C....e.kr.L.n....p1..x..*.U3...M.L~0..fk?m.B-z.......H;.9G.X@...5@4.+a...5\.....u.`&....@.BK..s=...#..i.g.fA5@.Y......`.`..e...S..LU..E...).D.N.._+."^.\j8...<.^......)....#/.f.].>.N'...u4...{wue.../pjE].....H...j..U."....)`!R.w...| .k9H..O0.....J.l.&.SC!....n.....M...6.8.\...(6.!..{..X.]A...i.....1}..p..0.....f...^..P..q..........s.X.^.....8..rf...C~<2`..h;>...............m........W@..C'..h...:..}D.._#Y+.....<..u..J..X.jw$.'+@Z....../.8.Z.~PR........3.t.......o..EQU.*..,-....l<..M..yA..0...h.'.......5.4yG.;.w.w.;P.`.I....mpA.....v.P..4Z...mF.z...z.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:DOS executable (COM, 0x8C-variant)
                        Category:dropped
                        Size (bytes):1760
                        Entropy (8bit):7.8953061106832605
                        Encrypted:false
                        SSDEEP:
                        MD5:98C62A8352341B911E7F7D09C3C63A2F
                        SHA1:4CFE8F1E2FB58FAB8D99B566CAEFF80472957696
                        SHA-256:850FF7604E36ECDAF99B62B2A3F0F2B53ACFB70200AB180622071FE69BC69A6F
                        SHA-512:1BD6AF64DF0CB74E39DE1468F80E9A327E43BE5C25BA2783C3955199222ED76C02D981271E4206518725F69CC7A1F8E037032CEEA0EFED575E0F2D8FFC357265
                        Malicious:false
                        Preview:....<.eL..d....!....b".hP... .+..D.3.Qw.fb.Ju.b..|F|.B.}P.8..Hc.b.N.. ......p.{.x..q.0.\I%......@sLQ._._s' .U....x.n5{b.Ag.H..L)9..C../$..!.n.f.p.L.?I]T..6{......;..*.......:...PP\.../.8w.jM#.FZ..-.....J.Y.s.4.H.X.......4...;C...<..2._..ta|r.=cn...{..9W.+..\..T..s.CC.V..(.....VV.Z~..h...|C.&...Q...Z......[.o..1.x.r.X..B.Xvi5K.m...!>q._....[..0.r6v-..f.sl.......j...}..y.n}..Y.I).#X...c...<q..=....%.FZKG...0.o.M.&..jFc.E.g.:'.e..v.Hk.....e...c.qv"....mu.1...t.....{..j"..>.huL.F..5.....I].T.v.\.v.8.t....'..0........a,.........kUP.py.B9.....g...h%....R)...V'6vd./.w....N..Y.z..{.Wg.O.].......t..W \..?0....~m.."......@..}......R..O^|....s..".j>....I.\..;..-..-<.X...qG..;........[...7.....t..zz1.+1......p.....S...0p.+O..QQ[8(...l.ew...S..@.L)....Y.............~.....GV...'.......lR..Li..d............(...).0.Z5\....#.Y.~o.+....xz*3...|...C..>..O>......H7.ic&w..h.M...y.&qSN.&..W_LF).4Z...b......,.}.I.*.........z.d.zQ.T....H.k..q.wn..iN..y....R.+...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2871
                        Entropy (8bit):7.9297822238540645
                        Encrypted:false
                        SSDEEP:
                        MD5:231D51E255A92F35FA50C88132EE6CDD
                        SHA1:9C8367E36BBD048860EA7B1FD8269336E43711D2
                        SHA-256:60CE9E51560ACD70B8DA5017D164872D19E690B2D7965B0DDDF497C6EB1ECA3E
                        SHA-512:A73C872DA59B9779A1398A6930F26E9C3FCFAAB8201395B3C466EA7068AEF8B25F8A67EFDC900E9ECDF7E4E50B7F67ACFD8CB04FE3D3CFC566BFBB4C3BFF92D6
                        Malicious:false
                        Preview:)....0j.............Pc.o9[..#.yX%dW..vY.."d.#m.=.SK....-Z.;.{.....wYj..m.|...{......6.=.G..$.y.o.<.'...^c..%].Z.}......E[G...X.x0.6gB.!k....o.....>.c.oU...p.>...W.5.,{.K..,Y....^..5.$[..M....dcpC@,.@l.....h...BL....-Sxz...j.~.[...M..3.....Mde.B.\..Lh..u.x%..>N.......R....I..L....%.\a..Q....e.2O.......&...S.t|....:........~.......N...Ai....;..M..06...r.63....s}. .y.....L#x+.m.N=...o.pt2.7..>.@....v\..G...%/**...,....b.0...3..w.1=.-.4I.~...X^.d[.p.O?..J....j.7...Q.X.a..x..?..24..VKSF..t..hM.(r7..B{.eV......u8.W.NN..2&kNtM.v*.j.tG.9...7.%...r....U....P.8.....T..#I..W.....h...-..l...d...$.N..1.4.-iY...Q....g.5...]...f.P...1Z.#.@_k......Lx..rD....-j....T...N..(...8....!.YJ.j(.FF..m..hw`*`..EA.w..+..I......l{a......Q.w.c......,...../.)g6.......&.I.%v.7...'qh.F.J..|..j.m.bi.l..'..Jq*V.Y.(7.m...\z..D[...\0.....G....v.%,Sa/........%e].Y.A.|..n.D..4Y)P..$..f.e.-.../...w.....x..u..GE.x...*\...]a.I.Q...T...#....o....pY_.i..........e...a.?.*a..V..M.F.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2732
                        Entropy (8bit):7.925782376836183
                        Encrypted:false
                        SSDEEP:
                        MD5:37693ABE91FBD778A1DD27EA12BE4AC5
                        SHA1:3BD2A9A073A42D0D3EEAC90653392A5AAFE624BC
                        SHA-256:7D267BD8A781D38BA5670DFC83F332EBCE29A89C1619C140CCC5C4A439D02F6E
                        SHA-512:93320350E188F02033412563ED6420E59CAE66FEE9438623016B0C9C05476796CA65CA87F2CEBA874A872C42FD2DD58AEF25DC363281D355C7F63D22B93C0592
                        Malicious:false
                        Preview:(...........f...KU.EL...#....{.Y...T5oqqh...y.O.Z]..k..q&...a..Vv$r..;..-.9..1./s./....!.....-}....&.|...d*C.....pi).rD...m..=...Gb1..\...../...1Q..9L.;L..mDIQhcQC|...-}...,.k'.ZD+.lL,R..)>.P.."...k."..W..J......v|..(..o.3643Y%..dGb$z...r...*_./... ..B..q......fj...m!mM%U.f..F42...b.%..W...C..}}......{...e.h....:....3.%6.6S....p.I..k..v...'..d.J....V{yS.r.5Q4.......K...4........W..].^.Y.N...o...QE.......`....".m.._"0......(.x..$........4......\d.Z#..mW..u.......%.a......l...7O)..!0.+Y@..._-i:.9.g..%..B.x.... ..s....b4k&.....o..g|..&X.g...5.......X.vd.i.;..Z.h.k....x..Z..'.1aA..U...SQ`..K..Y..t......*.....l......"J..S..N=...M...M.@7..Ey.".9OE..i..../.......$..d.D."..3......U2I..'...b...rf;..H>N.Y.6GA..D........7.u.!.a!..0mZ..U.....&......... -X.U...6..k%).n.0U.N[...N*.s..M.}.^?...B...Y.r.o`...Z........N.!.0-.....LeN."u.q.(..W_.6.1.W/6_..E=.'t...n.a..o].S%w+..#.......~5Z..sk.z.9.....7..e..$..w...>..Z)j..F.$...Z.1.g.Z....X.,.T.E....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1995
                        Entropy (8bit):7.895349643689366
                        Encrypted:false
                        SSDEEP:
                        MD5:A3F55C76995C009399C2E88B2D7E8C63
                        SHA1:8A5F57BDF1814E80074C51E94846FE156C342CF3
                        SHA-256:C6257B0E4185F7DD5D3AEC0C667CCACF7DE9809A6F1B97D5C2F8560BF9EDA58F
                        SHA-512:790734952C9BDA81DB68BD6B468745BF9BBA40FD46A3B96413DCEF4D882939934AC57D1501EE6DE298DA23249AB4CDA0097F7A3CC74DCFF9C6A0AD022F31A79E
                        Malicious:false
                        Preview:C.........x.9%-;).+.|G&....6E..&.:|Ai.-5....#Z...x..D.Y..A..[(P.)..]2SW..[.....-yCw{.Y...7......A.D..2H..s.4..m!../^.@.B....*r.F46...C<.N.B....o.,...e.Y_.Y...0......+..P;\^.y...~,s...i..7.i.......5C.@.X.....%.q'..lP .-hT.2.L.u......Egm.>.y..v7.....z.Q.}...y...l.g.0.G4..U....M.."...#.....q..R.c.R.Zw.a..^`.D>...@..&.G!_y9..e.b...w.7_...Z..KwG..b@e.....U....:.k...0.-...'$#.k..|HN.M...2k].`....P..^CS`..<..).....e..%{......k......*.Y.t...w\..T%...-......O2S....:...2g.O..r........A....:.J....+....^..`i...yBju.>.l.k..#..,9.y..#x\.........J1.A..q.3....G.O.j=.........y1...........~RL.......d.tdB..*e{j......{.a.K~.A.TW.N.^.4]..2.?}....N..^......-.Uf.|.e.........HC..#...G.....D..r...5@.[g4.........D$.......{... .....=.y-....T..n.M....,.0...{...9.?yu`.G.......[....3.R.}.-e....W.%Lv`.....T.N..f."="..J.{....h.eT..o..B.t.N.<+.[_...0....r..Z&v.+t.W..v..:.B..0......%.E....^.=..o...'........B....1.LO.a...H.Q.Kn.X..%yA.Et.W..h.D.Uj..:..[.w....O+<...8./L.O.....R...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2524
                        Entropy (8bit):7.925977037580978
                        Encrypted:false
                        SSDEEP:
                        MD5:8945A7CAEA5A4AFDD37EE7AD03DEB461
                        SHA1:1838D5554A4642B4450CF508C0261AE42ACB9060
                        SHA-256:7A18ED8802DE4C06D31C07216033288B7632969FB74CC3E31ED75943B60512F5
                        SHA-512:44C5553FE9BF5B8909C338ABD725B418BB1DA00607E6A58D7D017EA0B31E836AA6455940312031CB42865EAF34BBA07B7EBB15841877EE244E2F68175F075237
                        Malicious:false
                        Preview:.p.........k..a{..C.?.Y.j<.+...d".x...V...*....Q{S.....oU2...."......n.TTC._.=...M6.....J...$,..6.)3{5!.e@cO.4GH.4.........u.w..*..@(f........C..)..U.n ..a}....$..`!..........L.$/F.jN._We.I_B...[......ix..z..._.).)..x.I;...q..D.[.Xy.m...X......sxA...>.N. O.g......Y........"..i..l.Y.td...h.U.C.d..)5..K.15].w.,...<ce.:.......G .M._!..g.N..9..o.[R..@x..3.X...@......q...H...i...Qbke...o....C3+..,..".....mE.K,A..%.?.W..f.F....>..*........U.sE..5./.H.....Z..NK......C..hE.i..I-.P{...HhT..1m....u.Hv#.>...5.i**.L..|K..EU.s...K@v..M.21..Q|..Nt.H..o._Y....q^X..g."k,..c.C#.......H....3..R...|H.h...*...q....q.H>9+`=..dNx.J..0.....[.;N....p&........dD.....L.....i....V.(...NQ..H.......h....HmP...b..KI.{..%..Y.R.G......!........hE.........aGFV.Ms......w..it..z..^.|qv1..f..*...=.....w.......`"h].*..ex4..Wk?.\.nS2)..jj.u.U.;.t...v.........G..9.....c,p..w..$..Lu.Bd.|.3.w.nD..O.kU.}.:+.i.....*4.3.fci5.....s......w%.+t..a..VNy.....;.*..Oj.{m......p.W....A..j..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1997
                        Entropy (8bit):7.906298393917828
                        Encrypted:false
                        SSDEEP:
                        MD5:186AC23A9A7C79E6EE1672992F475DA1
                        SHA1:F4F1EDF3216F6F688ED63597B612AE552A2B319A
                        SHA-256:15F510A9CF1D1273A86DFC500FDA3245E4701BE4F3701C5A36A0D8482D4ED282
                        SHA-512:82C6883286E1CAFE410D04F30F672E5F4CA11D62A456B0953A7F8EB80179241ED0D45BDFBEA8C30AAF8C330A0A72F420FEE9D6AF2445A70F91A96D07D718ECE2
                        Malicious:false
                        Preview:IE..E#mU......H.n..y...s.).6.T9.X.E~....>b......S..>....h[.U.1.u7p.F>...l..g.DCgW...)....p@A.QB.y........3.[y....Te.*..2.....ro..:.R.V...a..K.....s.c..o.au:....O..<i...$Y.._.(.iU..]1...}.....\.\.x.Z................:.......#.J>*.....)[.).S.h..f,t7..x&.vP>:0.<.7o.wpFj.r<..a..5u...ro.....B.6C.6.s.y..j...)z%..l"g,)....'.@p.@...Rb....P..1K.Db...^.'...t..5x..U.=.>...3x=.......X.Z...i..d...B.En+......3...]B..:...( .)p.#...[RC:..y.-"W.+.......j.0.P..9.<b...Z#........5.E....`=.=..W......B..`.6.y.........L...JC.u&..#}.>.}aL'k...T.}.J.=..!.e....>Uf.N.LI....{.......Y8"..1......x..|..8.m.n$.b...m.$...........<.;...uZl...|...K...@L..[...G.n[/)...F...Ucs..[.A.....]U.X.\.E..y.20...b.?m.".~(.F..R,..p\(..gh...7.T.TC..%$.....l......!NdW.q..^I._..t)K....G2..j.. g..."...R...r.@..f.(.P=<..+....p+E...w..PmC.......;.@.......6).r.|~Q.X..~F.}.W..\..*..F#..;.n.?.Q.R`....X....0........f...v...4.~....Pl;p, #.^....fQ.0l<.=..H..FZ|..w...L.B.S...a.L..E..Y.S...W0..=.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1999
                        Entropy (8bit):7.906011741202492
                        Encrypted:false
                        SSDEEP:
                        MD5:00FC1844AAD7283A4C5F3F9E504EC451
                        SHA1:EB9DBDA0DA58EFE4CA163750B5B9DEF7D7D6C4B5
                        SHA-256:F230F270357DC31691A3FD443CD1C78E697B9B540901F144CAFC769AB42FF574
                        SHA-512:8E2A3D38B632941FEE9D82CA4DF8C44223727910CF6760AA6438A6D317945F6EB9CDA5A8243F7B778EF7E62D1EC7D149A16410899FC97FA93EEF1B3D07CED7AE
                        Malicious:false
                        Preview:..K..R.KI.2....j(.T4.,....l0.I..^..#...|4.A...........o...z..r.t.i=7z+SS.EhV..D}.[Af.Dw..6....Vh..[......b.5jbu.h...|...].Jx...%.L_..{.). 8.IG.h.9.`....Xm|w...@...X.Y.JS.z$N..........$.....u...^R# ..8Hr.......Xgq$.'.K...a...4.T'v].K..U.^...q.=....^.}..3.Dv5ez..pl....(J.H&...y....;nW3l... ..E....6>..t.(.g?.....=......X.;c.U...Wn[@......h....W.%..$Ho...3K.Sg.u..dP..h..-.....'.......=..O.......i0U.D....s.^...h|.o3].,qI..r.x.".~...<c..C.q.5.C..M..}/..B.v.?O5l%...+.=-...S%B.).....[.u_v..5bo...Ij.,.(O.n<8.V...n.o;.ay.q.p.(73...4.......Q8..)~.;.....;qu.Jl.J]yO.....&....u.f..].r....I_..w...RX1[/8....XE.ra..=9...AL...-fN=[J..k......y.i.k...F...........fiFK....H%.+|X(/.c(..J..a.g..hFI......u....-..A9... J.w.3........\_..."Bl!5.=.....)j..x....\(.}....1.kxm;.8..*........b...p./....!a...M\'[#..Q=]7E>.....cukC.....N....k#.C......^.........=.r..v% 9.....-Q.&....uK.t...].K.I.5.....5..)..r=....<:P{..q..se..,Y.C.(N.y.H~...._.).n...,;./.........BuU.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1925
                        Entropy (8bit):7.896916871702527
                        Encrypted:false
                        SSDEEP:
                        MD5:47045E0A7C039083663AAA82E7C0FC7A
                        SHA1:F7B152D055D5F9994A1926FB895AF8191012B4E9
                        SHA-256:11C36DB576A2CE27B1464E1815D12E41440474D6238B72A6D437367ACD9E9038
                        SHA-512:5663F49239D9628453B8E1099EBDD7675DE7F9C975216E5C09343ECF061CB755602FE86C8EB3A56BA16C3644B448F5D0A31D9EA74B2DF21F38FE732746A47FAD
                        Malicious:false
                        Preview:,..:......=K..1od[R..!..T...o.t.0......G.....x....wh.A..-.e.......d..q.[....Y/...&|..{.'.$...W.[o.:...lW........{.`J.x9P..1t.r........+.. .....o.......]...c(S.Kd/....O...Z.Aq.nEp........G........)z.p.7..A......s........`.n).;..=.wV...#I9..!...3....tg..cQZ.:..N..r.v.. Y.Y..LuW......qI..+....}'..h...+`y..~S.v...A*.&x>.BU.p..r..O........V.%Q.h..9.2.74..x.m@..r...o.x.x=..WK..]@..t,......S..s.^.H._.h..^;NY...R.m}C.......b...23N.3YW..].g..v.a..BD..l....%..._...T.%X=`4....UZ&..}.p.3..C...\..._..M..O.&....1'n....J.8.....?.9...K....|5W:.4.C...O.......6%..nEo.f.........9D....>..../..#..[.../..z...v.~..d..P...N.4]g,5.{.Y.....Y...R...M.5o`........P.....l>.e&.W....%..>ks...|......cQ[...~.=.\wU.\..&.l./.g..+...X...}.. -.#.r.o...b..b.....8.#7....3.....1.#..8.R.C..G...).}gx .P.....m.|Y9.a..BA..Fi.J>?...a....`.._,....[...U..B}. ....-|...4.X (..B..3...[~.FRh..qA.1..]..7.c..HC..S....o..^...x....<.81.$.$....].g...:.......w.|...q...O......s.....?..V>....1..^..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4129
                        Entropy (8bit):7.954037995834844
                        Encrypted:false
                        SSDEEP:
                        MD5:50E3C7C95934BFD0F2A54524526B0D0A
                        SHA1:47FDF79227FCBC49974B4D8EB9C58C317D08306D
                        SHA-256:777D78AF584E5E33CF3BEA6064D0057B3E9F98ECC2281822C1F252B1A59AB383
                        SHA-512:D1E83C06319E0B78D8220DF6514AF3254D218C85764245B7D8348932C7171836D20EE47FDA8EBAF36B4917F70D24456727F132FBB4B2FFA9D0D223DFA2BF9EE1
                        Malicious:false
                        Preview:..].Mf.x..3.meb,.}Y....ar9..).{.xiIG..$OC."...<..~..ZA...d..2.../.U.I ...I}..C..-O.A.....,Rr.}E.M.-F.R.1.QS.m.]......a..D.\.(.!rm....T.x...ESkO....Z ...'A>.D.._....M..u....H..P.YH>>......>.>f........g..t"m..\.$.....U[4..o...%.e..p...P.....9}....9.^s....?....nW...Q...5.&...g..B".....X.0..3,..FrJE29w..<....O.....P......*....$.....a.#.2.K...d~42.......(L...I....Ppg_..0 ....:.....!)..Q*.....g..r`.....v1.TL...g./).%.k..d5Z.~............9k.....h..8..].^.*.v~..x..b........kOP4!#......0.=.l......T.JF..>.B.Q.&.=....f.N.d..1.......S...G.v..i.[....,.6|0.;.6.(TYo|.*<mT}......M=..@.l.:D.ttq6..?.q....4*...W*.....P.m.:X?......t,+:.G.L*Y.4/.I.l....-........'.ON....>.FK.6..9...K..P.d@.]..mL.....N.O......;y....[.c...Z.Z#.-.S...|D.U3...*.$8B.(xS.6.9..h.....r..At...g.N..Kz...X7..fC........~=9v...80s....\....s..Y.y.a../0<.Y.....8r........W..{..Ee.z.*\.*R|w.....r;Gc...O?mL<..__......-...".._.b......&.K5-.;... ..7Z..f.."..I........S..K ..........o..0..C...\.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4129
                        Entropy (8bit):7.960747109422937
                        Encrypted:false
                        SSDEEP:
                        MD5:31F43AE9095E015820CC9878D42F6DFB
                        SHA1:9903E0BD3B224CBC686E87503DD715A02FA976D8
                        SHA-256:A6B8E9861291440C4300F666EBA53EEDB2C962AEF9302039ADBA486D67FC8BE7
                        SHA-512:DA31DB1FDE441D68B1E165707F79EBB6AAA0C1485EB49F4DF47142D55779E0BA27F409AD0FB3F91A4D3F25098CB17364BD23C79D0DDCBD6B3B0D98EDE101A234
                        Malicious:false
                        Preview:....5{W...UY.\.4.*....@1;........b......02.....>.d~..i.....d......<;.d.7..m...V1......\...'...Tq....6.vEkXv.2...P..c...T.z<.......W...V.).JX.".j..W.$....F..`zX.s.5..........zAyo...(...?....._=...N..dh.O......Tdu..w.E#8.0..(u.r.....l$n.l|..f.3\|....L..H......7.-.........Y.y.IU..@...B.b.................. .6~..,.v.m.B..z3W .r.....d:.<Y.,h2.G...O1....a../M..q.F.....8".6.....tm.1IQ.)Y..#...i|I.....X....7.(...^=2.x.......S.{N.......EnZ.q...V..........1oG!..M....~w.I...l.f...2 .>.B.&t"....]....s.at.[.-.\...E.]..&....bBzU..1..w.h.U.Sh.C..#..3.<.7oRKy....|.1...y..roC7..I..9..&..x...+BR.78...'.....W.5.Nu..|`-...H...W.t_{...b|oQ..N..r.,u{]a..N5.l.k.bjTk..8..W!......{....M..{..d.P..M2..KAn...I....No...(..%.....~..~k.....!-...L-....\...LBP.s~..*.;.%.V.b`..{...a..c..CO.|?.e..)..Q.......~h.-..E...T.5..>..Ls.......]..4w~+.]._.5t...c.W0.-..|pa........(..e{.>5...!.(.9.YwG.q.w.....+.;....0...g...o....C...(...3...fq.s+.#Q..q.+h"g...F.>j..x..>|.......D^G.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1637
                        Entropy (8bit):7.890609581997249
                        Encrypted:false
                        SSDEEP:
                        MD5:348C3B536DCA75F76CB687614FDB7BAD
                        SHA1:047B2A9D268E41D38E8349891007A50A99EB63B2
                        SHA-256:FEE3FC60962CE58938BE68137C852D123D2CF5E508AFE54E800021EFBE526A3B
                        SHA-512:E5086A0A74DEA7BD1233F1AC7421EB0F7E21E0DEBF189A4C0644896F420A3E0F77A352D80A9AFE6B1BAA431BACAC3200A781FC9D27F04C6E282B5932237B64E0
                        Malicious:false
                        Preview:....A.C.r...K..p_G..3Q.E.K....N...}......l.s...q..?..'\.......%.....c.....}......S.g@.FC<.....ED.....A.~.P.Y.M.|.(|.`...e...H.......`s..S...].....=.Qg......q..u....x.hV.,...~....h..Z..}'f).+IP:o"&n...D.......e...N......!...)N..KJ....e..g*.61.pO.......QO/......GS.....R....f..eh.3.(...M[.{?...e.`..8i4.nO....7.=..@.....`S...G.. ..J.......+....:q.G}...7.6....]../....l?;..-...=R...`...-.rB.I>2.A?..../..e...,].C./...h}.2#..^L.....X......`...L..+....................T..u...j_.=2.h.n..P.......w...A.w.......t..E<E.MT'...vB..!.#By...>. *+.v...#p.....y7M].w.v..V..Q4.\c_.N...b..._<.....P::...~2.._..#.i..'...-|.O.c4..1.B.u../...x...;Y.."...........p......'..$..?.>.b@5 ....S`.....4Q..S..s...vJED..P'.-.......V:@.v.1....I...\...P.g,..XWw.5.7j.......B..5...,o...`....0GJo....)cT%.+.pm.G...\B"P,..!.t.F.I....:..uD+......'Z.....=.IBG.Hp......$..X........r|`.U..l.*.?....P.....`..s|...7..>.xX*B.tU...3.......^.&...l2.AS.^A..2.......&K....0c..g%.O_B...N..^...by.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):66596
                        Entropy (8bit):7.997591683662872
                        Encrypted:true
                        SSDEEP:
                        MD5:EA6204CB6F8E6B7E528D5C83D1436208
                        SHA1:80D932B381A9825AE641A3FC660A5455BDB153CA
                        SHA-256:C0D9D935804FA9067EA49B049D7259840BFB54E98AF2BBDD81D9D34ECFA67515
                        SHA-512:55F3309E380D77604301F970B7262C5192FB9581D1132BEC25DE8AF2DB55CEDFC438223636762F65D5A8AC5C6D6D16DEAC940E11AA92DA0615869A7249D80A70
                        Malicious:true
                        Preview:}..j..T...1..)~..ax.-........B..\.]....F.....39..S.p...E..p.%f.|.Z.W.XW.XT....p9*.6....?.`C...0..^.......N.@........f.A|....|l.9....T."cnth4......cC.9..M.^.<H......!-...?.R.i.P.d....W.Z.6...5..}....%.\@..k|"..".4.{...C.46M."....r.;.:7mD.NB.*.R...H.!.9.X.I.....6.....G>..j..4......F....x....7..Oew.$bx.Ra....n.C/..r.& <w..............t..o.*......"m...B(....,/..B.jA....V+..ZD..;.._Uz........,6.?\....`.(.BD<.6e..2...g...d.<..of.J'.......o.:.w..T..t....6i.)........l......<.V.....-....+..ct....V......A..-..7.M...{Zl.hzE.I~..V..g.>...2..!D..6C.!^.5.O.t.......<..!../..<Y@3.\..A.MQ>..[...1..9P.Rp4.....W7...@.aR ...j..{p~..(.&R....r}.J........i#.j.......T.I...o....Hy.u.d..t..J........4..h...zq.t3.ny.u.`.....[>...\ka.Yh.*..7..V..R...\/.!J.]..d...lhf..xm.y...F..s1..7..t.T.]U.....xO.*.b[#].......K.9Z+...E...|..n....[...^...)Z.M$..[....cx.'....3..@/c.....94..I;..zs.4..w.T1......nt....v...7.T.3.j..b.......s3..{)..............*7.....k...Sn..m..k..@...Ht.@.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):21540
                        Entropy (8bit):7.993100051679909
                        Encrypted:true
                        SSDEEP:
                        MD5:1D2B68FD64811CDF51E02D6493D990D0
                        SHA1:5368604D292E1FDD6E3901F87465FF2EC6FD9BD3
                        SHA-256:680C8236DCD9C9CA53C37A8D7AD2D2FA70188D559D56DFE37BCBBCBFACA0CBBB
                        SHA-512:DC30A42DC775772EDA0F37F02BFDD0F1649E0C7AAB7A69C6BA3059EE17F1B27D1AC18F1ABC1D9D16E402F3A98C3B3341661395A902DC31D5D4D0C7557D40E00E
                        Malicious:true
                        Preview:.W.e............}.t...*.(..W.P]F.YP..nv3._..C....$.|.ZL.4......NJiZ.+\.x#....Z!U...|a.V...1.0...s1....a..Y..1I."6.R..C..H+...Y.U8...j...#.>....Q.-.1..tW...M....t5kS...Q..x.:T.._D....."../..[.....nU:.$...0j.,..=~. Y.`.U.H..e.g...m.q....-O..)...>g\tx..B$.A.{..u.1e.........b"m.....k....L.R..5..z.$.(....+..S.....+..<R....<..^...Ff..Y...<....a.v,:.-..._.....&.....f...6v..I..E..0(K.....`].}_.p...mm.......U..........s.jR ,\...`oW.....w..t.q.Lyw....#...&.2d...@}..S(..\...S2x..E..]K.l...r......5..03v..6.iO!........H.^..._+._..g.V..Y/4.3..R..+.l.$.a..p~X...E"....q...U.8...;8...&.q..../....bT.y8`sh.2.?m.z....S ...\p..&.G..gr...Z.I'7...4.T...|..,_...t}..#S.Y@...Cf.X.../V..rE)w..,..yL..r3..1:....h.....l.bbJ.N..5g..7....%..kD[..*.-.....n..$....I.p3Q.......U.|.k.../]....culuP.... ^.....g.j.z..J...zU.,...(...z#.0.>.e....E..]W.h.y.H.....u#R...N 0|...9.......:!......U........!z....3H..x.;.J9...`........^o.).<d....v.....w.Xx..J.....)....>L.Q.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):263204
                        Entropy (8bit):7.999329653863911
                        Encrypted:true
                        SSDEEP:
                        MD5:2CC03FF7838FCAA672E64A870D53B21B
                        SHA1:45D27E7920C7314150A417146A62F62CCCE38454
                        SHA-256:022764DABDECB36A87D7219553437A993BA4CCAC6EF81A1C3D00F122ECA5F3E6
                        SHA-512:CE5A660F519916E0C96A7AA120A33452DF4EC0CD6B97D0B385B9862FC6BC3DBDFD79E27841E1FD47E5985C2C556009FA95D8D43DA0731F9EC70FD2B4B3388413
                        Malicious:true
                        Preview:&NmC..............*.U!o8..^mU.q..sx..$.0.P. :R.......Q...?.{.......nUn/..g.CpR.....s.&.v...Z...W"'W.. .0@..&.B3.~..1[..:~C..P`..J.t..m..l.@.1...W....:.*.?9......j..O;_X./.a.R...n.....1.o..Y..R.zu..1.<...!......|..U.O....R& _...e'..j.>..v-...b.....43.....%.j...........7f..e...5B..wQ.......c..@...q..8PR..s...v..dV.^-.`.B.........Tei...g..1Z.%A.G.S.V.....U@...{.....(.(."(.C...... s.4.jC.?.L...p....s...$U...3....5...C.XCp..-...-......?.c.VkK...Pv.....P..f'.......u../C..5b.....b%`....O@..N'r..0cv..6.8.......?l......E^..Y.......n....L...:-3b..v..H.O..p:].......*..@.....%.W.w.TN|s.OF.T{....Y.......}.~f.-.p.O..W.WLZyr....@.N....vn/..,`k...7ASS.X;..2.#.....]@h.e`t.?..#.b].X0..N;....Z.c.(K.J...9~|^.B...i....H.__.........\~.F9W. RJ.\G..R._.......+.<}........1q..a....p..!....e...+#.|.......,....E.$.c...qFj.$...oW.)..R..."-.`.Oi.H..p4.1...Hd....V..gM.~..,......;...".ap.H-.0y.I'uj.8mc...........#a.Ha%..V..RVN...'...N73.Aq.UW..b..ta..8x...H.......@
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):66596
                        Entropy (8bit):7.9971786086226
                        Encrypted:true
                        SSDEEP:
                        MD5:32DE82776E04F5C33E3389DAE50FCC0F
                        SHA1:47B1291B41394F6468AECB12816522618C5CC374
                        SHA-256:EE6B8AC2BC56E2C94B74BA2370D141E83C6953D5226EBAADFFF4068779108D3B
                        SHA-512:3E77F3B3AE804FFB7FC578A47E46DEAD280DB796DFFFC985DEF3FA3C4ED05BE99E78D185DB0ADD20755F7E1F4120FFD2839B22CF382656E9CF37CA05FF322FC1
                        Malicious:true
                        Preview:e..+*..w.x..;.hnqP.6.......M.9..../..A..^.....>..A......l+ey.....J.%...-...|...rO.#"^;..3...(.2.y..r.....{Z..........[,.x".~..N....g.......B..z.}.+......K...![_......~^E..S..ohU.l>.T%%7..n.S..H.[O.q....v7<.'....a....7..2....].@o.s.EhI+...I:A.`aw.....#...0..#(Ty7...PT.C0...#qX.G..l..........*...b.h.8...m.....h....q&......._ ~.$;.=}{.X..#BE.Z....;...<b.D.z.)..y.0.>v.S..4..W.ufnD.s...Ts.;.q..../.WC..N.cZ...:..&..ai.W..R#..}.(p....0......?tY.I}m.Y.^:t...TQ.........,.s.c.-..y.....LZS.....*p.A..K..mc..k.../"..QYx.V..^...9..9....2m.`_.)...A.|0.*}..........j....YM'..t..A.o.g..."...I....EP...JS.vI.(...O.....K...J.d.%.w</G.,{6bja....?E<...[>.R{YG...g...;Q...$..".,...QC..r@a.^.......B.&.%....."....O"6..D....g..(,.........%.1c.jc..d..S.@.44..W.~f....J#.c...r...+.x..6.H-m..p....b...u......c..ls...i.:.ww2v..lN=...@.`2.0......{.S...q.o1...ccv......o.7....r.N.C..7....Y...?.2wq.h.....X.*.B..q.....^W]..8.(.u...b.y+............!.O...[..8..:...._...z.-..V
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):525348
                        Entropy (8bit):7.999630741154409
                        Encrypted:true
                        SSDEEP:
                        MD5:782B78EB5EC0386DF9FF5AE65873AB16
                        SHA1:C1A125488D24BE89B7E43482929B68E8C892117B
                        SHA-256:D21B8AF0EC867ABD50A0C272780AF4C5A31997F96A3CA984261BA24566A2DE02
                        SHA-512:8882D2A7D6C6E0F852031DFF969C031680F0C26278A78170F9ABFC5D16096E9B69B90C7317C7124293482B56BFFEF89E293032E19220066C849C721C57C08076
                        Malicious:true
                        Preview:lS....p...s../...4G.......i..l.Y.W..G.%..#6;.Z..S..Wc..=..D.@.I....$v..%.uC+.;(X-.M..~..Soi(..`..:....$...0".......*L.3...9..I....v.y.....!.8c.*......1..M2... ."..SH.."\.~...]U......b...wgL...ye....W.ZZ.1...&..'|t.E....2JYV.N.r........K.8.^.]..%=.u_.9.......B..3.#..jn$.<..ka...~.XI...C.l..8.....<L ....6....$...W..u.W.W.i.&MH......&...1...o...?-X.O..`..]..P.X.+K.....,...H}}...7 gn|...z..&....o.g........]...U.g{.y.&.#....TH0..h.!...FR.|..h..:I7W..kj...v9.2...H...RP.|k..S...H*:...Z...m..a6}..Y.D.........u6._-.V..0?.3)a40...........Acdv..B[..<.).L.....$T..L.....eFL*......+.q.1.B,k>U...x....m..y...y.01...k.{~....m.y.(-.L.....C.])./<4..7.A. ..N..~[.j..j.....S........=..._..E.,.u 'F.q.V.d....I.....O.|.-..f.7.#0..9..Z+.......w......{...2o.....XuE..\.l...q3WP.^)5..{.$Yg*.s........x..n.!..b.Z....:...s_..I+.......'..;..5..r....c&Sm./.G..%%5ou.[Z...7..f? ..A..[..2f.4z:.....9...B.@.x..k8.TdgT..~....t.._..fd....h..=R9P&..(.Z..b...3.^.p.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):525348
                        Entropy (8bit):7.999589724570779
                        Encrypted:true
                        SSDEEP:
                        MD5:C14BA24727105B5192ADF37DFD57378A
                        SHA1:1C0926FA99E3C710EF95624FB039A1EF9225241F
                        SHA-256:85F3C1CF12FD068725AF3AE61527365849576B35751AC00991706089CFC309A6
                        SHA-512:8C2113F21377A16D34025AAD0C97E45ABA57B5101EA18F57ED18E67804EF4A22B54320ADD4ACA9F3D42187FF3F0C5FE9578D71750DF0055592D13201223DCC36
                        Malicious:true
                        Preview:a.R..a..0..w...@.....ie........Bc.f...........P.7{.5...z.i.d..k...*?\..q$.[.i.C.~.....{.}.j.]ra....U6.f....c....S....n"muXE.[}JjS.}.d...?.T&...V...,K..r5.O.....z....~.q.]..t$....\...g#=....W\X4.M..6.&l..Ud'.hA..U. ...\.....K..|.4..M.z4.:;.......y|.V`.cm:..L....Z._..w.l....V..`....}U$_{g..l........D.y.&.......E"o\.'..3.....'.6..m.^..b..#FcJ..U..w..sk....#...+~...:M0.....pI...K....|.gaW..r.@&..9.)bO....N.ih..Y.......!W.T........(.q..$.....>B..Lt.].YP.8.~.k<n..0..b..q...{.W. k]..5Yb..Z.....bZ.!..z.?......\...R..KV.#..H.)6:8...p.4.UP.[.#..X..J]Sj...........U.XL.....Z!...[...-.....x0.Z..e.......K...Ec.M....F..C..P...`.^L|..!U.+.^b...I`...Gw............v..;2.....Uk..O.P....?..P.('[...X*........;.......n..i......'...S.8....-.3`~.:.....F..rO...^FP....u....&Zh8.[.7...F.k...2..(.....N.....b..5.X....]Y.|.w.....>?...SD.I..M..A.....w.WI/...,.....iM..4.V...>_.L.,.N^.Pi.q}v.Z...W.).F..s_..P.+.a..6....?..U.#..Y.......k......_...}pD.+..Q...tb.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1150
                        Entropy (8bit):7.817999533295696
                        Encrypted:false
                        SSDEEP:
                        MD5:5808FE5F8BB2687046F99C44288D58ED
                        SHA1:E50E34C3EE4F71434C45F755B423E8829785671F
                        SHA-256:D01DDE0B60627BCFC36B94798EF568EE2B8053D9E01981C5D3835E5DD6EF83DC
                        SHA-512:DA827F96418790EEC65D698D1293F55E8F11C423F8E2A0B5C6051987CB0C8E13614717B463E386A0B3099E3D90224E829AB03053952113DFB39A1349BCF687A3
                        Malicious:false
                        Preview:.. .n!.w..94,..{.8....>gF.^<Tw.|..p.+.{..M*..ZSWD..Bd.....S..n..@z2p6....N..c2...}.2.g..<O...K+..Y..g...e ..`4.t2.[....A.f....F...h..;.i.;\.+X...s=..*...V!..h5..Z.o..R.)..^....Gk.._..=O.+.G......=......tHE....Yd.tL...n....S.....r.tZw.]_Y..c...s..Q..Q..Q...Ju...D....o@...)O..v..>......+MH.......+.l....U.N......E...~qg...QW.m.....S......I.)..h..5...#.Q....'.q.2s.+...Y..Y.....G..<i...e..(..5.......q..x.+p...Q...5<.r..)...y.s.}.d.....L1d.I..."..._...(..w....Y...0...C)X..oO.P...vN-.}.vd.$+.K..y-....Jx...8U.MRg..z.E..8{.....}...@.x.4...I.e.0.B.^..r]......O..,j.S.".c..B.w..G...r.h .G..:6A.P.....wK:....Us..w@.G..F..(k.N.st.d....m...s...e=.U.......#....Y...8.I......p#n.!@wm..h..g.V.sw.cJJ....O.W_+.UK.M...vi.E`...nt.iK[Ha.78YU..n..Sj...,...J.....K....<..T..h..N.&...<8!U6*x..e.aX.pK.yMD.[<.km.M(....D6...X.Eg....|..!...P6Wc...s.uPB.%v.q~.....w..5....4_.I4..V.:t<..../m..x........Qf.j&...ak...v...o.#..Hg.Z....k.....B20.8.k6T.k...?..".z....A..G.\
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):704
                        Entropy (8bit):7.687334597819678
                        Encrypted:false
                        SSDEEP:
                        MD5:9082B7CA00F4589DA1E268349EBB2576
                        SHA1:F0FE060552FB11CB18E794005F3026186D207D42
                        SHA-256:0CD6CF27072D96D74046B9A95A031CFF26DFD122F268D8B9439453727E32F4E6
                        SHA-512:2EC312DB7969C55AED3DE32FD765EEAF127B7306C077C0217F49FC23C66496C6D8C1F87B6500EED19839A39AB430FC30F2B9E6AB9DF1C5A533265E9E840553B7
                        Malicious:false
                        Preview:..v....7.(.....:............pr..e../W.........0...TO'...m...W......./.....0.e8Jv...\s=rM..9K.....!o...5.17.....g;$.L]m.|.K...5..O..IC.L....lwW..C\p9....gi".+..c..Y...K%..=.V.|2....K::.TC..."......x..4.uE#.l..4.w.3..4............=n../....Q._....-.Sx.Y.o......9........q...._...9.O.u%....7\...I........L......g...........#..L.....D..s...`.:+pYn.XZ..=...d..|.O......`r.....j..M. o.w..U.9.....&6...2.X....*..{<..8_.G3 0.T.V.N.L.....0ev.kZ..t_...........Lz..A..vC[.y..om.........9.0wG/:..[..~"p]....U...T.H...5...c.=..E.....\W..C.....[......I..^.J........x.~.BI..4........:.q)$....#.G.v..K.mSi..f^7...h.o.S..|W..Z..L6......p....(.c..i.a.....7[ ..V?.E;..>.L.f.......q.*+./.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):538
                        Entropy (8bit):7.639572638917211
                        Encrypted:false
                        SSDEEP:
                        MD5:854CBCDB53D531B5DE9D9BE5AB0DCAA0
                        SHA1:C50E53771CFD724C7E0A7CBFC2571E5D6C1BA995
                        SHA-256:FF63D11F1AC61B1494E33365B1F8A10CF6AF7A0611AF372C55182878299467EE
                        SHA-512:31C5A507FB83786ED93942404E569D4B324120BD67539B13A33DAD416CDA4009A0B2120FC3BE1D65004C3AC299BA5D242B770CA1215317022A4697906200D68D
                        Malicious:false
                        Preview:2r.M...H...Y.P..RN`:..K:..w..pef..~Y.Ng!?.`...yG\.....P..Ln......UwQ....V...&i.TwWA6<........m..._.o3..Q..."(.D..$`....dC.u.-Ldx...e.^.........Z|Fi.F.f..z.....+.Gm...Ii..V.}.8..0...Z7..D5#.o.J............V!.\.-.l ..s.E..-Xp...KR..n..M.w..w'.vE.b...."..1...^....."....'..0.waS..9.n...b.......G.......Gt6..@.R.5@C.P.k.@...*..)..p{.XZ.g..i.T..J..l..h..?x...W...}..'-< ..sq....../q.tNu.q.[%u.Y......].&h.......g+.5J"..0.....S.P......5...)L/.u.....00.. X.....L..>...S...,.p..o.......c.n.....3.Q*...MWv|..? p....9...>
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):828
                        Entropy (8bit):7.731913718846697
                        Encrypted:false
                        SSDEEP:
                        MD5:B92D2DF3E9A43FCA10D55810BCFE7DF0
                        SHA1:8EAFC7B5DBE172E9718A497BF3B4E8A9B843641D
                        SHA-256:E30545A00C39242A6C97B75D6D2E7E7ED6A24F139C51AD3830327E09935415CB
                        SHA-512:BA93D6324372144EA12847FCF78243C852BC5DF1DDF452013FE50F2BC32706B6C9DE9B351DE0B3EA233D7C04EB2F7BD158A4A804642E8244276F8F8AD4DBDD65
                        Malicious:false
                        Preview:hU...ZJ.M....{.ca(...'.O.O....p.a.....r.Erc1..'.W..p..%0.....c(..J'a..j...C....1....._$..U...{...........l..{...O.q.;.....3.oE..X......w.&m.C.C....v.9..+-._..a...=B.|.ROf.[.....$..H.(.N2....3..K...a...8.7.`..=..-...).]..*<.!z.V...;2.#...*._L...4......GB..O..>.a..A..$[(.A/...."....`:.oz./1....7K:(.........J.......\:.,O.3E.x...~...b[._..6....ys.gRv.[.\^.Q....3...h.Jtl..4...6..F...:Z.+.......{|."...$.y..V......;...>..c..d.J.....h...J....7>-.9.|...Z<s.=l............OJ...q1&.....]K".,5pE..1...A....wgK.f5.3.c.F9q..)U.|wP[.L......#f..T.........i.?.......)bY........."? .ijr.j....).....Y.e...{4.K5...3`.D-.h....$.1.Q...C..o.z....Z...Y.&.k./...H....z....M../.[,.z.7.+.wV...A....;.)o{...K@d...z..e...Ru.+l..Ax...G...@`+......F....(.0].K.._.:....z...O.eDL......$..'%.u...JU..``.....G..s.S.K
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key Version 2
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.60941961975116
                        Encrypted:false
                        SSDEEP:
                        MD5:09294DB00ED6D3C3EFFCDD3EDFB4AB98
                        SHA1:EF17515DE00D89D617985C23BA56758C97FB44CD
                        SHA-256:E210AAA21119519ACFFE4FE8E81C703766F2B53159F2077E0BAE32BE8514F970
                        SHA-512:3CE8B6D676D34E3F6B764B851271898020D60058B06DF16E32F3F5FD92C08DF5BF54BBDB3DEC4F98F3DD11C2E11C41C169708C815FF2276BBF04A1EB38DB3AA2
                        Malicious:false
                        Preview:...1...T..jz.]..K:Z)^.g!.d.J.di....C]O.F...%5......w...-.SLz....:.;.zV.q7.....@W.d.g.W...0...U.z_...r..6iH..)....n&M"Xe...V....9e...._~....5...l0..r..3.S8..y:.g4....cE.o&2)\g..V{.b)'..`U..4.......5....m.B........w..WU.g.<.......A..v /v.To...OQhJ..p.DF....#<.C.q./...|s..Q....lD.N@b.x......p8#T.:c..W/P.d.........B8K.*.G8.S...F......VX....n#.FQ........V.V.qA..9..yV..{..N...0ove..-..+.v4...I;+.M.+......U...=\..p...}[...@....A-@...s....S;.,.'.k.R...B.e=.....H..$\.R.~z.o.....5l.#$.....~...dv...<.3..x.P. q1j....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):546
                        Entropy (8bit):7.644307956476826
                        Encrypted:false
                        SSDEEP:
                        MD5:C4D445A0435AE1DBABD9DC7A2BBEB96B
                        SHA1:6FE8C71573964D8C8FFD6D4ADAF2C6971F74BFB9
                        SHA-256:5E6D5813902A52EEBC97163434DCB48029E65CF208D1BEF5AD94A4CA5BEB432F
                        SHA-512:3F9129D69B2261D3E30EFA542D05DC4E1EAC6C76CA7F57E05D7B96181BF96C2642337B2A8F12CFC459DD53D8D03CEC6275A012104591E030FFB70888F44E4721
                        Malicious:false
                        Preview:.+WU....7..t.Kg.I.....l....Ob.}K:........#.<...P{.M.....t...4...yr...t..V..... .....Nw/t...mg....E....X.#7E...8G..e-.....w.....z..8p."....v..@.Jh._.j.P....>.W.V.......DS6....v..&.:..RQJ...3\I.h..]V.3...`.H....na.;.4..........K.."+B>F".(f.S.C..} ....J^9-.L.*.`!....+....=.... ......q....x.fa..(>.w..C$.v.....PU.A.Ji.<~..$y.."")=.u..jK..V+...}..bs.r-.]....h..HY..o........j.N.-E..:K...gdr..g'X..h'.l..$.>..y....T.)]..6;.=B...4).I..:55.ZJL?..f.7<#.<..y.XF..<.....FW.-.P$....6.$.:O..9..._7@oE..........J.9..E.....U.Y..&....G...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):45586
                        Entropy (8bit):7.995897797093324
                        Encrypted:true
                        SSDEEP:
                        MD5:71B71C8465843FC88CBB392254C5683E
                        SHA1:CE4A294BD2223B3E0E0D3101EF50E5BBAA6BAC06
                        SHA-256:9E7921EA42B0CAB6476EA5DA54FF21D4109F4282AD1FDEA4B1ED7D2C579C00A8
                        SHA-512:BF542C0037A240CE25729CDF1DB1FE4CA8A575827E2D13000399844CC5997A88134D7D81B6ABCD9B3ED7D85228EF6D15993903E2559B379131921FD6A8F32C0F
                        Malicious:false
                        Preview:..%.>.GC..0..%.....c.6.O..'Hmf........v..r....x.K5..W..D..C..m...68dCU .Ns*3....M.p....]..QNs..V.....=Y.6.z.Rr.....6..S..^.".~N/.9..0f........n..W.mt..Y.>..q.u.!....8n..?...(..Pb..2...]..!..Ha.*..*..:x...Mbb.O./x?+.X){.7.....m ....l.f...BRq..........!..x....Q^yw.4...;.....!.L....c.O,aC.=.qFpi.C=.i|7.].}.....{...1+..}.k.....v...H.... M8.$........_l..\....7).e.(P.z.6...l......F.@....e.....+...8....(U.....+j.....A.S..`:.).H..?4.....X..j..%*.'......`..eF.+.....),....3-0p$Qd...w.........{...Ea.|........!.`9..N,.OGC...g'H....T..W....M.G........G4...U......<.Yb!....C1......6X_0.8.......mJ...*k:mF%.......3.w...D......W[..j.b..f7.1.{.v...h.......g...>...H..Z.......8.,.I..IQ...rB.x`u.UG..!G6b..l..;.7...t.........i.....?05*..qj....F.H.*.F'....u)}.f-u`..-..y]B9.\"w..E.D!<.;.jW......1.9^..0w.W........ts...,.l.8..y.Q..\. R.....VD...X...a&p..v7....y[T.y..).5T.D..e..s.(.lC......H.>%G..<....C.H7.8..A.^B.p..d,HYr.m...........82I...|.8...V..b.".;i..I
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):270866
                        Entropy (8bit):7.999340047018902
                        Encrypted:true
                        SSDEEP:
                        MD5:4929AFCFA25A214EDD4A4553152CFD80
                        SHA1:7DAC7BE15C6F70FC6806DB9720CDF682B451ACB3
                        SHA-256:C7CA3332498674363B36B192772C907A0D8F321BAA79FAFED7C3E7C415B8373F
                        SHA-512:1DF1BCFD4D25A6DA19A31F35DA0E585C7A461374B97ACDBE6E98490D0FB64CFC7EB57570C78591AA5A9CA14673E4BF7EB4C3CC196954D02B22D2025C403124A9
                        Malicious:false
                        Preview:..0.Y.V6,..V;..G....c..a.y..C...LJ`.O....(..(h_...j..Hy..O...y..(<ct.(6"..U....0s.a..a1u.x8...=......VJ...=)..r..c....|&,..\..a&.j>....(g..H...X..t.n]...iU.....).d"...|f]....X.*..j.l.'.s6..F..'.....4C..X..FT..>*..k.~[8......k..=2....I9+.x[...Hd".{P...<.o........8.....c..i$dv..<M.p#c....Q>Pw..6d(9}+.W.&.~.hY?...A-....a..A..{c.=.......N.......M........l.O.q....0.....1._G9.@e..i.H.m.~....U.......\......."./.....o........8.I.+H4.F..J...b$.7.b..FxpY.d.......x.p..T..^.2.VA...6.+..V,.i&.h.T^...|p.3.....h.'..C..%....m5#..r...g2..It....3.m.mE......I..6...o...4.....`.x.E.5Yj.;U.!..1!.P8.{......P..6$.I.........eh.<}[.Fw_..A.....i.U..}.P=.8..6..._V#......d(p...4.+.HWq.@.~A.8G}.f........Yj..^.....C....:.....(%.....".,Z.t....d..R-;.x_...p/.(.S.e..*k.X:}'.......|....&...j.O.W.....-(.........uw.Vx.........XLe2;#.O..m.Kd...<. ......N.5Ee... i..y..R.88.k.uv.....:H.pz.*..;FI",...BK.X.FI..?.$.+.....52;\..d.9..7...W..Q..........c..V.p....xM.......,....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):263042
                        Entropy (8bit):7.999224950164853
                        Encrypted:true
                        SSDEEP:
                        MD5:A2F1BAB01DDF5EC47D6DA1B626DA95A6
                        SHA1:6BD1622902BC200F6F4AA27EFBFE2866AECF3ADA
                        SHA-256:0C88EC298E688652488CF8845DD3904D0418AF61A6D3BFACB8E475E17850C680
                        SHA-512:21131C9BC2AF471B5DAE9C423DE1C360AB8AAC445B2FAAD61EAB6842F2464395749A4B9C02D24FA36EF55A377588C238684D7EA60606463E1E46A3F73B1BEFC6
                        Malicious:false
                        Preview:F...EF0:..d].T....b...F..;.T2R<.A.a..v[.._.U.....Rm...!.Q..89.../Y..C-.0.C.Q`......{.z.l.F-.{.......I.dw.T...>..yDV.n...........Q~.........$._.I.b~..+.=.2..s..Nt.....g...'p..K.\.I.H......"g...."...c...M.pd.b.d..gs..kH...].H.qx.h.2WK..K..;..<P..E.~.C.......j.g.4..>A.$.....4kC.H..r...q.^/R...|...~3f.>..S.u.$V.P..%.f,.v~..#'f..e..{...{.i/...i..%..L..s..9...@....7`...V.x.3/.y.........A{.s.q.+......v[U`....Wyz.U........:n.`l [.t..U.`t.8..L......ly(8^..@.^[.......ByP..#;Ue~...Y...a\...`..9...".'..Fn".........i4.".a......mb).i...6:...X....0..Q.........5Q....<6.?..i4j.n...b.G>....O1..Q...5}.......l.VB{...G.sb.....?C..5|V.R..;[.`.&.....T[..%..........z.^..F.....y....1>tm.P._....g.m.........mqa);p...V.s.....6.^%..C...6.....R.S.{a.......o:K.a...w..K..J..R.)...J.Z....D..|...t...z..\p..d.'.......|..=....~Wj,..V.3.%.....F.+..x.(.#"b$...X.k\OO..=....G..`h....lRM&yK.....i..yh...$.Q......4)i.../...z....M...{...\.&..].|....*.`S..K.P<..`.D
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):739
                        Entropy (8bit):7.771202218332302
                        Encrypted:false
                        SSDEEP:
                        MD5:6D2445ABD7DBCE4FD6A035C47801343F
                        SHA1:0EBB9F00F981344C1E3E5BA7A6434070FD6965C2
                        SHA-256:D3E720511A80AA86EB880C7CA82C75B4820D5D4F3B62D2469830ABEC3BD57D10
                        SHA-512:CF12A8382FF3D0F731EFC7CBB01DA0DF8688DDFFA6822FEF02D8677A41EE0294F495C0AA62D9038D115F980AB1373B8F820C804DB9704FCB0085C0C8F567B708
                        Malicious:false
                        Preview:..B.....$..w.5h..Y..c..08.62....(Ym.[.....M.r13..I...c-\g.~.. ..m.x8q..~.G..Q...i.=..P....E.)....QDm....t.j..Z..S..........>.._s..\F...MM-g..]....o...I...o.mY..U.....4.`]Ex(d.z.?..k.`...Wr.f..?V.l..C..Jp....P.8.-`...K:6l.....L..*.!)...rt.NN8...1v.}...8.D.).l=*/.'|.U+'....J.I.I{..+...x..;y[qV...6.).9.y#_.j...<=b...._.U..?..l....K..c(.......'i....Mqe.....HF."...\....\...beM. 24..Pf.....!.........z..2..5..\....2s'.].fz.o.x.wB8"....B.......e9............&yC.t..,v..#...]...%........3..r4.b ..-a.;.\.&.Mbm...U...l..{.3..=...^t..3;.#.....1z..p.r..AVa-y....'.<.C..;...)..o..~...........)..L8%. .[..4..J..i$.j......s<...se..'Z..;.....7..X1../U.V. .....~4..<h..y;..(.s...V...]t...)w..,....G..q.:W...7I.w..x.;-a..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):750
                        Entropy (8bit):7.762188219519023
                        Encrypted:false
                        SSDEEP:
                        MD5:EC929CED5FF02E02E31D6EEB81AB19A2
                        SHA1:FD53017B17E67BA9AA952CB0DF004FFD8D2C980D
                        SHA-256:33F1F9DAD5B5D4B74A46C7B69C66ABB1AEB22C8430C9D3CB83FAF7EBF22239D0
                        SHA-512:26342EDCCBAEEEA7FE712782E613517D3F942FB39F72106AA8197F2A3FE2F9E4BC5721AC0CAFBB89864DC8789C6A2E4DAD15A3F945FD9306EFEDA4737D233943
                        Malicious:false
                        Preview:...X.......t\....hk.g....5L.d....x.Z...D....:....?[1.......J...c,aFg.x..a..Io.K.#......'./.......F..tM.......(.}......4F..K........;.y..............(...M+D...JYN..-}f.,....X..H....-..(..%.y.....6..i..>W..?..?Hu....\...k..+.K:Gdv.....I.[ ...,F...!#.`.ZY..w.=...5\....r..ZB........X.@s....Pj..=.h:rw%....a..H.>.w..{......-.....seO...pT.z.W.*.kN3..`....*...8*}@.[m....Sf...Z.....7T.,WX.M#.[.vi.L.D.H .B..h.g.n.E.....;a6..../!...rA..*.......^{I.~...........(.r...#X..._..K..{.m4m....k>.$t.[kj.B...x.r.........r..../p....-}..."...}.]....k.ey.N...~..E.p9m......=#.%7l.q.~\......N~....jz./.....^.....<'...q99a.|$vn.."....m.qRg..A...]..c.TY5!@.Lj..=#.rB....hS......`.!.0...4.n..".8.h7<..'.N._..%.e...4z...O..m..t2.6*...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):708
                        Entropy (8bit):7.723647294446149
                        Encrypted:false
                        SSDEEP:
                        MD5:856F8787EC3A46BE073C49CA938190A2
                        SHA1:BB856A7EAD43218C9F88082FC40DB75EF579DCDB
                        SHA-256:A6993928E0D1F298C6EE7D15494F75F22A1A8DA5210B5A7974DCF00A0E8AAA26
                        SHA-512:1D0AB141B29F9BC2220193E355DFFD55B1ACD00BBC2C6271766F4FD1DFBB851E3F4D4467D7AD9CCCDDDCEDAC45210514635A109E380978D2DCE9145FA0C22C14
                        Malicious:false
                        Preview:.%..... ...N..eDR.....u'wT@#.m...o.l<2.nT..C....qZM...m.....-.}.$Y.O.%.)....~....N.LF......5..P<hH........C@f..Z.T.(...|....F.1.h.X..i....i......C..5 pM.._.x..$..>.".......>..!..U`.. ..K:`0.*..x}H....F.wQP..fO......A(..RP. .\a.h...=..;~.,......R..-.b.9.;IBp.9h>4$D....L....5...........ef.<E:R..3.m;^B..d..S....A3..YP.7.0.$..(..|..VA......u.p.../w....arw.Yi%..WL.'z..=...r.m1.3wi..m............p..R.4>.......\.)..@:.<R..@.%P.i.m^.......?|.,.z...4.t..W......h..U.uhGU.Pp.".7x.:.&.w.c....q.)R....p.$...:._.........a............#.......}..(......k4..-_*n..VX...(2L..Xs.w.(.....K.BWC.^.N.....@.p.@Y...o....:.nS....aD.a&.~...D...{.}e.)...U.2.i....y.=..j....>.4.J..l.t..&.. l
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):780
                        Entropy (8bit):7.730340209910231
                        Encrypted:false
                        SSDEEP:
                        MD5:426856B991737F1D08782DA064278D24
                        SHA1:092CAAD63CC93343B550EDC1A0005B0CE5E28AF6
                        SHA-256:04CF11EDC8FF3D76778C3146C9320E6A4A0FB2C010A6BB66345B4720D32C9814
                        SHA-512:66CF4E258C0D825FBD6472A0F2ED0D6085FB467A1F7BF1C47570024346540D38710841CF593F56BC52FE4EB82DBB0C4FA212251EDD9D80713638CE4CEB1C4610
                        Malicious:false
                        Preview:.~.FDE.kl..A....2*[..... ..).....B<m.J...V..2.%...rD..X......P./.zY.i.......>.....KJ.].V6.....t).......l$b.K....3[....S..x;...).w..A....<.,.@.5V_.#.4e....8........."6....T..D&1.....j{....eK......."7.....v..%.5.../[:....6U.....sL..O8.......9...5..i..K:92p.0t..^.(.h.o.Y.8../.....b.M(.."..y.@..I]V..<u..ou.........v<..[.n.Q...s-^........)./a.C..l.TbY.c.~>2bd]`.."[.q....<.j....s..%...[..n......a.:I`.S.oy...EQ...t..0#.j.g.o.Q4.....8.w...f../..w.F[..O.....6"..-....c..cj....%...S}6.n .....(............`.@....8V.ju7..\}........v..M..q.X..Wi.}...c......"7.....s.?....X.O#....K.^.j...=cf5(...}|.}(..B.^5Y...=.:...rC.&.g(.......s.8.O...>SY..aFCe."......|lK....O..l4{.6........1.1..V..u......MII.....i.U.......n.1.v^.!.#g..+=]x..~.....z....N.."Z.>
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):728
                        Entropy (8bit):7.716971738423425
                        Encrypted:false
                        SSDEEP:
                        MD5:FA2EFC3F5D3D9DD0976B07132EEA12D4
                        SHA1:B28D8A5CC1B94FB3A5576DEF67FE50141553617E
                        SHA-256:6BE048171B97FA882AADD20929E2FDB958DAC0B08B8F0B55415F767208FA841E
                        SHA-512:D96E1C7A6F9E546B7D25D56A99E2B7235683AF9F0A869ED060C6FC2BCA41ECF85967D9F8D257A1C342B00EEC74398B6B109B8828AABBED8B63424D1B02E6E7C6
                        Malicious:false
                        Preview:..-.Y.. .t....L.h.I.?..,..h...~}..q.J..+s8...n...Rd..F..?.....R....X.J.y=`.w........uE..<........D..3.im..%.V._......g...|..w<.Q.U..W.n.3..`...h9wZ.,..(.".#F.-...).l....HI<..!/...c..(*Qb......]xr.........K:..^1".y^#...w.?....ZG .p...j.9.y.[.........E./....q.QtAU.2i@.#..f.......uW..N;p.XHU.>T.<...`.....U....]p...@...z~.A...0.....J..b...../#pYq.ZH..Z.KHC.......3.v..M6....'...5N...:;\~.....,w+.....O.Ez..[6...J..Y^.)S.}JQ.rg..CaiJj9.E..n...)c....Q...F.v......Xv(...........j.<...W.jQ~..3..5....0?..'.c.7D....y..M.........b.-;....d.......tI....<.....cZN.......f.!)X.N.#.r.|.n...0..z.NT..Hs.$.n.].^I<.M........ f...2ycv..c..}i.eu...!.G..._...;B..=....0g.e!...&.?....x..V..x....R8.a#
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):726
                        Entropy (8bit):7.7182318153783935
                        Encrypted:false
                        SSDEEP:
                        MD5:CAF987681AB89377097259FEBA4E82A8
                        SHA1:0AD789D7FEFD2614A01F755B510A0A089A3B4CAA
                        SHA-256:2182F91E6D0E5A94418943876C7EEC921BB4697A67C458B61270D9E3EBDE1EA7
                        SHA-512:87B6A81E8F34B8D45E796C199E4D47AD9160468BD1FC8703355EAF13EB6C301305C51CF4B3C751598042D6C623CC29B00A6339D57964844719F0AB5A4C1162CF
                        Malicious:false
                        Preview:..Z.u..H.....u.He.sq.yJ.aQ.h4.X.r.=.N...;......>!......g..G'|....@B.....J;..J...C.6.....y...G...33z.&...D..."(C8.U.N...k.....hjy.T..#G...'......'F.......J.:..'\..[.h`k......c..p.......}....l|......%.P...K:y.OS.r0.4.8..?..Z............H..v..au........+z3x....UT.'..&./.V.......Kws..).}j.9..b.U.z.....<.'..C.&Y......m...4......Wj..718..$5..X.Z.....B...X...V8..lBz.'...]..U..s..\|.8..Tfg...N.....`.....7: ..T9...d..M.:.c.4......zw.:I.|E56....t...f.>+p.Z....*...+..;>.KQ.R..m...W....Z..I>....7.@....|~~k\....t...%.q..G.[.f..:..@..Z.@#A2........Z...q.C.V.A....XR..e.(E...N...)....[^...)...w...I.G.qq...Xn.5......D.......r..d;...R|O.W.b6....1L...!...F[E0..&..k.1.4.E.i....2g....I......0%.*MN
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.717732966559436
                        Encrypted:false
                        SSDEEP:
                        MD5:3793AA713C37521321AE51F459BCF05B
                        SHA1:EF2C97259AFB874E667EF26045D43873F6E4528E
                        SHA-256:CB2D9EBC5DCFC4E09CB72E14821721731A5CC40A21B39F942FCA0BC429C02BBE
                        SHA-512:0869F1CB7CC4F2F898471BFCB18445BAF3E6EDF110E4FF486CA0B250A334B35D0957DCC63735B4EBA69C0422CD4B385875823A6F8A840528D541FB7C15504D7F
                        Malicious:false
                        Preview:.Ne;.S..+....dE..ly........^.......Pw...nP.F.4'n..%...%.........;y.`6*.4..'..u......q....eV..W.#.a.z..JQ '..C$.?..>.&..../2~..2.~.......i...'..A.....s.o.U{..69.........(..z..Q....CA..z.M,..X^.iV}!........!.g`.ks.2q...K:..[j.....#WZ..5r=p.... ...F8|m...J.C..q.........C...9.h.*.............c.m}.B)Mp./...a0u...ycG0./....&....Ak......@.^.?h..............*5.'.W..^.....Wk@........Y~.+....".R..A..{..)p&...l..V.....#.r..X..Ft...o.J.CPe......Z5........5..@..G.....$S.=`...../..\..0.FB..._.....V.1.J!..0...2.....YZCuR)....~I...F.....(..ONs...W.c.y.F..Z......v....5`...%dCi.U..x.e........y.+........x*B.D.....FJ..s...^5OdP.d..i=,>....a.eF ..Z<.......A[?lM(O#)./.B..$.....[..:.xB...07...Mt.o6.9jgyE.'#..<.%..Bq.(.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):750
                        Entropy (8bit):7.73406000243464
                        Encrypted:false
                        SSDEEP:
                        MD5:405D45452155F1CD01DD8B7B977E0C0F
                        SHA1:179B281DA92D4B6D6A9BC400C38F4FB7AB4F77D5
                        SHA-256:A56D3CF3AB82F12B02DDBAAB840600852B934D0BD7537B66F3015AFA6772867F
                        SHA-512:0DA7A55FEBA365BEAA628BA2C58A3AEB4DB80108624ED002B8ACD293875633F1B1EAC75D600B512BDEF1F5308412BD0CF0B6836A12D1CA20159A4BD4F766DCE9
                        Malicious:false
                        Preview:.~...;..a+?.J..=..t....E.b...pT...Y..B9... {1......O....z....&.....0..y.A<.^.z...jk.-.'KG..F.Qr....[.C[....I.T.?./.Kp..|..'.-?..s..>Q..w.6..'...:u...?;..bfr..[..F.j.H.3.....^.b2...kQ..P[+M...........O..~q.........z.]tl.G..H..K:..w\.-..d.....!=B.u....y.+...|.......".<.!q.v.g.{(.r.4..!..^W-....x.....<(7..2d..cl.....CE..mK.Zj.....bk.>..Q.VcGFv..`.........E%E..+..........X.p.gj%.>..7=n.u...VX....d+u.m...]......Q). ...)...L...=....|'.Hs..C......I..gw.e.."G...h.D/.f&.8...*.l.#z..\...o.b;."s.2<.../.B.rE)..'.^.....i......9..K...F..+...[...)Sl.<3..4..].k.J..3T.]..br..q}.5)......;n..<...Y..r....9.....E...c..O.p.u..*..a....;=.O.m..?WC,...W.G.........O'.....(b.b5M.....T'.<W..r....%\...7e..v"..b#...*.-w..e.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):743
                        Entropy (8bit):7.678330944213672
                        Encrypted:false
                        SSDEEP:
                        MD5:8825F78DC6DA4471F3127B5EFD5BB48E
                        SHA1:8FE5B3A40593356C0119015A80EBFB20E13ABB3A
                        SHA-256:48ED6D8D5FE33669457E31CE2ED08ED763AFFB17F340B65922B6D7DDCE6F6FB9
                        SHA-512:5B74790BD45802011B0A1465793D8760166CC298DD48BCBE6C8D99EE10BC371FDA91B30CD417F383BC713D6573A99BC4A3217ED7A671BC60464B4622A1D64A00
                        Malicious:false
                        Preview:a`I.:.7.#;x..w...B..I....+......}p.}aS....M1..c...GF...]n.U.+.a..V........Z|...ns../>......Mb.......f?.c.....T.2?zG.k.{.J....]F...[.l........|!..5."5....m.F.3G.5.e..2.>.>L..ZT...0:...?.ba.a..L.3....'M..L..LJx..y....(.'K:`..d..:..B.F...g..<....9;M.bD..Lgip..:.T..O.\O.p.....5.,J..S......#....Cb...C0I_._......x...~-.vs...5C.q.F<V...._.E..30v.P;.....:..aH..12.0;..]J....,.Q.......r&/.e;.IN.9x.m...Zs...cz..E....H.5..Ip..N.Z.`{]...b...-w....0...y...#....,_.....-..Zk..0....[?...;A.9U(...Uj..y.J..6Fg.........F.X9L...6.....<..raLv...6J.%.l.."~...1.c.w+G.B..yg..%%.....W...{.szpn..7.jP.H...2S..x$.D.....r....w.m_.R..>]/9.7t..e/.....gRM ...<..;..'..p.)#..F%.z..9!........V.8...j.>..X/.6..#....'%>..H.........XV.5n)
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.698769183882565
                        Encrypted:false
                        SSDEEP:
                        MD5:E7E617690F72CBDB72C20899FC56E437
                        SHA1:9956295F53CA9E3537753E41FA5B00561FAE52EF
                        SHA-256:DB4783173793C2BEBE3D07B977AEF93B6FB4607CBB2E96A7DE8E007B3BC5DFB8
                        SHA-512:6021DB939AA21CB9288F02EEDE7538017F167F689A23F361BD29A3B4B946ED5C8D37E71D3099281139E597720454D34F7313377600C71B0B5FB5D141F8F042B6
                        Malicious:false
                        Preview:]..Gz...oT..._..*!]...y.Rv.0)..Z..Z..<....17....3gn...a.w=@O..@v9.1!...O(]}.Y..a2xr.7....v....?R...{p...L..lb.+..-l..*J.=..a.. ......V9n...n.Ega..F'z%.)...C...=..;.Hf....o.x../..!.~...o.Zr3.........L...1..u=.E..v.e.2.K}.{K:Q3X<.../7..gZ....a\n":<....9...yN..;..(u"...5S.D.@JBz)...~...4.XZ..pJ....m.....C..[.V..."8z.R-...<.E...w..u.......O.".g..l.....je..l.....k%....O*..._.........b..^d.J3RXSE.r5Kp.........X.qU<..n6.'....h.....<c.V....|. [....l....c...L.0.7...h#..#.......H...'...p........0...$>......}M..~.."k|..V.-..|.-".=...Q.F...z...N...E...}...R...F4..xpy..N+...A%.=.V..u.`....8?"K..P..M`...xl..F.p..."..N...~....Xi*V.........x..^.#. ...g.....,..q_X.$...<..+i++\..S.XL..Z.M4._.R......Z....N../.QY.3l..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):743
                        Entropy (8bit):7.740519267569339
                        Encrypted:false
                        SSDEEP:
                        MD5:5F8E5727F452AFF41D2CA0087C189D00
                        SHA1:3DE35112FB668ADE23A28EF12041804036526543
                        SHA-256:DA42EA0D68537EBCA0ACA77F398D0227D324873B490826AC952A060560107782
                        SHA-512:9A49B4AEE4B8FD5299CEF9D130E466F181DC8DF6C37E390B2CA14C62DAD38DB3D07A2E0F8882034800E6F6080307C651764B1A06304E5F5B95F06A0103DEBBFC
                        Malicious:false
                        Preview:^B..5~....A(.P.aB......'..YV..I..TR3...?........B...$GrLF[G.C.{{..VnV.u"&g.....[...`.....J...J..L.wWq%.\../.*q..$.W.m.(owc....5.G{........g......S.l.y.`..(l....{..P.%>.R..W8.N.c.......!&.3...>..I.=...C.jH....z.u...'K:k.3."..G9....D.........r.#.s..u.......c....,.c..'."..!."./0.N.'X..jg.x.+K.le...V.....!...r....\..K.Ent.5.@&.`+...h.....;e...y?qw..K&][.Iu[.T-H....J...M..E3'J....`.>E1.......[&..u..q.(.........m......y.x.$.l-.].~.....9]Kn.P.0\w.G..O.k...o...&........^m.q...L.U.'q...P,Z.W?..pk...N.3<.<...}T....Db.W..Yv.F..-Y.....3..r.Z.D|....t..4....;....>%.Q......M.2S.`.<...A....._../!.<.;|....&..(....UA...v.0.......Gr..;~..F...Gq.).........o...fl.mIe.H:.....Fz..sT.q}.Y.|~+.g..B6L3d./.X..H.i....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):713
                        Entropy (8bit):7.701827349940963
                        Encrypted:false
                        SSDEEP:
                        MD5:FB4AE96E6270B55224FB854732165D1B
                        SHA1:E54AE19FF9B09C4DBC8C4F3628E79B44903F239A
                        SHA-256:5B1A0DD873FE1437B1F00D714EAE1DF3670EA804E104422A195ABF8363284F2F
                        SHA-512:7CF874B9CEC4E25BFAEC3684C7F1332CD8C81C46B0BE80BC12527F247DC8AD7466CF550301C727303EA91E5D0D054706B1FCEA7B8DF1389F59D180862B243798
                        Malicious:false
                        Preview:...aK..._....k.?.7......=..{.Hh.@m.............np~.G8.....&zk.. ..o..nX,2..`...2i..6....g.~...9v..Z.G...sS U.O.g.x.....w.2..,.+f~...V..b~...y...8;....k...]..f..O.c....`./...P.......U..~.K:U........R..]...rK...'./....,.s......_..K$lIN..fd..0..x...].......%:..+..........e.W....[>..........xz.K..W.98.qGe.N.]k..'..&.t..f.a}/.y..U.-_.Q........u.wmB....jL.o...f..g......B.7pao...@v........+.hZ.I.}..N......&..1?P..f...p.5..9...b........_..[%..Do...9.!..P....,....n].._...r=.~..T..L..=&.C.....aiF'F..6.1x*.,V.$W.....S:...%@BE....`.).k....W...vn..u.)L..>.|.3v...w...A2c.5N*.?..F.... Mr.,..He......m......h.qf..o.'......:>..<.x...h.-j4m..z.....@VY...V.......a....H.u....YGlH.W1....K..+.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):770
                        Entropy (8bit):7.678753512036993
                        Encrypted:false
                        SSDEEP:
                        MD5:AB980F89683190C961037DBBFDB6CB8D
                        SHA1:6E686A988C2E42466ACAA78D8A256B76821D9B0C
                        SHA-256:0DEC4514E3F552D6266B6591FE439592D8EB2EA53E57D310EB92AF4E7CBF845E
                        SHA-512:B31F03F20AD0C3EB7737A82DC17EB27BFDBAA9F6C263F931C7B83B75BE411C9EC8D52EAC3C1AE0F05D1D28BC6928057EFD00289436EF8A8C580E292E64F58098
                        Malicious:false
                        Preview:KL.._@4c#!....A....l.f.7C..Z{.v..TG5...g..B.y..\..g0... m.1-..g..E...[..k.o.X...f......y...K......8.PsK...,.S.;.i...2....%..nVS..)+p:.@..de........iA...4\.).EA.&.y..O..2.....d.WL;..3J.\.#..SF...Y..;. ..n...[c.+}.c.....c...y:.....?O... ..:pV.K:"..@....IR..y.....|..n...''H.l.3.e. .bP.......o.k"P.*..V.4.....^...&k...%N-....1.Gc}....$yp3....b...[.|8....o.d.*.{.j?a.Z|...Z.>k...@9..._..."..E.{zj&."..b...p.A.......~w.k..K.A::...v...2.".....3...K..j...K.....1...<.^.....@....4............|.....B...\..3.........!.....E..f6.1nE.........F..fe...~..Q...U,.....t8P.G..S..h:..X0.X.,.. .RY...:....E.z..U.$q2L.W=.@...npb.....9......._..xG*..I.JX..Z``...f...be~......P...T....~'......Z...g....9..C.........&v.B...~T....H|..Jq...q.mzb4&zx.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.7686056424584065
                        Encrypted:false
                        SSDEEP:
                        MD5:D0E7EEEB12096AE1AA94AC9FC2F6BF17
                        SHA1:BDC8CF6D30044B06AE830D76D690B7EF1D374D75
                        SHA-256:DAED30F2E768D68BF19A70D87EE97F3780EBE9B0A6C3F823376968AE8B7D0EF8
                        SHA-512:6E42F9AB4C1F7346910BD746496998ACA4EB9800F27C33B83C91A1290BBB0BDA6C102A1B99A1DC0C674120C8C8E8236FBFF69C8E440C504821703BB36DE8D9A7
                        Malicious:false
                        Preview:.R...,E...!.Q.G.qH.z.....<q`......~.+;.u..m......&.Q$..{...W6Z........H`.E..mn.F.....8.@... U.;....yWP."..l$ ...,.T**.l.3M...4....>}.Q......5S....7T..Qc.[A7Y6{...c3..L% ..ZOP..e..X9.dI.......b.;..#..+.....J?ud9.l.{.WK...i.s..7K:T...Oz..S.....6...T4Z.!9.53.2..E..@...p..7vo%.p.N.BS^.n.S.........).c.F..bI. .|.w....&=.%22Yr.m..4D#x.%...h<a.r4..V......a...V..X>vm...w..6:.\N.?^...=..>.g.`............A.+.".# .%-../2N\7x'X..b...e=. .z...[A....x1.4.../`...z4.a.'.C...W...CsL.q...1..4.B.^.K.....B...{...,...Kd..M5g...1,G.......-@........q|...'......q...#.+...fI9.'._x|...f......*..U..p..S...g...f.pr.w.?..1.:....+<W.........vU.#......,....v........6.u...n.ee......>.PF.{0.].....c....l.?.r[....H.........n......_2.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):766
                        Entropy (8bit):7.778574028845146
                        Encrypted:false
                        SSDEEP:
                        MD5:43A280890E8F3434EF63F33AC8F06A8D
                        SHA1:CB18F12C0739E41C8A9777F49FBFAF51882674DE
                        SHA-256:EA8221276A4E4916B66A1CE4A681BAAF4A3FC16E436908ECCA487BA16D76AD0D
                        SHA-512:18480C64065FE3EB0A414442FF36FDF037685F0EAE9F459EE947BFED772A72BB82098C3DDFB3AF1D15A6269E26677FB150346B1B27C2A44B707605C0A8A7F193
                        Malicious:false
                        Preview:./.y...ZN.........Vi.l9..!...9y1..]Y..|.b.Z.............{.Y.F......A..k................L.. .~.]+@.Z\.i....Hr0..<....x.S......S..H_.$...&.......8M...U.....8.)rQt.mI.:.^...f.G...}.d.......q..Eu...l..........u.._...yE...........7.<tn'.x.....K:Q...W{.}..6.Wt......Ra...i....J..L$.!3..^..........!).2l.#.DQ%....XZ.{J`.!..2..c~m..?m.&.=@m..?p....g..c1.U.l.M7\.FP.......F.F......!O:......./.7w.bT!4..H.<..+L.z..fXz.....6....<t@.o....v>..5.f..d..o.p.ma[j..Ox].do(s.)3C.}6...*4............i.d%..&..H2..3.TQ..L...v.%......T....F..=.....4....sb.x...9(.kc..A}.....I].W....8.T..F..U|#..,..@=......`..e.9.|e....A.rn....o.Z......{......EHc/u.."..T.Z.:..uV..}.xed.8P..../..B....57.PU.P..Xw....e....+/..z.....].OJe5....GxZQ:+a..,h;s#7[b6..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):711
                        Entropy (8bit):7.700103346194274
                        Encrypted:false
                        SSDEEP:
                        MD5:7BCBC68F64A652405BBC3CFA21DFF5E4
                        SHA1:521B9F3B5A50EE754D497EF4BFF1A440D4113B9A
                        SHA-256:E9E60E55E573405C2E39BD930FFF9CE837267023004767E60F5F3BDA6A777565
                        SHA-512:0161E08FBEA0D969816D71FBB61BEB1FCB8A22CD49906D0A0A1A47734EE09E6D1EA2197CE9F995EC4CE500DBA17E8E9A2A55D6C432F5810654FC7129E32B647E
                        Malicious:false
                        Preview:.jf\.D...&G|.L.h.5.u(;.G.+./.x...(h...=..9.."..V.#..Q......n...i..Dk..B.f..2.....{....b......+}"......._.Yzn.q.<E5K.et}"!aG..%.?....V:.[<./b.r.. ..X.3..U.#..7...0.s..N....hP.\.~..E...jK:k..>.........o%..v.<....u..Ay.D..fX.S.8d.HE.(...."....P...H7..../j......xXdYvJ`......(..$.Z.D./&..a.x.F>...8.{...I.......p.!h{'G....r.j&2..v...F.....8`+.rj. .....n.......Y.....I;b.."..".......h+7f.U....$M..ys`?.-.6j.qy7....i..q.{./."..S..7........!U....0./.v].".4EV.I<.h..K#<....R...9.GA#..Di.v.rU....J.7.5gC|?...b.=J6.^....&.z.C.|+C......f..1...|........o......A<..`.b.C.Q?~l.X...n..........,:.oi..).%.3:Y0x..J+`...dk?..(........j{....,...:.2.;..........AA..s2...8R.-...p.!]o.....p.m2.Q./6.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):745
                        Entropy (8bit):7.7474804189565925
                        Encrypted:false
                        SSDEEP:
                        MD5:39238AD8A46BD75626FFA17A60ADACDD
                        SHA1:76713E799FCADC24DAE91B1E7776090B3C93182D
                        SHA-256:1CCA14174B90808A2C4CA1AFB4E950176A03B8D7EAB6150CAEC932E75802F899
                        SHA-512:393ADCAC7A4C0765F52CA4D0E09A3C78C25E07CAC01D1A49D9BE3BC8827A4B93F6C624CC2B4A114A25389D4DB75DEBCE0D2A6EC9B4B9CD9A4BCCBDAAE23B61D0
                        Malicious:false
                        Preview:.......2.]...t.e.N..i..`....d.......J+3d..Y.9TW...x...]...._.7.3].L..u.>...0...u|.M......,.Pe..J...Q..Dd.........u....E[.T.}1..(.u.<U.o.$Q.....I.G.HI.......6..s6|.w.\.....g.....{F.*.}*<..-.(Z.a.......b\I9..8e`.|4...<Cx..K:s:....._]n.DbE........;.zN..5I.~.;.CSl3H+BX.^.b.......l.2`..2.....O...Kr......4.*.Y...X....6?.....,..`..[......|>.IA....H\DZ..G58~....n.N'Z........W.z.%..4&..o......g......-...]......d.}..h..........'m....D@.bH-...a."ym.N..$[...,i.../.b.....1.@..)A8.......3l.....,.k:fk..5..,.U... ...^y.i;.i.JI.K...@...y......h..9.W....&...........=.:..........o4...n...](Z.....p...R$..I..>..d.2..T2..R'......[..@W..Bt3.....ww>.ZL.^g.U..-...)JF...r?.\.E...\\<....x`.A....o.......E.a. ...Y.u6{..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):721
                        Entropy (8bit):7.6698179884555335
                        Encrypted:false
                        SSDEEP:
                        MD5:198968950110A72D573DEAA18F5D1CF9
                        SHA1:1AAB32237DD482727274FDDF716108298576E060
                        SHA-256:71B7FF89A6A661B48C3D64311DDE6FC177A1B47FCED66E83F6EFC1592C48C2B9
                        SHA-512:25D30D676DCE90F7F3EF44B90ACA5CF86B587B695A42D78A9A7D34AE335A0B95B97CC0F9FB60799E910786DC483A86AD36FDDA3DF278A4D69FB014DA5A04BEA5
                        Malicious:false
                        Preview:..+..6a..c.6...s.;|k.'...].mM.z9;....7y..r.5+. ...."....f.s..~...v..C+...I..n.>5.....?+...;.afT1....4x.....<*......X.E..u....XI.P..H..'..?....pW..6.,.c).s&.E..\+.X.._..M.0V...m..8...v.T..!....K:...=.:.H..~.?....G..............7.vn`.J.. @+w..N../..1.y..Q._..(WC..>......Y.\_...?.K.!.........7^.!.C...u....N...............7...,...u..o...|l.!U...G..M>...+.).j.,.....X.5Ls..8...f...Y1.r...+c.-.....2TR..'....G..c.....s..".F;n. ..t7........@{.m.V...D....c.h....&...s.u....&.a .N..z.:zk.. \.S...!...(.>.7).bh..T.?P...;...K.z..p.t)..........[.dK..i]<.'F.....;.uP.@...D.../... m.....f..(..*..w_H.R...KP..K......nk5U...jV...i1Y.e.+'a..#U.G..O,.JX.s.ZT..`.;l'f.K..YV(H....+..............mS
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):778
                        Entropy (8bit):7.7571538393569215
                        Encrypted:false
                        SSDEEP:
                        MD5:8E4B7575D0AFE88C0D624A56C27161A8
                        SHA1:0E122D626F6613EC7C2737CC81460E0501A82541
                        SHA-256:028F05F76FE2A5E4B6FB13CED6442F166247074817269D41AFD4880124F3F90E
                        SHA-512:CE7B0739274919D678423000494DBD5E5190CF80B34520A387925D0627D6E247EACD957185DDB3F7F1638D90C99841F925DD063D582170B1B61379F327A36063
                        Malicious:false
                        Preview:N.k.............lC...#2)&...A..4.V...0..9...?r.T.6.I.P.=..dV.mIW...F....)...@..d.....wE.......3....2f_..$...g....M.nS.N.<.U/T..C<.."..Wi.A...L..S.?.w.H..G..ILrMR6a..`...1........=.Afn. W..G<.y.eR.>.....ZVl..y.Ii.....1..B2.F.#&B..T0.:...}.^....,...a.K:..(.....Q...U..;.W...6'h.T-..|M.."..Jg.z.F%*...B.H......x.....A.g ..o....B.....(iu....7h.......gx.@..\.......d...Gu..b.z...[........,c.........z...z...$XA..&$.u......,/...X.....p'...E.j.$..>...].4.N.I`.M.....q.....`*t..^.B...j4Kv8..^2.j.._.z.RLm..Ub.....f.>W:.1..W9.....Q.u$...0Q...<2..OF'....4/..v.&['......hP.g.7F..HS.._6*=F.&t..}..>s4.. .zT.3..Q......5..sr.._]...%.`.jep..z...OK.(nn\.c..i......R.r..MI......h...[!1i...&.H.X.0.A...?..R....h...0.....#Ng.......y.#..4.......E".r.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:Dyalog APL version -106.-83
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.698420204357925
                        Encrypted:false
                        SSDEEP:
                        MD5:F4DF63B5B3FF5E5F0B043B7F9FA07629
                        SHA1:C4A2E80682ED9E2AB1F93357110778CA4E5D587B
                        SHA-256:2DF6E6F76C178DD12654B498CAC57CA5A402C6CBE5E6F8F96BFA5772B4861219
                        SHA-512:A1A49E119CEB05C011D9DD1180466CD721BC113CC9C64F904E330BFD1BD7E4DA6AF6680AECD26EA0E266D9F662C9CFAD186A7789AE82D0B8B524D24D63F346DB
                        Malicious:false
                        Preview:.....N...R.._J[.R.C*pl..D...........y@.L*S..5. ..!d.MC..6`,....%?.....Px...4...c..Q.E..Q.:.{.8F..1.T.a.W....gU....e...-=.F.x.....JNa..(..P|.v\.6.......V...>...ic4J...`...1.y...].&....;O.N..c.M[M.k........w...>=n.PU$.H..^.K:...D...)#|.g.t..%I..\3.-r..s....R...)D*......a.....jw..^.Y......3j.V.zG..Ra(4.{.O...:]K..K8id. s&...1.Y.".[<..:k..!.UU.*.o.....@.#u'....2o...v.P...j......|.....g...3..x'....g..`...*..O......ToD.....v!..*...RO..t..}d.&...K.....3._ .0.p..0..OY?.D.E.@@...v...32{i.N`.J.I...Vq)....N.p...P.....x.....FY.&E......|..RF0.x.....O."..Z.v..Civ...-.pg.....E@g6.Fr....,.....),&ZnM..8?.q...."*...1..Q...FW.z...}.f..`.+...;..n#.:..h....Hj.......EF.B..T/.-#...t...E.#..V..W..L...~.%L.7..o...:<).#.0{...x
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):746
                        Entropy (8bit):7.772540097905055
                        Encrypted:false
                        SSDEEP:
                        MD5:D71C4E9D5173B72531EDCC8E6304DBAA
                        SHA1:A3CA31DD0745FF5DD189DF44B50B376F08FC20AB
                        SHA-256:FC51785C0BEC6C79AD1AB8C0E760144361BC9C1EDC836FDBA29B9C6AC7D0FC74
                        SHA-512:D287EB1D4E6CDE25E6866B3BEF95C0D61EF6A98865215CE26D839A4E502A0906F85A917954A0AC473BAD9BA763D500DD59BCBA4B71C954F58FA4F78D751119BE
                        Malicious:false
                        Preview:Ufhz.G....r./...l^\..u.C........+...LMe.V.wL......ed..5..T......_..iAs..U.......m.6.nC..]$......o..v.,?7.k 2)W[{.,...Y5.P..z`.......O.J..Oa>..= R...x....u..!=YH#%..R.......z.?,}.j. .Q..*.`..F......l_..3N...MS...cR..v(?.jW...]K:[A......NkE.......M......O./......G!Q+...z1.=}.D.$'.$Z....f.D.P.7......9..R|.V.t..A...~.....G.....}{..........8...g...2...So.-.`..W/i3......r....v...P....,h...H.0.7.......YFQ....!R.....(..>....&.?........F...&;..fy..]|=.e...Gf..8....8/.O..q5g`.Wn.....3oV.?DK.Q..#5..k....S.c.G1..;...2...MY.X^J.zv.-....;3.%^hj8....z."..c!....M.U.3...i(/ht.z......M.....S.Ta......=LEj+..P......wj....*./X.....}d5Iq.*b..P...P....X>tI,.....*.J......lu.....c..y.F.^.Z.....).S.Z'.x.....0e"..U`..-..[.h
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.727084575624928
                        Encrypted:false
                        SSDEEP:
                        MD5:C47279383FF3FE98EB44BED953D96230
                        SHA1:91A38EB678BF25F7AA27AFFDA1CA59D5F4E9861F
                        SHA-256:6732FFEA5EA52D5651B52DDB3CFDEB36886B7542DE96DD1A3640623B7DA07731
                        SHA-512:2CD8E4396CE52C5E57B39A0336276971D7E0C628FAFC9A39BF6CEF8B6AFD9AADF771D90C6FBB1BDD66BE527618460EF1ED9B398C0FEA87421B88F6E534ED68C8
                        Malicious:false
                        Preview:r}./>..KJ'."-.H'...I@30zf.>.k..y;-<......HK..I.P(.C..)../....V.......|.b._.........g.yS..V9`..(..$Z\*h[.~.#.o.G..ai\.....4..?x.K.......0...>.N@..]..a.........I!E...P.A..]e.*.RZ6<3...4..8.:...]*.F)....Q......=n.X..S....D....h-E@O.:.K:..^*}c.;.4j.b=7.Ok..W.h...l..G....V.....c....1...b.J...?9.Z.].o.H..R..bn.B<........p..K.......1...^._..#.Q..."..iI....R.wf....(7......GY.]......1....j.C.8=.R.Z.S..I...q_Q.S.......Q..t..c...s........C.ye..._'l6r.<...K-@........g'..qV.J.w.Y)...y...`..D...z...N...S......o.}.ZN%..f.R.....,....'.....)`kU*...sKx...@.h8-W.cic.$.K'j*..B..=..>. +6..[ka.}|.........(T .3.x.......O...{Kk.(....L...X?/......6Y.....'(....i.m.r..7..m*Vx.p_K.I....;..Ad.9.^..8.....)."=........u..W.g..B.]{..A..)Z."..RP..g
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.7309222570707234
                        Encrypted:false
                        SSDEEP:
                        MD5:9EA7CA59070414CB36E1188D2A551754
                        SHA1:C95CCADE97ABB93D60096749A9616F9AE7C81203
                        SHA-256:ED7746698AF979B0D8D402AC24CFFC557BEC00FC827C293BDC94835BC62646E6
                        SHA-512:EA8EC6F8D873830D47E16C364B83744265BA5EA7029E0760909E3534F309ED5D2E15E2A4D4950A8A57F64817C2660011B53B01EB6F65873E2B36154832E3CF4C
                        Malicious:false
                        Preview:AiZ.W..Q.I.Z.j.-..n....{..1......G.^:z...+w.R.h.u...m&...+....L..R..S....c .H....s..x5.Q......B.Z...r.C.....}.S...io." $Z...Dh.(..qM.w..^.E.X.......<^.}.u..b..4Q...d.<.w).!+....]z.j.............qC...),...21.U'..B;.`k+.K:P5..i8...H.J.. ......@..+....2@...>..H.....p....&N.\.m..L....Ff.BI.Y.;.9....x..|..!...#....d.}+.{?\Mt.I)e....:...u.U.cU...S... .6.A... .u..oN....{..Jbw.}...>..{.coz.JG..w.p.w..d-.1`M.U..+......<o.&..YF.!..3.{%....G.X.?.=0....s5\..._..F...n.7F..N..?#..t..+..........l.?!}I..f...?o..nc.`B.o...Pl8U...3...e.;iB.....p.N(.H.x5.?....(..LfY....z....Y.pI... ....glJ..A..s.M../....A14.....(.......Dm&.8.2~>...6,...5CH}..G.6p....T.....Q..$".3.E.Z".q...T.w...g...|.n.L...B`....O..*M.?..d.Nk...-.Q..:A
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):738
                        Entropy (8bit):7.753703642398077
                        Encrypted:false
                        SSDEEP:
                        MD5:DFD971CF56721449154EED17DD2ADFF1
                        SHA1:85BB789B93CA1E847C481F994BFC01629A98874E
                        SHA-256:CFC4EC90F902A40EA75ECC38B9652AADB7E4B525A62EE5D643ED08D3BF8507F6
                        SHA-512:55CE8C116ADC2B7F9E1AE5D92C47D2D206348B43BDA8952DE0A15C6BC153EC7C5CCC3A3F569D55AE909DB9FC110757B2991F146E39E08C1B063719403641606A
                        Malicious:false
                        Preview:6)XL...~..s....qRi.AD......+df..C.f..{.q......N(.%J.....&...c..n<.....R.*.i..Z...3..u..*..?..[....\.o7r..a 3.J4.1.#...%$...S.,.#.L...~.c.7)...}..d"W.d..Y;eWo.w....6...(I.....+d....W...^..J>......8.|5k.7.O}.!&.`"K:9{..P.G.-5)..s...7......mLm..5.un.G..|^..HQdz.I.,`.j........0.m...u.....l......:|..zo..q..9....l..d.B?r'8~v......q.7..DP.`....|V...+......9l....ED.aU.;..=xl..#..G]7vQ..m...{x<&.e....".H\.u(PE+TW.k.L.!..c...i..:...B.B...\.<.P..-E..<.x...'td......F....-..Dc.......F.J...6.=>.r( #..Y3....aJ`....i..W.8(KR.r........O.:...{..t./i..y..ZlV.z~.U.t.:.U.f.......wZ4........t%+b.^.....S]..Gd..Vb.:R.$...<./.?/...T......s.a.*...=QmU.[uOBb8.._..U...Qb.%8.u.jti..N.FqZ.........,yY6..ZTT.C.....q....4..G...%{9
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):745
                        Entropy (8bit):7.737052298707597
                        Encrypted:false
                        SSDEEP:
                        MD5:1E914FBB536777D3B5874318A4AE5E48
                        SHA1:A1D9D8BBA87B50A7E0299FFEB193E31070361999
                        SHA-256:3DD8EEEFBA3A27FEE20D1B53880E04DCCA059147AE98F23F6FEC75F5002B4E52
                        SHA-512:4057A921B1DE319309D06BEDC9993F1C36C6D4B433A6EEED7E091BFE9C4814D11B25D7E1120407060AA25E2B5EE982432799329964E7E699C99D31A482C484E6
                        Malicious:false
                        Preview:6...B.J..!.W-P.f.C@z..b!.......A.t....2.eC.t.w ......u.].....V.S../C.*)...........C....j.!..~A....Y.$...J...b./..|..>j.f....G..*G.....D:.5..xVK...R#..C..?.......-r..*'.%.V.dq......l.......k;s.Ao..&..?.*...6.z...I.3...8K:...m2.}(.eq.4....A]...C...dt..fD...M..qp...0F...v..!`>.-..~..fHTGd..9Nb.g...9.'......i.....p...Q.J4..^........U...j;.....(..J.` ......%..&F...L..S_.....T<26..aH...&.(..?.@]..q.x.eT.1.j...f.....n<.<`-.mH.g.).2.f7).4.*....e.......LS$..I.|.u..%."6..L TQH.[..L..k*.....-/."..ow.6....pw;.LV.....l.rUO)J..=..(.........u...<..y..........H-.<...;..a...-...sR....+J.{.,+up7Lip...C.#.*.9..z|..s.{1<=*......K!v..Z...!...c..9...7...WR4RfN.. ...#.3....0..koh.R....9'... .o..&A. ...=p...4......N..../...F
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):736
                        Entropy (8bit):7.7088846763991326
                        Encrypted:false
                        SSDEEP:
                        MD5:CDF1CEA902B68C04BB265A60D339D04E
                        SHA1:2BECE15307DC97907C172DA69739F7A40CDED758
                        SHA-256:A03CC2B4941A1191A459F876B1E5863F409129D55E1360BB37FF06FD8BC7AA63
                        SHA-512:D51146ACAA23A1CB0E71B205B21DF19249FC22CC8EE728DC75A5170C32DE5E4969BF5C767E1B5B8D76A0E49053858DCD51BAE99AD513731A0E1620138381AA35
                        Malicious:false
                        Preview:*sV..@...u...wN..`.:.Bx./.;........."@.dy.|'..;.x..E*.;?~....Q..-..Jk.s~.k.....o....E.CQ.XDNdW.y:.....f..@.}.C9j...tG......y.|.~X.F...r.="U..e...zjV&..7.."..x..7.m....E.q...4Fk.`|...C.@.g.......*y.Fg.Ue.......XK:........]...#..l.E<.|..H.b..I.(p|.....6@..__../.*...?.$L......:.w.O%...!..Y8_.."Ak.K`.R..[....K4.c.|....'YK..Ug.q..[...L.m...|..Y.Wh.B..2..T.($.9...v.lR...-.>.\|...."....agd9*. ..4......l#.BSF.f1...,..Z..h0.K.&..&....?J~)9...Jf.EUFRS.#.]..*......m....'D.K.....6.4Q.....^.G...9..x..ug....Q.}qE.f*...w..d..Z..........9....7..........Y....;..&......Z`R............[yC%..:.."q.~.-.p......VZ.,..)...n..G..G%.o.}.O.M_........pr.A.....r..{.......5....rjxb<.4.S...q.7.S..J..P.FY...u1.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):745
                        Entropy (8bit):7.7055478153972725
                        Encrypted:false
                        SSDEEP:
                        MD5:2C548A91BE9EC3231E723279A2177B46
                        SHA1:9D6CC28F42FCD8879F0C05E6088CB5575E220670
                        SHA-256:266B61DAEBA4F31D655E9025AD1116CC34AC5B711C5196CC6C343804CC939456
                        SHA-512:677163ABA072AC67628D332B8669EC7231A3A8E6C1EEB06AF299D45AAAB409222B23590EA0E0C07FF6B8F63AEB9DDBDCBA181F583AAFB9325185E4D9DBBE3798
                        Malicious:false
                        Preview:t... .R.=..;i.}.#.T....]=.l..HP...b<m..k$.....#.d(.....l.:.<\YKZ'..0.*yQe.T..Z...!...M.|.....$...9.Z....#.{h..{.d.......Z..[.@b:...g...&.{........`b].i=o..zM...?...."%.g.Q|...t...*H..EP6...ZR$.......G...~"s.)....9..H/.e8.@B.K:......m..sN..,....gW7.yGY*.w.Y..AP...P0.](.7~."(.f9.,/b.;..8L......MR.6.=.DX.f..-...0.......c....^..].L..vn.&b>..Oj..1.ZQ.......AC..-Qb..GP..\....b...gl...'.8.j.."......)..4KL5f.kA...7.a..J[.6....MV..nEk.D. #.T.\...2.J'...}.].jf).....qi.O...| . .7...'.......7..p........VR......B.....;..9.&>.J.@.2.THa..x..oN{.....m......X........e.F..Z5.8HtA...J..Re......^.Z,....n.y...!\-.Q..=.)..k....n..t....;...4...5..e`....K6%..P..~.....{..b.N..L.[.....;....s%X.X8.p..x.......e^.'ST.$..X..H0'...,b...N#
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):7.750051962782722
                        Encrypted:false
                        SSDEEP:
                        MD5:85677D9A1AB06DC70635CF8F09A819CF
                        SHA1:EB335E5AFB4E185E55DBCEFE6DBF8F2C0DA47409
                        SHA-256:54906755F7ED5C25CF2A745824C40A616C9F56B5A12998E1E3BAE1BE5CADAF83
                        SHA-512:34671FD29E0A309655B761F9A9ACBA219E4A524D32C94979A35F14A4EA4EF7F93827C676B66F174753D3F40DA8A86AF5616C2B9B17ED14814F93303B86B9A028
                        Malicious:false
                        Preview:..t..p`<Z......v..._....sM....Zl]I.G|.....*.....!#./.1..U..e\.$...0...S.._.........5..D...h.e..A.....-...[.@.'....#.*SH2....t_.......vb*..%.2\.8.WO.5.i2..z...>p....4zf.^..R...N.=..S8....|U....@d)..|.{.....u..Z....H....NL .B&{;...c2..]K:.03..O.-.._...fb@|V<..A.8.W7..w:...$s.$.Bi.,.T.kh.7Q....z..1P....>c.0D...u..K.;..r..D%.&.2w....#T..FI$..;..E..........+?M..._.gB....[...o...7......T*...&.UOa~`.X.T>k......S..G.h...T.T....@.......,T.X..F...vx..W....Y....i...0B....n...ss(.6..*.m6.._.D.h......Xh...N..6l.2.....c...p.PR>C.}.....^gI.N..{\~...+..4Q..md2..t..x<.u....?t..MS.=I...@Z9....=.`..$....C.3..<q..H...>.).{..I.q[k..~0.j...sEU........|.....C.d.. ........3T.m.9r........8-...J..J.....nqR....E..;.....s.1d.x.g.........&..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:COM executable for DOS
                        Category:dropped
                        Size (bytes):747
                        Entropy (8bit):7.705840876758807
                        Encrypted:false
                        SSDEEP:
                        MD5:4BEBC2A76F5E84CF26B81843A36C7D4B
                        SHA1:4C598258995B9D910CB252A88723A0656B3167E1
                        SHA-256:C84B20F97BBA6C7DF7A9040C0B0966F57319750D220384DF165D0918497067EA
                        SHA-512:3AA67407B1E1B4C2579EAB0A35EEEB1D242C345CCE23AAFB5D3082428450B942E950F8526CD494E0145674B42A01B1C1F77E875B1CBA36D2DF3FD59740B1842B
                        Malicious:false
                        Preview:....1.L...N.r..R79........\N.F'PF{.T.y'.O..;%..9.x...}..s.e..$._..4Y...f.4.~.......LR.m"..3~..OW$.....v/#o...2;....)..i..E..gH...?..2Qv....y.HM.\J...q.'Ej.|.j..]..v..'.....~...P.."...@......o.2.2..WrW.!"..Q]e.<........'..K:.G.....8.P5..nD.. ..G...Q.9N.d..B|.....5Z.YM...(0...A.x...#5E.....\..L'....8e.fm21....DYc....G21x.<.&.PIjU....3n.........W..O.xQ...ZsS.B.%....x.g.Ut.-.d'.h....t^H...`.t..u...C......cDH.).e.g...-T.cb..}Q..........,[.i.GAJ.g.]..../....x.GK./K.In..Z.......|..Al........S..a...,%9.?...[..Hd.8...59<.......M?.)./A..)..%!5.......%.j-.).]H.[...@....'9$y..nG..;.. ......l..............0c.+..s..p .u...18s.....*&_.g..B..u9.Y.......`..N.E@.2F.T.>...o..r[......t..,.te~.T.8.T9D..-;DoeM.. 0......8.4..|......R
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.749066656538684
                        Encrypted:false
                        SSDEEP:
                        MD5:17AECA645BFC75BC4E0C0368D79905CE
                        SHA1:4411CA6DEFC1A992666F0C69DEEA639E795B12DF
                        SHA-256:E2F0BF7E3742F3306829CCDEA25F61563D60DD81F7B631AEAAF7CCD3DBDCFA2D
                        SHA-512:CD4DBBF2584F69D41D29A42366B854C3A3880CFFCDE82E7665C39642D607F3349DB9F4086B59A9F09F293079D0E359F0FC62D61058257015D7E216E25472BF5A
                        Malicious:false
                        Preview:~`P..g...W.[.g.....L...p..f..*,R....K|M..a...X...R.e.yP..?..`1....Z....K`.4..N.>..^4@...b/.%i....T3B....gJF.[.@.6..5.T......V,`{...l..u..t...y;d4.h.Y2..aC..ZS...Rt..ZI...)R($..0.'...4..(..W/=.4..d.O.............YX...A`.*;..OK..(K:cj..)J.]..s?.RI.!..:.:.|.".1...X...hc..N..#....7._.....X.(.&.~F7.n`D-..$#..N....J..?|.E.....%I<?..5....Vp.[J...i..f["3Q....6.3Pn..a}g.#....frO......$..B..4^D.M..i....IT......F....M....1~M][...z.......1...T!,s.pQ.5.{L&8[.~wG.So..FfM.h.T........e..E>.....x....6."Y@..}q..B.r.$.4.../?.\+......Y.....fjL.40..0.M.,..fm.lKM.#......l.{..a.D..v.}H.=.Z.......rB(...K..j8R...v..Ew.2U.n.v.#._..:..&.k.mb...].{{...L.`C.p..7..F<g.`...S.\. ...\2}V.......KRS...t....tA..0..=...."`..U.r7n`[/..?.0.DZ...;#8...2
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):740
                        Entropy (8bit):7.738874651703161
                        Encrypted:false
                        SSDEEP:
                        MD5:17BCB9FC10EC7915FBCB4710F44A68D6
                        SHA1:1479BEEAA57592D517EAF229FAB6CD8C0DAA7DFE
                        SHA-256:030477D804669FADACB4574DCE0AA7AD0402BE86A0D9524973DE7BE8E792F53C
                        SHA-512:E0307D43747CAADBB311A114EC9BB8FDBAAF67C8BB6BBF35119DDC1B71BBDAE17831AF0BA9544A2A3471F1440D10707774C2E7F9AECFDFDE15331E7DB9588E15
                        Malicious:false
                        Preview:@]IFt...WH..'.~.U.._....O.t^.#.WB....$.....+..Q..;V..\..oK-h..,]2.i.,M....]....Z..v".1fs..K..q..$.{.Q{..G....].{=m%....0.......~h.F.#.5. (.t?.~...r.s,.G..'3.C.]....]).Ac..K.4....).@!W...w.D..sH>.y....]..>q3f...\ "..cSFB.K:.p..5.*j...B...D..ck....:6.:..y...R-.."&.C../a...M..l..E.y...g+@..0..qD.b..........p..&..'..........z...LS.Ow..A.T.!r.....]........(...X...K..U.K$.G....5.u......U....[.H.^.U%....`..nt.l5..%........mc..kl]R+\...x.3..-djvq..N..=."..........F.;I,{......j.yJ+.'"..q,{.p.;o.X....(N...Q...K...>)xK....n.q..k.$).?..|u..D..P.x-..^.JfU.3.NW8..=B../l..q~9../....D..Fv.Gh..e.r.%.....j.l.e.(.J...Og.{=.z....>.."_...C..PC..H/G1.."3..,.J...)\[......?.K.....f.........w.....&.BMm .%...Pu.I...&..?....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):7.725003454254933
                        Encrypted:false
                        SSDEEP:
                        MD5:036C3F17C4B3210C1E6EAA441C300C51
                        SHA1:9E3FB4BB43E5B8DF8DAAFD34011BD2236EFCCA60
                        SHA-256:12C0F83F3F2DCF3727FE6402AF23306861231268BC348FE7534C182E1805D79F
                        SHA-512:596049C423888A87C5DE2285DFD3CDF142BABD18422D4524E7045DF393D2EEC7F25ED45817FCD8C6B62DAFB5EBB976BE43F2F3721FAD69D61CA0F7841C803736
                        Malicious:false
                        Preview:..R....=..vh,S.A..O...T.<.g..]..[{.U.:0.A...........$.K.E%[.B$^49A..l..DvP..7BJ.S.^,......b....X..>......J>X...(./..Ru2zP..!r/u....<.bX9...p.....6....tH.,z5.I_.c....#......Cb ?...U..p..].ejy....^4..{..<.=PwkGZZC5.J...Q..]..L..K:....w(...{`h..?j.GR...n...U.SUl.^.$..q.^.An.7....}Q...\E.A.&:......,)q.....N?...8Q....g3o.t|..L.YR\.'.93..\..K...:.&D..e=.....&.S_....*.._.?.B.T..............ORvB9.u....t.^...E..Kt......[......K..J|OL%r.^aj{q.}.....^78].:..@....~x.<cZ.mM.dl.Qa....\....d...+.EC*%..../.<`.......b.[..M..47...0...NT....u.T.*&......&u}.......a.d.'..v..+*{..uX..N!A...i..Ny.!^|Y.[rLD ...V..fW....Xv.6H.ZK.Z.YY..K.......b-..x..z.Ab.....O...S./vX..B..aU.=.N..N~.8Z.#... ..Y".....u.0.\z....e...x.....;H..=.6.h...V.%....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):764
                        Entropy (8bit):7.753050383957791
                        Encrypted:false
                        SSDEEP:
                        MD5:1FE0EBDE86FAA9E1DEB22C9D71C80CD8
                        SHA1:3366910A53B98DD0032ED877D099E484F6AE825B
                        SHA-256:5A16B08687C36DD38BAD193B7B70D771B7C6EEAAEFE15C27176E741DC8E7ACF8
                        SHA-512:FBE317A9BC79CD2C4B0F607A1B659BF664FEF7FD294378907587D34A96312E7832CD8A0128568E2C14C5E5695E8DF3F30166E78490416A688F6579BA21CC8CD3
                        Malicious:false
                        Preview:..4v.#..j.:.U.us.....)R....[...9n..d..j..# /M...L.A.%.1...W......'W.f>.U.~n;...O.iNJ9.@.l.s`6&H....\...q...b..b.^../..&.'.D.2.PF.......i@...3?..KU...Q....\k.!...,.p..<$...............-....p.@.........].0..r.2....W.`9{...U.t.. .L.S....%.K:x.....}V&........l.....hC....../.7../A....2..V.6...T...jK.)... ....0....T`..M.z....`3.%..I9/d.ETem.'.S...6A......l...]..~...2...#...k.9....#.J\...F...$...`.3..E..e........(....[=.a}..'XXe.N..=f.~.......h.#....)..O..?..w.(6.."Y.Vn...^?a@..%...|.c...'.....Q......x.u....Z.......F....I6.i...Y....E..,yB..RM... ..p...".y..:...._.....{.o......}^5.y\..p.@.?......4f.e......_...........D.z..)....0..1.7..c......s:..Y....K...b.[........9....U.d....e..q+_..:'....;.\~.|%..sx....t...U..!&...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):720
                        Entropy (8bit):7.665304489669695
                        Encrypted:false
                        SSDEEP:
                        MD5:06E4DBDEB0BD41F76A19504BF30AF559
                        SHA1:1B854EBCF2C5E1205F1D92DC155D1ECF03D63895
                        SHA-256:00DB667A66A92ACB54653AB2414B24E8238178BC37E7540878CFEF32B43906EB
                        SHA-512:2847546C15D93C61FF5A881E4275DCC3495C9ABA4D6C5425D03CF5F1C936EF0CC72E4B8129FF5659D102BC971D1BDF8269F12626C2A73DAE09A1EB71077466FE
                        Malicious:false
                        Preview:... ."-...G.C.gR3Yd).r...W1P......~.k.5..#.v..N2....K.. .Erd..mY.~._....N)VWW...)..HR.....^...j..e{.....3...'..p.........y.......b.J...7.A.N.WR...#.....5g..b......(q]Qb.L..l...IS..To.).w..l.{L0&.d.aK:..HYY....f+.3...0.j.k.n...k....edl.H..h.*...wm..~....m.Y..N .o.....0. ..?.~.q....0hs..Y..b'<\..$..7.3.....e.....+j.....A...sg...r\.eg;/U.C..fqe$......e..l....:..5.....0=..+X..l|..P..;..v.....CVN.v...A...|.u9..P.2....}M.....k.I...^.....A........Z.........g`'~]..H...`..8'.X..d."w.%.....9...]wvq...r..co..X.k.....=(V...;`...5R.o}.....Jx..5......g..9.../..^G.h...u..3..;.h.....J..F..?..Cs~...+.......1..g......U....\....P..@...j..l.U......rnt...oX...;.<.?(..5...!G}f7._6...........lG..........2.=
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):741
                        Entropy (8bit):7.771574309393397
                        Encrypted:false
                        SSDEEP:
                        MD5:6F4CA7145D4A6AFE53A89450A49C54D8
                        SHA1:85DB418FF98FAAE73403A2EFD03044489F41E83C
                        SHA-256:6B3C54AFCD96A343D7423007C8F9235E014867DEF4FF1E5D46400ACC76173DBF
                        SHA-512:6181F590BB4052EADEDD4026A7667B85902ED6419E125A55A42635FA748262270182F78914FBF9B2ED7522840E3079B39318BC1EA19258CA29DC4A0254C7427D
                        Malicious:false
                        Preview:..Z..dl.........m^..;..-iCl:r.w.,kP.#t.`.\.D.N..A...w...ct_+.[..L%.b/E%..NAT[..z(....r......%.......^.y..D..ns.)...L.R.z..5..(..F......_.,...y..........V.s..SgT^-epF/...@.bj?.h......44.c~o.0..+9/..f..d].........a..+.JK:..,#. ..+..A........ v7......!.`X..5&Z].X.....yf..S...<.B....3...%.2..3......m/ 'S.xr.`.j.tO6y.J;....7.p.G;o;..eU..H1......'W..+.."u.a./........-.`r6;....*?.y...$l..L2...L....i)U..'.)..cOS...l........'..).`..B..}.{....z..<..m..V...C9..p.t.>.4>.1.r*>.........I....y.8..~.....".7.#.+.......:...&.m..Z\h|C..1<..... .........^..o.Tm...a.......*.=...Pm*XRM...1C#.>......P.L.].Mk.S.c.....VN.\A..Mg.N)Q8...=1.P....a}g.&..tF....LZ.<.q..O.?.A.bt.].S.._\..O.F..d].f&.....ZK....<... juwfF..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.732903828867201
                        Encrypted:false
                        SSDEEP:
                        MD5:84798D5D7F96506749744661B3AF3FAD
                        SHA1:A6BDF6BE1B53D8516D3FD641A1BEF8316BEF8687
                        SHA-256:8E64135648361763A7564ADEE706D68D19A0FB8086CAEE41432CD00A61514868
                        SHA-512:5A530FAACD59C7A688EF087AC8786CBACFA769B145CB8121F7150E8461EE9469FA83C27470D3BBD7FC081AD99F04DA632250C33D8716F036ED226C3EAE142193
                        Malicious:false
                        Preview:..ly.....R.(...~.....$....:..u.w..}&...CH.....;.....\$..&'3q.0.GY_d3... .C.K.M.3S.>v@.2{.!g...D=.ID.<..F?@1.o...jH.....H.;..z..6."j....d.(.e.1k..s.,...[.H....Q.-.},.;..!.$.._+..L=..lO.a.V~..%...>.'..y....5S......%8...K:....odLf...XF.>F.Ao..o6...&h|.Y.......,/<...._..s}wDh...k....|.L4.o.QJ*a..R..3.....!pb.c...wC..m......%..=.t..6..!qH...p@...TG+D.9.X...>.C.h..Y.*.iw.B.X....c....JFL.Z...U.u .....)..... ..%W..p..&.o-.....;..i.:..i.C.I.9...........5..>sET.._..V.."lT...:.....5.!.....Z.......:..*.4r...Q.....}z8{..h>#....).[!.......@o..!....d..[..|FS..JZ.1.28.s.g..X..{...c..g...w#_[^x..6......j.d.n.^..$.3...19.x..W.9..*YO.y.H.....;d.G...;..}@.v...q?...b!..ru2U..3..w.s.j!.pl....0.).r>. (7e._.s....Psj(.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):757
                        Entropy (8bit):7.701620739418066
                        Encrypted:false
                        SSDEEP:
                        MD5:C425E4EF12DE356F8E156A61A87F352F
                        SHA1:D26DEA40F22CFD5BE9BD94ADCE6982A45937CD41
                        SHA-256:D93657641043ED71B53D95F10D22324FB7841514AC18CAEE083BCD017E454CD6
                        SHA-512:F07A1433DDF7E1FB08175D8D3AE9D522ED138CF15BF5513E74CCA12A055CB2FBE5E1A09544BFF52B738CDDD483336A41AD75F41D17829A0BD6D3E852A9269BB2
                        Malicious:false
                        Preview:J.'..xlI..8;.l.h.y...2..,.%........L[.pC....3.......k[.g..f.r5..<......:O.....=...vu)X...dK.BJ~yH.l-.4@...=.J.+.gs......[^..S.i....:|.Zn_....k0.]5a.$?L^..,Ra.,.`.....9..F.J=w?...YVc;......v.=..x .n..k..i.....y.........}."F0..]..H@.>K:"...,N-*..(..1.r.B.FUU.[=1:..}.Q8.<....n.u..m.GF<....F.F.#A...8.h|.|.+@.,.V8..n..<_M....fm.r.9..>P..... .Nw.t..C8W.f.!A.bpBCy.W.f.%..R [....f.30...}........(c.l.X....U..E..g...qs.x.H.X?n.9r.I.8.[....M.4...5J...r.Nfv+*...H='=.F....>.E...c...Dw....?J.?.Kem.F..T....".....V...u$...B..h.(.m.BCI.IQ....'D.._x.u9...5..._"8u.]...@o\KV[~.H......b.3......._....d.(.B.)..@A......;.6....F`.7.k;..0."'.[.L...t.^dA.......6.9.f1....A.(N.......4.ah.Kv{'.....w.eL3X+..U0.8i ;0...CkXa5...Ss....S.x.D.|..qgS
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):747
                        Entropy (8bit):7.688019648019293
                        Encrypted:false
                        SSDEEP:
                        MD5:521FE288BBDF2971359DB45CBE9AC627
                        SHA1:C0DD37E31E6F016A43E319627069DEB926995A7E
                        SHA-256:5879335F2E7E61437B7A0CBCEF56CD6BEBCDA9FB55071453F760BECAFF412743
                        SHA-512:49670BA2EA1FDB55082561B4922053F624E471521C6BE638A43EC1F6B9C26D6579E68F166BD5677D623ADEAFD3CF6BC63AD10126A453D8D64A822903DE75537C
                        Malicious:false
                        Preview:V.......... ..;..S.E..*....K.m:..&..A..$.:~...".$.Qv...V?Ff8......(? ...c~..- ...........@.......p..Om.....>%.1s3Z1.....n.$(*.=...T.p.}.H? .i.`.R.........V$Y....).."^.k..[4....e%l.....u4. .UA4....-......../.O..y.4...J.BK:V...[...\...yl...L.{a6.hX......Lh.kb.. ."I&e.Y.Bjb.D...B.a...^.PQ`i5.......V.^..e.4.|HB.}..=..D>..a.......Q.%-.f..9?..o...`v...P....$....5...y.I....#pD..x..K...6.F?d....c...........o2..v.RPF.v...Q.....,....,QV.... .b.\..Pak.........*.....VG....c..>......a....h....z`....n.M1.2..|sp..>...8..J.b.3..........mJ...]Cyd(..M..gb..j.a.(.....k.....O.+X...x..A.cg..*.....b..U.p..k...v.I.....v..f.".v....M^^.n..%!.MA...x...q7G.P.S.y......sPl5W[.1...:.3..Qb.1.....S .....1&N..+.....3..K..@$..uTZ...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):742
                        Entropy (8bit):7.746261622850538
                        Encrypted:false
                        SSDEEP:
                        MD5:FA6B57E13E6030327F5BA923B7EF0FC1
                        SHA1:3E310585185421B84CEFC018534AB61DDAD8E66B
                        SHA-256:F61317DCD0BBEDE72C7C35F0EA9E00ED26E24AF358B905B971883FEDF4992204
                        SHA-512:565AA9BF0616DB665ECCED902100E65CA5A335D4BAD52CE224C2290C9CF142C3AE2CFEDEE276A8AFAD2635567902672E1CD74930755FB12ECE0D0814CCD4938F
                        Malicious:false
                        Preview:....zrN...........#y..+5rd..C...% ..8nvzIF....S.......6.q2.W....@.1b..k..*.0..!e.h.^V#....D.6K....Ox.....^a}+..9.c..........?...gH.89...kg.;5........2t....i.>@....5....,...X+...Mk.....4tW.4&.]..z..........3$.$.oM.ps....]K:Z.b..6.T...I=.w.:A.P.."+..%.......?.3...9....c..D~...n..D.[.f...L.#...Z..-..A.........<.Ga..V...$..bz.S...5!.. k.8.F|......tL....`.c...h._$(..u....z!`...o".]/....+....x}.........L..G...*o~.......X...J...(0-%..[@..'.M..v;H.......CY....g1...c..bV..<`#.ItB/....O...F..............Es.4....0.-qI.5.2..0..#`ik|.oU......:.4YA.1...T.'.:q..;j.`8.#V..U.@.8..$..# ..3.ZMp....N}.t........nr....o..u...1..VX./:.W.Z*..K...w..._4C./.U..[..7~.1...M.........~y:l...y......"._.y0...._....\...6.-\^stG.S.z...).#
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):722
                        Entropy (8bit):7.67558856556533
                        Encrypted:false
                        SSDEEP:
                        MD5:69F3F807BE866890B767484F4079AD6C
                        SHA1:63ED3156394B52BED539B90D0403EA3E82B0E77F
                        SHA-256:8EB90DFAEF075E7D5AE153C5749F26DC5D235425279C44CD1364EBA96C832193
                        SHA-512:AA72191EE07975C7C99C2EEB969F597A097893EB7E14C332AEE81C3B1E475C0929AEC6A40A067059E86222122338079236C728526022B16E4CEC814B7D2B3905
                        Malicious:false
                        Preview:..7...]......Y......v..;....Z........%..]...E9j}`.Y..RL.sW....;t..?\....>5G..X.G.?...i.....+.'...v.R...0A....NN[v........F..C,`. .)R.%..X.B....gFsF....,..;W..?..Au.".....h.d..^*v"..=S.%&.5..^...:.9]EK:..*JC......o...;...5 .2.7....U...a..[CldOb..5.l5.>.y..JC';..cX.ehY..."..s.yeN......R.8...}ra.z{....".Va.....,.........B.Mv.%.qx..[Y!.=..MO|.o....J....~......3...#..s.8.t...vZ.b.-c..X#...F..p.i .V..FO.}..."Rp...6.`...F.OR...LZ...~.W..BP-..7..q..-.-....UG.......9.2......gsXl...V1<'\)P.0....f.|l...D..]{(u.2l4N.xU%.....}7.+..t.V..1\y.D.9......%Ou.#...l.{.>7xj=.\...Clb<...u..LF..d?.p7y.....vv...f.y..l.....(q5g.GO.d....ui..o....\.....O.k.r\.. ...i.~.|..".$.T.8.k.s8h.x.f12.KAA...b?;M.N...JV...O.>.n#
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.768635650317789
                        Encrypted:false
                        SSDEEP:
                        MD5:1F013FDB4EC41475436B8EB6D9BF33DC
                        SHA1:69B50B1D7F5BB0CD910710FAC02C060E67802CD0
                        SHA-256:F928E85CA2A58A5A0252606ECBA89B3D9DBCE8D18D7203B6F0DB5DB41B8115D8
                        SHA-512:B5B9BE3A9E242E974E9EB53306E8BFCB7454E94269BF93F8D44490FED8D95BED442D63AA37F0465CCC78AA5A7B29367E4AC47179F9B54C667B689B504955348A
                        Malicious:false
                        Preview:..+v.(......K.N.t....##.....b...R...-..C..U?.A.E..7\%..D..G.u...V}z....#....i...oqt......{&'........[{q=...G.>...{8..n.....X.,..yI.._..I...v.L..c).!nP....$.Ot7....../kf.,...:..6......i.>...kt.......j...YN..$...0nU..zM.r}...u..K:BI_.^n..Y.t;...P|...N...4f....;..(!..;..e06b#....T..c(.jHh...#lm....sK'9.....X...DRzJ.|.....].7.......`w..+.M1`......iC*.&.J....T..x.;.....u..F4...pH.3"G.\..=...Zd.....L....."E...To5...E.... .6.c.B..n.....@.....n...o.8.F..c.=l2%.0.....]..N#e......./L.......u..+.P......VW0.....&....Y..q.]TJ>q.~.A..z.cP$.$....#.{.7..Mw.C._.F..~....EWdu.37..<0.......F]..;.'i...\s.F.....*..S............pUX......c.v...W.+...ALyi.1%...u.O.w.V.7..>....Zi...>...95..h.+.O.........|...U...y!r..../.w....;.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):748
                        Entropy (8bit):7.7030532876552416
                        Encrypted:false
                        SSDEEP:
                        MD5:CC9B2CBE785666BF2E38818E7A0738C2
                        SHA1:8E9765F56190C5897AB2158FDABFB508B3697F03
                        SHA-256:82573CC1A0EF4C6C84C0D25236E6B0C7091E32BC06BC5678CAD40A5F86A0029E
                        SHA-512:846FDF481D153E6D2F842CB57F43FA48D3F8FA457466A05C66CD9F454D6DB251605218177651C8AABDA6F9FA8BE3D7F6EDA21210CF0A40B25A90998A24277463
                        Malicious:false
                        Preview:x7..9..k6.}...)C{..g....a...}.2.Hv(..~.(n.C....5.y_U.Z.8.".A....|...I....tX....!..Z7.^..e..F.....hq7.K..;.\....l.Y.S_....g8.Z.d......Wt.4...7'v.#C..2K@X.'........]..3......}I.7.g..`m.U..o.....|8|1..=Q...2..X1...PP.h.G..K:8.....AN...........H..f....'..Dc.].]....7..e....x6..!..q...6..q~...I}u..9).~.3....H.".8./.....o0..s......4.........=...|.k.....r~m.....M.G0J.i6>...y...P(b[S.)tl.J..q..,...N.....l8"./.|......X.k.....7...q..*.k...f.{...m...5R...1G.#..[.v=... P.Q.{..).C..f...:.U....ic..>..C.,m.pTL.....B..[,^".`q........wg.....W....{..zq:N.2L.[....Vc....I.9 ..M.)>.DG...>y.>!..bg..n.R...*....Adfb..!q......(:.-nD..Z..m}.n..PX.{.}...p.u.%Y.P..D.a.B.dl..9.s..8..|....".n..5...@..i.U.BZr.@$A......{B...*...#6
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):745
                        Entropy (8bit):7.704886333680278
                        Encrypted:false
                        SSDEEP:
                        MD5:1C1FE3E41C734C1B08FA4315F2D5DC31
                        SHA1:AC6E49133666BFC215A9A2BE9A7AA9E271192F50
                        SHA-256:180C570CD18373405A0056BF6B07D21B8791EFDE983A80D41F7E3295368EA9A1
                        SHA-512:758CA7114DF0A9F69FA4AE7F08BE28C88A3C79C7000C3402E7F4B1E48C21BABB1BF9B738E6C5D0ECFDF0624033D9526C90FF04C57806FD6336E3E52EA49CAE28
                        Malicious:false
                        Preview:...h...g.......lWh...P..w.c.%gZ~..Gzj.{T..|.3R.k...2v..b...~qG.+2..92E.iS...^..D.&.........y?2..0Q.v.{..A&'|..h.K..F......=X.UqP..:..R.e.........L..+HT...n....Y#.BB..M.....|....J.5.O..D.....bx.E....+,..8.g0G1.`K..|b.O?$wM.K:Mf.m.B.!zj......#..}(}..]V!~.i8?T...T.,.x...U.r..X...M...{:...a8..A.....A..X...$]0h......O.k..^.~. .je?.Y.1)g..;>G.(.&..z.'.tY.&W'.F]:dX(5._.LV.SFn...\..'.y...3.{..;.OqK..V..........7..ag.......,[...f.Ha....)WL..\.C&Ml...w\.7.~.8FCM)|.7$....7|..B;2..@.A...I...[Is9.i.N.P..^...............tk....B_~.t[]..M....!.J.....;]C......]..d.\4ys...1...p'.#.#FU-z..um>t.G.>D..N....U..........(.N.......c.#..F#..*;......=..q. .T#.!&7.).i?...f..@......a...l....@.+.K@.!=..)fu.+.D....0?......([.N.N.`.....B..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):743
                        Entropy (8bit):7.722245444509778
                        Encrypted:false
                        SSDEEP:
                        MD5:8CA99AB61F9E0BF666FB2338DF0FCEB5
                        SHA1:CECCA5A90671D877F5DCD42B1BE3073DA8E67CDC
                        SHA-256:D9B9791E758B96A5D24897EC557AE6FF84B69FCB66DE5876208E345180042ECB
                        SHA-512:C7CAAD7FE8180C2B07B7AB3CE8FC6FFC02B20C1ADB1D0C0973F28EEC83E33FEB03C21F060A17FFD28DFE3104067F4C80C45EC68C534AF5EFF00F8F01CB66E4DE
                        Malicious:false
                        Preview:...v...H..?...n{Zy......,...<.^..0.r.Q.sx..s.f...U.Nh.....E.[:.<.......*c...+..{.i?y...b/ZCq..:.,.D......./. +S....Z...H.$.....4~...[.k@.......T...22.>...@.b...KX%..!......?k...Z...e.^...Q..iG...S.r....>....K:.x5C8.B.r..P.......uG.......X.K....!N[..'.*9C.}.1...;'....HB.V.....T.....C..#X....{.n.......=...Q..U.....+...qd..r..n.Z.....,r.G6G.w8...Vc.....4.....|..V.....54].....V)..NI........f.:TRl..m...nK.'...A.9.Q.Q......,U-.2zRJL.t.?./..#..c..z.RX......%dP...@.I...&.*.J..B.(.f.......w;n7.5%....o.mp.m.h..i....~..V).W.Q?..Y...o.{..:.Q.u.o+EM...nr=.<q....3M.q.9..-D......]./O......\..q.......i..`V..!{....e..G..!..y h.\..].4~Q|\.CX.;..bU..S....-DV....g...N.m.cX....~l.?.....?L...A.... .]..za......6."...A..0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):722
                        Entropy (8bit):7.730012432093169
                        Encrypted:false
                        SSDEEP:
                        MD5:F2FB45B7A875D1466BCEF3CD38595B27
                        SHA1:A06D3180ECA4E9D1A61CFADCEFC89031C4ED581E
                        SHA-256:3AF399CECF9B27D3C7A430DA6779ED862167DD4F68B5B29006E5C2FA33E0A8AE
                        SHA-512:38D378FDCD8145DE2ED07F9272152514E2C881469FB02D36D59623D289E186455BC30A2960D6C5E6B4BFB83AA6381028F69422634AD109AA963FEF98826B8EB0
                        Malicious:false
                        Preview:h..e.B..}-..=..]..Eq.dr(eP..h...t.h......._..R..\?#...].1T.A...:..u.."bMp!..<c......A..p.r.z....>....(k;.n.|.._..2.#..6d........EJ.A.......|.C....Z..&.]..Gnt.....c..~.$....6t..f..]B.O.w...P....U.....JxK:.<.K.r.".....t.=..2......\...\..........f5../0`.d...I.,..~^.?....Q..C..Y_....M.;$...S...oeIU.s......L.w.D.L.&./2.i7.M...m.RM.....#b.-...pfR..p[.7.M.....-...h.`..Y..T... ....RP$..*...o...I..?.A....h.?>g5..b.8u..n....h.+...@..u....2d....S.2.F./.XO."%.vHsB....._....t8E...M...Qz......B..m...........V.'.>y.CZ.N..sW..[...........K?.g...O.h.[.D..6p..b..../y4...e!2.`..6CVS.F..._r...v.|.5h_...]Y..L3u.z..A..#`..f.E..Mw@......k3!..vZ.J.6...N,8.T%,.bhO...-.....~w.x....z.z......g....D.?fx....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):742
                        Entropy (8bit):7.742641216507771
                        Encrypted:false
                        SSDEEP:
                        MD5:C8E9ADE7B9290B95CB7E3D7564FC3278
                        SHA1:B8E0D0D2609A7D7134BC3DA9F9A0FEB50C9E8A88
                        SHA-256:40339D32B8B9F328E8F174FAECC7DEA2E6DF8043F86704493CF02BC2387F0A01
                        SHA-512:5326F5620D1C4FB8D2F9F23E3CF06EAF228279975B4AE722E4DA1D65E10B4E1C5B298863D4EF56C60A9CDFA20633A99BCEBEA8871D28DF933BA0CEA1C4666230
                        Malicious:false
                        Preview:.O.....]Y.&.e.....9.T.....4.....+..U;k...}...b...g......iQU.c.%.Rd.+......V..vi.`|.B..Ag.....%.......A.._6....+....jL.p.v.[..:.a..N.q.....(cq.........`....&i....|.NrNX....^.bn.)..;H'......zk.E./j'l.T.a7.K..x.....\...K:M.b...C.M.a.qD..e.L..vi|1.Q.5......C..jX.,p.......=M.#....u......<.v..T...G.e.Y.\..>.0..>Jc3I?.....=.k..r.D.U..M.6..)..S.Q.ly...E.HR<V3'..:d......Y../.(...'@.*.S?v..+..s..L...Z.28<....Q...)...$.q...z\`.%`..s.x\.S.Z.7A.J.....H,..Q&.Q#r.*A..6.3..^.. ._.M.EP2I.l...p.1s.H..!.#.ob...........d.....Z\.}t..?T.K.#...xQ. Q.c......|.....PBN..x_...3...I/..Sb...U....(.....F.]..#...?b.<.*...x r..@..Z0>P..k.>....h..........YP.M..X...G......R.K84...".N....k. .u.....p.v~....~@fL..E. ...&e.h.`2...dTw.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):745
                        Entropy (8bit):7.723768379109835
                        Encrypted:false
                        SSDEEP:
                        MD5:D4DE411CD904D2CC959035A63774B73C
                        SHA1:ED1362D4E51A7782265905D179B29A0BA8217FB1
                        SHA-256:EFBB0077B67271FC81A5B84121945DCFB123BA10F60CCE6F6A4D4A81518FC532
                        SHA-512:5B37DA3D6C32E238C447AC50A4A01018D7A14F7C72A62AE25B2EA03B10E3D24E1740A9E39819FFDEBBA0EA0850FD35D95A3FFEFB2B0DB143ED1F7BA488281326
                        Malicious:false
                        Preview:....^)..zQ.m.Y`..8........A..Wp`d...KA|=."....}.0./.7....%J...V.....&.o.8._.d..P.ge.[..gg..y 0..M.......p.{N..+.....e.....;5.....L....+zW...........?6N[0s<.+..z.I.;a.V..7...)z.e%.........'X4...m.........:......E.+.j.M.....lK:]B.9.....!..g..=9.......a...HE.p.k...D....1Z...........l..VWp.P.......$.<..B.Kz{B<.z....B.A3._.`...}g....i...3.L\...0.8.~xD..d...2.pr...iA..^.W~........(.*CSP.n.Q.o-l....*I....R...'...4....o....LS......{......HU.%.M.}E..9;.....y%m.\.x....b....6b... ?....N...y0....F.|zrx...!m......v..\E..#.R4.7....rF...h.../x....l.&.}TH.g...a..e.e.M... ...I....,Wf...?.y.J..^....B.E.v.*...f.v.OQ....[ E..T.`....Q@.&..Xf..d]..f....L...`o.K.n.3.w..,......$.:.;..K...._...7....d.M.O.0k.f...`-...P.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.750247672402144
                        Encrypted:false
                        SSDEEP:
                        MD5:D338045A994F8BDB5C9A0C0DFEC2415D
                        SHA1:8D7EB5BE904AD1F9C9860B10FA609B4FB940300A
                        SHA-256:79ED49DAB30025B640DFD2B47ADA5BC126F48580A6B4F3F777AF9050F31D43C1
                        SHA-512:81A153C2375FC00931D8FC2079B71DD17E1F108F86F3FA836547DD4A5DC7AC02E79CB65EA3A43C7F881DF4269B72D211D2D5A3099B29635F728A3ED6827DDC8E
                        Malicious:false
                        Preview:0........}t..|...i-.dW.j.,.....H.i..i:.G.q...\....P...,....3..1o...*.cK.(.I.m.K...!.P0.x.f..t.6p...HC..e..'!e....._'.s.a..4,...4K..$1..cr.`.ws....& Q7..a...._a&..z..s|~.?[k5...H..:YS\.. ...D.4t8...,.h......N.*@....l....N........tK:..<~..R}.~N...`.....U..f(.p<..`%..!....oR.........~........qVJ.:t..E.ig..#j.b..B...i.6..[!..}i....v..6......%.$...M..0^._m.=s....>.M.5...5.. `P...u..`....Gj).w....h.U...T-G)..!....0..V.a..Sfz..,d..d.W..hC.....:o...u.......v\...p..Vk&.{O.....Mn@t......@Rb... vK.i..90Z.O..ZN..[/..Wo4..C-..b|}G..X.t..*D.C..)..\.FT.6=f.?+.z.r.............?....*In....X..$G.G.....`NQ......V[......+lk.z...xI/l..X7..H..u.....h........`z......<.W..S.H.t|n,/.O..S...).c.....0..+...G.. .#.....2.7..#L+.2%.652...i;
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):745
                        Entropy (8bit):7.754487127294791
                        Encrypted:false
                        SSDEEP:
                        MD5:BC7195E0324FAA6F148D077C66E43629
                        SHA1:62ACF2A040F46DB932692B7A19F79A58BA0857AC
                        SHA-256:E4F616185B969C48479F3A6BD1F3064EE06A27F13E70456ADC7D127823AEE1D9
                        SHA-512:E714554BC8502FFC041A2DC2FFDC49810DF5A4BF0BD7702412AB408EC45F08AB220760025656EB7DBD29E5F0970530C949B013366611E98AE262C2F8DA0F7888
                        Malicious:false
                        Preview:[+m...}......X\.+8...z..........@.X.{..T?..Y.w!.......J...5.K4$.k...up.+[A....m...?1... .S....E....!....T.<........<tH.......ZM...SZ.h..^.E.m......e+...3t5..|...yO.}!@Y.v.A..X."..._.<...3...M...`zc...g..A...#...}o^.i..K:....QJ.(&..<....u....F.DD.....K#.3.4.4.........:.Tu....q....b,...P9..EC.C.......}..[.V D.C..D...'....%I.Y.._.?...G#..H.).'j....[../..B-.l../......Q..Rg.....f.(..B.. X...e..48.U..}.xs..E.....J.n..8~..R.J....."8b.BY..N**sX.G~..'..y..M.j.....k.....A......M.!...K...<.S.3+.R......B...1%..`...F..l.?.[..e/bq16.C..#....S.a8.0.&.N.{..9.o.D.....;.fo....n.F..N:j..F#...{...:/F...z.6p.K.a.x.....2...L..~.G.....).E.......I.^/..../...-.2...m.l.........7.Y..R.j.K.$.r..d.e.n..?......B....,.}...7.|H...s.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.73111681762283
                        Encrypted:false
                        SSDEEP:
                        MD5:7ECE50AB4B00CE969E84828F44E1DC50
                        SHA1:E04ECE1027F9778E86E35AA17BB034F95C314B22
                        SHA-256:54CB972DC8BC7834451CA5EBB2B22AE4C3A990F9A322DDD2E7A526EA2D2A988A
                        SHA-512:B5DA0BD6A689AF731DEEA450A05BA479E883BE913FECE7DDF46574B9C4EA05530B6E832DED9645076A431D4A055AF44443549D6BDFBE0248968C87E032896E26
                        Malicious:false
                        Preview:.\.....V.....NB<9..o.......z>(..).c......@?.V.#..+...2.1..W...M.QC..4.I..j=..>Be8..p}...d.y..kj.[j....7....b8.#W..f..6.'t....">1...y..,a.....V......L...;^.Q..GH....C.P..V_.4R..LT2..I......jb.a..@\.{....K..^.....TQ^..u..a.>...6..CK:...Oi.r.....Y../.J0....!...B....z$^.n..R.....T`.<...F.Q~.^rM.A.[.o..=.[DrR..Q....L...d...\..?9........g.EB...xQKo..1...Q...^....F.-d...@m`.5E...as...f..3.....V.|.\.......jp.......$...I..9k..P .....4.4V.l.x..?..E(.q.....9..rx..N.W..j@K.'tD.1g..L....L.b.Y.......i...L...k. |.4.[..X.d....j.Sl..<...~... ...u....9.e.e......<.....h...>&.ww..w...^.IB..g..{k7.B0.a...`..B9c"#..\.~...q..^k..KZ".h....HT.F..4....".".+..\j...`z..@>.&..?...D@;.X..i.J-....V.............2$..8....,.x..E.4..E6.3..`.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.7593580252199255
                        Encrypted:false
                        SSDEEP:
                        MD5:542B4AB710E9FCE50004B09DB428B24C
                        SHA1:7814DB2F14246D68165D54C923F00F73619617B8
                        SHA-256:467B144C2D968AA16ADFE3F76E39797FDD65B283EAEB83A2927F6FA94CE182F2
                        SHA-512:7405EEE9DBFF0035EDE1BB4DE83990C02BC4AD253875848C207173C973B249EF8EC09FEEE4B36AC38E2388C6A34A8B1780DF9BB06F13A92053DD9971F135514A
                        Malicious:false
                        Preview:.q.GGJ..;O[>._.....O{...t,._>....+..nK..X...I>.`D.......1....Fl..K.P..6...J..m......')FN.(.....%h!...d..|v.~j...x..S2.1.e.`U..b.6;T....l..9..m...Bb...l.........t...|S....O..L.o.z..8'....D[.c.C......j...e..N..c.WK:Ih]fe9..\:aYu-.4LSx.....i.n....+..6.....LD.(..-......]U....Wj25{.n .m.s......'.\.-...1.F7..........9....N....a....d.#~.8.!...[..!...s..../..v.Fl.].i.Qs.d...R..I...K.....>.f_..^....q.....=.].......+2 .._..:..7z(+P..P.3...l.#..W..k.f......7.!...Tc.{...m^#C.%R........../....:.[.7......5}0e..0.......lf.D9m4..4..k..u...=....i"5.. .......H<C...Z.....G.d8....~.......k.bx.`.^..=5...q.~......5.......ri.....~2(.>s.3.....q...jKe..]+z5.J.R..-.*.E>....7..6pPz..TL.d.S*..{g..Q.;.....v<........0&.._..M.#.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):742
                        Entropy (8bit):7.727342176017102
                        Encrypted:false
                        SSDEEP:
                        MD5:9BB6B3C82D2D73B3CB4B9D2D38DC83E0
                        SHA1:1287D0310B633B835CC1294C0EA2D78D623AA92A
                        SHA-256:99EEF193B51728EC69DC9A9B3D50647FA08C46188E86FB5377E08AD43D969B4A
                        SHA-512:BDD4E718B0664A117D8391FDD666FF3F896640A1030D77E8798E4E91E20BD82249D00AE7245386C7B5E251E2906DB1F44BC8D385E612EF4714F95DADC67EE768
                        Malicious:false
                        Preview:.e...(..N.E..M+\...x.<.l.;...^."..C]V...+(..~.=.h.W......oj...o.........Y.....).7E..,..7.z@......nr...:_&....!..hgT..y.S.....N.2...-e.P8..).i6.]....).MG........^...0..A..w."|.;..{f.,".Wv.K......`y.G].m..+O&....3./N...9]..K:.....;.W...6.,...fkz...0..Q....v51...[...5t.....^..SCm.s.4?!.lc..~W..-...V..........r.m.^Bi.<.7 KU..z...W.%s.p.(....../C.,f....?......A.?RW!.`........rx..*.i#@0.Rf......{...1...n.]...{.4..u.7"=........c..+_....#$.x.K..SHa:."...-h...?T...Ts...}..b.._z.".3.y`..TgP..M...{{>..IU......[.TZ.H..6.P..8Ul4.......p.u{........+lF5l...G.....X2S.4V...:..r.......hI..a"..T.......d..P.Q.d.w.X.?@.$.!.)q.E..zDAe...e.tj.My".........R.@.F....K.J.P.......^Ugs.jJ!.X....j..g..%.V6E,..AM......N....8....z.."
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.700694397053739
                        Encrypted:false
                        SSDEEP:
                        MD5:789B8BA9F4E326B3676ECB522EFE0543
                        SHA1:3BBA60C11A2659EE3819BB26B1A587D6B859DCE8
                        SHA-256:40C6E2D46D65FE3ABF993C451E53EB2EF046777BE55A01AEA97E5010DB37AC86
                        SHA-512:9AC97402CA4A0AF659E2A9811ED4FFD93C572FB67C7ECDC09489EA0695D8D4C2C9633E753DB48EE5073AC70570A9A228BF1533B973FFF108998785CFB3E1744E
                        Malicious:false
                        Preview:.i&...[.A.....U.._@....p/"..Hh0Z7X[.!/..f. s.9.o.6.a...PH2._..M..(...{...........[0Q.ejzQZ..I..)..M4........Z.%.ce<."F[B..).....<.T....5...Pc5Z..Q..*df...b.c../..0....k..h.(..)..d.)f..Q.Q.C....4.g...;.Na.j.O.....w.+.cI+....K:DA.....5...O...g...$...NJ..\X.%....]up6^.+..y..0]....PXm...+F......_....}/;.v.m.......g....X.....FZE.>.z6QH=pR...o...-D.W.......!L[.A.`O.S...&o..V;w....a........N..?....G;..kI.>..6.7....s...E?~'c..iE4...HRC@.;..K,..(..6..y..d3.p....9.qe]$%...4.p.....4....`..O..DG.U..$m._.knPC..{N..._..M..\.8..w.......ZrS.;;..g.......-F...o..c$..t..]IK.....Q..w..d.....{Ew&..0.......0..".}.c....eA...'..cO.n..pH........mE.Y..BAo..?..D...Qs.9A.P......D..c.y.i.z..S.o.f.....7.4...>0I...&....{.6u..v....0=
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):7.709398212296696
                        Encrypted:false
                        SSDEEP:
                        MD5:0893F4F6659529CFBE3EC24B72F20AD4
                        SHA1:9BCBA59FA5B3922D82489B5E48758F0350F455E5
                        SHA-256:C7A121AB69F3EC2F5D98BAEDAE4CAA5D9424B66BD47B8CBEA1106ACA69392531
                        SHA-512:C7997CA487EF541946E4D3BDC88FF3F40261972181EFD22796FDC80FEA49FD3501A56E30E14564B6C0D82394C593322ECC869815AA59AA44EBDE5B4A18EBD6C6
                        Malicious:false
                        Preview:.4n.Qy....m%.<'.`.......!.a...L'T.D.....V....h..dj..[.J..z....!..Z....6.<{..s..{7.x...C>.4...-..j;.0....v...@....ge.G..\5j.r...7.......Z....1N.W=...'.9...`5.D0W..zB..t...U.>.........t.6.M.........Z..jKi?.J....O...']..@{...'.K:6K:..`,s.z..Bq.>G<-.h.u...=....``.......7.&...l...W.....S..+0C@5../C.........~m5..O...#u.f.3\JO.....O,.E.KX@.$x..+v*xp.6$.H..f..G..;'".....x.._.&.J.....{[....../..lz.,..$.R/F..&9..l......`....}.........}..2.c.......nj<H..Nf.H.(.............J.r.=i".f.."3.....^.f.:4hE.....~...X+#6.....O.kg.K........X.4+.F...r....M..U.y....K..bN.. "..`".)...N...A..._...]!.g. n...F.pH/..vJW.q3..*.5..e..MQ.n...z.>..X...zf.....\F.NF....1.a...s..e.aw.i..j......;.}oz..^.+t..A.0O..k...J.6*.f...[
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):755
                        Entropy (8bit):7.721423987548133
                        Encrypted:false
                        SSDEEP:
                        MD5:9815B0C8A506897C4DB82102D64B4A6E
                        SHA1:E8C80AD0243028A1328078833CB92391FA5A4646
                        SHA-256:47DECDAC22391AD2B013B70F6560F8782B36A2B6A42CC369772C9739986A46D9
                        SHA-512:1C69B8F033234C6874C720633318CCD96C0A7167E2A58475B112A79DA679A2DC738004DC8E116A6B272FC085F1EFED57CC1540A8E2CD09FE298572FA689AE6B3
                        Malicious:false
                        Preview:.a...+.#.O5.{2!..........5m]..0..XV._.:.1..h.N!.1.........Y...C.[.....L&....>.:gg..)%.j.`..w..p...(~..4^.@..,.I..?.Q....M......m~/..M/..z,..|.\..}..lP......QO.(pi...S..m%/...e..(hy..."N...*.J*7a....z....T.[...$].._...6..d...^>.K:B.....V]!..i.}...k...'...k......s[.!.;..L.%SEJx..x.~{....2.D.c;....+.5...v[.MS...uU.{.(.1...G.....>.5....y..\..~.i..S...B..P..{......h.y5..o4.Q..\.}..>...._.+ ..h>pV.(._.....T"g..U..c2.......e_4'........}.Az........\.Ic..$..8.h.....tR6...{QF.)...*}.....S&...w9.......C.....\./........m.;.c3....R.g...h.0.7._m.(.@.h.}.Bd..7.j.=C..,...=TR..AtG.<.7.=.....+L3../..bd...J.8l..H.4.......ZLIG.../m.KA.8.,..1..:.rG......p.4M..Fjz.S.9..t.x_...gO~h."....Nu.l..F..X.h$..........Z......".^..T.]z.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):7.762377679623029
                        Encrypted:false
                        SSDEEP:
                        MD5:425B88E2CA8B2504D0988F92ABAB150B
                        SHA1:B1F253B9DCC13A8540939A91D6D33035E8366849
                        SHA-256:D2BC51AFB1B393851BBDF6A2846A63967CA02FAE25F93BFB1037688D12942EEB
                        SHA-512:4C4F73AE2EF26D4CB47767DED8B35A2DE62D073A907520491A61B0B578A59FE09FEE8D32AEFDF9F9C60283F42B3B73983542153F18D704357042B1A03309FE78
                        Malicious:false
                        Preview:.H.J..}9..xyp.G.>T8:o..}.....\....oF...k[ED.....{...nkRo.....V.....7.5Y.C..W...Ut.!1%..r..J..a;T..'....@..".^h9...5..L0U......q..s...Y..B.5.1.......nb2.....n....].".3E.BI...S.>.......'S....S...6..tT... 3...tjh%Q.....K:..uE......?.... [...z....FHn.^N6...1..R......@}.+.U_f..:.........Q...m.x...NJZ?...V @?.s.N...wX\'dsn"..|}...'...>.....`ODT.L...(.(..E..7..{7N...i..Z..$.:...]%..[.e.9.....d.. ....q..)R...b*..L..}.0]...../$r@...-.-.u.`.V.J9.&...a7..g.&....&W...[.#M.D.%.y_...6.U...6.k...M....X....II.2..#B2O..i.....L.~.=.r....^..'XW.5_7..OKq.|Z;.EgHK.......8.*...,f..`.Y0m..........~.IY..!..(.L...'..f.&..F....HK8..j<...|>..o....v.........d=....\...K...U...H@.&H.V.IeJ....=R.K......=...k.rr......y4N.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):738
                        Entropy (8bit):7.727264138485051
                        Encrypted:false
                        SSDEEP:
                        MD5:3C335795723570EE06D444019732AA7F
                        SHA1:418F68451331CF90C6CEA293654B298C88F40812
                        SHA-256:87B8A0586FB856BD93320BAEEE25F54CAABB7138521E24A47970E6D28296CF7C
                        SHA-512:AD675816E4199A4FD5A3B3137AFF12D58CA98EEE48DF0DE6159662D92CD44983187BAB81047E0A31FC67CEDEBF34797746741897563BD0367DA8B319702DFB19
                        Malicious:false
                        Preview:i5../>..G.!....E"..Yq...w......r....~@.V...sP.5.'....+v.......x%h...... U+l.'[.H.i.a.m]H........P.$!..D.@z.s.j4.....)..R..s.....r........................bs.a2.....0.0.........1....(....~..>.Y.,..g..{.4.f.<..uK:F..w.V:....n.J.kX..7.x..Y..}.;.B..+1.%.....}>@.$4+S&.?x.D.E....s.e..C...Z.O...#..U...6.X..S>v-..UK....zx :....A...@..M.Q.ow./....I.a.6@_........9.0.<vH.~.TE.`Z..-..F'.Vbx#.#~.4.c..j........T..Z....02.....T....DF1....Q........~<C..on......X..H...R....V..(=R.S..^.......R..2sMK...N....N.p...~<...+.#.)3(v..^71y.Y.o.!@....@...on.R..Q.\....nw69..Z...X..R.J.LR..K.D.0v2...2.@9...H.....cQG*.{.I......h...............Z...g<.....7h...1...e..m.4A.H..S.....Kr7...c.. .n.[.......5.C.v@&.@.V?d
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):762
                        Entropy (8bit):7.7423736434547825
                        Encrypted:false
                        SSDEEP:
                        MD5:DD3A55A48D5C5FD6FCE7D12E3669C33A
                        SHA1:594E9E7D2BA28AA8B4B107784A5033F3DE41E62E
                        SHA-256:6C4E1BF8B0CFDA2DD927D46BF06C6535AF06E5A89D8F706A00C65AD1D9717561
                        SHA-512:070A54A3D21D606B7A022D267691B667CC3B922AC00FC06364BFFC7127BEA91C976CB3CE65823086E7674B9E6851BE2D82273BD0426F0F777758177B31707268
                        Malicious:false
                        Preview:T1B....S..}...1E.Aa*=..x...['.u....Fwn}..#..u"Wp.. ..l ...p..x.f....GT1B^.X.....~.0.ot.M......T).l.m....V-.Z.s..xTxP....H.Y]{.._.....b....k.}...*.II3Vm.Cdb.......94.@...K....C:.....de.uY@..8..^%........>F..akW{..e8=.(..J+.[)=..".N.x.z.v.K:8.+..:......1.....'U....`...e...KH../<.B..{t..M..a...4mg...Dh&V).L.O.R...$..e..:...oh`...G............".7.G.....?..+.y...c.g..y....J..1..`i.}!.t.@.....j.I#.]. ..J.:.A....0...`-v.[.U..DF.QRG.qN.........."...?;N..G{....Vz....b.........p........s...f...rc.u....@:.W..?..|.<1...t....8... .....V..(G{..Bw.....ID...y.Lzm...Z[W./.....n7SZ....i1Fp)....m...OUm..F......ou.x.... R+b[........J..{.a..,x.R.o.).M.ic/..T,....p.....<4.k.1H8).)(q.O<>.>............=5..Bp.Z.T..Z4Ty./....|....a.q....$..N..3:(.J~.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1970
                        Entropy (8bit):7.911135802261452
                        Encrypted:false
                        SSDEEP:
                        MD5:8540E300E7DB9027D28BDBE891CD6506
                        SHA1:3873DCA2CEDFD20927C5B4BC63E5E8FBDB3A2DED
                        SHA-256:66706C9AAD7A9CB2288A7E312624E5F84C2EA7038B3F112079050CEB190FCBD5
                        SHA-512:B051BA3001EB5E70267CCACE24DCF662BB1AA902369038B87E2C6B6DB6DE190A1AEE1056B1887D54939A57741B8F70964787D10904C69D33FBD72F2EA12E2848
                        Malicious:false
                        Preview:!...2.s.,x[.V...o..Q..S.s.\...'7%.W..e.K..y.B..^./..s....>.1....?f\..*y.....G]V...^G..%.{..,....%...v........z.........[C..Q....l..'\..O..cn.......Z..03..]..|92.?....]0......bV...X9SIz../.t>Y.t{WuF.w.-.n....7...}..$....W..A.:.M....H."E..r.f.v.[u..;...'C.m.B....^h._.j.[......x.J.8_V.....IZ.^..).e....,... .zI,I@.5...MGG....x..b..U..K..8.3F.M.A.....1....NCn.0..n..X...T.0.K.B.ft.?C....T....?m~,.e.m.bt.BF.5.x../....`z.>.V=Jl|Xq.D..;........Ez...}K$......|...F6[[.z&6....8....ht.e4.A9_..w.0...........jO...iX.,..6C..u.t%..KpL...Rp.1d.Z..[.h..Lk..!...#.m....XU..?.....3..6.2k.n.. ...uT.z..$......df......B..L...-(.......s.zS..hJ.7......A..r.&......].P.f........U.;.wM.}..........,....5.!.A....w9....N...z.......pQD.s-.q..gDd..p._K...0...i....(..Y....<0M...92Y..D...j.;.|.....z.......ul.$"'.G}.r.*.*E.$..o...x....`neJ..C......Vn..\.:.OV:.Z.T..2..y..l...?6h...Bc....m.....+%..uiA....9.*L~.V......Q....3.....yR3.3.?...O^w.l.=.....s..);......"%..sp^.ao#.........
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):554
                        Entropy (8bit):7.626174742881058
                        Encrypted:false
                        SSDEEP:
                        MD5:EFB6B1A1626DC1DBDE86F4ACAD347CB3
                        SHA1:66716345B2628F1D439D3633FFCA7A59316EF7D7
                        SHA-256:57B34D4806632574424455559E1E3F4C062C65B753FDE512746AD877DDA85035
                        SHA-512:5940904B5B5BAE9F70A0C48433D48F1924D767935C470CB4B7F0539BF15B51A3A112594E0C1D6EF44A47EB5859F5F249455BDF54A16D24E839EE9C20F88C47DC
                        Malicious:false
                        Preview:.......N....y..L..:(S.E..ce.IEI.En..f.K:p...Ky(..{..+.._..<..C.q.&W.Y..8eUa.:..b.=... ...N#&....h-m9..#........^)....vG...Z.a.Y........+U......pR.-..sa...I..H./Pl.W.7J.P..}.S..$.,0=0"..u.*.....E..*R..0C.....A.V.?u...U..R..w{...rB...=a.j..jq..W$9M1.[.....h.P.V..YR.*.....P.?[:(.p.g.&..9.q(V...n..lhM3. #.t.A...P..Xk...?.......8.`g.n=.q[^C.6..6H&..6..(c.r..Abe.2'5..v..t(f.X.].pk..O....;al\..:..x.%.B[~W_m.......*.D ..O.nV.|..T2OU.v.....w.p...........z~N.....a9.P..W....?9x*@..5X..w1.@.BQ{.L.g^...:?.I.3A.K.9....=.@b..cf.Y.,;3T={.o
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):578
                        Entropy (8bit):7.679966303804833
                        Encrypted:false
                        SSDEEP:
                        MD5:AA1C6E0FC25CCE972B424D1C22BCD8C0
                        SHA1:76E6594D9F5223535BA2EC83EB343D6A8D8D5C35
                        SHA-256:9992B4920DE01F259151823708724D0591FD3A90AF7D3079FC1A8CDFEC3E8FBA
                        SHA-512:2BC5697A2D693613143A96AE95C92836516E4DE4C3458BF386282458292FA5E220A03FE1C0BD7F3FDEC3FB3367B7A0333AF297CBD45F6B32A3D0935FD3A6A344
                        Malicious:false
                        Preview:..F\.......,.Vc.....".^(.k....`...M....d.y.W...>..z2.O....K:[~.......^&G..\...)s..@r...6L...Lq.j..<....../.o(...J.9...A...Kh.......m.'y......jID..aR.x1..oo..|.v.T../L(..z.m.R.8..Y1.&.$....A..X&O...[4.J....M..A...P.X.......[.:.....R...Y..>..WY.c..E.....s+b./).R.`..=%R..L.]..%.d>....qx.....8.V....M...P-/....w../r..<........SP/......K.E7.N6P.....-ps$...ih...........<gs.+c\.E%..E[]....I.....x....Q..%.p.n.RM.Ya.3.\.#vw.Hz...D......f.TVg...^.4.3.b>..nn.....LD....Z8.OyvF........`..e.../....?.h^WI^Z...;.D3...*..Q*..#.h4.v..=G...Sa...F.C..L..^.B.'.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):554
                        Entropy (8bit):7.626996567956568
                        Encrypted:false
                        SSDEEP:
                        MD5:08813A0EE7565AE92ED926E8AE47507A
                        SHA1:C42FAB93075BC7D3A0F954873376619927950FFC
                        SHA-256:E289D9AC8EEF05F812F2A280CF00E9D91BA51FECFAD3D735F6AFA238D3E079EB
                        SHA-512:20A1B434421B7F03B7B9464C2369362968FCE49DE30BCB1BF5959120EDBA6B6A6E6D695561E756EC7C3942A311DA333DEAF57F0DC1B5A7492815D63F16E639F1
                        Malicious:false
                        Preview:....0|...}.F!.`.....`.g[...,.`...r...v..K:CZ.}..Wn.. .I&c8y....,..g....zK....#..lk;... ./.>HQESw..X..x5]...<.......&;.....;.Z..-......<e.oS..1>..)..;..(.c.e.o....:..7.....l..6/..A].l.v...0.t.Vi..Y.dR...Ap.k4....*....d.5.?t4..9l.:.....8......*...^<h@..z.L\.-.>...%s..*...sEM....Cm.O..>a..}.m..}...8x..O..b....&.J.......Y...I.n1.L._C.$..YX ..g.B..w..1%.s.(...cL...e..|....0.....}|...s....-.Y...!..3..[.'..J.i...!.Zf...C..j[.&{.x^..Q..eC.2...(.N.JJ..4/="u..|]/H.@c!. .....*.o.N...C}.....:r..U...& .6......./[...q..HR..%....Abi{@...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.586028545030992
                        Encrypted:false
                        SSDEEP:
                        MD5:8FFEA1C9B5214D4463771FFE547BF215
                        SHA1:5002578B8345315C57C28612C75894EEF9E83048
                        SHA-256:E5CA0C4BC8ED24F93DED4988596D1220F17CE2AA0B86F7AE065C97FB05510D8C
                        SHA-512:7E22EBF729D75518D37ED40343F98AA831A7CFA21F8C65891635EFDF30F84566FCE84C796D42AFEC430C5B6CB79A1C61DF1154F7838AB4680F8518E53F2A1339
                        Malicious:false
                        Preview:P.y..}.....]....K:<..M(.M....{6......R..IL..:.....].k.+...]. =.|....X.p:..p.Z.3C..q/....).S#./..]......@....^...>...A<Uh.u.`..dS..j.}..3.(...h..X*...y..1....DE.Vk.%..6>..!.......5N.r".^.0....m.*....M...j...=.Ha)..w)..BP.2f~v...v(../.+u.<.......E*...S.z.....]b.t..K....l...w..*bX...C...w.@..S...&N..{q...e...m...*j[.W...d...R...+.&_....`..)q.[....v.Xq.)...H..-?k.j4.&....;.uSB.'e......-.MAp1Q.6,V.[..X...T...c..#.C.Nd*.....g......ky.6.=....,..<.V....H...z.....W.....#..]+..F]i....y.Dd}...S....I
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):822
                        Entropy (8bit):7.730344448741066
                        Encrypted:false
                        SSDEEP:
                        MD5:74A731BB81DADC3EB904779B069CB436
                        SHA1:AB39BD092EF71B6238355F14916E46F8C0A442CD
                        SHA-256:00EFC4588A00EA2904094217BD34818898720BBB7D22264D97C8DD34FB9DE6C3
                        SHA-512:CC4B7BA5A07B7FE513EC0CB08DEB6F680883E80659B5D277A7621380BA429FAC24ABD79AA17C92528DFE8A17D71C93CB5ADFBAF1BDCDDB258DC1297E04669C81
                        Malicious:false
                        Preview:s....;].A...i{.eU.raY..].um.... %[..[q.{..P...F..f`7y.E_.@....=.e.t...._...' ..29T=...L.GCF<n.!.]=F.DOz"~Y,HA.....6p.65.;.p.f>....&...q....0.U.PD.=.../.U..}.:.l..... Z......4....8h.....}....z.\.F.;.._@...oG.W6.U.P%K.u.k_.\.%.......Y..~ .'<...un2.......ne!$r.`/....6'.....VR.a+:..D.......K:....7...T...&T......!.H..7Y.hb..[>.\2..W .S..)..-`....M.f,...6........(#.O....I.T...#.>L0......w....m.......,..E.'t.&V7.....7P.!V.a..i}d>........w%7*.....+.seI_..zs...~..M..VuRs..|f...*ZK.........2.m....(.Gn_N.o........R&.v.=\.....!b...MF.$.....t.).]OQ..e.....IQ...Q..S.~1.......\........MV.%K.."x...Q..kA...W...U. ..>F%...1sv....=.y%.^s.*....0.....,';=m[....O.....4.zW..l.....-....,..$Se@.fX7...`N:-...ou.l....N .._..d.J..fq..(...V..0..]..,M...3k!...&..U[...Ev.N.M..'.w19..jN&...Z.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):822
                        Entropy (8bit):7.713399411132949
                        Encrypted:false
                        SSDEEP:
                        MD5:6005C2097BB5653CD4B7E17E84EBCF32
                        SHA1:C8FCECB9D3AF7735B5E0095F0F0C444A186F0922
                        SHA-256:66325DA2BC5768BE1F8F158536BE24B1B080B0EF4D71807675D5C2861EB11F3B
                        SHA-512:7758EC6752819C0DE90748F48057529F57FCEFE31DAB35B9549029F073DE824C25FC0C05BD5B9E20D79354BC80FE99B9A7D85F9A0F6EC95E0ED5A0FA649FDB99
                        Malicious:false
                        Preview:8.X..6.:..p.tMyCjp....*QT..x(.&8E.tOa.k.Y.m..%c.j..C...O......,^.G..\D..0.C....Q..M..j...aU.6.......x...Q.d...T...2.......1NG...&...>$.9.^.w..m.\...X....E..8/-.W. ...{..T..Q".|...M....1.m6].{B?tj.e..n....i'.v.*..4.`p.7.?G..?t.bC...o...8...k.u}.59.%, .h....H.,......... ...Z&]*.E.{}..j].g.K:s.......*..(.....N.].......cA..S.5"A:.c..5.0.i.>a...!~.@..W...w{..A..-.....C..E.....:VnYP(.0..N.p6.:.&...E.T.'....c.MhA..SK...;.dN$.......%.yZ.$u........3.....<K.....`..g ...B......J..A.fK...+.....mc....5.].Gf....Q..d(..!G..x....T6~!..........<...*.O)..;.5..(^B.. ..\..AY..f....8.N.... .OA...%....^0.(..J#..J7...D;..K^....t.*E..Y.o...`..B..9,...2M.E..tQ. .I........<N..6.......kz..Jo>1,.....n....-.....y...y~|.@...Y.h...s...*..D...&o`.z.%o.1c./'Cv.6...E....l.xi.|R.L......p.d[..u.jJ.VZ..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.604945208330923
                        Encrypted:false
                        SSDEEP:
                        MD5:56FD1D3FEB3356D69F36B3193AD8A310
                        SHA1:0C1A5C707719047D37FD047045C51438877A8F5F
                        SHA-256:CDECCD3FF12AED04300FB357A419B0CDCC52565C69FAAC67383FF9EF4E5421AA
                        SHA-512:2FD61750F362C7009999491EACC4226C18769C91A85333BB35FF62C8A54CAEA334DE14BE8F3EE5F17FEE32661FAA7776D4DBAFABE695E0CC687F1531F9406AEA
                        Malicious:false
                        Preview:..;..<....vn.29.K:C.?[.F.~...B..\gu...t=..@..s.%.2W.d..J..$..........$.q.| .To..a(.N...q.*..w......X.)\B.......u."C.x.<{\.dXX...xB...A9.0.....s.@..H.*g&.....cdR.0.l.e..?........*Q..*p.M~j..0.m..D.%.~.gA~B.u.>......-v...5.v....UW(j2C.}n.xJt....O..\...(.......l.u.YY7.F.QX0G:...{..`.^g*.....U.z.f...f...v.b.r..!..6D @O.eX.\...9.0.YBF...."9..>W..<...S%u.JE.Z..T..U.1.H._..7..v.. n.4..D.Gk..'PI....h......R.W)qa5..uu...G;U..-..h....g...{./]....\.cC..d.#..T...Ts.#.#<.pDgOi.Q.q....BR'.t...2.m.J..7}t.*.l*......(wV
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):546
                        Entropy (8bit):7.683796457098014
                        Encrypted:false
                        SSDEEP:
                        MD5:355F3BA99C8D854A40E5E09B7D407DA9
                        SHA1:FC75300D9B20C2852DA14F62C2F98BD03EFC4D64
                        SHA-256:6E4BEEEA5F4F78A263095CCD1B6A5B610B27F95AC5A1C57D1C6604187E8D3EF7
                        SHA-512:8857AFF4DD5963A8D0CFC306C2328ED0D8AA1290EC1E62DEC93F743C20AF2392A2898373EACC198D2D458C479A9A5F779E49E887585C9EB1CB7237F2287AD303
                        Malicious:false
                        Preview:..o.@.'e..7.D$}..$r..t.V.Y..k.=K:3....!9...Lk.*G.afN......w.C..a...jH....i.9q...d......h....Z.}6 .h>..F<.......?J.@..~s.E..f........M.#........nu2.7{.o.q..j..#..rXv....$.m9m......[)..wS....'....w...v.._...R...)}S%...@l.Y.........K...0.pcc[9.7...%0..4....GA,8./r.2BZf.v.E]Ic?..r..q.`Z.H\".&P-...#"P.vV..CF.y.....'.'xJ............NI...\......?..).2...1.M'.v.......S.LzL.T.6.v.5.TK.v.....q^..W...v...9...j.`...k......6<B./..1A.p.]L(c.._Z...E5Y.C,./..U;.E.......I....N..Vd.dwI..j...N.x.I..5...|7w..q.M..4PS....i...X..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.601037114069625
                        Encrypted:false
                        SSDEEP:
                        MD5:ACE7D0FE60E9BA0C37561D0B8445E05A
                        SHA1:1BCAD60DAA944EBE93944518B9104B0C45DCD0B4
                        SHA-256:AE3CC4FC0083A00F8489D2B96D83C84428EBC1CFAC94375149B3D40BBA186A2A
                        SHA-512:986C6121DEDF3F1F697DB81D925F2FD338852CDFBDE739E5E96657BD8AF5BD034E4A56B8A32926042472151D833D1C92F1316199DD17327073B87655B346EB33
                        Malicious:false
                        Preview:.&..>.....y..Z.mK:.........?m...L.:....9....V.R..3..C>..OXx...3.-Bh.Q.i'._..?..M(..s^...].cZHf.i..MR?hj9..Y.j....._.<!O..C%.N>..D...).)8.2..-.BT.%.= L..<.`.]......'=....q.......X@.l..&..CgM..\.A..r..Oh.Y....}.h.c..V...7..3...h...1...0..b1.}C..<.....,."...Xp&p...G.y1..2...LD"...E..8{.._-.R....Pv3.nS..Z..Y....z.h3.F.%.&$I..)G^D...I.WP..K.i....c.84..%....l.v...sG.Di...I...Y.X4...C...i^%_/|.)l.....(.]9....u..wBh.9=........).*.-s.P......".os...1p:.d.{.X...F"E.i_..8.....v+v.l.{..$.}\.:.$../L..8...P..UE.@Z.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):866
                        Entropy (8bit):7.75785286224459
                        Encrypted:false
                        SSDEEP:
                        MD5:7892DD73CB4B0CEA7B8441256CB7CE1C
                        SHA1:8073D035FCA378209C01C091C9B12B5B40EF6128
                        SHA-256:CF3F56753407D42635E876EFC384FD4EFBBC9FAE5D982B7E0BC3F9F320666F80
                        SHA-512:04F87FBA6BF93AE421AA29E470E2182EB4E99CF1F06F365CBD415A2BAAC4E190E7AAAEF267B166B7FA8A705C38D20D5584D03B1481B4894154F2C1196C959ED5
                        Malicious:false
                        Preview:......Z....k.....v.B.T..bg....L..\....[R.A.....ZF'..{Or....o8q&..p|..a#...eC.Ag.......k..........}"..>..6.\O.%..<..|.Y3.....p.|..M.d..<...N.1i.....%....p.`Hx*..*.MnE...`..v.....L...^[~$9U..A.e.(R.....k%5..'...\...0.7...nU.NszS..T./.2.....~j|w.*y.........B..x....p.t.L,...7...8..y..O..X..b.72..(....r.S......4.:.dR#.....S..^.Y..f...K:+..i.=......ak.....w."r.....d.....r......7.#.v.`P.%...mW......{wsL.n....B.h+r..,.1.......N."!.C..a....E\....h....#^.1..2.z..%........J..._k...`.3..#$....;......r.M9..`./]..0.8.O.EX...z..S%...AZ..Z.C..i...}...U......|..4...>W.n.p.......#C..W/..7......Z...!.?E.G9P.^qDq.&.R..a.#..w...{..v=..e.$..8z$........|...)......}'}1....%Q...4.....o.j.y .)..t.3.?....!..#.Kv...b..D....*3.ff.Uy..y.nx...gwJ._.{...,..E.@....6a.K....zh0.d].u.S..a...s.kaGc(+.7..gl...[<.....#2dZ2.t.........|.......,...R....r.Q]0c
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):863
                        Entropy (8bit):7.75273079729081
                        Encrypted:false
                        SSDEEP:
                        MD5:01EEBB98BCAEF68E9F165A0A9B9DA06E
                        SHA1:CF293445834B519111EFD984A554E8D49FFF9800
                        SHA-256:BFE51848F821BBC229F04E5EAC42365A0292B4AFF3CA8145E336A2C164F1C9BD
                        SHA-512:FC26569B31F8D16CBBE667CFE9A8B4670AA6C1B18BE6F103A8378549E5562BE8C1FA0FEEE6ACFB87414FD122D7A4D77EA5B7393CD37CA80831F7E84CA79E8045
                        Malicious:false
                        Preview:$..=.....{...'...%.Y..W.=_.#sR...[..b.sW...h.E@}.....Q..3GD...[.V..V..P...4.0|%........i....Z.|8A .2|.1..p.W..,-!.H..Z.W....i..l....:l.v..X.:}a`U.K.r.iQ...x.....!o,.i2.UC(.:..._.....B.YK.c....aP._;...b.1[...%.le....VK.C.........H<... ......@...3L..(.........N..[._....B....A....v.9...j<.aTj..X....3...=.U..r1V.lyW[.....0.D...~.k....K:...........$.E.....x.J...*`N.....;S-........Z.x.#..x.'.8...X......=.....#W.#~3.A.~...].[..Q...8...1.41.......<6RKA}+p...h...8Ue!.....I...@..oP5.S........]...s..1..d+......."..j.0.....k.Y..ebj....qM...,8'...,@..5..X&.._=~F...!....{z.......8........u.4r.S.....O........(&.G"..&!..|.s:..p$R..$nES&... ...$....l.81...4.Vo.sh.N.X.".`..#.w....P...~..J......zqI.....z5..8..w.*.w.y!...1..w)..S....OF2.......B...B..)t......bH..^_U...,m...wa<...........+.".W>.........k{....d.).>....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):571
                        Entropy (8bit):7.632503303652045
                        Encrypted:false
                        SSDEEP:
                        MD5:13716B0218023892F3F5186CD2B9FDAC
                        SHA1:5F33E0320F71E2FF86D65A763007425C91830B18
                        SHA-256:9AAE4FB98F7A593EE4ACF8F1212BA2E98D9DB1EB897280FBCB2E52F752AF1AF9
                        SHA-512:14EC2D00870A8D3C3C5CE26AA0F9545630EE12FB21E57DC4BB3979FF7F65DA7C778129BFE4364E5E1452F33FF411D0DAE28BBF8CE2C655CCCE3329B9719B96AC
                        Malicious:false
                        Preview:...9.^...^#....:..&.h..1....a.dY=B.07..k........'..K:~x?]j..5Q..........3vp;.pZ.F....W......<...Z.0....t+P..%.O...@pN....}...+......0.Q.2...C7.6u."v0..(..>...j.]}.#9{.y...$.b9...t.$...J..I..l.....D.....t....=.~..0.....?.Wy....G...?..?x....N.U)6..RE...Y..q..q..38.$7.......2>.8...onu-...........p....x.3.).tp{.,.1.{.y...C;..DA....M.g.=-jR ....w.YC....K.?.NsRa.W[m.__+.A...a.DSmT.?.O..8......t.0..o3..#..J3..6.L[..kp4.%3:>.+Qq\8...6.2...S.]..:... a...D..J.7.....!..B...+...c.....sW...x"..ZnW>fN.@..>A{...=]..M....:u....v.........
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1014
                        Entropy (8bit):7.790418060967413
                        Encrypted:false
                        SSDEEP:
                        MD5:5E506F7FBB3E48E105FD93E5178E5706
                        SHA1:D2C7D3977A7741F460654F4CE23C05FC46DF6D02
                        SHA-256:972B47C9593A0C6322593FBC1DFE794C1C50600E08ED3A2F0E1C520DC3A9E88A
                        SHA-512:3EBE54D026586BAFAA50A5681D84D3B5C403D7F8E66D23F7A8B55F0415673A4C1D2EB7509D59C40504E96B0D377E21445827430A3B17FA0DE56F83D4542AE8B1
                        Malicious:false
                        Preview:2.*....R.W`...GY.S.f1...c..O..y..-...).w.=..r..5.k{...[.m........6..|..El..p.9.......9.B.J.i.....3Z..7..F[.F...?.._..bt4....N.......E.k}......~=..hX..1G..6xlU.;.<\.7.Y:.L.k..l...6~PI..hg.S.!Z.k..u....`.\....[.6...^..A^...`S.qf.t.S}......6...`=9.{.t..\^x..25...K8.....=~.+.....H...v....JF.:g.Y.,@.YR%....|..O.G...."..h..O.SF4..........S....n(..:...jh....y`5L.W.7.0...C......b.m...KCb....!j.z..j...s.S.H.K%ZQPY.-R...:.......q.A.6.Z...>.P|,.~......:........Z.2.R.n...1..w5...kK:._d..............e..q....-.P`..?..u....bn$3v.{..G\.m..o(..A.?DPk..O:k.....j.gH.CW.e......".&.d[m.a...bF..N..g..$...on....J-...L.G.o.kv...Rue.3e_N.-._:....#.X0...R..\.yU..i.8`...}..P6......2...i/..A...Z....g.U.H.r,h.,J.5.K.R}^1. ))...l.I.x.s".....NJTJ>.a3.`..)....3s#.m....?s..$.V.L....O..3.c.!.>.tG........A.p.$.+..'..}.s.P..ak'..i....U...k.i.....{....@1j.^'BB)j.TH.a.a...>Y......j.......3.*.I....%.-#K....<.s.7...%......U.o.o..l.....G....S..A..F.^]`.~.]..gaq.....Q.N._
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):571
                        Entropy (8bit):7.623575545257529
                        Encrypted:false
                        SSDEEP:
                        MD5:11AA50A5C85BF2BC8F0F5C2F6E799808
                        SHA1:F0CDC2577B425FFD9EED559D92248E3856C047EE
                        SHA-256:5CBCAA40FF3154EEE5BCE3009844233F43D09873772D863022B6B56678309A23
                        SHA-512:DF3265D58831D45399433DC476DA4EDE71B568E30AEA5EC01C0D955EAD8618D8AD2AE37B362100EBBFA577F47FC6A2318F253B8EBD0552CE214CCB7CBBF4C3A5
                        Malicious:false
                        Preview:b.s.X....."...a..]..A{.8.QS[.....\.|a.S"u.........A.K:.....YTQv...i......hu...s.h...t.).;R...j.}V...5....a..;..6...PG.].hh..^tb.f.-.E....=..{3...r9.g..lD.y.#.J.-...Y.P.(..2..+.Tf.?.....G.0!.R.I...p...3}.=A..b...-.Z.2.`....&.g..<....0~.Q.....h.2.fi..F..&.O}|Tt,..-..E..>.h~.Y........v....[..>...&.em.f.o$.7o.w. .Z..O.1H..t.i4.._..._a6.]....i..K...Iv?.f.....I.....G:=........y.Fs..g.NI#...4zK.. !O.i...m..B.!e.]..0.L....ig5.R..(...jT.)....U....-c..h...uU....p...F.g.y....:Z..6.t....d........n?......y.T.4....$...^...U.P9.*H.V8.za..5.....U..ar
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.552624737447541
                        Encrypted:false
                        SSDEEP:
                        MD5:11F0983990686F21ABFE45C9CC722D37
                        SHA1:80FF33ED5E560E13FD5B9E7FB825F0DC8FED2E40
                        SHA-256:B82D482EC33F500A51D4540B0ACCCAFBB4F43F7DF3C9878C77881E4B4292A7EE
                        SHA-512:49C97AA17804C32B1CCFF3417D5231CCFEFA3264E22F615D3C88E42F6C7B54E2E0539C37961C8BE4A1465559EDD1E37EFE59762A8267DEA5106D376426A2C682
                        Malicious:false
                        Preview:.,J...e.j.N..$.K:.j..d#..3......._...B..3@......8.5....?.[4..c].o..~..3..(...Go......J.Kx....#Iu..%..Y.$#..A.N_.....h/..U..l...I..@Y.M3.x...U.KR.c....{..ls._M...N.J.L"...p.:S.M.Yq...n?J.........z...0.=Q....U!..M_l..T.d...h...$......@|..k"...oq.CuX~...i.......5^5F..".....S.s....T.g.. b..~......|.,..[.!..V..d...|......+T...Q.../.-..f....&.a4......f!..gk.b....8.#..h^....xi.Q......M.._.<...F<.j...8./f..~.y...x@x......g.@...:` .\..1$b.~.;.).}.I..k....Z._..N.F......Of<[c>..|.~..".={s.=B..A.. [...y.t..R.$UU<n
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):21010
                        Entropy (8bit):7.990712003904818
                        Encrypted:true
                        SSDEEP:
                        MD5:C4D1CB79BE3FFC1FA5D841F2129F8A69
                        SHA1:4C7C23A625CE65728CAA571B68882D9ACF33BE7A
                        SHA-256:74ED27C9E07D08C29E85C951B1A394A393776F39A0A27A7FD5AC29CC464607C5
                        SHA-512:692B50012D0F60CD915C4023C765017C1948C2A793B3596C929B4F746F2E0AC56E7F37CEAFDE28F100C710C1813FD04433459D715CA5111210B6844B08EFE9DB
                        Malicious:false
                        Preview:...!I0..)u...-u..y.4.....3..`B.9O.zd.[.....6......Z..C..T.IK...u.0#a...&.?..|wP#... .rn.>..]-A.3.i&.QDS..r/.E..}e/."...*u.....t....X........,&..:X..rA+..5.....|.. ..).4...(.C....Q8....'<...0..D0~..x...Zc.5Z.V..1.(...o...-Z.(1m....B..e.e ....77..."w...!q.n.T.z.c..xqrR....:.....B:...Mr".5g.......w......K....Bv..#.{:zy.KY.....OE..F.v.D....k..&..*S~...oA.W?l&.....?.t.......$.J...~.fZ.~...R...T....j.%._.Pn..N.h.ulq|........^..A.b.l&+N?..#.........5..?.8.).W...aM..F4..K....".....\Xi.0um.@..@..>....7..4/.e..;".#..j..}...b...UM!*N...b....2.=u.84....9 .2.......`..T..HJ...y.3.......YZ........e.+...kZ........#<;E-.......k..}._.D...].A...yt.c.2.{.;!..1....~.....Z.|".X..@.c.n.#E.Z.g._Z.R......u...D7..]b#}a.......hk..1.K.tkt...N....._O..M.zKm.[..Q\."".YB.A."..Y.w.P...;<.ZZM$.V.Q{&.0...Uw....r...../.j..#......e..[9.N...:.5R.W.f:.=...-..#.0...'.Ze.........vj1..z..8<.z..k0..n&.v.!.E..'..Ga'..."...9.<.-.......1..U..3.l.@~..XR.o...,......];.5...vzz4.+.......+./....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1005
                        Entropy (8bit):7.82834258714113
                        Encrypted:false
                        SSDEEP:
                        MD5:A66442BB8BA992B9438711D8390DD624
                        SHA1:06768AEC4E0CCEE812AF7E9B6D853D5C47AA0A4B
                        SHA-256:92D5C1C07E28B3B65E7E90E469AABA6B94DE4CE70D45211D8ADB5F1A9B9A8DD8
                        SHA-512:EC5BF3E67E2AE2522013198FA80D114E718B1998E2192265560AACE67681D780F82956A26C74CDA954DA516477EBFA18E427DD848F6C6B960E6060FD54912B9D
                        Malicious:false
                        Preview:W.(......&h%,"....:..Z..V6n.d......L.3......u..w.u0..;)A.._0^..u.sM5.\._..9.5.....P.......T+..v.@2...m....Q.K0>...U5...(..._....F,.>`.\1...d........D~.5..|.H...KBT.....: ...T\.T...21..+.,..Gt.9........L0..D|.zg0D....:...&......:.G8.N#...lv6....I.#...X4....d..V.U#...VGG=.z....b.H....B.s...R....J(........i...(M<..6z..R._.l.B.......gx....o.%..C..UG.u......}.o..e.$..> nb..R..E...X......y..<m.EO.0...d..Y..B.E.;u.M..F....GF.+.,|5...J......1D....J...5\.3.u....Utc-K:Q.c...]...Q..7)./...t.... .#....Z...p..........>r..../....n.b.K[$Vc...Pa.c.A....o...H....;&..k.;f...d..+..m..M.F.'.N.QoH..cA.N...w.S....(&...Q-..$1%...W..e.0....J.......`H...@TH$#....`..z7~%.C..>....ko.g.ZC.}.8WV*Y..P=DoX>.54.C`7.`q..._..rY.$./j...%.......3...s..f.`....~6....sp.Q......F.e.u.E)..K.x.Lq..=..?bw.:..k..h.,N.S.gu....@..A&^.vF.U..)..hu...@&..C.4.*/.BqI*.25SJNw:..@......'...h...4..y.`p......,d.%.1..~.,.y.u......@...q<X...=.`.X..6..6...48yO...}...[r\.4.=`.....g.x.e.-..=..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:DOS executable (COM, 0x8C-variant)
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.547653646110922
                        Encrypted:false
                        SSDEEP:
                        MD5:AA36C0D988D8692DFE604E7CF09E4431
                        SHA1:D1A1EBED748DB4167C5EDDF721917D5139A60B2A
                        SHA-256:2F7E743FC17393C2BEEA42E201E6A997B034AA7ECA5E58269C07F78CD67439A8
                        SHA-512:D9334D053345F93F08CE1C0F56BF4041C1125DEB00AA038A7942E6503262C7784A37A4775DF60D737AC7DA711217EE8D96D796D913B5870840CB77C4647A434C
                        Malicious:false
                        Preview:..J.f`A1..}.n..K:ns...r.P1...dQsL.YA..Dv.v%.7....M......k..T](....<.;......_0b._..PN..m.XsC.X.Pu...S..'y..(..5..u.QC.0BOk.).n8L.....C...\.YJ......6eK../|8....0..=tGi.".Sn............c...].......|w.q....ApD.......@.-..H.\..3H...n.L...DE.....W....J.?.dt..2..;X2.{o.X/.j.../#&.L...B..l..1.-_Y=U.].......B..&..Lxcgx.{...1h.Zj...op{M.:h.....n.=jBqB....E@....jc.G....!OR.J...>..Y..X.s....QA.n....Cu..B...e.D..i...v:M.,...[.0..a.H......I..-j........P.lqJ^7%.sc.....,.>u.0h0..=....h.....o[d....w.........Z7E.n.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.645870839409613
                        Encrypted:false
                        SSDEEP:
                        MD5:33C822B62CC45B8B65145F38361EF146
                        SHA1:C5E7FC74A17659D0B8655559D833C5B23B4F3762
                        SHA-256:EE1D8D9014353D0CA59C6F91B68E43A41B2D31873FAF5D41AFE4D15AAC877051
                        SHA-512:D9B9DBCCC19A9F07E7FD1A06B416343BF5885937DBE5FBD29DD44919FA233D7FA25BFC291BC20C38EAE87759BF13D3F5F5201342790A5970F1D92AE9640638BE
                        Malicious:false
                        Preview:_......I..U...C.K:..Z........+'...~T..T.e3y...........0;.>T...o.X}9u..U..Ie.V...l1<@...I^..7..p.....>..49../~.3"~..mK.4'2.*.......%.J.8q......3{I..,l.....Sl..L..6|wd..|/... z...B....#..'.....,..K..$@..)}M.v..F...wp........8.R\p>...('....pc..5t...T....'............(.b.'......x.s..O.f.e...RO.V....]...8...;..X....t.m..oa+Ob[..G...D..=.....Bvk.....!..I...]+&.;T...@.p.....]j.H{D......l.g.%.L..Y...TCSA.....\.v..M..w..&.Y......'...f... D..C.ktv.....:.B..6=.G........i...0...;~.r....[8.K.!...S .......F..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):37394
                        Entropy (8bit):7.994735188644946
                        Encrypted:true
                        SSDEEP:
                        MD5:DC540202A860B8CA8DC0B7E3F7F2C468
                        SHA1:B9719B4453DB3245389110019CC4E41BA1CF58AF
                        SHA-256:9AF896A8CF3E93CDF13396A4B1D7004D05106EDF397D31645D801CE82D88B7EE
                        SHA-512:7A091C31C6B9E5BF3FD4CB6DF3DD6C6E7FC22B4D4CF6710D0E5231BA37DC59E3C2C1207C83B40D808EC07D8156A2A97F3D0F5EDBD73B1D20C54EB9D4E2068A6C
                        Malicious:false
                        Preview:.sg7..v...o.O......H.s.M..>...-.M.=.% .......[...[...h...!Q...b.j...~.."..K......2....S.P...G.#2.8|..4..M....j..0W..Z5...q....BTfA.Y./1..T..?IJ..f....!.9.k....ZgBPsv.*x.*.h*.'...90t....."...s...z....D.`...,q1.M..p.B.f.^o>..........|..?.....O....z$.b...N..nw.cI$..F..e.:...,.....j6...~...CtE.#.8..?#L...4<.$..^r#.).....F).....~...U.+R...E..2WU..u....0OEkmP@......tm7s.....Ju...G...'..MPYy...4.ou...y./.+1w.U....4......./ ..h7..}'.'....(.'...4p....j.x.A.8.D.I.C...^@.....9......x.;\&....J: .^..6.pZ.FqO.jWl&...@.......Bj.....{..............H=a...~...Q4^.Q...MjW........n.@s...j....C!../,.......bn..=.z...q.F.A..#...A.....d.....6P.b.F.e<+q....U.c]+/..0t..~`..WN|....x...r.Y.".. .W..4.,$#...[.B..]....Pa.....7u.d$..s..`.....M..m....Jx...d.......B...c..5.ym.N....9.....JYT...pA?...!.1.[...i..j.s...D...E<Qo..5....P.sX!..u....cx...K.......5i..)i.;Dy....\..[...c1}dS.....]5.i.v...v.j8....3.%J5"..X...i.x15...8...I._n......x..\.~..El$sw.9...(.G..J=f.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4364
                        Entropy (8bit):7.955757083424095
                        Encrypted:false
                        SSDEEP:
                        MD5:ADCB7B579481F3EC8E1768F9B96DDA8D
                        SHA1:FC8A705F583E1DA4AB173EAB3E060BA2EA85803B
                        SHA-256:CA1D2A6461C3452595ED1D0D78AF6F44C587E1A30C406A0C128DCE3C559C2A8E
                        SHA-512:850B7FB9D088714451EA54D3F0446712312705FA744D8B8C3C85B1481478ABC2F2FEB1886D532ABFC852927751D54ADC7535FB11AC7AF5214424835BB9DF6E8F
                        Malicious:false
                        Preview:...F!:l...7T..Z.$-1...|#.....~.0..m....&.lZ_......-c-..$ 0......s.q.......8..."!(Ysc/.&L....Q..S,.=>.....)@..|..N.../\.a.9._..T...2..`D..y.....+w.l......v....#.<...4#1.zV..rTE.N.6.......w..9...-%..l-'#..S..(.x...S...dz5 XO........eG....<|.U....>.......,V........>../.u....&.`..j.....@5;.K.3/......4..8...,@...:1.oa...x>.0.`_.dNB=).....>.i.SIO..D....7..T?....cK.L&...%,3D./EE)a.sQ..=...*I>'Wc.%.......E.+.pn6c..*7]...........qi.I.-(......ybX.Q:...SN...~P...p....;gi....i.x..e(.j.X.2.WD..R=.[....u.6.@...[.^.I.pa.$6...+..~.>...>.."....^.A...m.}MF.........Pw...&.......V...x..D}..0....n.(...@,^...Y..I..5.(S.;&..~.".4...]zt...6..E....G.?.T......U..3........^~.z~.u......J(..+.N.5X.3H.h...<5:.%...C.......... d.?.^{J...N....}.+.....-.5.y...d'C@.._#.a..T.S....W.......CN..;..0Yb..?X....~..oW.....R[.e...<{'...[.^....K.....d..>.I/.... <;S.5.*!.....W....SNZn..2..HI.]e...Rm. ....rW.]T0L.a5........b=.......94.l.x.9.Y.....z...S.A.=/....#.........-=...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):546
                        Entropy (8bit):7.6629515229906975
                        Encrypted:false
                        SSDEEP:
                        MD5:B3F8D33CF8EAA26BF44FEDEE720C1262
                        SHA1:D956CD1AAD61F9BAC99C6A15EFBB9D038142DAE7
                        SHA-256:917D205C687815E618B42D6710CBFCCBC85B1CAEB8C0139640818FC4581AD34D
                        SHA-512:9C29F4E8FDAC3148BC39645254C80DB20AF7D148120EE3B7EFAA4411540DAE273DD94FB96EE28A9F92C84D685234588B0E7E4EBFEF24BFBBA0349A09E5D36584
                        Malicious:false
                        Preview:.....k]....$....'............K:..F..1e7..q&.....~.6..~s(........(.:.B....M..k....,.[.*.Y.;+.....v..n8Sk3..lhet..w..Ud.$j(X3..`..'....mZ'.....DnR..^-...H..i#.V..H.*.,..0....!....t.]..-.]T )rK...-../.E.cs...Fu.}Y"....2.=.I.G...~.2......z-"..5.L.>:H...T.y..6.p.{p...cKkth.....rUn.X..?...o7....D.3.{..uM..s}.W.v.P4..VD..4k...}=..~8..o[......zFO...Y..Gl.~..9S!.H*.PQ5..........@~II9.W.../c;.L*...3........&.....wy.A-..M......2..../...1nG0.......U.o.1!.8.HN]C...q.....Q.u....:.,aJ1H.4..(....xE.f..W.s^.fd..$.g...Ec.Q.._.....7].
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.61275975446314
                        Encrypted:false
                        SSDEEP:
                        MD5:3F7C183610523173183327023F801014
                        SHA1:7BD1D24ADFC2499FAD694FD15382532C2E9FCBEB
                        SHA-256:FC38ABFBB6CDFC92FFAF7E521E93A65F8A5E6B529F0433BEEBBDB0FA9ACF8C18
                        SHA-512:E07C26E2C24AA0706482A580223B0E1549047DF24C8E65648CFFBB6502DDC031B78D215C2C7619C84C7AD601E253648E213274F1E1273D856BBDAC9EFCACC8E9
                        Malicious:false
                        Preview:......{.,......K:.+5.....m.qL...'P"..x'G.&.:.....x...+vw....[...w........r..?...1zw>....E..Y..+.+K#V.....+.._(...Ps....G..[6....;....`>p.N.....%..u..G.T....c.xg..}$V.0......N.k.>.]0...U.;}.c..z.)Z..JJ.y......I.T.8~.Q$......uF.j~..8..J......D.d.5....C..o.v...H..@...(..........7...?&v.{U#4.i.o....g...("....G.;.R..c]......3.b.us.L..-.'..v....?..'.....bv..#..V..YS.N..s....N>.R..z..F...\..NeK5.Zh.....A.-..x+p{t..=9...M...M|..<$`'../P..?$.5..U..mL..e.Z..C.\.J..q.-V....%qaW....K..x...s..Q..yR.J....Z
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):854
                        Entropy (8bit):7.7628578827654895
                        Encrypted:false
                        SSDEEP:
                        MD5:8C9D99E7B14CF86726C8CAAC6DBD0438
                        SHA1:B30E126E24FC0F4CDA14903C87D350DB7FD51342
                        SHA-256:B1F9464474635F96A3B8C2B5C3E2CC33180471ED6C8A97F8D753470A93A96EF0
                        SHA-512:CC52ABDD8346DDC5D26CC56F2F8ACCC0FFD05AED9AEB19E1447522982B108FC19406DFDB0DA51DA38636F0791D1B17B8327AF8942530C86C6924AA2850136B49
                        Malicious:false
                        Preview:...hP...j..o?........C.W..|e.."6.......c...a.$......x!.j}..H.mxj.,t..5.l../.+&..0L......s.....GD.s...U'@.c.;.OA.....+I...ZY...0KL5.1.v....@....g.N....bB<NK...o.z......"....Y_.s_...t.H..,I.)..j....[0......7.i......!&^.V...<dO..`....9..Mn?.E.C|e....q. T.c.A..T....w....m....S p.o.,.j...S.:........#...E.. .. .."h.'.Q"B..f.{"+x..K:m9pD.SK....oJ...$.v.|..m....c..z..V.fA.Z.j.P...f.-dsd....X...a.o........c(..u..-..!v.<K"v.8PR.9.Y.y..-..yKz...^.t..%]....ni8...D....8.....!..k...-.N.k....$..7.[......!.%.6.....jt..i\......V..h.`+K......1..g......bJ.C'.>oV0......E...i..}b}._J.."@rX.k.T.y...yO.=....kUJ}k.....\..N.}.......i...>.......i......./@.D~@ ...:.E..oQ...A.@E......gQ..3.dj..$$......U.9.>hK.c.._S.........:..../$.c..n.3!........_...9bD..x...............Q@V..Wu.RT.$..6/K...-9........L.Axv<x.{.Z..l..m>.6..163-
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):851
                        Entropy (8bit):7.7472011096857765
                        Encrypted:false
                        SSDEEP:
                        MD5:194292E10CA15166E213494E87DB5F05
                        SHA1:321F1313E95B8EC588D5F711C04D96D3F0FC3E05
                        SHA-256:6AB1C1FC613EEEA3A29D88C649956F0C2BFD109CE29F686CF809803CF3AA1839
                        SHA-512:995C07C8CB09241B6E80171B095586A17A1C9D4252A3CA910DD4628479B8D208094CF2963EE91B7FCF3CF9EEEC2D5BAD37481CC642E16D90639263E08AAF1A79
                        Malicious:false
                        Preview:....@i.<.=..L..L2..~...:)..,.u.oK,.(w..#..B...TFWHJO.N.2.|..U.....`.:Nj.l...m?.K..X..........i.U....-.........X..>y5.Wz".v2h..U.Czn.i&m...y...b[...n.ld.m1....R.1.|........_...Gm.3..V.?.Z@.F..........'..<..e.h...@Qt.........j+..og1.V...=.Y.9....),~....O^&s..b......@f v.Z..q->x...7..:&).Et..Mw....*......n.v...N?.#??@.......6eTK::0..z.6..c..b...P.p.:.Z.)...6......df, ..OfK.....(Rl..K.......d[..A.="j.P...^5.@..?$..et./..._RN.D.r6.])S.&.........D1.RIb....:0r.F...X'9...l.%.k......^.r..>.Q...HZ.._.^.j..v.^@C..=I...&.$eu.|^.pn.p.`.......s...p."..U...$....^c.|W!!S...\~...>.+j.'..,...6.[F..N..-.p..3}x....d^..i....I.q*....p.=.28.\`..qI..Yc.?4<..K..(F...w>.X.#+...'.S..".Q.@.s....?}6...~.Ob....h..Qm.E.....r.o../WD8y.'"3..x.rE._._.2L.XI7...........b....S.b..`.....g.b.O8K.)..9....G3.e_.`a&g_...8..<?M....?..c..}.E.v..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):571
                        Entropy (8bit):7.61297718606677
                        Encrypted:false
                        SSDEEP:
                        MD5:9B03970443F317833A8C5C88B9BC87FE
                        SHA1:BEE5B09731A88EFD2492DCB284E7C2223741339E
                        SHA-256:7F25F22E66BDBDDA401C5A7BA7FB944F4999A2AC923F8248EE368DDC5BFFDA48
                        SHA-512:72C1FCDAABF8AE3B0E5932AF996A53E9AB76A2DEA80852C145C55BEFD113905CC1024EF69990EDFAA7F5ED27BFDD569565295BA539A6389D1166C05DB4FF9E71
                        Malicious:false
                        Preview:..V%..D7"V....<..8 I.,.q....P.X....c.|..:..)cF...I.t..YK:.........c.y.[.W.\../....p....q...O.s.R....a...CAk.....r.:.$..w..c...f..$..)...&...M...d.(..#. ...B!....>..$.}.<..w_..z.M.b).8.Q.......=.j+..o...b.....y+.rK!(........Vj% ..s..w.b[b.Z,.V...7....#...u...s..}."..+h..3K..........m.#..1..a...~/..ZfV.I1..$..Q...Nvb-........4.....3...=.R[...C..$R.{W..M..F.-x_..8m......h......u"....y.IP9j..s.I....B~...W...d.~..tH...\..[.Q........J.h.....|..V......!^..&.INg......ts.~....Z..w.s.yV?...7W...o.....8..#.V.z>..e..........>..".GC.N.4.MX...E..SL%.yJ3
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.570039464720289
                        Encrypted:false
                        SSDEEP:
                        MD5:529AE03A9656CF5BA2DA1E18AB0BFAC0
                        SHA1:6DF6EBF1FA7EF69D58158671696C5F3B15B1A0D9
                        SHA-256:7B416CA516B157726DEB873C9AD0F1DA87E39D872AF714A974EE98B17B4DA37D
                        SHA-512:09D6723272D0782431EE358216182D62502888E0F4541D610D9F130F109D7450CEB322EFFE2DC8DAE9DE686B1733540DD099EC2FAEC36EF9912B13523C44CCA3
                        Malicious:false
                        Preview::W...c.s.0.4(..xK:P.:....h..m....'..qb...7.....^M.'c.F..Bl7.I.._......~.ZA]n..T...lp...3S.qM/......Y.\..".~T.'..|..U.T....M......n.^$......Z.:.Tl.Y.......o..(.c../..@w(h.u.}.=a..".7.5bf.R.......BU..^]...R`..4..+I..W>.^S...s{j.R:Lx+.....[.G.x.....'.h+..?.....^...V&........tb.....y.z..)...G_..#.....5.:.."=]N5P..L.tz.p]..Nf.e..a....VY.....m>..%.F.&x...8..E...$.....`uf.Z=~F#.....8........M.*2z.......z.T<.-.&.....s.a...Z...Y.5(..........v.>.....I...=..:T....t.~..7.A.4...s.B.H.3....%...4ye@%P^V..`.D...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.570019607162397
                        Encrypted:false
                        SSDEEP:
                        MD5:26F2372015BB9E347C109BFFD7AA0696
                        SHA1:830EE99C5107C45FAACFC2E366798339F83276A4
                        SHA-256:90F70E15A45DD25ED0D6AC51884536B5B02B8BAFEA5955DE19F248DF82576396
                        SHA-512:B5D12D88DDB947FCDD000E517D26B521D4A4EDFE4A75D925676ADF33100DF57E09C28CA187C275FCC2D37BAC38AB3C9F925FB9446FCBE3B763546784A2D21BAE
                        Malicious:false
                        Preview:Jb.'E.+M.S.....K:...So..G5.`.6[[L.0!.}.j.OJ.....;..sn....}..t.n..~...:,^....]*.Q.].7...&|.(..J..e.].......6..dL(7.).e.H.<0;'..Z.c..t,xa.t~..{./....4d.t.KanC..*.i!..;...W..i'.'YU........r.bq...m....0m.`.F..Scwc*&.....I... ..0.=A..1U.K..W.....:.g..G...j.m..d...t.Z].&.....Sjm.....kf.....v.[..V..M.b.0...[.?..O.....[..)kK_.k{.>.m.-D.v.x......SK.71.`..Q..[..Q=..}.>....8*$..g...z.x.@J&).1!N..`.......x..1..(bJt..3M....+-~W.m.a..6...~SKH.....=>.D..x......il..gy...X|.|...H.....R.....c.W3,.(n..,7Q'G.:...H../r...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.611712289251929
                        Encrypted:false
                        SSDEEP:
                        MD5:1B2C40EA1330FDC4B84504EA98F2014B
                        SHA1:DF83D73EE0591C508C95C9137F5AA404DA6812F7
                        SHA-256:E81DA05A0949054CB4F69372A617AC1FDD75D2077D856F7AA0EA7F5CAA7CABDF
                        SHA-512:59DD24390BCF5BEBEAA3433DC4DCB62509D3E138635C274B08B9491096952083F419F84B62A91C6ECA2BD7BE428163887C423CCB5DA54868356513C08B9BE4C4
                        Malicious:false
                        Preview:..[&. .:Fh.o.. 9K:..^.2.h...}.J.syU.............~..X`.....0..9...-.t.r..z....C...........,.}.%wY.S/J8.A.....^1.......cY.\.n.4.hHpM....}O.lQ)vW...G..M.........)>9.'.o.; .....-......7$......t......U[u{....r.......9..>.r.e........[...A..ey.9..+..d{.Cv...*.O..7...V...SRo...=....5......].,7..../....J.h....H..N!..9.......4../....;.G...%........A.....X."I.O+...|87....]a..>Eqx....K....y..........b..].......}v.<..^.?..y6...6..w+..;T..J...-1...cW....#...9DD....gf?`/u......-...z.d.....[lp....S7..V?.aBC.i...c.o
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):131602
                        Entropy (8bit):7.998707513911353
                        Encrypted:true
                        SSDEEP:
                        MD5:E3DEAC82756E6622E92A9B9574F8244A
                        SHA1:257B26B79FD76F23ADC9C640BA807CDE22E6F190
                        SHA-256:47C88C28AFD654C628D3AAB13E0DA6A4A8CF172257C43A3B224805FD451AACBA
                        SHA-512:9B3A8B722D001338716CC65D050C1F72C86907698477EFA64167F91915E271AFE1B1255B91E0F72D513EE3F9F347FA53F5A05530B58E75B07D71DDDCBAF3E7C9
                        Malicious:false
                        Preview:'.\...}&g....v..Q.CX.=t..Z.v..m.~<.....;...}..ad....%...<..-z|..N..:.c.....|Z.......x...\.n...v.o.R.........f..i.{..\.P..]..b'Pk........?..lO\OPZ.....@.0...gV.6Q.1.;.U[...o....=J.AF.3...&.[.L......:b..G.b..v.7d5.$..&~._w.H..xl.w.9...f..O..q.......:.0..C97y..J.V......z.B)...].\^.K..\.b.CKXR...U..9.@.......e...M..q..B.!7...6....i...Dk.?....+.u4..&..Rc]._...PB..7.[>w.d.0.1X$I..R...n.9..N."......l....!.0.{....'.O.....W...|.J0V-D3.|-..eF....a....o..:..'Z......8z.m..D.z./q..........dk..3J...i...;..e...(c...Zs....v..".3..!....-B.;!....P.;hb..........\...qX...,..2.v......X.8G..1Cj~.3.M......X...=.P.\..`.Nz3Y.k".f.:......QG.y.G.9..]'8..xQ.+D..@.......9.D.:..cb.X.....y...BP..IX;.a...z.....j*`&.YK.5\..U..B....f.. ...<6 .0....JZd.R.6..v..j...$:..D.....F#2j..]T.A.F...E\.h......`....T..~'.g..l9..( ...9.."..2. .Ju...(.*e..Qn_...L.\j.......#lw......-......[....4.'.p..u}e{.:bE...\..^...G...,..o.....3.7...f1...... ..H.8....o.^@..M..eb..x.x.N..k.."C.v..V..=d
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):637
                        Entropy (8bit):7.644486757656767
                        Encrypted:false
                        SSDEEP:
                        MD5:924D42F53622B28C140E21648EABBF68
                        SHA1:35BBBDC943D48B7A4589806B24EBD4A7ADB4F21B
                        SHA-256:77151C59DFEC74278B79C7D1072AAD84D9040EC0CAF428B522B636CF034CE44C
                        SHA-512:3C5EB2C920A6A2E904E79A3AF2CB9B8B9AF4D20CFA8DA85F062C13952A6DC81A5C715A82F223FCEED070FCF5A809682871BC53A10E05089C72FD937A859182EC
                        Malicious:false
                        Preview:Hd...3.7.UW.oA.....4.i...4\...8(r;.I.>....}s...2.<W]q,..b..._d...C....`.E..Q.H..b..s...H6.}......5.,.G.[......<y.>..g.K:~A...[..<..0.I*..*.._.......<.qO...?.%.e....i.6...q..w*..P%.]/...A..B..S..O=...9.m.HAxl....6......|o..3P..V+G%.J.2.Z..mB?i&.=9&......N...L.n.kn56.\8.r.....*QG.........9}8...}.D[..I..O.....t.....Ix.qy...u..d..l...w..y.W..A.3.va(.<.Xr.......Z..F{)}Y.g....$.7Nt..?/....d34.{v.>....Z......2....B.{<...>..Z.....4*.....k..."Tc..E.B.T.^..-7[.}.L+*\.4.r.)..c..j..V%.C..c.0.."..#<k.......G@..>.#..;!..}.&.K...w-.E.G.....Zc.h-..2.aA...Q.......S4b|"t..it.|..R.0[9(M%..m..J)...9..n..:.7.j..O.po~...w.x...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):546
                        Entropy (8bit):7.625861057719366
                        Encrypted:false
                        SSDEEP:
                        MD5:45F14DEF30199491A9D38FC7142F35C4
                        SHA1:227F9C16BB52360F935241B61CCCFF2D1333CB95
                        SHA-256:4DA417F9A28BF9AD35D645D8B1E0A2817C4F643B04F3EFD2F3014CFCF78881E0
                        SHA-512:47E4D543D22BF1D1FF0D8241841C2EA2EE74EC6F1F6C7BBA0F9915478D296FAD8331E9BF7FCE57FDBDFAA221B950D84D22B4771842C899162258BA4821F36B03
                        Malicious:false
                        Preview:.^....V?......}..o.R.....n.M.$..K:xv..w.7[.~..'.LA...(..rAIp..f&D...f..>KO}?.....z...#....w.l..N.........$.e_.<.t=I...S.vu.g.....G.:.............E.T..}..!b,..m.$J.........w....!Q..5........_^.aI...N./.B...9&d.6...^.g.V.A<...F....Hk....U..G.a.}I".=../^>=.....@...h.....Z#..d/o.t..P.......+.a.A/..5.ZH..=..nZ..\.[Qf.=e...Td......vl....R..B...........i_.V..C...A:1L{-.qn...-..P........T..~.^.....^.vg~.KNf!..W.........@...H,.....u..T.H....e....bR...:..s(t.T.....3..............!;...wl.......hn.E..1.@.f.lL7..Uzwf.5e;().N....(....B.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.641682330947942
                        Encrypted:false
                        SSDEEP:
                        MD5:EB4EF0F6FB108BF2E2657BF6BF213713
                        SHA1:EBB06D99397F4D081D216AA991AC11058BEB1752
                        SHA-256:F7211F49F1FDBDC4B2B2C98A403F3B75C18B1523F6EAB807B35DE5C49FB727EC
                        SHA-512:713012F13B9FD63CCEFC3937F0447F6BB10410FB087A756C2A285C1407A01EB916AAB7DB21C5E4E38A67916446C302482041252E9B4B026C416A71F6329555AB
                        Malicious:false
                        Preview:....|.so.M..Y[.K:....*..S....SC./j....S....]1f.O).:....*..I...r. w..........qyW........m..h.......}.}...F..B........F.w.`,.p.Y....{=L'..ng>.....6S33.B..T.ttLZ(2......n.f...)...7>..}.5J.<R.;..A.@.A.....5..Z...@........b&.8w.(.....l....{...In#..^UZ.J(.a.y..@....?..A.DlC.;.j.S...3.Z...bk.....N@.RLn.....4.}x..]d.K. ...-...l...ej..m............P...J6..d.....5..H..s..*9z.";.{u\,..w_.V>...5...+..Uk3.@.7. ..0..s..b../rM.....t.h.w....V........}.}..t.+.`?....B./5..D.'....b..\.-].=.>..~{...T}.'0.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):854
                        Entropy (8bit):7.7371783777637395
                        Encrypted:false
                        SSDEEP:
                        MD5:AE90C21EB851DF6ECEC19A236ABA6F71
                        SHA1:9DF623E9E7181B6951ED899DEDD224BD102B98C8
                        SHA-256:117E1CCF2FCEB2F8D9F203DE981CD53411892AB12A440DDC1A4515185F3ED78C
                        SHA-512:379F69655B7610C0E198C7244CCE2706D7E7FB3BE216F277111AF8D4F76C5AB71B5EE5956D265819CFD55C58E2F756A98622771015BBD2FC0175F557232A6763
                        Malicious:false
                        Preview:....P M.F.g2.?...[.N.......9..*6k]..5....H...m zf....R.S?9]......_......n9w@.....I.{...B...V=....2@....#re.zy~..,......1....1...../..!....EA....?O....!....\....e.l..lA.pZ.......>@5...{.>!...........H;..#(.r...RZ..C.7.G...c.[.e...q..}\..)....~..........X!.G.W...B..b.......&.C.Z-U..T..KF.P65...a.g..|.Z.V..a.N..>C..>:9~;=.....b$.?K:S.M.{Sv.XZ..8.C7....K$..s"y...T..p..~.....e....&....R.......q...T.6...;..KP.O...P.u{....N..!P_.7S.U..y.}.U:Fp..D.H.a.,.D.T.'..p.A....z.OR....x.2.Q...M....Q.M.. ...@A........9.....s/..b...Cl...^y......{g..i...,..t...0.AwR.z.6....4....t7M]59.z$`0.{..(k.... ..vA..u.!.p..2t.xe... .....eV...x.e6 ..O.~T0....26.q.......j....B..gDa.....$.D...h.?a.k.t0...d..y.X.4.......?.(.v..9......"..3E...J._G.......J.r...../.3.s._..^9...Q..x....&...i...gD.i...(....a..F.Q...qY.?.C.t.O~.+...P..7.L:..E.G.T.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):813
                        Entropy (8bit):7.771831239499417
                        Encrypted:false
                        SSDEEP:
                        MD5:7ADA5447AAFCE796A7C1ECDD76F3B8EB
                        SHA1:A990A9791F88AD6B2F7F41DA357D52191139FEE9
                        SHA-256:872186FDCE9837808F59FD7251B990070903D78BFBCCC33897A6F1FC747CE3B7
                        SHA-512:9F054CA2EC389F3594254AE90483182DC79BB0243E0416F92D5891E223E849EB631A2B41F021555523B8A15F227D56D438EBF0592CA5A675E8DBE9EB42528919
                        Malicious:false
                        Preview:3=Q.....O...l/.m.4sP.2.N.mD.r..W)..P.1......z8?.......'Z.*b..~...a..B.........c..`...Xw..xpO}...o...|..eB...T....BJ....U. \..0..Sl...t...[.Lk........RY.1,../.p...D.....F.S.\~.X..:.5]...Q....#p}...r.%..rS.q.(|.\i...5. .."Et..@nKJ..Gr.<..d..D .'.>..;/6!fJ!......b|6..Q.W....SE..|..$K:...C.......2G......=Y.]...a.7....y..l.....?W.P......b..."...>57..^%.Z....Dmy.J..h..`...^4...0....%c...WUEe.'..F...$).-..:.!e..!e.,..Y"l..t.3....k...n#.N.t.9.._.A...N....R.Gb..........OI.P...D.,e.5....p.UrO..=i........[...j...I.un...?.l..cPY..jU..VdrRP........0.Fk.s!.....s....M..A.r.Y.#.....-.?.......|..).HQ...%.`....l....T..`.M.3m...:&.s].f.0m..V9..t/...........'fj.^.p..fdN.....{W..H@...N.....4R.-.8B..I.V...f8m..nw.8...p..;............b.m._.}.....5..%....L...Y......R7*o..<V..]..>3..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):571
                        Entropy (8bit):7.642276262627685
                        Encrypted:false
                        SSDEEP:
                        MD5:C74BC5E4B29A18666EDF7EE80EB3FC1D
                        SHA1:3EA6811A75D8FE47FD5869A7A3C1DEFE7255640F
                        SHA-256:51D25781B9015686339219C83F8C1731B0B21242A7B125ACDD4B760E8F2BCFF6
                        SHA-512:C6A69971B75A0E502063E00841AF3D1452160BE51E870CEA3E051785A6396ED3785ED0CA450DF04A6B8DFD5F0ECE48F41DDFEE0C0927045C49F40C13F2C3F3C1
                        Malicious:false
                        Preview:..?8....I.k...gQ.K5.H.u../.B.Ra1"..8... ?8.6.*vC......K:q...=.......B....K.p...h..|.a.QIO+..$....]F.puNG........M&K#A6.%.E.F.:U...2tG.t...42&..kk.lf.i...}.^......8.......'L..!..y.4c. .."P...""..n)..f...lL2..K>.s..~p0.!....Ys.N..3..IPhV...f..%...>o.7..<...%<....S.^.....s...r...L.x)..8.f0e-.........Hw.hx\......w..E.......!.........a.....$..q..H.....!..c[,W...."_.6..}g.I.5.....F...W..\ :.9...N.-,E.....I....,......y......TM8%).7..q.F~Kn....*..,e......+G...,1....o."..e.c....._o..m...5.X.(c..:...i....%.6.b.5.t....R.s:..SS...^..#.....5.Xi...+
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):690
                        Entropy (8bit):7.7079808929002605
                        Encrypted:false
                        SSDEEP:
                        MD5:31750128D770CE358CA4713207363EBD
                        SHA1:62451BEF12D29CA22572B9EB930E387A00B343CD
                        SHA-256:A113687FF8ED931C37EE3C0ABF92B4ADEA11C07415D271235FE8E361061479F8
                        SHA-512:9176A65CA810A2829D34F72E13CED6920F6B4BC8C57F0B306154C30B594AF736072B52D3CA69C848CAE2EA5371C44B53BEB66CEA4488C00B66231B2DC7B251EF
                        Malicious:false
                        Preview:...V4.{..O.n...[.^...[.2...8#.....!......?.........k...S.....:..U`.5I...."..*..%.9..t.1..S.B...5....>L|.P........{.......Z..y..PC~...n..6..v.. .<...j.x...y.|4.;j.0..;K:GFs/...}6..wM~Pf.y...k..l..~.....f.8.'...U..0:...K2e...5.n.o.}..,r..2....b2....... ..$...P.D&..f,v$.)Z.......b. -R...V8.H.k..T+F>.a...h.,5].Z+.}.Ht.J.,.B.K...GBe..^.......PiT.f.....w..$.P......g(.$C..M.cx$..z.....!c....R.yX..Y:u....B.c..[.4..3.K..i.y+U....g.....o.-..d|..l.-3..@.B....n.Z.D...}.Ln.5.2.8C.X;....?..9.n.h.NO.0....P.:@..M.tL/.<.S...H.pj....$Z....5..W.x..P...$....2#+k....e.......R.4.<.....Q... .s.B..Ek.d|n.5...r...O...G..".pB_..B../.L......-..........2.J.Vr2g..n..m..Vk..-..`.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):546
                        Entropy (8bit):7.6232621348455725
                        Encrypted:false
                        SSDEEP:
                        MD5:C2AAEF87CA504EB73BB53DC8A6A48487
                        SHA1:4709257415B731B2E10F50F898169E6E80AAECAB
                        SHA-256:3C3798F680856C03A5C82A3C8CC011F3C1223EAC55187FCF565F76E87BE12D23
                        SHA-512:DB5D57EF0EFFD18B2DFB66769E963A5CFF344F70887EF668A46BE285221F57E0E0EFC8D76016669EC30BD56CEDE1693121D77E24F557F458C3867423512CD8A6
                        Malicious:false
                        Preview:H.'.y..../tE.w.:......g.....K:....K7.7=.p...:{}...t.6.2..`+..s.7FZ..6.....~....X.......Q..S...@.k...`.....I......4%$.q.C...........%...i.....fX"W<.L..s...rM.......H).:$QOE.P1M.9..+XO......'..w....C.)}.).>./.t H..rC..y.F.B....1{7..aa..U.r;n..T....CQ.t_L.0.qr...k5._....6.206.]C.J..Jq.#.+....L.D.U.[/ .a......i....D.~.Dxm......jDx.p...L...e....o....F.{.. . =N..4.z......3..m.'..Z.z....oR|GC.....*"kL.%.....Doz.1.'Z..i."....E.\O9......8.v.`..E....N.....o.u...6....[')..k2.;Tv...X... 9.4.a..........ad.M."0....b....0..\R..=
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:SysEx File -
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.645906540301762
                        Encrypted:false
                        SSDEEP:
                        MD5:21CFB963C873A65EBCDABC4DB96D1F6F
                        SHA1:F6175A5CA7BD4AB854F6737DC31880F2F793C915
                        SHA-256:225F00A92D65EAB8FA74DC7CB93F3364098E4AE7F95E136B2F63963A8BF0CA3A
                        SHA-512:7614E1AAAB101A4E782D58EB03C598AAC15828685856F79A85C8D00F6B5E121C4E912558427DFECAC220F4B5555C91F1346483D7DB0E44F363BEE479533B8E2B
                        Malicious:false
                        Preview:.;.Tg.C.H6`.....K:.z9.@....p.[.1..K.r".P..v!.....;D."...bJ..m.o....h6..p.$~.......X..!...=9..y...x..^Z...._.*..0Z.1...:..^.].0..e.....f....p.]@0.....s.&z.*GR.}0\e..<.].#..yA..Z..+....@....H.TQXM......L..c.G.=.@.8../...NY..POu.`.9.ZN32z@w....m.....,!...\a"..A.J..W.V9..s.c..g...?.V..m...Io5j...e.v.T*.l.~:.n...bT._.@@.."..^......i..<.'......./.zPV...-H..V..m.^..o..5.$......#q>.-..xPt...J.BK.?n.Y.\;.E.....ef9|P..W...t]..`...Xl..\W,..9..2.K....".....s..sn<.....DR.\...E.K.>....Z"...P.......'h..D..h#...^.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):872
                        Entropy (8bit):7.8012054446669294
                        Encrypted:false
                        SSDEEP:
                        MD5:3BB33548DA6F19AEF96BBD650AC0BF08
                        SHA1:8A1162C9728C127F4B99A7EF2224029E972E1FE0
                        SHA-256:6796C19CB18F44722649DD1C4A01B9F31EEFA868AC773F16C20B3D2DFBC58C79
                        SHA-512:F62602842BE641C5FC8482C71753C9B5C2E7F298CCB83D3C92643E6598205E94E972D6CE5875F8182371723F0E17D934A1B5ACBC5C8EB2A5463988985F107BEC
                        Malicious:false
                        Preview:q.(.^....d.,.\.D...3D.....b...Y..{D63.v..nq..e...F.x.F]...M.F......~.a.,.k|.T.w[..Iw.s.........aL............0=....4(.E..gx.h..1.....)..*R.,.p.Qp.G.FO.<..V3.D.....ekJ..<..j..8FQ..fpZ.#qv........d...H. ...j..H..P...C....M.p/x.h.a..H.8.....`..}2.._p.O..j.y....-....~.1.s......&....Z..r..^X..^...+.UuyM..T.Nz.....ONzuA.XK......v...=..1h.^iD0.7q..aK:2.[.....f.cnG..6....D.^)......7^..9..9.S..a....T.N#>$!..Hmu..as...K..`.7.02.:.[...f....j.K...<..0.......F..T..:.>.J5...+.2e.S.).....J....(..n...D.....c...'#\..A.0.*..k.T..U.)].."..?N.. ..5.... .Yv%...;..(...R".=.H)L..)t.o....X?"Q..k.=..:..b..Rr4...6}..|*`....u.A]&.4..a?f..+..z..Q.....2.(.P.1...._9...g./.P.>K.W..`.....]........=P..Q...l..>..z....A....%xs@ .K.l...6].j......0...W........[.<h.....xAKE....f}.....B...'....:..#......h..w9c.E,q..V..i..7....l.T@.VW)$6.|...y..6^y?..]...^..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):831
                        Entropy (8bit):7.781170415596494
                        Encrypted:false
                        SSDEEP:
                        MD5:18A47E3503FDFE92649AD8C5F3AAC8EA
                        SHA1:4B309392DB6B29952A1B13919A45B65EA4F8E10F
                        SHA-256:F71080680A0364BFE4FFD7A5609BAD66CA7CAA7E234EFE0CFE2C1703744AC9EC
                        SHA-512:2616AD6F9B9F62D3638FCF60083355A29540D7E425529061B74EB078808C9035F549A55EFBF1E28EB6F321E183485B09D716EA8E22317454268A4F98B94096E9
                        Malicious:false
                        Preview:..5.......1.S.`mP|\...mJ.s.w....Z3....=2...A%.P)...F....Ur...dj....=sT..............q.(..jk..s:..|0....e*.%5.....Xot.....`...K6.i.R;~...t...Q...i....#....H.LK.J...G.Mz#..A.xK.......h00lL.f.)....LyK.c...>.u .../.N0......u.Z...~..j[...t.x%."[.............'...2....N.|SM.1.%6[@...A".9R....&.Y...}..<....K:...p.........z.ih.~D.*jr.L.YD]..d..._.u..dI..E...A........K"..c.$f....q2L.....x....WX.^.b.9GD.....O.G...@..Cg.$.`8...n.....b......} o0..c.9..L.0.U....T!....{U.....@&Y.(.....k.DI.z...U..H5ku....L?...z.+v..'.00...&.Q.Wz..DC%..=. d..Ds...7.P....?.:..vj..i.......f..[<.H.....k."........w..b.....%4+k.q.b..gE....:o0..y........9T....U..Cg....hH.M....X.7..i..q....-5...4.K....]b.....c.O.5.}5....b......k.3......F....ocR._..h.A..#UW....Jwj.g..5.qxKp..0....uN..*......7.FW1.i-?...av}......cO..[.7..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):571
                        Entropy (8bit):7.565185620957526
                        Encrypted:false
                        SSDEEP:
                        MD5:270ADBD408D839CB1D8A08A76A7CF4C0
                        SHA1:B6F64077E922C22E0E991C7745122C3DAF1BBD4B
                        SHA-256:096742FA4798A7F4A09C33D05092F3D866E1A5C7F240E66DA9440EC19FC110C0
                        SHA-512:306F2A8BED9796B5183AF77C449D31132430ED479C922F3F7EB20E7FC48A996260DE78E43A4FF392FBACB4456DDF68B134421697E39FC05789AC0354D5314C2E
                        Malicious:false
                        Preview:]ah.A.td../......i.#|.p.D....O..H.........)u".u.t_...K:l...S..IwA0.....O.. .O..~.N.n.hZa.u.. ,3.U^P..;.!..Y..fL?zpN-/.-..yu....I.V.N.pJ.E=.d.k>.8yh...;..o.N$.o.N.&\.C6Hn...:....J..#.....g....?.....`.)...UJ....* .2 ..y.cN.z.8.#o.SK.%9Veo..N...c,..,'......LE..Z/....L.......]a...s...=v...g....o@R./..&.&.H{.$..9f.9..F...f...k+.x4..iR...t<..Z=.*.y..{9....J...5....F.n......`..#...*.=.L......A1<.DS.\..].~..R]@.*..EOp4.....g..4..........R..tm..b...L....Y..g.J`.(.]..i...t..@..........>"...(..%A2.Is.}:...}.MDZJ..$E@.#..Yl.....R..|@...)...a...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):25106
                        Entropy (8bit):7.991831189819636
                        Encrypted:true
                        SSDEEP:
                        MD5:E33760975079435D4CE69A92D18690C9
                        SHA1:C1A1171CFC0EFB57DC5C3B49B1C31AEA1298BD6E
                        SHA-256:24DB2CA4EAE733AE9B566F32102B910C19612BD2F4C3FA7C84CF03699715D49C
                        SHA-512:A8E052B8495D76169EF40B173772CB6557335D46BF9908847152D6684F79F2E2E4AF395E679F358108277023FFE5484A9C29E9BFE11B7669DBAE6D07EE165BE4
                        Malicious:true
                        Preview:lx..V.||."..a...L..P7:..{.ID.z..Y..Fj..q.=).~....a..^a.U....'-......U&..|._)...3.8...]...|..-).g..m\......Ks.nc....OM.f......@.WyCOx3.bJ.J,.1.."Sy..M..Bk.g8j. .vh>.L..."X7.......-><..]..Rq..5....UD..y..;n..I......v.+Q..j.H..?b.4.w..z ..wO..+D....:.l[][...B......i^.0.R[...k.eH...KJFV.G ...s^l...W..E.35z...z0.#.....n..7;OC..`.....T.%...........TxX.r...YM....W..^.6U..|]l..;.o...H}.2....Oz.'.>._Uua.|....T/.h...v*.u.(....v..n.aC..!?.E.....y[Kmks...\7.=.}..d\.....F..hP.....1.-.d...G....*w.~'V.z.{.F3!AE.t^..p.t...i...'...w..&.4'+......f....^u.Z..|.......4....I.g.u....'\.hs#Oi..@.F.l1..xw.P.<8....f..s..1..Q..........u......o.d.,....X..=....8.O...|.......*..}.d..t...d.%7..V....|0...^....vy.....8..;..7.....aW....G>nDyW]]....D..e.%.....K.....sx{......2..o..C......i.U.zI.3......[e..y....!.....\+..v.G..U.z.m.FK..e?.^...1iEf....C.I&.?.A..8m0.SG...gZUwA...V"...Pz$ij..(..)D"lk....s....0;....jeT..;T.b.a.m..w4%.MN.Mhb6@W.V;..*.~.....T.O^M....W.??..M.2.xZ...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):57874
                        Entropy (8bit):7.996839954892327
                        Encrypted:true
                        SSDEEP:
                        MD5:A6A7C30C020DC56D33D3C1C48234A42B
                        SHA1:B8C154C8F962623B2F314B4B4774B390587849F9
                        SHA-256:35EF79B17DBBAEC1711D96DF5C55B5F7E1DFAC780F683B1861EC284BDAEF6CF0
                        SHA-512:192CEB66B0A7EC6D1A83C12339264C1931F2864101980554809DFF94C24D45EE569BF85B230179ADFFB4B7581ED3C674FF4309D208CC1E25BFA5B9A35F7DC127
                        Malicious:true
                        Preview:"&.b8.K...M....f.ho.#......b........}...f....P....Es?............/.>.^:....$..!MfQ...Y.c.#.......p2n..NOqBF...z..>qZK...KC`.m.....y.....Yq..0wx.#..c`.J1...'Y..j.Z6z!(].8.)...p.C..-u\.....>V..F"..q..y....t.....a..P.....=.I....f$..i...}n..../...r}...h..~'.q.....[....5|....z.C.C.`Z:_...^Eb<.......[...{..%.7...h.6.Ff.2..fX;j......39....m:..v.. ..7A;......a..:'`u4._%..;xqw......P......2......c.!6......-.......{..Jn..7!.L...`{K6pk.g......4...=.sD..S..Q.....f@..H...p....Z...2@...dI5..wf$c...PX.n....@{x.#.M.2../.d..c0Oz.Od?...a.CUs..J.e..C.......;b..M+.P........8.c..u..H...n..W.....%...!....8...r..o..8..].X...Q.5....g...zZ~k8...=..$H.2Ux/vc.y.SP.}.sA.h.O.-.[...........p..m...NIC.Y..1....`I.]....c.k2K._..c......l.....0.2tp.w.X.d7.}U_.60~..7v......I.!...(.....S_G.~g#.;.. .,y/..g/6$vOU..O.7..[(b..$.. 3.....^K....LI...-.....o...!..a7^.f...x.6..jX....40?.`m.GJ.g^N..@..^.C.....$.~..#.........[.p...U8...ZL.Jq.O...7F..=e}.o.k.....`.Z...].&I..4.{\#.1.i.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5300
                        Entropy (8bit):7.9616848982224555
                        Encrypted:false
                        SSDEEP:
                        MD5:65A9FA7AFB568FD9AEA293D56063F836
                        SHA1:F6807B96CA57899DB87240157442B490258ECE15
                        SHA-256:F2CF4C3CD9862E3585C9D46E8FEB3C9EFAB38FFD6704BEF06ACF18C88366B07F
                        SHA-512:ED9C3AE6EE303717CD0AA416A379D75E28B95D747C93148FC50D04F55F93A8D9FFED572A4833DE8840EECA90AFD6D82FDD16CE4CEE09E781362868E48F01FC0B
                        Malicious:false
                        Preview:G...5>..&.?...l.=..Y..0.b/R..-N=n..`t).H.x..y.....(|;.+k"|r]k...F[..k..aq.....t..H.z.U5.........Oy...BjO...Z....ZJa..tvB.p6...c...K......9..]....g.......i.z....h.0..j.......w..g.d:..M[.7.W..9...3<.=...][...$.q......_..E......7Kc....~....}.C.C.a.0..106.uvb.sx....G#..*.d...a.O.l.d.0.]..U..z.f...<E..Aok.Q.......2./>kj...hu..QC...n...x..b...cQ.8.._.9".12..h+f.A.CXO.....Y..@...28.c..m'.=*..|...R.)h.....o.......$...&b.c.<!.......'wpi-.....o.[..*...:GT*........]Q.p!.>....T2.-|s]q.=.jd[...I%A".....1)AI...u.y".p.<.4..B1..w..?4.Dq..t^..HN._.4.P..).Y..T.2......5s......F.....ar6.}DK.$..O>.#8Or..a3.ek.L~.s.. .[$....K...>.V/.K.z<*../.........v=...X?.z...".p....80.6..p.pN.!J...o....d.....J....0Y].$..QK48.......IRr@.C..#E.jR....[<`.t.L.B-R.....}b..p{- :....Z..7k8.......9..,..p=F.)....I3..\..FG-.fPf?....d'O...8....Yo+...[......T[..A....X.a..W..*.........s;7.j.Ls..d w.j....V.Yu%..D.#.9.....~.....-N.._.x1._..9`.7..2...2.....0.AM..3.b>../.sE\.X..}v..b...H%...D
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.66177279675314
                        Encrypted:false
                        SSDEEP:
                        MD5:958ECBE575F09049B180C65FEBA9262B
                        SHA1:B05CA8986B039C0C52251E994B8464FF57AC110D
                        SHA-256:5FE9E7AC825079C49BCD76FD09BF831228F1546813B42FCC9547975450691B30
                        SHA-512:B4A5678ABA688DEB4C940A28F6F754E9A786265BB0FBFF7764D8B1A50F090702521C82DC4C6C44CBFFAF4E1D8DD0238173B1530D5763772787FE5DAE00EE05E4
                        Malicious:false
                        Preview:~..%...*..c.(..8K:X..X.Y..R.U.i3.Q..?.....S....Ms..g......!..i.$.H[.@...\...7E..X..J..a`..J.....u..d..]a9.. ]....-..#,.Z@I.V..[d6.<b.i.\.....N.@.)3..2.....#............h`0..?....0 .......c(....o...R...C.#...K...M.zu.z.v.R.....$..r..,Z...&h*bb..g..8..HT%f.{...8..(.^....D%|.*L...)`....ET.U...~.k...(..b/>.e[.[`3r.{..}$.2.y0.O.c1.l|..?.......|V.3.*"6.....d..*0.=.xu..JL+zTO..2..v..|.\b..t.....x_.@.F..us.i.jl......6..:....j.Z...R..z..fY.rl...jq......./...E....5:".P..>@.!...$.CX......yO'..l......H.......7..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1001
                        Entropy (8bit):7.829529962696463
                        Encrypted:false
                        SSDEEP:
                        MD5:B72BBE0242C6D1BB4CEB392DC436D90D
                        SHA1:E450E8FBB682F89731117968B71E9B434C24760B
                        SHA-256:56CE1EEAFD6591DAE8C9FCBC7B98BC838E278A77CD20ABB80DF42DC48F9E143D
                        SHA-512:6F0A691132518621923DAD693677D30143D48E1C0B63755F494DAE4E3A700CBB51B731A2117389F7E4064C39B1A4109570D43D2A784D08E686153C0F9D93A575
                        Malicious:false
                        Preview:u"N\0.y..&......-..p.f..=.n.. .r..Q.O.0.H..q{z~..X..0}.. xOc8YjY.(+..`NM,...H.h^..8...X.]<..H..z......y.w.G.?m...e. ..<.GT..C...<$..)..u.p^....]...S6j....._.?,.r...3.5k."..-.lT..~6.>......m.]=..H..G.....`.S....~#...}P....k......xhy..i........N..[w......u..>.\o.<.8....g.1.&....)...s..A.$.@.^G.4%....-..P.=,..../..n|F.>..[^J.....hmR.N....U....J..2..k......>p.....4.1z.v.2...........S.0...<.9f.*..r...F..%_....E.>.........-t-A.(...-.K.~...._.B.u...R.K:..7..l..;......|Ti.='7..0.&.v.$~{RZ.X..C-_.....-UP..Dx.9J..&...):..p........,[.)..R|[.6.r.Y..p,zQ..'5.+K"0r..=..+..8y.c6.M..4.....a.J.I3...W....#z...W.|.2b.....k=E....e......../.F.`......^T..<.......ZP..7!^.g...Z.*w.]...].?..m..y..B{&Jj....B.%..N.i5..N...Eg...*.../I..>....].l..P.J....1M....F.8n.....-_.L.=.....~.f.........Z.....]........A...O.l..rb.l.mL..j...)".?U.....39...w.be..|...n.G.+.N.t.#H..+h...B......ts.....*.....O...d.<%&........p.S..@._c.........J.....#e..0.H=\...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1001
                        Entropy (8bit):7.816434057817023
                        Encrypted:false
                        SSDEEP:
                        MD5:F0F0FC563B59C1747CFAFCAE29BC6872
                        SHA1:51CBCB64AE33E92C3FB653A10ECDB3D7A23D7364
                        SHA-256:0D8BA4FD571E8194B7E51EAE996AC68F35D12F2473F9B072A66DBFEB2FDC29B8
                        SHA-512:357CBB29B11A4FBE462FA8527C4CE375F1D917DC016FC954977F1E33B6907B16D870AA5581A659C09913853BB72EB2146577DC8CB988FCFE780EDC6D358B0DC9
                        Malicious:false
                        Preview:...v...Iw..<.-....'...v..i.....L..4.=......a..M....pa.Z$.-r..lH..xS..r...O....'..`.*..m.!.!.+O..@|.M.w .}Zm*.T.P.a.f6.;.V?.s4"Ca.S....<...X\.l... c...7m...!"......dV...v.....D......X.t....I.Q.Z....$....i.[J..._d0H".j........c_pp..k..m...y....6#..].......4.......A<.T.p....L\.q.f..&..[q.-....vC.r.Q2...D.X.y....C'"....20..Rsn.........D.C....:M......... ?.V..........o.[).B...Gj.j......1$.v..R....;.r.&S.U.&...c.?.1.I.]...........\.2K...........+.......TI..u..z...K:XD...<.....Wg........PLI.n.uR-....r..A.U2.t8.>J.z.i...:...LT.C.4.a..*..9.....I..T..#.u..L./...`3..`..;...m..h.G.$.]d..gB..Wg=.\R.|V%..r0.....D..].2._8.(>..$k.e..Cj[-...X.K-j/.b.?E...8...S...#.^$.%mX7...........F.AF]dF.>.,..,...FM$K.j.....>.F.O"...]..{.L.E.:..g...*...l............g..?....N[.....L^.I+.@...U!...:.}X@Y.N.2).>..S...:...o....bJ|?.>.m}[#.2.i....Y.S&..'. D.rQE..........eL.]?..w|.<...z....k.w..g.....T.-.Q.....%3.t........C........G~r.....[..U<V...{.X.......k.u..........^..nf
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1001
                        Entropy (8bit):7.83105378633856
                        Encrypted:false
                        SSDEEP:
                        MD5:75AA9353ED37BCA60C98A3F173CC569C
                        SHA1:24DEF10914EF00CEC5E0168CD02BF280A825D82A
                        SHA-256:7B0A8F826C3EBF5B843AF15F92A9B0517217847A18657F96E18351E150217CAD
                        SHA-512:9A291ABD23403A1A2E73729C80629ABA8F41764E0B9311A038A88AB36C69B58151BAC4CC4478F8FF77A3CABC4A004F814D2F30F47D535720A97B7906854FF177
                        Malicious:false
                        Preview:.$E.UZ..../+.M.'..>...G.u.VvV.&Y.j..."1.6...0..l'.N...W@....5 ........SHc.).h.w..R.D.....*.....R.pr.s..ay.R.:}..)k^5.fv.HIa....8..b....D."wb.{.C.c.,.i.I..v...R..^{.....U..M._)b."....gK@...0f+Qu.Xe....L.#:.../.W...^..UZ....3...p...B.......r...a<!...z.?...y3...c.{.....v.DG5..t../...7......V..s.'..r..K7.5E..&.4....g..!XFA...&..R^....qy..6\...8....B.DD.:."..........:....X.w~%~.j....u5Q...b0..1.......0...p..w.v'~...{......2..\."D.O.-,...p..\...oT...L.7R..L$N.i.E?K:..1.T.]s.^e..n0..vr........5......i..3)x.."=.mtmm.<Tv.<..v...-w..+.Y/%...8[..!.~....;.,.dT......gQ..d&.....,..5.X......8......jIh.'..../.1..ru..W?...imT.g.d..^....((Z.e.b..\..T......Q.3d.%...v.:.X..-.....t..W...>)o.`........X]...\.O.8&.8S...n...[....oq.){..<Z.........f..Y.-.C...[H/..c.D.....L...... i..7.....Z .-.......`...L#.~..v..f.9.)..t..2..#.I)hP...ct.;\~..?.r......I....3...c...G..|,..P.8...4_..+=)....._..x.....e.i=.....c?...|.>%=2f....]......8.R..y.5..:X...Nko..>..?..C
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1001
                        Entropy (8bit):7.826440285545861
                        Encrypted:false
                        SSDEEP:
                        MD5:D1019A1CF59970FB8C2580A67F489E79
                        SHA1:B15DB5FF9E7C4F5717B9DA4051502E8C6603BADE
                        SHA-256:6ABA78AC315362AEEAA9F1B04E8C7A5BF6D0154E0797D7BA40CB7019EE62BD1B
                        SHA-512:ACCA272158FB52E8851DE2988FA35C44663E41DED597BFBE09595B2A55983A1FFDC69BC785765C0DE4152FAB8E67F481F269760759BDB51D35D73DDF8ACD6386
                        Malicious:false
                        Preview:.=N..].#.Q........}.....^Z.6.^qmy9._...._TUe...:!\.......?.-*.4.Z....!@..L.B...]Y".8.Ev...!dH,sW7.e...F.=.-..z..P.x.S.B^..%N..N......R.N.m.)..#9..o.`-~.H.....C..m.<.w...G...P..0k/........%i....Xo.L.=U.m.j+.M......S..\.S.u..sxy.LJ..J..(.....npH]...oTw....z...J+.-n.......)S..cmL..%.....u&.+.o..w'W.dE`..T...Vp,D..@A...a.u.-..0.....z..=L.\c...._.Q..3..]...'..2.s/r...W...%.. .E..-K..-O...b...t.7.t..B.a`.@.8q.E.....S.;..+.X.wxV..k....07.( ..\..v.:>s....2.v...K:.SF....Pk..._....+..8O:=t?...b.7.'|....4.%&X..|..=,..x............Wg...Q.u./.G.lR.83J2..v..eh...."..&.YA3l.d(uf..k...'..7....Ch.|.......k...S.*t.h.&.1J. .........i.se.s..lA..}r.....$~j.Y.h~Fk.{..Pk.v%...C..L..x.)..C..C......n.!..&.)..J..,.b....r?....... ......6.|...Z..@.$..w&.....l...z.{..k.<.J.t.C...l...5.g..{AC.`.g:....H3........U+Q..%^.h....r..a..f..$QF..O...=zO|..D..._......!.{!B.6..].O:,.@.\.05#.y!eu.!.$.+....!.........K...eK.}....{.;.(...c.W.......| .......}..~(......
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1001
                        Entropy (8bit):7.846407050312748
                        Encrypted:false
                        SSDEEP:
                        MD5:3CDBE2C1DEFBA25C66DCFE4814B528E4
                        SHA1:2C8F7B714AB46EB8FC4CAF66B8811FA936821D96
                        SHA-256:76712F2302FC590C07397A91AD53F01F9A7EBC111E4E4E60EAD45ABDF89D0391
                        SHA-512:7F2691ABCF02B74112E45A0220C4462D15A77241072C5525190376EB2A04B0B5329CE40E306C7F034E85A82AD6ED5EB4DA7AA3B811757E7F65ECAC57A55BA772
                        Malicious:false
                        Preview:4^.+..W....L.D.*........`(.....h&m.w.Bl...K...g....[....%.NjU0.n.y...J:|gpf.h.ZU.a ...7vh..9D?.........tvK...KI.o...n'.kxp.../Z.vk..S... ..w.@..T.8;!.cTm+......{.}..-........B......+.-....ygLV....-.._.q.../A..G.8:.g,.."^.....}.-LZ.{..`....]=;.0..K,p...yS....^........W7.HDfDg..wC?.....A..kW......jx..?.....W1.Q.....a..J....K8..e.&.1b..x;.^...|.......'B....:E..$....X.u6.\..qj....2.(.K..T.z....x_.3..w.5]..-...MJ.x:8..*8G..dC.).b.j[.m4%.B$...L..L..9...O........|&.K:H...Z..7...+....`.3.q.s5....3..Q!(..rLI...G.qr./"P...=Y.a^.Ud..[.R2...F....o..o. ...9B..{...6.-$&.bD..:._....!...U1..=.......vF....E.u.~..x.e...S9H......7............r..=...(..t.~....5.'.gu....'K`v......!1...P8b.f.`V.`g7../Y../....X.Q.....3....-.VefR.@..xM..C,.t4.N..ypB..S-m..2=i.y5....0........9"".=..p...H...7f<....O.Z..t#.}V.;.!h\.K.. ....Q...$..c.<...U@g8.....w.O;.d.TV.K..'@1~.@.%.......n:....8.X.X`..*..?.#.........>.Mz..y.........3.Q...U.....o..m....d44[.T...{6..P...c.=r...k.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):8326
                        Entropy (8bit):7.980426259708846
                        Encrypted:false
                        SSDEEP:
                        MD5:607127B134B94D3AE4F2E4BFC85C4A14
                        SHA1:2E4A75883D46571DB7F1EA87E0B3DA5DA2417A69
                        SHA-256:57305EE6F4D02B454C15017824C0226AC319DB57E45147CE05445D807D5E5372
                        SHA-512:8716C69ADC039071D39B607ACF304691DBDD5F9046A18B95BB46515EA528EBC90E29D11D9AC2020F8DFBBF2F81E8DC882D842BF9D710389F475BB50419E84D34
                        Malicious:false
                        Preview:.@f..G.....^=.GL...5...E[..U%..@.y}....CI.s...3.y......u...:'..T..?.I.?~...K..;p>:....m9...3..bO......q.$..S..o.|.3..@..........h.0.zQ.M......kG{>.. ..&...l...)V.,.N.....A:.{.;.5;,..W.GY6I.FY.~...6b.|z..5.. .i.l*...;3.@.K$].......7....nH.g.@.~2.h^.im.8.......c#..m.C.+L.Yq@%..$.......z%......V.,..%2k..h.....r.....z..k.'...".c...._;.,....w.H..0Z.&..5..2..........K...cS-2....W...f.....&,...(RhnO..g..s................9.....T..O.N40f!.....n..}...k....8;....F.Aw.[k...4:...w...@..O...p5E.\.."R..f..;..s....."..,8..U.v...T.@j?Hx-...W....-3.(R...p..BD.V.oV...(.....2....es.....K.c..r..E..,g.q.....h........2....i.rF..Q.1.-.&.0a......"..:..&..fW..2-Bx.0.Fu.D.d.%i.z...e.OOg.b7..g(..G.&....S*JB.7p.$...L".ge@e4...........M.J,.Q}>/p..bKe...b.w9\..4...fa.xD....-...w.....M\OH.M0....z......1*..XsN2........h...sM...&...'A....@.R)....Q..)=...7...^5D.J......uz.......@...2]...\.E..(......{d..Q{.".E..~@I.c6...%.G.j.`'i....f.K<.4.@....a...&i&]H>/..v. ..6*.M....1.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):868
                        Entropy (8bit):7.775295292875186
                        Encrypted:false
                        SSDEEP:
                        MD5:6CFA6DBC5A85B26F30ABA0163CCD1F4A
                        SHA1:77E862A94B9FE21B8FE835A574C6ABCDA3E22F2A
                        SHA-256:9C2F1DCA24B678603F322F522335F72D6E9502B4B0291DC0EC1055E63C34232D
                        SHA-512:B83DC17A6636C40463C1AC8821AA1CDA51F4F70159879D1F4BD3E5E5B464CEEDC676BB5F840654AEB869F52509E2E67763D5ECDDB15E10A3FD29FB103CC3B374
                        Malicious:false
                        Preview:......$)...W..qn=P..G.1.i.....t&..0..pg.>.q.8.a.M%*}....*..M...e.{.bZ>.7.o.K."Qsq.4... M........%<.....d5...~z.m...O...ys.n....T\....mh$F=.!.t9...K.x.Y..]<h.a..0_.]~.....8..V....O.g.Q..B..^....E#8;m...|..L.$...M.....CaA.=S..|......e....7..s.M`..W..Z.....m.A........l{.S'....-.m....qUM..aCf..ZVDi.%...R!.../...$4<V8.h./..].*Z..C..K:z....d5..5J..;..K..$V1$.w...2...Y.....x...Y.~'t.O..a[.t!{....J..M).q-...z.fe...........*..h..L..=.%..v.....|..T.,...E..."q....A...A...F....[.o....Z].O9."n....).4.4W.4..i.}M.....p1..z......b...E.X2.5L....T.Dim..".A).......-0.Y*.......B.......$..Tc.......".\....G.oP.]B..}.....|z.bU%.:. .y.W.X@..aJ...6.vJ..LQ.2;/....F..(.._.+G....A&.V......(..=.Qd;?#.nw.c.^.,.!..a.7..'.ca.9&.$..&.DF*. ...`.=1.]ch.+......b.....W....^w...k_X.].T...t........D.-..-l$..[..]u..fs..u.bV.Z.\...wN....=.`..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):820
                        Entropy (8bit):7.736158024701727
                        Encrypted:false
                        SSDEEP:
                        MD5:7457A92C9B3FBE1DF060E6554EADED63
                        SHA1:A44E35629F4B5721CE4E92B794D4A1B881B707BB
                        SHA-256:8366C3B5C7DCCE600E6676D8BF77B81CD76446619FBC1CF6468037140CED452F
                        SHA-512:808AA687B8E601700D10362D0EC7AD137A4C3C7FB9D0A198AD1ED4BDADF41CF88984DB0B5AEA8DA4563C1880D716F4C136F88D1BC418E80BC3C1A7F02168F068
                        Malicious:false
                        Preview:..7..}...2.p.l....l.z.a|....'..U.M...e......,wO....Y.X..L\.. f@-.z/k.v)y...../..0U..yQ...T.....f$..~;.&...;i.Ii......,..t)..V........{...J.....X....F...J.E.......}.o]l..c.?.D...+....JQC..3.7..vN...2..f..,....E...`..x...'.....K..{..B..3k..%..u.`.T.e.) 6{....\.(v.j.6........S;.(S.K:\@r...._.$.\........u.)<d..'...<.....<..LK~...<6. .q...j....?F.........de........^W..,..,...5....4.../.=....I.D.i.r...".I..Jk%f.<2..~.....e.2.'v.Q.... G../YX..o5[.UMr..u....v.b..(........&.....Fv"/.........C+..8/T..{...#.^..]l..rf...Ma.3!.jH..[..5.xs....\.*.1...KE..&.......a.................w..<..W...9X...e....NQ.cc.o=..25..-.j.7.,.N{..ulI...a.?..%.!.x../y.n..'1.#T.y....\Y...>.3..[..nr[.J&./.l..6....}A{.5O.#. p.u.fF.q...;.:......T#.r..*........q$wm.C&d#.VpM.S.8t....)..xR...Z..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):942
                        Entropy (8bit):7.81371821319483
                        Encrypted:false
                        SSDEEP:
                        MD5:0A683F27B88ED72466C11AFACE6759EE
                        SHA1:7D316BB2050119CADFA4C1896870A1291958C7D7
                        SHA-256:C6ADB066D769FBA0FE4D00C2DD35BE8D434E1966876D28C419BE751B734600C6
                        SHA-512:379E3152F808CD42E78925DA04A0E4AFF0BD7FF4FC28913CC5004C53C1F7DC792E91A44148A05C4000D7003F54DB3F777C257AE5A75F515A53A590F283F8A34B
                        Malicious:false
                        Preview:.....n.&q.cX..s.............t%2WB...4..B..um.k.......G....Dt......V..a..d2s....oe.O/....{%..@..3.0..s.tqTui...C..S.Y-P../q.h.vA.7.r.w.%u.....?.....7HG/.D...g..+M...Jq.*...0i...........*.$..%?..T..M..(.&..Vs..t.....Q.....B\...r...EZs.."U......*O.(..GxN.0...].=.=I.....#.k..s.....0j..." ....*&...1..bi..5.h...w..i.._.X/.*.....c....V..%|...tM...I.3i.v|0......@...W...aY~..B...x..r.{.../..fQ.U.L.S.9....HK:sr.~....*....xR..F..n.HB..F..F.2.g..y*...]..d....;,.....Y.....|..>X.RUF\H.T7..J.}:..7/.......Zs~..,.4.g..8.A.C....l..F3.i\i..t....E7...c....t.I.._N.,OW2!D..G.l....y.....5...3.tleD.r..`H..3..K."..C..v..C.P......y#.ffp%r..zv...<....B.T...U..i{.mc..._.$4..:...,?..j.*^!C.$.2#y.m.Y..?2..0.rZ.D..,..39y..E...N.......[.,?|C@ir......:_f...-X....j{ ......:(...Lwp...c..A.1..g.Je3.".....J...7%..P./5PBP.....=....?Q..... .?k....3...E.=..b..jA:.*.U.H.<)c...Ne.;#.\...J~..j...-.>...Z.Z.Rv..'...#.&
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):930
                        Entropy (8bit):7.782205352649964
                        Encrypted:false
                        SSDEEP:
                        MD5:01BD86E9DFD57C3C9FD691CC2342F01C
                        SHA1:B3CD764F25C7EE765AF18C73A994B3C2401EC3C1
                        SHA-256:85C3FBEAC4EF46F597BF50206DCF8145BAB04DD2A00F5FCEF0E62AF77FB9DF82
                        SHA-512:574C947B4B636A723EEBCB85A67AE4C9F54BB3406C341E1B671ECCE3EDDC1328B7B97C91E6F9850C01DE63EAA647DA01154D38FBEB23AC50520425083FE1E26F
                        Malicious:false
                        Preview:d..._jK({..e..e..SO....AF.QnV."....1....b..d..m.,b1.....4..|=Y6.z80...&.....:..I.....2..{..A......!.E.%....5*{h......x$*..~..@#......S.b....M.n...).G...G.....s.?.c.h.Vq..#.#a.;.....*..q...b...y.t.*]....K.8.0...^E..p.Q>g..r}.....mT|Ar..>...5..b.J..*~&......a...9...-t+.r.\.a....7.^.n=....l...p...!..5.j...ohx....}.)1.....q~.C|..W..b~..WEQ.............6...6B...@Hw&^).A....G.p .....C._a;.!....K:\K....D........ .....+.E.s.b...........O.K... .l..;....X9..Y....<....SW.S...`Zk.s.y..%.....+e.a.!...'[RO.:.....^.C.U./...E....2(.D..:.s...m.....[_.C7;2u+....UOV#.... .8...}...t. ...2.....98n....d...%}E....O...=.y+..Z.Nq0....~3y)._\..d..}..'.*..E......5.%...4.sTP:....[(C...8.,...Z5Q` ._.y..#..o'k..?.q...bh..!L..!{Nx......,.kA.v.....L.AK..{uI\..Z*9.."l.k.ha....^^...@E..6.."...I.q....M.".UQB.....:L9j..e[.....d..<...8...Q.S..*%!.6...@....(..-.;.`.....d...i.].A.<.QY...z.l..gC.%.j(.1....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):942
                        Entropy (8bit):7.796620311005519
                        Encrypted:false
                        SSDEEP:
                        MD5:BF5036E0C66EEAED2E6653A04C31559C
                        SHA1:1A7D3D6A14246EA929D44B391D1425475579B39F
                        SHA-256:4A411A903571524E2E04BE4B6BB6522981306DB7251FDA074A979D752847DA0A
                        SHA-512:F53A52B6D3AE5641A9B0875CDF6248B19895FA48AFF13A576FD52C4259CC884706A4AB9E291D3CB1CDA09EE024621D6F1EDC7C89A8C07AA9A08B310FFAD5F946
                        Malicious:false
                        Preview:Xq......".@.%.....(".M..B..g.y....I.~-..................EI....?.."v. .:....5.u..OQ....m.V..QY.....kL....:....W..o.=.78.Y.^.TT..@.u-..|.@....Z..NR..s J..]..m.&.2.B=...=.-~8.x...}.."U3X..=*.=...f....%..+p.........7Js.e..).<?..r|.K........#.../..A..H.....{..~.zy.....+..S7...|~..1.F.;..&%..%=../mp.Y.S.)...w...(v._..4.y......Vb.%"....).n..+.....=0w.y{Ed.h.8.o...w....J.S.;..}...&.r.l......Ba%C..">.n.A....K:..jXUC.n..#k..KO......n...N.K...c1.5....a8...."].=....RK.....l.0..\.J..........s..p...f,.[9.........1...f..`B.P!...r..... .&.....yi0........%.D.H...xl..T.h..(D...=.._..~...N.atq.#....b;....~..q....@v.p.o6.L.H)a.nK...'.+..[.{.>.........T......g..:.~Y\.+....1....'..k...:..=Tc....a...._.:.e....0.!x..$....s.`........2m_`g..p...."o.w..#..w.W..Q.@..&...^.ImPG{1?.Px.......n....+.....S..cs:.@U..UNn.Y..8..e..'(S.[)...(.&.S...HM.h.?Xt......... .==Q.....3..@.R..m....N...>..$.Ey.GJh.....z!\.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):942
                        Entropy (8bit):7.805471844703747
                        Encrypted:false
                        SSDEEP:
                        MD5:A1CDD729889401B564B63BC07A1B110F
                        SHA1:7FDE83B2EF85E3A83AE8F652437A2D155EDE2B9C
                        SHA-256:C045C158F951DC2CF9B726867B7EA316DABEB4703256588559C5AE3A9521CA5B
                        SHA-512:3E8B1FF1AA9F66AFA8B4D1A8D68B000FCACEB57E7C6044C949C261E009C8603F41918570C2EF8C0F4E1C3ACD876520C85EB0EB20695518A7DFBA9C4FF3ACFCE5
                        Malicious:false
                        Preview:.j..K=...llv......l..b.m.r......4.t..#..nS....i_.lGy."...o....f.....^A|.'...*..Q}.i...=j..C..H{$.bA...Wi=....n..H5U.:..............GQfG....h..SW&....J._B'..&.sJ....~f..o.......=.J..~Ip ..z.".T.S.Q......-.5\...y..&..u..~.#..^...J.e...k.c.J...]C9I#....Q>....Y.>...&\..k..N..x...A&.Dn..........C.Y/.9p......U...>j..'\`...:..&.X>.c.l..^.v...{.|..Z!U\.'.[...Z.G.-P..........|.Z...).c...K..n6Gr......e.X).zC.dT3.V.JK:m_J...d.....Qv..AGO"..J.s.....5...%.;..o.#q#aV.,P..<.Pk..&,..l...G8....|../<..Ej..EX....0..F.W......p..%./Z......W..9......#..7d.k.CA..D..X....Y ....Y...x..MCo...v...&7.HR.<'/(...U`6.[F.O..*.....+..x....F..{D..=.%!.......N"o.Ae.5.i..ge.'P....]8.^]6.k.0g.p...:...84..[..H.....g...........(.8E 26...2.@.....1...7Y9G78...-.#.SZ1.=@.J{..m..h.p.Z.....i."A"......E.xn:.."x.%.|..N..@,R!..o.?_O...B.IE..s..@.vQ...EVZ..... ON..$..w[.....C...h.d.`.p.kt..B_).^G..D.DXm....Q.tp.j..%2^.q!:h.. qK.1....X.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):942
                        Entropy (8bit):7.820742933638607
                        Encrypted:false
                        SSDEEP:
                        MD5:DBDC2E7C4084FD683F54200AC92D3FBE
                        SHA1:52996539ECE19330B96982DD78A571CFC8AA3DDF
                        SHA-256:43881DF78796EBF1F0AE3E6912CAFB7899889E17FF2F5B53D9997E6C2C80001A
                        SHA-512:EA77EC3F4FDC901775765FE1E3EDB03B815B2921CBBEC63F18EBA416049C0B7875CE7D6C83FB1A767B30338F6D39B697A0AA1B03089826D29CEE73CFF69088DC
                        Malicious:false
                        Preview:.@...W9.5.|WP.F.c.......e#..A...+..Y.D.G..'...${....2.h^.......C.>...R.9Cq.!X....v..R.........O.d.......,....`..r<..LO......l.-.}.....Y...r..d[K..^.9........2..p.0<.${'L......*.....~.^V.&52.I.#V..e5My.........Y......>..qi8.P..`..y.e./{&.r...Vs..)OX?..=...l~....).W....{.0...x...U.t>9..x$...7[.5.....,a3m=.^[a......sN,a.....X.....YOx.+...&W..!.wfs..\....c8.{n[g.2f.R.M...R....G.H.c..2E.^q}..........GK:F..@.t.....]@.......9...;....w...:....Q.KZ.To.J.,.....`q..;i.ot..U......r.....\ ..$....g5....z.rl.....8....7.<...!..S..Y......s7..o.(./..d=J.....>..N.....7.3.*....@......U..19.[fo..(_......I.Ea)`...6.,r.c&..]..jx...Ky.............H;p...?.N,.........8.n...Bv.....=.....bF.......`....w..d:Ro..0...%..tb..{.N.5.E.h6.R....c.6.........m(U.e...2.-.[~.r......Z.....F!$ .....V...F.d.......k._...i....9..B.x...uJ.+:......m.H..<...I.x1dq.Q.....z1F...e.'L....d).qP}..;%.u...9..8.-1..7..J....A.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):860
                        Entropy (8bit):7.734070237334912
                        Encrypted:false
                        SSDEEP:
                        MD5:187607DF272F6C1756A9940E8DE0D722
                        SHA1:1C18C501704075162F84C61E65ABED522220F2DD
                        SHA-256:C7B223F92F4E4D1BA349EA55E8EED1DBBB938B534C087F6DC95A3902E1C96EBE
                        SHA-512:0FA01E074D81F32F5B8DE63C1EA83716C71CE1285817EF9B12056DE076D15927A50E37B1B20C782D147023C1177B46902A1CAD6F71668BB53793DE531F1F90F2
                        Malicious:false
                        Preview:Oh..Z.!....V.}...t.%..%.#;{.p.+z.k...@U..8..a.x...^t.....(.u...(..%..6....|7[..TG...D..c.^..|x..Y...$..3.^..... ...!.ke6.D.9.o.{."..f...(.c...2.......B.i.G...q...."JyN.C...{ 2.5a....%.!#c.V.6...x.......N.....J......U..w{..r...\y.4.n5...uu..J.W..."wy...=.d..|..,.n&...A..?.../..6.......@.s.n..`.mI...M.Z6.O:....Z..._...w..#;!cEK:x>.......N........J.o..r.|!.%SO#.dg.;$..n.5O..8B..Dg...0......<...D.. m.l...d...}>#.6...0....<.|...5O@......`....w!.......?......&f.t...&.......9...U.]... 6m.{.....I..H.@...b.9.Ve.s@..........c|......~..5.b....l..U..0...3....{.!F....!...o&..&.Tr$.i.....`o+...7...pkvu.."..A...F..k.15.8..h*.Q6U1.Z......c.)6.t.y..Nm..&..j.*.^.......+..2..e.9.Jw.=..K1.....Y!aT....\.....s. _....'.y....8b...$PtDTP,u.....:w.J'e....]Z.....E.5l....aN.c..d.i......#.y............i...~.J.Ah..O....q.b{[.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1598
                        Entropy (8bit):7.865816588531327
                        Encrypted:false
                        SSDEEP:
                        MD5:B782FE0968F0DBEDAC828DF1E672DD89
                        SHA1:FFFD1799246478557F149E5757ECEF9069C10EB7
                        SHA-256:48C88C03AB700D0F039F0F6547A1CE2A87ECE818D863B291B4B2455A98142832
                        SHA-512:37B2E87B862382932EA23707226CA44FE6A7A969C824D5780BFE664E6361C21503D5FFD27C8A3F68B520A35F72289F39FB2FBEB8DDF93D0C1E406465FE96A1FB
                        Malicious:false
                        Preview:...6......y.$0wc....R^....S:L../F..-Nt\.SlZ...T."..]...nf.X.X.....cw.....p....2.(.....]v....g.FO.HL+4]......=......|W.L..^....zt.5r..M._/7/.7....?<.>7J...o...&.....{y......../.UT.E<.G<...D8........l.p.-Da....:!..a..#.../...1_..2.(.h...&F.~7?.|....rw..a....."..'v.A-._........M..Lg.R.}.2_.v..../.V`G}3.Z'....'.\...f./I}..y.fP-N...DRk.....c.rr..q..:5&.3...!.~..........Y,Q.Z.....x......... ...P....%."...Z...S.m..fl..z......K6.E..l..n3#..>a....l.t.M5v......x,........~Ar5nNp.$y.s.......v7.o..._..OK..(.b9....<.hQ<....U..G..:..A..".W......V....H&,L...C..h..P..0q.).W..495......q.I.[..W...WO.jR49z.x.....y.3.."...,]...a.EO...7.?.~....9....0....J5...b......@u.I\0..GL....(Z3....<:WI.....(...!..M......Q$.8e.cn....2.9PS.4}$.w.......)..(Q.....]..bD.Ap.C....%^.)..8.!.^.!.....}..C.n.........."....q.bf..1]...9....h,:4+...|.l.`..p..N.....(......s<......_-..C...o...QG.....8.l..<#l.1)K]......Q...-17.......~...8.R....e......\_.Vw.z..X....HH3.w...r.)j,.....n
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2293
                        Entropy (8bit):7.917530945977255
                        Encrypted:false
                        SSDEEP:
                        MD5:47CB392BEC8787D1BA5173152CF4EDE6
                        SHA1:19F6E1DC64B7DAEBBB0374CC658DE0E5A5993D69
                        SHA-256:7B793901CD17B24F58E55167A0A2ED46F08A32723F6E7CBF9A38DAA22870B7F4
                        SHA-512:3B8CE8EF6959C69A0120EC15622429C9B0D25B235917B8747441FBAA0F47BDBC37F9ABB31A004A87AB5965CDC869B44FBE6530FBE42588C9E151ACBA19931CFF
                        Malicious:false
                        Preview:.G......b.D-l....~N.c...A1.}.^@..e......21u....Y!.T(?...K.l.N.|t.W.d.Y:...l|<..Hd....U......R...w5"..K*.'..3.h~...C6...T5.N.yYdz.w...A.w(..<.......QRCX..0...b.b.......8..+/...$@..g&.9..T..S.CB..|......M...'}....p.I....Pb...\h.a.?....&.g..|H....9v=./.3..Jd.k.;T..;.....J(1..7.q....}\.w.Z...K...=X.j.R.3...<Lmn9..d.2...tq...o@Kp..I..+.w..H7>daC..N=.".-U.+........X....}........u.A.....L.0.cm.|..."..a.i.Q.Ui].o...\M...Ak.t..$.c.5ZQ.....TS.i..zE...{..2H.S.i#&\.w... ..^.n.....\..7&.V.[.e.h..i.n...)....w....Q.\...{.5...S.|E..z..+...`.....n'.r...ru....P.......9.`...?...x...BZ^I......x...As._Z3(.J.jm]!F....p.X.......}....b>..\.C..i.?..g......1.]q.0Qp.`1....N.sdX..4....:.C....A.3.../....}yYh.v6.... .|.\....>...K..&......s.U......%O.i.z..}.%.p..zJ.3<...!h@w..`;......gZ....le.........p.w.K.ww..%.....Ki..G....b.kp.m(L..e....^.;..)..*=b8...?.~P$.y.`.^[RL=d.@..V.d..+..ie...C.....Va...>...y.m.~?Dw6.E...o.)....^.W.z..\.|"m.1w...#FZ.`....g}B...f.&...Z..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):186159
                        Entropy (8bit):7.999056423469024
                        Encrypted:true
                        SSDEEP:
                        MD5:CA98776ABC6E632941220479BE24883D
                        SHA1:8EAC55718C45CC1AD3B875B8BC45A556769F8834
                        SHA-256:660DC3AFEE651BB8DFE840E62B28E6AF9135FC9907D5168664BA093635E36E62
                        SHA-512:7D76AE0F2F3F6C13BDE146558138F213576521D651D5E95A3CD296B3BE75B0476E3500F2D2544C91C4F3D83089D408006B8298F163287281D32CF5E35231654E
                        Malicious:true
                        Preview:{..b....$..<..X.M..AD....h[.,.t.=.r~yCsk...F.C*]e...].....uK...\.......,S$.QxBC...tQ..S;_...+....[.$I!..G.{3<7V...ay!.8.jZ.._..G..8....v.6...I..0.(?mM.../%.Rb......!...R%.?.Ez2...bE..J.t......\.....H..#l...g4..}.....)+aAl.....?'.G.J..r..c.e....a...n........n6&...[.}.\.=g.c....B..........H.c.Z ./...s..!..Jq..........Jr.F0.M...|...DzFP..|.f......s.rFH.]t....ev.e"..2.T...........d).....(..M..cp.*.....&i<....8..^E~R2..3.{.....)..)&..A...m...z..2.^....*l_....a ..?. ...b........b..&.R.q.....%.K./..a..5c.Qs.U0V..f./SXm.wE.cZ@.r%.4~'..o.....aB...Hv.'xu...P.vyv..(.95...L.......Y.Q..>.-q.4........~e...;..c2.......$......D2cA.K...T8.w*wq..q.Jj...e..s....d.....(.J.`g. .4...s...w.e..RD.m..0..~6..{<...Vx............U.vw8..,.....*cu`~.jU.f.sc.^...C'....L.Cc..n...q..s..2.(.U....16..s..).......B.Z.1Cco..Q...3WE.@......b.4....*/...W.c..=..(d.[.djO.v..d.)..W..J.S_E.t...?.U_..z.d..(b..6.N.0.......G..^..Ftr.(.....X?..u.|j..PP......:.m.....(.....*..x..u.uK?..`
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):11940
                        Entropy (8bit):7.985238322826868
                        Encrypted:false
                        SSDEEP:
                        MD5:3FB5639FEAF93553124A69755B283B5F
                        SHA1:066F3FCD46E72F85D43F99428169C37204FE1163
                        SHA-256:3921D20F5280B66A86D87E6EEC605A7CFDFDB4586142AF3003AA91E45D1FAF51
                        SHA-512:4540FBB4324F82E8D0011943EB5C56E054376EABEB1BA1AACBF1AEB9E6F45246AA6183CA06BC2A036D1A6E609B793A833FDC8FB70B8668A9289890DD9C755A4C
                        Malicious:false
                        Preview:f...#..-w.(z.0.{....[.M...C..!....3.8Q.j..ML.....7.2U..*.......~...1..G.=....6!..S0.: >qhS.i....S...-Q.;;i.c..g....m!.@.sn.T....u......*~*.Z....W...@.....mQ...?O.<8.Z0O...d.]..b....f...XG..N.tW...X...|.vZ...g9..........PV }.Z;......Rh.8.J.....^h.=..j...{E....w....P.. O.,..._8&pG.B.k.[3,V[b>..g..^v.L.o.^..."mT.K....c......e....g......g....H.(.4.....:5/\....t...%'..s.....}........1.@.+.....\....... .\.....C*.1..;.....Z..eyJ..Z..}.FQ..S....... s..i.4xM..'.....-..UrR.O.N ...-.J-....16.{.9Q.f.A..0..8.B.>.~!,,<...u.(p6.>..w..$....`|....{_...l\.*.....T.."....Z..(3........?.....(..d%....f...#.{}.....W#.f.M=.....g.B....yrv..V9./..r...1.i..e .E.gL+..%.n....B....:t>........%..<:j*....%.9G+n1.X...l.!..z.k../..P..7...i.% ..?......JX....e..r....*\{...<.....z..~.....c.*0......=2..._$.Qo.,A0..]Sd.N....... T.Z.5..;.;..L..GH/..O;$..(..p..,(.96M.'....e~..G...^.,v^......t3[.N...<i....}....`.u.)m".,,k.).4....<H.UY7.,.f...E.XA..;.(...t..R-..R.J.U,...6.,..W{..9.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):228062
                        Entropy (8bit):7.999162505712604
                        Encrypted:true
                        SSDEEP:
                        MD5:146EE081C188FE97A58A3B33477DF2FD
                        SHA1:0D937C7A3AE163FD075F4A07072A54A078CB760B
                        SHA-256:A5DE91C85FEC3E10E44C1FCFC459A0C8DA440B35509D925B55AE6B1D0463B1A7
                        SHA-512:824B3FA8AE0E0117811329AB43970E38622E76F40F2EE1455A74551B9328ECE06330154DACCFFA3F239F86D9414C8F7EE464B77F56CEFF00081D6AFF57E473DB
                        Malicious:true
                        Preview:D*..0.BG........f.b.A.z...%./..Ts.F.......3.....5....Q..Kg..X...M..co...J....\....Je.3...T6E..L..|=$|..".? A.@./.Q|Rt.D.}Ye...Vt<46%......f..P%.h...,.3....aG....:..&v...o.,.N.T..I..D2..X..H`.3..%....1.z.}E,).X&8.^....K>.....".,L....1y..@@.wx..2.......Zl..q.V...?..<..<2.{("...T1+6.-I.j...U.5....<.a.J'...~...........a.....\QV.DOT.`.X;.G.VA~.f....E..p..pc.H..M}......w|(K.J...2.i[K...$.KQ.....nhY.Y.........'.(...l5....r._,f.......S.!Tz0\...F.q..>u...T.;..^.......9..9)~8..."4\.~..V..=i.....D..}...FlO.TC.z.<.H..Z4[....&{ .c`t.i.a.LzIg...&)%...<...nV 8..N[SE..5V.....8...................D._..OFl..D....yfh......lF.d.z......1.....N..o.$.7=.-.q(.es...rQG..h....V....9.0.F.3...].`^.(Z..q.Xje|3.u...N)../.....MXZu..LX..c.`R.x(.....i......t.`^8....=..E"T..jq..xp...[....].w'[g....)..!.....G6...n=..2.n........Z.../...%.5c...X..m..:.T|.._.}g.W.. .r.f.B....q...y..}~../A.`.Q}..@.).%-:.K...B.1..V..p\..#.(..3...C.p......>g.s.....g.]....U.P...g.v...G).
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1355
                        Entropy (8bit):7.8674612943672875
                        Encrypted:false
                        SSDEEP:
                        MD5:AC7B09D04BF224CA4A0661289BFBA14F
                        SHA1:3075848F50B45BC9FEA061DE00FD5363BAD09AA4
                        SHA-256:E6E1DD8BA8C77709B009A0AD64656F75F25AC5BB229C06B19AF59005873FD2E2
                        SHA-512:F6086D4FEBF5BBB12FCD28405384884CCF0EC2FA79A6EC4077C75FADA42E5738A0737B32C926E74C33D9FC6C5524C7CA5ECBF413F4494F5FA2A1965223306F4D
                        Malicious:false
                        Preview:.bU..d.=.....Qn!...s...G........!=...i....j..[....>...\.n..N.K!.......y%..ij..).oC.X..J....aA.......>.05`....i.i...lS..6.%6.i..Z)...>=.u=..........b2..{.<....g..>|...:.P.I..O......6..KZ.....+.S.8.(K..T..id.o..4.~..}:..."h... ..k...D..I.^c:U....}.......S/J6..q...g.wU....3P.0.^"^...Q..F.Xn[....PB..p...,l.N..t.`. .[...f>.O.Zb.H...i.....J4......Kk8B[.|...V..H.s.....1"Kk.......(...........X.......@.....d..(...\.O...cQ.!&.*..P...4#\.x..jT..*2fM..t,...p..v.6..t.M.J...@.6~s.z..12.H.`{.>.......E.H/...}.....:...z\.9"(x...u...dL.....n...F....._{0..k..z....h..$..........7.ET7./X....Q.K....*<...=...-.E%........?8..'=z&!.sF'...U...........j..t....c.1.:.a)u.?......)=....XEl|$M.2..>...Hf...I;.............h..g.M...5.+..&bk.F.5D.p.1:.Hr2....U........(.D.Fv.d?..O.D+.....Str..j/.%.7..m.=9a..G(..v..C@.f.9]fK:2.N..aA......x.1.E...B|..{.......$..)B..8}Tn.`m..~E..z.c.^........F.i.B2.eB%V.^e@...&...p..k..^..f._....M.)..-.Q..".wV.wi.o....@m....Q.VE"..a...vq..&B
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1354
                        Entropy (8bit):7.851793730137431
                        Encrypted:false
                        SSDEEP:
                        MD5:F9F050CF06CBE05E2317B5377D357DF5
                        SHA1:ABD7437C3B6D3B9C606CB6DC80FD29B6EEA049E8
                        SHA-256:3A88753501D8E28867A8FDA7A488F75EA2CF05584F467388EE94FC9D108AB350
                        SHA-512:141EE0CB945B771BF67910EFE3928F4C1B86EA53E6533B16E8EA6B12AD43DABDEA17F6EAE52CEBAA042073DC8EDB4CD4AB449AC3BBB8B47DFC51B4294A8169D2
                        Malicious:false
                        Preview:aQ...=..5..+..gN.....s.....{.le.k.@?..wf!..r...d.S.PP.<*qf.7[..BV.7.....|>!..+..Y .._'4v<.[....l..k...n..t.......k..% .TQ..y.....}B.._j).*.kD`2......A..y{....kSdS>M...,...4d..0.o..b.a.T..Ac..%T...........y...G.h..%?......n..#.=..l.2.%pd-1.gk.....Ri[_...n,.......g....8.:.....<..T..3.....x.9.o..7dI..x..-7hWn.C........K...h...Tw+B.c:.G........I.....e......v.( .0.n....3...-.......s.9.....=.4/.=.o.s...L.....0Uv#...f.2D.....#.ce.L?.9wP7......`fwX/B.."?...........w...y.R.4.y...s......a...C.K.[...x..%.;c.(d..<.h.Nm........E..l.K9>..'....i...-!.m..hdDc.V.......r]..7V2..d...U..$...:~..}X:.0.%.fKjo.eqF..J.|j9Q.M&..t...K.{......-._....y.)5q...w........S..).../0q.T.D........K7...T....G...t..o.#...B..i..;.x....9..GU...X).ig.w;...L.f.XV.6.*J.o.....?4K.su....Hx|:J6.2....~.Zr5.`8XeI*.J..k.m.g..\..K:.Z.>.V..<.k..,0.q..Ahye.l.....6..6.].....T.!. O.8..C...^........?..Vg.P<.P..'..o.`.....k...(...{3............m+.A..$.e..../.-,"5.+0..'..VJ.N%..f..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1354
                        Entropy (8bit):7.867465620111182
                        Encrypted:false
                        SSDEEP:
                        MD5:F28446A18828849A1AFC1571E966B579
                        SHA1:7F37E213450B1030EB5DF664EA3BBFFC22F3DF58
                        SHA-256:2C768DD9C4E83A889C9421F5F57BBEA26D8AF4D9CFDF05A8CF5C097C8DA35DEC
                        SHA-512:224174F8D0E892392E75134E806C2DA645A3D59778EE8175E4F9F9EBA7C45232368682DA2CC9C66F14F1D773A3C816B33A432F5C2352B885F6B3D14C77C98831
                        Malicious:false
                        Preview:..d.:....W..gB.8<.z,..'..#?4..b..$.b.W*.a&s.O..$..R........{g./......\[.t.>.#...5'.,.g.).[<..p#.....w:+.U....}$.8.........K..e...E...U..BdO..l.q.yd^.a....lj,j...|....y}......Us.S*..9I.....C&?...].e..j.cB..u..:{.].&.Z$...A...xo&..4...s].`d,x>....+....s....Zo.P.6Z.qp...t5r...."+.&P..,{q......2.1c..f.........n". <}....v.GR.....&.....Q.....)...3..G..).D. _.(u&...2..nH2.n......d.. !Ra..# ....H..B..o....).FN..e.p.yx......u..m.g...E.>.....8..}.x.3.zo~=OE;.....x.U..d{u.3...R.*...m.....U=..-..@.Jz.j...Z.rB...g.Er......}qL....L.%.C.........'.6P|..(....0za8.uA.g...lE...P.N....2Rs7.t.........H.K.w...N.16!..Y..Yq*..\....N..H....D../N\+..I].?^...B.<j.....lc.K....-.Sww..tk.^A7...S....JZe.z^...H..:...V.kQ..n,..}.Q...;. 4.sK.$E.w..t.\<XW...V./...k.#...._.^xJm.#......c..6...a..dY.&vS..e*...o=.....2..s[Y.K:n...\.&.Tu.r.,.z.K..mw.A...?sC..V.x%..|....j...xl4&...$..3....w..*.l-..CW.q.A.P...V<./.b....&a.4....*..N.....M..X.....)?.:..0.?...V"G7...Z.:...\|..`.E.e.Z.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1345
                        Entropy (8bit):7.856548586589939
                        Encrypted:false
                        SSDEEP:
                        MD5:3E3D2B0987BCB462E57A4CE25A44D748
                        SHA1:E7BCE63B8275494B582A768CE723CDB3D94B1F0F
                        SHA-256:8633A6B61208785FB761CC438EAD2C23CC9D95C50BBE8D1AC98E7A67F8942780
                        SHA-512:1CEC078B417727411062F674571E34BEEA4109197266235671863510464D984BD92540D624FE02CCF2272C152D3BED0117D92481B7CAAD938FBC79915102168A
                        Malicious:false
                        Preview:..x.QJsZQ..SP....9...|/8.:.N....-..o..F...BQ..^....0r.l....S.z.l...W\.k....qm.5.2...O..\.}.Bmf...Rg=....#..x!..o_..(.>$.D......_...".3.....k.v.k...X(sP....@.h>$5..tv;N.4,..I..wLS.P..y...{=O.`...d..K...r.ED..>.Uq...o.sL{.XS....E............1..A.(V...JO...[.L.=D..@.Y.nt'.FH3{....wH.v.l^....yG..$..b<m.$@\]..p\.*.I$........m%r_<TN.....+..L.W...4.E...l....V....).!.B./.lN(.....K..A.>d..`]:.\.5.JQ..Vf....6.}...G]...V..E.. ...o.-)K..._........[c.M"x....f ..s.)+..t.E.....O$.^.Jn.2..._ ...?.O.w?<..T../H...x....+.Yo...c.!l..u..RN..Z@#..P....^F..T..k.r...`..A.w.,y....U..&....r..50..B.A.:........V........3..=....z14..z...o..../H.oZ.S..i.e.....[..)RN.S=N\.2.Wu...E..Y..H............yvU.u......D..:.'0;...g....W...Q.<T.u2v.g.^"|4.\.\....1@.B{.............H.....b.w:.w-1...h...+b....`W.......&...$..K:..RV..\..*V..h.a..A.S.>..pv#..r.6HWg9..=......J!&*....*T\..n.I..I.#{..9.!>..A..h....T.m..P..._{.F.}h.........z.hk.C..}LF...=.S7.N.....|9.Jo..I>D...n.!.."F..5.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2315
                        Entropy (8bit):7.912187366365332
                        Encrypted:false
                        SSDEEP:
                        MD5:9BF82E9095BAB02CB49346BB9D437E01
                        SHA1:618B8B9ADA6A66A4B181F742F43743766813800E
                        SHA-256:9DC0B58528184120EC259509787F55D368A70308EA0E7ACFBE3268FD5FBB83AB
                        SHA-512:E09A53068701540349F28A9980208876A0B66CC1D4E682EA98F5D6DCE9B921DB3C6CDF5A5B67D7D277175B07926DAAF7B15DDC951C97A7CCA0DD74E19BC4867A
                        Malicious:false
                        Preview:T..;o..y}L?.Nf[..$.[4..(...np....T...#......./.....b.J"..._B"..R~@l.Q(.Uv3..T.....4.y...........W.t..lm.......v.:..Q`.6...p.P&h>.-..Q.....V>-=..?h...t..q..^.....>.1C..yk.U.._s.E...i.?...B..1UdEc...Dc.M|..1.8/...k\R.KS.p...=.L;..0.5F...]...q.iE.~..~..d.|.....i...x{..|38.E7..I.O.N..1.C.#7U.uQ...y..P.9....)...|.+R......X.VTA.....a..).p.H...U....$.B..H......g.4.).s.C...n8!9...U.4~3.u6..3+z?.ln.7.g^.K_..*.._..MF.Dgs.Zy(......pC.._..E.r..y...#kPJz.....EW..ZTL{........G~.cC..o..=%.z.9..p".~.8F.TA..S...1.%it.6...#..;~.Z"A1..L.s......8P.,..z..&8.'V.N%?_..=..j.UY.~..Y..).....3Z76|.;.....M.%6DI...\..[7...........G......u...DJE....D.....AX.yr...o...W:..\}@."p_q.r..3..1D.4..M..P....-.p..W..A...h..t.....*G...T-..e.."...a|........sP@..S._ ...z3._/3wi'.u0...C{$.=tn..YX4x.(0.....M..:.E..J.X.>.&.M.cU`s.,X......l.7J...&.5.K.>:)qk.^I:..T.4'E.....T.3wi....h.x..{.N.....m.8.@....|.@i....n".Ed..V.xr..n..:W.q.E.......r.M#..3.Pqq..?.6.....=&..G...#.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2310
                        Entropy (8bit):7.927526912174098
                        Encrypted:false
                        SSDEEP:
                        MD5:CF05E67AD559BBB96A4B875E2726CD1E
                        SHA1:DE3C0C07B1788C9083DC3E414F1834B2AC49224A
                        SHA-256:9D2E7012849B11FB34232FAC35C4CDA5BD9409B62C6E06771BA60964551CC535
                        SHA-512:59C361542DCFBED02CD64309E10399F4A07ADEFA9A7C78937BF127A460BCC7E3B3DBFCFF0CFFEEF5A5E543AECA5828CBDE5B7076DF92EDBB168285EAFB875FF9
                        Malicious:false
                        Preview:-.....+zT.....%..._....NK....A.....M...d.:g..M...-..}....G.v{..'..|H.PT....(.%...."v.tz..?....-.oZ..~.......X..|......G...sf.tTv`... .z.. ..tT#...)....(.rC..{{..P4.....&.... 7.=.!..k.9........k..6dd.C._\-.h...g..`.....Z. ..x1.........\..l."<...0....#.#..2.Hj.7F.D.e...1...E..*/..;..<6...JB.-...xmr..8..A.........I/<..N.z.;g.5.ts:#..WS..1.6U.U.U....`......_hy.Q....k...k4....k4....>*t...d...{....l/..%.h..=.%..M8.]....:..7.Bs#E$.:..?...u.3^.3..j......{(..Q.J.x[M..h....$....xm.pZ..n".["$.........x..d..4i....#....B=.`......R..rru.t.Z.....P'Ix....j.@yi~.o..oT.6.D~..n.'PW&wN.S]... bC..6Y"......&.M..1..\M....%.n..k~vS~.:....b.;e....j....!.B.l.F...|...<.jc9.m..Q}...0.....pN..W.O..n(..Jlq......*.I...B./l.9...`.q!....nKXx3.....?f...B...Y.J51...v2e.....&.....X.....M...r.uw....aw..5;.x..U./.g...~.../.5...IS..@...X...m/.2.7.xcR..&....Fcd...}.?x....=......AL.0.6./......+D]..vy.R..P..Ei....|.y.A.....Y.-;E..$...?:=$F...S.K..o...Y.k.f.).>.^..D.9xO....s
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1352
                        Entropy (8bit):7.837829700560088
                        Encrypted:false
                        SSDEEP:
                        MD5:55B241D09A0F12E97A1F5CB5879B2006
                        SHA1:F46DF5CA81ECEC0B8FD2EF90F5389311A339E16D
                        SHA-256:B99D70AE40071BC155DE00204D98A598D1ABDF8E03E1C2D6E7004DCFF2BF7968
                        SHA-512:1B3CDA064F3B9F6C026F32A574D0FF6C0FDFD0E60C773F6A4F6AC87230FF9CD8ED1CD99FCBEAB473A4BD810D6654E3B37F98067A4094070E83D31F62A5C9F8C4
                        Malicious:false
                        Preview:.>`.Se...a)A..$>D..AU..Z..s....K.y..n...+.UUb.......Sv...}6...Z.x.Y..p.T....+.._H.1.l..]#^..^...`X4v.....;..(....s.*b....G..D....hb=...Y.\.h\.g:..{....x....0.$4.9Kn...@.o.CA.5./.^.+.......|...$....#{e.X_..Q...s........TJ......iJG.....Z ..!.[Z.j.UUO....B;...,..;K.}...?P.R....6.(.....s..4...._.... ....u..)...Rar..................gnWw.B!.....Z..[/8I.Mv.4..2O..C..:..(E.....rh.....%d...@}....tW.+3.l.{.....D.)..M.v....*4../`u.X........|..l..d.]....".{....yFW.1J.1......7.TB.^r....i..W..6:..........y..j...3...~.no.......P.Y.Fij."...U.......O.....S..T.&.4ol.*....!......S..B#fq8.c>?..._M.Y{%..v...(.c..u............=z.......F<HK4....?I(%.-qa.D.e..d..6._.....^..}.a.A..v....:..9...C../..q.0k0..[=.`Q.6v......6....\.%{6l.c..........Eb+(|Y..6.cR..M..,G..<0.HB.#.-.:....L...a/.UE[..K..G.*4U.(...?$.;..".. ..K:.:.5<.#...wl...7...`.L.@....Y...?.F...bzv...6)..s.K?!.6..w...xY..?2;.?..S.!} ?>.g..yz......7..w....{g.....f.z..e.....R...[B....1_j.G.x.Ya.W.e>.....a..e...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2290
                        Entropy (8bit):7.917289790876229
                        Encrypted:false
                        SSDEEP:
                        MD5:7AAD3A715314B43EBF298156D15CF1BC
                        SHA1:1426788C7AE1A60C1B609FD2EF0DF84F8F9F16C2
                        SHA-256:ECC094C398DA85640DC2B941A4E49353C1B2A2BFD8CE46AF710BFB620458FF6C
                        SHA-512:5533C8108EC610DF0821E28B40C7A4F6158176DC459E3E6B89AE88DF3E51D589C363D1E0317A4AB4F662CFCD85C4FFF7C8A2AFCF6D9E535E85E7681D5E15FEB6
                        Malicious:false
                        Preview:O*ER.)8........}..f|Z......woM..!..;.....\].]..|......t..IpO....K!.........e...&w....JW:..L..x.)Y....H'7.!..l..W"..o..}.'....j......?7Q3..$+.......'$....&..<......@.....x8.Bd#._G.h..4g-...)...*tV...N...'.k..\... %.u.....j..@......+.....z(..M.......W.....D.'{.5+..+Y.t.!...#H..nq(.q.!_.'.f .:..:R....d.....=.~......B.F[l....fO...3@.r.|...............!lh.-...7.eY........Q.r..s>.(...[.w.....4..q.6.2.......F~t-q...F.L[.1...G...A. .......^..MN. 3QI)..n.O0<N3.H..k............:.!..,7......F}.....E.Q.....v.C..}..#.b....`.....x..:b.......M_...4o..q...P.... .{.....w...r^7]n....U.6...Y...h....x.+_..K....r.u.........WhA.4Y.q.>..-.....Bnv...Ow...;=.x........l.b.M`...Q%.3Xs.:.2?.Q.....T.}...@..."..!...o..\Ie.6K.7.n\x.._.2D.....=.4.~...+......P.. Q..,=.....b..Q..6h..z>1c"0...J............N..."..U...F.j..D..M.2.......gE>...l.&].{...e..za..Ow.kl6...h`....-.....w.%..R.+..L,.R!.......ls.<C.l..zDl.M...... ....(1X.x+'')M...#9....)...._b..aM}....g
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1355
                        Entropy (8bit):7.877840970422042
                        Encrypted:false
                        SSDEEP:
                        MD5:0F42A2EC1872EAD0B13300856E520F27
                        SHA1:FD91D20E202D11F2829661DF28B1C7E21FDDF143
                        SHA-256:1C70C56325B6E814CAE8AE53D484B0844CBDEE0C7532CF366A4430DB9D5A6366
                        SHA-512:2A632AA915983333EE7F40520B84270036B008CAEAC6D7CED649BA576FC1F9804CBBF8598FA73DF1D36A81F0D07869D52BA9E9DBA5F3D2804E24EA7DD47E1C66
                        Malicious:false
                        Preview:WI`..w.....R.+.-MT.yH..[..p.`<j........b....UQ......W..._.[.D...O.u..x'q..l.+N/.9.<;.gw..U.p>p..Q8............B..Y.q...S....%....|T!$.z.P<......-J.(...4..MJbb.7.m........Z......V[...E.|...i..x..(.9w.........Jb.. I...TQ..Hm.7{..8;.c...m'....u,.m.,M!V...~g......Gd...Q..#g1>*..........*..)...g,!.?..U=2.\...\....6...Z..z.....L~......].........,...{.i]*.]b...IX..........qj....n..4.c.Wzw.g..Q$tt_.w..X)>.....&..l>av[........E..4W...(.R!.....V6...A....1\.oDz....K.8.d....>L..$d"N..D....z......,.....K.....|...+.sB...:..8uM.w.J..{D...c5.X....5_..z..[So..8.fro..3$...K....E{9|...Q.4..m~.S0.>@...Z.x.`F-....z...*......5.....k6$..N4..B....MrB.,........pHHj./.N..hc........J?.g....a.M..>+.K.L$<I.n.z?.b.N.....C....S...Z....D...V.7s.........?..J.M...p......7..(.{..8."%...%.Mr".c0xJ...'d.......FW.h....=.n>b..K:zw..C.Q.q....~4B=l...h.o.U..Dt..'^...d'2.)..7..]g.Bqw...]a}y*x..Be..t.b3.../T..p_.C&1..L...d./.../s...H....T.w5...uj.<...S.....s.1...i.{..N.T%zf.=.Rh..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1349
                        Entropy (8bit):7.817326882179333
                        Encrypted:false
                        SSDEEP:
                        MD5:17BDEC761E56DA17D27AE8395BB2FFB3
                        SHA1:4B54FC64B6ADD8E351EFF578BD949B1F8EDB2F88
                        SHA-256:34359463222C266700235E887B91F387471631E025D169BB59AA078D4114222A
                        SHA-512:0E8F3BFE542A460D3EF990082F67598BBF6C4E5B5ADEC7D87F95E36E2958D0634DDD9E7C6016090220BCFCA58CAE56175308ECE81428D9774546BC683DF2CB23
                        Malicious:false
                        Preview:.(!Z%.*.[JX.kE.Zc,.q[.....x&.....X....M/O....#...Hs.n._.$R.............1..%.H..t...$y.....N...DS...[l.u..N.f..8.y^.dz^..lt.>.h...'...u.S.#.....K.u.5..4T<..H....)#..C........#.W....$...(..X7.s.."....\..V..h.~4...1..>.H..D.8X$D..M..6.s.....#.$m....A.cd....\yn..^.u.o....R.~..>....6.G........L.&.(.=T[c..v8|...i.[..2k.7f8t.....B...i.B ...a...^.... .. .....50w.H.....Fh.'.39..<...f.t.&.}|@..~]..g5..wU.V.[.Q.3....T.. ..A|.0u.J`...gd&~.........n.,.b(0f......?..=C.>.l..b.qA...G.T#.."...$.^... .^Qb....N#.".1./;t.|.&..M.N.x.)(.-.s..R.e.-...(..V.?.......r..i........".....!.f.E=3^..|n?..y..B.0...P*T.63...0.....V.,QVn..0ne}9..\..}jA!|..*1..].QfA..I.S........?\...w..`\.PBtd.`. .k.$vm.M.w..5.IL.b.....t..`Q........>....G...ig..1A........(......c~s[....po.[.+tQ>..[.V5?..@........~.(x....K.|K:.......+..^.N. ./G>......z..1.i.......d.JF.....(...Z(.^...?.....f...|..(..w..@v......MCc...o.V.@..'W........X..!HP0aX#...@.....i0.",..u].9..|...D....H9..n..".u
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2455
                        Entropy (8bit):7.923269588246222
                        Encrypted:false
                        SSDEEP:
                        MD5:37468F6F5B18D777863A69DA17CE14F0
                        SHA1:BE2E0D9B28218B93EB14FFE2E83342DF9B455D22
                        SHA-256:D038D15D2F8C11A7C0A454D48951035EBF20C2994A056B0C7B88BD6EBCEE2F13
                        SHA-512:CD5E5F99D54A622069ECB1A98AAE231D08103CBAA2D9173F5636D7DE96AB682A1442950189ED2574F4EF1E77800467336E1AEF837DF7652BF7E5BC9666C114F4
                        Malicious:false
                        Preview:@..8..t...(E!.E...V......w....a.8..(.N.g......}..~]...5.c....Y./9...Jc...... aFz....._.....#.......?.(.1...'....k..@p*y.Y..Js..[]N=.OR.@.0...>..u...kK2.SJ....^th...\.z.9..B...j....G....1}e...Y.sn9....5w..n.+^Y...Q*...,=jc..)O.y.......S)..XQ.....W..M.....}.i....)5Y..<..s.7..$M.;.\...F.Y....L....l..e....rw.QyT..9.7.7..8FaH.....>i.8D.Qa.....~....H...1.n....;,.y.:.>3..lM.6d.].........`;o.R..qMJT.E.{.GS.H.7b..[WjW.*/...M.m...9w.o@....o..Kr.........-..XW[....}@Cj....i{..........i...X#..GF..F...2a......M...i. .X5..U.mA.Kx.~[.ug..=.,6.d"8...?...;.,/...4.-.N.s.e.#.SXF....$...D.@......Qi.C&..&..hd/...x..Tt.a...-..:..M@.....;.@_..?..)}....p........../Dt5./ x...[?..f.1.....'...{.>.U...........\V.r.\..Z.. ,...6..k...7_z...`..G......yzb+...:If9..Q....[/wm..)..|u.:.0..U...k...6.xp8....\.B..X.0V+1.+)...Q.+.(.kS.S.W^&.......6..t.....i.:<..V.t...s.#0.H.M.c.B.T.f*7.L..........-?F....z&..p.<:L....B.s......U......m..1.4...>..,_8>.~!S..g..{.k........z.....O&./
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1351
                        Entropy (8bit):7.864330602586891
                        Encrypted:false
                        SSDEEP:
                        MD5:B9F707F152D3537B239A85824A61DEA3
                        SHA1:F3B470EE694D48E5E74B25AD86F517DFEEABEF46
                        SHA-256:B57BE4CAAE137527827C0A7560DA930E35891992412D69A50D5693F3A090EC22
                        SHA-512:3D8269E39C60CD8C1B8CBF5665A8DC33A50FDD3B9B409086C75AE8003FD238FDD7626BAA50C3018116057E60EA807F40625D46E55428887A332599EAE682857E
                        Malicious:false
                        Preview:&..p...^&..j.X....S...1..}.....Wl.......{...j.#.2F......<.5.2...}......?....k.c..o..d&.w....Uh)#.mn.5.....?..r.j9.z..]....<...v^.E.B..J3...C~V..02..........`m&2/..I....M.s.x.P..[...).G.....u..{...E.........(.w.X+....J.H ...$k...C..y....t9...i.m......N..[-z........CXd...NJ...k.W....9.UA."5...\/;k.....@c...9...<.......d.f..B..S.D\...f...ip<|...'(...../?.......W..$......T.^..vQx..(l....K.....)..........}H...`...GI.As...K.N.N]d.../..X..+.....(...A[.+K.$s7.,w6...3z#.....]....."k2..$Z......m.4.Z.".x..........<P...c#..<.Gex..l.d..(.]..'.o......+X.d0....K;..X_...%...'.r.2...bU....g......K.H.)qKD....c..@.i.Ao.?.N.RV ..n............8..|.C(.g.+..;m..*Sa..@.,........Y..$.v....t....]......W0..6Q$.X...(."......Z.....t....=Se..5....X.....w..U..cQ..c.".6.W..b.M.v......<.....;.8O.....).D.e6.%...K:...k.?...Z........#1...........HA......I.0Qj.N7Y..2....P.3....4.>.xP........8.\.x5...Lf.lY.).Ju1.....Bo...V@2.......a....R/...@........?.n....7.c.'.|$..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1347
                        Entropy (8bit):7.86389303113841
                        Encrypted:false
                        SSDEEP:
                        MD5:F74DB6B917EBCF6498DA7D4C03A2EE6F
                        SHA1:41128D83C26718C1E21997A9762B190B7F1096AF
                        SHA-256:D1E99514AE47D4BF0BE642AFCCBF744CCA190C2B7AD7440C6B8D48F2FF3376B6
                        SHA-512:30FC0A847BB48C0290B0C1BD2861502486837471E25300DCC85BABABE97F671E667266D01BD65F6BF69E597134D2D4C3CE3426C69D62224060A0F6ADB45C4C20
                        Malicious:false
                        Preview:..._,3!.v...../.....8W.".-.)r6>>.(.BO.lq>k..y.L...9..6V`~......sj..v..+k.<..Y.E..74.C..m......\..........H.....|~3....Fq.?PU.s.{.x&.....>Y.j\.f:..e.7.%.=x*.Q.}./..7y.L.tM..\$s......"p....XdS#3{eR..[...._}B.......,n......w.8..g.%....u..T........~...o4_..F.7.:.ME...........7....Y......V........^].L...=....Z(.f.......r..l.w(..*EI2.P'&....S....7^q,./...+.?..Y aj...B..q....E..+`.^qgy...Nq.Q.M@t...|<.gn2.....-B..O...6#.6...r<?.l|>.d..\i9.6x..............rZ.8..."..kEq'....[9..l.4.x.;..d....+P^~.7x.C..t.V.......p.0.3............#..].,...2w.W@)j...|..Q.c...4X...#.N..0q......~...7C....|..$.$K.....";T.wQ...^...H<..3.M..|e.t._U..........2.._.6.ZH{(.CK]....R.b..,Z..X..L.bO.\.Bg.q..-..*.6.....N..#/.,p{..e.6...p...7.:.y.h..Z...[.h;....n$...D3......0....N..8S.xs.veD.S.("..S.u.G.Q..>..^..+,.<a.U.Y'...6e...K:......[.W.f...8.......W.(.1c. ..2?..wd.F@........L..5.x..G.C..,A.o$"."s...)a>;...~.t.H..@..v=[.. ..6M..RVB.4s.z.|bI.l.;...d.....+j..X...r.6.$.(,..n...g.?`.R9.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2310
                        Entropy (8bit):7.932606902557657
                        Encrypted:false
                        SSDEEP:
                        MD5:DDE146F80723F6142D02CB807B95DFD3
                        SHA1:948F04CD97173EF8FB29CD09A64149CFA61A89C5
                        SHA-256:278374D8AEC85467E503DAB392FE2AFCE6F5BABF438BF6642A4D1767D025D218
                        SHA-512:C75855A0D76169E08B0E795D10D1C1066AB665D9DC0621C3853BB1B8B3591664DDF25167B7EA739AE6EFB57CC4E4A5400AA40788F3A7901BDC8C2CA0A617D608
                        Malicious:false
                        Preview:[vs..}.B.u^/M..@..:].....m8...(..Y..:-...r.QE@^....t.Ot..?..Y|u..'.....I...ApR."~3....M..pW.F<*Z.D.];..f;...p.I2.. ...<1...?...)...>[).......Q...!r....:C...0.NG}.....Z.r.bj...1c......M.}$....@@...D.........g.....r4...h.y.%mS:?bT...e.$..y.~.2pF|.....Z.......z....E..........tS.E.j8#e..s..7......V[..s..k_DS./. ........S.4......Bw..m.....*1...:V....>.r..I...i..Q......j..?..Dk%.V.5...{RP|*K...#.2.,..@xY;S....f.A.p...V?...Y......[y.^a...W.D.+.>...t5.FW..:VP.......5+..;d.G.cJt6.k.=~.H.+C...5\...rGls.S.'87W1..f.....|z.../..]Sx#.>.fn...a$m...|d.L.c2('T....$Q[..kF_.[7J9(.QK\$p....ou,...3...E.....NB.Ok]sR."..s.`..-.2uFz.O..;.[]x.#D..T......&.G.9f..Is'-.#...BTe...b....q..J?.[....(....m...F......wW!..4.y...&.5'b.U..O.b<.......S!..Z.$]Ib.v.g.th...n.h.#..AE....6.6w...S.._......Zi........z....5Nm..j_.w.P..#..*..nviz..F.#.....v.i.LA0.n.O...3..BL.]....HQ..s._v.4.......P..`.h..`Q..[........X!.LL.I<.. .....2Z}3e..mo>H....>.T.uo0.F...{.J'.L_().a....a.iv.;....7.)..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6280
                        Entropy (8bit):7.968791946900917
                        Encrypted:false
                        SSDEEP:
                        MD5:5759B29DDB371FFABD3E434F6C5D0EB1
                        SHA1:88E7757D8ECC688CB52B54C22B07F10A566C3F96
                        SHA-256:EC102FAF0BEA52B6BE7752AA65BFE7881869452F9EB378B8A351BF38EAF33A35
                        SHA-512:EAC8244357176047FC08BC44FDB294F460633EDD470F346FA0722BC15EAA12E571DBBBEE2337FAB4D205D5AA4972A340256E782389B5113310C1272FDB3F1E4E
                        Malicious:false
                        Preview:?w...:..9......^....#.1b.._8.Z..zg..z..%_.@.{.r....'/.....d.E.h>.^...2z.`.(.l..$.jQ..H.?%.&-EF...:7.g......}.+..~.uu..$....4W.^C..@1I.Iq...pfi....?...v....4.2.8..A.."..gI..-s.ua.Q....o.%..&.+..+f...x..u....).~.Gi._=.H...!...2.\.O....?........2L..`..l..xcP...:.X.........0.v....:.'..MDP...|..e.\....$...o/x.E.c...H.ZHXb.m...!*.?.J.K....PaJo.M...#....vSdl....@.4j..E.b#9..'d.#&-...*B..PP#..j...J.y.AF...m.}...%5....^.<MP.b......Jo.........e=l..'&.k.....$..u.p...*),;.|gp...P.&{.l../1.)|...1..YK ..i.@......N..w}.,|/.i.......x...(..N...V..-..=.o. .0t[.h1r.V.{...&.,.R.7...../..5./3.V@..|...D......WR...........5......E.7..">.=...Q.e.].O%....}.Z...o|..].1.2F@..Q.~P..Ll...,J.]....kHw"...D>.a.r>O...J4ue.b.......p....^.U4J/9........v...>..k"Cb..I.F.S..C1.......]2=.6a...$....c.WC]..f..l...G..n~e|.uj.........ap..z..c..7It.........n0...|=I..~.M..;..J4i..=.10..6....7o;._o.K.].^[...4.......lI.B.t+x.B/..[..~...49..3..&t...qlGJ..G.......M...`.."o.x......G..:.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1842
                        Entropy (8bit):7.889355990753637
                        Encrypted:false
                        SSDEEP:
                        MD5:D933C0DE43E00D3E2329E2BBE094104B
                        SHA1:E06C9B33CF8701A2CCE6BC78032FFD104E60C4FF
                        SHA-256:1CA9631DDAECB1EDB510A6557F83F1F862382933627DE929DC14EB31C916EF71
                        SHA-512:6CB732F76155CEEFA260B3CA5C39D9C3D77DEC206B2C561F421F8C0651B6EC5A7137034B42016C55955B34480034CC0153A0FCBD406C71F6022F53D11D9BE5D7
                        Malicious:false
                        Preview:.Z...c>... t....W6 ...U_|.PEF......*.U+#.Y.....Ot,A...5./0..V....s..2.w......m...%.K...%.to......8.*..)F.<3+=.b.J.N..Kn...5....a.. ..v...!....l........X.....m.k.......G.%.2..WI=P..-.=..-.0....#.X........$....gDh.L.3<E....{D..o/Og.t9..N.......vs.k.D....z#.......;P..m....c....s(#K.K. Q..>.N...9./.v}.U.&..+...~w(...v.`.B..A..wy.H,..au.......*..}..q..#B.R..j.....E%........N<..i..P<..>Gl.......n..nE..x...".....1).<.!|*e.C}.B(_...".u.7...S...v+rL..%.8..9Ed~E.h.......A5Q.?<.Y{|...E.0..gh[.S..C%.{..\.....m6.c.s..in....;..a.!..x..$.y?.=.)r..Wv...)..i..9. *z........E.4..._..V.h...|G.r.S7...rr.mN....dOG..k.......>.nt.r3.>&...Q..N.t.. t.B3.&.........h._I+:.T2c*...W..IT..>..G.0..h.....c...... k..9.....o.;..p..qu...\s2..v'4....KM::k.81..%.".C...F.......9.+.."Wn...0.W.......D.T.B..ym.....1.).ba...#o....v..4*......-....h..x.....dM. ?.5.g0..B=y.....M..#....\.${j.&pt...D..z..L....)!.,.].E.1y...K.>7...sT.pO]..e.od.#.]..>...x.M..W.)......v[.>q+.n.;.\.8.jw.DT..~...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1064
                        Entropy (8bit):7.832569186378624
                        Encrypted:false
                        SSDEEP:
                        MD5:D4F761FCBCC13F7BF80A48E3BFBC8AFD
                        SHA1:34CD56A577904906B4F2EA2FA87801C6B51CD98A
                        SHA-256:61CEB0E310CCD1CBF1B32C4A8B5DCD32ABA63ECD53C11926941C4A3B9A87CF0E
                        SHA-512:3901248814D9CE10E20BC064286C87DCCCBB5C83B315FFDC0B77A60EFB3D1C62A662E1720F5D0C2519A4E4D477A5EDE6FAB2C0CEE130C49943507BE66B463655
                        Malicious:false
                        Preview:yPKQ.BRXAP.O..u5.v..[LZ.....R..dq...$.f.j(..Nj@.:....\...+.\{...s..%n........H...*4..u0..b...E..Y.)l.34...*.X../m.s..t..C.S...X.>Ns...y.)...@G....auWp5'..,>.a]9.{jq..~.|P..V..<..Y..`... f....1.Z|..o..W^.z1n.+.z.a..A#./G.p=....&.b.6"...)(V...(......l.7......~..A.3>.c.'...}....u.I..AQ..s..-... ...s....7h..}.z..};.[.8r.2....Q.8....7w..c[.t..9...Y{`...C...V..s8..}..l...t..R..J....MT@ly.Ir.R.9......kb\..&<......."...M$.v............7C.k..)..\....\.<.(6.r?./....@....Tl.........9..pQ[S...(`_...dX...........zS.(G;3.j.N./....Z.uK:-...0$...+.+.C..=.T.z..pS.8..;..|.x.H..1l..#.....l.<!t..?..`...x..A....X.M.T....4.x2..+Rmj..k....i..!.u<.}.?.R..=....T.........s...bJ....L...*..+....s...".....L.[..a....'...$.... O..Gif7..........+k....@...Z/..mWa#U.....}~s.7dB...x..8E.B.76u..f.....T........L(9.]I5...sM.k....c.D.#3}.+i.U;...0.0X.)..{.9....s.b.K...V.|..(h....yF~............rJ.,..Q.....i\..g>.+.X.....8.>.....V..MZ..}n.W.=:r.d<v.._..D/.{.+...F....D...em.8.=:
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3878
                        Entropy (8bit):7.946905473466786
                        Encrypted:false
                        SSDEEP:
                        MD5:B1202FEC8B2C115B08246F26EFCD90A4
                        SHA1:AD638CFA5425C21950BFFA5D7EEDE396A5D9693E
                        SHA-256:DCCA7214BC709767759C3D6543CDA0DAFAA7495FFA325A581D2687E1E26F117F
                        SHA-512:F9FD01BBCF3C5A18CBB73B50FFD1E5BC07C192179CDA388D008DF4BD537E5A424394E7B84835565D2DA54BDDA6F37CF56217752EAFE79637235CDEBD20CA38C2
                        Malicious:false
                        Preview:..`V.@..M.9........J6..?...{.A.b.....4.....z...U.....U.I'2.....y."".....Yw.L.._......@.@%.O...e.?.5F.. j.j>......4B..w..7.....]A......e'.........X4b.Z.C...;i.s...L.].....#.@.....,..h ...X.1.N.<m+{8q>|........k..m..F.?......JD../T.%...b./C..=..Q..|.....!.my.._.f......T.[E.........`...II.J.?.....T..$c6..........cF].Y......o7..PO.........%...6..:... ....X...T.~...D..P.A...$...!x.. .{..._...Z-...'.p....?x=I..N.`.;Un..LV.lm.^..f.#}v....]..%...R.d..k.zm....{.....U...v...... 6..a.w12>.P..zL..S..p..?...\.b........:Lo(.G[......2hJ.DJ.$.?......N..i..B.Z.h...@...._^.n#.t..68..i).....dd......H..LR.V5.O...,..c.}P.KPs./~...Df<.Z.d.CBuJ.B.p.@.......,.[......3N.......l...>#.....o...k3.\.+.m4b.G..L.^;.n`@..Q{m....n<...t........`.Y.z..........o..\B9.?...M...g......?.P...:.7.*...\}.;...j[..9.......[...{:..<..........W..\....J..B?9...`..,.....S..e.m.....[ ..N!.#.a.6"..w..'#.hV,.?...5(a..L.0.R`..XR..r..1.2....s.....1M..>....SO...h...k..8Bp...'..U.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):13348
                        Entropy (8bit):7.987830421038074
                        Encrypted:false
                        SSDEEP:
                        MD5:B7EA866F83F1616F958FE8D83F8BB190
                        SHA1:3ADE53446D96BC201C1968257ED3589197AB8C45
                        SHA-256:1646386FBF2B7174CD446682D229ABEEA215639C94FFB9C48376BC05281B6127
                        SHA-512:B6B0641CBD7A8C6029FA50FF14CB5E0698844A27051EE8AFB36B1115D1213B3C7B1CFB7CD0AF171046E93D2D760794684525D9BB750D4AEBD58A4A1E79894CDC
                        Malicious:false
                        Preview:..;..5#8..{.....+..*n...q.....5+...6/^._.b........vz.d.^..j..h...F.}.i.Vlz.......j......vy..........1..@.^~..p..m.R.K......z.++X..qJ...i..R.Z 8L..6+.K...%gx....X...x^a.3.:..>.....g*.........hcW.aj.nm4......(.U..iX.4.........p.5#.2ZJ2\[SE.C.I5.....c.....yd....~....I-d.$w'.V.U.D....b......._..G.. ...p8.....NYz...T0|.....h.......k....y...........n.L3..........C../......x..\.K.>..Lg.\.k..7.....3.F..".n...'.>.7>.3z.*(KM...Z..P..DQ".$Wn9Oy.&...z..........!.R...........L.........1..pU&&D.+O\...s%.......y...n.U.c..xJ/P...}].`K....V..,.$g.[wO.&cH.Hy.D.....soU{..souSG......O....4.jt.N..g.[..[.y.;.E.....~5.......P...2..Zv7..H..,.;6.)^.z.;..La*.l.B.]..{.or##}V..0.S..q..y.\..2.....(.z..$.e.#..<.l..K(qb.`=.R.S.<.]w.W.F.$..z...:2...R!.D3.a.L.A...,L..u.DH.aOm.W..s.jw......e.... .S...h..-..}..<.o.tN..Y...4..S.~.D...1......k..>A.?.F....@-..._..8......1.".....d....Y..du..0.BQ5...N=..c^.>........6z...wD...3..<.......O....;.UFjV.Bh...xF...g..S?5.8={.....(....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):67786
                        Entropy (8bit):7.997162159411845
                        Encrypted:true
                        SSDEEP:
                        MD5:37B678C2AA3D801FA610790E4EFE300C
                        SHA1:AB4882F4EBE1309DAEB0B93A7CD1BCC7B81B25DA
                        SHA-256:578C14E30E4CA44A07F84E0322A6E0C794650D38B745E2C504EB6BB2E6D1ED64
                        SHA-512:A43C01E55082117FD18DC9C7F06FDAD2CC340714EDFF688B8A294DEC562DD5306073C2613966C86656F2CB8F665D1FB2303558D0409182055584ACA92BD7D406
                        Malicious:true
                        Preview:.......g....Bu#X<.F.k.$..H..?h./.PU.*+/Pr.k8..,...PJ.t..z..J......!.....MV..c..U..Z*.K%+XL..n....@.-+..eh..W..+...yx.......W."6..KN..D.?.C..=.g......9.c)U'...o....j..M....%....c.X7....={...X.j.4.......3....}....&..D..xn.._.i'.S..B...s....\..2|.FM$z..nl.......V..j....d..6zr...&"a...7..D!..b...z.uM....|g.....X....I..(k.....{...C../KQ..9?P.5.a.F.....B........IN..T...`...4....6.k.a.+..p.~.-.q.f..6..+.%M..E'Ni.....@/.....2!.K9.z.....E..j....k..c.a..6...zO.K........t.........:.7B.....?.; H./....~..F.f4.i!..T{......_..j.e..B}.l...w.t-.. UO....$@.'{.c...(...GD>/.2cW..!..w.R]*....W.f.........)..B..._.p.f|,...N...B..qM.-...@*>.+.-9.#m*..~.*.z.....]..P....],......P.iy.<W9.....^ b3ERMS.Pi?.Rb.+sJn..s..T..,.%.K...rS..'.A.l.ts.....#P24..-..j.0..L..f...0..Fq.......`\@/(KS.P%k.b..5@....a?....(8Q.../I...'...$./..y.l.Ph...xMF....P..@.m....5.+.r........!q*.P#......f+...KD..9..;..Ys.4P.~3..M>.Gl.H...._@s.&..9..f..l.-."~...-f.=.@cV...8..1.(w.fCdw...E..&.o...,c.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2188
                        Entropy (8bit):7.911428774982957
                        Encrypted:false
                        SSDEEP:
                        MD5:F3B5AD64FDA285BE005FA5405A0AC671
                        SHA1:F60CE809C11D8784EC3E788DCE0B7BB455540B32
                        SHA-256:B2E0039D1C5262783D8B64FED93D06DA1E483C9F3F21FC832C4789B05211AEC8
                        SHA-512:C262949078ABC8C1DD19FE73168AF570FCCDAC5DB2C66E1B485FA465B0EC648C6E35274E4B0E48367C38F81A0F1CB8B2FBE234705C8D15549EE463ABC272DF30
                        Malicious:false
                        Preview:p/`r#..i.f.J.:F..H.8..7.tO... 5E...`..1..Q....{.G...@.(..[R.`..}..C....].Yb..n.ax.&..C'O.3.g..t..._ ....x...Y.x..$.E.,8..=...%K=........G....e*!_.F..v.1....OZ......k..../9F.S..6[T&....l Z.<H......9_.n..F...B.....3.@..&.-........Y...mE........=..H6{EJ.....w..`{.>..|..we..}....o..0@......dyW..P..*...`.x.>.<.........M'.ZG9...'.Vd.B..n1.[.....B&..*A.7...7z2L..P...,...$..}.a|.Y........(...1.5.......2h.A6'.0..?...h:i.1Ra.#E....,... ..>5.......F...9#A..}./.....(....d.m..lz..F2..M9....J..>3...GR...?m.....>ab{..'.w.g...<.Xz.....w}.K.j..a.+W....K.#(.Anj1.,5g.._}[U.|.tKv.6.-.v*....."4....UQ...106...NFm4..R.&.*|.NNSS..d..7..R4....x.....LM[....6|..:.<..d..p....&!....X..W..J.....}f._wN.W.....{...a.O}.......n.!.qe....E..o........G.T....9..f2ShF....v$..U...W(U..iM<..)M.....+.....B?|H..\.=...|..U{7../...Z.......#.6Ar.7....c..].....F1....P.?.;m......h.8......./..%....mej.......y.i5N.S......k....T.....g.......4.p..'.&.....V....M'....e_...EP..7...a
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33298
                        Entropy (8bit):7.994671282547329
                        Encrypted:true
                        SSDEEP:
                        MD5:CA1D85BC913B0FE5C334D1F93832D6B5
                        SHA1:0324136DA570A014EA355807E60698A8032A1C64
                        SHA-256:6277B180D8E8DA644DD404F96130C8799E812CA40EE107B9BD8B5D12260078F0
                        SHA-512:AECCC32E88964A5AB8239A990C42BAB2C02A27B02915A0433D6765B706F6A052DCFA36FC5A391E64DEAAE2B8E6CE3D16067A4C71B7DFDB5B6761092DC4D0E6F8
                        Malicious:true
                        Preview:V..l.~..Iz..U.*1........o.'...........E`.^........]......jZ..^.h.............+>.6.H....eQ.>.J..=........t.z_8......4Wp.n...,XM/;Y.=.oL'...Z.}..a...{).UN...F<....^O+..J|#..........a._\ kw...=f...[.a_.....x..P.....Jc..^..._....o$",.M.....k.?.RJ....<....G...].......%...3....$..Wv..K/.....?...?.......p<M.*I[g,)...!..>[2..'..`....?.....[?.4...w.6.3....2B..|.I....*.....<.9H.h....*.-.xU....`.jn.....T:.M("q......P...&..?......N...WV..P..QY.A......{bu@e.>.!.4et...(%d....fmR.........u.B@..8s:5... .o.6y....2...:w6.v..)i.....6!..hY.+.M..N.=... .0.i9E#...5A..g.......W.L......E.....Ws...e...d.....x..$.6=..fX*.3....U....C}.. ..#..a.|2......Le.7w... .'|Y~A..).`..</.D.9;....5.S.....M..;..v.....8.3.3...U..P..fdkl....<.....F..]..|.-.B....].C.B1.4.....6&.~.....q...=....t.G.<.#..).Z..J..[_Os..-*Hxn....n.~.m.. .}<...qt.....2.,|c..O.$]-.'+..<@syJ.vD....w4.........i...| .@...y..E.1.....K...<-...~J....c....f...#.Q..6..H..(.k.....].c..8.....w...8F
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):34358
                        Entropy (8bit):7.994562058986842
                        Encrypted:true
                        SSDEEP:
                        MD5:A1C9240B5906ACCA6A5DC22B42B97A80
                        SHA1:BB317878584C43FCFFF2F8E018E94EF46A8F87F0
                        SHA-256:1AF24758968D275F32AC7FF39579D64FD42B0FC783C512669245A968799A32CA
                        SHA-512:58DD3854F9B95CDF10C93DE40181585850611C5FE34BDF10C6BB73F4CDAA4F48ECD63B4CA8462A49325AC49737D2C2A043C436F7B97F3938454BC769DBC38DA5
                        Malicious:true
                        Preview:.82.@...b-y#.(...E..z...L.....".P.......\...4X.......{2..~.p..T......A1yj*c ..t.+"n..)vI...g..AF>T$.@).$.(......} !..5....Y.h^.."..C.Fw...../C..8|H.pp..Wa..v..7..P`.)...?.].V. "'.....'[|.f. >..Zc(#..tSO_.Q.L.h.a!.e.q....>..Tk|........6R...u........`............?Q8......z...\..1e<A..5t^CQ43.......q..\.....-...P..:v".b.....r.M.....*<...!.(..u..Q.m.|.veN.&u.._l.X..Orf.K.".>8....\..Z.zG......;.L....Z5lk.o!.Z..N.q&rr........d.M5R.z..d.l=.>..p^....Y....@f.Xa.5....C..G..U..)..f.=..7c...8.$Dp..l..}..T.0C......ff..X....q....lp.j.]Y.[3.W.<.Z/.ZM.R.....\R..s...F.C..`A..G....[.`% .......o1.j....G.HZ-..\....R.Y,.!..N.(.?.....!.M.OL.5k.B....ZM....1S){...0...v.g.OU......P..o...y...k..f.Q..[..%..L..&.pq.....K]..].%1.ykM..%J..L.{.... .{X.s*..../P......[Y..\.i..X&?..xE...M0....+..ds.}<..y.(F....&i=.o6...=..?..._nWr..g..d.U../..!..!"....r.~.`.A..^E.aR.c..fO.X.9..h/....M.W...Ln.....(.d -.....Fi...$..:j)T.hn.;.K.#_..P.R.)AO.X.mi..+...I.t4M...z..1m@...R2..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):531
                        Entropy (8bit):7.584518882655562
                        Encrypted:false
                        SSDEEP:
                        MD5:F94C9A11B3FF3DE7724D351FF7C5B56A
                        SHA1:A7D70C9B60E7EB9EF62ACBA75AB082F167B03547
                        SHA-256:E086D6B16A995A31DE452379BEABA05372D391A33CB15AAF95DD0AAC06462848
                        SHA-512:3064F16BDE4FD8E68747519EEB54CF9635F4A0A4EE2E99EE1EFE2E3AB2A7E75047523656C8845020FA9E65EC066EC44B16D862A3BA64CFF23651B5A458E1AD73
                        Malicious:false
                        Preview:}.:wEQ.C...#.F.G(K:NMt........4..."....8.C.....(v..^T...A.....*;CNAL;.:)h.hA...u...a....).5Q<0Gd....4..Bs.=.r%..z.r../...X...C.......q...h..D.......G.^+...K..\...._..._.2...<.v@.|s.wynt.OE..L.X...+.U....G.Iag...u..!..=D......3....:..}....2m.........e.w3..j.:.....I.X.?k.....|B*s...J=.nQsC...6.a.F...X}T%....,".=`P.jm=...Mp.O6.=.X....z=...H...W..5..^...lpJ...3~......./...........q.......9N...h6R./..C..%._../.M..}..4#..b.(.:.P.T=.a.S.B...MO.....6K;.!......1"..^[...;..Q?..m...:...d..9%7w^...|......
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1591
                        Entropy (8bit):7.881955636583867
                        Encrypted:false
                        SSDEEP:
                        MD5:6A1AD2EEC226AC03528890550954A780
                        SHA1:F3C3630CADDF96CDF2045C99AF6C6E1FEE7F4A6D
                        SHA-256:0F8E8ABAD1A3E7AB2AC29A0D4D1D7AA1F2642C711E296D26F01E1E5013F267B8
                        SHA-512:3FD4B469B60FF92B5BF998FEE8BEDEFC321C665C94467C224911DFE944DC63A883A4F3426851FD75881A9D130278D8E204D98D67CED37131B3950BA8B81E8E94
                        Malicious:false
                        Preview:.VR.^.9K.(.....M.%m..^.............dr3.O.H.rd.NT....y..."...`..gU$.....\......(dkC.)E:.KP.`..r_......F.|..Zj;..U...P..5.....w.....2....'.....g......Y1n.&e...G@.l...eW.[.F...N...GfJ1N.o.c....J.H`..C..YRPN.Y..O.>+v..C{.0`........6c7\.k.k$..g.]\;....:...............Th6.Ua5F_..+...Z.aTp.hml...~......+\hv........u..Y.$...AZ.fK.!.Q.L.(.R..$.3|..Z.1N.Z.V..YU.{.......4.TS..x.1..Q.I......G:kl.....z.y.e..H.....i.J.......(M....I.......A|.R.mJ..rJuTSw..kJ...Ud..@.../Yx>...L.?.^.|.[.......D;#....E.d....MF..b...^...(....q.*........S.T&.R.9...w0;.Z.-F..?.L.{.H..P.@'..+....n.E.{.h....m..<..r.....t.......<.s`Q.n|M.y.... .)....r.^.O|<'.3.gtM.......p......Jg.[. .+s;.i...]D3..6.....jT..],..SM\...EO-.hDcf.d...(.7.J.H.Q....j.^.....6n.b@x.h... V.A....o/...,...Vp.o].[.X.OM......j.....t.LV^.)......hz.a..X..|g]U...|@M.WQ......j... 7Iy.5;..._.$.2....J~%+..[.}'.g.I.....B .`g......]."\.O.m.[...........b.^..#.....R..p.....%..R...]7......o.'....^..3r.].~..n..........N.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):13107
                        Entropy (8bit):7.986786053560389
                        Encrypted:false
                        SSDEEP:
                        MD5:BBE5769C43640EEF4C1CA3953119DA56
                        SHA1:200630C96E097932F12DADE1B0C1BF541FFF9BB6
                        SHA-256:0F480E6F9D73DA5AC5B6662ECACE2A6BD933CF3B19356F1BF6475CFD7157BACF
                        SHA-512:04955FDE9F25AA1D7DE922E003AB4811F9BB296F7112A655570C313961F06A0CB83235BE3A9571593F35BD832D5EA42434FA66587C563031CEAB6429A650FD9B
                        Malicious:false
                        Preview:...|x....._....[&.V1<..'....!..H....F....^...=..q...sB..d.2.....5T+]).^.5.2..........<.I.[...9.z../..#.b..c. (.....?Y.m,&.GT.A..jLC....;).0T...Y`..9=....udL6_%.....B..U6....m...|V.JD.SZ........^.RD....'.T.]&.F:''W.d.)..=%...^.^8..a.mb.r=.#9.@[....9GdE......u.T.?....q.F{.X.t..w+.-A.p......BXT..e.S.I*$....O....]..6...!.mZ...z..:..4.. .......7:..,.&?..s.....[...z..M/8].hb..&..e...o..IJ=..Ir....;..7....Ex.|.D.O'w.4...KC..0*...+o..}.j.}e...V..c.......9?Jy2.>.Jm....P.m.-.....,:..Nx$K..j....e....&.j....8....2L.D......'.d..}).g..D.WY?*.3.&.`.....|.i......,...B..n.K...k|...>..\PdH.U....J'4J..L.k`...&......R.>.....~...,..R..J..B..7-z.H.#...}.f&CMb..2.;.........Y.8.:.G..B...$F.1.m...g..m=21...M^.o.A....=....4.......}.>.O..h Vt+ @.+V....j.}.U.......v.l.u_..<. .U.hs...G.....:J...s;.]HR....7q..I.w!..v"}.vA.J.'}i0.{...T..k...J.0.V.]..rp.._".%[02T..+..v@..r>....VeP..&.....R...B.ma\8N.0~..*.."....2."..&rL3..a...$WU5...k.9...G.M.*.w.o.....&m.YC..").0...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):17444
                        Entropy (8bit):7.98957133422093
                        Encrypted:false
                        SSDEEP:
                        MD5:AFBE59A2941417FB6717C4B3AFEC0D2C
                        SHA1:2FE25CAC7E09ADA71D1C9C870893D5AC2EDE2A11
                        SHA-256:FE35F32B1FDF2E83844CE81C873144A38C569D59A5D2C58A9B1D1C64E30779E1
                        SHA-512:CE3ED0B8A3ABA786823C97BF45252720B113D1E62C6044D71E4B814D54EE7FD6ABD62223FE204D9A6F1D0DEDE3C9C9FCD95DE33CA7E08814B3E0CB4435E8FAD7
                        Malicious:false
                        Preview:a.5p..;....z..."...?..B.I..9..E..J.c.p...z....os.<...V...O|v..u...F.>.n....T.H..7!...A..ay.!D..........#......B.&0....... r...T..D<%3.5.@S...V...n.......-}.'8D.c.].w.....v.e..'.5.Row........9..^....j..a.......=.@....uk.om ....$..n...\zZ..".lA.@.K......q#..mA.6|P..z..9..}P.Q..]..\K.!y'.$4W)...$[H..U...).[.h.."(R{>.7.w..e.{..002..?C...6....R...4..[$-X..jT.b..'..UJ4..?..=...@W o.d...N....2............\.VGK.N..J.Z..e.'.9...!i..~..._."....|.a.|t.....at....N..j.D!.F*.$.S.^.*.?V..p.g.."..c9...R3.o......&..uc...}*..[....B`. .../.YL..T.7....k....yG....._.O....b...R.......s...Xy...`......%..lG(|=./.G.?.e...di.].....kX!.....Q.}q=.NX.`.j..`A.n.v.yl. SC.x.z.OU..2.d..qx.......c.DhHo.4....1.....Y......@X... .:.5..E....2NuS...R.r....o..rC..|^z....e...i.Xf.=)l...M.j...............2....Cy...aE.{..N.."..V_.>.$..$..y.%L.<F...I.?..e-K.v./R.........w3.>+H.@..x.tC..L...:.x QRu._g=.Sr............l%....R.E.........d..Tz...z...*.{......k...(1..m6.?1q.a..>..V..#..S..$p..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):17974
                        Entropy (8bit):7.989471578033043
                        Encrypted:false
                        SSDEEP:
                        MD5:F6A7EB4E18FE8901B200AE708799C06E
                        SHA1:BF0B9CCEE9D220EDBEB59B66628B1CDFC7664117
                        SHA-256:12C3BA683C1209DBE3AE248DB9AAD7D90C3A43DBA267E29B717EC111F62607C8
                        SHA-512:199A01FF48B57CB18A5392F7E7DE6455CDC1759F168955EA5EA0ADFC7B5FDAC5937AED2CE1D9BA81575D1E52A9846478A4FAAA16CFE3BA132C52BD5076DB1851
                        Malicious:false
                        Preview:.[..Ho.[...l.L..4NK.....M......\O.......9._...U:..(.p..[0..h.eZ[...\.k..[1M.y....q..Z..I.^[.a:..#....zH.i &...."o....t...~...hg=q4.....mqj.T`.tj.sF......83,.....H.Ht2\..`.".*w~...>...f...T.......H0.jsh"q.?R.......O.z..)X...w..9<.....l.d~o...,3......bb.L"N..e..6\..h.M..N...'r...^Z.7..S;3..(I2...4.a=.Fi..4...m...F...W..TK.o.)Kv..?-t..Q..q...*)...x..2....* ...u^.5.O.....+,w...9tV.R...Z.|.E.2...........+..U9Q....?....y.I..V.....l.......O.y4...F.%1.#8.9Tb.|...zM..Q....#....H..`...].xW.....R...U.....To....@.Gw..n..(BG;.B......W,%r..*....p.9.G.F...G.Am^.....ks,.*cT...........{-|.*..;.j2M.q.&`T.y.?W.......0..e^..._....n.-...I..i.3.\t......R...h...S...............7.|.~C..C..l|5=..6V..,...uLB.......~..k......Xq....= $.9.,t.f...E5..&.j.z....mw.."".@...M.a7.}".&Yu2..dF@O.\[uP.c.Z%e<i.....%....D7.s7.TA..D..Z....Lm.S..t..WD.~.eP.=0.......Q...eFk(!x..;.V...A^.Z....x..._....^...C[..0.....P...%6....m:~....G.k...kBL..|.Qx.+...8....ZO.ba.......c.#.a ..q&..n.:.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):42978
                        Entropy (8bit):7.9955107021514955
                        Encrypted:true
                        SSDEEP:
                        MD5:0B4E18A5310AB7B99935B77DDAC4E83A
                        SHA1:1DE4DEF56B1FE81C75543892B1A210A8734C39B0
                        SHA-256:7D2ED13AEA77AD5FDC85F0106AFFB67FDC39152A2A4E5E1AF915A59D2064079C
                        SHA-512:1D0DF600E991A4321B8D3DB82DA677F452E3D1AB072CCDE667615BA05A5BEB3BE0B6C26AAFD93C4506D191B4591024C73462B372BED71C0301D6E97D63B7BC6C
                        Malicious:true
                        Preview:..-..7!.;..t.a......E......E.N" /=K.....1..i.I.n..Vr....P.Y..u...{.e.Te.n........4jc...O..i!M.>....99.q...R.2?.......@....j.i.)+.D.nL.Ep.`..z..l$;.......AI.&.=.P:.F.FE.k.8.....+...9...G.7"._NC(x.F.4.".!ng..8....1r*u .rL...m0.z..v.....G..3bM7.......)....z'.1...t....`.j...I. ghy;$.DM...H..3.....O...&..y}.y...E......T....L<.-....k.Np.g...>..-.5b..H.......R......_...&X..y.7..bM....$..B+.r6.E6......z....p.I.p~@.m..Rr...-P..x.s......p.)....-........ .v.K..k.....M...<.@...O.3.;Ak3..K..Ub....*.@Nq.1mG`'.XHg.s.[....b-.K.<...W>..o..%';......_!...%\...4L.`...T....k.Fb.J.....<%.&.K..w..Q....l....o.+...XSl?..3.l.{....y..m.}5........[....=.0.7..K.V.z<..*.:.b+...4^.c'..Snt.....8..q..C...B...3..,;~...u]. K='...Q.Pk..0...npW0HF.>..4F.<r.....%....B;e]u...=x......N(P........!..v{..A..QW..i...l;.b..........U.,H.&...../..."..4#..b.......r.x.E....;....-.*P.B|;.;.w!..%..^.]S^..~i{].'...A_......$.S.b1.......c..[.h.U....s.M1...1..V.4.....il.g.L..NV.#{
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):43508
                        Entropy (8bit):7.9961731451203475
                        Encrypted:true
                        SSDEEP:
                        MD5:901AAC9DF9A61B5E83F4E64650BF2D80
                        SHA1:7F559FE3435243FC2863DAD4F1704A7F100C763E
                        SHA-256:0A40A043A1F924EF4D0A6114F7C040524B545E96C5EE4C7CB8C8BDB1F0411930
                        SHA-512:855BE66C22C3480C3B4B2941C7B7E0E307C8FEE8C831EE4F09B740E2BF4348DA908F13D1D117114EDE0F44C8C6464204BA4329D9CFBFC769B2F102E8384EB6BD
                        Malicious:true
                        Preview:..}...C@.....4'...4.VQ.m..4@L ..[.R...m......95Xg.cs.v.08......./.g.N.)p.....t......~...h..(.U..G..#.P&.{.`.M[...}E...+.F..,.q.5......=...%.$f3...g....V*..c....D..R.=h..vw...q?. 1...2p.|........l...zE.Q..).<G1.......V.<..QX..u..V...=..}.r.&(...L;Vs...CY..........X4....D.n9...p...Z.?...b...3..t.....,..........@.c.....J9..c..d"..*rc.6.....L..2&.[..?.........9.Z3}).vF.-H.%...8..`.*Hl.f../.A......$.KS.....i.4l!.[':.v?.1L.r.x....l..{..p9%$O.<u.z..E:..2A...$.fq...{.p=t.....>.{3m.].9.2...NMYl....q.......92S..+.a....j..n.GE..e<.6....@.>..m0.{&<<f......=......L.e.y.mL"'....|>.s....=*N..?v.Z0.@.0.JK^.WbP%.....rJ%^zN....j6m.~....yQ...R.'......... -Y.....a.......h_.....*..T.....1..t....bn...*m...R.1O..q. ..&P.#..._>....N.N.j....~.......Y.1.....r.1.....D.[x_lm,...d...w.lTv1.e..^|i.....g.}.....V...^$.-,......M.1....k.^.3I .S.9...N!Hc..r...."4..C............"..-S.7...V4|(....K>.O...ee..z}idv.):...6Ax..Z.P.9KL+...8...i........Y........;@*].B.......b
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):35546
                        Entropy (8bit):7.995101037389163
                        Encrypted:true
                        SSDEEP:
                        MD5:B20204E00AC75D219EBF23209A9B8482
                        SHA1:2FEADF38849A4397421BAE60138E260F12D206C2
                        SHA-256:5AB8853DABCEB8C73D7DB2C7590C772A62FD19EB676953B5354B907F65C25E22
                        SHA-512:226B30AFE934795EB8E9E45371A98D2C0221900A347881D6F997F5235EB296FA73B5C0DAE123BA41A2323807B45AA05C015625C9D2CA39EDD944A178C315F70B
                        Malicious:true
                        Preview:.9.p..<..!g...O.V.~.Y@....&pR.w<g.....7...=.....eo.0...`.........vB.7.5uE...>..Q...v.Qe.jJ...[..t..{r...9.=(t.Q."....>.C@..e.......?.,..t..Wd.....!.f...K\?......\#@.....f..S..d.@.v*..ht8i@.w...c.f.....).V..<.;.h..-.l.):..............%.g..m.D.zr..r.=s.l...a.\}.*+{B..&`.qR!P.>.....5.o..M..9a..c~l.8v..L...:p!.z4.....!...m.g5'....&uKQ.V.....L....^..m..3......IoLa....e).......!.2.%....]ohB%...]Fv..(.'.....W..~....Rj..[.nX. ....H,..6.3...W[|...X..}=}y...x..)k.......).P./M...?...~...L..B..F.g\....D.r.Q...V1.....5.;....@.H..3..R..W.].%.7...D........S5_..V@+...%>T...k/L....~....>..l..~..Q..iC,.H.`*ql..Z?./.E.._.W..)....[>v:D.:G.....f5Y.o.^a...~..]..U.-z.w..x.W.+......_.3R<.Hs.0ko..}.....IL.b}...n.>..)...mJ?.V10t.,b....wY...J..........|..K....#...\J#..%.\E.m..._....(...@.c..j/\......S..5S}E[..].}X.....f..u...$.)~].7..=.[....#..7Z.Qi:.....C\C.g.....|....Uy9.#f.G.m>..S..c.q...d.u..;\...ze*......lU...TG.Cpea..*b.S+.e....!..S.6..1go.EUVN.P..PU.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):36076
                        Entropy (8bit):7.995574787857948
                        Encrypted:true
                        SSDEEP:
                        MD5:807509143AE34AACB5FB5DD2E2FCF5A1
                        SHA1:7637210DABEF1D37DBA9878CCC6D5B922E5724C3
                        SHA-256:860ED28653DA4CC089BCC7C754979689356E33DD146876BDB8DB6A650B40FB0D
                        SHA-512:A9E9BB34A7D82C060684348F8A36454E15C5CD02E24D067E49A9E0461F3D72427DFA411E748DE7CFF70D1A1023C68193A439F2AD7EC6466085E7FE53115AE025
                        Malicious:true
                        Preview:4..yTJ...V.j?.......}.......L./.*x.J>.4(..].x.b..U......G.z[:*._h...Jm.u=e#O8...;\o.f.G..i........$........X......We2..Q...x.H....c.7.;.S.?%..d..+r..ytD.....e.<...J......o.......=.....>}..B ..7@.t6.@.).w.....'..~[.T.F..qZ?..j|.....7n....l........&0 .A].=.._..u.s._s...A.^e..q.........EC..,..=..s..3.?......./.l|..[..I.~.h...\)......b.{.V....'.p.{>...j..d..MC..B.... J.j.+...Z/.......%..=.qg.".K|.`..Z.C...r...Ef....Pa...r..n.?..q..3..."..o..S[.l.} ....f..TS.5.$..<h.O=Y<...)..t..V..E>o~i{Q...R.I.@........7.[6.y..g...Uq...|.QM......N...7.....>.o0..:6H.;?..6.@V.L9y....U,C.a..d.b. ..{.S;.7.w.`U.#...%J.O9..0..?WQx.1P...N....._?.(K..&..R|....C.=...i..@.!c...lr.-....Nk.4....N.E{.X.....\.\H.@...I.^ri.<h{A7..S.....AZw.n.j9D.4i.'y.x..L...........t.\..].\...e.1.<.Y...sSj=.Y..c8....Q&b[..tL.... ...W-.!.@.-.w...[...q'$.(.1.<"..]....o....G7x.]7.G.._0...Z..g...H...zU..F2.].._.....6..AdN.nHtb.n.....L..<(o..........E?..g..b.a...3'.G....}.F.tH....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):105474
                        Entropy (8bit):7.998211224889266
                        Encrypted:true
                        SSDEEP:
                        MD5:158529605AC7A1D0871834E2EEA3D2FD
                        SHA1:D3A0EC854FD0B93EC6AD1155F50FC2351EDEE504
                        SHA-256:02777611BDE228F45C10C4BCB7862B240F08E6F4D96D30AF23FCC5E8EE19067D
                        SHA-512:24E158C07B3AB145D066696A8D403C130472DF61E3E4E0354477C9F923251BA6A04E644899143AB23A49E4EFD6C9B6DA0AAC20B081B13A4F07047E00EEC12BE5
                        Malicious:true
                        Preview:. .....g..F>.9z.G......b.-.[1..y8......Z.r...nilW)...mX..._...f.Wd.d.F_.M..k..uu.f.....M@.~....w"9..W...8.....&9..S...".t.<"...5v....fo?......R.....h..T..q.#[).....Dm.........?..$..\.xaV.7.0.l..-..m.q.....>..x0....W..v.r..!.``.....|XI..;...jJ-.7Vm...h@T........t...H~#...!*..B......=x.}.t.~......>Q..*^.a....9..[.(K!.JR*....gTxjc..z.Y...}.U..^.W9.....M...W.?K.... .....%.+m.'.\....'....E..~Z.!..;..4O.9..e./..4K..3........)..1.<..ZT-(.+0....B...$.....Q....z6.....;.X.w"..&A%x......(.].q.[Iy.|.,.9.Ra..8.45.s..Z.........}.2dC.D6M...cZU@+..k.N.O....l5q...+..0.4....Cm..c.Q..l.vk.<p]..H.9....u.....v..#]..~.../.u._([-%...=.8..0...X.^...y vk.....$."`..oy.9.-..].($....|.',....(.&t>....]pk.........9.l..P.yT.P<o..g...)kT.+2.t...(..a.PP+...i..k.....w<..v.pD?..F.3J;.z.G..f3.b.^....e..8^.W.e..q..;Q..k..i<..A..P...6}&.W...$F..C...zA.f.l.......3. ......&..).k.]..w..k..d...O..*"I.mY.9.._!x_;3...."|..=.....sz.rh..[.........&.]..$.b.7.%.0.^.....-..nv..z.6...;.~.M
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):106004
                        Entropy (8bit):7.998508601302576
                        Encrypted:true
                        SSDEEP:
                        MD5:9935F042BB95EA0DE7F15BDA9473A2D0
                        SHA1:2B7851B0D2ADBBD2134D2C9E36EC565D63813174
                        SHA-256:5E6F5753325C18A77E82508C0BF8BD6161AD78002C81E89FD39F340072813848
                        SHA-512:A5E72CA6038DEBFAFA24CC04F5CEACA95152E25A250CA325954F27B845F2E9BBD2B580B4EB1FE26416FE60383B674F558B4CC0BAFA8947C4A7531E82D1ADE634
                        Malicious:true
                        Preview:.w;.f(.T...GQ.J.K...?.}.s.[.....yG.H....Q-....;....0{.E...B..D.A...Y.w(....<.RPW..e.c....w.w.l...<Ii^n.l..d...3~..wX...N.y..UW .pL.g[..pr....I.Q...y.s?.3..B...7b.,5....M-O......7.n...).Oi>...._.&.R...u[.JX....K..r......B.?..O.(.i.i..Lv.u..&.R.XG.. ..........0.+b...9KVR...%..._*.>.5.b.R.I.3:.(.0.7.Wu..Qt.kP.5.JI.w.Ux"..{g...Y].1.#i....S.....jFF.!..K.zc...u/.%...Zd_KA...#.....&Y.R<..o...Z.O...2.j..)B.>..H.pq1.YV...g....._...P......j6:o(.*..C.n....U$....l.q.C..,%:T....c..._Y+.$..(.&..Q...'./K....4..p.G...p.;...jk...Tl...NF.f.Cf.).)o.....6r.Y.`.(S....K.>....d.AVc..6..........u.p*#.@h...}.M..j.ZO....tW?..c..cX.....N.*]i.oL.K.A.....*.....82.r.j..X|.q.....1....om.P..7{...I..E..6....f.....t.W..... .y..vf.$.v.?..P$.q..'.!O..?.........b....K.}i.[.c....os.".}#....Z ..r...8.._k.l...K?...R.-....n..g5..z...O..z.J..I.S..D....z3D2G*......c..k>vbe}.y..j.....>.[.a..K.......C........e!....6.....h...g..G.h.&5...S.(dH...y...h.M...?"Z.;.#..c.|J...W...V6..(
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):59380
                        Entropy (8bit):7.996744574350896
                        Encrypted:true
                        SSDEEP:
                        MD5:8EB1E902ED1B9F16652F2BCE4C53B8D1
                        SHA1:DE37EE7206AC35992FCF1725DCA8067BEE00D30C
                        SHA-256:3C08691216D5ECFB5A71D2158E838DCB2E9DB4F237C98C383FD6AF7DAC4C6F78
                        SHA-512:AD8F68C00F4A988FC316F010FE40B9BDD1246EFEFCBFCCBC47787E6BD7933D3CA94C22B09104CA782F894FB4A87B97621446B6E64B85FF2CF27D0259BF57FABE
                        Malicious:true
                        Preview:.X.g.]..nC..Q.b.9.o^n`.C&M..'.$1'.........!.,M...Q.d.>..F.&|....|.KY..o?pL".5.....2.>.. 1...W%n.V.Y.M)dZ$.6.c...:......K.z..V..f........y..Y..1.{=6&.q..z.....U.....D..H:k....g..y.....hs..;.c.d..g...w.....].!x[. @.. ..k..<L........t.:.vj.:.i. H.J..~..K.....6s.T...G...l....[.{.&..........,..s- ...D.Cm.....'*..d.....!.....I.0... .u....}.d.-....YQ..TV...H.e)X.....l.'.y..#d..9+R:....i.I..9y1...(..Bn......Y....?}.%;..~`.....i.....N*n....C...O.O.....~..'A..M1.P...GYZf..B.....3.+...ZF.".p.n......2.N.T...~b[.!...K......cw2.)^x...? ..y.`..g.`...Rl.#Q7.Gr..Vj...4..)&Vn....p....WB.h;.-.)...yb5U..D"......=.a.2.GL......#h.$r.:.~.'F...=.ow.3G..\`.......{yC.kI.R.Y.:8....F].N...O...`.pX......OI.c.e.....eBw.P..C..z......%.DX..i8.4..O..|..Q...R..N......&..q.-../c....8..Y.fp:/$.U..)...L^...7..}P.u..>p2.m.6...h.......:.f?..g...R.).W.................{_.....\y6...........b....I.44).6...\..{*......l5..3..>...N{......(.. .]..*z...iF.9..z.Rpz..z#..*.^.ap:~.<pX.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):59910
                        Entropy (8bit):7.997012322592712
                        Encrypted:true
                        SSDEEP:
                        MD5:F97D7D711ED00CB0A3B5C55ABEFA9D2A
                        SHA1:5F4794F4D204FDED7A6A0F9FCAE573EDDC693DC8
                        SHA-256:4C3EC0F988F675E1BFED7991E84E3FA11F05D3C33B2B0BC71E2C765B149DFB85
                        SHA-512:A6B90005164F8C12A8168A41CB91DAD11D5D4B176BF274EAAF080CBE45761D91568884848EFE9FB51B3D3198F95061E4DA351C8F888236400C6816DC72D74493
                        Malicious:true
                        Preview:Pb....s.g..T..n....S.v....f.x....YKG.........gd............~~\......D.I.b1T.....N..ju.3...Kf.X~.......L.T\.7.....E3..M..b...)...AI..C.O.4*......h.......*...4.Q....l.4..]..0$.......I..>..}..Fa._h;;ube.F...~x.E#.3b._... ..-p.p..H...i..).HM.....[...%.=.rZ...?7F...b...(QKK.[:|1.8....M....AkB.1.N.a.2.?p.....PI%;.d....^}....\.....-......'....`)=..D.2d0>.<.%...%.......<p. 1,.HP....!.gL.FO...7..`{............^..Y.r..].c.P...vNF....?..o.........H..._D.T.^.;.Av.Gob.xM.0/S.a.A.y2[...-.....\.w.......KK.9....I.50X&J.$....G.T.....l^W....{...C|99.Pq'..E.,.\......R..Ho..`.....{......!.';..'<{.Z..0<.d....M....i..6.7...Ox...5|.6...[.8.t....7.....J.ac.af.r..).^...T..-..x...C...9.....51..x....aXU......0...B...W...ed...h.....V....O..F'.Z.dv..X..R..8.Jas...-.6..K..7s......".A..+..{.rw._.*..s.A...].....U...<{..........!.....y.v.. ..p.%.|..<.._...d{UN.....V.'.C..s7...+rJy...h.'....pE.q..u.......&....G.l.K..0OD.".;..Q+W.M"6...Q*2.w....p....C...._+.G.V..n#...O.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):29762
                        Entropy (8bit):7.9938587241814325
                        Encrypted:true
                        SSDEEP:
                        MD5:CC5E3F7C7901B7285996CE6F0E3207CD
                        SHA1:C2C0419DF2B8F72A4F464EEFEEE88EF168B223D7
                        SHA-256:27696CF07A774A79A0D84DF9E92D6675E21C9ABE299AF98820183BAA51D9545A
                        SHA-512:F4CAC74C7792B68540BB8679AB7263C73AAFE0FB7B9B9B3E2E62259D8EB18953468408C3498A543C7E91062C4A4E830C031473A7D66CCC356AFE87C5B18AFA85
                        Malicious:true
                        Preview:R.+{....1..../...Y.:..&..J.Ll4....j...,.W......-^..H.{A...k.Z...."....h....3=?....'....>..mY:..1..B.....8%....kBX.yq&..O.}.4W.I.[.JQ.Vkv...g...{sb.R..*X.....[n..`T8S._#Po]..Y.((..../.k.87"+3..=-.S.Ca.]..5....c. .rM...4......bz^.4\C..ie.+......O.#.i..j..w....G..&qRY.].kvM.+....0'y.$(-o.V..S0.....!.._...(%......4B..%...(..Ks?..8..bi..y.~.G..k.x....h.....|.H.l..m..YI..<..y.}....$..Mfm.!...lHW....GQ.....3.....V..*...p.U`.?u= ..^...)hyu.w...r...E.....`.}=.y..@.aK.t.....|..a8..e.....W[F..q..3..1N...jn...>.6....ok...J..e..s....A.2t.$..".gM4.e.+:%..1.......:]....G-}..pO.@y..V.Ce.(5..KV......B^l"....9q.4...@.U,...8........^*YH../..u`R7LV..Qy...@.#p~.:E.`.SOX.....uQ..F+.^.UO......~.@.W..I...KbC.s....|e.._.k.......KOk.C.3.d.EQ/...4[.Z.q4..+..\...*.C..f0U.:>..^.8..q1l...G..].t'[..S.C.@...d.....Q..n.....T.o...i.+#._Rm..*po....OX..B...L...<%I.X.;KSK.A..@Z....K...*...;.U....~..I...8...r..J'...i.T..~...y.x..r..T....;...v7 ]...:t.\}.G...y...}.=>..W.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):30822
                        Entropy (8bit):7.995244697261461
                        Encrypted:true
                        SSDEEP:
                        MD5:46FC9C6B96211F8DC9330632182CEFD5
                        SHA1:64F4F3AA86F296536E737AB847147C90833770D6
                        SHA-256:8BB3DE032E2B617BA7B214C7F9CC5A51FC931C35EC35E333D01FACC9663F81DD
                        SHA-512:D060D7CB1B99CD05EFAEA67CEF2CB670190F313FCB6A17C895E5CC6D9241551BCC4C57508842752E9949B87EEA3C6F7FC5B61D5AFABE470E2DDECF6EEEFBBECE
                        Malicious:true
                        Preview:.... ..R1Z...........,$-h^....Oo..P...PI..........^,....u.2S.......r.Ct..CM....ac...j..Q.%3.(.m..!M.....<S..2;...U..IA0~.......).......t*....!.+.2"..m15...T..-iA.7.)G...........M..w.l4.n.W.:O3+B.n.W..<........$.M_;.4`K..Uxq.b...e.".t8.?/..W3<|.q...J....D..m$..6.jU.../.c;!E......@.aS$..p..H~..N......3_Gr.........=.2..la .....yz;.....S..~..c.pz..|........k..fh........c.=;...d.L......o'8A.m{..jP.....P.f0.J....8k.7t..{.TjKA.U....2.X|.....;....K.:...>c.1...4..==.4=qM....]qF/4...&e.....u'...Hk......E..9.}.ff....O.V...>..*-Y..L..98.P{I.I.>...2..XNZ..r..7....f}.;..\..YJ...F.-.......I.#N..........+........0e.....g.W...m.:L..,.s..;$....:8!.0......>5.....0...I5..._.]H...dN.A?.y..&3....DJ...Q.yN=m....*...F..2.,......Z...@...z..R...5..f..FD~..s*.....$I.~...........E+...4w.+.]..c/........2..Ri9.n.......n;...B...."./...m.)....x.s).........H....s..>.2.y.Ta..=........'w..I.."J(|.}....S._.1o.8.... ..c.%~...P..*.T..b....%.p.AU.E...g...n4.g....a.w%T...;Z...u..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33298
                        Entropy (8bit):7.994093016188524
                        Encrypted:true
                        SSDEEP:
                        MD5:1983C68A89F430C3FEFC47F485D510B2
                        SHA1:E2A33EB47FB3605DCF057ADFC8531E14183095B7
                        SHA-256:A82A280C098AEF90667F3057ABDDF4D13CF31EA97C0EB4F3A74B889FB999E770
                        SHA-512:1A2FE114319F1353F6EC36D17624AB8823E5D0D62E40D0A12C97A1BA4F16E52518D4401483CAA5B01EEFA9340D2728FD78519CCB5B7E4A93E2782DAC04C06BAD
                        Malicious:true
                        Preview:.d)...m?d!.)./.:........05..V5d_.&~.V...Ya....u@.$gQ...,.2.yz/....t....^'...H.Y.GcR...-2.....c..M......T.."...0;$O.....@*%=N..c3.k......lxk.C..X............X......j,...9.I.0._..uw+m.@N=... I..tJ....a{..Nd..w..z..N.o.....w.c.v.2.4N...e.}.G...v..o.|..w.G4v...x..B.!".f.n(....O..dn._!.rNP..q.........}.Vo..p*m.!...av...I.>,..Sh:hz o..w...95....]!.,.zI.....tG..Q=J.P.$..I.......K..~..78.....{._...Fg....1'....B3s,...U..zoW.y`E.4.=...E.S...mY~..U>..W..0..\......$`".:a....... }.Q..S..Z.F..w...r1G.........S.u. ...IT....@..<TQ=jk..E...h.2..sW.9.I.m.Q.....+.uD.......gN...a:..m G.../(>.y.s....;..:H...}.u.`.>jB}"b#1....C.........WC.h.'M..Hg.s..7...e/>A.Sp%.'w4..2[..ea...=T;.2.."|.w.8U.O..l...u.)\v..L..+p%.a..e..L.r...5......X.p.FR.l.i...A...m.'.q..h..p+I.PV...38.k..-......[.vE]_...n|..^.:...).T......`...._... ....Z+..l.%U..j..G..L......._...b.|.T._ ....U~.y.I....G.J......R.OA... ..X..5..(....k..k_@.F%..LzqEg.\..V.m.....-54.Z~.....n:..._+!.h..E
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):34358
                        Entropy (8bit):7.994531572914693
                        Encrypted:true
                        SSDEEP:
                        MD5:C6EC48CD67EA40199294ADF62FF966BE
                        SHA1:82A2B7757C79A29EA0644C33E439A5B0D2FBF001
                        SHA-256:797DA60F49ED2150813D2B14396AC722F509C13236680A7347F540D7229BA5C3
                        SHA-512:490CEB0898EDABDC1BC965BD4ACF2D57C93B37C2392DD62DAB529414DFFBC7EB08865EA33E3A29B5D5AA0331FF1F865C12E4DBAF509C2BA9D5C4356C55E76F82
                        Malicious:true
                        Preview:..R..?.../.,T.":.2..v.'r....`.+t.{]K.X...B..'..2...-~...6/.p..TIdz....BN#X.3...z.......ND(.A..&{;..|...Vy.Gh.3.3.....FP.P...j.2D...L....0....H..!....?;h..T..L=K..V..j]....C.....5.t.......AKY~...]..q%..Z?....n.(X.$Oi..bC...M.#0.ojc.....F|..E..s....Q..ot1..Z....0...Y\_]..... *..8.......:.._v..w....d......U...._.36l....i.s.5.......-X^...(.g.....J$. ......V...Q....Q.p.PQ_C4](.s{.N..I..u.._.<<i..U..xV}.\g.x...<HO...!k:`.....gG.Plje...i....>.^..*.e.w/3..<(...)..<..k."kaM...I...=:.r.........n.o.~...EzF..7)......:.8|.o.zf.....U.'..y.[..h..^T...}...J.i=.._.[.i..K..gR..=..onf..Q..I....:.......RKfx....E..U....B.W=......-..:.-..0.\!>...=.r..+...i..5:...CE..,..2g...N.a..y....B&]...n'*.....L6..........@...2Db..J..sJ."..5.D{y....`]...Sc1..A.!n.....xWZ.ujd:.BB gS..#./.....<.......N^..3OcsE".T..cU..4H:.9DqJ.v...R37B+.*.Ex...K..9.*V..3.PT..D.B......DF.m.N.....c......\...{...{.l..q.....=.[......r.B:......m.8..q..7e.w.w.tS...1.S...U.x.-e...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):531
                        Entropy (8bit):7.567442136175641
                        Encrypted:false
                        SSDEEP:
                        MD5:470F5C4CD8DAE2E53A62142A27EF1375
                        SHA1:42AF265F456FB3BB94276E615B9795A557EA9D8D
                        SHA-256:6888E4EC80C659761B7A71F33F3B782DDA34962D1944906BCD098EC9F0C156A0
                        SHA-512:2FE124CD9A427F382E83538E5E3839706C169A399FB3ACF805687465CB352CBF0CCA909E352B91D6F3C82EC64F996570952BCE8A0B635E1F5A72FBF62E7D9C28
                        Malicious:false
                        Preview:.{..,:.........X/K:......|u.E0......ae.2...=.>.MuZ.<Sf....u.k...{......~h.4.vX9z).S-.L.u.|Z@...0<C..&...v.......T'...B...>.SxSSVh..;.O..{G*j..{H=..:...RHwB..p..Q@..#[x..B...j..6...|..bh.r".E.(.eR.x.N8[....q....lj....!...@..!X.....~8.D[v&.C..g..T.I..lu?.<.a.z...n......^..}z.r......~..:.x.y`..0C....Y..6cM...N.[.h..z..W.........f..?.GL.....(-.m...T..l%.qL@6..(.6vR`.~2..)^s.}..ap}1B..Gv..zq...~..f.>3......).H..N...EWZ....v.p.*..e..D'..l,p../.s..O4.......N..-..6.GW...{F.^.Tv.9....4.I{G]..N..S..j.@
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1591
                        Entropy (8bit):7.887451620239915
                        Encrypted:false
                        SSDEEP:
                        MD5:6D1648A88FD65E876BCD533C5F2DFAD7
                        SHA1:928AC75C2F00CCD4D6BE5D67D7E62AC52F6E0C7C
                        SHA-256:801838FA74533B9387B05C1EA0DE00F6D9FD0B6AF0740A8C02F525E994B1DC31
                        SHA-512:6BD34965034AF093A2B868DDC436F4EE02C8B3752F13E85C544BB676C078607BAC89D81975E3BB6AAC2A2C902CDDAE78E2A99069FDC51002DF9152E12AED39BC
                        Malicious:false
                        Preview:.B.b....!;...)U.....J.r.f>.....%.5=PP.c.}...C'x J....rl..#....=X...3...Adg8....&..............*.......-.....e$F..I.Q...y....#..I.R.j..u.Bs..........v....D)C$>...[..!..Mv.6P...sR.]...pM...Y..:...g.}j..6..26.~3;.W./....'..2.;"v>...5f9{..0.X.....`.R...l..9M...+.!*...$xX/.fE.(........k6.yr.a..k;L&...;.g./YHS.r...b:-yb...]$G.%+.z...O....aJ.GUu ..Mc.K.......~.5.6x.Z..B...*..kq.b.G(.[0...+...O.J...]....._.|.} hkr...H.N....~....;.....Q....K.s..j..K.I..*.h.c....I.A...<2Cr...aN+....B..]....=T...F..bz3|...a..........6+..._.w...h.)./..Q.r.1.k.=<.l..G{..1.`....[.a.{oq........ d...m......4...\..U9.....iKk{p..<..2c.7./...<k.4.N.E........(...'.. c].&%L'.?OH5.~......DM%.fJ<..15%.^..=\WT{..1.]../...L.]#..z......dD..A....T;....1.../:ZDL..c.d&.....Y...4...9..sy..z3.)...+...{.c..(y..$}:.o..m..6..`...a..o.}h[...I....w....J...$...7K.OP..d@....D.y...*..+e....~{P5@.U4.l.=.$.."a....K...=.y.m.....W.._..)&.l..5.....SB...A6}`.X.{b..... TM..........F.X.2B.....v..N.#.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):31692
                        Entropy (8bit):7.993558789336186
                        Encrypted:true
                        SSDEEP:
                        MD5:9EFBCEB058365B2018F676AC3EBE9971
                        SHA1:97C51C75FFF7171D099BA9E12C8AACBD07599B0B
                        SHA-256:A6D30AAB29820685DD5A4A9C6D6EBE549772F35253ADC1A3455B8D2882FD0BB4
                        SHA-512:10F84E1738AA9629B77FE47F251451DBA90534E77643E16390AF9EA680A0C5CB51DA1A7E6C6437E3D5B66A17CD6A5D199FD612BD11BF25C4E1CA2382ED8B1088
                        Malicious:true
                        Preview:......a7{.t........+W......x......gW.n.b.LG.9..+.+^bC]Y...=s....,w.YFl..(pI..E.F....Ru(9..z.L.N ..............Sa........-~.).....J..n....*..K(a=..o......L.QJ_...3....n{D...?.fHM...S........y..9...HG..,.u.].g5.P.m..[.."..\nAx...X.Y;..`.RE....1...g...A]f.sJ..uH..8.&...nj..{.Hi\%.(...[..u.......N.....A..2........."...7.#....Dl..~.\.#6k..Z....I..o....S...g.5A.......9...d.w.j....S.O..M'..A.....w+....."w..i.t.. ..1.P.......K...2.:Pug`...8.!h..P.)5)..4.....>.W................1..,r..+.....&se....~.u.u..>#-FL..D.y..(.\)e..t...............]"...P3.A...:...=....t;C..b....Dz............U,. |..@.-....i.2.....GtG....@24......Z......^N oL.......>..3v....$k..S/.?....a.up.!..np..}..e7.r..*.."8k`.....-. ..f{E....a..I`.G.....=........H..H....x.\\.=.w1.....6.Q..[\#....2.x.!(..tD m........A*......J.([....A1....c..u.(V@K/O..&.|..u.WS.......,....h..:..h.......?1.^..5%/..T...\3.^*WN...y..w.....l.2.&T...@&.e.....c....F..F.........uv......L.q...\...7..Q..3K,(..2}T.u...C
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):32222
                        Entropy (8bit):7.993508921402831
                        Encrypted:true
                        SSDEEP:
                        MD5:C3927D8CE78CDEBD9F3872702F57A706
                        SHA1:F572270BA4B2A86AB450C5ECE6017A0B9EF67B13
                        SHA-256:7EAA924EFFC08A5079FA9D47EB386C081B893DE0EF987EBE9B144869CD4B0B51
                        SHA-512:9BB4E567994F40D0283537592760697AF37B42E3E84CAD1F0DEAA6C90093929ADFA26FC6B5068567F6F2C714FEB6322CED6BC958E4E2A8348F3DDC98E9ABA10A
                        Malicious:true
                        Preview:f r..$.-.. `.............F.Z....&..1.>M... )J.Y..`.0.N..=......9P!lv...k.S.|2?.....'...<?.....,.;I...!....0.i.F.x..8..;w...lGl|.L.g....R..iL..ez.(.C......GX.;.4....7.H..A..UlA.......Z.n~bv..4...k3K....>..U.6.......!..c..P..(|.1i.P...2|.1.2.xX.<..._:~.:..z.T."....J..j]...K.l.<...k.3F..S.~E.9..`.E>..T6...5....?..p.........Y...u3.A..R.E|....df.qz.(Io....s.....w..m.k......&Q....9.R...b.....".M...O\.A#.0.../UE..#....5.b...n...w.ZyW..6.o;.W.@U].}.6*..8.n........*9.'.ANQ+...?.uX....(A..rA<".I....v.N{..f...&xs*.*....b..0.d..........b..F..Rs._..r...#+.%.\..4C<........D.....kb.q.<....7a....j,.U..2.#.y..y.:.\&.r. .......*..I.^+...]...-..P..w...b..b...M.&.E..$CR.A..!...:.i./..hBL.+.9..2.oel.........,.;3:.....<.C.h....X..Te...D^.7.PF]^.~ l0..7WS#c.......O.uM....#K.)./...E)M....)K.../....v.h....c..4.[w.A.X...-i.T.=...q#....MI..t.....Q....Y.et....jcGZt5i"u1./i.v..]=.g..U...|4.$0..!&.4...*....}[.K=a....td1..Lv..f...E..S...}....2.F.A.....0..>........
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1598
                        Entropy (8bit):7.885359742776844
                        Encrypted:false
                        SSDEEP:
                        MD5:A2AC9F391D0C459FF2EDD02E1D63952B
                        SHA1:9D37E925BD14DFCAFB67CD8AB354C4F1183E593D
                        SHA-256:225213CFEBC0663290AF55AABB77E3D43F2870EF48A9060E55DEC2F6DE03F1D7
                        SHA-512:CBA4E23A19E3EFC7671797057F0B97A9B69870BE7CF03DFEDDA4DE0C1F88188F656403EFC91E47040255B48107D22301022C07ADE27549CEBECECEF112830C01
                        Malicious:false
                        Preview:...'.....I.l.....l.}........}...lE.|..s.w..w..8W.5....7...@q..H.....y.). Q..;..!v.......Q.....".C......A'....r.)...I#..6h...x.(j<u.m"2.J3.Y...g)Q...5...0...6a4f.Sr..L.$..+..c^..y.....iwb%{.x^0.O..w.<.Z]&.S..mn..o.f..........l.S..p.....Y...~..z..\J[.>J,;-...o.%..q.......Y~.1...k^]o..........{sh..#....%.cj:.B....E......Cq..'3..<S~.E..j_.L......EN:.[...m..]*\.\Gy..t..>....9.DD....2-...`..T....u......7......Y!....4..N.x.MZ.b(......=.-...S...rK./...+V......!o..Q.E.F..Y...f.......z..c!|.X.6..z.[;.....Z..J.C.oz...-..=A..R..O..~.Gn=..wE.XsKo..I...A{g'...y....+e.X".E<.F+..y.f:..m....!.D.FW..$F3.Vl...~cM..M+.6..$...i*..Ni'.*...^......F(.v.`"^..f.6L.M.G.....bS...:.(].[......S.M.1.....@-.y..<o..*....B#Lp<(...s..xmj...+..gp..9m.tk+.$.(K..4ws8.......e.A.t..G*.Yn...<g0.....o.PzC~.r..mn.......Nv.-c..c.."*...?...._.O....-iC..%b.im.)....5....</ZPPnj..@z.k..{Cq..*=.....]..."y.gC_.4..L..z....kti..+Pa.|}.0...|v...+..p?. L...CA].mdv.x0.B.^..A.{.....i.h..[LN.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1068
                        Entropy (8bit):7.8201090119906755
                        Encrypted:false
                        SSDEEP:
                        MD5:7954C643F3DBD7B96E14948B564F011C
                        SHA1:79F08FA5A36C33A39597992FC7DCFB4E094A17CB
                        SHA-256:29ABED70F35D02E60D946DD5380F45CD1DFE2900675C2782F2DDCEF61078ED65
                        SHA-512:F2922D94AAA5A33745C36287BF6C815030B56D596E69FBF607D24D03827D6B7486AEE0175DC5CD4E93B4FC07B81E24216E1042C1B5AB8417ECEF47D1513CBC13
                        Malicious:false
                        Preview:m.pI....^&..R..P..H].U."j.....)\9..o..R.s.G.....\.|3....l.6r...:.RMIoe....:.M...r`a.;...1.M....7.]+.F/~...}.w.......B.....X...-.,.H.1N.....`....A.......8v..1{...0..*sm.w.d...DYl\.}..."h.7.(.X.:.M..h?r...j)..0O..p].D...z.h.5..W.*y..7q~x.=o.V..V....L"...G^.D.ZB....e.......n.4m..@..R...f.p...nO.9[......Nu..U.5.*.#.......k.V..s..V...jm.s........]../.."1.)}...?.....o.._...S.?..7...H.4...7y..@...r.N.,..B....A.:.....K..xv...'\ ../...P8..K..g:....d...q.0.O.....p...}.....M......qk/P>...zS....g.......B...!....g.Y..h.T.J.........jJO..K:G<....W.....L...'..v.k;........@.;.].f../.O...\...U.A.]1....7.....J.,\=..Q...,...3<..9.#.G.o\(...\..{.....|G.|.?..S..du/.:}.}.{.*.#...<.%._.....(.+....Z.{.....b3>]..5....c.Sh.7..-....FE{.|..v..c.yT.Gn.z.KL.....&.[1.?..S..en.$.Z+>D.....1|.YH.c3t.4..hcKY.=..x.U5k.....=......*.{.#?...i..~...]/A..Wv....2pE.=.}.K*...{(.....cA.....=;K3.f./..3.,1.&.'......7.$u....Q...8....a...N|o5......^...n .....B<(Al..D..VK+R.R..u.."....r[.)d.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1082
                        Entropy (8bit):7.812838399787491
                        Encrypted:false
                        SSDEEP:
                        MD5:E606BE129D4405C041895D1A59DACA9F
                        SHA1:ACB855513324C026925BBD15A00D28931E7C5715
                        SHA-256:7814FF02408DFB0020064EFA4ACFAC7BB14B7D7BB53B8DAAFF2AA9C2C2CD2489
                        SHA-512:87D2B3C64732D795DD1A56BAB80914A034758755366C7649EE3612F173C70A12C925C4B7EDDA9C41BE4F10AB2E0560CC6D25F6139B7D8B38D3FAC2E322EB576E
                        Malicious:false
                        Preview:..,.r..o...ik..dU..W.A.<.9eD...S.{5.v.i!.G}i...ezn...`.4h;i..C.......]?...b.!..#...l.H.S.4.E...v.e...d\s.J.8.g+..9H....bn.`.`... ....W.....E.h..yL..d.../.hp.|.|...V...>.I.......;...EC..i..2b.G\|.XF@...3..%....1b...C*}. ..:..{S..n....ch..9Y....o..Zb...@.N..4....E......jV.....x....yP3.>..,q...O.*_...-...4}Uo.\.F?....._.....l..<...~^.T.&......6....b...m?.yX#...."....{.%.D,....i..@2..o.z.....-..t.s.'..fe."qk..._.!.".UY..D...].f/@.[.X.....^.T.J.W.>.....A!.......%a.._(j.up.....J.?..$3..p..T.tq].Y.uT.k....h..?.u.....@...@.W...Q>zq.Y...y+K:@.w...Q%_Ra..rr..Q..H.o v.`...%!L.`.-..%i.....Y...-$.H.....Arj..3.....u.e.....s.5/..*.r..dr..&.R.k.I....1.V..f"......g]..._.#....o.73.Oa.aQ!.......U.k....<&.....;xG....K...0...D..]dI.k..sw.....D..........>>R=.x.<..%n....,.J.".....*..l..A*........s.....&.........$.\.wT..zyY....2q-.7T.3..s.ve.:-4^D.b.U.n.....Z.#=..W.m......Sa.....9.5.....0..&.!.._.q}E..}EU.el.%..t...`.....Y....od...\B...o...E...).......T.l
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1084
                        Entropy (8bit):7.821713529988243
                        Encrypted:false
                        SSDEEP:
                        MD5:B67FF7F3610DD4B75AA7B18DF75EB30F
                        SHA1:1ED31D7D93BC3175A480D56A5C7C83F244A38355
                        SHA-256:B40003C3580211FFF3AFC7A83347F5FA04D4C6FA40B070B122CD0E308787010E
                        SHA-512:07A21D635BA738E8D4668CA1DE74C62B52CD4EDF7638FD1FF9FC660BB942C4A938DE3A8A708234928F264C59AEA21249F3C0AFC9FE01EC423CA1670DDC350705
                        Malicious:false
                        Preview:.C.sL.*.H6...Z..3....\w4..;....8......X.q^.ml_.[f.cg...f......~N$..#v.Z....zMF.Mgx..(.5!.....r<eq^...M.....D.3....P.....&..<6....B4....X...Y....X:+H..l%cq+.od..!v.....W.Z.{Y>BJrO.|.*Y..r....X.OZ.. ..#<P}.e.4..<.....O.f:..rt*b..6s.....NP...x{....-..=.Zm..q.`...}...%.....,....}.H6...`[.....rM..R.K..._........6........R.a.Gr#-..b.....g#S...P@...v.5Jr.*..U(..........T.o......9:......m..Lt....hSh..}7..zOr...pU.u.k.oB..c..{Ty.F....C.l.d"..v>S].......~...c...#.H?.c....6.:.R..Y\......W.........-..W91....1.G......m.g....}M~......s.VWc..F.....~2.5K:i.U7.*..E....8.2x).i.P$C...=......s.\Cjw]>.....r..."!@.../.........eY.".3.e..9.k<.....S...[......^|..m..)p.T..&ek.Zf..|...1...$x..~.5n&B:... .>NY#.. +.+#p..~%.@....4.M#..p.../..l.....}..<f."...P+.!t.....ZcL.Q.....[...B.W..4....ps%.... .Eo.?3.P%e8(Jt.K....5`.g...].6...~.M._>...I..DKa_<.9......A....4<Wr.M..J.............8..v....[..Q....d..u.A..~...3....$....R^......S....V.#..EY........RN..f..4.......VL
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:DOS executable (COM, 0x8C-variant)
                        Category:dropped
                        Size (bytes):11300
                        Entropy (8bit):7.984706097984198
                        Encrypted:false
                        SSDEEP:
                        MD5:E95F3A0D9CB860DD464BA0F28A359F6F
                        SHA1:05E83FF143CB84AEDE0AF1ACC52A16AC67FD2F6A
                        SHA-256:5AC604FD3C73F9B9FC8A731E8D06E216FF3D3F80466297C333F05644F4C2F917
                        SHA-512:F6651C51050B086040AC712FBADE5F6AF41965263EFE24D8F9AC29E3FD6CB6725FFE33BED0FD3A66F5CA795C9CDBD2CEA1E4BAE31D5B8008EF85BE061AA3A0D6
                        Malicious:false
                        Preview:....9.K...$+.^y..|-.&..n.=)&D2>w. ..||C...G.r.T.q-.V.,.........q.....9 ..pIx."K...G.8...f...9..k.t.1.]...QP.I@^.H'DJ..z.&o...e.l...r...$..YO.@U..P3....Z:.)l..&..4yV.......QT.i..(...m.,Q:.W..V.P..{3U-.8......T..z...2.A.m.....^......f..[.p..t.<..'....}......D.b ....a...z..@..6!/....`C.....\.{.<u..gK....Sm.>O.+.#Q.>.!....;I.rN...~G..W....1U.....).D..F...Tl...8.}..iV.?..h...{jL..kG.ufR$'..o.b.@jf.k{.].^1.L...S..@.z.....mF...t..Q.&....8.e ..M[..-.S!B+...Z.VY......._W9.@....e3...cLAHMe........w>=...bB..........GE.Jp..\ .(....-'.k7.H58.. ;K....X......8F.R.T<N.........4';..n[..T$..*z.b.}..!V...N!.\...."....oy.[.0g.3..>...G..(..2?9.f$..RCA*...U.P.S....$.n(....7m.g...U...N.K.9>@..w6.h.Y...-?....s..A.t..F.5O.u._.....M..nM4...Wbc!.+.;s.N.5...H........X...I3.b...R.R.W)..E!...KR..~..W.t.H ..../N~...OD..9...6.L......a.'..7L..vE4M.^*...-6x.3. `Ci..D;.3...' s..=_..eX..P.X?.rrH......{+....&..$GS..]..4.....p./...z{.r..dOZ..E.._..........Ol..5.Tp."*.........Q..-W=.0...h
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):25212
                        Entropy (8bit):7.991952830157954
                        Encrypted:true
                        SSDEEP:
                        MD5:CC3923E4F2441186EC28429D526AB40D
                        SHA1:7422E604763844E604012BA90E4C15ACADE87175
                        SHA-256:C4D207BF6C87383600C4C086E68474529B122F1797EC6969ABE136A550F7D088
                        SHA-512:D10633C5471A757D0CFB77662A9F1A199064E20EF33AF0B926A5ADF20C34FE99E22A83DF8C30C6409A0E9FE8F36770FF4FB4FAA5D3D65955C646401427E37130
                        Malicious:true
                        Preview:.y.o..V..2.qx/.....*.M..o.Y{....^.B...k.f.eI.._7`.=G)!.F..c\...Kx.o\.$..;...._T.....J..8.X..}$..v;..6h.....k...\......8.W_....zhcE.56...S.2...).Ds.....E./*'p.F...OA.H..|.)...c...V..%.#y.....&.....Q.5.?..s....S.."..W.[.M......*G.}.ih..e...+.!...%.0{Ah...0.F..R~y...q2K.b9.SQ.....w:.....ZM..6.A....."..XM&.c.?....l[.}.{%..e+.NGX..yA..NP;.Z...N....soR.......3...N.k....L.lW..d.o.-...l...e.R...1..2....uW.`}.....p.#.b..!V.T$..s....u..7C.Z1NO'.3WH.Y.,..C.>.z6Y.8U...j.!..E... ,&....,Xr.?.<.u...Y..2.......Tx.P...g}.. ....w.<.2...d.. n.u.`D..|~...`.5..5./...c.//..."..VDn..pUI.."...I"...@.}.k.....;...(.Y...x.vR...........M.g. .1....}.M...\......5.....Q....K.....w.1...E........(.L54.q.t.9\|..f...y*.e.....3c.F..;|.J...(.G..)8......0'..0..B.o6fl...Y.R....0.......x..}..1..%yE.H....Nu..:....J..U6.....&..p..|....XZ=_h..~.h'.ks*...!..D..6.....9."......++.e.w.g..|.a .g...u.w~^..]+.%v6...../x..%.(..\........Z4.E.3H~...H...ND.O>....i4.sw$.>.j..z....l3R.&..oK..y
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1324
                        Entropy (8bit):7.857890409241553
                        Encrypted:false
                        SSDEEP:
                        MD5:00A1376C3987626F8158E7FB3EC708F2
                        SHA1:87C4AA44BE45951AAF2673181F019ADECC3BDFCB
                        SHA-256:FB77E39B1F12CAC127B46D4EC7997D3F0F164D152748F4041C53876293ED22AC
                        SHA-512:5B93CA2299EDB3927E75510005D7B29254DCB3C6EFA6D74F2257DF6EA74A978E8946560D3B959F763E986366531AF54BFBE92E56C218FD852B139B5411A5DF22
                        Malicious:false
                        Preview:E.W....<......B.6...f.....T..p3.`..&. .N..u..y.G...`.BxT..l...b.g.....f{.xg3T.?....d....;F......Qx...i.Q...#3..;..{.4.1.WK.+Q-..................%.L=bXs...m#.(..yr.A.`....n.,,7..V.8.M.H....fdB....$x.v......^..}.L..C..Y...!.C!L..T...1...pi..<..\.~q.83.!.@.\..,...A=.-....lGA....8..x...J3.B.........k.TM...Y..1.F....x.=Q2.M.h..l,.<_.d..0y.. ..em.Q.)q.+r>sU..~._.1i(..E{......M'..b.....Jv..C=:t......,...g#].[.dX.{..PU....U}t..if..K9y U......x..:.<.\..X......g...l..=X..........s.B%...ks.Wy..;.o....%..p.....W;I....%..'...f..0.0..A|..b.0.?@.'.F.@].....BM[SA....%....u......M.04W1#B....Z...|..1..*....]..PD..... !..V...vF..u.........v.=.q...}..U.v... +;.N..~.(.......~4...'f.vw.".).n..`...h..}..e.w...".S..F8.W^...5.....a....Z..qo......w....R3.....>.`..;:....c ..[K:w..[.{..Y..........0..YZM\...).be.-.vl.Nn.&.m.b...8bV}.@I..V....G.....+..m.q.>4t..@.S........kX...Y..J.4L......$w%.........;...jY.+5...l....4.2U.....n.P..^..7./....Ph.w.2.4L.#@o....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1096
                        Entropy (8bit):7.791238129183
                        Encrypted:false
                        SSDEEP:
                        MD5:EA585F69C8B5F22D0F29FFEA2FD08633
                        SHA1:DD5330689AB80EE95F712F1411965D3DCDD76065
                        SHA-256:D059EB66AE7DB77210723D31C61324F56BA3163DFE38724B7705C2D480FA06DC
                        SHA-512:F26311C71E2CAEA79EDED5B7AC26A956EC8C65BB981999B6FAEE065C5705BDDEBD90D7E2BAEC23453E6B31073B963CC7D302581E08223A4C50D7F2EC07117806
                        Malicious:false
                        Preview:S......Qk.}\.o.]...).y.....F......b....:T...G..Z.Y..i.......Q..E... -}+...-J........a.ebD.!n...u.&..).'.....\.0....b....'F..q.L..a.i...l.=}q......9.'GXP.}.}..r?.1.g.......*4..........._h..7Gw.$...Z.%.o.k.2M.(...vn...-R.=Kj.&.X.R}..r...#.....3.KT......Y{.!..._...uI.(.........\...."9G.......Fst..eI....W...\AO....].9.J....Q...YT.WO.4.2..N..9..P...2*...z.........B,....E....9#.&..........HF2..=.\u.Q|`w~.y(....)n.WX.....p.!......c..p.)..B..#}......x.(g..].?.#.x...(.=r.J.?......n..".X_$3I..2C.i..R4....}.m.k..Ao...*~.'O.Y.....p...(."..J...;..I.+)=K:..a."2....+.........).O<=]..Vk.q.|~.(F...K..8}T^.q......."....E......K.m.......'......p.\....>*...&=.j.T.PLP. `..T....`..L.K.X).4...n..2f...`...:w....d.`..(.X..2,..Bm.n...Z...'.1......04,.$......../......|.....OIBxW....%......H........E./Q...v.~....I+...[...tSx.#.Gm.U.?.........2]l!.m&..%..v0CN.NY@..GY}..|...Db...1.j"e..D3.~F..].t.S....}..5..4.......,x....".e_..........%.9.....7.jw.l,)g3.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1114
                        Entropy (8bit):7.852143515729038
                        Encrypted:false
                        SSDEEP:
                        MD5:E98AFD67DA7E59DE59B7AE5ED4B563D9
                        SHA1:560551B1453E93433EF6A999CEFD52EB75DBEC84
                        SHA-256:5AA49DFBEDD96B07F9EFD345506BF458EF28D7DCFCEAEF6F4F270581301DBD5C
                        SHA-512:A1AE6A3F1EF10A4F87534C7446554ECC8EC59AA6B9E950DAB2D66BA603D84DF9DA31C57B7CFCF45CDC8270B70BCAF411D4F5ABAD4BAC1AA162CD10B3BEB0F6E5
                        Malicious:false
                        Preview:.......u.LL.,k#0X3{..c=...v.Z.X....l..%V9y.;..4..X..mt...u..c>E..k..dY.fu.q...kR..&..x/~..X...@...Y. ....6\.f..3!..6.|..f..+B.tF.JG.r...'.+..._......K..(..J$.,..@...D,.m..9*t........).T.&..}];..}....5.Y.,.a^...$.`(d..e=KA.{.K....O4...[.?.'.$&..~.......o...[........h[izz..{n.........e.GF"...,....=..w.t..%..9.....m0u.6#Y.>..t.WH.xg(.0uA.......4n.n.......z.)..fyr......E+e..h.............d.y...v.........([..N..B.q.......\Q.G[.....F/=.H...c.4.P.$).=n.3....W..$.Q..f.....t..T.%.C.b*.}a1...#.&-.@.7z.q...blB..-...Vg84.j..=.d...}...e..zb\.yz...u...z.#...%...G7.0p>..X..<h3wK,.....0K:@....d.!.9~...~.l.=.Q..m...Y.-*=....I.Z..3X.C. .`R.J........O...I.F..8.Q..^....P....`..e.P....E5:.f&..B>~.nC.....pn........N..r....*..H...a'..;%y..J...........T...2p.}...i.oI,>.eYy.........U%!.R{H.On...I....X]N+'.G'..).9.T..*.Sc...u5(..G....S....?'i...2..&...N{...N./`...9.O...-%#s..._td.2...SHm....M.....J...vN..O..*.v..g.......y.1.".hHu9..J.".#U.8w}h.>:....(..5d.....cW.~.fF
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2020
                        Entropy (8bit):7.912182142159663
                        Encrypted:false
                        SSDEEP:
                        MD5:B0FEAD8144CF2C473D7E9E54ABB53F35
                        SHA1:D58A981DB249EADC3DEB8526351F01BD4C0B20E3
                        SHA-256:C92881B123DFB9B9D3C73EE016B25C44207C42D326CDB94848062F5DB340B685
                        SHA-512:D18F8149FDD877ECA999BAAF990035A9C77066EB8CD9655FC72B8C190AC8A93D0672CF51D4B57498C9FF5FA0C43D6F2DCA3F221EEFFB39293AF77024AD5923A6
                        Malicious:false
                        Preview:q.|.1..o.z......;:..tK...f2q.jd. ..Pz...........#.5].(....n.$.J.....Q.. ...<..i8GxAt.....ut...|..dU..p"E..|.".B.[.......W.#...v.@$.|.>B...E.m..Q.&_..0o|.........r...Q.. ......>......@......[.......}...m....p@C/.-....pn.;[....m...]t....?.*.j.GR. .?..`.........C.g3......<....C....>w.z.z-...Pb.$.8......"....,..vU.}..[...N.WJ.....-....^....%..........s...-.un..."PW_...>G!....$...o........n..^.&'..dP...V.0s4.fI......./k.A.x.k.O..4P].j;[..~>..k..(..7.\...L.2...5.4..=....!?...}....r..g....P.es.9.5Bg.?......._..'._..vB...S...<.(...........5.6..D.]y..A?..u!./%C=.*.....V.d....y..i....B.....#t8Xlf..Q...).`c..!.u.Q..yZI{..T.hn2u.zW.&...o..R....6uG.R.M..t. ..;..d..QL...c>........O&.......p.h..ML...q..^...Q...ZY.@.&`..*......4.3x..(.|QwD..<K....Qv...X.,X.E..a..v#..1.A6....@...-c...8....Tec.xh......v.L..c.*+.~...5i.............0A...K9.;9..!..X.v9r.b......'G..%~q).#.O....u....W.:...-.sN..[9.p+.,,.E..\..E...."ak...g:...]6".....c/.M...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3366
                        Entropy (8bit):7.949728595317222
                        Encrypted:false
                        SSDEEP:
                        MD5:E4AC78EAE27B96241817A834274CEA42
                        SHA1:B30EF499364C2639ACCA9E0AF91C38EE292F4AC3
                        SHA-256:8879A36A4D9D26BC6DEA6E2D38A77FE026E06632CEE399DA2FCD344F9B97F2A7
                        SHA-512:6163227BF196EBCBE6C674A94761017611F0945693D94314F8681A1BF91DC5531555CDABC98135FEA34F1FF95C5F2958416066751D53638A845153DFF40D19EF
                        Malicious:false
                        Preview:.W.f.........^..a...>.>}.^.......Y.....P.5)z.yM`....RA8.......[..N..z...E..E.\. ..LW..gU......g"......P.D8...........+....-...9...R......L[.cZ+.R.Q......?2nx..=n..w.$...t......R.}....^.9....M^..%.....2...<^t_m............w.9.h.X.G...B....... .L..".Y..B.a"(.v5z...21.!.p 'd.s..,....!.{.X...EW+...\r.kc...>k,CY....x.3=..h..8......d'...d..@.....<.....*8.3...6..d....t..Z.%...Y..7..k...:..F.Y...Qv0...6D.@....n&..[.....x5...Z...t%b\..wu..G.....g...p......>I.......H.~n..r..:.....4.....R_.s....-........).t.fd./.R.[.En=.,..~c'R..1}q8@\..c'}^..."..ur.w..jGy....sh..z.$.j..&..mT@J..R.*.zrc..?....Ru..^..FA/.u)~....`.w4...R(.j8FsO'..`+....J.3..k........W...R.Q/H.G....9..c..j4'x...=...8.../..\[.s$..LB.{?.....,.....3..?4..W.C....Q?B...g%h.,..s..............u`<.c...u...V..{.k.V.. ...m...=.Yd.]..<R....a..kF.U.>.M..>.......^.^..J..........J...X1q.b?..;e#.Z/..I..(M......c.8dp..2..cK|lVgq.m.XF.k...u..\uP.W &..a...|.dw..7.+.X.>......D..VM..p.Aq.av.G
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3436
                        Entropy (8bit):7.949629886645097
                        Encrypted:false
                        SSDEEP:
                        MD5:AA5D61CD187EDA5DA7F596C557C93F7D
                        SHA1:872671D14364E31C9605E42AFB5D483275974B9F
                        SHA-256:3F45BAC348E2CA2F31547A74479F7C6BCFC41D37495B9727370F2CAA7A49F165
                        SHA-512:414E28930B070DD6EC2DE0CCC3BCB6D21EC4396B375CBF7D1A3B0C6125E4B01379C572A01FA16C29FA78B70CC8525D6FBD28C387A008049F033879B6D075B861
                        Malicious:false
                        Preview:...3....BxTN.W&...>~.j...._&....$\..J...m.,M...M-V.Da3.bS.!.*.V..x..0....\4>...K..6F...i.:.QS ..ThO^.`w<Q-..!...0<..d..E.d.m%..b....we...U..........ET/*.....5.W./..[rDT...K.F".T0.T.Asa...8K..........C....Dp.......'.M%....{^....I.%.4.|hv.qf.....W..j........>.6+Fg...Dp.i.2L.:.P..[.GA.o..f.n.._n..8....._.....-dy-.Ab.........C...|"..^m._..x.2s.b6..D..........NXv..v.n.........1.a....].T...q.6.c.q...~A5..N.R...".H..^e.(.J:.z...6...+.k.N.....E..=r........f..J.%.P...I.\Vum.s..Z..%.n^_y......-....B...../.*._'D*[........2...oa(].y.._..C.G.{...jD....1.......2.y.B...b..U4.CA....d2.....x.3..nM..Qu....~...v:...t...pV(Hs....u.m..=.Yi;H.$4..<M....*r'...eZ.[......WNO...W.#b..A*:....LD.L..p.o.........Uu.Pe.f..Y.!...K.m?.^....P..E|a}....E..f..m.s*_. ...%.G.l`V.....c.B..!..P.:..._|...z.N.$...N.........V..a.e..[v)N...t......]....nk1am.i..7.....WY-......C=. [..q...?...X.......w.o\.......m.%n.{..B....M..X.....V)...$..&..:Vd.0..D[6H\+M.[.N.$.. ..7o.4..Fvm...\.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1412
                        Entropy (8bit):7.867523721666885
                        Encrypted:false
                        SSDEEP:
                        MD5:8FD01821BD7378F4F45D180388CECC6D
                        SHA1:77A40BFAC739A90CE98ED7652A5569049123A3A1
                        SHA-256:AB617118665E5DEC442FD135CEDFD76A458EEC4DC0F8138D5D62C212E934C5CF
                        SHA-512:B81D94148EA3A25FFFC4123D0B79994B106BBA6F314E709096BFF1646DB790A032CB0CC78F267D99C2DB87491A66C577725FE7B327E4406034ADDE6B47FEFD5C
                        Malicious:false
                        Preview:&....~....'9.....?..}q.aB....,........8A.....*.=....-.vTTY o..S.{.o.....d..k{.....P..U..*....do..V..MD.^.H....PNi...n.r....#..~..|.._R..s6m...KRjR.=.[L./R4. .T....}?....^.sxI.VD.2..SU.V.......J...^..O*........qR...n....;{%%.T.M....<Q.y...O.J....G.u..\..A.]_.........Z.w.V...4.."Bb..........1wn.N.3.,&.Z... .3..u.5oP4HW..j...B..-.>.#./....Y.-.@*?.qz..m.V....P2....>...R.a..c.STn.4gU`...@.+...y..P. .~.G..,9..a=^.k..'.w;._....G6H....8..V4A..g6..-.}.....5)..:.@.`..ern.q*..R..~i/...S....(.c.Y.UkI..m..Fy6.gy.W.Zp\.hI]*.d..j....}f./..........G.4U.@.s..3D9...b..S.Q..}\..MvNEX7.a .+_........7gv9js{O.*..f..{}...].#x.....n.`PM./ ).....eJ......3...P?R'f..w.P...tB..n...iiW.@|S..>.,tH.}.\.;..ao8.q....y0.?[.......L..`.Il.f...8P.... ....B.-+.T..eD........J#.#.!.!p.5...[{.@0I.#..|..M`...r....y...#..7....k.<....M...a.t..OK..>..r..D}..`..V..b...Bb2..H>..h.`9]........}.K:9...`... ..R..C;-..<K..g..k.J.s.T r....H.qY...].S#.]..y...r.N....F.;k.CthE...K..)hg....c..\.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1467
                        Entropy (8bit):7.86646497906759
                        Encrypted:false
                        SSDEEP:
                        MD5:ACEE7E756F2CB3FAD126421CF4A59C4E
                        SHA1:31A594BE8AC87A89EAC1545117F1E6B691CAF33D
                        SHA-256:44D9B664473B08B603C2A72D8B78D57486B68B762B51C29CCC8B49600DEA82E2
                        SHA-512:99C482398ED44C8C664DC153A8C10A5B5535D6D65985A8DB9B6DA054F4B4B967DC154DCFC97540A4B7B77519DF60B6821AD5250B7391E48DBC13946F46DF8A2C
                        Malicious:false
                        Preview:KL.......y.....h....+.....)~v..._.zxn+3...Av.bg'.d9.N....YL.....h.Z.y......&N..=R..r.].7#.y*...[...^.r.....A.=........B1..2.9IAg.3j....9..b.M..@.r...5.^..|...YY.*...q....7..cB..]j.......(...|...h....s.T..:%[.....t....7...[...].}7..)..m...?.O...R.....z.H.H.F..Y@`.....9...X".q.....U4#7..r.n.. R.R.M...L.#.x.*D.usnIM..UX.xq..)D...&...)...$h..O.'0..gDo_O...u...2..DZ...yd<......5pK.s...6ei..!...p..*....P..d.(.Qx..o/.*..%....R..>.W...K{=R...b.....B@....'.P .........R.PrP=....iW..&..N[.....i.%.}.d.jvDi....`.t.....3....].l'+3.....7...rP."XM..a.K....|...j.<P.y..8...S.K4?.S.K^\y6.2.E..i.XR.X^.d.}...^..Ve...oC?..F\.....@.W...Nh..5.s4.p..N.....M~W...*t..R....!.Ea..K...d.{OLQ.7o=.X.=..h.........L.D..(;"......e.}k&....em.wt!9l^...]9....=.@Z...X"....&..)_BT...P....z......}.$.?b...I..c.\w"wWb....V.....Y|.I.`./...W...K........d.!.Lj..ID..,H...y.1...>y..z....yM.....3...|m.!O.[n...+...&T...N#.a..._.....K:._....g...|z%H ....+........F.2..u..&|.u.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3266
                        Entropy (8bit):7.943187218037063
                        Encrypted:false
                        SSDEEP:
                        MD5:8001AF4381F1125E8D950E71B6E64DF7
                        SHA1:A534BCA5052EBE88DDDA5D08D04ECB7C0CF78740
                        SHA-256:F2608BABDAA4EB45814A5A1A748B7CAC9EC58A756BD86524DEC6AFE93A74AFD1
                        SHA-512:3A97909F12F73F44D5B7B87DF54348D5E3141D74AFB29FF7BBCD34926027EE272F00C80DCDBF882B79A80585AEC595DE4FDC13BB0636B6037DD318F68DE41995
                        Malicious:false
                        Preview:...`....I.j.....}.{*...$..8.....C..f..@`qw....[..Z.&....&...b5....7f}-.Z.{..P!.}.....BZ...).%.<.L1BE.iq../>.....8..<kh.B.}m#.......=a.....y......'....,.E..M...y....j{.4..K..b.'0.<....J..^.B....G......Xk..nz.;..u'}$.u.....P...........G....z.`..b6{...h..G$...z..oa...A.m[.....$C.....2..(..J.=4.`u.......X....V.no.a..j...H.De..`.N.N.t_c.V;....T....m..vG...'9....|F0...(~.Z6%~...."Tf..&.;...Z.....'..i<."A..S..q}.+/O.G..'..=...Kyv.x..,..+.@3v2...ew.;.?.t.......^...T..YQ............?<.m..tt...Zu.ci....M...I.W..p..Y.}f.aw`.rz.S..EG[.}...>..BFGe....=sk..k.......j.^......'eP........t.'w....w^J.....(.k..U..v'N.Egr.9......M.Ex..-.w....X..Dwzm-3[iy 9..&^.?..Q.>..Y.Z..IX.}..n...`....s?.........!..i...|....m.<.....f.T...h...D...d.t^..o..E.h.M}F{<o.4......Pp.5%..;.Rt.=x3....#i.:l...!....V.M.V...CI..#]..j..5....,2.....E..G.R".....2;).$....FL.G|..)n(..#.;H.FQ.9\.."Uf+....t.....Q.T..2..&...(...O.).5|.%...E.H'G@.~........a..N./!|....#.D..Q.U.U~`....x..sK..r.A..D
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1143
                        Entropy (8bit):7.855202446452908
                        Encrypted:false
                        SSDEEP:
                        MD5:61ABFC219055EBCD56E0A7ABB5721736
                        SHA1:D93D504DED9BBA337F82A17F0892D28F97D271C7
                        SHA-256:DBCDC3EAF89C9ACD0F95C99A2E8DEA1A6810EEDB73333485631D1ABBEC655D8A
                        SHA-512:65802DA33A246526CD51FE7D7060D38D69050524C88810853A086733E2B552ACBEF1107C6614FB123EFFBDED38C1362280D6FA6D8ED193028CFCB7B5D79E0ED2
                        Malicious:false
                        Preview:y..U].\E./5.....+......."....};r.\.a..].^...j.!...o..cQ.-......|.N..|.......H............Vo......e...c.lvV........9.,.g....Y.F.s...e..j3....fG..>7..8...t...(...0M2.y.V%......I...kf...Q.bM.l.P....cN...N*h ......5...u.9x.D.~...!.'L..)5..........N....9k.}.L<..*.vn...J.F..:G)..D.$.wk3`F.!.....@..T.C..bWD(Y.....$.G........q....Z.........v.mw9..b..1a{../...#.g....{..U..L.'.._.g....;......'6..s{.<./L.>...O...@.p.E8i..K......TX._S.pPS..Q..?..nXe...].s.....M...l1(.........Z(.az.Ii.....)..U.Cg$@.*w.5f+U.E.&>....4......f[k.)..".n......F.[p.n.5in.K..`...voO.......3.v.t..r......*.y~Q....N.`...K:!....u....{.....Y..A.*g.S=..c...,.a.N..2a.|.`F. 4.|wY@h...au#..?.....FpJWZ.9.u.p......t.vt....8..3'.C;.c....'....c......V.....L..D.PE.o.kY.Adm.3...|uWj.G...8.81...0.e..yn.q..L......v.F..........w+....<...F.N.j/).=....XL#O.....C...).o3hb..B.[U..FM..V.N5.....o..M..s......DF.C.)Y..|...X`:..+$.......b..7...j.@.[...C......P..d..iZ.3... ._..4....E.4...S......>...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1394
                        Entropy (8bit):7.889018943147721
                        Encrypted:false
                        SSDEEP:
                        MD5:16BDFE3944633A1EE1E57ACF3AA3D47B
                        SHA1:1B3F23A2C30646256B9209F4FD5ECF398C9ACAF5
                        SHA-256:1598D629CC11751F36C181077640B9B10C39777C12FCE60BAF98C66EF2D71FC7
                        SHA-512:D742263DE1B970282D2E08357B6F7A38E2B98E38E08E92FE02E063022EDACF12BA212EC9883102A8DC6C51D253B67F63199C04E61508173C6BE65D0D14DB4E16
                        Malicious:false
                        Preview:..Q/.....%{..%..k~.hWd.1.A..k.*D...hl$`...]6..qxa....M.......>.G..4.%'E.5...z....~.4...8m'2...(..(.p..r.J....].......}..Gkt.`........(l.......[........M..*.b..Ltt......`.C"fBRO..h..5.....m.fw....kt...]...-.z...E..:8.dD....c:.:N.)...............z...GTY.0B..7...4........p.'...}#1.$.o................dC9.ul.?2.}.u7.[..O0..-.....a....o@..q...C...,.......=y..n.U..M..D..!@.U...f..2$.....21...F|..^`*}..>..4.@p.6&.."B+~.'..D&.L...Ip0Cr.M..c.S.OZ......[_..{8....'9..x..u.....m.s..1_.y.\.|...{7M=...v.0.......^.zL.&..u...k.N{.........T.l.....u5J......T^.......NC..H.rFFx......Ca^.....Or.Va..Q>..,..=.Y.nb.t...4x0aX......./....'.K.A.....b..Z..r..Y.)G.x._....:!.J.ZI..zw../....6.qMY<.=.$/.*`.=..vD.t....ns.S....]|...........h.l7J...]....A'.o...E.]...L..}.2....<3.v....A.;mf=.).l.j..mT.N+..d%...p *....RM...P....Lh...9..{(.G......#..5/.0m..[yiK:.[..5+.g...{=?.....9...h.e..w...d........;.P*.u.d....p..-..rM.|b.5CBh.......,..%....2....s.R...............e
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1208
                        Entropy (8bit):7.839086105898627
                        Encrypted:false
                        SSDEEP:
                        MD5:9311B29619FE6D51FACD596E98D3077C
                        SHA1:D8BD6010833C314DA96873B4710AB77492D97E6C
                        SHA-256:3C8CB81592AE82A6157B9F3CEBD5A1A62A5C4130C78480ACFC4C0F268E6E7F71
                        SHA-512:CC564FAC26B6A66C62D302341C9CB11609070B4E879F2BC2D626551DB88D1D95FB6BD78899CF3CE21AE2E0C27146B8E53C9AFDE33618225170A98475CF358C11
                        Malicious:false
                        Preview:.[....&[c%NL.CP...W@W..`]..S..h?.y..w.H...K.y7..f$..:.^=...X.......f.%{.T......n+..jf.WM.+!Vi....A.Sl..#.X.9.-.Ed.......\.3.............|T.%...-M<..7t.?..?X.J..........4....}.t...(]`.. .d...(:.i.......r...[.'.f[.;Gj[.....rL.o...K.....hm........e....W.........K.. .o.{#&..4...X.....?..%^u...=....r.ic5..."m...mso...m.O.QU..|.!.h...G.D...Q...."..~9....N9.;...^@...|......T..e.J.K....Y.....J..1H..xA.n.X.oJ...]..V..,V... ...q.'].c<.U..m7..kd.4P..]ec.F.L`....<.DN...(.:.vvZv..W+.B......._...(..._,._.b.9...b..g6.....|..V.5..L...jJz...Jx(..eG.......@/.....2....y..~.G...m.\..6...G..gh.U.m..7Z...>..}..%.....!....'w.u!.~...Lx.|.G3.)^....... s. ...J.*.............J..3"#E+K:}........5.$....uNL....L..b.^.l..Yfw.?.1gS...(.y,..K.t=.N.\.S=n.M..W.../.y...z.@..Cj/.|.f....d..I.!.M....g.Qn...k".........)-D..B.m.%....lG.<...E.....%.....+T.W:....>@....Q....uu....!......q..#.......w3_~.............R.<8-h............[.n;.&R?.j2.....y."u."J_....,..5z.%.l.bf.$..o.,jI....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1060
                        Entropy (8bit):7.790497758106308
                        Encrypted:false
                        SSDEEP:
                        MD5:4FE9261F5B7CEEADBC9063F55D6B0805
                        SHA1:D076BAB7941F871BA14A8BCAA947F621B0828319
                        SHA-256:C462D6D51E693C6AB90663BD6FCBD1C94485BA5F54C2B771250FA631B36791F5
                        SHA-512:D8613C2C18C8529E058AEB258F16A139FF89F0F9F686B0A3EDBF48CD40216FE092244728DC2E6BFFC154729E9742FEB91E77EAA20BE8AC7CEAD92EC0169B18B9
                        Malicious:false
                        Preview:<...H.?.....,.u.S\.pL.,3O4-"9..w...P..zzZw....}....^......VF...`iZ.j.~..mo...62....o.AT.TcF=..........B1X.{M.AJ..)v....g...k..^C"...].........|&....BO..Yq...)D9...M.S+:E.......>E~s4s...a..kl.X<[..QQ..O.D.Q<Q.w.z.R....y...v..,.h.dt.)......`...XP...:E..E.g.L.......:...Xf....P4...K..9..2yQS......."...D.s.........."..9.:.L.v?.l.t.IO!-1.s.)p....V./z..&k...e....p_!+.....q....@lJ...YST..G....c......CC. ~A....../h8b.B..^........v*/.a`.5.:...........a.....q.&k...S.=..s.....6/n;0"i. ..j...^...p..p.........._/DW...P..+].T.7.FM....X.K:....Mx..hK.i.T{...Ky[{.....p.l..c.#.N.rc.....`..k".h=.c[It..b......6....y.=..|...(.+..*.O..C=.....{n...[h..[\..n.#g.]..a...q..........D.....+..._...X.V.3.I..BX..OLV...~.T...J...(.Y["....g..=[..j9..$..!A.$..3^t.*...f...A..p...DLw.H..e...../..l]R'.h..h.!.M..b.....y0.....m..|M...-.../.#....]...a...a.o5'.....)..m|...N.*..#7o.+ag..I..FWd.r..@L".5...$".O....2...........R....=.IP.Z.....TS{?drf&....3.7.._D.v..).0...t..hb*S...?-..W
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1084
                        Entropy (8bit):7.811102030976985
                        Encrypted:false
                        SSDEEP:
                        MD5:CC4DEE6663BC174139C838155ACEAA7D
                        SHA1:116CE8FB4C980597076225ABB6954C2289D018E2
                        SHA-256:A6DFE4DEB2656093210E6AC8F343FB12B6F002E1BB59C319D817389E350937A9
                        SHA-512:CD86BFDCE5E4FD0954C699C093CF64B88E73E167F7280537D7C6C0562C40CA13BB1A473386441C1804D608569F4E7D82AE3748779C60E2909FDEE16A4A7A2399
                        Malicious:false
                        Preview:...?d...JF..-2.j...$.[m....0.h..cc.qL"\*..l.B. .y.U0y.o......<.....O.g....[...j..........Jzr%w".=.d....R9.)..B.2.m.....N.....I9. .._/.v.FM...[g....g7../...X.=.Y..\.j.>..{p1c(.a^w.i.....d'..l...W*Rn.. s..n..J....i.z.l....CV".|w{...........@.]..s..S....VT>5.,T]..4....%.l....cD..>{......V.........pc...C*....1/.~W.........*.)o........v..@F.t.[^.C.......\.....3....-...ye.3_..B..?.7.+*........R.5.}.x.f..C..n<.)=....G.qfa..Rw......V.W..n....... @..c.....!/2..S.4...8..h.VJ.Y.>.Z..iX..B....N.......^....Y.KfD.N.qg..~l.6....v..5..1.^..VL.....d.).K:..(....f..C3?`.A...&......g..=.....!;{i+.~..7..r.R..k._o..^.......RQ.H..${.A.[.......'.f...Dh..|<..s.qj...'...{F..z...r.K.+t......y....k....<..L.......|=.t..T....4..g..%...o.Y...@m<.1j..h.b.}._.V....w..NF...d.C.'....i...O/Xb3.Yj.o.L...x<U...".o...4...8..${u.....q.'L.9<.VZB.......o.....~1..(\..5_...].....:...m....H...ef.@..D..[.%..k. ....Z..r.*aM...l.Y...\.>....]2............}..,..f?f...v^..M.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1528
                        Entropy (8bit):7.8836068933750045
                        Encrypted:false
                        SSDEEP:
                        MD5:ACE570C496D620B5FF0A01C32DD6D6D1
                        SHA1:D1A6C253C606AACC33EC61477301D0EEABCEEA95
                        SHA-256:02E87BFEF1B4D776312E23DA2922C7897F8269AE9048D0A5F919ED0B6807B812
                        SHA-512:4FA8C3C5DACCDC240C1ADF5740B726A453AAFF274DEEE1C451E8339F6806384FEAB5768103241E12D229A7102C43CB93523D430424E3EADD422732B60200F646
                        Malicious:false
                        Preview:.h_..s..Z........+F.l0.V[@..n\SL.d.L...vO.....(.2.71...i......4.70..8.,....zw."._.K..y..8Q.....T..q.'.%G~.N.....8..5.Q.......a.}..6."z#$..1.......F......3...U..Ey...Q!iE.A.QR..PU*.!s..z..=. .1^1%d.Xoy`...|y.\"..#C.9..`q.=.M..../...2.......M.@._/...]~......,..Qb.(..5.v<.I.T..t._(.........I...t!a....F........T....|,......Pr....r.Z..D%...Z....i....$C...m.....c.,?Ln.n.M...J...|...:N...}j.S..(s...;.).(K.Pw.`$.B...}......|.tYH.B.j{........U.W.L.]....#E.u.89.n./..d..-.?,.",9%...%....-../..!....H(.D..(u$.!:,..6Bp....:...)Q...9..S..d.TD.o[../..,.=....q..~wn\XA<Z...s....H...a....+.:.l....cf._.|UN.&.....l..9..3...K2...._/.......26>.`CSM..Y..J.&Qz...X.c....Cv..C........<Z.j0.......XXc.h-<3...K..M..4.X.hz.....Q.j*.<..5.. k.S.F.x..C.<...X@n.F..\rW..8..dCUZ.n......o.."W...vc.......^..../..%\.....6..$..8.B..K.-uHA.F...Ia........A;..e...m.f....%12WNg..8^+>.{.@..].y....!..W.A...!...(..F...G..=.ta...?D..+...D.#.K:.Br.....DzKT3....k3.i."[.u.}..m...w.p...I..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1084
                        Entropy (8bit):7.81589121203279
                        Encrypted:false
                        SSDEEP:
                        MD5:D3068A439D169EBB15381F3AF2E9F00E
                        SHA1:20BC68AEB135274CCAD334936D7C5084C41B887C
                        SHA-256:E3686342AAA5B6E66ACA95680A907ED5F6AA788AA1CCF548FC82BC421C9304F6
                        SHA-512:26825BE6F0D4329F6E82BF5FB01314E0BC021A28FF3DDCCE42D9D27C3C579106DF3F2BF769CEC3102C70A7BB62DBC5356967F28A991FA9E1EF2368E5B5517C94
                        Malicious:false
                        Preview: .;".].".<....nE....O....".i....0..j..+...t..X|.Y.B........X.(....T...u...Zp..F..)4..$.$`3..sL..,4... .!h.lWd%=.5..m..$..yh.y.F]..zy2s.[IP....Y....W....N...8..N...."<.G...P.5.....Zb~k...d.....w.H.dr%.#v.......7.da.>...q.>._....r......)9.%..<..A...W./n.L...H....^.e..>:.......g.^...,...T$.n....:./agi..6.....sH...qv.zQ...a._M.I../t...k....'3f..d>i`...2..E..."....k..8.......n.|u.4..n......<......=.(..6B"..o:.......Q.*...G.p.g.W...'.A.......a)q.".H.P.6|]..e..8g.B*C\#..QE../..f+Y....R..fS.....H.U..>M#...p..A..'T.......2...X.q...f~....G=h...K:r...tL....%.R.7:m.G.v.Z...^"C.........^pJo).<..j...Y....6E....1...8#...Q.=..c|...J...Q.hG.RB.../.bvx..E.;..y.....G.S.e.L.HLh7..xd...}0o.2.......S.D>c.N..@..5.....eZ[DZ.5.6k)e.w.{...%.!(....F..I.O.^..@(3.......?..f...W.@J...I....k..=..MQ.....{......E.']A:tMU..$.L,<....k..dr.(....+....Y.e.....a..l.%.....J..=S....~.E.......9.I..8...I[."......k...)...S...!........Vc....N.......n....J..7.-.2...').X-xf...,.....T
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1060
                        Entropy (8bit):7.810040433390215
                        Encrypted:false
                        SSDEEP:
                        MD5:74B9969A3DD16095ED18215802253F4F
                        SHA1:2A74412570EA2AB6A9A1CFCC24D86DFE295EBA83
                        SHA-256:0D66FE231D8F9A227875E2CCF6FDF0570A850C51C7BB090435AF838434A3767B
                        SHA-512:4BF05155529A8247740A01F437CFB252019B240F93185B3CDB5ED96B1A5375268659D53EB3EA2C46046BFF2DB0E1BDAB1DBAB83E18E07D49665B5593D656426F
                        Malicious:false
                        Preview:0.,....FJxlzB.+.P.S.*....Z.....h...o...v..";.=..S.F...;..qGD2i...._..H.*..P.o...a..V.s.7.1....Y.H..9e1..m.....f..h.(..G.x..r..gBTK....Te.^..^....'.k....6..p./A....J...tv.~..@gwl.A7h.Mp[R.@......ukC..u.T(..p....D....}...V..?oqA..0........}2k..J.9w.V~_..6...|.C."....H6rzHS.E.I)r/p.P.._.S.,...j|.B.'\)P....*.v.R...h.....a...bY...7.,@.'{...+..]..]..0...H..qYLj.....H.g.1*.?..BO......O.4...Q....].FI...BF0\..7..%....;.C..._..c.ipP......n..={.H$..id.~..x.z.v?d,5...z....j....1...d.....K1 .. .5.i..7.v|>..t.n.....C...P...5.M..g(.K:.S......;.t~.np_.-...h..b>h....%..e..;..z..4Fk%._...u.'...d.d.u.&.T9p..........o3w...\1....$.<.b..@.G>.#qY.t.=.H.@.P._....!Q<.o...k...Y..@U.bA.....`|/...w=......r.:...$%..v.=r.2.A....m.U.m..4G.@..z.n.0..&@..'.......A.I....l."...^g..e.\Kf8o...e.:....k..q.0.1m$.Y.x...}..e..nl.Dn..G.v.{.6z.....4O..kX..0.S.a91'G".s.U....{......F..e.I..Uxa.g4k.../......T.f........b......--.U...."uCr..g.q......f......@*}.............6..`O........v.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):1256
                        Entropy (8bit):7.826773660214105
                        Encrypted:false
                        SSDEEP:
                        MD5:85619C661BCE465A59449DE944AB9F7C
                        SHA1:F5CF779BCCE0761F575D3FA1F5E5644AC00AAA07
                        SHA-256:8E8CC867CBA7B08B536F35F168DB713567E3153BA01FDD87FCD4827A989CFECA
                        SHA-512:749E4CBBC2ABBAE26DD391FDB29ED13A95745378EB10B49FF57D1ADAA91FC421146AABCB6531767E6D9AD09CB9C67D6CDBEA9E613852BC5FC6E02215870783FA
                        Malicious:false
                        Preview:.D..fS.U^.s.Cht.qNM..\t$..&.o...wvmu...b.c.^.q..N..,.!..IS......E...b...y....~.~..}T..we.J...~.H.d.F..n.D.y=...x..C(....*.C..m....9.MZ..7.,.k6..2./..*.iV.m..{@#-......IQ)..Dz....j.'../*0.......!w8."./{....hA...8.h>}y.-f-..Ha.....[..h.y.w.eg....\.....~.bg^....9....C.....%.....IRR.A...^o....._......t..yj.w..Zi.ov._...X....<..9.G[..0@.. 0.N.'!..Ff.y...H......3.]%.D.GK.+5..L.]...."..1&-4.....X....t....T.=.....o..6......:...t..p{..K.....w...O,..n....Aaf.....S..6K.D......$'R.8......z........h....]._s.~.2E...=.e.K..i16e.t*.Rz..J.o8.[..D.+H..5.h....nT.X......BH....?.......R#....j.B..w.^f.....J.D....Y....:.u.@"zQ....f:..m.(B?....W......V&X.Em...G.=....D..j....!....baH4....8..|...{..].u......6%.u.{.V..+..K:..S...G....p6..\..1i.L..8.......{......'t~...?.-.....!?...v..r.1..6.c..9...+.y.eN.... ..(I....E"....#}.......1......d.rG...o.....$Ac.. ...G.....UO....9.....A.7.......I..*f....c..v..s5kyIw.f/....>$.%.%.@w.*O.!...D.0mL..H...\.c.>R?.N......?
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2078
                        Entropy (8bit):7.914338006020793
                        Encrypted:false
                        SSDEEP:
                        MD5:F662A02842EFDD1AE0A5D8ABF744A4DE
                        SHA1:0E388A33587DDA8035D4311E29567EF685E6C43A
                        SHA-256:6033A0D42D957FA84E49FFD106007A5C577A2D89244020D52130EA0D38295692
                        SHA-512:4BB5C32C484FF4C8D4BD359FC47F6CC9C30ACDD090EF420171DF71E9C888A65C38BB6A8E0C1BFE42AF2B87B58E9E5B781A9A2C1170A9ABEFADA3FEBF6ACA67B0
                        Malicious:false
                        Preview:...ta.."d..X.........%c.n.b....Flz.ly..../.D.FK.../....6...Z.....%.....RK[..6..S[@.|..*a '(.z.h.....'".z.L!...D...4..N.m.(\..J...i..J...7IS1......z......G..Z_q...|.n..,...7(..z..y.-).........U@......>....s"%....#.a.... ..>..;......5.8Q.0Y+....:.f:U....`.....I..X..a.x.... .n[.D.=......S.PMc..*....U.}'..`.a...[....vG7.w...9.D...S.rr......B.....A.......m=.EE....V.. .m...|l..........>B.}Q..^.N;..~N."..h...>{..1..B..g.....*3N...l....aJ..+2.Hf....6O...w\@...........jGM...7....."..7..&U....Q...%`..M.]..F..*...`.....=..#.BP.Y.l=8Q..z.<..>.}. ...Bg.........er3X{on.../.&I.z?.[,%..{..N.\..,.5..{.?.<3.9.H.Qe..=1.}...Q.3.w.hW...W.....~....O.0.aj...x.]R........Oi....K..\S..YJ....[.....x.K.`.0^...p.....0....h.;j...9.X..s.#.W#...N.0.!..=Dy88...[..\.....ps..e.....L.OEv...%5.......2.'.Ve?O...........v..A..;.....V....|.Y.;b...8.QJ...}._L.6...=!....(..'.V.`..Iz....J....:3........M]T.4&..2'......+...+>..8.......9.OsP,.u.t...}x?.....Y.F_.?s.'jz.6.. .C.7.i..T
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3150
                        Entropy (8bit):7.9411753028315974
                        Encrypted:false
                        SSDEEP:
                        MD5:BFB09ED2D8BDDB255B7F8249E76242CE
                        SHA1:0C4A4E295286F8A9F8190592F947AE79100508FF
                        SHA-256:12612D4B3D26C129DC20A52970E22EED3658FEA18EACDF81B6945F5B4ECAC474
                        SHA-512:DC93FA8F4F25AB7158C5D936DB8F61537E78B2E7257E640EAD7ED8D13AA202ACD9D2C0557C71AC2EA312A99C97EA31B74F99ED9B7BADAD69A569B524A9908629
                        Malicious:false
                        Preview:..1..z..........b....RYs3...V.9H.8..|6......+.[&...^...0;.4...D.`...x....C.D..6......r.R{..>uy.&..G.l2...SQid5.v......$...'.C...P...k...n..J]...B..i..`9.T...;g,...ev.&.a.X.....7f..&..`..CVj.f..u....Cj.#~..O..ZP.+.^.Q.|....N....R.]C......&..2.3..o.J......Bj._.e4..(....K..`.T}SLB..u..T2>.-2....S...B...|...q.1...b@.....x3..'.H...F.-.C\..f.....9....K..LH......_..Dx.Igu.".....NU..H.....#.c.v..a...u....o....)..Z......@=.....)..C..S..$..z|...&R..|.:..]2=.:...U./........y..9c,.K.z.Y#.N..w[....#O.1.l.....$.~7.B.(..G..$..2...k..3.i.d.p{;..sN"2....]......%*TI......--'0..{..W(..6...t..v..+...q.^...+z.u<m..lg.A....$...Z.m...u'.\V.!...}1K.y......t|.E.f... At8.f.L..p.tdkt?YT.0..I...]..v_0..c.#.R......kRB...e.z.p..N.......V:.....h...C.M....x....h.J....B..$Q.4..m.bR.....=2-M....1.uW...>v...8.z/..6c.......dS.X.%7vQ......Y..J..~"H..-.S.6.Vne.g.X..6.t.?.k....."..:...a$q..I.......S...R.j..i.g..xQ.GT_ ....5A.`... .M.....O..+.@.`......j.N..0..}y.4....2l...c......w.fr.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3107
                        Entropy (8bit):7.942832667392422
                        Encrypted:false
                        SSDEEP:
                        MD5:D8A3076C5D027B326CFD6814ACA2A07F
                        SHA1:1E63B3B1EE5930A066A960A4E035D36BB136B6F7
                        SHA-256:947D3347014A860459705F496E4BD8B5786A5FC1DCE21F1ED35486AFAA0C1F79
                        SHA-512:AB024C06D1275229D6DA83A6CBBF1867FA7DD3B46EC84B1CD3EE42BB49DD2D5C3C9CF5479B36E65DD5848B2F1B49A4DA8A214DFD73F65041D8155E7C18FBADB6
                        Malicious:false
                        Preview:r........-q.Pc...?......Vu..OE..U........5.....`....5^..UD$..B1..O..~...u-...nw.vsZb.-".N...c+.#.-Z.3?..n.3........Uv.\wv.N.r#R...jl...m.P.F../..e.....t.$.. .......!....9&M..Q...o......|.>..Y.U..yo...0..@..;g....p:...{..t...j...%..J]|.......i.u!..jNa..P).......c.b.v..U.1...k..@f....\..H.......!suJ..>.1.o...x^...`.\..v#..;.}...I..]r@...R...y..pO.^.&...a!.nr..:.CU.#?..F....1..... .Q....3...'.k.....I..............8/..Ba...........V-.T....0As.tNniy.4..vx..r.2je..X..j:..tY.....WAu..".p.Y.S.......wBm.:k+..]..R.e.b.kn5R...D...(..xUb`..d.)a...p.....>..\..cX.TU.{.t..e.G..H.......g....9M...........*J.B.O..l.....L{..).'...b.w.3.zl....FG`[+Ti.N,....E5j.f.:.Y...../F..m...*;....z.X..ECws.YLNq........y...mq..H...jl.FF.{.._.[....BiTx..)PYW.....0...\.I..%'...b..v..2..u..v;E./..K......4..."..L(....Q.".h$,!1GJ.v^{@#u...K"...-..z..LFl......k?.m..".M...o....7...C0.3.....'.Cw#H.Q*......dz..6.o\A~...iI%-.....2M."...yM.<.c..]...c4A;....9....<~.T...W.s...j.2..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3124
                        Entropy (8bit):7.938888229848099
                        Encrypted:false
                        SSDEEP:
                        MD5:D3E57F9696E039A5B8ACFEBBB284AD66
                        SHA1:91DC02B394658EBC9025EB516F3C84B8A5E80DA4
                        SHA-256:1E5130A956342993ABF29E8E60E31855EE077DF135689BDD2E22F514D03F1B94
                        SHA-512:11D285B5E8B48D007C9F09BEA92876B2CAC10E6FED15360283EC04654596EBC5FC19045D4A4FA8BA893130CD3B12407581D244AF710F487A576671D0FCABDDE9
                        Malicious:false
                        Preview:Yo...xidHia.f.[?.w.$..By@G..S...4g.b?...; r%..A....t6..l*..Ph........~..........1\.B..|...}.[..S{.v.!m.7".R.F........Z.B..)......q..P.....O..=:.0.i..b...j.ze..A"...n:......t...n.....;..s.+X..):.k:7.i.......J.........Z`[.g....o.Z{..j.v...X....n.._V.&..sG~..,.S'.e.<..}aC.......\.ykq...<.....{....NR... ...x..U.....x:..p..fh6......x3.O.....X.{=...r/...;.=.>L.93!......\g.w.w..N..O..a..H..O......P,.7.m..,......V|2..n[=^WY,.t.X/.Z ..&..6....2..(.zA......'...<.6Y.7..:.y..!*WSe....(.H.*..be}..Z....5..e.}...../.x.y."...bm..^Q..D.....`Vx?.fXI.o..*..U..E.)........S,m.'..*J..T.|Q.>..E2.f.}...Km.Z..J..5:KqF..................X}..s.......q..y...+...`q+r.+.o...].d.W.0...\H....c.n.".{..#....1.t.%d...y@E.m|f._#..N.}....)......Wm.j.E.v9>2...n....6.m.....A...K..61H...[..}.g..N...K.E|..h?M..:`..e8%...|...^.....`.J......y....x....Y3...RI0..ElR{.S...TQ..X...{...H.W....;AT..A~.'.h..<..k.......b.G.9(?.......j.....O6/.V.>.-..\........h.6. /.@DG..k.Dy.Qq..RW.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2084
                        Entropy (8bit):7.911723990888468
                        Encrypted:false
                        SSDEEP:
                        MD5:750F6660FD7AA2530CAC42D95C74CF65
                        SHA1:C9AE84BD2B2BC97C048AFF4F3D181BB75B5C63F6
                        SHA-256:FEAA5FCCDBA81B3ECC5B4DFB5F3255C9AEC808FC8AC0EF85BD005A35C1EAD7D2
                        SHA-512:75035B57A09FB8E3D1785688E9A0240964EFB6EA693FBFBFB96B1B0418550F4D71B1211DD03AFD530C68097313E13128228A117A98F6B8FCA01B839660DB29F0
                        Malicious:false
                        Preview:4..".^....m...k......5....Y....o.vvv...g.c..........A....[yuW....kq.R^==..~D..g.....S#c.>.Tq......h..T....YJ...G..z.*.;z....J..g..Cq.>.|.n.i....1#..E.!{<...x.v<h..nFg.yCx2O....E...Y...3..k....Tp..CR.9&..g!.q...]BE.....'u.h.lo...r..."...$%r..&eG..Is.l9.Q.C,..IQ......'..gp~x(<.:.`....4..........IQY_.w.qb...(...Z..'Qq...L...|/L6..S.,....=D..f.2......<.EH~..5X.ci.T.k/B5..hv.......a.z....z4{.KP.".!Y.Zm.."1.'9.....{.y....3.8.b.U.-..}o.D...}.G.yFv.pTK......C.N...y2.55..`.....R...............a..X>.......C.E.....K.!*...oL..D......pS.}...>..../.(...>99. .......[b'.l.K.j}9.Uf.,q..IBnr.o.{ULv.#.=..8..[.7P.....6]..F......~..7x....(..e@...!.p..h{(g.NMr..S#..L.._.h..Y....?..$k:S.A....Q..8.....s.Q..y.dv]......0s.....k..../..[...8.v.1m..{...q..g.[gC.q.q..:.gm.7.Q..x.*.<..-_....::.....o.CN...ym..C,..r....5=.C...G.O...E.2.|.=."z.-.-@.w.e.q.....;....N.....H.zKv............M.....A...kPz51..[..Z.\....+......<.N.1 .V.i.z..W.U'.G...8D8.._53!..A.e........Jg..G.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3135
                        Entropy (8bit):7.941730176952539
                        Encrypted:false
                        SSDEEP:
                        MD5:3013D5BCCAD056A60E3CCB5A84E273CC
                        SHA1:BCB37C6E3DE4413DB773ACE1683094F1D194769D
                        SHA-256:CFD01D17D8A7F952A60569295568299B4EE64B40AF9AEA6F3F0BEE7B71B7B93C
                        SHA-512:AACDED9DFC5AB10BA5326B0D9A2C95F88E00F3AAE959B28FA19C522E51E12935270F246FB9F49FF95B208384ABDAD2A472280FFF55B6F09A40729F72C8302286
                        Malicious:false
                        Preview:.....p...<.z.Q..>.....Ve.7.5.<.....v.i.Y.xJ..o..\.vu..C.....6Yd./..;..P..qc..b...6..G.@....p...N.fq.r._...........:..X...s'0P...p.:..(..?.d^f2.H..@A.,[Wt........\m.,..7.Y\..}..dR9.Mq.....<..8....S.px..%.o^.oiL...Z..}.r._.x2.x>..f...j....5:.6....Bx....FR..C.t8....? ..*W..0..~.!*.W....8...v........-o.t..A..[V.S$..<p.y.W...rP..K^h.dA5.^a.^..K.j.%..X..=..C..........8S.S.b.%...4....T..{.d(..G.=|........k..I.W..-.8Vb=...xU).P.F.n.G..o...F..Ef.{.T.ID.......N..W.p`...8..*J...R....[...C.9Z.-.1W.....8..;...Dv.........X.....'~....Q'e.../...B..I....S.......=#..B.*.v9...&t.....Y}.w'.....z`..I...SUl.Z;MQo...I...2..n.b...{.&.N.....]..vX*}.L.*...Q.'.....M.....B.#@..]a...a.7......*;@Q^.K#.......N..P./...d=\.m.hu...\...n.~...DK.8....o;.O..o>...=.(k}..baIHp..../pC...V.L.\H....@.L...W....S.(-.."qd.$oo.k.@.v..>.J..MH<..\!..../|......}Y.:.W..+8...f.....t.............Zb..+S...B..:....*...kV...$.8<..U..1.....{P#..l...E.....l..8...U......$.Ev.....T...Ba.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1511
                        Entropy (8bit):7.88213156906849
                        Encrypted:false
                        SSDEEP:
                        MD5:19C136A34DD81281A49F5CCC89FEDD2B
                        SHA1:5379CF5A535AF55DC6415F499762474CC0DFAE47
                        SHA-256:2EC416ECB102751C0CF6C1711CD8345710BA156361BCE33222EB424E1EB5448B
                        SHA-512:297BCAD38DF4C1936CC00DD93EA2447B7059D1B19CECDDC0474FE69E52534091C8698786DB3696A8DF2461AC20760B25C2204F12F92E8F4C8C27342F661598CE
                        Malicious:false
                        Preview:...K...?.e..Tf........ .b<].ip?..=.u.A...k.M.&X.......{C..>=._5]/..s......H.3.f....a.4..K....Xuc.*9F....du...Z.O..J.;h.^.\.....p..b4s....t:.u>...t..m....y8..^.....H..........>.k$,6X.Ix............L..{qy...Q..:'..d...t.(W..r.oK.....K...m.......%..>.N.9.3...%.!p..Y..#l+.....#=a..u`.|..{.........3..h....L.F..?....1F5.t.j........C.h..G..G!...v...m~U.$.........Z.:;.....a...N.<..U..?n..........\s;.W.o..;.&.K.....T..*.^....A.A....1..,.@...u..m..}....:..q.O...zC..T..0..+.lN...VD.!,.|.....b^.....9.V'+....N....VK.AE.(.=..W..j..y..j...0y+G...B.. .wd8j9|xa.|.H..\.0.h-...l[Q...Y.....?F}..U...=..=7....e.t<.I)...8....~........@.......[O..|i.......V..vg.....=b.$_........L.,...aFa..R...A...1.0|.qaR...7bK<.C...,.>..6L....iS!....zV..s7U.....+.*>~.g..d...y.....X..uF...CB...x5A^.~.8..zRJ.;.stmI>....wOBj..1.%.?..*]-.c..h.....=....J.|...|....AQ,/.....FB...`_..UCX@..jf../.Ze.s....XE..; .2.C..w...5s8.Cr.#f...p.}...(Dnf..V.]UbN.J]$.....FHw...12U_.Y......0!..vK:7
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2596
                        Entropy (8bit):7.92798151154488
                        Encrypted:false
                        SSDEEP:
                        MD5:C775AAB10958196BA8AFA6FB2BC57805
                        SHA1:0BE5F031DC71E3DBCDD07720CBFBA9A230595A79
                        SHA-256:9A518635E7D2AC7CFF465F07B1D8C3F70CC3499F798454FA919CA224D8DD0C8B
                        SHA-512:B2E08EBB3CF298F1B279A77D29DBB895D84F8B177E44EF95891A8C0CCC6BFF8C9564828DA5F6D6C91E65CA862FD6CDD4B3D77A999D166EFAFB3A39E44E6EAB7D
                        Malicious:false
                        Preview:......V].sh;t............U0.Z.......}.@We/... .^...Fl...."....xQFU5.n.....!s...81....1H...wv. ..<.-..m..Xv:...xz......Lt.....s.wb...n<......o.h..$...*H.y.O.r....w.T.bx1.Hu..n .......C.[...n.s.5........r.P........'JiC.`B)5.n.....u5.I^(....&o.....EW:..*..+..V%....VF.3...Ds...!..n...j....:.q.3.v.6...i..P{.q.>.l...k...b.!S..6@R..h..*.5`5.R..%.R.' ....tL......I.H......}7..z}.,4..9W.+/...\.b..P.Z..a.....HH.......@'...Q8c..D.J.UDm..W6>.$.....6...UkY..'._L..Qj.r...x.W..C?....[p.....U+..'.%uWdl...[!C=.u4....k#.s...q.M..k...............$Py.M}&....$.b..LD...K..z..5...:.@...E...G..gx.Q.;2c35FM...l..G........W.tQ9Q\.}..~.}g.........a..%.%./2'D.H.z.x0..../...2.3..c.m.6%.........@f.....h+.p....;+..^.....W.1.[...S...+.J.....k`.f.+N..m'...HC.a.k..QAR.x.H..v...:.).+.2iD.~w.=..A...h..7<..`gPz..Hn....?.....%i.........s..-..1..i.wU..v.Bv.@<....]^.....'....]v.T../.........*.rC.U[C..,.=RV.ee..Bk'P..'.1.....F..".2HG[q.68...F&.....o%.5..U...J.....=...Y..._..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):6692
                        Entropy (8bit):7.974854514871072
                        Encrypted:false
                        SSDEEP:
                        MD5:5E8E122134A6E147682BEDD9E8207AE3
                        SHA1:B95D46499EEDC9F829C0EDB4E75875DF9268B0E9
                        SHA-256:5AA59CC31B913A272FC11A64E3EDDF7FECEA7754060BAA67A6FB88D4FEE77885
                        SHA-512:E88E7BF693DD0D76132FBD66F0A915B46F783855AFF87290396AD5F9B8CFFD7EE5866E8FB0731B32DBB53787392C5C918513B74EB590F6C77E65FC60B18FA61F
                        Malicious:false
                        Preview:._...+..}.....d.5f;d...V...o'Z.[...W{-...(7.d..7...8"qlN....d....Re)......p.-.......r.d.....>...?..=.O2.j...R*..dfMr.^i..[..O.....s-....z...U.9i.E.@@1.{C..P...~........}.L.......6*..[)...t,....R7;..t%B.2[!S..G#=..m..F.}g...;..,..6q.5l].A.FOP..j...7.*r...[_....8..?...Qhj..=...fK.J..G8=.@Nf...)....>.;..!V.h+.S(...........^iQ"D&/j...m...QEOs.Mu...X.m...!.l.u./f.4..XA.o..u.W(.,M.v........%.M....5..v".^..H........S...D..Q.....U.O.Z...N)..Aa5..h-......YP&..lV....".>s...,..(^'~$x*.0:U..VTZS...BB.D..X.D"...1....^...G..=.../9x.4=S../@.....A.r.h.%.Pd..l(..'.m..{l.q.U..F..U....~...U...P.Jbn)+*9~...D..m."..K>.....^.Z.G.....!...b.6H"...E..B...Z`y.&.D.>F...f..x.eM.;..}.}.NLX.[:p ..T?wD.`?n.~.=....].9..]..."..^.81.....=o.a.=.pg..+..9..nNq..P...e.a^....t..mr.n.\...D..-p...N....HO...U..%O....c.Kr.5i......cf...*.W.../.}..6EwjK%..W.q....F.03.+....b.`..V..]N8..V.#.........\....r.v.u..~D..ZS.@...<.....|$>..z$1.M..g..r..)....t<t....Q..X.....^.z.......+.w...9...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.918380767674056
                        Encrypted:false
                        SSDEEP:
                        MD5:6EC64A6788373D894A5EFC5B55737061
                        SHA1:04E5EC384564F44092C900C16415638D21430454
                        SHA-256:B171AD85A230EB73216ADE8F6EE39F049BCCCB6FE8F785C1963642FE35450166
                        SHA-512:3F1BD2F24FB36C21F370FFF2052FD8A416CFD2CADF8107854DABA5E01FD56F7E338CA92F0B01AE592E0C45F895B460AED4C3F5BBCACC702790FB5FA90FB4A8FF
                        Malicious:false
                        Preview:~/....k.I..46{.t9W.Bi..#...l.=<Z....7H...[.K.n2......u...x-.c..P..-...c.i...0y...U......:AL.P>.D..E.q...O..4..lh.....;...Y..F-M.....`.2.....b.....f.....q.Ew.,5.n.O..L...S...X...G..l.5...yO..>...N..X......Kp....p..{,.Tg,..X.x.i..2>."S..|...K#..2....D.h...f.(N.E...'...z....II^....Z.F.:Qp...2....)4...U.....n....%.7....xV....,...C.....A.n..#. ....t..b..D.TSb4.P.G+...I..a.........`.a.iqK.9MQ...oJ..D%>G..1...*%...g...q.iO.."..BGb.....1.^5m.....j.I.@J5........Q.....!......C!E.J..V.dZ...yS:..Z.0.J.s\....~.?w..S....|z..?.,7k'......."r.c..[.TY...F+.../D?%..t..".B{O...>.......0..1z..ap.l......3....z.u........l...$m...}.^2.[...n>b..c..0.*Z..Ft.8...........Yh..d..."........2......:cx[9.K.54Q3R.\%.+.u."wa...]...L&p..I2I..5ms..A.).{5..X...4m.9.W..6.$7[.A&.}....X... L.g.`.r.s,Z...2ak.t.{.,..........M...$Q..d.=......{6.R.02... ..D..MNCC...*.)k...i.x{..O6o..=..6.W<9.R......A._.......a..E1.Whu//...2ho.9.c..C..8...E....u(].w.....rW...G..8..R..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.886226709602487
                        Encrypted:false
                        SSDEEP:
                        MD5:A3061BBF3C61F3D17AEA58990F694F4D
                        SHA1:72F26B58D22A9D41A726A9770696A3BC8EB2CE4E
                        SHA-256:09D899F1AF5A834EBB2B0D36B4695514FC6A57306B06A743FBD7A8BD22EBE793
                        SHA-512:9958C55BD7529705026573D7711B2078539BD3FBFD59C1A292E6030CD9B5F8793392F039AB344CD215E612496DF3091AF248380D2BF273495D91EDD145B9380A
                        Malicious:false
                        Preview:WX..2..m.....;...2.....OE....Q.->.|a.....m.;..-.*...B..&6..tou....S..M...X.zM.4F ..i..W.W..NQ.-..weI.....o.|.m.R[......N.%.....!.8.v.~%.'..pY...hv.....<.....u...U."...[....[...O$_..~.Y....<.....t.2XK..!.....4.Q.I*.85K.+Q...m...\U.M.%..u....@D..t.:.\Q.I.M4.F4..g0A50..-! .W....$.B..I..M...{....+.....E!.k`)..j........[..,........U...9x..R.w....D.k....7..D...6.P..Jq.........."...i..t.\..>.#..'96tJ.+.(.s....An(sBO.'..f..y&<f?.a...(S....rm,k...L.....p;4.1~^.F\...>......k4/........yKH....I......j.........30B.a.)0u).-=.....'6..hSY.pm...+.X..tm..;.`..(-G.7G.h..h....H..E).RSy7.b..b....~...T......$....Q.....WK.tG2.....g.7....%.q.6.(".....c...G....Y......s..`..c....`.3.....%.y*...[..&.3/=..M.:^S.H..WV....re...}..=...f.F_}.Me..J...T..wy.V.m/U...0.........}3.W...b..D.....8......2.>V].O0.....J..}x{.-.....*}..W._...7....)......d....m.SO..".m.>..s.(.M........Fw.vE..[..v.d...y..D...6S.[.....@....K5<C9X.+.Dk.........[G..9b'C Y......VD...3u%L.d.%K
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.916659730375456
                        Encrypted:false
                        SSDEEP:
                        MD5:A5E04E207D673A172622EFBEAD1BBE0D
                        SHA1:A331FFFA1B4957FE675C80258B71DFFAF84028D3
                        SHA-256:FA7E906E69FFA7AC96634CAF36C91C71A2EDB92A980F9EF4BC69113E48AEC14D
                        SHA-512:CA387A4EE7D90AE7DAD4783128F14F05487693063CC8BF3A246C59062B5DEF939D961D1FF8F9D5ED65EFA1D0E1A1CE75554464D447AADFE05EE42E1332884925
                        Malicious:false
                        Preview:.Zb....i.H....`Z%.U.H........RF.=.<..&da..u......%\...t.e.?.Mz.G..2.0L...{...G..$.f.f..U.!...........J....k.(SBH.:..F..H;S.....T)9k1.=jL....%.<.TdQw....#...L.;&S..\.1....U...Z....D....H.........Fv_\M,..W...C....6....N...,xx...V&..../|DG8.@5..g..&..9..Z..X.F..@.....p..*`F.c.n..o.!+.l..#.1......T..?+...X.....<......T..U,;oIRQ...G7..b_:.....N.,6T.?...(...W.9.6. ..dk=.......e.C9.C...Z.s0.....v*\.x.U.Win.$......7.....<...,....F{H......x...;"=.j...]!....>R0%."..bs\yZA...>.....p....)..x..H.........X{.ho....n.._Jz.n..JEs-s.E&w........]...C..I...I....wv..f.4..b.Zy^.Y..v.._dV..rL.Q...G.A..+a.x......V.'mj..o.m..Z.F..qj...z.2d...fw?._....4.H.P.W..#.o.i..v.q.3.Mf....l...X....4.w69..rja7...E.O...'.!..V.y....<.C.{........[1p..z...u9..=.D.A.d_l..g..r.{?wT-2....E_...v........&L..}....5<M.S.F..%....3...-."..n.0.@...1m,.c..`.././..(..m.F..;.7.0>.Nt...%.......4o.2/...]..N.O...M-.8[.E......C..x...=.g...5...C..m~.&n.,.Ag;.sua p.y.j!K.h.y.X....D.......9....".
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.916938276299279
                        Encrypted:false
                        SSDEEP:
                        MD5:46B0772578E8D9D1CEC1EE73EBDB976D
                        SHA1:E8F0BDF45CCCE0091638059BD71ECEE2C7F05CFE
                        SHA-256:9A819970624F28F184677DFA278401779894AD4CD7782A1258944E64B6BCF47B
                        SHA-512:B0E8ACAE25D34532A27A0E9E43283BD1789F53000D838EFA28AFA0D3AF45C682D73289BADC4C045B8ADECCABEBADE0124E7385EF17CDA780E18B56B9C93EBE42
                        Malicious:false
                        Preview:a=..e.^.O...^...M'^.......].{=u..)R...).......0N.,..3.?....6..NS.V2..6.].......Z.o..L...M. ..p...5..XqQ.la...+...'.....j.<.y)..9..jmX.^|7:..e...#.`.E..X...*.....%...+H$bH..t9y.....^S%.^..S.S..sl.c....e.W;/.7}{...&(..0D...7!.....9.....5..L..t[y.i"$..]L.j0.P....|...b)"iM..?%z ...q=...=.3J./...G.0.h....o...F ~.3.....Rcl..QH......X{.z..KO.U.t.o~..f.......o .o..";i.[....?..._r..!.U.....:W.7..8...v.......`....K0.a...#."V..t.-^b.......s......b..;....x.Qv.)SB.J7"....a..<$n[~n..W..7..<sM.V.q.~..r..#...i.7.@xPQ.U.z[*.1.R.|1hv[p.....\L^.?..m........$....z....M..-..........x.y...Pb...?..3...".2....^g....E.yc..]u...H.?.a..-k...A,.F._.....X...E.........E..w.Vf..<....T1...v0...j...........w...j.)..9....0m...dM....)...C....$-..y..!c.t..,...^...j....`..%....cD...(..../...H2.a9.J.o...&D.c.;1?....>.v....!.z.SA\.K..K...9o9~....\/../...7..~....@[.f...2.P.^rzq.y,.A..mi(H...#.4.Hm...fH)...<..6}.2...|...4......c...i7..*.../.R.ef........U....-4...Pf.b....gn...fQ..W
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.909573754592628
                        Encrypted:false
                        SSDEEP:
                        MD5:3FB4A9A2685712A74E0699CAB2FE4237
                        SHA1:43C96CE17EFC6EBBC5D2A3078A2C4B7402048EEE
                        SHA-256:1B0A0F1D0FE56B9D3A25AB1B181618AB777064458F88BE0DB509071AFB636CB8
                        SHA-512:D7467D6AF0AEA0F5258C2885FF6D1AE23A523337DC9676B556665DD23356F96C7C4E5FF2D6508A7333BADC738DDFC73AD15762E927E21647A3F13D4315F0D3F9
                        Malicious:false
                        Preview:....U......S.N.....]~.~.[...o.M.C..N..|.LG.j{....3.Xsv)...$.@......Og.R@...v`.X.$.E.;$....hod.....F....,.....K..zI....}Q..u..-..~..?..'Z...p.....<.L0.?B...ID...]...jJ;.lX.D$L5.r..,B....xR... ...Q}g:8L.0.o......gr..~..,...v...p...8..d.!`..!..o.!...J...3/.P...0.:.......N.. ...)..0.C.:TG.D......`H;..^.e...F(...8x....t.i..W....*.2}'....U.Cq.5l.zP}..E..WZ...W.h_.I..0$..N..w,y...F..I.. ...}xc.I....q..............r]....FQR..X.8P....v...y.....d..BM...2.....(.S6....Dhuu)..Iu..un...B.|<."........~.|.k.[.Y.^....g..........NW...c85..J......A.... .F..S..av 7.....V..6Qvu._....3..Wl.B.O.....F?.[...w....dU-.c.r.K.7.....ty...9G.c.>.w:.....-......%_.....of#..{6I.J..r_......././.......R.....^..b...9.9...{.0.o....:...7...y.;a.u....;..4...L.0.<....D..8%..9@$.a.k.z.#'.....>n...k.#..g..!..#..V}..............z.K.t...F....K$(...>...p:.G...El...j...v...d..........3..p.J1.....~Oi_..G......I..D...#T.........!......|...,.r.'....A..,!.?<.rP..[...n.l...l.(....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.8965075264365305
                        Encrypted:false
                        SSDEEP:
                        MD5:ACD34049F14FA3BEDB7ADACAC0355CCB
                        SHA1:CBFF7689689664721EC9B4A5DE7C33A583F2C423
                        SHA-256:F84EC1C1DA92B40BF301372C97CF5BC86899C27EA90A593D8228157C662A9A5C
                        SHA-512:47D66F4B43B6A885D17BD97358FFF5244214794CE6DAE6DA96D378F7C9D6FD1533ED6ACB5443BE27D323C32DDE3E14C8EA4B7F37D35E8E36B27E1770FDAA559C
                        Malicious:false
                        Preview:H..a.b..],.....U....4,.N..$.a..=..li....o..u.O...6E.....'..7}p..).4h..m0.N#....bIJ.]..dY.apV.....!."E.".....q....I.d...o w..4..{...0.GYhS.......V1..W.X.d..6.]+..7.!.m.L.#.%f...n..}F...R.z.@on......*....ib!.Og..i.<.!..........j.A..m...*%..M7....B.M.Gh*.3]..0.s.S! ..Cw+.... *.A_W.V.......1.&..G..a&.(PA.^_..KE.)...qZ;.6..2.-.`*m.\.3.e.\}..y.Nj..O..DWN..8....!Q.....R.&.r...d.]O@.."s..TH..`.....W%..42.V.q....O...a."..........r..z.;.`/..y....?...NsvO...]L..\e.....i...YH...A.U.z....s?Z...N.&.-^..;.H*..D.! .Ly6j.'..v...[4g].td.n.(F..u0..1...^..u3!].^..{.C.'.=...Jo.g.D..N]ph...(f...~....f...........8....e..|.."-}R...M-..?..R.U....'.......Q/IP..|GU.a...e}..=...H....Crc.:..~f.m&b.TU.'.f[./R...'lF.....g..j..znS.+.....h........Pu....~.3PM...}....+1 a..g!x..)q.......{.D{q.....K...h...'.b.d...y........1RA.........-....F.C..@..........ZUI.>.....A.wH~.s.'UNB..;.q$.3r....>..^n.@.......^.L..I.L...........hr7'e.._...P'..Uq)......n].i.)7.U.^<ih.X./4..5.h...X.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.920198549698501
                        Encrypted:false
                        SSDEEP:
                        MD5:9C51A77BC39EFC9DD00986A273BB8C7A
                        SHA1:84BA5F46498341BDBE11B9A44B6AD0D0DAB5CA56
                        SHA-256:D9E08B4AECFF9CBDACDBCB3E9AF647471D326FCA7199835F45F16D1F45725575
                        SHA-512:675C7EE2E651932E027610956E88AABCD7F1A3D9E2AC4FDFAFE3853A52A4C9E97DF7F11A2423D5A18202846D0895F0022EB7035D7817B1AECD59ED9CC655C57F
                        Malicious:false
                        Preview:U.:QY.R...YQ.....Y=.*.Yh.q.. ./.. ..|sd....H......N0C...y..,.A.hL.$r.....]...........`3.T......*..n.../........g...Hf24.r..g.$..N.`............v.K..\.......O..nr...].....*./(we...:7....h!..=../2.1Z....B.)r..@O}....q..[.]...rqs..p`\.....<....i.Q..MX7O.-O'.H.....LY.....I..:?..V5..p./...5...f......mf.......,..~s._...W.K..!^5.i..U..{.i.I.'..s^....b........-'...T.7.J.*9.....V......+.81v.+.e.g..c.:i...."RfW.X.r..6ZZmI.......1....c.g,...jS.g....$..F&e.6......0zS..g`.L$}...9....PW=."'.}.y0r.. .W7e..D...6/.,.:$..I.i..q.Le.Iy.......Y]l.$u.).yn..H4sf.)...U|...C............J....F..)...&..:w2.R.F..|.P{<L..k.q.!....7......(....e.U?..o.,d9|X\..q&....&.V........3b..$..Z.@.z.......K.......]....:.&`.'.I...H.va.3.{....H.E.P..2.z.(...kX.*....z......~...c..pS.YB~.....k.Ym.5....N...U"+........".8.B^.......y...+..o2...?n...#Qt.....[.'.Io.(;.g..h+.Ss..:"7bD.I...).....u...@3..:prk..U.2.,...S.. .. .&..!M..g...x.%b...[T...|......4..M'.....U0....%.8.U.1.p..E.EaK.4.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.9096713238618666
                        Encrypted:false
                        SSDEEP:
                        MD5:69D26FA1EC86454E476AB7E40F8BBBAB
                        SHA1:81550928906EFAB36E3E4B2EE97E0FBBC734E02B
                        SHA-256:D1C5B1F4F286EDF44CE8E15DCF1107E24580685E06BE7D0F70BC1D86AF42B027
                        SHA-512:B778CC26B1E596A04BDB780916F612E86C14A70F1AECF8A21D8729EF94861B8BD5A089AA6014B7DC1928AAA674D113A82CC3E59ECC768419A174D9D0323BEBC4
                        Malicious:false
                        Preview:'.....{}.?`2.......j.Rn.J..6.jV..=..7.c...D..k...@.,.XB]S..g=...J8....x.*..E..b.....c.M....2'..........c..N.Tn..A....l{.>...w....Ixle..._5.Z....]...@..|89....8.......+.pz..OxW'-....C..g.?G......n......7.d......Q..............a.h..\:..w....]m...+p...Xi.I7.yh... Q....u6......oz....s.A....u.c...u.F`.Dx...$.T~..P...............v.k.$=.T(z....B.......o..6c....HU...g[.M...$P\...'|..!+M...Z.ER.,.Fy..V.._.l.c. ....<y...eN.1_.^..]..>...8........rA.r....8/]...B@a.<.....8.`.|......c..i...N\.`...d..t6=..E.9}.gB..-.rX}....D. .&O..{2......PE...&...A`...-V......Ef..d.9o...ho....T.?..1.U.lv.).8.{pa&...Y...31.>i%.0.h...e...]..=.M...z....3.......V-...OF.(......Dg.6H...x3.....uw'..........o....t.K).yi.MtT...*S.Q.....7.....3....{..v...y..l..o.g....Y.$...L.I.'p...h.|...j*.S5.g.^........}.>}..:......k...-..t..G.f.......r.r.....y.C.|..CF^.u..vT..:.C.~....L=.&=!....Ws.9...-5.....J............$...F^Xg.....\_..].OW.S.&a...Wd.......4..s...0=+.......|.A..8..|........
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.903827149873287
                        Encrypted:false
                        SSDEEP:
                        MD5:F8DAA7A556A23058931BD638D8034593
                        SHA1:4324AD1A7AB2CD9DC70C0C98515813B90C1C8FBE
                        SHA-256:675D537AFE8D134836E2DF1BFDFD697B6A37C4903D8B597E3864066AFAAE29C7
                        SHA-512:BE003801357C5E987B32248EE5869372154B7F3AFAED30CEE09CE13427E3DD9D76FFBF05F1AECEB3B886B98A5AEAC8B046D3FF55CA4EB0812FFA20952795B215
                        Malicious:false
                        Preview:...SpV.Xh...\B.x...&...j(............n".9M0/./..P...B.vcp.?+.......(.....`F9_..4K....<`.;...o.A.f...........$U.;8...h.-.-=2.^.....%..-...:/.q3...1../..w*>..jf./i...|..v..:w.t..Uu..K;....N..._.^7t....U.E.u..q.D.E..+...xQ.ZCB...#.......f.r...p.S......x..../#xA......|...U`.F,...e.l.s...,s^3...y.S...<.W^.....r.>......+.P.'..:....IT..Z.....x....r....r..f.3...5..(>n..1...s..|.2....7.N...}...Q...4..L+...*.t.).<.S.f._ckB.&.p.!..=.3.*.M........./..23oh/?...1s..=>...b.....P_...(....T.XK.a......{/y..N.p..t...vI.s.d....-X.1S....v..Ky.0e..Ymc.So..?.^.n..;u>..;i..;.....~=.2.1B..1;DZ.X.$.!Q..U9.Y.f..X..?A5..4.....~.g.Y.d..O.....u.9a....z......tK;....1.c......Xr..0p1&.`j..W .F8sU..q.......L.M.;..'..h...c.i...H_.....U..{...fk..fv.0r.L.....s...'..sT@..o.$Q...........$.\2......G.t^l...x.-...s..........Y..1N...D...c...+.9EgW....]..]..1.{d.v.08.n...^.U.s`.....a{..\.J..Wk%........Kr.......1....3...[A9..|....f...E7...Y7...Z..4\.R<.Tf...i.pp!..1z3s7.dE...(....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.906105118409948
                        Encrypted:false
                        SSDEEP:
                        MD5:DE4371CF9718859B4C60CFEB15C16B65
                        SHA1:A1C43F73201DD39B7CD0D871CA2B75B5E5E01CBA
                        SHA-256:3AB4B5A1F3A4449C4014BF9464DEE7D4E3F22E9F4036421A6009CD1586A92660
                        SHA-512:78BDB3DF9B0CD60A6AF375820683B040CB290E910958F4A1101AC136F756804AD9B5B89D5F6B8546CF4817185C64C593414B5772330CCF6FE0C3B1B52C14A024
                        Malicious:false
                        Preview:...E\.."s}...w....D@e..+%..d.Y".V..@'..t........@....Up......Q..2.$|X,..../...P..3..Q.!y.qG....k.......\l...Z.&D.c.0.S.$.k.1.....Y...?..(z[7...cjJ.......(5Yo...<.}.`......c..0O.....X&..8.....k.RtS...E3..M...H....>.p......UU.A...M..2.p.9c.........l......#....g.X..*_./1.u..Hk.......3kH._...I.[.$...6F0.um.~.cL...OU.*..$..e....`&.n.#D|..u<C]...?.Xp ......u.....E.D.....g.7W.!.....Bb....)v....8.m$.f..x!:..Q..9fv.wc...G.....,...x..k@.......>.Y....i.%....\..-..u&....e..C..b..........|....'(..61.@....eH..M....4.....A.....1../#.~......8ZX.Y...d.1]1k.bIh}...?.H"z...y.J.,.S.B..."...=W.G..CDr.@K..t..C.Z..7.s.M.,.F.RTPC...m...8....7G.E+k2...{.O4...M.x...[..~.....9"..`Kbng).'kS@ ].0.>.\.|.....[,........!....e....bK.....p....7.XC?..R;o...5..Z.o..x....l.{5.pR.Yz(.?...4..)BU..0....%....%k..x.fd.....8...;z.T..g.~'X..0.....Si.c..F.X.R.E.f...[.Y..SDP._R\..dN.Vh..bb.f.iyb.J...].(i$8C..Ex..k.....{...._..5....j`S......`.m.;..O....E%..^w.....\......?RAT..A...]9a.N(A*...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.920119388198143
                        Encrypted:false
                        SSDEEP:
                        MD5:20174145FFDA34700A4D649012C6962D
                        SHA1:B618E8A15BA6D76BFD0FDCCB9B21492AF3277564
                        SHA-256:FAB25F7DFE0A679219501B99B68C67D039418D693506597FB74EBC84916749C6
                        SHA-512:C78C377043EAF7932AE9A10163937FE777A8C857A7F201D5CA680B4272D9B1D038C446E55B96E6A774211C3880185B1DA9F9C366FF6F593ADA11AA04BB6E5DF4
                        Malicious:false
                        Preview:....`....+@h..%5..1..W.3X..@U>$..u.....9Pcy;r;W.1......g..V]....*v..e9..}.%..$......0..y*.=y.+...0-,...w..1Y3O.....nA...k.x.Y..7......cf..&3.00.....d0..g...Mcb%.$.nH.....Y...).."hS.....^..jcW9.15,pQ.x...~.....C...@B...w.T..G....{._..?l..w-....v..../.....u.q.O...Nd..V.].z.'....-.....U.mK.jc..p.t&.I...%.$c...........Z[.v.h.>.@_a...O.h.....-....C,{...3u.UTH$...yZ..!.%....#<,...w.`.G.VRX2.o../#..Cc.:...J..1.h7c..L;..Ei,#z....U..(Y..!.....T.@.L..L............m...>..2..U@.7....?s.f.'.....E..u.y.._Xq......9,..`Q..%..$O...7........I./.._.[.:.u.z8.k.K....X...f..bD3..~.z@.(.d....x...QeX...;9!.@......b[........uA.....5]....S.J..R.?..x.n....0.|..}.../..i#........UhV.7R...q.#..P..Db.../K..#_.{...Xb...cr..F`q.....jS.o.y.y...HEv.].?AF.U-...0|I......V3.)0.)...../.K.g..:....@...ir!.o...H......;c..jJf.. .....?.......u.Z"(su.....{...`..*.....P.p...%.......z.r....fm..g..k_H$5.B*8;zw.|L..!y..c.w...8.D.[k1c........(<.........8..9>..-c..<....Ut.X0#'...{.Y
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.92007235890859
                        Encrypted:false
                        SSDEEP:
                        MD5:44C41C7E7D2FF796D474759C9408F89D
                        SHA1:A966B842E7ECE109DDE426D2D6DE8DBA0418FE8F
                        SHA-256:A7D35AAA9148AF38B1E8960A888916D08A7EF6D9CF2B4C700E373FF6A0F459DA
                        SHA-512:B64826EEF930150C45861A0E18AECD16A1A48159F342290EEF5709EA9FD8EC671EEBC8C864C5C7728E15B2D186CD00FD10775D52717AD9309CEFA7EECA15861E
                        Malicious:false
                        Preview:nP\I..C.V.f.. ..#b..k.D.......&L..)...u.=".....T.v gi.xR.E!{.T.#....3yh..0T.v..a^5..=.e6X..4..x.!A...[^Q...+..y..n..M|..W.+oX.Q.....n5.c........-.,.)..N...u...-...|f~T.98;..G.c.7..|...20.R*.(78......r{4.5.S..z..}E.b.J'1w(..$h7*._H...z..RYqQxn....wd.>....._z..|.<..\.l..V@Vs...Fzv...<q.,.@.u1a.T.rv......... ._@>c..S...g...`5..T..............Z~...{....0sP..SG.A..."...?...S&.v........8s.P.L.xo.......?N.k..\......~..+v.|...z8>.@..........;...^{..Zh<..N.0...w-......g...wit6..Y...,.q.2..."..]..Y.HX.j...wAC..y!.G.' .?.,...`.BE.J4...)Z... B...e.....i4..lA.;.K...a.6..wr...........OF=.|.<......K..+.....(_p.#.[."..`w..H.C...v..wx..9...b+Y..0...s...\.....}..Q.l.w......=@{...p....V....a....U@.H@.....9w?...b..a FK.j.&V.Gu.OJ..^.y..*C.."w...$XFlQ.....e.....N...r.:...+...b....z..+:..".-A........".......'.....V.f..9q.*D....q.....c...E.yf....n]...-....%||.c.T6.......m.@p.l.b>...I%V#.k.J..tPr~C$n.m.o..Rs.S..g.T..*..3uT..`L.C^..."..wP.:I..:.0....[3...U..E
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.917434201480752
                        Encrypted:false
                        SSDEEP:
                        MD5:F7FE260C4E552E13830DC745D4503B35
                        SHA1:1D301CA98242DB6126BC2B503112BBC0B7B8A76F
                        SHA-256:802BA2FAB400A6FC07EAB6DDB7D1C4A4AA22BDE6AF146C01CF95B9406FA4DBCF
                        SHA-512:886F7012FB27DBB8A696E2F33E613AD620F64DD563775A456E11740848DF36D499DE66652FD01460D616CADC640A9A474DD89E89E6E210C89E4950E100DBC916
                        Malicious:false
                        Preview:"!....{.$b.F.'/.&.u.e&.N....(.(G.....R..>."....<.^;.J.m..A....v........JX..V.E...e.....S..[.......v;X/...0n&'B..(.$.~.tg.O...n].....b8-....m.j..RK.9.q.2G....s.xN+.../.m.QIsQ`. .DP.G..Z*(>..o...C.([Z.:zq...{./..0.....}-............m?8.1^>.C..........p..j.98..|+T..8...l.(...!..?..N....+i\..."..p..I^o;3..6s..O...Bu..Fo@.:..m8.S.s....f.j..].\.~Uo'.5D.M:.....f.z..Ll..`....O...X.:..{.!..2>w..760..C...$.U.e... ..5...#oV1#_ZF...7.FS...i.w?b.,.B.._.a..73....FjS....>..r..J.....I.9R.w..o.7..f..B.;8.4.+...P.T.. !_..75.........6.y.....b..!.6<\S.`.t.a.{.s.]..]xL.|.........P. .....z:N...Jr. J..).,.=^.x..s......5. ...v'..P...,...eK..i.{j...|8_dy.Y.qg2.Al.....W'....?.{.9..A..,|~0.......G.. Wy_..h.,........8.]....#..............B%.x:<.........TJ...S....q.?72<x.1[....R.&.......X:O..X.....EC#+Fx.;.!............e0>..4og.G..#<..}.....`2z......?...g,...K.O..."&^..}).).a.Z.1.%..c.M.....$...#.y..L....j;.f..Y.....{M.W./xp...*Q+I.T#D.*..l..=r...L.......D>.K.....,..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.917210163194763
                        Encrypted:false
                        SSDEEP:
                        MD5:07983F4E2DC4575D4472628F2F48F97D
                        SHA1:6FC45A3B67DC631C4D8850257ECA9C38B63E765D
                        SHA-256:89602405DBB2D04B641DF547AE30DD7A3A59973B58B4D5DBAE96A1A3D92F67CA
                        SHA-512:3D16F6707CCB29E641CD601D0E8B244A84CFBC555BCD124C1EDEAD349A948EC35C3B86C9BE99E6D8423573574EFA16706FBAA4B5D4F3D394187EB1157525AFCB
                        Malicious:false
                        Preview:....C.tJ.rY..D>..<.......W...k..}..}M&.k......c6...,.8o..Q..U.XE9i..G.z.|..I-...=..M....Y...d.7..KM;...A.%[..^..r...6V.?ut.. m.yE.uR`.u&C?_..."....K.E... ....IP]..../Z....L<..v~..-..x.....k.".m=........U.|...w...Q..M.2A..;......D":.%^....[(W..@.T.L1..83.V. ..D..o.....(...+...,...xT.#e.F0...'1..z..|......y.[...{.y......3.Y.b..|X..c..p..;7.*7.\..c.;.2.6f..;k=\...g..f#B...o.-.h.R>Qc....... b..)..:.K......s.....[.....RX.{..9B'.sS...?{...Q...$Fcf......N....._.._.,.{r.Vy.].3OCW.........]k%.../C5R..E D..C<Z...'b..y.....P.9:..|.l...]j....k$8K.....V.0...3.ZQ...L6..zw`c2.....q.N%.<....B..n\....XXy*v.Jd-........I..,\.....\..?.K.9.7&...'.a.M`.a...h&..8..'..3.#;.M..'vx..W....D.|.+..*IE*........#.o~y.....;..aS"@h..E.r*E...........[..Fqr-B.DX......(..........@V...L.N.&Dq}.T..[.:...x..J....2.Nr...'..].@....?..g..;.QN./...F.M.{..8.G.JlA0...X..Z...H.^h.[..:.q0..."...s.FG......DG..$..E.HQ......*...#oCh..6S.7.)%1.\C.\..=..Y{b..i..d.G..R4...xY.a....F.f...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.916409897919538
                        Encrypted:false
                        SSDEEP:
                        MD5:86C656F5607F742085D0C70D70310B3A
                        SHA1:E6E9E48CB74E1B87AA79476C7383CA119071FAF8
                        SHA-256:988F2BBCBEE588D0FB05D708599300CB0B818B85849C297E2DFD00F7235836C2
                        SHA-512:E1865BDC4D0E43DB5DA5BF6F4429567BF096B4FA748A0D2D7A229B9E891DC4AD1786C36FD96C1887959A34EB2E9EBFAEE28F4058362F10D6344C1F69A360F45D
                        Malicious:false
                        Preview:.?H.^YKR.B.0.b...#.P./....{~/S...%pv...M"Q5.V...9..J.2;.B.B)..*$...=.....x.j..`..n..r..+...... .iAZS.M.3..$W.l...$...,...^.p......y..{X...%...gSW.4. A-.L].=x....'...<.j.G.....oKb..........4Z.[-...J....WH.....TI.f.q.U76...h........eC.?....4=...O.....).k...)......M.....q.Vz..M.....=...........%..V....."...H..WLj....C/u.<.t...m.#7-.b.h.{I..o.P......'p.N]X>.T$....'`...E.I...m_.....7.@...o.....uz.......fF...4Q{.$W.. /ln.k|.V~h...+..o.y[...W|?..%.}.......d.E.H5...3Z..a...h~..n.1.-.v......\.t..F..........ZI..D..|..*..ba.....G..-B.ez ...v...J$Y..K.QX..........H..FZ$5..W....1....A.:.E...$...[.._N.D...PM...0.....'.x.BNH...0!...h.U.M.y...l.&...........u..eA..F..1.Y|.U.>....c.*.. .........B. ..".(..X...1..U.cL..sI.)U*.cE9....I......788.x..v.n4t.IX..vE......Q.gY..+.....Laz.....4V..|p.s..r!.JH.=.F_...#.gB.dE&N..j.....v....[.......VFi..GT..d.q.....K...Z...J.s...1.5.f.....!s.+../.1o.O......UW9..i@....<..D..:..>iJ1VX...g.2.X...A'..........Q.].........J&.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.901090124289482
                        Encrypted:false
                        SSDEEP:
                        MD5:53D6DE94CC0781FDC5CC73952C527CE4
                        SHA1:D7B0B2AAA4D3EFB07DB0B0DC9762186E1B522561
                        SHA-256:E4197958729D7E939CB19A7666C9E2C04DACFDEB9D71DD4DADAE7E895708A181
                        SHA-512:2964A05564AE7FA868FCA72A9998CB516703053A687A29E786921A865D730714FFC9BEA83DF60530414048AB2342578D2D35C97900AB6253C84B6B41A5D417FD
                        Malicious:false
                        Preview:.B...b^2...g;.........?.`4.......`..,X..t.."@.O..<../.**_........C.I.m...F.H.wTO.q..i....>?...^...L..NZ1GL.....p.......k..$...U.....E.IT...h0b&h?........LH..x.q..G&.k.YVb%.[G)..}..{..b.y.tE(....K......P...7....-.2.8AP_.H...C.....$t......W......q.. Yk.5h..N.l;.........g...=6Oee..0*......2...:O.&..H...2...\.`4..zf...f.g.."+.1.M.G.?.....].......z.-...B...!.v.8.`ZA........C.....CUBdx1P.\=.?8....[.Mbd.|......d$.-7vt6.3...1.\.$.h.......C.{.....l.~...'.{_CDSD..,.....-b..X..k0..h...d.`.6^....I'.@.ZK/..9.FR...=..t.I\.Nx.r......!..:..7.?.........1.:}w.`.$r.....{.... .Y.Y..R.{|n.....n.g.Y..k..h!..4Fd..A.H!.....}.=.H{ ...p.&Df..f|.........A....W<.t..Y.j./^........j..4...F6n.*Za......+#t.1=.{Y".Jw..&.f...x.$ ..)E....././g.}.K0...Cf..;.HIn2....b......e3....Z.W..p...6.$..d."..yj..2...s}.......j.H..#n..|..E../Z=...K...4..J:..*.h.?..e^..v[.S..W.3.~d.r.1U.W.(QyE...~...,... e.../U.%...Q..,;=...o-..a.x.hb...,.[..W.T.tu...y}.AU..(.:..$a..g.;O...x.d.[..Ak.N..4.".A.k.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.92327090109017
                        Encrypted:false
                        SSDEEP:
                        MD5:0D27F6BE5B0A6BA51605ED1578481B4C
                        SHA1:F73F5433A7D40EA87C46D94788C9ED3A172261E4
                        SHA-256:00955305FC6B0536C0DFA8F9DFC083B785230FD6DC4D1A5128DA1B32B221699B
                        SHA-512:C520301994B695BC617C8F795DB62F6D08A2F4B39D21648E7ECAC44C38DB4C4A9C97224FC2AB9ECD2B5DBA5DBFE3059B1055953158C4980CDE14194AAA46CB97
                        Malicious:false
                        Preview:;..W<#..T@...([od1GdE..f.u.-....gA..G..0..L....}.A...Y)..-..Y\v_.q..2l....N.<.....B.+|.W.E.M?.yHB...l.v....w@...7s. ..D.l....i.U.#.;h..*\..Gq.:.i.@...5.. tj...D.[.s/.`....dJP.r....E.E.{.c..37.Dl....nb..t.....n..@.KIH...._^Z..4..."~.{G...=,f......p`.....A..w.<..Q0..........n.Yl.....MT.....d......1....S.Z>v...%t.4......*...7.bJ............M. )..l,....{.....m}.S....Z.\..:.*8....s.Fy.....F.p.G.q9....#..q.uK<....Z...._*....Q,E.,T...g....d.'..A."hb.....Mo...Ic...L",........~f.)F.^...$.C.|0.....|.1q.#.L....l5.T...s..!~ky}.h ..2.|....*....i.,:k..t..h..m..4..7.,....'..I...!....L..T.W.+J..R_..|$.N......e?..2/../<;p9 ..MAp.Q...._...+..'<.5..U(.VE<..j.....6....c...>l. ..../.!.6.+.y.,R........B.Y@=\..x.>...<.N.M..9d...7..Qz.U.y..U...78....5.....m.m....8..rQ])i6.,T..n..^.Q~.w.)...a.z.E7......b.w..R.}..V....c..Z....M.....Z.... ..!.....'...X..=.2..".|.B!y..lHS......J...(..`'.6..|^.\ .t..Gm.c..j..L.j~.......vO.l.{...u.....S.....@.HDj...n..{.h..i..7.+,.s.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.906717309050098
                        Encrypted:false
                        SSDEEP:
                        MD5:79CCA56C48BB951E35D6F0C250694EE9
                        SHA1:65366B90921270D49399C8ED354CF71DDE5171A9
                        SHA-256:34E4ABC18BEF99CA7E852DDDA3CBD4125D8B3D84051B04A137E74C008513F117
                        SHA-512:AA368D2D1E2275D97B9C980402C8753D1333460223C4C969918C5A7DBBB3114271336CD9B2F6A19293F195884E1C8C4308417355308323C3963894212F868A74
                        Malicious:false
                        Preview:O....3[J...-'....m..4..c..M.#..N/..2W........T.V\..`..*o..H.M..4aR...._....6..k/.b)..*vqcmJ8.j...Z...........2t......o;ch..h..h.h.)....D.O.eT\^.f.).!..^H2...w2..h..D.wM.U...!?.v.qG..v^3..W..G.@g&O......K....^.RW..e...\mG.T,.._?..!+c3.......S2.[....m..Kk...mu.......7o...&.{.IV... J.4.-i.S.=..NMj.."e.... .Q..V...).z....}.@..Bn.(.h.mF.M......^..1M.Y.>T.v.Y.*I.}.5.u3.Vp..Yo...o..9C...)D}EjL....Ck......Lq...%%s)...y..56Mrq.o~.Yq.?..K..VX7.....q.......!.I..3'..v.tj.@#H9.......L.\/....i.C..%.U..>.B.C....c.`w....|...`...z.....<....v.......p...s.5...).^}..R...1?.gez.pGL....,h.}.`.8........)c.B.:..US.2....Uj.j.59..'.82M..].. ...[.JEDD[..<.%bqC....E;..........P...9..MMg.w..~..1....c..|.:....~.[6.Q..g......R.....,.l|U.o.?J%G....>......E.{.M2....t..cE^9c...!..6@....$*Su.Ct.N..a.%.D......w...(...\y.z.;.f.C..|L.....G..+..H.....:L.....@...\.....(.?].....'.m|<N@.g.^_...TV2.|.%F..`"/.L.F..C3..|..9.....].#...L.*b....G..m^U..<....J.6M....I...R......'.b..+W.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.911359851810829
                        Encrypted:false
                        SSDEEP:
                        MD5:17BC2F7E70B8566B2750A7C20C94B548
                        SHA1:5B4B82A3D00B8DA2080543407806155DEAD5F667
                        SHA-256:4DC52BD1216660F38B5EA550AD38C10F9361D66B478D466CCB35FAC232B88544
                        SHA-512:D4A1C94F145D254AA1A43B488C26FDB34DCED7B99D259629458679E23ABAA9CDCDFDEC2B79BB5500DF6F2B6FFCD1A5823C820CD2DE2C30B89D9873541D976D84
                        Malicious:false
                        Preview:.....cIi..WGQ.A."...=..=.q1.Aq..2RNG-.n?+(...EI....|!......s.=K......L..<.:.6..S#...X....].G.....HOl.qE...9..NVB.=-.........W.1..B.A.Q.X.`}.PP.l.....D.^..F.<o.......t..d$.R.P.+...Z.`..<^..<.....3.}X........mVA.Q...x@M.....\...iY..rQ....._...[]*....HwC...u..f.W..@.oi.TW..6...a..`..Nw.".a.P.|...V..`..*.L.....xB......s...'!o.k..,T..4........v.....&7c.?s.941.F>8_.?.-...j.PJI...Q......>..7..b); lCe...S..7.`].!....m..`I/..D.J.:.U.?.D.:....=.(.4.dM.P..........i......%.c.~.2.y'r...?#5.a......]...h..vD..).x...Q...~jpX...Z[..(...#...+.YY@.=9.7......S.<^.@.......m3BY.....~....Jn..]......r.R..dC%8..........9.s?....z-W.@.3.I..]....|:.....z.a..9..gK.......w..*....W%v.g..G.L....N,..|.-..... 3f..D..U.........6..Q>.$.s]O.L=a..[<.|2...}.wI%.}9..>..c...!.c..y3$H)..x{............tA.uy..L].....7..P.^....t...V.. ...dM..A.P..,d....,9bP..l..S9d...C..+.d./...a....fkD.g....h......?..X...(.|........d.xz....yiH.y..y.&..S.l..L...a.bEV.O..X....&...J..y....`.8.....N``X
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.907385386561953
                        Encrypted:false
                        SSDEEP:
                        MD5:92822AEC05A4FB40DD797B6B63151059
                        SHA1:E4C54AFFCA7F176D07F3B69BBE45FCA877E51852
                        SHA-256:E64D2F325A0257E5ABC50D0F5CA3E9EC751070F0EF7E5F9CC53F0565479E4EA2
                        SHA-512:178BC72D1EDA518C9EBC3182C08BE987A751A573C49ABB45C1DBDF7EE35801B42B8C0418C617D0B88E765FB84DB278E06130A04BD03682DCD034F03400E3DF96
                        Malicious:false
                        Preview:#*:.f...Q.tJ...G...8.k.z.2..6...EX9!.X{@Y..Y2......{.5%{GDG..vV.....j.Q.*....yO.6..".G-.}..Z.1}...Qm.$....Q......w..i.5Z.W..N<T..>d..<T.....hMP|E0o.J.&G..U..;...i.4..%1...JS.....Z{1..G....^...=..$ag.&].t..:...(8....U.0...G.+8...w....3.\..g..]u...U&l....y...zIx...A^.]........@;...|.....5..b{...X.e,.9...jv.3N...Rp?.1-..6F'>.=.p..$ui...17u...%..AJ\CUNK....=.f}...-R.7.L..w.3.1..ESr,..hg...S.<4\zC.......)?..21...r.C_S$..<u..ei`vN.i...:Y......Y.N../..h-..)..MS.-C..>w....u^j....!h).l.....vf*....BP.Dd.S.#....4.o7.`..\hz...sHD...Y...^Q...Y&..^,...<g..vn).*A........%<.{.z.....4{.....!C.W.9 ..K{.9.^.l .8...g....!...'t#q.?.l.#L...n2=.p>.....}....YX.?[<..L}..3.....z.O....W.).`B...#...]......s!']x.........*(..7{..O.j.D..s.....:.}..Z.@...=.ZGj'.UT......}..o..#....Cn........C.5Pz.e[X&..zF....).{.+..7.(.).....Y.U.7c9'....i.&.@.y......F[$.s.y.......P.....B_..w:.......UQf.....dxC.).S..m2CY.,.....f..{7..Y.O&..c:[....m.Uk.....y.. o..y...l5..N.i]..w.r........Gjd.B....!f
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.912289041079758
                        Encrypted:false
                        SSDEEP:
                        MD5:AF165275FE08290B1F5F814697DBDF1F
                        SHA1:AB946EDF2109A64A65F240C222EC0BCED66D805F
                        SHA-256:2CF0E67397C3CF66C48334C07BC71EEBB46FFF2D55771DCE11B5945DA6DE2CCE
                        SHA-512:5263A77A0BA6C3F9A44E4C9B4D6AA86E99C0FD3DB46264CF83A71BC4B4E738FA99CA2B30EA79F50E17080CB9D5AC3A3A6F06EFBCC3EC17BF5654843D7A2B53DB
                        Malicious:false
                        Preview:5..h.vnK.N|B5(..t..7.......h...f.DR./.G.h.......:[...K*.d.<...*#...d.n[._.A...p...k.....H...I...v..>_...r..!.....u...~U...G7..D...&|Y........=..b...A..<.09.F.e:.;..{...YP..{Tv..QF.^.?u...G..i.f...*....X.Jv6.r.........:..r.S.tdlL+<...u.MF3..@.....#2.2.Fo....l#....=..g$.......9...nv&.o^..{.2.C.J".....<=p..F.|.....a......j...on.......#)Ak4..WBI.@..........``..h.....Rl.x..l.......+.%..Y*N.. =....{.(V....Sq...I.k...}6....Y....M/+..C.;...nv.Z.=......0;Z.|u.Rf...6s..A.......d..;H.6.-.v...R9.~7...Kf.E.h.....2...DP{......J.......3.|.G..u...e.........h..._...n-f}K..O[...z..w.[t.`n0S..8...OT!.....6.N...Q...r2.]?.V+..:.+u....$.aS....m..d.8..c.b.....b>.R.v.r...h...Z..,...5WM...l.).8...V[............J.p..>..c...QE....Q3m.!....^....~r.f<..~.g... ...w.A..%.+.@I=........;....x.z<.....*-tNs..bSR-.wY....'..m ,..>F.C.t.....uY[.4.q..ZW.J.n.Bk.........@..K.:.b=.K...:....l.~.@.F*....#.A.R..^....fr...R.}.-[..[.vh!@<....l.+..;"]./.`...B......>..=Li
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.902314555257931
                        Encrypted:false
                        SSDEEP:
                        MD5:4F02D971D456F0C87D1561D734E52298
                        SHA1:8A2228B79E87831C992134F6F6ADEAAEC07408AE
                        SHA-256:C4C5CC2FA0C0DEFB33AB24290DE32E02C8648F0039E540FBD8C71D39731D59DF
                        SHA-512:CC6160C3D7341D7CE5FD54CA0F2E5398DE985BDD740AB50923BA03F2D53222D4561CA66928980477F1B554546B52C92D74D4E8D6A18C2AB4ABB0264088FEA8AB
                        Malicious:false
                        Preview:<Y..B....k.8.I{n.8<.....1..n/;...a..I.&.D.....BDl Y..,q...`)9...y:..n!{._K}..c8_,....t.XT.w*.IJ.K..,-.R..h+X.GE........!.....L..I.R.Q..HB....4G..iHS.~s....M.6).Y.2.7.c...A............/.......u:`..........i..M..`....../EBCz...[..<.*....j.\......de.e~.U.p....._.zr.pCG0.U.>O.0L.e.\.N......|#.Q....E.t..%g....}x.D"..{..../..z.|L.S..V..4.....q..@..Y2U!-b..&..~ .....e....Q...dgnX...K.T....Go.h...h.o.w...Lk:7..Hn....Z|.t.....Sy...E...l....+.OX....t..A=.B.W..K2.FMEu.GY.."...4!>7.;V..k..[-VN..U.]&...2Co..8d..}..kN(..d.W.^....../..Uw....5....0.b.a.B..].F1`'...t...h.'.........K.X..d. N.Ba.....Y...C.pL{$D#...2....E$.2......l.W.a...=!.G..M.N..o...F...........R.......>.C#W....OU..Z,.H\..r.w.>.I..w..=.........8....3.;..`.....S../U'...@Zo............D..+VZ...Sg_|..n~'..c.nt..`.<)....`......._..;hI.]&..z..o.y.J]X.i0...S,s........f....}..@fV.4.}..Ur[.E."..j...w.6.i...7`..k..d.].K.......{x....v2.O[....r4.....v.> .Z`L....I..g.n...../..O.GC.@...}Q...7..j....8...<..+.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.915407022798605
                        Encrypted:false
                        SSDEEP:
                        MD5:DA068D015159ED90216D5ABAE288D093
                        SHA1:F0CD703EE06CA527C78B8266432894B74D1A018F
                        SHA-256:D5F2DB1B46D94E81FEDCDA1807E254B983827FA61CF70E57D7286084E78F14E9
                        SHA-512:5090D32884EE2C05DE6BC5DF1D2915D0EC05D51B6CC1CC93EA54BB7E93A39B316B2D7ABDC886E4FA31A3862308C11D15841D4E09887105C80C8E5AA0B40EF22F
                        Malicious:false
                        Preview:..Q..D.........1.h.$+p...p.PW._fL\..+...Z...g|ji?+a..E9.....V.~~\..>...;.;.>.7.w......3.`./!j..i...........P./B.m(.D.D....h..3.#.3&.-.z....Np.....>...>.....n4.MR..*...~9P......7.f...?u.;y:..._.3.M.%^F..v..a.=..|..!......i...-..0.fF..k...IY..$dP.bnVJ...u<Z,..l....U.5F.h..|^..d.H.....QaJ.2.f..c........c^...........\.D..@0p....j.{.^<.I.....T$..aYc..Q.W.Vx...g....|.B+0$.....):....A...1._...0....:........f#.],;.....QV,.X...eQ^..bf.....#...`.f..G..m..|..y.i.C."...........[........p-E.g,._...... 2..4..L.].i.B.....h....lx...!....s.#.Sq~...+...%.....`.A.....u.s...,.d.....`.-..f...=....P...Xk.....J.K..f..B+.'C|N.y.a..T...(..Vrk........=..g.g..-..9...-HR......M.Z<.H....8.K/.\.........d..{k...<.<.U..l.....O.H......A....1..R.) .C....Yj....;.d(.r..`..W.V..vY^.....xy6aYCV......XL.}.A..-.=.x.GK.=.>..N....7.5..(.'X........3.......+........>Vs.U3...........]..%!......J....,.(...a...C.....4.....3h|..5.uf_.Er.x.Y.i...5.[....Z...Or .3.B.z...@p..."
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.899811248046435
                        Encrypted:false
                        SSDEEP:
                        MD5:29F3E989DF7B9C612FEC1845EE55D785
                        SHA1:0977BC59772894F0D7A69C8B25068A823C2BD1D9
                        SHA-256:D606B4072F32EBB22838170B4009EBF660F19EBB27BDEC2ECACACFFAEFAA17CE
                        SHA-512:CADAC27DFD3477BB5FBC9E5EB9BB0D7FA26D158C42310AE7CAD6AF0C6D343CEBDC77B1C154C78160D9091E2F077C89201D6A4AB755F96A58298DE8EA3857AB25
                        Malicious:false
                        Preview:.X.^.....V-$.....R.....].[ZS..4@.....J.F.C,......Ja....z...I.63-G.d\|Di=x...2...@g..+...r...b....b.q~d.=.....F=..s.4.....K.N.n..e...._b..m.rja+r....h..6sm..{.0.C.....:+)Y.t.gQ..o.3a....K...G=.g.....H9.K.;....f......{Ig.VM.mT175.....I.......$@1.n.? M-.7....^.....4..h....R..Y<+p[.....(\sA.....Xjc(F^,....@...`..xG.!2[.Q.^......V2|.......i.g|k..9.D..!.......6.......]. ..R.C.q....@.L+.....03..1.e.6........I..b+.4..'.X.oQ........J..Mg5...8.......[t.0..t......Z...2j..z.......M.........s{*..<.v..4.:..".6...ZP.Zi\.~.t.z..t...W.H.O...vW...3.Kr.2?XD#.).......1...&.....P..[N5.E$..E'E......s...{.....Gs.Jt<...w....l.)Q."... ...V..Co.,.....-r&J/....O.U...R...e.......E......Ez..J....=oU...E...>.t0}..n..J...*..o,,z......J....0.o. ...?..;%........r;>..4>.qr.I..SP.rr.WZ.=.-\....X....p.@&KQ.d...d2.....e.....+.|..cu.!C`}....5.LV.K8...QTe.)...l....8/.s...To.......5V...]..Q...B..H..6.#2X...]p.^......J...2N%...*...24..I,......0G...V..,.&4.~.c..v..\\. Bb.Z.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.911325261824067
                        Encrypted:false
                        SSDEEP:
                        MD5:87A9966E04EA2753350F26DE5B4CAE17
                        SHA1:36B54E84774680B0EEA460DFC6EC0D97826BE9BB
                        SHA-256:2AA31A9830E43E5F9CB23200DE772E9166303E616EDBE7991EA4E7C10E83AB75
                        SHA-512:57B93B87CC0E81B6E8B09A7F2B48E97FC0D9AA2914704572DFC63C9CE5554F6EFE96666CC58501F7B0645B41DDFC8ED7F053CE2B96B390039A60D0F620CDF9BF
                        Malicious:false
                        Preview:X..5J...T..W....O.Z......*...cN.%A.....B...'.<.MP!8c..P.zq..)...9....^...I...#.Y..=.%.._..r....L.....2`.%......J.n..?.!....+1.r.f..H*.%mW.)....M....l....j...!o..H..{...%m.P.....)*.s."G.|.....=.j#.D.3.$.$....65..o.+o.r..e4Ade......u^...f.n..2...h.....iLu4....Pz+..e x{q.|H.>P....d.K@.9.^...@....O...i3.f..2Ner..d1.q.vn. j..3<7...:.......8A.._....,...2.E......A.....FE.^.>.$.+;.O.6;d{)We........W0....O...o..AWA84..,....Y.. ^>..#C.e...}........u...p..XWz......m..a.1....X..p......C.K."m.XJ...*F>...A+..L/...D.....5..YN.{f.A.$....?..c^...Q.gw...}.\.....F.QU.H;.v..(U..,...].R..t......d.....6......Z..,...a.u.9..2..E.Z).......M...l.....N....Y.8P...C.N...R..y.,u...2K..z.B.7.........a%...j....Kt.9o}x.p.V.>..Z+x[pq...;.M.t....(Bm.{:.....r.`.......9..qbX-h.........D..\."/./.. ..D.H&...};s...%....U0%L.eV....d.v....U$..'.y.?>..Q...4!....]L..).6m.Z.3..E...G....o...~.LF.q..i...]f..5.,....i......GT..1.c...T^..33@....(..7kna...>C..-~).b+f"....G...9..~.H...S.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.906989038412779
                        Encrypted:false
                        SSDEEP:
                        MD5:A2D522609E4F0F20EB8099A0DCCA2233
                        SHA1:06AFC2A47AC593F3C5723D089A1C12BFD5F52C9E
                        SHA-256:E47308ED12AC3B8464B85D117DECE3227AEE169DF643E4E8259D28A81769BA25
                        SHA-512:9A9633CD63CC00AAD845158454168CAE86B0236F7667184026C582E4C581B8AF59510894D935D5067A66B564095589405B6A197B9656CAE96443AEF082AA8C27
                        Malicious:false
                        Preview:!'.}......`..49..SR...B)..O..$:.R9...w.f3......C..Ctf...?...5...{.\."U.O...!.%Q..".D'A.e..3....(B..;..u..B?..!;d......8..hv...0.X..w....47...?..".=..V.C....Tl......@Q.9.`...@..P?U.O_.JKH..".p;..f.7.pH....^...jaFV....v.P.Z.....G..e.l.o..+.x9y.}2.=gm.n.... .,.^.@.q..:......}...MM^\..i..$4|..K..........R.&.z..._...{.(...P}Gy.O.x.....-...%.P~0...b..".....f0*.?....X....z."n..........s.H.Ujm.B7.-.~..$.PP.v..,.nU.T..\A{.[.....`..5...1......|.....y...3.IgF..9.m.8.5?....y.......7..%.G.t.!V.x_..+...?.Z..c./.>..m....;w2Z.[7...=.9`.!....X..Y.~*rb.~"....(..*....`].S8E......z8;@.(..k!..H.8..p....E7...=.....F..n.^......*K.'Sh.o....l.. ..A.!V.@........cD..#r.a....H..r.....!..\.c.6.Ptg.y.p.{.v.5.>7.@v...K..v.........H:..p.x71)...n^u.Q..ym.5........f.._.OsN.6...i...qg?..'O..0b..O...^s..SVM.....B.}..v.x...)_>.B.<j..U[....l.0..b:..-.$.........B.i...x(...Q.......c.'....ra......R..K...oY.r..Q....5i..C.{..4cF....._..Yx~...b.....]~?~.>wa........5...*C#A..!.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:zlib compressed data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.909368544276859
                        Encrypted:false
                        SSDEEP:
                        MD5:90A66A534401A29FE78F0ADA62AD0DBB
                        SHA1:98AF59BD199B21291DD4D342756FF7B018E11698
                        SHA-256:B5FB6EAB49DD3B8D5B38EBE95BF41BB13169D8D2597C300EF60EEE1395CA7529
                        SHA-512:550631B3F3B66C4B72E78476464007BC0A0C5FE5ECE0C5BDD2B2ACD6F297DACEFA39C697392AF4FD39FF3F5969C6C9F35205146C33DEF277B0D20E5D555523FC
                        Malicious:false
                        Preview:x.mi.(....sd..N.`B3.w..F.jK..:c...`.....k...7.r..8G..r......'....h....b...h>....B_K.A..>n..[g.s..G...i...K.I.61.].A`L...Zh.ut.Y.~Y{.2h...~9..0.6....I.&.mG.b.[..".-...?g..ev4e..7.@....0...l."........\.#..}2f...L...b.#..;~..j....7.]..@...j...:5..$h.B.42H.6...._1P..jM8`_.W.B.^S..HQQ4KOw.(S\\.3..V...'.|.j._.,....t.#...M.rIo..7g>....E*....k.v.}...8....pB...../jR.e....j.X....aJo..{.....5...D.K..'....2.....F|.t...Y....J..@...k,.M.Lw......s2E!.~...6..~.*;6..l..} ..........?B../..D..-.P...R..N.7.Nw...J.s'|_..~..Z..wl#...V.n..,..1|....".B...".....c...&2.......]..Y..,....2;S..r.L...............*..7G.p....".icg..+Dq..a...U......p....Pz....*q..=..}U.(OC#.LU.a.".R%5...(....W0.&N>.......l.y...N..[.J.Be.!.}..cn.J..%..).-L.VL....mx........>.N.j..0#....=.I....6.n*.f....IA.2k..xsn!*./.....\.f4....LZ.w....z.ok%#.C.>.A..)M..........3.j.B].)d8J....by.,g..v...n....O..V.~ .....>.>......Q.^.V.MG.5...#.P]2Y..f..C..A......|Zx.9..h....I1.._n.u,...y..p....b^..nM(>.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.90491762122937
                        Encrypted:false
                        SSDEEP:
                        MD5:A2203E6F111552B4B4B9D3B6EA8AE1C7
                        SHA1:51AB943C230C1AE7812AAB9061CAED9BD30AE97F
                        SHA-256:2B9F4DB05B3EF58BC0279E932010B5E2BEE086A3B8207F21D2E754C668F3FCDE
                        SHA-512:4808EBFC3C3C70321C31D57F71CF09B954FA22D4953EB6A793331643CE999504A588898E33C162A4F1D5CB17B8E82BE4CAE401F2E97482CB509FF30B6DCFBEDF
                        Malicious:false
                        Preview:.~.B...B#....9..,..qX..<$.k6C.V.90...8>.%.qNof...q.b.G..P..W..NAR.2i....[.Q...#.i...Y..1....tVv..I..'.#y..[.t.@...R....1..0.7L..e{..W^w......b&&.>..:..h)..^.,<O&....nf...Z..;Jz......(_..=.........=..%..,)..b..Z.H......L...F.Z..TjC..&....9.o..3..:.^...=..h...g..Bi.I..!.q.<.C$..w)...5%......l..j...jr>.,.).?>j.Y.V.[%..1..eFr....,j..G.......!..DZ1?..X....a.5..B.=s.[....Ex..*.3v._q.O..5"h..r..W.)!....&,......S...N5..../..6..{.a0.8.v7.F......../.[.W.w..z..w.%...ZCZd.!...c.DN....m.u...(.3..... .).a.....J:..........;Fg.).E...$Z+...fmO..Ki\...*H..rH}.adq`x;.{..X..ZI........=U.....T..%..........G..L...nJ7JG..fJ...;'...M..6?.'........:Qh:...,.c.w/.S.....~.....Sr...5...*.g-X....ZzQr..........I*.b}1..7".I6.7..z~y.kD..!M>f`........d......0.-).5...$.\..K.9..;....6G.cS.!....;N....H2..j.Q.d.:....+...j.A.2!c..?....M7.2......Q..el.V..M...?BR4g.~3...!..5.@.u.."...r....5....Y&.qJ.].k....kDK....Xc;q5..(|........Z.G.F.V.....8.*...X..@).sE..@._..b.a..+
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.914394476096196
                        Encrypted:false
                        SSDEEP:
                        MD5:CC0BD7BDE843A13E46FE09CCC3F1B42D
                        SHA1:D13CEB2E724E4851E6485780E6D7D92CD776B1D8
                        SHA-256:54C106E5F44EA06B0C3A140FCACBFC7C680892FC386A1979D2E0D3C756C799F3
                        SHA-512:AA5179E77AA81C19F0D39952A04D9E5DD12EB3E166D4EF0B047728E92D485DB988234A304BA98708694BEFF450CCF3C6A5205FCC9F8767C94DB64AD27CB03FDC
                        Malicious:false
                        Preview:.....g.md(...1.`..A'..4..8.......[k>..QR.....ty......?.....nc...C..........9.+....\<.A........}.>0g..m.....C..m.'.......g....]......h!.&....kzrmM.39.G.{"..s.e......_'.k........v............fo.%`.q..I.4...Z.3}S.L ]j.^_.m1.rXz?g...1Hq..n......"[.....F...o../w....8n.c..xF.B..6^+..%.-.4..5k.\....zqz...3.*...rQ.3..JL.Kv...-.gY..y:...-...^..k...[..J.}(lu.].rl.r.i*V...7..........o..n.y.PGj.$d.....&......y.[".<.....Up.).K..v...t......hH.Wb.K...;f7?........c...6...X$.PtjQ..,..............FD....-.l=...9..4.t..~kE.......).t4x.C...>.&N....J.R.6....)}.S.Z].........0.!=8..)-b^PX..W.Y..).e.......!.+#..B.$U.....+.N=E@e...W...(..[B....]......Z:..(>..ho%U...\.+n..:.....%4.Pz...y.I@a..JE.J.4....F.e.E.........g.P.....u/...O.....N..2/.N..I.b......T.....U..i......5.......a*R.E....<.?.7....W.ur......E........J.......@K..).EW.-.....@#..^.yr.....3..;......c.k..._HU..K.CnK.)K..g.....px.....8..u....U.E.O....>n..*.?.f....*..9......@.=\.O.d..V.H.".).....;.[..H..>.M.....NL
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.902344063633647
                        Encrypted:false
                        SSDEEP:
                        MD5:D28021032488221D36AE1FBD942BCCB7
                        SHA1:CCC873128899DBD5353C22DCAEF7D736849BC962
                        SHA-256:B6AC76773CAECCD8A7A73DB5A49801C4CF2C3A549AFB1C8B27E3AEE989EB0BA7
                        SHA-512:0D47D52C6691ED90A8C67D0AB1248894576CA894158F7B85F37EF2AD05692FD27D78A98B360BE1EA763B0632823F11A933E8F90372A52CAA45BEBFA9561359A9
                        Malicious:false
                        Preview:..q..Qqi.Dj.(h4L...+...i.Ii2..z..6..r.".:..W(...YW)5t...q3gL......q..7.Brd...q.%....-......;....]..V...g.-..{+.R ....u.8.C..{F.Sb.q..q7..*..u..}.5.s.g...c....I.s.d`.`.>.`]k\..y.p+.A..6Pg<....6....D.Khi.C.C.../..J_i7.V)...$z....]y..U....+.D.........(.1.....(5........v.c.1M....e..K....EH.x(...-.9..f......!z.G.....F.My..{5Y.Xd.....(<....?s$...(..>...j... .u..1..t.?.P7.,.B......."i.0,B.+.h.m.3..`.\{.|...u/........j...{.. .S.E....Y..`.n.w......\&..r.8R..R..HI!.-.+...u...[..C..~v.721...T.Tm..i1]H9..v.vG7....{Z...N....(..I..4...}.....v_...."T.J.3'.[,...W{.i4.1.......c...r.|....+S%tQ6...>...X.....c...x.....JM.M....f..$.=.....fH.y..q......G)xR..K.~....K.G..9v..$c..._j....jj0..R"...![.vz...?e...<*IPn.bP...0O...\.y.h.k..Q....B.{.B4,.8.......~.B......H...,a.~.N."......".x....m.....u...&c.lr.d..;...;.5.....?J.!..iB..........q..t.Y])O.X..dX.......-....L..-..[.[<,.wt.J@M].^..\.e.....`X........._.........n....*d.y..)..z5.P..g~..4.i....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.901674665338826
                        Encrypted:false
                        SSDEEP:
                        MD5:9D46935B57C5A08A761CF60CC712A57A
                        SHA1:201680176A2CC95EC9CE8245852ADC90FC72C298
                        SHA-256:8F8BBCA399C8F530AF1F70B98C5A03164490E0BD1F2DF8C16C22C78EBE1F40BA
                        SHA-512:751DD8A4F92D290209A7A0715FA9310527C10A29D5B0B5A1B5E330DDBBACC8AAD7C42FD41C9D7EC78CDFBC54C1C2D4DFA55FFE60C06A25D2532F6F1C7B1EA728
                        Malicious:false
                        Preview:~.J./.&7+....I..I^8.a....$o............%de......./j.H...L....gU.....=At...,B@.*.w......?....H.|...b.R.M.........R.......CdV...x.(.".....w...Uj. T._..:..}..J^a.R.......l;.T.=.....r..>...ft......%.~...../.C.zd...X.Nf3.4l...9(g.`2T....g.7..u.Z..D.K.q+......T..H.....$.q....;8R...Y|M...n.j.3.a.6`l......=....u..!......9Y.."."[09....Y....Jv...3.l.+.3.....9]..P.QK.......M.D.....G.|zc.....l..8.bY....f.1...L.&l{.[..h7h.!b."....'....[...CJ^8|.c .>..b..2%....NA..#.<..h...ca......Ye'.....&...^.....`...&t..ZJ..|.K..>u./.`.v.B.=...P[G..M.4.=........Ki...h'..e.a.r.!. ..~.=@.HG!.BM.2.....a1...8?.~.+.)...=T.`.v..pJ......\ +.T...*=..E...QDA.h&..Vd...j.!T.;.....Q.......;3.O.\.q.g.C....#.l..k]l.O..<...[....C9.<..-...K5......d.8.z.a<..3mZ'.C....{..?&..K..Bg>...'..Mw..]`...l.%C~.{....1.v........2...i...o.e.ni.......1...Lg...d.b......2..s ...O.u.d..+..q..M..%......w.......}n ...z.L.~..nq......[PW"`........~.[....p.B..)..-qSz..mx......:..voZ..|:....f.F.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.910789290853433
                        Encrypted:false
                        SSDEEP:
                        MD5:C60F2609C4123CBE30B4C831B4F651C0
                        SHA1:E37EA987F27611A6AAAED5A15060DE2EB8C02C05
                        SHA-256:D4F52E21AD466A43EBAACFBE9A987CA015D6E799AB00B36ED95B61217026F9A6
                        SHA-512:6E430AC9E117477C75C283C515DC5E198FB7E717E54F402402CE4A0D60AAE451BB7DC691BA7E7B97C7D65DCBB9554CEDD2E385D157D0C8D44BB77F57BD9F32B4
                        Malicious:false
                        Preview:... .......q..U..Bi..f..O.4.".\..`.._.DN...=.7.d..V.X.f....&x$.rJ....K..q~6:\.!9.....BfH...8..q..niJ .x..z...5..'@sc.&|mw.B.yf..a...2.G9F.u.P..}..Ej...........b.]......iU.>#..G..T.]..G........f......x.n.lO.>.....V...*9r;|].4.H.,....8M..f.....&7._D.0............... .R....}../...J...)k\Ose-C].w'.I.G.~...N.....na.-yqo.9V...6u&F.\V.{.j.w,V[Y...5u;..BI..f......Q..~....#..a".o...E?.....;I=.1Y......`.......v.\.....T..T...y.....F..+ ...c..x..2.$a..~B"7-..%h.o& .....l.`b...2..hQCU"...N..T..xX....cu.8.>..sf?........p..5.5.U....&......J^...D.D...>....l...)..=....}35.W.|..|...t.....Z.J.2~..;.S......s4D?./.LA.mWU....P...:...F....E..Y..M...U...W .}.P[...k....?.(.RH.....s5z.i4r}.)..c.\m........S..A.u..&.0.....c.B0-w.S.q..5..f.E..R..|~.....k..l...:..'........|..S.b?..6..XK..rvF........A%....t....+.......|..*.8+G.t<.......xo...s.hU|..)....t.M(Q.Ye.:h..rN7P..NL....*0...YE..t..{|F.p.(.E>..p..2..%!s./{..t...'3..xh.F.^...)f...X0".g.ed.........b."
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.904407104645274
                        Encrypted:false
                        SSDEEP:
                        MD5:7439052B5A5E5480FEF6C7C614846E99
                        SHA1:AEB0350AB013781194486F43400EE2BB74597DE4
                        SHA-256:9468C7246CF0096239BEFEC8A4551B94C3A382BCF5395078E7179569A387EA6A
                        SHA-512:204CF9CB5C636ED3F6D985175F5CA5A6BD7C0101422CB6B7AEF48324189F58F8EC839D96C61A1479A5A81BCA02A46B49A586A6E2EDD38803F83E80D09F5FEAB3
                        Malicious:false
                        Preview:'.......[...mi....Q.j..MI-.$.@.;.cv5x..cLq>_.kS;..4..s..h.~.B.7j...o.7.....E.g....>.:L..H...p{3..IL.../.a.]....0....T&....[....O.wZ.;F7.:R....r..'.........kod0c....q..Zh.y...w.....3.$..V..._......$..d+..[......i.QM..IP;..=.....?.g...../I..5.4..Ma..:f.!.?.h:K..q.J...9.4..N..<........`7.{..A..k..I.w8>.....1..n...j.i.N..tiH*Y.P....WQ.D..5P.*.J....=...|D.qc....?p.".... .J..T.x..u....0..!.?....25...........H....!......^.D.V...a.\..q'.'.h@.....u.1a..?~....._.).K.e.H.a..+.w..^.d...3G.K`)6....O.e.g..T.w../J...z2.U.Q...Z../.nf`.i...g...c5............9.e.......o.D.....i..&.a..7...7...w?..`i.@.....*.1.\n}=.$.......!y&.X..5.c..f.V...$7.KP$M.NN2n.....*...V.y.......d.....:5P.9...t4...........FE.?0.Y..[.....Q|%M....R\E..h.u .E.-..N,~...<.C.eZ.."...E;6S.U.....-....IT......e...~{rsQGi.rUS.b.e ..Wc.M.v.e.K.h...|......b- @I.*.`...,k..R#b.%...._*W..._.p.s.6;;t.....\..N....Lg.G-.y..R.$V0<N..!.........Pa4...+.J....}/....w......(h.L;.R6)'.....!.M..{...h.z
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.911312205949896
                        Encrypted:false
                        SSDEEP:
                        MD5:28BA5A8EBA753C8119B20F20043FF5D3
                        SHA1:C647696AF3B6ABF7D8241B6133A0E39E2FB25D79
                        SHA-256:1EB025B2CA403254F7098059631C9745B4818B2AE1541A9D051EF9B0D0F44F05
                        SHA-512:ECF00DD9D6DB36B0C0CA2A2C40192C9EB2836D75983ABFB2AFE941611F4439315E6030107D636FCB368CF6422114C9532E3DDC83FDDBA4E905A41ACA8054FFC4
                        Malicious:false
                        Preview:.]7.........I...o.ii...t.....&y...$...>>...8S{....h..Kh...1........\.r.....\..._LB.A.".lW...j.`Ta..L..t..=......&......%D..Y.N~.o"....P.%.?.......R....w.c.u........R..UUZ...VI^..~..Fz.H...F..PZ...A.6..0/-...J..\o.x?..Iz...o.Lo.&*.........Ka......x8......u..Y/nA..d8..K....L$.......X..Rh...$.p-....@P,.N.;.?R...h...l...FI2/7@gM..$(.f......2.PG.*..C.&4zs.\.(.../5.z.........\.T.Sq...K3..ARp...6...xQ=G.t..7......v]H..X.....$j..{..I/....P..i.Q.(.,.....S.....;...^bT...t.goIF'-...........K..^;3.#....>J.gZlQ...oVvBU#7.c.T..]w..\.Fx..f-.eN{..R.(c...[..O...5..s...pg....:V5........r.G}.er....); .y@(/..C.~..6.....l.N....hG....l.h..>...OB.5$@.u3.o...O2^+.../.g..>o.....[.z....~...y...B......bO.i%K\........4.9....gP).X........-..1.....Xc..........6....r.A):..}...OrN...N..#....mt17_.$...F..c...vQ.On.r....n...O..[....Ol.S..j..7k........i"...'^.{..8x.Fm.{..(z....;j..~\.Y.....[6..R%.!R..8.....b./....i.E.BUx.&...:PB.W....;.(.".o'..K.....{/P..l.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.917557714947226
                        Encrypted:false
                        SSDEEP:
                        MD5:47C5DA32CE98AB42A2E92F2FB1E346D4
                        SHA1:530607BF25B2D46733A75429D9096FD94ACD825A
                        SHA-256:92BA4521F0592FDCB311DB122F336B8EBB0AF7A55D113CEA8EAF6A415EFFFCCB
                        SHA-512:B0F2C09215F25554D90E3185E8D2199B15FCEBDBE50E2DE2D9BADDE878B700DB88F025485414489BADF0B051FCFFA7D0E45EF01FEE526C24C73DF6C0CE8FCABE
                        Malicious:false
                        Preview:..A.;......*.+......+R.=...q.H.n.D..Z/|C......./...y.5uz.....a..)..)22...3o....I\.KH.#..e...\..{.WM.j..T.nlQ.0.1#...f......V...@...<C2...... .P..A.......:<Z..K|.\.EV7.=.7.a..|u]A.T.E`..ywe.k..~.b^w.~]%.j.8...6..[...,..|.~\f......4.p0mJ*..2....uns.dh.K[.B...V.[w..d?..S|.....b.$....G.<d...%p@..cOP..S.<<8.....`+.W.W...Y....P...V."8.X..S......zvk.w.A/.B..A..g.&v.~[...U.b.Q.o..Vn....M.8..b.vs.S-mC*.H....1c.w..N.@........).e.....Z.n2y.vQ.....Lx{.z....P.7..jN...8=...k.@...l.."MEF1.....,.c...B..|.........q..4u._ol..(..a.e.,....{F+#.[dZ[.#&..`....^'.A.h`.} .C.....W#j............G...._.S.aq*<._..J....[.e*e*_...Pr.D..)._H.b.8.....H|...3]...j...j.....y#.....u...........eX....-.hR.",}..|.`...~r.G]....O..i ..R...;...jK.7..zL.-..B.4m..(R.9.(.........Z...e.....P..m.#.....i...Ww..".}..",..0...zk^w8.~.C..>.B..o)...._.v.#IY......tG.....|.d9x7.}.SlG.....#.(}N.....qB..]..Z..3...5$ 8..D.E.a.~N}..7X./kv...;V.jhL4n.H.16(;3f...F.jU...ipd..]...F...Z....y.y.G.q....0p..<..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2086
                        Entropy (8bit):7.915898916564516
                        Encrypted:false
                        SSDEEP:
                        MD5:989A140F6D628C210D0901DB1AC90260
                        SHA1:8649E98BD0A7BEACC83CCF48AFDEDC17E8E11EA5
                        SHA-256:B112617E081EB3EDD707191E4B1E476161373B740A09DD716BE630C7B8CEF6C2
                        SHA-512:E2B821B754A77FA3AF2A0A1E1321A7566864208CC6ECCB6A14A51225B2D4EB46DC67F00548C38D8D596593859C76A3BDB2C13552EF7D00DB2B2C51C9EB977EDC
                        Malicious:false
                        Preview:........GE.......U1...N.Y.f....T...R..........S..N.b...."...\..h.~........8..f=(P."......Wp,..p.M.=CtC:u.....%o...h...C...d.Y.GJh3...m.B{..#.C...C..f.....gJ..@....o.A.3......q#.....{.-B..$.t..N.&%.sT Z.}.d.;....h<.Y.W:....+W. 4.....b,...........bQje..]z....y..i)..,.|.O..MZF[.L...2.j.}......-......82...Gt...N..7P0.d ......y...EU....a........s..pu].c^y>...N.g....E.......8.<..+.VD.a............/Wu>...Oz.......:.....O....%gt..Jt.p.6h.C.Xrv....-.F..V...u-8...R....En..R9.%_N...U.G...&......)J.S....0*.U....{..@.\.#V..yJ.k....o...f}...XT..z..4.3.I@..MX......?..C`.V..s....9e..F,Y,c..../q5 ...KA.......(W.}A.C..<..^....V:Ne..l]............{?.............AN5D..[.&).(c..=i\R.3..)..kqy....R-..a...V-Q.2N.l~N..Di%.t.'....F.d.....*.."9..x:.j...4}...@.ryz*.M....H.@g..oeg..@@p|.....W.q%.Ll..b..."....J|......\.".......I...x...........[.............f1Y......x.....e3.C.)..(.QOS.........[ns.P...W.M.0........U..L\{0.Dk.y..e.0..FoN....hCM.c..}......KBA...~I.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):2109
                        Entropy (8bit):7.903041105091689
                        Encrypted:false
                        SSDEEP:
                        MD5:FC66C7EBE1E18C54979E93B843824538
                        SHA1:00CAF6752FB5C3D78CEEF50D7E0C42B0963A0E56
                        SHA-256:47B6FEB52B6A6FDFA01B424B25949383AE224E11CA60A2D8354F21B8A9150D3E
                        SHA-512:8A9CF22389867295BB0D8044B8CA534C252417845ED66CB94EFA155A0233A54BE3844B7C64A5AC8C4CF9F7B1739F3AF9C77A3F3549820994A62E3CED87E4180E
                        Malicious:false
                        Preview:.,SW..Z....>\{..........%.N..l5(.....t.o.."....8...6d....0..%.....7.. ..-=.d.......Q..-..j.^7%..]:4|....1..i~!..>.......}..Y.<..^.EgU{4.Y..6.......4U.;2.2...rL}.U0..gK.|...0......".....W..3...........*.1#...Q9...]z.x$:..0.@/.K.....R..o]F9...(._J5M.z..G.....>...6.g.gy.o.<Eq...nR..<...43,B....M..x.n=.).J.L...P.5T........q0....R.RAq 3+..|A.W....%..5m.......{..?a.>.e:...|...v<....t..nm.g..T.....wmD..cq..PYc._..U}^..4.e.. ...uy)F.....R..x..'S..,H$|.j&.i!.eU..k..oP.i..f.5>...........%..j!....J...Nn..p.LTr...G..q.....m.M....v..E.4ip...,P.H.'.A.K.&/.k*..N.....(.h.@.d.PM.A.7+...'.B.....k o.....%Q.....&~.t,....h...qR.....d....u].=F*....B......S...S.=Q..6.a.....%...7..!.,.I..;.\p/.IA......W2-W\.Q4...N...E._d7......Z'.y R0Ddw..,...VY^-.1. ..O4./.1..Z..m.I1.!..pw.m.d.kDA..v...y.xj]F._-....N.n..j..n.........*.._b8..>.....:.WO.L.....$... .37p..`."7x$..'.....6..l.?........s]..*7....;3R.......Ir...@.0...~.......?.q|....1...3.t.I.N$..8.0..............k
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1063
                        Entropy (8bit):7.835550390493124
                        Encrypted:false
                        SSDEEP:
                        MD5:F044C728CFDE168CD49F741B9E996D7C
                        SHA1:CE9E0C959D64D30E764A23D4EA447139BDE8E7F7
                        SHA-256:A802EE49E40D78C9EB87E05AE4DBF485815DF1A9E9A9AD2815BA38DEA8A512CE
                        SHA-512:91BA7E0C85C6D0435BC17F1E68DC63C5A55E98EA44CEF70CB54F73F0BA8495743075D83996A673DF766A4AD44B53E09A95E2C1482746964F88865E2D2F927DFD
                        Malicious:false
                        Preview:...(........E..[..l.f>C.4...X.W.<....%...=})...k...W.D.#...u..]...d..F..\.r.........EC..I..y]V....|EC.}dn[.....M...G..qr..k.6..A6..(uj.........+......J..".;..n........}JOP.3.}...........O..6=~.B..05...E\...&.ESW1..KX...~..7@.@.7.......r..Oa(.....I.g..[Q>WT.><"B.J.;..$...&..Z...X..F[..p{.&+...M......?.W..~V......2.A*.....|.n..T..@.L.20/...J1ro...>H......&.(VnL.U^.v>%.r+:....|.$+._F..........N.....q[Z....paZ.....s.S..<.......y.X..@,.'.!..8.Y..67..<..`q..."....yg.s....eTE-*u._.MG..UJc..{.Q....Qxl....}...*.3.E]Y..<.K:.......BLt..|..<VP.8.1$..B..4......y.#.Y.i?.:..G..Q.fv.$.l3.j..?..B..7.7@...@..'... $.y.V..*.n0...]8Z..&..P;.9.W.[z6..Bt'...N..6i..w.8V.......c..............c.\..%Y..VI.]q...Hf...6._.....E.K3.X..m$.S.....Ups.p.....NN.yC..O1...QM....u.CO..\[.......^.......#-q*.6Qa-.......;..>.w.....=>..cY4g.2j.%-.....h.....c.+....b...J.+...45.|....6....4L:...;V...R...S...j.A.B....3&;....n.WI'..A...$....!..aL_.......x:.P.i....Q....U.....8..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1067
                        Entropy (8bit):7.835473645525355
                        Encrypted:false
                        SSDEEP:
                        MD5:887D7A997EF939FB986326466E8E5CFB
                        SHA1:92DE4CD026267904A84CB83498C1539666AD8A12
                        SHA-256:D47D16D662C6FEF058F1EE51061B2D6083B3DE6661D69B995E07DCD4B52F1A4F
                        SHA-512:E74E3DC9D81CF4FECDABFB60694470FF9460A2A50D82C9520C175C5304CABFA9D7ACC9841349BE9EA249DF674F2F702127755040696051D8C4AF698E06161A89
                        Malicious:false
                        Preview:.-...9...J.N...C.. E..<....3;.N...... ...F.q...O.$.:....B+y.....;..5SA.m....3.;......VN.p..'I.g....y.~T..+.3..]:{...^......&j*....1K.ZP,....`.Rd..-i.2.B9......e..G....2....Q.+.4.e..Kd.95.|T=`"..,..:...5!_..8.-&.t.......t.<e'.w<5.......yZ'%..o."(.>7.Q..L.........GO.W.].*........*.<.O.G}.T.p7....ZgTa.}..w.[,...|...CW~.hKT........].#H.Q.....4n$.!;.....1..F..E7.3...%..cR.3{......E.}.T<...4-Y...C..t}...Pa,.ZHU.Kc.G.Z_.c\RviO.X.X^...P+X...E.2#.n.i..q6.....(5u.."o..4........V.z...QB.J..X.......D..~.KQt........+.....)...?d..~K:>....|IV./....jx..\.I5).G.......A.fo..17]...2..F....Y.O.$f..K.O.....O.TGY!.~.^D 9EML...I........"b%(.^.&..N.Pm...o...t...b)g]..J$.G...b.n..Mw.V.)I...$yy}.C......JR..o.|....,....0H.\...F2Y.....lB.Y..G^...m..m.j.....Mp...l$o..c.cH.O.n.`a6..du..T.1...m"...[Bb=U..u.G..;....F......Qob.....6Z...b<t5..c}*...Wh.2.a..Y=....J...M@..lvlh7.4.b^.<t.1w12,Ro../.vS....\.......... '..._V;.A...Xx..../gf...=....7.|1...;.t.d.D<.v.x.^om...0K..;
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1060
                        Entropy (8bit):7.845293635891613
                        Encrypted:false
                        SSDEEP:
                        MD5:1920E1A75ED8C3253561A16B92A1102E
                        SHA1:FCC6B69341533922E990D7596DA38E83EB336830
                        SHA-256:364E89F18F1186BA4F8AC3DFB260AFF8C0D014CA973DBF7701754AE8F66CBE07
                        SHA-512:C2FA2F0552D82EE4602815CDA14388394F42E5EB5F3BC52BFC1A561AEAEA415E6854007A44714C521D81789777C674DF9A377342079BD47C9DF083AE50324450
                        Malicious:false
                        Preview:..`z..T.Ktl.N...]..Mt...B9.p0.<c.N.`..$R.9/t.......h._#F..9d.A.$.W6}..{..0...X..#.&.....8..F.z..3..#.. .Nl.h..m........x.v....K..e......o....?.2.o.....9J...l(".....@....... .....,.x;w...,.|9.{iU.;...".b8....~.6g0.....Qz.D.a.gW.?.......i...I..AL.J..H:._.7p...t..(_..t.V.,........P...d..... ..M..B. .g...B$.,Q."..9D.1.)C....\f~.u.E}.....{g.s.1.TBE5..K..J....L.J......k;..0.[r.km..Rn.|.G}.k.@...'.+*.."P*!.bK@...|..g.r.f.N..b..k.<..r5}.m.X....y..v.O......Z....N}3...2Wb.2kN...CA.,.....!......?...;.....KT.D...VK:vo..=....'..0&.c.z5.....n.O.d...:R.....Xv.&~....F.l.i)X.....6...!...U.:.E..(.;7r.[...^..[&.t.X.. ..W.q.......{..$f.S.;AV{..Ya.....d..V._&k...w......^g...}.9rn%+...^.u..+u..L9.$.=8...-..B.si.1.S.p...Z1..V+....,....-1.Q.k..uQ.TfDg..h..DVOE...b=.<.0M.d>z.....*u6.h........5..*Ik.lM.....Nn.S..W.!.03...u......v...pE>.9..gA..d..xk.z..9.....1..L..YA..$i....{..=.6W.....C.<...[.xTwI...V............_.Bn..E..h.u'.;(^..#...4..;`..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2172
                        Entropy (8bit):7.922059830075725
                        Encrypted:false
                        SSDEEP:
                        MD5:98F118284A690EF6C7475D948614C714
                        SHA1:A353DCECFA0AA3B71F5A4825336543F847A634E3
                        SHA-256:7999DD24029651440354F5C494C3EE0372F1444F5355A701726BDED1E6D9EF0F
                        SHA-512:725ED7A62888C5660E4CBE6BFEB55337972A5729F9D4665AB2A874A94BDDF8A5BA54D2CA30A4F6F12E3AC04449B02D7927AA44CEFE3EF17045FE8E1C88C5269E
                        Malicious:false
                        Preview:d.n...8...LZ?.....T..u...........x.su..u.....#=.<......6[...g..x*..H.....!..9..c..?.y..q..9.D..&.H...ME..&..fe.z.%.5X.V<..c.k._......q..,Z\..Q.s....*cTg.i.&..%*b....L_....>#..`.*.<.!c..X.....R.#.&.0..7?........4KM^..{.J.Q=.4R..t.q....^.N.._..!K.)....[A.....sDRyUHS..13G.W... ....A..h.D..d.]"...:..;.......u.....(...t<*.....".U.3.g.......H.O._jK..C.i...S{......"...17...)....C(..U7.....{A..M.....7.^.T....%.`7_....Y..."......-T..?..l'....E...b. ;..9].@.....r*.OV...@.r.7.....=.....~w..o].1_qP1Y$..?LR..>.....5..3..W.N.g.*hgI.mG.@_>......_3J..M=.p..1B.z...2..%.. T........d......gL.A.;..W.........rFc......M.J.."F@.dg.....W.....19........ZX$2$=.k....1...n]A.!.Le.......Mev..1T_...?y.k...mS.@(e.N......Bx..S... n.N..H..y+.[..tZ.j6 ..8y..D....<..N.....,\.:.}..%y.z..].;...BN[m.b...(.T..8.eMi...C....k.a.{{....g.....]Z..7..{.#...Am...u.Z..1J..3A.W....S.B<..G....>......9W...&T...no...y--."...1.G.r.......I..Nu.........V....X.As? .q.........8
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):1064
                        Entropy (8bit):7.82032069964671
                        Encrypted:false
                        SSDEEP:
                        MD5:7D0BC0938DAF6D38C557BC7688DFD0E5
                        SHA1:EB033873BF2AEEC637E2C27DFE21B59918011837
                        SHA-256:30F95A45F2BC452E372AC798EB2642FEF210EB8FEC43490DD7F29AB32B3B29C3
                        SHA-512:C12CB73659C4F70CF0BAB5AD00ABB9B6DADF557F393112E037A2E527F8541FC99F350945141E30020A2178C3004EB421D98B409D47363D4B9BBE8DE1E6AB6345
                        Malicious:false
                        Preview:.{H.k...E`4..Xk......E.g.Qa>.K%.1...}.=u.l.."PDK....n&.oN..Z.}..B....|...Am.....V..dM.^.%.p.......|..-]...+..I...|. V4..SC....-...H,.1...Q...hE.!l...q..C7>...G...?...Z....f]it....I.:.......6..3(.n.%...@I....i..2.q.~tV.<....g.^.."..$I.q..'7..$4...L"a.t.....gM7E.......... .._...?..D..lW.....<......Gx&.7s.!i\..*..*...G....|...Dd^.R../,....._%./.|J.^..L.eD.b.nw..c.....b...U7.n...1....LI.....&.X"%...S....f.fya..s].iH.^..%...%..-....B....(c..1..X1...$H.......F.1...W_9......W..VB.p.uC((,G....F.S.{..F3.{.5..<.|.Lwgt%.rutW.K:.?...].&..........3x...n79H.SQ...?.......P.'p.[..l.P~......)..8..x......@L&.P83.'(.[..5..t\.!#...t"..h....$.R..Ct.}C...E;...t....`..T;...nw....M.h-+J.#.S|..x.......s...<.d.V..<P.Ah...Y+...+..P...%j..^.....]..W.F.|..*>...B<..L....(...D.(..3.r.....2..*.]..O#^l.JC.]N.h...)D?|.z...gJ...c...l1._.}.7./.f.....x....................J.x...EG`...ODx..%...(E.4waKi.=.L.......*I..... .A..D.M.../?.S....<.....J=...z..*..3..`...o./V3...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1754
                        Entropy (8bit):7.876716358473137
                        Encrypted:false
                        SSDEEP:
                        MD5:436A383B7265DCBCBEEEAB34C73C3669
                        SHA1:2BD622589766A9D2D1DF3FAE0F68116B072B255E
                        SHA-256:19A832758AACFDA80264FCA7FA576232B6EED882959BA9DDBA58C33C72B1B159
                        SHA-512:5435FB4CEF01FEF4BDFD7BA361B4A1F52178ED44E7E9520698B4CE12AA3A9B88FB19279D433DCDFB0A1DA4ECABA012B005AF31B5741411DA8FB3691AC05504CE
                        Malicious:false
                        Preview:9.~....U.+g..N.T&..T9...^.d..HY.9......s...7.hO.....g..G.m_.8.+(....i4 ^.*5...;o&...`.#H.H.....zl9...V+.sW.l....w..7.r...5..`....W.(.A"....I*.1.[.C......k..Q..`..%...._....q....J;N."N.6M..d...yM!.@sb.&..?...........2...=<.1.#..53...W.r..8.|Z.Yz... /..K0h>.....n..k...^...`..'..&.qq`.H.....W...m........".E|....(xQ.e.....}n9/hV.n.Q..:.8B...%R?..p/.....R.vU....N{7-(..2\W.*.@#p....>.....Y.(.-....P..Yl.:.?A0..^..C....z....6....K...q.}uZK..\...&.....#.y,Z,..*A;_.0...c.4..{..3q1P&.."...;..N...M.c......;..~.....3..C......0...~..f..f../Qm.gb..5...l.EI.f.>.*(~.<....u.&...,...\;(.|....=.t.....g.>{..5..6p.....#V.1..I...(....h7.W.@U.....E.|..........<4@....8+.......n...Y.>b.nl....M>...7B...XIl..J..E..!.o.NZO9....H...P>.......?.+=.wIk..|.....A.xI.1..#..<.g.........{.4d3.n..~...J..4n..Z....4.....Gp4.M.4q..e.p.O.~>o.....q.u...;.$.e...b.g...H:...1...+1r....".8.._hm..H....@........(.y..h.0n..V...:...AR.m.`.gOz....0....D.z..9.K8.P}*.....|..`Zb.>.N.....:.K3
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2166
                        Entropy (8bit):7.904369665472067
                        Encrypted:false
                        SSDEEP:
                        MD5:D338FCDAB67FB320C781A057A7EA3C96
                        SHA1:B027A2DA5C762786BA83E6744E29E466DD4BE6A2
                        SHA-256:B184233F1AF6AD6A89AC58A722E54CA780D2A9BB7E81208F7B27D3B54D362E59
                        SHA-512:16EE9A70DFE8EC9C233363D539C5963B374EBECABBCBE7F1FA59A3B3D518481CEC044DF7A7622EA1DAD88B934D5ACB2783A700C302F961E0EE572AEE21CB1259
                        Malicious:false
                        Preview:a..ex..\}"3.....B..o.S@..T^[g.....T..$...w..57..........a,\0...v4.\.O...E.[3k........G..O.A.....#Y.0...^.Qi2Du...a7...'X._.F.N7....xG.{!{.;,.....'..{..}..+...f..o.j........q+.^&....Rz3.6.2.q...}./.5......v.@&.L.kG..%TQ `.)..&i..H..5Ry.j[...Q....1.......p.W.e..+~..N..-.. ..c_.LgO.Z....I8...8.`.Q(2.53...).7."W.[j].?..^...[C.".p.H...!.....b.....).......H.......<'<a..1QT.?..........G...l.0a........$S4}..P............O...+..8q..4.6....".].. ....!..F.jao...,Z.....Ovz5. .C[.?g.0.Zd#.u..Y.J......UE....<....p..4.....k..`>{.......O.....J:..[..P....43...|.......i.U..r.)n..A.......M.K..t....+".>.%.$a%&O..].4|U.H.-.a..e?..Gc_Z..2.x....^.z..[...>i.G.b...g9......x.S.3.m../_......d..(.....k'..Z.w).P......f.T.ez......M.a.uiRp.3...,......cMh..$ay.-......HI.........E.1.8.)@..;.......{......&X!B..H=I8..F&0..\..70...'.i<...o`.5R.uS..z..til@x.6..k.n...9.... .tZ.$.4.....hw`vz.]..I.^..j..6..l/../.....<'WiPk..Z{.......t}.cy...=.v.| CI.r..fD..3m..O..r.<.a.a....S
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2168
                        Entropy (8bit):7.90698476499898
                        Encrypted:false
                        SSDEEP:
                        MD5:C5A9F5679757A727C7313BB4ABA583B7
                        SHA1:EC01F87B4C0457FF56567F421F95289A93667FF5
                        SHA-256:793A0480B038BB82E312E3E5E1A248820E197D228D3A7DFCCF664AFA59F9BBF4
                        SHA-512:4C035138B31869392841D4D17B1284DC7524E70022ACA030175BC86F4F6FE29ED2FDDE4A382300C82D0A762BDD0572D0E839DBB1A4C2B9BE44B3616BE44BBCC6
                        Malicious:false
                        Preview:A$.......">...G.9&q..]@M.d<_II.#.F.gg.nH..N.'.+.....;.fs..t._.......D.e"i..^t.......rL..7.........Y.M.q<M....3.Al.B......... <..&...q.X.yw}/.......gd..4m.^..Ne.......r:..u...eYBf4o..)../.1N.<.Lc~.a.1Jo@...7>...Xn!.H_.`.{.....30r.!{ ..n.gZ.F.....?.dZ.*..w1Z.).k...H......*.af............;...~.!u!Y..d.V{_..%.iT..^...K...vg..V....cU Ru....X,.........4....mpR%.....+..=.....n.:Z.3h=p.....2.%.g.#......K'.?...x.W...........r....5%..(...bHS....].R...."sf.>?|.....H.i.O4.|.5.....*."......,.I}\.(.....W`..1$:.~.<<.....a.R...g.......1...:..}@.{O.C.{P#.=.c.P..7./.O..?.%....p.}...@.u.t...D.".@-,...A.....(....1...$..*<...|..[..!c..NE%.j.2...>,......4.y..,..!...).H...`...&3..*.T.egP..v..A).W...)...U...../.KlU.du.m"WW2..$o.|3..V.-...P...U.aDs...."T..v.......\....;..yz.rI.u.w... .k....rdB..?Z...8d.......D..i...^....d.|.V>.F.X..K...P$.KHM$....u.!.?..W.5...........~..H....FZ..6.x....Aa..o...bO...u.N.q.-.Z".w.!.<..t..@.<.p...2.....O.Y.......@.....c.y.\?khi.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2166
                        Entropy (8bit):7.919212495300964
                        Encrypted:false
                        SSDEEP:
                        MD5:A34FCE83AD3540F9C377FDE4FBB7A944
                        SHA1:818A8DCDFEB2014F5F975319B2C4A2B96F561DC8
                        SHA-256:3850E92F5CE4BC9FCC20888DD117A806BEC0198F593E1C40276156C511121624
                        SHA-512:2A83D06E3E92091A8CA3392B57DDCBA14587F12027A4A05BAC3795DE33E2308CE0152CE2556006237C54D4CABBAB54105D28D7DAE5A449ED3B49CCC6145E0307
                        Malicious:false
                        Preview:;0..4...9..3...3.SJX...ML...."...]..=..Vt...zp.O.VU..}...cO..d.6?.../.....<.D"..C.r.....".~.J~F.....?UtSa.....qh....v..q.wH.h&.W........l.k.w.j.t....0.*..YIn..j......r...:......U..{2d#...T.$@.rbH"i...G..*.e\U.x...l.K6..2%..aQ(...)=.}....7.f.@!{.}........ic.!B..B..\..M...n).7j`90...].b..~..o.... u..[.nw. Rt...G..nEs.{..VnYzh..2.>..XlZ.42k.. 6$#F..q..S....iP..54y.8?yM..$.DbJ.qoO..pG=@......,vt%V..l6.i.A.;.@..t....u_$.........[...b....gg..e.......'.S.}.+.*j_Br.;.+.F[...';...Y.\....X....6.CE.=....K6...7..n.*.!|...N.a.SV[...._...vy..n..:..2...a....#P..j@.(.5#1hA....H6*..J{.[.\qU..G.td.n@0......{3ZH.99.'.....kt.7.oD...^V..b.../...........[..\.........e..<g|.q.'.`.Y!0....V...;.H:>.G.M.F.rH}.,.......=...:.}..2.>..W$S.B.....VS..H.wJ.YO|..}.2......H8n..D._G.7.uf...u..-...@S...e...A...rc..u..I6...:.....fi.Q.....@.W.3H.Q..........f.........s.?.....W#..;.._..[.U..s...#...6.<..}.YQ^x.........$H&GJW.....<"..B.=...5..=...!+6^...V.#.C.......W..,..}".R.*.`...|
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1628
                        Entropy (8bit):7.873238279007829
                        Encrypted:false
                        SSDEEP:
                        MD5:2A56EBBFAF9D57B4AC40B87DFB82E192
                        SHA1:61D46E30B77733E56FAA0E1F42B6E14E4791035F
                        SHA-256:34E3CDA4E2FB114958FA8DC43C7B4774543D5846A3C844814D43E3D36DDFD547
                        SHA-512:0AF4E7025C25624C0055CEB5C716035E6CD36ED541F5416E18506DDCDB33C6B75FFAAD483CCD38DB6820B7FDCF93E090AFDD7C3F9C5748EB3D0C399A7C66A3D5
                        Malicious:false
                        Preview:.<.oSD..z....W.e_..;.X..!..`...|......t.D;.s..l'...qT..M.#.@s..[..W.z'.(vQK..r......~/.Q..<u..........E....i...j.2.y.g.!... C.Y%.r\.M..F.jq)-E..`..!.".d.sq...o.ne.uJ........|..IV.o"..5.......iY...i*r..B.K.,..fd.q...QaG..7...mn.`8......nG......m.N..|..>.....MK.P.{..^.g.O2...6U..#L...\6...E...........|1.>.z=...."PF.f..9..v..dx....po..x...VhK.. h.,b...'.T?.yEi/.o.\.?)'j1....E.h.......K .d.@.}...W6\....z.=..g....0...1W.%...........J..3....w..5.g..Z.....)..Y.zin......j.O..D..L ..h....4..L....g..'.:"........).r.YZ...*2...O...... vC..;.......B)A..#.....@...).}G...n...N.....I;9r......).-.>.;.........6.n?G..b-o...$.y..K........Z...SL.h..tK.i..I).Qu...=-.Vf....iG..[.Cz*.D.}.).....h.......6...F..E..E....r.:.y.....-.y%DMM.S_S..MF:.......j@.....y.._[LC.........c....p..e.0..z..o1sU...<.%...\]o..l..L...',$.=.........b.-fN..*.......;.....|_.Y..YCTr...ZM7!1..&....Sp.^_U.24.F.%.1.Y2.E)!Dx.....Z.b...|[$Pk.....s..}Ws..y\.d..o...On.<....*.}.p.....}x^..*.nF...^1..l
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2400
                        Entropy (8bit):7.93360656285474
                        Encrypted:false
                        SSDEEP:
                        MD5:FCB042A822513AF79DE2BAA844E7C92C
                        SHA1:FD9BA097C9282DBD2A3623ABCBD00D17EA3B5C69
                        SHA-256:611EFDB889A3DDA6E8967B588E0BA5595FC65410AA427466191FF61337CBBB72
                        SHA-512:E720D251A91CDD637C8ECB8205084D469504DDD3771796D634E379768FB75701387514E1A25D0381E244E1FE5AE7CD3F4840EAE9B4130DBC09D908D4FF97D686
                        Malicious:false
                        Preview:Q..`...d0..3...].aZ~.....}.B._...."..+./UD.*.......L/Z.....!..:.t..4.cW.P..U..l.........,..{....G.d.2.%-..l.$.."$..Ar..x.|.....(.......%.....[p..~k/...9q....T'....-.E.Q:];P.`q.....E.d^.w%.O...l].L...a..::.F.%.....*.......~.E.W..j.....Oz..m.......p.Fq.>...uJ}*l.#..I.5...:..c...\b......QBQ. .TY.~.M.?fc.~.{...r.]7~ux;..q..W..pZ.....I..82......5..]..7)..)p'.>S.....oP.h[..)y...*.).8..J..)[.....`..3b..Z.....$..J.A.../%...<#MI8....n.\`....`.V.#8......g.!'{2m.v..*....D.....n...1.>..d.3.g.S[.&n..:.W.iH.!..G....._6I.y+X..W..Xa..7..C.....|..N!R..|V9..5K.m.N.cb..9.M...E.{}.....J...1I....c...(..r..;{..../.B.iF..G..y..."6?p(.7@".....%.*.HWQ..(..?\!_..../.$sm...v..o.G..{5I..W.n.......E.-1.0f..3.M8..~!36(A.R$.h..p2*i..*4jS.q...y....Q..n..4..{.s.......7..>...v.Jexw.....f..'...'..J.*b.....k'6I.)P.....L..1..D.u....iH./..h..$gp.[M..v..}{.p....t....7....}........'.....G........8.O..........".^Z.C*R..-..J.##|m....M.......F5.RX|....((N.rn....<)....Z....T..O4h.s
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1398
                        Entropy (8bit):7.83586589780636
                        Encrypted:false
                        SSDEEP:
                        MD5:908A10F2488F582C2576E963C92C5E6B
                        SHA1:B46866E52210A67E53641B4C8802FA989DE5B3D8
                        SHA-256:BEEAEF9AD8A3D2BCF73A0F6C8C3C4CEC6BE0DFE5F523DA98F3D44AB2B3A45274
                        SHA-512:7B8EE4C1094AC6DA93C018E678AF6E26F3905AF35A6CA674DEE170071EAF4FCD0DA655670B8E007AA88D7147456E61BC55866D06A901EBEA3BAD12150E080C60
                        Malicious:false
                        Preview:..{s..&.9.)..^..."5.J.,X.<TM..B.y_..U............/.....9.X;.P..u".Onv....8~.4.!..0.K.....0...a+^...+.f.P'.!..z_1....&.eK.].'....!..9.>I..D.".......b:E.v-.E..T._...`.p...<(...S..{8....8$u...RBo.m.0.......S...Pj...7..L.....5...x.~.d.53`z........n..d.YB_Zt.{...t,R..?1d.......og...KN..R_5o..?.j....^.)z~..N....>.....T.....B..G..A&j...Z.!..qZ?8..P.*.kL.f.;....Tq$2..j.QYJ..6kv..W~......AmP]<p..7.w...U..M.C.I.......|.....f..L..Of..\....?.4...&.K.....o.4..f6Y+..S.3^@...Qv.....6Y.PU.>...._....K...@oO1....\L:M..[u..)..n...B..2A%.n.JoEK..0f......@.*u...!.%...aUE:.....F.._.#x.'.b..cJ.....*:LYb.EC..h...0....,.s....SN.....1...C`B..........SkS...;AK.L.e/b.jJ=x.Z.j...;........&.Ym.......[j.=8.V.<..3e..^..X.Y..R`k....Kb.MB.n ......od1cf|...j<. ..'..........J];....z.X..1|.B.p.R...i.x.........`C=...yg.?8.......@.......jFT.&g~.l.....".....K:@... m..H.e2. F..)......@.../.mM.{......U..M...5..&..ld.&.1.....*..t=.I.=3-.k...$.u..E:.Y....D.`,=&%g@.i.\c..AU[
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1234
                        Entropy (8bit):7.838952763561307
                        Encrypted:false
                        SSDEEP:
                        MD5:7E67456392F03827C3B18507E9D4A005
                        SHA1:D141A0C867D5E2C4CCF5736E767BAC408BF22908
                        SHA-256:1C3A5187D646224070A95104022D7C8DDF3061182491400DA50FA69A234CC225
                        SHA-512:F16691D6457994FCFB5C8988ABF9CCCC7105698D227FFB8714C5ECF568D4A4790F9FA98398A30D6ED7F6E6E9B932B8F1459C3644BD1888612BDBDE831ADE9755
                        Malicious:false
                        Preview:2G...L........+..).f6.H....6...a....(.....5..:.4%....|...g."w..,3.......k0....;...-.FB._...G....e>...@....a6Q..../...r......|.;......m!~......~...$.......D..rg...E.+#.=....B..0._.C.u...Y.m.uHt.C%./w...k.h.|..9...p..x..ON`...xa.1{.a.H..6...L}.Jy..]B...R..........j..*..}..R..U.o...Q..J).,^G...y....j...2..HG..~X).u.W....X.G..q.3o....2T2..x3.X.T.a.i.lgVO.tw.6.3.....j...$.hYCy.Kd.....1...%||._.k3.+.(..n.}L1N{.{...^.....k........k...G.}...X.\,.J..O....]q.`.T...T...D...-`....vj..R..aj..o..=.h;...M..@.. O$..,.`.,^.fK..5ys7".@8f.....8.q."..<P.oL.^...u.';..S......1..3@.....a.O..*..K.....]...6.1...%...^ ....@.......:.;<..18...i.c....~.i...MN?......F......r....(..!Et6.m.....O;;.K:e...5.)B.|.#..d..D.5.u.m'...^*.b.y8...........>..khZ.T).S.~0...KW|..TIw...%..$."Kr..k..q.Z...B;.D.....d.Q.[.q.p@J.B`Y$...~\..s.........c.M...p....~...R..6..BSB......%&=.<..+.c.*..K..0..](}L=..'L...0...h...A............O.'.......Jf.%....%K...X.Q..i..f....w.k.#v..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1230
                        Entropy (8bit):7.851097360752481
                        Encrypted:false
                        SSDEEP:
                        MD5:82A36CE2D302932FF3BD40CE278A1251
                        SHA1:0528D795485AD50D228EC16544D9FF8F86631A83
                        SHA-256:77A7D5CB9115620A967DD12EC03C0EE66DE8D08EF877413559D34115CC7C44A3
                        SHA-512:0445C30AA716D15ADF735F6EE892ADC555A780402959AFC8E3A8A853710B7E17BD3A992C173A7EC099432F5BB3C61E5B8343ADE5CF8D37700922B4443F3BFBF8
                        Malicious:false
                        Preview:......V.k..y0....a.X..R.7...VIQ..|..g~B...H~..........7.#..b..}qy....$\../J...g5.K..'.%..W.....{..N.[..:.].......s...f...3.. h.=..T..-.[(w[;.d...Qu.Q..TF..._.j.!..]..W(..E.G.-/>.Vj...`.i.5.k3Id..L%&.WP...+@M..U+..U.c...L4.%$...'c-....._...'..........v{....C.....x...l....PF7..}G.X......o.....kt.6.7......MS.4..k/J)..`\.o.|...s.<Uv..&W.aQ..g.({.'k._o..i..q..K:;.J.]..c...+>u....;..4......H..dc..YND...|.$......?..f....CW&..v2.Xw..4L..=.<Q...?...[.B..OzT.!.+{.Ya....G.B.5_W.(..Fm1..6h2H~...%....9*k.A..N..h.l..WqD..g.:..-..xS..).h...E.P<..4}v..#...H....$l).^.)..q..X....6e..?.v......l..".K.^/ a.f.Z..jz..<.W..B%....H.....j..MLI.#...R....E*q.D...9&:..n..Dg...3...NC.......Z..D..K:rc.T../....83...1~.>1....lBR.;..?.m.G.9rI...._JZ...My.?..lq....g|.Zdl:...?...<.yM..k..O...h..RM...GF1.yx..=..x.....3......l..n=...8+6E.Q......Tg..t.>...k.2.)..|..........M.....Y....E.../..)X....y..K..'6.3u.9.I.V....o3.....Q(..[..P.....T..4w.[..A..a..U....u..<.-.9[.J*.r
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1234
                        Entropy (8bit):7.841533147144139
                        Encrypted:false
                        SSDEEP:
                        MD5:F373E92730BC134C8E0134012D826152
                        SHA1:56B87F037A119056B12C3BA2116D8B38889FBD41
                        SHA-256:05F88AFB4E03BA5207BA227BB0B70CDC4B363BC86C7CF67F279938F933CA87F0
                        SHA-512:B0007D0662C082909859846A999EC6C6B7640BEA0024C6A65DE1C607B8C557FF782198E5B72D2271D5335D7CB553E566BD7BFCAE29C7089A7BE8AD5983960085
                        Malicious:false
                        Preview:#..O..4.c.Q3t...?8{.n.~P...8....Ob..Z...f...R.`.ic)..~......U..*.'D.!....Lw...`.....nk.m..R..|..s.Ox....${..$8!.5..M.e. .9..!..h.L..?....L.B....}J..ft....,G.V..i'=7..[c..z..-#.5..3z..BnK..^..B..O...;.}.2;....H...M....Xr....T.S&....53...{:..p.*,j0.Z.....%...K..T....A.].5.+FcR.V.._.z.|?.}h.)........o.5/....k.u......}....`..5...C.3......M..?.;-..M.PU.u.g...F.V.iE..b./6.X2...;.3.?#......'..[.:\g..u.x.*RdB......G{...n.Y....jR.D ._Q.c..k......B~P'....?.A6..m.`.`f'.7.....'....3.Z...o.Z...q_..?...*.....v.x.}......1#.H.:..V5.F...D..0&...t..P...~..".....q..s...b..z.....o7.J.*]dR..o7.v.U.:'W6.]......i...$..~....*Z.T....v..]w.5..y*....c...._.....G.?..D.3<LJI..|....s..aUjx..w....m.g..V!.;..l.....a...7.K:.`~..z]jn.J`.;k6eQ\.|....._.O.../.o.<..MmO.......2..\.......1s.5.'i.m...*._Z......IWn!.....t2_...`..H.|oV...!6...%..P.a.>5}=..+......Xy@.Mn. SBh......nb.....[.*.l...pz.........s....}...!..E..t_......P..O...meO.....8......|#..:{.a}..![..P......K.V..&.....Y'.Bn...@a(.0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2341
                        Entropy (8bit):7.925489631684525
                        Encrypted:false
                        SSDEEP:
                        MD5:2DA479C7AFD8EE81C75810468D7530E7
                        SHA1:75D118450F1E7023C96BAC7C4A362B26A4342A33
                        SHA-256:2CB8402F6F91D0A1F5D2BCF64E431E6112C9AA9DC2B4B4C43F891C6DBF7CC459
                        SHA-512:CBD2F0B9B628CD961D2E46E81AAF3B6908A8587A72EBF5EE0B8023431EE9FAF05C3B50912D6078EAA631C1411D78BBB519ED674E6D40891E26B026705DF446D0
                        Malicious:false
                        Preview:..l...[}|]..z...ONI.Y.f...s....z2.n..q.Cx....S...[........{...r...A.z.{,J..:y.......N..R.^...w_m..5b(.K\jC.....9..w/.Oh..)...w!.........za1.+i.?....`.8=S.{x.k..."c....fUP.M.. s..CC.....\..L.6.a.U{.DB..uq.^u7..g.wh.-#.I....."S./.RIP......i.4.k.{....m......W...o.>&.VR...H..mX.......)Y..d-k..(..#.c.l..@..c.J>...'^.....j...l.^D..[..@..J.......C...i>..'..).J....m..y&..{...\?I...:N.)....{UR..>?..\"t........W...=`...y!.sr....,...5K.....3@..y/_<.rnr-....F...8.M.f...QhQm.m........G.S.0.!....o...k.......M.....f.`<b.l.X...O}.OV@.*D.!.4.....f..9]... ~...q...V.....^#Y..&6.!...5N#......}.Q.jJ)T7.!......../....-.v..q._.;.....OkOIe.b|9.R..X.V....g.......x...c@.....Nl{..Z..B..bO{.\H+..0..R.,.....rG...:i.P..|#Oj....Z;.....~..8._;-.&...}k.chE..b...n.2....a.....Oo5..8..5.x..=_..>....S.tO.4....;.4.o.p...OQ.9".+I.QW..>.@.H0..T..2^..C..=..MHl`....F....aE..m.....".~%"Y...2ETC.y..?p:.G..x...BS..6B.T.....Q.T.\.u..Q.~.....>.].s.....f.. .....0;W....G.v.6O0.:
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2202
                        Entropy (8bit):7.909440418548876
                        Encrypted:false
                        SSDEEP:
                        MD5:DEAD4FAAA549091FF5BEF4D712772EC2
                        SHA1:71C7B6C269DAD0F4D5E52D61EB3F85801F263505
                        SHA-256:8D6E30EA2A25D1109D7988179F3AECEA34F608CDEF4E4A0FE8D0397C988FE693
                        SHA-512:E5956DB70198CAFA6C64EE3D34A0F5F6F8C3F1119371B7938F6A77FB91AB087D4E06F1823AC230037A523C021CF2445284FC624E6AA5DDCA4703F5A982268387
                        Malicious:false
                        Preview:.2;..'s..9.....N...H..=&..Xe].Xs.&)....Y.....c..~.r..Y.....r....jVG....%...f.c.:.X%.E..Q..U...;..#T1=3.,(.\ J2.f.F4.9..E..L.:I..^..jt...1....&.S.~..@.Z%..-...!...9...H..>.g..`...E5[..@.....H.L.+_;%......V.+$0P..r.R.....&...7.....T...!a...)?P..-.)s..`.......p..".....1.`!...O!.5.\^.._5.o.....>-...j..._.........7w.....{2Np.y..KP.K6]..,\....Z.X..J..!...q.%...^..:.....FN.Cc.EZ..P.%$...*:../5..b...lpW....?"..C.".<...'...K(I.\......6..}..@....mp.....q.i0....,...?....].*3..o.k.hc....'.@Q..(w...'CgX...2.yC...y._.Z.9.h>...{..'.....8...'..r...A........#W.2/{U..nf.F..?..I.>....W?.....g.qNp.`5.i)>>.!...l..@.>.:,*...'...|....~.2R(.......T..:w......n^t........'..lg..8.....KTB.?...!.}....&.M.....+q.....7d.o..,Ef..Y.|",L.UG.dO.)........L_.Hh].5.m..Z.s.D...S..A....yU.4..|...l..F.l. ~..i!C.Bx.sC..rT.?....c....dKub.,(f....*.U...P.CS;..(t..vZ.X#.h..f.8.j.......S.!.....uE.H........s...:..5.h...,..ec.....O.n....K...d..7.....$...j;.{K/.R.'@s.:.^.yR...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1465
                        Entropy (8bit):7.882793294636453
                        Encrypted:false
                        SSDEEP:
                        MD5:E4F723AD2C807342F674008F5FFEBA52
                        SHA1:6FFE504D7EFD49C189CE266675E21B55EEE29C6E
                        SHA-256:AF18942047C61A5020CAF307F518E3EECC65C12875B15811D259190603459128
                        SHA-512:7DE02C2C484EDD3A39BA5869E3D1C64A033D5D75F452B4D7CF829685BDDFA88909BE14CCAD949BCB889E6F51FE837CC45A3DFB2A1C679E45C8E03066E0967C92
                        Malicious:false
                        Preview:.^%........z.L.@.W./..sy....h.s..P....C.)..g..xn.".b.l..Z.Te'F...).I...6..1.....!(Q.w..Bp.....N}X..9..W...[.8p.L..c>..dQ.].I......E...d.y4~.s?.t.....R9.&...}+..,...{..h...L...]vJ..6Q..Aj->...{T.IK....0.O........*...n....<kH.......t|...3V...........V......\.kKN...2'.-....T......c.......~...Z..f8a^.j[.-.....cHh.a..cPE.=.k#.3.Q.U.J}!.......;.x....i.]$.sv.z..6kra<.......*..B.s&`Nv......C..F...y.W6.AP..p.L..j.uq....>.&....lUqE.....Gss.Ya........l.}.=a..N..A..E..?m.L3ccuu..'........4.....0.......P&.T%....).....jb0.. .Q....%.p.vv.l..M).iU.....p..).K....1.Z.|\.!4.g.r*N..l_.S6..A..I.......gb&P.].D...)2#J...f)..$......KA.M.:.=.lkw.I..@@..>...v..L.3I..=PA.d._.R.%..3....fy...4.?S...._}..O.FE..n...\..........R..-...D.. F.2'..q.}..M..N...F.d.. l.0T_.]`9.Zf....-..u..X2.7...G..y.V.F..vD...JX....m..&..W...|..Ek..5?..O.....3;..z?.X..X{..U...."....>......m...iSl70..!l.+...3Q&..Gb.2.KH:..qM..h.R....E..h..;9.w.K:=.....~...8[.a.....c..j.G.5y..z]..O..Bh..O=..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1994
                        Entropy (8bit):7.923134875617663
                        Encrypted:false
                        SSDEEP:
                        MD5:2644766041580EEB1883651CB0CCF617
                        SHA1:F1B3DA4A6446A46EC192CC4E2D9CECE0065EA0B7
                        SHA-256:741CD4E92002745B753E3D5F38063E324A46AE65F1B0EA10F04ADE5BBA9A51ED
                        SHA-512:2168B5693A18E890F63434DBFFFCAFABF2DCFBF82DD81F050B2B59D114ACA1D46CA348DE0F51B435A57DF8042ACFE26E9DC782B8455D3B967FF60E43C305E65E
                        Malicious:false
                        Preview:..zg[..<..H..6Ic......|....6.@..lR'....2.>"...r..S7).H...MH.....<.LY...<....<.a..&;;(....p.@..._.E..{..g...So...YuM|..~^..O..."..(..=.m..#.,.R.c.......G....<."..>..Y..E...0.6{..X`.#.a._...d)K?....g:FQ....#...A...\.#.(^J..k.....SB8...0.r....l.K..|r.....H7Q...n).F^'..@.V..;?........f...3I+.[./..k.#..Vn..|...........o..lW..K/Z..*.;...T..T.&..>J...u.Z.f=.HZ.-....../W./.v.t(..&..a..b....1%.W............M....M-7.$9#...sF....b....L..o]`7-.).J....3f.E.6B........Q..=[..p#...4..`W..2.S.....1.t......}z..!....'b.);..?.'..C. J....i..r..L.1.2.....v.TS.....y.[.(@.B...!b..*"'....HK...77...W.yy.-W.J'5.f.....d..R.:.O..q=..z..K0........]V..t._./%o...9.h........&.1...+..0.IS..C...Y...... ..'4k=..^......+..?b.|.. +]).I..5..46'R.._..wQ....h.....@:c...?........`.Fn/.d....g......G..cZ...F../..P...............%..U.f..K..h.".....1..@.)..~..o:...3.....qf..K,4.z.2...v......". ....\Ob....w.....=..J..HNa....:...Ol...JhG......Ax..p...e.ACi...L....!B..K.".N.z.5..@
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1467
                        Entropy (8bit):7.8821447612702125
                        Encrypted:false
                        SSDEEP:
                        MD5:C79EA2E4F017A7A1AD6CB75A16FB88C5
                        SHA1:D8FDAC31D4DBFBDF2B2028725B866BB75D52A6F2
                        SHA-256:92DA7B9F783CE078D5840A9F5AB98E19D5772ACE1B9A90906C10D7360DEA80E2
                        SHA-512:1F0AC26A2AC56BB766A72973FAE1FD07650AEBB0AA309DC6F8496ABC1519FC75ABBACFB3E85355F7369F99D193598D0FF770CC063DD47F543B54961CD4542DC5
                        Malicious:false
                        Preview:%...].L...(.......Oh..]FR...d.....m%2.5sD.E..r!@.<..Ot.'..$.../I....r.S....-...n.!.r..C8h....x.E....o. no.*...D..O..V.^w..O=.....*zn.".]]-.Q.L...Z..\.v:N{....q....l....2f..w.............sj6...."AiK..../...8...dKm4.Mc.1......:...w.&^4d...GJ....?.h^-.H..........x/....q....da-q}Qj..xqK.^..z.-.Q.Q...ie`.0S...75}.SD..l.~Ha].....'O.[ub.hH..V..m3...#....d...@.y..V=..gr.+..!=.p..........b..C....5.rk.j..T..z=.."$b?%.2..*}..........H.f.....t.......0;.-..[.j.^eHNa..q?~..[P7..B[.y2.....l..d.)....n<.._...A.ag....c._..$.....z.&...fe..q1..+..o.............=....1.c.5...NN.o.d^2.[...B.8..F...-eW..W.;@......$.6..F.kup.9.f.. ....e...I..|..8........6u;~.#..s8.HN.~....@.H.?.[...$../H...*.d..t..=r.d.`.)+..>\.%.z-......I:.7.FD_.n.G]t.g.X.p$.z._...=..P....P.L_.M.....k...'..?J....%..3...-...r8..ZfT.`.E?....#.e....j(....)....:...&.Y.....qE.Z......J8`.....^...i.........pU....m... A..T..(..<..AX\qy.'.....%Pz.'K::.).!Uz.?D...l..C.+........O.(I.......F....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1469
                        Entropy (8bit):7.880596721514819
                        Encrypted:false
                        SSDEEP:
                        MD5:8B89A8A074FEBFE10F50BD3460CD3DC9
                        SHA1:C10A128D58AEFC58C791416B77352C99AF5AFB35
                        SHA-256:196D448CC9485485E4476AFAC24656BCE69CA9FB6EDAE01326AF85E8E8BE4FF6
                        SHA-512:19B6F550EBF9C7DA74C1FCC22FF4AF95A5FFF14E63AC3000F8F20668D8B85B98F0D1355D0B7A0F14E86413B1A672A1B1BE0509C7865A14DD1CB6A2826EC7EB57
                        Malicious:false
                        Preview:...<J!Ds.E..!`..k...1..o..'....@....SI..E...u(7......E"|..G<........b...\..L.{T3.'Ya.z........^.JA....P.M..T.J.<..I.U.8.~..,.}..k.x.."ig..........;..E.KO]d..A.+..XZk.>...~.X.P.f.).o.....b.#...v.H..y.?4c......Iw..OR^`..<..=...2..!H.Z...............,..'.w#e. ......h.1..>WdY.{.n6...R..s6.]N.x&.../..lX...].hYS....p2.....*...._/,...b.....a.he.W....=F..Q..c.H..`S.`.d...<&.I.$S..JA.@.........F.=..g.H.e...J........Y..?.(.$-y4.X= .5....q./1...h....h.y..IRk]............zl...H...?.0..T:..*.UqE..4.k........x....)A...RW...n.\..q..6c>.5.<su...<.....4.4.2 .....yD]...}-..5..>...e..#%Zo..g.B.n.....)....GM}..b....z-.b@.;1...&r\.........-.......y..*W(..8 ...$.f[.o..0L9.0.......y....r.L/m....@......*.....b...\*...@TZ..0.q..[.9..-..#....;....j>l.>.............PO]....&..O.C.^..O;Thg,[*je....Jb_i.(..........~S....-.X'.Wip.{...W.....1..|4{....8..q...6M...3...1.$3"..We.K.j).....J.......'Z....0..n... .1......K:qs&`Y....lj{..oKM.....}j.Il.i...tr..x..,..L
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1395
                        Entropy (8bit):7.867252310513616
                        Encrypted:false
                        SSDEEP:
                        MD5:DB7B5497AC1CB730300630FE14AED666
                        SHA1:2377818F24BCE61DBCF221A1D4CC88BD4475AC90
                        SHA-256:7B80EFD348483A792B3C19102D28CD7AF5B1209D6EF2A5A41384CFA9626DAE34
                        SHA-512:8E5895F063401AA7A7D3567FF96F00D0531C999A20A37653703B1B9F9A793863443C267367B4BA9BDF0B9722841188A86956E3509A06C0844E122D6851B0D781
                        Malicious:false
                        Preview:`..3G...~..D=Y.e...H...@......\...-_.UG.Y2.._C!:..&.!....Y.J%jF.AN.fJm...{.{...,..a....E.?#..FN.7=..J.r._..5.i....E......Z....J<.d.j=.Vp(....{B.....l.S.,...BLi.=(....@.zQQ.)...1.....W!...l._..H..>W..w..hB.Ns..=k..0.m7......g.=.u..;]...EX.~..y.@=...v...}!".#..)="S..2...}x..P..A...;....[Z......Us`-....h.......<..&H(...r,.{,.,..JA.*...U..9wu=j..G.-...j.....;..<4..;./H....9.....s.K7..9\..........Z.x9.6&.B.%..6..x..`...4..O@+..........g..=....s[\c..E0.0....7...~.d....>M......;.$..".."..Q.....E......Y..E..(...dw@g8T..%.....!ZX.S...+f.......Y..z.f.3I..R.bL..Q7.M....<...D%.P..#j^.^...1..U...h......{.zmH.......Bq...........".5.<.._f. .rM....:..{s<PtH.*..:....g.A..b}.G..h.Q.|+\..}..K.<.....$#m......_-.C....*R<..W..$..;F.."....d5.l...&Ui!hd.$......E..{.%.IK.OxI..C...RR.s..Z...B.^,..M...g1X.v.....:d*......j3 ....@.@..|........{..~..*.'K:x%.Y.V.]1\...9hkLh..F..6:......u."C'4NJ#.;.rI.....J..(...9.jt=?..%...Q-...F.....J...4....+j.u)Xwj......Z...../!.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3599
                        Entropy (8bit):7.948328758365818
                        Encrypted:false
                        SSDEEP:
                        MD5:0E6B2765C3512AEB5A6991D601251742
                        SHA1:8708DD4D99354FD9CC5157873A1F1EBD3BA0CA80
                        SHA-256:FF52AED42842B9AA58C0F0390503657BC61F49FA7F35D56D9FF621CDD982E4BB
                        SHA-512:74086F69AB50A1112B8EEA955C04F10C07DAB7C71EFE76DF8C7619DAE42A5BD5A5FF4607CF4805249CC865A0A694128A91709BBBEE4F9418C0F3A015693701DF
                        Malicious:false
                        Preview:..6.9........aM.0,./V..x\...v...k=.p.E...Vj....h.'..N."w.|.#.7...`C..E.EU..D-....$..<f+..%.5...&..S.A..[>.|m.<...;.K..[N.....,..sl..Y....M../.....*...9.tcq.W.-E.D..p....!....t...$.......h.#hPE.\.....k....h6.....q./...1#.@}....y.W..i.Bc..8./......j....h....\H._/.{..K..,...<.....1...1...&..~....2.PtA..0..D..V.$.E....U$.G...-Y.,.^.[`..h.)<Qh.K1.+.e3{q.q._.....+.....1...J.@.a.....:.PVy...t".|].<....F.m.1E.y..9&.B........_.<...d)'B.8...#m......8..2.4..K..;`..4...@......1...'..*.Cn........#_h.t......nv.~}}y..~..R*49...+.AD.m......H.pKl.F.od.......aP...zj.....Z......J!.3......M..9.}..8!j..~..9.S....|..W.?.R..@.7................?'eC..B..\..Y...Na......x.............^E..A...$A.z..C........O'..R._.X._.......{./.6.....cLv...........@...i......'.(..!.....[..O|E...W.Y...9x..u.#..z..b..VH..#..l....>...O...6W.M.Y.?.{...a....g...~."....B.~m..gr..\....{W....d...._.hs.e...k%. ..T.G;u.m.Z....4....BK..6...d....?.:... C.`Z1.f.r....o...-BQ..}~.j#H.".l.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):3599
                        Entropy (8bit):7.948957024316111
                        Encrypted:false
                        SSDEEP:
                        MD5:59C6B82224B8459CB74BCE9F410BD337
                        SHA1:2EFE2E8776E2CCE2D983ACF6CBDEF73FC464A05E
                        SHA-256:B1B83908B7D16D655B2D6E28AE78F1373017EDE12408FF586BAF65A6388C1EE8
                        SHA-512:290C6D20B1302DDAA6F82BF6D9AA00447FE65BCCE2DD75403A06BA783418817279D9214C28A98B846EFECDBFE6A8DFA23A24BC82A0296CBFC42B6EB7272B22F0
                        Malicious:false
                        Preview:16......`...1H.^6......)..N....PG[.o4..................Q9....7...V.f6.V..l>L...JM%;.<...o#.........P)A..rR....7.~p..7..'0.:~.i.8j.t.....&.Jr_.w.t(.s......?G.....Qc..t./.dD...J.`....` .]....(...7<n....n.}:..G......n....7..4...R@R>R.gj....$..t7../..a.:....B.A..]A....^+.I.S..#24!q......J.P..+I.c.A...7[.....l.|.9( ;=..4..0=.y..w.C~..\.....C..r5.[..ce...FhR&*.=..f.@ZaL5..~.F3.9i4|\G...'...&..\g9.P.l(.}...D.+.u....}5...mz.3R...t..K/.h`../!.......D.]D>h..8Ei.wI/{.9)zIryr...3..g.[@.|..Q....^.\.k.:..mX:.TfoR..6G..ordk...JZe.X.Q...]4~.%c..\....TX.Y.....X4/.|m.+....!.C..oac....%.Yd.[M.B..xzp>h.I.1|@.e~....0..*...'...Z....f..A|n.53..........c..L...SW.sz,....r....S^_...r..JGijw.?|X>.....9:<U...!b..V....;...^.......+.X....f...S.F.G.E..P..T.[..........D...X.8...oc/Az.......h......$C...M\...Y.L...1..I..O(.h......-..;..r........E...[.|..i........s.>K1.......U.J...?........i/5.......@.... ...H.$.?(;<.8...J..|U...%..Y.L..5QQci...f13.....e..M.i(.e..U
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1324
                        Entropy (8bit):7.866263229167652
                        Encrypted:false
                        SSDEEP:
                        MD5:7FBD35CB6BF37239DFA77D1B090D74E1
                        SHA1:C726A9669AC9A36C64FAEB5FF81B2833F80B9D15
                        SHA-256:ABDD3A2948C1D2BCFC30201189DDC2513AE9E6FB89FF99D2C99B5B6B0E739B6B
                        SHA-512:2B14E5089323513EFE9156239B3DBF2DB12252DCC6CC41B75D3A25A02F8341CECCF3141AC8F5D930D0B1F449B6F02B1A4BC6E4BD8A09FB6D441CD2AC11B69DC4
                        Malicious:false
                        Preview:#v..a.px.r.QY..C.A.[\....qS../.y..;....p...y".R..`h$...e+.'.P.L.w.K5R..........71.n..P...cJ....8....r................[.y...v.............$.......z.....8f.v.0~..>.4.....,O,^.X#*.y..h..".....n<...j.WhC4I_.%4.'r....{...=ty...0.2n......{......Zp.g.*/5~...fI..3..J.8a(.p..\.@*.c.*...2~.l.a.i'.Y6..u...N.XGA.....I0.:V......w.\v.3B.coD8...`..}})....rD..X)c...T...:...M.....+..-n.S.?.......F.=J....e.e.6r%..XQ..d.l.:v......@hk.Y...af..i.%...&"...K.<"h.KP,..l*...l.|...KW.pa.1..e).m8....jQSv...C.M^...J..:2>....Ey..`.#g.....)t/.E....e.}.A.s.{..k..D ..k3...w..3...".XHCj(@n...Mx.C...M...[.T..t>..WK....G.....%M..}.b..I..b.>.e.]..5.f..!..x.l..\...c.d......@.9.<.....Qh.O........@.@.......9j..dE.$...........zJ.Q..1O;7] W.4&....j....u4e.P......7.g.~-..)...6...y..R.z).qf.K:;...&=1BPu.|.b.&.....f...l\*.}..kT/..nM...C.......llyl..j,)L0.N.....c....*'...s.`....Wxd.=.. .....mA..>Iv.P....6G.9d.(.dX..a..G...Q.T.ZWQ..@N.d.x......*....QzS6lC..s.`.-.YL=/.c....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1234
                        Entropy (8bit):7.823546093971488
                        Encrypted:false
                        SSDEEP:
                        MD5:6AAD0A70292DD5147727E4472F78161E
                        SHA1:E56771F722A4E2DFD07DED11A3320B95A7054FE1
                        SHA-256:747B7A53A0E73C5539A9A3272F1B91D663F74AABEC644796C75DF96CA869687E
                        SHA-512:EE837E4F744E4AAB810AABBBD764B9E6072E9F1EC66F18F1BC8DCA1D56692C184DBCA1947C642D0EE6758C2B97D00BA3C029FC2B004376052405475BA0091A7C
                        Malicious:false
                        Preview:*..N.....#..u.'.~)..t......2..B.A.yi.......p.c....k/.!.2.P.AG...n.v.$B...2..N.........W.....B..a.W'.....y.uv5Y..X....Q..<..sp.....d.....J...`+y.8.nnH+j.2.L..6...O.....HP..5.A.2..j.TP..x.fp.RB.....\!.c6).p.8.A.>{F...3.d....9.....D...."..BP........y..9."*'.YW.{.}@=......]T............df......@:.!L..\uT..9.p.....K2...j..I...Ak..H.9..o.5....* ...z..H.q.....<..v}...d.4.x./...=...j.-..&.......z......RHj..D..8r .t9*...c...w*......)=.X..<..XJ1pbI.L..Q.a..vnB).oA0..@.Av..R....f..h.L..F..@.W.....(.u"fU.i....4....se.......:.Q.j...(.bojx.m.....l.!.YJ...X..(E...H._%.(.Kp,Md...v.J..P...z.qb..i^".........H.(.... ..OD*..4.Do=_7.\..x!G.d!b.....L\H~..=.jt........i.*.d..%.B=)..<p.v\=..?V.W._..l5...F.K:...............Q$.}...w...P.@..~R.x......G......q...1Ii.4.hn.S.H7{..lEx..g.........c.+!1.$..E.b)...<.h#...*X.....p....-........Z.+h.../v.#'..}$.~U.....299a,c.p9C/:T&e...xh.cO:...Lv...MZ....?Yo.;.].X...;t.`.=....h..X.A......?6C..".... ...T.$...5........J...e..s..$o
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):68214
                        Entropy (8bit):7.997113355471589
                        Encrypted:true
                        SSDEEP:
                        MD5:455B1D641044C1D6E9AB0E17C29080BF
                        SHA1:F003FFC97537E9DB542EE3FA729928839B9D328D
                        SHA-256:1BFB7A72E9715747BFF471BB3F3AA5D3297DE4A2FBC702D6ADE031E7A4D99C15
                        SHA-512:5B74E60EE4BBDB7F3865FC8AC5108898D6922358779B63F01F7FF71B19389D3ECB15DE1103B1059EC9F95F8F16B281868980C7ABEAF6DADBB4BE7B0DE675F44F
                        Malicious:true
                        Preview:.U.h.....8.1..J...K......u...f.7z.D...V.;r...Y..>..w.....oB.1...W9F.y.u.}VQ..!h..M....a.z.k....=tz...^.B._.+.Bs......\..i...&........X\..&=.....h.0...R..P.q..)...%..2 ........mVMa..;F.O..u...S2..P"db.?.~..6Q....A.%.).7....[XnF..Y...J..M6...5]..S..@.....f...-.l.P....7...H.......-d.2.v.....z.........%..b..{......l...7.+.wb.YUs..6..g.F._.4..B@...[!5Uz.....&7......I............mZ.P@^)P.A....L\...r..."..;=s.?w..A......4.......-8.m....|b.d.o.Y..n......t.......9... ..d..I...jv......Xc.p.G.Wb.P..t....4.G..S"X..X_gE."..M'H..8......*h..]......S..E..........B.&/.d,#/..|......S.|.5..](...D0...|..G.aj;.o..)v....&up..(..<.e.'6...j'i.&...Ky..!8...s8uy..}. ....C....\..[.....0.`.....R....%...../..-.Q....=b....WM'.p........%...g.<.f..~...m.......B.c^..,..<.&.k...Z.Y.......*...]?..O..Y.h8.....Y....$...\...........P..J.X_....b..H.sK.O.).z.yL..b.~j..$].i9c..K.....p..[]}...M#o}:..i.....:.ZF..N.r....*!...:.2..LS\./........O....T..$.Au....Z>W.E..#.!_...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):112923
                        Entropy (8bit):7.998426839505144
                        Encrypted:true
                        SSDEEP:
                        MD5:A10CFF26FE4E6B2BD4D160B606A4D2F4
                        SHA1:688213446B4C1C86BFC3857CDC1CE0F5D8EC1435
                        SHA-256:B6764CAF936FE3338F49A29861F100022FF8A3F11089E57E87344A2599966228
                        SHA-512:4C2183AB7387C92A4F58B50667C9F4ABED7305623DCEB605AD4A8B1C82CB3A478F8E6AFF409B0CF653F71447DA181E841ADD8F1B9BBCC2E53B89905327D208DE
                        Malicious:true
                        Preview:.%.....R<..,..~80].k.....3.[.......$.(..\t...t.u..B/.;..3o..Z....T4..,.......=.W..p...,.Q.V......B....M/..5.1..0..../..e.y.>..D[...|4.kC*...z-+..v......e&h3r.n....w....e..;*..nm.'.........r.;...*.0...b..G..`...Q.=..2...daB.RM.L.V...L..}......W..}A...3}#Y....6.P.....mx@SBC...1.Th...a,...N.._).[i. .>........(3....5m02...o...,P........}4....8zi.......5..O..*_.b}._.y0"..5..Ny.K.!`1k..a....D.}.r....EpR<.\.<.A.>u..,....#'B...6hN\.......&..6q.r...T%,..?.O...1....|.. ..S..>.ZZ...p>X.e..alf.C...k..d..B....rI.X....6..y.8..=.K.{..p.:..."....f....-.....D...*W.# ...T......h.....(..I2.........F......-,,.3#.v.C.ro..H7e.{. .T..>.t.\.O.}.1Q._...z......C8.....G5..i...`o......&I4.h8....3`.'%v...[..Z.....Y/......H.w.>.....E....Er.:.A...&.{OXF6Y3...]..*|..+...._.q.RU..<D..z_!...8...i.X.~....;a...9yn..&Q...0..0z........L.....y:."..|......N.H.6..N.[W.. v.F...W.BL.MK.^U`j@...5>..7....x..b...=$...DF*.l..i..r..P.V.@o..OjQ..s.7'..P....4....7.D..A..0/<.Fv.@.hU
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1070
                        Entropy (8bit):7.822836204609909
                        Encrypted:false
                        SSDEEP:
                        MD5:6257886F8BE1262325778E879EE75803
                        SHA1:0154B1B254096F276934F8A9E289943E57DF1F95
                        SHA-256:527D280E58CE28D71706DCC1E92B5FAC034BF1D503D04BEBD356D94C96373D34
                        SHA-512:66DD9CB014E542C90EC5E48E4FB116578FADDCF8208235E17C86CB25DDFF0AFEA38BE36B58005CF695A3CCADDAA8FF903E640483732B557EC76D2FEC05D59968
                        Malicious:false
                        Preview:.O.......&.Q..S..|....@..j.U.J..4.<.......Uq..a.....vw...t...&};J#-...(..}..jr..3k..u.&..X.U....@5J%\.....8....R.IN...46...../....C.c..=..1..M...t..1*....~].we>.%.k!b....=...@|..k.JI.........mt..)$.5SyS._.&..9.9...aQ.:es.-........-....^D..+s|..u....huk).]...A..'...Vsg&e.41j@.....:.)TOv.K.B. .2...c.g..M..E............`..2=5.L.......e1(3..3E..X.Hb.OS.S'a|..3...^.@...(.qk.P......Y........Q.9.hb.....+...$.'.H: =nm'.X...J.:...0.f..M..okb......2....z...V.\.2...M.......b7...Vj.q..]_...n......-{.>.....Of:tl...o.z.4N....,<\K:..&.S.......BV.....V...q.D.\/.$.6...@$....)..hfD._g.Z9...X...fj....|....^..t..:...;.5.]G.?t)_.:#.s.^.s......`rB.\-.e..=m.m.s.>B...iS...iY.o@..ZH.,.Db.....h...#_..=..G.l.....0Yf..m...*............J.2a....OB..x..M...@...<....`.A.iD...0.m.LB'9.|.i.......[....."...{.....U..F.G{.>.s.xG..|.....K..I.g....r..'4.e......9...We..hh....pJ`8..7.0r.....mZ..|.G.g.>_,.5i.J..Y>_..Q....d...m...6i.X......r.z.-..l.p...f[.:..F...vQ.K=!.G1sa..iQ
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1107
                        Entropy (8bit):7.8402777584960095
                        Encrypted:false
                        SSDEEP:
                        MD5:657A2B7719B26BBFC377983A6DD1EDF8
                        SHA1:76D08D3E88E27B3008AFE3F3120549A98F5FCBEA
                        SHA-256:06A2116430B00B6EC9F4EAA7A3CFFB5783CEF677E62020A473C74C6B3C26B29E
                        SHA-512:1E23B5B9272B2BF80D7342ED25486079C2C010A6CBD8B1B3CA2AE7C94229C9A6DB54E502DC9FC45D52E4ABF1971F2BA85E43BE0C6BF01229B8244530C307A9D2
                        Malicious:false
                        Preview:-/(..@9..._\}..d...Uh.k.....p...=...r...\.....ke..|.j....p..X/."..l....p..P.A.I..^.N.n....` !.W...j..xB5..y (1..@_.......{.MZ.{...~..Pj.x`..B.~..x2W{2.V..U..LU...Oc.....>eR........y..>.|T?..8...F..\..c.9.L..o..!...-.-T..(6....F.....J.....Y....>'..K;.......}.x.......'.\...6dc.6.+s.~g....a.>7f...3.7.>t.:o..*$%L...OA.:..A<..]..:T;..X...i._`...J....p.S.H. .QN......P.8Q.....^.J......q<q.QP...'S...m.rL..);[e....hG.K6G..h..H.!.......c1.j....T.X..p..,.?p.PA.{v...^ui.....;g......_g.."O.....t...<!..+..g..)Q......uu.....ef.k.r...x.f..eWC.b."\5'.....13....Bs.7P.SQ.0....[K:J#MR._.6w......... r.?b....6(.|)w..E..j,4A.I.....E...n.xo.i.wh..R.G'.1..%|<6....q=....|...${...m...u.:.`1..`K...~lAcmkN...*.n...E.+.co..h.uhC.t4.....p.....h.a......y..S.]rtl..H.k..G..e...:....A$....'..fj..w&oc......n..!.5.[/ .u.^.N...b.O.W>@F.l.{Dl....U*LDj(.]k.B..e:.x.XH..E..q.A..........&....h.S)&..;d6..Y%95....k.i.!..........N6.n.......6....^...%..qt...;#....5.m~.Y.3....w..'/.r..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1509
                        Entropy (8bit):7.870821483157506
                        Encrypted:false
                        SSDEEP:
                        MD5:6F98A56790C90D0DE3B7F06338D83632
                        SHA1:0A5EBD2DDB5FC72961F3E254A6EAEAE23776E387
                        SHA-256:C7F7F3487775DEB6D4B2AF852F3168EFD2461873DAAECA423AFF9AAEBC19373F
                        SHA-512:534C2C898DDAEB13E780E8F097E20A1570520007E7AF172502C4D7658F7398B947D71462AAE65604A718108E757D66C92627E482C90D58A613CD79C1C13F58C1
                        Malicious:false
                        Preview:u....si".5../.O..v.DsW.....7..y..z<.t./...|.5.S."........V.p..g..<u*.g8..........O^.dT?M.e....I2.K}..-j...j.~....K.h.,.".z|.N..5..fD.6...x.nkr.7~.....8]&.aL.4..T..........>..A.....y....~.v...f&.ob..T...Hv&zc&5.g.p.$..i.......4..?).8..j..y./.Of..v..i....ea.5....ae.{:....S^...w.PB.^..7e5.M:$.h_....w.....8.uf....".s,..wv.wW..P..K.s..I....q.L6.:Z.0So....p.)..dW.L..5;.E..w..wFDe9u.'L..."...m..L3..wY.{S.R5w6M...f...w....d.bcgX.^Z3.,J....c.......Al.....\.k......B..0..l..?..Em...... t.......|.W.%.5..@.F.:...!zQN)...DI.....L'$.[..iK.\2.QH<...p...}.HY$?...8..n.{..gc..........6u.;.G...h.<.w.w.1.D-.W......`.........y,.e.q.#....j.%,n.....tJ...p.9....a...2.G"..v...nu...%.A.z0c._+.Ni....9..M....f..I.1........C...1q....v.X.k^.Yg....8.....y...!.j....E."..g.....b.].....~L&^....?.[.VT......:]R.+.+.Q.5r0t.~....K..o..Jny..[..../.}e..B]..`..p...-18G............Y.,..:z<Q.K..&.k.j$....H...s....i}.2-..q~..D.b.....#.NO.....{K..x/...E....z..b..8<..R_.n.X.Q....u..K:E..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5170
                        Entropy (8bit):7.961447946935878
                        Encrypted:false
                        SSDEEP:
                        MD5:C1DB1D103BC2C143C0977DFA1EC3177C
                        SHA1:B1907CB6A6B7D5922B532FCAB03185DADD601BA4
                        SHA-256:3A96FC0AE809C29A120013D4AF85D46B00279906A5694FFEB11A59A9DD8836A8
                        SHA-512:DC1284CBFA3E1A30B57048B6EBBE757C1B09462FCD21278EC52E32CB100AB15B787685C3EDDDFB43E4E88F9BD605D2B5E7D06F2CF0EF73EFDDF40A2C36138DC0
                        Malicious:false
                        Preview:9)A.hdY.V.&.MvP..1z${..u.u..k0.|.m:5..D..D..........:....-..i..".4a...MK.)/{.j..p.us...r.T.......K.<..*.......KG....y...t.HFc....nb...G.Q..x..z.1*..2.'...)y$.h...Y;S.iP..d....1.U..C..K.6.".......dX2.A........=.......-Jl?p..?..T.(.i; ......J@....?"Y..-y.1=$...Zy...}.[6.pb..`.I.?(.X....*mr3...n.Ws(...s..4..%.. .^.IS.....Q.m.....W..>I.l.;....."~R....P..A.7}...K......6..]...Z...#...WQ..8.Ge.J..'......m.a...%..L.@:....7j..lH...[...........v..ZS.`t.6.T0|...w...!.'.s.q...C.%...#.h....}ss...f.3${'....-...'.X...:...@^1...w...x?I..u.F..(.=.NM.-..gX<..}.w....1.T..`..[Kh.. .D...(...I.<7< ....ju.....c.................q....],bz.....P...U#...y(}.B...,.n0wWMKI.;.%q...........`'... .i.OT..'z=.8...Kt4..._.1F./.stC.$.........bj.P^.)x..".!.zi..s...)y%...y..{8Y..xO./.n.."...}s..7.Z..R.;...4...i8....kR..S.p.o.....S.......\;.?L...K...4...........d..A.q:.lb,.Q.}...4.r...}....~pJ7a......G=j.....L.B.&@B....8..M$X.........V.O..1&......)4y..up...../..)...;....l.@..w.J.cc
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1591
                        Entropy (8bit):7.876514807766019
                        Encrypted:false
                        SSDEEP:
                        MD5:D68A78C96DB48944FB4D3E0A9B58E0EF
                        SHA1:8AB7B9C2987965303CEF00A8E999426F79574B84
                        SHA-256:B460081E59F4B25319E4DBFB03C031E4F58BCF22590314109C81A4A8184209A0
                        SHA-512:2D6F6B5350BDCF5265D78E578F5BDEB7C2547A71EEFC42D5235EF1D85BBA67991EC26426963C29E1514DFD368A003AB7EED4FAF2053588305F7318794A5D3CAA
                        Malicious:false
                        Preview:r/.z..@T4..VKh.rBjB...tP(/.^A.PA.LLC.w..,6..?.4.Y.y.s.,..7D.......Ga.Q'....\../....7d....z.`..............|.8.6...4......3..U.PH.DF.a...L..:..}.&o.Qu.P.:.y....8.....)).XY...o...;....-I......0..>..);ah&..2.]....K.@E&7.x.V..m....P..Gm...6.4y..v.......dx..*n...H[.......N...9.....P...{..r..-YBY..".F.$...#p.@..Si....2.P.4.o%(...sJ..D..?$.M...xq..F....K..T...^.}....n..y......q..$....>q.N.....Nm.iD.9.wSg.{tY. .3s./...7I8...r.1.>.N...Q4.H...j.....-.....)S.vK.H...\F..g@.......5Zc:%.<....o...&z}. .W..(....K..o..Y...V.q5:.3w&`!{.....sJi..&..,...V...}y.5.I...G..2.S..........|.....Mt......#..!...I2Vb...'...Ey....\.j..g..zZ{.....+S.....<...$.%..2..o.e..w.{.V.l.~kO.^.1..$..l......r.~S....:.........ak.,.M..@?a..o..Uh..b....0...{^E..V.s&...o.V....?.C.......)^.+....yR5..p...!...EW...H.!.@i*e,..9t..."g..2.u.I.........rK...,.N..X.V.$...0.g,..W&W..g.|!. .i..o...u)...g.xz. ......f..o....v:.@mn.......$..b.5..A).....@v..U..!.>...D....1.A.$]/...XGt...?..-p.`./..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6482
                        Entropy (8bit):7.967631214734816
                        Encrypted:false
                        SSDEEP:
                        MD5:F22E3AE858BD8A43C92AA81180107A6F
                        SHA1:8D2B1BE900B1E7BDBD681C134D4FE4BFF29ED8C6
                        SHA-256:8E00AB19591B0AADBCB731A652AF7F3C5AF979B118CAFA52650899FD5C12A1CA
                        SHA-512:5A720A840236F5F5E946477C2D6AA48ED1F7D4148E61401497D0848DBE7F79DA76BA934A9F8B68ABB0DAE084F0F0DD35C7F8673B8CEB6BED6CBB939140E91B42
                        Malicious:false
                        Preview:H."...*..#j,,X..._........5.....xPM...I./...m:....+......\.ff...!....3.i.X{w.z...-b.....T.......jLAP.....|....5......^.......]....G..EqA........Fe.=..3.-...0K<.<.(.qJh.bq.i;..A....c.z...;..&6..>,\.}[b..q.[m@j..rk.+..M5.( j&.W.....T.r/...M../,W.n....$.,..w...$Yk'..D.h.....3.-.~.3D..Ori.&..X.RY......Y_.a.N$....!h.K....R.....%a...Jo..k..w .."....#4%.....^....,.#.?.0.....@|......H.m"si%.y..%d9....(w%...T....A. x.S...(@...x.j5.rI"..B.x..ar.5y".O`c..v..&...b..P.[.2.........Z..........CB.1.....N@zx6p..+..6....A..a...s...D^.Z.)9.8.T.......1.....`=[/TA...h..Y.....;......f*...U.......6OOk3b!.V....|..v....].\.O....?XF#..MdK..SAU....t/.|T..... .."u.....R..r...R......D..)#~*X......{....../..h..lM..%....K.d..d..C\... ...........>7.e..@..a......tf_..."...6.<..!. h.4.&q.\i..q{h..u.m...L.KE4......[:8.....G..$.S....D..o..V.H.c..>..M..P$..3.......<.he..w........?.....=^.x......J.........../\i.T.>i._Fm.>..q....P."U..Q..4...Sh...`.z.I.........4..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1084
                        Entropy (8bit):7.828439453480589
                        Encrypted:false
                        SSDEEP:
                        MD5:39FDBBF5D540FF456EC3DF74A4167A99
                        SHA1:039F3FF0DEE0542F6B0645AB00F37FD7D30819AD
                        SHA-256:571BC71BB981FB2069BBF1615CAD8E7776AA154D92DFA59054DB11F2DAB11C1F
                        SHA-512:661E084D61943C6A5CF87C8E70A78196495958F93C600E86E796C11342A750B81EBE085034D6F892C82CFBDB2A209BFA6468961CFE9F6E659E74FA22D554FF1D
                        Malicious:false
                        Preview:o.W,..#v..i.Rj\.j...0X.L....,.B!.1._[.*N..n..-/.....c..H..>./.R.>x.J4.@(|.z|.....0..E.G9E3..w....k..L.j;...H....>....+.Z..-9.....r.n..&...).H...\.T....H..Q....0.....,m....Y3...1..i.@..3...f.[hVR0v..v.....G~.Ha....a.....?.T.L.<..m......9.@.'W_?......(.p...~f...^.w%...D...U..o@,(...c9...YH.uj.;....V....c.....!.-.&_.x..l+v..N.o$.-......z......%.!j... .v..`...w.d.......,W..R..0.[,.U.Y..V..}..:.......jf.r..)r.u+...T....y^.K..k..Bg......W..\..wam....k.2.&..11..$...uW.-.|...F.9..dl...j.*..:.JnN.`q.j..v.iWE..7.....D.P......Z...XP.3..,K:=]...w(#..{....].t.D..S.Ik.b.0...y...l.>.....+.R.({Z...u>.......P..]g.g..OB..\)r...)..b....$|.`...9.;,...l......D.F..Y.[9l..#M&-.3.../.=W3J...3...;0.d..@.D.....1...j..5..=S..e....5...xv^..u......*....6]...k.jY.2Gh..\.#..A..:.R..]A.F+C..r..AM.(..|..&...q.X.x.<$.aB.1../...2....`6.o.w%)W>...C...]A4<3...I.....VAv....b..$..A...p.XJUY....@..-..r9......8..C...uh...L9...7'..<..._.k..67..Uw].....r.6...jd.q.....MU1_
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):230436
                        Entropy (8bit):7.999113590664393
                        Encrypted:true
                        SSDEEP:
                        MD5:12185101A8FB11FDC5439A43652AB0D3
                        SHA1:88231FB44B72DA1224F42A1439E1A04E0CCC1F41
                        SHA-256:7325BE44B7587888355D1DC6C9CE34EAAB5B0A8CA15ABECEA8BCAB4A7D3C96D9
                        SHA-512:B3C943C44FD3B21299EE5CBCA2877B1C91D768CDD537B9B06FEAAC250DC7629DC4C56407520DDF9893293F4CDCDB7E2FAD9F0634FAD56B62C82493E080D77B6F
                        Malicious:true
                        Preview:...S....K.cq.n..i`P.._1K.Y.M...ZF........Y..b..:."I..1'.7.Y..K{...?...xYXPo4Z."..bb.....F.......B.....{@2...x..B..~W...9.....9.r.......G..h....6..^.9.m./..3.'q|Jz..~g..vq.:...a.Z..{..h}.~n...y.."...G....-.L.<...Y.9K.;.U.-..ziv.........W. ...$e..=3.I...A.vV.N....}9&(......:5P.^.5.._.ot...y..M,U.o5..7?f....y.....8.:F*.....MG...N..X.......3.:.....q~.....2.~...d-L:.S!w.&.....g.'...;>....9f5`..............<.#f;~..V..M...+...G)...E%.K...n..L...7I.a..wk....Va.u..g4.HqS..$..bt.(..%........x<....H..in...3..C.....$......ZY....*....6._........@....6....t0@......A...y+L}.Y.....QG....`.d..au......z)..] ..............KP`...Uln...n9.....\.R...K.".8B.y..GEy..!.6/:n..q.y..].......9P.........i._`N...I.9.....A[.2(....).p].........W.........##... R.umR.b.G(.s........d.....!..a(..8....Q..9).......l..8.z.n@...F.I.<..p.(...cP... .Z1..q.5#j.....^..Y....I9.0B.@%.U<>..w.....0.^.v.S8h...uq.....+?..l.J7........);.P..g.K./.i.~.....'......\...Y.!...I@..m.%rF....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1260
                        Entropy (8bit):7.861040190546441
                        Encrypted:false
                        SSDEEP:
                        MD5:6DD106C2F359C9AAE27A144CE3B5224A
                        SHA1:ADAB91510A5B6AF088A72EFE32372EBA13A87539
                        SHA-256:61166AE5D419EF0210ABFB3897DB271973FFF0EF5DD385F9CECA01DE3ED933F2
                        SHA-512:F461CD087226FAA64024E039E8F016E26C306F88D1234FF3140AAE0CE73C0ED2293CA23B76AEADEE94D0F070BABE1B16BAD7176CD425DD71C643FE7D1CC0A5C3
                        Malicious:false
                        Preview:7.4*....OWjZd.]iRj..^....;....5.`\E....t.8.P...l$.q.........H...^..'..{...R..*@..o..:7..>r..a..9k.N.G..s..[=G..Q.*..66.J...?*s.i)...Z^...Z...U..J._E......FM}......Q..`..}~.....{.T.R..q4...u7..JrG.p....|P.=.j*.U.8...'p..0.7.kh..<Nc..Q.k....+.!.P..........S.r.Ar8........i..kA:tU..V....f.X..{....$...W.4......[..o.Nd..s.0.[..2.....!I..u..&..a..M..6N.K....v*.7..~.....5.4.>...(..r-..>.W.....'._..M.d....vR\..h.V.J.^.e....0$..L...G..W.n...)..&%..F..j..>..g..y.k..G`L.".0O<.`......KXl.J.Q.9"@2#.....].<.RR.#..Z..v^B...WU...C......e...2.\..O(...;...0/...&...2..=.+.......62.p$...s\....oc.[(.'....l..jb...+;.I..N:....v.+j..C..3n..=.-...*..A.......x.j..pt.k....U.,...lg+*.._.."..F.h.K..O.)......Ui.k..=.$U.r|w.K:..W.U.c..9.......b_....r.....T.......N....M.p.h.....b=]...............c..."..W...(.[%x.. {^...)..G..|.H:I.."T&J....}....E..v..p...D.P....gC!...!S.{cv...j...yfUm=...3...zS.+s....8UD...h...fiu..O.... ..........sM.......x.6......Q.......
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1935
                        Entropy (8bit):7.8920271221796865
                        Encrypted:false
                        SSDEEP:
                        MD5:8F971A0D3F2D1FB828BA478FA9973D17
                        SHA1:7D4E4215FDA7C4AD2E1B85E12D55C76DBB8D074D
                        SHA-256:4E1F6CB3D8EB4925739F603C5FAD9169B8B4789F4C7E4F462BBB630B5E88E9CE
                        SHA-512:EB66D19CC85EF61DDB95752821F8F855521939A499152B18750332A8DF7F5DCB13222A94D1FC5E90FE119CA28355A4034758E7FA676750C36DDEA5AA64D252AC
                        Malicious:false
                        Preview:=fIa3>..^.B...HhA.r.{.......t(..e..^...j.......<R.g..3.v(.mV...?.).....t;`.....B..H...u..A.F&...1.V.D.....k8^..JK.....ot......&Se..-...."..l.W3..^~.........+...1.J.y>.J(vKf....'...V..=%..wgp.adFs.....s.\ef./.M...{+u3./W.h..jAF..V.?'..2..F.<..j'..tnCW..}.|.Zcf?...z.VLo......4...I!=...&....lH.}B.}...#.S.7.d..bB<.{3.....(.b....vR.9..j.N*...3.&.Eh>.z.E7^....d..l.K...o.o.[.K....@.MJkv..........8...&.$.....x.v5;`.K...n....|.|(r.......5......Tx...Z/x.+HF9.a(#...C...IH.^......X.d|._.?.w.g....q.UV.{...8..\.B(Y...@.p.?.(....:L......._/../...+...u&V.DK..s....8...1.]............y.H.lM] c46.~..yJhA;..T.BH,....(qeM..9......UE.W....3....._.....G.\..G.....TB..h.#P..&"....:Z....9sn..R.S...U..&.......>. e..e/..;.u<.&.kt.0"W.'..-...D.}....?...<....K..Pn&.p..h....w.x..E.,y....7.......z.......B.D&............!.I.YL..OJ?|...L..q9...I.A!.P.3..M..p'..jw.s..DAJ7.d.X.:..-.dx..].5.l..j........U..e.....K...}..7.B/5;...Q.j..rb....fx.........4......y........
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:DOS executable (COM)
                        Category:dropped
                        Size (bytes):263204
                        Entropy (8bit):7.999390517921562
                        Encrypted:true
                        SSDEEP:
                        MD5:6E2B233CE29325D49639B71C1315D3C6
                        SHA1:351B762A2E5CE458EB996BBB76053ECC6A6F3571
                        SHA-256:E62D1BA828A860DAC2152A45213279EA17F5EEC8AABAEC84022FD68CB2FC7330
                        SHA-512:F91B237ED08C11564D6D3D602AA160DAD81E5EDF73A67E06E98FBC3E9B52DB90D11FD3C85E7C8F7E4CFC7AB703104AA01F342CEEAD4D8F7D3EBB76451AD70D6F
                        Malicious:true
                        Preview:.M..r..ln.NV.........rU.J...o.E...%....N.Q..G...y.F...k......!...TF..h.mb.[..+[|k3}......j.5...K=.i.['...v/^...`...|Qq.S..-..]..{S..A......4..#....3..TSE.2XA[...=.O..w..otE.o....w...l.....+sN......t1....fp...IcN...Z..8J.WF(/..+H..g...oXYW.JT.....k!.E..4..t;_.bJ..$...[.2...$..2|{.m.....F}..'.@U1e....5..{`.|....k"<..P...)X......m)Q.....)..d.+e..i.O.b. .(.S..G.C.x..!.L..M........./&9...+.M.YKK......`...awR...QA..v..w...t..hi....W.'.s.*..y...+....<m.j.gcm..`.s..^....L/..<.,..1.29..|.........&...T~..........zL....Oj....j`P.w......S..y.:=.\m....@.1.Yw.. ".Uz..b./?{F3.....F..Kr8&C..}VP[... .a..n......J.[.R....f.a?.4)o..N.O,....lk...."."...f,_...vd.b.*.".zb..Z...5.o..o;..&.K"..[m.G......K"..S?..95..q.3H5..U.&..O.J:.T.a2..q.w........7.J.......T.1.......N...A....B...;.X....{',...e...h.fOQB....!....5`>].R...........g..Tg..j..h('.A1/..A....bc...}...}.h......1.Cy..Os........s.X1.Ep..vK.eNq.f\...:.......q...*...F<..2V....i.....\..n.."....@
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33828
                        Entropy (8bit):7.994388128184701
                        Encrypted:true
                        SSDEEP:
                        MD5:BC95152FCACC179A854634321EA00439
                        SHA1:EB8DEB800A8D6D1D94F4D82CF557A36F10374015
                        SHA-256:8A58B77F91F0ECE46C927CFD98BE718E0D86312437566B30A6613CB5BEAFBD44
                        SHA-512:5C2642917CA7C6FCD02BE419054F00F082CFDD97A075C14DD8ED2294A93FDAD4759A5D54BD50BEA80CE7478580AE8C18ECC7879A0DDE72BC0F2E0EF80A6F0C8B
                        Malicious:true
                        Preview:.N.#.f...eU.J.].w..#..)......w........H..6....NE..p...A ...Y..u.w[.?....@T..?..X....>6..%..J.X....#..^=lEG.4..)VW.q.]>..IiO.y....`.......U.[4?.#.Jp..X....j{.Zz..+..?...{......(.%.{.....s_...................x..@k.y........."#!...W...z7.}....+O...*4..X`..-.,.`...........}.:.j..j.>.k...{D...".E.....#c.w.^...&.{B$D.R..4.Kd...;.....AHs...q......s..r..Y...Q..QN.....\A..=...}7..w..~;z.&.......6>.P.&../l...P.q.7.`.....].M>`$..>|...M..?k...w....P*`X....%o.fY...v...Gj2......r.i6.......J..q.w.<FE..d@.@..f.;C.N..A.u.2.l.'..F..b...5.c..l...Q...E...KO.....$MZ...#...B.!.Kk.....=x`.+...?..IO#].Y...a."'.....xkE...%....5-....O0F..;..4d/p..C.f.a*.rM.M....%4b'../..I.k<..I....Mq..`...0%..:~........x..o.)XH~K.N\..g....(YVh"...j.m......T.z...|^_Y..:]........j...S......y.t...$f.....,..Li.....i....r.M...p:[..)n......J..J...........4.....1+C.Z..E...O.s0.....b..%.+(....WxR`Z+../z.X........=...,)j..<Pk..;.P?..Q..&...\..M..v..R.{..F..b._g..->&......".C ...>I
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1060
                        Entropy (8bit):7.830576357087013
                        Encrypted:false
                        SSDEEP:
                        MD5:1626D0041F870181B8C7AD60E8A78A9D
                        SHA1:FC0FD5C28CD1026C043D430C1EC176E3EE954085
                        SHA-256:931F79631313347391FC9ED7760F416C2BBD312CABF271DB0DFA75BA1BCE197E
                        SHA-512:D8A4CC593CB189B1DE8D69B50A21ACDD1A205E529D83E4018E2FF548903F103A9A7F898A02821ADC85CDF2793A69A07C78211B8BC263CCED4DF05A19FA5D4861
                        Malicious:false
                        Preview:.....ap.$...........g.h?..6...#.N.^....E~p......j;.....CG../Y.....{...,..pQ.X.{W.`...3@Z$Z..^.q....v9&.]..r.......@d.`%.h.W..wV.........Y....oHF.e5..K..G.A.....ao/.....p..r.P..........o7.Y..._..^..l..nm.T"..x...m..]19..X.fjia.P.w....^.c........3.E5T.M.Q.?..T...JV.z..q....D.....v>....b. .E.f...<.....c...j......+H.\...t..7....Y$E_. .n.a..iv..j.mc9.U.P...?{./.v.k..(-y.UL..k...Ea..F.,.54.1.../..b..TKXZv._.gZ..+iM...'E...)..,.....}$.I.h...)....z ......v..9.Z.....v..}|...qW....s.....V.....X...t....W..mv;..a...g`.?..<....K:..IBH.k.vN.O.$..J.....G.5.y.{LNR\...[.......6:.x..Uvh<.....:.w...x.g~..48.=.....q.DQ q.2...M..!..I..C..O.q...\I.r03c.eb..W3.t...B..[.4;{.P(.........}.dm.G..kPC8j.h.^`.'........c...`L..7P.{......x..}.g..b.+9Ze%@..V[4.a.D..{..;.3. ..C?Y......7..y..B..M....|oI.C.gRe.u.jT-..n...`zb..3.~....H.............._......+#9>C.!...b..U..,\3....X@..s.>...;.v7..P....[Z...K.2.-QR..8.0.&..&u...j.6IO.O.|...........'.) .+Ed......%.-fs.l"[.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):99364
                        Entropy (8bit):7.998161232440782
                        Encrypted:true
                        SSDEEP:
                        MD5:76DADC38C500C7D5FDDC8A9396F497D7
                        SHA1:B4BC3D8A5033C40BD3E326DAA3502EC775CB8A84
                        SHA-256:00D1FB7812BF81B53587BD756694AA7ED6FC7199CF65D63FFCA458ED15CBC08E
                        SHA-512:6618A4F110832B4DCE9CE69CE57B347BDD07F615731A43EE2B06B276B0A52B3F44689AC05AC52D4A79E6E832E6E66A2AA6A9AD1F83BD2B73444365AD6E8B66BD
                        Malicious:true
                        Preview: ..g.~.. ...Q....}.G.*.~.....q^.$.`....G@v.,w._W..".X.v....r..QL..Tg.....u9......yS.....z....\.....z...|2CN..%E.=.U.....]...S.6}...D./.u..&?/4.}...Sg..T.a......O.~....26.y9.]]..QMO.y....i.W....zy|.H.........(t.[.%.E8..zt..Xi.C3k.....3?..b..:r..........;^.Hs..4..... ...gX. J...g+.c!...C......TD...${`........`J......O..^S......3.G.r.R!f..P.5....I.*.u.#.>....\BL..C.$.o..}...P......h8&...D...'.3.Zj7.cd...L....G..l.<c..F..1.7[..j..njx......D..v....E1....N.b..I.m)9.. .(....k.?.&r...@.....m....S,....jdD.......A,.W.UQ{...U.1.E....s~iuV/.q...C<.\..LB|.4.......U..OU'.D".\.[.1...(*.S.".t@.V..n1....[d...<...@C..*.S..P....T.Z....l...*.._....U...C4..;..,s..$K....?q*....p.|..&.m....|..`..!....e...G....L.Z.......?y....RC.v...3..k.p*F.J.f-.o..Y......>>.....E..7.Y....F...S.6u.T.X.O.U.'.u.k.....d...jn}............\N........ft..y..V...3.U...o..Ls.......l......U....T...m...{O..].fK@$.....x4E<......~.....}.;...hg1r.,.....J...q.x..#j$.I[hKzu..1o..Zg~...?i.(.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4040
                        Entropy (8bit):7.95049182948274
                        Encrypted:false
                        SSDEEP:
                        MD5:94AB95E4677AD0148ECA439791379852
                        SHA1:DDAAA6EB8D839F455D6AD9F895CDED0AB8A85AED
                        SHA-256:BDF05C3301C02E491040A96EAEE86C1840BD58C95F984349CFAFE6027918B686
                        SHA-512:B7F34D6C2B862E5B6847C742705C0E67FF3FE23800E12EE8297EBE304B1D73F7D490CFE8877A11238F9FF8FAF19558C95F410FEAC9C62DDC6DEE14BCA62CC087
                        Malicious:false
                        Preview:...d..'o.b........(.52(>...&B..;ts@3...sJ.):.f...d.E.l.W.....A..p.PS......a].W.....1..F.]....l..Gs..sf.E...AA...uzd.|>5.W.TZw...?._.F[S.4..."b.9.s.......,....i.j.jQ..Z....C.?...;....U....I.0..M...2.\.23.2\.YT.bt......6...,lZO....(..:..X...z]...Y.c.sO.....[<+-...B.el|....i....]{.^.Yv...%..2..U!..5...@.."..@.!.Zgn2(:...7.!.F.U...*........%5.p.4HRp.E,....i....OQ...=Lj.V.".1.F.Tn.......?..^D..ccH......[.K.(G.U..m\...yz740)..X...x.....:B.e.gJ..n..Y.&...n.......`D$J.j2.....zu.ZP..www......6F.'L..%).h....kl..&J[j5x.'...A.2....,jX...T.n.9..i....I.:-.....'LR.[.ub58./W..3o..'.o.Af.G.3Q!.G.....d.........{a.lO.Db/@....n..*.L..}f..:M.,..Y..hH<..?.8Dv)l....9.R..~gN.=g..1..7.....R....u......(q.6..'.k.K..J..D..<..X.~.........{...]~.g....}7(.=h... ...L..~..Q....N....FP....(.(.Z..n.a..../..K.....y.N.)....".&..<.r.L_...L.....9k[aI...B.}..}...6.jj.....n.r.j+^0Y..>.........[M.....+u.z....4Y7E........K0.?...d.e.;^..Fd0..R.Z...j.v....c...Bv..{..=.g .".....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4117
                        Entropy (8bit):7.9516074482704555
                        Encrypted:false
                        SSDEEP:
                        MD5:8B7AC91D648923A2D628C04391068693
                        SHA1:27F2BEDAB5B1C0F011F77E53CB892D895951D9A4
                        SHA-256:62C2A0CCFDEB239237092D443875763DF8D5C68FEDD46B5C7CBC605BD89AA535
                        SHA-512:0A9D1AF95C93B5E05170287764A2B1B2DB3605E7E609DB2BCFDE23D50A3E84E2068654C0E9D932B6920602B6BFADA11EE31D6904F29E6FA51A977A88E1176051
                        Malicious:false
                        Preview:..^0..X.].e....w.....".".......^.....+.o......e.6D.ZJ.8X..(.....'k.AJ......P.hy....]..6......f0.'.Q:....R..hV9A...r.R.....E..}..<..6...N2>.n.>.<3.......F!.{......2.m..D.z.9.VT..o....rg.B..MN{#.t.......G...#..#F5X=b.....~...K~G.@t.0..9..=.T.:..;..]{./m.._{..OZ.(.....x?...LT..bZ.U...'..a...^o=\..[aN%b...q....+...U_...J...:3.s...r...q..p..k._.....#.......F}..Z.1..}bO..j..B...#.bvf.88.dQ...\.d...\.$)+0...!..5.M..U&._m.n....X.*...vR4......&.0A...qB.....[1.:..W......1......D<(1.@.).....Pi._....K.V.8Q.. ]..{3.m...'0.d-cC5Um"..w....8ng..&.@M...f|....".Fy.&..F....j..i..f....f.`."..x.../h.F...0(=...Jx...H...M?{.....{..A..1..... .?B.@^.%A-....C.-.....Kx.....%.....@.....m.:U..4}.O..".(..../....>....nbbX}..eX....+...R......b...%..R.....u...&...Mb...x.\....=...=s6....#K.9...I..^....R..#...OJ......^..Kb.......g...)...0d=.^#.lZ..G.`...KWs.r.3.?.r.x.^^.../..k.W...#l.....}'b."...J.!.^...aj.3....y]..T+.&..]..H.lC..S\HYV./.1..f!.....N.co.,Hx...:XI...XOY.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):18155
                        Entropy (8bit):7.989800938149748
                        Encrypted:false
                        SSDEEP:
                        MD5:F99A68F170E013C7B43F7074D83FA595
                        SHA1:4558799225D301FE555E7248EEFA0B9D4A01A6D8
                        SHA-256:059E5CF21F48835ED1DEE800C5EFE3A781B83A14B5F8110E41DC66F3FF3F31F2
                        SHA-512:4D840CBF6459EAFDD0512F07FB2DB7DE66E3116FD5FD553B6395137A2DFBF23C535CD946C4CB86ED712BE0A255EC7E33FDCD9AB5594E081C53F0063ED859F7C3
                        Malicious:false
                        Preview:......:..._vxDY.9o.'b.~...?.....&....$.j'J3..h.~]5..P?..`......~..J.O.M..EH.......=.:23b..2.U..?.Ab>.7...q..4<..<...l.1..|.......1..\0..;.4.=.D....i?..l.H*.].t..../m..>&.......N..[...3+k.R.p....5w.....HM$.WY.+.T.....=.!.".....w_..+.J:go...@.>:y..Z..sU.p......../.ME.....M..{.*.{l..omu...m.N..{..@.'.o....pl..L.....[w..\.K.............Ez.b..H..W..#.5...QJ....~`.$...P....;.a.[.....q...,.^.ZF.;...e`.%...8..........^.....q.d..N.t.\.....3..]&vc*^.;o...F....[J.@....Z.b..+@.1'.d.....1.G....+d!.1.-W.....}8,.]C3..@..s.3N..r.fR...`.....P.D.P.)..qB...._........m.=oX....3....C.yA...H.W.he]....B...K....,...cpW$.I.H..=DiP8$....u..Bh.2.......d.R..r.o..%!r..#u.....4........h.....U/wx.4.Z4....9...m.9..u.1u....6S$..4......w...`'..A.q.p8uL......z6*n....Cr....._.8..m..,[ .'a.xCn.R.e......6.;.7.../.(W^.&..V..J.eEPN..MV.M..;5..m..wO??.`...j.(..mj....T}.c..@./P.%.n8.>U.n..1....5{.%K(..y@...........T_..P.86+.H%.9..fr...*.b..i.:.o{k..R^|..%.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):18154
                        Entropy (8bit):7.989059608127687
                        Encrypted:false
                        SSDEEP:
                        MD5:B28B6318E1C94E75FCD6856A7C53EA4E
                        SHA1:0E9427CB4E59BFDD7EB485CAE8CBE7768EBA66D8
                        SHA-256:25BD3AFDBAE75C92B9350F1111A59CE8DC14B540C8CBF3344DF87B9F5074C6AD
                        SHA-512:F19B6278732665680B408B626A8300535E0D4B4825BAF15C2490CA8E14B7D2E828D7E10BAC817AB675361499DAB9C777425B5A2804E7A049496143EEBCD858CD
                        Malicious:false
                        Preview:..K+.T.....F....$@v..~A.C..h;..y..D.s...x....te.c%.....`...*;ZQ...<.G.L.s..`.-...C._.f.._.mV..*"Ka,..cZe.........*...+0s.Hug.....;.zt..s.j.....k..~Er...................X....%h.^........'..z......]....H./...$n....2.FG..=).Tb.....h.S....C.....;.F..A10........n..-xQ..S...v.yy"H.....a..f?......... 9.X...S2....>. ......-...m..1B>.>.^...M.F.|.a..+%..i.|..[....u...2.?..E..W..b......4*2.n%...S/.`..|...%.XC..r., ....z...k/:... .f..P@.T7[o.4...\.X...7g.=..#C..:D.....-...B6^.0+. ..;.......:V{.,p.G.....sz..}J.z...?q(@.....*.../Y&tm.O.....r>..m.1.H`...l.&rn.sm$..N.L..,.t.$..!{.y.r2vM!..=.6ZE..iI.J....a+......Q..;...........{7.).....b..p.&:..\.U]..Us...:....@....3$B....uE..Z<..6.\..A:.A...LS.K8...FI_?.........k.N.q....%...HE.....^......wW....1...*.=.U.yF../,,..?...R?.nD..4.6....*FGP. 1D.<...W...D..$..].........g...$...[k.B..x.5.:..KBv...aX.`y.."..;..rh.QOpB0.=Urh.uwO:......Tq..6g..P0...K....;6..f&.:.Q3+f.@I.)m.B?..y.....5*ix.E..Nt...*..31..ok
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):972
                        Entropy (8bit):7.815113038980049
                        Encrypted:false
                        SSDEEP:
                        MD5:7446B87B0A2531887A011BD75A52D13F
                        SHA1:A8AD3A3A9DAB071BB6C1CC1130C6304AE1524FE1
                        SHA-256:34D9842081CD09BE2B42FEFD0BA99A1F7E8C38A48B3750B58DFC88B42556A1C9
                        SHA-512:F2254CCCA74627CD92E026A4A7133F0AFCAE875252DDC7E70B47B3854E330055E471B3EB884B42ACEA9FEF47D7E853D0D708E5BD16B3F051B6A7C03A91F5AED5
                        Malicious:false
                        Preview:.^].W..^.9...p...H...xe\L....s .A.l.#.a....c&GDY(xM.9..w..-.....j,.5..jm...P.z.(..F1.>.m....*.....W...FR4..T..}.....`..O..D..8....`...Y~...h>.C4..Z.)3JD....Q.V,.....{.%W'p.CN....8..?.......c...B.ZC..&B.+..D.D......SI...na..k.]........Z.......E..%.-..Vu..H.k*N........~...X...e.6|L....u..9T/......{.Z6.u.S. .....N&......c...I.$.....j...*T..y0.j..Z..z.L.....Yo.......U.i...F.hg_...0v.t..jM.F.5..@..'.}`.Cz ...$...S,..h.".B.........Y..n.N.K:....L1..m.A...VL...].%*.d.1*.D.}0....]..9A|..t...]....7.^m....dr]......GcR.#N...y....GK.....Y......09...&$$.gk .).'m<..1k..<\.I.I..p.....`.(.F.i.F`.Z.D.s.y.:.X*"V.\.Z|.h.+x.h.....b..X.>..[......i.Sv3...<{$E...U..].NA.f..g..zik.`.:El..`MB..U....|q.KX.,.....G....V..u.A...m.O$.;...*....O...-.$_..tg....8..L....|.4K.7p,.....l.M.J.2.3.D[.....+...5.#q=4`.T....xC..i7.._A.(........iv...@\_...h..(..x%....b=..iIw...C.-.T..<Z.u.....SKK...Bl....B...~...)P.O....n......c....PK....-.Egm..V.?.M....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4862
                        Entropy (8bit):7.962503428713925
                        Encrypted:false
                        SSDEEP:
                        MD5:D334A8D941D7E2898C934196FE25E8E7
                        SHA1:1F34CA33BD10C050CE3E4A436FC20E9640DD74D4
                        SHA-256:1407EA4AAF1AF031305B5CAF8936579D4C05BDDCDADEF6E0405FC7FDEC13BEFC
                        SHA-512:3AF010D1D81760354525B05A2941400A44FAF7819C93E1BEA96DB347770E7595FF85E19075FA4CAB1938C1E14305771D5116A9898EB13DE099F747A411D49413
                        Malicious:false
                        Preview:....Z...Fi}8..3...c(..].g.d16............R.9....7.....RF.@..E_.........^.l#n|.&.e.....x\Y....u.....w..m..Y.e..X..dS..L...Z.)...Wl.pe|.n.P..?.......&...n..w.'....|.K,.Q....L=.!.h..7.vY..B.j|./f...jI.1.7.-.qk..#.(.\..{..}.D+,.....c..&*$..9.i.)<..w.fF...,...k.d..&Bhne...^.(.S..;.(.....u.<...)U..*6.d.K...B/.Y..0. q...t..)...~W):.......d.8.@...^..........U..}.S..^...A..v.k.~k.{N.7..S.gKA.^V9I.:#...p->.!<...{..9...Wa.....s...t;..^...eb.9..."....Z..W.U...T.K....x..X..0..O..q.2.a.g...`1.....v...../.4.h.P..*w.O.9.p.....v>.....-.;B|K9.p-+....1..^.P.......S..........z`...d.|..J..#8...1.s...9/4............HP)+.a...)1.....D.4..m.D-O....=....._IJ.W......."....f.WK....w^......L.}'...o...J.....Q_......L...F.4.o.P<\+>...K.......Tj@z/....d..._@...d..M.Nl.8...2K.....1.$.p....-.L.....bO....u%>...Z!;....Dh.C..7:?.3....s.0K....e..:0.i.'v....UbW.q.@{..w.t....(...Bj....1P=S?H).0.y.-.1[.U.'.T.G...L&,..=_........8@..T~[..z3..pZ..q.s..=...NF.9...1c,.]f.,..,
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):971
                        Entropy (8bit):7.789479900439242
                        Encrypted:false
                        SSDEEP:
                        MD5:5473E8BCE3F20539ED7EEB7C3A040EA0
                        SHA1:054EFE8AD91A35434418798CF54296BC0C487EB0
                        SHA-256:57514EEC0EE605D543B82BE9E1A2039BA46B00E86CC816FC28321F7B5ADF9F3D
                        SHA-512:D5085E6E8E24B29260FEC90EBC92052AF89A87899594E078A8FC49151575618230872DD037BFEA04617D7B36B28EF199E12D6B5FDB4204CD8ADAE1481F6D1FCA
                        Malicious:false
                        Preview:.:.2S....?9....(qu..3.A...ti.P\.g.K,....%..t..K1..1...sNF.[.....Z.S%.6.?...o.!...m.$]..@P..X@j.9t....@..*4..r...-p...#A........g..JK......#.J.x.ZKO...^.?*...[.%...d...Q...l....v.h...->..z.x.9.sB.G5$.%1.I...u........-(av.e..lb.C....Q}..!.8........4.n.{..............+..*..:t=..a.BK...f_.-T./#T.....@.....s..............a..rQ..v...T...E..i.E...D.c...._J.f&....<..S...?.....E?..C..O$.W..!..;g....U......dy`.N.M.M@D/%X.......W...'...<.A...K:.nI.;....BM.(..6.T.Lt....x.T./+@..z.r..m..w.....J..5N..E..JZ.E...er3..^j.....Rz......... ..c.M.M.M.2.B.~DK...z...ax.[1..`.Wx...l$.?....R..u.E.H?.y. ....A...L~.N\.p.W.=..q[........so.d.g...w.M.......P.!.....8,..T#..-.toS.KD......y.V..Q.I!.H...m.=....a{YM..V.\.......OU2.|...d...............Gj.S....*..."...Na~..NU...k,f.G.M.a.N`.y..C....m.J.I.....PK...U.....'.=..!..~R!. uJ....?.J2.K..ir.D...9x..G.h .&q.a......h..j..E.....*l..V..M..............MwR0+_.g$.8.9....8...D......8....V}.H.....s_
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):15811
                        Entropy (8bit):7.987291927126773
                        Encrypted:false
                        SSDEEP:
                        MD5:AA81BAB8C865097812FDE05EFA6CC831
                        SHA1:913BBFCEE8C09595A42E07AF12AAECEB42D64A4F
                        SHA-256:97D45AA18E029981D0A80EAE4C38FA961E8D024C7928832183E88D3951A5D042
                        SHA-512:B8AE92D1DB505720DA40A9590DD7A2488E7BB2F1A88EABC8EA9C9A70336924783AA724F7683AFE92BBD9E86757DA7D595C7C7962602997C727AE17B5A7508891
                        Malicious:false
                        Preview:N@Br|.#l.7.:.......tV.....M|.....A8.N...B.!.1n]....|.d..P...s.S.=...D&`..J?.2..v.\..l..}..#..h.DZx.w.:....4.#H.@.O.>dD'KT:.>..k._.....ec?Z..ZB2..~..@p...l.......h....a.........s(..(...t.~..eh..u.Y...I1.9.]N,.!M,.P(... ..&Z(..v.n....?...P..Z..{~.}6..=..1=.A.8|.>.A=.w.d.n.....*m.d.3X....L.&.37..d.a....'..(..G}.V.Wb.Mx.....&w.z0.........u..2.2r.......0.l.t..E.......L.L.7r7...+O..9...E...`.v...XJ9.F.$...8A......y?4.(..G.u..U.J..........^.r.....h....h....`.dR>*_!l......Jd.?..?...Q..z.HI....e.`P.c.....pA..(.v..K(6C..W..j.& *.v:.).d.&..#yJA8....a.X.i....W...f...J....~.N...*x;=.v.X.2.. .>/0.L+%.y..Z.|.O...&..h........\..J_.....e...b?....C..KY.E..............dF...p...o..!./.c..u.|n........ku.a@...6E..E.].#...]...H{.D..Jb1.|%s;...Gi......E.'O8\.H#....ZOd........W.'x.....FYL#.....K.....c....s!1I.;......G.@A.....!J.<{..Zl.}c......,.W.&...Y.'0.:.k.8-.........}E.a..I..m.=.5+....[.Gq.bN...;<....3.Cxi..>...E..p..qQ.+1..'o.(Ng.:1....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):13836
                        Entropy (8bit):7.984725768584388
                        Encrypted:false
                        SSDEEP:
                        MD5:397C29F00EC88D636CAF930E9980E8B1
                        SHA1:A0B00E7CC799C6EE0D218896FBE2F90442F0B13A
                        SHA-256:D1AF1E3BDB9D3BD3E34D5B1905E6718B796D5231CF0C2FB004A81FF97655BD8F
                        SHA-512:86ACE8E15A2E95B997B5E39A61D5411AE5BDE04D854A93A11C88892881F95B32F2DCAD9B39E506F264E7D922592F652EB95F7AE0BC329BA088A8D01DBEA803A4
                        Malicious:false
                        Preview:E.....h.IJ.....,.@../.!:..'-"._....b.......F.O.a.dc..';^...#3D.......Y. {.B!.......\H6.5.......TU...@....|..a$....-X.*.....K\...\...~....;....]v..{..F.P.| .._..[.MT..B....n.....M(?.@.....].S...C.W....=4..#..>.. $.*.%-....Q.G..&*...R.n`.........[mZ).P.......})\.s.Nr3l......ds.iF..`....Y1...l(...s?..<..S'v.?...I.3...X.NT.....f.\..1.Wn....=W....6.$Pk......O...G.........s.....yR.R.].[n....?.]....Y....J....\`S.`...Jt.............T.9.I8........;{.6....w..Y&.w./:[.Z.P.T.....R.....M.6.....C.6.q.lfe&......3.......!...f..2..C. ..t..=..xf.\.)@.N...e..i."...-.I......_.oqe_.W...`.IZsz.`....v.-.....P.Z.e.Obp..T..._..Y!...T[4..O.F...F..........b...RB.I.%E'D~...u..{.u.v..o.#o....)....)..#*A....a.f..c4.M...|....Q. ..Q.G%.[}d....*.6...AZ..aC.Jl..r'..n....o...|....U#..g.Sy..sU...U.R.D.....c.........u..q....W1.f\..I}.ev4..PU..P./...<..j...%v.. .C}.../7f4..|u......h..c.4...v..a.P.N.....<..n.m...V.(;E]S.f ..0..k>a...i.d.N...R4F=..6...N....pI6Kk...`...x#.>..No.Sw..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2383
                        Entropy (8bit):7.928410485482645
                        Encrypted:false
                        SSDEEP:
                        MD5:5363210361AE1429EDA82D041A093E9E
                        SHA1:E07D55EE301E79B34BE1104CE75B90D7A27A1F67
                        SHA-256:B9795B4612BFF2C84E47F0507E6141267A53504D2CEB336398A66B2E408FDC2B
                        SHA-512:59F10E0054114E80695C02511DC7812FC0E264545CD9E85280325C0D2E1BA4402BC900F1A02B75C7CB9638AC98069E51934ED1FD8C6A89C22FAB7B2A51D768C2
                        Malicious:false
                        Preview:...,K.Q..._...A...c!Q3+*..:^.yc<.{...dU.1!........$.PTS.C.iM.@q.F.=..Z?{.N.sR....M.^.@-..GBJ@.]k-....?8.(.-.+y..._.m..$7...R...8....c.^.j...8...y%.+.@@G1.(.u.........]#...%.a......\......Y...T.5.N|.t..9....=z.4..*|.u.,#L...;.H..9{..^....f...n.,...b~).....U........Q.ec?...w.../.`qJ............*U.O0.@Rj.........al.v.....N'|...........%.X.F...&..Nrw^}....0"...3...^2.LM..._.W..K...4p..w.u1>jC,....8..fs.5...8..m......s..w..3...G.h.7....?o.....a....Y....?.8_..#.._...k....:....e...#+..=.t.WS_..z.....6.0.KF.W4?A.jny....5..vg,.......)H.7z.PN.}.O.tW...f..,I.ZK..i...........<.W.R......k.4m0...,K7.0...@..X...h/...E....<..e.Q..$.cC...;..y. ./pK.m..Qhe.8.....A..=Q.l.]v...l....9....s...e/b...`\9.......Z..j.F..r.$w.K]...?).I.V.....*..;......G.hu.~4._k$m%4cT.#.mHxx..Sj..6.e.bK.g...]..........$.M..>0+..0....M.....?.F..........Og...<.....".....h.~7"l..T'._y..........o.#..J.d..-.Q...@&...(..Z..).l..0u.jF....,.....p..Ai[..7.H]1k....r6.kd..8.>.F.Z!..`D.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2457
                        Entropy (8bit):7.919345104889149
                        Encrypted:false
                        SSDEEP:
                        MD5:F83A16C5A7B896143C84EB6BBF693DA3
                        SHA1:41E2A92FDCF289B0095A7E4A00DE06FBFA07763F
                        SHA-256:E62D3C0A3760786B8D62EA8C8751FD8B96186620B8A8338E837CF59DF8E6E007
                        SHA-512:5EE5593C558C6620406B559400F86CB1FA0D172600E338C379B57F4A3D13F0F590B6E9310EA6865FB45160A2C71B1FE27461595E399B1162AB081CF34049F179
                        Malicious:false
                        Preview:..i...[.4.e.O\b.Z..?..........%.a.0..Y]M.`>?.....m..I..:U.1..>.hv.p6.~..j.......t.*..-..E...k..e..0......A~.&.5..oC.O.6!...KT1..........$'O-9..w...p...w.v.]..v~.f..)......2.9.2jA ...d.v..:...-.E.O.....>...~..^../......w....!.^...@5K0Id6....>...B.5Pp....@..>..P.......#.....}..._.vR..........._.[4..~....X..S.\E.9u?...0UD..=.:..HI..x....l.(..f..O...E3x.w..Z...|.Y/...~..:....1............\..d....?.`3?d.v0v.V.}.2/.c...i.Ct...%.}i..`L.Iv......&....VJ.f...`J.I.....!.......t....x.2..U.L!...A..D....%@#.......!C.........G.....%.....k_.Q.L.tI..x..(=#..-^O.Y..B.1.W..w_.)...JUr9...cH.O...._.0..:8..">..knn.{g...i..Nb..8...b.c.H...2.}f.[...1.....'....f..7k!s..P?BE.=..*..L.+.^x1K~O.6.sgB.pD.|.u.H..L..,..?....)...O2...P*d.@F......$...7m...HUC..+E_..{.#.n..M;.j...Z%...r....0.`S....]E.8...'.V.Q%.......B......sCfUW6Y..V....>0..C....]..u....u?..*..EmF8..A.q1.......|..|..;. ..r...vs.q`..(.3... ...O......@7UV(.y...{4.g.;./.M........vj'..k..P.D..d)Lb....k
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4223
                        Entropy (8bit):7.957998652406373
                        Encrypted:false
                        SSDEEP:
                        MD5:64B46EBF145870CC02B1C0FED62CB76C
                        SHA1:2A5934E2B3F224ADD265D881023A52B8E9907CEC
                        SHA-256:DF829057A0A6EFC4417EA80D1E63837794B4296628662D2BB687A19792958D05
                        SHA-512:050B2585D55BEA4029FC90D4E02D5F953BC8D8BD1D9E62D0456AEDCCD8228A9FD0899199EEEF15A6CB1CE08EDE04C4A62E7E7F919EDC7979D0B75E1CBA66755C
                        Malicious:false
                        Preview:;[...(\..v.v\#...V.K.._>..@..$......`{.r.4.....y...-/.;..tl..&E91.$....g.8;.J.1;7....&.M.Z.....~...U'.=..:.jL[7.CO.1.X-X.3........o......_.J....Xc_..]....jPCi..+...O./`..=....$'G5.]...o...<.\.m..........3V..w......VI,..1.iU....p.....{..b.>.?..|......D..+..'.e....<.A#m.......Vm.w..{.X..G..M...j.....*^/O...~$.I?...o.!.7..cB.O.-..$_h././w.5u.Jt.v.*..V.(....v....#.=.....C.=....`.!.. *.3.. ...i.}wg+...R...9..T.......k.mU>..../.v..o....0...m..5=[}...^$...NB,..I.X.q..?...SV.{97Nv.].(..P.....fEPg.Rt..Ae{Vk..^.*..^.,.]...[.SJ...l{..Z.....@7..d...)..S..V.fu..|...V..Ls...O....+.........2...V..r<..y0e/4.....'g..e.....*.5Y.e.c.j..@s........./2.(..7/o..}.a.:.......br.....f..L........Q...2....^..!...|J. ...W.8.dX...-+..\v\. .f.....P.....G.~.].|...%.....o..-.g.=@......Y......m.!..;..$..{...U....m.s$/.......&...q...*..o.|..G,.`..O...n..m..;.W.2.0.A;...u...jR..4..H}.I.y....~F.7.....|...+.*(3./Qz...O24...h...*.K..,]..f..J@.5...D}.r.&Ui..P..'..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1967
                        Entropy (8bit):7.905419449531446
                        Encrypted:false
                        SSDEEP:
                        MD5:04F2D133C4559F5379A21A14262D4722
                        SHA1:5B7FC83991D9D4C1446FA1B938F05E3AAB835D07
                        SHA-256:33517D84CA19CB248AF312E588E5C0C87BBBC526FE081380DE082AD18779002E
                        SHA-512:E2624058302253EC89E93C82EDAA080FF4D90346BC931EFE26B2439A9BE56599AAB8FBF0A1069A5833EEFFC23DDFE70065DE24F44B566D859142FDBD4840A010
                        Malicious:false
                        Preview:...r.Utm..!p.B...U.{..f.%".g....e...|L.V........KA...Lv..F...;.f....>.}#k.?.]K....N...>.JZ.t.F.t"m..o....;1.MqJ.....Y.a...L.......v .|.*....Ui$.4F....472..K,.`..P..tO.Q..9.mn(.....}..Z..N.sO..y.K<.kY^.n.5.P....f..._....3..1.8U...^_.......?q#mo..(....p..)P..}.\3..x...};..^.........X<`.'..HG..LE.D.(.I........e#8."'e..\$..8W...o}.....y..Q:/."....B6f..>...|=.."..}...X1....4T.....W.Ze.4..~.L..<.."3,.;0.......U....O......I-...].. I$.Y..M.-/..s.)..B........Y........v....A.u...t.J...8....?.G........\.t.....@...\....v;L.=.\X.B..*.P..........X3QQ.hk.*1...x..j...{.T.1*\v.Z.....|..9.;.....O...j.z..3....lD. .....r..r.ZC..qs.qYA.6kZ<....-....J..z%..V.....o...q6pS......4.}W@........KTl"...&..(l. ......yW..v.w...u.."...'.....B.....$.......W..a..{..k.y..........T,~...,..W..........%..c.+.n....{.*..p..V.]T...7....]f'.......]#...9...tq..<Jy.....h..5Z}..P...G..a."y..m.....K.......#E"eqn>RU.H..?(..n..8.......U...kxP......E.#4..&....6..:
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1968
                        Entropy (8bit):7.92254380030836
                        Encrypted:false
                        SSDEEP:
                        MD5:7CE20C130E3A4B86FD78A3607FB4C191
                        SHA1:7A17FB363EBF3A41E32F5C6AD36DB50360209D2D
                        SHA-256:E026C83B6FA1CF1181E5A7A40EC6D6C20963DE50EC7726ABD32AD947AF47E1FE
                        SHA-512:C7A62ED2B23F927CE171BE66EEEADF19CBC6C8C656E8CC39FE1BB5CF224F0C5033866EC566A924A07DE0A5A7EAFA346EA854739862BB56A56F03ECE27D6142EF
                        Malicious:false
                        Preview:...d.\.:.%...X.)R..(.]F./..$.lo....T...c.2f"!.........L.&.p..<2.:diH.N5....:..<.....g....m.1.d....m(..:8...s..Y-.h..g..uM..{D..}...Rm........rL...@..vd.^.!4..t.C.W...y.TY.C......S..a3.....K.R.Jr..........3i..W.:L........:X..Td!)..+.N.]..(....;...6......m-..B.-.....,Z>.]M...W5\|.g...].....8(.S.o.5,......C}.....[..r..V......&..M_..B(.<.3..B....Sg...&*.dy..X..,y..0....t...F..-.>`..S..h..E..}.ec..7..5.0.........E.hT.^.\a....^...s|.2-X...dj1X...x.Eb...@g..!...U.....7...(.7.$..$h.......'...p.q.a.[.n.`.#J\x.R.G.JS.Q.N.....0......r......2@mv._.T..%.M...I.zH....?......V9.......... .YZ...%yRI.n...#......4[...T%K...H....Q....h......n.N..\.$.,.#y..gq.q.KqZ..\2.. .i...q...5..%P.e0.)...V.....%....WRkb.F9Q.....e..I..K;;.vb.t.u. J.t..L..u.v..n...m.].u........$E$.(j.\.+..w..D..$.7.5V[.F...T:}_:......Mc.+v.f<$...M.....s.....^*.`..T.Ai.U&..?^.-..N ....5v&f/. O..Jvg.)..!.q.u.9.Kj.a.@Z.+Zf....K=KjG..X..b.....6|....ri......t.&.k....pmk,..-U$...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2333
                        Entropy (8bit):7.913189886301227
                        Encrypted:false
                        SSDEEP:
                        MD5:4128F05E1EA001C859A76C62FAD72F58
                        SHA1:A735DBA39E5A1DCF38659C117CFF998DC8AE76A7
                        SHA-256:9AB8E093DB2B6382C044F78419EF3212DA7F268547414E0081484F486346C3B5
                        SHA-512:628CA2AFFFC3274D38537FD978ADA2991CB4FD99D60243D5D89DA7AB3A14FBADA4B0DBA04B0347EC6E63E3D4F9C4696D578FBD4235F7329D31BC3870D855EBDC
                        Malicious:false
                        Preview:+..o..(..-..Ek....".~E{..?...J;.....Y...f..I..c.N.#.K...R...<.y.gr.....E........... n.VS..<.'.(.....g.....*..G.KmAw..jy.....NB.R..c._..:.}....:.^./.....Z9.....h......BLPG...S.`.|[Z..A..D....:.I....%.......:D ."..W...Z{p....*7..h"!_..Pj..h...;....5.0.WdgDH...Y.)...p.(..I.G)g.XK[...v<.i..D6V...n..%E.#..n.Gu..".Y...l..b.U._.V....0...8:.....k../....}..|+...Q.~+:~E/..q..d..i..m.f@V..._B....h.Z.`.."...<.P._..p..!.....{..>../......v....V.6.q.].P.SvfA..@c..14..Hf..[.6......N..N.Q..5..$..+eu.-z.R...9...L.......<.^..p.q..XNbx....e.>.v...K.#.&.t.....p/WQy/.k.?......9...:...z..^..h:.rx..}.......sX.)..l.0.P.I.S...p..\...........G(.<n.k....u.wK....fF.q'J......B....@...HkX..a....._..VK..&......D...J6..v. ...2,...Q...H?.....>......"...7qE(11.I5.Sz...s.Z^..(Qjw..F./h."ME.....lc.._otVP.ZjNf.W..x.ms....N......`/..... ..nw.>G.,......~.A.[...e.,7..".q.,l...L.nDzWt..Fv.....9..<.c.aQy.sI6..2..ILMt,<.X.oc..\.q.;@......W...=.+6.......R-..4r3..O..[..?Vq.......
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1967
                        Entropy (8bit):7.911879274422531
                        Encrypted:false
                        SSDEEP:
                        MD5:592F1408B86E6D77353705DCDEDFB74D
                        SHA1:A1774908E0AC9E6A50E5DAE22740D9167BAEE239
                        SHA-256:C05DF83268DF3B19F672D302BE4C7CD606B7CAE9BD25346D161F5DFF142B991A
                        SHA-512:6A4AB50E07086722FCA8302544436C8DC38C93A0A5C8416F2E0F704FB4114BA3C84349C7F2D3BEC74B70426B88BD10C087381B4911BACA7368F010EEFF7E4EFB
                        Malicious:false
                        Preview:2.......P..}.#.vS.k..96.$.g.....b.e.W|........HX.......@.ZsR....../%.^t.0.Z.X..=HYN...'3...n.....c.9.z.'y+..h.O.|Cc.pB .....^G/E..Sd).....1|Q.[..V,....y..CD...J..L.>o\....Ub.....{.3...{Oh.../}..'..l. N.....?8R.m..*.9.J.w~?.91.c.l.Q.-.f.......F;>8[...x.n.`{.w!\...u.Fa.n.....>E...z.x..5:..'4m..........^..w$nC..[H..Y ..|...>=.2....dl96.%....&a.J..2N.*?/Y.w...C{....Z#AD..qa%..g...1....E...Jw.O7.2ub$...7..k....N.-....J..R......J..*....n2.G|.~.y...J)4>c..d(.3...2 C.8K....s..c.{u?..V.E0.....Z...UX~..NY.j-.2...~.m...b:H6..e&-.%@.."..w....zX_{..l.~..I.q./.J.L.e.x...Xqf...H.m...n<4!......_..m.7.\s+..w.......#..a.2..I.vw.u...n._.$..L...]::P.r...JW.._.....T.....s....gj.O..`rz..U7...V.x.{.,.n.._.c.\.l....%.=.RT....9..2...b.|.)..5^.8...}e..q...A^.[c.la.%.|..i...DT....T.X....I...c....e..L..2...{.v6.r.Y.4!};...q.O.nI.9...e..c>.F<.....R...._.5.!.KwqD''h.Y.....!-VX........bM].0.'.d.WX./.....o..w..O.I.a~1.,-p.R|.|r..j..B...a..>...".....YkZ.....;...8d,
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1221
                        Entropy (8bit):7.832388498494923
                        Encrypted:false
                        SSDEEP:
                        MD5:3C4B3D717573A14D1A23C1C4E214B91B
                        SHA1:AC75DB62987B574ABDF537DF7949FCCCC6E23D76
                        SHA-256:FF5F60F92E94692FC6467F6C37DA56841A20F7D4A2C204DC8F9665070811A72A
                        SHA-512:7F517424896D912D9377784F8BB8FE9462570DA5F226F4E2328752E37EFE24CA0670C8CA772700590B1AD85F2221101EF7468E3A3D18F166906CB642215D36F2
                        Malicious:false
                        Preview:.S.g..C.s.r...L.K#...e..........)t.[.\...v9.||... j..w.8V.+C.F.l.[....ixT.v$.n.{..}3fQ...4_...}...hw............z.HU.l%.ik........l.~O...pZ.]....{...&Q...mz.$0w8r%......-'..N@N._..[A..l..2?..+.....Q.r(=C.x.L..X)..)..........o......x..Wj....iS.0..o....d....$.E.s.B<g...n-....5I..6.t..#......9..aD..#..+.f.xVA..:.e.......R....DT.MF...g.o5.@.. .....|#......K..U..*...]..O.....1w(u ]..V...y-n4U3..{<..f.5.4..Dg...j]A...../f.E.4<.....}.DG[.T.S'.......{..QwE...9#..{../^....F....3....M.!.nY..%z/..R.9.s...(.N.x.U..N.`6B..h.....9xS.`....*"..jq..G-.I .c*._{1.3..<:t@..&X.....<2I.......bL...~Qa.07.....!eV....(.c1\....ID..CHV..AH.R..98...x..6....r...5.....\.'...i.$O...K:n...CZR.r.E...&.....J..(.....Q.Z..N|[.._.mY.vW..Z.....ZzU^..q.4.;.....FK.+.....L..T.cr.M..a.eMWl....D...qO..H._...B'..%...(..<...-O.3#e..R.......A..j]..-.hjN5..H.........g....].g...TMQ..-...]........`....R....&\...>.E.A...39...$..$k.I...1.m.uM.t.n...R..)K..Q..-.6.v`vu.JI......
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):1111
                        Entropy (8bit):7.829004642627011
                        Encrypted:false
                        SSDEEP:
                        MD5:AAF3AF7C92EE7758DE554057EE912C38
                        SHA1:BF1080168DD8720252E6DBD177E99A5FE491F7BB
                        SHA-256:1A9405905B2E6728FB40B78FA7EA488B4288F1AC0AAEE9D893377326621297E7
                        SHA-512:DA026B7324AAD93B3E0F1BA476DA7791A8CCBF2A2762FE0E2D3A03F344ECAF11B144C316FC74FA10E80C6B4A0E1FB04E66439B6EC05191B21F22AB3392E0A472
                        Malicious:false
                        Preview:.O$..~.....q...Q~.q(:.dp?I.^.l|....,.tR.G...e.......Q...$1....&.o.......t...^...C..eR72.O..e.........r>..H.j%=...;..n9. .%.h~.....0...iP.... ..;H.G.,.......&k..t_.P*.......^8.....9.Lp...-.2_~.............wI..if...n[.......x.J....r>l.....#.=/...!....fY/...CE.8...5.......S.3..Tb.S.0PA..Yy......O...`7...i.~C...p.......T.((. /$/..:.).qV......v...).F.Y8]P.5..#o.;.d8.p..i...|.s.v..#u_..6....+>O.cO9.0...K.H..y..(..a.HC.(k).5....,>.i..".vp....3IC..Vm.....d...4....Pr....4.g..X..a.BT...u....p..Z...U.;.f?..Y...si.H......e.v...b.y..s.y....e...h.......%..)....c.#M.F.P..0K:...m.Gh.\.....m>.x.X#...C..Z...#|0u}$....p...X.........}...u4Uu...3.%....}>mK.A.:G.Z7*WL.{M8.{..i...w....OO.5Zzp..d_...k.-........<.^...W..ZQ...#Q...K..Q6.....U6I./.....B...XXGD.F6...>L9f-./....U ........9.$..i..W.5.`.pk..%{v-50.......}.........._.-.3...T....*P\.....ES7.A..;}w..H..O...(..N..T.:`I..-..G..h#U).....V......6.%....#y.a.?.LX..E,......x..8)...3.n]`..56..B..)).c.A.I..<..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2149
                        Entropy (8bit):7.918301341481532
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCE6F33EE9CCB8FE80A839D5E1D8999
                        SHA1:447EC4A0B0485A487839E5384896829D9ECE25C4
                        SHA-256:76AC912677B2ABB6CD00612AFB1DD76D72297C695A399AF8095FC5FFBC0F3268
                        SHA-512:690971808F8768C0C23A88D223B744810A956C096F844D981CC0A2C6C955050FB3E56FD7A74FD2F5BBCFF5414FAFAE6CE6DECAB24A4F6EA62D0F493293318265
                        Malicious:false
                        Preview:FV&<...\....5..qM$n..:.E~.........,R...s....}H..g..W..........S....VW.D(+.2.....h.N..i...X.I...l...u..lM-._>Mu..w.8G.+...X.].}.6..O...XNO/?.... X8v......IY]t....!)Z.z.......X'`8K....w...l_.6Ak}F.8.../gR1X....[!.,.......^.f.A....z_.1.........S..T.i..&C.cl}......S.Fw...........{7@v3Ehd.L.`.5....|....v...Z..............e/o....H...Y..B.*.8.....;.i}..:`.t"..N....?..J`L.QSF.T.g..+...y.T/i.......d....1-.[^5..%...A.%..t...R.%..5.~.j.....nG.3........X.%=...M.!q...*.._[...h.y...........+..-.(...Y.i..D....L.dv....H~.O....Q).o.}.g.f..d.i....-.]..>.;.oJ./.[.~.y..j%..4_.....Zf...RH..#...[).m..*.-..6..}..._..h.;b..h......)....K.TX.(P/.}G.$.P.2.L....M"3OJ...!%.....R":..h...W.s...5.^...)..Y\..y..p..... ...i.ElUW.p..Z.......,...?....v7...[. ..n.m..JwoYp.x>.A7..X.a.K.bI...2...J...Ep...u4w..$..b.t.D.3....b....a.<.b.T.....wH5Y.2`...K=.:O...L<.K....N6.....)z*.....h...!. .....3;. .O..8...<E.D.MH..u.m.<..s.-.b...j[...s......ZI.e..o.Q}...b"~...U..9?....NS.......{.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):37890
                        Entropy (8bit):7.9950773376974125
                        Encrypted:true
                        SSDEEP:
                        MD5:AF978E35D74A92EBDEF2ED83D322F156
                        SHA1:F0A7E2EBEDD49CC44955B631177754CB1165ABE5
                        SHA-256:DFDC968346401EE61F7C7F69F46C00A5A9AC747C6B0597B8F31E463F31EDB091
                        SHA-512:D8FF9B2A2B9CBA67309D3780E9B1B2C462C637D0252956B53CDF06A538FF9D9E4C5BD88D27125A9AEC500CC6825270E367AC418ED6F24FB5C7EAF62C69400F72
                        Malicious:true
                        Preview:=.&.....W..S........{..3A..c.".P..M8r;..Q.-.j..P!.......,.@. ..A..'..a.q...6..)\..*.........6.......0d.+`..........6..6.#G..G......&]Pg.....I..q.lp...zI...z..W..,.+..K|............n.......a..e$\/.+....L..$.....%..O.T..v.....u..q...>.p..&.8!...HL..z.,8.'.k.z.P.Z..l...P.1.2...4.o.*...l...k?...b.....*q|..]..5......G..._.{...Ys2.g..p@.>+.C$Iz..#.PRYK.*XtI...v..P.]......~n.....CY.....x....M.=.O....ste.....0.}o.../.~....H........n/5na...X.5.J.z.d.....9...u...Z3...t..a...%..'V.#......VU.E..Z.upg..^..D.XF.:{%..(r./..-;|..$..]..Bc.../...P.6.I.._".....{L..[h8.h....h...g.wTf...B.2.K......BL...g2,r..'c#7.....^Kg...{....%.......q..mW1.........'..j..P2*;.....o$...c..V<.I..gP2R..j$..{........I..Z.>.K..o...`.N...X4.?&../...qL...6f.].B..y.sK2.<.#.......gN...p..RZ8.....5..?..E.xH.."..w.3jV..../..#..}.V.x..p........Z.`1.a.|.a..ah...SE...(......T]......\;..BE..J..``.aP...K.K....Z.......Z.....,..D*.S7.^.j....wB!.....]"._.........h...]R.....;I
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33828
                        Entropy (8bit):7.995482726702538
                        Encrypted:true
                        SSDEEP:
                        MD5:81B6F252A7460951A092661621F1C8C6
                        SHA1:BF8174D98AD8FEAA6692E86380A12D4C5531F0FE
                        SHA-256:7C183A6FE77B06B9800E73D92D56CF69A2FAABA86F80085207610D59BC0C292D
                        SHA-512:34EEF1C37EFB9B4455FB468C7F752498FA3A9E5DA33A588BE25ED79D2430612DC2EB3ABD918B2068A80A6E31952BF3EB7BD8AD312E007F0775EA3BE884529FB6
                        Malicious:true
                        Preview:j...O..Ib=.4.e\xY.+....E.3..o.......D..6At....."8~-.S.....N......M.........^.-g.FL?.z.=...... $.|.....!T...c....X.EU..x*..E..#...M...e....bkk!e...{..C....?..L.%{._{...:.R.`s.xM..}.j,.".|."...y...9K.H-.F..G.QgZ.m...J.)..iQ.8.U.$..a.!rMr.....S.o.E. ...7..%.NSZ?]....W..k.D.A...I...tv.3..y.X{WLb.v@.9.4..M.F.x.-2<L.....5..Ap.g..+....S..,... .^....l&.u..M...:$h....{...`..........V.K..W."Avf....Z.(."...~....FP....z....@.^.Tv....B..T.3Bd.%.\*.1~x.sJ.....d~....u.....p.\v`..B.;&..+.D80.;{'w.0.Xw...7..T.VTn....qf\..].R,qA..{..lhw%lns8........z,...-}<...q..."...9^..4.!..2&.>*..p.wK.=.o..C/ .i.....Q.%..*.t."8..}(y.75X&.s....W...>I.w:R.....+.Z..z...()ak,t18.A..4..n.*.Xo.SF.)7...vT..m.c"....=...S.h:./cJc.(.j.K.Rf........0.<...@......Z..2$I..Y.....o..B{..N ]..H..v....-vR+.=...?...Tvy.^(...7.q*..@i..H.)4...Pe..Ds..9.....%.-{G..O{..S. .....>.[.. 6(FY......@.Y.K..2....a...Y.,...I.w.>...t..sR....y@..R.8'.2L5.[T..e.5.U....^;..<Q...C3....T1s>..aA...'.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1060
                        Entropy (8bit):7.804346579062151
                        Encrypted:false
                        SSDEEP:
                        MD5:59E5B960B2D9A19DD25BA66BA4B7FBBA
                        SHA1:E7BE9B3FE4BA5B62623C3DAF80C00ACBDA2FFCC1
                        SHA-256:185E862CC811EC6D30AEB9FF96BD50561EC0385CFDDEF5BFCB62C43B8C8A709B
                        SHA-512:27EBB98C56DAC6DA33A15BCC2CA843D2F5824350B19CACD4238034E595B47AEEC721E7384224EB1E29A5B96568FC7FF8E7FFC9C136A3792CA936A7C5749D8826
                        Malicious:false
                        Preview:`u..V.O0.F....}.....K...k..Z7.P#.M.K..x.AG2i.s@. .....g.u.LQL..~.4)1;.....:....y8...,>h..:...\...$.`<...s...?e...|x..{..2.!..!2%..D.j&........S..j_..H.1....L`..H..I..z,.....(..........E..A$...]b\..H9Rrci.Z.)K.Xl.C..Pp...6b}B~.0.O4.!H..94."..d...w.^........h...... ....kF.P.i...R....F..;O.....[.5H..t!J...."x\.]...ytW6.....S.Rr..I.......J|...........&.;......_l.bP..Vs....6.:u.....w..2...UuI'...+n.t..d.*.H....mD..c-...2....X....O...XEt.Rg..Z..4vK..6+..X.T7.F...h.9..mr.e..D*...;.R.Y....Pk. ....#..q{j.$...[......%K:.......M.TEW......?.L.. .5.+.h.........t....{O......k..'M...a.r..Ks$6..=.K3..."...M.|..x..6.;}..........,............9.SC.....-....g.......Bw...Sj.Gq.<o..|.[..c|....8;.v7.V..jf.......w...it....eP+........nJg...9-[n............N.`N..E/..0...R....5.oV,......[.D.5...j.....4....H..=.o./.j..:g.xP.I..%......St....V.......&L....#.A..N8/.2.nY~...".%.x..}N.L..S2.(....R..0....p.Ld...|.~}.......y.?..O......e.}....9.5&..H=..qfB....;..&[R...T
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1440
                        Entropy (8bit):7.889582185933984
                        Encrypted:false
                        SSDEEP:
                        MD5:A9B62DBA2DCA65EA28FC4CE141A0C706
                        SHA1:9DEA1D723109E9DEF869BD4BEDE22EB81A268995
                        SHA-256:46C41F110A7C961D1316046949B3E0283C193F74BBF5B613E1C58D89B160020E
                        SHA-512:335DD4E323265B22A8E8E2FA6C8E06CF75FBCDAC169E2AD548441CC2F2D8263B96FA7EFCA68FBAEA579FB265CABEFB6736A4F4612C9689008FFB490EA0DB7DC2
                        Malicious:false
                        Preview:.....".D..KF..o..S..z...B>..q@OY.m....^..";.a..>...s..=4.....2^..W.....9|.m.6.X..... ._...QS9..}....0/..E.a....f..` BC..e.........Q.&+G6......./.2W.":.,......od.M...g..".a....I.].0p.c.<..C.....[.(...e....#...}.M...i..."u..H43s.|...!u[...G?.?...X_.2Ra.....X.k...U.3.A.P..._D.........eOUB$...Vz.p...F.......`..3..`3..&..@8{........9..6'1.g....v0r...............pS....w.E..4.......m.`xz..j0.hoKf.Am.B.v..Y.........S*..S.r...=8.0...F..H5f.......%....S..Y..,..NEi.;'-G..O.D....J....$R...@4.=...B.....%.+.U)...d.P...fcY9.....r.8;.....l4G...rm..v..h....k{.UU.7S......x......$y8..n.O..&.f(_mLc7.!.F3...(T.[..;/.A.. .}..P.f..[.....E[R!;r#..R.......d.Wyt.).P..D.y.;..e].#.g..K..**..-......1.J~.*3..........kFl..(N...,.c...8.......C1.+.....{}..&....j...-.>~1.........=........[ .I.G.}...A...E..S...a..<...k....R.....F....aXM..Q.>..%ARy/.....xw..0.....8..i..&..e..fF..]..6....sW.......K:..v2.H..2..).........( .f.. 3+C.?/DY...*.]Yo.|hjQ..#ob.....{.......d.e+
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):295972
                        Entropy (8bit):7.999398176776774
                        Encrypted:true
                        SSDEEP:
                        MD5:41AB42E8B216E33ED24A16883F371745
                        SHA1:4493FAC22EB5A6B529254806D693C9A344B346F8
                        SHA-256:853AE528F5DADE3DC7D17529CB3D239957B3C608319F52AD368FE1CF241ED6CE
                        SHA-512:0A9EA95EE58E3772E2B9FC72CAF79B726E12A93E5CCB4CD038BB5C64F2CD9224D5ADFEA05F0C7661B83D6DF0AAFED887E5AEB7D8E93BF3DE7DE22219939CCCBB
                        Malicious:true
                        Preview:...hh.....r..{.S%/~.-.}.s..&X.)8?....@.....>.....0...d..M....%.&.2..i...-C9.E.|...'..OB[..Z.w.L%..=l.w(N.,...l.=/.'.0.........&<...p'N.x...s..Nrs..J.-._N.gR.b...&....zY....2.9r...nk..y......@L9.J....g6.1..{...]...].._.-.c.{...i.4..Z..Ue.4........Fs.[....d$.V76.t..k.1}.j......."h".nB..9Cf.{J..8.y..T.........L........m.N..._...{H.]E.Q...'`.;.Wc.Q.V.U.H...g...hp2q./[...O.Clxo.aU..../.....F......m...........+....BoH....N.nj...kU..Q.f....'....[.}.d.AJWo._,....R.Z..M.xC.~..... ...&..!V...6*...>u..-..l..d...@k.c"u...t...bH.`yKEA..?.YR...d....D..1&...'.xUk..r<;.E.)>*}(r..........HS/..6e..*+*..W..W(5.^...r.3.2D.L2tOFz?3,z:%...j'..U.....-w/t*C.........Us...V......P.[S..aX..I.?...,.a....2.....A.Sk...,+..... ...F..&<.m...S..nV...%..b..n..wYI......U...".[,.rq0U.p...!U.e,.R..._:....."..9Qa.:}-..u2...L.5}..z.]....a`.X2...;e....94Y...z..4....k[..>Q.5.Q[.]..2Ot...U.c..x...+............va?.K..,...`_T..u<d0.z.......7.r3...4.<.[o.j.Y4.H.:...C...*+.X.v.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):99364
                        Entropy (8bit):7.997859594138403
                        Encrypted:true
                        SSDEEP:
                        MD5:8C2D44B0EC10CB72F2804BE74D906B2B
                        SHA1:004EC4E10C881832C32879D59E8E655AD9E9F03F
                        SHA-256:229F3629155537D40414B89F396EBC1A594569A31F53AC14433DA5AD1AF82466
                        SHA-512:026F4DE13E31BE907C69C82CBC26D31AC556F07BCA1767D340523C3F1D52A5CEA7BEBD8D156C517F92BE7F5EA664242C1F2B73C24EF844E131322CCF4C14C730
                        Malicious:true
                        Preview:.XI?r...a........|./a\S.V...cZ.1..S.).....4.K..A)..P.F@.....U-.6B...6....?..g..b7.W8....+C.%...".....7.-..i.9....2..q&.<.......H...d5%...m..F.....T=.s...Eg.h'....pmg.....c.).1.8s.[..-.......$t.Q..+.r..l.[M,.oa..}.Z@........2....I. .'.......1.Q.....;n...9.(....K.p.\...Me...>...W}.t...Q[,..9.. .......ay..;....-{n....... .A.\Z..})(...l.~5..D.TW@.....P..Dq7..Jj.f3.V!y)..<.UK.r..H._.[..!@.Za.>...R..`.R.....z....m..!a.k..d........:.Z>.>!.Wl..._.lz....M..2E...'1....R.....,./2|&Dh)geDZu..........b.Czk..c..$...../.F.?.U4C....1.A.X.....w......+...r.,.@......gL..c.....u#..L$u.[.T.%..O.?6..@6.KJ...I).l..Y%.|.G+.9...o.i..g0..W#...#a72.}.n...D^.\%5FH..n.0./0. q3J.5..E.>..k.?.`Z;y...L../..zN...}k.../.O..3.s..qI..-....n9g.v".lL...A}......g.;2r.YO.y.o.O..R..0.R.lnGj.m..Q..X....l\?.F...m.=9...K.>Y..+..&......&....T..`.<V.%.E3..E..E|.*J.,."....hOG}..r.....Np.%....{...VdR..5C..-1.P...Urr......{..G'...S..w. .;M4A........EQX.i<6...U.m.S..#.+........T=..i.7.?..-
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):1577
                        Entropy (8bit):7.856499473564786
                        Encrypted:false
                        SSDEEP:
                        MD5:A088253402211C39437A3DCBE2F25256
                        SHA1:8DC6A412763F59EC35A6A684F334AA7D94AAA289
                        SHA-256:9745A2534D3DEE590783C36CC11853D8E96E11140AAF5F3F997239D824E94F52
                        SHA-512:820694E495F196F940084CFBAA042110B22A5E624DC70E64B0F1C4FFCAF2B6DE0E0664892AB7859AEA8606295CD2A5BE4A5046B4F4B47E574B9ED2E2DC829CA5
                        Malicious:false
                        Preview:...*.T..9..+......v{.....z._.3..,.0..@.y-',.t3...h..5.m......3m..j..C.~G.{[..p.....I.x....;A.?a...].....q........x.G:.s$..h....@B.w&..?f..4...}/.7..cU..O....h..u...P....O....C.4.".L........m....y.E........I.nG.:..T4m7..A.g..o.'C.........jmH.w..x..N.t.0.l./....9Dfc..J..D~...8..\.P....j...^c.4.db.8..]..S.T.......|.y~J..Qa.c.).....<.A..^q(.~%.[.<..@.1.C.W"M,[.......t..L2..%,.E.(+,...........U.b"e..).I.R....0.n..o.......B~..%^....#>Z.....]..TF........J...e<.X...3NI.UD...3M..$..:.:z"F..tMB.....xX..~.;.I.PrP.-...d.Z. ....c.....>.m...~..*.....N.6.......9~....P...y.i......7t...Z....Sd.:............R$....j...H....IM.e.I.v.....^..&..n.y..u."q.h....O.4./.r..O9*.w..bzb..Z.)M.0..*_25Y.(..eb..xt...7..Z......}9.\.O.M...x._....ri.7.q"y..........b.?=%.[6.....XFJ7...tD.y.mV...(;..:.r...3..e[.].C5.C$*3..O.I.Kt.2.$.R.......\5.;Q~A..o........m..;..0Q.~.7.l...f..&d.y.. C....;........,\Gl.:4..KeL..#.Y.}.:..g.#.........<....~...<57.c..o.O.]r@h.9.v9....O....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33828
                        Entropy (8bit):7.993984345991108
                        Encrypted:true
                        SSDEEP:
                        MD5:6851B3E71B76E3ADE1125A926E3309A3
                        SHA1:9E1E6B0870570508F5BB71AA6E4F6EF3D07C6C7E
                        SHA-256:2F2D16628AE7067AC9F57A54F373C2166A9D3D5AFDE10682DFFD43C637FBDFDA
                        SHA-512:FE664546B5D9CB380054EF9F36BE4A8348B9627CC2E4BA3556078FCFBD54D18F97824523F24A3C41F8648EFA978179C7373A7ED7AED2DEA35E41682A99D494C0
                        Malicious:true
                        Preview:.9".|gF.X..d+b+.F...8.....a9*.....)...o......"..\.7N..U1.)Ny.<4{k....'.[J..z.m>.'b(......1.*.t.e.Ej.....g..)....B#....l.....H v..I_#'..wyV..6.M..eebEO..9z..0...V.G.^.@...6.g8~....Z.q.Q+....?!.... .ba...Fjq.. .Oy......,f6...........,.....`4t;B.=...::4G..r1Q@.n#B...q.$.V..........>...r0TNIA}.....i...zO?...?.N...>Hf6...~.dx=9Di...4PlV>..y$...).j...t...r0..z.J..H=.D.X.a.g.F.q..W..c....}._..}6..e.bzA;f........U.)b..{A_"ry...$/D&3...BXH...+R3v_..q5..?.R..K.;.#....$#...#.r.%=X6...M(..}.I.Z....y..X~E....R.r...N....4..E...iO.3WO..t]?.Aen.u...C..(.I=.CD@.lk.p.e.{..30@j....zN....~w............ .......^...4.f..Ir.......w]x.RZX...QL..g@.H].=D....a.!.;}...:.E.}....>...G.!#.F...c..\..9.=.O..R.G.....7...6 Y.V....|.K..y.^.4....}q..e....,.t#Xb\..H...7.u..O..Y......$......A9...I...E..G.M.E...).MB..J-.b..k...Pl!^Y....e.`..8.........K....3...R....L.....9.a...\G.#{....m.6....L..vy.$S~b.d..cL..>.. .FS.v...2.....".\....#u..W@].%l..}.Z...'...:.j....y...I...!.d..2.&...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1060
                        Entropy (8bit):7.801679149243118
                        Encrypted:false
                        SSDEEP:
                        MD5:A26CBA4BACB4D5F03DE5BD299116CE2A
                        SHA1:886AF10B0AD73EC1891D8E2D840BA23A34BCBEFB
                        SHA-256:5AAEC3627A4BDDAF596F8CBD609FD96ABDF551E6C749122B737B1B39FBAAB5EB
                        SHA-512:5B5F1D3D5BC2873E1D0FDFEEBDD9702381AF1E07949E1312C1F7632833E0D857346282A7F1472D9061CBC236FDAC4ADC3F6A8E3AEBEE280317EC6EF86DD63F30
                        Malicious:false
                        Preview:.@{~.d.$VyBl..}y..!49)...ll.HN.3g..?&.J../^..&.....&E.>.,.0<..O?6..g).e_..........a.r...gmb..n..,.=7...<>..M.%.k.$.l...j..J.H......Y?..._|..@..-.8......p.........A6.T..0.I*........j.<.K..{..../ST}s.uZ&..>e.pn......M.Y.^m..i.+L1dLb......um...Z-`.....!..2.H.Y......7..0.....J.G.:; g.Y_.fn.gFpioOd..}YU$.....V...;.N0v.on..*{RP...ln.a..P..Q..2!.Q...{.-.V..u..o[h.c].-Fw@Ef..tZ..H..d.W.i..^....r3....^+...%......&..g...].........$..'XM8..3.2...e.$& .....-./.$B'....%...Y.|.z.E....O....i.y....KT$U....k...'..L.....C...,....'I...PK:j.......J.........;W...k..@.p..L.m.....%.@.(.TL.H6\..R...u.(. ..,.....^...T.B..N...k..h.........iR.]..d70..o..1....O.......MG....df.M.,....N....!...S.._.Y/ ...L.+.80...]G...%ez..yy<.>....2..].oe...kah>..b._V.3~..u&..*D'>!".>..CP..Sj...........V.....g.tC.......0.5...MO..Fb....e.6....o..'..k..'gAhoC.s..Rh.6..)a`.>..^..R.Fa=3wo[..B........-..Xr..w.J.y.,.X..a.w...<d.o._...YRx.AUAx......H/.V...$s..|OHm....K..u.T....w...e.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):10404
                        Entropy (8bit):7.979689694859694
                        Encrypted:false
                        SSDEEP:
                        MD5:DDE488108B91E334EF5AE285A17AC32E
                        SHA1:5ECA0A66507B22538AF3F47CBFBD18D408ADC5C4
                        SHA-256:A05C7F0E6ECB82724E63170676D817D035795440EBA83A3AD83AC689F038A4D1
                        SHA-512:D3A767967A935FE32D67E018A751AD40DD93FAE6FCA7DDCBE0FB8FE62530C060947FFABA04E3D2BA02DF16EDC44FC2022E1252205A85AEBB6DE77B8FF9CDCB1E
                        Malicious:false
                        Preview:.]..f...Z%..&.....*"~Q..k.u..y..Z.k.R....b.r..m..`G..Bn8......2.,*..:...D.*O}....%..%`0.....%?.}.#.....$.5.}..0.$...&y......._......#.........!...\.le8c>.m*x......&/.~b.q@..M.....A=.....~......p.....L.x -..nI.}..WZ..~...r...M..Q..q.$.v.bp..Z..^.B.w....[R...`Y....m....m.{...P........MiEksYv..._)"....a./....~..uZ..yO..m^...-...b3?z_.9..T/..M..(S.5...).....o...cv.....?..;..w...(b..v.....f.f....?./.i@.....z.r..W.A}Z..>|~.O....~f..F.J.}.E).....dj..w...|......<.........b.Q.%}....0..Ku.h....C..?dP.<...)./..\..Yx.._...Lyk..)2...F.../z.F........?......W.B5./.........3. l.TP.<.....b.|l........|..[F...h}...B<R..?...:kmM{v.+.H....N..4.+...F.a..g.v..\(.8L6s$.kg....`.k.ppq.........q.....I..z.Di9}b..D...*..Y.....>..........&.b.6...h`.g\..l.X..%..{..%G.B............h-\@).v#...@E.a.-....V..<0C[.r/...........tnz$.:.am.......9[....WN..J.G...|Dc"....a5.s.jJ.0.=..f,..@.a./O.Na(...".....f.C.1M....0Xd..U<....:..&..<...[qYwD.B...!....>.+}g.T..VH.=.8".V
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):66596
                        Entropy (8bit):7.996979906840043
                        Encrypted:true
                        SSDEEP:
                        MD5:B6689F33FA7E313CF564846A36FF0A06
                        SHA1:2236912AB278E30AA465FFE8952EA0AC99992C50
                        SHA-256:51CD2A895BC3AAC37F29E6461FA1EE9D0D906DEBEF1CB476B167E8CB33ED4185
                        SHA-512:A67C70D838E7BDC63C6320F070CCE23C364D0C540F1C81D05AD61280A4708E166D65CE8FAEAEA96557673F0EE4A536CEF8F31D6B50DAC9E9AA7A032F148A9256
                        Malicious:true
                        Preview:.3.......9\.d........N.....%....=vK....%.k.Q.bB.G..-M..F)..k....(....(.....OT...+..g.H..r.7....tP...s.....h....]........kS~...3....:&...O.>...2..uG.d....q..3E8!./.%02.r.A.NJ).[...L...,.-......qBLm...F.r$.-...\C.T...T.Y4.T....C(,..ZZ.z>>;.......0..4t.....*y#......_..<...-...y..J.L..........`N]ut.s...a.d.....h..<.|...-..I|...'...q .Yw.OD .'.k....tq={U.....q.h5....?X....E..^u6.r2c.}....:..#.u.U.5U......0.*-.H3.:......-...x.......... J.&}..W..`.~+.....c.;..0.<.R/+..v.X..\%6..T..6.6...$kx...W~]....os.A./....%..w..3.C.1...;!...Mu2*.. ...:.@Y.T1D.9l.....3..VRqx.uj..i...D.WJw...E.PF..k.l.c..!.ovZ.7~;...|?5@d...QB.........0.W.-?....zv..+..6......>!.meH(.....o.J.V..R.;.L.$XSF....+....(...-.......Tvqa.....j!&.U.G..zi.&..n1b.$.>.....|..{.S..f...A....zu..%.?,....W..|..)..&7(.R.ImL..i.s.m...c........Lx..v.pX........Tbr j.CHK.u.J../N..I..Xe..T}.>J.mP..O..KJ=.V.-.A...8...t._`.R...|..b..D.:.....&y/.=.Y.N.....Wgx......"e.D.'.F...h/.M.u..}...A..G6^..\&....'..j
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1551
                        Entropy (8bit):7.879443185346961
                        Encrypted:false
                        SSDEEP:
                        MD5:6A7366F64F4A81B24FA13BA47B561CB6
                        SHA1:1C8AC749C3416C543C5E8666B7478CA471F349DA
                        SHA-256:5BA3932E99FAB7F41741C956EFB0315747785FECA90797A2E69916EB968F9A4E
                        SHA-512:C28109A02DB4A84BC3A6D4D4B1D89B74BC2325D6C0AEE8AB08AA3BE3F7C13B099B20A8DCFF7604008498700EC5F7589770144D68EE90E0EED7BC42FF79844324
                        Malicious:false
                        Preview:mF.......^n../Fe....!p....%;..Y..c.....0QO.a..h.....i.....P.L./?W...E.B..+..NYb..M.......bb+.z...a%^......"......Q<N...S.T.a..n..N...d*.*.!9..-....O..M;9.}l..(|....Q..S.6i.....T.2#.;...>GM..^j9.8....ok.l..+/..F.g...'.W...o...?..Kd...Y..B.6......t.O..o.D..-uk...I@...t..&-..yUC~.....#...S..+,@.G....+.&.....Eq..*.?d......u...)O2........-]..X.;$....:...l.....}..p.{,....n?........*.;Nb...T...X.3....H.m.b.e_8..K/....=..8...8~/..I%m$........e...IU.L.G.........rGO........\.&.&.*.......I.'.BT.s_.9y-.(........n..V.9. ..X.4(e.gN..q(T..Z..%..A..g$v8.8..40].L....F.r..hz+.."m.jK|6....<&........I.%f.;.)Z27..E......$.3...E..._*!\(..C..@.Q.% .yQ..q...+.(....V..zO.Hz&%..7.R..a...Di._.8....b$".....;q...f[a..k...N....]..%.p%.*.Z..^o.CR.i..Z.a..m..<:.......j.f...t..O.....1q7.J....c%..r.%.N.....O.1.~6q...6ox$.uJ...p....]...)1.o.....}.?Q}.%r*.P."..L.zD...:..z...[D(..ixJL..y.x.'\w..uV9.L.&..;.V#..y.(K.k.,7vZ_.c....Ly..9..../.h?.S.=...6...*xpK...u....}/....3.S.....W..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1552
                        Entropy (8bit):7.880412733153505
                        Encrypted:false
                        SSDEEP:
                        MD5:F5612497BCB0F7301DBB2B9C6C5A98BA
                        SHA1:6DA1D3A0531284A2C8B905CFEE13794B9D9B83E2
                        SHA-256:9A3DFD295F3657D7CFEF11730997198E0237C776424E73EF08F436199C98C5F4
                        SHA-512:0514C37AF1E2DEB1E816CE976E7C6C6EB7022B60461232D2D393DA593D7F7C8142B8F3033F3F3417F31F4374C14C0471FB4276C06A54DA96E87193EF86492056
                        Malicious:false
                        Preview:b.;0e.R..%...r....4.s2.-^.giV....hB+f5.i..;s".=1...W.....C.X.#...kN.......YPD...H....t...[Z..M.f.qvfA...u.....;j@...q..f.fx.'.}Y[_e.f...e..=.l..X.....:..]...py0.+.q....'[..5...Nr.\./j."._.M*.F.\x!....t.|S...m....@7..\:.~t.|.C*.......DK....s..o.....nt...)x..f.......'.....3t.Z.......vk...E..G.+.J...0.\...@..S*..a..24..^In.@..M$I.2.0C...f.o..=+.p....z9..4g.. ...j....I. ....3k..:.:..-.y..##.:h-_=...x>.....B.........t..........7....).#t.A7..F._w+..l..a...v.....,.h;.P...!......=..Q.....'.....Se&............ie.r....Hf(M...Y...........F.s.xffM.v.b.!+{....Xc.y..........y.......%g...8........i.G.*.q....+..L......../.Y..`...]..%....J.G[gK..?R,.8.==..3.^....m..`)+..w...$....Abl]:.X.jF..\..X...C8.+.F.=B.Fg...9..'KRv.n...E>.Z....C.K`..O..^.....'..+.kz.SHQa.c.u ...B.....j`.Qd\5..WH...|...hgy........7.V..J.W7.......+L$....Q..W.s.{..S..s.b.o:..J.5.wOp....].}.s....4.62o...l..wY.c...P.~P..2.. X.Z(.Oi.........M....$.....l.;...0...* ,DQ.o.)......\..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):42489
                        Entropy (8bit):7.99507447934345
                        Encrypted:true
                        SSDEEP:
                        MD5:899A7265BD31C894DE842AAAC8597463
                        SHA1:FBCAAF76F3D63631A328B962AFF3139E5422A104
                        SHA-256:BE2C284CF4D16CC27A818C45B3E88F22FDF008A2F30F2D7EC2E766E5BAADDDB9
                        SHA-512:8C0D2ACF4668FC4A2EE74E8833FFEBA63348B679B77D65E1815F94AAE47E06027E29A6C2A5523006C53C9A75FB61F30C8329A142A7729A9A676B6BDE5D600162
                        Malicious:true
                        Preview:.<A..R..~...<z.....j.&Z.`..g.'.c...NF Ik..a<.....Y......kw..Y..C.Z"q19..#.{......-........m].N..9i..u.A..6.m..q[`p<.jQ....A...*..H...j...h..O.*Ae.d.U..k5)....MA....f.@r..MV.;.s.c.=...`.......ZV..W...5.,.z.7..3WB&)2\.~UU}...51..K..o.l.A.y.y........z...9~.,.B..S..~...z...[j.....6t..X=..).0.?4..m.F.^.d..J..B...Z.c1[...c.'.0.p...t..`9I..........6.O.~w.6L...F..\.Y....b..}....^...{...$.$OQ.f^.....>X-....G0.J..68.........^.7.pO..^..n.3.N..D//c.iS.4o.......^..kWE.........yEK.u.....$.N).BG.T.9(g.)..S....y...l.T..TO..Z...Y...V...c4v'..A.#.=.y....\...K.C......i.\.B5.<0..7.J<.w.K_.d........9.[Uv,......+.O..Z....2.!...,.h.s..9_.FBO...BF......A.{....M.aS...."MR.38..../V.'.....@{.o..a7........vrIU.$....u....1.$.U.-........].....-Q.0......F.g....y.....:...8..........K...7.7.? 6A...i.b..D.*^.....!..oY.....[J.~....u..(...#.o..::@_r..O..h;x.7..........<.......... ...aB........Gy..[6..#..h>.W..k....c....G...`.e..DWg.......ca%.@..4Z.\C..wr..2...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):9718
                        Entropy (8bit):7.9823126238525735
                        Encrypted:false
                        SSDEEP:
                        MD5:43F39A574ADFE8062F424E2634FEBF6C
                        SHA1:59A119BBA225E80FF812B92624BABB29FC374EC6
                        SHA-256:68ECCD8055DFDFF2812DBE3E88E03031639330C86392ECFD01E71FD4192B213B
                        SHA-512:446EC3720DA242B86812C2A02E06C684C128E2FDA535F80B0D3AFC70A3E11B7416CF7289450D8A1DC9417ACABDE93EFF1F6BFEF62979E9BD77C79883691F502A
                        Malicious:false
                        Preview:....#q^.R..."-...T......XU....X0.[..o2...k@.K..a5#,.0.U..G....C....~#......e...X}.Q.c.HS*.......|..9...y.=V\.Wj.i..y.....n..|k.N..J.I.`6......BE{....Y3a.1)a..j.......?.^.g.q....|...S..q.............s..25xM...W.Fx....*.v%?......S...%..Kh.........F...?S6.PJ..#...uO."...../RCe8.1V.......FN..]g.N...",..~.*..A.|..'......=...A6.!}.Z.x....a...R.I..C....r..E./..L>....9...Rbg.h..(z.p.`.......:....p.!.[.(..a.D...l..}..../N.BV.<y.B..qCY.W$q..p.......i..Y..3B2....l#O(.......HC.......u2M.e~.q4...[.kj.R,.....i\|...K.....rv.):.(v.....NMV...te.s..I....c.....D...z=)..(...a............?...j...la....K,.E..;.....-."5..=}....v!~..T....v..6nt ...N.f;L...z.......>B(e.I..g0F...J.."K....p.B...6..n.....G.....}..S8......O7..=U!.tEcEo^..U:.k..yX.e.)........+.[...5...xx.{.K._M.[8...+......Z`.@.)i.2.9..x./0...(.m,.GP....&t.7FU.....?X............SO...3..`...........Z.z..&...Z+w. !....6..G...$..8...[h.m:.:......c..kIL^..+...n.t2....."......J(..B..../..H8*}
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):73133
                        Entropy (8bit):7.997757531244572
                        Encrypted:true
                        SSDEEP:
                        MD5:E340B6E9E411CC557C166783816157E1
                        SHA1:03128057742B4F49B6B2E3B5EAE197FC19E69531
                        SHA-256:A733BBD903ECA40B75EDD309AA4F7E3ED6C661FAE09709B3E6EBF978BE7864DD
                        SHA-512:5EB69B589847C09EA2A91ED2FAC128D942D6D8A9A2B82F2F876B7E68B167D02924C5019FBD6E2CE6B5B658BB24B87DF8528A9C0F60AA5E6CA8421B62687F2DCF
                        Malicious:true
                        Preview:..D.!....f......._...\.*FaE..b!.9.......2.......L.....+E.-.35.}.[Q.Tr.YZ.3../.........J...Ci..G.....%".x=DD&..<g. ..Y.H.9Y.../bR)kDR#..wS....V.I...._6....X1.tpc.nu..b..|.?..g....._.......+...<l........pV.oB...[{g.@;*...)y.!.v......[D.M[.KQC.^.(........_K.=Tq..g..3..[..S........'...,.......,..>Aq=.f".n..a....8..|?.~.....m4..7.2..y6....4$.....iB|.A^..B...w`....&.........4.........!....t..H............t...."......c...o.....|...(.o.1yNU*".qT.'[.e..9K[../;...7"`..u..387...F..@.....*....;w..+.&C.b%....d..v}Z?.|.S......4.Q.M.1j..z...^X......}..GP......$.3..`.UjP(....P.FsG.\.^,.`..R...R.O{.....g....&..nI.._S....R.X..c..q..]....../:*.z].M@Nt.d.Q...t.o$..0...^.Tn..W.@...n...>.R.qy........<..J?.....T.D+....t.V7.Z.A.}..}..,ihI.../..xA.2...C..>3...6...W..)......F+..JVgB...[H..pV..|..7.._.AR...W.w }C?X:.vK*[J~.._.....-+.Tj%.y...Tub.U .3.'8...yy..Z#pT..U.1.vk.Z....o.,L.|.fE.<.2.<....h..J:&=%.g.A.m...........t.38.....&....D..F......YW.N.&..,zwN.55...........t
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):73143
                        Entropy (8bit):7.997648624481053
                        Encrypted:true
                        SSDEEP:
                        MD5:EF0DFF6400E0F8C0F1C66BF7BEF86A3F
                        SHA1:6EACC5B1F61015F6C0AF4165DFF9304277FA2825
                        SHA-256:D142AA866FD09BCF32DD3BEECA76186CC8CB3BC8FD07DEC869AF775B3E5C5183
                        SHA-512:98E1A777029DCA044102F78F828EBD8BBC091DD1D1ECF49BC9E3109C6C8D8EF7B7769CC13ADC4E91419D6AF94053F1196FF58418B157938C2E5BF498F77D5D73
                        Malicious:true
                        Preview:... ..I...jq..j$On1.Z.PId{(.+0A,.Z.P....}.kt.r......c.F.8.+.A@J~..a9..u.2.g....3...r.sz..3v.2...Y..{.V..a`W}P+..;.[.t...w}..Jg...8...E57xL...S....S.S._..P..TM6E.....-...s.W..D.;L.4...`S..{ZnY...B.q.3.fe%.hn..5=.....53.A^l...D..x.!.T#...........,...wp8...C,'...f....6..=..$.~U"R....p.-.SD?...,.^..^wi......+......{.`....>*.b..G..&..va.....b....>;..#..fxJ}...F..`.?......\$..\A.F..5...&...a.J..{...2.......`..E..1f.uY.i..:..@.{..S..=......o.(V..%\.f....w.E............ }#..N.B'....\.@.$.t.]x.7..(..k.r%.O+CK..>.3..06...).R..A"0.7P.n.3.....g....'.p......d$(.|..:..[>..13Z.6..GRl.$.Lb.S......U%.f........zD...cE....O......j.x....hUC.:.a.E......P.`(l.C..S...'.T..T....a$..R.-....@}9y..h.L.qN@.....{.Hd....v.j.bK.L.....[.7#.^4..t}.H8b.7.;.x.H.y?...J.OV....^.#.qs....E...6..,...Q..+.x..u..h..g.|...fbe..hT....U...I.....df.Ot4.......S....be.S.Y..N.Zg;D|F.....w..Ln.a..z>.M.L.g...(7.C_Jg.....B.9..z.~..0.....N=....P.94.T.B\....8.EN...J[...C....t...:SA...DS.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7742
                        Entropy (8bit):7.977569969643252
                        Encrypted:false
                        SSDEEP:
                        MD5:8EC92D67869D6E30FD7721387D391986
                        SHA1:957C88389BA721F1013734659855089D13FADE05
                        SHA-256:3E4CADEE6B582584A21DA85556F885FBACE8F91BBDB19D95824B5A173427D9ED
                        SHA-512:DB13EE5549C8C0F5F67F629FCE407A3F14F05050688FFD2A918CFF06AB3B5ACFDECB3EF634FB567C996872EB1A82A6887729A459A944D77F992A628956AAE354
                        Malicious:false
                        Preview:~3..+...*..'..............`>.........E......Y..pd..Sk:..|.$..A.t....|0X{..?.2:.}...2...vyI@(x.x..H@Y.........,....S...f..Tyd.jX8.b..q^.H..(-Ck~....\..D._...C......T...k..8..y.......+h. ....b..[..sa....yF........91(..E..z:......J.....i..-......Q.t.........@...py.?.{.....&....Rk....#...._ J.&.......e...vR..hZd@....U{^.7..Eo..v}...vO.p.n......z..p...rq.t.1...v.U.\..X.\.....<..|.y...m.H.H....G...W...j.$."...h........w.........O.L...1.m...P.........r...b..S+..X..At{...?.Z.D..T....1....q.|....,..!.G&B}(....E..S.EIuA..L.l.B...W....7......>.i.....m.X..0.%[.#..}G @f.k..+..V...n..I;.}.g..E..@.u.6..( I .{....a.."N..*..Q....X...{9.....+0p...V@1...R.P.T...!.....J^.QC...@].}2..+..~..H.U...U..$...X.O..J..$.-3.@.0..'UZ|)...-..k.aq..d&E.1.-.2{.%S.#..G|-..g....B.K.@2...7.7.u0U.w....l..9.2..<8..51...Y..Y.N......9R?....a.i...=.._ ._..U.a..Y.x.@........<.>.....`}S.C.A8....."3...d.:..=...J.?S.u.;..W..3..../(2....[....5*...\..0..P.....t0...}z.....u'b
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7749
                        Entropy (8bit):7.9757244828636065
                        Encrypted:false
                        SSDEEP:
                        MD5:4B20175D05A12F3595E230149BEC1146
                        SHA1:7E19D934B96914AACBDB22F27C92A9F0033221D9
                        SHA-256:790D4AB5285CCBD5F8282E34A4D0E2D38F69F8D0BB66B72383C14C1A156C352A
                        SHA-512:ED191D1DDB1DFF16DDDEF8CF8F56E563BB1C8FFFB92D9A1FB7487A29B28C75300411E1C63BA44E1975BAD7F521BBE4E4435F66F3DF5CF0FCF4917DC6AF39AB91
                        Malicious:false
                        Preview:.].'.D.._....b^.F....W...N.tc$....g../...>...6.G.V[W....W._y G..X...n.8).....cW.J..e.>....)8..,u..tt..(b.M.eO..oJ..l.Y.b....P.c...Al..&.on2B..Y.Zum......N.b.4.R....R9.c....F..&~.............,1U...A....&b.e&.r.....Qf{)....n...{?_....?..<g.....)^.!6..d...z....;i..Ki....?...<]...x.!..4$...w..ju.9....W2|... ..XK........0...4..[.Nm}..y...]2._....{.-....UoQ.....`.....gm........e..:...M...I...%*.....Z..}.H ...r...84S5.....3.:.B.RY?K....+.f.A.)h..N..I..Z.d .......@)s.{4.Bp...:5...}&..M].i..I.}.c+_|<.7.-}%.g.h.7.mo}.*;.h.c-Zb...1.}.`.W_.iVT.`n.'U.B.&...~........<.8..(..$..%..C^^} A..N}.0....P$.Fsu.....}>.rL..t.X88.w.V.Qg...%..I..._<....i..F1'U/oem.H...q1Vj.....*(.X..3.%..).}.....k)L..Y.>.g..U........+r.....8...(....j.....9>.V@....6.....dZ...^..u..(.....!V....h.........?.8h.x..m<*.'......Z10..p...-..Q.5..-;.C...].$w.R.k.F.|.j.....M.#...P.....D.v..t..-..K.t.>|.j.....>.xMa.K}.&.-P}I.....s.|.V.y..;.....?.......?.....T-...S...".....H.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1409
                        Entropy (8bit):7.859791371453591
                        Encrypted:false
                        SSDEEP:
                        MD5:2C28D983E72ECC59FC874C8B9C5AAD94
                        SHA1:D96BD46988774229330D2355BE53847579D0D2BC
                        SHA-256:400400D3E8E1AF4A405A7FBBBD56959A3428D3B308620CFDE0FB229AF1B1AD0B
                        SHA-512:F75626530636B31D28675A17298649E8FDB79BD11858F04A5AE3E4F1B2C517CB49550CE27F109B182AA293FAB4AD4F93F652A670DDD749EF3FB7DA8C6762F3A4
                        Malicious:false
                        Preview:.6..\F......l...C.i_!..L.F..1.......e.T.U/...U[mqo`..n.i.5...<.-...r.+....].. %....}....^.5..u.P.....k...F%|.=miBM .K.j...aA.C;(..OR...jC..%..h....Q`j...<..[.t........|x.Vz._w.)..B...b....e..qi.*p..}k...C.O.......>........C.VBk.N...'...^.^...T..ge.m._..!.MN./.....N]I.:.S..... ;.A8...7...........J.R...`...|u".9w..)^..Q..4...o.........k..!....5..:.P...m^."....?...B5M.....Jwu....:.D.)......?.,|u.`...z.|Z.l'_h.....-..=.u...?.J<[.l.TO'a.6.....a..\>1..5%...f.`....7..E.....-1..w.eQ1y.p~-.n. ;..v..M.Njm;7.3.g.]g8.#.o.....*.B...u,..3s..`.....Ku.T.r.`=9.I....q..B.NR..m..vg....hL..y#&.QR=....8..6~.lA..f..-u.M.5v.+>R..g..Iq0.......;..`......<./..c..I.X...b.4..W|..."{..[...Ub.....a.~.5FJW.[.p....I ..N.X.0.v1..w...6..(...f.e.....X.*qxb ...#..Tm....Hzs....*... .....;.4q?...A;.7..|.xD........[.q>.fc|...}u>|.ZQ...b.2.<)....\<...a-............5.pV]..4...K:.....H. K.= ..(0.|v........5.{"...+.;%.. ......(...../....5/...x..~L....(.I?MyUN...,.6:.u...fnp..*..)&
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1348
                        Entropy (8bit):7.850307251842624
                        Encrypted:false
                        SSDEEP:
                        MD5:E3D3E1087A2F2D294701EB0920BC48E4
                        SHA1:D1B24DE5666BD89C0BC7F08D76CE7C6D9F1AA2F6
                        SHA-256:85F52065CED3BC31F94070D8C5584C21632252B15568B655C03F5F00802C43BF
                        SHA-512:CEC13A457765E4EC278D2F283EEAE17C3997CEB718DE375C23F8175578244AE4345D38ECCB91E62B8D2DA876F91E7C7CB12C8EED5D40D2BEF2CB10BA25FE4712
                        Malicious:false
                        Preview:.M@.W2I.....O_...C...o<a....>*.....t@...b....i.4F...iO5x..v....7..Z..w.>.xPJ..fy.C.....-h.,.2......M%k.B.?..kX ..5.!.*.6.Z.$...I.v7..u+..6.K8...{.2..YmL..%.9.Z....}.z..N%..T.8/t...W...I.(.~.M....mN..g..FZ..E#.B.....Yo.....`........ /..h......+..j:.....nI.:j...%C..M..} ..F...+..}...w4......Z].L.-...&..b0ww..."...sV...F....G..o%O..W....<.>....az.....HM..z..0$g|f8...6...t...mdk._v...2..C.T.......;.u1.g.J.(4.h...[.q.[..)p,..R.2..A...D...... z`b....m.0.BT_.X.f..0tM.>... ..,...uam.;..4.......d)..]k.I)/...iM........,.g..T6-.d5......*tS....P..T...........:.GW.....Z..!..^V,....i..S..........`O[9..I.y..g..z4.NY.;. ..?".8b....>a.ss..'.3..B.......^.AZS.........e|A.(..0..+.qD.O@{y...>.v...Uv.....$9 ..b..4.dy...gI.>.4..Cl.iac..M.0d.5sZ..."..\...4/...q0...^...Y..m....,w../.j0..fU..v.p.W.....Sr.K:~...2.....!.g8.{.T.=.i..N....l..=.E.j...O..#e..>..RB1.>+de.oN..Z..m...x......%.c.,HOv5.'.nN.....#.."..$...]..t.......@5...=.8..Oz.A..L{s..=7..f...U..m..L..$
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2538
                        Entropy (8bit):7.920972032725855
                        Encrypted:false
                        SSDEEP:
                        MD5:C47CC41297C76A772B6D1491E7701704
                        SHA1:900C5B87C54205C9B6AFED4500D60296EC25CE24
                        SHA-256:1410051E078C8A398AC7ACF397BFFAD257CE84964318C3C3DBCE9D5E8E7E5689
                        SHA-512:49BDE3FCFF5CE86A145CD0882429FEB06CC2AF3CFB4987B8E1169284C610D0DCFE833349DC08ACBE07B3D7148FF387FF5614625F3D33C94FA39FEFFDBAA19FDE
                        Malicious:false
                        Preview:.@F.g.{>..3.{`.3..3w..E.*....f1..o)....W.........6..=...X......Dc...R*....qF.r..2.._+...t..;.X.lr.n/.D..w>.w.j...n...&oT.~......I@.. M..Z...nV.MdH....._..O..6..&...u....'.r.ri.I4@.n...6J..\..=~M&A....p...../s..Cs...N&/.G..e.v.R.f-?.4?..M1....d?hy..J.w&s. UC..bz....\4.n=.^|..'P.;m..;..[q%.......H%..7=...(.*.m}..G|L.o..~..Ky...t.<.....B....AG....|u.f...-. .._.....0...u.:.X....UH)._............5.O...I9...8S...Af..g.]... ..]A...V|+C.{.3...=.C.&.p.Z@']..;.j)...H8..v..9.I`.?.j[.....@.q.W).k....B&.:.Y4..>.C...h...B3b.;.b.5C.%.N..%E}..."....C..O..G(.#.O.m...1..wAB.1.. .....M..}Y...u...G`=..........PO.w.......## ..-.E..t0....Kz.......}.6..~/$..o.O..5..X.0.......G.7B.!6..v....".ox.\...^.>B...J.5+.L&.ay.1.MV....l.1Z...q.z...A....&.9$: :mK'.|..F.|...+w=2..~).#.. .RP.-..}..N...O.,w....8bP$.._^2+.f...$/..x."D.q.i..V...2.a..L6..h......nYK.Z..z..orfrc.N,.zj7....r......dhd3..&.oa.....N...K..N.f....,...Th..I..>...>}..0..NF.J....74T......p..N...I..Y..UG.\.....2..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2538
                        Entropy (8bit):7.911333854976779
                        Encrypted:false
                        SSDEEP:
                        MD5:B4FACAA99A0E8F4CBC6EDD1A46CC4B97
                        SHA1:D73022D4C13C97E4D8943E6A2B6E6FC78ED29769
                        SHA-256:0A9C7659A541BC428344BCDD03804091511DA72947D0E2EEE9F4F5D52EFF429E
                        SHA-512:6FE04687A5EE283329AD68B41A1406518F672937F9F6A17451D2F09992378ACE7804DFB1B9DE76F84DD25EBB61D6C430B47134A9D1F9459A3538066DAC2FB174
                        Malicious:false
                        Preview:..@a...G..h. ...........T.v..R.B}.>.`*D..6..+...!...}..8G..i.k..6<.m...Ez%.....d.d......(....e.....V}..#7....9...."Z.X..v.....b.....&..w.<.m,o...#;.c.=...4q.|.P-J.).......3...X...-i.l..N.I....%...c%0...../..N...s....y*..0.....=./#?..FFJ6..n...>3.....)T.+.....*3...pJb..9...sa....;.TG..{...|.h....Gz.J.v<...Q.&...9.......0..0...k'..9l,..I....tcdp....mXt..0X..|v'..")-$....P..$......w..[~8.....?..S..U.{D?.x.....?..;4.%.Q.-d...0M H.WG....JQ....wF.V+O.E....$OD8W...ND..D%....]..UT;.?....+..~j.k.....V.rUT....Z..6V1*k....7.\}.G........uz.......\t8*-........._. ..&].$.a...H.K,..S.ig._.}..k.....2.5^.s....L...o..-..p.l..7.@k.q.5...?.1VE1.`.....AP.r.... .b.N.....O1).~.|.+m..N7>..;.@`b"............WG....l.S.o.\...$....n../.]...b..+.t[.......T...s......:..y.|#,.....a.V.U.V....,? ......s.r.%vC.@.....b..cx..~..i.j&?%.t..]...1.,...Fe..\.Q..V..+..5i....b....W]1..Q..=...F3l..[.....=Z.4...UQ/w..%r.+...e../...cX.....).j".....&.oWb..'....].U../...O..h.=^
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2277
                        Entropy (8bit):7.919235737127271
                        Encrypted:false
                        SSDEEP:
                        MD5:9058726FB286F31DA0F55D7138B666A9
                        SHA1:50AA26585BAF1D526E62E79BBDF89A9B19516F3C
                        SHA-256:2A12E2B9A4CC17382C224F29A043F487FF86FFE20848D61DEAEA306DE8BF2775
                        SHA-512:2610DE0A84BC5CAB225C0CAA64F1A1175A72FA447C79DDCF90E0E052172B230AAC155C1432357757CFD394E4AC65EE27414119764751A702F868FC2F844F2F16
                        Malicious:false
                        Preview:2...e.....I.+z..i.......]..T).r.y..z.|."....dmr..|..'s*P3.`.[...3.F.]^{..3...W.V.j.2....:.@F!..q.]..E8...x..T;.\...e..2"......nxm.N.O.....Q...2...-..G.`H..."B..\.t".D5....`...dp.....i.......w.9...=..I..W..O+.\^.i..*......,..x..Tw&{.......-p.q..3.yT..C..O..O../~y.....k.R..hN.L.C........[.&."..$N....2v.p{^.E...T$.......l......O. [..X.;VmV-..............4.....^.B``P.].9.nT..1.B Y%....}..n0.:Q#......<..J..0.d...d....d.1.G.....E..z.....06M...Xm...#;.uQ#...q.]`\..d.`.-4..%..........+)+u..m5.L..X@....A&.c.>#...1.`Jq..1x...sMR>...B.[......W6o.k.d..J....!P.vR(q"..."Z~.'...X.8..L...;.5.......K...TxV.*$.Fp..z...PC..(=.... .j.....> .N.P.j..}."....u.3...y...A_Z1.....&.'...J.....q^9!t.0.z...........^3...+..}G$.[..7=..H.e>i?...g....Z..G...c>.^..{.WY ......(..Bn...jH...Q..7z.E9|..'...HIB.....[r..j(......%...F.nU..wW..5.`...2......k.....F."(U.OdC..\.1R.%..x.Q+.E..B....Sq..kl[NOp....#.7yW5..p0"Uwn....8M..=...iKz..J.'.D...b.%...b .=...e...t....}....)....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):1078
                        Entropy (8bit):7.791466124152845
                        Encrypted:false
                        SSDEEP:
                        MD5:C59D732C3158E20C6183E42444E69287
                        SHA1:06BC938D3F52F142E3124AEE1453D861533061AD
                        SHA-256:F76BD86E7C3D7A4FD477A302C233F925BB2B51B9A34D79C3072EBDD73773616B
                        SHA-512:5200CFDE689A14019A956F016510D9FEC7B222CD6E4A8A636BF6E502DD3E85794284B73075616AFC7B586C995961D95CBED6A24368B3B3901A2460D19AFAAAB9
                        Malicious:false
                        Preview:...8..T.:...t.{.K!GS..P.....o.../&H..l..~.5.E..`_.p...ds...4..u.C..m1$.[...#v.p..E..0hs0....#eLiI.s.j......:.....".../...yI.J.....*~.....c.@......f1.R....l.(>,...H.|_.B.b....V../....^Q..-..D=..mG..V+.K.hJ.........../...O.CCE.)az=..V...af.......R.!..,.&..Q...y.c.z4.......#.j..r.Q.[..?..N.MX.y...._|z".W..7YQ.=.f...d..g)...vO..........E$I&....~..`.....N.'"K...1.......~.S..'.m.......{../"..m8..Vj.T<B[...."..et2..NS.+w....P#.....6I.o..S.....Y.R.lT..4..a@$f...>S.x.$L...a.......&.6...W.].Y7.'...$x~....l0...G..=d.......?..J..zK:..J.....l.. ..y...].{K$~kE.Bt({.!.......~.a..%..............!_[..s)...-...$.....s.B4|Z.2$...J2p!.k+I..>..p....B......[...W..[...........C.q0....'..Y..5>06.....W.....I.FO..%..1.{b..J.?....u...g.......E...............T{.....'g.....m..1%.w......x.6i....?...t..%...w:.^S..m...:..'O...94{....D?.*..].e...@0..u@.'.p.JH~..z<P+..i.K.)2.~....xt....l.P..H.>.L.%E..pS.........G4.H..Q.c1.{.o.EE..mEY...Q..A..hg.".~...?...]+P..u(.W<
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):5156
                        Entropy (8bit):7.9636384096957595
                        Encrypted:false
                        SSDEEP:
                        MD5:73C91016E0B039C2CF677F3B4EA5C722
                        SHA1:F3510E4364FFB2CA0BE2A2BCB111CA36F65C4259
                        SHA-256:70EEC19BD4261E2E5BC0C420FE518CE5A166079260CE974AF7D05347EAF0C431
                        SHA-512:BFEE6A3D76CDB056F0B8D66A8E85C7BAE329D482D654D18DA3391FC790037AAF5FEEB88A04571E24F893DA40F4DFF20821D4BAD5629E9F4D95B0C5B9250BC914
                        Malicious:false
                        Preview:...F#n...M.'.z6.|l........E....B.c...X.....U.Io....5.;p.C8..c.?....<....<.p....U7<eD;.P..KIJ/.)....la.*..].7!......Z..../....x......m.4.U..S....u.....e2...!...XZ.]f..#..<.?..}....{."b...2..5..).*.l.K.......&6"...|.R....l3.E...<:.............4(c.(..,......6.w....X|{Wz...6.~..3!...{=..v.S...Ej.I.nr.6.X`.......@.Z.O.....]..#..#....h. .P...`.\.E..J....._!fF.....%J.(h)R..=.Q.......q......=....M.C...3s.fsIg.~..nfO.l)9.=D.(V..>...>..{.E....=..Z .6e8.aF.g....!.\.,...u.yk.qIsN.y.._...Dl.c......\z.........i.f.<BVi...F...)..#@`p..g.@.#.d....o.`.Z.3A..w.@.B%c.w|.'w8...=.E. ;.>Y.o..N.B>.+:..ASsCt...l.Rl. .2x.....e..K{U......^r..w._.H...m...+(.E.^......m).inz.uif...~`....!8.......#!.n...n%PU~..k9......1 .rI.....;gC`!..|m..sA.9.E.F....z.w.9.O....N..m..L.d...ES.%..Y.*:..'.*W.d<0.....l....{..w...R.....t.zR......,.............X_..WU..`..1E...K...w.8:.JV{...<.4..r.....C....#\..L.I$...j..3...{.....1U..."..f...........b..Nn..U......py..#.....=/.Y
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Secret Key
                        Category:dropped
                        Size (bytes):132132
                        Entropy (8bit):7.998524352353172
                        Encrypted:true
                        SSDEEP:
                        MD5:8A32FFA9DF1CA9999A0884D56DBADEEF
                        SHA1:22F55C02429B7211BE95D97D2159DF2EE9E695FF
                        SHA-256:5A543E09D19B05D6312385A58B30E59F2AC51A8E2DFE600964776BA659FB8995
                        SHA-512:251951320658613861D7600CE6E2F39ED7EA3B7E8D7BBA85C0A4880080AE10FE21A849B0640D717E547DED0EDA205A13817177E36F62ED3C799E6AF7C42F0A7D
                        Malicious:true
                        Preview:..T..08...8^...7..].SKC.NJ..~B....d..Oz...V.#.^..n...x.._6._..D...v..-.....l\qr.3 ..\.m...._4.f^Gb.Z.}Q......N.vUD.z.&"..[..,...>.{..wr..g'.. .d.SX.r.6..@.#..t<$%{n..).A.t.....B..a0.6......^b3.pk....K.A...0....wK..#..zuh.t^F:W.%..9K....v.RNP&..N=........<.U;......U.bhV..5...06..aw7..+....&.H<$f."S.I..W.w.4.j.]IZKo&Y;.b.!P~...U.X.J.....!.g._..J%...vY.....7..H.0.....SZv.vbc..Q...t[N...fJ~...1......n.uP.=pI+x2...>...P'.<......nK.|...:.....$.+$J.e.....~..W...:.a.K>r...}(.(...&EDU.\.N..&...rG.|"#..8X...1.c..g...Qz]3..m...5{......q.s].....H.m5....5..)3...-...9..n:P......a..x_.....R.TL). vV^.O.L..f.D.@.~C....h.d.`e.j#...-.b....Jx.sx.i+.3n.l...`..d..........1.........:.....v...3.....?c^. .=a......J.o..3I~A>..|.......h.a..vd..%.K.O...F...=....wnD..^+_v.{o...e|..~=..uq*..j....w/.5...L.'N..[...{....\V...........H....,?..Z.....\..ij..m........o....?.fw.&..p....E..p1.4PG*1?..5.....j..A.:..B...*...]....?/.....g...I.o.0.\...<.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):566
                        Entropy (8bit):7.616625516375614
                        Encrypted:false
                        SSDEEP:
                        MD5:7C9ECFE5AD4A2859B081CE78B8467CD7
                        SHA1:90F76FF89372CE841EBF5EBFF7F6500C87EA9B5D
                        SHA-256:F83B77941B2D5DF86F7B2AF21867D990AC68694947BBB2492F60E4674871562D
                        SHA-512:7272BC0FD6100ABE0DFCE5A193F6A48ED9235871FD93F12651A583A3657B807FEDA9303F15AE0323F41B6D77FE6150C0F70681F4429C4D2F1EBA177E20EF30E4
                        Malicious:false
                        Preview:..'.+cW...8....{E...."A...|H..S.....r..M.'\;..y.9K:..M......Dv2.Zb..S....bQ.F.i.......|x..1..|.No.........P..r..K.vu.{........T+y[.Kg.5.G..nDZ...-tH..s...... '..a.....Eo...p..V........Y..GMz.r........l.b.6....%....&.(...=P.q.9......%.>..3..pR.KCYp.y..F....`..*.c.k.3....+ae0.....qv...kR.b...Rw lMp......v71X.X.&./.....)...2X&.a..<.....6j..7[..).......d...|..i.?k\x.|/......r.s...q?...`...........%...&.R6?..T..._e3w....J...\.n..r.(.p*....i.....09.l..|?E... 08.C...j..ot....s..Q..Y..._...:G..h..r.3.Co....j.$.."w={..3..6..~Y...\
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1096
                        Entropy (8bit):7.8327041538782325
                        Encrypted:false
                        SSDEEP:
                        MD5:5DB818A15B3FEA73FEBFB2CC70162486
                        SHA1:66154DFBCDBCB4F67CB827994AE1C60BB21C265E
                        SHA-256:01CE2246B3FEFC6F6F5F55D56D433135F1DC6631AB05EB0A4A33F7C84DAAF489
                        SHA-512:0519BD3EA696825C6B3315167A2E15149A862A099AB414B7C58202C520521BD7FE8B5FD8E055D148CA99D584FF57E4ED95C12B74F09F5A2C567BCDDBA6286B22
                        Malicious:false
                        Preview:.0.n.v..B....y...;.k.0..5..<...k..q...0.G...jJ..u[v.......K8@..%2.@..0RB..0...&,I=.6.b..........\j.).kC....K..VOQbL.bXr<zI.i.:.*E.f..POf_-..O.....p.M4.....<[.x..`..:....vP/e.R...vu...._.p....0....% ...B.E..j.O.....?.;._-......_.."*.7...Qn....('...8.r.....4.S.Yu..j`p...u.vKY.Cg...C..\.o.R.g.gg7[Z..Tt.]......\....Y.Fl.x..F../c.dd..|.0...u..#?..b.[_..o.%..1WB..Y.Q}.C..d...c.g.a..e....Q.-@.gRL.s\....a.^.2..,._...T....v/..E..:J...<...b.=...q.v.....*.p..3.XW._L54.....>....".o{i..Q.n.H....|I.O.....f/JLN.....A.M....oX{..Q.i..|I ..7..(....gq..{....d.K:}]F...:.S..O.8..JD~.....6c.BH3.+..w.p.XL.z..-......4...;....B....N.........pH.&..D..Ly.qq..'.lh..^Tr...P.l...a).u..V....Q...3Ce<.zGMz..!0...qA.n.d......R..0..|..t..A%..{...W$;......#@O....~H....AR..G]..........?y..A.}.H.oJ1......Q..\....#..2...{....A-...I..N...4.z.2....Q)7.nh.....H..h...1).+.....AgwC.,......._.YC\ug-...'.W.......2.1..5.....Y!.......D.+t...h..!/..UV.......3N4V.R..K..DC3...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33298
                        Entropy (8bit):7.9954109530044475
                        Encrypted:true
                        SSDEEP:
                        MD5:CA46C8BD59D7739186AAFB2EFC2039AB
                        SHA1:E9D5E7A8A35F3E0C3B8330D3C90F3ADBC1247BCC
                        SHA-256:7FDAB57AB8CCC79C079E122FAA6C0E269F7F1AF739C41D978E944369D9E238D3
                        SHA-512:8F6C4676C612849D2716AB8EE1E0A50B9E2AF83A502A60AEEA9F5F8AF01A69BEB3B0E69D973DB576884D97D678B9D805CCC8CEA6D8278BA5AA867BE246CAD780
                        Malicious:true
                        Preview:.KQ......F.]..y.x..' .3....i..'..J.#.k*.....!.9..|q.d.............r@...ZN-..xz....rT..........$u._....S...nL.._.|h..].To|\.A\;V.r.+6...=._...e..:.....X.8.`..a..%.qB.V..a..g.?K\....J...@z3w........N.....V" ..`B.]...uZ....ucz.[....wq.p.uXu..-:....\..V.....;g...W. q..nLQ=..0".......O.A.y...v0.Ug.W..jm.5K..E...[n...I&.)......bry.E..@...voa.1W(......(......&......V..p.5.D.y..Z.N.....*.;}p.K1e..qe):y/.R.E..~4;.=......xK^b.:.j'..xV........c,...Up..\.Z6}.&.Y..5.!.S.TT.S..#L.wW.................Kk.. ..x.$....|9..$.....N.&.|.B.t.?d.|<.........?.@=;t.jZtSa.......A.(q.>m.....oY...\.^k......J2..|.V...8...x......."......(z.......=K]....sy.....#/.e..`:.V3.{..U.R)GZ...D...t|..n"..<..).N@..i....ec.....\..t......;..Eq.S...;.Sa2V.l&.6c.h@...].._.zg..+...Xq.....1lc....1l..l~.T....._..$Z...!.P.n.!...|..9.T.? ..Z....M.{F..[.....D.`.".J.k.F...b<r9(....Z .)('.T...*.M|../ ..';..R....(XA(.L....NG>yh........%.(.3.)jz.....k./..s..,y.Rh'b...Qb......wh....G.|_x.....l....C.L
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.612571329047833
                        Encrypted:false
                        SSDEEP:
                        MD5:CF76FEB04069D0657340835E6596E702
                        SHA1:6E18AD69EE55E453DA6336DD476BD0529C55E477
                        SHA-256:EDCE1DA6C808770BB5DEF1BA71C86EA6558756088FA4469CE58EA657FCF741A2
                        SHA-512:FEA8559DE3747AD8B8509E7E5C71496F5DAEE301577AC4950E421E660D5F8DC9CB9405BD5123E6B57D38478221BDEA7ECC6DAB56E876BD2BD2AF30D80693BE13
                        Malicious:false
                        Preview:..4..^..`...p..K:rN..t....m}..).*.0..S1..l:.%...y.p]B.)o......r.../gb..t.m..}lG.5up.>c..K.T....-9............3/K.J.u................GfE..b...T1...x...%..,8.s....;".s7.._Eo..GK.....x5.Z'...>..o....z.As7r...}..d.9.|L|.3S.....O^.WKv...VE.*..E.Q.-.T|..P.....;.n. .9..[....j....i.......\c!.o. ...,...=M.~.6.M..P\..?...M...lr.U.AC' `G..<a..8.>...m.....n..S@{J....+...L..!.'...d......EE[ew..O..8..qtv{(...}H..R...|....o^..'..-t........./.Q.......Qy.K4...J......D.....pf|C.L,..g.&...tb.j..8_R.[n.m..(X.A-.l..~....*.D.c
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49682
                        Entropy (8bit):7.995692574991689
                        Encrypted:true
                        SSDEEP:
                        MD5:A62C5B60B779E5D77B2085547937EE1B
                        SHA1:9F27B0FF91DC79A8643E2F6519AE5AFBA31EA993
                        SHA-256:43B19BDADF3176B5811C6B5D22FEE7D79B368E7B1F2D0BA93998E9AE3AD904FE
                        SHA-512:C7F2636E79AC2666B5621EB1CDCBBC3E8D05BC489EB4E2B87C11C1728BABACB7E6958DB878AB3FF40FD96D08D367A279FD36ADD035A419465887D787809E7DEF
                        Malicious:true
                        Preview:...5..8..U.V...E..62~L..fH...a2#...6F...l.{...|...?.l....._..V...y.6X.0....u.itH.3..o......\.5M.UT..0.|9.O=..?........s...8....b.LH.(....*X...7d..+yc.u..P.....y..../]X..R>I..M..e.16]2.&.I....1...!...N,I.:.a.....s}./.?.b3..{.%...T.p.J*.:P./..u......08-.%...?-.hP.{..[K9..Nm....`_...s...5.8....av..g.......3...0-{...=E.-B_...K~H.m...M....i2.:{O.3...;r..UD;..D.P@.M..Z..M..C..L..k..3.PD..~.}x.7...).{Q.....Rvn.,tH~..v.X...z..P..k.R..W...oB~...q#n.C.S.k..]...T.[.;O..d....~...9Z.B.pR.6.9l.p*.'T.]O....e..8yH..C..B\.....4.~;.U}...G.@".W..8(.o8W..va$.f....R...Vp\.-..zl>../....(a:z..CB/.#.C..f|..._.?.w2..^zZ.6.:.......5_..'I.?Y..}Pd@.......L..:\.!.....C@`n..h.3.1%.....Y".#.P{..z7....n..P.BP.".&...... ..VG#_..j.Mmj[H".a&w..}K:.yUd....M`.dA.}|e.94./'#..`.p.....e.._./..V:u.#qo..n.+.8e&....fN..v.4.aq?..%...).L/..MEt..`.....7../......hE.{..R.I;...M....@9.7..9...G.~..f|....[Fk..M.QC....}`.29.Y.R.......&`..E....b.2._.:X.lV.}..AL.r.a%.BNe.6.~
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33298
                        Entropy (8bit):7.994718528632719
                        Encrypted:true
                        SSDEEP:
                        MD5:CBB81909D5845304807D96473BB1EDF9
                        SHA1:5DF93C5D87428897085CC5E56C6748F6D5D60900
                        SHA-256:8D55CDDF10C709A47EB081A2A39A81042754878C78B88F9DA83A500EA8E238B1
                        SHA-512:707D66D868E9BAB1D0CF2984B6988769F84D50830B7759DB2F9A2913BAD2658FAD48D826F389E59ADA5C22C2FF78808009C729496B9B060A2396CFB09CE86BAB
                        Malicious:true
                        Preview:_rN...,6Eq.u.~drP...qp..C.\.DB..V......P...:`6s.~6klw.......vO~k...r.J.P.U.`...q.6i_.'.PY@.T._....d#M..a.I).<....H.N....."^".Y.W..0r;..$I=...".n}...fs.X..1U..V...`0..#&..=..i..-`.5.....#....J.Y..b6. ..C...|...2...............*.e..nG.n.]...5h.....xi...F{.....8SS..83._...g|.C.8.ah3.2Iz,.....p.Z:Hf..w.4...6w.r.q.{.1....Z..t;... ....S>....90>]...X.\......&J.Jw...$d.4....'.;..).Pg....H....jR5E4M.$L,...m.(*O&..Q.G..pHu^....v.F...H.....%...oi..B..dJ.r..`..I....<!a.^..B!\..).....LV[a....y_Dr.c..Peh.9..G'...q..b.K].|......o...W.y...'^"*.4.3.C*Z.Pc...:...z.dM.e.*..FK4.Y..r.}.qF.[.#.(..H...:..cKg..H...M%xb..... ..b-d{.$ ....I4..lA..^.2..D..r..|...PMl........dk....n4.I_N.K.\....(|.(..P..y..iY.T.;..z..j.t..2.c..(..<*<5.......[..........$`.`.E,....~)Q...HgF.i...."|d..9.zYm.....IW..X.W..i.:W...6....b......Y.a&.Y'5..h..-.z............L........`/..+U`.q.o.d*..`....[N.7..-.M..o`.?.X. l..~.U.....6........P+$.w.!...(ll..Z%.#.ui.|<;.]:..g...M..drxy
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.682419536611333
                        Encrypted:false
                        SSDEEP:
                        MD5:43A9A6B39BEDE45AD35E12E99D847585
                        SHA1:F8B20BDBA321968211DA013CDE8951F7F5574F8D
                        SHA-256:0B3A09C7065F3A1EEFCA18DFF84D0495F2169A6E2D8EC0B7723F68D6668262DE
                        SHA-512:2AEA774872B1A84AA193314FADDDD015F2B17BA39D073EBE7768C1E659905B9D70A0C7F44CEBC01184E601E27F8B1AA6A426E3371C620860685B5DB5E226806C
                        Malicious:false
                        Preview:.<=~e..6.kA.Q.$K:..;e..........M %^.9t......:.1....\.?U.yG.k..d(7.V.........5.....thZ2&1.. .9.+Hq....},.8.7..w..X.....9.....5S.....i..B.@u._....m,...B.:...I.J.p.....q.p......j......R..).Y.R<>.....%H~Xd/u.(Q#..X...;.3R.o$7.S..RLAM..."...[b1.F..}.#)+.....}...]|...a.Ww.0..P.Cp2MS.=......:X.^>..$....... T........r..x..2/.rI.4;T.I_Y..]..ol.f....\-&G.0.........[....~.j.bl.:1W.=e..z...u..h..d......E..%....x>..ME.e.C.8..........<3J\4...j`......D..~D{.J..M".|1.gB....:....l.L....j.<..p.r:.O.....q...,......p.....D
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49682
                        Entropy (8bit):7.996845509872262
                        Encrypted:true
                        SSDEEP:
                        MD5:125C5B184106F1DCE54A152C2E4D0D25
                        SHA1:212B1CB69CE2F4611195873340D3BD57C06F96F3
                        SHA-256:CA338E4FC099991D0543C2ACA2D42A748585E8ED7A728F6C195A06E0EEDE4B3D
                        SHA-512:5A48772F4DA1A4F39EE5F68B17399F1D8DDD68F332123846C37AE1876A0B0767C579E2D6A89C5516101B77D4F3B447B366C58758706D5B3619D2D2CB7DF408CE
                        Malicious:true
                        Preview:.7.....<.[K.:....3...oi....G...c...euw.Rhv\.<.....ba,.z..o....u`..~\..u|...?~...Y...5=.m.w....VQ..c.Z...W..I.j..2P...1?...w.G#..wNh..3..\N&bs..B....b."....<.C.h.j.R.cP....^?*....y...P...(...N..FL...i.&...e....Xa.....D.3..\j..t......8..`@....tF.)a.....^.P...-...{....d+.oT.@.j.x..ld.eD....u.}.....l.....[q..=..Mo..v......P.$)..j....S..o..6R.U.<.4.f;..F.*...V1....8.%6.n.....U..>.ojt..........6.~...N).Y>..........9...n...A.M A..t..&.$5.c..I.*.b..G..w.............#...y.......32..l.x.....Y}S..W.....{K..#..R..S.!...B....M...}.......'.,.Q .V7.T{....N..*.y.I..Jm+.c.....L..!.@..6.1'.{..0...j,W.\]Wm_."....@.....M...).d..i;....m'....x@.!..:C..i....4ix.......A...6.B.'...('..@..Bc..*...b"lk.....'J........c7.M......$f.C.i..w.}N.>.n.._tD`6....R..ha.F...%^}.....^[.Q.k#...M.;@.'.X...c$.].O...g^..&..............`[.p............7..@h..E..CM.3.z!......|.A..d..*.1..l....d.4.a.VzA4Y.......-..6.z...V..Cge.)...4.......D..k.2.|:5gr|...G.1.].O.Cp.Sv.>..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33298
                        Entropy (8bit):7.994153721624563
                        Encrypted:true
                        SSDEEP:
                        MD5:8F60A0180ED2C370D50DAC4FDAABA989
                        SHA1:A2AB91FFFDDF1AF2CB279D7EBBC77C996B4B95C1
                        SHA-256:4F08E54B05ED6558333B014290C789893753503FEE59F37FE7EB8E81C14B21D1
                        SHA-512:DFAE1C0846ECD03822311708D96B8FDD761B997D2F041333E46A9EE4E2D6019F579B382F5B29729D15B0815AA166F5B2D7A33E6ACD73534159E9F0CA1E6E5437
                        Malicious:true
                        Preview:....n.X6...Nf.QF...Q........k..k.y.l..t..A....Z&.U.6.dc...>.jA.`g......m...X.a.%...H...:..6.A$...$..........\.53.%t.0..@@..x.....8...ok...y6...*.2(..w03C....TX........(....^M....~..........`.F..9.F.... ._..5T/qP.Le.....k.BTj.....?]-.=..H..M7.S)......@@Z.&..G..T.4OhZ.R.....0.pi."..tY.y{2.p]..+..g(........\.f.....<w{....s.....Ja.v.x..d..+.....<. ....V..h9..]p.I.d.m.0.X.lJ.'..$S..`.\..1..H1.-...>..J:..IM.x...d..I...@.....Jd....W4...b...}^..#!.s....1.Ah......a.9...R.U._i...$.b.h...V$]9c..D.K.T_.o.~X._>^.^@!......8!I....=.Sd.TprBE/...g$.k.>.Q....:..(.."..=...U.}U...WI...)...P..Y.):....... ?.u2....Nr.&p...h7....xK.g`@.(.@.k...kJ..x..^o..9...N's..:.md.*.d8...qU7....w. .-R...j.g....>....!E...*#.d.(d..Mf.?..1.."P.bf.i..p..GW....w....9....^d>H..g..[.5..4..:.H=...?..~....,.Qv8.S..1jvE.......I...$^.k!@Q....u..#.Tt...9N....}0E.L..IHW..a....3G^.VA..b./....1o\$.@.ik.J.....!TR...O..+M....:B...a.........^..!.R.<'.)....:.]K.q...A.C.:DgF'.67..9.:.H..k...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.604270457575309
                        Encrypted:false
                        SSDEEP:
                        MD5:CACA00D3D0FAECCD9220803AA4782E21
                        SHA1:E00F1795AF821E40E4AAC14894F2E7781BA4E495
                        SHA-256:5000F2FD69D2F64B90211301E4328B9A0121F5665D545FA6C38768776DC062CB
                        SHA-512:B4E93D20BACEF12FE9E782E61EF404331BDA930942E6424D7CA1C623DA243954EEC45CF04897FC4773DA70F04E0F78F5005B8337D8CF357E645432AB8562F3F6
                        Malicious:false
                        Preview:.O.[...a9.U...:5K:....E.v(...r.Q.a..e...y+'..?c..^....Fc.....6.Oj'S.\...:.]C..*kt._D|..iD..w.6.w..5.iG..........g$.'I;Tj...G:..,du...@%........G.a.Hy.C....q..k.4<...........g].'.t\G.<j!3T....vQ.,d:.d.Z..,..1.x..N6.-...qf...5....j..^g.....D.P...'...%RDs.]Ys;V[.~x%TO....jq.z;..QM....~...V..L<.c\.4z*f...2O.$.#|.C.$...h\#hR..%.~[~6+7.q.#.:!.$}<.>....O.H...t..X5......F..&r$~'SGd....pv../....^.8.n.....'.@....Ud...T..-..yw.a...W..K.....2.e...>f...x{..p...M.4........F[0.|k...J..P...&y._....k..)....f.F......
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49682
                        Entropy (8bit):7.9965244696941085
                        Encrypted:true
                        SSDEEP:
                        MD5:903A58F2B5F9CD5687C3FB1808E3F2CF
                        SHA1:667233CC636E405200495403752212B85E200230
                        SHA-256:ED172DA2636F8A6F7C9ED18A47889E97057C0D8C8F18AD5F3E8D03473972D78F
                        SHA-512:A5BDF73D2E700CDA1F3B56CC28D2EDA63E8C90F23213907FA94FE21A4FBFAAD159D7BA74177590596E33A21BF95226745CCC1BC34CB9A858B1136084A511C953
                        Malicious:true
                        Preview:"d.yM..G....B}1.....d.-.".'.f.l.O......Fb..+W.......,..D.._|.Y.pA{7.}e]j.S.+.~r..c../....{.P.6..T..L.Q<.......Y.;#...b.}.X.j..?.i....)......*l.8..F.Z...+......m.c...@Osf...jb..:..u..|p..#...............D...Y.........w.:B.0 ........t.cF.M.h....HUo$zG,.Y......a..=`..... ..VU...>.k...h.G>.@.Cg%.)...f..9._.2...j_...3.h..%I..!7...v|.".....j..Z.u(M....%..h..$.....a)..!...Y.Wh...zy.60..+..$....i0AU..Y....c..p.. \....u...!. 5:..]bj. iY05....&3%Z..1u1..p....!....1...S.E\....T?.......uOL4.<.4..j;D2..Bgg..J.C..7..[.2..H7U...t!...>h....jq.G...Q?;#|cC......%|.).R.I.]`5.B...V...[d.{.....c~.....lu^.J......E).\z@...../...4".y..k..5..Y.|#...~nc.3.1....L.9.RS....r..2A...SMz.M.(}q..+.KW...1U..G../..td.YEP.Q[...y....;..p.X.\.6..3...w.L......*.Su...u......D..._...la....x.~x..L.......,..;B-.Q...,......H(..D.f>j....r.m...#...v._...;.....9.Fho.%.m...-I..M...r.l.QS..XXQ.=j..h.l|i.n.....5.;.Q.....0...2..-1..S...c>..gS]..2._..:MT7.'...(......A.=.oc..c
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33298
                        Entropy (8bit):7.994469392491614
                        Encrypted:true
                        SSDEEP:
                        MD5:67AC4D26ABA424A7BF71028403822811
                        SHA1:F4712FBEFC2007328EC88530F50963F316479E2A
                        SHA-256:AF8AB77F59F0C01404C52F2CBC8E39B1F7621062A018279638111A261CCC0EB6
                        SHA-512:57AAB262E7B15B93D9B996A587DAE41B6AF6F8980775C4B81167A7530BB8107ED2DDEAFFCC479BC3023CEFE21AC7BC9B4D7AD2ADB775203931F4BFF155C6EEBC
                        Malicious:true
                        Preview:...[............e.Q......\r.... o.y.b.|.4,..(.....G..E.5E.N...A...6...O...%.u.....!.(...Z..Br...2.........p.....'.T.8...5.h^e...L.r...... %.m..r.....m`.y...G%...f.I.5...B..9.O?.W.....H..G..t.8.s..{..c...}...P'...&`Q..V.....b..X..^.....q{.N|...K.c.[h.XCn....d...{..'........"T...4<...t.BU....BAr?..g..`B.kT.+y..?.).>...u...Tt..$.......#BetI..Z.-T..........rz..s?T3..d.#.di.dV.^...S.X.T..}sV.....e.C$Hj..x._..d...5.!;..M...tQ..^..l...K.k.Ms..j.Pv...~*..?....e..o..P:.b:....IV...I...].....yg.e..!....'..gJ....>*.J.H...JV..N..h.l(.hrq..g9..............^.....".....Q...#.'..<...P.0..D...\R...]#...h.T.. .//..Ny.|d.0x..1...W.v}...m..,.....L..;...mP.-A.....N..w......}.[.s...F.?.t.V./..cV..q.#.\.o...7..L.Xy.......}........"..5PsC....W.(.&...[D...>..Z.../:.+.......3....HT..v9....<...w..yZdm..2..M..u.Y.h...g.10;.:.+...n..\K\.....3<A:.1..nTQ.6.la.L.^.....=.}.9...........ea.......}'+h.zW.o...RI's.. 0_].`a...*...(...m.........8.^_..U&...w.O....jVg
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.615815338599738
                        Encrypted:false
                        SSDEEP:
                        MD5:DD3DF5B3B11DD04845ADC77C956E440E
                        SHA1:BC70935429CBF270BB082337285586AD47917579
                        SHA-256:648D5C57F906B208D363BBA929783AACD93E394F1A32F000D3B622964CD13779
                        SHA-512:E695BA6045740C09D34AB3790EBFD1B187ECA482A8C9036A90F4BD83F5A149C4C5B0028C8E3AF07933AF0E34B683F6A5D66E312C1A3F7A81D01AD2E03D4160F5
                        Malicious:false
                        Preview:J....<+..)`.....K:2.c%)....>-,N...7F.....R..n~.}.5.*..3.b.3..A`.........-]..ts.......[bY.'Px.......F.q...j....k._....d....2....`).55.".`.....]..U=.T.t.R..K>./..?.c.../.....d..>.\2.DrVf.\.............u...[..2^],PJ.g.(...."...w.....~.........5.Tq..9.<."..iX-O..!*..OP.......>25.@.K.5A|.W.-`.3Ac.(.M.5...1l.#....jU0..S,.....G..fQ&..`..i.I..)GH.F..?..7.h9.T..._.fS...m.E.IB...M]?.k.Y..........WX3...qZnd).Nj...h.....<S&....8.g...^...!....a... ...J'..*......A.C..i:...w.. 08ZZa..[...C6..Q.Uu.K...AgIv...[.....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49682
                        Entropy (8bit):7.996638923011128
                        Encrypted:true
                        SSDEEP:
                        MD5:ACF675F31FA34C24A7F7140DA737F88F
                        SHA1:AE87250F414D566B6E7D761861DB58A9F995D020
                        SHA-256:35B09C874E03AC21D2F49363BA6D6C1218A724EAB9EA8CB774BB73E24AE10E94
                        SHA-512:86861723E9979254F114574BC7A7F34DB7E28287BADD047517F2FCEA9340BCA6C0357201C13A6C2BA100E6693D89742144287E99B1027A55C3B526D8EEC0F30B
                        Malicious:true
                        Preview:....K.k...sN4hl.RG..p.I........a%....~f..?L....q8......!...c.I......&8;.N........M.K.......j?.]...Y.e%.M.*{Wj..H.../4..T.=..`2...#.2...c#.i..j..<IR0.d.>..@nc....W.M?f.}|...?...O4^..'..Q3.X..c.E....6QPI..+C...b...K...Y!.k..b.A.e`19)..T.(.(:.}VdU.u9..(V..vlv....f!3..........-.>..`...L9.,d+\..9>..4j.....r..!...Z.....]d.4...=..q.?.8y.....qqDT.8...F...S....%..J..X...5.n..?7 y.DI.J.......m..#.. ..'.h......@..)...XM...(..#..3G[...S.?;.f.@....*9..f.;...u....}-..$..8..?.6N)"aU.\A..!....y+G8...X6`|......B.:.N..w..B.;V.../`,8{....I}.....l....#.K.G..l,.c.}..%...-...r.R.QC...H.....K.y..*....o~.v.un...G...p.6.`_]....b.7W..!".M.K'.O....G.....b<&.j....0.....h#2]1S.....'..q..&....LlYL.cT.......Q..Y1.<....5......S.!......^..1k.....=HD.wI+T:......?..X.z.V*.5`P.....'.^.:1..Cu..W..S...d..r..$..../`)...I...9,E.l.x........o[`.iD6@.....lM+o.....C&.u%..]).T..q.9xB..(.`|....Z.;....gGOiT.cq....y.{?I 7`........7.BM.G';......0.J...W.bP.m.pRs.du....L.?...o...e..Z._...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33298
                        Entropy (8bit):7.994712868169059
                        Encrypted:true
                        SSDEEP:
                        MD5:D36FB01783A76400C900CB425225A043
                        SHA1:32B2844D6330F325A7C610F794ED2AC60949E9B7
                        SHA-256:88D6255E1BB0A88C37EA575ACEA4B3989B4F24CF7A29162A3F8F39DA87BB7C80
                        SHA-512:EF19EF39B4A45DABA3C5EE69F4AC933CBBF26AB5443E1C41061F8D2F1667E647135C56DD2B7E6C37F38240962A904A500E7D745C7163C516E8105AEEB78AC7F4
                        Malicious:true
                        Preview:..]a..Jo......mtN:a.I}.]k.ax/.#....%f...(.V.cV.:=.h.l....-..........m.N.k.L.1.2.u..3v.W.w..6.....9...H..q.u.sjV"..Re....c7..U....G3..v.A..L...P..&....gb....N|..5....z.p:.._&.%DK..V2`..'...Z.e......@.%&4.d.$#...DP...f.s.Y..%.!.h..:....w..&.iL.l.*?..?..y....l5..i.{b.6..e.P.}.qOpr*._........v...>.....l..*.%.M..~.....L[-...v.,.j5....r..(y}..? X..C..Bs..(.'`..V"......\...S.$|.+.A..6...^sM..6'.~...;.5lJm..F8././.6|;...gz..t.Kk.Xj...$0..V... .e.`.v.}O..f_.7^.!5.<.Jy..Ep4A...9.tg....94.293.Q...K......e...._..e%m.^....yQh{j..6.....gF...pO.....I.:..l8.!.x..+...T1...!3..)"..n..<TH.`~.0.*.,R...kk.....@.;.!..].yq"..w...V..a .l..E...9.H_..8..`.%#.o0.........la.NK'G:..FqI..B.Q...hnv..6..?.C...|.X...b..I........9...C.c9....V.JP....>.).w......`...}...&..0..=.ULDZ."C.;.Mf>.x9.|......u..D.s.Z..R.$..!`..|...'..F...(...A.j....#q.?....N..f0.................dx:..Y`.0E..K.i...&i...x....vG,..j\..0:%6.$i.j5..0.V'Tb%U(h.....}....nB.a.C.z.>_$.......(5........7
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.6433870611901416
                        Encrypted:false
                        SSDEEP:
                        MD5:C7920F46F35A0E975D7C9E28A87C9D58
                        SHA1:C39C9A682C8B8651C91E365A6B52F4FC2783DBC7
                        SHA-256:BCD989575A90386753B979B2EF4D247D616A2E2B84BDB8A44B4EA2226AF97ACD
                        SHA-512:2B57EC0CE26AD0DCECD720A345B9CFF3DB8A82BCCA0990069292F5C940CD337B2AD41E4D3F877F255DEEF450F32D38069091FFFF0EBF4D12885AFD88DC2D7801
                        Malicious:false
                        Preview: ...r#.k..=jl..K:.H..^I.n.N~. .j.Z..=.......dS%...8.c.i..T.Y..-...._..y........T..28>..AC..9~...(.|..2...?.,......q.<...T.r=."\.9...0sq...X............T.......5p....>.[>h...E..-!....B..3]...F.-.B.4.;...!...|.....:....m.+.v.X4!....a..sU...?.j.....c.Y...g. .'...J.../4.5.....y`.T.Pg.I...v..z..M%......@.x:.l4qpP...&Q...u...-...&^.D..~...X..^=...F..w|# y-.*.l.^.k....'..M....P.RmV.......f..~.J.I.h..(..J.;.....)~.....n..R....M=b.2.:.....+.q...V....7S.Q..F.Q6.......!.t."k.oEO...4..z>y..v.JO..O..b.Q.Z.)k.R#..Y.J.j4.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):49682
                        Entropy (8bit):7.99695270753695
                        Encrypted:true
                        SSDEEP:
                        MD5:C4C3776CFE8A20DCBFC8BEF222906C2B
                        SHA1:2C1B38D9BF7B4CAADD12B23701BE31A70865BCF7
                        SHA-256:3C35620E8E68A74D90D785A711C0B12D07BAEF47F7BB7E6772A1E60DEC74B075
                        SHA-512:8FFFD312E33F7072DC3915E6440D2F7BB7FC83E313B01210AC28A24133E20E7618DD39DDF0EA792B127C45134AD9B8C67DBD00BAABA4B14000EA7351AF8EF6C2
                        Malicious:true
                        Preview:.d.)a...s.;{.]vIC[.a....f.4. .p..J.?..,7...D..T..Jk.]....Lc....y.7^...Jj5.s-..L.....R..Wc.."..U.jQ$;*Q..Yl.>Go.......f.......dMb.If............;v....@...hw..06W.......&L.........,.?..v...N.;.4.3q...+.c.hK..d....{<...../'}.l.....K..7.0..m..V.NV...}....8*....=.......NJ......j+.0.4.O1.^~.eru.uR..\x..*..|........Q.....A...C.w$..m....%.}..y..(.......W.$#8..+..&...KwO.w.........4..g...TP..E...W.;$....d.g....&..m.....2...".Q....0v....wu..^...!.=..9I..C.3....j..=l.>...._...~M...=h..Nu}.QN).....L.y....Uo9..8..g.!..}.An7..s...@.....I.O.....fz.L\/X .b.....vKXO......._V.8k......BU...=....&....rL"6"v}..l.,.At...#P........om..u...ope...S$4......d..Mqj..n.z...i.h...@."..J..v:.Z......T..T|. ..E...........U.........ynmg........#.v..@6..._....8_..fg.?..Z.._.m...@.7p..w..Mw...n.)..\3..T'...t..:)....l.,].Gbqpj...w5.F.{.J.}.J.=..mB7........XO....tp...(M.wXg.....='..s.,.7... ....8.o......4'4.Ne.*..m.qFA.tUh...s..v...VM....fK.....r'B.LZi.s..aQ.X......vq(s+..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33298
                        Entropy (8bit):7.994229649822899
                        Encrypted:true
                        SSDEEP:
                        MD5:DEE48C4366B91F8580B75DBC5BA95778
                        SHA1:EC3EE2DA0E242B7CBFBAB09BAF8ACB8B12FA26B6
                        SHA-256:3FD15FC7A3024D8EE6E011413E7441E66922F45B5EA1F9C1A36B923F56BC6C06
                        SHA-512:B9399B8198AC5D6EF4179975AAA03CFFBD540180D08D77EC4D28A84B0866655B15C6BC3708D6BF38C07C821A6C92AF5E473A10A88070604B8A7BF2345C60E2E2
                        Malicious:true
                        Preview:.F..^t.`...O...@....8.j#.....t..h...il...j..x......J.w...G{=.A..6.|.B..N{P./.n.s.C....ay..P......~.p.....l.M&.d.m...C..o..d...Ce@h-.@....r..h.._....[.0.T^..*.f.V,Z.Y...iz.^.Ff...M\.:=q.!...........g&..*S.Xu.~#K.1...W.m...a.K.<.....S.K.$M...........H.TF1...7..T..i....y..F}..aA........K.......0.|.rsD...1D..FX.S.........<3W..7.*.}Xz....!.......o..F..mH...t...."N...K.d*-?..........)5..S......1.-A+.#...'E.c3..h...t...$......dg...^W..P.._..a.zK.(1.Ncv..WS8.>S..0.A.u.u....l...W.J. ..kn>.........q...X.p..F.Uy.......z.7...2..i...`./...9.O`...?l....Z..{*...`i`.D/JW3T...|Q......5.W.G...o--......O...X.Y."[.$.o2d.P..s.$2N.&..!.SE?"fJ%.G.#.]....s.,.?.D|.?........U..RoSS..g....V..)..:.....w?.1Y.. .4. ..F.'...u.........)..B.s.3..\.s.q1.I..-).Q?..*.g.._...\..Z.?.S>...o?|.%w..9E!\C4/my..s.*.p...s.#:.{.oR..7..o....>E..H.tP..9.....,_7c.S..i............ .!. .W...\R.P..:.mF.......m.0.....*v...b..........p7.d.5.Afh%0....F-T.mSa$. .W.Z|J+?..h.c^.....b.&.....?:.Y.e.bs..z
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):7.640331788523678
                        Encrypted:false
                        SSDEEP:
                        MD5:7A61D5215A5E0A0193A28DABE1DE468E
                        SHA1:E675955AF4B04B4A5DFCA82E2686D581D3A57D18
                        SHA-256:23FFA5F8B6A8C40EC479061ABD95376D2313AB1DF9C7C83B316E125DF6726C1A
                        SHA-512:AD909B9BB0B5F65A9753773467861E0ED55A6CFC7EB3BE2560D30D5EBEEA16E1AFBC938744DF4EA20CDC37E3C40569276BF1A6C547243FC0B97733A952A9DC10
                        Malicious:false
                        Preview:....Kw.N.;..s.z.K:R.W*.,..%R.R5.!..B...*\qo.6..;......@\H1!.2...].0.R.R4c..J..w(.#.T..../xjo.....u......G..\J.(A...........1.A(.G....8Z..U.$..4.....J5.n.K..6$)=r*...YIO..5.%m..+..I.4.1......S........S..."...y8.#;x.h..L.N.-#....I.j.xQ.,q.;C...v.....%.8Q.X..ii.W.U.l.x....T...o..B.ZSaT.C%...@..2e...e..o.n.Gu...k......o....g.......".1.2.c.U.'....H{....`..n0=D`.(......Q...%..0>.........rC...&..Q....w.Kp..p.R..oEj..!.n.W.....uRve.$.V)./v.-.5...O)W .L.?..^...KD..lQ..E.h.L.H....M.....O..ov.~[.J0.H.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):590354
                        Entropy (8bit):7.999643529549885
                        Encrypted:true
                        SSDEEP:
                        MD5:DB30D8CC4016EE8D18E27C23CF012467
                        SHA1:EE0735BA756767C09818A15E48CE4A1EB2DD1171
                        SHA-256:8880993E007EEE36D86644980564E2D2CB5B7D4DE3F737766EB573F73FF19D65
                        SHA-512:EF600A91CD096F9DEC84744B38B452B940BE759781EE8FFB1A2B78E88F60D5A96FAD333BC1BA1754D291C11DCAD936CC326F7FF6AA67D5A3E01C477EFE7CCC5C
                        Malicious:true
                        Preview:.|.e.2f.PO.'.Q~.-..=....9n...;1.Wu...a...nG..1.y........B.....>.!V......l......x.y.y.....-*.ca*H.-..F....b.`=Hp.6...z.@.bh.D.G&.....j_....^x.S.h.e..,.:...U.}.=a>B.....j.A0.[..h.U.].0.....|k).PF.....a..... x]Na............=..n(...U$...W.P.'0.IJ.C......d.'(..Q..\a.........f.g..BV33..P;..&..~....Z....I...TE&.....l(.Q....Wj...v.<;..M$.^w..qVz..d].T..P....Q.J.P.........`..A...j.Q.n..}....R...<S1.F++..hl!E..>\G.m...T`x.o8..........y......s.....,.4.S.....*...r.o.:....*...eQ.gQ.S..N..j..C...<.K...G....P.C<P..6.W..b..4t...".La.@....(.Rr..>..&..>.w.l.efO...m........e...v...............t...J\..`..Ox=q.F..vj...B.&.7...GO...e.``..VN.Y...G3..."N.k.B\^[...h..M.TO.C.8.%..S...e......P.0..G...|..2p...HY.#Y..0;..3.{.F.?kM=Y.rt..X.O7...]7....Q.h.22.....[~<..+>..d....0..i.Ay...*~...#...S.......(......Z..:._)..Y..O..2m:.-<.eV<.w._{.j2.;....r......B]K............X..=.6...v..qV4...r..n...c........AW..%..f.a"P.9CN3...B...MRA.z.x...r......q...t.;D$4JV...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5614
                        Entropy (8bit):7.971429371441884
                        Encrypted:false
                        SSDEEP:
                        MD5:F484479CAFBBD25CE0B55FA978B143B0
                        SHA1:6654385717AAC69F2C9D522B356D64F4049FF147
                        SHA-256:273C2B29D9CC4A3FE409F8778DD9E3181EE67A70AEB4750DC21FDADB37DFA872
                        SHA-512:C9FAC82F615199FB768D78EB97BADB5A3D1664CFBD0F28A81248024B46F72BBFC5F2E73531367BE3EB90B6DE3BC70001E31E7DE7C3EA12831330D4E93A9F76F4
                        Malicious:false
                        Preview:w?<j.Qe.c...5.j.!..n..ar.....a..A..(.....]_......$...6{uC#..=..C..........j..Yx?..@...S.=c...+...Y.D.#...!n.^9....\......;.+W<v2.jV.n.;..%....px...-...c.*.=*i...{@.1Rm....O.x.Ky...D...g....=.s.].M;...8..5...W...E.CB.!.....U..7....yc.<....L.w`>.....x..!..On...N.S.H(..0.@..y...3...W...^.D...A..:..f...A.bv.9..$<v....R..[....d.....)N.........L..Q..lj.7........G>..+.K.~{..[I..0........[hB..B..:..u..6...E...<,}.&S...S!=......EbR.z...AGxV..bz.N\lk....2......P..../.xJ%...[d.....m..[..r[...[.$T.v..x......R...*+....4I....%|@.h...9...T{WR..{.o.....~F+..{._~&.Kv=...WQEyp..=98...!.A.P.....M...'+..N...RK......\.....8$......$.% m....o.E.34.f..z<.]......r...m0].1\O"...?.-.D..?./.....V.....3...=.~..y...4...0..........x..8.q>&.G...t6...:.BR.IP...z^%'..9M.....'.LT.....<%.....6...[d.X.....X...~....[..0...nFV...rW.v...H.....(...........&.a+..AD.~x.5.."w.^b..d..0.X"V.H......V..h.B..'Z...ig.n.c{3..l...._v5Gt.KRi:.5...f....e.1|+...w{\..u....'.`G.0.S...\.. ...S..0..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1110
                        Entropy (8bit):7.8400345611257105
                        Encrypted:false
                        SSDEEP:
                        MD5:7D0B7892FB97C00344DB84AE3AF24DF7
                        SHA1:37B993F7ADD1BBA2E7E0B0E2BB4E5959EF396D86
                        SHA-256:C8FB0E228463728F5E744DD6029DF5BFF0761FE6D883362E697B73163163DE91
                        SHA-512:0730797E74B95D7728CEE42C05E9E9AED0CEDC08F15E93F92149471394AD9B7011BB362A9CA1BCC2CA4B9E7019157F537AFAE6B7E303A75FE04E1B0838D79C6C
                        Malicious:false
                        Preview:V...jD..-\`.;.....|/.Q2..r.k...K...R.TW.b../..H..w..~b"..:..y.:.'G#..%.iG.=..d..b.I[L.....Y.i.Pd.{.V.b.....c.:3XP.[..K...R.?.N.E...R.p+.+#*....`Qt....O..m.Y...G,..q.Ye#o..H..Rb..?..kk.....FQ".>z...i..d^._...?.#...5....."...#y..l.L..&(;r.'.6...w/...*..a..7>.I;.W.P.....{P.Y-Hs#...3.. .U9{bu...e.x8...P..i.N....y...p...;.s..m)..3o0...~...?..{2......V>y.5....V..;...x..Y6..`.6..=..8.kt..9=%.6.#..3p/?..(.YH...~....|I:..%....K7.(.]n+.H.*x........I.*.A.yh..............5...;Lz...s/h.:..S.E.*.~.Y(+..E.... .4..e..p....?Ti..3i.[Q.P]=.32....2r.n......t\.Y...T.7^:...R..&0.Tw.K:.N.a4....}.g......-;..O..Q.gu..9...a.....5...../.Oe\"+8......]/.....r.J.t/n'...2..n....NF.q\..h.x..)x....E...>...O..=3D!T..&\.*...@.q.-.....>*5.<..mW....Ap.^..r{%.t`...4..K.hz..!%.a.W..s.....!...}...xujKX.h....(.>..G....,.;<....K.3._5Bu8.....;.T.\..... B..y.P..e..w.y.I`.L.&..Q..f....{..=36....w?.DB"D.m.F.Z|.a......, .m....N.5..?..4..'.H}.....ox^.....@...0.C.....~..G9q.'EU.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):33828
                        Entropy (8bit):7.995608676675862
                        Encrypted:true
                        SSDEEP:
                        MD5:C9CC84846C85DE0E13D4F32E241A44CA
                        SHA1:1E56B1EC73600EAE9BB283222B28A7C175644B46
                        SHA-256:CFEC594655C389FC7E0FF6F5F18547DA68E9C16087C31502BDF462A308A932E0
                        SHA-512:AB031C7BEE34ADBA53538E7184EA445198C26C7B5C0B0E19BEBD005EB79D184014A23FC4AD0DE148C739B97AE8B103F11F8D27BE0BB4610EDEC3535BAABDB4B3
                        Malicious:true
                        Preview:t.5.B.A....a.....S..0O@..m.Z...H.cz,.O.L....#r..'....."NJ.K=.$...'U0.-.1Y..j..`].|2..T.{.j^......^.j2y.^...u.0....o7......63t.N..8aj=. p...A.$.....E..[S.k..|.....k..c<....a*.....GC.`....D....B.O.S...ml...#..[pw/Zx.(.q.]l..q...Y.f.+.[....hP.G>0.....n#.%.....jK..^....$...'..........B......7$+....S.-..E:..`s.2.....U.5...#.4..bm_G.....b.[..+..Fi.YC.Vx...9..TiC.......~.o6._..+.......7.]\..-.c.p.B..;_y{.Y(.V.R.,...<...R.......;#.I....ym..\5.Q..C....Z..U.eXS..2%o......:.x#..."/.M.....R. .v^.c...\D......kAP.`.w..t.dM)..U=.z......$.....u.E.....?S....H_..&.1@N...,V.P.+x...y..../..6^y....b.-SL..e_.L..Af.O.p..........S.+{....g....f..u.H..qs.......-.i. .....;J...p..)4hX../S...(`U..=Ol.B.8k1.TRvK.....vR.<F..P.2..M......M..Lr....xd..........W%9...|.7....v1.;b..2sn...>..~?......<v..-J9...u......~..[..|..#..>...?..n.-...mGV2....OK.2.'..._. ...;...8....z.H.....M...c...j...Fz.dV.F.d..r.@)}$1....F..l._...z.%k.P,.......i......y.R.M.J..V.::..%...R.?Y.c..po....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1060
                        Entropy (8bit):7.809129350374338
                        Encrypted:false
                        SSDEEP:
                        MD5:B61D1B787EA602D84168CAC8F145BDF6
                        SHA1:85DC610C5AC870E9AC4397A3E5EF9DD3218ACB57
                        SHA-256:019A31C24EC1FB50A9F240ACAF08A3D8CF5A37AD021A3783A58A8A988E6D9629
                        SHA-512:73C1F62A3FABCF04983C8127844A1FA5C0BFDA21508C16BB2C71EEF352C689F69C0AFA340A58817F20C71DCE83882CD7ED710724D6708FB1709CCDCE72E4DCDC
                        Malicious:false
                        Preview:=k.])e!...~...<....KE.ix](....V}p_.8A..&NS.......L.....k..Q.T~.!.8`.T...^E.+ACK.t-..4....|5%T.Q..B....n.....)P.>m....Q...k.j.2.....b..YL|.lp{F.h...;.u.a]...W...4.h.....SY_.u{J..54...i......9..=....A5y..F.n4..T.[tj.$0.h.YR..../D@....S.s.9.....&.8..>..z...?.Y.B...pUzx..z.z..../..*.u...).R..._...Ut..l...2.h%........Re..C!XV.7C.6....V..;/..46l....%...F.........c...+.aP2..c.....-.....h..<.$...H.G.G........%.R ....e........6..r.<.A/.f..N.3.>.........mY6_.FH..P......9.]...O.O..f..L...W.qm.SEE...~I..q+0..y.m..@Aq.].d.W..K:f.).Q..~} .`.B....|.l.C...nqb.k...Fwo.\.hp'..tDu..T`.....$...tM`......O/bLq..N.}`...b...D.....(...2.....+.F..P....'.?:Lr.s.%R...N.0....J&&>..O3....gR.......X....D.l.W7.........n&;..4.d..t$...X.A....Mnb...g..X.!.dZ..V^...V..`...fQS0....).L...jUO/ ..<..p..b!8..9Dax.H...`....g...d4......Z.o8.....A.Og..@.>..%...P.5.o..X.j..P..Be!.I..l1.+.V9..x.|.R........!.0[...)........w..;.J..Glg.[}...G....~..u/EA`..'..O_...R.w.VSa......K2{L;C5.
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):99364
                        Entropy (8bit):7.998104455862253
                        Encrypted:true
                        SSDEEP:
                        MD5:9018F6B403E206C26EED817489F47851
                        SHA1:29A466D22433AD617B26C4C26E2D23976FDDB6CA
                        SHA-256:D25217ED3B191DE6EA981A2C762E450E6FD5FFEEA65336EEE124CB95847E8AA3
                        SHA-512:0C86F41E10D777AFBE5E365F7901F69E27C383C367DFA69E21F632D4793395BC26B42AE7D3898154DF4CE6D6C6AD94B455AB34711D7ADF61E6F064BF60392F07
                        Malicious:true
                        Preview:..I....2'....r../U.N>.g.6F.......U...r..(%k..a<}w..@..K...........S....E.....h... ..l.....En....0R.,t$.......f..c..-}.......)[x#.n....]J.i..(.mkp...W...*-...:.1..~T..2.th.*.!v....Z>~B:.C.{.n..9....v..~.. ..]......X.t....G.8...ek.\._.+k4..QsW..A>.9a$..Y.g....YW.,...d..[.o...A*{.....{.7.]y.....6d`f.J|.Fi...M.%...K...d.....Rf.^...f..O......S1....}e..jWkq...........&..).Y.&.....%.?.&...y,m....&.Y....%)]q(.8dY<..&...Q...J..{...}..<!&..L...i....Lmc+.V.D.f.'L/..{...!....l......P\..@.........y.q.G=,........UZ....a...;6uk..."..;..@.N.8.;.c.B..E.8F.v..D.(#..%.D..X...{.Q8... ..........s1&...M.R!..jr..c...zD".).K.....(uX.26..wa..7.....8...#<n.}...\7.o+..qy......\.B.=F.'..x.. ..v.^..+.y...6G......ER/z8...."V.zC..U.../.v....D.k..aB$|FX.H...5L.....f.+q?>.d...p6...g...JHr.8.B<..].Q...4BM:....z..O..x..cwU..l...e3......r...i.Sy[...'...F...._.\a.8.l.Ii3.......n....`_...kN.....l..R.D....P?.F?.gL..D.<.`...'.HO..D....jv7..^*...?..../.........m..&..4.U....
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1062
                        Entropy (8bit):7.810064282340467
                        Encrypted:false
                        SSDEEP:
                        MD5:D59FB45B4B27D3D2913DB37ACFFA7B3E
                        SHA1:85FE6F1AA92A3184A98FB591ED25705B41A8BBE8
                        SHA-256:879161515942869A7BE00D40DF9B16C974BB42B7968D1AA0D18554DA497DDCB7
                        SHA-512:CAC41905D5BD60A2842F28964403B5496C76E8C5754F18DEE3633FF0213F7100E105F3DAEB714BA5355125433C7D143408F8A8B9131809F995CFF61108678722
                        Malicious:false
                        Preview:(.....X+S{?.rru.....[....W$.....m..i.....<N......D..i.F..V...0...Km.O.. 9.r|d.......kr4pL..>...{...v.s.DO......)0...;!....8..iW..r%.M.._#.\.*r_E...,W....&....S..3.+.!.J...._...$7.>.S..$.E0<n.....-..N..0.3>$$..:^.Y.&./.hl......V.....7...I..5.#}.7..b7....".R..k....%)Z...`.&..).e......|..vRU.!..S.R...VC.2J.M....ODo....^.....6........m.6.(."~..-.. .....|r..X...+;}.q.."....|.w..0.xW.]v=.Q%'...W\...,.L..T.z..r..C.c.|.j.6J.t.Q.......ft.<B{.....[..!.'>.'`^..a..uUrk.Dt.gX..P.....B....+T.".f...*x.\S.X7.t.Bw ]......1L..s....|...K:{.1...ve.z..........6F.E?....27V..N........s..Q.\e.q.~.f....3.... Sq..G.u.^.W....e...w.....@Q.D...q.,.K.......ov.._d.......r#+....6.t.o_At..O.}9..q.p1.5......G.f....(D..W._{..`..U..E.J...v.......%'.A..N/..~..}....O..zS.....1)w.......*...%r.....<i.RD.D...@.&..Rq....rkS.\.EC.\ev".....p1.u..E...j..+..&.r..~..~N.u.,.........Op....,....Prw...4..h.u...{u...E[........E..@.%.Op%.....\......... ."I...O.......39........n.Id.Y!
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1135
                        Entropy (8bit):7.808121189671173
                        Encrypted:false
                        SSDEEP:
                        MD5:55F30BDBA5045A36E9CA89FB2A08BCBB
                        SHA1:9DAD6BFECD40A7D6924267D6AD1758BBDF85230B
                        SHA-256:9409B1B559724334A7585EDAB84931B86692969B49F74E5F9E18E503D85D73A0
                        SHA-512:7D3195B42AA7E8C3EF070EF11F32A2132A153C36BE7F5F1F1A1486209E826595A90FF7F4124B843F6A4CDC20EEF06F8EFE746F833447EB5F8879B302FC09F1F2
                        Malicious:false
                        Preview:....@...../Zo.X[..X..W<...K.Ji{."Z&...$>..<N...~.......D.2...XJ...B.......hXC&.=!....@].c..0.R..Cc.....g.....Rj..Mb.n.n.....q\u*):...u.]PK....."..+ky...T.....rSH..@*.i...P...lcX...`.........7>.+X.0J.3...d.l..3.U.)~a~.3...#.wc..q.....:..>.....X...=/.2*"#...2....S.w....c....Xe...UN..D......J.L..a...].....,.e........-1..Z...M.+......J....t8.D...d2p.\..67)....NW.v...]KK....uh....g.".6..n)...0.].l..V..)8[c...O..M.W..iR..WY/..._....-...L.3..*B.;A.R........;....S}..q........4.?...b.|=..[.e..g..jJEj..a.mQ.......dw.RU.S....\..Z..v......lo4{B.......m.m.HV..........p#l.hr,.2a.'.j.U...K:..0r~.n?c.DW.s1.m.A.e...k.;.f..Q.v......f.%&..V.?.M"..%..-..!.....]}..n[dGBH...-.._2..O....&(.:WO'y,D.i..I......y..8b.....uU#..a..z.s.......>1d;.2...y..|.U...v.q.b.s7....3....#......&w..RU......B...."^..r9....Z....e.G...9E......z;s.CU*k..7....hH...uUS}.B.7......*..W.v<NR...8|.V.....L....D.....{.-.5t+..-..@..SmY0..O..WG....g.a.H.`.A.eL.@.L...*.x-......=..,.9.`-..n
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1365
                        Entropy (8bit):7.884411415191281
                        Encrypted:false
                        SSDEEP:
                        MD5:754A969E279C0095EA616226555B79F7
                        SHA1:1184676EE8B71C9F36C6D370604C5B49F82A9F08
                        SHA-256:1BDBD4B055D9F93263BEF26B1B4759ED4367B594EFCC0BE06F1DE9DE9BDE354B
                        SHA-512:4F6760EFAB3ABAD7EEC77B90934AE64035570CBA6255C5C476DCB6A63DE3DA55450370736EF7901BD14D63C1D9912221C4B1508874B6E9789ECD9C4642FBA263
                        Malicious:false
                        Preview:..U...d?..SF--.0*k...y...a..J...H........p.....71..e.5.o.r.....8.......s....O.%|........=.^Y....hG...J.c3n`.%...d.S.UZ.5|...x?f.\.......;.....GZ.s..Y.q..o..$..6.._....n.W..T.N/..f.8F3...).i7.sR.A.xj...8n..>*.M..o.)."..z..OF..lM...].u?..c2l%.o....tZ.c>...*.j...$.....6.5gPP.GTa.a.......~.V.......-n3=....../>.QKT..#.sK~....x..!K.V.Fz.......-..(...MHD#&.S...Kg.m.V....}lr.=K..I..U.4.".9.t.n..|0.l..i....Z.~j.L.=%.w..&. tZ_....)<:.Nh..-.. .;.#J.d.....l...#w.. (R.'A.</...mx..Xc.n....Y........$..){z..n.rez....w.PS...J#Q~..$n..<.$.C..2.s..ov.3..!....j+:.).....=3........L.=.U....*Vc..Pz.Ulv.6I.\.../.5..\#..!/..z.8.X...A~C...<"H....9!..("..$F..`....{Sz.~..B...s..+.iI.sg8_...N.;...9....V.......f..ha.k.....qb........5.....q.%...Wy....>.....l3....?..b.Ib.3...[o.....O.2...M.....{".9...b..qa..H@f*C.tLq...|.C.......e|......8..K:RHx#5..7jyj.%`.3S.....l^.....g..L..:.`...;U. @'..ww.......w....4k.$..>2...^.M.:f..3..h^(".,...Z.{..}#a.^.'...3Y..^.....:e...p...d....=m...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1068
                        Entropy (8bit):7.789156806724464
                        Encrypted:false
                        SSDEEP:
                        MD5:9DC3114F5C4528D5114A2DB59415C35B
                        SHA1:91B3FBB9EC1141303DB26A5CC2346D48E42D6A24
                        SHA-256:C49BB987CFF933B99E22AD053A5C1AA6A1F5DF0C06875D21B681F063FDD9041A
                        SHA-512:E87C81425147FA8E7DFD52247D067C617C8DEEA01E03FE27E5F63E2DE574E1CAE37CC15D939CD7D8B9F746F06C1E71C2820A7ACD3DB0E0CF43BFBC1E149D9C23
                        Malicious:false
                        Preview:...zK.X....K~4J.._..^..D.6...._.F...i ../.X7..D..myh..6.rT.t....|...B!...).. 5.....n.j...eD..,)+.w..xYo....~y&7n.#..Dtf\'...r.y.NCMm..}..w..k..w.v..e#.d...._..i*..A8..I.##B{x.{.Va...|.q.L..v..<.H....*...Yx..iz;...?u.....u.9.X.-...m.6..SE...I....N..Y...P.X._...c...6w.k.j5.\.a.X..#..)....D......R.6.4..U.X....(..D..5..hnn ?\.....G..>?uzz....W...?..,..*bE...a..%.N...J.$....[.....b..K...<|R...+.# ..xt./;...IV..e..hV|%...Lv..L.............b.g.w.2..B.D.+....).k.5..;5R..3.:....L...e~b..../....`..A...#.8.8@......i.-jj..0.....'S-<K:...F....,.d.3 _.&V....Vf......::..T"i..)..W........>.,....#j.V.6...q...P2.].........s.P?,..!.ny...g.R<R.i..Rz.-.#).W......OX.......I..1....;.h.....f..b0.E...!...p..............D..M...mU.........i......A.Hi.......b..?]..h....j{..aZ.,LF5.6.;q....qy..N...+.n.H.q.?.p....TN....n~....0........-+a..T..W.....P[..uT..E..-,s..*...H.J...lD.u.'..JO.>.....=9..-XfX@.8b*.]..5.].@.G..;?.)..n.2..xN...J.rD$T..c..".Fhj'Gh\.M.y.!l ;
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):538
                        Entropy (8bit):7.6300191833365165
                        Encrypted:false
                        SSDEEP:
                        MD5:66D434D1E8CE041CAC81897552BF162D
                        SHA1:558F71451BC999003B05C9273D1C42FA0E6DCCC2
                        SHA-256:A3283B79FCF5D0E3BB65EE361832B2CC397C99CB66EAD63A2ABDFDEF6D9CF53D
                        SHA-512:D19075F3206F1FCE7CCAD05495B74A09B784F0E264F411C3C320FA0E72D205ACB1FEAAEB16037B75938BCA6BF8A022D3BD28C516F4F74E18A92A1385A2BC02B7
                        Malicious:false
                        Preview:.c7S..S.h_......r.jF3.fK:..!..&C..=5..D..@&.._..l:3...+..$...g..0.-H.s...g........`.(<^..&..q.d.]>..f_......Z.$L{.!01..&...rn....^3;.R...GV...Y...)L..0.......2........D..%/wT..."0....).]....q.~O.p...*.Q.r....iXK;.l...l..&..y.......i..|.hUz.(.n...d.j.!i..?..'z.....#]h._.].tP.z.L#....w..0!9@\+...S....M]...iO....4t..HX..f...B.I..!C..:...~/..mB.(_.K.....U,....4>........C...E..!..5.|O..v..,.+.`....@.@C..xT*....`...5.gn.....vM...6.u=..Y]gu.....;.%...2..h.;D.D~[..*?..d.p.W....I.y....BJ..3.......?...VC....$\k8...
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:OpenPGP Public Key
                        Category:dropped
                        Size (bytes):550
                        Entropy (8bit):7.655177139356095
                        Encrypted:false
                        SSDEEP:
                        MD5:DE058D5497F28C782B470B22A25EDCCC
                        SHA1:D0BE3476EF1F58F6193AD88DC6C1B2651E13586B
                        SHA-256:5542FF1F5B1D3BD950864BF92956C6E8E9D40AC4D135F46F52E3350CC0B91417
                        SHA-512:03FB9D59CA03B06B64FDE0E714D66D1F7A97F4AA8C1CF162D4167B11F41455607414AF536E71BF7B5686573650F650DEB73028F0982CA4AFD71A3F8CF4632AB6
                        Malicious:false
                        Preview:.....J...^.....l..Z.P... &.Y...\;4K:;{.gJtI.e...P.@...Ot.0...../m........b..+l..2X\J...|....|g !..............#.V.Q...zJ}......A...,;...4Z..mp......n... .......V.t(....QX...8j......(...1KK..o.3...s9Z.y.=.Eq...... .!i..@...=..O..UQw.6..wP.~.+........J2.#..H......O.E.],I..-j..0z.0....D.gzd.x....S..........h.&......7.*10.....G.E..7(..:"..Z-...Dw~t.\...r=..f..z.<>TV..... .A.z.yZDf...-......E.8.8..$.3_....kHQ^s.G85..J...N...B.V.2....*l...&.-tP.#P...g.....B...k....-....D..r.....7o...+U...s..-..{.M..z..W...?O..5.\...S.=..
                        Process:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        File Type:ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5
                        Entropy (8bit):2.321928094887362
                        Encrypted:false
                        SSDEEP:
                        MD5:AD20B43650D9760DA69255BB4B6939E2
                        SHA1:366E5E1F3A42873808359C9F842FD834569E0BC1
                        SHA-256:11C04C6D809C6684BE6C8883B73CBF50FA2557C61B3043056C6EF22DA06C8882
                        SHA-512:3E0F9C8CE6DB4E87701484DCED45DF62B414C52B3DBF1BAA9ED32F0E2B835E17B88134176EF606E73DCB035B394AAE8EFE0FE9132B2FF7F537C3448FA8373D1A
                        Malicious:false
                        Preview:C:\..
                        File type:PE32 executable (console) Intel 80386, for MS Windows
                        Entropy (8bit):6.582344067937223
                        TrID:
                        • Win32 Executable (generic) a (10002005/4) 99.96%
                        • Generic Win/DOS Executable (2004/3) 0.02%
                        • DOS Executable Generic (2002/1) 0.02%
                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                        File name:OZ1ORrbotn.exe
                        File size:970'240 bytes
                        MD5:ccaa87a7a44fa59ae536138e2313bc3e
                        SHA1:01cb1af569bf29abb61f7d38623dd82c86c82617
                        SHA256:768d390a232501b58b9626b4764d10f7a41732dbd5a8f559664d2f1d9f7d1cd0
                        SHA512:b9acb03117948cddd384dd4cadaa32284a438ad4911511413cf5ae22a854f4ad3e39a4a0fd992d33d61ae8fc4c3438eaf4925f733001fa906357d1f71aa35402
                        SSDEEP:24576:QJ4CJtmWWjp3e2Z4lesBsw6bDrNKZC/iUs+:QJ7JJqpRsVB+DZKEiUb
                        TLSH:4C258E20B652F437E8B344B28EBCEA5E552CFC5007245DDFB3C826AD6A750D12E33696
                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........H.y.)g*.)g*.)g*:..*.)g*:..*+)g*:..*.)g*.Ad+.)g*.Ab+.)g*.Ac+.)g*.Q.*.)g*.)f*.)g*.Bb+.)g*%@b+.)g*%@.*.)g*%@e+.)g*Rich.)g*.......
                        Icon Hash:90cececece8e8eb0
                        Entrypoint:0x469650
                        Entrypoint Section:.text
                        Digitally signed:false
                        Imagebase:0x400000
                        Subsystem:windows cui
                        Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                        DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                        Time Stamp:0x66E346D5 [Thu Sep 12 19:53:57 2024 UTC]
                        TLS Callbacks:
                        CLR (.Net) Version:
                        OS Version Major:5
                        OS Version Minor:1
                        File Version Major:5
                        File Version Minor:1
                        Subsystem Version Major:5
                        Subsystem Version Minor:1
                        Import Hash:0f08693ab833479be49010b596b1e753
                        Instruction
                        call 00007F8D24B87E43h
                        jmp 00007F8D24B8706Dh
                        int3
                        int3
                        int3
                        int3
                        int3
                        int3
                        cmp cl, 00000040h
                        jnc 00007F8D24B87217h
                        cmp cl, 00000020h
                        jnc 00007F8D24B87208h
                        shld edx, eax, cl
                        shl eax, cl
                        ret
                        mov edx, eax
                        xor eax, eax
                        and cl, 0000001Fh
                        shl edx, cl
                        ret
                        xor eax, eax
                        xor edx, edx
                        ret
                        int3
                        push esi
                        mov eax, dword ptr [esp+14h]
                        or eax, eax
                        jne 00007F8D24B8722Ah
                        mov ecx, dword ptr [esp+10h]
                        mov eax, dword ptr [esp+0Ch]
                        xor edx, edx
                        div ecx
                        mov ebx, eax
                        mov eax, dword ptr [esp+08h]
                        div ecx
                        mov esi, eax
                        mov eax, ebx
                        mul dword ptr [esp+10h]
                        mov ecx, eax
                        mov eax, esi
                        mul dword ptr [esp+10h]
                        add edx, ecx
                        jmp 00007F8D24B87249h
                        mov ecx, eax
                        mov ebx, dword ptr [esp+10h]
                        mov edx, dword ptr [esp+0Ch]
                        mov eax, dword ptr [esp+08h]
                        shr ecx, 1
                        rcr ebx, 1
                        shr edx, 1
                        rcr eax, 1
                        or ecx, ecx
                        jne 00007F8D24B871F6h
                        div ebx
                        mov esi, eax
                        mul dword ptr [esp+14h]
                        mov ecx, eax
                        mov eax, dword ptr [esp+10h]
                        mul esi
                        add edx, ecx
                        jc 00007F8D24B87210h
                        cmp edx, dword ptr [esp+0Ch]
                        jnbe 00007F8D24B8720Ah
                        jc 00007F8D24B87211h
                        cmp eax, dword ptr [esp+08h]
                        jbe 00007F8D24B8720Bh
                        dec esi
                        sub eax, dword ptr [esp+10h]
                        sbb edx, dword ptr [esp+14h]
                        xor ebx, ebx
                        sub eax, dword ptr [esp+08h]
                        sbb edx, dword ptr [esp+0Ch]
                        neg edx
                        neg eax
                        sbb edx, 00000000h
                        mov ecx, edx
                        mov edx, ebx
                        mov ebx, ecx
                        mov ecx, eax
                        mov eax, esi
                        pop esi
                        retn 0010h
                        int3
                        int3
                        Programming Language:
                        • [IMP] VS2008 SP1 build 30729
                        NameVirtual AddressVirtual Size Is in Section
                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IMPORT0xdb6140x3c.rdata
                        IMAGE_DIRECTORY_ENTRY_RESOURCE0xe70000x1e0.rsrc
                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                        IMAGE_DIRECTORY_ENTRY_BASERELOC0xe80000xa9bc.reloc
                        IMAGE_DIRECTORY_ENTRY_DEBUG0xc90000x70.rdata
                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                        IMAGE_DIRECTORY_ENTRY_TLS0xc91100x18.rdata
                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xc90700x40.rdata
                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IAT0xaf0000x234.rdata
                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                        .text0x10000xada3a0xadc00c9f7ea6efd13b48b75563a77357e4232False0.4660816659172662data6.581795528318743IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                        .rdata0xaf0000x2d3100x2d400c8a612cbb37f40b0a2b58257ed06f4b4False0.37933787983425415data5.078661474498864IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        .data0xdd0000x95080x6e0028b2152e37ed7077e57d0d6bf22a55deFalse0.16019176136363636data4.951631141802382IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                        .rsrc0xe70000x1e00x200850aa99c8c1a85dc7545811d66bb0c17False0.52734375data4.7176788329467545IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        .reloc0xe80000xa9bc0xaa00f58e61be6be8ec95a0ece286729bdb0dFalse0.5607536764705883data6.5391247441917955IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                        NameRVASizeTypeLanguageCountryZLIB Complexity
                        RT_MANIFEST0xe70600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                        DLLImport
                        KERNEL32.dllGetLogicalDriveStringsW, GetDriveTypeA, GetDriveTypeW, FreeConsole, GetLastError, FindNextFileW, QueryPerformanceCounter, QueryPerformanceFrequency, GetCurrentThread, GetThreadTimes, SetEndOfFile, FindFirstFileW, lstrcmpW, SetLastError, FindClose, WideCharToMultiByte, MultiByteToWideChar, GetStringTypeW, FormatMessageW, CloseHandle, DuplicateHandle, WaitForSingleObjectEx, Sleep, GetCurrentProcess, SwitchToThread, GetCurrentThreadId, GetExitCodeThread, EnterCriticalSection, LeaveCriticalSection, TryEnterCriticalSection, DeleteCriticalSection, GetCurrentDirectoryW, CreateDirectoryW, CreateFileW, DeleteFileW, FindFirstFileExW, GetDiskFreeSpaceExW, GetFileAttributesExW, GetFileInformationByHandle, AreFileApisANSI, GetModuleHandleW, GetProcAddress, CopyFileW, MoveFileExW, EncodePointer, DecodePointer, InitializeCriticalSectionAndSpinCount, CreateEventW, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetSystemTimeAsFileTime, GetTickCount, CompareStringW, LCMapStringW, GetLocaleInfoW, GetCPInfo, SetEvent, ResetEvent, InitializeSListHead, IsProcessorFeaturePresent, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetStartupInfoW, TerminateProcess, GetCurrentProcessId, CreateTimerQueue, SignalObjectAndWait, CreateThread, SetThreadPriority, GetThreadPriority, GetLogicalProcessorInformation, CreateTimerQueueTimer, ChangeTimerQueueTimer, DeleteTimerQueueTimer, GetNumaHighestNodeNumber, GetProcessAffinityMask, SetThreadAffinityMask, RegisterWaitForSingleObject, UnregisterWait, FreeLibrary, FreeLibraryAndExitThread, GetModuleFileNameW, GetModuleHandleA, LoadLibraryExW, GetVersionExW, VirtualAlloc, VirtualProtect, VirtualFree, ReleaseSemaphore, InterlockedPopEntrySList, InterlockedPushEntrySList, InterlockedFlushSList, QueryDepthSList, UnregisterWaitEx, LoadLibraryW, RaiseException, RtlUnwind, ExitThread, GetModuleHandleExW, ExitProcess, GetModuleFileNameA, GetStdHandle, WriteFile, GetCommandLineA, GetCommandLineW, GetACP, HeapAlloc, HeapFree, GetFileType, GetDateFormatW, GetTimeFormatW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, FlushFileBuffers, GetConsoleCP, GetConsoleMode, ReadFile, ReadConsoleW, SetFilePointerEx, GetTimeZoneInformation, HeapReAlloc, HeapSize, FindFirstFileExA, FindNextFileA, IsValidCodePage, GetOEMCP, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableA, GetProcessHeap, SetStdHandle, WriteConsoleW
                        ADVAPI32.dllCryptReleaseContext, CryptAcquireContextA, CryptGenRandom
                        Language of compilation systemCountry where language is spokenMap
                        EnglishUnited States
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Nov 2, 2024 17:15:01.796657085 CET1.1.1.1192.168.2.30x5453No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                        Nov 2, 2024 17:15:01.796657085 CET1.1.1.1192.168.2.30x5453No error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
                        Nov 2, 2024 17:19:13.054436922 CET1.1.1.1192.168.2.30xdb66No error (0)shed.dual-low.s-part-0036.t-0009.t-msedge.nets-part-0036.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                        Nov 2, 2024 17:19:13.054436922 CET1.1.1.1192.168.2.30xdb66No error (0)s-part-0036.t-0009.t-msedge.net13.107.246.64A (IP address)IN (0x0001)false

                        Click to jump to process

                        Click to jump to process

                        Click to jump to process

                        Target ID:0
                        Start time:12:15:04
                        Start date:02/11/2024
                        Path:C:\Users\user\Desktop\OZ1ORrbotn.exe
                        Wow64 process (32bit):true
                        Commandline:"C:\Users\user\Desktop\OZ1ORrbotn.exe"
                        Imagebase:0x970000
                        File size:970'240 bytes
                        MD5 hash:CCAA87A7A44FA59AE536138E2313BC3E
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        Target ID:1
                        Start time:12:15:04
                        Start date:02/11/2024
                        Path:C:\Windows\System32\conhost.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Imagebase:0x7ff720030000
                        File size:873'472 bytes
                        MD5 hash:7366FBEFE66BA0F1F5304F7D6FEF09FE
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:moderate
                        Has exited:true

                        Target ID:8
                        Start time:12:16:25
                        Start date:02/11/2024
                        Path:C:\Windows\System32\OpenWith.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\OpenWith.exe -Embedding
                        Imagebase:0x7ff7aa1d0000
                        File size:123'984 bytes
                        MD5 hash:E4A834784FA08C17D47A1E72429C5109
                        Has elevated privileges:false
                        Has administrator privileges:false
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        No disassembly